{"id":797,"date":"2023-07-11T09:53:50","date_gmt":"2023-07-11T16:53:50","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/identity\/?p=797"},"modified":"2024-04-03T07:07:38","modified_gmt":"2024-04-03T14:07:38","slug":"azure-ad-recommendations-adal","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/identity\/azure-ad-recommendations-adal\/","title":{"rendered":"Introducing Microsoft Entra ID Recommendations For Identifying ADAL Applications"},"content":{"rendered":"<p>Earlier this year we <a href=\"https:\/\/devblogs.microsoft.com\/identity\/update-your-applications-from-adal-to-msal\/\">announced the sunset of the Azure AD Authentication Library (ADAL)<\/a>. ADAL has been officially deprecated on June 30th of this year. As part of this announcement, we heard clearly from our customers that they need help in identifying applications that still use ADAL in their tenants. Using the <a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/develop\/howto-get-list-of-all-auth-library-apps\">ADAL workbook<\/a> enabled that, but required a few extra steps that we now made easier by directly integrating the functionality in the Azure Portal as well as the Microsoft Graph API.<\/p>\n<p>Today we&#8217;re introducing a new way for developers and administrators to identify ADAL applications running in their tenant within web-based and local experiences that they already use &#8211; the Azure Portal and the Microsoft Graph PowerShell SDK. It&#8217;s all powered by <a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/reports-monitoring\/overview-recommendations\">Microsoft Entra ID Recommendations<\/a>.<\/p>\n<p>To get started, in the Azure Portal navigate to the Azure Active Directory blade, and in the <strong>Overview<\/strong> section click on <strong>Recommendations<\/strong>. If your tenant has active applications that are using ADAL, you will see recommendations appear within 24 hours from the last time the application acquired a token. To get details about a recommendation, along with next steps that will help you migrate to the modern Microsoft Authentication Library (MSAL)-based stack, click directly on the recommendation.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/devblogs.microsoft.com\/identity\/wp-content\/uploads\/sites\/74\/2023\/07\/recommendations-azure-portal.png\" alt=\"Screenshot of Azure AD recommendations in the Azure Portal\" \/><\/p>\n<p>We also made sure that recommendations can be obtained programatically &#8211; whether you&#8217;re writing custom applications or monitoring scripts, you can use the <a href=\"https:\/\/learn.microsoft.com\/powershell\/microsoftgraph\/get-started?view=graph-powershell-1.0\">Microsoft Graph PowerShell SDK<\/a> to get the list of recommendations. If you want to customize your workflows even further, you can use the Microsoft Graph REST API directly by sending a <code>GET<\/code> request to:<\/p>\n<pre><code class=\"language-http\">https:\/\/graph.microsoft.com\/beta\/directory\/recommendations<\/code><\/pre>\n<p>To obtain the list of recommendations with Microsoft Graph PowerShell SDK, connect your account to the command-line interface (CLI):<\/p>\n<pre><code class=\"language-powershell\">Connect-MgGraph\n  -Scopes \"DirectoryRecommendations.Read.All, DirectoryRecommendations.ReadWrite.All\"\n  -Tenant MY_TENANT_ID<\/code><\/pre>\n<p>Next, select the <code>beta<\/code> API profile:<\/p>\n<pre><code class=\"language-powershell\">Select-MgProfile beta<\/code><\/pre>\n<p>And lastly, use <a href=\"https:\/\/learn.microsoft.com\/powershell\/module\/microsoft.graph.identity.directorymanagement\/get-mgdirectoryrecommendation?view=graph-powershell-beta\"><code>Get-MgDirectoryRecommendation<\/code><\/a> to get the list of recommendations associated with your tenant:<\/p>\n<pre><code class=\"language-powershell\">Get-MgDirectoryRecommendation -All | Format-List<\/code><\/pre>\n<p>Recommendations related to ADAL usage will contain detailed information about all ADAL applications, the first time those were detected, and instructions on how to migrate to MSAL.<\/p>\n<h2>We want your feedback<\/h2>\n<p>We&#8217;d love to hear your thoughts on the Microsoft Entra ID Recommendations experience for detecting ADAL applications! Let us know on by clicking the <strong>Got feedback?<\/strong> button in the Azure Portal.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier this year we announced the sunset of the Azure AD Authentication Library (ADAL). ADAL has been officially deprecated on June 30th of this year. As part of this announcement, we heard it loud and clear from our customers that they need help in identifying applications that still use ADAL in their tenants.<\/p>\n","protected":false},"author":113816,"featured_media":798,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[32,33],"tags":[23,16,46,50,22,3],"class_list":["post-797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-product-updates","tag-adal","tag-entra","tag-entra-id","tag-identity","tag-libraries","tag-msal"],"acf":[],"blog_post_summary":"<p>Earlier this year we announced the sunset of the Azure AD Authentication Library (ADAL). ADAL has been officially deprecated on June 30th of this year. As part of this announcement, we heard it loud and clear from our customers that they need help in identifying applications that still use ADAL in their tenants.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/posts\/797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/users\/113816"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/comments?post=797"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/posts\/797\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/media\/798"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/media?parent=797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/categories?post=797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/identity\/wp-json\/wp\/v2\/tags?post=797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}