惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
量子位
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
Y
Y Combinator Blog
Vercel News
Vercel News
云风的 BLOG
云风的 BLOG
宝玉的分享
宝玉的分享
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
Microsoft Security Blog
Microsoft Security Blog
B
Blog
Last Week in AI
Last Week in AI
有赞技术团队
有赞技术团队
博客园 - 聂微东
腾讯CDC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Microsoft Entra pushes passkeys, tightens identity security
Anamarija Pogorelec · 2026-06-02 · via Help Net Security

Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days.

Microsoft Entra security updates

Features reaching general availability

Identity and authentication updates

Phishing-resistant MFA is now available on Linux desktops through the Microsoft identity broker. The feature supports Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, bringing Linux support in line with Windows and macOS.

High Scale Compatibility (HSC) mode helps large Azure AD B2C customers migrate applications to Microsoft Entra External ID. The option enables organizations with about 5 million or more objects to move applications without requiring users to re-register or reset passwords.

“Customers can run the B2C Policy Analyzer to assess migration readiness, and account teams and partners should engage the EEID migration team to guide eligible Azure Active Directory B2C customers toward the right migration path,” Martin Coetzer, Principal Product Manager at Microsoft, explained.

System-preferred authentication covers both first- and second-factor authentication in the Microsoft Managed state. The service selects the highest-ranked authentication method available to each user.

The Devices, Security Info, and Organizations pages in the My Account portal have been redesigned. The updates simplify device management, security information settings, and organization management. The rollout is scheduled to finish by the end of June 2026.

Registration Campaigns support passkeys, including FIDO2 credentials. Administrators can prompt users to register passkeys during sign-in to encourage adoption.

Users can register device-bound passkeys through Windows Hello and use them for phishing-resistant sign-in with biometrics or a PIN. The feature does not require devices to be Microsoft Entra joined or registered. Interactive Windows console sign-in is not supported.

Governance and management updates

Organizations can synchronize security groups and memberships between Microsoft Entra tenants. This enables centrally managed groups to be used in multiple tenants for access control and collaboration.

Administrators can view all accounts within connected applications, including orphaned accounts. Discovery reports help identify access gaps and support application onboarding. The feature requires Microsoft Entra ID Governance or Microsoft Entra Suite.

Agent identity human sponsorship can transfer automatically when a sponsor leaves an organization. Lifecycle Workflows can notify managers and co-sponsors about upcoming sponsorship changes.

App Deactivation allows administrators to disable applications without deleting them or disrupting tenant-level governance. Deactivated applications cannot obtain new access tokens or sign users in. Their configuration, permissions, and metadata remain available for later reactivation.

“This approach is useful for security investigations, temporary suspension of suspicious applications, or situations where application configuration data must be preserved,” Coetzer continued.

Features in public preview

Domain-less SAML federation on workforce tenants allows external users to sign in to applications or workforce resources with credentials from their identity provider. It does not require email domain matching during sign-in or invitation redemption.

Sensitivity labels for Entra security groups bring Microsoft Purview labels to Entra cloud security groups in public preview. Administrators can apply existing Microsoft 365 label policies to security groups. Labels can be managed in Microsoft Purview and applied through the Entra admin center, Azure portal, and Microsoft Graph to support consistent governance of group settings, including guest access controls.

Device Soft Delete adds a recoverable state for deleted devices. Administrators can restore device objects within a retention period while preserving device identity and related security data. The feature applies to Entra joined, registered, and hybrid joined devices and reduces the risk of accidental removal.

SAP SuccessFactors provisioning supports workload identity-based authentication. It replaces long-lived usernames and passwords with Entra-managed credentials and short-lived access tokens. Existing provisioning jobs can be updated without rebuilding them. The change applies to inbound provisioning for Active Directory and Entra ID, as well as writeback scenarios. It supports SAP’s plan to retire basic authentication for APIs by November 2026.

Access packages can govern Azure role assignments at the management group, subscription, and resource group levels. Role assignments use request, approval, and lifecycle controls similar to those used for applications and groups to support least-privilege and time-bound access to Azure resources.

Lifecycle Workflows adds a User Attribute Updates task. It automates updates to user attributes, including custom attributes, within workflow steps. Administrators can set or clear values through a controlled and auditable process.

The Entra Security Operator role expands support for SOC response actions in Microsoft Defender RBAC. Analysts can disable users, revoke sessions, mark accounts as compromised, force password resets, and remove authentication methods. These actions apply to non-admin users and reduce the need for full Entra administrative privileges during incident response.

Policy updates and enforcement changes

Starting July 6, 2026, Conditional Access policies assigned to the “Register security information” action will apply during registration for Windows Hello for Business and macOS Platform SSO. Users must meet requirements such as MFA, network restrictions, or device compliance before completing registration. Tenants without policies for this action are unaffected. MFA remains required by default for passwordless credential registration. Full enforcement begins July 13, 2026.

Self-Service Password Reset will accept only authentication methods that users have registered beginning September 7, 2026. Contact details stored on the user object, such as email addresses or phone numbers, will not be accepted unless they have been registered as authentication methods. The change applies to all users, including administrators, in Public cloud, GCC, GCC High, and DoD environments.

A registration campaign will prompt users without registered methods to enroll after sign-in starting July 6, 2026. Administrators should ensure users have at least one registered authentication method before enforcement begins.

The passkey (FIDO2) authentication policy receives a dedicated 20 KB allocation within the authentication methods policy. Previously, all authentication methods shared a single 20 KB limit. The number of passkey profiles per tenant increases from three to ten.

A new operations guide for Global Secure Access covers post-deployment operations, including alerting, health checks, change management, metrics, and recovery procedures. It provides KQL queries and templates. Separate guidance is available for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.