<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>NBPTech</title><description>Field notes and findings on Microsoft Entra ID, Azure and identity security.</description><link>https://nbptech.nl/</link><item><title>What this blog is</title><link>https://nbptech.nl/posts/welcome/</link><guid isPermaLink="true">https://nbptech.nl/posts/welcome/</guid><description>Field notes on Entra ID, Azure and identity security — written down properly instead of disappearing into a scratch file.</description><pubDate>Tue, 18 Aug 2026 07:00:00 GMT</pubDate></item><item><title>Restricted Management AUs in Entra ID: two undocumented paths that actually work</title><link>https://nbptech.nl/posts/restricted-management-aus-entra-id/</link><guid isPermaLink="true">https://nbptech.nl/posts/restricted-management-aus-entra-id/</guid><description>Restricted Management Administrative Units contain a service principal holding Application.ReadWrite.All — but the design depends on three configurations Microsoft does not document. All three tested against a live tenant with az rest.</description><pubDate>Tue, 19 May 2026 10:00:00 GMT</pubDate></item></channel></rss>