Skip to content

Commit 11e6e48

Browse files
Merge pull request #241572 from OWinfreyATL/owinfreyATL-WhatsNew-June2023
June 2023 added to whats new article
2 parents 330ef84 + 4447b2e commit 11e6e48

File tree

1 file changed

+153
-14
lines changed

1 file changed

+153
-14
lines changed

articles/active-directory/fundamentals/whats-new.md

Lines changed: 153 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,158 @@ Azure AD receives improvements on an ongoing basis. To stay up to date with the
3232
This page updates monthly, so revisit it regularly. If you're looking for items older than six months, you can find them in [Archive for What's new in Azure Active Directory](whats-new-archive.md).
3333

3434

35+
## June 2023
36+
37+
### Public Preview - Availability of Exchange Hybrid in Azure AD Connect cloud sync
38+
39+
**Type:** New feature
40+
**Service category:** Directory Management
41+
**Product capability:** Azure Active Directory Connect Cloud Sync
42+
43+
44+
45+
Exchange hybrid capability allows for the coexistence of Exchange mailboxes both on-premises and in Microsoft 365. Cloud Sync synchronizes a specific set of Exchange-related attributes from Azure AD back into your on-premises directory and to any forests that's disconnected (no network trust needed between them). With this capability, existing customers who have this feature enabled in Azure AD Connect sync can now migrate and leverage this feature with Azure AD cloud sync. For more information, see: ADD LINK
46+
47+
---
48+
49+
### Public Preview - New provisioning connectors in the Azure AD Application Gallery - June 2023
50+
51+
**Type:** New feature
52+
**Service category:** App Provisioning
53+
**Product capability:** 3rd Party Integration
54+
55+
We've added the following new applications in our App gallery with Provisioning support. You can now automate creating, updating, and deleting of user accounts for these newly integrated apps:
56+
57+
- [Headspace](../saas-apps/headspace-provisioning-tutorial.md)
58+
- [Humbol](../saas-apps/humbol-provisioning-tutorial.md)
59+
- [LUSID](../saas-apps/lusid-provisioning-tutorial.md)
60+
- [Markit Procurement Service](../saas-apps/markit-procurement-service-provisioning-tutorial.md)
61+
- [Moqups](../saas-apps/moqups-provisioning-tutorial.md)
62+
- [Notion](../saas-apps/notion-provisioning-tutorial.md)
63+
- [OpenForms](../saas-apps/openforms-provisioning-tutorial.md)
64+
- [SafeGuard Cyber](../saas-apps/safeguard-cyber-provisioning-tutorial.md)
65+
- [Uni-tel A/S](../saas-apps/uni-tel-as-provisioning-tutorial.md)
66+
- [Vault Platform](../saas-apps/vault-platform-provisioning-tutorial.md)
67+
- [V-Client](../saas-apps/v-client-provisioning-tutorial.md)
68+
- [Veritas Enterprise Vault.cloud SSO-SCIM](../saas-apps/veritas-provisioning-tutorial.md)
69+
70+
For more information about how to better secure your organization by using automated user account provisioning, see: [Automate user provisioning to SaaS applications with Azure AD](../app-provisioning/user-provisioning.md).
71+
72+
---
73+
74+
### General Availability - Include/exclude Entitlement Management in Conditional Access policies
75+
76+
**Type:** New feature
77+
**Service category:** Entitlement Management
78+
**Product capability:** Entitlement Management
79+
80+
The Entitlement Management service can now be targeted in the conditional access policy for inclusion or exclusion of applications. To target the Entitlement Management service, select “Azure AD Identity Governance - Entitlement Management” in the cloud apps picker. The Entitlement Management app includes the entitlement management part of My Access, the Entitlement Management part of the Entra and Azure portals, and the Entitlement Management part of MS Graph. For more information, see: [Review your Conditional Access policies](../governance/entitlement-management-external-users.md#review-your-conditional-access-policies).
81+
82+
---
83+
84+
### General Availability - Azure Active Directory User and Group capabilities on Azure Mobile are now available
85+
86+
**Type:** New feature
87+
**Service category:** Azure Mobile App
88+
**Product capability:** End User Experiences
89+
90+
The Azure Mobile app now includes a section for Azure Active Directory. Within Azure Active Directory on mobile, user can search for and view more details about user and groups. Additionally, permitted users can invite guest users to their active tenant, assign group memberships and ownerships for users, and view user sign-in logs. For more information, see: [What is Azure Active Directory?](../fundamentals/active-directory-whatis.md).
91+
92+
---
93+
94+
### General Availability - Privileged Identity Management for Groups
95+
96+
**Type:** New feature
97+
**Service category:** Privileged Identity Management
98+
**Product capability:** Privileged Identity Management
99+
100+
Privileged Identity Management for Groups is now generally available. With this feature, you have the ability to grant users just-in-time membership in a group, which in turn provides access to Azure Active Directory roles, Azure roles, Azure SQL, Azure Key Vault, Intune, other application roles, as well as third-party applications. Through one activation, you can conveniently assign a combination of permissions across different applications and RBAC systems.
101+
102+
PIM for Groups offers can also be used for just-in-time ownership. As the owner of the group, you can manage group properties, including membership. For more information, see: [Privileged Identity Management (PIM) for Groups](../privileged-identity-management/concept-pim-for-groups.md).
103+
104+
---
105+
106+
### General Availability - Privileged Identity Management and Conditional Access integration
107+
108+
**Type:** New feature
109+
**Service category:** Privileged Identity Management
110+
**Product capability:** Privileged Identity Management
111+
112+
The Privileged Identity Management (PIM) integration with Conditional Access authentication context is generally available. You can require users to meet a variety of requirements during role activation such as:
113+
114+
- Have specific authentication method through [Authentication Strengths](../authentication/concept-authentication-strengths.md)
115+
- Activate from a compliant device
116+
- Validate location based on GPS
117+
- Not have certain level of sign-in risk identified with Identity Protection
118+
- Meet other requirements defined in Conditional Access policies
119+
120+
The integration is available for all providers: PIM for Azure AD roles, PIM for Azure resources, PIM for groups. For more information, see:
121+
- [Configure Azure AD role settings in Privileged Identity Management](../privileged-identity-management/pim-how-to-change-default-settings.md)
122+
- [Configure Azure resource role settings in Privileged Identity Management](../privileged-identity-management/pim-resource-roles-configure-role-settings.md)
123+
- [Configure PIM for Groups settings](../privileged-identity-management/groups-role-settings.md)
124+
125+
---
126+
127+
### General Availability - Updated look and feel for Per-user MFA
128+
129+
**Type:** Plan for change
130+
**Service category:** MFA
131+
**Product capability:** Identity Security & Protection
132+
133+
As part of ongoing service improvements, we're making updates to the per-user MFA admin configuration experience to align with the look and feel of Azure. This change doesn't include any changes to the core functionality and will only include visual improvements. For more information, see: [Enable per-user Azure AD Multi-Factor Authentication to secure sign-in events](../authentication/howto-mfa-userstates.md).
134+
135+
---
136+
137+
### General Availability - Converged Authentication Methods in US Gov cloud
138+
139+
**Type:** New feature
140+
**Service category:** MFA
141+
**Product capability:** User Authentication
142+
143+
The Converged Authentication Methods Policy enables you to manage all authentication methods used for MFA and SSPR in one policy, migrate off the legacy MFA and SSPR policies, and target authentication methods to groups of users instead of enabling them for all users in the tenant. Customers should migrate management of authentication methods off the legacy MFA and SSPR policies before September 30, 2024. For more information, see: [Manage authentication methods for Azure AD](../authentication/concept-authentication-methods-manage.md).
144+
145+
---
146+
147+
### General Availability - Support for Directory Extensions using Azure AD Cloud Sync
148+
149+
**Type:** New feature
150+
**Service category:** Provisioning
151+
**Product capability:** Azure Active Directory Connect Cloud Sync
152+
153+
Hybrid IT Admins can now sync both Active Directory and Azure AD Directory Extensions using Azure AD Cloud Sync. This new capability adds the ability to dynamically discover the schema for both Active Directory and Azure Active Directory, thereby, allowing customers to simply map the needed attributes using Cloud Sync's attribute mapping experience. For more information, see: [Cloud Sync directory extensions and custom attribute mapping](../hybrid/cloud-sync/custom-attribute-mapping.md).
154+
155+
---
156+
157+
### Public Preview - Restricted Management Administrative Units
158+
159+
**Type:** New feature
160+
**Service category:** Directory Management
161+
**Product capability:** Access Control
162+
163+
Restricted Management Administrative Units allow you to restrict modification of users, security groups, and device in Azure AD so that only designated administrators can make changes. Global Administrators and other tenant-level administrators can't modify the users, security groups, or devices that are added to a restricted management admin unit. For more information, see: [Restricted management administrative units in Azure Active Directory (Preview)](../roles/admin-units-restricted-management.md).
164+
165+
---
166+
167+
### Public Preview - Real-Time Threat Intelligence Detections
168+
169+
**Type:** New feature
170+
**Service category:** Identity Protection
171+
**Product capability:** Identity Security & Protection
172+
173+
To address emerging attacks, Identity Protection now includes Real-Time Threat Intelligence Detections, also referred to as Rapid Response Detections. When emerging attacks occur, Identity Protection will now dynamically issue new detections in response to these attacks. These detections utilize Microsoft’s threat intelligence in real-time, meaning Identity Protection detects emerging patterns of compromise during sign-in and challenge the user accordingly. For more information, see: ADD LINK
174+
175+
---
176+
177+
### General Availability - Report suspicious activity integrated with Identity Protection
178+
179+
**Type:** Changed feature
180+
**Service category:** Identity Protection
181+
**Product capability:** Identity Security & Protection
182+
183+
Report suspicious activity is an updated implementation of the MFA fraud alert, where users can report a voice or phone app MFA prompt as suspicious. If enabled, users reporting prompts have their user risk set to high, enabling admins to use Identity Protection risk based policies or risk detection APIs to take remediation actions. Report suspicious activity operates in parallel with the legacy MFA fraud alert at this time. For more information, see: [Configure Azure AD Multi-Factor Authentication settings](../authentication/howto-mfa-mfasettings.md).
184+
185+
---
186+
35187
## May 2023
36188

37189
### General Availability - Conditional Access authentication strength for members, external users and FIDO2 restrictions
@@ -89,7 +241,7 @@ Last year we announced the [public preview of custom extensions in Entitlement M
89241

90242
The latest version of MSAL.NET graduates the Managed Identity APIs into the General Availability mode of support, which means that developers can integrate them safely in production workloads.
91243

92-
Managed identities are a part of the Azure infrastructure, simplifying how developers handle credentials and secrets to access cloud resources. With Managed Identities, developers do not need to manually handle credential retrieval and security. Instead, they can rely on an automatically managed set of identities to connect to resources that support Azure Active Directory (AAD) authentication. You can learn more in [What are managed identities for Azure resources?](../managed-identities-azure-resources/overview.md)
244+
Managed identities are a part of the Azure infrastructure, simplifying how developers handle credentials and secrets to access cloud resources. With Managed Identities, developers don't need to manually handle credential retrieval and security. Instead, they can rely on an automatically managed set of identities to connect to resources that support Azure Active Directory authentication. You can learn more in [What are managed identities for Azure resources?](../managed-identities-azure-resources/overview.md)
93245

94246
With MSAL.NET 4.54.0, the Managed Identity APIs are now stable. There are a few changes that we added that make them easier to use and integrate that might require tweaking your code if you’ve used our [experimental implementation](https://den.dev/blog/managed-identity-msal-net/):
95247

@@ -718,19 +870,6 @@ For more information about how to better secure your organization by using autom
718870
Cross-tenant synchronization allows you to set up a scalable and automated solution for users to access applications across tenants in your organization. It builds upon the Azure AD B2B functionality and automates creating, updating, and deleting B2B users. For more information, see: [What is cross-tenant synchronization? (preview)](../multi-tenant-organizations/cross-tenant-synchronization-overview.md).
719871

720872

721-
---
722-
723-
### General Availability - Apple Watch companion app removed from Authenticator for iOS
724-
725-
726-
727-
**Type:** Deprecated
728-
**Service category:** Identity Protection
729-
**Product capability:** Identity Security & Protection
730-
731-
In the January 2023 release of Authenticator for iOS, there's no companion app for watchOS due to it being incompatible with Authenticator security features, meaning you aren't able to install or use Authenticator on Apple Watch. This change only impacts Apple Watch, so you can still use Authenticator on your other devices. For more information, see: [Common questions about the Microsoft Authenticator app](https://support.microsoft.com/account-billing/common-questions-about-the-microsoft-authenticator-app-12d283d1-bcef-4875-9ae5-ac360e2945dd).
732-
733-
734873
---
735874

736875
### General Availability - New Federated Apps available in Azure AD Application gallery - January 2023

0 commit comments

Comments
 (0)