← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

App instance lock guidance now covers single-tenant apps while External ID documents passkey API

This period was dominated by targeted documentation guidance rather than a broad rollout. The most consequential edits clarify that app instance property locks apply to both single-tenant and multitenant applications, record that Enable property lock is enabled by default for new applications since June 2026, and document External ID's credential-management API for customer passkeys. Connect Health guidance also now identifies Global Administrator for agent registration and tenant-wide data-collection procedures. The remaining updates are mainly a cross-reference change, a corrected claims example, and procedural text such as the AD DS connector module path.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

12 updates

3

Connect Health Operations

Feature update

The documentation now identifies Microsoft Entra Global Administrators, rather than Hybrid Identity Administrators, in the default Connect Health RBAC guidance and Owner role description.

Connect Health Agent Install

Doc update

The documentation now states that, by default, a Global Administrator account has permission to register the agent, replacing Hybrid Identity Administrator.

2

Zero Trust Protect Tenants

Doc update

The documentation now says the lock is configured for all applications, rather than all multitenant applications.

2
1

Connect Health User Privacy

Doc update

The documentation changes the recommended acknowledgment role from Hybrid Identity Administrators to Global Administrators before stopping data collection for all registered services.

1

Configure Security

Doc update

The documentation link was updated from guidance for all multitenant applications to guidance for all applications.

2

Sign In With Passkey

New feature

The documentation now directs applications to use the credential management API, with low-privilege delegated permissions, so signed-in customers can list and register their own passkeys.

1

Claims Customization Custom Claims Policy

Doc update

Example 3 now clearly describes creating the `JoinedData` claim by joining `extensionattribute1` with `-ext` for JWTs issued to linked service principals.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…