A critical vulnerability was resolved in Veeam Backup & Replication v12.3.2.4854

Reading Time: 2 minutes

Veeam Backup & Replication

Yesterday, Veeam addressed a critical vulnerability in its Backup & Replication v12 product, that allows adversaries to execute arbitrary code on the Backup Server… but only when the host is domain-joined.

 

About Veeam Backup & Replication

Veeam Backup & Replication (VBR) is a comprehensive data protection and disaster recovery solution designed for virtual, physical, and cloud-based workloads. It provides fast, secure backup, replication, and restoration for platforms like VMware, Hyper-V, AWS, Azure, and Google Cloud. Key features include image-level backups, instant VM recovery, ransomware protection via immutable storage, and built-in WAN acceleration.

Veeam's products are used by over 550,000 organizations worldwide, including 82% of Fortune 500 companies and 74% of Global 2,000 firms.

 

About the vulnerability

Veeam Backup & Replication v12.3.2.4854, released on June 9th, 2026, addresses a critical vulnerability.

The vulnerability, known as CVE-2026-44963, and accompanied by a CVSS v4 score of 9.4 on a scale of 1 to 10, allows remote code execution (RCE) on the Backup Server by an authenticated domain user.

The vulnerability was reponsibly disclosed to Veeam by Sina Kheirkhah of WatchTowr.

 

Is my Backup Server vulnerable?

A Backup Server is only vulnerable if both following conditions are met:

  • The Backup Server runs one of the following versions:
    • v12.3.2.4465
    • v12.3.2.4165
    • v12.3.2.3617
    • v12.3.1.1139
    • v12.3.0.310
    • v12.2.x
    • v12.1.x
    • v12.0.x
  • The Backup Server is joined to Active Directory

 

Call to Action

The above vulnerability is addressed by upgrading Veeam Backup & Replication v12 to v12.3.2.4854, or up. Please update your Backup Servers.

Veeam has long recommended to no longer join Backup Servers to Active Directory. If this recommendation was missed, reimplementing Veeam Backup & Replication on non-domain-joined hosts may be a worthwhile item on your system administration team's backlog.

0  

What's New in Entra in April 2026

Reading Time: 7 minutes

Microsoft Entra

Entra, previously known as Azure Active Directory, is Microsoft's Identity Management-as-a-Service solution, offering seamless access, easy collaboration, efficiency in IT processes and improved security and compliance. In its Release Notes for Entra ID and in the Message Center, Microsoft communicated the following planned, new and changed functionality for Entra for April 2026:

 

What's Planned

Migrate from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync

Service category: Entra Connect
Product capability: Entra Connect

As organizations look to strengthen identity security and advance their Zero Trust strategies, many are looking for simpler, more reliable ways to manage hybrid identity. To support these needs, Microsoft is beginning the transition from Microsoft Entra Connect Sync to the cloud‑native Microsoft Entra Cloud Sync, helping reduce on‑premises complexity while improving security, reliability, and day‑to‑day manageability.

This shift is a key step toward a cloud-managed identity future that will provide a more secure, resilient, and easier-to-operate synchronization experience. As part of ongoing modernization efforts, Microsoft’s strategy remains to deliver stronger security, improved reliability, and simpler identity operations.

Beginning in July 2026, Microsoft will begin notifying organizations through the M365 Message Center, Entra Connect Health, and targeted emails about their individual transition timelines. The transition will be rolled out in phases,

 

Update SCIM provisioning applications to use modern authentication

Service category: Provisioning
Product capability: Outbound to SaaS Applications

SCIM provisioning applications that use the OAuth 2.0 Authorization Code grant will be updated to support modern authentication methods, such as OAuth 2.0 Client Credentials and workload identity federation. Existing provisioning jobs will not switch automatically. Organizations will need to update job configuration after the new method is available. A small number of applications that cannot support a modern method may be retired from the Microsoft Entra app gallery.

This update strengthens the security of Microsoft Entra provisioning integrations by moving away from older authentication patterns. Modern methods are better suited for service-to-service scenarios and can reduce credential management overhead, including the need to rotate shared secrets.

This change will roll out over the coming months, and timing will vary by application. Microsoft will share impacted applications, organization deadlines, and supporting documentation through monthly What’s new articles and the Microsoft 365 Message Center.

 

Switch from basic auth to workload identity based auth for SAP SuccessFactors provisioning integrations

Service category: Provisioning
Product capability: Inbound to Entra ID

Microsoft Entra is introducing workload identity–based authentication for SAP SuccessFactors provisioning. This new capability allows the Microsoft Entra provisioning service to authenticate to SAP SuccessFactors using Entra workload identity and short‑lived tokens instead of static credentials (username and password).

This change helps organizations transition to a more secure authentication model in preparation for SAP’s plan to deprecate basic authentication for SuccessFactors APIs by November 2026.

 

What's New

License Usage General Availability

Service category: Reporting
Product capability: Monitoring & Reporting

The License Usage page in the Microsoft Entra admin center helps organizations optimize their Entra licenses by providing visibility into feature usage across their Entra tenant. It shows how many Entra ID P1, P2, and Suite licenses the organizations owns, along with usage of key features such as Conditional Access and risk‑based Conditional Access mapped to each license type. Admins can also review usage trends over the past six months. This view gives them a clearer understanding of the license footprint, the value the organization derives from Entra, and potential over‑usage risks within the Entra tenant.

 

Configurable Token Lifetime Policies General Availability

Service category: Authentications (Logins)
Product capability: Platform

Configurable token lifetime policies are now generally available in Microsoft Entra ID. This feature allows admins to customize the lifetimes of access tokens, ID tokens, and SAML tokens issued by the Microsoft identity platform by creating and assigning token lifetime policies to applications and service principals.

With configurable token lifetime policies, organizations can adjust token durations to meet their security and usability requirements.

 

Microsoft Entra Agent ID platform General Availability

Service category: Other
Product capability: Identity Security & Protection

The Microsoft Entra Agent ID platform is now generally available. The Agent ID platform provides an identity and authorization framework built specifically for AI agents operating in enterprise environments. It enables developers to create and manage agent identities with enterprise-grade authentication, authorization, and governance, using standard protocols such as OAuth 2.0, MCP, and A2A.

 

Microsoft Entra Certificate-based authentication (CBA) support on iOS and CBA as second factor General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

Microsoft Entra Certificate-Based Authentication (CBA) is now generally available on iOS. Native iOS sign-ins now avoid unnecessary password and multi-factor authentication (MFA) prompts, enabling CBA as a supported second factor and allowing it to be prioritized as a system‑preferred MFA method. People can choose another allowed MFA method if needed, based on tenant policy.

 

Entra CBA as third option in system-preferred MFA methods General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

Due to known issues on iOS platform, the Entra certificate-based authentication (CBA) method was not allowed as a second factor on iOS and CBA was moved to the last place in the system-preferred MFA list.

Microsoft has enhanced the user experience during sign-in with certificate in native iOS apps by removing unnecessary passwords and MFA prompts with all the known issues addressed. The feature enhancement enables Microsoft to support CBA as a second factor on iOS, and to move CBA to the third place in system preferred MFA methods.

 

Issuer Hints for Microsoft Entra CBA General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

The Issuer Hints feature is generally available now and helps improve the sign‑in experience for Entra Certificate‑Based Authentication (CBA) by ensuring people are prompted to select only certificates that are trusted and valid for their organization. This reduces confusion, minimizes sign‑in errors, and streamlines certificate selection especially on devices with multiple certificates installed. Issuers hints are designed to enhance both security and usability without changing how certificates are issued or managed.

 

Entra CBA Certificate Authority (CA) scoping General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

Entra CBA Certificate Authority (CA) scoping in Microsoft Entra allows tenant admins to restrict the use of specific certificate authorities (CAs) to defined user groups. This feature enhances the security and manageability of certificate-based authentication (CBA) by ensuring that only authorized users can authenticate using certificates issued by specific CAs.

 

Enforce Conditional Access policies on every PIM activation General Availability

Service category: Privileged Identity Management
Product capability: Privileged Identity Management

Configuring reauthentication with Conditional Access for Microsoft Entra Privileged Identity Management role activation is now generally available.

 

Enabling Social Identity Providers in Entra External ID Native Authentication via browser‑delegated (web‑view) flows using SDKs for applications General Availability

Service category: B2C – Consumer Identity Management
Product capability: Developer Experience

Build secure sign‑in and sign‑up experiences for applications in Entra External ID using Native Authentication, with Social Identity Provider support such as Google, Facebook, and Apple available through browser‑delegated (web‑view) authentication using developer‑friendly SDKs.

 

As an AP requestor, I can see in My Access who my approver(s) are if the access package owner allows me to General Availability

Service category: Entitlement Management
Product capability: Entitlement Management

In May, requestors will be able to see the name and email address of approvers for their pending access package requests directly in the My Access portal. This feature improves transparency and helps streamline communication between requestors and approvers. At the tenant level, approver visibility is enabled by default for all members (non-guests) and can be controlled through the Entitlement Management settings in the Microsoft Entra Admin Center. At the access package level, admins and access package owners can configure the approver visibility and choose to override the tenant level setting under the advanced request settings in the access package policy.

 

Prefetch Workday termination data to customize account disable logic General Availability

Service category: Provisioning
Product capability: Inbound to Entra ID

This Workday connector update resolves termination processing delays observed for workers in APAC and ANZ regions. Admins can now enable termination lookahead setting to prefetch data and tailor deprovisioning logic for accounts in Microsoft Entra ID and on-premises Active Directory.

 

Microsoft Identity Manager (MIM) 2016 Service Pack 3 (SP3) General Availability

Service category: Microsoft Identity Manager
Product capability: Identity Governance

Microsoft Identity Manager (MIM) 2016 Service Pack 3 (SP3) is now available. SP3 focuses on stability and supportability, modernizes compatibility with current platform components (SQL Server, SharePoint, and Exchange), and adds an additional deployment option for the Synchronization Service by enabling Azure SQL Database with managed identity authentication, helping reduce operational risk for hybrid identity environments.

 

GSA iOS client support General Availability

Service category: iOS client
Product capability: Network Access

The iOS Global Secure Access (GSA) client is now generally available. The Global Secure Access client on iOS and iPadOS requires no new agent installation. It leverages the existing Microsoft Defender for Endpoint (MDE) to route traffic through Microsoft SSE for Microsoft 365, internet access, and private access.

 

GSA Cloud Firewall for Remote Networks General Availability

Service category: Internet Access
Product capability: Network Access

Organizations can use GSA cloud firewall to apply admin configurable, 5-tuple (source IP, destination IP, protocol, source port, destination port) based filtering for all internet traffic acquired from branch offices through GSA remote networks capability.

 

Network Content Filtering based on File Types General Availability

Service category: Internet Access
Product capability: Network Access

Global Secure Access supports network-based content filtering based on file types. This allows admins to monitor and control file transfers across the network to GenAI and SaaS apps to prevent unauthorized exfiltration of content.

 

$count filtering in sign-ins API Public Preview

Service category: MS Graph
Product capability: Monitoring & Reporting

The ability to use $count in sign-ins API requests is now here, allowing organizations to perform count computations directly in API requests.

 

App-based branding via Branding themes in Microsoft Entra tenants Public Preview

Service category: User Experience and Management
Product capability: User Authentication

In Microsoft Entra tenants, organizations can create a single, tenant-wide, customized branding experience that applies to all apps. Microsoft is introducing the concept of Branding themes to allow organizations to create different branding experiences for specific applications.

 

Microsoft Entra ID federation with External ID Public Preview

Service category: B2C – Consumer Identity Management
Product capability: 3rd Party Integration

Microsoft Entra ID federation with External ID enables organizations to let people sign in to customer‑facing applications using their existing workforce Entra ID identities. By leveraging standards‑based federation, people authenticate with their home tenant while applications hosted in an External ID tenant rely on trusted identity assertions from Entra ID. This approach reduces the need for duplicate accounts, streamlines sign‑in experiences, and allows organizations to extend consistent security controls across workforce and customer scenarios.

 

Account Discovery Public Preview

Service category: Provisioning
Product capability: 3rd Party Integration

Microsoft Entra ID Governance now supports account discovery for connected applications in public preview. This capability provides administrators with visibility into all accounts that exist within connected applications, including orphan accounts.

By generating discovery reports directly from the provisioning experience, organizations can identify accounts in connected applications that are not assigned to the enterprise application in Entra and simplify onboarding the application.

This capability requires a Microsoft Entra ID Governance or Microsoft Entra Suite license.

1  

Come learn with KNVI about the impact AI has on IT

Reading Time: 3 minutes

KNVI AI-IT Impact event

On Wednesday May 20, 2026, I’m co-presenting at KNVI’s 'AI-IT Impact' event Dutch at Nest in Amstelveen Dutch. Fellow speakers Raymond Comvalius, Tom Dalderup and Erwin Derksen are my co-presenters for this day to answer the question: What happens if AI is just running in your organization tomorrow but no one has a clear idea of who has access to what, which apps act on behalf of whom and who monitors the rules?

.

 

About KNVI

KNVIThe Dutch Professional Association of Information and IT Professionals (KNVI) is an independent platform for sharing professional knowledge and expanding the personal networks of ICT Pros, information professionals, students and employers who want to keep their employees up to date.

KNVI organizes multiple meetings per month, publishes AG Connect both online and in print, and offers discounts to its members.

 

About the AI-IT Impact event

AI-IT Impact Day 2026 is a day for people who feel that AI is no longer about experimentation, but about direction. About the moment when you discover that the real questions are not technical or organizational, but both at the same time: what do you allow, what do you shield, and how do you keep it workable without stifling innovation?

Attendees get a clear, down-to-earth picture of where AI pinches and yields benefits in practice: in choices about use (Copilot/ChatGPT and everything around it), and in the control points that often only become visible when things get tense: identity, rights, consent, governance, lifecycle. Not as a checklist fetish, but as a way to safely accelerate AI.

This day stimulates, sharpens and helps attendees make choices that are already relevant on Monday.

The program

After a short introduction, starting at 10 AM, Erwin Derksen discusses organization and technology with a session focusing on six real-world scenarios. for each of these scenarios, he provides an overview of which AI is the best fit, what should be the requirements to implement AI and what could go wrong when introducing AI in your organization into these scenarios. He also discusses the upcoming AI act, AI literacy and NIS2 requirements.

After the lunch break, I present for an hour on identity as the AI control plane. Immediately after my session, fellow Microsoft MVP Raymond Comvalius presents his views on the AI ready workplace.

 

Join us!

Are you ready to start mastering AI, instead of merely deploying it? Do you want to learn what AI choices you have to make in advance to avoid hassle afterward? Are you questioning why identity is increasingly becoming the control plane of AI and what that means for your environment? Are you looking for practical AI baselines?  Let's explore together, with inspiring speakers, on Wednesday, May 20, 2026 at NEST Amstelveen!

Get your tickets here Dutch.

KNVI members can attend this event for free. Non-KNVI members pay EUR 195,70, excluding VAT. This includes a 1-year subscription to KNVI. Subscriptions to KNVI for students are a mere EUR 35,25 per year. Subscriptions for individuals start at EUR 117,50 per year for members aged 27 and below, for retirees and for unemployed people. Organizational subscriptions are available upon request.

0  

From the field: The Case of Protected Users being shut out of RDP after removing the last Windows Server 2019 Domain Controller

Reading Time: 2 minutes

From the field

Troubleshooting stories from the field are the best. That’s why I like writing them down. Although, sometimes they might appear as straight cases of schadenfreude, I feel there are lessons to be learned for anyone, if you’re willing to look closely and listen carefully.

This week I experienced an issue at an organization, while they were transitioning their Domain Controllers from Windows Server 2019 to Windows Server 2025. It turned out they were following Microsoft’s recommendations, except for one…

 

The situation

The organization has an Active Directory Domain Services (AD DS) environment with Domain Controllers running Windows Server 2019. Recently, they have added Windows Server 2025-based Domain Controllers with the intent to decommission the Windows Server 2019-based Domain Controllers. The Domain and Forest Functional Level are both Windows Server 2016. (This is actually a requirement for introducing Windows Server 2025-based Domain Controllers.)

Admin accounts are members of the Protected Users security group and typically sign into the Domain Controllers using RDP from devices joined to a trusted Active Directory forest.

To optimize the hardening of the new Domain Controllers, the identity admin team has configured separate (CIS benchmark-based) Group Policy objects (GPOs) for hardening.

To align with the upcoming public certificate lifetime changes, the Public Key Infrastructure (PKI) admin, managing Active Directory Certificate Services (AD CS), also created a new certificate template for the Windows Server 2025-based Domain Controllers, based on the Kerberos Authentication template.

 

The issue

After decommissioning the last Windows Server 2019-based Domain Controller, admins can no longer sign into Domain Controllers using RDP.

When removing the admin accounts from the Protected Users security group, they can sign in again.

 

The cause

In this case, the cause wasn’t Windows Server 2025’s default settings. The hardened settings in the new Group Policy object also didn’t contribute to the situation.

The issue also isn't caused by any of the protections that Microsoft documented for signed-in Protected Users: RDP didn't use NTLM as the same approach to contacting the servers worked on Windows Server 2019 before. The new Domain Controllers were addressed with their fully-qualified domain names (FQDNs).

However, when reviewing the certificates issued to the new Windows Server 2025-based Domain Controllers, I noticed that only Server Authentication (1.3.6.1.5.5.7.3.1) and Client Authentication (1.3.6.1.5.5.7.3.2) were specified as enhanced key usage (EKU) extensions. EKUs are object identifiers (OIDs) that indicate the applications that use the key.

Smart Card Logon (1.3.6.1.4.1.311.20.2.2) was missing.

When I asked the PKI admin, his response was that he removed the Smart Card Logon EKU, as “smart cards are old technology and the organization doesn’t use smart cards.”…

 

The solution

We ended up creating a new certificate template based on the built-in Kerberos Authentication template with the recommended changes for Domain Controllers running Windows Server 2016, and up.

A certutil.exe -pulse on the Domain Controllers sealed the deal.

After enrolling the new certificate template, admins were able to sign into Domain Controllers using RDP while being members of the Protected Users group.

 

Concluding

The Smart Card Logon enhanced key usage enables a lot of strong authentication scenarios. Don’t remove it from your Domain Controller certificates.

0  

What's New in Entra in March 2026

Reading Time: 6 minutes

Microsoft Entra

Entra, previously known as Azure Active Directory, is Microsoft's Identity Management-as-a-Service solution, offering seamless access, easy collaboration, efficiency in IT processes and improved security and compliance. In its Release Notes for Entra ID and in the Message Center, Microsoft communicated the following planned, new and changed functionality for Entra for March 2026:

 

What's Planned

Agent Registry consolidation into Microsoft Agent 365

Service category: Other
Product capability: Directory

Microsoft is consolidating agent management experiences to make it easier to observe, govern, and secure all agents in your tenant. Agent 365 will be the single source of truth, offering a unified catalog, consistent visibility, and simplified management. The Agent registry and Agent collections blades in the Entra admin center will be retired on May 1, 2026.

 

What's New

Synced passkeys in Microsoft Entra ID General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

Microsoft Entra ID now supports synced passkeys as a generally available authentication method. Synced passkeys are FIDO2-based credentials that can be stored in built-in or third-party passkey providers and made available across devices. Admins can manage the use of synced passkeys alongside device-bound passkeys through passkey profiles in the authentication methods policy. Existing passkey configurations can be managed using the same Entra ID authentication policies and reporting surfaces.

 

Passkey profiles in Microsoft Entra ID General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

Passkey profiles in Microsoft Entra ID are now generally available. Passkey profiles provide a structured way to manage passkey (FIDO2) authentication by allowing admins to define multiple profiles with different requirements and target them to specific user groups.

Each profile can specify allowed passkey types, attestation requirements, and authenticator restrictions, enabling differentiated policies for scenarios such as admins versus standard users. For tenants that previously configured passkeys, existing settings are migrated into a default passkey profile.

 

New M365 group creation experience in My Groups General Availability

Service category: Group Management
Product capability: End User Experiences

Microsoft is improving the Microsoft 365 group creation experience in the My Groups portal to give group owners more control and clarity from the start. The updated experience lets you configure key group, email, and security settings during creation, so your group works the way you expect without extra admin help later.

 

Microsoft Entra Connect Health now enforces TLS 1.2 General Availability

Service category: Entra Connect
Product capability: Entra Connect

Microsoft completed a full migration to TLS 1.2 for Entra Connect Health and removed legacy TLS 1.1 references as part of security hardening.

 

Just‑in‑Time Password Migration in Microsoft Entra External ID General Availability

Service category: B2C – Consumer Identity Management
Product capability: B2B/B2C

Just‑in‑Time Password Migration is now generally available in Microsoft Entra External ID.

Organizations can migrate user passwords securely at first sign‑in, allowing users to continue using their existing credentials without forced password resets. This enables a smoother transition from Azure AD B2C or other identity providers while reducing migration risk and operational overhead.

 

Enabling Email and SMS OTP MFA in Entra External ID Native Authentication General Availability

Service category: B2C – Consumer Identity Management
Product capability: Developer Experience

Build secure sign‑in and sign‑up experiences for applications in Entra External ID using Native Authentication, with Email and SMS OTP MFA available through developer‑friendly SDKs and APIs.

 

Microsoft Single Sign-On for Linux support for authenticating with Phish-Resistant MFA credentials General Availability

Service category: Authentications (Logins)
Product capability: SSO

The major improvements that this release provides includes:

  • Enables authentication using CBA/YubiKey with certificate (PRMFA)
  • Removes dependency on Java runtime as part of the Intune install
  • Improved performance and reliability when authenticating to EntraId
  • Provides device trust using Entra Join instead of Entra Registration
  • Increased stability and performance for authentication requests

 

Improved readability for Authentication Methods Policy Update audit logs General Availability

Service category: Authentications (Logins)
Product capability: User Authentication

Starting in April 2026, the Authentication Methods Policy Update and Authentication Methods Policy Reset audit log activities has been updated to improve readability and clarity. Previously, audit logs included the full authentication methods policy payload in both the old and new values, even when only a small number of settings were changed. With this update, audit log entries now surface only the specific properties that were modified, along with their corresponding old and new values.

Policy-wide updates, such as Registration Campaigns and System‑preferred authentication, may continue to include the full policy payload. The activity name and triggering events remain unchanged. This update affects formatting only and does not change policy behavior.

 

SCIM 2.0 APIs for Microsoft Entra ID General Availability

Service category: Provisioning
Product capability: Identity Lifecycle Management

SCIM 2.0 APIs give organizations, developers, and partners a standards-based option for managing users and groups in Microsoft Entra using the System for Cross-domain Identity Management (SCIM) 2.0 specification.

 

Tenant configuration management APIs General Availability 

Service category: Tenant Governance
Product capability: Tenant Governance

Tenant Configuration Management APIs allow organizations to take snapshots of their tenants' current configuration settings in a JSON format and to enforce configuration settings by offering continuous monitoring of drifts.

 

Microsoft Entra Backup and Recovery Public Preview

Service category: Entra Backup and Recovery
Product capability: Entra Backup and Recovery

Microsoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.

 

Microsoft Entra passkeys on Windows Public Preview

Service category: Authentications (Logins)
Product capability: User Authentication

Microsoft Entra passkeys on Windows are now available in public preview. This feature allows people to register device‑bound passkeys directly in the local Windows Hello container and use them to sign in to Microsoft Entra ID with Windows Hello biometrics or PIN.

Entra passkeys on Windows behave as standard FIDO2 credentials and can be used for Entra authentication flows without requiring the device to be Microsoft Entra-joined or -registered. During public preview, the feature is opt‑in and requires explicit configuration through passkey profiles to allow Windows Hello as a passkey provider.

 

Cross-tenant security group synchronization Public Preview

Service category: Provisioning
Product capability: Collaboration

Cross-tenant group synchronization is a new capability that allows organizations to synchronize security groups across Microsoft Entra tenants. This feature enables centralized management of group membership in a source tenant while making those groups available in one or more target tenants, simplifying cross-tenant collaboration and reducing administrative overhead associated with managing duplicate groups.

With cross-tenant group synchronization, organizations can extend their existing cross-tenant synchronization configurations to include groups, supporting scenarios such as shared application access, resource authorization, and consistent group-based access control across tenants. Admins can opt in to this functionality and configure attribute mappings and cross-tenant access policies to enable group synchronization into target tenants. Use of cross-tenant group synchronization requires Microsoft Entra ID Governance licenses. Existing licensing requirements for cross-tenant user synchronization features remains unchanged.

 

Tenant governance relationships Public Preview

Service category: Tenant Governance
Product capability: Tenant Governance

This feature allows admins to request and accept tenant governance relationships, which grant admins of the governing tenant access and administrative control over the governed tenant.

 

Service category: Tenant Governance
Product capability: Tenant Governance

This feature allows admins to discover related tenants connected to their own by B2B activity or shared billing information. Admins can use this information to request and establish tenant governance relationships, or to quarantine potential risks.

 

Tenant configuration management administration portal experience Public Preview

Service category: Tenant Governance
Product capability: Tenant Governance

Admins can use the Entra admin center to manage tenant configuration management capabilities of Entra tenant governance. Admins can use this experience to:

  • Create and update monitors to define the desired state of resources in your tenant across a range of Microsoft services, and monitor the actual state of those resources relative to the desired state on an ongoing basis
  • See reports of monitor results, and details of any configuration drifts identified by the configuration management service when it runs a monitor that you defined.
  • Manage permission for the configuration management service to monitor resources in your tenant, by assigning app permissions or Entra roles.

 

Secure add-on tenant creation Public Preview

Permissioned users can now create add-on tenants that are owned and governed by their home tenant. Governance is established through tenant governing relationships, granting admins access and control via GDAP.

 

Entra Hybrid Join using Entra Kerberos Public Preview

Service category: Device Registration and Management
Product capability: Device Lifecycle Management

This new capability enables a Windows device to become hybrid Entra-joined immediately at provisioning time, without waiting for Entra Connect Sync or requiring AD FS. By leveraging Entra Kerberos, organizations can modernize their hybrid identity architecture while reducing infrastructure complexity and dependency on legacy federation components.

 

Passkey Adoption Campaigns with the Conditional Access Optimization Agent Public Preview

Service category: Conditional Access
Product capability: Identity Security & Protection

The Conditional Access Optimization Agent now supports passkey adoption campaigns in public preview, helping organizations roll out phishing‑resistant authentication in a structured and automated way.

With this capability, the agent can assess user and device readiness, generate a recommended deployment plan, guide users through required steps, and automatically enforce Conditional Access policies once users are ready. Campaigns progress continuously as prerequisites are met, reducing manual effort for large‑scale passkey rollouts.

 

Phased Rollout with the Conditional Access Agent Public Preview

Service category: Conditional Access
Product capability: Identity Security & Protection

Admins can now use the Conditional Access Optimization Agent to safely roll out any report‑only Conditional Access policy in phases. When you initiate the process, the agent analyzes sign‑in data to recommend a low‑risk, staged deployment plan, starting with smaller user groups and gradually expanding, so you can turn policies on with confidence and minimize user impact.

0  

Join Jay Gundotra and me at the M365 Community Conference

Reading Time: 2 minutes

Microsoft 365 Community Conference

Jay Gundotra has invited me on stage of the Microsoft 365 Community Conference to present on Entra and Microsoft 365 Governance solutions. As the virtual Product Owner for ENow App Governance, I'm joining him, and of course I'm inviting you all to join me for this session.

 

About the M365 Community Conference

The Microsoft 365 Community Conference is a premier event focused on Microsoft 365 and delivers an unusually dense concentration of Microsoft-led training that would otherwise require multiple courses, consultants, or extended trial-and-error.

The Conference offers over 200 sessions across IT, security, data, development, and business roles, of which over 110 sessions led by Microsoft engineers and leaders and over 150 Microsoft product makers on-site. The Microsoft 365 Community Conference also offers 21 full-day, hands-on workshops (pre- and post-conference).

The 2026 Microsoft 365 Community Conference takes place at Loews Sapphire Falls and Loews Royal Pacific Resorts in Orlando from Sunday April 19th, 2026, to Friday April 24th, 2026.

 

About our session

Jay Gundotra (Technical Founder and CEO of ENow Software) and I present a 45-minute session on:

Top 5 Challenges Managing Microsoft 365, Copilot and Entra ID, and What to Fix First

Wednesday April 22nd, 2026, 1:30 PM – 2:15 PM, Room Banda Sea 1

As Microsoft 365 evolves, many IT teams discover that managing the platform has become significantly more complex. Collaboration sprawl, evolving permissions, expanding Entra ID application ecosystems, and the introduction of Microsoft Copilot place new operational demands on admins who must balance governance, security, cost control, and AI readiness simultaneously.

Our session explores the Top 5 operational challenges that Modern Workplace leaders face when managing Microsoft 365, Copilot, and Entra ID today, and why these issues appear across organizations regardless of size or industry. Our session breaks down the technical patterns driving governance drift, reactive troubleshooting, and visibility gaps across Teams, SharePoint, OneDrive, identity, and licensing.

You will learn how platform growth, identity expansion, and AI adoption reshape admin responsibilities, and how to regain operational control without slowing collaboration or innovation. We include practical administrative checks to help identify oversharing risks, unowned enterprise applications, and licensing inefficiencies. You'll leave with a clear framework for moving from reactive management toward proactive operational maturity, along with actionable steps you can begin applying immediately.

 

Join us!

Register for the Microsoft 365 Community Conference to join us!

1  

Sean Deuby interviews us on Entra app sprawl for Episode 91 of the HIP Podcast

Reading Time: < 1 minute

Hybrid Identity Protection Podcast Episode 91

Raymond Comvalius and I featured in an interview with Sean Deuby, Principal Technologist Americas at Semperis, for the Hybrid Identity Protection Podcast on Entra app sprawl.

 

About the Hybrid Identity Protection Podcast

The Hybrid Identity Protection (HIP) Podcast is the premier podcast for cybersecurity pros charged with defending hybrid identity environments from cyberattacks. Hosted by 15-year MVP alumnus Sean Deuby, the podcast includes conversations with global identity experts who share their strategic visions and practical guidelines for securing Active Directory and Entra ID, preventing and remediating identity-based attacks, and recovering from identity system attacks.

I also featured in an episodes on Choosing the right authentication method and an episode on Getting rid of AD FS.

 

About our interview

In this episode of the HIP Podcast, we explore a growing blind spot in cloud security: application governance. As organizations adopt more cloud apps and integrations, identity platforms like Microsoft Entra ID often accumulate hundreds of application registrations with little oversight. We explain why governance so often falls behind adoption, share practical steps organizations can take to regain control, and discuss the next frontier of identity.

 

Watch it

You can watch this episode of the HIP Podcast on YouTube:

 

 

 

 

Listen to it

You can also listen to this episode of the HIP Podcast on Spotify:

0  

Entra Connect Sync 2.6.3.0 addresses an issue where auto-upgrade would halt synchronization

Reading Time: 2 minutes

Microsoft Entra

Microsoft Entra Connect Sync version v2.6.3.0 addresses an issue where auto-upgrade would halt synchronization.

 

What's Fixed

Microsoft addressed a known issue in Entra Connect Sync v2.5.190.0 and v2.6.1.0, where the Automatic Upgrades feature could stop Entra Connect Sync from synchronizing unexpectedly with the following error:

System.IO.FileLoadException: Could not load file or assembly 'System.Diagnostics.DiagnosticSource, Version=6.0.0.1' or one of its dependencies. The located assembly's manifest definition does not match the assembly reference. (Exception from HRESULT: 0x80131040)

From Entra Connect Sync v2.6.3.0 onwards, auto-upgrade now detects modifications to the miiserver.exe.config and miisclient.exe.config configuration files and skips automatic upgrade on these installations.

If admins manually upgrade and previously modified these configuration files, based on earlier guidance to support Password Hash Synchronization (PHS) in FIPS enabled environments as a workaround, they might encounter installation failures.

 

Version information

Version 2.6.3.0 of Entra Connect Sync (previously known as Azure AD Connect Sync) was made available for download on March 10th, 2026.

Admins can download the latest version of Entra Connect Sync from the Entra admin center.

Superseded versions

Past versions of Microsoft Entra Connect Sync 2.x are retired 12 months from the date they are superseded by a newer version. With the release of Entra Connect Sync v2.6.3.0, support for Entra Connect Sync version 2.6.1.0 stops on March 10th, 2027.

Support for Entra Connect Sync v2.4.27.0 and earlier versions of Entra Connect Sync has already stopped.

If you run a retired version of Microsoft Entra Connect, it might unexpectedly stop working.

0  

Join us for the upcoming Dutch Microsoft Entra Community Meetup

Reading Time: 2 minutes

Dutch Microsoft Entra Community

The Dutch Microsoft Entra Community, run by fellow MVPs Pim Jacobs, Jan Bakker and Michel van Vliet and Microsoft senior product manager Stefan van der Wiele has been gaining significant traction since its inaugural meetup on February 1st, 2024. For its upcoming meetup, Raymond and I were asked to co-present one of our favorite sessions.

 

About the Dutch Microsoft Entra Community

The Dutch Microsoft Entra Community (DMECnl) focuses on organizing meetups around Microsoft Entra technologies throughout the Netherlands. The purpose of these meetups is to share knowledge and experiences on Microsoft Entra, including Entra ID, Entra ID Governance, Entra Permission Management, Entra Verified ID, Entra External ID, Entra Internet Access, and Entra Private Access.

Sessions during the meetup will primarily be hosted in Dutch, with the exception of foreign guest speakers.

 

About the March 19th, 2026, meetup

The Dutch Microsoft Entra Community organizes their upcoming meetup on March 19th, 2026. This meetup is sponsored by Interstellar and hosted by them in their Delft office. Starting at 5 PM dinner will be served. Jan, Pim and Stefan kick off their community at 6 PM with a welcome and a quick overview on what's new in Entra in the past three months.

At 6:20 PM, Tim Wolf of Semperis fame takes the stage to talk for 60 minutes about securing Active Directory. After a short break, Raymond and I take the stage for another 60-minute session.

At 8:40 PM, drinks are served.

 

About our session

We’ll present a 60-minute session on:

Entra ID Applications and Agents: Five Do’s and Don’ts

Thursday March 19th 2026, 7:40 PM – 8:40 PM

Microsoft offers application and agent integration features in Entra. Just like every other feature in Entra, management, governance, and security for applications and agents require a certain level of attention.

Unfortunately, application governance and agents are not part of the official Microsoft curriculum. For most Entra admins this is a huge and potentially dangerous blind spot. In this session, we provide better optics around the situation and our real-world insights, as experienced with Entra ID application and agents.

We sprinkle valuable tips and tricks throughout this session, specifically designed to keep Microsoft Entra applications and agents in check, making this is a MUST attend session for all Entra admins!

 

Join us!

The March 19th, 2026, Dutch Microsoft Entra Community Meetup is a free event.
Register today to secure your seat.

0  

What's New in Entra in February 2026

Reading Time: 4 minutes

Microsoft Entra

Entra, previously known as Azure Active Directory, is Microsoft's Identity Management-as-a-Service solution, offering seamless access, easy collaboration, efficiency in IT processes and improved security and compliance. In its Release Notes for Entra ID and in the Message Center, Microsoft communicated the following planned, new and changed functionality for Entra for February 2026:

 

What's Planned

Microsoft Entra Connect security update to block hard match for users with Microsoft Entra roles

Service category: Entra Connect
Product capability: Entra Connect

Beginning June 1, 2026, Microsoft Entra ID will block any attempt by Entra Connect Sync or Cloud Sync from hard-matching a new user object from Active Directory to an existing cloud-managed Entra ID user object that holds Microsoft Entra roles.

 

Jailbreak Detection in Authenticator App

Service category: Microsoft Authenticator App
Product capability: Identity Security & Protection

Starting February 2026, Microsoft Authenticator will introduce jailbreak/root detection for Microsoft Entra credentials in the Android app. The rollout progresses from warning mode to blocking mode to wipe mode. People must move to compliant devices to continue using Microsoft Entra accounts in Authenticator.

 

What's New

External MFA General Availability

Service category: MFA
Product capability: User Authentication

External authentication methods in Microsoft Entra ID are now generally available under a new name: External Multifactor Authentication (External MFA). This capability enables organizations to meet multifactor authentication requirements while continuing to use their preferred MFA provider. Microsoft Entra ID remains the identity control plane, performing full policy evaluation and access decisions on every sign in, including real time Conditional Access enforcement and sign in risk assessment.

 

Microsoft Entra Connect Sync now supports Windows Server 2025 General Availability

Service category: Entra Connect
Product capability: Entra Connect

Microsoft Entra Connect Sync now officially supports Windows Server 2025. This means admins can confidently install and run Microsoft Entra Connect Sync on servers running Windows Server 2025, enabling your hybrid identity environment to take full advantage of the latest Windows Server enhancements.

 

Device authorization grant flow in Microsoft Entra External ID General Availability

Service category: B2C – Consumer Identity Management
Product capability: B2B/B2C

Similar to Microsoft Entra ID (workforce tenants), Microsoft Entra External ID (external tenants) now supports device authorization grant flow, which allows people to sign in to input-constrained devices such as a smart TVs, IoT devices and printers.

 

Sign-in with username/alias General Availability

Service category: B2C – Consumer Identity Management
Product capability: B2B/B2C

In Microsoft Entra External ID, people who authenticate with a local email and password now can also sign in using a username (alias) as an alternate sign-in identifier. This alias can represent a customer or member ID, insurance number, frequent flyer number, or a self-chosen username. The alias can be collected from the person,  assigned during self-service sign-up, assigned during user creation or user update via the Microsoft Graph API or in the Microsoft Entra admin center.

 

Custom banned password lists supported in Microsoft Entra External ID General Availability

Service category: B2C – Consumer Identity Management
Product capability: B2B/B2C

In addition to the global banned password lists already supported, Entra External ID admins can now add specific strings to block during password creation and reset.

 

Expanded attribute support in Lifecycle Workflows attribute changes trigger General Availability

Service category: Lifecycle Workflows
Product capability: Identity Governance

The Attribute Changes trigger in Lifecycle Workflows now supports additional attribute types, enabling broader detection of organizational changes. Previously, this trigger was limited to a set of core attributes. With this update, you can configure workflows to respond when any of the following attributes change:

  • Custom security attributes
  • Directory extension attributes
  • EmployeeOrgData attributes
  • On-premises attributes 1–15

This enhancement gives admins greater flexibility to automate lifecycle processes for mover events based on custom or extended attributes, improving governance for complex organizational structures and hybrid environments.

 

Delegated Workflow Management in Lifecycle Workflows General Availability

Service category: Lifecycle Workflows
Product capability: Identity Governance

Lifecycle workflows can now be managed with Administrative Units (AUs), enabling organizations to segment workflows and delegate administration to specific admins. This enhancement ensures that only authorized admins can view, configure, and execute workflows relevant to their scope. Organizations are able to associate workflows with AUs, assign scoped permissions to delegated admins, and ensure that workflows only impact people within their defined scope.

 

Revoke previously approved access package assignments in My Access General Availability

Service category: Entitlement Management
Product capability: Identity Governance

By end of March Microsoft Entra ID Governance approvers can revoke access to an access package after an approval has already been granted. This gives approvers greater control to respond to changes, mistakes, or updated business needs. With this update, an approver can undo a prior approval decision, immediately removing the requestor’s access to the access package. Only the approver who originally approved the request can revoke it, even if multiple approvers belong to the same approver group.

 

Microsoft Entra Provisioning Service available in Microsoft Azure operated by 21Vianet General Availability

Service category: Provisioning
Product capability: Outbound to SaaS Applications

The Microsoft Entra provisioning service can now be used in the 21Vianet / China cloud for the following scenarios:

  • API-driven provisioning
  • Cloud Sync
  • Cross-tenant sync between China tenants
  • SCIM provisioning for the non-gallery / custom application
  • On-premises app provisioning (ECMA).

Specific gallery connectors such as Workday, SuccessFactors, and AWS aren't onboarded to the environment.

 

Custom Block pages General Availability

Service category: Internet Access
Product capability: Network Access

When you configure policies blocking people from accessing risky, NSFW, or unsanctioned sites or apps in Global Secure Access (GSA), they receive a clear HTML error message with Microsoft Entra Internet Access branding. Admins who would like to start customizing that experience with text aligned to a company style guide, callouts to company Terms of Use documentation, hyperlinks to IT workflows, and more, can now do so.

 

New end user homepage in My Account Public Preview

Service category: My Profile/Account
Product capability: End User Experiences

The My Account homepage has been updated to provide a more task-focused experience. People will see pending actions like renewing expiring groups, approving access package requests, and setting up multi-factor authentication directly on the homepage. Quick links to apps, groups, access packages, and sign-in details will be easier to find and use. This change is designed to streamline account management and help people stay on top of access and security tasks.

 

BYOD support for Windows client using Microsoft Entra registration Public Preview

Service category: BYOD support
Product capability: Network Access

Bring Your Own Device (BYOD) support for Windows using Microsoft Entra‑registered devices is now available in public preview. People and partners can access corporate resources from their own devices. Admins can assign the Private Application traffic profile to internal accounts, including internal guest users.

0