Translate

Showing posts with label Azure Active Directory. Show all posts
Showing posts with label Azure Active Directory. Show all posts

Tuesday, November 30, 2021

Easy dealing with different identities in Edge Chromium

When it comes to deal with different identities in the browser (Edge Chromium) then its sometimes hard to keep track which one is used in which browser window. To here is my ultimate tip to simplify this. 

Simple make use of color themes. Its pretty simple but very effective.

Due to the nature of different functions and also different demo environments I need to keep track which credentials where used where. So the "good old times" of having 2 different browsers (using InPrivate mode there) to have 3 different identities are gone. And also 3 are not enough in our days.

See here mine different ones:




How to make this working? - Simply select the color themes in the browser settings.


This is very simple, safe and effective. Just try it. I won't miss it now!

And yes what you see in the first screenshot isn't a leak. Now its official that Win365 Enterprise gets also AAD Only (now in private preview but officially announced.)

Tuesday, May 4, 2021

MS deprecates TLS 1.0 and TLS 1.1 in AzureAD

Microsoft announced they will deprecate TLS 1.0 and TLS 1.1 as authentication mechanism in AzureAD. This was already done with Office 365 with less impact. This time the impact will be much bigger!

Reason for this is security as there are serious vulnerabilities out there like Heartblead, POODLE, BEAST and others. Also other major vendors will deprecate the usage of TLS 1.0 and TLS 1.1 as also specified in RFC8996!

The MS cloud application catalog is reporting already more than 2.700 apps from the 17.000 apps not supporting TLS 1.0 or TLS 1.1.  If Azure AD is used for authentication for one of the affected apps they may fail after June 30th 2021!

Also old on-premises stuff will fail when used in combination with Azure Active Directory e.g. but not limited to: 

  • Use of outdated operating systems (Windows 7 / Window 8 without "extension", Servers older as Windows Server 2012 R2
  • Use of outdated browsers (used for app compat reasons)
  • New AzureAD device registration on older OSes
  • Older Versions of Azure AD connect, PTA agents oder AppProxy connectors
  • MFA extensions on ADFS servers with older OSes
  • NPS extensions for Azure MFA on older OSes
  • Azure AD integrated applications and PowerShell scripts based on older .Net Framework version not configure for use of TLS 1.2
  • Software as a Service (SaaS) applications or other Line of Business applications hosted on platforms without TLS 1.2 support
  • Webproxy with SSL inspection which are not supporting TLS 1.2
This list may not be complete but should show the full impact on this!

How you can solve this issue in certain scenarios you find here more information's:



You can do some testing on this also on: https://www.ssllabs.com/ssltest/
(Please keep in mind that more than one URL might be involved in an authentication process!)


If you have Microsoft's Cloud App Security you find with this advanced filter all the affected software!



And last but not least you can find for all authentications on your tenant a report showing outdated authentications. How reliable this report is, judge on your self in your environment. We found still some strange reports.

TLS deprecation report (every 2 days you see a new one. You only see the last 3 reports!)
https://servicetrust.microsoft.com/AdminPage/TlsDeprecationReport/Download

Friday, September 15, 2017

Bitlocker recovery without MBAM and AD

Some of you may miss Bitlocker Active Directory Recovery. This feature was skipped in 1607 (!).
Reference: https://docs.microsoft.com/en-us/windows/device-security/tpm/backup-tpm-recovery-information-to-ad-ds

So you need MBAM instead. Which is in general a good idea.

But for MBAM in general you need MDOP under SA. And there is a constellation where you cant get MBAM normally when buying Windows under CSP.

There is as always a solution. Recovery key out of the Azure AD Box :-)



Pieter Wiegleven had here documented the full solution:
https://blogs.technet.microsoft.com/home_is_where_i_lay_my_head/2017/06/07/hardware-independent-automatic-bitlocker-encryption-using-aadmdm/

Have fun!

Tuesday, August 22, 2017

Windows 10 Passwort Selfservice solution - nearby - builtin

Recently a customer asked me how to add a browser window to the lockscreen before login so they can add their "old" Password selfservice solution add again to the user experience.

Microsoft added the Password self service solution to Azure AD Premium also for local clients without the need for a website. You can reset your password directly on the logon screen. By clicking on "Problems Logging In?"


Sorry the picture shows it on Windows 8 but for Windows 10 I did not find a picture. Microsoft either. But it looks nearly the same in the UI experience. 

To verify your self you will receive a phone call on a pre registered phone. It may also include additional security questions when you add them during the verification process.



You need therefore either Microsoft Identity Manager (MIM) or Azure Active Directory Premium which includes the onpremise license for the full MIM for server and client. Thats why I state "nearby" builtin. You need a "little extra MS".

If you have Enterprise Mobility & Security then you have it already :-)

Here you find more info and screenshots about it.
https://docs.microsoft.com/en-us/microsoft-identity-manager/working-with-self-service-password-reset

Friday, January 27, 2017

Delete an Azure AD Tenant - Mostly with Powershell

From time to time I need to cleanup my Azure Tenant with old unused Azure ADs. When you are a MS Partner using https://demos.micrsoft.com you get more and more MODxxxxxx tenants in your Azure Portal. Cleaning them up is a bit annoying.


This here will help you.
https://blogs.msdn.microsoft.com/ericgolpe/2015/04/30/walkthrough-of-deleting-an-azure-ad-tenant/

If you have still an EMS subscription connected with. Then you need to open a ticket from the Billing support to release them. This is something you can not do by your own!

Open the ticket from the Azure Portal!

Wednesday, August 17, 2016

Mobile Device Management - simplified joining options

With 1607 the options to join MDM while joining Active Directory or Azure AD where simplified a lot. So you do not need to check 2 different options anymore.


So best is to prepare your Azure AD with the right options first and enable auto MDM enrollment there.






See here:
https://blogs.technet.microsoft.com/enterprisemobility/2015/08/14/windows-10-azure-ad-and-microsoft-intune-automatic-mdm-enrollment-powered-by-the-cloud/




From a user perspective you you have now 4 major options described further here:


https://msdn.microsoft.com/en-us/library/windows/hardware/dn925028(v=vs.85).aspx


Options are so far:
Corporate owned - Active Dirctory
Corporate owned - Azure Active Directory
Private owned - Azure Active Directory
Independent - MDM using a deeplink

Thursday, July 14, 2016

Azure AD Connect: Synced attributes

I am asked from time to time what attributes are synced with Azure AD through Azure Active Directory Connect tool:


In general its just selected user, group and contact information.

Here you find a list of synced attributes:
https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnectsync-attributes-synchronized


Depending on Windows 10 features there are also a few machine attributes synced to Azure AD as well. This is necessary for specific scenarios like Passport for work and requires actual versions of Windows 10 build (build 10551 or newer) for devices:
https://azure.microsoft.com/en-us/documentation/articles/active-directory-azureadjoin-devices-group-policy/


Be carefull and dont think you know what you are doing by partially not syncing them. Depending on the services they are really necessary. E.g. Exchange onpremise stores a lot of informations in AD. So Exchange online do as well. Therefore these attributes are necessary for proper function.


Unless you are the developer of the cloud application like Exchange Online you are not the one to judge if an attribute is necessary for correct function or not.


So either you feel comfortable with the attributes or just dont use Azure AD at all. Everything else will just mess up the AAD information and the cloud applications will not work properly.


Azure AD also stores Bitlocker keys but only for Azure AD joined machines.
https://blogs.technet.microsoft.com/home_is_where_i_lay_my_head/2016/03/14/automatic-bitlocker-on-windows-10-during-azure-ad-join/