top of page
Search


Are Your Microsoft Entra Extensions Actually Being Used?
Today I'll take a deeper dive into what Entra Extensions Manager can help with and be used for. As I went over in my last two blog posts, custom extensions have a habit of sticking around. An application gets built, an extension gets created, values get written to users or other directory objects and, a few years later, nobody is really sure whether any of it is still being used. The application might be gone, the extension might even be deprecated, but what about the data? E

Sebastian F. Markdanner
3 hours ago8 min read


Introducing Entra Extensions Manager: A Better Way to Manage Custom Extensions
Ever felt like you needed some more options to store data in Entra, or the pain of having to figure out what, when and where data is stored? me too... In my last blog post, I went over the different custom extensions in Microsoft Entra, their strengths and weaknesses, where they fit in, and my thoughts and recommendations on when to use each. On top of that, I promised to show a project to help manage them, as working with custom extensions can be a pain, especially in larger

Sebastian F. Markdanner
Aug 3111 min read


Choosing the Right Extension Type in Microsoft Entra
I’ve been seeing a lot of discussions about the different extension types available across Microsoft Entra objects, and I have a few thoughts on the subject that I want to share with y’all. Being able to extend the built-in attributes and data model in Microsoft Entra provides a flexible way to handle information across our organizations for monitoring, automation, and governance. With that said, I don’t believe the 15 predefined extension attributes are the best route to tak

Sebastian F. Markdanner
Jun 158 min read


Getting With The Times: Time-Based Conditional Access
Conditional Access is one of, if not the, strongest tools in our kit for securing access to our organizations. And it seems to be on the cusp of becoming even stronger. Some time ago, while scrolling through LinkedIn, I came across a post by fellow MVP Daniel Bradley. He highlighted a new property that appeared when experimenting with the beta Graph APIs for Conditional Access: a new condition called Time. After waiting far too long, I finally got the chance to sit down and e

Sebastian F. Markdanner
May 115 min read


Mastering Microsoft Entra Authentication Contexts - Part 4: Monitoring and Reporting with KQL & M365IdentityPosture
We’ve covered what Authentication Contexts are, why they matter, and how they help us strengthen access and data security in Microsoft 365. Now it’s time to answer the next question - how do we monitor and report on their usage? Unfortunately, there’s no built-in way to gain that visibility today. Neither Entra ID nor Microsoft 365 provides a simple method to inventory or audit Authentication Contexts across our estate including Conditional Access, PIM and Sensitivity labels

Sebastian F. Markdanner
Nov 3, 20258 min read


Mastering Microsoft Entra Authentication Contexts - Part 3: Advanced Data Protection
With identities and access strengthened in part 2 , it’s time to turn our focus to real-world data protection with Authentication Contexts. One of the more underused capabilities of Authentication Contexts is their power to secure data across the environment, whether through direct enforcement using Sensitivity Labels or by protecting user sessions via Microsoft Defender for Cloud Apps. In this post, we’ll explore exactly that: how to secure organizational data using Authent

Sebastian F. Markdanner
Oct 20, 202510 min read


Securing Microsoft Business Premium Part 04: Passwords Unlocked – Mastering Self-Service Password Reset and Password Protection
With authentication & authorization covered in the previous posts of the series, it's now time to dive into strengthening our password policies, empowering end-users, and enhancing overall password security. As I've gone over previously , passwords aren't exactly bulletproof, but for many organizations, transitioning to a fully passwordless setup overnight isn't realistic. While we steadily work towards that passwordless dream, managing and securing passwords across the org

Sebastian F. Markdanner
Apr 3, 202515 min read
bottom of page
