Plain-English daily brief

What changed on this day

53 changes were tracked across 8 Microsoft Entra products. The leading updates include Management for SSH-based server administration; Retire Service Principal Less Authentication; System Preferred Multifactor Authentication.

53 updates

Fundamentals

4

System Preferred Multifactor Authentication

Updated

When a user signs in, the authentication process checks which authentication methods are registered for the user. The user is prompted to sign-in with the most secure method according to the following order. The order of authentication methods is dynamic. It's updated as the security landscape changes, and as better authentication methods emerge. Due to known issues with certificate-based authentication (CBA) and system-preferred MFA, we moved CBA to the bottom of the list. Click the link for more information about each method.

Audit Logs

Updated

A Microsoft Entra documentation page was updated: Audit Logs.

Sign Ins

Updated

A Microsoft Entra documentation page was updated: Sign Ins.

Sign Ups

Updated

A Microsoft Entra documentation page was updated: Sign Ups.

General

3

Groups Settings Cmdlets

Updated

| **GuestUsageGuidelinesUrl**<br>Type: `String`<br>Default: `""` | The URL of a link to the guest usage guidelines. |

Troubleshooting

3

Error Codes

Updated

| AADSTS50102 | Unable to load CustomClaimsTransformer '{type}' was specified for principal '{principalId}'. |

Troubleshoot Macos Platform Single Sign On Extension

Updated

Apple's app-site-association domains are critical for SSO extension functioning. (*) You only need to allow sovereign cloud domains if you rely on those in your environment. (**) Maintaining communications with the Experimentation Configuration Service (ECS) ensures that Microsoft can respond to a severe bug in a timely manner.

Monitoring

2

Architecture

1

Authentication

1

Agent Optimization

Updated

- During the preview, avoid using an account to set up the agent that requires role activation with Privileged Identity Management. Using an account that doesn't have standing permissions might cause authentication failures for the agent.

Provisioning

1

Salesforce Provisioning Tutorial

Updated

If you're using a Salesforce Sandbox environment, see the [Salesforce Sandbox integration article](./salesforce-sandbox-tutorial.md).

Security

1

Standards

1

Governance

10

View activity and audit history for Azure resource roles in Privileged Identity Management

Updated

Privileged Identity Management (PIM) in Microsoft Entra ID, enables you to view activity, activations, and audit history for Azure resources roles within your organization. This includes subscriptions, resource groups, and even virtual machines. Any resource within the Microsoft Entra admin center that uses the Azure role-based access control functionality can take advantage of the security and lifecycle management capabilities in Privileged Identity Management. If you want to keep, audit data for longer than the default retention period, you can use Azure Monitor to route it to an Azure storage account. For more information, see [Archive Microsoft Entra logs to an Azure storage account](~/identity/monitoring-health/howto-archive-logs-to-storage-account.md).

Suggested access packages in My Access (Preview)

Updated

In My Access, Microsoft Entra ID Governance users can see a curated list of suggested access packages in My Access. This capability allows users to quickly view the most relevant access packages for them based off their peers' access packages and previous assignments without scrolling through all their available access packages.

Groups Assign Member Owner

Updated

Follow these steps to make a user eligible member or owner of a group. You need permissions to manage groups. For role-assignable groups, you need to be at least a Privileged Role Administrator role or be an Owner of the group. For non-role-assignable groups, you need to be at least a Directory Writer, Groups Administrator, or Identity Governance Administrator, User Administrator role, or be an Owner of the group. Role assignments for administrators should be scoped at directory level (not administrative unit level).

Pim Apis

Updated

A Microsoft Entra documentation page was updated: Pim Apis.

Architecture

1

Pim Deployment Plan

Updated

* **Groups**- Anyone in a group to get just-in-time access to Microsoft Entra roles and Azure roles. For Microsoft Entra roles, the group must be a newly created cloud group that’s marked as assignable to a role while for Azure roles, the group can be any Microsoft Entra security group. We don't recommend assigning/nesting a group to a PIM for Groups.

Fundamentals

1

Create a custom extension to externally determine the approval requirements for an entitlement management access package

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. While entitlement management natively supports dynamic approvers such as the requestor's manager, second-level manager, or sponsor from a connected organization, these options don't cover all scenarios. With [custom extensions](entitlement-management-logic-apps-integration.md) calling out to [Azure Logic Apps](/azure/logic-apps/logic-apps-overview), you're able to determine approval requirements for access packages at the time of request through an external system. With this external call, you're able to determine approval requirements based on each of the [ApprovalStage properties](/graph/api/resources/approvalstage?view=graph-rest-beta#properties). This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.

General

2

Whats New Docs

Updated

Welcome to what's new in documentation for Microsoft Entra External ID in external tenants. This article lists new docs that were added and docs that were significantly updated in the last three months.

Security

1

Tenant Restrictions V2

Updated

1. Install the [WDAC wizard](/windows/security/application-security/application-control/app-control-for-business/design/appcontrol-wizard)

Fundamentals

1

What Is Global Secure Access

Updated

Microsoft Entra Internet Access protects access to internet and SaaS apps with an identity-based Secure Web Gateway (SWG), blocking threats, unsafe content, and malicious traffic.

Security

1

Security

5

General

4

Microsoft identity platform

2

Standards

2

Authentication

2

Convert hash to bytes for older PowerShell:

Updated

In this set up, the customer administrator manages the application that is used by Entra Connect Sync to authenticate to Entra, the application permissions and certificate credential used by the application. The administrator [registers a Microsoft Entra app and creates a service principal.](graph/tutorial-applications-basics?tabs=http#register-an-application-with-microsoft-entra-id.md). The application should be assigned the required [permissions](#microsoft-graph-permissions-for-byoa)

General

3

Enable Multi Geo

Updated

> - Mulit-Geo doesn't support Japan region selection through Microsoft Entra admin center.

Monitoring

1

View Deployment Logs

Updated

1. Navigate to **Global Secure Access** > **Monitor** > **Deployment logs**.