And we don't want to leave something with that potential for misusage laying available in our AAD.
About Me
- Olav Tvedt
- Bergen, Norway
- 19th times Microsoft MVP (Security and Windows). IT-Dude @SpareBankenNorge
Monday, July 20, 2020
Unused Azure AD Connect accounts "On-Premises Directory Synchronization Service Account"
Playing with #Azure Privileged Identity Management made me aware of two active accounts from old or failed AAD connector installations from way back.
Thursday, July 9, 2020
Requesting access with Azure AD Privileged Identity Management from PowerShell
Using Azure AD Privileged Identity Management (PIM for short) as a method to control access to Azure resource are nice security feature. It makes it more trackable and gives the granted roles for a defined time period.
You can add approval as a necessary add-on security feature, use MFA or other adjustments. Read more about PIM here.
BUT! it can also feel like a pain in the... if you use it a lot. So I created a small and simple PowerShell script to request the access for me.
You can add approval as a necessary add-on security feature, use MFA or other adjustments. Read more about PIM here.
BUT! it can also feel like a pain in the... if you use it a lot. So I created a small and simple PowerShell script to request the access for me.
Subscribe to:
Posts (Atom)
Cleaning Up Unknown IAM Assignments Across Azure Subscriptions
If you manage more than a handful of Azure subscriptions, IAM hygiene quickly becomes one of those tasks everyone knows is important, but ...
-
Working with mobile device management (MDM) require a lot of testing. With Windows 10 testing is no problem (except those things that demand...
-
I found myself in the situation that I needed to get the Windows key out from the ACPI in the UEFI bios and preferable get to use it in a ta...
-
Felt a bit stupid today (again). Have been struggling with some Microsoft Surface Go devices. Love the device but, when they are shipped wit...
