[{"content":"PowerShell Connect-MgGraph -Scopes \u0026#39;User.Read.All\u0026#39; Get-MgUser -Filter \u0026#34;accountEnabled eq true\u0026#34; -Property DisplayName,UserPrincipalName | Select-Object DisplayName, UserPrincipalName KQL SigninLogs | where TimeGenerated \u0026gt; ago(7d) | where ResultType != 0 | summarize Failures = count() by UserPrincipalName, AppDisplayName | top 10 by Failures desc JSON { \u0026#34;displayName\u0026#34;: \u0026#34;Require MFA for admins\u0026#34;, \u0026#34;state\u0026#34;: \u0026#34;enabledForReportingButNotEnforced\u0026#34; } Table Product Role Entra ID Cloud identity Intune Device management Defender Endpoint/identity XDR Image ","permalink":"https://bean-law.xyz/posts/sample-rendering-test/","summary":"Draft post that exercises code blocks, a table and an image.","title":"Sample Rendering Test"},{"content":"Placeholder body. Replace with a real write-up.\n","permalink":"https://bean-law.xyz/posts/sample-failed-signin-kql/","summary":"Placeholder post for a KQL write-up, to see how the list handles several entries.","title":"Sample - Hunting Failed Sign-ins with KQL"},{"content":"Placeholder body. Replace with a real write-up.\n","permalink":"https://bean-law.xyz/posts/sample-conditional-access-notes/","summary":"Placeholder post showing how a list entry looks with a cover image and a two-line summary.","title":"Sample - Conditional Access Policy Notes"},{"content":"I\u0026rsquo;m Beau LaWalt, a Microsoft 365 Engineer working across Entra, Intune, Defender and hybrid Active Directory. This blog collects technical write-ups, PowerShell/Graph scripts and KQL.\nWhether I\u0026rsquo;m breaking things pushing changes straight to production or learning how the \u0026ldquo;old heads\u0026rdquo; manage this thing called Active Directory, I always find myself finding new and novel ways to get shit done, often from watching the folks in WinAdmins discord, come join the dark side!\n","permalink":"https://bean-law.xyz/about/","summary":"\u003cp\u003eI\u0026rsquo;m Beau LaWalt, a Microsoft 365 Engineer working across Entra, Intune, Defender and hybrid Active Directory.\nThis blog collects technical write-ups, PowerShell/Graph scripts and KQL.\u003c/p\u003e\n\u003cp\u003eWhether I\u0026rsquo;m breaking things pushing changes straight to production or learning how the \u0026ldquo;old heads\u0026rdquo; manage this thing called Active Directory, I always find myself finding new and novel ways to get shit done, often from watching the folks in WinAdmins discord, come join the dark side!\u003c/p\u003e","title":"About"}]