惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
腾讯CDC
博客园 - 聂微东
爱范儿
爱范儿
罗磊的独立博客
P
Proofpoint News Feed
博客园 - Franky
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
Blog — PlanetScale
Blog — PlanetScale
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 司徒正美
美团技术团队
MongoDB | Blog
MongoDB | Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
I
InfoQ
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Microsoft Entra pushes passkeys, tightens identity security
Anamarija Pogorelec · 2026-06-02 · via Help Net Security

Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days.

Microsoft Entra security updates

Features reaching general availability

Identity and authentication updates

Phishing-resistant MFA is now available on Linux desktops through the Microsoft identity broker. The feature supports Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, bringing Linux support in line with Windows and macOS.

High Scale Compatibility (HSC) mode helps large Azure AD B2C customers migrate applications to Microsoft Entra External ID. The option enables organizations with about 5 million or more objects to move applications without requiring users to re-register or reset passwords.

“Customers can run the B2C Policy Analyzer to assess migration readiness, and account teams and partners should engage the EEID migration team to guide eligible Azure Active Directory B2C customers toward the right migration path,” Martin Coetzer, Principal Product Manager at Microsoft, explained.

System-preferred authentication covers both first- and second-factor authentication in the Microsoft Managed state. The service selects the highest-ranked authentication method available to each user.

The Devices, Security Info, and Organizations pages in the My Account portal have been redesigned. The updates simplify device management, security information settings, and organization management. The rollout is scheduled to finish by the end of June 2026.

Registration Campaigns support passkeys, including FIDO2 credentials. Administrators can prompt users to register passkeys during sign-in to encourage adoption.

Users can register device-bound passkeys through Windows Hello and use them for phishing-resistant sign-in with biometrics or a PIN. The feature does not require devices to be Microsoft Entra joined or registered. Interactive Windows console sign-in is not supported.

Governance and management updates

Organizations can synchronize security groups and memberships between Microsoft Entra tenants. This enables centrally managed groups to be used in multiple tenants for access control and collaboration.

Administrators can view all accounts within connected applications, including orphaned accounts. Discovery reports help identify access gaps and support application onboarding. The feature requires Microsoft Entra ID Governance or Microsoft Entra Suite.

Agent identity human sponsorship can transfer automatically when a sponsor leaves an organization. Lifecycle Workflows can notify managers and co-sponsors about upcoming sponsorship changes.

App Deactivation allows administrators to disable applications without deleting them or disrupting tenant-level governance. Deactivated applications cannot obtain new access tokens or sign users in. Their configuration, permissions, and metadata remain available for later reactivation.

“This approach is useful for security investigations, temporary suspension of suspicious applications, or situations where application configuration data must be preserved,” Coetzer continued.

Features in public preview

Domain-less SAML federation on workforce tenants allows external users to sign in to applications or workforce resources with credentials from their identity provider. It does not require email domain matching during sign-in or invitation redemption.

Sensitivity labels for Entra security groups bring Microsoft Purview labels to Entra cloud security groups in public preview. Administrators can apply existing Microsoft 365 label policies to security groups. Labels can be managed in Microsoft Purview and applied through the Entra admin center, Azure portal, and Microsoft Graph to support consistent governance of group settings, including guest access controls.

Device Soft Delete adds a recoverable state for deleted devices. Administrators can restore device objects within a retention period while preserving device identity and related security data. The feature applies to Entra joined, registered, and hybrid joined devices and reduces the risk of accidental removal.

SAP SuccessFactors provisioning supports workload identity-based authentication. It replaces long-lived usernames and passwords with Entra-managed credentials and short-lived access tokens. Existing provisioning jobs can be updated without rebuilding them. The change applies to inbound provisioning for Active Directory and Entra ID, as well as writeback scenarios. It supports SAP’s plan to retire basic authentication for APIs by November 2026.

Access packages can govern Azure role assignments at the management group, subscription, and resource group levels. Role assignments use request, approval, and lifecycle controls similar to those used for applications and groups to support least-privilege and time-bound access to Azure resources.

Lifecycle Workflows adds a User Attribute Updates task. It automates updates to user attributes, including custom attributes, within workflow steps. Administrators can set or clear values through a controlled and auditable process.

The Entra Security Operator role expands support for SOC response actions in Microsoft Defender RBAC. Analysts can disable users, revoke sessions, mark accounts as compromised, force password resets, and remove authentication methods. These actions apply to non-admin users and reduce the need for full Entra administrative privileges during incident response.

Policy updates and enforcement changes

Starting July 6, 2026, Conditional Access policies assigned to the “Register security information” action will apply during registration for Windows Hello for Business and macOS Platform SSO. Users must meet requirements such as MFA, network restrictions, or device compliance before completing registration. Tenants without policies for this action are unaffected. MFA remains required by default for passwordless credential registration. Full enforcement begins July 13, 2026.

Self-Service Password Reset will accept only authentication methods that users have registered beginning September 7, 2026. Contact details stored on the user object, such as email addresses or phone numbers, will not be accepted unless they have been registered as authentication methods. The change applies to all users, including administrators, in Public cloud, GCC, GCC High, and DoD environments.

A registration campaign will prompt users without registered methods to enroll after sign-in starting July 6, 2026. Administrators should ensure users have at least one registered authentication method before enforcement begins.

The passkey (FIDO2) authentication policy receives a dedicated 20 KB allocation within the authentication methods policy. Previously, all authentication methods shared a single 20 KB limit. The number of passkey profiles per tenant increases from three to ten.

A new operations guide for Global Secure Access covers post-deployment operations, including alerting, health checks, change management, metrics, and recovery procedures. It provides KQL queries and templates. Separate guidance is available for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.