← Previous day

Next day →
Microsoft Entra daily update

What changed on this day

30 changes were tracked across 4 Microsoft Entra products. The leading updates include Microsoft Entra Conditional Access optimization agent; Agents; Service Principal Table.

30 updates

Fundamentals

4

Agents

Updated

The [Conditional Access optimization agent](../identity/conditional-access/agent-optimization.md) ensures all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings. In preview, the agent evaluates policies requiring multifactor authentication (MFA), enforces device based controls (device compliance, app protection policies, and Domain Joined Devices), and blocks legacy authentication and device code flow.

Developer

3

Authentication

2

Microsoft Entra Conditional Access optimization agent

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings. In preview, the agent evaluates policies requiring multifactor authentication (MFA), enforces device based controls (device compliance, app protection policies, and Domain Joined Devices), and blocks legacy authentication and device code flow.

Quickstart Desktop App Sign In

Updated

- [Tutorial: Authenticate users to your WPF desktop application](./tutorial-desktop-wpf-dotnet-sign-in-build-app.md)

Conditional Access

1

General

1

Harden Update Ad Fs Pingfederate

Updated

Though the deadline has been extended, if you are not yet on a minimum supported version, you'll experience the following impacts after the original date:

Microsoft identity platform

1

Support Fido2 Authentication

Updated

FIDO2 is supported for Android apps that use MSAL with [BROWSER as the authorization user agent](/entra/msal/android/msal-configuration#authorization_user_agent) or broker integration. Broker is shipped in Microsoft Authenticator, Company Portal, or Link to Windows app on Android.

Monitoring

1

Tutorial Create Log Analytics Workbook

Updated

In addition to querying the data with Kusto Query Language (KQL), you can create a custom workbook for further analysis and alerting. The least privileged role to create or update a workbook is the **Security Administrator** role.

Standards

1

V2 Oauth2 On Behalf Of Flow

Updated

Regardless of which API is identified in the authorization request, the consent prompt is combined with all required permissions configured for the client app. All required permissions configured for each middle tier API listed in the client's required permissions list, which identified the client as a known client application, are also included.

Governance

2

Lifecycle Workflows Tasks Table

Updated

| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |

General

7

Developer

3

Assign Users Groups Roles

Updated

1. Select **All applications** to view a list of all your applications. If your application doesn't appear in the list, use the filters at the top of the **All applications** list to restrict the list, or scroll down the list to locate your application.

Fundamentals

2

Authentication

1

Tutorial: Authenticate users to your WPF desktop application

Updated

This tutorial is the final part of a series that demonstrates building a Windows Presentation Form (WPF) desktop app and preparing it for authentication using the Microsoft Entra admin center. In [Part 1 of this series](./tutorial-desktop-wpf-dotnet-sign-in-prepare-tenant.md), you registered an application and configured user flows in your external tenant. This tutorial demonstrates how to build your .NET WPF desktop app and sign in and sign out a user using Microsoft Entra External ID.

Authentication

1

Service Principal Table

Updated

The Microsoft service principal sign-in logs capture service-to-service authentication events for Microsoft services in your tenant. While not necessary for security investigations, the information can be useful for understanding how your services are interacting with each other.