Joรซl Prins's Avatar

Joรซl Prins

@intothecloud.eu

๐Ÿ‘ถ๐Ÿผ Father at first โœ๏ธ Believer โšฝ๏ธ Liverpool FC ๐Ÿ”ด ๐Ÿง‘โ€๐Ÿ’ปIntune | Entra ID | Defender | Microsoft 365 ๐Ÿ”—intothecloud.eu | Modern Endpoint Management

560
Followers
295
Following
39
Posts
09.11.2024
Joined
Posts Following

Latest posts by Joรซl Prins @intothecloud.eu

Preview
Youโ€™re not managing PIM if you canโ€™t see PIM for Groups Are "Unmanaged Groups" bypassing your Entra ID PIM policies? Discover the security gap in PIM for Groups and how to detect it with the new PIM Manager.

I wrote a detailed deep-dive about the architecture, the hybrid delta/full sync approach, and the logic gaps I found.

It's an absolute information bomb on the architecture and logic.

Read the full blog here: intothecloud.eu/p/pi...

#EntraID #PIM #MicrosoftGraph #CloudSecurity

27.01.2026 10:21 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

What's in this update:
โœ… Full PIM for Groups support (Owner vs Member policies)
โœ… Security Gap Detection
โœ… Smart Sync (Delta Queries)
โœ… Multi-workload Architecture

Repo is now PUBLIC ๐Ÿ’ป

Huge thanks to everyone who provided feedback! ๐Ÿ™Œ

27.01.2026 10:21 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Under the hood: Delta Queries โšก

I didn't know Graph Delta Queries existed until I started this. I was fetching everything on every refresh. Thousands of calls.

Now? 500+ calls dropped to ~10.

Itโ€™s a massive win performing huge optimizations.

27.01.2026 10:21 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

The "Unmanaged Groups" Blind Spot ๐Ÿšฉ

While digging, I found a refined security gap. Groups can have isRoleAssignable: true, but no PIM policy attached.

They bypass PIM entirely. No activation limits. No MFA. Only permanent privileged access.

PIM Manager now identifies these automatically.

27.01.2026 10:21 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

PIM Manager just shipped a major update. ๐Ÿš€

I planned to build the Configure wizard next. But I realized PIM for Groups behaves fundamentally differently than roles.

If I ignored that, Iโ€™d be building a tool that only works for half the product.

Here is what changed ๐Ÿ‘‡

27.01.2026 10:21 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Stop struggling, start managing: building PIM Manager Microsoft does not offer a single-pane-of-glass dashboard or reporting function for Entra ID role management. Getting answers should not require a dayโ€™s worth of work. This is the gap that PIM Manager fills.

One dashboard & report where Entra roles, assignments, and configuration come togetherโ€”built for audits and day-to-day control.

Nuance: actively evolving, with data accuracy as the absolute baseline.

๐Ÿ“ƒ intothecloud.eu/p/pi...
โš™๏ธ pimmanager.com

#Entra #PIM #RBAC

17.12.2025 12:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Stop struggling, start managing; PIMManager is here.

PIM in Entra shouldnโ€™t mean clickops, scripts, and audit spreadsheets.
Yet thatโ€™s how most RBAC and PIM audits still work today.
Manual, fragmented, and error-prone.
Thatโ€™s why I started building PIMManager.

๐Ÿงต
#Entra #PIM #RBAC #Security

17.12.2025 12:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Practice what you preach. Use what you advise, be consistent, make actions visible. When words and deeds align, trust grows and ownership follows.

Full post on LinkedIn.

#Leadership #Ownership #TeamCulture

09.12.2025 09:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Soft skills give knowledge its value.
Works when in doubt.

Full post on LinkedIn.

#Leadership #TeamCulture

02.12.2025 09:00 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Trust โ†’ Empowers.
Give context, let them think & do, and keep accountability.
Better choices, more energy, real ownership.

Full post on LinkedIn.

#Leadership #PeopleDevelopment

25.11.2025 09:00 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Ask juniors what their idea was - on wins and misses.
Surface assumptions, learn out loud, tighten the frame when needed.

Full post on LinkedIn.

#Leadership

18.11.2025 09:00 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Donโ€™t overload juniors, teach them to manage their own work.
Check my LinkedIn for the full post.

#Leadership

11.11.2025 09:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Let juniors make mistakes. Trust + safety โ†’ growth: small blast radius, two-person check, step by step.

Check my LinkedIn for the full post.

04.11.2025 09:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Join the Microsoft EMS Community Discord Server! This server is all about getting closer to the Microsoft Enterprise Mobility + Security community! | 2552 members

๐‚๐ฅ๐จ๐ฎ๐๐‡๐จ๐ฎ๐ซ: where the Microsoft EMS community slows down to learn fast.

Every 1st Wed @ 8 PM (AMS).
Short news, key topics & an open round-tableโ€”stories, lessons, failures, next steps.

โžก๏ธ discord.gg/VBqRHKqNat
๐Ÿ“… Next Wed 20:00 (AMS)

#MicrosoftEMS #Security

30.10.2025 09:00 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

10 years in IT taught me as much about people as tech. A leader who listens and acts builds stronger teams.
The series starts Tuesday.

Check my LinkedIn for the full post.

28.10.2025 09:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Couldnโ€™t agree more with Erica; security isnโ€™t a destination, itโ€™s a practice.

Follow @merill.net for these top-tier videos.
Follow @ericazelic.bsky.social insight that actually makes you better.

#ZeroTrust #InfoSec #CareerJourney

27.10.2025 16:06 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

A bit late to the party, but this oneโ€™s worth sharing it!
๐ŸŽง How a Pharmacist Became a Pro Hacker.

entra.news/p/how-a-pharmaโ€ฆ

Whether youโ€™re starting out or 20 years in, this episode hits home.
Curiosity. Re-skilling. Building trust in security, one career turn at a time.

27.10.2025 16:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
What's new in Microsoft Intune - Microsoft Intune Find out what's new in Microsoft Intune.


learn.microsoft.com/...
2/2

23.10.2025 08:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

โ€œFunctionality may varyโ€ - Microsoftโ€™s quiet way of saying โ€œuse at your own risk.โ€

๐ŸชŸ Windows 10 stays allowed in Intune after Oct 14 2025 - but not ๐˜จ๐˜ถ๐˜ข๐˜ณ๐˜ข๐˜ฏ๐˜ต๐˜ฆ๐˜ฆ๐˜ฅ.
Devices still enroll, yet policy behavior may drift.

๐Ÿ’ก Grace time, not a steady state.
#Intune #Windows10 #ZeroTrust
1/2

23.10.2025 08:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

(2/2)
In my latest blog, I explain why SFI is a real game changer for building security as a mindset, not just a policy.
intothecloud.eu/p/se...
#MicrosoftSFI #Security #Cloud #SecureFuture

08.07.2025 08:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

๐Ÿง  Security as Mindset ๐Ÿง 
Zero Trust is evolving, and todayโ€™s digital boundaries are more dynamic than ever.
Thatโ€™s why Microsoftโ€™s Secure Future Initiative deserves your attention.
(1/2)๐Ÿ“–โฌ‡๏ธ

08.07.2025 08:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

๐Ÿ” Managing local admin rights doesn't have to be fragmented.

Bringing together Microsoft Entra, Intune, Autopilot, and Windows LAPS to create a unified approach for managing local admin rights.

๐Ÿ“˜ Discover the comprehensive solution: intothecloud.eu/p/lo...

29.04.2025 11:00 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Windows at Microsoft Technical Takeoff 2025 - Windows IT Pro Blog Quickly find technical deep dives and demos to add to your calendar. Get the guidance and skills you need to deploy, manage, and support the latest features!

Check out Windows at Microsoft Technical Takeoff 2025, coming up March 3-6. Please share and spread the word.

aka.ms/WindowsAtTec...

#Windows #ITpros #TechTakeoff #Microsoft #MSIntune #Windows365 #Copilot

13.02.2025 22:47 ๐Ÿ‘ 10 ๐Ÿ” 8 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Post image

Isn't that nice! Fetching application assignments for more than 700 apps within just a few seconds. New update on the roll for #IntuneAssistant.. Coming soon! @msintune.bsky.social @intunesuppteam.bsky.social #mvpBuzz

14.02.2025 14:28 ๐Ÿ‘ 11 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - SecNinjaltd/Microsoft-Defender-for-O365 Contribute to SecNinjaltd/Microsoft-Defender-for-O365 development by creating an account on GitHub.

Iโ€™ve created a bunch of Defender for O365 drawings which you can download from my new GitHub site.

The idea was to help anyone new to the product how policies work and hopefully make them a little easier to navigate.

github.com/SecNinjaltd/...

10.01.2025 16:55 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

A new dedicated resource application to enable Active Directory to Microsoft Entra ID sync using Microsoft Entra Connect Sync or Cloud Sync is coming ๐Ÿ˜ฑ

In the announcement the mentioned reason is "upcoming security hardening"...

6bf85cfa-ac8a-4be5-b5de-425a0d0dc016

#EntraID

06.01.2025 18:29 ๐Ÿ‘ 40 ๐Ÿ” 13 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0
Post image

โ„๏ธI created this tool some time ago to make it easier to manage the startmenu and taskbar of #Windows11 by using #msintune

Check it out and let me know if you have ideas of improvements.

www.rockenroll.tech/2022/01/10/w...

#mvpbuzz

28.12.2024 08:45 ๐Ÿ‘ 27 ๐Ÿ” 4 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Let's secure the cloud PC! Intro With the announcement that we are able to connect via the Windows App to our Windows 365 Cloud PC's from the major platforms (Windows, iOS/iPadOS, MacOS, and Android), it's time to give our users access in a controlled and secure manner! In this blog, I will try to

โ— New Blog Post! โ—

I've just published my first blog on securing access to the Windows 365 Cloud PC. ๐Ÿ–ฅ๏ธ๐Ÿ”’ Discover a solution to secure your digital workspace while allowing access from BYOD devices!

๐Ÿ‘‰ www.intothecloud.eu/...


#Windows365 #CyberSecurity #Microsoft

24.12.2024 09:01 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Folks we are super excited to announce the launch of Maester v1!

To celebrate ๐ŸŽ‰ ๐Ÿพ we are joining the EMS community Discord for an AMA.

discord.com/channels...

Read more at maester.dev/blog/mae...

12.12.2024 12:03 ๐Ÿ‘ 85 ๐Ÿ” 22 ๐Ÿ’ฌ 4 ๐Ÿ“Œ 1

๐ŸšจJoin us in tomorrows Spotlight session!

11.12.2024 19:26 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0