Skip to content
NBPTech
Go back

What this blog is

Most of what I learn about Microsoft Entra ID arrives the same way: something behaves differently than the documentation implies, I work out why, and the explanation ends up in a scratch file I never open again.

This is where those go instead.

What to expect

Posts here are findings, not tutorials. Each one is something I actually ran into — a setting that doesn’t do what its name suggests, a permission that grants more than it appears to, a gap between what a portal blade shows and what the Graph API reports.

Where a finding has a security impact, I’ll state it plainly, along with the conditions required to reach it and what to do about it. Where I’m uncertain, I’ll say that too. A finding written up honestly with an open question is more useful than one padded into false confidence.

What you won’t find

Nothing here identifies a customer. Tenant identifiers, object IDs, domain names and account details are redacted or replaced with placeholders, and anything affecting a specific organisation is remediated and cleared before it appears. Where a finding concerns a vendor-side issue, it goes through disclosure first.

That constraint occasionally makes a post less vivid than the original investigation. It is not negotiable.

Corrections

If something here is wrong, I would genuinely like to know — identity platforms change quickly, and a post accurate in August may not be by December. Posts that get materially revised carry an updated timestamp.

You can reach me on LinkedIn.


Share this post:

Previous Post
Restricted Management AUs in Entra ID: two undocumented paths that actually work