Skip to content
PodcastsNewsEntra.Chat

Entra.Chat

Merill Fernando
Entra.Chat
Latest episode

75 episodes

  • Entra.Chat

    Microsoft Entra memberOf Retirement: What Admins Must Do

    25/08/2026 | 42 mins.
    On 3 November 2026, the memberOf operator in Microsoft Entra dynamic membership groups stops working. Nothing errors. Nothing breaks loudly. Every dynamic group, dynamic administrative unit and entitlement management auto-assignment policy that uses it simply freezes in its last known state the people who should be added are not added, and the people who should be removed stay.
    It was a preview feature for four years. It is in a lot of production tenants.
    In this episode of Entra.Chat, Merill is joined by three guests for the first time: Gregor Reimling, Chief Azure Technologist at adesso SE and Microsoft MVP for Azure and Security; René Wasel, a Microsoft 365 specialist and Microsoft MVP; and returning guest Eric Woodruff, Chief Identity Architect at Semperis. Gregor and René co-organise the Cloud Identity Summit, which happens to fall on the same date the deprecation lands.
    The conversation starts with the deadline and quickly becomes something more useful: an honest audit of what groups in Entra actually do, versus what administrators assume they do.
    The memberOf operator existed because Entra does not resolve nested groups the way Active Directory does. It was a flattening trick — take the members of several groups and produce one flat group that applications, licensing and policies could read. With it going away, the panel walks through the realistic replacements: move to supported attribute-based rules where an attribute exists, stamp an attribute with PowerShell where one does not, or convert the group to assigned membership and script it. Gregor and René both raise the version of this that is easy to forget — a rule written years ago that nobody documented, using a sync rule editor nobody wants to reopen.
    Then the discussion turns to the part that is not on any deprecation notice. Nested groups are supported in Conditional Access. They are not supported for group-based licensing, where only first-level members get a licence. They are not supported for Global Secure Access, where a nested group assigned to a traffic forwarding profile applies only to its direct members with no error, no warning, and nothing in the portal to tell you. Chris Brumm found that one and wrote a Maester test for it, because the only way to know is to go looking.
    There is a new group property that blocks nesting in both directions, undocumented when this was recorded. Sensitivity labels have reached Entra security groups in preview, bringing a guest-access control that stops new guests but does not evict the ones already in the group. And Merill spotted something through Entra.News Daily that deserves more attention than it has had: an agent’s user account is a user identity, so existing dynamic user rules already evaluate it. If your licensing group has a broad rule and your developers start creating agent accounts, those accounts qualify. If it is a group behind a Conditional Access policy or an exclusion, that is a different conversation entirely.
    Which leads to the sharpest point in the episode, and Eric makes it plainly: the security of a dynamic group is the security of the write permissions on the attributes in its rule. Some of those attributes are self-service. Some flow up from on-premises Active Directory, changed by people who are not thinking about the cloud at all. Microsoft Learn now carries an explicit warning about exactly this, and it is why groups used for privileged access cannot be dynamic.
    The last third is about the Cloud Identity Summit itself. More info below.
    If you have memberOf in a rule anywhere, the useful thing to do this week is find it. Everything else in this episode can wait until after November.
    Featured sponsor
    Cloud Identity Summit 2026 → One Day, One Topic, In the Room
    Identity. Security. 2026. On Tuesday 3 November in Frankfurt, the Cloud Identity Summit gives cloud identity a conference of its own, now in its seventh year, and free to attend.
    Two parallel tracks, Identity Management and Identity Security, run 50-minute sessions in English. It is deliberately vendor-neutral: Microsoft Entra, AWS, Google Cloud and whatever else you actually run. Eric Woodruff keynotes with Identity Security Kindergeburtstag fourteen years of identity being called “the new security perimeter”, and an honest look at what that has actually got us.
    Why it is worth the trip:
    * It is in person only. No livestream, no catch-up recordings. The organisers built it that way on purpose — “a strong focus on face-to-face conversations to support networking and exchange of experiences.” If you want the hallway conversation, you have to be in the hallway.
    * Everything is identity. No filler tracks. A whole day of people who work on the same problems you do, from an international mix of industries.
    * The Community Ticket is 100% free. There is an optional paid Supporter Ticket if you want to help fund the event.
    * It is easy to get to. adesso SE, Prisma Frankfurt-Niederrad — around ten minutes by S-Bahn from Frankfurt Airport, ten from Frankfurt Hauptbahnhof, and a short walk from Frankfurt-Niederrad station.
    * Travelling in? The Crowne Plaza Frankfurt is a ten-minute walk, €89 single with breakfast on the “Cloud Identity Summit” booking code — 50 rooms, held until 5 October.
    One more thing, given what this episode is about: 3 November is also the day Microsoft retires the memberOf operator. If you are going to spend that Tuesday thinking about Entra groups anyway, spend it in a room with people solving the same problem.
    Subscribe with your favorite podcast player or watch on YouTube
    About Gregor Reimling
    Gregor is a Microsoft MVP in Azure and Security, Chief Azure Technologist at adesso SE, and a passionate advocate for the Microsoft cloud community. His expertise spans Azure architecture, Microsoft Entra, Zero Trust and hybrid cloud environments; he helps organizations successfully navigate their cloud journey. Beyond his day job, Gregor is a frequent speaker at international events, co-host of the Cloud Inspires podcast and co-founder of the Cloud Identity Summit. As a Microsoft Certified Trainer, he enjoys sharing knowledge, mentoring others, and helping IT professionals get the most out of Microsoft technologies.
    LinkedIn - https://www.linkedin.com/in/gregorreimling/
    About René Wasel
    René is a Microsoft 365 specialist, and a Microsoft MVP for Microsoft 365. He describes his work as helping people actually use the technology they have been given, and he is active in the community as a meetup and event organiser. He co-organises the Cloud Identity Summit.
    LinkedIn - https://www.linkedin.com/in/renewasel/
    About Eric Woodruff
    Throughout his 25-year career in the IT field, Eric has sought out and held a diverse range of roles. Currently the Chief Identity Architect for Semperis; Eric previously was a member of the Security Research and Product teams. Prior to Semperis, Eric worked as a Security and Identity Architect at Microsoft partners, spent time working at Microsoft as a Sr. Premier Field Engineer, and spent almost 15 years in the public sector, with 10 of them as a technical manager.
    LinkedIn - https://www.linkedin.com/in/ericonidentity/
    Related Links
    * MC1448379 - Microsoft Entra ID: Replace MemberOf rules by November 3, 2026 - https://mc.merill.net/message/MC1448379
    * Entra.News Daily, Merill’s daily diff of Microsoft Entra documentation changes (mentioned at 26:26) - https://daily.entra.news/changes/2026-08-14/manage-rules-for-dynamic-membership-groups-in-microsoft-entra-id-16/
    * Maester, the open-source test framework used for the dynamic-group and nested-group checks discussed (mentioned at 06:09 and 30:06) - https://maester.dev/contributors/agnivesh
    * Configure dynamic membership groups with the memberOf operator - the official retirement notice and migration guidance - https://learn.microsoft.com/entra/identity/users/groups-dynamic-rule-member-of
    * Manage rules for dynamic membership groups - covers agent user accounts and the attribute write-permission warning - https://learn.microsoft.com/entra/identity/users/groups-dynamic-membership
    * Assign users and groups to Global Secure Access traffic forwarding profiles - confirms nested groups are not supported (discussed at 15:50) - https://learn.microsoft.com/entra/global-secure-access/how-to-manage-users-groups-assignment
    * Group-based licensing - confirms only first-level members receive licences - https://learn.microsoft.com/entra/fundamentals/concept-group-based-licensing
    * Assign sensitivity labels to Microsoft Entra security groups (preview) (discussed at 25:09) - https://learn.microsoft.com/entra/identity/users/groups-sensitivity-labels
    * Eric’s Cloud Identity Summit keynote, “Identity Security Kindergeburtstag” (mentioned at 34:12) - https://www.identitysummit.cloud/speaker
    Related Entra.Chat Episodes
    * Operational Groups in Entra with Nathan McNulty - https://entra.news/p/operational-groups-in-entra-with
    * Mastering Microsoft Entra ID: Real-World Passkey Deployment Tips - Eric’s previous episode, referenced at 02:12 - https://entra.news/p/mastering-microsoft-entra-id-real
    * From Active Directory to AI Agents: The 25-Year Saga of Microsoft’s Identity - the keynote-turned-podcast Merill promised to link (mentioned at 40:16) - https://entra.news/p/from-active-directory-to-ai-agents
    Chapters
    00:00 Intro
    01:17 Meet Gregor, René and Eric
    02:12 Passkeys: what comes after the rollout
    04:17 memberOf is being retired
    06:45 Workarounds: attributes, PowerShell and sync rules
    10:41 Why Entra wants your groups flat
    14:36 Where nested groups silently fail
    17:45 The new property that blocks nesting
    19:27 AD-sourced groups vs Entra-sourced groups 25:09 Sensitivity labels come to security groups
    26:23 Agents are already in your dynamic groups
    28:23 Why dynamic groups are not a security control
    31:31 Inside the Cloud Identity Summit
    35:21 Identity is not the “new” perimeter
    41:44 November 3, tickets and wrap-up
    Podcast Apps
    Apple Podcast - https://entra.chat/apple
    YouTube - https://entra.chat/youtube
    Spotify - https://entra.chat/spotify
    Overcast - https://entra.chat/overcast
    Pocketcast - https://entra.chat/pocketcast
    Others - https://entra.chat/rss
    Merill’s socials
    YouTube - youtube.com/@merillx
    LinkedIn - linkedin.com/in/merill
    Twitter - twitter.com/merill
    TikTok - tiktok.com/@merillf
    Bluesky - bsky.app/profile/merill.net
    Mastodon - infosec.exchange/@merill
    Threads - threads.net/@merillf
    GitHub - github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    Pass-the-Passkey: What Michael Grafnetter's Black Hat Research Means for Entra Admins

    17/08/2026 | 36 mins.
    Passkeys are phishing-resistant. But that resistance is enforced by your browser, which binds every authentication to the origin that requested it. Skip the browser, and the guarantee weakens.
    In this episode of Entra.Chat, I spoke with Michael Grafnetter, Principal Security Researcher at SpecterOps and Microsoft MVP, about the Pass-the-Passkey research he presented at Black Hat USA 2026. A family of attacks against passkey implementations across Windows, Microsoft Entra ID, browsers and password managers.
    Michael starts with the vulnerability chain he reported to Microsoft. Windows was writing the complete passkey assertion into the event log, and Microsoft Entra ID would accept a replay of that assertion for up to ten minutes. Any user able to read those logs including a member of Remote Desktop Users on a shared server, or unprivileged malware quietly reading event logs without tripping EDR could impersonate whoever had just signed in. If that person was a Global Administrator, so was the attacker. Windows now truncates the logged message, and Microsoft Entra ID checks authenticator signature counters to reject replays.
    One clarification Michael is emphatic about: private keys were never written to the event log. They stay bound to the TPM or never leave the security key at all. What leaked were the short-lived digital signatures made by those keys and for this attack, that was enough.

    We also covered the attacks that do not depend on any single bug. Malware running without administrator rights can call the native Windows WebAuthn APIs directly and raise a passkey prompt flood that keeps returning until the user gives in and approves it. Synced passkeys, exported from a password manager and decrypted with a keylogged password, hand an attacker a credential with no ten-minute limit at all. And a browser-hooking technique Michael calls a passkey detour attack quietly redirects a legitimate assertion into the attacker’s own session.
    The defensive thread running through all of it is the same: every one of these attacks assumes malware is already on the device. That makes device trust the key control. Privileged access workstations for administrators, Conditional Access requiring compliant devices with EDR running, and the clean source principle that says a system can only be as trustworthy as whatever it depends on.
    Michael closes on an optimistic note, and it is worth repeating. Passkeys are still the future. They remain far better than passwords and phishable MFA, and every attack here costs an adversary vastly more effort than sending a phishing link. But as passkeys become the default in Microsoft Entra, the threat model deserves an honest read.
    Watch the demos. This episode includes three on-screen demonstrations that are much easier to follow on video than on audio.
    This episode brought to you by Workplace Ninjas US
    Workplace Ninjas US isn’t just another tech conference. It’s where Microsoft experts, MVPs, engineers, and IT professionals come together to learn, network, and build lasting connections.
    We are a community built on diversity, mentoring, fellowship, and creating a place where everyone belongs.
    Our core DNA comes down to a few pillars:
    * Over 60 sessions from the largest collection of MVPs and SMEs you will find in any event in America.
    * Amazing mentoring, development, and growth through our one on one mentoring system with any speaker, our hackathon, community theatre and more.
    * A diverse expo hall featuring some of the best Microsoft partners in the world that will help you drive deep efficiencies from your M365 stack.
    * A place where you will learn how to think differently and collaborate better through a collection of activities and can return refreshed and invigorated to drive change in your organization.
    * Don’t miss out on our early bird tickets while supplies last
    Subscribe with your favorite podcast player or watch on YouTube
    About Michael Grafnetter
    Michael Grafnetter is a Principal Security Researcher at SpecterOps and a Microsoft MVP, based in Prague. He specializes in Microsoft Entra ID and Active Directory security and PowerShell. He is the author of the DSInternals PowerShell module and the researcher who originally discovered the Shadow Credentials attack technique, now widely used by penetration testers, red teamers and attackers alike. He has presented his security research at international conferences including Black Hat Europe, Black Hat USA, SecTor, TROOPERS and BSides Lisbon.
    * LinkedIn - https://www.linkedin.com/in/grafnetter/
    Related Links
    * Pass-the-Passkey research and tools, including Passkey Injector and the DSInternals.Passkeys module (discussed at 14:57 and 34:22) - https://github.com/SpecterOps/pass-the-passkey
    * Pass-the-Passkey research paper from Black Hat USA 2026 (introduced at 07:34) - https://specterops.io/wp-content/uploads/sites/3/2026/08/Pass-the-Passkey_A4_v2.pdf
    * Shadow Credentials, Michael’s earlier Active Directory research (mentioned at 01:46) - https://specterops.io/blog/2021/06/17/shadow-credentials-abusing-key-trust-account-mapping-for-account-takeover/
    * DSInternals PowerShell module (mentioned at 01:34) - https://www.dsinternals.com/en/
    * Passkeys (FIDO2) authentication in Microsoft Entra ID (context throughout) - https://learn.microsoft.com/entra/identity/authentication/concept-authentication-passkeys-fido2
    * Synced passkeys, device-bound passkeys and passkey profiles (discussed at 23:21) - https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkeys-fido2
    * Deploy phishing-resistant passwordless authentication (context at 18:08) - https://learn.microsoft.com/entra/identity/authentication/how-to-deploy-phishing-resistant-passwordless-authentication
    * Require device compliance with Conditional Access (recommended at 21:12) - https://learn.microsoft.com/entra/identity/conditional-access/policy-all-users-device-compliance
    * Privileged access devices and the clean source principle (discussed at 21:55 and 35:41) - https://learn.microsoft.com/security/privileged-access-workstations/privileged-access-devices
    * Unit 42, “Pass the Passkey: A Novel Attack Surface in Passwordless Authentication” — the Palo Alto research on Google Password Manager passkeys (mentioned at 26:27) - https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
    Related Entra.Chat Episodes
    * From SMS MFA to Passkeys: A Practical Microsoft Entra Migration Plan - https://entra.news/p/from-sms-mfa-to-passkeys-a-practical
    * 5 Lessons from Rolling Out Passkeys to Millions of Users - https://entra.news/p/5-lessons-from-rolling-out-passkeys
    * Attackers Are Targeting The AI Ecosystem You Cannot See - https://entra.news/p/attackers-are-targeting-the-ai-ecosystem
    Chapters
    00:00 Intro
    01:02 Meet Michael Grafnetter
    03:09 How the Research Started
    06:50 Windows Hello for Business Was the First Passkey
    07:30 The Signature in Your Event Log
    10:18 No, Private Keys Are Not Logged
    12:25 How Entra Mitigated the Replay
    13:44 Demo: Signing In With a Stolen Signature
    15:22 Malware-Initiated Passkey Phishing
    18:08 The Browser Is What Makes Passkeys Phishing-Resistant
    20:42 What Defenders Should Actually Do
    23:04 Synced Passkeys and the Export Problem
    26:13 Credential Exchange and Password Manager Risk
    28:19 The Passkey Detour Attack
    30:43 The Authentication Broker Debate
    31:57 RDP Redirection and Remote Passkey Abuse
    32:59 Spotting a Suspicious Passkey Prompt
    34:46 Passkeys Are Still the Future
    Podcast Apps
    Apple Podcast - https://entra.chat/apple
    YouTube - https://entra.chat/youtube
    Spotify - https://entra.chat/spotify
    Overcast - https://entra.chat/overcast
    Pocketcast - https://entra.chat/pocketcast
    Others - https://entra.chat/rss
    Merill’s socials
    YouTube - youtube.com/@merillx
    LinkedIn - linkedin.com/in/merill
    Twitter - twitter.com/merill
    TikTok - tiktok.com/@merillf
    Bluesky - bsky.app/profile/merill.net
    Mastodon - infosec.exchange/@merill
    Threads - threads.net/@merillf
    GitHub - github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    From SMS MFA to Passkeys: A Practical Microsoft Entra Migration Plan

    10/08/2026 | 53 mins.
    Microsoft-managed SMS and voice MFA will stop working on February 1, 2027. That deadline makes passkey planning urgent, but enabling a new authentication method is only the first milestone.
    In this episode of Entra.Chat, Merill speaks with Jai Maharaj, Product Manager at Microsoft, about the practical journey from legacy MFA to a passwordless Microsoft Entra environment. Jai explains what is actually being retired, why organizations can still use a customer-managed telecom provider, and how passkey profiles support synced and device-bound passkeys for different user personas.
    The user-experience case is compelling: Microsoft reports roughly 69 seconds for password plus traditional MFA compared with about three seconds for a synced passkey. The security case is stronger still. Passkeys resist phishing by design, but Jai stresses that deploying them does not make an organization phishing-resistant until it enforces the right authentication strength and addresses the passwords and legacy applications still in the environment.
    The conversation then follows the complete identity lifecycle. How do you ensure the right person receives a passkey during onboarding? How do you verify someone requesting a sensitive role? How do you recover an account without relying on knowledge-based help-desk questions? Jai connects those scenarios to Microsoft Entra Verified ID, verifiable credentials, Face Check, identity verification partners, and self-service account recovery.
    Sponsored by
    Scan, Score, and Secure Your Applications in Entra
    Application identities represent one of the largest attack surfaces in Entra and are often among the least consistently governed. ENow AppGov Score helps IT and identity teams understand where risk exists. Its 25-check assessment evaluates Entra ID application integrations against Microsoft-recommended governance practices, analyzing:
    * App registrations and enterprise apps for excessive permissions
    * Expired or unmanaged secrets and certificates
    * Risky consent grants
    * Privileged service principals
    Results are delivered as a clear, defensible risk score with actionable findings. No scripts. No manual inventory. Just a fast, read-only scan that reveals app sprawl, identity misconfigurations, and blast radius so you can prioritize remediation and strengthen your security posture.
    Subscribe with your favorite podcast player or watch on YouTube 👇
    About Jai Maharaj
    Jai Maharaj is a Senior Product Manager at Microsoft. He works with customers and engineering teams across Microsoft Entra, with experience spanning ID Governance, Verified ID, External ID, and passkeys. He helps enterprise and public-sector organizations move from legacy authentication methods to phishing-resistant authentication.
    * LinkedIn - https://www.linkedin.com/in/jai-maharaj-0938305a/
    Related Links
    * Microsoft-managed SMS and voice retirement timeline (discussed at 02:19 and 06:31) - https://learn.microsoft.com/entra/identity/authentication/concept-sms-voice-retirement
    * Customer-managed telecom provider FAQ (mentioned at 03:41 and 07:13) - https://learn.microsoft.com/entra/identity/authentication/phone-providers-faq
    * Passkey profiles, synced passkeys, and device-bound passkeys (discussed at 09:44) - https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkeys-fido2#passkey-profiles
    * Passkey concepts and Microsoft performance figures (mentioned at 14:22) - https://learn.microsoft.com/entra/identity/authentication/concept-authentication-passkeys-fido2#what-are-passkeys
    * Microsoft Entra Verified ID Face Check (introduced at 31:57) - https://learn.microsoft.com/entra/verified-id/using-facecheck
    * ASD/ACSC Essential Eight maturity model (mentioned at 33:41) - https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model
    * Microsoft Entra account recovery overview (discussed at 36:59) - https://learn.microsoft.com/entra/identity/authentication/concept-account-recovery-overview
    * Verified ID identity verification partners (discussed at 37:12) - https://learn.microsoft.com/entra/verified-id/idv-partners
    * Microsoft Entra licensing (discussed at 39:27) - https://learn.microsoft.com/entra/fundamentals/licensing
    * Verified ID and Face Check pricing model (discussed at 39:27) - https://learn.microsoft.com/entra/verified-id/verified-id-pricing
    * Deploy phishing-resistant passwordless authentication (mentioned at 52:34) - https://learn.microsoft.com/entra/identity/authentication/how-to-deploy-phishing-resistant-passwordless-authentication
    Related Entra.Chat Episodes
    * Microsoft Is Auto-Enabling Passkeys in March 2026 - https://entra.news/p/microsoft-is-auto-enabling-passkeys
    * Mastering Microsoft Entra ID: Real-World Passkey Deployment Tips - https://entra.news/p/mastering-microsoft-entra-id-real
    * Entra Ignite Recap: Synced Passkeys, Agent ID & The Future of Identity - https://entra.news/p/entra-ignite-recap-synced-passkeys
    Chapters
    00:00 Intro
    02:19 Why Microsoft Is Retiring Managed SMS and Voice
    03:32 What the February 2027 Deadline Means
    09:27 Synced vs Device-Bound Passkeys
    14:22 From 69 Seconds to Three
    19:02 Making Passkeys Easier for Users
    23:14 Customer Passkey Deployment Lessons
    28:41 The Secure Bootstrapping Problem
    31:57 Verified ID and Face Check
    33:41 Essential Eight and High-Value Access
    36:24 Self-Service Account Recovery
    39:27 Licensing and Recovery Economics
    44:45 Why Face Check Augments Passkeys
    49:40 Enforce Phishing Resistance and Build a Roadmap
    Podcast Apps
    Apple Podcast - https://entra.chat/apple
    YouTube - https://entra.chat/youtube
    Spotify - https://entra.chat/spotify
    Overcast - https://entra.chat/overcast
    Pocketcast - https://entra.chat/pocketcast
    Others - https://entra.chat/rss
    Merill’s socials
    YouTube - youtube.com/@merillx
    LinkedIn - linkedin.com/in/merill
    Twitter - twitter.com/merill
    TikTok - tiktok.com/@merillf
    Bluesky - bsky.app/profile/merill.net
    Mastodon - infosec.exchange/@merill
    Threads - threads.net/@merillf
    GitHub - github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    The Ultimate Microsoft Entra Global Secure Access Migration Guide

    03/08/2026 | 48 mins.
    An Entra GSA migration should not mean throwing away years of useful SSE policy work and rebuilding every application, segment, and rule by hand.
    Existing configuration carries hard-won intent: which populations need access, which destinations should be blocked, and which exceptions keep the business running. Migrate2GSA creates a path to preserve the useful parts while making the migration a deliberate cleanup opportunity.
    In this episode of Entra.Chat, I spoke with Andres Canello, Principal Product Manager at Microsoft and creator of Migrate2GSA. Andres demonstrates how the open-source toolkit exports configuration from third-party products, converts it into a common CSV schema, gives administrators an intentional review step, and provisions the approved configuration into Global Secure Access through Microsoft Graph.
    The goal is not to configure the product end to end or remove human judgment. Andres describes it as a way to accelerate the repetitive 80%. Conflicting segments default to “do not provision,” existing applications are skipped, generated Conditional Access policies remain disabled, and there is no delete API call in the toolkit.
    The conversation also covers greenfield provisioning, backup and restore, reusable consultant baselines, and the unusual development story behind more than 30,000 lines of PowerShell. Andres explains why detailed, published specifications produced better AI-generated code than incremental prompting—and why the intent and edge cases in an open-source contribution matter more than who typed the implementation.
    Subscribe with your favorite podcast player or watch on YouTube.
    About Andres Canello
    Andres Canello is a Principal Product Manager at Microsoft, where he works at the intersection of modern identity and Secure Service Edge. Over his 15 years at Microsoft, he was a founding member of the Entra Global Secure Access team, helping shape the product before it launched, and has since guided some of the largest identity and secure-access deployments in the industry, from banks and miners to national governments. He’s the creator of Migrate2GSA, an open-source migration toolkit used by organizations around the world, which he built end-to-end using AI-assisted, spec-driven development.
    * Andres Canello on LinkedIn
    * Andres Canello on X/Twitter
    Sponsored by
    Maester Cloud turns every Maester and Microsoft Zero Trust Assessment run into a durable evidence trail. See new failures, fixes, accepted risks, and posture changes across every tenant - without digging through old HTML reports.
    * Keep 5+ years of tenant history in your chosen Azure region
    * Compare runs, spot drift, and get change alerts
    Become a Founding Supporter for $99/month to fund open-source Maester development, shape the roadmap, and get self-hosted private-preview access plus 10% off hosted for life.
    Related Links
    * Plan and troubleshoot UserPrincipalName changes in Microsoft Entra ID (mentioned at 04:07)
    * Azure AD Mailbag: Conditional Access Q&A by Andres Canello (mentioned at 06:43)
    * Migrate2GSA documentation (mentioned at 45:37)
    * Migrate2GSA source repository (mentioned at 45:37)
    Related Entra.Chat Episodes
    * How to Migrate from Legacy VPNs to Entra Private Access (Real Strategies from a Veteran)
    * Global Secure Access Explained: Real-World Rollouts, Mistakes, and Best Practices
    * Identity-Centric Network Security: Entra Global Secure Access Architecture & Benefits
    Chapters
    00:00 Intro
    01:05 Andres Canello's 15 Years in Microsoft Identity
    06:43 A Conditional Access Mistake Admins Still Make
    11:29 From Early Customer Pilots to Entra GSA
    13:21 Why SSE Migrations Should Not Start From Scratch
    18:31 Beyond Migration: Backup Restore and Greenfield
    23:27 Export Convert Review and Provision
    27:02 How Specifications Made AI-Generated PowerShell Work
    35:22 Conflict Detection and the Human Review Gate
    39:14 Microsoft Graph Provisioning with Safety Built In
    43:35 Automating the Repetitive 80 Percent
    46:15 Contributing to Migrate2GSA
    Podcast Apps
    * Entra.Chat
    * Apple Podcast
    * YouTube
    * Spotify
    * Overcast
    * Pocketcast
    * Other podcast apps
    Merill’s socials
    * YouTube
    * LinkedIn
    * Twitter
    * TikTok
    * Bluesky
    * Mastodon
    * Threads
    * GitHub


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
  • Entra.Chat

    Why Entra Admins Need Microsoft Purview Now

    28/07/2026 | 54 mins.
    Conditional Access no longer begins and ends with identity signals.
    Microsoft Purview can now influence the controls Entra administrators are asked to implement. From insider-risk conditions in Conditional Access to inline protection for sensitive data moving toward unsanctioned AI apps. That means Entra teams need enough Purview knowledge to understand what triggers a policy, how users experience it, and who should respond when an alert fires.
    In this episode of Entra.Chat, Merill speaks with Ray Reyes, Principal Security Consultant at Engage Squared and author of Mastering Microsoft Purview Deployment in the Era of AI. Ray explains Data Loss Prevention and Insider Risk Management in plain language, then follows their integrations into Microsoft Entra ID, Microsoft Defender XDR, and Global Secure Access.
    The conversation moves beyond product configuration. A policy can be technically simple and still require identity, network, data-security, HR, management, and data-owner teams to agree on scope, ownership, education, escalation, and remediation. Ray’s practical advice is to understand the neighbouring Microsoft security products at a high level and deploy Purview gradually: start in audit mode or with a limited group, learn from the impact, and expand with the business.
    Ray also shares the story of the charity he and his wife started in Nepal, how it grew from supporting roughly 30 street children to reaching thousands, and how that chapter changed his perspective on work and stress. He and Merill close with an honest discussion about burnout, layoffs, gratitude, personal branding, and building a career safety net outside any one employer.
    Sponsored by
    Recent layoffs have left a lot of strong professionals in limbo.
    That’s why we built Sponsor a Seeker, a simple way for the community to lift each other up.
    For just $29, you can gift a full 3-month Job-Hunt Pass packed with: • Unlimited resume & job description scans • AI-powered rewrites that actually beat ATS systems • Professional cover letter generation
    Every dollar goes directly to the seeker.
    You can: → Sponsor someone like Alex M. (recently laid off front-end engineer) → Or request sponsorship for yourself
    Either way, you’re helping keep momentum alive in a tough market.
    👉 Take action here: pastthebots.com/sponsor
    Let’s turn “I was laid off” into “Someone had my back.”
    Thank you for being part of this community, Rod Trent Past the Bots
    Subscribe with your favorite podcast player or watch on YouTube.
    About Ray Reyes
    Ray Reyes is a Principal Security Consultant at Engage Squared and the author of Mastering Microsoft Purview Deployment in the Era of AI. He previously worked at Microsoft, where he led data-security subject-matter expertise across Asia Pacific and Japan and helped customers deploy Microsoft Purview and Microsoft Defender XDR. His work now spans identity, data security, and the wider Microsoft security stack.
    * LinkedIn → linkedin.com/in/ray-reyes-598062125
    Related Links
    * Mastering Microsoft Purview Deployment in the Era of AI by Ray Reyes (mentioned at 00:00 and 02:25)
    * Microsoft Purview overview (discussed from 03:29)
    * Adaptive Protection in Microsoft Purview (discussed at 22:09)
    * Learn about Data Loss Prevention for Network Data Security (discussed at 33:31)
    * Configure Microsoft Entra Internet Access content filtering (discussed at 34:18)
    * The Resilience Project: Finding Happiness through Gratitude, Empathy and Mindfulness by Hugh van Cuylenburg (mentioned at 47:25)
    Related Entra.Chat Episodes
    * How Microsoft Is Securing AI Agents in Entra — Conditional Access, Zero Trust & the “Block” Debate
    * How to Migrate from Legacy VPNs to Entra Private Access
    * What’s New in Microsoft Entra — May 2026: Passkeys, Agents & Cloud Sync
    Chapters
    00:00 Intro
    03:29 Why Purview Matters to Entra Admins
    05:39 How Microsoft Purview Evolved
    09:46 Data Loss Prevention Explained
    16:04 Insider Risk and Employee Departures
    22:09 Adaptive Protection Meets Conditional Access
    25:00 Education and Alert Ownership
    28:51 Breaking Down the Security Silos
    33:31 Network Data Security and Unsanctioned AI
    38:29 How to Roll Out Purview Safely
    41:20 Ray’s Charity Work in Nepal
    47:10 Resilience Burnout and a Career Safety Net
    Podcast Apps
    Apple Podcast - https://entra.chat/apple
    YouTube - https://entra.chat/youtube
    Spotify - https://entra.chat/spotify
    Overcast - https://entra.chat/overcast
    Pocketcast - https://entra.chat/pocketcast
    Others - https://entra.chat/rss
    Merill’s socials
    YouTube - youtube.com/@merillx
    LinkedIn - linkedin.com/in/merill
    Twitter - twitter.com/merill
    TikTok - tiktok.com/@merillf
    Bluesky - bsky.app/profile/merill.net
    Mastodon - infosec.exchange/@merill
    Threads - threads.net/@merillf
    GitHub - github.com/merill


    Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
More News podcasts
About Entra.Chat
Entra Chat is a weekly podcast hosted by Merill Fernando and delivers practical insights for Microsoft administrators and security professionals through conversations with identity experts who've been in the trenches. Episodes feature seasoned Entra practitioners sharing real-world deployment experiences and Microsoft Entra team members who build the features you use daily. Get the inside track on best practices, implementation strategies, and upcoming capabilities directly from those who design and deploy Microsoft identity solutions. Join us for actionable takeaways you can apply immediately in your Microsoft 365, Azure, and Entra environments. --- Entra.Chat, its content and opinions are my (Merill Fernando) own and do not reflect the views of my employer (Microsoft). All postings are provided “AS IS” with no warranties and is not supported by the author. All trademarks and copyrights belong to their owners and are used for identification only. entra.news
Podcast website

Listen to Entra.Chat, The Rest Is Politics: Leading and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features