Topic Hub

Microsoft Entra ID

Published Microsoft Entra ID coverage currently on AdminSignal: Conditional Access baselines, emergency access accounts, and dynamic group troubleshooting. This hub does not yet include PIM or SSPR walkthroughs.

11 curated AdminSignal guides and signals on this topic

Start with Conditional Access and emergency access

The published Entra articles on this site are the Conditional Access policy map, emergency access account design, and dynamic group troubleshooting. Those three topics cause more tenant lockouts and assignment misses than most portal walkthroughs admit.

Dynamic groups are an assignment dependency, not a nice-to-have

Intune, Autopilot, and licence assignment all fail quietly when a dynamic rule does not match. Capture the rule, the user or device attribute, and the processing timestamp before rebuilding the group.

Break-glass is an operations control

Emergency accounts need cloud-only identities, phishing-resistant factors or offline custody, Conditional Access exclusions that are monitored, and a quarterly live test. An unused Global Administrator in a password manager is not a recovery plan.

What this hub will not claim

There are no published PIM, SSPR, or app-registration hardening tutorials here yet. Those topics stay off this page until a complete, sourced article exists.

Deep-Dive Tutorials

Entra ID Emergency Access Accounts: Break-Glass Design That Survives MFA Lockout

A practical operational guide to Microsoft Entra emergency access accounts: cloud-only design, Conditional Access exclusions, phishing-resistant factors, offline custody, monitoring, quarterly tests, and recovery when admins are locked out.

18 min read · Advanced

Exchange Online SMTP AUTH Basic Authentication 2026 Migration Planning

A practical operational guide for planning Exchange Online SMTP AUTH Basic Authentication and credential-based Exchange Online PowerShell automation migrations, covering inventory, EAC and Entra checks, mailbox and tenant settings, OAuth, High Volume Email, Azure Communication Services Email, relay caveats, app-only PowerShell, managed identity, rollback, and prevention controls.

32 min read · Advanced

Migrating AzureAD and MSOnline PowerShell Scripts to Microsoft Graph PowerShell SDK

A practical migration guide for replacing production AzureAD and MSOnline PowerShell scripts with Microsoft Graph PowerShell SDK, covering module strategy, delegated and app-only authentication, managed identity, permission discovery, cmdlet mapping, paging, OData filters, eventual consistency, throttling, beta endpoint risk, logging, rollback, and prevention checks.

34 min read · Advanced

Microsoft 365 Admin Centre Mandatory MFA Readiness for Admins

A practical operational guide for Microsoft 365 admin centre mandatory MFA readiness, covering affected admins, break-glass accounts, security defaults, Conditional Access, per-user MFA, phishing-resistant methods, Graph PowerShell audits, sign-in checks, service-style admin accounts, Phase 2 tooling impact, safe rollout, and recovery planning.

22 min read · Advanced

Troubleshooting Guides

Intune Company Portal Stuck or Enrollment Not Completing: Practical Diagnosis

A practical troubleshooting guide for Company Portal hangs and incomplete MDM enrollment on Windows, covering Entra join state, licensing, automatic enrollment, Conditional Access catch-22s, logs, safe retry, and prevention.

16 min read · Intermediate

Windows Autopilot Device Not Importing: Hardware Hash CSV, Duplicate Records, and Profile Assignment

A practical troubleshooting guide for Windows Autopilot import failures, covering hardware hash collection, CSV validation, duplicate records, tenant permissions, Intune Connector checks, deployment profile assignment, dynamic groups, Graph, safe retry, and recovery.

22 min read · Intermediate

Intune Device Not Syncing: Last Check-in Stale, Sync Button Not Helping, or Policies Not Arriving

A practical troubleshooting guide for Windows devices that stop syncing with Intune, covering portal checks, MDM enrolment state, Company Portal, scheduled tasks, event logs, registry evidence, IME health, network issues, Entra device objects, Graph checks, safe retry, and recovery.

21 min read · Intermediate

Microsoft Entra Dynamic Group Not Updating: Users, Devices, and Intune Assignments

A practical troubleshooting guide for Microsoft Entra dynamic groups that do not update, including rule syntax, user and device attributes, Graph checks, processing delays, Intune assignment impact, Autopilot targeting, stale device objects, and safe recovery.

20 min read · Intermediate

Intune Compliance Policy Not Evaluating: End-to-End Troubleshooting Checklist

When Intune reports a device as "Not evaluated" or stuck in a compliance state that does not reflect reality, the issue is usually one of four things — and this checklist covers all of them.

18 min read · Intermediate

BitLocker Recovery Key Not Backed Up to Entra ID: Why and How to Fix It

BitLocker keys failing to escrow to Entra ID is a silent failure — no error on the device, no alert in Intune. Here is how to detect it, force escrow, and prevent it from recurring.

15 min read · Intermediate