What changed on this day
28 changes were tracked across 5 Microsoft Entra products. The leading updates include Add a platform to your app registration; Session Lifetime; Howto Authentication Passwordless Security Key On Premises.
Daily.Entra.News28 changes were tracked across 5 Microsoft Entra products. The leading updates include Add a platform to your app registration; Session Lifetime; Howto Authentication Passwordless Security Key On Premises.
Administrators should limit the number of applications they enforce a policy requiring users to reauthenticate every time with. Triggering reauthentication too frequently can increase security friction to a point that it causes users to experience MFA fatigue and open the door to phishing. Web applications usually provide a less disruptive experience than their desktop counterparts when require reauthentication every time is enabled. We factor for five minutes of clock skew when every time is selected in policy, so that we don’t prompt users more often than once every five minutes.
author: justinha
author: justinha
If your team has determined that native authentication is necessary for your application, follow these steps to enable native authentication in the Microsoft Entra admin center:
author: MicrosoftGuyJFlo

$cloudCred = Get-Credential -Message 'An Active Directory user who is a member of the Hybrid Identity Administrators group for Microsoft Entra ID.'
//...
author: justinha
Open PowerShell and run the following command. Replace the fictitious app ID with the correct ID.
Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Entra ID. This account uses username and password to authenticate requests. To enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Entra or Administrator creates a single tenant third party application in Entra ID and use one of the relevant certificate management options below for the credentials.
:::zone-end
`https://portal.cloud.hashicorp.com/sign-in?conn-id=HCP-SSO-<HCP_ORG_ID>-samlp`
Plan your single sign‑on deployment in Microsoft Entra ID. Streamline role assignments, certificate management, and licensing to ensure uninterrupted access.
Configure user consent settings in Microsoft Entra ID to control when and how users grant permissions to your organization's data. Secure your environment with step‑by‑step guidance.
>[!IMPORTANT]
Learn how to add a platform to your app in Microsoft Entra to securely handle authentication tokens and enhance your application's security.
`https://app.highground.com/#/login/<company-slug>`
author: shlipsey3
The following diagram shows a typical governance lifecycle of an external user gaining access to an access package, with an expiration.
A how-to guide on dynamically determining the approval requirements for an access package externally using a custom extension.
> [!div class="checklist"]
Tenant Restrictions v2 is supported on all clouds however TRv2 is not enforced with request going across cross clouds.
> [!NOTE]
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Discover how to use advanced diagnostics to resolve issues with the Global Secure Access mobile client for Android and iOS.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
manager: femila