Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Aujourd’hui — 9 avril 2026Flux principal

Microsoft Entra March 2026: Passkeys GA, backup preview, and Hybrid Security Fix

Par : IT Experts
8 avril 2026 à 17:52
Microsoft entra backup and recovery in admin center (image microsoft)
Microsoft's March 2026 Entra update promotes passkey authentication to general availability, introduces a built-in tenant backup feature in public preview, and announces a breaking security change for hybrid environments, taking effect June 1, 2026. Additional changes enforce TLS 1.2 for Entra Connect Health agents and bring several multi-tenant governance capabilities into preview. This article covers changes relevant to administrators managing Microsoft 365 tenants and hybrid Active Directory environments.

Source

À partir d’avant-hierFlux principal

Pourquoi générer son mot de passe avec l’IA est une très mauvaise idée

21 mars 2026 à 18:22

Et si votre mot de passe aléatoire « généré par IA » était en réalité plus prévisible que vous ne le pensez ? Derrière des chaînes en apparence complexes, les modèles reproduisent des schémas récurrents et manquent d’un ingrédient clé : le hasard. Résultat, une nouvelle surface d’attaque à grande échelle.

Microsoft adds passkeys to Entra ID registration campaigns

Par : IT Experts
18 mars 2026 à 14:41
Configuring registration campaigns in Entra admin center (image Microsoft)
Starting April 2026, Microsoft Registration Campaigns in Entra ID will support Passkeys (FIDO2) as an authentication method, enabling organizations to deploy phishing-resistant credentials. The update introduces significant configuration changes, particularly for tenants using the Microsoft-managed state, where several campaign settings become non-configurable. This rollout is part of Microsoft's broader strategy to eliminate passwords and aligns with the introduction of Windows Hello passkey support for Entra accounts.

Source

Autofill credentials into the Windows authentication dialog fails

Par : IT Experts
17 février 2026 à 17:33
Credential autofill restrictions
The Windows January 2026 security update introduces security hardening that restricts applications from autofilling credentials in Windows authentication dialogs, affecting remote support tools, automated authentication workflows, and screen-sharing applications. This change addresses CVE-2026-20804, a Windows Hello vulnerability that allows biometric injection attacks.

Source

Microsoft to disable NTLM by default in Windows

Par : IT Experts
2 février 2026 à 15:46
Disable NTLM in Windows Server 2025 using Group Policy
Microsoft announced a comprehensive roadmap to phase out the legacy NTLM (New Technology LAN Manager) authentication protocol in favor of more secure Kerberos-based alternatives. The company plans to disable NTLM by default in the next major Windows Server release and associated Windows client versions, marking a significant step toward enhancing Windows security after more than three decades of NTLM usage.

Source

Microsoft Entra ID fixes Conditional Access policy bypass, will enforce MFA sign-in for OIDC-only requests

Par : IT Experts
30 janvier 2026 à 14:43
Grant or block access to resource in Conditional Access (image Microsoft)
Microsoft will improve how Conditional Access policies are enforced in Microsoft Entra ID starting March 27, 2026. This change addresses a security loophole in which policies targeting all resources with specific exclusions could be bypassed in certain authentication scenarios. The rollout continues through June 2026 and forms part of Microsoft's Secure Future Initiative. Because these sign-ins will no longer bypass Conditional Access, users may now be required to complete MFA, meet device compliance requirements, or satisfy other configured Conditional Access controls, such as approved apps, app protection policies, or authentication strength, before accessing the resource.

Source

Specops Secure Access: Multi-factor authentication (MFA) for Remote Desktop Protocol (RDP), and VPN connections in Active Directory

Par : IT Experts
28 janvier 2026 à 14:35
Specops Secure Access supports multiple authentication methods for multi-factor authentication (MFA)
Specops Secure Access is a multi-factor authentication solution that adds a second authentication layer to Windows logon, Remote Desktop Protocol (RDP), and VPN connections in Active Directory environments. It is designed for on-premises or hybrid Active Directory environments and extends MFA to critical Windows access points without replacing Active Directory as the identity store. The solution addresses the growing vulnerability of password-based authentication and helps organizations fulfill compliance requirements for modern cybersecurity standards. It can also help organizations meet cybersecurity insurance requirements by strengthening access controls.

Source

Microsoft Entra ID auto-enables passkey profiles in March 2026

Par : IT Experts
28 janvier 2026 à 14:24
Configure passkey settings (image Microsoft)
Starting March 2026, Microsoft Entra ID will introduce passkey profiles and synced passkeys to general availability, enabling group-based authentication configurations with granular control over device-bound and synced passkeys. Microsoft will automatically enable passkey profiles for tenants that don't opt in during the initial rollout, with existing settings preserved to maintain their current security posture.

Source

Microsoft 365 admin center will block accounts without MFA in February

Par : IT Experts
14 janvier 2026 à 12:32
Microsoft 365 admin center will block accounts without  MFA in February
Microsoft will enforce multi-factor authentication (MFA) for all users signing in to the Microsoft 365 admin center starting February 9, 2026. This critical security measure aims to prevent unauthorized access to administrative accounts that manage tenant configurations, user provisioning, and compliance settings.

Source

Syncing passkeys with Microsoft Entra ID

Par : IT Experts
31 décembre 2025 à 14:15
Microsoft Entra ID introduces synced passkeys to simplify multi-factor authentication and reduce the security risks associated with traditional methods such as passwords and SMS codes. This feature, announced at Microsoft Ignite 2025, enables users to authenticate with biometrics or device PINs without entering passwords when syncing credentials across devices via cloud-based passkey providers. The implementation also includes high-assurance account recovery using government-issued ID verification to restore access when users lose all authentication methods.

Source

❌
❌