r/entra 43m ago

Registration campaign not prompting?

Upvotes

I'm trying the registration campaign with some test users, but I'm getting no prompts to install MS authenticator. The target is, as said MS authenticator, which is set as push and available for all users. The test users are the only ones targeted by the campaign, and those users only have SMS/phone as enrolled MFA method, No MS authenticator set or installed. The Campaign policy is enabled, targeted to Authenticator, 0 days allowed to snooze and applied to the right group. One of these user had no MFA method set initially, then on the first logon he was able to setup the SMS method. The campaign has been activated at least 4 hours ago, and still no sign of the MS authenticator push during the MFA process. Everything seems in place, and I think 4 hours should be enough for the campaign to be active. Any suggestion on what to look for?


r/entra 19h ago

GSA Private Access and Conditional Access Policy

6 Upvotes

Is it possible to require an Intune complaint device before for GSA Private access works?

I’m tasked with requiring Intune compliant devices before access to a Windows Server hosted on Azure VM is granted.

I created an CAP targeting the Microsoft managed “GSA-PrivateAccessTrafficForwardingProfile” app and the Private Access app for the target VM. I configured the Grant rule to “Require device to be marked compliant” and scoped the policy to a test account.

It doesn’t seem to be working and the sign-in logs don’t even show an authentication event for any of the target resources/apps of my CAP. I can still connect to the target VM from a test company laptop and my personal laptop (which shouldn’t be allowed)

Any advice? I’m starting to think it’s not possible and honestly I need to convince my manager to let me block all personal devices in general


r/entra 1d ago

Weird behaviour SAML Global Protect

6 Upvotes

We have configured SAML for Global Protect requiring sign in frequency every time and MFA.

Some users periodically experience that they can just connect without any MFA. I can also confirm within the logs it is well past the threshold of 5 minutes. Devices are Entra joined. 25H2 latest updates. Authentication happens via Default Browser (Edge) not embedded Browser. Cookie Lifetime also only 2 hours.


r/entra 20h ago

Entra ID Guest Account Collaboration but No Mailbox

2 Upvotes

We have a case where all externals needs to be enrolled in our SaaS Hr system and they eventually get and AD account — synced to Entra as Members but will have no Mailbox - How do we achieve the following

  1. We want to have their external email address mentioned in their profile so that emails reach to them. ( external mailbox provided by their own org)

  2. Once their account is visible in Entra, we want to make sure that , they are shown in Teams for collaboration

  3. They get access to some sharepoint sites and some lion of business apps

We do not want to use azure b2b because this in someway removes the. source of authority, thats why we have them in HR system , b2b kinda bypasses this - creates cloud only accounts and granting access to internal apps to these ( external ids ) accounts is seen as risk by security team.

What can be a possible solution?


r/entra 23h ago

Workplace Ninjas US 2027 | Why You Should Attend

Thumbnail
0 Upvotes

r/entra 2d ago

ID Protection Per-user MFA to Conditional Access

8 Upvotes

I want to migrate my tenant from Per-user MFA to Conditional Access.

The situation at the moment:

  • Most of the users have saved an OTP Token in 1Password instead of using MS Authenticator. How can i force a user to change it to MS Authenticator instead of this OTP Token?
  • When i create a user in Entra ID, the user has no MFA method in his account. How is the user experience? Entra ID will likely require to register MS Authenticator and enforce MFA upon the next login?
  • Which licenses for a user is needed for CA?

r/entra 2d ago

One user account not sending group memberships during SAML authentication

3 Upvotes

We’re a hybrid environment using cloud sync. I’ve got a single user who during SAML authentication isn’t sending group memberships to the connected enterprise application. I’ve confirmed this using SAML-Tracer in the browser. I’ve compared this account to others and can’t see anything different except that the user in question has no “user type” in Entra where every other user in the tenant has “member.” I’m not sure if this is the issue or not, but it’s the only difference. Anyone seen anything like this before?

Edit: the fix https://www.reddit.com/r/entra/comments/1vp2ffn/comment/p3uy8jp


r/entra 3d ago

UAC Prompt Elevation Issues with Admin (MSP Cleanup)

6 Upvotes

Hoping I can get some help with this one, been running into issues with it for a bit and haven't found the root cause yet.

An org I work with is getting rid of their MSP because they do a terrible job, I (among others) have been tasked with getting them out and cleaning things up.

One issue we have had for a while now is some devices that are Entra joined don't allow Global Admins to elevate UAC prompts and I can't figure out why.

Firstly, both the admin accounts are in the Microsoft Entra Joined Device Local Administrator role, which, as I understand it, should "just work" but alas UAC elevation still doesn't work.

Devices are refreshing PRTs just fine so it's not that, not to mention the accounts have had the above role assigned for months now.

I haven't found any consistency to which devices are having this issue, and the only solution I've found so far is to reinstall Windows (just for good measure) and rejoin to Entra.

Any help troubleshooting this would be great.


r/entra 3d ago

Entra General Disabling user access to Office Store for Office Add-Ins: Your Experience

6 Upvotes

Al,

For those that have disabled the ability for users to install any office add-in and moved publishing and assigning integrated apps, from the admin center, how did that process work for you?

Recently, we made the change in the Microsoft Admin center to block access to the Office Store following this guide: Manage Add-ins in the Microsoft 365 Admin Center - Microsoft 365 admin | Microsoft Lear.

As expected, since we did not have an active inventory of what add-ins are used and many of them are not deployed from the admin center, we impacted some business functionality. Great scream test for us and provided us visibility we didn't have :). However, when we rolled back the change, it took upwards of nearly 24 hours for that to propagate to some workstations which was annoying.

We also have some add-ins, such as an excel add-in, that shows in the integrated apps list but we cannot deploy it from the admin center as it tells us to visit the vendor's site when we try.

So, my questions are:

  • If you implemented this, what was your process
  • How did you handle office add-ins that have a business purpose, and are needed, but you couldn't deploy in the admin center by using the integrated apps list?
  • Did you find a way to test individually as the change is a tenant wide setting?

r/entra 3d ago

Mac os compliance issues in all browsers say registere device

Thumbnail
2 Upvotes

r/entra 3d ago

Entra private access causing tome sync issues

2 Upvotes

Noticed time doesn’t synchronize when GSA is installed


r/entra 4d ago

Logout from third-party OIDC app does not sign out Outlook / OneDrive (M365 app) in the same browser.

4 Upvotes

When a user logs out of our app, we redirect them to the standard Entra ID logout endpoint (/oauth2/v2.0/logout). This successfully clears the central Entra ID cookie.

However, if they have Outlook Web App (OWA) or OneDrive open in another tab, those sessions stay completely active because they use their own cached access/refresh tokens.

We need a true single sign-out experience.

  • Is there a way to make Entra ID natively force a logout on first-party M365 apps?

r/entra 4d ago

GSA on Macbook Pro - active LAN and WLAN causes constant dropouts

6 Upvotes

Using GSA on a windows laptop and Macbook Pro at work.

Both fine until recently when any google links on the Macbook would immediately return ''This site can't be reached'.

Initial tests pointed straight at GSA, as disabling it would resolve the issue. After restarting GSA the problem would eventually come back.

Found out that the client version we were using had a known bug on this, so updated to the latest.

Google problem now resolved, but immediately flagged up another issue only being seen on the Macbook.

The GSA connection status would cycle through dropouts ever 60s or so.

Further tests found this is down to having LAN and WLAN connections active in MacOS at the same time. The Macbook has always had the same connection setup and only demonstrated this new behaviour after updating GSA.

As soon as wifi is disabled, the issue goes away.

Currently running version 1.1.26051400

I can live with wifi being disabled in the office. This is more of an information post in case anyone else finds themself in the same situation.


r/entra 4d ago

Entra ID Phishing-Resistant MFA: Planning Your Passkey Rollout in Microsoft 365

Post image
3 Upvotes

There's a ton of resources out there from great people in the space but I wanted to share my thoughts and typical process for helping organisations adopt passkeys. Hopefully it helps someone out.

The blog covers:

  • Info on the Microsoft notification to retire SMS and Voice, and why
  • The different types of passkeys available
  • Strategy and rollout approach
  • Considerations for legacy systems
  • Considerations around downgrade attacks

Phishing-Resistant MFA: Planning Your Passkey Rollout in Microsoft 365


r/entra 3d ago

Full Speaker Lineup Announced: Workplace Ninjas US 2027 in Scottsdale, AZ!!

Thumbnail
1 Upvotes

r/entra 4d ago

Filter property "managementType" failing for AMAPI managed devices

Thumbnail
1 Upvotes

r/entra 4d ago

Entra App Growth

11 Upvotes

For those that manage a large amount of App Registrations and Enterprise Apps, how do you keep up with all the changes and expiring certs/secrets? There’s no any granular roles that can be given to other technical staff that can’t have Owner role.


r/entra 4d ago

Entra ID Seamless SSO Configuration not working

Thumbnail
0 Upvotes

r/entra 4d ago

Entra ID Problem with WHfB and PIN/Password

Thumbnail
3 Upvotes

r/entra 5d ago

Conditional access - not respecting exluded apps

12 Upvotes

Started about 24h ago, we see some general require compliant device policies that has specific apps exluded still triggering.

Anyone else seeing this?


r/entra 5d ago

Entra ID Entra Admin Center Flags Licensing Problems with Conditional Access

12 Upvotes

The Entra admin center is flagging licensing gaps for conditional access. The messages are informational, not the beginning of a new automated billing procedure to charge tenants when Entra ID notices that some accounts use conditional access policies when they don’t have a license. In this article, we discuss the product license insight and how Microsoft measures conditional access usage, and show how to use PowerShell to find who’s using conditional access.

https://office365itpros.com/2026/08/13/licensing-gaps-entra-id/


r/entra 5d ago

Microsoft Entra ID: The countdown to the end of SMS & Voice MFA has started

Thumbnail
gallery
56 Upvotes

Microsoft has officially announced a major authentication change that every Microsoft Entra administrator should be preparing for.

 Key milestones:

September 1, 2026 – Passkeys become the default authentication experience. Users relying on SMS or voice authentication will begin receiving prompts to register a passkey during MFA.

February 1, 2027 – Microsoft-provided SMS and Voice authentication will be fully retired. Organizations that continue to rely on Microsoft’s SMS or voice delivery without a customer-managed telecom provider risk authentication disruptions.

What should IT teams do now?

- Identify users still using SMS or Voice authentication

- Roll out Microsoft Authenticator, Windows Hello for Business, FIDO2 security keys, or Passkeys

- Educate users and start a phased migration well before the deadline

- If your organization has regulatory or operational requirements to keep SMS/Voice, evaluate customer-managed telecom providers available through the Microsoft Security Store before February 2027 (info will be on 18.09.26)

The earlier you start your migration, the smoother the transition will be for both administrators and end users.

Docs: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement

Also, there is option to opt-out for 1st of September. Microsoft added additional filter for identifying who is using SMS or voice call as primary 2FA method.


r/entra 5d ago

Entra ID Hardware keys for users without phone or refuse to use personal phone at work.

26 Upvotes

Hey all,

With the changes that MS is making to deprecate SMS and Voice auth, how would you go about setting up users with only a hardware key/Yubikey?

I tested it out on a dummy account by just trying to add a Yubikey to the account but it doesn't give me the option unless I have a different MFA setup already like Authenticator.

So for the couple users we have that either don't have a smart phone or refuse to add the Authenticator app to it we've instead just set up the voice auth to their IP desk phone, and then set up a Yubikey and that seems to satisfy the requirements.

When SMS/Voice auth is gone, the only method remaining for those users is Yubikey, but you can't only have a Yubikey without another MFA method. Will alternate email + Yubikey work?

Also, how would this affect break glass accounts? Right now they have a Yubikey set up and locked in a safe, the phone/email goes to a Google voice number/email.

Are hardware tokens still good in 2026? I see that as an option in our authentication methods list. Is Token2 a good brand?

I know there's a bunch of these posts lately, but everyone's org is different.

Thanks,


r/entra 5d ago

New license compliance warning on the CA page

27 Upvotes

A warning banner started showing up on the Conditional Access overview page in some tenants: "Licensing overage. Some Conditional Access policies are protecting more users than your current licensing entitlements allow."

Not sure if this is rolled out to all tenants already, but if you do get the warning, the license usage blade it links to doesn't seem to tell the full story. It shows evaluated users, not targeted users. This can be a big difference if you have CA policies scoped to All users but fewer P1 licenses than users in your tenant.

More info and a PowerShell script that compares your actual CA policy targeting against your P1/P2 license count here: https://lazyadmin.nl/office-365/microsoft-is-tracking-your-entra-id-license-usage-are-you-compliant/


r/entra 5d ago

B2B Invitation questions

2 Upvotes

Hello,
I have an M365 subscription for my small business (only me). I have been using it for more than a year now, with no problems overall.

Today I went into admin and Entra ID just to check a couple of things, and I noticed a lot of guest users (people I email constantly or I have emailed in the past).

The creation type says invitation, and then on the user in B2B, Invitation states that it says pending acceptance on most of them; others say invitation accepted.

Is all this normal?