Summary
Keywords
Full Transcript
Are users getting blocked when they shouldn't? Is Intune saying "Compliant" but Conditional Access saying "No"? In this deep-dive masterclass, we walk through 30 real-world troubleshooting scenarios for Microsoft Entra ID (formerly Azure AD) Conditional Access. This isn't just theory. We go step-by-step through the exact logs, PowerShell commands, and KQL queries used by L3 engineers and Identity Architects to solve complex access issues. We cover everything from MFA loops and location blocks to complex device trust issues involving the Primary Refresh Token (PRT). Key Topics Covered The Universal Troubleshooting Framework (Sign-in Logs & What-If Tool) 20 Specific Scenarios (VPN failures, Legacy Auth, Break-Glass accounts, etc.) Deep Dives: Decoding dsregcmd /status, Error 53003, and PRT Analysis Advanced KQL queries for Log Analytics 📄 PowerShell Modules Used: Microsoft.Graph.Identity.SignIns 🛠️ Tools: dsregcmd, Graph Explorer https://cloudknowledge.in #MicrosoftEntraID #AzureAD #ConditionalAccess #CyberSecurity #IdentityManagement #M365 #Intune #PowerShellN #Cloudknowledge 0:00 - Introduction & Scope 0:45 - The Universal Troubleshooting Framework (Sign-in Logs) 02:15 - The Engineer's Toolkit (PowerShell & dsregcmd) 03:30 - Scenario 1: Blocked in Trusted Location (IP Mismatch) 05:10 - Scenario 2: MFA Prompt Loop (Session Controls) 06:45 - Scenario 3: Policy Not Applying (Report-Only Mode) 08:20 - Scenario 4: Device Compliance Mismatch (Intune vs Entra) 10:00 - Scenario 5: Emergency Account Locked (Break-Glass) 11:30 - Scenario 6: Legacy Auth Bypass Attacks 13:15 - Scenario 7: Mobile App vs Browser Failures 14:50 - Scenario 8: Location Logic (Inside vs Outside Network) 16:30 - Scenario 9: Service Account Blocking (Non-interactive) 18:00 - Scenario 10: Admin MFA Not Triggering 19:40 - Scenario 11: Blocked After Password Reset (Risk) 21:15 - Scenario 12: VPN Login Failures (Legacy vs Modern Auth) 22:50 - Scenario 13: App Specific Blocks (SharePoint vs Teams) 24:30 - Scenario 14: Guest User MFA Bypass & Trust Settings 26:10 - Scenario 15: Compliance Failure Post-Windows Update 27:45 - Scenario 16: Risk Signal False Positives (Impossible Travel) 29:20 - Scenario 17: MFA Frequency & SSO Issues 31:00 - Scenario 18: PowerShell & Graph API Access Blocked 32:45 - Scenario 19: Hybrid User Issues (Kerberos vs Cloud) 34:15 - Scenario 20: Login Success but App Error (Token Claims) 36:00 - DEEP DIVE: Decoding dsregcmd /status 38:30 - DEEP DIVE: Common Error Codes (53003 vs 53000) 40:15 - DEEP DIVE: Primary Refresh Token (PRT) Analysis 42:45 - DEEP DIVE: KQL Queries for Log Analytics 45:00 - Advanced Graph API & Audit Logs 47:30 - Summary & Golden Rules Microsoft Entra ID, Azure Active Directory, Conditional Access, Troubleshooting, MFA, Multi-Factor Authentication, Intune, Device Compliance, dsregcmd, PowerShell, Microsoft Graph, KQL, Log Analytics, Cyber Security, Identity and Access Management, IAM, SOC Analyst, System Admin, Office 365, M365, Legacy Authentication, VPN Troubleshooting, Error 53003, Primary Refresh Token, PRT, SSO, Azure AD Joined, Hybrid Join, Conditional Access Policy Troubleshooting, Entra ID Sign-in Logs analysis, Fix Error 53003 Access Blocked, Intune device compliance not syncing, Azure AD MFA loop fix, dsregcmd status explained, Block legacy authentication Azure AD, Troubleshoot Conditional Access What If tool
