# Entra ID

Published articles for Entra ID.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

DevFeed: [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](<https://devfeed.tech/articles/spring-ring-an-inside-look-at-voice-phishing-campaigns-in-microsoft-teams-7760.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/>)

Author: Noam Sala

Published: 2026-08-31T10:00:36Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [remote access software](<https://devfeed.tech/topics/remote-access-software.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Cloaked Ursa](<https://devfeed.tech/topics/cloaked-ursa.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloaked-ursa](<https://devfeed.tech/tags/cloaked-ursa.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [payload](<https://devfeed.tech/tags/payload.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [vishing](<https://devfeed.tech/tags/vishing.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

Spring Ring is a coordinated social engineering campaign that used external Microsoft Teams accounts and voice phishing to impersonate IT help desk staff. The operation targeted more than 150 employees across at least 10 companies and attempted to deliver remote monitoring and management tools or custom malware. A more advanced variant escalated to an NTLM relay attack against an organization's domain controller.

### Source excerpt

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

## How Does CockroachDB Automate SQL User Lifecycle Management?

DevFeed: [How Does CockroachDB Automate SQL User Lifecycle Management?](<https://devfeed.tech/articles/how-does-cockroachdb-automate-sql-user-lifecycle-management-23818.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/sql-user-lifecycle-management-automation>)

Author: Pritesh Lahoti,Biplav Saraf,Sourav Sarangi

Published: 2026-08-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [okta](<https://devfeed.tech/tags/okta.md>)

### AI overview

The article addresses how CockroachDB automates SQL user lifecycle management and notes that large enterprises commonly rely on identity provider and identity and access management platforms such as Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

### Source excerpt

Fortune 1000 enterprises widely rely on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

## Fewer lockouts, less manual work: What's new for 1Password EPM admins

DevFeed: [Fewer lockouts, less manual work: What's new for 1Password EPM admins](<https://devfeed.tech/articles/fewer-lockouts-less-manual-work-what-s-new-for-1password-epm-admins-1972.md>)

Original publisher: [Read original article](<https://1password.com/blog/whats-new-for-1password-epm-admins>)

Author: info@1password.com (Jairo Camacho)

Published: 2026-08-26T00:00:00Z

Content type: release

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [documentation](<https://devfeed.tech/tags/documentation.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [integration](<https://devfeed.tech/tags/integration.md>), [multi-tenancy](<https://devfeed.tech/tags/multi-tenancy.md>), [news](<https://devfeed.tech/tags/news.md>), [outage](<https://devfeed.tech/tags/outage.md>), [releases](<https://devfeed.tech/tags/releases.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

1Password announces releases for EPM admins focused on reducing lockouts and automating provisioning at scale. The updates include Entra ID secret-expiration tracking with reminders and guided rotation, integration between Multi-Tenancy and Automated Provisioning, and Vault Migrations for populating shared vaults in linked accounts.

### Source excerpt

As a company grows, more employees join, but the size of the IT team overseeing critical systems often doesn't grow at the same pace. Admins have to be intentional about prioritizing their efforts to meet the needs of a growing organization. That's why we're excited to announce several releases aimed at helping admins optimize their organization's use of 1Password in two important areas: reducing lockouts and automating provisioning at scale. Preventing avoidable lockouts Entra ID Secret Expiration Most 1Password Business accounts sign in via SSO through an identity provider like Microsoft Entra ID. Admins rely on a secret provisioned by Entra to establish connectivity with 1Password. However, it comes with an expiration date. Once it expires, the connection breaks, preventing anyone from signing in. This was one of the most common and disruptive patterns we'd observe with customers. Entra ID Secret Expiration now tracks it for you. Simply record the expiration date, and 1Password will send escalating reminders across in-app banners, emails, and login prompts at a fixed cadence (e.g., 90/60/30 days). Once it's time to rotate the secret, follow the guided flow in the Admin Console, confirm it's working as intended, and the countdown resets automatically. A predictable secret expiration date should never become an outage, and now it doesn't have to. Standing up new parts of the business quickly Multi-Tenancy and Automated Provisioning integration Earlier this year we released Multi-Tenancy and Automated Provisioning, hosted by 1Password, two critical features for admins to manage provisioning, deprovisioning, and parent/child accounts at scale. Now admins can use these features in tandem, so enterprises with multi-tenant setups can take advantage of Automated Provisioning. To get started, check out our detailed documentation for setting up the Multi-Tenancy and Automated Provisioning integration To get started, check out our detailed documentation for setting up the M

## From dotnet run to Foundry Hosted Agent in 3 lines of C#

DevFeed: [From dotnet run to Foundry Hosted Agent in 3 lines of C#](<https://devfeed.tech/articles/from-dotnet-run-to-foundry-hosted-agent-in-3-lines-of-c-2950.md>)

Original publisher: [Read original article](<https://devblogs.microsoft.com/dotnet/from-dotnet-run-to-foundry-hosted-agent-in-3-lines-of-csharp/>)

Author: Bruno Capuano

Published: 2026-08-24T19:00:00Z

Content type: tutorial

Language: en

Sources: [.NET Blog](<https://devfeed.tech/sources/net-blog.md>)

Topics: [hosted-agents](<https://devfeed.tech/topics/hosted-agents.md>), [Microsoft Agent Framework](<https://devfeed.tech/topics/microsoft-agent-framework.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [.NET](<https://devfeed.tech/topics/net.md>), [NuGet](<https://devfeed.tech/topics/nuget.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [azd](<https://devfeed.tech/tags/azd.md>), [azure](<https://devfeed.tech/tags/azure.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [csharp](<https://devfeed.tech/tags/csharp.md>), [dotnet](<https://devfeed.tech/tags/dotnet.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [framework](<https://devfeed.tech/tags/framework.md>), [hosted-agents](<https://devfeed.tech/tags/hosted-agents.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-agent-framework](<https://devfeed.tech/tags/microsoft-agent-framework.md>), [microsoft-foundry](<https://devfeed.tech/tags/microsoft-foundry.md>), [net](<https://devfeed.tech/tags/net.md>), [nuget](<https://devfeed.tech/tags/nuget.md>), [observability](<https://devfeed.tech/tags/observability.md>), [post](<https://devfeed.tech/tags/post.md>), [production](<https://devfeed.tech/tags/production.md>)

### AI overview

This tutorial shows how to deploy a Microsoft Agent Framework console agent as a Foundry Hosted Agent using one NuGet package, three lines of C#, and two commands. Foundry provides managed Azure infrastructure, scaling, identity, session state, observability, and lifecycle management.

### Source excerpt

You built an agent with Microsoft Agent Framework and it works great on your machine. Now what? Turns out deploying it to production takes 1 NuGet package, 3 lines of C#, and 2 commands. Let's do it. The post From dotnet run to Foundry Hosted Agent in 3 lines of C# appeared first on .NET Blog.

## Avoid Azure secret rotation with secretless authentication

DevFeed: [Avoid Azure secret rotation with secretless authentication](<https://devfeed.tech/articles/avoid-azure-secret-rotation-with-secretless-authentication-2231.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/azure-secretless-authentication/>)

Author: Cody Murray-Bruce; Ben Johnson-Staub

Published: 2026-08-12T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [migration](<https://devfeed.tech/topics/migration.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cli](<https://devfeed.tech/tags/cli.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [infrastructure-monitoring](<https://devfeed.tech/tags/infrastructure-monitoring.md>), [integration](<https://devfeed.tech/tags/integration.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [migration](<https://devfeed.tech/tags/migration.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

This article explains how Datadog's secretless authentication for Azure replaces long-lived client secrets with federated identity using Microsoft Entra ID and OpenID Connect. It describes the short-lived token flow and configuration or migration options through Quickstart, Terraform, the Azure CLI, or the Azure portal.

### Source excerpt

Learn how secretless authentication for Datadog's Azure integration helps prevent telemetry interruptions that result from expired client secrets.

## Vercel Passport is now generally available

DevFeed: [Vercel Passport is now generally available](<https://devfeed.tech/articles/vercel-passport-is-now-generally-available-1161.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/vercel-passport-generally-available>)

Author: Yanick Bélanger

Published: 2026-07-31T00:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Vercel](<https://devfeed.tech/topics/vercel.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [jwks](<https://devfeed.tech/tags/jwks.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [okta](<https://devfeed.tech/tags/okta.md>), [payload](<https://devfeed.tech/tags/payload.md>), [scope](<https://devfeed.tech/tags/scope.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [verify](<https://devfeed.tech/tags/verify.md>)

### AI overview

Vercel Passport is generally available for protecting Vercel deployments with Okta, Microsoft Entra ID, or another OIDC provider. It provides verified visitor identity to application code, supports group-based authorization, enables token verification in downstream services, and records successful authentications in activity and audit logs.

### Source excerpt

Vercel Passport is now generally available. Passport allows you to protect your Vercel deployments with your own identity provider. Visitors authenticate through Okta, Microsoft Entra ID, or any OIDC provider before viewing a protected deployment, and Vercel forwards a signed identity token to the deployment so application code can build on who the visitor is. Read visitor identity in application code The getIdentity() helper in @vercel/passport reads the Vercel request context and returns the authenticated visitor. Vercel strips client-supplied values for the x-vercel-oidc-passport-token header and injects the verified token after Passport validates the session, so the identity your code receives is already verified. The subject field is a stable identifier for the visitor, scoped to your team and the Vercel Connect application that links Passport to your identity provider, and externalSubject is the visitor's ID in the provider itself. The helper returns null only when a request arrives without a Passport session, because unauthenticated browser visitors are redirected to the identity provider before they ever reach your code. In local development, getIdentity() returns a configurable development identity, so the same code path works without a real identity provider. Authorize with groups from your identity provider The signed Passport token can now carry additional identity claims from your provider, such as group membership. Request the groups scope and allowlist the claim in the Vercel Connect application that Passport uses, then read it from the identity payload: The additional identity scopes documentation covers provider configuration, including a full Okta walkthrough. Verify identity in downstream services Forward the Passport token from your application to another backend as a bearer token and verify it there with verifyIdentity(), available in @vercel/passport 1.0.0 and later. The helper checks the token signature, the Passport claims, and that the token

## Entra Agent ID: Protect, detect, respond

DevFeed: [Entra Agent ID: Protect, detect, respond](<https://devfeed.tech/articles/entra-agent-id-protect-detect-respond-8270.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/>)

Author: Katie Knowles

Published: 2026-07-06T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This concluding article in the Agent ID series explains how administrators and security teams can protect Entra agent blueprints and identities, detect suspicious activity, and respond to compromises. It recommends limiting privileged roles and permissions, reducing reliance on secrets, reviewing third-party blueprints, monitoring agent activity, and disabling or deleting compromised identities or blueprints.

### Source excerpt

This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.

## Entra Agent ID: Inside a cross-tenant agent compromise

DevFeed: [Entra Agent ID: Inside a cross-tenant agent compromise](<https://devfeed.tech/articles/entra-agent-id-inside-a-cross-tenant-agent-compromise-8268.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/agent-id-inside-agent-compromise/>)

Author: Katie Knowles

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [blog](<https://devfeed.tech/tags/blog.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This post demonstrates how compromising a privileged agent through a third-party Entra agent blueprint can enable cross-tenant access. An attacker who controls the blueprint can add a credential and authenticate as associated agent service principals, identities, and users across Entra tenants, potentially exposing identities with different permission contexts.

### Source excerpt

Continuing our Agent ID series, this post demonstrates how a privileged agent could be compromised through its third-party blueprint. This leads to a cross-tenant incident similar to Midnight Blizzard, since an attacker with control over an agent blueprint can authenticate as any agent associated with that blueprint.

## Guide: How to Unify Identity Across Cloud and Data Center Infrastructure

DevFeed: [Guide: How to Unify Identity Across Cloud and Data Center Infrastructure](<https://devfeed.tech/articles/guide-how-to-unify-identity-across-cloud-and-data-center-infrastructure-29954.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/unify-identity-cloud-data-centers/>)

Author: info@goteleport.com (Mayur Pipaliya)

Published: 2026-05-01T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [IAM](<https://devfeed.tech/topics/iam.md>), [trust](<https://devfeed.tech/topics/trust.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [data centers](<https://devfeed.tech/topics/data-centers.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [data-center](<https://devfeed.tech/tags/data-center.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-and-access](<https://devfeed.tech/tags/identity-and-access.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>)

### AI overview

This guide explains identity fragmentation across cloud accounts, data centers, and colocated infrastructure. It describes siloed identity systems, credential sprawl, and differing access models, and presents approaches including hardware roots of trust, short-lived certificates, shared certificate authorities, SPIFFE workload identities, reverse tunnels, and protocol-level enforcement.

### Source excerpt

Inside this guide, discover the root causes of identity fragmentation across cloud and data center environments -- and what it takes to unify identity.

## SCIM Realm API as an Experimental Feature

DevFeed: [SCIM Realm API as an Experimental Feature](<https://devfeed.tech/articles/scim-realm-api-as-an-experimental-feature-31770.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/04/scim-as-experimental-feature>)

Author: Keycloak Core IAM Team

Published: 2026-04-10T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [API](<https://devfeed.tech/topics/api.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [experimental](<https://devfeed.tech/tags/experimental.md>), [feature](<https://devfeed.tech/tags/feature.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.6 introduces the SCIM Realm API as an experimental feature. It enables clients using the SCIM protocol to manage users and groups, with compatibility work focused on Microsoft Entra ID. The article also explains how to enable and try the API.

### Source excerpt

If you have been following the latest blog posts, you may have noticed that we have been working on implementing the System for Cross-domain Identity Management (SCIM) protocol in Keycloak. We are excited to announce that the SCIM Realm API is now available as an experimental feature in Keycloak 26.6. The SCIM Realm API allows you to manage users and groups in Keycloak using the SCIM protocol. This means that you can use any SCIM client to manage the user and group resource types in your realm. This is a great step towards improving the integrability of Keycloak with other (cross-domain) IAM solutions and downstream applications, thereby enabling common cloud use cases for identity (de)provisioning. In terms of integration, we focused on making the API as compatible as possible with Microsoft Entra ID, which is the integration most demanded by the community. To do that, we have used the EntraID SCIM Validator to validate our implementation and ensure that it meets the requirements of Microsoft Entra ID. In essence, the SCIM Realm API is the Admin API but compliant with SCIM. How to try it out? Since this is an experimental feature (not enabled by default), you need to enable it when starting the server: docker run --name kc-scim-api -d \ -e KEYCLOAK_ADMIN=admin \ -e KEYCLOAK_ADMIN_PASSWORD=admin \ -p 8080:8080 \ quay.io/keycloak/keycloak:nightly \ start-dev --features=scim-api Let us create a realm myrealm and enable the SCIM API for it. To do that, you can use the kcadm.sh script to create the realm and enable the API. First, you need to configure the credentials for the kcadm.sh script to be able to connect to the server: ./kcadm.sh config credentials --server http://localhost:8080 --realm master --user admin --password admin Create the realm myrealm: ./kcadm.sh create realms -s realm=myrealm -s enabled=true -s scimApiEnabled=true Using the administration console, go to the Realm Settings page of your realm, and check that the SCIM API setting is enabled. Once the

## Building MCP servers with Entra ID and pre-authorized clients

DevFeed: [Building MCP servers with Entra ID and pre-authorized clients](<https://devfeed.tech/articles/building-mcp-servers-with-entra-id-and-pre-authorized-clients-21749.md>)

Original publisher: [Read original article](<http://blog.pamelafox.org/2026/04/building-mcp-servers-with-entra-id-and.html>)

Author: Pamela Fox (noreply@blogger.com)

Published: 2026-04-02T23:44:00Z

Content type: tutorial

Language: en

Sources: [Pamela Fox](<https://devfeed.tech/sources/pamela-fox.md>)

Topics: [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Python](<https://devfeed.tech/topics/python.md>), [vs-code](<https://devfeed.tech/topics/vs-code.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [entra-id](<https://devfeed.tech/tags/entra-id.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>)

### AI overview

This tutorial explains how to build a Python MCP server with FastMCP that authenticates users with Microsoft Entra ID when they connect through a pre-authorized client such as VS Code. It outlines the MCP authorization flow, OAuth 2.1 roles, and why arbitrary-client support may require an OAuth proxy.

### Source excerpt

The Model Context Protocol (MCP) gives AI agents a standard way to call external tools, but things get more complicated when those tools need to know who the user is. In this post, I'll show how to build an MCP server with the Python FastMCP package that authenticates users with Microsoft Entra ID when they connect from a pre-authorized client such as VS Code. If you need to build a server that works with any MCP clients, read my previous blog post. With Microsoft Entra as the authorization server, supporting arbitrary clients currently requires adding an OAuth proxy in front, which increases security risk. This post focuses on the simpler pre-authorized-client path instead. MCP auth Let's start by digging into the MCP auth spec, since that explains both the shape of the flow and the constraints we run into with Entra. The MCP specification includes an authorization protocol based on OAuth 2.1, so an MCP client can send a request that includes a Bearer token from an authorization server, and the MCP server can validate that token. In OAuth 2.1 terms, the MCP client is acting as the OAuth client, the MCP server is the resource server, the signed-in user is the resource owner, and the authorization server issues an access token. In this case, Entra will be our authorization server. We can't necessarily use any OAuth-compatible authorization servers, as MCP auth requires more than just the core OAuth 2.1 functionality. In OAuth, the authorization server needs a relationship with the client. MCP auth describes three options: Pre-registration: the auth server has a pre-existing relationship and has the client ID in its database already CIMD (Client Identity Metadata Document): the MCP client sends the URL of its CIMD, a JSON document that describes its attributes, and the auth server bases its interactions on that information. DCR (Dynamic Client Registration): when the auth server sees a new client, it explicitly registers it and stores the client information in its own

## Keycloak outlines experimental SCIM support planned for version 26.6

DevFeed: [Keycloak outlines experimental SCIM support planned for version 26.6](<https://devfeed.tech/articles/thanks-for-your-feedback-on-scim-support-in-keycloak-31759.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/02/scim-support-survey-feedback>)

Author: Keycloak Core IAM Team

Published: 2026-02-26T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [iam](<https://devfeed.tech/tags/iam.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [release](<https://devfeed.tech/tags/release.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak describes early development of experimental SCIM support targeted for version 26.6. The initial focus is using Keycloak as a SCIM service provider for user provisioning and deprovisioning, while SCIM client support and integrations with external identity providers are also being explored.

### Source excerpt

First of all, we want to thank everyone who took the time to fill out our survey on SCIM support in Keycloak. Your feedback is invaluable to us as we work on implementing this feature. We are currently in the early stages of development, and we are using your feedback to guide our efforts. The survey results have shown us that there is a strong demand for SCIM support in Keycloak, and one of the most common use case is to use Keycloak as a SCIM service provider to manage user provisioning and deprovisioning for external applications. We are prioritizing this use case and driving the design and implementation of SCIM support in Keycloak to meet core set of requirements for this use case. In parallel, we are also exploring other use cases and requirements for SCIM support in Keycloak, such as using Keycloak as a SCIM client to integrate with external identity providers. As a result of this initial work, we are implementing a SCIM client that will allow in the future to address use cases where Keycloak can act as a SCIM client to integrate external SCIM service providers. Even though we are still delivering this feature as an experimental feature in the 26.6 release, the feedback we have received should allow us to deliver a solid implementation that meets the core requirements for the most common use case of using Keycloak as a SCIM service provider, and enable integrations any SCIM-compliant client, such as Microsoft Entra ID. That said, we have identified the initial scope for SCIM support in Keycloak targeting the 26.6 release, which will include the following capabilities: Expose realm users via the /Users endpoint with support for POST, PUT, PATCH, GET, and DELETE operations Expose realm groups via the /Groups endpoint with support for POST, PUT, PATCH, GET, and DELETE operations Support for a limited set of SCIM filters for querying resource types Support for pagination of results when querying resource types Support for fine-grained permissions to control acces

## A Modern Guide to Using OAuth 2.0 with C# and Visual Studio Code

DevFeed: [A Modern Guide to Using OAuth 2.0 with C# and Visual Studio Code](<https://devfeed.tech/articles/a-modern-guide-to-using-oauth-2-0-with-c-and-visual-studio-code-37536.md>)

Original publisher: [Read original article](<https://deanhume.com/a-modern-guide-to-using-oauth-2-0-with-c/>)

Author: Dean Hume

Published: 2025-11-03T10:45:24Z

Content type: tutorial

Language: en

Sources: [Dean Hume](<https://devfeed.tech/sources/dean-hume.md>)

Topics: [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [.NET](<https://devfeed.tech/topics/net.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [API](<https://devfeed.tech/topics/api.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [code](<https://devfeed.tech/tags/code.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [net](<https://devfeed.tech/tags/net.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [oauth-2-0](<https://devfeed.tech/tags/oauth-2-0.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>), [visual-studio-code](<https://devfeed.tech/tags/visual-studio-code.md>)

### AI overview

A practical tutorial on implementing OAuth 2.0 authentication in C# with Visual Studio Code and modern .NET libraries. It covers creating a console application, configuring OAuth settings, acquiring access tokens with MSAL, and calling protected APIs such as Microsoft Graph.

### Source excerpt

Master OAuth 2.0 in .NET 9.0! This tutorial covers using OAuth 2 to acquire tokens and access Microsoft Graph user data.

## Zero Trust VPN and networking guide for business security teams

DevFeed: [Zero Trust VPN and networking guide for business security teams](<https://devfeed.tech/articles/zero-trust-vpn-and-networking-guide-for-business-security-teams-31201.md>)

Original publisher: [Read original article](<https://tailscale.com/learn/zero-trust-vpn>)

Published: 2025-09-23T18:03:01Z

Content type: tutorial

Language: en

Sources: [Learn on Tailscale](<https://devfeed.tech/sources/learn-on-tailscale.md>)

Topics: [zero trust networking](<https://devfeed.tech/topics/zero-trust-networking.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [tailscale](<https://devfeed.tech/topics/tailscale.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Google](<https://devfeed.tech/topics/google.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [google](<https://devfeed.tech/tags/google.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [networking](<https://devfeed.tech/tags/networking.md>), [okta](<https://devfeed.tech/tags/okta.md>), [security](<https://devfeed.tech/tags/security.md>), [teams](<https://devfeed.tech/tags/teams.md>), [vpn](<https://devfeed.tech/tags/vpn.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This guide explains Zero Trust networking as an approach that verifies users and devices for each access request, applies least privilege and segmentation, and limits lateral movement. It compares this model with traditional VPN access and describes how Tailscale uses identity, device posture, authorization, SSO, and SSH features to support Zero Trust principles.

### Source excerpt

Learn how Zero Trust works and why it beats traditional VPNs for business security. Get implementation tips, compare solutions, and discover how to limit access without killing productivity.

## Integrating OpenID Connect with Redpanda

DevFeed: [Integrating OpenID Connect with Redpanda](<https://devfeed.tech/articles/integrating-openid-connect-with-redpanda-12709.md>)

Original publisher: [Read original article](<https://www.redpanda.com/blog/integrating-openid-connect>)

Author: Ben Barkhouse

Published: 2025-09-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Redpanda](<https://devfeed.tech/sources/redpanda.md>)

Topics: [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Docker Compose](<https://devfeed.tech/topics/docker-compose.md>), [Security](<https://devfeed.tech/topics/security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [cli](<https://devfeed.tech/tags/cli.md>), [compose](<https://devfeed.tech/tags/compose.md>), [docker](<https://devfeed.tech/tags/docker.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [okta](<https://devfeed.tech/tags/okta.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [redpanda-api](<https://devfeed.tech/tags/redpanda-api.md>), [redpanda-console](<https://devfeed.tech/tags/redpanda-console.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

A tutorial on configuring OpenID Connect authentication and single sign-on for Redpanda. It explains OIDC's relationship to OAuth 2.0, supported identity providers and deployment options, API availability limitations, and a local Docker Compose setup using Keycloak, Redpanda Console, and a Redpanda cluster.

### Source excerpt

Learn how to set up OpenID Connect with Redpanda to protect your critical data from unauthorized access.

## Neon's Microsoft Azure Native Integration is Generally Available

DevFeed: [Neon's Microsoft Azure Native Integration is Generally Available](<https://devfeed.tech/articles/neon-s-microsoft-azure-native-integration-is-generally-available-5023.md>)

Original publisher: [Read original article](<https://neon.com/blog/azure-native-integration-ga>)

Author: Monica Steinke

Published: 2025-05-07T18:01:03Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [azure container apps](<https://devfeed.tech/topics/azure-container-apps.md>), [Database](<https://devfeed.tech/topics/database.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [company](<https://devfeed.tech/tags/company.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [postgres](<https://devfeed.tech/tags/postgres.md>), [product](<https://devfeed.tech/tags/product.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [sdk](<https://devfeed.tech/tags/sdk.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Neon's Microsoft Azure Native Integration is generally available, bringing serverless Postgres into Azure workflows. Developers can provision and manage Neon resources through the Azure portal, CLI, and SDK, with Entra ID authentication, unified billing, CI/CD support, and MACC eligibility.

### Source excerpt

Neon's Microsoft Azure Native Integration has reached General Availability, providing developers with a powerful, serverless Postgres solution on Azure. Neon integrates with your existing Azure workflows, including unified billing, Microsoft single-sign on (SSO), and full MACC el...