← Previous day

Next day →
Plain-English daily brief

What changed on this day

24 changes were tracked across 4 Microsoft Entra products. The leading updates include Troubleshoot Security Copilot Policies; Partners for Azure AD B2C to Microsoft Entra External ID migrations; Add a Microsoft Entra ID tenant as an OpenID Connect identity provider (Preview).

24 updates

Fundamentals

11

Conditional Access Cloud Apps

Updated

Admins can select published authentication contexts in Conditional Access policies by going to **Assignments** > **Target resources** and selecting **Authentication context** from the **Select what this policy applies to** menu.

Filter For Applications

Updated

1. Under **Exclude**, select **Users and groups** and choose your organization's emergency access or break-glass accounts.

Authentication

4

Authentication Passkeys Fido2

Updated

:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png" alt-text="Screenshot that shows how to delete a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png":::

Policy Alt All Users Compliant Hybrid Or Mfa

Updated

The prompt for authentication usually occurs when a device is offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired.

Standards

2

Developer

1

General

1

Monitoring

1

Policy All Users Require Terms Of Use

Updated

To test your policy, try to sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a test account. You should see a dialog that requires you to accept your terms of use.

Security

1

Policy All Users Windows App Protection

Updated

There's a known issue where there's a pre-existing, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

General

1

Conditional Access

1

Plan Conditional Access

Updated

- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?

Troubleshooting

1