Week in brief

Entra Connect Sync hardening guidance identifies a dedicated first-party synchronization service principal

For the week of 22 September 2025, the supplied record reports 40 updated Microsoft Learn items, with no new or removed items and no Message Center entries. The period is therefore primarily documentation maintenance rather than a product-announcement cycle. The most consequential item is the Workload ID guidance for Microsoft Entra Connect Sync, which describes a dedicated first-party synchronization service principal. Other meaningful exceptions clarify Conditional Access configuration, hybrid-joined Temporary Access Pass setup, Global Secure Access deployment conditions, and ID Governance workflow and licensing guidance. The evidence does not establish a new feature launch, preview, general availability milestone, retirement, or broad tenant-wide behavior change.

  • The 26 September Workload ID update says Microsoft deployed a dedicated first-party application for synchronization between Active Directory and Microsoft Entra ID. It appears as the Microsoft Entra AD Synchronization Service service principal, with application ID 6bf85cfa-ac8a-4be5-b5de-425a0d0dc016, in the Enterprise Applications experience. The page describes it as critical to continued on-premises-to-Entra synchronization. This is documented security-hardening architecture, not evidence that Entra Connect Sync,

  • Updates from 24 through 27 September cover resource, action, and authentication-context targeting; user, sign-in, and insider risk; trusted locations, IP ranges, and GPS-based network signals; session and grant controls; Insights reporting; and inclusion or exclusion of workload identities. The Protected Actions guidance explicitly states that protected actions require an authentication context added to a Conditional Access policy. The supplied evidence supports a documentation clarification, not a new Conditional"

  • The 23 September Temporary Access Pass update states that users on hybrid-joined devices must first authenticate with another method, such as a password, smartcard, or FIDO2 key, before using TAP to set up Windows Hello for Business. Administrators supporting hybrid-joined enrollment should ensure helpdesk and setup procedures follow this sequence; the entry does not describe a new TAP launch.

  • The updated Global Secure Access material says Netskope coexistence requires a Netskope Real-time Protection policy that allows Private Apps. Domain-controller scenarios require Windows 10 or later, an Entra-joined or hybrid-joined client, line of sight to the private resources and domain controller, and an identity created in Active Directory and synchronized through Entra Connect. Private name resolution sends an uncached DNS query to the GSA edge DNS proxy, while linking threat intelligence to the baseline####

  • Updated governance pages cover lifecycle workflow tasks, the Pre-Offboard inactive users template, workflow-version management, customizable workflow email message bodies, and delegated My Access approvals. The Access Review Agent guidance states that Microsoft Entra ID Governance or Microsoft Entra Suite licenses are required. These are workflow and licensing clarifications; the feed does not establish a new availability or licensing change.

For Entra administrators

Account for the Microsoft Entra AD Synchronization Service principal when reviewing Enterprise Applications and Microsoft Entra Connect dependencies. Update hybrid-joined Windows Hello for Business and Temporary Access Pass runbooks to follow the documented authentication sequence. For Conditional Access, Global Secure Access, and ID Governance deployments, use the explicit prerequisites in the updated guidance—authentication contexts for protected actions, private-resource and network conditions, and licensing for Access Review Agent. The documentation updates alone do not justify a broader rollout or policy change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

8

Protected Actions Add

Updated

Protected actions use a Conditional Access authentication context, so you must configure an authentication context and add it to a Conditional Access policy. If you already have a policy with an authentication context, you can skip to the next section.

27 September 2025

Conditional Access Grant

Updated

Admins can choose to enforce one or more controls when granting access. These controls include the following options:

24 September 2025
7

Entra Cloud Sync How To Install

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).

24 September 2025

Access Tokens

Updated

eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6Imk2bEdrM0ZaenhSY1ViMkMzbkVRN3N5SEpsWSJ9.eyJhdWQiOiI2ZTc0MTcyYi1iZTU2LTQ4NDMtOWZmNC1lNjZhMzliYjEyZTMiLCJpc3MiOiJodHRwczovL2xvZ2luLm1pY3Jvc29mdG9ubGluZS5jb20vNzJmOTg4YmYtODZmMS00MWFmLTkxYWItMmQ3Y2QwMTFkYjQ3L3YyLjAiLCJpYXQiOjE1MzcyMzEwNDgsIm5iZiI6MTUzNzIzMTA0OCwiZXhwIjoxNTM3MjM0OTQ4LCJhaW8iOiJBWFFBaS84SUFBQUF0QWFaTG8zQ2hNaWY2S09udHRSQjdlQnE0L0RjY1F6amNKR3hQWXkvQzNqRGFOR3hYZDZ3TklJVkdSZ2hOUm53SjFsT2NBbk5aY2p2a295ckZ4Q3R0djMzMTQwUmlvT0ZKNGJDQ0dWdW9DYWcxdU9UVDIyMjIyZ0h3TFBZUS91Zjc5UVgrMEtJaWpkcm1wNjlSY3R6bVE9PSIsImF6cCI6IjZlNzQxNzJiLWJlNTYtNDg0My05ZmY0LWU2NmEzOWJiMTJlMyIsImF6cGFjciI6IjAiLCJuYW1lIjoiQWJlIExpbmNvbG4iLCJvaWQiOiI2OTAyMjJiZS1mZjFhLTRkNTYtYWJkMS03ZTRmN2QzOGU0NzQiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJhYmVsaUBtaWNyb3NvZnQuY29tIiwicmgiOiJJIiwic2NwIjoiYWNjZXNzX2FzX3VzZXIiLCJzdWIiOiJIS1pwZmFIeVdhZGVPb3VZbGl0anJJLUtmZlRtMjIyWDVyclYzeERxZktRIiwidGlkIjoiNzJmOTg4YmYtODZmMS00MWFmLTkxYWItMmQ3Y2QwMTFkYjQ3IiwidXRpIjoiZnFpQnFYTFBqMGVRYTgyUy1JWUZBQSIsInZlciI6IjIuMCJ9.pj4N-w_3Us9DrBLfpCt

23 September 2025

Agent Optimization Review Suggestions

Updated

- Policy details are provided as both a list of all the details that are changing and a JSON view of the entire policy, with the changes highlighted.

23 September 2025
4

PowerShell

Updated

* Microsoft Entra Connect synchronizes identities from your on-premises directory

25 September 2025

Howto Authentication Temporary Access Pass

Updated

For hybrid-joined devices, users must first authenticate with another method such as a password, smartcard or FIDO2 key, before using TAP to set up Windows Hello for Business.

23 September 2025
2

Tokens Microsoft Entra Id

Updated

| Token Type | Issued by | Purpose | Scoped to Resource | Lifetime | Revocable | Renewable |

27 September 2025
1
1

Groups Dynamic Membership

Updated

You can create a group that contains all direct reports of a manager. When the manager's direct reports change in the future, the group's membership is adjusted automatically.

23 September 2025
5

Lifecycle Workflow Templates

Updated

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

23 September 2025
1

Access Review Agent

Updated

- You must have [Microsoft Entra ID Governance or Microsoft Entra Suite licenses](licensing-fundamentals.md).

27 September 2025
1
1
1

Hardening update to Microsoft Entra Connect Sync

Updated

As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `6bf85cfa-ac8a-4be5-b5de-425a0d0dc016`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.

26 September 2025
4

Private Name Resolution

Updated

1. User requests a DNS query for `app.contoso.com`. If not cached locally, the DNS query is sent to the DNS proxy at the GSA edge.

23 September 2025
2

Customize Block Page

Updated

1. Navigate to **Global Secure Access** > **Settings** > **Session management** > **Custom Block Page**

27 September 2025

Configure Domain Controllers

Updated

- The client machine is at least Windows 10 and is Microsoft Entra joined or hybrid joined device. The client machine must also have line of sight to the private resources and DC (user is in a corporate network and accessing on-premises resources). User identity used for joining the device and accessing these resources was created in Active Directory (AD) and synced to Microsoft Entra ID using Microsoft Entra Connect.

25 September 2025
2

Configure Threat Intelligence

Updated

Since threat intelligence is critical for users' basic security posture, you can alternatively link your threat intelligence policy to the baseline security profile, which applies policy to all users' traffic in your tenant.

24 September 2025

Netskope Coexistence

Updated

1. Create [Real-time Protection policy](https://docs.netskope.com/en/inline-policies/) to allow access to Private Apps.

24 September 2025