V20250506
Changelog
Conditional Access Policies
- Added: RoleCheck 1 to verify if all Tier 0/1 Entra roles (with assignments) are included when more than 4 roles are targeted in a policy
- Added: RoleCheck 2 to detect included roles which have scoped assignments
- Added: Additional
PresetViewConditional Access Policies with session controls - Improved: Split multiple
AuthFlowMethodsusing spaces for better formatting - Improved: Show
SessionControlscount in the table - Improved: Adjusted some warning messages
- Improved: Enhanced detection of policies blocking legacy authentication (Detection will not trigger if all four app types are selected)
Users
- Fixed: Incorrect number of app roles
- Fixed: Incorrect warning message for potentially sensitive app roles
Enumeration Summary
- Fixed: Incorrect number of PIM-onboarded groups when PfG was not enumerated
Overall
- Added: Started the implementation of a
-Verbosemode
Full Changelog: V20250502...V20250506