Live data from Hacker News

Does Company ‘X’ have an Azure Active Directory Tenant?

shawntabrizi.com

181–190 of 197 posts

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#181

Earlier quoted context omitted.

> It's even worse if you have personal and business accounts tied to the same email address - you never know which one you're using, or which you need I have a friend who managed to do get into this mess, and he's still not sure how he did it. firstname.lastname@companybizname.TLD is apparently linked to two separate identities at Microsoft, one is a business account, one is a "personal" account. Every time he experi…

This is a legacy setup that can no longer be created. Microsoft removed the option to use a custom domain for Microsoft accounts many years ago, but hasn't forced people to change. However, your friend can get out of this scenario by following the instructions on this site: https://support.microsoft.com/en-us/account-billing/change-t... They'll end up with @outlook.com for their Microsoft account. When using Org serv…

> This is a legacy setup that can no longer be created

Thank goodness for that!

> However, your friend can get out of this scenario by following the instructions on this site

Thanks for the tip, will try and walk him through this next time I'm with him.

> hey'll end up with @outlook.com for their Microsoft account

I doubt they actually need/want access to the Microsoft account. They don't use this work email address for any consumer services, as far as I'm aware -although how could one tell what services it could be associated with?

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#182

Earlier quoted context omitted.

> It's even worse if you have personal and business accounts tied to the same email address - you never know which one you're using, or which you need I have a friend who managed to do get into this mess, and he's still not sure how he did it. firstname.lastname@companybizname.TLD is apparently linked to two separate identities at Microsoft, one is a business account, one is a "personal" account. Every time he experi…

I read an explanation from some Microsoft page or rep. that it had to do with making personal purchases in the Windows Store when you're signed in using your business account. IIRC the rationale was that the personal account could persist beyond your employment, so you wouldn't lose any purchases if you switched jobs. If I indeed recall correctly, then that doesn't really make sense. Just force people to make a diffe…

> IIRC the rationale was that the personal account could persist beyond your employment, so you wouldn't lose any purchases if you switched jobs

Except if you lose access to the work email address by switching jobs, surely you're one forgotten password away from permantently losing access to the personal account too? It's linked to your _work_ email (only)...

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#183

Earlier quoted context omitted.

So in that case, every cable company is a local monopoly and shouldn’t be allowed to bundle channels. Doesn’t anyone see how silly this sounds in 2022? Disney is by far the largest entertainment conglomerate. Should they not be allowed to bundle Hulu, Disney and ESPN? Intel has over 80% of the PC market, how much hardware should they be able to bundle on their motherboard? And HN has a habit of calling any big compan…

> every cable company is a local monopoly A regulated monopoly. Key difference. Although of course today "regulated" is largely a legal fiction. Nevertheless, it's not so simple as pointing out who has the most market share. It's a pretty messy area of the law, and the field is heavily tilted by money, even more so than most areas of the law.

It’s not a “messy” area at all. It’s just a misunderstanding of the law. If what you’re saying is truly “illegal”, no court of law has found it so since Office was introduced over 30 years ago.

What’s more likely, that “bundling” as you define it is illegal and has never been prosecuted in over 3 decades or that you don’t understand the law?

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#184

For the HN B2B startups here supporting Google Workspace SSO and not Microsoft Azure SSO, or offering Sign in with Google and not Sign in with Microsoft... why? 85% of big businesses are on the one you don't support. "Results for the Fortune 500 [to see who's on Azure AD using a] CSV with a list of all the Company Names for all 500 companies. Running it through this script, I find that 417, or 83.4% of companies have…

The hate is very big and developers will convince their bosses something is superiour without understanding business needs.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#185

Earlier quoted context omitted.

Unfortunately, unless this changed too recently for me to know about it, that feature is default off and labelled "Experimental" or something. So it's difficult (ask me how I know) for someone who knows way too much about this stuff and has implemented it themselves, to explain to "leadership" why they should change that default.

I don't know the details except that we've been using it since early this year. The docs don't make it seem like there's anything particularly complicated with enabling it[0][1]. [0]: https://learn.microsoft.com/en-us/azure/active-directory/aut... [1]: https://learn.microsoft.com/en-us/azure/active-directory/aut...

It isn't complicated it's just one push button - but it isn't the default and so you're going to need to persuade somebody they should turn it on.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#186

Earlier quoted context omitted.

I read an explanation from some Microsoft page or rep. that it had to do with making personal purchases in the Windows Store when you're signed in using your business account. IIRC the rationale was that the personal account could persist beyond your employment, so you wouldn't lose any purchases if you switched jobs. If I indeed recall correctly, then that doesn't really make sense. Just force people to make a diffe…

> IIRC the rationale was that the personal account could persist beyond your employment, so you wouldn't lose any purchases if you switched jobs Except if you lose access to the work email address by switching jobs, surely you're one forgotten password away from permantently losing access to the personal account too? It's linked to your _work_ email (only)...

Yeah... all I can recall was it never made much sense to me.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#187

For the HN B2B startups here supporting Google Workspace SSO and not Microsoft Azure SSO, or offering Sign in with Google and not Sign in with Microsoft... why? 85% of big businesses are on the one you don't support. "Results for the Fortune 500 [to see who's on Azure AD using a] CSV with a list of all the Company Names for all 500 companies. Running it through this script, I find that 417, or 83.4% of companies have…

There are legions of people who swore off anything M$ years ago when they found alternatives that worked better for them, and they stuck to it.

Here's the perspective from the outside: M$ has billions of lines of code, or more, and they just keep patching their software. They established their way of doing things years ago with DOS and have built on top of that since. That's how the entire industry has done it, but since M$ got so big they can't just refactor things and drop support without a billion people yelling at them, so they keep the old code and just keep patching.

They have so many people banging on their software that most of the failures are caught pretty quickly, but then there are the edge cases that don't fit into daily business activity and M$ gets pwned in that space. Their software is so vast that it doesn't cover their entire decision tree, so on the edges people begin to play around and find things not covered by testing. They might be complicated exploits that tie many things together, but it's not beyond the general public to find them with a little digging. This opens up a full exploit on M$ systems or infrastructure, then they get around to patching it a month or two later.

From the perspective of a CISO this is unacceptable. I prefer my auth software to be explicitly precise.

This might sound crazy to someone who is in an industry where "everyone is doing it", and there appears to be no other way to integrate but with M$. I'll let you know we both feel the same way because it's crazy to use (and pay for) such slovenly designed software.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#188

Earlier quoted context omitted.

This is a legacy setup that can no longer be created. Microsoft removed the option to use a custom domain for Microsoft accounts many years ago, but hasn't forced people to change. However, your friend can get out of this scenario by following the instructions on this site: https://support.microsoft.com/en-us/account-billing/change-t... They'll end up with @outlook.com for their Microsoft account. When using Org serv…

> This is a legacy setup that can no longer be created Thank goodness for that! > However, your friend can get out of this scenario by following the instructions on this site Thanks for the tip, will try and walk him through this next time I'm with him. > hey'll end up with @outlook.com for their Microsoft account I doubt they actually need/want access to the Microsoft account. They don't use this work email address…

They can find connected apps for their consumer account on https://account.live.com/consent/manage.

Re: Does Company ‘X’ have an Azure Active Directory Tenant?

#190

Earlier quoted context omitted.

azure AD presence does not imply they use msft sso as their sso. sso integration when interacting with a fortune 500 will be a minuscule aspect of the arrangement should you get there. an f500 does not simply decide to use your product and do an sso integration et voila. they want a compliance regiment, a custom crafted legal arrangement, risk assessment, probably an onprem discussion, if you’re small enough a straig…

I hope others listen to this and continue to believe that growing through being a great shadow IT option isn’t viable. Makes my life much easier! If you want to be used by business users in a hurry, be under their p-card limit and support their SSO out of the box.

It sounds like this is exactly a path you have taken with B2B PLG. Mind throwing the rest of us a bone and giving a sense of what your seats/month and/or growth in seats/month looks like?
Post reply on HN