What changed on this day
24 changes were tracked across 2 Microsoft Entra products. The leading updates include Certificate Based Authentication Certificateuserids; Register Passkey With Security Key; Migrate Off Email Claim Authorization.
Daily.Entra.News24 changes were tracked across 2 Microsoft Entra products. The leading updates include Certificate Based Authentication Certificateuserids; Register Passkey With Security Key; Migrate Off Email Claim Authorization.
A Microsoft Entra documentation page was updated: Migrate Off Email Claim Authorization.
| `mobile` |Any string value or `null` | ```user.mobile -eq "value"```|
Microsoft Entra ID provides a rule builder to create and update your important rules more quickly. The rule builder supports the construction of up to five expressions.
Learn how to create a one-way outbound forest to an on-premises AD DS domain in the Microsoft Entra admin center for Microsoft Entra Domain Services
- Avoid the use of the `Match` operator in rules as much as possible. Instead, use the `StartsWith`, `Equals`, or `EndsWith` operator.
In this article, learn how to create and configure a Microsoft Entra Domain Services forest trust to an on-premises Active Directory Domain Services environment using Azure PowerShell.
This article discusses the most common methods that you can use to simplify your rules for dynamic membership groups. Rules that are simpler and more efficient result in better processing times for dynamic groups.
| **Custom OU structure** | **✓** | **✓** |
1. On the **Properties** page for the group, select a **Membership type** value of **Assigned (static)**, **Dynamic User**, or **Dynamic Device**, depending on your desired membership type. For dynamic membership groups, you can use the rule builder to select options for a simple rule or write a membership rule yourself.
:::image type="content" source="./media/groups-dynamic-rule-validation/validate-tab-view-details.png" alt-text="Screenshot that shows detailed results of rule validation.":::
A Microsoft Entra documentation page was updated: Howto Build Services Resilient To Metadata Refresh.
A Microsoft Entra documentation page was updated: V2 Howto Get Appsource Certified.
:::image type="content" border="true" source="media/how-to-register-passkey-with-security-key/inline-registration.png" alt-text="Screenshot of the Add a passkey (FIDO2) option for a more secure sign-in in My Security info.":::
To protect against token theft and replay attacks, explore the types of tokens used in Microsoft Entra and their role in authentication.
2. [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate-byoc)
Self-service password reset (SSPR) gives users in Microsoft Entra ID the ability to change or reset their password, with no administrator or helpdesk involvement. If a user's account is locked or they forget their password, they can follow prompts to unblock themselves and get back to work. This ability reduces helpdesk calls and loss of productivity when a user can't sign in to their device or an application.
By using self-service password reset (SSPR) in Microsoft Entra ID, users can change or reset their password with no administrator or helpdesk involvement. Typically, users open a web browser on another device to access the [SSPR portal](https://aka.ms/sspr). To improve the experience on computers that run Windows 7, 8, 8.1, 10, and 11, you can enable users to reset their password on the Windows sign-in screen.
`[[-Certificate] <System.Security.Cryptography.X509Certificates.X509Certificate2> [-CertificateMapping] <string>]`
- [Conditional Access](../conditional-access/overview.md#license-requirements)
To protect against token theft and replay attacks, explore the types of tokens used in Microsoft Entra, their role in authentication, and strategies.
Learn more about how forest trust work with Microsoft Entra Domain Services
Policies can be applied to all applications in your organization or to specific applications. In this tutorial, you learn:
A Microsoft Entra documentation page was updated: Saml Claims Customization.
1. Create an authorization policy based on the following table: