← Previous day

Next day →
Microsoft Entra daily update

What changed on this day

18 changes were tracked across 3 Microsoft Entra products. The leading updates include Restrictions on identifier URIs of Microsoft Entra applications; Authenticate to Microsoft Entra ID using Application Identity; Provision custom security attributes from HR sources.

18 updates

General

5

Groups Dynamic Membership

Updated

When the attributes of a user or a device change, the system evaluates all rules for dynamic membership groups in a directory to see if the change would trigger any group additions or removals. If users or devices satisfy a rule on a group, they're added as members of that group. If they no longer satisfy the rule, they're removed. You can't manually add or remove a member of a dynamic membership group.

Fundamentals

3

Microsoft Entra ID: Update to user sign-in with Microsoft Authenticator Lite and Microsoft Authenticator app

New

Microsoft Entra ID will update the user sign-in experience with Microsoft Authenticator Lite and the Microsoft Authenticator app to address accessibility issues. The rollout will occur from late March to late April 2025. Users will see a new message instructing them to refresh notifications if they don’t receive a sign-in request. No admin action is required.

Message CenterMC1050723 on mc.merill.net ↗Plan for change

Security

2

Restrictions on identifier URIs of Microsoft Entra applications

Updated

The [`identifierUri`](#what-are-identifier-uris) - also referred to as `Application ID URI` - property of an Entra application is a required configuration for resource (API) applications. Ensuring the property is configured securely is critical to the application's security.

Prerequisites

Updated

- Domain Administrator or Enterprise Administrator credentials to create the Microsoft Entra Connect cloud sync gMSA (group managed service account) to run the agent service.

Troubleshooting

2

Groups Troubleshooting

Updated

2. If it returns `EnableGroupCreation : True`, then nonadmin users can create groups. To disable this feature:

Developer

1

Provisioning

1

Standards

1

Authenticate to Microsoft Entra ID using Application Identity

Updated

Entra Connect uses the [Microsoft Entra Connector account](entra/identity/hybrid/connect/reference-connect-accounts-permissions#accounts-used-for-microsoft-entra-connect.md) to authenticate and sync identities from Active Directorty to Entra ID. This account uses username and password to authenticate requests. To enhance the security of the service, we are rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Entra will create a single tenant 3rd party application in Entra ID and use one of the two certificate management options below for the credentials.

Governance

1

Entitlement Management Access Package Auto Assignment Policy

Updated

You need to have attributes populated on the users who will be in scope for being assigned access. The attributes you can use in the rules criteria of an access package assignment policy are those attributes listed in [supported properties](../identity/users/groups-dynamic-membership.md#supported-properties), along with [extension attributes and custom extension properties](../identity/users/groups-dynamic-membership.md#extension-attributes-and-custom-extension-properties). These attributes can be brought into Microsoft Entra ID by [patching](../identity/app-provisioning/user-provisioning-sync-attributes-for-mapping.md#create-an-extension-attribute-for-cloud-only-users-using-microsoft-graph) the [user](/graph/api/resources/user), an HR system such as [SuccessFactors](../identity/app-provisioning/sap-successfactors-integration-reference.md), [Microsoft Entra Connect cloud sync](../identity/hybrid/cloud-sync/how-to-attribute-mapping.md) or [Microsoft Entra Connect Sync](../identity/hybrid/connect/how-to-connect-sync-feature-directory-extensions.md). The rules can include up to 15,000 users per policy.

Troubleshooting

2