Recommendations
Updated
Daily.Entra.NewsFor the week of 18 August 2025, the supplied record shows a documentation-led period: 63 entries were updates, none were new, there were no Message Center items, and two documentation entries were removed. The most consequential update is ID Protection guidance that places sign-in and user-risk policy configuration in Conditional Access and tells tenants using legacy risk policies to plan migration. Other substantive guidance concerns a Group Source of Authority cloud-conversion preview, Conditional Access exception governance, External ID CIAM transition, and managed-identity regional moves. Global Secure Access changes are procedural, including a Multi-Geo routing illustration and a TLS administrator-role step. The evidence supports no general-availability rollout, changed service behavior, or product retirement; the removed entries do not include replacement or retirement details.
The 23 August update to the ID Protection guide says to configure sign-in risk and user risk policies in Microsoft Entra Conditional Access. It also says tenants that enabled legacy risk policies should plan to migrate them to Conditional Access. This is updated security and migration guidance—not evidence of a new policy feature, enforcement date, or changed runtime behavior.
The updated Entra ID article, whose title explicitly includes Preview, covers Source of Authority, prerequisites, supported scenarios, and step-by-step guidance for IT architects and administrators. The supplied record establishes the preview label and documentation scope only; it does not establish general availability or a tenant-wide change.
The updated ID Governance article recognizes business cases for exceptions and describes using Microsoft Entra access reviews to manage exclusions, avoid oversight, and provide auditors proof that exceptions are reviewed regularly. It is governance guidance; no new exclusion behavior or required review cadence is stated.
The 19 August External ID update is a transition guide for migrating legacy customer identity solutions to Microsoft Entra External ID, with security, compliance, and scalability identified as the goals. The supplied summary gives no migration deadline, prerequisites, or availability change, so this should be read as migration guidance rather than a launch announcement.
The Workload ID regional-move guidance says to copy permissions assigned to a user-assigned managed identity and warns that listing Azure role assignments may not be enough when permissions were granted through a service-specific option. For a planned move, administrators should confirm that the solution does not depend on those permissions. This is operational migration caution, not a new capability announcement.
Focus follow-up on tenants that use legacy ID Protection risk policies: review the linked Conditional Access guidance and plan migration; the supplied material gives no deadline. For Conditional Access exclusions, use the access-review guidance to check that exceptions are managed and that regular review can be evidenced to auditors. Teams evaluating cloud Group Source of Authority, moving legacy CIAM to External ID, or moving user-assigned managed identities should validate the documented scenarios, prerequisites, and permissions before acting. Do not treat the page removals or the Global Secure Access documentation edits as evidence of a service retirement or rollout.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

To ensure that the users can easily and securely access applications, your goal is to have a single set of access controls and policies across your on-premises and cloud environments.
* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)
* [Manage access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)
* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)
This article introduces an administrator for Microsoft Entra ID, part of Microsoft Entra, to the relationship between top [identity management](~/fundamentals/what-is-entra.md?context=azure/active-directory/users-groups-roles/context/ugr-context) tasks for users in terms of their groups, licenses, deployed enterprise apps, and administrator roles. As your organization grows, you can use Microsoft Entra groups and administrator roles to:
Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
A Microsoft Entra documentation page was updated: Whatis.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/GroupsManagementMenuBlade) and in the left-hand navigation pane, select the **Groups** tab and then **All groups**.
A Microsoft Entra documentation page was updated: Scenario Azure First Sap Identity Integration.
| Requirement | Description |
| Requirement | Description |
Datawiza integration includes the following components:
By default, the user who creates a Microsoft Entra tenant is automatically assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role.
If for any reason Secure Enclave needs to be disabled, follow these recommended steps:
These articles provide additional information on working with groups in Microsoft Entra ID.
For more information on Microsoft Entra groups, see:
For more information on Microsoft Entra groups:
|-----|-----|
> [!WARNING]
Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)
Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.
These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).
The following products and services appear in this guide:
The following products and services appear in this guide:
In today's world, threats are present 24 hours a day and come from everywhere. Implement the correct authentication method, and it will mitigate your security risks and protect your identities.
For more information about Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).
npx create-react-app reactspa --template typescript
1. Run `sudo apt remove --purge aadlogin` (Ubuntu/Debian), `sudo yum remove aadlogin` (RHEL), or `sudo zypper remove aadlogin` (openSUSE or SLES).
Microsoft Entra pass-through authentication allows your users to sign in to both on-premises and cloud-based applications by using the same passwords. Pass-through Authentication signs users in by validating their passwords directly against on-premises Active Directory.
When you target the Windows Azure Service Management API application, policy is enforced for tokens issued to a set of services closely bound to the portal. This grouping includes the application IDs of:
Microsoft Entra Conditional Access is a feature included in [Microsoft Entra ID P1 or P2](~/fundamentals/licensing.md). Customers with [Microsoft 365 Business licenses](/office365/servicedescriptions/office-365-service-descriptions-technet-library) also have access to Conditional Access features.
There are scenarios when it's necessary to allow access for a small, specific group.
You need a license for PingAccess and Microsoft Entra ID. However, Microsoft Entra ID P1 or P2 subscriptions include a basic PingAccess license that covers up to 20 applications. If you need to publish more than 20 header-based applications, you can purchase more licenses from PingAccess.
The following articles discuss the different ways applications integrate with Microsoft Entra ID, and provide some guidance.
To assign a user account to an enterprise application:
|--|--|--|--|
For more information on Microsoft Entra groups, see:

- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)
Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:
Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:
To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and User [risk policies](../id-protection/concept-identity-protection-policies.md) in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
This article describes features and methods that allow you to pinpoint and select external identities so that you can review them and remove them from Microsoft Entra ID if they're no longer needed. The cloud makes it easier than ever to collaborate with internal or external users. When embracing Office 365, organizations start to see the proliferation of external identities (including guests), as users work together on data, documents, or digital workspaces such as Teams. Organizations need to balance, enabling collaboration and meeting security and governance requirements. Part of these efforts should include evaluating and cleaning out external users, who were invited for collaboration into your tenant, that originating from partner organizations, and removing them from your Microsoft Entra ID when they're no longer needed.
| | Description |
After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
1. Select **Request history** to confirm the request was canceled.
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
In an ideal world, all users follow the access policies to secure access to your organization's resources. However, sometimes there are business cases that require you to make exceptions. This article goes over some examples of situations where exclusions could be necessary. You, as the IT administrator, can manage this task, avoid oversight of policy exceptions, and provide auditors with proof that these exceptions are reviewed regularly using Microsoft Entra access reviews.
Transition to Microsoft Entra External ID for CIAM: Learn how to migrate your legacy customer identity solutions to enhance security, compliance, and scalability.
manager: femila
1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.
**Azure Instance Metadata Service (IMDS)**
At a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed identities.
:::image type="content" source="media/how-to-enable-multi-geo/multi-geo-support-diagram.svg" alt-text="Diagram that illustrates how Multi-Geo support routes traffic with Microsoft Entra private network connectors.":::
This article tracks the changes in each released version of the Global Secure Access client for macOS.
- [Microsoft Entra ID license that includes Privileged Identity Management (PIM)](~/fundamentals/licensing.md)
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).