Folks, I'm excited to announce something for all the die hard Intune fans.
Check out today!
+ bookmark it.
BONUS: Sign up for the email newsletter to get the updates delivered straight to you inbox daily.
As orgs move deeper into M365, Entra ID resilience has become essential to operational continuity.
Join @Merill Fernando and Craig Birch to explore the new reality of Microsoft identity recovery and hybrid identity resilience.
👉Register here:
Excited to speak at HIP Conf 26 in Nashville! My session “KDS Root Keys and Where to Find Them” will cover online and offline attacks against virtually all KDS Root Key scenarios.
#HIPConf# registration:
@merill Feels like I've been fighting NTLM for the longest time. Even when appropriately configured, the controls are only as strong as the apps that honor them. It's a dumpster fire -
@merill It’s 2026 and no central way to easily audit Kerberos and NTLM. I get I can look at audit logs, but I want a web dashboard.
One good outcome would be to “see” if someone adds a new Kerberos app. I work on a site with 200 admins. No one can see everything going on.
New video: device-bound vs. syncable passkeys in Microsoft Entra
• technical differences e.g. private key handling
• where Microsoft Authenticator comes into it
• risk trade offs
• most likely model for most folks
WATCH:
#MicrosoftEntra# #Passkeys# #Microsoft365#
It's 2026.
You should not be onboarding apps that still use Kerberos and NTLM.
You should be actively looking to migrate them to modern authentication.
I hope that's something all of us in cyber can agree on.
Hard to say I agree with @merill, @techspence, AND @JorgeALopez because I thought there was going to be a battle royal over this. The post isn't "AD is going away". It's "make AD less important to your business". Crap, I guess this is a 🧵.
Microsoft Digital Defence Report on Ransomware
The Microsoft Digital Defence Report from last year is a fascinating read and shows how most ransomware compromised orgs could have avoided it by just doing the basics.
Here's an overview of the report in the context of the recent MGM news.
There are just a handful of companies in the world that have access to the type of data and attacks that Microsoft has visibility into.
The State of Cybercrime
Microsoft's unique breadth of signal intelligence is gathered from multiple sources—identity, email, endpoints, and cloud—and provides insight into the growing ransomware economy, complete with an affiliate system which includes tools designed for less technically-abled attackers.
Human operated ransomware targeting and rate of success model
🧵👇🏾
Did you know that you can download Microsoft Entra Architecture Icons from 👌
Please like and repost to share with your network.
Remember to follow me for more tips like this + sign up to my weekly Microsoft Entra newsletter @