Daily AI Update 7 Sep 2026: Entra SSPR Security Change

Daily AI Update 7 Sep 2026-এ enterprise identity security-এর একটি গুরুত্বপূর্ণ পরিবর্তন কার্যকর হয়েছে। Microsoft Entra ID-এর self-service password reset বা SSPR এখন verification-এর জন্য শুধু explicitly registered authentication method গ্রহণ করবে। User profile-এ রাখা কিন্তু authentication method হিসেবে register না করা phone number বা email আর যথেষ্ট নয়।
৭ সেপ্টেম্বর থেকে কী বদলেছে
Microsoft-এর official guidance অনুযায়ী, ৭ সেপ্টেম্বর ২০২৬ থেকে SSPR verification-এ registered method বাধ্যতামূলক। এর উদ্দেশ্য হলো proof-of-possession এবং user intent-এর সঙ্গে password-reset verification-কে সামঞ্জস্য করা। Microsoft Entra-এর মূল ঘোষণা।
কারা প্রভাবিত হতে পারেন
যেসব user আগে শুধু directory profile-এ থাকা phone বা alternate email-এর ওপর নির্ভর করতেন, তারা reset করতে গিয়ে সমস্যায় পড়তে পারেন। Microsoft Authenticator, SMS, voice call, FIDO2 security key বা passkey—সংস্থার policy-তে অনুমোদিত পদ্ধতি—আগে থেকেই registered থাকলে সাধারণত disruption কম হবে।
AI যুগে identity control কেন জরুরি
AI assistant ও autonomous agent যত বেশি enterprise account, data এবং workflow ব্যবহার করছে, identity recovery দুর্বল হলে attacker উচ্চ privilege পেতে পারে। Password reset তাই শুধু support feature নয়; এটি access-control chain-এর গুরুত্বপূর্ণ অংশ।
বাংলাদেশি প্রতিষ্ঠানের করণীয়
- Entra tenant-এ authentication registration report পর্যালোচনা করুন।
- কোন user-এর registered method নেই, তা দ্রুত শনাক্ত করুন।
- Authenticator, passkey বা security key rollout-এর সহায়তা দিন।
- Conditional Access policy report-only mode-এ test করুন।
- Help desk-কে নতুন recovery flow ও identity-verification rule দিন।
শেষ কথা
পুরোনো contact field আর secure recovery method এক জিনিস নয়। Explicit registration, policy enforcement এবং audit trail—এই তিনটি password reset-কে আরও নির্ভরযোগ্য করে।
আগের পর্ব: Daily AI Update 6 Sep 2026।
তথ্য হালনাগাদ: ৭ সেপ্টেম্বর ২০২৬।
