Week in brief

Week of 5 May 2025: a global Defender for Identity sensor notice leads a largely documentation-driven Entra update

The period was principally documentation maintenance: 138 of 145 records were updates, with three new and three removed entries. The clearest operational notice was the 9 May Microsoft 365 Message Center item for deploying the Defender for Identity sensor on Microsoft Entra Connect servers; it says the update is globally available, recommends installation for monitoring, and says no action is required before rollout. The most meaningful Learn changes are scope and behavior clarifications for Workload ID token lifetimes, External ID passkeys, and Access Reviews, plus preview setup guidance for Security Copilot. Other clusters, including phishing-resistant passwordless planning and custom authentication-extension documentation, are guidance updates rather than evidence of launches. The three removals have no supplied detail, so no retirement can be characterized.

  • The 9 May Message Center entry instructs organizations to deploy a Defender for Identity sensor on Microsoft Entra Connect servers and describes the update as globally available for hybrid-identity monitoring and threat detection. It also says no admin action is required before rollout while recommending installation. Because the supplied summary uses both new and classic sensor terminology, the evidence supports an operational availability notice, not a clear retirement or breaking change.

  • The updated page says access, ID, and SAML token lifetimes can be configured for all apps in an organization, multitenant applications, or specific service principals. It explicitly excludes managed identity service principals. This is a supported-scope clarification for a preview, not evidence of general availability or a newly changed limit.

  • The updated passkey and FIDO2 guidance states that internal or external guest users, including B2B collaboration users in the resource tenant, cannot register passkey credentials. This establishes a documented support boundary; the supplied evidence does not show that guest behavior changed during the week.

  • The updated Microsoft Entra ID Governance FAQ says that an access review captures user assignments, group membership, and reviewer configuration at the start of the review. Changes made after the instance begins are not reflected in that instance, clarifying runtime behavior rather than announcing a new governance feature.

  • The updated Agent Optimization guidance says initial agent enablement and setup during the preview requires either the Security Administrator or Global Administrator role, which have Security Copilot access by default. After setup, Conditional Access Administrators can be assigned Security Copilot access and use the agent. This is preview onboarding and delegation guidance, not a general-availability announcement.

For Entra administrators

Do not treat this as a broad tenant-reconfiguration week. For hybrid identity, no pre-rollout action is called for by the sensor notice, but teams should evaluate the recommended sensor installation on Entra Connect servers. Anyone using or evaluating the Workload ID token-lifetime preview must account for its managed-identity exclusion; External ID designs must not assume guest or B2B users in the resource tenant can register FIDO2 passkeys; and Access Review operators must remember that mid-review changes do not update the running instance. For the Security Copilot agent preview, initial enablement requires a Security Administrator or Global Administrator; Conditional Access Administrators can be delegated access after setup when they have Security Copilot access.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

30

What is the Microsoft Entra architecture?

Updated

Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/whatis.md)

9 May 2025
30

Certificate Based Authentication

Updated

1. Authenticate with a certificate that has policy OID of 3.4.5.6 and Issued by CN=CBATestRootProd. Authentication should pass and get a multifactor claim.

10 May 2025

Microsoft Defender XDR services: Deploy the New Defender for Identity sensor on Microsoft Entra Connect servers

New

Deploy the new Defender for Identity sensor on Microsoft Entra Connect servers. The classic sensor is now available, enhancing visibility and security for hybrid identity environments. This update is available globally, and organizations should install the sensor for comprehensive monitoring and threat detection. No admin action is required before the rollout.

9 May 2025
Message CenterMC1060476 on mc.merill.net ↗Stay informed

Sap Cloud Platform Identity Authentication Provisioning Tutorial

Updated

* By default, the value of the Microsoft Entra user `userPrincipalName` attribute is mapped to both the `userName` and `emails[type eq "work"].value` attributes of SAP Cloud Identity Services. If user's email addresses are different from their user principal names, then you may need to change this mapping.

9 May 2025

Howto Mfa Userstates

Updated

The per-user MFA administration experience in the Microsoft Entra admin center is recently improved. To view and manage user states, complete the following steps:

9 May 2025

Usage Insights Report

Updated

![Screenshot of the sign-in activity details for a selected application.](./media/concept-usage-insights-report/application-activity-sign-in-detail.png)

8 May 2025

Passwordless Remote Desktop Connection Session Initiation

Updated

Organizations deploying phishing-resistant passwordless typically have a need for some of their personas to use remote desktop technology to facilitate productivity, security, or administration. The two basic use cases are:

7 May 2025

Custom Extension Overview

Updated

This section lists the custom authentication extensions events available in Microsoft Entra ID workforce and external tenants. For detailed information about the events, refer to the respective documentation.

6 May 2025

Custom Extension Email Otp Get Started

Updated

- A familiarity and understanding of the concepts covered in [custom authentication extensions](/entra/identity-platform/custom-extension-overview).

6 May 2025

Custom Extension Overview

Updated

This video provides detailed instructions on configuring Microsoft Entra custom authentication extensions and offers best practices and valuable tips for optimal implementation.

5 May 2025
21

Sso Linux

Updated

- Support for Bash scripts for custom compliance policies

11 May 2025

Freshdesk Tutorial

Updated

1. **Create a Microsoft Entra test user** - to test Microsoft Entra single sign-on with Britta Simon.

11 May 2025

Device Join Macos Platform Single Sign On Kerberos Configuration

Updated

9. Click the folder icon to upload your **Configuration profile file**. Choose the *kerberos.mobileconfig* file you [saved previously](#Kerberos SSO MDM profile configuration for on-premises Active Directory) after customizing the template.

10 May 2025

Kao Navi Tutorial

Removed

A Microsoft Entra documentation page was updated: Kao Navi Tutorial.

10 May 2025

Tutorial V2 Android

Removed

A Microsoft Entra documentation page was updated: Tutorial V2 Android.

10 May 2025

Darwinbox Hr Integration Tutorial

Updated

Open Darwinbox studio and navigate to Connector Library. Search for and install the “Microsoft” and “Microsoft Entra” connectors:

9 May 2025

Device Join Macos Platform Single Sign On Kerberos Configuration

Updated

Refer to the [Microsoft Entra ID macOS Platform SSO documentation](./macos-psso.md) to learn how to configure and deploy Platform SSO. Platform SSO should be deployed on Enterprise-managed Macs regardless of whether you choose to deploy Kerberos SSO using this guide.

8 May 2025

Sharefile Tutorial

Updated

To configure the integration of Citrix ShareFile into Microsoft Entra ID, you need to add Citrix ShareFile from the gallery to your list of managed SaaS apps.

6 May 2025

Best Practices

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).

6 May 2025
4

Managed Policies

Updated

Administrators with at least the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role assigned find these policies in the [Microsoft Entra admin center](https://entra.microsoft.com) under **Protection** > **Conditional Access** > **Policies**.

7 May 2025
4

Delete Application Portal

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

10 May 2025

Hootsuite Tutorial

Updated

1. Perform the following step, if you wish to configure the application in **SP** initiated mode:

8 May 2025

Hootsuite Tutorial

Updated

1. Perform the following step, if you wish to configure the application in **SP** initiated mode:

7 May 2025
4

Overview

Updated

author: owinfreyATL

11 May 2025

New Name

Updated

| Identity and access management | New identity categories | Network access |

9 May 2025
4

Check Status User Account Provisioning

Updated

The provisioning summary report and Provisioning logs play a key role helping admins troubleshoot various user account provisioning issues.

7 May 2025

Plan Auto User Provisioning

Updated

Refer to the following links to troubleshoot any issues that may turn up during provisioning:

7 May 2025

Plan Cloud Hr Provision

Updated

To troubleshoot any issues that might turn up during provisioning, see the following articles:

7 May 2025
2

Howto Analyze Provisioning Logs

Updated

- [Check the status of user provisioning](../app-provisioning/application-provisioning-when-will-provisioning-finish-specific-user.md)

7 May 2025

Whats New Docs

Updated

- [Skip deletion of user accounts that go out of scope in Azure Active Directory](skip-out-of-scope-deletions.md)

7 May 2025
2

Connect Fed Group Claims

Updated

- Support for use of `sAMAccountName` and security identifier (SID) attributes synced from on-premises is designed to enable moving existing applications from Active Directory Federation Services (AD FS) and other identity providers. Groups managed in Microsoft Entra ID don't contain the attributes necessary to emit these claims.

9 May 2025

Protecting Tokens Microsoft Entra Id

Updated

If an adversary is able to successfully steal a token, organizations can enable certain capabilities to automatically reduce the

7 May 2025
2

How Provisioning Works

Updated

[Build a SCIM endpoint and configure provisioning when creating your own app](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)

7 May 2025

V2 Oauth2 Auth Code Flow

Updated

Redirect URIs for SPAs that use the auth code flow require special configuration.

7 May 2025
1
1
1
2
6

Entitlement Management Dynamic Approval

Updated

- At least the [Entitlement Management Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) role of the catalog where the custom extension will be created.

8 May 2025

Access Reviews Faqs

Updated

No. Access reviews capture a snapshot of access at the start of each review instance. Any changes made to user assignments, group membership, or reviewer configuration after the review begins won't be reflected in that instance.

5 May 2025
1

Access reviews - FAQs

Updated

In this article, you find questions to commonly asked questions about [access reviews](access-reviews-overview.md). Check back to this page frequently as changes happen often, and answers are continually being added.

7 May 2025
4
4
3
3

Enable Passkey Fido2

Updated

Registration of passkey (FIDO2) credentials isn't supported for internal or external guest users, including B2B collaboration users in the resource tenant.

7 May 2025

Training Videos

Updated

The video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verification.

5 May 2025
1
1
1
2
1
1
1

Workload Identity Federation

Updated

Learn how workload identify federation enables secre access to Microsoft Entra protected resources from external software workloads without managing secrets.

11 May 2025
1

Configurable token lifetimes in the Microsoft identity platform (preview)

Updated

You can configure the lifetime of access, ID, or Security Assertion Markup Language (SAML) tokens issued by the Microsoft identity platform. Token lifetimes can be set for all apps in your organization, multitenant applications, or specific service principals. Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.

11 May 2025
3

Troubleshoot Connectors

Updated

**Objective:** Verify that the connector machine, backend proxy, and firewall support the certificate the connector created. Also, verify the certificate is valid.

9 May 2025

View Enriched Logs

Updated

- A **Security Administrator** role is required to export Global Secure Access Network Traffic Logs in Diagnostic Settings.

7 May 2025
1
1
1
1

Agent Optimization

Updated

- For the initial agent enablement/setup, you will need to be either a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview. These roles also have [access to Security Copilot by default](/copilot/security/authentication). After setup, you can assign Conditional Access Administrators with Security Copilot access. This will give your Conditional Access Administrators the ability to use the agent as well.

10 May 2025