Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings

Fournisseur
Microsoft
Produit
Microsoft Entra
Type
Sécurité
Date annonce
2026-07-01
Date effet
Date non publiee
Impact
Concerné

En bref

Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings

Ce que dit la source

The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web

Pour continuer

Lire la source primaire

Choisir votre lecture

Le rôle change l'angle de lecture, pas les faits, la date ni le niveau de preuve.

Lecture pour un commercial

Qui est concerné : The audience described by the Microsoft update is represented by: Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will

Pourquoi c'est important : The change matters because the official source describes: Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will

Urgence : Surveiller

Prochaine action : Review affected accounts with the customer using the official announcement.

Opportunités commerciales

  • Use the verified change to open a scoped customer conversation.

Actions techniques

  • Assess whether the documented change intersects the customer's current stack.

Questions à poser au client

  • Does this documented change affect a product or workload in scope?

Risques et objections

  • The official source does not establish facts beyond the quoted material.

Points à confirmer

  • The effective date is unknown and must be confirmed before scheduling action.

Preuves et traçabilité

Chaque extrait est relié à la source primaire et conservé pour vérification.

  • Capture brute
    2026-08-29T09:22:49.319599+00:00
  • Événement
    Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
    source
  • Produit Microsoft Entra
    Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
    source
  • Insight un commercial
    Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
    source

Retour au fil public