Jan Bakker (@janbakker_) 's Twitter Profile
Jan Bakker

@janbakker_

Not a single password was given that day šŸ”‘

ID: 950997800598327296

linkhttp://aka.ms/janbakker calendar_today10-01-2018 07:48:39

6,6K Tweet

6,6K Followers

1,1K Following

Jan Bakker (@janbakker_) 's Twitter Profile Photo

Microsoft recently launched/refreshed guidance on how to protect against token theft and token replay: 1ļøāƒ£learn.microsoft.com/en-us/entra/id… 2ļøāƒ£learn.microsoft.com/en-us/entra/id…\ Go check!

Jan Bakker (@janbakker_) 's Twitter Profile Photo

Yesterday, I chatted with Danny van Zon, who pointed me to YubiEnroll, a CLI tool from Yubico for enrolling Yubikeys on behalf of your users. It works really neat and is easy to distribute and pre-configure. Learn how: janbakker.tech/register-yubik…

Jan Bakker (@janbakker_) 's Twitter Profile Photo

This is extremely powerful! Love the improvements and flexibility added to this joiner task in Lifecyle Workflows. By default, a Temporary Access Pass is sent to the manager, but there are several other options to pick from these days. šŸ’”

This is extremely powerful! Love the improvements and flexibility added to this joiner task in Lifecyle Workflows. By default, a Temporary Access Pass is sent to the manager, but there are several other options to pick from these days. šŸ’”
Jan Bakker (@janbakker_) 's Twitter Profile Photo

Using the 'employeehiredate' attribute in Entra ID for Dynamics Groups can be extremely powerful but poorly documented. Together with Claude AI and Lokka, I created a guide with some nifty ideas and use cases. janbakker.tech/unlocking-the-…

Jan Bakker (@janbakker_) 's Twitter Profile Photo

Working on a "but cheaper" series, where I try to mimic ID Governance features within built-in tools in Entra ID and Azure Logic Apps. Stay tuned!

Working on a "but cheaper" series, where I try to mimic ID Governance features within built-in tools in Entra ID and Azure Logic Apps. Stay tuned!
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.

Since we now can use Entra ID connect sync with a service principal, I thought I'd look into the new security measures. On hosts without a TPM, we can dump the cert+key. On hosts with TPM (second picture) we can use the key to create an auth assertion for roadtx to req tokens.
Jan Bakker (@janbakker_) 's Twitter Profile Photo

Here’s a new post for you! Poor man’s IGA; creative solutions without spending too much money. janbakker.tech/poor-mans-iga-…