Cross-product topic

Security

A cross-product view of Microsoft Entra changes related to Security.

Latest Security changes

SAM Account Name

Security

Enhanced synchronization can source sAMAccountName for hybrid users from onPremisesSamAccountName in Microsoft Entra ID. Existing domains retain current behavior until enabled; enabling updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation.

Flexible federated identity credentials (preview)

Security

The documentation now states that GitHub flexible federated identity credentials must match `sub` and at least one immutable claim: `repository_id` or `repository_owner_id`. It also updates examples and operator support details.

Set up a Flexible Federated identity credential (preview)

Security

The guidance now requires GitHub flexible federated identity credentials to match `sub` plus `repository_id`, `repository_owner_id`, or both. Portal and Microsoft Graph examples include these claims and optional workflow matching.

Best Practices Agent Id

Security

The documentation now recommends creating agent identities from an agent identity blueprint instead of using standard app registrations or service principals. It also adds .NET usage guidance and lists required roles and permission.

Call Api Azure Services

Security

The documentation updates its C# examples, separating app-only, on-behalf-of-user, and user-identification scenarios. Samples now configure agent identity options and pass the credential to the Blob client correctly.

Integrate Aws Bedrock Agent

Security

The guide updates “Entra” to “Microsoft Entra” in the diagram alt text, setup heading, and TENANT_ID descriptions. No technical procedure or feature change is shown.

Connect Health Agent Install

Security

> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.

Id Protection Dashboard

Security

Microsoft Entra ID Protection provides unified risk signals that aggregate correlated risk signals from Microsoft Entra ID Protection, Microsoft Defender, and other Microsoft security products. Instead of evaluating alerts in isolation, this capability correlates identity-related signals across products and evaluates them together within the same time window to calculate a compounded user risk score.

Security Operations

Security

- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)

Security operations for network access

Security

Security operations guide for Microsoft Entra Global Secure Access covering detection patterns and Sentinel analytics for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.

Entra Offerings

Security

>The licensing options on this page aren't comprehensive. You can get detailed information about the various options at the [Microsoft Entra pricing page](https://www.microsoft.com/security/business/microsoft-entra-pricing) and at the [Compare Microsoft 365 Enterprise plans and pricing page](https://www.microsoft.com/microsoft-365/enterprise/microsoft365-plans-and-pricing).

Licensing Identity Protection

Security

Starting soon, ID Protection for agents will require a [Microsoft Agent 365 license](https://www.microsoft.com/microsoft-agent-365#plans-and-pricing) to extend protection to agents through [Microsoft Entra Agent ID](../agent-id/what-is-microsoft-entra-agent-id.md#how-to-get-started).

Configure Domain Controllers

Security

- The Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.

Licensing Identity Protection

Security

Starting soon, ID Protection for agents will require a [Microsoft Agent 365 license](https://www.microsoft.com/microsoft-agent-365#plans-and-pricing) to extend protection to agents through [Microsoft Entra Agent ID](../agent-id/what-is-microsoft-entra-agent-id.md#how-to-get-started).

What If Tool

Security

**Has filter** indicates whether the policy has app filters that use custom security attributes.

Ai Prompt Injection Protection

Security

Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.

Configure risk-based step-up consent

Security

Learn how to disable and enable risk-based step-up consent to reduce user exposure to malicious apps that make illicit consent requests.

Microsoft Entra Agents

Security

Learn about Microsoft Entra agents, AI-powered automation tools that enhance identity and access management operations.

Network Content Filtering

Security

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.

Entra Agents

Security

- You must have available [security compute units (SCU)](/copilot/security/manage-usage).

Policy All Users Windows App Protection

Security

There's a known issue where there's a preexisting, unregistered account, like `user@contoso.com` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

Tutorial Internet Access Application Discovery

Security

*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.

Tutorial: Configure content policies

Security

Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.

Group Policy

Security

The backup location and network share are configured with appropriate Active Directory security groups to ensure only authorized administrators can access the backup data. The ACL model aligns with the permissions used in Group Policy Management Console (GPMC), maintaining consistency with existing GPO management practices.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…