Week in brief

Retiring service-principal-less authentication is the week’s clearest Entra behavior change

The updated Workload ID guidance describes a security-by-default retirement of service-principal-less authentication: a client service principal will be required for all applications. Otherwise, the week of 16 June 2025 was mainly Microsoft Learn maintenance—184 updates, two new entries, seven removals, and no Message Center items. The two new Entra ID entries provide migration guidance for legacy MFA and SSPR, while the strongest additional signals are an ID Governance visibility notice effective 30 September 2025, telephony-fraud guidance, and a Global Secure Access/Conditional Access/Entitlement Management scenario. No supplied entry establishes a preview or general availability event; the seven removals lack item-level detail and cannot be treated as product retirements.

  • The updated guidance says a client service principal will be required for all applications. It cites the risk of abuse when resource applications or APIs perform incomplete validation and frames the requirement as reducing the chance of that gap returning or being exploited in third-party resources. This is a stated retirement and authentication-behavior change, but no effective date or rollout status is supplied.

  • Updated Entitlement Management guidance explains that access-package visibility controls which packages users can discover and request in the My Access portal and highlights important changes effective 30 September 2025. The supplied text does not describe the altered rules, so this is a dated documentation notice rather than evidence of a specific configuration change.

  • Two records marked New add Microsoft Learn content for migrating from legacy MFA and self-service password reset policies. The evidence does not say that a policy was retired, enforcement changed, or a deadline was introduced; this is new migration documentation, not a feature launch. It aligns with separate updates to the Mandatory Multifactor Authentication material.

  • The updated Telephony Fraud Protections and Throttles guidance says Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. It also says some regions require opt-in through a support ticket because of elevated fraud risk. This is security guidance and a description of behavior, not evidence that a new control became generally available this week.

  • ID Governance · Conditional Access
    Governed blocking pattern for unauthorized websites and unsanctioned AI apps

    An updated ID Governance scenario combines Global Secure Access and Conditional Access to block a specific unauthorized website, such as an unsanctioned AI app, while entitlement management provides governed exceptions for users who should be exempt. The scenario targets web applications that lack provisioning or federation and should be read as implementation guidance, not a launch or availability announcement.

For Entra administrators

Workload owners should identify applications that rely on service-principal-less authentication and assess the stated client-service-principal requirement; the record supplies no effective date. ID Governance teams using My Access discovery or request flows have a dated visibility item to review for 30 September 2025, but not enough detail to infer the new rules. MFA administrators can use the new migration pages and check whether their region requires support-ticket opt-in for telephony-fraud protections. The remaining sampled edits are reference or implementation guidance rather than confirmed tenant-wide changes.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

28

Authentication Track Linkable Identifiers

Updated

:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::

22 June 2025

Certificate Based Authentication

Updated

:::image type="content" border="false" source="./media/how-to-certificate-based-authentication/steps.png" alt-text="Diagram of the steps required to enable Microsoft Entra certificate-based authentication.":::

22 June 2025

Delegate By Task

Updated

> | Configure registration | [Authentication Policy Administrator](permissions-reference.md#authentication-policy-administrator) | |

22 June 2025

Fido2 Hardware Vendor

Updated

ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌

21 June 2025

Authenticate Application Id

Updated

Microsoft Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Microsoft Entra Connect. This account uses a username and password to authenticate requests.

19 June 2025

Resilience For Federated Applications With Colocated Users

Updated

One scenario that many organizations [building for resilience](resilience-overview.md) in their identity and access management architecture need to accommodate is continuity of application access during temporary site disconnection. The organization may have one or more physical sites at which their applications are deployed. Some of their users are colocated at those sites and need to be able to access local applications. For example, employees at a factory or at a store may need to be able to sign-in to in-house-developed business applications managing operations at that site.

19 June 2025

Refresh Tokens

Updated

| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |

19 June 2025

Telephony Fraud Protections and Throttles

Updated

Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.

18 June 2025

Activity Log Schemas

Updated

Learn how to interpret the details found in the Microsoft Entra audit and sign-in and logs schema.

18 June 2025
18

Mysdworxcom Tutorial

Updated

You can configure and test Microsoft Entra single sign-on for my.sdworx.com in a test environment (my.acc.sdworx.com) but not by using the gallery app (import SP metadata, to be provided by your my.sdworx.com contact). My.sdworx.com supports **IDP** and **SP** initiated single sign-on.

21 June 2025

Claims Customization Powershell

Updated

- [How to: Customize claims with the claims mapping policy in Microsoft Graph](/graph/how-to-claims-customization)

20 June 2025

What If Tool

Updated

| :---: | --- | :---: | :---: |

19 June 2025

21912

Removed

A Microsoft Entra documentation page was updated: 21912.

19 June 2025
9

Secure Generative Ai

Updated

Microsoft Entra offers a comprehensive suite of capabilities to securely manage AI applications, appropriately control access, and protect sensitive data:

22 June 2025
9

Migrate to cloud authentication using Staged Rollout

Updated

Staged Rollout lets you gradually test cloud authentication features with selected user groups. These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains.

19 June 2025

Custom authentication extensions overview

Updated

The Microsoft Entra ID authentication pipeline consists of several built-in authentication events, like the validation of user credentials, Conditional Access policies, multifactor authentication, self-service password reset, and more.

19 June 2025

Sso Linux

Updated

This feature empowers users on Linux desktop clients to register their devices with Microsoft Entra ID, enroll into Intune management, and satisfy device-based Conditional Access policies when accessing their corporate resources.

19 June 2025

Whats New

Updated

**Service category:** Conditional Access

19 June 2025
7

Licensing

Updated

manager: pmwongera

22 June 2025

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

20 June 2025

Whats New

Updated

For more information, see: [Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources](https://techcommunity.microsoft.com/blog/identity/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991).

20 June 2025
6
4

Security Best Practices For App Registration

Updated

Because secure applications are essential to the organization, any downtime to them because of security issues can affect the business or some critical service that the business depends upon. So, it's important to allocate time and resources to ensure applications always stay in a healthy and secure state. Conduct a periodic security and health assessment of applications, much like a Security Threat Model assessment for code. For a broader perspective on security for organizations, see the [security development lifecycle (SDL)](https://www.microsoft.com/securityengineering/sdl).

22 June 2025

Darwinbox Entra Integration Tutorial

Updated

Go to the Entra portal, select **App Registrations**, and then select **New registration**. Create a single-tenant app as shown below.

20 June 2025

Data Residency

Updated

Microsoft Entra ID is an Identity as a Service (IDaaS) solution that stores and manages identity and access data in the cloud. You can use the data to enable and manage access to cloud services, achieve mobility scenarios, and secure your organization. An instance of the Microsoft Entra ID service, called a [tenant](~/identity-platform/developer-glossary.md#tenant), is an isolated set of directory object data that the customer provisions and owns.

19 June 2025

Entra Admin Center

Updated

* [App registrations](~/identity-platform/application-model.md)

19 June 2025
4

AD FS application migration to move AD FS apps to Microsoft Entra ID

Updated

Learn how to use the AD FS application migration to migrate AD FS relying party applications from ADFS to Microsoft Entra ID. This guided experience provides one-click configuration for basic SAML URLs, claims mapping, and user assignments to integrate the application with Microsoft Entra ID.

21 June 2025

Getthere Tutorial

Updated

To configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.

19 June 2025

Error Codes

Updated

| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |

19 June 2025
3
2
2
1

Integrate Darwinbox HR with Microsoft Entra ID

Updated

The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.

21 June 2025
1
1
22

Create Access Review

Updated

> Access reviews capture a snapshot of access at the beginning of each review instance. Any changes made during the review process will be reflected in the subsequent review cycle. Essentially, with the commencement of each new recurrence, pertinent data regarding the users, resources under review, and their respective reviewers is retrieved.

20 June 2025

Review Your Access

Updated

The first step to perform an access review is to find and open the access review.

20 June 2025

Perform Access Review

Updated

After it opens, you'll see the list of users in scope for the access review.

20 June 2025

Access Reviews Faqs

Updated

A Microsoft Entra documentation page was updated: Access Reviews Faqs.

20 June 2025

Darwinbox Hr Integration Tutorial

Updated

The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.

20 June 2025

Deploy Access Reviews

Updated

A Microsoft Entra documentation page was updated: Deploy Access Reviews.

20 June 2025

Manage Access Review

Updated

A Microsoft Entra documentation page was updated: Manage Access Review.

20 June 2025

Self Access Review

Updated

A Microsoft Entra documentation page was updated: Self Access Review.

20 June 2025
4

Whatis

Updated

- **Microsoft Entra ID Governance.** [Microsoft Entra ID Governance](~/id-governance/identity-governance-overview.md) is an advanced set of [identity governance capabilities](~/id-governance/licensing-fundamentals.md) for Microsoft Entra ID P1 and P2 customers.

22 June 2025

Access Reviews Overview

Updated

- **Have reviews recur periodically:** You can set up recurring access reviews of users at set frequencies such as weekly, monthly, quarterly or annually, and the reviewers are notified at the start of each review. Reviewers can approve or deny access with a friendly interface and with the help of smart recommendations.

20 June 2025

Entitlement Management Access Package Visibility

Updated

When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and upcoming changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, outlines how it currently works, and highlights important changes effective September 30, 2025.

18 June 2025
2

Entitlement Management Global Secure Access Restrict Employee Access

Updated

In this scenario, you set up Global Secure Access and Conditional Access to block access to a specific unauthorized website such as an unsanctioned AI app, while using entitlement management to provide governed access to users who should be exempt from the policy. This scenario is useful for generative AI applications and other web applications that don't support provisioning or federation with Microsoft Entra.

19 June 2025
1

Feature Availability

Updated

[Microsoft Entra ID Governance](~/id-governance/licensing-fundamentals.md) is available in the US Government community cloud (GCC), GCC-High, and Department of Defense cloud environments. [Microsoft Entra Workload Identities Premium edition](~/workload-id/workload-identities-faqs.md#is-the-workload-id-premium-plan-available-on-azure-government-clouds) is available in the US government clouds.

22 June 2025
4

Whats New Overview

Updated

Not all Microsoft Entra products are part of Microsoft 365 and Azure (for example, Microsoft Entra External ID). The What's new feature ensures transparency about new features and changes across all Microsoft Entra products in a centralized location.

22 June 2025

21790

Updated

- [Cross-tenant access overview](../../external-id/cross-tenant-access-overview.md)

21 June 2025

21790

Updated

- [Cross-tenant access overview](../../external-id/cross-tenant-access-overview.md)

20 June 2025
3

B2b Tutorial Require Mfa

Updated

1. Access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.

19 June 2025

Supported Features Customers

Updated

| **Types of application registration** | <ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li><li>Enterprise applications offer [more options](../../identity/enterprise-apps/plan-sso-deployment.md), like password-based, linked, and header-based.</li></ul> |<ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li></ul>|

19 June 2025

Claims Mapping

Updated

If you need to issue the UPN value as an application token claim, the actual claim mapping might behave differently for B2B users. If the B2B user authenticates with an external Microsoft Entra identity and you issue `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN attribute from the home tenant for this user.

18 June 2025
1

Leave The Organization

Updated

- If you're using a personal account or email one-time passcode, you'll need to use a My Account URL that includes your tenant name or tenant ID.

19 June 2025
1
1

Cross Tenant Synchronization Configure

Updated

This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.

22 June 2025
1

Faq Customers

Updated

Effective May 1, 2025 Azure AD B2C P1 and P2 will no longer be available to purchase for new customers, but current Azure AD B2C customers can continue using the product. The product experience, including creating new tenants or user flows, remains unchanged. The operational commitments, including service level agreements (SLAs), security updates, and compliance, also remain unchanged. We'll continue supporting Azure AD B2C until at least May 2030. More information, including migration plans will be made available. Contact your account representative for more information and to learn more about Microsoft Entra External ID.

19 June 2025
1

Configure Quick Access

Updated

Configuring your Quick Access settings is a major component to utilizing Microsoft Entra Private Access. When you configure Quick Access for the first time, Private Access creates a new enterprise application. The properties of this new app are automatically configured to work with Private Access.

16 June 2025
17

Use Quickstart Idtoken

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

21 June 2025

Issuer Revoke

Updated

> If the verifiable credential is old and was issued during the preview period, this claim doesn't exist. Revocation doesn't work for this credential and you have to reissue it.

21 June 2025

Use Quickstart

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

21 June 2025

Use Quickstart Presentation

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

21 June 2025

Use Quickstart Selfissued

Updated

In the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.

21 June 2025

Using Facecheck

Updated

Face Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.

21 June 2025

Admin Api

Updated

The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.

21 June 2025

Verifiable Credentials Faq

Updated

1. In the [Azure portal](https://portal.azure.com), go to **Microsoft Entra ID** for the subscription you use for your Microsoft Entra Verified ID deployment.

21 June 2025

Credential Design

Updated

The following four attestation types are currently available to be configured in the rules definition. They are different ways of providing claims used by the Microsoft Entra Verified ID issuing service to be inserted into a verifiable credential and attest to that information with your decentralized identifier (DID). Multiple attestation types can be used in the rules definition.

21 June 2025

Verifiable Credentials Configure Issuer

Updated

In this step, you create the verified credential expert card by using Microsoft Entra Verified ID. After you create the credential, your Microsoft Entra tenant can issue it to users who initiate the process.

21 June 2025

How Use Vcnetwork

Updated

1. On the start page of **Microsoft Entra Verified ID** in the **Azure portal**, you have a quickstart named **Verification request**. Selecting **start** takes you to a page where you can browse the Verifiable Credentials Network.

21 June 2025

Opt Out

Updated

1. From the **Azure portal**, search for verifiable credentials.

21 June 2025

Plan Issuance Solution

Updated

All verifiable credentials must declare their *type* in their [rules definition](rules-and-display-definitions-model.md#rulesmodel-type). The credential type distinguishes a verifiable credentials schema from other credentials and it ensures interoperability between issuers and verifiers. To indicate a credential type, provide one or more credential types that the credential satisfies. Each type is a unique string. Often, a URI is used to ensure global uniqueness. The URI doesn't need to be addressable. It's treated as a string. As an example, a diploma credential issued by Contoso University might declare the following types:

21 June 2025

Verifiable Credentials Configure Verifier

Updated

Create a client secret for the registered application you created. The sample application uses the client secret to prove its identity when it requests tokens.

21 June 2025
6

Services Partners

Updated

You could select a partner from the list and build seamless end-user experiences for onboarding, secure access to critical services, self-service, and custom business application scenarios. If you're a Services or solution Partner and would like to be considered into Microsoft Entra Verified ID partner documentation, submit your application [request](https://forms.microsoft.com/r/AGVsXmf4EZ).

21 June 2025

Whats New

Updated

Applications that use the Microsoft Entra Verified ID service must use the Request API endpoint that corresponds to their Microsoft Entra tenant's region.

21 June 2025
5

Idemia

Updated

To configure IDEMIA as your identity verification proofing solution, follow these steps:

21 June 2025

Verified Id Pricing

Updated

To take advantage of the consumptive billing, your Verified ID authority must be linked to an Azure subscription.

21 June 2025

Register Didwebsite

Updated

1. Go to the **Verified ID** page in the **Azure portal**.

21 June 2025
3

Using the Microsoft Authenticator with Verified ID

Updated

In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.

21 June 2025

Issuer Openid

Updated

To receive a verifiable credential, your users need to sign into your IDP from the **Microsoft Authenticator** app.

21 June 2025

Plan Verification Solution

Updated

:::image type="content" source="media/plan-verification-solution/plan-verification-solution-authenticator.png" alt-text="Diagram of the components of a verification solution with Microsoft Authenticator application highlighted.":::

21 June 2025
2

Decentralized Identifier Overview

Updated

In order to be able to resolve DID documents, DIDs are typically recorded on an underlying network of some kind that represents a trust system. Microsoft currently supports DID:Web trust system. DID:Web is a permission based model that allows trust using a web domain’s existing reputation. DID:Web is in support status General Available.

21 June 2025

Dnsbind

Updated

The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.example.com/`.

21 June 2025
1
1

Using Wallet Library

Updated

- **[Android Studio](https://developer.android.com/studio)** installed on Mac/Windows and an Android test device. You need to enable [developer mode](https://developer.android.com/studio/debug/dev-options) on your Android test device.

21 June 2025
1
1

Error Codes

Updated

"message": "The request contains `includeQRCode`, but it is not boolean."

21 June 2025
3

Retire Service Principal Less Authentication

Updated

This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-rest-beta&preserve-view=true)). Service principal-less authentication can be abused if the resource applications (i.e. APIs) perform incomplete validations. Microsoft has verified that validations aren't vulnerable to service principal-less authentication. However, with this action, the risk of this gap reappearing in future versions or being exploited in third-party resources outside Microsoft’s control is minimized.

19 June 2025

Service principal sign-in logs

Updated

Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.

18 June 2025
1

Workload Identity Federation Config App Trust Managed Identity

Updated

The audience value must be set to one of the following values:<br/> &#8226; **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>&#8226; **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>&#8226; **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>

18 June 2025
1

Overview

Updated

- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.

21 June 2025
1
9

Configure Global Access With Pim

Updated

Next, we activate group membership using the Microsoft Entra admin center, and then attempt to connect with the new role activated.

22 June 2025

Install Windows Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.

21 June 2025

Configure Global Access With Pim

Updated

Next, we activate group membership using the Microsoft Entra admin center, and then attempt to connect with the new role activated.

21 June 2025

Manage Ssh Server Administration

Updated

Secure Shell (SSH) is widely recognized across the IT industry as a critical service for system administrators. It provides a secure and encrypted method to access and manage remote systems over unsecured networks.

19 June 2025

Configure Per App Access

Updated

Per-App Access is configured by creating a new Global Secure Access app. You create the app, select a connector group, and add network access segments. These settings make up the individual app that you can assign users and groups to.

16 June 2025
3
1

Connectors

Updated

You don't have to manually delete connectors that are unused. When a connector is running, it remains active as it connects to the service. Unused connectors are tagged as `_inactive_` and are removed after 10 days of inactivity. If you do want to uninstall a connector, though, uninstall both the Connector service and the Updater service from the server. Restart the computer to fully remove the service.

20 June 2025
1

Transport Layer Security

Updated

:::image type="content" source="media/how-to-transport-layer-security/security-profile-baseline.png" alt-text="Screenshot of the Edit Baseline profile screen showing a list of policy names and their priorities.":::

19 June 2025