<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Rev on Tom Plant</title>
    <link>https://2849e3c5.tplant.pages.dev/tags/rev/</link>
    <description>Recent content in Rev on Tom Plant</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 31 Jan 2023 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://2849e3c5.tplant.pages.dev/tags/rev/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Tenant Restrictions v2 - under the hood</title>
      <link>https://2849e3c5.tplant.pages.dev/blog/tenant-restrictions-v2/part-2/</link>
      <pubDate>Tue, 31 Jan 2023 00:00:00 +0000</pubDate>
      <guid>https://2849e3c5.tplant.pages.dev/blog/tenant-restrictions-v2/part-2/</guid>
      <description>For background info on tenant restrictions, check out my previous post.&#xA;Cloud Identity Service Taking a look in Event Viewer, there&amp;rsquo;s a new log Microsoft-Windows-TenantRestrictions/Operational with some events:&#xA;1004: The endpoint sync service (cloudidsvc) started succesfully [sic].&#xA;1005: The endpoint sync service (cloudidsvc) succesfully [sic] synced the latest list of endpoints.&#xA;That service has an interesting description:&#xA;Supports integrations with Microsoft cloud identity services. If disabled, tenant restrictions will not be enforced properly.</description>
    </item>
    <item>
      <title>Finding an unreleased Windows feature - Tenant Restrictions v2 (TRv2)</title>
      <link>https://2849e3c5.tplant.pages.dev/blog/tenant-restrictions-v2/part-1/</link>
      <pubDate>Thu, 27 Oct 2022 00:00:00 +0000</pubDate>
      <guid>https://2849e3c5.tplant.pages.dev/blog/tenant-restrictions-v2/part-1/</guid>
      <description>The Windows 11 ADMXs released a while back, and there&amp;rsquo;s an interesting new category - &amp;ldquo;Tenant Restrictions&amp;rdquo;. It shares a name with an Azure AD feature for restricting endpoints to specific tenants, but that typically requires a beefy TLS decryption appliance and expensive supporting infrastructure (VPNs etc). The ADMX category only has one policy, &amp;ldquo;Cloud Policy Details&amp;rdquo; (ID trv2_payload), but fortunately it has a detailed description:&#xA;This setting enables and configures the device-based tenant restrictions feature for Azure Active Directory.</description>
    </item>
  </channel>
</rss>
