Kenneth van Surksum - MVP
@kennethvs
Followers
5K
Following
6K
Media
967
Statuses
9K
Microsoft MVP Enterprise Mobility & Security | Modern Workplace Consultant | Workplace Ninja User Group Netherlands | Secure At Work
Amersfoort, the Netherlands
Joined November 2007
🚀 New Conditional Access Baseline (v2025-10) is now live on GitHub! 👉 https://t.co/PccIhklnbE It includes: ✅ JSON export of all CA policies 📄 PDF overview via Merill’s CA Documenter 🧰 Export tooling by Mikael Karlsson Based on my earlier Conditional Access Demystified
github.com
Conditional Access baseline for October 2025. Contribute to kennethvs/cabaseline202510 development by creating an account on GitHub.
1
27
156
RT @Mister_MDM: The Intune MDM Device Certificate and its renewal… Next year (around 03/04 of 2025) every single Intune MDM certificate wi…
0
6
0
Microsoft keeps rolling out new #Copilot features at lightning speed, great for innovation, but risky without #governance. In my new blog I share how to bring order to this fast-moving rollout in Microsoft 365 👇
vansurksum.com
The rapid and widespread rollout of Microsoft 365 Copilot has created a governance challenge for organizations. Features are often enabled before corresponding controls are available, leaving...
1
12
61
Ever feel like Intune takes its time to apply a policy? That behavior isn’t something new…. it goes back to the original “get, set, get” model Microsoft built nearly twenty years ago. The same OMA DM Protocol that once powered Windows Phone became the blueprint for every Intune
1
26
103
Balancing Control & Convenience — Preventing Edge Password Sync on Unmanaged Devices 🖥️ How to secure Microsoft Edge with: ✔️ Conditional Access ✔️ Edge Management Service ✔️ Smart sign-in restrictions Learn how to block password sync safely 👉
vansurksum.com
Introduction Password managers have become a default convenience in modern browsers, including Microsoft Edge. Microsoft now recommends enabling the built-in password manager as part of the Edge...
0
3
25
.@Office365 #Entra and #Microsoft365 are formed from many apps. A recent update exposes additional Microsoft 1st party apps for Conditional Access policies. Most are linked to the My Sign-Ins portal. Here's what's happening: https://t.co/rgvfcerH8o
office365itpros.com
A recent change has exposed the apps used by the My Sign-ins portal for use by conditional access policies. Here's how to find out about the apps.
0
10
31
Ever wondered what those S 1 12 1 entries in your Administrators group actually represent With the new AADSidToNameV2Support feature, Entra group and role SIDs are automatically translated into real names and stored on the device (cached) Here is the blog that explains how it
When you see an S-1-12-1-something SID in (for example) your local Administrators group, you have no idea what it actually represents. Now that’s changing! With the new feature flag active, Windows finally recognizes Entra groups by name. No more guessing which SID, resembles
1
35
138
On this episode of @marketopolis_ Webull ($BULL) CEO Anthony Denier shares how he’s building a trading platform for a faster, smarter generation of retail investors. - Launching Vega, an AI platform that cuts through noise with personalized insights - Turning customers into
2
3
8
When “Block All” in Conditional Access blocks too much… 🔒 Until recently, guest users couldn’t change their MFA methods when you blocked all cloud apps. The My Sign-ins app is now selectable in Conditional Access 🎉 Finally possible: ✅ Limit guests to M365 resources ✅ Keep
vansurksum.com
Introduction Configuring Conditional Access (CA) for guest users can be challenging when you want to strictly limit access to Office 365 and a few essential Microsoft services. Many Entra administr...
0
20
132
🛡️ Identity #Security at its Best🛡️ Our #IdentitySecurity Track dives deep into the challenges & innovations shaping secure identity infrastructures. From token theft protection to Conditional Access. 👉 https://t.co/uZCWUUgYla
#IdentitySummit #MicrosoftEntra #ConditionalAccess
0
4
6
🧠 Deep Dive into Identity Management 🧠 Our #IdentityManagement Track brings together top experts to explore the future of identity in the cloud. From Entra ID to external identities and automation. 👉 https://t.co/uZCWUUgqvC
#IdentitySummit #MicrosoftEntra #IAM #CloudSecurity
2
4
9
Join @Kennethvs & @ErikLoef at AppManagEvent on Oct 11 for “Fighting Adversary in the Middle” — a deep dive into detecting & defending against AiTM attacks. Don’t miss it! #AppmanagEvent #CyberSecurity #MicrosoftSecurity #IdentityProtection
0
1
2
When productivity meets flexibility, security must keep up. In this session, Kenneth van Surksum shows how to protect your data in Microsoft 365 and other SaaS apps, without blocking collaboration. Real-world experience, demos, and practical strategies to secure your workplace.
0
1
5
We just started with our #4 meetup of the year. This time hosted by @proxys in #Hollywoud
@MaartenGoet started the first session where he talks about a decade of ransomware. #wpninjasnl #meetup #community
0
4
6
We’re thrilled to welcome an incredible lineup of speakers from across Europe and the United States @ericonidentity @knudsenmortendk @DijkmanRogier @cbrhh @fabian_bader @svrooij @JanVidarElven @B15joshua @k_shaleen @SanderBerkouwer @kennethvs @vanhybrid @DrAzureAD #IdentitySummit
0
10
19
The Workplace Ninja User Group Netherlands is proud to announce that on Wednesday June 18 2025 we will organize our 4th in-person event in the year 2025. Our next speaker is Maarten Goet. He will talk about A decade of ransomware! More info at https://t.co/TSdnj4BZ6K
0
2
2
Important notice! Today, Windows Autopilot uses the Intune Connector for Active Directory to deploy devices that are Microsoft Entra hybrid joined. To strengthen security in our customers’ environments, we’ve updated the Intune Connector for Active Directory to use a Managed
1
36
125
🚨 Podcast Update: We just released a new WPNinjas NL podcast. Intune What’s New: May 2025 Edition is now available! @oudendorp, @jgelijsteen, @kennethvs and @sanderozemuller discus the latest Intune topics. #podcast #wpninjasnl #community
https://t.co/TQiMbIA793
0
3
5
Het is weer Microsoft Security Meetup met eerste sessie van @kennethvs en @erikloef over Fighting Adversary-in-the-Middle. Dank @Traxion voor het hosten van deze avond.
0
3
4
🔐 Token Protection now supports the Windows App! Tokens are now bound to the device/session—stopping replay on unmanaged endpoints. A big step for secure remote access. Start testing it now! 👉 https://t.co/9A3CASDre0
#Entra #ZeroTrust
learn.microsoft.com
Protect your resources with token protection in Conditional Access policies. Understand requirements, limitations, and deployment best practices.
1
0
0