← Previous day

Next day →
Microsoft Entra daily update

What changed on this day

171 changes were tracked across 7 Microsoft Entra products. The leading updates include Configure Transport Layer Security inspection (Preview); Secretless authentication in Azure; Licensing Authentication.

171 updates

General

43

Delegate By Task

Updated

A Microsoft Entra documentation page was updated: Delegate By Task.

Manage Stale Devices

Updated

Because a stale device is defined as a registered device that hasn't been used to access any cloud apps for a specific timeframe, detecting stale devices requires a timestamp-related property. In Microsoft Entra ID, this property is called **ApproximateLastSignInDateTime** or **activity timestamp**. If the delta between now and the value of the **activity timestamp** exceeds the timeframe you've defined for active devices, a device is considered to be stale.

Privileged Role Feature Include

Updated

A [Global Administrator](~/identity/role-based-access-control/permissions-reference.md#global-administrator) is needed to manage this feature.

Reply Url

Updated

A Microsoft Entra documentation page was updated: Reply Url.

Scopes Oidc

Updated

A Microsoft Entra documentation page was updated: Scopes Oidc.

Datawiza Sso Mfa Oracle Ebs

Updated

- [Video: Enable SSO and MFA for Oracle JD Edwards with Microsoft Entra ID via Datawiza](https://www.youtube.com/watch?v=_gUGWHT5m90)

Datawiza Sso Oracle Jde

Updated

* Video [Enable SSO and MFA for Oracle JDE) with Microsoft Entra ID via Datawiza](https://www.youtube.com/watch?v=_gUGWHT5m90)

Authentication

22

Secretless authentication in Azure

Updated

Learn about secretless authentication in Azure to reduce credential risks, enhance security, and streamline user experience with Zero Trust principles.

Licensing Authentication

Updated

The following table lists features that are available for authentication in the various versions of Microsoft Entra ID. Plan out your needs for securing user sign-in, then determine which approach meets those requirements. For example, although Microsoft Entra ID Free provides security defaults with multifactor authentication, only Microsoft Authenticator can be used for the authentication prompt, including text and voice calls. This approach might be a limitation if you can't make sure that Authenticator is installed on a user's personal device.

Policy All Users Security Info Registration

Updated

The following policy applies to the selected users, who attempt to register using the combined registration experience. The policy requires users who are not on a trusted network to do multifactor authentication. Users from trusted networks are excluded from this policy.

Macos Psso

Updated

There are three different authentication methods that determine the end-user experience;

Authentication Track Linkable Identifiers

Updated

:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/purview-search-teams-sharepoint-results.png" alt-text="Screenshot of Microsoft Purview portal showing results for SPO and Teams logs.":::

Datawiza Configure Sha

Updated

* [Tutorial: Configure Datawiza to enable Microsoft Entra multifactor authentication and SSO to Oracle JD Edwards](datawiza-sso-oracle-jde.md)

Architecture

11

Fundamentals

9

Sign Ins

Updated

- **How** – The client (Application) used for the sign-in.

Whats New Archive

Updated

The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.

Get Started Premium

Updated

A Microsoft Entra documentation page was updated: Get Started Premium.

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

Microsoft identity platform

7

Standards

4

Application Management Certs Faq

Updated

By default, Microsoft Entra ID configures a certificate to expire after three years after being created automatically during SAML single sign-on configuration. Because you can't change the date of a certificate after you save it, you need to create a new certificate. For steps on how to do so, refer [Customize the expiration date for your federation certificate and roll it over to a new certificate](./tutorial-manage-certificates-for-federated-single-sign-on.md#customize-the-expiration-date-for-your-federation-certificate-and-roll-it-over-to-a-new-certificate).

Troubleshooting

3

Configure risk-based step-up consent using PowerShell

Updated

In this article, you learn how to configure risk-based step-up consent in Microsoft Entra ID. Risk-based step-up consent helps reduce user exposure to malicious apps that make [illicit consent requests](/microsoft-365/security/office-365-security/detect-and-remediate-illicit-consent-grants).

Developer

2

Governance

2

Security

2

Emergency Access Accounts

Updated

Microsoft recommends that organizations have two cloud-only emergency access accounts permanently assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role. These accounts are highly privileged and aren't assigned to specific individuals. The accounts are limited to emergency or "break glass" scenarios where normal accounts can't be used or all other administrators are accidentally locked out. These accounts should be created following the [emergency access account recommendations](/entra/identity/role-based-access-control/security-emergency-access).

Conditional Access

1

Provisioning

1

Governance

20

Entitlement Management Delegate

Updated

* To add a security group or Microsoft 365 group: the user must be permitted to perform the `microsoft.directory/groups/members/update` and `microsoft.directory/groups/owners/update` actions

Fundamentals

1

Troubleshooting

1

General

2

Define Custom Attributes

Updated

You can control which attributes are shown or collected from users during sign-up by configuring the hidden and editable flags for each attribute. These settings aren't currently available in the admin center UI, but you can configure them using Microsoft Graph.

Microsoft identity platform

2

Use Quickstart Idtoken

Updated

**For Azure Active Directory B2C**: The app registration process is the same, but B2C has built-in support in the Azure portal for testing your B2C policies via the **Run user flow** functionality.

Architecture

1

Secure Best Practices

Updated

* Azure AD B2C tenant creation can be controlled using Azure Policy. The policy executes when an Azure subscription is associated to the B2C tenant (a pre-requisite for billing). Customers can limit the creation of Azure AD B2C tenants to specific management groups.

Developer

1

Security

1

Troubleshooting

1

Troubleshoot Alerts

Updated

*Microsoft Entra Domain Services cannot be enabled in an Azure AD B2C Directory.*

Architecture

1

Developer

1

Admin Api

Updated

A Microsoft Entra documentation page was updated: Admin Api.

Security

1

General

19

Authentication

3

Security

3

Block workload identity federation using Azure Policy

Updated

Learn how to use a built-in Azure Policy to block workload identity federation on user-assigned managed identities. Govern the use of federated identity credentials on managed identities so that no one can access Microsoft Entra protected resources from external workloads.

Workload Identity Federation

Updated

Learn how workload identify federation enables secre access to Microsoft Entra protected resources from external software workloads without managing secrets.

Developer

2

Fundamentals

1

Workload identities

Updated

Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.

Microsoft identity platform

1

Standards

1

Security

1

Configure Transport Layer Security inspection (Preview)

Updated

Transport Layer Security (TLS) inspection allows Global Secure Access to decrypt and inspect traffic at edge locations. This inspection enables Global Secure Access to enforce security policies such as threat detection, content filtering, and fine-grained access controls, which enhances protection against threats concealed within encrypted communications.