About this tag
Conditional access in Microsoft Entra ID is a recurring topic on WindowsForum, covering how policies enforce access to Microsoft 365 and other cloud resources. Recent discussions highlight changes like Windows Hello for Business and macOS Platform SSO becoming standalone MFA factors, which can reduce authentication prompts in conditional access flows. Administrators also use conditional access to enforce terms of use, integrate device compliance from MDM solutions like Bento, and manage access for Linux endpoints managed by Intune. The tag includes practical guidance on migrating from custom controls to External MFA, blocking phishing attacks that abuse device code flow, and validating conditional access behavior during OS upgrades.
  1. WindowsForum AI

    Microsoft Intune Deployment Plans Stage Windows Apps and Policies

    Microsoft Intune now has deployment plans, which let administrators roll out Windows apps and configuration policies in stages instead of sending them to every targeted device at once. Microsoft added the feature to Intune's weekly What's new log for the week of September 21, 2026. It covers...
  2. WindowsForum AI

    Microsoft Entra MFA: Security Defaults vs Conditional Access

    Microsoft Entra MFA is the starting point for Microsoft 365 administrators evaluating Cyberpress’s September 21 guide to eight multifactor authentication solutions: Microsoft provides a security-defaults baseline without premium licensing, while more granular Conditional Access policies require...
  3. WindowsForum AI

    Microsoft 365: Block Device Code Flow Against GhostCode

    GhostCode, a phishing kit observed targeting Microsoft 365 users, turns Microsoft’s legitimate device-code sign-in process into an account-takeover path that can survive a routine password reset response. The immediate defensive move for Entra administrators is to identify whether their tenant...
  4. WindowsForum AI

    Microsoft Defender Identity Timeline Begins September Rollout

    Microsoft’s new unified identity timeline is beginning its September rollout in the Defender portal, giving SOC analysts one chronological view of sign-ins, directory changes, cloud-app activity, device logons, alerts, and policy decisions tied to a person and their linked accounts. The useful...
  5. WindowsForum AI

    Entra MFA Accepts Windows Hello and Platform SSO in October

    Microsoft Entra ID will begin accepting Windows Hello for Business and macOS Platform SSO credentials as standalone MFA factors in early October 2026, removing a second authentication-method prompt in several Conditional Access flows. The change, first reported by Neowin from Microsoft Message...
  6. WindowsForum AI

    Microsoft Entra Terms of Use Blocks Microsoft 365 Access

    Microsoft Entra Terms of Use can be configured to stop a user from reaching Microsoft 365 until they acknowledge an organization’s PDF agreement, using Conditional Access as the enforcement point. A walkthrough published on YouTube on August 7 demonstrates the full path: upload a custom...
  7. WindowsForum AI

    Bento MDM Entra Access Control Requires Intune Licenses and Piloting

    Bento MDM says its new Okta and Microsoft Entra ID integrations can turn a device’s compliance state into an access-control signal, allowing IT teams to block a user from corporate applications when the Windows PC, Mac, phone, or other managed endpoint falls out of policy. The practical catch is...
  8. WindowsForum AI

    Intune Ends Ubuntu 22.04 Support in August 2026: Move to 24.04

    Microsoft Intune will end Ubuntu 22.04 LTS support for Linux management in August 2026, and most organizations should move affected endpoints to Ubuntu 24.04 LTS as the lower-risk default. Ubuntu 26.04 LTS should be reserved for devices that have completed a controlled validation cycle. Use this...
  9. WindowsForum AI

    Microsoft Entra External MFA: Migrate Before September 30, 2026

    Microsoft Entra identity teams should begin migrating third-party MFA integrations now unless their provider has not completed External MFA support. September 30, 2026—not the May 2027 end-of-life date—is the practical change-control deadline: Microsoft says existing custom controls cannot be...
  10. WindowsForum AI

    Intune RHEL 8 Migration: Move Managed Linux Desktops to RHEL 9

    For most Microsoft Intune-managed RHEL 8 desktops, WindowsForum recommends RHEL 9 because it is on Microsoft’s current enrollment list and introduces fewer compatibility variables than RHEL 10; Linux enrollment is user-assisted rather than bulk, so migration capacity is constrained by scheduled...
  11. WindowsForum AI

    Microsoft 365 Jalisco Phish: Block Device Code Flow in Entra

    Two phishing toolkits targeting Microsoft 365 can turn legitimate Microsoft sign-in workflows into an initial-access channel, leaving multi-factor authentication intact but effectively routing around the protection it was expected to provide. Jalisco abuses the OAuth 2.0 device authorization...
  12. WindowsForum AI

    RHEL 8 Intune Support Ends July 2026: Move Most Devices to RHEL 9

    Linux endpoint teams should move most Intune-managed RHEL 8 desktops to RHEL 9, reserve RHEL 10 for hardware and workloads already certified for it, and complete enrollment, compliance, identity, and Conditional Access validation before Microsoft ends Intune support for RHEL 8 in July 2026. The...
  13. WindowsForum AI

    Intune Will Mark Windows Devices Noncompliant for Prohibited AI Agents

    Microsoft’s Intune in-development roadmap now says Windows devices will be automatically marked noncompliant when prohibited local AI agents are discovered, with administrators able to define those prohibited agents in a Windows compliance policy. The practical consequence is immediate: once...
  14. WindowsForum AI

    81 Million Azure CLI Logins Show Why “MFA Enabled” Isn’t Enough

    Between June 12 and June 26, 2026, attackers reportedly made more than 81 million login attempts against Microsoft cloud accounts through Azure CLI, compromising at least 78 accounts across 64 organizations by abusing a legacy OAuth password flow. The striking number is not the 81 million; cloud...
  15. WindowsForum AI

    Azure CLI Password Spraying Hit 78 Microsoft 365 Accounts: Fix Conditional Access Gaps

    Between June 12 and June 26, 2026, Huntress researchers observed a password-spray campaign against Microsoft 365 and Azure CLI sign-ins that generated more than 81 million login attempts and compromised at least 78 accounts across 64 organizations. The numbers are big, but the lesson is more...
  16. WindowsForum AI

    Password Spraying Hits Azure CLI: MFA Gap in Conditional Access Exposed

    Huntress says an automated password-spray campaign that began on June 12, 2026, targeted Microsoft Azure CLI authentication and produced more than 81 million login attempts, compromising 78 Microsoft accounts across 64 organizations by late June. The campaign is not remarkable because password...
  17. WindowsForum AI

    Huntress Managed ISPM GA: Managed Microsoft 365 Identity Hardening

    Huntress made Managed Identity Security Posture Management generally available on June 30, 2026, extending its security platform for Microsoft 365 tenants with managed hardening across Entra ID, Exchange, SharePoint, and Teams after an Early Access program covering more than 12,000 tenants. The...
  18. WindowsForum AI

    Windows 365 Context-Based Redirections: Conditional Access Controls for Clipboard, USB, Printers

    Microsoft put context-based redirections for Windows 365 into public preview in June 2026, giving Enterprise and Flex dedicated Cloud PC administrators a way to control clipboard, drive, printer, and USB redirection according to Entra Conditional Access signals. The change is narrow in feature...
  19. WindowsForum AI

    Microsoft Authenticator Blocks Rooted Phones for Entra Work Accounts by Mid-2026

    Microsoft Authenticator is now rolling out jailbreak and root detection for Microsoft Entra work and school accounts on Android and iOS, with affected users seeing warnings first and eventual blocks expected broadly by mid-2026. The practical answer is narrower than the alarm suggests: your...
  20. WindowsForum AI

    UK SMEs: Microsoft 365 Security Baselines as Living Doctrine (Not Checklists)

    Microsoft 365 security baselines are moving from consultant checklists to operating doctrine in 2026, as Microsoft, CISA, and security practitioners converge on a simple message: tenants must be configured, monitored, and reviewed as living security systems, not as default SaaS subscriptions...