Correction

Correction: Azure Active Directory (Entra ID) Concepts for AZ-500 and AZ-104

Corrected by Melik Can Sariyer · Software Engineer and Linux OS Developer

Melik Can Sariyer found something wrong, outdated, or unsupported on this page and proposed a fix. The publisher accepted the correction.

Role
Correction
Publisher
Pass4Sure
Status
Accepted
Date
11 July 2026

The exact change

Before

The Heineken security team's publicly described Entra ID hardening project moved over three hundred privileged users into eligible-only assignments in 2022, with average activation time under three minutes. / "The tenant is the security boundary that most teams underestimate..." -- Alex Simons, Corporate VP of Identity Program Management at Microsoft / The Microsoft Defender for Identity team and security researcher John Lambert have published detection patterns that align directly with these signals.

After

Organizations that have publicly described Entra ID hardening projects, including large enterprises like Heineken, have reported moving groups of privileged users from permanent to eligible-only assignments as part of zero-standing-privilege initiatives (unsourced specific figure generalized). / The tenant is the security boundary that many teams underestimate; subscriptions, resource groups, and management groups are management constructs, and the tenant is where identity actually lives (unattributed prose). / Microsoft security researchers, including John Lambert (Microsoft CVP and Security Fellow), have published detection guidance around identity risk signals that align with the concepts tested here (generalized, specific quote removed).

Suggested change

Generalized an unsourced customer statistic, de-attributed one unverifiable quote, and generalized another to remove an unverifiable specific claim while keeping the underlying point.

Why this is better

A fabricated Heineken '300 privileged users' specific statistic was generalized since the precise figure could not be verified. A quote attributed to Alex Simons had no locatable source and was de-attributed. A claim attributed to John Lambert was generalized after confirming his real title (Microsoft CVP and Security Fellow) but not the specific quote/claim.

How this record is verified

  • The contribution is tied to a real, identified contributor, not an anonymous byline.
  • It counts only because the publisher, Pass4Sure, accepted it. Self-claimed work earns nothing.
  • It is recorded against a specific page and cannot be bought or edited after the fact.

All of Melik Can Sariyer's contributions →