Picture of Marius A. Skovli

Marius A. Skovli

Co-founder, Partner & Principal Consultant, Spirhed | MVP Enterprise Mobility, Microsoft | Identity & Endpoint - Security & Management - Zero Trust

https://www.facebook.com/MariusSkovli/

https://twitter.com/MariusSkovli

https://www.linkedin.com/in/mariusskovli/

Works of Marius A. Skovli

Secure Boot certificates expire in June 2026

Microsoft’s Windows UEFI CA 2011 and Microsoft Corporation KEK CA 2011 expire in June 2026. Every Windows device with Secure Boot enabled needs the 2023 replacement certificates installed in firmware before that, or it will eventually stop receiving boot-level security updates. The deadline is real, the deployment is straightforward, and the inventory across a mixed

Mapping Azure RBAC across management groups, recursively

During an Azure governance review last month, a customer asked a simple question. Who has Owner role assignments in their tenant, and at which level of the management group hierarchy? The Azure portal answered the first half, then asked us to click into every Management Group and Subscription one by one to finish the answer.

Auditing Entra App Registrations: configured vs granted permissions

An app registration in a tenant I reviewed recently had no configured permissions in its manifest. The service principal behind it had been granted Directory.ReadWrite.All anyway, eight months earlier. Nobody on the operations team knew. The grant did not show up in any of the dashboards they checked. That gap, configured permissions versus granted permissions,

Detecting shadow accounts in Entra ID with PowerShell

Reviewing a tenant for an access governance project, I noticed something odd. A senior consultant had three MFA phone numbers registered in Entra ID. Two of them belonged to a guest account from a project two years earlier, created during onboarding and never cleaned up. The account everyone actually used for daily work had none

Making Windows Update visible during Autopilot enrollment

Autopilot makes the first-boot experience for a new Windows device almost magical — until Windows Update kicks in. Then the device sits on the Enrollment Status Page for fifteen, twenty, sometimes forty minutes with no real signal to the user about what is happening. Behind the scenes, PSWindowsUpdate is doing its job under SYSTEM context,

IT/OT convergence isn’t a network problem, it’s a control plane problem

IT/OT convergence is one of those phrases that gets used without anyone agreeing what it means. For some, it’s a vendor pitch. For others, it’s a Wednesday morning meeting where one team explains for the fifth time why the engineering workstation on a plant floor cannot just join Entra ID. After running a few of

Smarter Entra PIM activation with PowerShell

If you live in Microsoft Entra PIM, you click. A lot. Every workday starts the same way — open the portal, find the right role, type a justification, pick a duration, activate, repeat for the next role. After about the fourth click I started looking for a PowerShell shortcut. When I couldn’t find one that

My Experience at CTTT25 in Tallinn

Examining security trends

Piecing together insights from #CTTT25 in Tallinn, I’m exploring advanced security, PAM, and Zero Trust frameworks. Discussing best practices and GenAI’s influential role.

Subscribe to our Tech blog

Stay up to date on the latest news and trends. Don’t miss out our exclusive content and helpful insights.
Scroll to Top
Troll

Contact us

Troll