← Previous day

Next day →
Microsoft Entra daily update

What changed on this day

36 changes were tracked across 6 Microsoft Entra products. The leading updates include Understand the stages of migrating application authentication from AD FS to Microsoft Entra ID; Migrate To Xtap V2 Api; Troubleshoot App Publishing.

36 updates

Authentication

4

Access Token Claims Reference

Updated

| `acrs` | JSON array of strings | Indicates the Auth Context IDs of the operations that the bearer is eligible to perform. Auth Context IDs can be used to trigger a demand for step-up authentication from within your application and services. Often used along with the `xms_cc` claim. |

Troubleshooting

4

Troubleshoot App Publishing

Updated

- MFA registered guest users remediate their own user risk. The guest user [resets or changes a secured password](https://aka.ms/sspr) at their home tenant (this needs MFA and self service password reset (SSPR) at the home tenant). The secured password change or reset must be initiated on Microsoft Entra ID and not on-premises.

Error Codes

Updated

| AADSTS50088 | Limit on telecom MFA calls reached. Please try again in a few minutes. |

Troubleshoot Macos Platform Single Sign On Extension

Updated

Apple's app-site-association domains are critical for SSO extension functioning. (*) You only need to allow sovereign cloud domains if you rely on those in your environment. (**) Maintaining communications with the Experimentation Configuration Service (ECS) ensures that Microsoft can respond to a severe bug in a timely manner.

Developer

3

Manage Self Service Access

Updated

In this article, you learn how to enable self-service application access using the Microsoft Entra admin center.

Id Token Claims Reference

Updated

|`aud` | String, an App ID GUID | Identifies the intended recipient of the token. In `id_tokens`, the audience is your app's Application ID, assigned to your app in the Azure portal. This value should be validated. The token should be rejected if it fails to match your app's Application ID. |

General

3

Connect Version History

Updated

This article helps you keep track of the versions that have released and the changes in those versions.

Fundamentals

2

What If Tool

Updated

The following conditions are required: identity, target resource, device platform, and client app. All other conditions are optional and are assumed to be set to **none** by default if no value is provided. For definitions of these conditions, see the article [Building a Conditional Access policy](concept-conditional-access-policies.md).

Usage Insights Report

Updated

![Screenshot of the sign-in activity details for a selected application.](./media/concept-usage-insights-report/application-activity-sign-in-detail.png)

Provisioning

2

Configure Entra To Active Directory

Updated

|5. Enable [your configuration](#enable-your-configuration)|Once ready, enable the configuration and users/groups will begin synchronizing|

Group Writeback Cloud Sync

Updated

- [Provision groups to Active Directory using Microsoft Entra Cloud Sync](cloud-sync/how-to-configure-entra-to-active-directory.md)

Architecture

1

Governance Deployment Employee Lifecycle

Updated

Use custom extensions to create workflows using tools like Azure Logic Apps. For workflows, you can enable custom task extensions to call out to external systems. For example, a Joiner workflow with a custom task extension assigns a Microsoft Teams number. Or, when a user becomes a Leaver, a separate workflow grants access to an email account for their manager.

Microsoft identity platform

1

Monitoring

1

View activity logs of application permissions

Updated

Microsoft Entra is a platform that allows you to create and manage applications for your organization. You can grant different permissions to your applications, such as accessing data, or performing actions. It's important to review these permissions periodically to ensure they remain appropriate and secure.

Security

1

Standards

1

Fundamentals

1

Governance

1

Authentication

3

Developer

1

Fundamentals

1

General

1

Security

1

Tenant Restrictions V2

Updated

- Enable client signaling using Windows GPO. You need to check 'Enable firewall protection on MIcrosoft endpoints' and WDAC enablement. See [Block Chrome, Firefox and .NET applications like PowerShell](#block-chrome-firefox-and-net-applications-like-powershell).

Authentication

1

General

2

Current Known Limitations

Updated

- Only the Global Secure Access client for Windows, starting with version 1.8.239.0, is aware of Universal CAE. On other platforms, the Global Secure Access client uses regular access tokens.

Fundamentals

1

Assignment Network

Updated

Administrators can create policies that target specific network locations as a signal along with other conditions in their decision making process. They can include or exclude these network locations as part of their policy configuration. These network locations might include public IPv4 or IPv6 network information, countries/regions, unknown areas that don't map to specific countries/regions, or [Global Secure Access' compliant network](../../global-secure-access/how-to-compliant-network.md).