Plain-English daily brief

What changed on this day

41 changes were tracked across 6 Microsoft Entra products. The leading updates include Security Defaults; Workload Identity; Registration Mfa Sspr Combined.

41 updates

Fundamentals

6

Security Defaults

Updated

As part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.

Registration Mfa Sspr Combined

Updated

By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.

Whats New

Updated

**Service category:** User Experience and Management

Five Steps To Full Application Integration

Updated

In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.

Developer

2

Authentication

1

Microsoft identity platform

1

Frontline Worker Management

Updated

Frontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).

Security

1

Policy All Users Windows App Protection

Updated

There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

Fundamentals

1

Whats New Ignite 2025

Updated

- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)

Governance

22

Create a monitor (preview)

Updated

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

Enable tenant discovery (preview)

Updated

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

Pim How To Add Role To User

Updated

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

Authentication

1

Fundamentals

1

Security

1

Troubleshooting

1

Register Didwebsite

Updated

The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.

Conditional Access

1

Workload Identity

Updated

> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).

Fundamentals

1

Conditional Access Users Groups

Updated

A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.

Fundamentals

1

Bring Your Own Device

Updated

1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).