What changed on this day
17 changes were tracked across 3 Microsoft Entra products. The leading updates include Agent Optimization; Configurable Token Lifetimes; Certificate Based Authentication.
Daily.Entra.News17 changes were tracked across 3 Microsoft Entra products. The leading updates include Agent Optimization; Configurable Token Lifetimes; Certificate Based Authentication.
To create a PKI container object:
- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.
author: vimrang
Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.
This article shows the new and updated documentation for the Microsoft Entra application management.
1. If you wish to configure the application in **SP** initiated mode, then perform the following step:
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.
| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |
| Attribute Name | User | Comment |
Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
> Error code 1002013 indicates an expected (and successful) interrupt of the sign-up flow. [Learn more](howto-troubleshoot-sign-up-errors.md#sign-up-error-codes)
Microsoft Entra is updating the default sign-in background for Work or School accounts to align with Microsoft's Fluent design language. This visual update will roll out from late September to early October 2025. No action is required, but internal documentation and help desks should be updated to reduce confusion.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
New and updated documentation for the Microsoft Entra External ID.
- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).