AAD

Entra ID – Automatically remediate user risk with on-premises password change (preview)

It is becoming easier to manage user risk in hybrid environments with Entra ID Protection (formerly known as Azure AD Identity Protection). Indeed, user risk policy requires to change the password when the user is identified at risk. However, the change of password was not detected by Entra Protection signals when the change was performed […]

Entra ID – Automatically remediate user risk with on-premises password change (preview) Read More »

Entra ID – You can now use Employee hire date in dynamic groups (preview)

As you probably already know, Microsoft has introduced some time ago the Employee hire date attribute in Microsoft Entra ID (formerly known as Azure AD). Well, good news as you can now use this attribute in dynamic group. The Employee hire date (employeeHireDate) is a string type. You can use either Greater Than or Equal

Entra ID – You can now use Employee hire date in dynamic groups (preview) Read More »

Entra ID – It is now easier to identify privileged administration roles

Entra ID (aka Azure AD) now allows you to quickly identified privileged administration roles. While it is obvious for some roles (such as Global Administrator), some others may be more subject to your own understanding/interpretation of the role. To help you, Entra ID is now showing a privileged tag, which can also be used as

Entra ID – It is now easier to identify privileged administration roles Read More »

Azure / Azure AD – Administrators can now reset user’s password from the Azure mobile app

By now, Azure administrators should be aware about the Azure mobile application for Android or iOS. Few month ago, Microsoft has started to include access to your Azure AD tenant from the Azure mobile application (see https://t.co/ayBZHVODXx). Well, this access has been now improved as you can now reset user’s password from the application. NOTE

Azure / Azure AD – Administrators can now reset user’s password from the Azure mobile app Read More »

Azure AD / Intune – Local Administrator Password Solution is now generally available

It has been a long awaited capability and has been in preview for quite some time. In preparation for its general availability, Local Administrator Password Solution (LAPS) has been included in Windows – both client and server – thanks to the April updates (see https://t.co/8fpzOY7f7x). Well, good news as LAPS is now generally available –

Azure AD / Intune – Local Administrator Password Solution is now generally available Read More »

Azure AD – You can now publish multiple internal URLs with a single Application Proxy and validate backend SSL certificate

As you may know, you can publish internal web applications using Azure AD Application Proxy. Until now, when you had to publish multiple different internal URLs, you had to create one Application Proxy for each URL. Well, good news as now you can publish multiple internal web application using only one Application Proxy. The first

Azure AD – You can now publish multiple internal URLs with a single Application Proxy and validate backend SSL certificate Read More »

Azure AD – Update your Conditional Access policies if you are using ‘require approved client app’ before March 2026

If you are using the grant control ‘Require approved client app’ in your Conditional Access policies, you need to update and migrate to use the grant control ‘Require application protection policy’ before March 2026. At this date, the control ‘Require approved client app’ will no longer be enforced and will act as if it was

Azure AD – Update your Conditional Access policies if you are using ‘require approved client app’ before March 2026 Read More »

Azure AD – You can use conditional access for PIM (preview)

As you know with Azure AD (P1 or P2) you can protect access to your workloads using Conditional Access. Well, you can now also use Conditional Access when used with PIM (Privileged Identity Management) (in preview), or more specifically when protected actions are being used. The below protected actions are currently supported: Update basic properties

Azure AD – You can use conditional access for PIM (preview) Read More »

Azure AD – New authentication method – Authenticator Lite (preview)

A new authentication method called Authenticator Lite is available in preview. Authenticator Lite allows end-users to perform multifactor authentication without the Microsoft Authenticator app. Some end-users may be reluctant to install corporate applications on their mobile device or in some country/region there is a legal requirement for employers to provide corporate mobile phone if corporate

Azure AD – New authentication method – Authenticator Lite (preview) Read More »

Azure AD – You can now use Token Protection with Conditional Access (preview)

You know that you can use Azure AD Conditional Access to secure access to your resource by enforcing MFA, device compliance… Well, Azure AD Conditional Access has been updated to allow you use Token Protection. Token Protection attempts to reduce attacks using token theft by ensuring a token is usable only from the intended device.

Azure AD – You can now use Token Protection with Conditional Access (preview) Read More »