← Previous day

Next day →
Plain-English daily brief

What changed on this day

100 changes were tracked across 7 Microsoft Entra products. The leading updates include Mandatory Multifactor Authentication; B2c Ief Policy Administrator; Training Videos.

100 updates

Fundamentals

12

Mandatory Multifactor Authentication

Updated

If you're using a federated Identity Provider (IdP), such as Active Directory Federation Services, and your MFA provider is integrated directly with this federated IdP, the federated IdP must be configured to send an MFA claim. For more information, see [Expected inbound assertions for Microsoft Entra MFA](how-to-mfa-expected-inbound-assertions.md).

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

Intune Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).

Monitoring Health

Updated

Learn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.

Usage and insights report

Updated

Learn about the information you can explore using the Usage and insights report in Microsoft Entra ID.

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

Authentication

11

Authentication Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:

Android Qr Code Pin Authentication

Updated

This is configured by the Authentication Policy Administrator through an [app configuration policy for managed Android Enterprise devices](/mem/intune/apps/app-configuration-policies-use-android) on the Microsoft Authenticator App, setting `sdm_suppress_camera_consent` equal to `true`, similar to how the `preferred_auth_method` is configured.

Global Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.

Helpdesk Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).

Refresh Tokens

Updated

| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |

Password Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).

General

10

User Administrator

Updated

> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |

Directory Writers

Updated

> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |

Cloud Device Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

Monitoring

9

Attack Payload Author

Updated

Users in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation. Access to reports is limited to simulations executed by the user, and this role doesn't grant access to aggregate reports such as Training efficacy, Repeat offenders, Training completion, or User coverage.

How to manage inactive user accounts

Updated

Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.

Howto Use Workbooks

Updated

Learn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.

Developer

4

Partner Tier2 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

Partner Tier1 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

Application Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.

Hybrid Identity Administrator

Updated

> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |

Security

4

Security Administrator

Updated

> | microsoft.directory/applications/policies/update | Update policies of applications |

Attribute Assignment Reader

Updated

Users with this role can read custom security attribute keys and values for supported Microsoft Entra objects.

Attribute Definition Administrator

Updated

Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.

Standards

4

Security Operator

Updated

> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |

Global Reader

Updated

> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |

Troubleshooting

4

Provisioning

2

Attribute Provisioning Reader

Updated

Users with this role cannot read audit logs for other events. This role must be used in conjunction with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.

Conditional Access

1

Microsoft identity platform

1

Monitoring

1

Azure Information Protection Administrator

Updated

Users with this role have all permissions in the Azure Information Protection service. This role allows configuring labels for the Azure Information Protection policy, managing protection templates, and activating protection. This role doesn't grant any permissions in Microsoft Entra ID Protection, Privileged Identity Management, Monitor Microsoft 365 Service Health, Microsoft Defender XDR portal, or Microsoft Purview portal.

Governance

22

Security Reader

Updated

> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |

Understanding access package visibility in the My Access portal

Updated

The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.

Privileged Role Administrator

Updated

> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |

On Demand Workflow

Updated

A Microsoft Entra documentation page was updated: On Demand Workflow.

Workflows Faqs

Updated

A Microsoft Entra documentation page was updated: Workflows Faqs.

Authentication

3

B2c Ief Policy Administrator

Updated

Users in this role have the ability to create, read, update, and delete all custom policies in Azure AD B2C and therefore have full control over the Identity Experience Framework in the relevant Azure AD B2C organization. By editing policies, this user can establish direct federation with external identity providers, change the directory schema, change all user-facing content (HTML, CSS, JavaScript), change the requirements to complete an authentication, create new users, send user data to external systems including full migrations, and edit all user information including sensitive fields like passwords and phone numbers. Conversely, this role cannot change the encryption keys or edit the secrets used for federation in the organization.

Training Videos

Updated

The video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verifications.

External Identity Provider Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:

Developer

2

B2c Ief Keyset Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users assigned to this role can create and manage policy keys and secrets used for token encryption, token signing, and claim encryption/decryption. They can add new keys to existing key containers, enabling secret rollover without affecting existing applications. Additionally, users in this role can view the complete details of these secrets, including their expiration dates, even after creation.

External Id User Flow Attribute Administrator

Updated

Users with this role add or delete custom attributes available to all user flows in the Microsoft Entra organization. As such, users with this role can change or add new elements to the end-user schema and impact the behavior of all user flows, and indirectly result in changes to what data may be asked of end users and ultimately sent as claims to applications. This role can't edit user flows.

Fundamentals

1

Provisioning

1

Fundamentals

1

General

1

Developer

1

Fundamentals

1

Managed identity sign-in logs

Updated

Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.

Security

1

Attribute Assignment Administrator

Updated

Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.

Conditional Access

1

Developer

1

Version History

Updated

| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |

Monitoring

1