Week in brief

External ID fraud protection and Application Proxy CAE previews lead a documentation-heavy Entra week

The week of 6 October 2025 contains 51 recorded Microsoft Learn changes: 49 updates, one new item, one removal, and no Message Center entries. The clearest product-status signals are two explicitly preview topics: Microsoft Entra External ID integrations with Arkose Labs and HUMAN Security for sign-up fraud protection, and Continuous Access Evaluation for Application Proxy under Global Secure Access. Other meaningful updates provide security-response guidance for ID Protection, Source of Authority planning for AD DS dependencies, and coexistence and DNS deployment guidance. No supplied evidence establishes a general-availability release or a changed tenant default. The new passkey item lacks enough detail to confirm a product rollout.

  • Updated Identity Protection risk guidance describes a detection associated with a malicious reverse proxy that can intercept credentials and issued tokens. When triggered, the user is raised to High risk and administrators are told to investigate manually; clearing the risk may require a secure password reset or revocation of existing sessions. Related guidance recommends adding corporate VPNs and IP ranges to Conditional Access named locations to reduce false positives. This clarifies response guidance rather than

  • Updated External ID security documentation covers configuring Arkose Labs and HUMAN Security to block bot attacks and fake account creation during customer sign-up, and the page title explicitly marks the integration as preview. A separate authentication update explains that the domain_hint parameter can send users directly to Facebook, Google, Apple, custom OIDC, or SAML identity providers instead of first displaying the Microsoft sign-in page. No general-availability status is supplied.

  • Updates across the Source of Authority overview and preparation material describe converting group Source of Authority to Microsoft Entra ID, deleting AD DS groups that are no longer needed, or provisioning security-group changes from Entra ID back to AD DS. Architecture guidance specifically calls out LDAP applications that bind to or query AD and applications that prompt for AD credentials. This is planning guidance, not evidence of a newly announced conversion capability.

  • The updated Global Secure Access material includes Continuous Access Evaluation for Application Proxy, explicitly marked preview. Related coexistence guidance covers Palo Alto, Netskope, Zscaler, and Cisco scenarios. In the Cisco Private Access scenario, the instructions say to add DNS suffixes from Private DNS or Enterprise App segments when the Private Access traffic-forwarding profile is enabled; the Zscaler scenario separates private-application handling from internet traffic. These are deployment guidance and,

  • The only new record is an Entra ID Authentication entry titled Passkey authentication method enabled; a separate What's New update contains the label Type: New feature. The supplied material provides no capability description, prerequisites, tenant configuration, or preview or general-availability marker. The page addition alone therefore should not be treated as proof that passkeys were newly enabled for tenants or reached general availability.

For Entra administrators

Treat this as a targeted documentation review rather than a broad change window. For ID Protection, the updated guidance says an Adversary-in-the-Middle detection raises the user to High risk and may require manual investigation, a secure password reset, or revocation of existing sessions; named locations can include corporate VPNs and IP ranges to reduce false positives. Administrators planning Source of Authority conversion should check LDAP, AD bind/query, and AD-credential dependencies first. Organizations using Cisco coexistence with Private Access should review the DNS-suffix requirement when the Private Access traffic-forwarding profile is enabled. External ID fraud protection remains preview material in the supplied evidence. Conditional Access edits about deleting unused disabled4

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

8

Source Of Authority Overview

Updated

One AD DS minimization approach is to convert the Group Source of Authority (SOA) to Microsoft Entra ID. This approach lets you directly manage those groups in the cloud. You can delete AD DS groups that you no longer need on-premises. If you need to keep a group on-premises, you can configure security group provisioning from Microsoft Entra ID to AD DS. Then you can make changes to the group in Microsoft Entra ID and have those changes reflected in the on-premises group.

7 October 2025

Whats New

Updated

**Type:** New feature

7 October 2025

Assignment Network

Updated

Some IP addresses can't be mapped to a specific country or region. To capture these IP locations, select the box **Include unknown countries/regions** when defining a geographic location. This option allows you to choose if these IP addresses should be included in the named location. Use this setting when the policy using the named location should apply to unknown locations.

7 October 2025
8

21822

Removed

A Microsoft Entra documentation page was updated: 21822.

11 October 2025

Connect Health Agent Install

Updated

- Make sure that you satisfy the [requirements](how-to-connect-health-agent-install.md#requirements) to install Microsoft Entra Connect Health.

8 October 2025

User Source Of Authority Configure

Updated

:::image type="content" source="media/how-to-user-source-of-authority-configure/try-update.png" alt-text="Screenshot of an attempt to update a user to verify it's read-only.":::

7 October 2025
5

21953

Updated

Without Local Admin Password Solution (LAPS) deployed, threat actors exploit static local administrator passwords to establish initial access. After threat actors compromise a single device with a shared local administrator credential, they can move laterally across the environment and authenticate to other systems sharing the same password. Compromised local administrator access gives threat actors system-level privileges, letting them disable security controls, install persistent backdoors, exfiltrate sensitive data, and establish command and control channels.

11 October 2025

Connect Health Version History

Updated

For feature feedback, vote at [Connect Health User Voice channel](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789)

8 October 2025

Guidance It Architects Source Of Authority

Updated

- **LDAP Authentication/Queries** – Applications can have LDAP server settings pointing to AD and perform binds or lookups, custom-developed or third-party products prompting users for AD credentials.

7 October 2025
2

Delegate By Task

Updated

> | Create terms of use | [Conditional Access Administrator](permissions-reference.md#conditional-access-administrator) | [Security Administrator](permissions-reference.md#security-administrator) |

8 October 2025
2
1
1
1
1

21837

Updated

**Remediation action**

11 October 2025
1

Identity Protection Risks

Updated

Also referred to as Adversary in the Middle, this high precision detection is triggered when an authentication session is linked to a malicious reverse proxy. In this kind of attack, the adversary can intercept the user's credentials, including tokens issued to the user. The Microsoft Security Research team uses Microsoft Defender for Cloud Apps to capture the identified risk and raises the user to **High** risk. We recommend administrators manually investigate the user when this detection is triggered to ensure the risk is cleared. Clearing this risk might require secure password reset or revocation of existing sessions.

8 October 2025
1

Howto Identity Protection Investigate Risk

Updated

- Add corporate VPNs and IP address ranges to [named locations](../identity/conditional-access/concept-assignment-network.md) in your Conditional Access policies to reduce false positives.

8 October 2025
3

Licensing Governance

Updated

The following table shows the licensing requirements for Microsoft Entra ID Governance features for member users. Microsoft Entra Suite includes all features of Microsoft Entra ID Governance. Licensing information and example license scenarios for Entitlement management, Access reviews, and Lifecycle Workflows are provided following the table.

10 October 2025

Apps

Updated

| [Genesys Cloud for Azure](../identity/saas-apps/purecloud-by-genesys-provisioning-tutorial.md) | ● | ● |

10 October 2025

Entitlement Management Request Behalf

Updated

1. Sign in to the My Access portal at [https://myaccess.microsoft.com](https://myaccess.microsoft.com) as the direct manager of the team who you want to manage access package assignments for. For US Government, the domain in the My Access portal link is `myaccess.microsoft.us`.

8 October 2025
1

Plan Conditional Access

Updated

- Admins who interact with Conditional Access need one of the following role assignments, depending on the tasks they're performing. To follow the [Zero Trust principle of least privilege](/security/zero-trust/), consider using [Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) to activate privileged role assignments just in time.

8 October 2025
1

Licensing Fundamentals

Updated

- **Free** - Included with Microsoft cloud subscriptions such as Microsoft Azure, Microsoft 365, and others.

10 October 2025
2
2

Fraud Protection Integration

Updated

Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.

8 October 2025
1

Authentication Methods Customers

Updated

When you use identity providers such as Facebook, Google, Apple, custom OIDC, or SAML, users usually see the Microsoft sign-in page first. From there, they choose their identity provider. To simplify this experience, you can use the `domain_hint` parameter in the sign-in URL. This parameter lets you skip the Microsoft sign-in page and go directly to the selected identity provider’s sign-in page.

9 October 2025
1

Register Saml App

Updated

This article describes how to register your own SAML application in your external tenant by creating a *non-gallery* app in **Enterprise applications**.

8 October 2025
1

Zscaler Coexistence

Updated

In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.

8 October 2025
1

Cisco Vpn Coexistence

Updated

1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**

8 October 2025
1

Netskope Coexistence

Updated

This guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.

8 October 2025
2

Configure Domain Controllers

Updated

To configure Microsoft Entra Private Access for Active Directory Domain Controllers, you must have the following:

9 October 2025

Cisco Coexistence

Updated

5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.

8 October 2025
2
2

China User Support

Updated

There are two scenarios that are applicable to Global Secure Access in China:

10 October 2025