Microsoft cloud changes, explained for the people who run it.
What's new in Entra ID, Intune and Azure, what it means in practice, and the steps and scripts to act on it.
PS> Connect-AzureBlog -Site azureblog.co.uk ✓ Connected · Static Web Apps · edge: global PS> Get-Post -Latest 3 | Format-List Title Title : Road to 50: how this blog runs for about £1 a month Title : Intune in September: deployment rings, faster compliance and stricter automation Title : Lock down app consent without blocking your users PS> # 50 posts · 18 tools · 9 deadlines tracked
Latest
RSS feed →Free admin tools
They run in your browser. Nothing you paste leaves your machine.
Learning paths
Posts in a sensible order, with your progress saved.
Recent changes
What Microsoft changed, and what needs action.
Entra ID
Identity, sign-in, Conditional Access and governance.
- PowerShell · Entra ID
Unattended Graph PowerShell scripts with certificate authentication
Scheduled scripts can't answer an MFA prompt. App-only authentication with a certificate is the right way to run Microsoft Graph PowerShell unattended.
- Entra ID · Security
Microsoft is retiring its own SMS and voice MFA. Here's your plan.
Microsoft-provided text and phone call authentication in Entra ID ends for most users on 1 February 2027. Passkeys are already being switched on. What changes, when, and what to do now.
- Entra ID · Security
Microsoft Authenticator now blocks jailbroken and rooted devices
Authenticator now refuses to add or use work and school accounts on jailbroken or rooted phones. There's nothing to configure, but your service desk should know.
Intune
Device management, compliance and apps.
- Intune · What's new
Intune in August: unattended Remote Help, DDM app installs and eSIM
Helpdesk agents can now support Windows devices with nobody at the keyboard, Apple VPP apps can install through declarative device management, and corporate Android gets eSIM control.
- Intune · Security
Intune in July: macOS custom compliance and Defender settings that finally win
Custom compliance comes to macOS, a preview stops Group Policy overriding your Defender settings, and Store app search goes regional.
- Intune · Windows
Windows LAPS with Intune: unique local admin passwords in minutes
If every PC shares the same local administrator password, one compromised machine means all of them. Windows LAPS fixes that, and it's built into Windows and Intune.
Azure
Platform, networking, governance and cost.
- Azure · Governance
Stop surprise Azure bills with budgets and anomaly alerts
Azure won't stop you spending, but it will tell you early if you set it up. Two features take five minutes and catch most surprises.
- Azure · Security
Private endpoints and DNS: why your private endpoint isn't being used
You created a private endpoint, but traffic still goes to the public IP. It's almost always DNS. How private endpoint name resolution works and how to fix it.
- Azure · Security
Key Vault: move from access policies to Azure RBAC
Key Vault has two permission models. Azure RBAC is the recommended one, and switching is simpler than it looks if you plan the role mapping first.
All posts
50 posts- Road to 50: how this blog runs for about £1 a monthAzure
- Intune in September: deployment rings, faster compliance and stricter automationIntune · Windows news
- Lock down app consent without blocking your usersEntra ID · Security
- Unattended Graph PowerShell scripts with certificate authenticationPowerShell · Entra ID
- Microsoft is retiring its own SMS and voice MFA. Here's your plan.Entra ID · Security news
- Intune in August: unattended Remote Help, DDM app installs and eSIMIntune news
- Stop surprise Azure bills with budgets and anomaly alertsAzure · Governance
- Private endpoints and DNS: why your private endpoint isn't being usedAzure · Security
- Key Vault: move from access policies to Azure RBACAzure · Security
- Intune in July: macOS custom compliance and Defender settings that finally winIntune · Security news
- Windows LAPS with Intune: unique local admin passwords in minutesIntune · Windows
- Microsoft Authenticator now blocks jailbroken and rooted devicesEntra ID · Security news
- BYOD Windows access with Entra registration is now GAEntra ID · Windows news
- Entra Connect Sync is on its way out. Start planning for Cloud Sync.Entra ID · Hybrid identity news
- Intune's advanced features are coming to Microsoft 365 E3 and E5Intune · Microsoft 365 news
- Entra Backup and Recovery is here: an undo button for your tenantEntra ID news
- Account Discovery: find the accounts your SaaS apps forgot to tell you aboutEntra ID · Governance news
- Soft delete for Entra device objects: a safety net for device clean-upsEntra ID · Windows news
- Cross-tenant group sync is GA: one group, many tenantsEntra ID · Governance news
- System-preferred authentication now picks the first factor tooEntra ID · Passkeys news
- Rolling out "require compliant device" without a flood of ticketsIntune · Conditional Access
- Packaging Win32 apps for Intune: detection rules and return codesIntune · Windows
- Entra Agent ID: giving AI agents real identitiesEntra ID · Security news
- Configurable token lifetimes are GA: when to shorten them (and when not to)Entra ID · Security news
- Require phishing-resistant MFA on every PIM activationEntra ID · Governance news
- Intune Remediations: find and fix problems before users noticeIntune · Windows
- Tenant configuration management: snapshot your Entra config and catch driftEntra ID · Governance news
- Hybrid join without Entra Connect: hybrid join using Entra KerberosEntra ID · Hybrid identity news
- Clean up guest accounts with access reviewsEntra ID · Governance
- Synced passkeys and passkey profiles are now GA in Entra IDEntra ID · Passkeys news
- Six KQL queries for Entra sign-in logs every admin should keepEntra ID · Azure
- Why Edge suddenly switched language on a whole officeIntune · Windows
- External MFA is GA: third-party MFA without giving up Conditional AccessEntra ID · Security news
- Resource locks: a cheap insurance policy against the wrong clickAzure · Governance
- Group-based licensing: finding and fixing assignment errorsEntra ID · Microsoft 365
- Azure Policy guardrails every subscription should haveAzure · Governance
- Converting synced users to cloud-managed: Source of Authority is GAEntra ID · Hybrid identity news
- Deploy from GitHub Actions to Azure without storing a single secretAzure · Entra ID
- AADSTS75011: when the app insists on how you signed inEntra ID
- Managed identities vs service principals: which should your workload use?Azure · Entra ID
- Named locations: getting IP ranges and countries right in Conditional AccessEntra ID · Conditional Access
- Authentication strengths: requiring the right kind of MFAEntra ID · Conditional Access
- Turning on Defender CSPM across a landing zoneAzure · Security
- Test Conditional Access safely with report-only mode and What IfEntra ID · Conditional Access
- SCIM provisioning when every target is its own appEntra ID
- Break-glass accounts done rightEntra ID · Security
- Activate PIM roles from PowerShell with Microsoft GraphEntra ID · PowerShell
- Find expiring app secrets and certificates before they biteEntra ID · PowerShell
- Rolling a SAML signing certificate without an outageEntra ID
- Temporary Access Pass: onboarding users without a passwordEntra ID · Passkeys
$ no posts match that search. Try another word or clear the filter.