What changed on this day
100 changes were tracked across 7 Microsoft Entra products. The leading updates include Mandatory Multifactor Authentication; B2c Ief Policy Administrator; Training Videos.
Daily.Entra.News100 changes were tracked across 7 Microsoft Entra products. The leading updates include Mandatory Multifactor Authentication; B2c Ief Policy Administrator; Training Videos.
If you're using a federated Identity Provider (IdP), such as Active Directory Federation Services, and your MFA provider is integrated directly with this federated IdP, the federated IdP must be configured to send an MFA claim. For more information, see [Expected inbound assertions for Microsoft Entra MFA](how-to-mfa-expected-inbound-assertions.md).
A Microsoft Entra documentation page was updated: Configure Security.
author: MicrosoftGuyJFlo
manager: CelesteDG
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).
Learn about how flagged the sign-ins feature can be used for troubleshooting sign-in issues in Microsoft Entra ID.
Learn about the types of activities and events that are captured in Microsoft Entra audit logs and how you can use the logs for troubleshooting.
Learn about the information available on each of the tabs on the Microsoft Entra sign-in log activity details.
Learn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.
Learn about the information you can explore using the Usage and insights report in Microsoft Entra ID.
Learn about the details included in the user provisioning logs in Microsoft Entra ID when a non-Microsoft service provisions users.
A Microsoft Entra documentation page was updated: Whats New.
This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
This is configured by the Authentication Policy Administrator through an [app configuration policy for managed Android Enterprise devices](/mem/intune/apps/app-configuration-policies-use-android) on the Microsoft Authenticator App, setting `sdm_suppress_camera_consent` equal to `true`, similar to how the `preferred_auth_method` is configured.
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
- Create and manage all aspects of custom authentication extensions.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).
| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).
Learn how to access and analyze Microsoft Entra sign-in and audit logs with the Microsoft Graph reporting APIs.
How to download the audit, sign-in, and provisioning log data for manual storage in Microsoft Entra ID.
author: msmimart
author: msmimart
> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
Assign the IoT Device Administrator role to users who need to do the following tasks:
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
Users in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation. Access to reports is limited to simulations executed by the user, and this role doesn't grant access to aggregate reports such as Training efficacy, Repeat offenders, Training completion, or User coverage.
Learn how to configure the Microsoft Entra health monitoring email notifications to monitor and improve the health of your tenant.
Users with this role **cannot** read audit logs for other events.
How to choose the right method for accessing and integrating the activity logs in Microsoft Entra ID.
Learn how to customize the columns and filter of the Microsoft Entra activity logs so you can analyze the results.
Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.
Learn how to use the Microsoft Entra recommendations to monitor and improve the health of your tenant.
Learn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.
Learn how to stream Microsoft Entra activity logs to an event hub for SIEM tool integration and analysis.
> | microsoft.directory/applications/audience/update | Update the audience property for applications |
> | microsoft.directory/applications/audience/update | Update the audience property for applications |
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
> | microsoft.directory/applications/policies/update | Update policies of applications |
Users with this role can read custom security attribute keys and values for supported Microsoft Entra objects.
Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.
Users with this role can read the definition of custom security attributes.
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
Learn how to configure SAML single sign-on between Microsoft Entra ID and a GitHub enterprise with Enterprise Managed Users.
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String||
> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
- Configure diagnostic settings for custom security attributes
Learn how to archive Microsoft Entra activity logs to a storage account through Diagnostic settings.
Learn how to troubleshoot sign-in errors using Microsoft Entra reports in the Microsoft Entra admin center
How to use the Sign-in diagnostic in tool Microsoft Entra ID to troubleshoot sign-in related scenarios.
> [!IMPORTANT]
Users with this role cannot read audit logs for other events. This role must be used in conjunction with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
> | Actions | Description |
Users with this role have all permissions in the Azure Information Protection service. This role allows configuring labels for the Azure Information Protection policy, managing protection templates, and activating protection. This role doesn't grant any permissions in Microsoft Entra ID Protection, Privileged Identity Management, Monitor Microsoft 365 Service Health, Microsoft Defender XDR portal, or Microsoft Purview portal.
> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
A Microsoft Entra documentation page was updated: Check Workflow Execution Scope.
A Microsoft Entra documentation page was updated: Create Lifecycle Workflow.
A Microsoft Entra documentation page was updated: Customize Workflow Email.
A Microsoft Entra documentation page was updated: Customize Workflow Schedule.
A Microsoft Entra documentation page was updated: Delete Lifecycle Workflow.
A Microsoft Entra documentation page was updated: Download Workflow History.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Audits.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Execution Conditions.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Extensibility.
A Microsoft Entra documentation page was updated: Lifecycle Workflow History.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Insights.
A Microsoft Entra documentation page was updated: Lifecycle Workflow On Premises.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Tasks.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Templates.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Versioning.
> | --- | --- |
A Microsoft Entra documentation page was updated: On Demand Workflow.
A Microsoft Entra documentation page was updated: What Are Lifecycle Workflows.
A Microsoft Entra documentation page was updated: Workflows Faqs.
Users in this role have the ability to create, read, update, and delete all custom policies in Azure AD B2C and therefore have full control over the Identity Experience Framework in the relevant Azure AD B2C organization. By editing policies, this user can establish direct federation with external identity providers, change the directory schema, change all user-facing content (HTML, CSS, JavaScript), change the requirements to complete an authentication, create new users, send user data to external systems including full migrations, and edit all user information including sensitive fields like passwords and phone numbers. Conversely, this role cannot change the encryption keys or edit the secrets used for federation in the organization.
The video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verifications.
This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:
This is a [privileged role](../privileged-roles-permissions.md). Users assigned to this role can create and manage policy keys and secrets used for token encryption, token signing, and claim encryption/decryption. They can add new keys to existing key containers, enabling secret rollover without affecting existing applications. Additionally, users in this role can view the complete details of these secrets, including their expiration dates, even after creation.
Users with this role add or delete custom attributes available to all user flows in the Microsoft Entra organization. As such, users with this role can change or add new elements to the end-user schema and impact the behavior of all user flows, and indirectly result in changes to what data may be asked of end users and ultimately sent as claims to applications. This role can't edit user flows.
- Organizations that own multiple Microsoft Entra tenants and want to streamline intra-organization cross-tenant application access.
> Cross-cloud synchronization is currently in PREVIEW.
manager: femila
manager: femila
author: barclayn
Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.
Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
- Cannot manage enterprise applications, application registrations, Conditional Access, or application proxy settings
| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |
Assign the Global Secure Access Log Reader role to users who need to do the following: