Entra.News #52: This week in Microsoft Entra
Learn about new certificate based authentication going GA, updates on Azure AD Graph API retirement, GA of Insider Risk condition in CA and more!
👋 Hi, Merill and Joshua here with this week’s round up of the latest news on Microsoft Entra from around the globe 🌍.
There are a few upcoming changes to be aware of including retirements and changes to the sign in page.
Read on for details…
⚡️ Microsoft
🏆 General Availability
Microsoft Entra certificate-based authentication enhancements • Alex Weinert
Microsoft Entra: Insider Risk condition in Conditional Access is GA • Message Center
🏁 Private Preview
QR code sign-in, a new authentication method for Frontline Workers • Microsoft Entra Blog
📖 Read
June 2024 update on Azure AD Graph API retirement • Kristopher Bash
What’s new in Microsoft Entra – June 2024 • Shobhit Sahay (ENTRA)
📺 Watch
Face Check with Microsoft Entra Verified ID - A better way to verify (3 min) • Microsoft Security
What are Access Reviews in Microsoft Entra ID Governance (5 min) • Rodrigo Fonseca
Create Access Reviews in Microsoft Entra ID Governance (6 min) • Rodrigo Fonseca
✨ Microsoft Entra ID - June release notes
Source: What’s new in Microsoft Entra – June 2024
Security update to Entra ID affecting clients which are running old, unpatched builds of Windows
If your Windows devices do not have security updates after July 2021, update Windows to the latest build of your currently supported Windows version to maintain access to Entra ID.
Enhancing the security of Apple devices in the enterprise with hardware bound device identity – 2-year notice
Starting in June 2026, all new Entra ID registrations will be bound to the Secure Enclave. As a result, all customers will need to adopt the Microsoft Enterprise SSO plug-in and some of the apps may need to make code changes to adopt the new Secure Enclave based device identity.
Upgrade to the latest version of Microsoft Entra Connect by September 23, 2024
Since September 2023, we have been auto-upgrading Microsoft Entra Connect Sync and Microsoft Entra Connect Health to an updated build as part of a precautionary security-related service change. For customers who have previously opted out of auto-upgrade or for whom auto-upgrade failed, we strongly recommend that you upgrade to the latest versions by September 23, 2024.
Azure AD Graph Retirement
Stage 1: After August 31, 2024, newly created applications will receive an error for any requests to Azure AD Graph APIs.
Stage 2: After January 31, 2025, ALL applications that are using Azure AD Graph APIs will receive an error when making requests to the AAD Graph service.
To identify applications that are using Azure AD Graph APIs, we have provided two Entra recommendations with information about applications and service principals that are actively using Azure AD Graph APIs in your tenant.
AzureAD and MSOnline PowerShell retirement
As of March 30, 2024, the legacy Azure AD PowerShell, Azure AD PowerShell Preview, and MS Online modules are deprecated. These modules will continue to function through March 30, 2025, when they are retired and stop functioning. Migrate your scripts to Microsoft Graph PowerShell SDK or Microsoft Entra PowerShell as soon as possible.
Private Preview – QR code sign-in, a new authentication method for Frontline Workers
With the private preview release of this feature in August 2024, all users in your tenant will see a new link ‘Sign in with QR code’ on navigating to https://login.microsoftonline.com > ‘Sign-in options’ > ‘Sign in to an organization’ page. This new link, ‘Sign in with QR code’, will be visible only on mobile devices (Android/iOS/iPadOS). If you are not participating in the private preview, users from your tenant will not be able to sign-in through this method while we are still in private preview. They will receive an error message if they try to sign-in.
Changes to phone call settings: custom greetings and caller ID
Starting September 2024, phone call settings (custom greetings and caller ID) under Entra's multifactor authentication blade will be moved under the voice authentication method in the authentication method policy.
MS Graph API support for per-user MFA
Starting June 2024, we are releasing the capability to manage user status (Enforced, Enabled, Disabled) for per-user MFA through MS Graph API. Please be aware that the recommended approach to protect users with Microsoft Entra MFA is Conditional Access (for licensed organizations) and security defaults (for unlicensed organizations).
Azure Multi-Factor Authentication Server - 3-month notice
Beginning September 30, 2024, Azure Multi-Factor Authentication Server deployments will no longer service MFA requests. To ensure uninterrupted authentication services and to remain in a supported state, organizations should migrate their users’ authentication data to the cloud-based Azure MFA
Decommissioning of Group Writeback V2 (Public Preview) in Entra Connect Sync - Reminder
The public preview of Group Writeback V2 (GWB) in Entra Connect Sync is no longer available and Connect Sync will no longer support provisioning cloud security groups to Active Directory. Another similar functionality is offered in Entra Cloud Sync, called “Group Provision to AD”
Visual enhancements to the per-user MFA admin configuration experience
As part of ongoing service improvements, we are making updates to the per-user MFA admin configuration experience to align with the look and feel of Entra ID. Starting in August 2024, you will be redirected to the new experience both from the Entra admin center and Azure portal.
Updates to “Target resources” in Microsoft Entra Conditional Access
Starting in September 2024, the Microsoft Entra Conditional Access 'Target resources' assignment will consolidate the "Cloud apps" and "Global Secure Access" options under a new name "Resources".
Upcoming Improvements to Entra ID device code flow
We've refined the messaging and included app details within the device code flow to ensure a more secure and precise user experience. Specifically, we've adjusted headers and calls to action to help your users recognize and respond to security threats more effectively. These changes are designed to help your users make more informed decisions and prevent phishing attacks.
From the community…
☀️ Learn
👮♂️ ID Governance
🌐 Private Access & Internet Access (Microsoft’s SSE)
Entra ID – Global secure access • Julian Rasmussen
📦 Apps
Granular permissions for working with files, list items and lists added to the Graph API! • Vasil Michev
Securing Azure Functions using Azure AD JWT Bearer token authentication for user access tokens • Damien Bowden
🔑 Authentication
Passwords: The Achilles' Heel of Online Security • Ewelina Paczkowska
Cloud Kerberos trust with Windows Hello for Business and Intune – Dual Enrollment…. What? • Joery Van den Bosch
How to Configure Cloud Kerberos Trust to Authenticate an Entra ID Joined Device Using Windows Hello for Business (WHfB)? • Shehan Perera
🤖 DevOps & PowerShell
Using the Get-MgGroup cmdlet in PowerShell • Rudy Mens
Practical Graph: Microsoft Launches Entra PowerShell Module • Tony Redmond
🚦 Conditional Access
Switch from per-user MFA to MFA with Microsoft Entra Conditional Access • Oliver Müller
Prevent Conditional Access bypass with Restricted Management Administrative Units in Entra ID • Jan Bakker
🖥️ Devices
🥷 Security
Detecting Lateral Movement in Entra ID: Cross Tenant Synchronization • Lina Lau
Enforced MFA on the Azure Portal and Emergency Access (breakglass) Accounts • Brian Reid
Enhancing Your Security Posture with Entra ID Audit Logs • Shaun H
Application Security in Microsoft 365 – Common Guidelines • Sruthy
🛍️ External ID - Customers
Using PowerShell to look at an Entra External ID JWT • Rory Braybrook
⚒️ Toolkit
node-jwt-validate - Validate JWT tokens in Node.js. • Waldek Mastykarz
🎙️ Podcasts
Ctrl+Alt+Azure - Entra ID licensing: One person, one license • Jussi Roine, Tobias Zimmergren
📺 Watch
Meet Microsoft Entra PowerShell (45 min) • Aleksandar Nikolić
Echoes of Intrusion: Demystifying commonly used MS Graph API Attacks (40 min) • Miriam Wiesner
Azure Client tools updates and improvements (50 min) • Damien Caro
From Cloudy to Clear: Demystifying Azure Authentication (94 min) • Emanuel Palm
Administrative Units (Restricted Management) - Public Preview (8 min) • Rio Hindle
Conditional Access Part 3: Windows App Protection (MAMWE) (14 min) • Steve Weiner
External Identities Hub Architecture 03 - User Identity Management API (11 min) • Daniel Krzyczkowski
👨🏽💻 Merill’s corner
🪃 Acknowledgement of Country
Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.