Build your own Tenant Portal (with AI, in an afternoon)

I spend a lot of time switching between the Entra admin center, the Azure portal and PowerShell - reading extension properties, filtering users by those properties, and checking user status and details. They are good tools, but they show everything, one blade or command at a time. And that is the problem. The questions I ask every day are not “show me this object”. They are: ...

October 6, 2026 · Mateusz Jendza

You ran Maester 200 times. Now what?

Maester is an amazing tool. Point it at an Entra ID tenant. A few minutes later you have one self-contained HTML report. It tells you which of about 280 security controls hold and which do not: CIS, CISA/SCuBA, EIDSCA, ORCA, plus any custom Pester test you write yourself. Run it once and it is excellent. Run it every night, across several tenants, and you learn something else. A report is not the same thing as a practice. After a few months you have a blob container with hundreds of files, three per run: ...

September 9, 2026 · Mateusz Jendza

Migrating from Azure AD B2C to Microsoft Entra External ID: Applications, Authentication Methods, Branding and Users (Part 1)

Why migrate? Azure AD B2C has served customer identity and access management (CIAM) needs well for years (XML Custom Policy Framework as powerful solution - but hard to learn and maintain), but Microsoft Entra External ID is its successor — bringing native Entra capabilities, modern built-in authentication patterns (passkeys, federation, native authentication SDKs), and direct integration with Entra governance and Conditional Access. If you run B2C today, migrating positions you for a stronger security posture, simpler access policies, and the latest authentication innovations. ...

June 23, 2026 · Mateusz Jendza

Announcement: Terraform Provider for Entra Verified ID

Announcing: Terraform Provider for Entra Verified ID Excited to share something I’ve been working on for the identity community 👉 GitHub Repository: https://github.com/mjendza/terraform-provider-verifiedid I’ve created a Terraform Provider for Microsoft Entra Verified ID, enabling you to manage decentralised identity components as code - finally bringing Verifiable Credentials into your IaC workflows. Why is it important? Identity is evolving beyond users and apps. With Entra Verified ID, we can model trust, credentials, and verification flows — but until now, automation has been limited. This provider helps you: ...

May 19, 2026 · Mateusz Jendza

Entra External ID Native Auth: Two Years Later & MFA via Conditional Access. Part 2

It has been nearly two years since my initial exploration of Entra External ID for Customers - Native Authentication back in June 2024. Since then, the authentication landscape has evolved, and Microsoft has continued to enhance the capabilities of Entra External ID. In this update: Native Authentication has been extended to support Multi-Factor Authentication (MFA). One-Time Passwords (OTP) via email and SMS have been enabled as additional authentication methods. I am still keeping my fingers crossed for magic link authentication and passkey support! ...

April 23, 2026 · Mateusz Jendza

Cross-Device Identity Verification via Entra Verified ID in a Multi-Agent System

TL;DR A multi-agent system (.NET 9 + Anthropic Claude) that embeds Entra Verified ID directly into the conversation. A QR code appears in chat, the user scans it with their wallet (Microsoft Authenticator), and the agent receives cryptographic proof of identity before it acts. Five layers of security enforcement — from probabilistic prompts to deterministic hooks — ensure identity verification cannot be skipped. The Problem: AI Agents Acting Without Proof AI agents are increasingly asked to perform sensitive operations — unlocking accounts, resetting credentials, approving transactions. But how does an agent know who it’s talking to? A username typed into chat is not identity. A “yes, that’s me” confirmation is not proof. ...

April 7, 2026 · Mateusz Jendza

Tailscale: A Developer's Secret Weapon

TL;DR Need to expose a local HTTPS endpoint to the internet or your private network? Tailscale does it in minutes. One command, no complex configuration, free for up to 3 users and 100 devices. It is a game-changer for my developer setup. tailscale serve --service=svc:my-service --https=443 http://localhost:3000 That’s it. Your local service is now accessible over HTTPS in your private Tailscale network with a valid certificate. The Problem As developers, we constantly hit the same wall: “I need to expose my local service”. Here are real scenarios I deal with regularly: ...

April 4, 2026 · Mateusz Jendza

Verified ID Integration for IoT

Securing Smart Access: Integrating Microsoft Entra Verified ID with Azure IoT Hub and Home Assistant Building a Zero-Trust Door Access System with Verifiable Credentials In this post, we’ll explore how to create a secure, decentralized access control system that combines Microsoft Entra Verified ID with Azure IoT Hub to unlock smart doors via Home Assistant. This solution demonstrates how verifiable credentials can bridge identity verification with physical access control in a zero-trust architecture. ...

January 20, 2026 · Mateusz Jendza

Entra ID Interactive Workshop Announcement

Introducing the Entra as Code Interactive Workshop Manual identity management works for small setups—but at scale, it’s hard to stay consistent, track changes, and ensure compliance. That’s where Infrastructure as Code shines. I’m excited to announce the Entra as Code Interactive Workshop; A hands-on experience to master Microsoft Entra ID with Terraform. Why Entra as Code? Apply proven IaC principles to identity management: Version control your configurations Review changes before deployment Replicate environments reliably Audit every modification Automate with CI/CD What Makes This Workshop Different? Interactive Progress Tracking: GitHub Actions creates issues for each stage with instructions and checklists. ...

January 8, 2026 · Mateusz Jendza

Entra ID Four Musketeers

Changelog 2025-11-17 initial version 2026-01-02 updated Zero Trust Assessment pipeline to publish only HTML files (all others are not needed to display the report) TL;DR Maester: Review your tenant configuration using Pester (PowerShell) tests written by the community or customised by you. EntraExporter: Export tenant state to JSON files. Review changes between exports and take action. ZeroTrustAssessment: Evaluates tenant posture against Zero Trust baseline. Provides the big picture and summary of findings. Together they enable repeatable change management, drift detection, and continuous improvement. Introduction Operating Entra ID at scale requires more than ad-hoc scripting. Configuration must be observable, assessable, repeatable, and improvable. Rather than building custom verification scripts, backup solutions, or assessment frameworks from scratch, leverage three proven tools from Microsoft and the community—collectively known as the Entra ID Three Musketeers: Maester, EntraExporter, and ZeroTrustAssessment. Each addresses a critical piece of the operational lifecycle—governance testing, configuration export, and security assessment—forming a complete loop for identity platform maturity. ...

November 17, 2025 · Mateusz Jendza
×