← Previous week
Next week →
Week in brief

Entra week: cross-cloud synchronization preview leads, while retirement guidance surfaces for Permissions Management and workload authentication

The most consequential product-level item for the week of 29 September is the 3 October Microsoft 365 Message Center notice for Microsoft Entra cross-cloud synchronization. The notice calls it public preview and opt-in, while listing general availability for late September–early October 2025; that is not an unqualified GA confirmation. The other meaningful signals are new offboarding guidance for an anticipated Microsoft Entra Permissions Management deprecation and updated Workload ID mitigation guidance for retiring service principal-less authentication. Much of the remaining supplied Learn activity is ordinary maintenance—especially a large Native Authentication API, CORS, Android, iOS/macOS, and SPA tutorial set with author- and manager-style summaries—so it should not be read as evidence of launches or changed tenant behavior.

  • The Message Center notice says the capability automates user lifecycle management across Microsoft commercial, US Government, and China clouds. It requires specific licenses and administrator enablement and supports configuration through the portal, PowerShell, and API. The notice separately lists late September–early October 2025 as the general-availability window, so the supplied evidence supports preview planning rather than a claim that GA is complete.

  • New Microsoft Entra Permissions Management content includes an explicit offboarding guide for an anticipated product deprecation. The same documentation set covers onboarding Azure, AWS, and GCP accounts or projects, alerts, analytics, remediation, controller and data-collection settings, user access management, and API settings. These are new documentation pages, not proof that the capabilities launched this week; no deprecation date or replacement is provided.

  • An updated Workload ID article specifically covers retiring service principal-less authentication and says tenant administrators should perform mitigation steps. The record does not state a retirement date, identify affected configurations, or announce an enforcement change, so the evidenced change is the availability of mitigation guidance rather than a dated service cutoff.

  • Related Learn updates state that policies created from Conditional Access templates are in report-only mode by default and should be tested and monitored before enablement. They also document enforcing Intune device compliance for Conditional Access-protected services, password changes for elevated user risk, and sign-in risk-based multifactor authentication. These are security and rollout guidance updates; the supplied records do not announce changed Conditional Access defaults or ID Protection behavior.

  • The updated Connect Pass-through Authentication quick start calls out Windows Server 2022, 2019, or 2016, TLS 1.2, placement in the same Active Directory forest as the users whose passwords are validated, and lack of support for the PTA agent on Windows Server Core. This is a documentation clarification for setup planning, not an announced installer rule or stated change to existing deployments.

For Entra administrators

For cross-cloud synchronization, assess whether the tenant needs user lifecycle management across Microsoft commercial, US Government, and China clouds, then check the notice’s specific licensing and administrator-enablement prerequisites; the supplied status is opt-in preview. Organizations using Permissions Management should review the offboarding guidance and plan for the anticipated deprecation, but no retirement date or replacement is supplied. Workload ID administrators should follow the documented mitigation steps if service principal-less authentication is relevant. For Conditional Access and Pass-through Authentication, use the updated report-only, test-and-monitor, and setup-prerequisite guidance without assuming that the underlying service behavior changed this week.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

186

Id Tokens

Updated

author: cilwerner

3 October 2025

Jwt Claims Customization

Updated

A Microsoft Entra documentation page was updated: Jwt Claims Customization.

3 October 2025

Teams Reader

Updated

Assign the Teams Reader role to users who need to do the following tasks:

2 October 2025

Dragon Administrator

Updated

Assign the Dragon Administrator role to users who need to do the following tasks:

2 October 2025

Whats New

Updated

| Date | Area | Description |

2 October 2025

Add Remove Role Task

Removed

A Microsoft Entra documentation page was updated: Add Remove Role Task.

2 October 2025

Add Remove User To Group

Removed

A Microsoft Entra documentation page was updated: Add Remove User To Group.

2 October 2025

Clone Role Policy

Removed

A Microsoft Entra documentation page was updated: Clone Role Policy.

2 October 2025

Configure Aws Iam

Removed

A Microsoft Entra documentation page was updated: Configure Aws Iam.

2 October 2025

Create Alert Trigger

Removed

A Microsoft Entra documentation page was updated: Create Alert Trigger.

2 October 2025

Create Custom Queries

Removed

A Microsoft Entra documentation page was updated: Create Custom Queries.

2 October 2025

Create Folders

Removed

A Microsoft Entra documentation page was updated: Create Folders.

2 October 2025

Create Role Policy

Removed

A Microsoft Entra documentation page was updated: Create Role Policy.

2 October 2025

Create Rule

Removed

A Microsoft Entra documentation page was updated: Create Rule.

2 October 2025

Delete Role Policy

Removed

A Microsoft Entra documentation page was updated: Delete Role Policy.

2 October 2025

Faqs

Removed

A Microsoft Entra documentation page was updated: Faqs.

2 October 2025

Modify Role Policy

Removed

A Microsoft Entra documentation page was updated: Modify Role Policy.

2 October 2025

Multi Cloud Glossary

Removed

A Microsoft Entra documentation page was updated: Multi Cloud Glossary.

2 October 2025

Onboard Aws

Removed

A Microsoft Entra documentation page was updated: Onboard Aws.

2 October 2025

Onboard Azure

Removed

A Microsoft Entra documentation page was updated: Onboard Azure.

2 October 2025

Onboard Enable Tenant

Removed

A Microsoft Entra documentation page was updated: Onboard Enable Tenant.

2 October 2025

Onboard Gcp

Removed

A Microsoft Entra documentation page was updated: Onboard Gcp.

2 October 2025

Partner List

Removed

A Microsoft Entra documentation page was updated: Partner List.

2 October 2025

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

2 October 2025

Product Account Explorer

Removed

A Microsoft Entra documentation page was updated: Product Account Explorer.

2 October 2025

Product Account Settings

Removed

A Microsoft Entra documentation page was updated: Product Account Settings.

2 October 2025

Product Dashboard

Removed

A Microsoft Entra documentation page was updated: Product Dashboard.

2 October 2025

Product Data Sources

Removed

A Microsoft Entra documentation page was updated: Product Data Sources.

2 October 2025

Recommendations Rule

Removed

A Microsoft Entra documentation page was updated: Recommendations Rule.

2 October 2025

Ui Autopilot

Removed

A Microsoft Entra documentation page was updated: Ui Autopilot.

2 October 2025

Ui Dashboard

Removed

A Microsoft Entra documentation page was updated: Ui Dashboard.

2 October 2025

Ui Tasks

Removed

A Microsoft Entra documentation page was updated: Ui Tasks.

2 October 2025

Ui Triggers

Removed

A Microsoft Entra documentation page was updated: Ui Triggers.

2 October 2025

Ui User Management

Removed

A Microsoft Entra documentation page was updated: Ui User Management.

2 October 2025

Usage Analytics Groups

Removed

A Microsoft Entra documentation page was updated: Usage Analytics Groups.

2 October 2025

Usage Analytics Home

Removed

A Microsoft Entra documentation page was updated: Usage Analytics Home.

2 October 2025

Usage Analytics Users

Removed

A Microsoft Entra documentation page was updated: Usage Analytics Users.

2 October 2025

View Role Policy

Removed

A Microsoft Entra documentation page was updated: View Role Policy.

2 October 2025

Prerequisites

Updated

- The Active Directory schema in the gMSA domain's forest needs to be updated to Windows Server 2012 or later.

30 September 2025

Prerequisites

Updated

|Requirement|Description and more requirements|

30 September 2025

Tutorial Basic Ad Azure

Updated

The following are prerequisites required for completing this tutorial

30 September 2025
38

Connect Pta Quick Start

Updated

1. Identify a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016 to run Microsoft Entra Connect. If not enabled already, [enable TLS 1.2 on the server](./how-to-connect-install-prerequisites.md#enable-tls-12-for-azure-ad-connect). Add the server to the same Active Directory forest as the users whose passwords you need to validate. It should be noted that installation of Pass-Through Authentication agent on Windows Server Core versions isn't supported.

30 September 2025

Howto Vm Sign In Azure Ad Windows

Updated

Sign in with the user account in a web browser. For instance, sign in to the [Azure portal](https://portal.azure.com) in a private browsing window. If you're prompted to change the password, set a new password. Then try connecting again.

29 September 2025
26

Sla Performance

Updated

| June | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |

4 October 2025

All Reports

Removed

A Microsoft Entra documentation page was updated: All Reports.

2 October 2025

Audit Trail Results

Removed

A Microsoft Entra documentation page was updated: Audit Trail Results.

2 October 2025

Product Audit Trail

Removed

A Microsoft Entra documentation page was updated: Product Audit Trail.

2 October 2025

Product Reports

Removed

A Microsoft Entra documentation page was updated: Product Reports.

2 October 2025

Ui Audit Trail

Removed

A Microsoft Entra documentation page was updated: Ui Audit Trail.

2 October 2025
25

Purpose:

Updated

manager: pmwongera

3 October 2025

Error Codes Onboarding

Removed

A Microsoft Entra documentation page was updated: Error Codes Onboarding.

2 October 2025

Troubleshoot

Removed

A Microsoft Entra documentation page was updated: Troubleshoot.

2 October 2025

Ui Remediation

Removed

A Microsoft Entra documentation page was updated: Ui Remediation.

2 October 2025

Error Codes

Updated

| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |

30 September 2025
14

Integration Api

Removed

A Microsoft Entra documentation page was updated: Integration Api.

2 October 2025
6

Overview

Removed

A Microsoft Entra documentation page was updated: Overview.

2 October 2025
3

Plan Conditional Access

Updated

Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.

3 October 2025

Require device compliance with Conditional Access

Updated

Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.

2 October 2025
3

Certificate Credentials

Updated

A Microsoft Entra documentation page was updated: Certificate Credentials.

3 October 2025
2

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

3 October 2025
1
1
1

Connect Install Prerequisites

Updated

- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.

30 September 2025
1

How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain

Updated

Objects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.

2 October 2025
1
2
1

Source Ip Restoration

Updated

- [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks) get a consistent view of original user Source IP address for assessing various risk scores.

1 October 2025
1

Howto Export Risk Data

Updated

Access more queries and visual insights based on AADUserRiskEvents and AADRisky Users logs in the [Impact analysis of risk-based access policies workbook](workbook-risk-based-policy-impact.md).

1 October 2025
1

Microsoft Entra: Cross-cloud synchronization now available

New

Microsoft Entra's cross-cloud synchronization, in public preview and opt-in, automates user lifecycle management across Microsoft commercial, US Government, and China clouds. General availability is late September to early October 2025. It requires specific licenses, admin enablement, and supports configuration via portal, PowerShell, and API.

3 October 2025
Message CenterMC1124558 on mc.merill.net ↗Stay informed
5

Planning Your Solution

Updated

- [Start a free trial](https://aka.ms/ciam-free-trial?wt.mc_id=ciamcustomertenantfreetrial_linkclick_content_cnl) or [create your external tenant](how-to-create-external-tenant-portal.md).

3 October 2025

B2b Guest Access

Updated

To enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:

2 October 2025

Azure Monitor

Updated

TThe external tenant uses [Microsoft Entra monitoring](/entra/identity/monitoring-health/overview-monitoring-health). Unlike Microsoft Entra tenants, an external tenant can't have a subscription associated with it. So, we need to take extra steps to enable the integration between external tenant and Log Analytics, which is where we send the logs.

1 October 2025
1

Azure Monitor

Updated

During this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.

2 October 2025
1

External ID in workforce tenants

Updated

- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available

2 October 2025
1
1
1
1

Export Connector Logs

Updated

1. Download the Azure Arc agent setup script from the Azure portal.

1 October 2025