top of page
Code

THE TOLKIEN BLACK GUY

PowerShell Demystified

The villagers fear and are mystified by the wizards' spells. We cannot expect them to understand the inner workings of our sanctum

Get in Touch
Home: Welcome
Search

Entra Id Defense in Depth for your Most Privileged Roles

The Sum of the Whole is Greater Than the Sum of its Parts I won’t pretend this is the norm, but I’ve noticed in different circles professionally and on some corners of the internet that imply certain identity controls are redundant or unnecessary because another control is already in place: “If we have phishing-resistant MFA, do we really need PIM? This seems like overkill and not a necessary control” ~A SharePoint Administrator for one of my clients. “If we use PIM, why can

Understanding Sign-In Frequency (SiF) in Hybrid-Joined Environments

Why Enforcement Can Appear Inconsistent for SSO-Integrated SaaS Applications You’ve set your Sign-In Frequency to 12 hours, but users stay signed in for much longer. You lower it and see the same thing. At first, it looked like a bug. Maybe Conditional Access isn’t enforced properly, or the policy isn’t being evaluated at all. In reality, Sign-In Frequency (SiF) is working exactly as designed. It just doesn’t behave the way most people expect. Once you understand how the Prim

Entra ID Application Policies: Beware the Impact on SAML Signing Certificates

Microsoft just made a long-requested improvement: you can now manage application policies  for Entra ID applications directly in the portal. Things like certificate and secret age restrictions - previously the domain of the Graph API only - are now exposed in a friendly UI as seen here in many of wonderful blog posts . That’s good news. But before you start tightening lifespans on certificates, let me share a gotcha I haven’t seen mentioned anywhere else yet. The Error You’ll

How to Find Required Graph API Permissions for any PowerShell Script

I was helping someone who had written a PowerShell script against Entra with the Graph SDK. It worked perfectly for him during testing, but as soon as he shared it with others on his team, the script broke. His teammates had the same Entra roles but didn’t have all the same Graph scopes. He already had many of the scopes he needed from his day-to-day use so he needed some help identifying what specific scopes his teammates you need. You’re probably familiar with Find-MgGraphC

Home: Blog2

©2022 by thetolkienblackguy. Proudly created with Wix.com

bottom of page