Device code phishing uses the real microsoft.com/devicelogin page. MFA succeeds, the attacker gets the tokens. Block Authentication flows > Device code in Conditional Access, report-only first.
Entra-ID
Entra memberOf Rules Freeze November 3
Entra memberOf does not error on November 3. Dynamic groups, admin units, and entitlement policies just stop updating and keep last week’s members. Export the rules now.
Nonprofit AI field notes: Fabric forecasting, Entra-gated research data, Power Apps admin cuts
Three nonprofit Microsoft deployments with real stacks and real numbers: Animal Protection Denmark using Fabric for kitten-season forecasting, Answer ALS gating Neuromine research data with Entra ID, and Everything Suarve saving 8 hours per enrollment with Power Apps. The pattern is data cleanup first, access control second, automation third.
Deploying Claude Desktop Behind Entra ID: The No-Backend Architecture MSPs Need
Claude Desktop ships with a shared API key in a local config file — no per-user identity, no MFA, no audit trail. For MSPs with regulated clients, that’s a non-starter. Microsoft just published an architecture that routes Claude Desktop through Entra ID and Azure API Management with zero custom backend code. Per-user identity, Conditional Access, auditable, and the config can be pushed via Intune. If your clients are asking for sanctioned AI desktop tools alongside their existing M365 stack, this closes a real governance gap.
