Youโre not managing PIM if you canโt see PIM for Groups
Are "Unmanaged Groups" bypassing your Entra ID PIM policies? Discover the security gap in PIM for Groups and how to detect it with the new PIM Manager.
I wrote a detailed deep-dive about the architecture, the hybrid delta/full sync approach, and the logic gaps I found.
It's an absolute information bomb on the architecture and logic.
Read the full blog here: intothecloud.eu/p/pi...
#EntraID #PIM #MicrosoftGraph #CloudSecurity
27.01.2026 10:21
๐ 0
๐ 0
๐ฌ 0
๐ 0
What's in this update:
โ
Full PIM for Groups support (Owner vs Member policies)
โ
Security Gap Detection
โ
Smart Sync (Delta Queries)
โ
Multi-workload Architecture
Repo is now PUBLIC ๐ป
Huge thanks to everyone who provided feedback! ๐
27.01.2026 10:21
๐ 0
๐ 0
๐ฌ 1
๐ 0
Under the hood: Delta Queries โก
I didn't know Graph Delta Queries existed until I started this. I was fetching everything on every refresh. Thousands of calls.
Now? 500+ calls dropped to ~10.
Itโs a massive win performing huge optimizations.
27.01.2026 10:21
๐ 0
๐ 0
๐ฌ 1
๐ 0
The "Unmanaged Groups" Blind Spot ๐ฉ
While digging, I found a refined security gap. Groups can have isRoleAssignable: true, but no PIM policy attached.
They bypass PIM entirely. No activation limits. No MFA. Only permanent privileged access.
PIM Manager now identifies these automatically.
27.01.2026 10:21
๐ 0
๐ 0
๐ฌ 1
๐ 0
PIM Manager just shipped a major update. ๐
I planned to build the Configure wizard next. But I realized PIM for Groups behaves fundamentally differently than roles.
If I ignored that, Iโd be building a tool that only works for half the product.
Here is what changed ๐
27.01.2026 10:21
๐ 1
๐ 0
๐ฌ 1
๐ 0
Stop struggling, start managing: building PIM Manager
Microsoft does not offer a single-pane-of-glass dashboard or reporting function for Entra ID role management. Getting answers should not require a dayโs worth of work. This is the gap that PIM Manager fills.
One dashboard & report where Entra roles, assignments, and configuration come togetherโbuilt for audits and day-to-day control.
Nuance: actively evolving, with data accuracy as the absolute baseline.
๐ intothecloud.eu/p/pi...
โ๏ธ pimmanager.com
#Entra #PIM #RBAC
17.12.2025 12:00
๐ 0
๐ 0
๐ฌ 0
๐ 0
Stop struggling, start managing; PIMManager is here.
PIM in Entra shouldnโt mean clickops, scripts, and audit spreadsheets.
Yet thatโs how most RBAC and PIM audits still work today.
Manual, fragmented, and error-prone.
Thatโs why I started building PIMManager.
๐งต
#Entra #PIM #RBAC #Security
17.12.2025 12:00
๐ 0
๐ 0
๐ฌ 1
๐ 0
Practice what you preach. Use what you advise, be consistent, make actions visible. When words and deeds align, trust grows and ownership follows.
Full post on LinkedIn.
#Leadership #Ownership #TeamCulture
09.12.2025 09:00
๐ 1
๐ 0
๐ฌ 0
๐ 0
Soft skills give knowledge its value.
Works when in doubt.
Full post on LinkedIn.
#Leadership #TeamCulture
02.12.2025 09:00
๐ 2
๐ 0
๐ฌ 0
๐ 0
Trust โ Empowers.
Give context, let them think & do, and keep accountability.
Better choices, more energy, real ownership.
Full post on LinkedIn.
#Leadership #PeopleDevelopment
25.11.2025 09:00
๐ 2
๐ 0
๐ฌ 0
๐ 0
Ask juniors what their idea was - on wins and misses.
Surface assumptions, learn out loud, tighten the frame when needed.
Full post on LinkedIn.
#Leadership
18.11.2025 09:00
๐ 2
๐ 0
๐ฌ 0
๐ 0
Donโt overload juniors, teach them to manage their own work.
Check my LinkedIn for the full post.
#Leadership
11.11.2025 09:00
๐ 1
๐ 0
๐ฌ 0
๐ 0
Let juniors make mistakes. Trust + safety โ growth: small blast radius, two-person check, step by step.
Check my LinkedIn for the full post.
04.11.2025 09:00
๐ 0
๐ 0
๐ฌ 0
๐ 0
Join the Microsoft EMS Community Discord Server!
This server is all about getting closer to the Microsoft Enterprise Mobility + Security community! | 2552 members
๐๐ฅ๐จ๐ฎ๐๐๐จ๐ฎ๐ซ: where the Microsoft EMS community slows down to learn fast.
Every 1st Wed @ 8 PM (AMS).
Short news, key topics & an open round-tableโstories, lessons, failures, next steps.
โก๏ธ discord.gg/VBqRHKqNat
๐
Next Wed 20:00 (AMS)
#MicrosoftEMS #Security
30.10.2025 09:00
๐ 1
๐ 0
๐ฌ 0
๐ 0
10 years in IT taught me as much about people as tech. A leader who listens and acts builds stronger teams.
The series starts Tuesday.
Check my LinkedIn for the full post.
28.10.2025 09:00
๐ 0
๐ 0
๐ฌ 0
๐ 0
Couldnโt agree more with Erica; security isnโt a destination, itโs a practice.
Follow @merill.net for these top-tier videos.
Follow @ericazelic.bsky.social insight that actually makes you better.
#ZeroTrust #InfoSec #CareerJourney
27.10.2025 16:06
๐ 1
๐ 0
๐ฌ 0
๐ 0
A bit late to the party, but this oneโs worth sharing it!
๐ง How a Pharmacist Became a Pro Hacker.
entra.news/p/how-a-pharmaโฆ
Whether youโre starting out or 20 years in, this episode hits home.
Curiosity. Re-skilling. Building trust in security, one career turn at a time.
27.10.2025 16:04
๐ 0
๐ 0
๐ฌ 1
๐ 0
โFunctionality may varyโ - Microsoftโs quiet way of saying โuse at your own risk.โ
๐ช Windows 10 stays allowed in Intune after Oct 14 2025 - but not ๐จ๐ถ๐ข๐ณ๐ข๐ฏ๐ต๐ฆ๐ฆ๐ฅ.
Devices still enroll, yet policy behavior may drift.
๐ก Grace time, not a steady state.
#Intune #Windows10 #ZeroTrust
1/2
23.10.2025 08:00
๐ 0
๐ 0
๐ฌ 1
๐ 0
(2/2)
In my latest blog, I explain why SFI is a real game changer for building security as a mindset, not just a policy.
intothecloud.eu/p/se...
#MicrosoftSFI #Security #Cloud #SecureFuture
08.07.2025 08:00
๐ 0
๐ 0
๐ฌ 0
๐ 0
๐ง Security as Mindset ๐ง
Zero Trust is evolving, and todayโs digital boundaries are more dynamic than ever.
Thatโs why Microsoftโs Secure Future Initiative deserves your attention.
(1/2)๐โฌ๏ธ
08.07.2025 08:00
๐ 0
๐ 0
๐ฌ 1
๐ 0
๐ Managing local admin rights doesn't have to be fragmented.
Bringing together Microsoft Entra, Intune, Autopilot, and Windows LAPS to create a unified approach for managing local admin rights.
๐ Discover the comprehensive solution: intothecloud.eu/p/lo...
29.04.2025 11:00
๐ 0
๐ 0
๐ฌ 0
๐ 0
Isn't that nice! Fetching application assignments for more than 700 apps within just a few seconds. New update on the roll for #IntuneAssistant.. Coming soon! @msintune.bsky.social @intunesuppteam.bsky.social #mvpBuzz
14.02.2025 14:28
๐ 11
๐ 3
๐ฌ 0
๐ 0
GitHub - SecNinjaltd/Microsoft-Defender-for-O365
Contribute to SecNinjaltd/Microsoft-Defender-for-O365 development by creating an account on GitHub.
Iโve created a bunch of Defender for O365 drawings which you can download from my new GitHub site.
The idea was to help anyone new to the product how policies work and hopefully make them a little easier to navigate.
github.com/SecNinjaltd/...
10.01.2025 16:55
๐ 2
๐ 1
๐ฌ 0
๐ 0
A new dedicated resource application to enable Active Directory to Microsoft Entra ID sync using Microsoft Entra Connect Sync or Cloud Sync is coming ๐ฑ
In the announcement the mentioned reason is "upcoming security hardening"...
6bf85cfa-ac8a-4be5-b5de-425a0d0dc016
#EntraID
06.01.2025 18:29
๐ 40
๐ 13
๐ฌ 3
๐ 0
โ๏ธI created this tool some time ago to make it easier to manage the startmenu and taskbar of #Windows11 by using #msintune
Check it out and let me know if you have ideas of improvements.
www.rockenroll.tech/2022/01/10/w...
#mvpbuzz
28.12.2024 08:45
๐ 27
๐ 4
๐ฌ 0
๐ 1
Folks we are super excited to announce the launch of Maester v1!
To celebrate ๐ ๐พ we are joining the EMS community Discord for an AMA.
discord.com/channels...
Read more at maester.dev/blog/mae...
12.12.2024 12:03
๐ 85
๐ 22
๐ฌ 4
๐ 1
๐จJoin us in tomorrows Spotlight session!
11.12.2024 19:26
๐ 0
๐ 0
๐ฌ 0
๐ 0