What changed on this day
89 changes were tracked across 4 Microsoft Entra products. The leading updates include Security Administrator; Deprecation Key Derivation Function Version 1; Security Operator.
Daily.Entra.News89 changes were tracked across 4 Microsoft Entra products. The leading updates include Security Administrator; Deprecation Key Derivation Function Version 1; Security Operator.
author: owinfreyATL
> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |
> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
A Microsoft Entra documentation page was updated: Permissions Reference.
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
> | --- | --- |
author: MicrosoftGuyJFlo
You can tailor the policy to your needs using the optional **Custom Instructions** field. This setting allows you to provide a prompt to the agent as part of its execution. For example: "The user "Break Glass" should be excluded from policies created." Custom instructions can be used to include or exclude users, groups, and roles. This can be used to exclude them from consideration entirely or for a specific scenario and can also be used to add exceptions to the suggested policy.
author: owinfreyATL
> [!IMPORTANT]
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
> [!div class="mx-tableFixed"]
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
> | --- | --- |
author: owinfreyATL
author: owinfreyATL
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> [!div class="mx-tableFixed"]
Learn how to use the authentication prompts analysis workbook in Microsoft Entra ID to investigate users getting too many MFA prompts.
Learn about the service level agreement performance and attainment for authentication services in Microsoft Entra ID
Learn how to use the sign-ins using legacy authentication workbook in Microsoft Entra ID to identify apps using legacy methods.
author: owinfreyATL
author: owinfreyATL
Reference information for the factors that drive sign-in and audit log latency in Microsoft Entra ID
Learn about the data retention policies for the Microsoft Entra audit, sign-in, and provisioning logs.
> [!div class="mx-tableFixed"]
Learn how to use the identity protection risk analysis workbook in Microsoft Entra ID to explore trends and gaps in your risk policies.
author: shlipsey3
author: shlipsey3
Reference information for Microsoft Graph PowerShell cmdlets for Microsoft Entra monitoring and health.
Learn how the Microsoft Entra recommendation to remove unused apps works and why you should follow the guidance.
Learn how the Microsoft Entra recommendation to remove unused credentials from apps works and why it's important.
Learn how the Microsoft Entra recommendation to renew expiring application credentials works and why it's important.
Learn why you should turn off per user MFA in Microsoft Entra ID with Microsoft Entra recommendations
Learn how to use the MFA Gaps workbook in Microsoft Entra ID to identify apps and users who aren't protected by MFA.
| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |
Get an overview of the audit activities that can be logged in your audit logs in Microsoft Entra ID.
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
Learn how Microsoft Entra audit logs display UserManagement updates from Core Directory during verified domain changes.
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
> | microsoft.directory/applications/audience/update | Update the audience property for applications |
> | microsoft.directory/applications/audience/update | Update the audience property for applications |
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
Learn how to use the Conditional Access gap analyzer workbook in Microsoft Entra ID to ensure resources are properly protected.
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
> | microsoft.directory/applications/policies/update | Update policies of applications |
author: shlipsey3
> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
manager: dougeby
> | Actions | Description |
> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
> [!NOTE]
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
> | --- | --- |
| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.
|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |
Learn how to use the cross-tenant access activity workbook in Microsoft Entra ID to monitor the resources your external users are accessing.
Learn how the Microsoft Entra recommendation to renew expiring service principal credentials work and why it's important.
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.