<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>iphase.dk — Michael Mardahl, MVP</title><description>Personal tech blog by Michael Mardahl, Microsoft MVP — Security, Identity &amp; Access, Modern Work.</description><link>https://iphase.dk/</link><item><title>Taking Back Control: Windows LAPS and Local Admin Management via Intune</title><link>https://iphase.dk/posts/intune/windows-laps-local-admin-control/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/windows-laps-local-admin-control/</guid><description>A simple, opinionated guide to deploying Windows LAPS to cloud-native devices and reclaiming control of the local Administrators group using Intune.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>intune</category><category>intune</category><category>laps</category><category>security</category><category>entra</category><category>windows</category></item><item><title>The Outlook Issue That Wasn&apos;t Outlook: A NetScaler LAS Licensing War Story</title><link>https://iphase.dk/posts/misc/outlook-netscaler-las-license-drop/</link><guid isPermaLink="true">https://iphase.dk/posts/misc/outlook-netscaler-las-license-drop/</guid><description>How an Outlook connectivity incident that looked like Exchange or TLS trouble turned out to be a NetScaler license drop after Citrix LAS migration.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>misc</category><category>netscaler</category><category>citrix-adc</category><category>exchange</category><category>outlook</category><category>tls</category><category>las</category><category>troubleshooting</category></item><item><title>Multi Admin Approval in Intune: Because One Admin Shouldn&apos;t Rule Them All</title><link>https://iphase.dk/posts/intune/intune-multi-admin-approval-access-policies/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/intune-multi-admin-approval-access-policies/</guid><description>A practical guide to setting up Multi Admin Approval in Microsoft Intune — what it protects, how to configure it, how to harden it with Restricted Administrative Units, and why your future self will thank you for not letting a single compromised account nuke your tenant.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate><category>intune</category><category>intune</category><category>multi-admin-approval</category><category>security</category><category>zero-trust</category><category>access-policies</category><category>restricted-administrative-units</category><category>entra-id</category></item><item><title>Autopilot Hybrid Entra Join via Entra Kerberos (Preview): The Fix We&apos;ve Been Waiting For?</title><link>https://iphase.dk/posts/identity/autopilot-hybrid-entra-kerberos-preview/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/autopilot-hybrid-entra-kerberos-preview/</guid><description>A complete guide to the new Entra Kerberos based Hybrid Join. Is it enough to save Hybrid Autopilot, or should we all just go Cloud Native?</description><pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate><category>identity</category><category>entra-id</category><category>autopilot</category><category>hybrid-join</category><category>kerberos</category><category>windows-11</category><category>windows-hello</category></item><item><title>The IT Admin&apos;s Guide to Horses: What Equines Can Teach Us About Enterprise Architecture</title><link>https://iphase.dk/posts/misc/the-it-admins-guide-to-horses/</link><guid isPermaLink="true">https://iphase.dk/posts/misc/the-it-admins-guide-to-horses/</guid><description>A lighthearted exploration of what horses and horsemanship can teach IT professionals about building resilient, scalable, and well-managed enterprise environments.</description><pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate><category>misc</category><category>horses</category><category>enterprise-architecture</category><category>humor</category><category>analogies</category><category>it-admin-life</category></item><item><title>No VPN, No Internet: Building a Windows Firewall Kill Switch for FortiClient with Intune</title><link>https://iphase.dk/posts/intune/forticlient-vpn-kill-switch-windows-firewall-intune/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/forticlient-vpn-kill-switch-windows-firewall-intune/</guid><description>How to prevent Windows 11 devices from accessing the internet when not connected to corporate VPN using Windows Firewall and Intune — and all the things that go wrong along the way.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate><category>intune</category><category>intune</category><category>vpn</category><category>forticlient</category><category>windows-firewall</category><category>kill-switch</category></item><item><title>Passkeys and the Personal Phone Problem – An MFA Update for 2026</title><link>https://iphase.dk/posts/identity/passkeys-personal-phone-mfa-update/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/passkeys-personal-phone-mfa-update/</guid><description>An update on MFA in 2026: Microsoft&apos;s mandatory MFA enforcement, passkey types (synced vs device-bound), addressing personal phone resistance, and self-enrollment capabilities.</description><pubDate>Sat, 10 Jan 2026 00:00:00 GMT</pubDate><category>identity</category><category>entra-id</category><category>fido2</category><category>mfa</category><category>microsoft-authenticator</category><category>passkey</category><category>passwordless</category><category>zero-trust</category></item><item><title>ConsentFix - The Quickfix</title><link>https://iphase.dk/posts/identity/consentfix-quickfix/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/consentfix-quickfix/</guid><description>How to protect your tenant from the ConsentFix OAuth attack by pre-creating and locking down service principals for vulnerable Microsoft first-party apps using PowerShell.</description><pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate><category>identity</category><category>entra-id</category><category>oauth</category><category>security</category><category>powershell</category><category>service-principals</category><category>conditional-access</category></item><item><title>Unlocking Self-Service Account Recovery (SSAR) in Microsoft Entra</title><link>https://iphase.dk/posts/identity/self-service-account-recovery-ssar/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/self-service-account-recovery-ssar/</guid><description>A step-by-step guide to configuring Self-Service Account Recovery (SSAR) in Microsoft Entra ID, enabling users to regain access through government ID verification and biometric liveness checks.</description><pubDate>Tue, 30 Dec 2025 00:00:00 GMT</pubDate><category>identity</category><category>entra-id</category><category>passkey</category><category>passwordless</category><category>ssar</category><category>sspr</category><category>verified-id</category><category>face-check</category></item><item><title>Exporting Teams Chats: Why You Might Need It, and How I Built a Tool for It</title><link>https://iphase.dk/posts/misc/exporting-teams-chats-with-graph-api/</link><guid isPermaLink="true">https://iphase.dk/posts/misc/exporting-teams-chats-with-graph-api/</guid><description>A practical guide to exporting Microsoft Teams chat conversations using the Microsoft Graph API, including two authentication modes and real-world use cases.</description><pubDate>Mon, 01 Sep 2025 00:00:00 GMT</pubDate><category>misc</category><category>teams</category><category>microsoft-graph</category><category>powershell</category><category>export</category><category>automation</category><category>archiving</category></item><item><title>2 for 1 - Mail Enable Unlicensed Admin Accounts - 2024 Edition</title><link>https://iphase.dk/posts/identity/2-for-1-admin-mail-enable-unlicensed-admin-accounts/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/2-for-1-admin-mail-enable-unlicensed-admin-accounts/</guid><description>How to save on Exchange Online licensing for admin accounts by using plus addressing or distribution list redirection to receive admin mail without purchasing additional licenses.</description><pubDate>Fri, 02 Feb 2024 00:00:00 GMT</pubDate><category>identity</category><category>exchange-online</category><category>admin-accounts</category><category>licensing</category><category>powershell</category><category>plus-addressing</category></item><item><title>Simplify Windows Hello for Business SSO with Cloud Kerberos Trust - Part 1</title><link>https://iphase.dk/posts/identity/cloud-kerberos-trust-part-1/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/cloud-kerberos-trust-part-1/</guid><description>Part 1 of a trilogy exploring Cloud Kerberos Trust for Windows Hello for Business - covering concepts, trust model pain points, and why Cloud Kerberos Trust is the future of SSO to on-premises resources.</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>identity</category><category>cloud-kerberos-trust</category><category>sso</category><category>windows-hello-for-business</category><category>passwordless</category><category>kerberos</category></item><item><title>Simplify Windows Hello for Business SSO with Cloud Kerberos Trust - Part 2</title><link>https://iphase.dk/posts/identity/cloud-kerberos-trust-part-2/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/cloud-kerberos-trust-part-2/</guid><description>Part 2 of the Cloud Kerberos Trust trilogy - a step-by-step configuration walkthrough covering Entra Kerberos PowerShell setup, Intune Settings Catalog profile creation, and verification testing.</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>identity</category><category>cloud-kerberos-trust</category><category>sso</category><category>windows-hello-for-business</category><category>intune</category><category>powershell</category></item><item><title>Simplify Windows Hello for Business SSO with Cloud Kerberos Trust - Part 3</title><link>https://iphase.dk/posts/identity/cloud-kerberos-trust-part-3/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/cloud-kerberos-trust-part-3/</guid><description>Part 3 of the Cloud Kerberos Trust trilogy - deep diving into the mechanics, migration from other trust models, NGC credentials, Wireshark captures, Kerberos ticket flows, and troubleshooting with klist.</description><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><category>identity</category><category>cloud-kerberos-trust</category><category>sso</category><category>windows-hello-for-business</category><category>kerberos</category><category>active-directory</category></item><item><title>2FA/MFA - Why Multi-Factor Authentication is Important</title><link>https://iphase.dk/posts/identity/why-multi-factor-authentication-is-important/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/why-multi-factor-authentication-is-important/</guid><description>A high-level overview of multi-factor authentication concepts, types (SMS, app-based, hardware), and why MFA is critical in today&apos;s corporate IT landscape.</description><pubDate>Tue, 17 Jan 2023 00:00:00 GMT</pubDate><category>identity</category><category>mfa</category><category>multi-factor-authentication</category><category>phishing</category><category>security</category><category>passwordless</category></item><item><title>Fix onmicrosoft.com Missing Default Domain</title><link>https://iphase.dk/posts/identity/onmicrosoft-com-missing-default-domain/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/onmicrosoft-com-missing-default-domain/</guid><description>A quick workaround to fix the missing onmicrosoft.com default domain alias on synced identities in hybrid Exchange environments by temporarily changing the user&apos;s UPN.</description><pubDate>Mon, 07 Mar 2022 00:00:00 GMT</pubDate><category>identity</category><category>exchange-online</category><category>hybrid-identity</category><category>onmicrosoft-com</category><category>upn</category><category>entra-connect</category><category>troubleshooting</category></item><item><title>How to remove credentials from a FIDO2 key like a boss</title><link>https://iphase.dk/posts/identity/how-to-remove-credentials-from-a-fido2-key/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/how-to-remove-credentials-from-a-fido2-key/</guid><description>Learn how to remove credentials from a FIDO2 key (Feitian keys specifically) and why housekeeping on your FIDO2 devices matters.</description><pubDate>Tue, 25 Jan 2022 00:00:00 GMT</pubDate><category>identity</category><category>fido2</category><category>security-keys</category><category>passwordless</category><category>feitian</category></item><item><title>FSLogix slow sign-in (fix) redux - Black Screen bug</title><link>https://iphase.dk/posts/modernwork/fslogix-slow-sign-in-fix-redux/</link><guid isPermaLink="true">https://iphase.dk/posts/modernwork/fslogix-slow-sign-in-fix-redux/</guid><description>FSLogix slow sign-in caused by the App Readiness service can be fixed by resetting the bloated StateRepository database.</description><pubDate>Mon, 30 Aug 2021 00:00:00 GMT</pubDate><category>modernwork</category><category>fslogix</category><category>app-readiness</category><category>black-screen</category><category>slow-login</category><category>remote-desktop</category></item><item><title>Managed Identities in Azure Automation (PowerShell)</title><link>https://iphase.dk/posts/azure/managed-identities-in-azure-automation-powershell/</link><guid isPermaLink="true">https://iphase.dk/posts/azure/managed-identities-in-azure-automation-powershell/</guid><description>How to use Managed Identities in Azure Automation to securely access resources without credentials, including Microsoft Graph API access.</description><pubDate>Fri, 02 Jul 2021 00:00:00 GMT</pubDate><category>azure</category><category>azure-automation</category><category>managed-identity</category><category>powershell</category><category>microsoft-graph</category><category>security</category></item><item><title>FSLogix slow sign-in (fix)</title><link>https://iphase.dk/posts/modernwork/fslogix-slow-sign-in-fix/</link><guid isPermaLink="true">https://iphase.dk/posts/modernwork/fslogix-slow-sign-in-fix/</guid><description>How to fix FSLogix slow sign-in caused by a bloated notifications registry key on Windows Server Remote Desktop Session Hosts.</description><pubDate>Thu, 17 Jun 2021 00:00:00 GMT</pubDate><category>modernwork</category><category>fslogix</category><category>vdi</category><category>remote-desktop</category><category>slow-login</category><category>registry</category></item><item><title>Securing SCEP/NDES for Intune with gMSA</title><link>https://iphase.dk/posts/intune/securing-scep-ndes-for-intune-with-gmsa/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/securing-scep-ndes-for-intune-with-gmsa/</guid><description>How to replace the NDES service account with a group managed service account (gMSA) to enhance security of your SCEP/NDES infrastructure for Intune.</description><pubDate>Wed, 12 May 2021 00:00:00 GMT</pubDate><category>intune</category><category>scep</category><category>ndes</category><category>gmsa</category><category>certificates</category><category>intune</category><category>security</category></item><item><title>Migrate BitLocker to Microsoft Entra ID</title><link>https://iphase.dk/posts/intune/migrate-bitlocker-to-azure-ad/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/migrate-bitlocker-to-azure-ad/</guid><description>How to migrate existing BitLocker recovery keys to Microsoft Entra ID using an Intune PowerShell script, without re-encrypting drives.</description><pubDate>Tue, 12 Jan 2021 00:00:00 GMT</pubDate><category>intune</category><category>bitlocker</category><category>azure-ad</category><category>mbam</category><category>escrow</category><category>powershell</category><category>migration</category></item><item><title>The Windows Hello Zone! - Part 2</title><link>https://iphase.dk/posts/identity/the-windows-hello-zone-part-2/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/the-windows-hello-zone-part-2/</guid><description>Part 2 of the Windows Hello Zone series - why PINs are more secure than passwords and real-world scenarios where Windows Hello for Business prevents credential theft.</description><pubDate>Wed, 16 Dec 2020 00:00:00 GMT</pubDate><category>identity</category><category>windows-hello-for-business</category><category>passwordless</category><category>pin-login</category><category>endpoint-security</category><category>zero-trust</category></item><item><title>The Windows Hello Zone! - Part 1</title><link>https://iphase.dk/posts/identity/the-windows-hello-zone-part-1/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/the-windows-hello-zone-part-1/</guid><description>Part 1 of the Windows Hello Zone series - real-world scenarios showing why biometric authentication with Windows Hello for Business is essential for enterprise security.</description><pubDate>Wed, 18 Nov 2020 00:00:00 GMT</pubDate><category>identity</category><category>windows-hello-for-business</category><category>biometric-login</category><category>passwordless</category><category>hybrid-key-trust</category><category>endpoint-security</category></item><item><title>Enable Microsoft Enterprise SSO plug-in for Apple Devices through Intune</title><link>https://iphase.dk/posts/identity/enable-microsoft-enterprise-sso-plug-in-for-apple-devices-through-intune/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/enable-microsoft-enterprise-sso-plug-in-for-apple-devices-through-intune/</guid><description>How to enable the Microsoft Enterprise SSO plug-in for Apple iOS and macOS devices through Microsoft Intune.</description><pubDate>Wed, 14 Oct 2020 00:00:00 GMT</pubDate><category>identity</category><category>authenticator</category><category>sso</category><category>intune</category><category>apple</category><category>ios</category><category>macos</category></item><item><title>Keeping Always On VPN - always on?</title><link>https://iphase.dk/posts/intune/keeping-always-on-vpn-always-on/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/keeping-always-on-vpn-always-on/</guid><description>Why Microsoft Always On VPN stops auto-connecting and how to fix it with Intune, including the AutoTriggerDisabledProfileList registry fix.</description><pubDate>Wed, 29 Apr 2020 00:00:00 GMT</pubDate><category>intune</category><category>always-on-vpn</category><category>connectivity</category><category>vpn</category><category>intune</category></item><item><title>Managing Microsoft Teams Firewall requirements with Intune</title><link>https://iphase.dk/posts/intune/managing-microsoft-teams-firewall-requirements-with-intune/</link><guid isPermaLink="true">https://iphase.dk/posts/intune/managing-microsoft-teams-firewall-requirements-with-intune/</guid><description>Deploy Windows Firewall rules for Microsoft Teams via Intune PowerShell scripts to silence the annoying Windows Security Alert for screen sharing.</description><pubDate>Sun, 29 Mar 2020 00:00:00 GMT</pubDate><category>intune</category><category>intune</category><category>teams</category><category>powershell</category><category>firewall</category></item><item><title>Passwordless journey with FIDO2 - Part 3 - Engine troubles</title><link>https://iphase.dk/posts/identity/passwordless-journey-with-fido2-part-3-engine-troubles/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/passwordless-journey-with-fido2-part-3-engine-troubles/</guid><description>Part 3 of the FIDO2 passwordless journey covering unsupported key whitelisting, AAGUID discovery, and reviews of Ensurity ThinC-AUTH, KEY-ID, and OnlyKey security keys.</description><pubDate>Fri, 07 Feb 2020 00:00:00 GMT</pubDate><category>identity</category><category>fido2</category><category>passwordless</category><category>mfa</category><category>security-keys</category><category>azure-ad</category></item><item><title>Conditional Access and the woes of being an external user</title><link>https://iphase.dk/posts/identity/conditional-access-and-the-woes-of-being-an-external-user/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/conditional-access-and-the-woes-of-being-an-external-user/</guid><description>Challenges of Conditional Access and MFA as an external/guest user in Entra ID tenants, and practical solutions including FIDO2 keys.</description><pubDate>Sun, 19 Jan 2020 00:00:00 GMT</pubDate><category>identity</category><category>conditional-access</category><category>identity-and-access</category><category>microsoft-authenticator</category><category>consultants</category><category>mfa</category></item><item><title>Passwordless journey with FIDO2 - Part 2 - Usage experiences</title><link>https://iphase.dk/posts/identity/passwordless-journey-with-fido2-part-2-usage-experiences/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/passwordless-journey-with-fido2-part-2-usage-experiences/</guid><description>Part 2 of the FIDO2 passwordless journey covering hands-on usage experiences with Solokeys, Yubico, and eWBM biometric security keys for Azure AD.</description><pubDate>Mon, 18 Nov 2019 00:00:00 GMT</pubDate><category>identity</category><category>fido2</category><category>passwordless</category><category>sso</category><category>yubico</category><category>yubikey</category><category>ewbm</category><category>solokeys</category></item><item><title>Passwordless journey with FIDO2 - Part 1 - Getting started with Security keys</title><link>https://iphase.dk/posts/identity/passwordless-journey-with-fido2-part-1-getting-started-with-security-keys/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/passwordless-journey-with-fido2-part-1-getting-started-with-security-keys/</guid><description>Part 1 of the FIDO2 passwordless journey covering requirements, setup hurdles, and an overview of security key vendors for Azure AD enterprise use.</description><pubDate>Mon, 28 Oct 2019 00:00:00 GMT</pubDate><category>identity</category><category>fido2</category><category>passwordless</category><category>security-key</category><category>yubico</category><category>ewbm</category><category>solokeys</category><category>azure-ad</category></item><item><title>2 Cool new password policy features in Microsoft Entra Connect Sync</title><link>https://iphase.dk/posts/identity/2-cool-new-password-policy-features-in-azure-ad-connect/</link><guid isPermaLink="true">https://iphase.dk/posts/identity/2-cool-new-password-policy-features-in-azure-ad-connect/</guid><description>Two new Microsoft Entra Connect Sync preview features: force password reset at logon and enforce cloud password policy for synced users.</description><pubDate>Mon, 07 Oct 2019 00:00:00 GMT</pubDate><category>identity</category><category>azure-ad-connect</category><category>password-policy</category><category>user-accounts</category><category>entra-id</category></item><item><title>The Trouble with PEAP and Credential Guard</title><link>https://iphase.dk/posts/misc/the-trouble-with-peap-and-credential-guard/</link><guid isPermaLink="true">https://iphase.dk/posts/misc/the-trouble-with-peap-and-credential-guard/</guid><description>Why Windows 10 Credential Guard breaks PEAP (EAP-MSCHAPv2) authentication with Cisco ISE and RADIUS servers, and what to do about it.</description><pubDate>Sat, 14 Jul 2018 00:00:00 GMT</pubDate><category>misc</category><category>credential-guard</category><category>windows-10</category><category>security</category><category>peap</category><category>cisco-ise</category><category>certificates</category></item><item><title>Getting Off to a Good Start with Microsoft 365 Groups</title><link>https://iphase.dk/posts/modernwork/getting-off-to-a-good-start-with-microsoft-365-groups/</link><guid isPermaLink="true">https://iphase.dk/posts/modernwork/getting-off-to-a-good-start-with-microsoft-365-groups/</guid><description>Essential tips and best practices for organizations looking to adopt Microsoft 365 Groups including naming policies, email domains, access control and Teams integration.</description><pubDate>Sat, 23 Dec 2017 00:00:00 GMT</pubDate><category>modernwork</category><category>office-365</category><category>microsoft-365-groups</category><category>microsoft-teams</category><category>collaboration</category></item></channel></rss>