azureblog.co.uk
// entra id · intune · azure

Microsoft cloud changes, explained for the people who run it.

What's new in Entra ID, Intune and Azure, what it means in practice, and the steps and scripts to act on it.

Next deadline · Windows Server 2012 / 2012 R2 Extended Security Updates end in 5 days timeline →

Free admin tools

They run in your browser. Nothing you paste leaves your machine.

all 18 tools →

Learning paths

Posts in a sensible order, with your progress saved.

all 7 paths →

Recent changes

What Microsoft changed, and what needs action.

change feed →
  1. Deployment plans: staged rollouts in ringsNew
  2. Client-driven compliance evaluationPreview
  3. Multi Admin Approval now applies to Microsoft Graph callsChangeaction
  4. Windows 11 26H2 security baselineNew
  5. iOS/iPadOS 18 is now the minimumChangeaction

Entra ID

Identity, sign-in, Conditional Access and governance.

all 35 posts →

Intune

Device management, compliance and apps.

all 9 posts →

Azure

Platform, networking, governance and cost.

all 10 posts →

All posts

50 posts
  1. Road to 50: how this blog runs for about £1 a monthAzure
  2. Intune in September: deployment rings, faster compliance and stricter automationIntune · Windows news
  3. Lock down app consent without blocking your usersEntra ID · Security
  4. Unattended Graph PowerShell scripts with certificate authenticationPowerShell · Entra ID
  5. Microsoft is retiring its own SMS and voice MFA. Here's your plan.Entra ID · Security news
  6. Intune in August: unattended Remote Help, DDM app installs and eSIMIntune news
  7. Stop surprise Azure bills with budgets and anomaly alertsAzure · Governance
  8. Private endpoints and DNS: why your private endpoint isn't being usedAzure · Security
  9. Key Vault: move from access policies to Azure RBACAzure · Security
  10. Intune in July: macOS custom compliance and Defender settings that finally winIntune · Security news
  11. Windows LAPS with Intune: unique local admin passwords in minutesIntune · Windows
  12. Microsoft Authenticator now blocks jailbroken and rooted devicesEntra ID · Security news
  13. BYOD Windows access with Entra registration is now GAEntra ID · Windows news
  14. Entra Connect Sync is on its way out. Start planning for Cloud Sync.Entra ID · Hybrid identity news
  15. Intune's advanced features are coming to Microsoft 365 E3 and E5Intune · Microsoft 365 news
  16. Entra Backup and Recovery is here: an undo button for your tenantEntra ID news
  17. Account Discovery: find the accounts your SaaS apps forgot to tell you aboutEntra ID · Governance news
  18. Soft delete for Entra device objects: a safety net for device clean-upsEntra ID · Windows news
  19. Cross-tenant group sync is GA: one group, many tenantsEntra ID · Governance news
  20. System-preferred authentication now picks the first factor tooEntra ID · Passkeys news
  21. Rolling out "require compliant device" without a flood of ticketsIntune · Conditional Access
  22. Packaging Win32 apps for Intune: detection rules and return codesIntune · Windows
  23. Entra Agent ID: giving AI agents real identitiesEntra ID · Security news
  24. Configurable token lifetimes are GA: when to shorten them (and when not to)Entra ID · Security news
  25. Require phishing-resistant MFA on every PIM activationEntra ID · Governance news
  26. Intune Remediations: find and fix problems before users noticeIntune · Windows
  27. Tenant configuration management: snapshot your Entra config and catch driftEntra ID · Governance news
  28. Hybrid join without Entra Connect: hybrid join using Entra KerberosEntra ID · Hybrid identity news
  29. Clean up guest accounts with access reviewsEntra ID · Governance
  30. Synced passkeys and passkey profiles are now GA in Entra IDEntra ID · Passkeys news
  31. Six KQL queries for Entra sign-in logs every admin should keepEntra ID · Azure
  32. Why Edge suddenly switched language on a whole officeIntune · Windows
  33. External MFA is GA: third-party MFA without giving up Conditional AccessEntra ID · Security news
  34. Resource locks: a cheap insurance policy against the wrong clickAzure · Governance
  35. Group-based licensing: finding and fixing assignment errorsEntra ID · Microsoft 365
  36. Azure Policy guardrails every subscription should haveAzure · Governance
  37. Converting synced users to cloud-managed: Source of Authority is GAEntra ID · Hybrid identity news
  38. Deploy from GitHub Actions to Azure without storing a single secretAzure · Entra ID
  39. AADSTS75011: when the app insists on how you signed inEntra ID
  40. Managed identities vs service principals: which should your workload use?Azure · Entra ID
  41. Named locations: getting IP ranges and countries right in Conditional AccessEntra ID · Conditional Access
  42. Authentication strengths: requiring the right kind of MFAEntra ID · Conditional Access
  43. Turning on Defender CSPM across a landing zoneAzure · Security
  44. Test Conditional Access safely with report-only mode and What IfEntra ID · Conditional Access
  45. SCIM provisioning when every target is its own appEntra ID
  46. Break-glass accounts done rightEntra ID · Security
  47. Activate PIM roles from PowerShell with Microsoft GraphEntra ID · PowerShell
  48. Find expiring app secrets and certificates before they biteEntra ID · PowerShell
  49. Rolling a SAML signing certificate without an outageEntra ID
  50. Temporary Access Pass: onboarding users without a passwordEntra ID · Passkeys