Loading...

Microsoft Entra change announcements - June 2022 train

Microsoft Entra change announcements - June 2022 train

Hello Everyone,

 

In March 2022, we announced our simplified change management process, which allows customers to predictably plan their deployments. Earlier this month at RSA, we introduced Microsoft Entra as our new product family that encompasses all of Microsoft’s identity and access capabilities. Today we're excited to share that our newly announced change management process will expand to cover all of Microsoft Entra. We're also sharing our June train for feature changes and breaking changes.

 

We communicate these changes every quarter to our customers with the blog and release notes and via email. We're also continuing to make it easier for our customers to manage lifecycle changes (deprecations, retirements, service breaking changes) within the Entra portal experience. Below is a quick snapshot of our communication schedule, with biannual product retirement communication and quarterly breaking/feature changes.

 

Categories 

Definition 

Communication Schedule 

Retirement announcement 

Refers to the retirement of a feature, capability, or product in a specified period. This is typically accompanied by the service/feature rejecting new customers and a reduction in engineering investments to enhance retired features or capability. Eventually, the feature is no longer available to any customer and marks end-of-life.  

2 x per year (Mar and Sep) 

Breaking change announcement, feature change announcement 

Breaking change: Expected to break the customer/partner experience if the customer doesn’t act or make a change in their workload for continued operation.  

 

Feature change: Change to an existing Identity feature​ that doesn’t require customer action but is noticeable to the customer. These are typically UI/UX changes. 

 

These changes generally happen more often and require a more frequent communication schedule. 

4 x per year (Mar, June, Sep, and Nov) 

 

 

Here’s the list of feature change announcements that are part of the June 2022 train: 

 

Max configured permissions for app

Microsoft recently made a change to enforce our documented limits on the maximum number of configured permissions for an app registration. Apps that exceed these limits could enter a broken state in which consent is no longer possible. On October 31, 2022, apps that already have more than 400 configured permissions in their "requiredResourceAccess" collection will no longer be able to add additional permissions above the limit. Current permissions will remain configured on the app but adding a new permission will require the app owner to remove existing permissions until the total number is below the documented limit. This change will help customers avoid getting their apps into a broken state in which they aren’t able to give consent. For more information, see Microsoft Graph permissions reference - Microsoft Graph | Microsoft Docs and Validation differences by supported account types - Microsoft Entra | Microsoft Docs.  

 

Admin consent for Directory.AccessAsUser.All

On August 31, 2022, Microsoft will require admin consent for the Directory.AccessAsUser.All by default on all services. Admin consent will be required by default when the permission is requested for either Azure AD Graph (graph.windows.net) or Microsoft Graph (graph.microsoft.com). Previously, the permission didn’t require admin consent by default in certain scenarios. This change will only affect new consent requests and will improve security and align Directory.AccessAsUser.All with its current documented behavior. For more information, see Azure Active Directory (AD) Graph API Permission Scopes | Microsoft Docs. 

 

Group email

We’re switching to a new and improved service to send group-related emails. Group-related emails for the following scenarios will remain the same but will come from a new alias ([email protected]): When a Microsoft 365 group is going to expire; when a user requests to join a Microsoft 365 or security group; and when a group owner responds to a request to join a Microsoft 365 or security group. This change will help improve reliability and will enable faster email delivery and scalability for group emails.

 

Default consent setting

Starting September 30, 2022, Microsoft will enforce that all new tenants “Follow the Latest Microsoft Recommendation” as the new default consent setting. End users will no longer be able to grant consent to multi-tenant apps that request permissions beyond Microsoft-determined low-impact permissions without verified publishers. This change will reduce the risk of malicious applications attempting to trick users into granting access to their organization's data. 

 

As always, we’d love to hear your feedback or suggestions. Let us know what you think in the comments below or on the Azure AD feedback forum. You may also send your questions, open issues, and feature requests through Microsoft Q&A by using the tag #AzureADChangeManagementJune2022Train. 

 

 

Learn more about Microsoft identity: 

 

 

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.