Plain-English daily brief

What changed on this day

10 changes were tracked across 5 Microsoft Entra products. The leading updates include Whats New; Explicit Forward Proxy (preview) session management; Tutorial - Use Face Check with Microsoft Entra Verified ID.

10 updates

Architecture

1

Connect To Cloud Sync Decision Guide

Updated

Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.

Authentication

1

Branding

1

Customize Branding

Updated

:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::

Fundamentals

1

Fido2 Compatibility

Updated

- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.

Conditional Access

1

Licensing Agent Id

Updated

- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.

Governance

1

General

1

Whats New

Updated

- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.

Security

1

Fundamentals

2

Explicit Forward Proxy (preview) session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Explicit Forward Proxy

Updated

During the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.