← Previous day

Next day →
Plain-English daily brief

What changed on this day

97 changes were tracked across 6 Microsoft Entra products. The leading updates include Authenticate to Microsoft Entra ID using Application Identity; Fido2 Hardware Vendor; Migrate to CrossTenantAccessPolicy Microsoft Graph API v2.

97 updates

Fundamentals

23

Fido2 Hardware Vendor

Updated

The following table includes each FIDO2 security key model listed in MDS version 137 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.

Authentication Oath Tokens

Updated

Users can add and manage OATH tokens at [Security info](https://aka.ms/mysecurityinfo), or they can select **Security info** from **My account**. Software and hardware OATH tokens have different icons.

Mfa Licensing

Updated

| Policy | Security defaults | Conditional Access | Per-user MFA |

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

What Is App Proxy

Updated

| Microsoft Entra ID | Microsoft Entra ID performs the authentication using the tenant directory stored in the cloud. |

Authentication Qr Code

Updated

QR code authentication is a single-factor method in which the PIN (something you know) is a credential.

Users Default Permissions

Updated

| **Area** | **Member user permissions** | **Default guest user permissions** | **Restricted guest user permissions** |

Administration Concepts

Updated

In Domain Services, you can also create a forest *trust* with another domain to allow users to access resources. Depending on your access requirements, you can create the forest trust in different directions.

Datawiza Sso Oracle Jde

Updated

* [Microsoft Entra single sign-on](https://azure.microsoft.com/solutions/active-directory-sso/#overview) - secure and seamless access for users and apps, from any location, using a device

Datawiza Sso Oracle Peoplesoft

Updated

* [Microsoft Entra single sign-on](https://azure.microsoft.com/solutions/active-directory-sso/#overview) - secure and seamless access for users and apps, from any location, using a device

Sspr Policy

Updated

* Microsoft Entra Connect synchronizes identities from your on-premises directory

Token Protection

Updated

| project Id,ConditionalAccessPolicies, Status,UserPrincipalName, AppDisplayName, ResourceDisplayName

General

19

Migration Resources

Updated

| [Tool: Active Directory Federation Services Migration Readiness Script](https://aka.ms/migrateapps/adfstools) | This is a script you can run on your on-premises Active Directory Federation Services (AD FS) server to determine the readiness of apps for migration to Microsoft Entra ID.|

Delegate By Task

Updated

> | Configure notifications | [Contributor](/azure/role-based-access-control/built-in-roles#contributor) | [Owner](/azure/role-based-access-control/built-in-roles#owner) |

Use Vm Token

Updated

| -------------- | -------------------- |

Connect Emergency Ad Fs Certificate Rotation

Updated

If your federation partners can't consume your federation metadata, you must manually send them the public key of your new token-signing / token-decrypting certificate. Send your new certificate public key (.cer file or .p7b if you want to include the entire chain) to all your resource organization or account organization partners (represented in your AD FS by relying party trusts and claims provider trusts). Have the partners implement changes on their side to trust the new certificates.

F5 Big Ip Headers Easy Button

Updated

2. The **View Variables** link in this location may also help root cause SSO issues, particularly if the BIG-IP APM fails to obtain the right attributes from Microsoft Entra ID or another source.

Join Rhel Linux Vm

Updated

Now that the required packages are installed on the VM, join the VM to the managed domain.

Manage Dns

Updated

For more information about managing DNS, see the [DNS tools article on TechNet](/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753579(v=ws.11)).

Prerequisites

Updated

|Windows server 2016 or greater that is or has:|• 4-GB RAM or more</br>• .NET 4.6.2 runtime or greater</br>• domain-joined</br>• PowerShell execution policy set to **RemoteSigned**</br>• TLS 1.2 enabled</br>• if federation is being used, the AD FS severs must be Windows Server 2012 R2 or higher and TLS/SSL certificates must be configured.|

Tutorial Create Instance Advanced

Updated

1. If you choose to create a virtual network, enter a name for the virtual network, such as *myVnet*, then provide an address range, such as *10.0.1.0/24*.

Authentication

8

Datawiza Sso Mfa To Owa

Updated

- See, [Easy authentication and authorization in Microsoft Entra ID with no-code Datawiza](https://www.microsoft.com/security/blog/2022/05/17/easy-authentication-and-authorization-in-azure-active-directory-with-no-code-datawiza/)

Authentication Qr Code

Updated

Users need to [download Teams](https://aka.ms/teamsmobiledownload). The following table lists the minimum Teams version for mobile operating systems. For more information about Teams versions, see [Version update history for the new and classic Microsoft Teams app](/officeupdates/teams-app-versioning).

Howto Vm Sign In Azure Ad Linux

Updated

The extension needs an HTTP connection to install packages and check for the existence of a system identity. It runs in the context of `walinuxagent.service` and requires a change to let the agent know about the proxy settings. Open `/lib/systemd/system/walinuxagent.service` file on the target machine and add the following line after `[Service]`:

Provisioning

8

Sap Successfactors Integration Reference

Updated

This section covers different write-back scenarios. It recommends configuration approaches based on how email and phone number is set up in SuccessFactors.

Define Conditional Rules For Provisioning User Accounts

Updated

> Saving a new scoping filter triggers a new full sync for the application, where all users in the source system are evaluated again against the new scoping filter. If a user in the application was previously in scope for provisioning, but falls out of scope, their account is disabled or deprovisioned in the application. To override this default behavior, refer to [Skip deletion for user accounts that go out of scope](~/identity/app-provisioning/skip-out-of-scope-deletions.md).

Developer

5

Application Proxy Integrate With Traffic Manager

Updated

| **Custom domain certificate** | Domain Name System (DNS): `nam.contoso.com` Subject Alternative Name (SAN): `www.contoso.com` | DNS: `india.contoso.com` SAN: `www.contoso.com` | In the certificate you upload for each app, set the SAN value to the alternate URL. The alternate URL is the URL all users use to reach the app.|

Use Vm Sdk

Updated

| --------------- | ----------- |

Troubleshooting

5

Troubleshoot Conditional Access What If

Updated

To validate that a configuration is appropriate, an administrator could use the What If tool to mimic access, from a location that should be allowed and from a location that should be denied.

Standards

4

Authenticate to Microsoft Entra ID using Application Identity

Updated

Entra Connect creates and uses a [Microsoft Entra Connector account](reference-connect-accounts-permissions#accounts-used-for-microsoft-entra-connect.md) to authenticate and sync identities from Active Directory to Entra ID. This account uses a locally stored password to authenticate with Entra ID. To enhance the security of the Entra Connect and the sync process, the application will now support "Application based Authentication", which uses an Entra ID application based identity and [Oauth 2.0 client credential flow](identity-platform/v2-oauth2-client-creds-grant-flow.md) to authenticate with Entra ID. To enable this, Entra Connect will create a single tenant 3rd party application in customer's Entra ID tenant, register a certificate as the credential for the application, and authorize the application to perform on-premises directory synchronization. Entra Connect will support two ways to manage the certificate used in Application based authentication.

Secure Hybrid Access Integrations

Updated

When users sign in to applications, they use OIDC or SAML. If the applications need to interact with Microsoft Graph or Microsoft Entra protected API, we recommend you configure them to use OIDC. This configuration ensures the JWT is applied to interact with Microsoft Graph. If there's no need for applications to interact with Microsoft Graph, or Microsoft Entra protected APIs, then use SAML.

Tutorial Enforce Secret Standards

Updated

* **Disable symmetric key usage in applications**: Symmetric keys are similar to client secrets in that they're shared between the application and the resource it accesses. This means that if an attacker gains access to the symmetric key, they can impersonate the application and access the resource. Symmetric keys are also more difficult to manage than asymmetric keys, as they require both parties to share the same key.

Security

3

Permissions Reference

Updated

Users with this role have permissions to manage compliance-related features in the Microsoft Purview compliance portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

Protecting Tokens Microsoft Entra Id

Updated

There are several capabilities you can enable to reduce your attack surface area and reduce the risk of successful token compromise. In the next sections we'll cover many Microsoft security capabilities that fall into one of three categories:

Conditional Access

2

Microsoft Entra Conditional Access optimization agent

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

What If Tool

Updated

- Learn more about Conditional Access policy application by using the policies report-only mode in [Conditional Access insights and reporting](howto-conditional-access-insights-reporting.md).

Microsoft identity platform

1

Application Provisioning When Will Provisioning Finish Specific User

Updated

- Some target systems implement request rate limits and throttling, which can impact performance during large sync operations. Under these conditions, an app that receives too many requests too fast might slow its response rate or close the connection. Gallery applications are configured to adhere to the rate limits set by the application developer, with no action required by an administrator configuring provisioning.

Monitoring

1

Troubleshooting

1

Group Writeback Cloud Sync

Updated

**Scenario:** Manage on-premises applications with Active Directory groups that are provisioned from and managed in the cloud. Microsoft Entra Cloud Sync allows you to fully govern application assignments in AD while taking advantage of Microsoft Entra ID Governance features to control and remediate any access related requests.

General

3

Tenant Restrictions Migration

Updated

1. In **Cross-tenant access settings**, [add each domain/tenant as an organization under Organizational settings](cross-tenant-access-settings-b2b-collaboration.yml#add-an-organization).

Microsoft identity platform

2

Migrate To Xtap V2 Api

Updated

Two options are available for migrating your existing policies to the new schema supported by the Microsoft Graph API:

Architecture

1

Multi Tenant User Management Scenarios

Updated

Use an external Identity and Access Management (IAM) solution such as [Microsoft Identity Manager (MIM)](/microsoft-identity-manager/microsoft-identity-manager-2016) as a synchronization engine.

Authentication

1

Authentication Conditional Access

Updated

The following diagram illustrates the authentication flow when a Microsoft Entra organization shares resources with users from other Microsoft Entra organizations. This diagram shows how cross-tenant access settings work with Conditional Access policies, such as multifactor authentication, to determine if the user can access resources. This flow applies to both B2B collaboration and B2B direct connect, except as noted in step 6.

Fundamentals

1

Protected Actions Overview

Updated

> | microsoft.directory/crossTenantAccessPolicy/allowedCloudEndpoints/update | Update allowed cloud endpoints of the cross-tenant access policy|

Fundamentals

1

General

4

Managed Identity Best Practice Recommendations

Updated

If you require that each resource has its own identity, or have resources that require a unique set of permissions and want the identity to be deleted as the resource is deleted, then you should use a system-assigned identity.

Managed Identities Status

Updated

| Azure Cache for Redis | [Managed identity for storage accounts with Azure Cache for Redis](/azure/azure-cache-for-redis/cache-managed-identity) |

Fundamentals

1

Whatis

Updated

|Managed identities for Azure resources|Provide your Azure services with an automatically managed identity in Microsoft Entra ID that can authenticate any Microsoft Entra-supported authentication service, including Key Vault. For more information, see [What is managed identities for Azure resources?](~/identity/managed-identities-azure-resources/overview.md).|

Monitoring

2

Universal Tenant Restrictions

Updated

1. In the logs, look for a **Status** of `302`. This row shows universal tenant restrictions being applied to the traffic.

View Traffic Logs

Updated

Connection logs provide a summary of all associated transactions, including the total transaction count and blocked transactions, allowing for quick identification of any blocked activity.

Fundamentals

1