Entra.Chat
by Merill Fernando
entra.news
Merill & Joshua Fernando
Sep 17, 2026Recent reviews on Apple Podcasts (1)
Excellent IAM Discussions
Four episodes in, Enta.Chat is an excellent opportunity for IAM (Identity Access Management)practitioners to listen to Merill and his Guest discuss interesting, useful, informative, and practical Entra ID insights! Looking forward to many more episodes! Kudos to Merill for yet another IAM community beneficial endeavor! MM
MikeM0808 ·
Episodes (78)

Active Directory Security Testing in Maester 2.2
Sep 17, 202636m#75
Active Directory is not dead. It is nearly thirty years old, Microsoft is still shipping new capabilities and new telemetry for it, and most of the forests running today will outlive the people currently administering th

Microsoft Security Architect: Active Directory Is 10x Harder to Defend Than Entra
Sep 6, 202659m#74
At Black Hat USA 2026, Microsoft’s David Weston put three numbers on a slide that anyone still running domain controllers should sit with. The Microsoft Security Response Center went from 80 patches in February to 1,142

How General Motors Moved 200,000 People to Passkeys
Aug 31, 202643m#73
Microsoft starts making passkeys the default in Microsoft Entra ID on 1 September 2026, and retires Microsoft-provided SMS and voice MFA on 1 February 2027. Every organisation with a large, messy population now has to an

Microsoft Entra memberOf Retirement: What Admins Must Do
Aug 25, 202642m#72
On 3 November 2026, the memberOf operator in Microsoft Entra dynamic membership groups stops working. Nothing errors. Nothing breaks loudly. Every dynamic group, dynamic administrative unit and entitlement management aut

Pass-the-Passkey: What Michael Grafnetter's Black Hat Research Means for Entra Admins
Aug 17, 202636m#71
Passkeys are phishing-resistant. But that resistance is enforced by your browser, which binds every authentication to the origin that requested it. Skip the browser, and the guarantee weakens. In this episode of Entra.Ch

From SMS MFA to Passkeys: A Practical Microsoft Entra Migration Plan
Aug 10, 202653m#70
Microsoft-managed SMS and voice MFA will stop working on February 1, 2027. That deadline makes passkey planning urgent, but enabling a new authentication method is only the first milestone. In this episode of Entra.Chat,

The Ultimate Microsoft Entra Global Secure Access Migration Guide
Aug 3, 202648m#69
An Entra GSA migration should not mean throwing away years of useful SSE policy work and rebuilding every application, segment, and rule by hand. Existing configuration carries hard-won intent: which populations need acc

Why Entra Admins Need Microsoft Purview Now
Jul 28, 202654m
Conditional Access no longer begins and ends with identity signals. Microsoft Purview can now influence the controls Entra administrators are asked to implement. From insider-risk conditions in Conditional Access to inli

How Xbox Secures 70+ Entra Tenants Every Night with Maester
Jul 20, 202646m
Xbox Security runs a gaming-specific Microsoft Entra baseline across more than 70 tenants every night. The scale is striking: about 50 controls, dozens of independently operated game-studio tenants, and one parallel pipe

One Compromised Agent ID Blueprint Can Cross Tenant Boundaries
Jul 12, 202654m#66
Microsoft Entra Agent ID uses familiar application and service-principal objects under the hood, but its one-to-many hierarchy creates a different security boundary. A blueprint can be associated with many agent identiti

Attackers Are Targeting The AI Ecosystem You Cannot See
Jul 4, 202644m#65
AI agent security is not just about attackers using AI. It is also about attackers targeting the agent ecosystem most organizations cannot see clearly yet: MCP servers, agent skills, packages, API keys, prompts, tools, a

From Windows Core to Leading Agent ID: Vince Smith’s Microsoft Story
Jun 28, 202647m#64
Folks, every big thing in identity started as somebody’s late-night side quest and Vince Smith has been in the room for a lot of them. In this episode of Entra Chat, Vince (the PM lead driving Microsoft Entra Agent ID) w

Shadow Admins: The Non-Human Identities Hiding in Your Entra Tenant
Jun 20, 20261h 8m
Not every admin in your tenant is a person. Service principals, app registrations, and the new wave of agent identities can quietly hold permissions powerful enough to own your entire environment and most orgs can’t even

How Microsoft Is Securing AI Agents in Entra - Conditional Access, Zero Trust & the "Block" Debate
Jun 13, 202643m#62
AI agents can make decisions and act faster than any human — which means your old identity security playbook no longer holds. In this episode of Entra Chat, [host name] sits down with Nikhil, a 10+ year Microsoft identit

The Learn-It-All Career Playbook for Identity and Security Pros
Jun 6, 202634m#61
In this episode of Entra Chat, we sit down with Christina Morillo , the Senior Director of Information Security for the New York Football Giants , to explore her inspiring transition from an identity specialist to a top-

5 Lessons from Rolling Out Passkeys to Millions of Users
May 31, 202646m#60
Passkeys are one of those technologies that sound simple on paper. Turn them on.Users register them.Passwords go away.Everyone is more secure. But in the real world, passkey rollouts are not just an authentication settin

The New Control Plane for Microsoft Entra Tenant Governance
May 23, 202649m#60
Microsoft had 7 million internal tenants and almost lost control of their environment and your org might be facing the same problem at a smaller scale. In this episode, we sit down with Jeff Staiman , PM Area Lead for Te

What’s New in Microsoft Entra - May 2026: Passkeys, Agents & Cloud Sync
May 16, 202650m#59
Fabian and Thomas join the podcast to share their extensive experience and unpack the massive wave of updates coming to Microsoft Entra. We talk about the massive shift toward Passkeys and registration campaigns, the imp

If You Manage Entra Permissions, Watch This Before Deploying Agents
May 9, 202644m#58
Microsoft Entra Agent ID Just Went GA Here’s What You Need to Know About Agent Permissions If you’ve been waiting for the dust to settle on Microsoft Entra Agent ID before diving in, the wait is over. Agent ID hit Genera

How to Secure Copilot Agents, Azure DevOps & Defender (+ more) with Maester 2.1 (Full Breakdown)
May 2, 20261h 1m#57
Maester is back with one of its biggest release since launch. In this episode, we are joined by Sam Erde, Architect at Patriot Consulting and one of Maester’s core maintainers, to walk through everything that’s landed in

What an ID Governance Consultant Wishes You Knew About Entra
Apr 25, 202646m#56
Identity Governance is often treated as a “nice-to-have” compliance checkbox, but as ID Governance expert Sandra Saluti reveals, it is actually the foundation of a secure, scalable environment. In this technical deep div

Stop Leaving the Door Open: The Entra ID Hardening Checklist Security Experts Actually Use
Apr 18, 202659m#56
Microsoft Entra security is evolving and the way organizations think about identity protection needs to evolve with it. In this episode, I’m joined by Sean Metcalf, one of the foremost identity security experts in the in

How to Design Bullet-Proof Conditional Access Policies in Microsoft Entra ID
Apr 11, 202656m#55
If you can’t immediately name your break glass accounts and the last time you tested them → you’re already at risk. In this episode of Entra Chat, Microsoft MVP Per Torben walks through the conditional access mistakes he

5 Entra ID Updates You Can’t Afford to Ignore in 2026 (Backup, Governance, CA Agent & Risk Score Exposed)
Apr 4, 20261h 0m#54
Microsoft just dropped a massive wave of features for Entra, and the rules of Tenant Governance have officially changed. Join us as we talk to three world-class MVPs about their hands-on experience with the new Entra Bac

Finding Every MFA Gap: Testing 250 Million Conditional Access Combinations in Under 20 Minutes
Mar 28, 20261h 1m#54
Emilien Socchi, Cloud Security Research Engineer at Storebrand, joins us to discuss CA Insight and AZTier. Two open-source tools Emilien built to find gaps in Conditional Access policies and categorize Azure/Entra roles