Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hierFlux principal

Active Directory : les dangers avec les mots de passe compromis

1 avril 2026 à 10:00

La réutilisation des mots de passe représente une menace sérieuse pour les environnements Active Directory : découvrez pourquoi et comment s'en protéger.

Le post Active Directory : les dangers avec les mots de passe compromis a été publié sur IT-Connect.

Windows Kerberos RC4 deprecation: what will break in Active Directory and how to fix it

Par : IT Experts
30 mars 2026 à 15:34
Windows kerberos rc4 deprecation might break active directory authentication
Starting in April 2026, Windows updates will change the default Kerberos ticket issuance behavior to AES-SHA1 for accounts without explicit encryption settings, while RC4 can still be used where explicitly enabled. This change, driven by CVE-2026-20833, affects every Windows Server environment where service accounts or devices still rely on RC4. Any service account, NAS device, or legacy application not explicitly configured for AES-SHA1 encryption may lose authentication capability. This article explains what Kerberos and RC4 are, what will break in April 2026, and what you must do to prevent outages.

Source

Using OpenID Connect (OIDC) for external MFA in Entra ID

Par : IT Experts
26 mars 2026 à 16:20
External MFA in Microsoft Entra ID (image Microsoft)
Microsoft has introduced external Multi-Factor Authentication (MFA) as the new, fully integrated OpenID Connect (OIDC)-based way to connect third-party MFA providers, replacing the Custom Controls mechanism that previously enabled external MFA in a more limited way. Custom Controls will be deprecated on September 30, 2026.

Source

Active Directory : pourquoi l’IA accélère les attaques sur les mots de passe en 2026 ?

12 mars 2026 à 09:00

Découvrez pourquoi et comment renforcer la sécurité des comptes de votre Active Directory en réponse à l'émergence d'attaquants assistés par IA.

Le post Active Directory : pourquoi l’IA accélère les attaques sur les mots de passe en 2026 ? a été publié sur IT-Connect.

Microsoft Entra Connect vs Cloud Sync : quel moteur de synchronisation choisir ?

6 mars 2026 à 10:00

Microsoft Entra Connect Sync et Entra Cloud Sync sont deux outils de synchronisation des identités entre l'Active Directory et Entra ID, mais lequel choisir ?

Le post Microsoft Entra Connect vs Cloud Sync : quel moteur de synchronisation choisir ? a été publié sur IT-Connect.

Enable Windows Group Policy Preferences (GPP) debug logging

Par : IT Experts
4 mars 2026 à 17:42
Enable Preference Logging (image Microsoft)
Starting with the February 2026 preview updates for Windows 11 24H2 and 25H2, Microsoft has made Group Policy Preferences (GPP) debug logging configurable directly in Local Group Policy via gpedit.msc. Previously, these settings were primarily managed through domain-based Group Policy Objects (GPOs); enabling them via Local Group Policy typically required manually copying the GroupPolicyPreferences .admx/.adml templates into the local PolicyDefinitions store. You can now enable per-CSE (client-side extension) event logging and file-based tracing on individual client devices without a domain controller.

Source

Blocking user SyncJacking (account hijacking) in Microsoft Entra Connect

Par : IT Experts
27 janvier 2026 à 16:30
Syncjacking exploiting synchronization for account takeover
Microsoft Entra Connect will enforce new security hardening measures starting March 2026 to prevent SyncJacking, a sophisticated attack technique that exploits synchronization mechanisms to hijack privileged accounts in hybrid identity environments.

Source

Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management and new automation features

Par : IT Experts
21 janvier 2026 à 13:39
Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management
Microsoft released version 1.2.0 of the Microsoft Entra PowerShell module, introducing production-ready support for Agent Identity Blueprints, enhanced application configuration parameters, and modernized invitation APIs. This update consolidates Agent Identity functionality into the main module and delivers new cmdlets for automated identity management across Microsoft Entra ID environments.

Source

Disable weak RC4 encryption on Active Directory domain controllers to prevent Kerberoasting attacks exploiting Kerberos vulnerability CVE-2026-20833

Par : IT Experts
20 janvier 2026 à 17:59
Prevent Kerberoasting in Active Directory
Microsoft has initiated a critical security hardening phase for Windows Active Directory domain controllers to address CVE-2026-20833, a Kerberos vulnerability that enables Kerberoasting attacks by allowing attackers to exploit weak RC4 encryption. The January 2026 security updates mark the beginning of a phased transition that will disable RC4 encryption by default and enforce AES-SHA1 as the standard encryption method for Kerberos authentication.

Source

Syncing passkeys with Microsoft Entra ID

Par : IT Experts
31 décembre 2025 à 14:15
Microsoft Entra ID introduces synced passkeys to simplify multi-factor authentication and reduce the security risks associated with traditional methods such as passwords and SMS codes. This feature, announced at Microsoft Ignite 2025, enables users to authenticate with biometrics or device PINs without entering passwords when syncing credentials across devices via cloud-based passkey providers. The implementation also includes high-assurance account recovery using government-issued ID verification to restore access when users lose all authentication methods.

Source

Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update

Par : IT Experts
18 décembre 2025 à 12:45
Microsoft is enforcing stricter Content Security Policy (CSP) for Entra ID authentication, blocking unauthorized scripts from executing during sign-in. Organizations using browser extensions or third-party tools that inject scripts into login.microsoftonline.com must identify and replace these tools before enforcement, as they will stop functioning while users can still sign in successfully.

Source

UserLock 13.0: IAM for Active Directory with granular MFA, contextual access controls, and real-time session management

Par : IT Experts
16 décembre 2025 à 12:14
IS Decisions’ UserLock is an identity-and-access-management (IAM) tool that adds multi-factor authentication (MFA), contextual access controls, session management, and login auditing to on-premises (or hybrid) Microsoft Active Directory environments to secure and manage all user access. UserLock 13.0 introduces a redesigned interface and strengthened security features for Active Directory environments. The release focuses on simplified navigation, certificate-based authentication, and improved remote access management while maintaining the solution's core identity and access management capabilities.

Source

New features in Microsoft Entra: WebView2, AI Agents ID, synced passkeys

Par : IT Experts
15 décembre 2025 à 14:49
Recent Microsoft Entra and Windows updates introduce multiple changes across authentication, identity management, and access control. The updates include an option to replace the legacy EdgeHTML WebView with the Chromium-based WebView2 for Entra ID authentication flows, improved identity constructs for AI agents, public preview support for synced passkeys, and expanded self-service account recovery. Additional changes cover jailbreak detection in Microsoft Authenticator, enforcement of a stricter Content Security Policy for browser-based sign-ins, updates to session revocation behavior, and new capabilities in Entra ID Governance, External ID, and Global Secure Access.

Source

Self-service password reset with SMS in Microsoft Entra External ID

Par : IT Experts
15 décembre 2025 à 14:27
Microsoft Entra External ID now supports SMS-based verification for self-service password reset (SSPR), providing external users an additional recovery method beyond email one-time passcodes. The feature entered public preview in September 2025 and includes built-in fraud protection through integration with Microsoft's Phone Reputation platform.

Source

❌
❌