Permission update for the AI Administrator role in Entra ID
Microsoft added a new privileged permission to the AI Administrator role in Entra ID. Users with the role can now grant admin consent to delegated permissions for applications and agents.
Microsoft added a new privileged permission to the AI Administrator role in Entra ID. Users with the role can now grant admin consent to delegated permissions for applications and agents.
Microsoft accidentally created a new “All Company” Microsoft 365 group in some tenants during a July incident. Administrators should check whether their tenant now has two such groups for Viva Engage.
Microsoft recently recommended migrating GitHub Actions federated credentials to an immutable subject format in Microsoft Entra app registrations. This closes a subtle security gap where recycled repo or org names could let someone else’s token match your trust configuration. In this post, I walk through what the migration actually involves. I also tested the newer Flexible Federated Identity Credentials (FFIC), currently in preview.
Microsoft has introduced a new admin role: Entra SOC Identity Responder. The role lets SOC analysts disable accounts, revoke sessions, and reset passwords for rapid incident containment without broader Entra admin access.
Microsoft is preparing a new Entra admin role. The Entra Customer Lockbox Approver role provides a least privileged option for approving Customer Lockbox requests in Azure.
Passkeys (FIDO2) are being added as a supported targeted authentication method in Microsoft Entra registration campaigns. In addition, tenants in the Microsoft-managed state that meet specific criteria will see additional configuration changes.
Microsoft is updating the Microsoft-managed default user consent policy for Microsoft Graph as part of the Secure Future Initiative, requiring admin consent for an expanded set of delegated permissions accessing Exchange data.
A new AI Reader role in Microsoft Entra provides broad read-only access to Copilot and Agent 365 settings, usage reports, service health, and Entra ID objects.
A new Microsoft Entra admin role lets administrators manage granular delegated admin privilege (GDAP) relationships, including accepting, reviewing, and terminating partner access on behalf of the tenant.
Microsoft has added four new admin roles in Entra to manage all aspects of Microsoft Entra Tenant Governance. I am summarizing what each role covers and how they differ.
The “Revoke Sessions” action in Microsoft Entra has been updated to invalidate all user sessions, regardless of whether MFA is enforced via Conditional Access or per-user policies.
Loop on the web still ignores regional language formats and falls back to English (en-US), even when a specific language is configured for users. This long-standing, frustrating limitation continues to affect users in regions where regional variants are used.
Microsoft is rolling out three new Entra admin roles for Microsoft Purview that are automatically managed through Purview role assignments. These roles should not be assigned directly in Entra, as any manual changes will be overwritten.
Entra ID now supports multi-device passkeys, allowing users to store their passkey in password managers like 1Password for seamless, passwordless sign-in.
Microsoft is rolling out four new Entra ID admin roles, covering SharePoint Advanced Management and the lifecycle of AI agents in Copilot.
Microsoft has expanded the Microsoft-managed default app consent policy in Entra ID to block 20 additional permissions, including access to Outlook Mail, Outlook Calendar, and Teams data
Microsoft has added two new Entra ID admin roles — SharePoint Backup Administrator and Exchange Backup Administrator. These roles allow organizations to delegate Microsoft 365 Backup tasks without relying on SharePoint, Exchange, or Global admins.
Microsoft has added a Dragon Administrator role to Entra ID. Designed for healthcare and clinical organizations, it provides full control of Dragon Copilot through the Dragon Admin Center, eliminating the need for the Global Administrator role.
Microsoft Places is introducing a new admin role in Entra ID and new RBAC roles in Exchange Online, allowing management delegation to local building and desk administrators.
In this post, I walk you through how to create and customize a custom app consent policy in Entra ID using the Microsoft Graph API.