Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hierFlux principal

Microsoft Entra SCIM 2.0: Now with bidirectional provisioning

Par : IT Experts
14 avril 2026 à 14:53
Entra now supports bidirectional scim provisioning
Microsoft introduced new SCIM 2.0 APIs for Microsoft Entra. The APIs now support bidirectional provisioning, which allows external identity systems to provision users and groups directly into Entra. SCIM (System for Cross-domain Identity Management) is an open internet standard that defines a common HTTP-based protocol for managing user accounts across different systems. Previously, Entra could only push user data to other applications via SCIM. Now, it also accepts incoming SCIM requests. The APIs follow a consumption-based pricing model, require an Azure subscription, and are generally available in the Microsoft public cloud.

Source

Entra ID Conditional Access Optimization Agent: AI-driven policy gap detection

Par : IT Experts
13 avril 2026 à 15:40
Creating a phased rollout plan (image Microsoft)
Microsoft's Conditional Access Optimization Agent uses AI to continuously scan your Microsoft Entra ID environment for policy gaps and recommend remediations. It requires a Microsoft Entra ID P1 license and a Microsoft Security Copilot subscription. Several new features are in public preview, including context-aware recommendations, deep gap analysis across all policies, and phased policy rollouts. This article explains what Conditional Access policies are, how the agent works, what you need to run it, and where its limitations lie.

Source

Microsoft Entra March 2026: Passkeys GA, backup preview, and Hybrid Security Fix

Par : IT Experts
8 avril 2026 à 17:52
Microsoft entra backup and recovery in admin center (image microsoft)
Microsoft's March 2026 Entra update promotes passkey authentication to general availability, introduces a built-in tenant backup feature in public preview, and announces a breaking security change for hybrid environments, taking effect June 1, 2026. Additional changes enforce TLS 1.2 for Entra Connect Health agents and bring several multi-tenant governance capabilities into preview. This article covers changes relevant to administrators managing Microsoft 365 tenants and hybrid Active Directory environments.

Source

Using OpenID Connect (OIDC) for external MFA in Entra ID

Par : IT Experts
26 mars 2026 à 16:20
External MFA in Microsoft Entra ID (image Microsoft)
Microsoft has introduced external Multi-Factor Authentication (MFA) as the new, fully integrated OpenID Connect (OIDC)-based way to connect third-party MFA providers, replacing the Custom Controls mechanism that previously enabled external MFA in a more limited way. Custom Controls will be deprecated on September 30, 2026.

Source

Microsoft adds passkeys to Entra ID registration campaigns

Par : IT Experts
18 mars 2026 à 14:41
Configuring registration campaigns in Entra admin center (image Microsoft)
Starting April 2026, Microsoft Registration Campaigns in Entra ID will support Passkeys (FIDO2) as an authentication method, enabling organizations to deploy phishing-resistant credentials. The update introduces significant configuration changes, particularly for tenants using the Microsoft-managed state, where several campaign settings become non-configurable. This rollout is part of Microsoft's broader strategy to eliminate passwords and aligns with the introduction of Windows Hello passkey support for Entra accounts.

Source

Microsoft Security Dashboard for AI: Aggregate risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview

Par : IT Experts
19 février 2026 à 16:33
Security Dashboard for AI (image Microsoft)
The Microsoft Security Dashboard for AI is a unified governance tool now available in public preview that aggregates real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into a single interactive interface. Designed for CISOs and AI risk leaders, it provides inventory discovery, posture tracking, and remediation paths for AI agents, models, MCP servers, and applications. No additional licensing is required — access is included for organizations that already hold enterprise subscriptions to the relevant Microsoft security products.

Source

Microsoft Entra ID fixes Conditional Access policy bypass, will enforce MFA sign-in for OIDC-only requests

Par : IT Experts
30 janvier 2026 à 14:43
Grant or block access to resource in Conditional Access (image Microsoft)
Microsoft will improve how Conditional Access policies are enforced in Microsoft Entra ID starting March 27, 2026. This change addresses a security loophole in which policies targeting all resources with specific exclusions could be bypassed in certain authentication scenarios. The rollout continues through June 2026 and forms part of Microsoft's Secure Future Initiative. Because these sign-ins will no longer bypass Conditional Access, users may now be required to complete MFA, meet device compliance requirements, or satisfy other configured Conditional Access controls, such as approved apps, app protection policies, or authentication strength, before accessing the resource.

Source

Microsoft Entra ID auto-enables passkey profiles in March 2026

Par : IT Experts
28 janvier 2026 à 14:24
Configure passkey settings (image Microsoft)
Starting March 2026, Microsoft Entra ID will introduce passkey profiles and synced passkeys to general availability, enabling group-based authentication configurations with granular control over device-bound and synced passkeys. Microsoft will automatically enable passkey profiles for tenants that don't opt in during the initial rollout, with existing settings preserved to maintain their current security posture.

Source

Blocking user SyncJacking (account hijacking) in Microsoft Entra Connect

Par : IT Experts
27 janvier 2026 à 16:30
Syncjacking exploiting synchronization for account takeover
Microsoft Entra Connect will enforce new security hardening measures starting March 2026 to prevent SyncJacking, a sophisticated attack technique that exploits synchronization mechanisms to hijack privileged accounts in hybrid identity environments.

Source

Security Baseline for Microsoft 365 Apps for enterprise v2512: Intune and Group Policy deployment

Par : IT Experts
23 janvier 2026 à 15:24
Security Baseline for M365 Apps for enterprise v2512
Microsoft just announced the Security Baseline for Microsoft 365 Apps for enterprise version 2512 ( (v2512, December 2025) as part of the Microsoft Security Compliance Toolkit. This security configuration package aligns with Administrative Templates released in version 5516 and introduces updated policies designed to strengthen protections in Excel, PowerPoint, and core Microsoft 365 Apps components. You can deploy these Microsoft-recommended security configurations through multiple methods including Office cloud policies, Microsoft Intune, or Group Policy to reduce configuration drift and ensure consistent protection across enterprise environments.

Source

Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management and new automation features

Par : IT Experts
21 janvier 2026 à 13:39
Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management
Microsoft released version 1.2.0 of the Microsoft Entra PowerShell module, introducing production-ready support for Agent Identity Blueprints, enhanced application configuration parameters, and modernized invitation APIs. This update consolidates Agent Identity functionality into the main module and delivers new cmdlets for automated identity management across Microsoft Entra ID environments.

Source

❌
❌