← Previous day

Next day →
Plain-English daily brief

What changed on this day

78 changes were tracked across 6 Microsoft Entra products. The leading updates include Howto Mfa Nps Extension Rdg; Plan Conditional Access; Copilot Entra Lifecycle Workflow.

78 updates

General

34

Air Tutorial

Updated

1. Select the **Workspace** at the top left corner.

Arcgis Tutorial

Updated

1. In a different web browser window, sign in to your ArcGIS Online company site as an administrator

Ideascale Tutorial

Updated

![Community Settings](./media/ideascale-tutorial/ic790847.png "Community Settings")

Meraki Dashboard Tutorial

Updated

1. In a different web browser window, sign in to your Meraki Dashboard company site as an administrator

Sharefile Tutorial

Updated

![Screenshot shows the Administration page.](./media/sharefile-tutorial/settings.png "Administration")

Smallimprovements Tutorial

Updated

1. In another browser window, sign on to your [Small Improvements](https://small-improvements.com) company site as an administrator.

15five Tutorial

Updated

![Manage Company](./media/15five-tutorial/profile.png "Manage Company")

Amazon Web Service Tutorial

Updated

![Screenshot of AWS services page, with IAM highlighted.](./media/amazon-web-service-tutorial/identity-access-management.png)

Assign Local Admin

Updated

In addition to using the Microsoft Entra join process, you can also manually elevate a regular user to become a local administrator on one specific device. This step requires you to already be a member of the local administrators group.

Clebex Tutorial

Updated

1. In a different web browser window, sign in to your Clebex company site as an administrator

Coupa Tutorial

Updated

1. Sign on to your Coupa company site as an administrator.

Egnyte Tutorial

Updated

1. Sign in to your **Egnyte** company site as administrator.

Fm Systems Tutorial

Updated

1. In a web browser window, sign into your FM:Systems company site as an administrator.

Intelligencebank Tutorial

Updated

1. In a different web browser window, sign in to your IntelligenceBank company site as an administrator.

Kintone Tutorial

Updated

![Users & System Administration](./media/kintone-tutorial/user.png "Users & System Administration")

Leadfamly Tutorial

Updated

1. In a different web browser window, sign into Leadfamly website as an administrator.

Panorama9 Tutorial

Updated

1. In a different web browser window, sign in to your Panorama9 company site as an administrator.

Podbean Tutorial

Updated

1. In a different web browser window, sign in to Podbean as an Administrator.

Replicon Tutorial

Updated

1. In a web browser window, sign into your Replicon company site as an administrator.

Slack Tutorial

Updated

1. In a different web browser window, sign in to your up Slack company site as an administrator

Sugarcrm Tutorial

Updated

![Screenshot shows the Administration section where you can select User Management.](./media/sugarcrm-tutorial/ic795893.png "Administration")

Teamseer Tutorial

Updated

1. Sign in to your **TeamSeer** company site as an administrator.

Timeoffmanager Tutorial

Updated

1. In a different web browser window, sign into your TimeOffManager company site as an administrator.

Whos On Location Tutorial

Updated

1. In a different browser window, sign on to your WhosOnLocation company site as administrator.

Monitoring

11

Sprinklr Tutorial

Updated

1. In a different web browser window, log in to your Sprinklr company site as an administrator.

Gigya Tutorial

Updated

1. In a different web browser window, log into your Gigya company site as an administrator.

Sumologic Tutorial

Updated

1. In a different web browser window, sign in to your SumoLogic company site as an administrator.

Documo Tutorial

Updated

1. Log in to your Documo website as an administrator.

Teamgo Tutorial

Updated

1. Log in to your Teamgo website as an administrator.

Tulip Tutorial

Updated

1. Log in to your Tulip instance as an Account Owner.

Provisioning

11

Inbound Provisioning Api Curl Tutorial

Updated

1. Log in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Administrator](https://go.microsoft.com/fwlink/?linkid=2247823).

Inbound Provisioning Api Graph Explorer

Updated

1. Log in to [Microsoft Entra admin center](https://entra.microsoft.com) with at least [Application Administrator](https://go.microsoft.com/fwlink/?linkid=2247823) login credentials.

H5mag Provisioning Tutorial

Updated

1. Log in to your [H5mag environment](https://account.h5mag.com/login) and navigate to **[Account](https://account.h5mag.com/account)** > **[Provisioning & SSO](https://account.h5mag.com/account/provisioning)**.

Authentication

3

Howto Mfa Nps Extension Rdg

Updated

Organizations can also integrate NPS with Microsoft Entra multifactor authentication to enhance security and provide a high level of compliance. This helps ensure that users establish two-step verification to sign in to the Remote Desktop Gateway. For users to be granted access, they must provide their username/password combination along with information that the user has in their control. This information must be trusted and not easily duplicated, such as a cell phone number, landline number, application on a mobile device, and so on. RDG currently supports phone call and **Approve**/**Deny** push notifications from Microsoft authenticator app methods for 2FA. For more information about supported authentication methods, see the section [Determine which authentication methods your users can use](howto-mfa-nps-extension.md#determine-which-authentication-methods-your-users-can-use).

Howto Mfa Reporting

Updated

The **Conditional Access** tab of the event details shows you which policy triggered the MFA prompt.

Fundamentals

3

Whats New

Updated

The hybrid reporting agent, used to send a MIM Service event log to Microsoft Entra to surface in password reset and self-service group management reports, is deprecated. The recommended replacement is to use Azure Arc to send the event logs to Azure Monitor. For more information, see: [Microsoft Identity Manager 2016 reporting with Azure Monitor](/microsoft-identity-manager/mim-azure-monitor-reporting).

Authentication Flows

Updated

To aid in troubleshooting protocol tracking related errors, we’ve added a new property called **original transfer method** to the **activity details** section of the Conditional Access **sign-in logs**. This property displays the protocol tracking state of the request in question. For example, for a session in which device code flow was performed previously the **original transfer method** is set to **Device code flow**.

Security

2

Brightidea Tutorial

Updated

1. In a different web browser window, sign in to Brightidea using the administrator credentials.

Standards

2

Tutorial Enforce Secret Standards

Updated

Once you update your application management policy, you can confirm that it's applied by reading the default application management policy again as [shown earlier](#read-your-tenant-application-management-policy). The response should show the updated policy with the restrictions you applied.

Troubleshooting

2

Tshoot Connect Pass Through Authentication

Updated

Navigate to **Microsoft Entra ID** > **Sign-ins** on the [[Microsoft Entra admin center](https://entra.microsoft.com)](https://portal.azure.com/) and click a specific user's sign-in activity. Look for the **SIGN-IN ERROR CODE** field. Map the value of that field to a failure reason and resolution using the following table:

Error Codes

Updated

| AADSTS50048 | SubjectMismatchesIssuer - Subject mismatches Issuer claim in the client assertion. Contact the tenant admin. |

Architecture

1

On Premises Application Provisioning Architecture

Updated

1. The Microsoft Entra provisioning service queries the ECMA Connector Host to see if the user exists. It uses the **matching attribute** as the filter. This attribute is defined in the Microsoft Entra admin center under Enterprise applications -> On-premises provisioning -> provisioning -> attribute matching. It's denoted by the 1 for matching precedence.

Conditional Access

1

Plan Conditional Access

Updated

**Ensure that every app has at least one Conditional Access policy applied**. From a security perspective it's better to create a policy that encompasses **All resources (formerly 'All cloud apps')**. This practice ensures you don't need to update Conditional Access policies every time you onboard a new application.

Governance

1

Fundamentals

1

Copilot Entra Lifecycle Workflow

Updated

This article describes how to work with lifecycle workflows using Security Copilot in the Microsoft Entra admin center. Using this feature requires [Microsoft Entra ID Governance licenses](/entra/id-governance/identity-governance-overview#license-requirements).

Authentication

1

General

1

Standards

1

Inbound Provisioning Api Grant Access

Updated

This configuration registers an app in Microsoft Entra ID that represents the external API client and grants it permission to invoke the inbound provisioning API. The service principal client ID and client secret can be used in the OAuth client credentials grant flow.

Developer

1

Source Ip Anchoring

Updated

1. [Install a private network connector](how-to-configure-connectors.md) in a private network that has outbound connectivity to the destination web application. A good option is to host the connector in an Azure Virtual Network where you control the outbound egress IP. We recommend that you install two or more connectors for resiliency and high availability.

Fundamentals

1

Netskope Integration

Updated

> When you sign up for the Netskope ATP preview, you are implicitly signing up for the TLS preview.

Monitoring

1