top of page



Conditional Access Resource Exclusions Remediation Guide with SIEM detections
Microsoft's Conditional Access enforcement change takes effect March 27, 2026. Learn how low-privilege OAuth scope exemptions created a security gap, how to detect affected applications using Sentinel KQL and Splunk SPL queries, and how to prioritise remediation before ROPC flows start failing in your tenant.
Rory Wade
1 day ago13 min read


Configure App attributes in Entra ID Access Token – App Claims Mapping Policy
Configure Entra ID to include App Displayname claims in Client Credential Access Token using Claims Mapping Policies for Service to Service
Nick Tillack
Mar 17, 20255 min read


Implementing Invite Only Sign-Ups with Microsoft Entra External ID
Invite-Only Entra External ID implementation to only allow specific email addresses from creating an accounts in your Entra External ID
Rory Wade
Mar 16, 20253 min read


Export Entra ID Privileged Identity Management (PIM) Approvers via PowerShell
Privileged Identity Management (PIM) is a critical security service within Microsoft Entra ID that provides just-in-time (JIT) privileged...
Rory Wade
Mar 1, 20255 min read
bottom of page