Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
À partir d’avant-hierFlux principal

Microsoft Entra ID fixes Conditional Access policy bypass, will enforce MFA sign-in for OIDC-only requests

Par : IT Experts
30 janvier 2026 à 14:43
Grant or block access to resource in Conditional Access (image Microsoft)
Microsoft will improve how Conditional Access policies are enforced in Microsoft Entra ID starting March 27, 2026. This change addresses a security loophole in which policies targeting all resources with specific exclusions could be bypassed in certain authentication scenarios. The rollout continues through June 2026 and forms part of Microsoft's Secure Future Initiative. Because these sign-ins will no longer bypass Conditional Access, users may now be required to complete MFA, meet device compliance requirements, or satisfy other configured Conditional Access controls, such as approved apps, app protection policies, or authentication strength, before accessing the resource.

Source

Microsoft Entra ID auto-enables passkey profiles in March 2026

Par : IT Experts
28 janvier 2026 à 14:24
Configure passkey settings (image Microsoft)
Starting March 2026, Microsoft Entra ID will introduce passkey profiles and synced passkeys to general availability, enabling group-based authentication configurations with granular control over device-bound and synced passkeys. Microsoft will automatically enable passkey profiles for tenants that don't opt in during the initial rollout, with existing settings preserved to maintain their current security posture.

Source

Blocking user SyncJacking (account hijacking) in Microsoft Entra Connect

Par : IT Experts
27 janvier 2026 à 16:30
Syncjacking exploiting synchronization for account takeover
Microsoft Entra Connect will enforce new security hardening measures starting March 2026 to prevent SyncJacking, a sophisticated attack technique that exploits synchronization mechanisms to hijack privileged accounts in hybrid identity environments.

Source

Security Baseline for Microsoft 365 Apps for enterprise v2512: Intune and Group Policy deployment

Par : IT Experts
23 janvier 2026 à 15:24
Security Baseline for M365 Apps for enterprise v2512
Microsoft just announced the Security Baseline for Microsoft 365 Apps for enterprise version 2512 ( (v2512, December 2025) as part of the Microsoft Security Compliance Toolkit. This security configuration package aligns with Administrative Templates released in version 5516 and introduces updated policies designed to strengthen protections in Excel, PowerPoint, and core Microsoft 365 Apps components. You can deploy these Microsoft-recommended security configurations through multiple methods including Office cloud policies, Microsoft Intune, or Group Policy to reduce configuration drift and ensure consistent protection across enterprise environments.

Source

Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management and new automation features

Par : IT Experts
21 janvier 2026 à 13:39
Microsoft Entra PowerShell v1.2.0 brings Agent Identity Blueprint management
Microsoft released version 1.2.0 of the Microsoft Entra PowerShell module, introducing production-ready support for Agent Identity Blueprints, enhanced application configuration parameters, and modernized invitation APIs. This update consolidates Agent Identity functionality into the main module and delivers new cmdlets for automated identity management across Microsoft Entra ID environments.

Source

Microsoft Entra certificate change: what admins need to do now

Par : IT Experts
1 janvier 2026 à 16:05
Microsoft will transition Microsoft Entra identity services from DigiCert Global Root G1 to G2 certificates on January 7, 2026. Organizations that do not prepare for this change risk authentication failures across their Microsoft 365 and Azure environments.

Source

Syncing passkeys with Microsoft Entra ID

Par : IT Experts
31 décembre 2025 à 14:15
Microsoft Entra ID introduces synced passkeys to simplify multi-factor authentication and reduce the security risks associated with traditional methods such as passwords and SMS codes. This feature, announced at Microsoft Ignite 2025, enables users to authenticate with biometrics or device PINs without entering passwords when syncing credentials across devices via cloud-based passkey providers. The implementation also includes high-assurance account recovery using government-issued ID verification to restore access when users lose all authentication methods.

Source

Microsoft to block unauthorized scripts in Entra ID logins with 2026 CSP update

Par : IT Experts
18 décembre 2025 à 12:45
Microsoft is enforcing stricter Content Security Policy (CSP) for Entra ID authentication, blocking unauthorized scripts from executing during sign-in. Organizations using browser extensions or third-party tools that inject scripts into login.microsoftonline.com must identify and replace these tools before enforcement, as they will stop functioning while users can still sign in successfully.

Source

New features in Microsoft Entra: WebView2, AI Agents ID, synced passkeys

Par : IT Experts
15 décembre 2025 à 14:49
Recent Microsoft Entra and Windows updates introduce multiple changes across authentication, identity management, and access control. The updates include an option to replace the legacy EdgeHTML WebView with the Chromium-based WebView2 for Entra ID authentication flows, improved identity constructs for AI agents, public preview support for synced passkeys, and expanded self-service account recovery. Additional changes cover jailbreak detection in Microsoft Authenticator, enforcement of a stricter Content Security Policy for browser-based sign-ins, updates to session revocation behavior, and new capabilities in Entra ID Governance, External ID, and Global Secure Access.

Source

Self-service password reset with SMS in Microsoft Entra External ID

Par : IT Experts
15 décembre 2025 à 14:27
Microsoft Entra External ID now supports SMS-based verification for self-service password reset (SSPR), providing external users an additional recovery method beyond email one-time passcodes. The feature entered public preview in September 2025 and includes built-in fraud protection through integration with Microsoft's Phone Reputation platform.

Source

Microsoft Entra PowerShell v1.1.0 removes Graph version pinning, adds device and service principal filtering

Par : IT Experts
11 décembre 2025 à 15:15
Microsoft Entra PowerShell is a module that lets administrators manage and automate Microsoft Entra ID resources—such as users, groups, applications, and policies—via PowerShell, built on and interoperable with the Microsoft Graph PowerShell SDK. ​Microsoft released version 1.1.0 of the Entra PowerShell module, introducing compatibility improvements and new filtering parameters for device and service principal management. The update removes version restrictions for Microsoft Graph PowerShell and adds functionality for administrators managing identity resources.

Source

❌
❌