Microsoft Entra daily update

What changed on this day

46 changes were tracked across 4 Microsoft Entra products. The leading updates include Enable Passkey Fido2; Compliant Network; Wildcard applications in the Microsoft Entra application proxy.

46 updates

General

17

Add Remove User To Group

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#home) as at least a [Billing Administrator](https://go.microsoft.com/fwlink/?linkid=2254515).

Developer

8

Configure Sso

Updated

1. Select your username in the upper-right corner. Verify you're signed in to a directory that uses application proxy. If you need to change directories, select **Switch directory** and choose a directory that uses application proxy.

Application Proxy Configure Single Sign On With Headers

Updated

|Fine grained authorization |Provides access control at the URL level. Added policies can be enforced based on the URL being accessed. The internal URL configured for the app defines the scope of the app that the policy is applied to. The policy configured for the most granular path is enforced. |

Fundamentals

5

Wildcard applications in the Microsoft Entra application proxy

Updated

In Microsoft Entra ID, configuring a large number of on-premises applications can quickly become unmanageable and introduces unnecessary risks for configuration errors if many of them require the same settings. With [Microsoft Entra application proxy](overview-what-is-app-proxy.md), you can address this issue by using wildcard application publishing to publish and manage many applications at once. The solution provides:

What Is App Proxy

Updated

- **Cost-effective**. On-premises solutions typically require you to setup and maintain demilitarized zones (DMZs), edge servers, or other complex infrastructures. Application proxy runs in the cloud, which makes it easy to use. To use application proxy, you don't need to change the network infrastructure or install more appliances in your on-premises environment.

Conceptual Sso Apps

Updated

1. In the Microsoft Entra admin center, select **Microsoft Entra ID > Enterprise applications** and select **New application**.

Authentication

2

Enable Passkey Fido2

Updated

Administrator provisioning of security keys is in preview. See [Microsoft Graph and custom clients to provision FIDO2 security keys on behalf of users](https://aka.ms/passkeyprovision).

Configure Sso With Kcd

Updated

You can enable single sign-on to your applications using integrated Windows authentication (IWA) by giving private network connectors permission in Active Directory to impersonate users. The connectors use this permission to send and receive tokens on their behalf.

Monitoring

2

Sla Performance

Updated

| January | | 99.998% | 99.998% | 99.999% | 99.998% |

Troubleshooting

2

Application Proxy Sign In Bad Gateway Timeout Error

Updated

Next, open a browser and try again to access the application. You should be prompted for authentication and be able to sign in the application. If you can authenticate, the problem is with the KCD configuration that enables SSO.

Application Proxy Troubleshoot

Updated

The first thing to check is the connector. To learn how to debug a private network connector, see [Debug private network connector issues](application-proxy-debug-connectors.md). If you still have issues connecting to your application, return to this article to troubleshoot the application.

Architecture

1

Road To The Cloud Migrate

Updated

| Management area | On-premises (Active Directory) feature | Equivalent Microsoft Entra feature |

Branding

1

Configure Custom Domain

Updated

- You can control your branding and create the URLs you want. A custom domain can help build your users' confidence, because users see and use a familiar name instead of *`msappproxy.net`*.

Microsoft identity platform

1

Application Proxy Secure Api Access

Updated

Business logic often lives in a private Application Programming Interface (API). The API runs on premises or in a private cloud. Your native Android, iOS, Mac, or Windows apps need to interact with the API endpoints to use data or provide user interaction. Microsoft Entra application proxy and the [Microsoft Authentication Library (MSAL)](~/identity-platform/reference-v2-libraries.md) let your native apps securely access your private cloud APIs. Microsoft Entra application proxy is a faster and more secure solution than opening firewall ports and controlling authentication and authorization at the app layer.

Security

1

Fundamentals

1

Governance

3

Access Reviews Faqs

Updated

While there's no direct "**Stop**" button for a series, you can edit the series to set an earlier end date. This prevents new review instances from being generated after that date.

Fundamentals

1

Compliant Network

Updated

Organizations who use Conditional Access along with the Global Secure Access, can prevent malicious access to Microsoft apps, third-party SaaS apps, and private line-of-business (LoB) apps using multiple conditions to provide defense-in-depth. These conditions might include device compliance, location, and more to provide protection against user identity or token theft. Global Secure Access introduces the concept of a compliant network within Microsoft Entra ID Conditional Access. This compliant network check ensures users connect via the Global Secure Access service for their specific tenant and are compliant with security policies enforced by administrators.

Monitoring

1

View Deployment Logs

Updated

![Screenshot of the deployment log activity details.](media/how-to-view-deployment-logs/traffic-activity-details.png)