To use the native authentication JavaScript SDK in your app, use your terminal to install it by using the following command:
macOS Platform SSO troubleshooting is the week’s clearest admin-impact item; most other changes are documentation guidance
For the week of 11 August 2025, the supplied record is dominated by Microsoft Learn maintenance: 28 updates, five new records, two removed records, and no Message Center items. The strongest operational signal is updated macOS Platform SSO guidance documenting a macOS 15+ concurrency issue that can corrupt device configuration and trigger unexpected re-registration prompts. New Workday and SuccessFactors expression-mapping references, refreshed native-authentication setup material, and more specific security and governance guidance are the other meaningful exceptions. Nothing supplied establishes a preview, general availability, tenant-wide behavior change, or confirmed retirement. The two removed Zero Trust entries are paired with same-day new entries bearing identical titles, so they do not by themselves prove retirement.
- macOS Platform SSO documents a macOS 15+ concurrency failure mode
Entra ID · Troubleshooting
The updated Microsoft Entra ID troubleshooting content says simultaneous updates from the macOS AppSSOAgent and AppSSODaemon can corrupt the PSSO device configuration. macOS may then start its re-registration remediation flow, producing unexpected registration prompts. Related material covers integrating PSSO with an MDM solution. This is troubleshooting and integration guidance—not evidence of a new PSSO launch or a behavior change introduced this week.
- Provisioning references for Workday and SuccessFactors were added
Entra ID · Provisioning
Two new Microsoft Entra ID pages document commonly used expression-mapping functions: Workday mappings to on-premises Active Directory or Microsoft Entra ID, and SuccessFactors mappings to Microsoft Entra ID. The existing Workday guide was also updated with an organizational-unit assignment section. These additions expand the implementation reference material; they do not establish that new connector functions or runtime behavior were introduced.
- Native authentication setup content was refreshed for Entra ID and External ID
External ID · Authentication
The Entra ID React single-page-app tutorial now includes the terminal command for installing the native-authentication JavaScript SDK. The Microsoft Entra External ID page covers native-authentication setup and user-interface customization for mobile and desktop applications. The supplied evidence gives no preview or general-availability status and does not show a change to service availability.
- Security pages add protection checks and TLS configuration details
Global Secure Access · Security
The Entra ID Identifier URI Restrictions update links administrators to a way to check whether the protection is enabled. The Domain Services TLS Enforcement update includes interface guidance for enabling TLS 1.2 Only Mode, and the Global Secure Access Transport Layer Security page includes an OpenSSL certificate-generation example. These are security documentation updates; the evidence does not say that protections were automatically enabled or that enforcement requirements changed.
- PIM approval guidance and Lifecycle Workflows syntax were clarified
ID Governance · Governance
Updated Microsoft Entra ID Governance guidance recommends approval for eligible role activation, at least one approver and preferably two; when no specific approvers are selected, active Privileged Role Administrators and Global Administrators become the default approvers. The Logic App Lifecycle Workflows update calls out the slash required after the tenant ID in the Issuer value. These are documented recommendations and configuration details, not evidence that existing PIM defaults changed.
PSSO administrators supporting macOS 15+ should review the troubleshooting guidance, particularly when users encounter unexpected re-registration prompts. Provisioning and application teams can use the updated mapping and native-authentication documentation for implementation work, while relevant security and governance owners can verify settings or syntax. The evidence does not support a broad tenant change or immediate rollout based on this period alone.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
26 updatesMacos Psso
UpdatedmacOS Platform Single Sign-on (PSSO) is a new feature powered by Microsoft’s Enterprise SSO plug-in, Platform Credentials for macOS that enables users to sign in to Mac devices using their Microsoft Entra ID credentials. This feature provides benefits for admins by simplifying the sign-in process for users and reducing the number of passwords they need to remember. It also allows users to authenticate with Microsoft Entra ID with a smart card or hardware-bound key. This feature improves the end-user experience by not having to remember two separate passwords and diminishes the need for admins to manage the local account password.
author: justinha
Authentication Strengths
Updated- Microsoft Entra certificate-based authentication (Multifactor)
Platform Single Sign-On (PSSO) for macOS devices is a feature that allows users to sign in to macOS devices using their Microsoft Entra credentials. This feature provides a seamless sign-in experience for users and helps organizations manage access to resources on macOS devices.
Howto Mfa Nps Extension
Updated* `https://onegetcdn.azureedge.net`
Agents
Updatedauthor: MicrosoftGuyJFlo
A Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
Zero Trust Protect Networks
RemovedA Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
A Microsoft Entra documentation page was updated: Zero Trust Protect Tenants.
Zero Trust Protect Tenants
RemovedA Microsoft Entra documentation page was updated: Zero Trust Protect Tenants.
A guide for architects and IT administrators on how to secure access to SAP platforms and applications
:::image type="content" border="true" source="media/reference-domain-services-tls-enforcement/enable.png" alt-text="Screenshot that shows how to enable TLS 1.2 Only Mode for Domain Services.":::
Licensing Pim
Updatedauthor: barclayn
Places Administrator
Describes the Microsoft Entra built-in roles and permissions.
Single And Multi Tenant Apps
Updated| Audience | Single/multi-tenant | Who can sign in |
The following table explains the status for *isCloudManaged* and *onPremisesSyncEnabled* attributes after you convert the SOA of an object.
S comprehensive guide to commonly used expression mapping functions when configuring SuccessFactors to Microsoft Entra ID user provisioning. These functions help transform and map data from SuccessFactors to create appropriate user attributes in Microsoft Entra ID.
A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.
- [Organizational unit (OU) assignment](#organizational-unit-ou-assignment)
A comprehensive guide to commonly used expression mapping functions when configuring SuccessFactors to Microsoft Entra ID user provisioning. These functions help transform and map data from SuccessFactors to create appropriate user attributes in Microsoft Entra ID.
Delete Application Portal
Updated- One of the following roles:
Identifier Uri Restrictions
Updated[Learn how to check if the protection has been enabled in your organization](https://aka.ms/check-identifier-uri-protection-state)
Saml Tokens
Updated> |Name | `unique_name` |Provides a human readable value that identifies the subject of the token. This value is not guaranteed to be unique within a tenant and is designed to be used only for display purposes. | `<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">`<br>`<AttributeValue>[email protected]<AttributeValue>`|
There's a known concurrency issue on macOS 15+ (Sequoia) that can cause the PSSO device configuration to become corrupted. The device configuration can be corrupted by simultaneous updates from the system AppSSOAgent and AppSSODaemon processes. The corrupted configuration causes the operating system to trigger its re-registration remediation flow, resulting in unexpected registration prompts for users.
Microsoft Entra ID Governance
4 updates> [!IMPORTANT]
- For `Issuer`, ensure you included the slash after your Tenant ID
Pim How To Add Role To User
UpdatedFollow these steps to update or remove an existing role assignment.
We recommend requiring approval for activation of an eligible assignment. The approver doesn't have to have any roles. When you use this option, select at least one approver. We recommend that you select at least two approvers. If no specific approvers are selected, active Privileged Role Administrators/Global Administrators become the default approvers.
Microsoft Entra External ID
1 updateNative authentication
UpdatedLearn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.
Microsoft Entra Global Secure Access
4 updatesVersion History
UpdatedRole Based Permissions
Updatedmanager: dougeby
Application Discovery
UpdatedUse Application discovery to detect the applications accessed by users and create separate private applications.
Transport Layer Security
Updated```openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCAchain.key -sha256 -days 370 -out rootCAchain.pem -subj "/C=US/ST=US/O=Self Signed/CN=Self Signed Root CA" -config openssl.cnf -extensions rootCA_ext```
