Credential Chaos to Control: How to Manage Entra ID Application Credentials Before Your Next Outage
July 24, 2026 •Alistair Pugin
Do you know exactly how many credentials are live in your Entra ID tenant right now? Not roughly. Not "IT's got a handle on it." Exactly. Give me the...
Read MoreLogic Apps are excellent for automation, but when they handle identity, the design must go beyond simply "it works." In this post, we'll show you how...
Read MoreHow to Offboard Service Principals and Vendor Applications in Microsoft Entra ID
June 25, 2026 •Sean Hurley
What Is Application Offboarding?
Offboarding is the deliberate, controlled retirement of an application identity,an app registration, an enterprise...
Read MoreTechnical Bulletin: Onboarding Service Principals and Vendor Applications
June 11, 2026 •Sean Hurley
The app onboarding process spectrum: simple or self-inflicted complexity
Onboarding an application, whether it's an internally registered service...
Read MoreApp Governance Accelerator 3.3 Detects Unused Microsoft Graph Permissions and Simplifies Governance Workflows
May 19, 2026 •ENow Software
Managing application governance in Microsoft Entra ID has become increasingly difficult for organizations operating large Microsoft 365 environments....
Read MoreThe report that is nearly right...
Read MoreIn a previous blog post, 'How to Restrict Microsoft Graph API Access to Mailboxes,' we explained why scoping your app registration permissions in...
Read MoreMicrosoft Entra ID Application Security Roadmap: How to Lock Down Modern Apps
March 12, 2026 •Alistair Pugin
Your Microsoft Entra ID application estate is already part of your attack surface – whether you’ve mapped it or not. In Microsoft 365 environments,...
Read MoreModern identity security is not about managing credentials; it is about designing trust boundaries between identity providers and relying parties....
Read MoreIdentity Security Predictions for 2026: What Threat Actors are Targeting Next
February 19, 2026 •Alistair Pugin
Identity security is going through a reckoning. Organizations spent the last decade hardening user logins with MFA, Conditional Access, and...
Read More