<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Chris Brumm's Blog</title><link>https://chris-brumm.com/</link><description>Recent content on Chris Brumm's Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 20 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://chris-brumm.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Private DNS Hygiene in GSA — Suffixes, Segments, and the Order Things Resolve In</title><link>https://chris-brumm.com/2026/08/Private-DNS-Suffix-and-Segment-Hygiene/</link><pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2026/08/Private-DNS-Suffix-and-Segment-Hygiene/</guid><description>The previous post was about what happens to a Private DNS lookup on the authentication plane – how, once Private DNS is configured, resolving an internal name becomes an access to the Quick Access app, and therefore something Conditional Access gets an opinion about. This one is about the other half: what you feed into Quick Access in the first place – the suffixes, the application segments, the FQDNs and IP ranges.</description></item><item><title>When DNS Lookups Trigger MFA — Private DNS and Conditional Access in GSA</title><link>https://chris-brumm.com/2026/07/When-DNS-Lookups-Trigger-MFA/</link><pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2026/07/When-DNS-Lookups-Trigger-MFA/</guid><description>Back in 2024 I wrote a deep dive on DNS in Entra Private Access, and it turned into one of the posts I still get the most messages about – apparently I am not the only one who finds name resolution in a ZTNA world more interesting than it has any right to be. That post was all about how names get resolved: the NRPT, the 6.6.255.254 forwarder, split DNS, and disconnected environments.</description></item><item><title>Token Replay Protection and the Compliant Network Check</title><link>https://chris-brumm.com/2026/04/Token-Replay-Protection-and-the-Compliant-Network-Check/</link><pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2026/04/Token-Replay-Protection-and-the-Compliant-Network-Check/</guid><description>This post is part of a series on the Microsoft Traffic Forwarding Profile in Global Secure Access:
Why you should enable the Microsoft Traffic Forwarding Profile Token Replay Protection and the Compliant Network Check (this post) Universal Tenant Restrictions Coexistence with other Secure Web Gateways Logging If you haven&amp;rsquo;t read the first post yet, it covers the basics of the Microsoft Traffic Forwarding Profile, how to enable it, and what the four security benefits are: Why you should enable the Microsoft Traffic Forwarding Profile.</description></item><item><title>Why you should enable the Microsoft Traffic Forwarding Profile</title><link>https://chris-brumm.com/2026/04/Why-you-should-enable-the-Microsoft-Traffic-Forwarding-Profile/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2026/04/Why-you-should-enable-the-Microsoft-Traffic-Forwarding-Profile/</guid><description>This post is part of a series on the Microsoft Traffic Forwarding Profile in Global Secure Access:
Why you should enable the Microsoft Traffic Forwarding Profile (this post) Token Replay Protection and the Compliant Network Check Universal Tenant Restrictions Coexistence with other Secure Web Gateways Logging The case for enabling it The Microsoft Traffic Forwarding Profile tends to get overlooked in two different situations. In organizations that are already running a GSA project – typically starting with Entra Private Access – it often gets deprioritized because the focus is on getting the connector infrastructure in place and migrating VPN users.</description></item><item><title>A second look at Microsoft Entra Private Access for Active Directory domain controllers</title><link>https://chris-brumm.com/2026/01/02/A-second-look-at-EPA4DC/</link><pubDate>Fri, 02 Jan 2026 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2026/01/02/A-second-look-at-EPA4DC/</guid><description>🆕 This is the updated version of my blog about Entra Private Access for Active Directory for Domain Controllers. You can find the old version → here ←. New features include the central admin UI and logging!
Intro In many environments - often for historical reasons - there is no strict separation of client and server networks. And if there is a firewall between the networks, the rule sets often allow direct communication with the domain controllers in the environment.</description></item><item><title>Using Global Secure Access in Cross-Tenant scenarios</title><link>https://chris-brumm.com/2025/12/21/Cross-Tenant-Global-Secure-Access/</link><pubDate>Sun, 21 Dec 2025 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2025/12/21/Cross-Tenant-Global-Secure-Access/</guid><description>One of the many announcements at Ignite (somewhat away from the AI hype) is the long-awaited B2B support for Global Secure Access. It combines Entra B2B, such as cross-tenant access policies, with the features of GSA, enabling an excellent user experience while also providing a very high level of security.
Use cases for B2B access When planning the replacement of legacy VPNs, the issue repeatedly arises that the VPN is not only used by employees with managed devices, but also provides access for service providers and consultants, for example.</description></item><item><title>Intelligent Local Access Deep Dive</title><link>https://chris-brumm.com/2025/11/19/Intelligent-Local-Access-Deep-Dive/</link><pubDate>Wed, 19 Nov 2025 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2025/11/19/Intelligent-Local-Access-Deep-Dive/</guid><description>Global Secure Access (GSA) enforces that all client traffic is routed through the cloud before reaching the target resource via Private Network Connectors—even if both endpoints are in the same building or network. This design ensures that security controls are consistently applied.
However, not every location has the connectivity of Coruscant; some sites feel more like the Outer Rim—and in Germany, bandwidth limitations can appear quickly. To cope, many users have resorted to disabling the GSA client when on the corporate LAN, a behavior familiar from traditional VPN clients.</description></item><item><title>A first look at Microsoft Entra Private Access for Active Directory domain controllers</title><link>https://chris-brumm.com/2025/08/19/A-first-look-at-EPA4DC/</link><pubDate>Tue, 19 Aug 2025 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2025/08/19/A-first-look-at-EPA4DC/</guid><description>In many environments - often for historical reasons - there is no strict separation of client and server networks. And if there is a firewall between the networks, the rule sets often allow direct communication with the domain controllers in the environment. Although a conversion makes a lot of sense, it is often not possible quickly, because various services like GPOs or Kerberos rely on this communication and a client modernization project takes time and effort.</description></item><item><title>Entra Private Access and the future of the Entra App Proxy</title><link>https://chris-brumm.com/2025/04/06/Entra-Private-Access-and-the-future-of-the-Entra-App-Proxy/</link><pubDate>Sun, 06 Apr 2025 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2025/04/06/Entra-Private-Access-and-the-future-of-the-Entra-App-Proxy/</guid><description>Since the release of Entra Private Access, I have been getting more and more questions about the future of the Entra App Proxy. Will it still be needed? Should I still use it? Are there synergies or incompatibilities?
This blog post is dedicated to these very questions and is part of my series on Global Secure Access
Overview to Global Secure Access Global Secure Access in Conditional Access Deep Dive DNS in Entra Private Access Deep Dive SSO in Entra Private Access Entra Private Access and the future of the Entra App Proxy Do I still need the App Proxy?</description></item><item><title>Deep Dive SSO in Entra Private Access</title><link>https://chris-brumm.com/2024/09/14/Deep-Dive-SSO-in-Entra-Private-Access/</link><pubDate>Sat, 14 Sep 2024 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2024/09/14/Deep-Dive-SSO-in-Entra-Private-Access/</guid><description>A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time now and more and more proof of concepts are being launched, it is high time for me to do a blog series about it.
Here is an overview of the parts (planned so far):
Overview to Global Secure Access Global Secure Access in Conditional Access Deep Dive DNS in Entra Private Access Deep Dive SSO in Entra Private Access Entra Private Access and the future of the Entra App Proxy With the addition of both UDP and DNS support to Entra Private Access, the vast majority of scenarios that VPN has been used for in the past can be covered - including Single Sign On with Kerberos.</description></item><item><title>Deep Dive DNS in Entra Private Access</title><link>https://chris-brumm.com/2024/09/07/Deep-Dive-DNS-in-Entra-Private-Access/</link><pubDate>Sat, 07 Sep 2024 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2024/09/07/Deep-Dive-DNS-in-Entra-Private-Access/</guid><description>A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time now and more and more proof of concepts are being launched, it is high time for me to do a blog series about it.
Here is an overview of the parts (planned so far):
Overview to Global Secure Access Global Secure Access in Conditional Access Deep Dive DNS in Entra Private Access Deep Dive SSO in Entra Private Access Entra Private Access and the future of the Entra App Proxy With the extension of Entra Private Access, which introduces both UDP and DNS support, the vast majority of scenarios for which VPN was used in the past can be covered.</description></item><item><title>Global Secure Access in Conditional Access</title><link>https://chris-brumm.com/2024/08/06/Global-Secure-Access-in-Conditional-Access/</link><pubDate>Tue, 06 Aug 2024 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2024/08/06/Global-Secure-Access-in-Conditional-Access/</guid><description>A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time now and more and more proof of concepts are being launched, it is high time for me to do a blog series about it.
Here is an overview of the parts (planned so far):
Overview to Global Secure Access Global Secure Access in Conditional Access Deep Dive DNS in Entra Private Access Deep Dive SSO in Entra Private Access Entra Private Access and the future of the Entra App Proxy In the overview to Global Secure Access, I particularly emphasized the good integration in Conditional Access for both Microsoft Entra Internet Access and Microsoft Entra Private Access.</description></item><item><title>Overview to Global Secure Access</title><link>https://chris-brumm.com/2024/07/30/Overview-to-Global-Secure-Access/</link><pubDate>Tue, 30 Jul 2024 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2024/07/30/Overview-to-Global-Secure-Access/</guid><description>A few days ago, Microsoft announced that Global Secure Access is now generally available. Since I have been working with the product for some time now and more and more proof of concepts are being launched, it is high time for me to do a blog series about it.
Here is an overview of the parts (planned so far):
Overview to Global Secure Access Global Secure Access in Conditional Access Deep Dive DNS in Entra Private Access Deep Dive SSO in Entra Private Access Entra Private Access and the future of the Entra App Proxy What is Global Secure Access?</description></item><item><title>Microsoft Entra MFA Fraud Deep Dive</title><link>https://chris-brumm.com/2023/10/07/Microsoft-Entra-MFA-Fraud-Deep-Dive/</link><pubDate>Sat, 07 Oct 2023 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/2023/10/07/Microsoft-Entra-MFA-Fraud-Deep-Dive/</guid><description>Microsoft Entra MFA Fraud Deep Dive Tags: Entra, ITDR, MFA Published at: October 7, 2023 Summary:
Recently, Microsoft released the new feature Report suspicious activity for Entra ID. Since I see this feature as a significant improvement and have faced some challenges with the old feature in the past, I have decided to delve deeper into the topic and share my findings here.
Now, you might be wondering what makes this feature special.</description></item><item><title/><link>https://chris-brumm.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/about/</guid><description>About Me 👋 Hi, I’m Chris - I am a big fan of Microsoft Cloud Security products because there my two favorite topics Identity and Security work together in a unique way. I&amp;rsquo;ve been working in IT for quite a while and have over 15 years of experience in IT security in various roles. At the moment I am a Cybersecurity Architect at glueckkanja AG and help our customers with my favorite topics.</description></item><item><title/><link>https://chris-brumm.com/disclosure/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/disclosure/</guid><description>Legal Disclosure Information in accordance with Section 5 TMG Disclaimer Accountability for content The contents of our pages have been created with the utmost care. However, we cannot guarantee the contents’ accuracy, completeness or topicality. According to statutory provisions, we are furthermore responsible for our own content on these web pages. In this matter, please note that we are not obliged to monitor the transmitted or saved information of third parties, or investigate circumstances pointing to illegal activity.</description></item><item><title/><link>https://chris-brumm.com/notes/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/notes/</guid><description/></item><item><title/><link>https://chris-brumm.com/post/2026/microsoft-traffic-profile/microsoft-traffic-profile-series-references/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/post/2026/microsoft-traffic-profile/microsoft-traffic-profile-series-references/</guid><description>References Thomas Naunheim / Entra ID Attack &amp;amp; Defense Playbook Entra ID Attack &amp;amp; Defense Playbook – PRT/Token Replay Chapter Thomas Naunheim &amp;amp; Sami Lamppu, 2022 (updated 2023). Core reference for PRT, RT, AT token types and attack scenarios. Chris Brumm listed as reviewer.
Entra ID Attack &amp;amp; Defense Playbook – AiTM Chapter Thomas Naunheim &amp;amp; Sami Lamppu, Sept. 2024 (updated Dec. 2024). Covers AiTM attacks, GSA/Compliant Network as mitigation, and KQL hunting queries using NetworkAccessTraffic logs.</description></item><item><title/><link>https://chris-brumm.com/privacy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/privacy/</guid><description>Datenschutzerklärung 1. Datenschutz auf einen Blick Allgemeine Hinweise Die folgenden Hinweise geben einen einfachen Überblick darüber, was mit Ihren personenbezogenen Daten passiert, wenn Sie diese Website besuchen. Personenbezogene Daten sind alle Daten, mit denen Sie persönlich identifiziert werden können. Ausführliche Informationen zum Thema Datenschutz entnehmen Sie unserer unter diesem Text aufgeführten Datenschutzerklärung.
Datenerfassung auf dieser Website Wer ist verantwortlich für die Datenerfassung auf dieser Website? Die Datenverarbeitung auf dieser Website erfolgt durch den Websitebetreiber.</description></item><item><title/><link>https://chris-brumm.com/search/placeholder/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/search/placeholder/</guid><description/></item><item><title/><link>https://chris-brumm.com/speaking/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/speaking/</guid><description>Community Talks (Selected) Year City Conference Title Slides 2026 Copenhagen Experts Live Denmark 2026 Let&amp;rsquo;s get rid of your Entra Connect Sync in 2026 (with Fabian Bader) tbd 2026 Copenhagen Experts Live Denmark 2026 Global Secure Access: Gateway to the Edge, Not the Abyss tbd 2026 Antwerpen MC2MC Connect 2026 Real world attacks abusing your Entra ID application misconfigurations (with Eric Woodruff) tbd 2026 Gorinchem Workplace Ninja Connect 2026 Breaking Up with VPN: Boss‑Fight Strategies for a Smooth Entra Private Access Migration tbd 2025 Dallas,TX Workplace Ninjas US 25 Is Entra Connect Sync Still the Best Choice?</description></item><item><title>Posts Archive</title><link>https://chris-brumm.com/archive/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://chris-brumm.com/archive/</guid><description/></item></channel></rss>