What changed on this day
46 changes were tracked across 4 Microsoft Entra products. The leading updates include Enable Passkey Fido2; Compliant Network; Wildcard applications in the Microsoft Entra application proxy.
Daily.Entra.News46 changes were tracked across 4 Microsoft Entra products. The leading updates include Enable Passkey Fido2; Compliant Network; Wildcard applications in the Microsoft Entra application proxy.
1. In your browser:
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#home) as at least a [Billing Administrator](https://go.microsoft.com/fwlink/?linkid=2254515).
A Microsoft Entra documentation page was updated: Powershell Assign Group To App.
A Microsoft Entra documentation page was updated: Powershell Assign User To App.
A Microsoft Entra documentation page was updated: Powershell Display Users Group Of App.
A Microsoft Entra documentation page was updated: Powershell Get All App Proxy Apps Basic.
A Microsoft Entra documentation page was updated: Powershell Get All App Proxy Apps By Connector Group.
A Microsoft Entra documentation page was updated: Powershell Get All App Proxy Apps Extended.
A Microsoft Entra documentation page was updated: Powershell Get All App Proxy Apps With Policy.
A Microsoft Entra documentation page was updated: Powershell Get All Connectors.
A Microsoft Entra documentation page was updated: Powershell Get All Custom Domain No Cert.
A Microsoft Entra documentation page was updated: Powershell Get All Custom Domains And Certs.
A Microsoft Entra documentation page was updated: Powershell Get All Default Domain Apps.
A Microsoft Entra documentation page was updated: Powershell Get All Wildcard Apps.
A Microsoft Entra documentation page was updated: Powershell Get Custom Domain Identical Cert.
A Microsoft Entra documentation page was updated: Powershell Get Custom Domain Replace Cert.
A Microsoft Entra documentation page was updated: Powershell Move All Apps To Connector Group.
1. Select your username in the upper-right corner. Verify you're signed in to a directory that uses application proxy. If you need to change directories, select **Switch directory** and choose a directory that uses application proxy.
1. **Translate URL in Headers**: Choose **No**.
|Fine grained authorization |Provides access control at the URL level. Added policies can be enforced based on the URL being accessed. The internal URL configured for the app defines the scope of the app that the policy is applied to. The policy configured for the most granular path is enforced. |
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted

In Microsoft Entra ID, configuring a large number of on-premises applications can quickly become unmanageable and introduces unnecessary risks for configuration errors if many of them require the same settings. With [Microsoft Entra application proxy](overview-what-is-app-proxy.md), you can address this issue by using wildcard application publishing to publish and manage many applications at once. The solution provides:
An end-to-end guide for planning the deployment of application proxy within your organization
author: aanjusingh
- **Cost-effective**. On-premises solutions typically require you to setup and maintain demilitarized zones (DMZs), edge servers, or other complex infrastructures. Application proxy runs in the cloud, which makes it easy to use. To use application proxy, you don't need to change the network infrastructure or install more appliances in your on-premises environment.
1. In the Microsoft Entra admin center, select **Microsoft Entra ID > Enterprise applications** and select **New application**.
Administrator provisioning of security keys is in preview. See [Microsoft Graph and custom clients to provision FIDO2 security keys on behalf of users](https://aka.ms/passkeyprovision).
You can enable single sign-on to your applications using integrated Windows authentication (IWA) by giving private network connectors permission in Active Directory to impersonate users. The connectors use this permission to send and receive tokens on their behalf.
| January | | 99.998% | 99.998% | 99.999% | 99.998% |
1. Confirm your settings and set **Enable policy** to **Report-only**.
Next, open a browser and try again to access the application. You should be prompted for authentication and be able to sign in the application. If you can authenticate, the problem is with the KCD configuration that enables SSO.
The first thing to check is the connector. To learn how to debug a private network connector, see [Debug private network connector issues](application-proxy-debug-connectors.md). If you still have issues connecting to your application, return to this article to troubleshoot the application.
| Management area | On-premises (Active Directory) feature | Equivalent Microsoft Entra feature |
- You can control your branding and create the URLs you want. A custom domain can help build your users' confidence, because users see and use a familiar name instead of *`msappproxy.net`*.
Business logic often lives in a private Application Programming Interface (API). The API runs on premises or in a private cloud. Your native Android, iOS, Mac, or Windows apps need to interact with the API endpoints to use data or provide user interaction. Microsoft Entra application proxy and the [Microsoft Authentication Library (MSAL)](~/identity-platform/reference-v2-libraries.md) let your native apps securely access your private cloud APIs. Microsoft Entra application proxy is a faster and more secure solution than opening firewall ports and controlling authentication and authorization at the app layer.
You don't need to open inbound connections to the corporate network.
A Microsoft Entra documentation page was updated: Identity Protection Risks.
Frequently asked questions about Access Reviews.
While there's no direct "**Stop**" button for a series, you can edit the series to set an earlier end date. This prevents new review instances from being generated after that date.
Organizations who use Conditional Access along with the Global Secure Access, can prevent malicious access to Microsoft apps, third-party SaaS apps, and private line-of-business (LoB) apps using multiple conditions to provide defense-in-depth. These conditions might include device compliance, location, and more to provide protection against user identity or token theft. Global Secure Access introduces the concept of a compliant network within Microsoft Entra ID Conditional Access. This compliant network check ensures users connect via the Global Secure Access service for their specific tenant and are compliant with security policies enforced by administrators.
