Entra Connect v2.6.91.0 veröffentlicht

Nutzt jemand aus der Blog-Leserschaft Entra Connect um auf Microsoft Entra zuzugreifen? Dann sollte die Software zeitnah aktualisiert werden. Denn in älteren Versionen gibt es Sicherheitslücken, die in der gerade veröffentlichten Entra Connect v2.6.91.0 geschlossen worden sind. Hier einige Informationen.

Microsoft Entra Connect ist eine lokale Anwendung von Microsoft, die ein lokales Active Directory mit Microsoft Entra ID verbindet. Microsoft Entra Connect synchronisiert (alle 30 Minuten) Benutzer, Gruppen und Kennwörter aus dem lokalen AD in die Cloud, um eine einheitliche Hybrididentität sicherzustellen.

Microsoft Entra Connect v2.6.91.0

Die Tage hatte ich im Blog-Beitrag Microsoft Entra Connect Sync-Upgrade vor dem 30. September 2026 erforderlich auf ein erforderliches Upgrade dieser Software hingewiesen. Microsoft hat zum 16. September 2026 ein Update auf Microsoft Entra Connect v2.6.91.0 freigegeben, und schreibt, dass diese Version Sicherheitskorrekturen enthält. Microsoft empfiehlt, so bald wie möglich auf diese Version zu aktualisieren. Ali Taran hat in nachfolgendem Tweet auf dieses Update hingewiesen.

Entra Connect

Diese Version enthält einen geführten Migrations-Workflow von Microsoft Entra Connect Sync zu Microsoft Entra Cloud Sync. Der Workflow umfasst eine Konfigurationsprüfung, die Einrichtung des Provisioning-Agents, eine schrittweise Aktivierung sowie eine Validierung.

Die Version steht ausschließlich über das Microsoft Entra Admin Center zum Download bereit. Ein automatisches Upgrade ist nicht verfügbar. Ali Taran hat in diesem Blog-Beitrag von Mai 2025 die Schritte zum Upgrade beschrieben.

Microsoft gibt folgende neu hinzugefügte Funktionen in Entra Connect v2.6.91.0 als verfügbar an:

  • Added a guided migration workflow from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync. The workflow includes configuration assessment, provisioning agent setup, staged activation, and validation. This feature is available only in the Azure public cloud.
  • Added support for an additional sovereign cloud environment, including Pass-through Authentication, Seamless Single Sign-On, password writeback, and Health Agent monitoring.

Weiterhin wurden nachfolgende Features mit dem betreffenden Release aktualisiert.

  • Phishing-resistant authentication in the Microsoft Entra Connect setup wizard is now generally available and enabled by default. The Windows Web Account Manager prompt supports passkeys, FIDO2 security keys, and passwords, reuses the signed-in session across Microsoft Entra services, and preserves Seamless Single Sign-On Kerberos key rotation.
  • When you configure Seamless Single Sign-On by using the standalone PowerShell module, you must import ADSync.psd1 before AzureADSSO.psd1. Learn more.
  • Cloud configuration cmdlets no longer require an explicit -AADUserName. When you omit the parameter, Microsoft Entra Connect derives a sign-in hint from the connector configuration and opens an interactive sign-in prompt. This behavior applies to Set-ADSyncAADCompanyFeature, Set-ADSyncAADPasswordSyncState, Enable-ADSyncExportDeletionThreshold, Set-ADSyncScheduler, andSet-ADSyncDirSyncConfiguration.
  • The Select Containers dialog in Synchronization Service Manager is now read-only. You can still use the dialog to view the current selections. To make changes, use Customize synchronization options in the Microsoft Entra Connect wizard. Learn more.
  • Updated the bundled SQL Server 2022 LocalDB from version 16.0.4250.1 to 16.0.4262.2.

Die nachfolgende Aufzählung enthält die Bugfixes.

  • Fixed an issue where installing or upgrading Microsoft Entra Connect with an existing ADSync database could fail with error 0xE0474352.
  • Fixed an issue where upgrading Microsoft Entra Connect didn't update an installed Microsoft Visual C++ 2015-2022 Redistributable version earlier than 14.41.
  • Fixed an issue where the Microsoft Entra Connect wizard could close during startup when the Windows PowerShell Transcription policy contained an invalid output directory.
  • Fixed an Application-Based Authentication certificate rotation issue that could remove the last usable application key during directory replica delays.
  • Fixed an issue where Synchronization Service Manager could close unexpectedly when you opened Connector Properties and listed directory partitions.
  • Fixed an issue where Change Credentials didn't open for connector rows outside the visible area on configurations with many Active Directory connectors.
  • Fixed an issue where expanding a previously deselected domain on the Domain and OU filtering page could reselect the domain and enable synchronization for the entire domain after the wizard completed.
  • Fixed multiple security vulnerabilities in bundled third-party dependencies and hardened local temporary-file permissions and SharePoint connector profile-image downloads.

Wichtig sei, dass Microsoft Graph-Berechtigungen zu Microsoft Entra Connect hinzugefügt wurden, heißt es. Wenn Richtlinien für den bedingten Zugriff auf App-Ebene verwendet werden, sind bitte die Richtlinien, die auf Microsoft.Azure.SyncFabric oder den Microsoft 365 Reporting Service abzielen, zu überprüfen.

Dieser Beitrag wurde unter Cloud, Sicherheit, Software, Update abgelegt und mit , , , verschlagwortet. Setze ein Lesezeichen für den Permalink.

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

Hinweis: Bitte beachtet die Regeln zum Kommentieren im Blog (Erstkommentare und Verlinktes landet in der Moderation, gebe ich alle paar Stunden frei, SEO-Posts/SPAM lösche ich rigoros. Kommentare abseits des Themas bitte unter Diskussion. Kommentare, die gegen die Regeln verstoßen, werden rigoros gelöscht. Wegen Missbrauchs bin ich gezwungen, Name und E-Mail als Pflichtfelder beim Kommentieren zu aktivieren. Wählt ggf. einen (noch nicht benutzten) Alias-Namen und verwendet ggf. eine Dummy-Mail-Adresse (z.B. t@hotkev.com).

Du findest den Blog gut, hast aber Werbung geblockt? Du kannst diesen Blog auch durch eine Spende unterstützen.