Skip to content

Commit d658d3c

Browse files
Merge pull request #231493 from OWinfreyATL/owinfreyATL-March2023-WhatsNew
March 2023 added to whats new in Azure AD
2 parents 8555d8d + 14ab1fa commit d658d3c

File tree

1 file changed

+131
-3
lines changed

1 file changed

+131
-3
lines changed

articles/active-directory/fundamentals/whats-new.md

Lines changed: 131 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,135 @@ Azure AD receives improvements on an ongoing basis. To stay up to date with the
3232
This page updates monthly, so revisit it regularly. If you're looking for items older than six months, you can find them in [Archive for What's new in Azure Active Directory](whats-new-archive.md).
3333

3434

35+
## March 2023
36+
37+
### General Availability - Workload identity Federation for Managed Identities
38+
39+
**Type:** New feature
40+
**Service category:** Managed identities for Azure resources
41+
**Product capability:** Developer Experience
42+
43+
Workload Identity Federation enables developers to use managed identities for their software workloads running anywhere and access Azure resources without needing secrets. Key scenarios include:
44+
- Accessing Azure resources from Kubernetes pods running in any cloud or on-premises
45+
- GitHub workflows to deploy to Azure, no secrets necessary
46+
- Accessing Azure resources from other cloud platforms that support OIDC, such as Google Cloud Platform.
47+
48+
For more information, see:
49+
- [Workload identity federation](../workload-identities/workload-identity-federation.md).
50+
- [Configure a user-assigned managed identity to trust an external identity provider (preview)](../workload-identities/workload-identity-federation-create-trust-user-assigned-managed-identity.md)
51+
- [Use Azure AD workload identity (preview) with Azure Kubernetes Service (AKS)](../../aks/workload-identity-overview.md)
52+
53+
---
54+
55+
### Public Preview - New My Groups Experience
56+
57+
**Type:** Changed feature
58+
**Service category:** Group Management
59+
**Product capability:** End User Experiences
60+
61+
A new and improved My Groups experience is now available at https://www.myaccount.microsoft.com/groups. My Groups enables end users to easily manage groups, such as finding groups to join, managing groups they own, and managing existing group memberships. Based on customer feedback, the new My Groups support sorting and filtering on lists of groups and group members, a full list of group members in large groups, and an actionable overview page for membership requests.
62+
This experience replaces the existing My Groups experience at https://www.mygroups.microsoft.com in May.
63+
64+
65+
For more information, see: [Update your Groups info in the My Apps portal](https://support.microsoft.com/account-billing/update-your-groups-info-in-the-my-apps-portal-bc0ca998-6d3a-42ac-acb8-e900fb1174a4).
66+
67+
---
68+
69+
### Public preview - Customize tokens with Custom Claims Providers
70+
71+
**Type:** New feature
72+
**Service category:** Authentications (Logins)
73+
**Product capability:** Extensibility
74+
75+
A custom claims provider lets you call an API and map custom claims into the token during the authentication flow. The API call is made after the user has completed all their authentication challenges, and a token is about to be issued to the app. For more information, see: [Custom authentication extensions (preview)](../develop/custom-claims-provider-overview.md).
76+
77+
---
78+
79+
### General Availability - Converged Authentication Methods
80+
81+
**Type:** New feature
82+
**Service category:** MFA
83+
**Product capability:** User Authentication
84+
85+
The Converged Authentication Methods Policy enables you to manage all authentication methods used for MFA and SSPR in one policy, migrate off the legacy MFA and SSPR policies, and target authentication methods to groups of users instead of enabling them for all users in your tenant. For more information, see: [Manage authentication methods](../authentication/concept-authentication-methods-manage.md).
86+
87+
---
88+
89+
### General Availability - Provisioning Insights Workbook
90+
91+
**Type:** New feature
92+
**Service category:** Provisioning
93+
**Product capability:** Monitoring & Reporting
94+
95+
This new workbook makes it easier to investigate and gain insights into your provisioning workflows in a given tenant. This includes HR-driven provisioning, cloud sync, app provisioning, and cross-tenant sync.
96+
97+
Some key questions this workbook can help answer are:
98+
99+
- How many identities have been synced in a given time range?
100+
- How many create, delete, update, or other operations were performed?
101+
- How many operations were successful, skipped, or failed?
102+
- What specific identities failed? And what step did they fail on?
103+
- For any given user, what tenants / applications were they provisioned or deprovisioned to?
104+
105+
For more information, see: [Provisioning insights workbook](../app-provisioning/provisioning-workbook.md).
106+
107+
---
108+
109+
### General Availability - Number Matching for Microsoft Authenticator notifications
110+
111+
**Type:** Plan for Change
112+
**Service category:** Microsoft Authenticator App
113+
**Product capability:** User Authentication
114+
115+
Microsoft Authenticator app’s number matching feature has been Generally Available since Nov 2022! If you haven't already used the rollout controls (via Azure portal Admin UX and MSGraph APIs) to smoothly deploy number matching for users of Microsoft Authenticator push notifications, we highly encourage you to do so. We previously announced that we'll remove the admin controls and enforce the number match experience tenant-wide for all users of Microsoft Authenticator push notifications starting February 27, 2023. After listening to customers, we'll extend the availability of the rollout controls for a few more weeks. Organizations can continue to use the existing rollout controls until May 8, 2023, to deploy number matching in their organizations. Microsoft services will start enforcing the number matching experience for all users of Microsoft Authenticator push notifications after May 8, 2023. We'll also remove the rollout controls for number matching after that date.
116+
117+
If customers don’t enable number match for all Microsoft Authenticator push notifications prior to May 8, 2023, Authenticator users may experience inconsistent sign-ins while the services are rolling out this change. To ensure consistent behavior for all users, we highly recommend you enable number match for Microsoft Authenticator push notifications in advance.
118+
119+
For more information, see: [How to use number matching in multifactor authentication (MFA) notifications - Authentication methods policy](../authentication/how-to-mfa-number-match.md)
120+
121+
---
122+
123+
### Public Preview - IPv6 coming to Azure AD
124+
125+
**Type:** Plan for Change
126+
**Service category:** Identity Protection
127+
**Product capability:** Platform
128+
129+
Earlier, we announced our plan to bring IPv6 support to Microsoft Azure Active Directory (Azure AD), enabling our customers to reach the Azure AD services over IPv4, IPv6 or dual stack endpoints. This is just a reminder that we have started introducing IPv6 support into Azure AD services in a phased approach in late March 2023.
130+
131+
If you utilize Conditional Access or Identity Protection, and have IPv6 enabled on any of your devices, you likely must take action to avoid impacting your users. For most customers, IPv4 won't completely disappear from their digital landscape, so we aren't planning to require IPv6 or to deprioritize IPv4 in any Azure AD features or services. We'll continue to share additional guidance on IPv6 enablement in Azure AD at this link: [IPv6 support in Azure Active Directory](https://learn.microsoft.com/troubleshoot/azure/active-directory/azure-ad-ipv6-support)
132+
133+
---
134+
135+
### General Availability - Microsoft cloud settings for Azure AD B2B
136+
137+
**Type:** New feature
138+
**Service category:** B2B
139+
**Product capability:** B2B/B2C
140+
141+
Microsoft cloud settings let you collaborate with organizations from different Microsoft Azure clouds. With Microsoft cloud settings, you can establish mutual B2B collaboration between the following clouds:
142+
143+
- Microsoft Azure commercial and Microsoft Azure Government
144+
- Microsoft Azure commercial and Microsoft Azure China 21Vianet
145+
146+
For more information about Microsoft cloud settings for B2B collaboration., see: [Microsoft cloud settings](../external-identities/cross-tenant-access-overview.md#microsoft-cloud-settings).
147+
148+
---
149+
150+
### Modernizing Terms of Use Experiences
151+
152+
**Type:** Plan for Change
153+
**Service category:** Access Reviews
154+
**Product capability:** AuthZ/Access Delegation
155+
156+
Starting July 2023, we're modernizing the following Terms of Use end user experiences with an updated PDF viewer, and moving the experiences from https://account.activedirectory.windowsazure.com to https://myaccount.microsoft.com:
157+
- View previously accepted terms of use.
158+
- Accept or decline terms of use as part of the sign-in flow.
159+
160+
No functionalities will be removed. The new PDF viewer adds functionality and the limited visual changes in the end-user experiences will be communicated in a future update. If your organization has allow-listed only certain domains, you must ensure your allowlist includes the domains ‘myaccount.microsoft.com’ and ‘*.myaccount.microsoft.com’ for Terms of Use to continue working as expected.
161+
162+
---
163+
35164
## February 2023
36165

37166
### General Availability - Expanding Privileged Identity Management Role Activation across the Azure portal
@@ -45,7 +174,6 @@ Privileged Identity Management (PIM) role activation has been expanded to the Bi
45174

46175
For more information Microsoft cloud settings, see: [Activate my Azure resource roles in Privileged Identity Management](../privileged-identity-management/pim-resource-roles-activate-your-roles.md).
47176

48-
49177
---
50178

51179
### General Availability - Follow Azure AD best practices with recommendations
@@ -425,11 +553,11 @@ For listing your application in the Azure AD app gallery, read the details here
425553
**Service category:** Other
426554
**Product capability:** Developer Experience
427555

428-
As part of our ongoing initiative to improve the developer experience, service reliability, and security of customer applications, we'll end support for the Microsoft Authentication Library (ADAL). The final deadline to migrate your applications to Microsoft Authentication Library (MSAL) has been extended to **June 30, 2023**.
556+
As part of our ongoing initiative to improve the developer experience, service reliability, and security of customer applications, we'll end support for the Azure Active Directory Authentication Library (ADAL). The final deadline to migrate your applications to Azure Active Directory Authentication Library (MSAL) has been extended to **June 30, 2023**.
429557

430558
### Why are we doing this?
431559

432-
As we consolidate and evolve the Microsoft Identity platform, we're also investing in making significant improvements to the developer experience and service features that make it possible to build secure, robust and resilient applications. To make these features available to our customers, we needed to update the architecture of our software development kits. As a result of this change, we’ve decided that the path forward requires us to sunset Azure Active Directory Authentication Library. This allows us to focus on developer experience investments with Microsoft Authentication Library.
560+
As we consolidate and evolve the Microsoft Identity platform, we're also investing in making significant improvements to the developer experience and service features that make it possible to build secure, robust and resilient applications. To make these features available to our customers, we needed to update the architecture of our software development kits. As a result of this change, we’ve decided that the path forward requires us to sunset Azure Active Directory Authentication Library. This allows us to focus on developer experience investments with Azure Active Directory Authentication Library.
433561

434562
### What happens?
435563

0 commit comments

Comments
 (0)