- Perform regular tests to verify that CRLs are downloadable and recognized correctly by Microsoft Entra ID.
Entra ID credential UX refresh is the clearest rollout; the week otherwise centers on security and documentation guidance
The week of 25 August 2025 was primarily a documentation-maintenance cycle: 22 Microsoft Learn items were updated, with no new or removed items, alongside one Entra ID Message Center notice. That notice says a refreshed credential enrollment and management experience will roll out in early November 2025, improving usability and accessibility without changing functionality. The other substantive entries are security guidance or documentation describing governance and native-auth implementation details. The supplied evidence does not identify a newly generally available feature, retirement, or tenant-wide behavior change. The What's New Archive edit is a navigation change, and its link to “What's new (preview)” is not evidence of a new preview feature. Similarly, the Mandatory Multifactor Authentication entry has no substantive summary here and does not support a claim of a new MFA mandate.
The Message Center announcement says Microsoft Entra will roll out a refreshed credential enrollment and management user experience in early November 2025. It is described as a usability and accessibility improvement with no functionality change. No action is required, although Microsoft recommends informing help-desk teams; this is a UX rollout, not a new authentication capability, GA announcement, or retirement.
- Emergency-access guidance recommends two cloud-only Global Administrator accounts
Entra ID · Security
An updated Entra ID security entry recommends two cloud-only emergency access accounts permanently assigned the Global Administrator role. The accounts are not assigned to specific individuals and are reserved for emergency or break-glass situations when normal accounts cannot be used or administrators are locked out. This is security guidance, not evidence of a newly shipped control.
- Certificate-based authentication guidance emphasizes recurring CRL validation
Entra ID · Authentication
The Certificate Based Authentication Certificate Revocation List update calls for regular tests confirming that CRLs are downloadable and correctly recognized by Microsoft Entra ID. This is operational and security guidance for existing CBA deployments; no changed revocation behavior or availability status is stated.
- ID Governance documentation details access-package cleanup and delegated approvals
ID Governance · Governance
The Lifecycle Workflow Tasks page describes a task that removes all access package assignments for users. A separate My Access update explains that approval delegation lets an approver assign another individual to respond to access-package approval requests on their behalf when the approver is unavailable. These are documentation updates describing capabilities; the supplied evidence does not label either as new, preview, or generally available.
- Native Authentication React tutorials update reset-password and sign-up implementation steps
Entra ID · Authentication
Two Entra ID tutorial updates point developers to sample components for a React single-page app: NewPasswordForm.tsx for password reset and CodeForm.tsx for sign-up. CodeForm collects a one-time passcode and is required for either email-with-password or email-with-one-time-passcode authentication. This is a tutorial and sample-code update, not a stated platform launch or behavior change.
Brief help-desk teams about the November credential UX transition; the notice says no administrator action is required and identifies no compliance issues. For certificate-based authentication, the evidence supports regular CRL validation, while the emergency-access entry provides a recommendation to compare against the tenant's current setup. Governance and native-auth updates matter to teams using those capabilities, but they do not support a broader configuration rollout.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
15 updates```json
author: justinha
1. Create *reset-password/components/NewPasswordForm.tsx* file, then paste the code from [reset-password/components/NewPasswordForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/reset-password/components/NewPasswordForm.tsx). This component displays a form that collects a user's new password.
1. Create a *sign-up/components/CodeForm.tsx* file, then paste the code from [sign-up/components/CodeForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/sign-up/components/CodeForm.tsx). This component displays a form that collects a one-time passcode sent to the user. You require this form for either email with password or email with one-time passcode authentication method.
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
Find Tenant
Updated2. Browse to **Entra ID** > **Overview** > **Properties**.
Whats New Archive
UpdatedFor a more dynamic experience, you can now find the archive information in the Microsoft Entra admin center. To learn more, see [What's new (preview)](./whats-new-overview.md).
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
author: shlipsey3
Agent Optimization Chat
Updatedauthor: shlipsey3
Applies To External Only
Updatedauthor: garrodonnell
risklevel: High
UpdatedMicrosoft recommends that organizations have two cloud-only emergency access accounts permanently assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role. These accounts are highly privileged and aren't assigned to specific individuals. The accounts are limited to emergency or "break glass" scenarios where normal accounts can't be used or all other administrators are accidentally locked out.
Microsoft Entra will roll out a refreshed credential enrollment and management user experience in early November 2025, improving usability and accessibility without changing functionality. No action is required, but informing help desk teams is recommended to ease the transition. No compliance issues identified.
ai-usage: ai-assisted
Microsoft Entra ID Governance
3 updatesPim How To Add Role To User
Updated- Select the role scope (in this case, administrative units)
Delegate Approvals My Access
UpdatedApproval delegation in My Access allows approvers to assign another individual to respond to access package approval requests on their behalf. This feature helps maintain productivity when approvers are unavailable due to leave, travel, or other commitments.
Lifecycle Workflow Tasks
UpdatedAllows you to remove all access package assignments for users. For more information on access packages, see [What are access packages and what resources can I manage with them?](entitlement-management-overview.md#what-are-access-packages-and-what-resources-can-i-manage-with-them).
Microsoft Entra External ID
3 updatesApplies To External Only
Updatedauthor: garrodonnell
**Applies to**:  Workforce tenants  External tenants ([learn more](/entra/external-id/tenant-configurations))
Applies To Workforce Only
Updatedauthor: garrodonnell
Microsoft Entra Internet Access
1 updateGsa Poc Private Access
UpdatedWhen customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).
Points Of Presence
UpdatedThe table lists the deployment status for the APAC region.
