Week in brief

Conditional Access optimization-agent guidance expands; TLS 1.2 and authentication-flow clarifications are the main admin signals

The week of 30 June 2025 was primarily documentation maintenance: 244 updates, two new pages, no removals, and one Message Center notice. The substantive exception is a coordinated set of Security Copilot, Agent ID, and Microsoft Entra ID updates covering the Conditional Access optimization agent. Other meaningful updates clarify authentication-flow enforcement and TLS migration for Microsoft Entra Domain Services. The supplied evidence does not identify the optimization agent as a preview or generally available launch, and no retirement is recorded.

  • Two Security Copilot pages marked new on 5 July cover reviewing and applying the agent’s suggestions and inspecting its metrics and audit-log events. Related Agent ID and Microsoft Entra ID updates describe recommendations based on Conditional Access best practices, identification of users not covered by an MFA-requiring policy, and the ability to update that policy. A related page states that at least a Microsoft Entra ID P1 license is required for the review-suggestions workflow. This is an expansion of guidance,

  • The updated Microsoft Entra ID Authentication Flows guidance says sessions using device code flow or authentication transfer become protocol tracked, that tracking survives subsequent refreshes, and that later non-device-code or non-authentication-transfer flows can still be subject to authentication-flow policy enforcement. This is a documentation clarification of enforcement behavior, not evidence of a backend change introduced during the week.

  • An updated migration article says Microsoft is disabling TLS 1.0 and TLS 1.1 for Microsoft Entra Domain Services and identifies TLS 1.2 or later as the stronger target. It references a communication from 10 November 2023, so the update is security migration guidance rather than a newly dated cutover announcement. The supplied evidence contains no enforcement date.

  • An updated Microsoft Entra ID page says applications using Microsoft.Identity.Client and one of the listed APIs require changes, and notes that the public client API is deprecated as of MSAL.NET 4.73.1. This is a developer-facing compatibility and deprecation clarification; the evidence does not say the deprecation began this week or identify the affected API list.

  • A Microsoft 365 Message Center notice says the default sign-in background for Work or School accounts will be updated to align with Fluent design, with rollout stated for late September through early October 2025. The notice says no action is required and suggests updating internal documentation and help desks only to reduce user confusion. This is a visual sign-in change, not an access-control change.

For Entra administrators

Admins evaluating or using the Conditional Access optimization agent should verify the stated Microsoft Entra ID P1 requirement for the review-suggestions workflow, understand which MFA policy changes may be applied, and use the documented metrics and audit events. Teams using Authentication Flows policies should account for protocol tracking across refreshes and subsequent flows when testing sign-ins. Domain Services operators should review migration steps for dependencies on TLS 1.0 or 1.1; no cutover date is provided. Application owners using Microsoft.Identity.Client and the affected APIs should consult the deprecation guidance. The sign-in-background update requires no tenant action; internal help-desk or documentation updates are optional measures to reduce confusion.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

131

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

3 July 2025

Attack Payload Author

Updated

A Microsoft Entra documentation page was updated: Attack Payload Author.

3 July 2025

Billing Administrator

Updated

A Microsoft Entra documentation page was updated: Billing Administrator.

3 July 2025

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

3 July 2025

Directory Writers

Updated

A Microsoft Entra documentation page was updated: Directory Writers.

3 July 2025

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

3 July 2025

Exchange Administrator

Updated

A Microsoft Entra documentation page was updated: Exchange Administrator.

3 July 2025

Fabric Administrator

Updated

A Microsoft Entra documentation page was updated: Fabric Administrator.

3 July 2025

Global Administrator

Updated

A Microsoft Entra documentation page was updated: Global Administrator.

3 July 2025

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

3 July 2025

Groups Administrator

Updated

A Microsoft Entra documentation page was updated: Groups Administrator.

3 July 2025

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

3 July 2025

Helpdesk Administrator

Updated

A Microsoft Entra documentation page was updated: Helpdesk Administrator.

3 July 2025

Insights Administrator

Updated

A Microsoft Entra documentation page was updated: Insights Administrator.

3 July 2025

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

3 July 2025

Intune Administrator

Updated

A Microsoft Entra documentation page was updated: Intune Administrator.

3 July 2025

Kaizala Administrator

Updated

A Microsoft Entra documentation page was updated: Kaizala Administrator.

3 July 2025

Knowledge Administrator

Updated

A Microsoft Entra documentation page was updated: Knowledge Administrator.

3 July 2025

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

3 July 2025

License Administrator

Updated

A Microsoft Entra documentation page was updated: License Administrator.

3 July 2025

Message Center Reader

Updated

A Microsoft Entra documentation page was updated: Message Center Reader.

3 July 2025

Network Administrator

Updated

A Microsoft Entra documentation page was updated: Network Administrator.

3 July 2025

Partner Tier1 Support

Updated

A Microsoft Entra documentation page was updated: Partner Tier1 Support.

3 July 2025

Partner Tier2 Support

Updated

A Microsoft Entra documentation page was updated: Partner Tier2 Support.

3 July 2025

People Administrator

Updated

A Microsoft Entra documentation page was updated: People Administrator.

3 July 2025

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

3 July 2025

Printer Administrator

Updated

A Microsoft Entra documentation page was updated: Printer Administrator.

3 July 2025

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

3 July 2025

Search Administrator

Updated

A Microsoft Entra documentation page was updated: Search Administrator.

3 July 2025

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

3 July 2025

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

3 July 2025

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

3 July 2025

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

3 July 2025

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

3 July 2025

Yammer Administrator

Updated

A Microsoft Entra documentation page was updated: Yammer Administrator.

3 July 2025

Tutorial Create Forest Trust

Updated

Before you configure a forest trust in Domain Services, make sure your networking between Azure and on-premises environment meets the following requirements:

2 July 2025

Manage Dns

Updated

Refrain from redirecting DNS zones related to windowsazure.com or core.windows.net. If DNS redirection is required, limit the redirection to individual host names instead of zones. For example, use server1.file.core.windows.net instead of file.core.windows.net.

2 July 2025
18

21788

Updated

**Remediation action**

2 July 2025

21803

Updated

**Remediation action**

2 July 2025

21804

Updated

**Remediation action**

2 July 2025

21888

Updated

**Remediation action**

2 July 2025
16

Sla Performance

Updated

| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |

4 July 2025

Attribute Log Reader

Updated

A Microsoft Entra documentation page was updated: Attribute Log Reader.

3 July 2025

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

3 July 2025

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

3 July 2025
14

Howto Vm Sign In Azure Ad Windows

Updated

A User account in Microsoft Entra must be added to a role assignment in Azure before the user is allowed to sign in to Azure virtual machines or Arc-connected Windows Server. The same roles are used for both Azure virtual machines and Arc-enabled Windows Server.

5 July 2025

Howto Vm Sign In Azure Ad Windows

Updated

- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.

4 July 2025

Howto Mfa Mfasettings

Updated

Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.

4 July 2025

Mandatory Multifactor Authentication

Updated

Changes are required if you use the [Microsoft.Identity.Client](https://www.nuget.org/packages/Microsoft.Identity.Client) package and one of the following APIs in your application. The public client API is **deprecated** [as of the 4.73.1 release](https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/main/CHANGELOG.md):

3 July 2025

Msal Authentication Flows

Updated

The [OAuth 2.0 resource owner password credentials](v2-oauth-ropc.md) (ROPC) grant allows an application to sign in the user by directly handling their password. In your desktop application, you can use the username/password flow to acquire a token silently. No UI is required when using the application.

3 July 2025

Password Administrator

Updated

A Microsoft Entra documentation page was updated: Password Administrator.

3 July 2025

Sign Ins

Updated

A Microsoft Entra documentation page was updated: Sign Ins.

2 July 2025
11

Overview

Updated

author: MicrosoftGuyJFlo

3 July 2025

Audit Logs

Updated

A Microsoft Entra documentation page was updated: Audit Logs.

2 July 2025

Sign Ups

Updated

A Microsoft Entra documentation page was updated: Sign Ups.

2 July 2025

Howto Use Recommendations

Updated

Most recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.

1 July 2025

Concepts Forest Trust

Updated

A Microsoft Entra documentation page was updated: Concepts Forest Trust.

1 July 2025

Whats New

Updated

- US Gov -> Commercial

1 July 2025

Whats New

Updated

**Service category:** Provisioning

30 June 2025
7

Agent Optimization

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

5 July 2025

Agent Optimization

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

4 July 2025

Authentication Flows

Updated

To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.

4 July 2025
6

Getty Images Tutorial

Updated

1. If you wish to configure the application in **SP** initiated mode, then perform the following step:

4 July 2025
6

Security Administrator

Updated

A Microsoft Entra documentation page was updated: Security Administrator.

3 July 2025

Security Operator

Updated

A Microsoft Entra documentation page was updated: Security Operator.

3 July 2025

Security Reader

Updated

A Microsoft Entra documentation page was updated: Security Reader.

3 July 2025
4
3

Configurable Token Lifetimes

Updated

Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.

4 July 2025

V2 Oauth2 Auth Code Flow

Updated

Redirect URIs for SPAs that use the auth code flow require special configuration.

3 July 2025

How to migrate to Transport Layer Security (TLS) 1.2 enforcement for Microsoft Entra Domain Services

Updated

Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions is not known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.

1 July 2025
2

Application Developer

Updated

A Microsoft Entra documentation page was updated: Application Developer.

3 July 2025

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

2 July 2025
1

Plan Connect Performance Factors

Updated

The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.

5 July 2025
1
1
1

Agent Optimization

Updated

- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.

3 July 2025
3

Entitlement Management Verified Id Settings

Updated

> If you select multiple credential types from one issuer, users will be required to present credentials of all selected types. Similarly, if you include multiple issuers, users will be required to present credentials from each of the issuers you include in the policy. To give users the option of presenting different credentials from various issuers, configure separate policies for each issuer/credential type you’ll accept.

3 July 2025
9

Custom Url Domain

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Domain Name Administrator](~/identity/role-based-access-control/permissions-reference.md#domain-name-administrator).

1 July 2025
1
1

Microsoft Accounts Federation Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

4 July 2025
1

B2b Fundamentals

Updated

| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |

4 July 2025
1
1

Supported Features Customers

Updated

| **Sign-out** | When a [SAML](../../identity-platform/single-sign-out-saml-protocol.md) or [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#send-a-sign-out-request) application directs the user to the logout endpoint, Microsoft Entra ID removes and invalidates the user's session from the browser. | Same as workforce.|

3 July 2025
1

Workload Identity Federation Config App Trust Managed Identity

Updated

- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* values of the federated identity credential are checked against the `issuer` and `subject` claims provided in the Managed Identity token. If that validation check passes, Microsoft identity platform issues an access token to the external software workload.

1 July 2025
2

Configure Connectors

Updated

- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).

4 July 2025
1
1

Configure Connectors

Updated

For information about connectors, capacity planning, and how they stay up-to-date, see [Understand Microsoft Entra private network connectors](concept-connectors.md).

2 July 2025
1
2