Week in brief

Authenticator UX changes and the Entra ID Free subscription rollout lead a documentation-heavy week

The week of 15 September 2025 was dominated by documentation maintenance: 39 items were updated, no items were removed, and the two new pages were Global Secure Access PowerShell samples for creating and signing TLS certificates in test environments. The two substantive Microsoft 365 Message Center notices cover a changed Microsoft Authenticator experience and the staged appearance of the no-cost Microsoft Entra ID Free subscription. The clearest security-related documentation exception is the explicit Tenant Restrictions v2 limit on cross-cloud enforcement. No preview, general-availability announcement, retirement, or deprecation is identified in the supplied evidence.

  • The Message Center notice describes a rollout from late September through mid-October 2025. For same-device sign-ins, users will no longer enter a number and will instead select Yes or No. The first-run experience will prioritize Microsoft Entra accounts and highlight QR-code scanning. This is an end-user experience change, and the notice says no administrator action is needed.

  • Microsoft is rolling out a no-cost Entra ID Free subscription to track tenant ownership through billing accounts. It will appear in the Microsoft 365 and Azure portals starting in October. The notice explicitly says it does not affect billing or functionality and requires no action.

  • The updated External ID documentation states that Tenant Restrictions v2 is supported on all clouds, but it is not enforced with cross-cloud requests. Administrators should treat this as a coverage boundary and not assume that the capability controls cross-cloud requests; the supplied item is a documentation clarification, not a feature rollout announcement.

  • The updated Microsoft Entra Connect prerequisites require a domain-joined Windows Server 2016–2022 installation and recommend Windows Server 2022; Windows Server 2016 is in extended support and may require a paid support program. Separately, the SCIM provisioning guidance states that supporting at least 25 requests per second per tenant is required to avoid delays in provisioning and deprovisioning. These are documented deployment and integration requirements, not an announced forced upgrade or service change.

  • Two new PowerShell samples show how to create a TLS certificate with Active Directory Certificate Services and how to generate and sign TLS certificates with OpenSSL. Both are explicitly for test environments. They are setup examples, not evidence of a Global Secure Access feature launch, production certificate requirement, or availability change.

For Entra administrators

Expect Microsoft Authenticator users to see the new same-device confirmation and first-run experience during the stated late-September-to-mid-October rollout; the notice says no administrator action is required. The Entra ID Free subscription will also require no action and will not affect billing or functionality. Conditional checks are warranted for administrators who rely on Tenant Restrictions v2 for cross-cloud control, deploy Microsoft Entra Connect, or build SCIM provisioning: the updated guidance states the relevant coverage, operating-system, and throughput boundaries. Teams using custom authentication strengths can consult the updated passkey and certificate-based authentication guidance, but the record does not establish a new availability state. Most other External ID edits—f​‌

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

7

Connect Emergency Ad Fs Certificate Rotation

Updated

To revoke the old Token Signing Certificate that AD FS is currently using, you need to determine the thumbprint of the token-signing certificate. From your ADFS Server do the following:

19 September 2025

Connect Fed O365 Certs

Updated

Check the certificates configured in AD FS and Microsoft Entra ID trust properties for the specified domain.

19 September 2025
6

Activity Log Schemas

Updated

- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).

18 September 2025

Activity Log Schemas

Updated

- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).

17 September 2025

Audit Logs

Updated

- Where applicable, old and new values for the changed properties

17 September 2025

Copilot Entra Security Scenarios

Updated

This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.

16 September 2025
4

Troubleshoot Password Based Sso

Updated

Sign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps.

16 September 2025
1
1

Connect Install Prerequisites

Updated

- Microsoft Entra Connect must be installed on a domain-joined Windows Server 2016-2022. We recommend using domain-joined Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported Windows Server version may cause service failures or unexpected behavior.

20 September 2025
1

Use Scim To Provision Users And Groups

Updated

> * Support at least 25 requests per second per tenant to ensure that users and groups are provisioned and deprovisioned without delay (Required)

20 September 2025
8

Use App Roles Customers

Updated

When Microsoft Entra External ID issues a security token for an authenticated user, it includes the names of the roles you've assigned the user or group in the security token's roles claim. An application that receives that security token in a request can then make authorization decisions based on the values in the roles claim.

17 September 2025

Google Federation Customers

Updated

By setting up federation with Google, you allow customers to sign in to your applications with their own Google accounts. After you add Google as one of your user flow's sign-in options, customers can sign up and sign in to your application with a Google account. (Learn more about [authentication methods and identity providers for customers](concept-authentication-methods-customers.md).)

17 September 2025

Facebook Federation Customers

Updated

By setting up federation with Facebook, you can allow customers to sign in to your applications with their own Facebook accounts. After you've added Facebook as one of your application's sign-in options, on the sign-in page, customers can sign-in to Microsoft Entra External ID with a Facebook account. (Learn more about [authentication methods and identity providers for customers](/entra/external-id/customers/concept-authentication-methods-customers).)

17 September 2025

User Flow Sign Up Sign In Customers

Updated

This article describes how to create a sign-in and sign-up user flow. After you create the user flow, the next step is to [add your application to the user flow](how-to-user-flow-add-application.md). You can create multiple user flows if you have multiple applications that you want to offer to customers. Or, you can use the same user flow for many applications. However, an application can have only one user flow.

17 September 2025

Customize Branding Customers

Updated

After creating a new external tenant, you can customize the end-user experience. Create a custom look and feel for users signing in to your apps by configuring **Company branding** settings for your tenant. With these settings, you can add your own background images, colors, company logos, and text to customize the sign-in experiences across your apps.

17 September 2025

Enable Password Reset Customers

Updated

:::image type="content" source="media/how-to-enable-password-reset-customers/sspr-flow.png" alt-text="Screenshot that shows the self-service password rest flow.":::

17 September 2025

Solutions Customers

Updated

When you enter an email address to create an account, your email is verified through a one-time passcode. Then you can create a new password and provide more details, such as your name, country or region, and other information. Once your account is created, your email becomes your sign-in ID.

17 September 2025
5

Define Custom Attributes

Updated

An attribute with a Boolean data type has a user input type of CheckboxSingleSelect. You can modify the text that displays next to the checkbox and include hyperlinks.

17 September 2025

Training Videos

Updated

To start the training, go to [Guided project – Build a sample app to evaluate Microsoft Entra External ID](https://aka.ms/eeid/training-module) and follow the units in order.

17 September 2025

Tenant Restrictions V2

Updated

- Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.

16 September 2025
2

Add Attributes To Token

Updated

You can specify which built-in or custom attributes you want to include as claims in the token that Microsoft Entra ID sends to your application.

17 September 2025

User Insights

Updated

The Application user activity feature under Usage & insights provides data analytics on user activity and engagement for registered applications in your tenant. You can use this feature to view, query, and analyze user activity data in the Microsoft Entra admin center. This feature can help you uncover valuable insights that can aid strategic decisions and drive business growth.

17 September 2025
2

Custom Url Domain

Updated

- It provides a more consistent user experience. From the user's perspective, they remain in your domain during the sign in process rather than redirecting to the default domain *<tenant-name>.ciamlogin.com*.

17 September 2025
1

Multifactor Authentication Customers

Updated

This article describes how to enforce MFA for your customers by creating a Microsoft Entra Conditional Access policy and adding MFA to your sign-up and sign-in user flow.

17 September 2025
1

Microsoft Accounts Federation Customers

Updated

By setting up federation with Microsoft account (live.com) using OpenID Connect (OIDC) identity provider, you enable users to sign up and sign in to your applications using their existing Microsoft accounts (MSA).

17 September 2025
2
1
1