// graph
How everything connects
171 posts, tools, paths, labs and terms, joined by 351 links. Drag to move around, scroll or pinch to zoom, and select anything to open it.
Browse everything as a list
Hubs
Posts
- AADSTS75011: when the app insists on how you signed in
- Account Discovery: find the accounts your SaaS apps forgot to tell you about
- Activate PIM roles from PowerShell with Microsoft Graph
- Authentication strengths: requiring the right kind of MFA
- Azure Policy guardrails every subscription should have
- Break-glass accounts done right
- BYOD Windows access with Entra registration is now GA
- Clean up guest accounts with access reviews
- Configurable token lifetimes are GA: when to shorten them (and when not to)
- Converting synced users to cloud-managed: Source of Authority is GA
- Cross-tenant group sync is GA: one group, many tenants
- Deploy from GitHub Actions to Azure without storing a single secret
- Entra Agent ID: giving AI agents real identities
- Entra Backup and Recovery is here: an undo button for your tenant
- Entra Connect Sync is on its way out. Start planning for Cloud Sync.
- External MFA is GA: third-party MFA without giving up Conditional Access
- Find expiring app secrets and certificates before they bite
- Group-based licensing: finding and fixing assignment errors
- Hybrid join without Entra Connect: hybrid join using Entra Kerberos
- Intune in August: unattended Remote Help, DDM app installs and eSIM
- Intune in July: macOS custom compliance and Defender settings that finally win
- Intune in September: deployment rings, faster compliance and stricter automation
- Intune Remediations: find and fix problems before users notice
- Intune's advanced features are coming to Microsoft 365 E3 and E5
- Key Vault: move from access policies to Azure RBAC
- Lock down app consent without blocking your users
- Managed identities vs service principals: which should your workload use?
- Microsoft Authenticator now blocks jailbroken and rooted devices
- Microsoft is retiring its own SMS and voice MFA. Here's your plan.
- Named locations: getting IP ranges and countries right in Conditional Access
- Packaging Win32 apps for Intune: detection rules and return codes
- Private endpoints and DNS: why your private endpoint isn't being used
- Require phishing-resistant MFA on every PIM activation
- Resource locks: a cheap insurance policy against the wrong click
- Road to 50: how this blog runs for about £1 a month
- Rolling a SAML signing certificate without an outage
- Rolling out "require compliant device" without a flood of tickets
- SCIM provisioning when every target is its own app
- Six KQL queries for Entra sign-in logs every admin should keep
- SOC Identity Responder: contain a compromised account without handing out admin roles
- Soft delete for Entra device objects: a safety net for device clean-ups
- Stop surprise Azure bills with budgets and anomaly alerts
- Synced passkeys and passkey profiles are now GA in Entra ID
- System-preferred authentication now picks the first factor too
- Temporary Access Pass: onboarding users without a password
- Tenant configuration management: snapshot your Entra config and catch drift
- Test Conditional Access safely with report-only mode and What If
- Turning on Defender CSPM across a landing zone
- Unattended Graph PowerShell scripts with certificate authentication
- Why Edge suddenly switched language on a whole office
- Windows LAPS with Intune: unique local admin passwords in minutes
Topics
Learning paths
- Automating Entra and Azure safely
- Azure landing zone guardrails
- Conditional Access from zero
- Entra ID foundations for new admins
- Identity security operations
- Intune for Windows, start to finish
- Locking down admin access
- Passwordless rollout
- Ready for the 2026 and 2027 retirements
- Shrinking hybrid identity
Tools
- AADSTS error lookup
- Am I affected?
- Azure naming generator
- Azure subnet planner
- Certificate decoder
- Change request generator
- Conditional Access visualiser
- Deadline calendar
- Email header analyser
- Graph permission explainer
- GUID lookup
- IP range checker
- JWT decoder
- KQL library
- Licence SKU lookup
- MSOnline & AzureAD to Graph
- Practice quiz
- Private endpoint DNS zones
- SAML decoder
- Script library
- Sign-in KQL builder
- Sign-in log explainer
- Tenant health check
- Timestamp converter
- Troubleshooting wizards
- User comms templates
- VM size decoder
- Which licence do I need?
- Win32 app command builder
Explainers
- How Conditional Access evaluates a sign-in
- How Entra ID issues and refreshes tokens
- How Intune compliance reaches Conditional Access
Labs
- Build a Conditional Access baseline in report-only
- Lock a storage account behind a private endpoint
- Package and deploy a Win32 app with Intune
- Set up break-glass accounts with a sign-in alert
Cheat sheets
- Azure Policy effects and assignments cheat sheet
- Conditional Access building blocks cheat sheet
- Entra ID authentication methods cheat sheet
- Entra ID licensing tiers cheat sheet
- Intune compliance and Conditional Access cheat sheet
- Intune enrolment options cheat sheet
- KQL basics for admins cheat sheet
- Microsoft Graph PowerShell essentials cheat sheet
- Private endpoint DNS zones cheat sheet
- Privileged Identity Management (PIM) cheat sheet
Glossary terms
- Access review
- Access token
- Admin consent
- Application permission
- Authentication context
- Authentication strength
- Azure Policy
- Break-glass account
- Client secret
- Compliance policy
- Conditional Access
- CSPM
- Delegated permission
- DNS Private Resolver
- Endpoint Privilege Management
- Enterprise application
- Entra Cloud Sync
- Entra Connect Sync
- Entra registered
- Federated credential
- Global Administrator
- Hard match
- Hub and spoke
- Hybrid join
- Key Vault
- KQL
- Managed identity
- Named location
- Passkey
- Phishing-resistant MFA
- PIM
- Policy initiative
- Private endpoint
- Refresh token
- Remediation task
- Remediations
- Remote Help
- Report-only mode
- Resource lock
- Role-assignable group
- SAML
- SCIM
- Security baseline
- Service principal
- Soft match
- Source of Authority
- Temporary Access Pass
- What If
- Win32 app
- Windows LAPS