Lukas Beran's Avatar

Lukas Beran

@lukasberan.com

Senior Security Researcher (DART) at Microsoft. Opinions are my own. #MSIncidentResponse #DART #Microsoft365 #EntraID #DefenderXDR #Sentinel

1,543
Followers
241
Following
636
Posts
03.07.2023
Joined
Posts Following

Latest posts by Lukas Beran @lukasberan.com

It works fine in Edge on macOS. No issues at all.

23.02.2026 14:01 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Yep, I was feeling the same ๐Ÿ˜Š St the beginning, I was so excited about the smart watch things - that I could read emails, do phone calls, control my smart home, easily pay... But eventually I realized that I did not use most of the smart things any longer. And switched to Garmin that fits me better

21.02.2026 20:15 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I switched from Apple Watch to Garmin Fenix two years ago and would not go back. Garmin gives you so much more insights, data, and recommendations. When you sport actively and regularly, it is so much better. Apple is better as a smart watch, Garmin is better as a sport tester.

21.02.2026 19:31 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Yep, true. I always recommend configuring granular policies instead of complex ones - it is easier for troubleshooting and also much lower chance for misconfigurations.

18.02.2026 14:23 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
How Conditional Access Policies Are Evaluated in Microsoft Entra ID Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management. I often encounter fundamental misundersta...

Read my blog post bellow ๐Ÿ‘‡ ๐Ÿ‘‡
www.cswrld.com/2026/02/how-...

#cswrld #entraid #securitytips #conditionalaccess

18.02.2026 09:43 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

However, it does not work this way with Conditional Access policies in Microsoft Entra ID. Applying the same principle to Conditional Access policies will very likely lead to significant security risks.

18.02.2026 09:43 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I often encounter fundamental misunderstandings regarding how the evaluation of Conditional Access policies takes place. Many administrators are accustomed to systems like firewalls, where there is an order or priority for evaluating created rules.

18.02.2026 09:43 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

๐‡๐จ๐ฐ ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ ๐€๐œ๐œ๐ž๐ฌ๐ฌ ๐๐จ๐ฅ๐ข๐œ๐ข๐ž๐ฌ ๐€๐ซ๐ž ๐„๐ฏ๐š๐ฅ๐ฎ๐š๐ญ๐ž๐ ๐ข๐ง ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐„๐ง๐ญ๐ซ๐š ๐ˆ๐ƒ

Understanding how Conditional Access policies are evaluated in Microsoft Entra ID is absolutely essential if you are involved in their creation or management.

18.02.2026 09:43 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Great to see my post on Microsoft Entra ID access packages shared in such a valuable newsletter - thanks for the shoutout, @merill.net

15.02.2026 09:27 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thank you for the mention @merill.net ๐Ÿ™

15.02.2026 09:22 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
How to use access packages to manage group memberships Access packages allow you to dynamically manage group membership based on user requests. It works by creating an access package and then publishing it to users โ€“ either all users...

www.cswrld.com/2026/02/how-...

#cswrld #entraid #entitlementmanagement #identitygovernance #accesspackage

08.02.2026 10:40 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

It works by creating an access package and then publishing it to users โ€“ either all users or a select group of users. Users can then activate the package from the My Access portal after meeting defined conditions.

08.02.2026 10:40 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Access package in Microsoft Entra ID

Access package in Microsoft Entra ID

๐‡๐จ๐ฐ ๐ญ๐จ ๐ฎ๐ฌ๐ž ๐š๐œ๐œ๐ž๐ฌ๐ฌ ๐ฉ๐š๐œ๐ค๐š๐ ๐ž๐ฌ ๐ญ๐จ ๐ฆ๐š๐ง๐š๐ ๐ž ๐ ๐ซ๐จ๐ฎ๐ฉ ๐ฆ๐ž๐ฆ๐›๐ž๐ซ๐ฌ๐ก๐ข๐ฉ๐ฌ

Access packages allow you to dynamically manage group, Teams, application, and SharePoint site membership based on user requests.

08.02.2026 10:40 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

@proton.me, @nextcloud.bsky.social, Hetzner

28.01.2026 06:38 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

ลฝe by Babiลก (opฤ›t) lhal? To pล™ece nenรญ moลพnรฉ... ๐Ÿง

09.01.2026 10:52 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
How to enable auto-expanding archive in Exchange Online and get unlimited mailbox capacity Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB. However, this capacity can be...

www.cswrld.com/2026/01/how-...

#cswrld #exchangeonline #mailbox #archive

05.01.2026 08:53 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

An interesting fact is that Microsoft 365 Business Premium licenses, which by default include Exchange Online Plan 1, are also entitled to this feature.

05.01.2026 08:53 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

However, this capacity can be extended by using Online Archive. With Exchange Online Plan 2, this capacity is unlimited. Technically speaking, the capacity is limited to 1.5 TB.

05.01.2026 08:53 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Exchange Online mailbox archive

Exchange Online mailbox archive

๐‡๐จ๐ฐ ๐ญ๐จ ๐ ๐ž๐ญ ๐ฎ๐ง๐ฅ๐ข๐ฆ๐ข๐ญ๐ž๐ ๐ฆ๐š๐ข๐ฅ๐›๐จ๐ฑ ๐ฌ๐ข๐ณ๐ž ๐ข๐ง ๐„๐ฑ๐œ๐ก๐š๐ง๐ ๐ž ๐Ž๐ง๐ฅ๐ข๐ง๐ž

Exchange Online Plan 1 licenses generally have a primary mailbox capacity of 50 GB. Exchange Online Plan 2 licenses have a capacity of 100 GB.

05.01.2026 08:53 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

SwiftKey FTW ๐Ÿ˜Š

01.01.2026 15:43 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Used to be #2, been #3 last three years.

19.12.2025 20:35 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Uhm, well, Copilot was not entirely helpful ๐Ÿ˜ His knowledge base is either wrong or outdated, because the buttons and options Copilot is referring to are not there ๐Ÿคทโ€โ™‚๏ธ

11.12.2025 17:13 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

That is what I was afraid of ๐Ÿ˜€ Is there a template that I could easily use? Or do I have to build it myself from scratch?

11.12.2025 09:11 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Yeah, that is what I found out as well. I just could not believe that something so simple and so obvious is not possible ๐Ÿ˜ฑ

11.12.2025 06:57 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Is there any way to create a Planner task directly from an email? Ideally including the email content and attachments. I assumed this would be basic functionality, but I canโ€™t find such an option anywhere.

#planner

11.12.2025 06:05 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0

Jรก jsem si dlouho myslel, ลพe to je nฤ›jakรก satira. Ale tohle by bylo moc i na satiru ๐Ÿคฆโ€โ™‚๏ธ

06.12.2025 20:39 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Looks like Christmas is coming early this year ๐Ÿคทโ€โ™‚๏ธ

04.12.2025 20:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Microsoft 365: The Essential 10 Security Considerations - Ru Campbell MVP When we talk about Microsoft 365 security, we are talking about two things: The latter can be used to achieve the former, as well as other (non-Microsoft 365) platforms. For example, using Defender for Endpoint on a Linux server in AWS, or using Entra for single sign on to Salesforce. Given its omnipresence in enterprise IT, Microsoft 365 securityโ€™s vastness (and value) needs to be front-of-mind for all tenant administrators. The Essential 10 isโ€ฆ

New post: focusing on the key biggest Microsoft 365 security considerations.

READ: campbell.scot/micros...

When we talk about Microsoft 365 security, we are talking about two things: (a) securing Microsoft 365 the platform, (b) using Microsoft 365 security tooling.

28.11.2025 13:57 ๐Ÿ‘ 5 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Cloudflare status page

Cloudflare status page

@cloudflare.social is so broken now that even their status page is broken ๐Ÿง #cloudflaredown

18.11.2025 12:09 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

New video: 5 common Entra ID guests mistakes (Entra B2B)

โ€ข excessive directory visibility
โ€ข ignored cross-tenant defaults
โ€ข untrusted MFA & device states
โ€ข open SharePoint sharing
โ€ข no guest lifecycle

There's tons more! But here's a starter

WATCH: youtu.be/AXuj-U9p3jU

31.10.2025 16:47 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0