If you have Conditional Access configured and active within your Azure AD environment, there might be some scenario’s where users are not able to sign-in. If you want to troubleshoot these sign-in failures as an administrator you normally turn to the Azure AD sign-in logging and work from there to determine the cause of these…
Category: Conditional Access
Continuous Access Evaluation configuration is now part of Conditional Access
While browsing through the options in my Conditional Access policies I noticed a new session related to Continuous Access Evaluation (CAE). Time for a blogpost on my findings. Continuous access evaluation allows for a quicker response by forcing an access token refresh in case of a certain events taking place. In October last year I…
October 2021 update of the conditional access demystified whitepaper and workflow cheat sheet
I’m proud to announce the October 2021 update of my Conditional Access demystified whitepaper. With this release, we have reached the fourth iteration of the whitepaper and accompanying files. I released the first version in in August 2019 after writing several blogposts on the subject. In May last year I released the second version containing…
Speaking about Conditional Access at the Centric Craft webinar on Wednesday October 13, 2021
On Wednesday October 13, I will be speaking at the free online webinar hosted by Centric Craft. Craft is a community initiative from the company Centric which wants to contribute to the IT industry by sharing knowledge and helping all IT professionals develop themselves, even if they don’t work at Centric. My session will start…
Control Azure AD Conditional Access policy behavior during an Azure AD outage
In December last year, Microsoft announced that per April 1, 2021 they updated their service level agreement(SLA) for Azure AD user authentication from 99.9% to 99,99%. While this might seem like a small update in reality it makes a difference of 473 minutes (in a year with 365 days). With 99.9% the allowed downtime was…
Using Mozilla Firefox as a browser when using Azure AD Conditional Access on your Modern Workplace
Starting with Firefox version 91, Mozilla is now supporting Single sign-on support (SSO) and device-based Conditional Access as announced by Microsoft in the What’s new in Azure Active Directory for August 2021. The feature is still in Public Preview from a Microsoft point of view, and considered Advanced and experimental from a Mozilla point of…
OneDrive client sign-in issues due to Conditional Access policies in Azure AD tenant where you are a guest user
Today I experienced an interesting issue, for which I thought it was interesting sharing how I figured out what was going on. The issue/challenge The issue I encountered was related to the fact that I couldn’t sign-in into the OneDrive client anymore. When you are not able to sign-in, you cannot open documents which are…
My session about Conditional Access at the Microsoft 365 Security & Compliance User Group on June 30, 2021
On Wednesday June 30, I spoke at the monthly user group meeting of the Microsoft 365 Security & Compliance user group. The Microsoft 365 Security & Compliance user group is based in the UK and UK based user group consists of Alan Eardley (@al_eardley) and Peter Rising (@M365Rising) The meeting will started with a very…
A first look at Azure AD Conditional Access authentication context
During Microsoft Ignite in March this year, Microsoft announced several new upcoming functionalities for Azure Active Directory. One of the announcement was the Azure AD Conditional Access authentication context, for which I that time I already wrote about what it could do in my blog article: Modern Workplace Management key takeaways from the Microsoft Ignite…
Speaking about Conditional Access at the Microsoft 365 Security & Compliance User Group on June 30, 2021
On Wednesday June 30, I will be speaking at the monthly user group meeting of the Microsoft 365 Security & Compliance user group. The Microsoft 365 Security & Compliance user group is based in the UK and UK based user group consists of Alan Eardley (@al_eardley) and Peter Rising (@M365Rising) The meeting starts at 18:00…
A first look at using Filters for devices as conditions in Azure AD Conditional Access policies
Earlier this month I wrote an article about using filtering in assignments for apps, compliance policies and configuration profiles in Microsoft Endpoint Manager. And now Microsoft has made available a preview of “Filters for devices” for use in your Azure AD Conditional Access policies. Because this functionality is provided as a preview there is no…
Using Conditional Access to provide more granularity when registering or joining devices
This month Microsoft released a new “User Action” for Conditional Access in public preview. The new user action called “Register or join devices” can now be used to provide more granularity related to joining or registering a device in Azure Active Directory. Up until now, there was a global setting which you could define related…
Designing and configuring compliance policies for your Windows Modern Workplace using Microsoft Endpoint Manager
Measuring your managed systems against a baseline has been around for a while, in Microsoft Endpoint Configuration Manager(MECM)/ConfigMgr we can already use one or more Configuration Items combined in a Configuration Baseline to measure and remediate clients against an imported or self created baseline. You can measure for example if the Windows Firewall is enabled…
My presentation about Conditional Access at the Workplace Ninja User Group Netherlands
Yesterday, on Thursday February 16, I presented at the 19th Workplace Ninja User Group Netherlands Tuesdays Webinar. My session, titled “Azure AD Conditional Access demystified” started at 16:00, and lasted around 75 minutes. This session, which I prepared based on the various articles I wrote about the subject is continuously updated to reflect my current…
February 2021 update of the Azure AD Conditional Access demystified whitepaper and workflow cheat sheet.
I’m proud to announce the February 2021 update of my Conditional Access demystified whitepaper. With this release, we have reached the third iteration of the whitepaper starting with the first one released in August 2019 after writing several blogposts on the subject. In May last year I released the second version containing a lot of…