Week in brief

Android browser access becomes the default; Conditional Access documentation dominates an otherwise maintenance-heavy Entra week

The week of 21 July 2025 contained no new or removed documentation items: 254 items were updated, alongside one Microsoft 365 Message Center notice. The clearest service-level change was for Microsoft Entra ID on Android. Most of the remaining meaningful material was documentation or implementation guidance, especially for Conditional Access and provisioning; the supplied evidence does not establish a new feature launch or general-availability announcement for those areas.

  • A Microsoft Entra ID Message Center major update says browser access will be enabled by default for all Android users. It retires the Enable Browser Access feature in Microsoft Authenticator and Company Portal as part of a hardware-bound device registration change. The rollout is automatic worldwide, requires no admin action, and can be ignored by organizations that do not use Android.

  • Updated Microsoft Learn pages cover targeting resources, actions and authentication contexts; assigning policies to users, groups and workload identities; application and device filters; grant controls; authentication flows, including Authentication transfer (Preview); session settings; resilience defaults; report-only mode; templates; insights; service dependencies; and troubleshooting. Related updates also cover Security Defaults, MFA and phishing-resistant MFA guidance, and blocking legacy authentication. These,

  • The updated Microsoft identity platform guidance advises an app to call `getDeviceInformationWithParameters` in MSAL to determine whether an administrator configured QR code authentication. The app can then update its interface to show QR code authentication as an available sign-in option. This is implementation guidance, not evidence of a new tenant feature, availability change, or admin configuration requirement.

  • Updated inbound provisioning guidance states that tenant administrators must grant API clients `SynchronizationData-User.Upload` and `ProvisioningLog.Read.All`, plus `SynchronizationData-User.Upload.OwnedBy` for ISVs. The companion access procedure points administrators to API permissions and Add a permission. The supplied record presents this as updated guidance and does not say that these permissions were newly introduced.

  • Separate Microsoft Entra provisioning updates describe enabling accidental-deletions prevention for applications and cross-tenant synchronization, and indexing the `employeeId` attribute in Active Directory to improve inbound-provisioning performance. Both are documented as updates; the evidence does not indicate a changed default, a retirement, or a newly announced availability milestone.

For Entra administrators

Android organizations do not need to change configuration: browser access will be enabled by default for Android users, the Enable Browser Access feature in Microsoft Authenticator and Company Portal is being retired, and the change will roll out automatically worldwide. Administrators working with Conditional Access or provisioning should consult the revised procedures where relevant, but the evidence does not support a tenant-wide action triggered by the documentation updates alone.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

54
46

Inbound Provisioning Api Faqs

Updated

Learn more about the capabilities and integration scenarios supported by API-driven inbound provisioning.

23 July 2025

Provision a User with Expression Builder

Updated

Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.

23 July 2025
32

Token Protection

Updated

The following devices and applications support accessing resources on which a token protection Conditional Access policy is applied:

24 July 2025

Conditional Access Grant

Updated

Organizations that deploy Intune can use the information returned from their devices to identify devices that meet specific policy compliance requirements. Intune sends compliance information to Microsoft Entra ID so Conditional Access can decide to grant or block access to resources. For more information about compliance policies, see [Set rules on devices to allow access to resources in your organization by using Intune](/mem/intune/protect/device-compliance-get-started).

22 July 2025
26

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

26 July 2025

Global Administrator

Updated

> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices<br/>[![Privileged label icon.](../media/permissions-reference/privileged-label.png)](../privileged-roles-permissions.md) |

26 July 2025

Controls

Updated

author: MicrosoftGuyJFlo

25 July 2025

Licensing Service Plan Reference

Updated

- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID

24 July 2025
23

Ios Qr Code Pin Authentication

Updated

It's advised to call the `getDeviceInformationWithParameters` API in MSAL to find out if the admin has configured QR code authentication method. If it has, an app can update its UI to indicate that QR code authentication method is available as a sign-in option.

25 July 2025

Microsoft Entra: Browser access will be enabled by default for all Android users

New

Microsoft Entra will enable browser access by default for all Android users, retiring the "Enable Browser Access" feature in Microsoft Authenticator and Company Portal apps. This hardware-bound device registration change requires no admin action and will roll out automatically worldwide. Organizations not using Android can ignore this update.

24 July 2025
Message CenterMC1024404 on mc.merill.net ↗Major updatePlan for change

Add Application Portal Setup Oidc Sso

Updated

After entering the sign-in credentials, the consent screen appears. The consent screen provides information about the application and the permissions it requires.

23 July 2025

Secure Your Workforce with Microsoft Entra ID

Updated

Learn how to protect organizational identities with Microsoft Entra ID. Discover security recommendations, multifactor authentication setup, and Zero Trust implementation strategies.

22 July 2025
16
15

Inbound Provisioning Api Concepts

Updated

- Tenant admins must grant API clients interacting with this provisioning app the Graph permissions `SynchronizationData-User.Upload`, `SynchronizationData-User.Upload.OwnedBy` (for ISVs), and `ProvisioningLog.Read.All`.

25 July 2025

Users Default Permissions

Updated

| **Allow users to connect work or school account with LinkedIn** | Setting this option to **No** prevents users from connecting their work or school account with their LinkedIn account. For more information, see [LinkedIn account connections data sharing and consent](~/identity/users/linkedin-user-consent.md). |

25 July 2025
13

Global Reader

Updated

> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |

24 July 2025

Security Administrator

Updated

> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |

24 July 2025
6
4
2

Plan Cloud Hr Provision

Updated

This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.

25 July 2025

Plan Cloud Hr Provision

Updated

This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.

23 July 2025
1
1
1

Agent Optimization

Updated

If the agent identifies something that wasn't previously suggested, it takes the following steps. **The agent action steps consume SCUs.**

22 July 2025
1

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

24 July 2025
1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview](/microsoft-365/security/office-365-security/scc-permissions).

24 July 2025
3

Entitlement Management Access Package Visibility

Updated

The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."

22 July 2025
2

Known Issues

Updated

Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.

23 July 2025
3
1
1

Managed Identities Faq

Updated

You can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:

24 July 2025
1
1
1