Users are still being prompted for MFA with a Conditional Access exclusion in-place
I am trying to configure conditional access policies in Microsoft Entra for a hybrid environment. The end goal is to enforce MFA for all high risk sign-ins, but keeping seamless sign-in for trusted locations. I am encountering ann issue where users that…
Microsoft Entra ID
Strange auto-generated resources appeared in Azure
This week in one of the tenants we manage something strange happened. On Tuesday on 5:40 am (CET) suddenly all subscriptions got resources deployed. The resource groups which were deployed are attached as a screenshot. One of the resource groups is…
Azure Automation
Microsoft Entra ID

Cannot refresh a token with admin consented scope for business central
We’re trying to build an integration that connects with Microsoft Business Central for our customers. This integration needs access to read and write data to Microsoft Business Central. Our setup We’ve created a multi-tenant application with Web…
Microsoft Entra ID
AADSTS500089: SAML 2.0 assertion validation failed: SAML token is invalid
As per https://learn.microsoft.com/en-us/entra/external-id/direct-federation, the recommended Audience for new federations is https://login.microsoftonline.com/<tenant ID>/. However, when I use it, I get AADSTS500089: SAML 2.0 assertion validation…
Microsoft Entra ID

AADSTS53003 Access has been blocked by Conditional Access policies.
We are trying to run some code to pull data from Kusto DB/SQL (Azure Resources) using our C# code and that was working fine till some days ago. But when I tried to run the code two days ago, it started failing due to “Access has been blocked by…
Microsoft Entra ID
how to fix ad connect sync
Hi My issue is. Tried to do an azure ad connect sync, which seemingly worked. all of a sudden the majority of users on our 365 tenant got signed out and their ad account merged with their 365 account - issue is we cant change aliases etc and now we are…
Microsoft Entra ID
Enterprise App with custom domain is not showing proper SSL information.
I have some Enterprise Apps that are using App Proxy with custom domain. The wildcard certificate was updated but now it shows the msappproxy.net certificate, resulting in an error in the Common Name. This is new with the updated certificate. How can I…
Microsoft Entra ID
Help! Security defaults & conditional access in Entra - messed some things up!
I'm a very novice admin for all Office 365 platforms for our very small company...so take that with a grain of salt. Here's what happened: We were trying to install a new multipurpose printer/scanner/copier. The tech needed an email address within my org…
Microsoft Entra ID
Unable to log into Entra ID joined Azure VM
I can access the VM using the admin account, but not with my Entra ID account. Per the "Support + troubleshooting" suggestions, I have reset the NIC a few times, also redeployed the solution a few times, gotten all green marks from the Azure…
Microsoft Entra ID

Microsoft Entra Provisioning Agent Configuration skips Connect Active Directory
I am adding a second agent. When running the agent configuration, it goes from Connect Microsoft Entra ID to Confirm thus bypassing Connect Active Directory. The agent shows up in the portal but is listed as "not configured." What do I need to…
Microsoft Entra ID
Cancel free Entra ID P2 trial
I need to cancel Microsoft Entra ID P2 free trial before I am charged for 100 licenses. I try to go into the M365 Admin Center to cancel, and it takes me to GoDaddy. Thanks,
Microsoft Entra ID
Can not log in to the Azure Portal because of an incomplete MFA setup
Dear Team, Recently, i can not log in to my Azure tenant, due to the incomplete MFA setup, please help me with this. Thank you.
Microsoft Entra ID
RADIUS feature in Entra ID
Hi All, Referring to this document, it explains that Entra ID can be integrated with RADIUS for MFA needs. https://learn.microsoft.com/en-us/entra/architecture/auth-radius The question is, Does Entra ID have a RADIUS feature itself? Thank you.
Microsoft Entra ID
Mircrosoft Single Sign on extension for Chrome
Microsoft Single Sign-On extension in the Chrome browser for MacOS is inconsistently pulling the required device status(Join Type,Manage), which is affecting Entra ID Conditional Access. Here are the specifics: OS: MacOS Browser: Chrome…
Microsoft Entra ID
Unable to delete the User Added to account on the contact ******@robolens.ai
For the user, ******@robolens.ai, have the other contact email as ******@robolens.ai. When I go to edit properties on the email ******@robolens.ai, I am unable to remove other email. Please help removing it or grant me access to remove it !
Microsoft Entra ID
Obtain the ExtensionProperty with Get-MgUser as if obtained with the Get-AzureADUser command through an App with Entra ID
Good afternoon. Greetings. Due to an error that is throwing me the Get-AzureADUser command to access an App with Entra ID, I can continue using it for other implementations:…
Microsoft Entra ID
Locked out of Entra / Admin Centre and cannot disable trial
Hello, I created an EntraID trial and had to add a CC in order to test out an integration with Google Workspace SSO. Long story short the Integration did not work and locked out my ability to login to the EntraID Trial. I just received an email that…
Microsoft Entra ID
Authentication using Entra ID for VM by using bastion not working
Hello, I was testing implementation of authentication using Entra ID for azure virtual machine. I have followed User has role Virtual Machine Administrator Login, installed extension on VM AADLoginForWindows by while creating Azure VM -> Management…
Microsoft Entra ID
List role-definition Microsoft Graph API endpoint not returning few role-definitions
I am trying to fetch list of all role-definitions defined in an Entra tenant using the API endpoint: GET https://graph.microsoft.com/v1.0/roleManagement/directory/roleDefinitions Then, I want to query the list of role-assignments for the…
Microsoft Entra ID
How to limit user access to administrators of the organisation in a B2C tenant in the SignInOnly custom policy?
I'm trying to create an admin application that will use the SignInOnly custom policy provided at: https://github.com/azure-ad-b2c/samples/blob/master/policies/invite/policy/SignInOnly.xml This loads fine, but I now want to limit this to use only…