Field notes
RSS FeedFindings from working on Microsoft Entra ID, Azure and identity security. Configurations that behave unexpectedly, permission models that don't match their documentation, and the occasional genuine security gap — written up with the reproduction steps.
Everything here was encountered directly and verified. Where a conclusion is provisional, the post says so.
Social Links:
Featured
What this blog is
Field notes on Entra ID, Azure and identity security — written down properly instead of disappearing into a scratch file.
Restricted Management AUs in Entra ID: two undocumented paths that actually work
Restricted Management Administrative Units contain a service principal holding Application.ReadWrite.All — but the design depends on three configurations Microsoft does not document. All three tested against a live tenant with az rest.