← Previous day

Next day →
Plain-English daily brief

What changed on this day

6 changes were tracked across 2 Microsoft Entra products. The leading updates include Managed Policies; Mandatory Multifactor Authentication; Custom controls in Microsoft Entra Conditional Access.

6 updates

Conditional Access

2

Plan Conditional Access

Updated

Creating a policy for each app isn't efficient and makes managing policies difficult. Conditional Access has a limit of 240 policies per tenant. This 240-policy limit includes Conditional Access policies in any state, including report-only mode, on, or off.

Architecture

1

Resilience In Credentials

Updated

|Certificate Based Authentication (CBA)|In most cases (depending on configuration) CBA will require a revocation check. This adds an external dependency on the CRL distribution point (CDP) |[Understanding the certificate revocation process](~/identity/authentication/concept-certificate-based-authentication-certificate-revocation-list.md#enforce-crl-validation-for-cas)|

Authentication

1

Managed Policies

Updated

[Custom controls don't satisfy multifactor authentication claim requirements](controls.md#creating-custom-controls). If your organization uses custom controls you should [migrate to external authentication methods](/entra/identity/authentication/how-to-authentication-external-method-manage), the replacement of custom controls. Your external authentication provider must support external authentication methods and provide the necessary configuration guidance for integration.

Fundamentals

1

Microsoft Entra admin center

Updated

Overview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.

Fundamentals

1

Mandatory Multifactor Authentication

Updated

Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md).