What changed on this day
171 changes were tracked across 7 Microsoft Entra products. The leading updates include Configure Transport Layer Security inspection (Preview); Secretless authentication in Azure; Licensing Authentication.
Daily.Entra.News171 changes were tracked across 7 Microsoft Entra products. The leading updates include Configure Transport Layer Security inspection (Preview); Secretless authentication in Azure; Licensing Authentication.
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
A tutorial that shows you how to use a Linux VM/VMSS to access Azure resources.
A tutorial that shows you how to use a Windows VM/VMSS to access Azure resources.
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
A Microsoft Entra documentation page was updated: Delegate By Task.
Use the Azure portal:
author: cilwerner
manager: femila
Because a stale device is defined as a registered device that hasn't been used to access any cloud apps for a specific timeframe, detecting stale devices requires a timestamp-related property. In Microsoft Entra ID, this property is called **ApproximateLastSignInDateTime** or **activity timestamp**. If the delta between now and the value of the **activity timestamp** exceeds the timeframe you've defined for active devices, a device is considered to be stale.
A Microsoft Entra documentation page was updated: Microsoft Entra built-in roles.
A Microsoft Entra documentation page was updated: Microsoft Entra Connect: ADSyncTools PowerShell Reference.
A Microsoft Entra documentation page was updated: Microsoft Entra Connect: Version release history.
This page provides PowerShell examples to help you manage your groups in Microsoft Entra ID
A [Global Administrator](~/identity/role-based-access-control/permissions-reference.md#global-administrator) is needed to manage this feature.
A Microsoft Entra documentation page was updated: Reply Url.
A Microsoft Entra documentation page was updated: Scopes Oidc.
A Microsoft Entra documentation page was updated: Tenant Installation Account.
author: OwenRichards1
author: henrymbuguakiarie
author: jenniferf-skc
- [Video: Enable SSO and MFA for Oracle JD Edwards with Microsoft Entra ID via Datawiza](https://www.youtube.com/watch?v=_gUGWHT5m90)
* Video [Enable SSO and MFA for Oracle JDE) with Microsoft Entra ID via Datawiza](https://www.youtube.com/watch?v=_gUGWHT5m90)
Learn about secretless authentication in Azure to reduce credential risks, enhance security, and streamline user experience with Zero Trust principles.
The following table lists features that are available for authentication in the various versions of Microsoft Entra ID. Plan out your needs for securing user sign-in, then determine which approach meets those requirements. For example, although Microsoft Entra ID Free provides security defaults with multifactor authentication, only Microsoft Authenticator can be used for the authentication prompt, including text and voice calls. This approach might be a limitation if you can't make sure that Authenticator is installed on a user's personal device.
Step-by-step guidance to migrate from MFA Server on-premises to Microsoft Entra multifactor authentication
The following policy applies to the selected users, who attempt to register using the combined registration experience. The policy requires users who are not on a trusted network to do multifactor authentication. Users from trusted networks are excluded from this policy.
- A sample SPA that you can access via a URL such as `http://www.contoso.com`:
- An Azure subscription. [Create an account for free](https://azure.microsoft.com/free/?ref=microsoft.com&utm_source=microsoft.com&utm_medium=docs&utm_campaign=visualstudio).
There are three different authentication methods that determine the end-user experience;
author: kengaderdus
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/purview-search-teams-sharepoint-results.png" alt-text="Screenshot of Microsoft Purview portal showing results for SPO and Teams logs.":::
author: justinha
Learn about the supported scenarios and the requirements for configuring certificate-based authentication in solutions with Android devices
A Microsoft Entra documentation page was updated: Authentication Flows App Scenarios.
Learn about the supported scenarios and the requirements for configuring certificate-based authentication for Microsoft Entra ID in solutions with iOS devices
Integrate your Remote Desktop Gateway infrastructure with Microsoft Entra multifactor authentication using the Network Policy Server extension for Microsoft Azure
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory so that the users can then sign into a Linux or other POSIX system using pluggable authentication.
author: Dickson-Mwendia
* [Tutorial: Configure Datawiza to enable Microsoft Entra multifactor authentication and SSO to Oracle JD Edwards](datawiza-sso-oracle-jde.md)
In this tutorial, learn to integrate Microsoft Entra ID with Cloudflare Zero Trust. Build rules based on user identity and group membership. Users authenticate with Microsoft Entra credentials and connect to Zero Trust protected applications.
author: justinha
author: Dickson-Mwendia
author: Dickson-Mwendia
author: justinha
A Microsoft Entra documentation page was updated: Microsoft Entra security operations for consumer accounts.
A Microsoft Entra documentation page was updated: Microsoft Entra security operations for devices.
A Microsoft Entra documentation page was updated: Microsoft Entra security operations for Privileged Identity Management.
A Microsoft Entra documentation page was updated: Microsoft Entra security operations guide for applications.
A Microsoft Entra documentation page was updated: Control external access to resources in Microsoft Entra ID with sensitivity labels.
A Microsoft Entra documentation page was updated: Microsoft Entra fundamentals.
A Microsoft Entra documentation page was updated: Microsoft Entra general operations guide reference.
A Microsoft Entra documentation page was updated: Microsoft Entra Suite deployment scenario - Modernize remote access to on-premises apps with MFA per app.
A Microsoft Entra documentation page was updated: Microsoft Entra Suite deployment scenario - Workforce and guest onboarding, identity, and access lifecycle governance across all your apps.
A Microsoft Entra documentation page was updated: Secure Generative AI with Microsoft Entra.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
- **How** – The client (Application) used for the sign-in.
A Microsoft Entra documentation page was updated: Customer intent: As a Microsoft Entra administrator, I want guidance to so that I can keep my Microsoft Entra tenant in a healthy state..
The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.
Learn about the combined password policy and check for weak passwords in Microsoft Entra ID
A Microsoft Entra documentation page was updated: Get Started Premium.
A Microsoft Entra documentation page was updated: What is delegated administration?.
A Microsoft Entra documentation page was updated: What is self-service sign-up for Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: Whats New.
author: OwenRichards1
author: cilwerner
Learn how developers can request for permissions through consent in the Microsoft identity platform endpoint.
author: omondiatieno
manager: CelesteDG
A Microsoft Entra documentation page was updated: Msal Client Applications.
author: OwenRichards1
By default, Microsoft Entra ID configures a certificate to expire after three years after being created automatically during SAML single sign-on configuration. Because you can't change the date of a certificate after you save it, you need to create a new certificate. For steps on how to do so, refer [Customize the expiration date for your federation certificate and roll it over to a new certificate](./tutorial-manage-certificates-for-federated-single-sign-on.md#customize-the-expiration-date-for-your-federation-certificate-and-roll-it-over-to-a-new-certificate).
author: OwenRichards1
author: OwenRichards1
author: OwenRichards1
In this article, you learn how to configure risk-based step-up consent in Microsoft Entra ID. Risk-based step-up consent helps reduce user exposure to malicious apps that make [illicit consent requests](/microsoft-365/security/office-365-security/detect-and-remediate-illicit-consent-grants).
A Microsoft Entra documentation page was updated: Cloud sync troubleshooting.
A Microsoft Entra documentation page was updated: Troubleshoot Publisher Verification.
author: OwenRichards1
author: cilwerner
<a name='retrieve-the-ids-of-the-users-in-azure-ad'></a>
A Microsoft Entra documentation page was updated: Used by articles entra governance.
Microsoft recommends that organizations have two cloud-only emergency access accounts permanently assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role. These accounts are highly privileged and aren't assigned to specific individuals. The accounts are limited to emergency or "break glass" scenarios where normal accounts can't be used or all other administrators are accidentally locked out. These accounts should be created following the [emergency access account recommendations](/entra/identity/role-based-access-control/security-emergency-access).
A Microsoft Entra documentation page was updated: Include file for referencing attribute role caveat..
- Global Administrator
A Microsoft Entra documentation page was updated: Manage mappings and users in applications that did not match to users in Microsoft Entra ID.
* To add a security group or Microsoft 365 group: the user must be permitted to perform the `microsoft.directory/groups/members/update` and `microsoft.directory/groups/owners/update` actions
This how-to article describes how to assign eligible membership and ownership to a group via pim in an access package.
These steps walk you through creating the group that you will enable to be managed by PIM.
This article describes how to set up a lab environment with SAP ECC for testing.
A Microsoft Entra documentation page was updated: Access Reviews Application Preparation.
A Microsoft Entra documentation page was updated: Archive logs and reporting on entitlement management in Azure Monitor.
A Microsoft Entra documentation page was updated: Configure separation of duties checks for an access package in entitlement management.
A Microsoft Entra documentation page was updated: Configure Verified ID settings for an access package in entitlement management.
A Microsoft Entra documentation page was updated: Create an access package in entitlement management for an application with a single role using PowerShell.
A Microsoft Entra documentation page was updated: Deploy Access Reviews.
A Microsoft Entra documentation page was updated: Entitlement Management Reports.
A Microsoft Entra documentation page was updated: Entitlement Management Roles.
A Microsoft Entra documentation page was updated: Govern access for applications in your environment.
A Microsoft Entra documentation page was updated: Identity Governance Applications Existing Users.
A Microsoft Entra documentation page was updated: Identity Governance Applications Not Provisioned Users.
A Microsoft Entra documentation page was updated: Manage user access with Microsoft Entra access reviews.
A Microsoft Entra documentation page was updated: Preparing user accounts for Lifecycle workflows tutorials.
A Microsoft Entra documentation page was updated: Tutorial: Create customized reports in Azure Data Explorer by using data from Microsoft Entra.
A Microsoft Entra documentation page was updated: Tutorial: Manage access to resources in entitlement management.
A Microsoft Entra documentation page was updated: What are access reviews?.
A Microsoft Entra documentation page was updated: Troubleshoot entitlement management.
You can control which attributes are shown or collected from users during sign-up by configuring the hidden and editable flags for each attribute. These settings aren't currently available in the admin center UI, but you can configure them using Microsoft Graph.
Set up trust between a user-assigned managed identity and an external identity provider to access Microsoft Entra resources without secrets or certificates.
The [Microsoft Authentication Library for JavaScript (MSAL.js)](https://github.com/AzureAD/microsoft-authentication-library-for-js) enables JavaScript developers to authenticate users with social and local identities using [Azure Active Directory B2C](/azure/active-directory-b2c/overview) (Azure AD B2C).
**For Azure Active Directory B2C**: The app registration process is the same, but B2C has built-in support in the Azure portal for testing your B2C policies via the **Run user flow** functionality.
* Azure AD B2C tenant creation can be controlled using Azure Policy. The policy executes when an Azure subscription is associated to the B2C tenant (a pre-requisite for billing). Customers can limit the creation of Azure AD B2C tenants to specific management groups.
The application you build uses the implicit flow, which needs to be enabled.
Set up a trust relationship between an app in Microsoft Entra ID and an external identity provider. This allows a software workload outside of Azure to access Microsoft Entra protected resources without using secrets or certificates.
*Microsoft Entra Domain Services cannot be enabled in an Azure AD B2C Directory.*
A Microsoft Entra documentation page was updated: Microsoft Entra Suite deployment scenario - Secure internet access based on business needs.
A Microsoft Entra documentation page was updated: Admin Api.
A Microsoft Entra documentation page was updated: Customer intent: As an enterprise, we want to enable customers to manage information about themselves by using verifiable credentials..
Documentation for the Azure Policy that can be used to assign managed identities to Azure resources.
Step-by-step instructions for assigning a managed identity access to an Azure resource or another resource.
author: SHERMANOUKO
author: SHERMANOUKO
Recommendations on when to use user-assigned versus system-assigned managed identities
Step-by-step instructions for configuring managed identities for Azure resources on a virtual machine scale set using the Azure portal.
Step-by-step instructions for configuring system and user-assigned managed identities on an Azure VMs.
Description of managed identities for Azure resources work with Azure virtual machines.
Known issues with managed identities for Azure resources.
Create user-assigned managed identities.
Frequently asked questions about managed identities
Steps involved in getting a managed identity recreated in another region
A tutorial that walks you through the process of using a system-assigned managed identity on a virtual machine (VM) to access Azure Resource Manager.
Learn how to use managed identities with Windows VMs using the Azure portal, CLI, PowerShell, Azure Resource Manager template
Step-by-step instructions for viewing the Azure resources that are associated with a user-assigned managed identity
author: SHERMANOUKO
author: SHERMANOUKO
author: SHERMANOUKO
Step-by-step instructions for viewing the service principal of a managed identity.
Explore Azure services and resource types supporting managed identities for secure, credential-free authentication.
Step-by-step instructions for viewing the activities made to managed identities, and authentications carried out by managed identities
Step-by-step instructions and examples for using an Azure VM-managed identities for Azure resources service principal for script client sign-in and resource access.
Learn how to use a built-in Azure Policy to block workload identity federation on user-assigned managed identities. Govern the use of federated identity credentials on managed identities so that no one can access Microsoft Entra protected resources from external workloads.
Learn how workload identify federation enables secre access to Microsoft Entra protected resources from external software workloads without managing secrets.
Important considerations and restrictions for creating a federated identity credential on an app.
Step-by-step instructions for assigning a managed identity access to another application's role.
Code samples for using Azure SDKs with an Azure VM that has managed identities for Azure resources.
Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.
An overview how developers can use managed identities for Azure resources.
Step-by-step instructions and examples for using managed identities for Azure resources on virtual machines to acquire an OAuth access token.
Transport Layer Security (TLS) inspection allows Global Secure Access to decrypt and inspect traffic at edge locations. This inspection enables Global Secure Access to enforce security policies such as threat detection, content filtering, and fine-grained access controls, which enhances protection against threats concealed within encrypted communications.