Microsoft 365 · Entra ID · Intune · Security

Microsoft 365 Security

Practical guidance for IT teams managing Entra ID, Intune, and Conditional Access.

  1. Donny van Huizen 5 min read Announcement

    Intune Adds Client-Driven Compliance Evaluation for Windows (Preview)

    Seven specific compliance signals on Windows devices now trigger a re-evaluation in near real time instead of waiting for the next scheduled check-in. Everything else still runs on the old cycle, and there's built-in throttling most write-ups have missed.

    microsoft intunedevice compliancewindowsendpoint managementconditional access
  2. Donny van Huizen 7 min read Announcement

    User.ReadBasic.All loses access to app roles and license data this month (MC1470871)

    User.ReadBasic.All has quietly exposed app role assignments and license details since it shipped. That access closes in a rollout completing late September 2026. What breaks, and one discrepancy in Microsoft's own migration guidance worth checking before you act on it.

    microsoft 365microsoft graphentra idsecurityidentity security
  3. Danny Vorst 10 min read Blog

    Require approved client app is retired on June 30: migrate now

    Require approved client app is deprecated June 30. After that date, existing policies stop enforcing. Here is what to configure before the deadline.

    microsoft 365securityconditional accessentra idintuneapp protectionmamidentity security
  4. Donny van Huizen 13 min read Blog

    Intune Multiple Managed Accounts: what admins need to know

    Intune's MMA feature, rolling out in June 2026, lets users hold multiple MAM accounts in one app. Here's what admins managing external access need to know.

    intunemamapp protection policymultiple managed accountsbyodexternal usersb2bmmaconditional access
  5. Danny Vorst 11 min read Blog

    Conditional Access enforcement changes June 15: check your exceptions now

    Apps could bypass Conditional Access by requesting minimal sign-in scopes. Non-excluded apps slipped through silently for years. Starting June 15, that stops.

    microsoft 365securityconditional accessentra idmfaidentity securitypolicy
  6. Danny Vorst 13 min read Blog

    AiTM Phishing Exposed (2/2): Stop Session Hijacking

    Stop AiTM session hijacking with FIDO2, CAE, and token protection. Microsoft 365 configuration guide with 2 Sentinel queries and 7-step incident response.

    securityphishingmfaconditional accessentra idmicrosoft 365session tokenaitmfido2passkeys
  7. Donny van Huizen 18 min read Blog

    Unmanaged Devices with Microsoft Intune (3/3): iOS

    iOS MAM covers the full M365 app suite but requires Microsoft Authenticator as broker. 3 BYOD paths, the CA gap most organizations miss, and what goes wrong.

    byodiosintunemamapp protection policyuser enrollmentsupervisedconditional accessunmanaged devicesendpoint management
  8. Danny Vorst 12 min read Blog

    AiTM Phishing Exposed (1/2): How Session Hijacking Works

    AiTM phishing doesn't bypass MFA. It waits for MFA to succeed, then takes what comes next. This is how the attack works and why standard MFA provides no protection against it.

    securityphishingmfaconditional accessentra idmicrosoft 365session tokenaitm
  9. Donny van Huizen 15 min read Blog

    Unmanaged Devices with Microsoft Intune (2/3): Android

    Android MAM protects all Microsoft 365 apps on mobile, not just Edge. 3 BYOD paths, different control levels, and the CA gap most organizations miss.

    byodandroidintunemamapp protection policyandroid enterprisework profileconditional accessunmanaged devicesendpoint management
  10. Danny Vorst 10 min read Blog

    Shadow AI Exposed (2/2): Building a Governance Program That Actually Works

    Technical controls catch the visible surface. This part covers what a shadow AI governance program looks like in practice: approved AI catalog, the personal account problem, and a maintenance cycle that doesn't erode.

    securityshadow aiai governancemicrosoft 365data protection