A policy set that works in a demo tenant and locks out a real organisation is the normal outcome. Report-only mode, exclusion design and a deliberate rollout order prevent it.
Article collection
Microsoft Entra and hybrid identity
Practical guidance for Microsoft Entra ID, Conditional Access, authentication and hybrid identity transitions.
Published guidance
A user exists on-premises, does not exist in the cloud, and sync reports success. A read-only triage script that finds the objects Entra ID quarantined and explains which attribute caused it.
Application secrets expire quietly and fail loudly, usually out of hours. A read-only script that lists every credential in the tenant with its expiry, owner and blast radius.
Delegated and application permissions are not two settings on the same dial. One is bounded by the signed-in user and one is not, and the difference decides your exposure.
Two provisioning engines with overlapping names and genuinely different architectures. The decision turns on transformation complexity and forest topology, not on which is newer.
Break-glass accounts fail for the same reason everything else fails during an incident: they were configured once and never exercised. The controls that keep them usable are specific.
The sign-in log answers questions the portal makes awkward: legacy authentication by application, failures by error code, and which accounts are risky right now.
Directory synchronisation works for years and then fails in a way the pilot never covered. These are the failures I check for, and the evidence that identifies each one.
Hybrid join failures are diagnosed by a tool that prints eighty lines of state nobody reads. A script that parses it, names the failing phase and checks the service connection point.
An agent acting on a user's behalf inherits that user's access, including everything they could reach but never did. The oversharing problem stops being theoretical.
Compliance is only a report until Conditional Access reads it. Connecting the two is a single checkbox and the most effective way to lock out your entire organisation.
Moving to phishing-resistant authentication is mostly not a passkey problem. It is a recovery, enrolment and exception problem, and those need solving first.
PIM turns standing administrative access into time-bound, justified and reviewable access. Most deployments stall because the role inventory was never done.
Deleting a dormant account is easy. Knowing whether something still depends on it is the actual work, and LastLogonDate will not tell you.
What identity teams should verify before the mandatory Entra Connect Sync upgrade deadline, and how to reduce cutover risk.
A practical guide to governing AI agents with Entra Agent ID, Conditional Access, Defender and Purview, including PowerShell, Graph requests and validation.
