Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management and new automation features

Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management
Microsoft released version 1.2.0 of the Microsoft Entra PowerShell module, introducing production-ready support for Agent Identity Blueprints, enhanced application configuration parameters, and modernized invitation APIs. This update consolidates Agent Identity functionality into the main module and delivers new cmdlets for automated identity management across Microsoft Entra ID environments.

Source

Disable weak RC4 encryption on Active Directory domain controllers to prevent Kerberoasting attacks exploiting Kerberos vulnerability CVE-2026-20833

Prevent Kerberoasting in Active Directory
Microsoft has initiated a critical security hardening phase for Windows Active Directory domain controllers to address CVE-2026-20833, a Kerberos vulnerability that enables Kerberoasting attacks by allowing attackers to exploit weak RC4 encryption. The January 2026 security updates mark the beginning of a phased transition that will disable RC4 encryption by default and enforce AES-SHA1 as the standard encryption method for Kerberos authentication.

Source

Syncing passkeys with Microsoft Entra ID

Microsoft Entra ID introduces synced passkeys to simplify multi-factor authentication and reduce the security risks associated with traditional methods such as passwords and SMS codes. This feature, announced at Microsoft Ignite 2025, enables users to authenticate with biometrics or device PINs without entering passwords when syncing credentials across devices via cloud-based passkey providers. The implementation also includes high-assurance account recovery using government-issued ID verification to restore access when users lose all authentication methods.

Source

Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update

Microsoft is enforcing stricter Content Security Policy (CSP) for Entra ID authentication, blocking unauthorized scripts from executing during sign-in. Organizations using browser extensions or third-party tools that inject scripts into login.microsoftonline.com must identify and replace these tools before enforcement, as they will stop functioning while users can still sign in successfully.

Source

UserLock 13.0: IAM for Active Directory with granular MFA, contextual access controls, and real-time session management

IS Decisions’ UserLock is an identity-and-access-management (IAM) tool that adds multi-factor authentication (MFA), contextual access controls, session management, and login auditing to on-premises (or hybrid) Microsoft Active Directory environments to secure and manage all user access. UserLock 13.0 introduces a redesigned interface and strengthened security features for Active Directory environments. The release focuses on simplified navigation, certificate-based authentication, and improved remote access management while maintaining the solution's core identity and access management capabilities.

Source

New features in Microsoft Entra: WebView2, AI Agents ID, synced passkeys

Recent Microsoft Entra and Windows updates introduce multiple changes across authentication, identity management, and access control. The updates include an option to replace the legacy EdgeHTML WebView with the Chromium-based WebView2 for Entra ID authentication flows, improved identity constructs for AI agents, public preview support for synced passkeys, and expanded self-service account recovery. Additional changes cover jailbreak detection in Microsoft Authenticator, enforcement of a stricter Content Security Policy for browser-based sign-ins, updates to session revocation behavior, and new capabilities in Entra ID Governance, External ID, and Global Secure Access.

Source

Self-service password reset with SMS in Microsoft Entra External ID

Microsoft Entra External ID now supports SMS-based verification for self-service password reset (SSPR), providing external users an additional recovery method beyond email one-time passcodes. The feature entered public preview in September 2025 and includes built-in fraud protection through integration with Microsoft's Phone Reputation platform.

Source

New Windows 11 25H2 Group Policy settings

Windows 11 version 25H2 introduces 42 new Group Policy settings for administrators to manage system behavior, security features, and user interface customization. The update includes options for controlling AI features like Copilot and Recall, removing preinstalled Store apps, and configuring enhanced security protocols for printing and network communications.

Source

AD replication error 8418: The replication operation failed because of a schema mismatch between the servers involved

Active Directory domain controllers running Windows Server 2025 with the schema master FSMO role may create duplicate schema attribute values when performing Exchange Server schema extensions, causing replication failures across the entire forest. This issue triggers this error message: Error 8418: The replication operation failed because of a schema mismatch between the servers involved. The issue affects environments attempting to deploy Exchange Server cumulative updates or Exchange Server Subscription Edition. Microsoft has acknowledged this as a known issue in KB5065426.

Source

Understanding the interaction between Microsoft Defender for Identity and Secure Score

Microsoft Defender for Identity and Microsoft Secure Score work together to strengthen identity security across on-premises Active Directory and cloud-based Microsoft Entra ID environments by detecting threats and providing actionable recommendations. This article explains how both tools interact, their technical requirements, and what the new recommendations announced in September 2025 mean for organizations.

Source

❌