You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory-b2c/azure-monitor.md
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,7 +32,8 @@ In this article, you learn how to transfer the logs to an Azure Log Analytics wo
32
32
> When you plan to transfer Azure AD B2C logs to different monitoring solutions, or repository, consider the following. Azure AD B2C logs contain personal data. Such data should be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing, using appropriate technical or organizational measures.
33
33
34
34
Watch this video to learn how to configure monitoring for Azure AD B2C using Azure Monitor.
Copy file name to clipboardExpand all lines: articles/active-directory-b2c/language-customization.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,6 +34,10 @@ You might not need that level of control over what languages your customer sees.
34
34
> [!NOTE]
35
35
> If you're using custom user attributes, you need to provide your own translations. For more information, see [Customize your strings](#customize-your-strings).
36
36
37
+
Watch this video to learn how to localize or customize language using Azure AD B2C.
@@ -30,6 +30,213 @@ The What's new in Azure Active Directory? release notes provide information abou
30
30
31
31
---
32
32
33
+
## February 2021
34
+
35
+
### Email one-time passcode authentication on by default starting October 2021
36
+
37
+
**Type:** Plan for change
38
+
**Service category:** B2B
39
+
**Product capability:** B2B/B2C
40
+
41
+
Starting October 31, 2021, Microsoft Azure Active Directory [email one-time passcode authentication](../external-identities/one-time-passcode.md) will become the default method for inviting accounts and tenants for B2B collaboration scenarios. At this time, Microsoft will no longer allow the redemption of invitations using unmanaged Azure Active Directory accounts.
42
+
43
+
---
44
+
45
+
### Unrequested but consented permissions will no longer be added to tokens if they would trigger Conditional Access
46
+
47
+
**Type:** Plan for change
48
+
**Service category:** Authentications (Logins)
49
+
**Product capability:** Platform
50
+
51
+
Currently, applications using [dynamic permissions](../develop/v2-permissions-and-consent.md#requesting-individual-user-consent) are given all of the permissions they're consented to access. This includes applications that are unrequested and even if they trigger conditional access. For example, this can cause an app requesting only `user.read` that also has consent for `files.read`, to be forced to pass the Conditional Access assigned for the `files.read` permission.
52
+
53
+
To reduce the number of unnecessary Conditional Access prompts, Azure AD is changing the way that unrequested scopes are provided to applications. Apps will only trigger conditional access for permission they explicitly request. For more information, read [What's new in authentication](../develop/reference-breaking-changes.md#conditional-access-will-only-trigger-for-explicitly-requested-scopes).
54
+
55
+
---
56
+
57
+
### Public preview - Use a Temporary Access Pass to register Passwordless credentials
Temporary Access Pass is a time-limited passcode that serves as strong credentials and allows onboarding of Passwordless credentials and recovery when a user has lost or forgotten their strong authentication factor (for example, FIDO2 security key or Microsoft Authenticator) app and needs to sign in to register new strong authentication methods. [Learn more](../authentication/howto-authentication-temporary-access-pass.md).
64
+
65
+
---
66
+
67
+
### Public preview - Keep me signed in (KMSI) in next generation of user flows
The next generation of B2C user flows now supports the [keep me signed in (KMSI)](../../active-directory-b2c/session-behavior.md?pivots=b2c-custom-policy#enable-keep-me-signed-in-kmsi) functionality that allows customers to extend the session lifetime for the users of their web and native applications by using a persistent cookie. feature keeps the session active even when the user closes and reopens the browser, and is revoked when the user signs out.
74
+
75
+
---
76
+
77
+
### Public preview - Reset redemption status for a guest user
78
+
79
+
**Type:** New feature
80
+
**Service category:** B2B
81
+
**Product capability:** B2B/B2C
82
+
83
+
Customers can now reinvite existing external guest users to reset their redemption status, which allows the guest user account to remain without them losing any access. [Learn more](../external-identities/reset-redemption-status.md).
84
+
85
+
---
86
+
87
+
### Public preview - /synchronization (provisioning) APIs now support application permissions
Customers can now use application.readwrite.ownedby as an application permission to call the synchronization APIs. Note this is only supported for provisioning from Azure AD out into third-party applications (for example, AWS, Data Bricks, etc.). It is currently not supported for HR-provisioning (Workday / Successfactors) or Cloud Sync (AD to Azure AD). [Learn more](/graph/api/resources/provisioningobjectsummary?view=graph-rest-beta&preserve-view=true).
94
+
95
+
---
96
+
97
+
### General availability - Authentication Policy Administrator built-in role
98
+
99
+
**Type:** New feature
100
+
**Service category:** RBAC
101
+
**Product capability:** Access Control
102
+
103
+
Users with this role can configure the authentication methods policy, tenant-wide MFA settings, and password protection policy. This role grants permission to manage Password Protection settings: smart lockout configurations and updating the custom banned passwords list. [Learn more](../roles/permissions-reference.md#authentication-policy-administrator).
104
+
105
+
---
106
+
107
+
### General availability - User collections on My Apps are available now!
108
+
109
+
**Type:** New feature
110
+
**Service category:** My Apps
111
+
**Product capability:** End User Experiences
112
+
113
+
Users can now create their own groupings of apps on the My Apps app launcher. They can also reorder and hide collections shared with them by their administrator. [Learn more](../user-help/my-apps-portal-user-collections.md).
114
+
115
+
---
116
+
117
+
### General availability - Autofill in Authenticator
Microsoft Authenticator provides Multi-factor Authentication (MFA) and account management capabilities, and now also will autofill passwords on sites and apps users visit on their mobile (iOS and Android).
124
+
125
+
To use autofill on Authenticator, users need to add their personal Microsoft account to Authenticator and use it to sync their passwords. Work or school accounts cannot be used to sync passwords at this time. [Learn more](../user-help/user-help-auth-app-faq.md#autofill-for-it-admins).
126
+
127
+
---
128
+
129
+
### General availability - Invite internal users to B2B collaboration
130
+
131
+
**Type:** New feature
132
+
**Service category:** B2B
133
+
**Product capability:** B2B/B2C
134
+
135
+
Customers can now invite internal guests to use B2B collaboration instead of sending an invitation to an existing internal account. This allows customers to keep that user's object ID, UPN, group memberships, and app assignments. [Learn more](../external-identities/invite-internal-users.md).
136
+
137
+
---
138
+
139
+
### General availability - Domain Name Administrator built-in role
140
+
141
+
**Type:** New feature
142
+
**Service category:** RBAC
143
+
**Product capability:** Access Control
144
+
145
+
Users with this role can manage (read, add, verify, update, and delete) domain names. They can also read directory information about users, groups, and applications, as these objects have domain dependencies.
146
+
147
+
For on-premises environments, users with this role can configure domain names for federation so that associated users are always authenticated on-premises. These users can then sign into Azure AD-based services with their on-premises passwords via single sign-on. Federation settings need to be synced via Azure AD Connect, so users also have permissions to manage Azure AD Connect. [Learn more](../roles/permissions-reference.md#domain-name-administrator).
148
+
149
+
---
150
+
151
+
### New Federated Apps available in Azure AD Application gallery - February 2021
152
+
153
+
**Type:** New feature
154
+
**Service category:** Enterprise Apps
155
+
**Product capability:** 3rd Party Integration
156
+
157
+
In February 2021 we have added following 37 new applications in our App gallery with Federation support:
For more information, read [Automate user provisioning to SaaS applications with Azure AD](../app-provisioning/user-provisioning.md).
184
+
185
+
---
186
+
187
+
### General availability - 10 Azure Active Directory roles now renamed
188
+
189
+
**Type:** Changed feature
190
+
**Service category:** RBAC
191
+
**Product capability:** Access Control
192
+
193
+
10 Azure AD built-in roles have been renamed so that they're aligned across the [Microsoft 365 admin center](/microsoft-365/admin/microsoft-365-admin-center-preview), [Azure AD portal](https://portal.azure.com/), and [Microsoft Graph](https://developer.microsoft.com/graph/). To learn more about the new roles, refer to [Administrator role permissions in Azure Active Directory](../roles/permissions-reference.md#all-roles).
194
+
195
+

196
+
197
+
---
198
+
199
+
### New Company Branding in MFA/SSPR Combined Registration
200
+
201
+
**Type:** Changed feature
202
+
**Service category:** User Experience and Management
203
+
**Product capability:** End User Experiences
204
+
205
+
In the past, company logos weren't used on Azure Active Directory sign-in pages. Company branding is now located to the top left of MFA/SSPR Combined Registration. Company branding is also included on My Sign-Ins and the Security Info page. [Learn more](../fundamentals/customize-branding.md).
206
+
207
+
---
208
+
209
+
### General availability - Second level manager can be set as alternate approver
210
+
211
+
**Type:** Changed feature
212
+
**Service category:** User Access Management
213
+
**Product capability:** Entitlement Management
214
+
215
+
An extra option when you select approvers is now available in Entitlement Management. If you select "Manager as approver" for the First Approver, you will have another option, "Second level manager as alternate approver", available to choose in the alternate approver field. If you select this option, you need to add a fallback approver to forward the request to in case the system can't find the second level manager. [Learn more](../governance/entitlement-management-access-package-approval-policy.md#alternate-approvers).
216
+
217
+
---
218
+
219
+
### Authentication Methods Activity Dashboard
220
+
221
+
**Type:** Changed feature
222
+
**Service category:** Reporting
223
+
**Product capability:** Monitoring & Reporting
224
+
225
+
226
+
The refreshed Authentication Methods Activity dashboard gives admins an overview of authentication method registration and usage activity in their tenant. The report summarizes the number of users registered for each method, and also which methods are used during sign-in and password reset. [Learn more](../authentication/howto-authentication-methods-activity.md).
227
+
228
+
---
229
+
230
+
### Refresh and session token lifetimes configurability in Configurable Token Lifetime (CTL) are retired
231
+
232
+
**Type:** Deprecated
233
+
**Service category:** Other
234
+
**Product capability:** User Authentication
235
+
236
+
Refresh and session token lifetimes configurability in CTL are retired. Azure Active Directory no longer honors refresh and session token configuration in existing policies. [Learn more](../develop/active-directory-configurable-token-lifetimes.md#token-lifetime-policies-for-refresh-tokens-and-session-tokens).
237
+
238
+
---
239
+
33
240
## January 2021
34
241
35
242
### Secret token will be a mandatory field when configuring provisioning
0 commit comments