What I like most is how naturally it fits into the Microsoft ecosystem. Since we were already using M365, a lot of things worked out of the box, which reduced the initial setup effort. Features like Single-Sign-On and conditional access policies have been particularly useful. They allow us to control access based on user roles, devices, or locations without making the user experience overly complicated. It also simplified the onboarding and offboarding processes, which used to be so much more manual.
April 21, 2026
In our situation we have an IT team autopilot a device to get ready for a user. They become the primary user and stay that way unless we change them. In Config Manager, it could automatically adjust primary user based on usage. It doesn't seem like that is an option here. It seems to be lacking some maintenance options to keep things clean like cleaning up duplicate entra IDs for the same objects. When we go to passwordless authentication, there isn't a great way to do this when people have multiple accounts - ie, one regular and one priviledged.
May 13, 2026