You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For more information about how to better secure your organization by using automated user account provisioning, see [Automate user provisioning to SaaS applications with Azure AD](../app-provisioning/user-provisioning.md).
1013
-
1014
-
1015
-
---
1016
-
1017
-
1018
-
### Public Preview - Roles are being assigned outside of Privileged Identity Management
Customers can be alerted on assignments made outside PIM either directly on the Azure portal or also via email. For the current public preview, the assignments are being tracked at the subscription level. For more information, see [Configure security alerts for Azure roles in Privileged Identity Management](../privileged-identity-management/pim-resource-roles-configure-alerts.md#alerts).
1025
-
1026
-
---
1027
-
1028
-
1029
-
### General Availability - Temporary Access Pass is now available
1030
-
1031
-
**Type:** New feature
1032
-
**Service category:** MFA
1033
-
**Product capability:** User Authentication
1034
-
1035
-
1036
-
1037
-
Temporary Access Pass (TAP) is now generally available. TAP can be used to securely register password-less methods such as Phone Sign-in, phishing resistant methods such as FIDO2, and even help Windows onboarding (AADJ and WHFB). TAP also makes recovery easier when a user has lost or forgotten their strong authentication methods and needs to sign in to register new authentication methods. For more information, see: [Configure Temporary Access Pass in Azure AD to register Passwordless authentication methods](../authentication/howto-authentication-temporary-access-pass.md).
1038
-
1039
-
1040
-
---
1041
-
1042
-
1043
-
1044
-
### Public Preview of Dynamic Group support for MemberOf
1045
-
1046
-
**Type:** New feature
1047
-
**Service category:** Group Management
1048
-
**Product capability:** Directory
1049
-
1050
-
1051
-
1052
-
Create "nested" groups with Azure AD Dynamic Groups! This feature enables you to build dynamic Azure AD Security Groups and Microsoft 365 groups based on other groups! For example, you can now create Dynamic-Group-A with members of Group-X and Group-Y. For more information, see: [Steps to create a memberOf dynamic group](../enterprise-users/groups-dynamic-rule-member-of.md#steps-to-create-a-memberof-dynamic-group).
1053
-
1054
-
1055
-
---
1056
-
1057
-
1058
-
1059
-
### New Federated Apps available in Azure AD Application gallery - June 2022
1060
-
1061
-
**Type:** New feature
1062
-
**Service category:** Enterprise Apps
1063
-
**Product capability:** 3rd Party Integration
1064
-
1065
-
1066
-
1067
-
In June 2022 we've added the following 22 new applications in our App gallery with Federation support:
We're delighted to announce a new security protection that prevents bypassing of cloud Azure AD Multi-Factor Authentication when federated with Azure AD. When enabled for a federated domain in your Azure AD tenant, it ensures that a compromised federated account can't bypass Azure AD Multi-Factor Authentication by imitating that a multi factor authentication has already been performed by the identity provider. The protection can be enabled via new security setting, [federatedIdpMfaBehavior](/graph/api/resources/internaldomainfederation?view=graph-rest-1.0#federatedidpmfabehavior-values&preserve-view=true).
1092
-
1093
-
We highly recommend enabling this new protection when using Azure AD Multi-Factor Authentication as your multi factor authentication for your federated users. To learn more about the protection and how to enable it, visit [Enable protection to prevent by-passing of cloud Azure AD Multi-Factor Authentication when federated with Azure AD](/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs#enable-protection-to-prevent-by-passing-of-cloud-azure-ad-multi-factor-authentication-when-federated-with-azure-ad).
1094
-
1095
-
1096
-
---
1097
-
1098
-
1099
-
1100
-
### Public Preview - New Azure AD Portal All Users list and User Profile UI
1101
-
1102
-
**Type:** Changed feature
1103
-
**Service category:** User Management
1104
-
**Product capability:** User Management
1105
-
1106
-
1107
-
We're enhancing the All Users list and User Profile in the Azure AD Portal to make it easier to find and manage your users. Improvements include:
1108
-
1109
-
1110
-
All Users List:
1111
-
- Infinite scrolling (yes, no 'Load more')
1112
-
- More user properties can be added as columns and filtered on
1113
-
- Columns can be reordered via drag and drop
1114
-
- Default columns shown and their order can be managed via the column picker
1115
-
- The ability to copy and share the current view
1116
-
1117
-
1118
-
User Profile:
1119
-
- A new Overview page that surfaces insights (that is, group memberships, account enabled, MFA capable, risky user, etc.)
1120
-
- A new monitoring tab
1121
-
- More user properties can be viewed and edited in the properties tab
1122
-
1123
-
For more information, see: [User management enhancements in Azure Active Directory](../enterprise-users/users-search-enhanced.md).
1124
-
1125
-
---
1126
-
1127
-
1128
-
1129
-
### General Availability - More device properties supported for Dynamic Device groups
1130
-
1131
-
**Type:** Changed feature
1132
-
**Service category:** Group Management
1133
-
**Product capability:** Directory
1134
-
1135
-
1136
-
1137
-
You can now create or update dynamic device groups using the following properties:
1138
-
- deviceManagementAppId
1139
-
- deviceTrustType
1140
-
- extensionAttribute1-15
1141
-
- profileType
1142
-
1143
-
For more information on how to use this feature, see: [Dynamic membership rule for device groups](../enterprise-users/groups-dynamic-membership.md#rules-for-devices).
0 commit comments