RSSAmplifier

Blog

Welka's World

The ultimate destination for Microsoft enthusiasts

welkasworld.comRSS feed ↗20 posts

Latest posts

Microsoft Purview Workload Content roles in Entra & new PIM alerts

Purview Workload Content roles Entra ID are now automatically synced from Microsoft Purview into Entra, causing unexpected PIM alerts and audit log activity. This MC1199765 update creates direct role mapping between Purview and Entra ID. Here’s what’s changing, why it matters, and what you’ll see in your tenant.

Migrating to Microsoft Purview sensitivity label groups: what I learned

Sensitivity label groups are replacing parent and child labels in Microsoft Purview. This post covers what changes, how the migration works, what Microsoft documents, what I have seen in testing and production, and why I would be careful before migrating widely adopted labels in a live environment.

AI governance overview: stop panicking and fix the basics

A practical AI governance overview for organisations that are either rushing into AI or panicking over every new feature. This post explains why strong fundamentals, identity, device security, permissions and data protection matter more than chasing every shiny AI setting.

Blocking Bring Your Own Copilot (BYOC) on work documents

Blocking bring your own Copilot on work documents is something more organisations should be looking at. Microsoft allows multiple account access by default unless you explicitly block it, which means employees may be able to use personal Copilot entitlements on work files in supported Microsoft 365 apps. This post explains what BYOC is, why it matters, what Microsoft allows by default, what the…

Microsoft Purview Endpoint DLP Always-On Diagnostics

Learn how to enable Microsoft Purview Endpoint DLP Always-On Diagnostics and simplify troubleshooting by collecting logs directly from Windows devices without user involvement. This guide covers setup, permissions, prerequisites, and how to request diagnostic logs to speed up investigations and resolve issues faster.

Microsoft Purview Data Loss Prevention Diagnostics Explained

Struggling with DLP issues in Microsoft Purview? This guide breaks down Microsoft Purview Data Loss Prevention Diagnostics, including new endpoint diagnostics updates, built-in troubleshooting scenarios, and how to quickly identify and fix policy issues across your Microsoft 365 environment.

Meet the Scholars: Incredible Voices Shaping the Future of Tech

I had the privilege of meeting these inspiring scholars in Dallas, and their passion for technology left a lasting impression. In this feature, they share their journeys into IT, what the conference meant to them, their career ambitions, and the impact they hope to make in the next five years. Meet the scholars shaping the future of tech.

Becoming a Microsoft MVP

Becoming a Microsoft MVP in Security wasn’t a straight line. From rejection on April Fool’s Day to battling imposter syndrome and self-doubt, this is the honest story behind my journey into cybersecurity and the Microsoft MVP Program. No polished highlight reel - just resilience, community, Microsoft Purview, and learning to water your own grass.

How to Use PIM with RBAC Roles: Purview, Exchange, and More

Discover how to use PIM with RBAC roles to provide just-in-time access for users. Learn setup for Purview, Exchange, and more, plus the pros, cons, and gotchas.

How to Export Microsoft Purview Permissions (RBAC Roles) Easily

I was recently asked if I knew a way to export Microsoft Purview RBAC roles with members. I couldn’t find a ready solution, so I wrote a PowerShell script. You can get it from my new GitHub Purview repository. Perfect for auditing and managing Purview permissions easily!

Physical Security Cards: Phish-Resistant Authentication

Explore how physical security cards combine passwordless login and building access, offering secure, simple authentication for modern workplaces.

Conditional Access Essentials: From Report-Only to Enforced Mode

Moving Conditional Access policies from report-only to enforced mode can secure your environment - or lock everyone out. This post walks through safe rollout strategies using ring deployments, the What If tool, Policy Impact, Log Analytics, Workbooks, Gap Analyzer, and real KQL queries. Learn how to monitor, test, adjust and confidently turn policies on without breaking access or business…

Conditional Access Essentials: Custom Security Attributes in Entra ID and Cross Tenant Scenarios

Learn how to use custom security attributes in Entra ID to target apps that don’t appear in Conditional Access. This step-by-step guide covers attribute sets, names, and values, plus real scenarios like legacy authentication, persona-based targeting, and enforcing MFA. We’ll also explore cross-tenant access settings to securely trust MFA and device claims from partner tenants.

Conditional Access Essentials: Managing Exclusions with Identity Governance and Temporary Access Pass

Conditional Access Essentials aren’t just about writing policies – it’s about managing real-world scenarios. In this guide, I show how to handle tricky exclusions with Temporary Access Pass (TAP) for seamless onboarding, and Identity Governance with Access Packages for secure travel and exception management. Whether you’re new to Conditional Access or already designing enterprise-grade policies,…

Conditional Access Essentials: Authentication contexts + Secure PIM & Resource Access

This instalment of Conditional Access Essentials explores authentication contexts, PIM, and securing sensitive resources. Learn how to enforce step-up MFA, apply authentication contexts to SharePoint sites, and protect privileged roles with real-world policy examples, limitations, and best practices.

Conditional Access Essentials: RMAUs, Named Locations, Authentication Strengths, Service Principals

Strengthen your Conditional Access strategy with practical essentials. Explore how RMAUs, Named Locations, Authentication Strengths, and Service Principals protect sensitive accounts, secure apps, and enforce the right access for every persona. Real-world guidance for building resilient, manageable policies.

Conditional Access Essentials: Naming conventions, personas, emergency access & design process

Master Conditional Access with a Zero Trust, persona-based approach. Learn how to structure policies, avoid security gaps, and keep everything organised with clear naming conventions. From discovery workshops to practical use cases, this guide helps you design scalable, secure policies that work in the real world.

Conditional Access Essentials: Introduction, use cases, the art of possible

Discover how Microsoft Conditional Access protects your Microsoft 365, Entra, and Azure environments. Learn the essentials, explore real-world use cases, and see the art of the possible with practical examples. From securing identities to controlling device access, this guide is your starting point for mastering Conditional Access in a modern Zero Trust security strategy.

Legacy MFA & SSPR are retiring -How to migrate MFA and SSPR settings to the Authentication methods policy

Learn how to migrate MFA and SSPR policy settings to the Authentication methods policy in Microsoft Entra before the legacy settings are retired. This guide walks IT pros through the step-by-step process, gotchas to avoid, and key recommendations to ensure a smooth and secure transition to modern authentication methods.

Configuring M365 Company Branding & Privacy Settings: Simple Tricks to Reduce Phishing Risks

Company branding isn’t just about creating a visual identity - it’s a key security measure for reducing phishing risks. In this post, I dive into how configuring your Microsoft 365 login page with your company’s logo, colours, and even a recognisable background image can help users easily spot fake login pages. Spoiler: there are ducks involved, and you’ll have to read on to understand why!