Entra ID

Microsoft Entra GA Adds WAF, Bot Defense Integrations

3 min read

Summary

Microsoft Entra has generally released new partner integrations that let organizations add edge-level WAF and bot protection to authentication endpoints, plus fraud prevention in External ID sign-up flows, directly from the Entra portal. The update matters because it helps security teams block DDoS attacks, malicious bots, and fraudulent account creation earlier in the user journey while reducing deployment friction through built-in purchasing and integration options.

Need help with Entra ID?Talk to an Expert

Introduction: why this matters

Identity attacks increasingly target the entire user journey—sign-up, sign-in, and recovery—not just authentication itself. Microsoft Entra’s new GA partner integrations are notable because they combine stronger controls with faster adoption: admins can discover, purchase, and deploy select partner solutions directly in the Entra portal (and via the Microsoft Security Store) without the traditional friction of custom integrations, long implementation cycles, or bespoke contracts.

What’s new (GA): integrated partner solutions for identity security

Microsoft Entra now offers in-product integrations that add layered protections across key identity touchpoints:

1) Edge-level WAF protection for authentication endpoints

  • Partners: Cloudflare and Akamai
  • Scenario: Protect external-facing authentication endpoints from DDoS, OWASP Top 10 risks, and malicious bots.
  • Architecture (layered): Traffic flows through Cloudflare/Akamai WAF → Azure Front Door → Microsoft Entra External ID tenant.
  • Value: Blocks threats earlier (at the edge), reducing load and risk before requests reach identity infrastructure.

2) Fraud prevention during sign-up (CIAM)

  • Partners: Arkose Labs and HUMAN Security
  • Scenario: Add risk-based screening and adaptive challenges into Microsoft Entra External ID sign-up flows.
  • Value: Increases resistance to automated account creation and fraud while aiming to minimize friction for legitimate users.

3) Stronger account recovery and secure access using government ID verification

  • Partners: Au10tix, IDEMIA, and TrueCredential (LexisNexis)
  • Scenario: Replace weaker recovery methods (for example, security questions) with government ID document verification and privacy-protecting face biometrics for Entra ID account recovery.
  • Extension: The same verification flow can be used for Access Packages, enabling higher-assurance requests to sensitive resources.
  • Follow-on benefit: Users can register passkeys after verification to reduce future lockouts.

Impact for IT administrators and end users

For admins:

  • Faster onboarding and configuration for partner protections directly within the Entra experience.
  • More consistent defense-in-depth across CIAM and workforce identity scenarios, with clearer placement of controls (edge WAF, sign-up protection, recovery assurance).
  • Centralized acquisition and deployment via the Microsoft Security Store, reducing procurement and integration overhead.

For end users:

  • Better protection from account takeover and fraudulent sign-ups, with fewer disruptive incidents.
  • Higher-assurance recovery options that can be more secure than legacy recovery methods.

Action items / next steps

  1. Review your identity perimeter: Identify which apps/tenants use Microsoft Entra External ID and which endpoints are exposed.
  2. Pilot edge protection: Evaluate Cloudflare/Akamai WAF in front of External ID entry points (especially for high-volume public apps).
  3. Harden sign-up flows: For CIAM scenarios, test Arkose Labs or HUMAN integrations to reduce bot-driven registrations.
  4. Modernize recovery: Assess whether government ID verification is appropriate for your regulatory, privacy, and user populations; plan comms and support.
  5. Operationalize: Update incident runbooks and monitoring to include edge/WAF and fraud signals alongside Entra sign-in logs.

Reference docs (from Microsoft): Cloudflare/Akamai WAF setup, Arkose/HUMAN fraud protection integrations, and Entra ID account recovery guidance.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraExternal IDidentity securityWAFaccount recovery

Related Posts

Entra ID

Azure AD B2C Migration Tools Now Available

Microsoft has released generally available migration tools and guidance to help Azure AD B2C customers move to Microsoft Entra External ID. With Azure AD B2C no longer receiving new features, these new options give IT teams a clearer path to modernize customer identity while reducing migration risk.

Entra ID

Microsoft Entra ID Security Updates: Key 2026 Changes

Microsoft is making three important Microsoft Entra ID security changes in 2026: retiring Custom controls in favor of External MFA, enforcing Conditional Access more consistently during credential registration, and requiring explicitly registered authentication methods for SSPR. These updates matter because they close policy enforcement gaps, improve identity security, and require admins to review configurations before enforcement deadlines arrive.

Entra ID

Global Secure Access Operations Guide Now Available

Microsoft has published a new Microsoft Entra Global Secure Access operations guide on Microsoft Learn to help teams manage day 2 operations after deployment. The guide provides prescriptive monitoring, health checks, role assignments, templates, and automation guidance so IT teams can run Global Secure Access more consistently and proactively.

Entra ID

Microsoft Entra Agent ID GA Secures AI Agents

Microsoft Entra Agent ID is now generally available, giving organizations a dedicated identity and access foundation for AI agents in production. Combined with the Microsoft Agent 365 CLI and SDK, it helps IT and security teams onboard, govern, audit, and secure agent instances across Microsoft and non-Microsoft frameworks.

Entra ID

Microsoft Entra June 2026: Passkeys, Linux MFA, B2C

Microsoft Entra’s June 2026 updates bring major identity improvements across passkeys, phishing-resistant MFA for Linux desktops, and Azure AD B2C migration to External ID. The release also adds cross-tenant group sync, app deactivation, redesigned My Account pages, and new governance features that help IT teams strengthen security and simplify administration.

Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.