← Previous day

Next day →
Plain-English daily brief

What changed on this day

37 changes were tracked across 5 Microsoft Entra products. The leading updates include Migrate to cloud authentication using Staged Rollout; Retire Service Principal Less Authentication; Audit Administrator Events in Microsoft Entra Connect Sync.

37 updates

Authentication

5

Migrate to cloud authentication using Staged Rollout

Updated

Staged Rollout lets you gradually test cloud authentication features with selected user groups. These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains.

Authenticate Application Id

Updated

Microsoft Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Microsoft Entra Connect. This account uses a username and password to authenticate requests.

Refresh Tokens

Updated

| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |

General

5

21912

Removed

A Microsoft Entra documentation page was updated: 21912.

Fundamentals

3

Custom authentication extensions overview

Updated

The Microsoft Entra ID authentication pipeline consists of several built-in authentication events, like the validation of user credentials, Conditional Access policies, multifactor authentication, self-service password reset, and more.

Whats New

Updated

**Service category:** Conditional Access

Architecture

2

Resilience For Federated Applications With Colocated Users

Updated

One scenario that many organizations [building for resilience](resilience-overview.md) in their identity and access management architecture need to accommodate is continuity of application access during temporary site disconnection. The organization may have one or more physical sites at which their applications are deployed. Some of their users are colocated at those sites and need to be able to access local applications. For example, employees at a factory or at a store may need to be able to sign-in to in-house-developed business applications managing operations at that site.

Conditional Access

2

Sso Linux

Updated

This feature empowers users on Linux desktop clients to register their devices with Microsoft Entra ID, enroll into Intune management, and satisfy device-based Conditional Access policies when accessing their corporate resources.

Developer

2

Microsoft identity platform

2

Data Residency

Updated

Microsoft Entra ID is an Identity as a Service (IDaaS) solution that stores and manages identity and access data in the cloud. You can use the data to enable and manage access to cloud services, achieve mobility scenarios, and secure your organization. An instance of the Microsoft Entra ID service, called a [tenant](~/identity-platform/developer-glossary.md#tenant), is an isolated set of directory object data that the customer provisions and owns.

Monitoring

2

Standards

2

Getthere Tutorial

Updated

To configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.

Error Codes

Updated

| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |

Provisioning

1

Conditional Access

1

Entitlement Management Global Secure Access Restrict Employee Access

Updated

In this scenario, you set up Global Secure Access and Conditional Access to block access to a specific unauthorized website such as an unsanctioned AI app, while using entitlement management to provide governed access to users who should be exempt from the policy. This scenario is useful for generative AI applications and other web applications that don't support provisioning or federation with Microsoft Entra.

Fundamentals

1

Authentication

1

B2b Tutorial Require Mfa

Updated

1. Access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.

Developer

1

Leave The Organization

Updated

- If you're using a personal account or email one-time passcode, you'll need to use a My Account URL that includes your tenant name or tenant ID.

Security

1

Faq Customers

Updated

Effective May 1, 2025 Azure AD B2C P1 and P2 will no longer be available to purchase for new customers, but current Azure AD B2C customers can continue using the product. The product experience, including creating new tenants or user flows, remains unchanged. The operational commitments, including service level agreements (SLAs), security updates, and compliance, also remain unchanged. We'll continue supporting Azure AD B2C until at least May 2030. More information, including migration plans will be made available. Contact your account representative for more information and to learn more about Microsoft Entra External ID.

Standards

1

Supported Features Customers

Updated

| **Types of application registration** | <ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li><li>Enterprise applications offer [more options](../../identity/enterprise-apps/plan-sso-deployment.md), like password-based, linked, and header-based.</li></ul> |<ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li></ul>|

Authentication

1

Retire Service Principal Less Authentication

Updated

This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-rest-beta&preserve-view=true)). Service principal-less authentication can be abused if the resource applications (i.e. APIs) perform incomplete validations. Microsoft has verified that validations aren't vulnerable to service principal-less authentication. However, with this action, the risk of this gap reappearing in future versions or being exploited in third-party resources outside Microsoft’s control is minimized.

General

2

Manage Ssh Server Administration

Updated

Secure Shell (SSH) is widely recognized across the IT industry as a critical service for system administrators. It provides a secure and encrypted method to access and manage remote systems over unsecured networks.

Security

1

Transport Layer Security

Updated

:::image type="content" source="media/how-to-transport-layer-security/security-profile-baseline.png" alt-text="Screenshot of the Edit Baseline profile screen showing a list of policy names and their priorities.":::

Troubleshooting

1