Adventures in the Zero Trust Cloudland
  • About Me
  • Resources
    Azure Architecture Center Azure Well Architected Framework AADInternals Blog Awesome Entra AzAdvertizer Azure Cloud Adoption Framework Dirk-jan Mollema Blog Entra ID Attack & Defense Playbook Entra.News KQLSearch MCRA NetSPI Blog Office 365 for IT Pros SpecterOps Blog Zero Trust Core Principles Zero Trust Guidance Center
  • Search
✕
    • Entra ID - protecting security information registration - how to balance usability and risks?

      By Lukasz Kozubal

      Posted on March 4, 2026

      Introduction - why do we need to protect the authentication factor registration process? I believe we can all agree that relying on the password alone isn’t a viable authentication strategy anymore - if it ever truly was. As such, enforcing multi-factor authentication for user sign-ins shall be a critical priority... [Read More]
      Tags:
      • Microsoft Entra ID
      • Identity Management
      • Security Operations
    • Entra ID - tokens and cookies - a different perspective.

      By Lukasz Kozubal

      Posted on April 2, 2025

      No, I am not going to bore you to tears with another article on how refresh tokens, access tokens and session cookies work and how their implementation in Microsoft Entra ID looks like. In this article, I would rather like to consider specific sub-types of refresh tokens and session cookies... [Read More]
      Tags:
      • Microsoft Entra ID
      • Identity Management
      • Security Operations
    • Workload Identity Federation - great feature with some risks!

      By Lukasz Kozubal

      Posted on January 11, 2025

      The goal of this article is to present and explain implicit risks related to workload identity federation feature available in Entra ID and Azure infrastructure. The upsides of using it are well known and advertised. What’s more difficult to find, is the summary of main risks attached to the use... [Read More]
      Tags:
      • Microsoft Entra ID
      • Azure Infrastructure
      • Access Control
      • Identity Management
      • Governance
      • Security
    • Entra ID - smart lockout - protect your users from malicious account lockouts!

      By Lukasz Kozubal

      Posted on November 24, 2024

      I recently had several conversations related to smart lockout feature in Entra ID. Based on those, it occurred to me that inner workings of this feature are not as widely known as I assumed. [Read More]
      Tags:
      • Microsoft Entra ID
      • Access Control
      • Identity Management
      • Governance
      • Security
    • Azure Infrastructure - RBAC model - new roles with control plane permissions

      By Lukasz Kozubal

      Posted on October 13, 2024

      Some interesting changes happened recently (within last year 😉) in the area of highly privileged (i.e. control plane or Tier 0 in legacy terms) Azure infrastructure RBAC model roles. Up until now, the classic trio of control plane privileged roles with direct control over Azure infrastructure was limited to: [Read More]
      Tags:
      • Azure Infrastructure
      • Access Control
      • Least Privilege
      • Identity Management
      • Governance
      • Security
    • Older Posts
    • RSS
    • GitHub
    • LinkedIn

    Lukasz Kozubal  •  2026  •  https://blog.identitylab.ch

    Powered by Beautiful Jekyll Icons by Freepik