Azure Active Directory

Azure AD – Update your Conditional Access policies if you are using ‘require approved client app’ before March 2026

If you are using the grant control ‘Require approved client app’ in your Conditional Access policies, you need to update and migrate to use the grant control ‘Require application protection policy’ before March 2026. At this date, the control ‘Require approved client app’ will no longer be enforced and will act as if it was […]

Azure AD – Update your Conditional Access policies if you are using ‘require approved client app’ before March 2026 Read More »

Azure AD – You can use conditional access for PIM (preview)

As you know with Azure AD (P1 or P2) you can protect access to your workloads using Conditional Access. Well, you can now also use Conditional Access when used with PIM (Privileged Identity Management) (in preview), or more specifically when protected actions are being used. The below protected actions are currently supported: Update basic properties

Azure AD – You can use conditional access for PIM (preview) Read More »

Azure AD – New authentication method – Authenticator Lite (preview)

A new authentication method called Authenticator Lite is available in preview. Authenticator Lite allows end-users to perform multifactor authentication without the Microsoft Authenticator app. Some end-users may be reluctant to install corporate applications on their mobile device or in some country/region there is a legal requirement for employers to provide corporate mobile phone if corporate

Azure AD – New authentication method – Authenticator Lite (preview) Read More »

Azure AD – You can now use Token Protection with Conditional Access (preview)

You know that you can use Azure AD Conditional Access to secure access to your resource by enforcing MFA, device compliance… Well, Azure AD Conditional Access has been updated to allow you use Token Protection. Token Protection attempts to reduce attacks using token theft by ensuring a token is usable only from the intended device.

Azure AD – You can now use Token Protection with Conditional Access (preview) Read More »

Azure AD – New recommendations for applications (preview)

About a year ago, Microsoft has introduced Azure AD recommendations to help you improve your Azure AD security posture (see https://t.co/92sR2y0bR4). Well, these recommendations have been updated to introduce recommendations for Azure AD applications. While the first recommendations apply to all Azure AD license, these new recommendations for applications require Azure AD P2. The available

Azure AD – New recommendations for applications (preview) Read More »

Azure AD – You easily get Azure AD error code meaning

Have you ever try to figure out what the error code from Azure AD is meaning? While Microsoft has been trying to provide meaningful information when the error occurs, sometime it is more complicated and not easy to find answer. Well, good new, you can use this Microsoft site https://login.microsoftonline.com/error – you will notice this

Azure AD – You easily get Azure AD error code meaning Read More »

Azure AD – You can now enable suspicious activities reporting (preview)

If you have been using the on-premises Azure MFA server (which by the way is going to be fully deprecated – https://azure.microsoft.com/en-us/updates/azure-multifactor-authentication-server-will-be-deprecated-30-september-2024/) you already know that end-users were able to report suspicious activities. Well, this was a missing feature on Azure AD MFA which is now becoming available. First you need to enable it (this

Azure AD – You can now enable suspicious activities reporting (preview) Read More »

Azure AD – You can now set an Azure AD Application Proxy app in maintenance mode

If you use Microsoft Cloud services, you know that identity and access control is managed by Azure AD. Azure AD which comes with a feature called Azure AD Application Proxy to allow you publishing internal applications without configuring your firewall and can integrate with Azure AD for authentication and access control (see https://learn.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy/ to know

Azure AD – You can now set an Azure AD Application Proxy app in maintenance mode Read More »

Intune – Enable self-service password reset on Windows login screen new option

As you are now probably aware, Intune administrators were able to enable self-service password reset (SSPR) on the Windows login screen for quite some time This enablement required to create a custom Intune device configuration profile, as documented here https://www.hametbenoit.info/2017/11/06/azure-ad-allow-end-users-to-reset-password-or-pin-from-the-login-screen/. Well, as Intune has been evolving quite quickly and some time you may miss updates,

Intune – Enable self-service password reset on Windows login screen new option Read More »

Azure AD – You can now restrict tenant creation to administrators (preview)

As you probably know, users may have the ability to create new tenant using the Manage tenant option from the Azure AD (https://aad.portal.azure.com/) or Entra () portal   When creating a new tenant, the user becomes automatically a global administrator for this new tenant and this new tenant does not inherit your organization settings or

Azure AD – You can now restrict tenant creation to administrators (preview) Read More »