• Home
  • Contact Cloud Identity Architect
  • Privacy Policy for AdverSite Web Holdings, Inc.

Cloud Identity Architect

Identity Solutions for the Public and Hybrid Cloud

  • Active Directory (On Premises)
  • API Authentication
  • Azure AD
  • Entra ID
  • Graph API
  • JWT
  • MFA
  • OAuth 2.0
  • Office 365
  • SAML
  • SCIM
  • Securing Identity
  • SSO
  • Transport Layer
  • Troubleshooting – network and identity
  • Uncategorized

One Time Passwords

anuj June 8, 2021 One Time Passwords2021-07-07T19:49:00+00:00 MFA
What are OTPs? OTPs (alphanumeric strings) authenticate a user for a single transaction or session. OTPs may replace authentication login information or may be used in addition to it, to…
Continue Reading

SCIM based provisioning of users versus Graph API

anuj June 2, 2021 SCIM based provisioning of users versus Graph API2021-06-02T13:52:49+00:00 Active Directory (On Premises)
Say you had a SaaS product configured as an enterprise App in AAD and wanted to automate the addition / decommissioning of users for that app. There's a few paths…
Continue Reading

Microsoft Identity Manager – MIM

anuj June 1, 2021 Microsoft Identity Manager – MIM2021-06-01T22:52:49+00:00 Azure AD
MIM can be thought of as the precursor to AAD Enterprise Applications. It enables on premises AD Admins to provide users access to Active Directory and on-premises business applications. By…
Continue Reading

Adding an Internal App to MyApps (to AAD) using App Proxy

anuj May 24, 2021 Adding an Internal App to MyApps (to AAD) using App Proxy2021-05-24T15:30:50+00:00 Active Directory (On Premises)
One is accustomed to going to MyApps to see all their SaaS apps configured. However, even non-SaaS apps, including internal web apps and APIs can be hosted on MyApps. This…
Continue Reading

Why move from ADFS to AAD?

anuj May 22, 2021 Why move from ADFS to AAD?2021-06-22T23:42:18+00:00 Active Directory (On Premises)
Here are some of the reasons you should consider moving away from ADFS to AAD Certificate Management No Planned Downtime as in ADFS changes / updates. AAD Conditional Access -…
Continue Reading

More on AAD Guest Users

anuj May 22, 2021 More on AAD Guest Users2021-06-22T17:44:56+00:00
(Also read AAD B2B External Users   and Apps Visible in MyApps) Per Microsoft's Documentation Member: This value indicates an employee of the host organization and a user in the organization's…
Continue Reading

Invitation Flows for AAD B2B Users

anuj May 21, 2021 Invitation Flows for AAD B2B Users2021-05-22T13:55:43+00:00 Azure AD
Invitation flows b2b users AAD B2B users have to be invited. Either via an email invitation or a direct URL link. There are also backdoor mechanisms (powershell and graph API)…
Continue Reading

App Visibile in MyApps versus Access to apps

anuj May 21, 2021 App Visibile in MyApps versus Access to apps2021-05-21T20:18:55+00:00 Azure AD
There is a common misconception around AAD apps. If you can see it in myapps, you have access to it - otherwise you do not. This is not entirely true.…
Continue Reading

AAD External users (vendors etc) and Office 365 Access

anuj May 17, 2021 AAD External users (vendors etc) and Office 365 Access2021-05-24T22:33:38+00:00 Azure AD
 Guest Users (aka B2B Users) These are users that are added as 'Guest' users in your AAD tenant. Some external users ( vendors ) are truly B2B users. For example,…
Continue Reading

Query AAD for all members of a group

anuj May 11, 2021 Query AAD for all members of a group2021-05-11T14:05:48+00:00 Azure AD
To query AAD for all members of a group (note that the -All flag does not retrieve all users - try the -Top option instead) Get-AzureADGroupMember -ObjectId "my_obect_id" -Top 200000…
Continue Reading
«‹23456›»

Recent Posts

  • Capturing a Second Factor Before Full Trust
  • Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One
  • Inbound versus Outbound SSO
  • OAuth – a primer
  • Two OAuth Flows – Public and Private

Recent Comments

  • WFH and Remote Access Security Risks - Cloud Identity Architect on Work from Home – Laptop Options

Archives

  • May 2025
  • April 2025
  • March 2025
  • January 2025
  • November 2024
  • October 2024
  • October 2022
  • January 2022
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • September 2020

Categories

  • Active Directory (On Premises)
  • API Authentication
  • Azure AD
  • Entra ID
  • Graph API
  • JWT
  • MFA
  • OAuth 2.0
  • Office 365
  • SAML
  • SCIM
  • Securing Identity
  • SSO
  • Transport Layer
  • Troubleshooting – network and identity
  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Search

Recent Posts

  • Capturing a Second Factor Before Full Trust
  • Enforcing a Second Factor in Entra ID: How to Secure Users Who Never Had One
  • Inbound versus Outbound SSO
  • OAuth – a primer
  • Two OAuth Flows – Public and Private

Pages

  • Contact Cloud Identity Architect
  • Privacy Policy for AdverSite Web Holdings, Inc.

Tags

    2FA Entra ID aad b2b versus b2c aad b2b vs b2c aad b2c downsides aad connect versus aad sync ad connect transformations adfs to aad ad sync to azure ad API authentication and OAuth b2b from ad to aad b2b guest users aad b2c ad to aad Capturing a Second Factor Before Full Trust Enterprise AAD AppEnterprise AAD App guest users AAD ldap in azure ad list of attribute values AAD SAML MFA Guest Users AAD migrate existing b2b users migrate existing b2c users One Time Password option One Time Passwords OTP MFA AAD saml federation to AAD SCIM - Real World Notes SMS Guest Users Azure AD sync ad to aad Syncing new users and groups to an existing AAD tenant sync users to aad visible to all users aad app
Copyright ©2025. Cloud Identity Architect
Mesocolumn Theme by Dezzain