Nathan McNulty
banner
nathanmcnulty.com
Nathan McNulty
@nathanmcnulty.com
Loves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🐘infosec.exchange@nathanmcnulty
We can now change Source of Authority on Contacts as well 🔥

Looks like we can change contact SOA using the https​://graph​.microsoft​.com/v1.0/contacts API endpoint too :)
November 3, 2025 at 10:24 PM
A 138 character cmdlet in a production PowerShell module 🫠

November 2, 2025 at 9:06 PM
Everybody is always worried about emergency access, but what about emergency shutdown? 😏
October 30, 2025 at 8:55 PM
Just casually dropping nuanced licensing details on step 7 of a how to guide, as one does 🤷‍♂️
October 21, 2025 at 4:48 AM
I demand to speak to a manager! :P
October 19, 2025 at 2:46 AM
Ahh yes, Blizzard Antivirus, my favorite of all the Antivirus products 🤣
October 15, 2025 at 12:03 AM
Reposted by Nathan McNulty
Brilliant Conditional Access masterclass at #MMSMusicCity by @nathanmcnulty.com and @conditionalaccess.uk
Your policy is as strong as its poorest exclusion
#MMSMOA
October 14, 2025 at 7:51 PM
I can't stop laughing 😂
October 14, 2025 at 5:02 PM
Reposted by Nathan McNulty
👋 Check out this new Microsoft Entra blog post 👇

Your shortcut to Microsoft Entra deployment success

techcommunity.microsoft.com/t5/microsoft...
Your shortcut to Microsoft Entra deployment success
FastTrack has developed created 20+ short, scenario-based videos that guide you step-by-step through Microsoft Entra deployments.
techcommunity.microsoft.com
October 10, 2025 at 5:47 PM
Intune now has dedicated security recommendations docs just like Entra 🔥

The Entra security docs are extremely popular, and I love seeing other teams publishing this kind of guidance

Thanks to my collegaue (Josh Gatewood) for pointing this out!

learn.microsoft.com/en-us/intune...
October 10, 2025 at 4:49 AM
Did you know Entra ID Protection never automatically clears Medium or High risk?

We either need to use Risk Based Conditional Access policies to remediate or an admin needs to manually remediate

User risk = password reset
Sign-in risk = require MFA

learn.microsoft.com/...
October 7, 2025 at 10:45 PM
It's happening! Converting AD resources to Entra resources is here, and even more docs just arrived 🥳

Delivered with the User SoA docs is something even bigger - architectural guidance for shifting from AD to Entra using Source of Authority conversion🔥

learn.microsoft.com/...
October 7, 2025 at 5:30 AM
cyber awareness month is off to a great start...
October 3, 2025 at 2:12 AM
Hahaha, wow... 😮

If you leave App passwords enabled and enforce MFA through per-user MFA, the MFA enrollment wizard actually makes the user to create an app password 🤯
October 2, 2025 at 4:47 AM
If you've been evaluating the new(ish) Defender for Identity sensor (v3.0) that's in preview, there's a new config to support advanced identity detections :)

Just add the tag "Unified Sensor RPC Audit" to the DC's (docs recommend asset rule management)

learn.microsoft.com/...
October 1, 2025 at 10:09 PM
I just love how predictable cloud is - you can migrate or we'll migrate it for you, but either way, you're moving to the new service that will probably cost you more
October 1, 2025 at 4:52 AM
This was postponed, so there's still time... tomorrow is the last day before mandatory MFA for Azure CLI/PowerShell and anything else hitting Azure Resource Manager REST API
September 30, 2025 at 6:42 AM
Reposted by Nathan McNulty
That's a common and huge security risk that most admins do not know about. I wrote a blog post about it. www.cswrld.com/2024/11/how-...
How to disable Self-Service Password Reset for administrators
Self-service password reset can be a useful feature that allows users to access their account in case they forget their password. On the other hand, it is potentially risky, as...
www.cswrld.com
September 28, 2025 at 4:39 AM
In Entra ID, did you know sensitive cloud admins are enabled for Self-Service Password Reset by default, even if you never turn SSPR on?

It also doesn't follow auth method policies, so they can use email and SMS...

You really should disable it

learn.microsoft.com/...
September 28, 2025 at 2:03 AM
Please stop using Private browser sessions for cloud admin accounts

Look, we all know we shouldn't be using admin accounts while signed into our productivity account, but if you're gonna do it, at least use browser profiles so you can enforce compliance

learn.microsoft.com/...
September 27, 2025 at 9:33 PM
A 3 picture story of why you should default quarantine password protected files and enforce SmartScreen without allowing user bypass...
September 25, 2025 at 4:52 AM
This is, by far, my favorite Microsoft owned tenant 🤣
September 23, 2025 at 12:57 AM
😬
September 21, 2025 at 3:31 AM
When you first get a 3D printer, you suddenly find your first thought is "I could print that!"

It's not until after you print it you realize it was a terrible idea

Fortunately development time is cheap and easy to undo...
I seriously wonder why Microsoft thinks anyone wants these Copilot buttons everywhere in Windows www.theverge.com/news/782194/...
September 19, 2025 at 10:58 PM
I will become an AI believer the day it fixes the DCOM errors on a new Windows install
September 19, 2025 at 4:59 AM