What changed on this day
41 changes were tracked across 6 Microsoft Entra products. The leading updates include Security Defaults; Workload Identity; Registration Mfa Sspr Combined.
Daily.Entra.News41 changes were tracked across 6 Microsoft Entra products. The leading updates include Security Defaults; Workload Identity; Registration Mfa Sspr Combined.
As part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.
By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.
**Service category:** User Experience and Management
In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.
- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)
>
* [Configure group claims for applications by using Microsoft Entra ID](../hybrid/connect/how-to-connect-fed-group-claims.md)
1. Ensure the application is accessible. Sign in directly from the browser on the connector host using the internal URL defined in the Azure portal. If the sign-in succeeds, the application is accessible.
Frontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).
There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)
Learn how Microsoft Entra Tenant Governance automatically establishes governance relationships when you create add-on tenants using secure tenant creation.
Learn about configuration management capabilities in Microsoft Entra Tenant Governance, including baselines and drift monitoring
Learn how to create a new Microsoft Entra tenant using the secure add-on tenant creation workflow in Tenant Governance
Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization
Learn about governance relationships and how they enable centralized management of tenants in Microsoft Entra Tenant Governance
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn which Microsoft Entra Tenant Governance features are available with each license tier, including P1, P2, and ID Governance
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn how to view monitor results and detect configuration drifts in Microsoft Entra Tenant Governance using the admin center
Learn how to set up the required application permissions and roles for tenant monitoring in Microsoft Entra Tenant Governance
Learn about the signals and metrics used in Microsoft Entra Tenant Governance to identify and evaluate related tenants
Learn how to terminate a governance relationship between tenants in Microsoft Entra Tenant Governance and understand what resources are removed
Learn how to update an existing governance relationship between a governing and governed tenant in Microsoft Entra Tenant Governance
Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change
Learn about cross-tenant delegated administration and how it enables centralized management across tenants in Microsoft Entra
Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Learn how to set up a governance relationship between a governing and governed tenant using the handshake process in Microsoft Entra
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
**May**:
1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.
Learn how to monitor and audit governing tenant administrator activity in your governed tenant using sign-in and audit logs
Learn about Microsoft Entra Tenant Governance and how it helps organizations discover, manage, and govern tenants across their environment
"requestedCredentials": [
The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.
> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).
A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.
1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).