Azure AD Ignite 2021 Recap: Securing your application ecosystem

Published Mar 23 2021 09:00 AM 7,821 Views

Howdy folks!

 

As we shared earlier this year in The state of apps by Microsoft identity report, organizations have been connecting all types of apps with Azure AD to keep employees connected and secure in this era of remote work.  In case you missed Microsoft Ignite earlier this month, we’ve been busy adding new capabilities to help you secure and manage your apps in the cloud and on-premises with Azure AD.  Read on to learn more about new app management updates we made this month!

 

Increase IT efficiency with new enterprise app management capabilities

We’ve released three new enterprise app management updates to give you more ways to secure and manage apps while simplifying employees’ access to the apps they need.

 

  • GA of the new Azure AD app gallery experience – The Azure AD app gallery experience has a refreshed look and feel! The new app gallery experience allows you to filter for applications based on category or on the supported single sign-on type like SAML or OIDC.  Additionally, the new app gallery experience includes icons to help you quickly identify which applications support federated single sign-on and provisioning.

11.png

  • GA of the Application Template API – The application template API available in Microsoft Graph allows admins and developers to programmatically manage applications at scale in the Azure AD App gallery. Admins and developers can now list, search, update, or add applications from the Azure AD app gallery in their tenant via an API.
  • GA of the Admin Consent Workflow – the admin consent workflow, which is rolling out in the next few days, gives users an easy way to request that an admin review the application they’re trying to use. When users try to access an application that requires consent by an admin, users can now send a request to admins during the sign-in flow. The request is sent via email to admins who have been designated as reviewers and once a reviewer takes action on the request, the user is notified whether access has been granted or denied. You can also list pending admin requests by using APIs in Microsoft Graph or PowerShell. By using our new APIs you can integrate admin consent requests into your existing processes to streamline workflows.

22.png

Modernize your app authentication from Active Directory Federation Services (AD FS) to Azure AD

One of the best ways to secure your environment is to manage everything from the cloud—and that includes moving your application’s authentication off AD FS to Azure AD. To help upgrade your application authentication from AD FS to Azure AD, the AD FS activity and insights report is now generally available.

 

  • GA of the AD FS activity and insights report. The AD FS activity insights report lets you quickly identify which of your applications are ready to be upgraded to Azure AD with no configuration changes. It assesses all your AD FS applications for compatibility with Azure AD, checks for any configuration differences, and gives guidance on preparing individual applications for migration to Azure AD. 

 

55.PNG

 

 

Secure your on-premises apps with Azure AD application proxy

During the past 12 months, organizations have increasingly relied on Azure AD Application Proxy service to give employees remote access to their on-premises apps. To help you get even more out of Azure AD Application Proxy we’ve made the following enhancements:

 

  • GA of header-based authenticationAnnounced last year, Azure AD Application Proxy natively supports apps that use header-based authentication. You can configure a wide range of header values required by your application in Azure AD. These header values will be sent down to the application via Application Proxy. This means that all attributes and transformations available for configuring SAML or OIDC applications can be used as header values.

44.png

  • Optimize your Application Proxy traffic in public preview: You now can now designate which region your Application Proxy service connector group should use.  By choosing the closest region to your applications and connectors, you can improve performance and reduce the latency to the App Proxy service. 

 

MicrosoftTeams-image (1).png

Tell us what you think

As always, we’d love to hear from you. Please let us know what you think in the comments below or on the Azure AD feedback forum.  And be sure watch our on demand Ignite session “Prevent attacks by protecting your applications with Azure Active Directory” to learn more about these new app management capabilities.

 

Alex Simons (@Alex_A_Simons)

Corporate VP of Program Management

Microsoft Identity Division

%3CLINGO-SUB%20id%3D%22lingo-sub-1942490%22%20slang%3D%22en-US%22%3EAzure%20AD%20Ignite%202021%20Recap%3A%20Securing%20your%20application%20ecosystem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1942490%22%20slang%3D%22en-US%22%3E%3CP%3EHowdy%20folks!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20we%20shared%20earlier%20this%20year%20in%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fsecurity%2Fblog%2F2021%2F01%2F27%2Fthe-state-of-apps-by-microsoft-identity-azure-ad-app-gallery-apps-that-made-the-most-impact-in-2020%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EThe%20state%20of%20apps%20by%20Microsoft%20identity%20report%3C%2FA%3E%2C%20organizations%20have%20been%20connecting%20all%20types%20of%20apps%20with%20Azure%20AD%20to%20keep%20employees%20connected%20and%20secure%20in%20this%20era%20of%20remote%20work.%26nbsp%3B%20In%20case%20you%20missed%20%3CA%20href%3D%22https%3A%2F%2Fmyignite.microsoft.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Ignite%3C%2FA%3E%20earlier%20this%20month%2C%20we%E2%80%99ve%20been%20busy%20adding%20new%20capabilities%20to%20help%20you%20secure%20and%20manage%20your%20apps%20in%20the%20cloud%20and%20on-premises%20with%20Azure%20AD.%26nbsp%3B%20Read%20on%20to%20learn%20more%20about%20new%20app%20management%20updates%20we%20made%20this%20month!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EIncrease%20IT%20efficiency%20with%20new%20enterprise%20app%20management%20capabilities%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EWe%E2%80%99ve%20released%20three%20new%20enterprise%20%3CSPAN%3Eapp%20management%20updates%20t%3C%2FSPAN%3Eo%20%3CSPAN%3Egive%20you%20more%20ways%20to%20secure%20and%20manage%20apps%20while%20simplifying%26nbsp%3Bemployees%E2%80%99%26nbsp%3Baccess%20to%20the%20apps%20they%20need.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EGA%20of%20the%20new%20Azure%20AD%20app%20gallery%20experience%20%3C%2FSTRONG%3E%E2%80%93%20The%20Azure%20AD%20app%20gallery%20experience%20has%20a%20refreshed%20look%20and%20feel!%20The%20new%20app%20gallery%20experience%20allows%20you%20to%20filter%20for%20applications%20based%20on%20category%20or%20on%20the%20supported%20single%20sign-on%20type%20like%20SAML%20or%20OIDC.%26nbsp%3B%20Additionally%2C%20the%20new%20app%20gallery%20experience%20includes%20icons%20to%20help%20you%20quickly%20identify%20which%20applications%20support%20federated%20single%20sign-on%20and%20provisioning.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%2211.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F266133i823ED0D49EA43AFF%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%2211.png%22%20alt%3D%2211.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EGA%20of%20the%20%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fgraph%2Fapi%2Fresources%2Fapplicationtemplate%3Fview%3Dgraph-rest-beta%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EApplication%20Template%20API%3C%2FSTRONG%3E%3C%2FA%3E%20%E2%80%93%20The%20application%20template%20API%20available%20in%20Microsoft%20Graph%20allows%20admins%20and%20developers%20to%20programmatically%20manage%20applications%20at%20scale%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fazuremarketplace.microsoft.com%2Fen-us%2Fmarketplace%2Fapps%2Fcategory%2Fazure-active-directory-apps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20AD%20App%20gallery%3C%2FA%3E.%20Admins%20and%20developers%20can%20now%20list%2C%20search%2C%20update%2C%20or%20add%20applications%20from%20the%20Azure%20AD%20app%20gallery%20in%20their%20tenant%20via%20an%20API.%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3EGA%20of%20the%20%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fmanage-apps%2Fconfigure-admin-consent-workflow%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EAdmin%20Consent%20Workflow%3C%2FSTRONG%3E%3C%2FA%3E%20%E2%80%93%20the%20admin%20consent%20workflow%2C%20which%20is%20rolling%20out%20in%20the%20next%20few%20days%2C%20gives%20users%20an%20easy%20way%20to%20request%20that%20an%20admin%20review%20the%20application%20they%E2%80%99re%20trying%20to%20use.%20When%20users%20try%20to%20access%20an%20application%20that%20requires%20consent%20by%20an%20admin%2C%20users%20can%20now%20send%20a%20request%20to%20admins%20during%20the%20sign-in%20flow.%20The%20request%20is%20sent%20via%20email%20to%20admins%20who%20have%20been%20designated%20as%20reviewers%20and%20once%20a%20reviewer%20takes%20action%20on%20the%20request%2C%20the%20user%20is%20notified%20whether%20access%20has%20been%20granted%20or%20denied.%20You%20can%20also%20list%20pending%20admin%20requests%20by%20using%20APIs%20in%20Microsoft%20Graph%20or%20PowerShell.%20By%20using%20our%20new%20APIs%20you%20can%20integrate%20admin%20consent%20requests%20into%20your%20existing%20processes%20to%20streamline%20workflows.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%2222.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F266134i0D586976B683D3F7%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%2222.png%22%20alt%3D%2222.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EModernize%20your%20app%20authentication%3C%2FSTRONG%3E%20%3CSTRONG%3Efrom%20Active%20Directory%20Federation%20Services%20(AD%20FS)%20to%20Azure%20AD%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EOne%20of%20the%20best%20ways%20to%20secure%20your%20environment%20is%20to%20manage%20everything%20from%20the%20cloud%E2%80%94and%20that%20includes%20moving%20your%20application%E2%80%99s%20authentication%20off%20AD%20FS%20to%20Azure%20AD.%20To%20help%20upgrade%20your%20application%20authentication%20from%20AD%20FS%20to%20Azure%20AD%2C%20the%20AD%20FS%20activity%20and%20insights%20report%20is%20now%20generally%20available.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EGA%20of%20the%20%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fmanage-apps%2Fmigrate-adfs-application-activity%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EAD%20FS%20activity%20and%20insights%20report%3C%2FSTRONG%3E%3C%2FA%3E%3CSTRONG%3E.%3C%2FSTRONG%3E%20The%20AD%20FS%20activity%20insights%20report%20lets%20you%20quickly%20identify%20which%20of%20your%20applications%20are%20ready%20to%20be%20upgraded%20to%20Azure%20AD%20with%20no%20configuration%20changes.%20It%20assesses%20all%20your%20AD%20FS%20applications%20for%20compatibility%20with%20Azure%20AD%2C%20checks%20for%20any%20configuration%20differences%2C%20and%20gives%20guidance%20on%20preparing%20individual%20applications%20for%20migration%20to%20Azure%20AD.%26nbsp%3B%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%2255.PNG%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F266144i3CCF8EFC54D34F25%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%2255.PNG%22%20alt%3D%2255.PNG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ESecure%20your%20on-premises%20apps%20with%20Azure%20AD%20application%20proxy%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EDuring%20the%20past%2012%20months%2C%20organizations%20have%20increasingly%20relied%20on%20Azure%20AD%20Application%20Proxy%20service%20to%20give%20employees%20remote%20access%20to%20their%20on-premises%20apps.%20To%20help%20you%20get%20even%20more%20out%20of%20Azure%20AD%20Application%20Proxy%20we%E2%80%99ve%20made%20the%20following%20enhancements%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSTRONG%3EGA%20of%20%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fmanage-apps%2Fapplication-proxy-configure-single-sign-on-with-headers%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3Eheader-based%20authentication%3C%2FSTRONG%3E%3C%2FA%3E%20%E2%80%93%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-active-directory-identity%2Fazure-ad-application-proxy-now-natively-supports-apps-that-use%2Fba-p%2F1751707%22%20target%3D%22_blank%22%3EAnnounced%20last%20year%3C%2FA%3E%2C%20Azure%20AD%20Application%20Proxy%20natively%20supports%20apps%20that%20use%20header-based%20authentication.%20You%20can%20configure%20a%20wide%20range%20of%20header%20values%20required%20by%20your%20application%20in%20Azure%20AD.%20These%20header%20values%20will%20be%20sent%20down%20to%20the%20application%20via%20Application%20Proxy.%20This%20means%20that%20all%20attributes%20and%20transformations%20available%20for%20configuring%20SAML%20or%20OIDC%20applications%20can%20be%20used%20as%20header%20values.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%2244.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F266136i19BEFEDFB04636FE%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%2244.png%22%20alt%3D%2244.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fazure%2Factive-directory%2Fmanage-apps%2Fapplication-proxy-network-topology%23optimize-connector-groups-to-use-closest-application-proxy-cloud-service-preview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSTRONG%3EOptimize%20your%20Application%20Proxy%20traffic%3C%2FSTRONG%3E%3C%2FA%3E%3CSTRONG%3E%26nbsp%3Bin%20public%20preview%3A%20%3C%2FSTRONG%3EYou%20now%20can%20now%20%3CSPAN%3Edesignate%20which%20region%20your%20Application%20Proxy%20service%20connector%20group%20should%20use.%26nbsp%3B%20By%20choosing%20the%20closest%20region%20to%20your%20applications%20and%20connectors%2C%20you%20can%20improve%20performance%20and%20reduce%20the%20latency%20to%20the%20App%20Proxy%20service.%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MicrosoftTeams-image%20(1).png%22%20style%3D%22width%3A%20292px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F266142iFA14C898E1B1B714%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22MicrosoftTeams-image%20(1).png%22%20alt%3D%22MicrosoftTeams-image%20(1).png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ETell%20us%20what%20you%20think%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EAs%20always%2C%20we%E2%80%99d%20love%20to%20hear%20from%20you.%20Please%20let%20us%20know%20what%20you%20think%20in%20the%20comments%20below%20or%20on%20the%E2%80%AF%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F169401-azure-active-directory%3Fcategory_id%3D160608%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAzure%20AD%20feedback%20forum%3C%2FA%3E%3CSPAN%3E.%26nbsp%3B%20And%20be%20sure%20watch%20our%20on%20demand%20Ignite%3C%2FSPAN%3E%20session%20%E2%80%9C%3CA%20href%3D%22https%3A%2F%2Fmyignite.microsoft.com%2Fsessions%2F96b46abf-6790-4a56-bb18-3ffdbef9405a%3Fsource%3Dsessions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EPrevent%20attacks%20by%20protecting%20your%20applications%20with%20Azure%20Active%20Directory%3C%2FA%3E%E2%80%9D%20to%20learn%20more%20about%20these%20new%20app%20management%20capabilities.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAlex%20Simons%20(%40Alex_A_Simons)%3C%2FP%3E%0A%3CP%3ECorporate%20VP%20of%20Program%20Management%3C%2FP%3E%0A%3CP%3EMicrosoft%20Identity%20Division%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1942490%22%20slang%3D%22en-US%22%3E%3CP%3ENew%20capabilities%20to%20simplify%20the%20way%20you%20secure%20and%20manage%20your%20cloud%20and%20on-premises%20applications%20with%20Azure%20AD.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Picture1.png%22%20style%3D%22width%3A%20182px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F265262i02E18485F67578F4%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Picture1.png%22%20alt%3D%22Picture1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Version history
Last update:
‎Aug 19 2021 04:22 PM
Updated by:
www.000webhost.com