This document describes setting up and configuring multiple top level domains with Microsoft 365 and Microsoft Entra ID.
Authenticator UX changes and the Entra ID Free subscription rollout lead a documentation-heavy week
The week of 15 September 2025 was dominated by documentation maintenance: 39 items were updated, no items were removed, and the two new pages were Global Secure Access PowerShell samples for creating and signing TLS certificates in test environments. The two substantive Microsoft 365 Message Center notices cover a changed Microsoft Authenticator experience and the staged appearance of the no-cost Microsoft Entra ID Free subscription. The clearest security-related documentation exception is the explicit Tenant Restrictions v2 limit on cross-cloud enforcement. No preview, general-availability announcement, retirement, or deprecation is identified in the supplied evidence.
- Changed behavior: Microsoft Authenticator simplifies same-device number matching
Entra ID · Authentication
The Message Center notice describes a rollout from late September through mid-October 2025. For same-device sign-ins, users will no longer enter a number and will instead select Yes or No. The first-run experience will prioritize Microsoft Entra accounts and highlight QR-code scanning. This is an end-user experience change, and the notice says no administrator action is needed.
- Administrative rollout: the Microsoft Entra ID Free subscription will appear in portals
Entra ID · Fundamentals
Microsoft is rolling out a no-cost Entra ID Free subscription to track tenant ownership through billing accounts. It will appear in the Microsoft 365 and Azure portals starting in October. The notice explicitly says it does not affect billing or functionality and requires no action.
- Security clarification: Tenant Restrictions v2 is not enforced for cross-cloud requests
External ID · General
The updated External ID documentation states that Tenant Restrictions v2 is supported on all clouds, but it is not enforced with cross-cloud requests. Administrators should treat this as a coverage boundary and not assume that the capability controls cross-cloud requests; the supplied item is a documentation clarification, not a feature rollout announcement.
- Operational guidance: Entra Connect and SCIM documentation state concrete planning boundaries
Entra ID · General
The updated Microsoft Entra Connect prerequisites require a domain-joined Windows Server 2016–2022 installation and recommend Windows Server 2022; Windows Server 2016 is in extended support and may require a paid support program. Separately, the SCIM provisioning guidance states that supporting at least 25 requests per second per tenant is required to avoid delays in provisioning and deprovisioning. These are documented deployment and integration requirements, not an announced forced upgrade or service change.
- New documentation: Global Secure Access TLS certificate samples target test environments
Global Secure Access · Fundamentals
Two new PowerShell samples show how to create a TLS certificate with Active Directory Certificate Services and how to generate and sign TLS certificates with OpenSSL. Both are explicitly for test environments. They are setup examples, not evidence of a Global Secure Access feature launch, production certificate requirement, or availability change.
Expect Microsoft Authenticator users to see the new same-device confirmation and first-run experience during the stated late-September-to-mid-October rollout; the notice says no administrator action is required. The Entra ID Free subscription will also require no action and will not affect billing or functionality. Conditional checks are warranted for administrators who rely on Tenant Restrictions v2 for cross-cloud control, deploy Microsoft Entra Connect, or build SCIM provisioning: the updated guidance states the relevant coverage, operating-system, and throughput boundaries. Teams using custom authentication strengths can consult the updated passkey and certificate-based authentication guidance, but the record does not establish a new availability state. Most other External ID edits—f
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
20 updatesTo revoke the old Token Signing Certificate that AD FS is currently using, you need to determine the thumbprint of the token-signing certificate. From your ADFS Server do the following:
Connect Fed O365 Certs
UpdatedCheck the certificates configured in AD FS and Microsoft Entra ID trust properties for the specified domain.
Pagedna Tutorial
Updated|------|
author: msmimart
author: msmimart
author: msmimart
Microsoft is rolling out the no-cost Microsoft Entra ID Free subscription to track Entra tenant ownership via billing accounts. It will appear in Microsoft 365 and Azure portals starting October, requires no action, does not affect billing or functionality, and helps manage tenant ownership securely.
Activity Log Schemas
Updated- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).
Activity Log Schemas
Updated- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).
Audit Logs
Updated- Where applicable, old and new values for the changed properties
manager: pmwongera
This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.
>
Microsoft Authenticator will streamline same-device sign-ins by removing number entry, requiring only a Yes/No confirmation, and improve onboarding by prioritizing Microsoft Entra accounts and highlighting QR code scanning. Rollout begins late September to mid-October 2025, with no admin action needed.
Learn how admins can create custom authentication strengths with advanced options for passkey (FIDO2) security keys and certificate-based authentication.
Sign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps.
Discover how to analyze Conditional Access policy results with tools like Azure Monitor and insights workbooks for better policy management.
- Microsoft Entra Connect must be installed on a domain-joined Windows Server 2016-2022. We recommend using domain-joined Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported Windows Server version may cause service failures or unexpected behavior.
> * Support at least 25 requests per second per tenant to ensure that users and groups are provisioned and deprovisioned without delay (Required)
Microsoft Entra External ID
19 updatesUse App Roles Customers
UpdatedWhen Microsoft Entra External ID issues a security token for an authenticated user, it includes the names of the roles you've assigned the user or group in the security token's roles claim. An application that receives that security token in a request can then make authorization decisions based on the values in the roles claim.
Reference documentation for a custom authentication extension that invokes the emailOtpSend event for External ID customer configurations.
Google Federation Customers
UpdatedBy setting up federation with Google, you allow customers to sign in to your applications with their own Google accounts. After you add Google as one of your user flow's sign-in options, customers can sign up and sign in to your application with a Google account. (Learn more about [authentication methods and identity providers for customers](concept-authentication-methods-customers.md).)
By setting up federation with Facebook, you can allow customers to sign in to your applications with their own Facebook accounts. After you've added Facebook as one of your application's sign-in options, on the sign-in page, customers can sign-in to Microsoft Entra External ID with a Facebook account. (Learn more about [authentication methods and identity providers for customers](/entra/external-id/customers/concept-authentication-methods-customers).)
This article describes how to create a sign-in and sign-up user flow. After you create the user flow, the next step is to [add your application to the user flow](how-to-user-flow-add-application.md). You can create multiple user flows if you have multiple applications that you want to offer to customers. Or, you can use the same user flow for many applications. However, an application can have only one user flow.
Customize Branding Customers
UpdatedAfter creating a new external tenant, you can customize the end-user experience. Create a custom look and feel for users signing in to your apps by configuring **Company branding** settings for your tenant. With these settings, you can add your own background images, colors, company logos, and text to customize the sign-in experiences across your apps.
:::image type="content" source="media/how-to-enable-password-reset-customers/sspr-flow.png" alt-text="Screenshot that shows the self-service password rest flow.":::
Solutions Customers
UpdatedWhen you enter an email address to create an account, your email is verified through a one-time passcode. Then you can create a new password and provide more details, such as your name, country or region, and other information. Once your account is created, your email becomes your sign-in ID.
Define Custom Attributes
UpdatedAn attribute with a Boolean data type has a user input type of CheckboxSingleSelect. You can modify the text that displays next to the checkbox and include hyperlinks.
Training Videos
UpdatedTo start the training, go to [Guided project – Build a sample app to evaluate Microsoft Entra External ID](https://aka.ms/eeid/training-module) and follow the units in order.
Tenant Restrictions V2
Updated- Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.
Add Attributes To Token
UpdatedYou can specify which built-in or custom attributes you want to include as claims in the token that Microsoft Entra ID sends to your application.
User Insights
UpdatedThe Application user activity feature under Usage & insights provides data analytics on user activity and engagement for registered applications in your tenant. You can use this feature to view, query, and analyze user activity data in the Microsoft Entra admin center. This feature can help you uncover valuable insights that can aid strategic decisions and drive business growth.
Customers Ciam
UpdatedCustom Url Domain
Updated- It provides a more consistent user experience. From the user's perspective, they remain in your domain during the sign in process rather than redirecting to the default domain *<tenant-name>.ciamlogin.com*.
This article describes how to enforce MFA for your customers by creating a Microsoft Entra Conditional Access policy and adding MFA to your sign-up and sign-in user flow.
By setting up federation with Microsoft account (live.com) using OpenID Connect (OIDC) identity provider, you enable users to sign up and sign in to your applications using their existing Microsoft accounts (MSA).
Microsoft Entra Global Secure Access
4 updatesTransport Layer Security
Updated> [!IMPORTANT]
What Is Global Secure Access
Updatedmanager: dougeby
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
