Week in brief

ID Protection risk-policy guidance is the week’s clearest operational signal; no Entra launch is evidenced

For the week of 18 August 2025, the supplied record shows a documentation-led period: 63 entries were updates, none were new, there were no Message Center items, and two documentation entries were removed. The most consequential update is ID Protection guidance that places sign-in and user-risk policy configuration in Conditional Access and tells tenants using legacy risk policies to plan migration. Other substantive guidance concerns a Group Source of Authority cloud-conversion preview, Conditional Access exception governance, External ID CIAM transition, and managed-identity regional moves. Global Secure Access changes are procedural, including a Multi-Geo routing illustration and a TLS administrator-role step. The evidence supports no general-availability rollout, changed service behavior, or product retirement; the removed entries do not include replacement or retirement details.

  • The 23 August update to the ID Protection guide says to configure sign-in risk and user risk policies in Microsoft Entra Conditional Access. It also says tenants that enabled legacy risk policies should plan to migrate them to Conditional Access. This is updated security and migration guidance—not evidence of a new policy feature, enforcement date, or changed runtime behavior.

  • The updated Entra ID article, whose title explicitly includes Preview, covers Source of Authority, prerequisites, supported scenarios, and step-by-step guidance for IT architects and administrators. The supplied record establishes the preview label and documentation scope only; it does not establish general availability or a tenant-wide change.

  • The updated ID Governance article recognizes business cases for exceptions and describes using Microsoft Entra access reviews to manage exclusions, avoid oversight, and provide auditors proof that exceptions are reviewed regularly. It is governance guidance; no new exclusion behavior or required review cadence is stated.

  • The 19 August External ID update is a transition guide for migrating legacy customer identity solutions to Microsoft Entra External ID, with security, compliance, and scalability identified as the goals. The supplied summary gives no migration deadline, prerequisites, or availability change, so this should be read as migration guidance rather than a launch announcement.

  • The Workload ID regional-move guidance says to copy permissions assigned to a user-assigned managed identity and warns that listing Azure role assignments may not be enough when permissions were granted through a service-specific option. For a planned move, administrators should confirm that the solution does not depend on those permissions. This is operational migration caution, not a new capability announcement.

For Entra administrators

Focus follow-up on tenants that use legacy ID Protection risk policies: review the linked Conditional Access guidance and plan migration; the supplied material gives no deadline. For Conditional Access exclusions, use the access-review guidance to check that exceptions are managed and that regular review can be evidenced to auditors. Teams evaluating cloud Group Source of Authority, moving legacy CIAM to External ID, or moving user-assigned managed identities should validate the documented scenarios, prerequisites, and permissions before acting. Do not treat the page removals or the Global Secure Access documentation edits as evidence of a service retirement or rollout.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

13

Recommendations

Updated

![Screenshot of the Overview page of the tenant with the Recommendations option highlighted.](./media/overview-recommendations/recommendations-overview.png)

23 August 2025

Migrate Adfs Apps Phases Overview

Updated

To ensure that the users can easily and securely access applications, your goal is to have a single set of access controls and policies across your on-premises and cloud environments.

22 August 2025

Groups Saasapps

Updated

* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)

22 August 2025

Groups Self Service Management

Updated

* [Manage access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)

22 August 2025

Groups Troubleshooting

Updated

* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)

22 August 2025

What is enterprise user management?

Updated

This article introduces an administrator for Microsoft Entra ID, part of Microsoft Entra, to the relationship between top [identity management](~/fundamentals/what-is-entra.md?context=azure/active-directory/users-groups-roles/context/ugr-context) tasks for users in terms of their groups, licenses, deployed enterprise apps, and administrator roles. As your organization grows, you can use Microsoft Entra groups and administrator roles to:

22 August 2025

Groups Change Type

Updated

- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)

21 August 2025

Groups Create Rule

Updated

- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)

21 August 2025

Groups Dynamic Membership

Updated

- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)

21 August 2025

Whatis

Removed

A Microsoft Entra documentation page was updated: Whatis.

21 August 2025

Bulk Operations

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/GroupsManagementMenuBlade) and in the left-hand navigation pane, select the **Groups** tab and then **All groups**.

20 August 2025
10

Tenant Installation Account

Updated

By default, the user who creates a Microsoft Entra tenant is automatically assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role.

22 August 2025

Apple Sso Plugin

Updated

If for any reason Secure Enclave needs to be disabled, follow these recommended steps:

21 August 2025

Groups Members Owners Search

Updated

These articles provide additional information on working with groups in Microsoft Entra ID.

21 August 2025
7

What is the Microsoft Entra architecture?

Updated

Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)

22 August 2025

Microsoft Entra deployment plans

Updated

Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.

22 August 2025

Secure Fundamentals

Updated

These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).

22 August 2025
5

Choose Ad Authn

Updated

In today's world, threats are present 24 hours a day and come from everywhere. Implement the correct authentication method, and it will mitigate your security risks and protect your identities.

22 August 2025

Howto Vm Sign In Azure Ad Windows

Updated

For more information about Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).

22 August 2025

Howto Vm Sign In Azure Ad Linux

Updated

1. Run `sudo apt remove --purge aadlogin` (Ubuntu/Debian), `sudo yum remove aadlogin` (RHEL), or `sudo zypper remove aadlogin` (openSUSE or SLES).

21 August 2025

Connect Pta Quick Start

Updated

Microsoft Entra pass-through authentication allows your users to sign in to both on-premises and cloud-based applications by using the same passwords. Pass-through Authentication signs users in by validating their passwords directly against on-premises Active Directory.

20 August 2025
3

Conditional Access Cloud Apps

Updated

When you target the Windows Azure Service Management API application, policy is enforced for tokens issued to a set of services closely bound to the portal. This grouping includes the application IDs of:

22 August 2025

V2 Conditional Access Dev Guide

Updated

Microsoft Entra Conditional Access is a feature included in [Microsoft Entra ID P1 or P2](~/fundamentals/licensing.md). Customers with [Microsoft 365 Business licenses](/office365/servicedescriptions/office-365-service-descriptions-technet-library) also have access to Conditional Access features.

22 August 2025
3

Application Proxy Ping Access Publishing Guide

Updated

You need a license for PingAccess and Microsoft Entra ID. However, Microsoft Entra ID P1 or P2 subscriptions include a basic PingAccess license that covers up to 20 applications. If you need to publish more than 20 header-based applications, you can purchase more licenses from PingAccess.

22 August 2025

Plan An Application Integration

Updated

The following articles discuss the different ways applications integrate with Microsoft Entra ID, and provide some guidance.

22 August 2025
2
1

Groups Lifecycle

Updated

For more information on Microsoft Entra groups, see:

21 August 2025
1

Howto Use Recommendations

Updated

![Screenshot of the list of recommendations.](media/howto-use-recommendations/recommendations-list.png)

23 August 2025
3

Id Protection Guide Remediate

Updated

- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)

23 August 2025

Id Protection Guide Introduction

Updated

Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:

23 August 2025

Id Protection Guide Investigate

Updated

Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:

23 August 2025
1

Id Protection Guide Detect

Updated

To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and User [risk policies](../id-protection/concept-identity-protection-policies.md) in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).

23 August 2025
5

Access Reviews External Users

Updated

This article describes features and methods that allow you to pinpoint and select external identities so that you can review them and remove them from Microsoft Entra ID if they're no longer needed. The cloud makes it easier than ever to collaborate with internal or external users. When embracing Office 365, organizations start to see the proliferation of external identities (including guests), as users work together on data, documents, or digital workspaces such as Teams. Organizations need to balance, enabling collaboration and meeting security and governance requirements. Part of these efforts should include evaluating and cleaning out external users, who were invited for collaboration into your tenant, that originating from partner organizations, and removing them from your Microsoft Entra ID when they're no longer needed.

22 August 2025

Entitlement Management Access Package Approval Policy

Updated

After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).

21 August 2025

Entitlement Management Access Package Approval Policy

Updated

After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).

20 August 2025
1
1

Conditional Access Exclusion

Updated

In an ideal world, all users follow the access policies to secure access to your organization's resources. However, sometimes there are business cases that require you to make exceptions. This article goes over some examples of situations where exclusions could be necessary. You, as the IT administrator, can manage this task, avoid oversight of policy exceptions, and provide auditors with proof that these exceptions are reviewed regularly using Microsoft Entra access reviews.

22 August 2025
1
1
2

Managed Identity Regional Move

Updated

1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.

21 August 2025
1

Overview

Updated

At a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed identities.

20 August 2025
2

Enable Multi Geo

Updated

:::image type="content" source="media/how-to-enable-multi-geo/multi-geo-support-diagram.svg" alt-text="Diagram that illustrates how Multi-Geo support routes traffic with Microsoft Entra private network connectors.":::

20 August 2025

Macos Client Release History

Updated

This article tracks the changes in each released version of the Global Secure Access client for macOS.

20 August 2025
1

Configure Global Access With Pim

Updated

- [Microsoft Entra ID license that includes Privileged Identity Management (PIM)](~/fundamentals/licensing.md)

22 August 2025
1

Transport Layer Security

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).

19 August 2025