Part 6 of the EU data sovereignty series. How to provision users from Keycloak to Entra ID via SCIM β the ImmutableID anchor problem, attribute mapping for Governance lifecycle workflows, deprovisioning, and handling edge cases.
I've been breaking down Microsoft's security stack since before Entra ID was even called Entra ID. No fluff, no paywalls — just technical depth on Entra, Sentinel, Defender, Purview, and Azure Security that the official docs rarely give you.

Discussion on technical topics and MVP path exploration. Pick the intensity that fits your timeline. Only for Individuals.
Part 6 of the EU data sovereignty series. How to provision users from Keycloak to Entra ID via SCIM β the ImmutableID anchor problem, attribute mapping for Governance lifecycle workflows, deprovisioning, and handling edge cases.
JIT password migration and High-Scale Compatibility mode for Azure AD B2C to Microsoft Entra External ID are now GA. How the custom authentication extension, Graph APIs, and HSC coexistence model work.
How Microsoft Entra Conditional Access now evaluates AI agents: subjects vs audiences, the three agent access patterns, and how to scope policies to agents with custom security attributes instead of managing them one by one.
A practical Microsoft Entra ID security checklist for Custom controls migration, credential registration Conditional Access, and SSPR registered-method enforcement.
What changed with passkeys in Microsoft Entra External ID, when it was released, how it compares with workforce tenants, and what can be automated with PowerShell.
Claude Fable 5 pricing, model capabilities, availability, safeguards, and what I would check before using it for agentic coding or enterprise workflows.