Configure Security
Updated| Check | Minimum required license |
Daily.Entra.NewsThe week of 6 October 2025 contains 51 recorded Microsoft Learn changes: 49 updates, one new item, one removal, and no Message Center entries. The clearest product-status signals are two explicitly preview topics: Microsoft Entra External ID integrations with Arkose Labs and HUMAN Security for sign-up fraud protection, and Continuous Access Evaluation for Application Proxy under Global Secure Access. Other meaningful updates provide security-response guidance for ID Protection, Source of Authority planning for AD DS dependencies, and coexistence and DNS deployment guidance. No supplied evidence establishes a general-availability release or a changed tenant default. The new passkey item lacks enough detail to confirm a product rollout.
Updated Identity Protection risk guidance describes a detection associated with a malicious reverse proxy that can intercept credentials and issued tokens. When triggered, the user is raised to High risk and administrators are told to investigate manually; clearing the risk may require a secure password reset or revocation of existing sessions. Related guidance recommends adding corporate VPNs and IP ranges to Conditional Access named locations to reduce false positives. This clarifies response guidance rather than
Updated External ID security documentation covers configuring Arkose Labs and HUMAN Security to block bot attacks and fake account creation during customer sign-up, and the page title explicitly marks the integration as preview. A separate authentication update explains that the domain_hint parameter can send users directly to Facebook, Google, Apple, custom OIDC, or SAML identity providers instead of first displaying the Microsoft sign-in page. No general-availability status is supplied.
Updates across the Source of Authority overview and preparation material describe converting group Source of Authority to Microsoft Entra ID, deleting AD DS groups that are no longer needed, or provisioning security-group changes from Entra ID back to AD DS. Architecture guidance specifically calls out LDAP applications that bind to or query AD and applications that prompt for AD credentials. This is planning guidance, not evidence of a newly announced conversion capability.
The updated Global Secure Access material includes Continuous Access Evaluation for Application Proxy, explicitly marked preview. Related coexistence guidance covers Palo Alto, Netskope, Zscaler, and Cisco scenarios. In the Cisco Private Access scenario, the instructions say to add DNS suffixes from Private DNS or Enterprise App segments when the Private Access traffic-forwarding profile is enabled; the Zscaler scenario separates private-application handling from internet traffic. These are deployment guidance and,
The only new record is an Entra ID Authentication entry titled Passkey authentication method enabled; a separate What's New update contains the label Type: New feature. The supplied material provides no capability description, prerequisites, tenant configuration, or preview or general-availability marker. The page addition alone therefore should not be treated as proof that passkeys were newly enabled for tenants or reached general availability.
Treat this as a targeted documentation review rather than a broad change window. For ID Protection, the updated guidance says an Adversary-in-the-Middle detection raises the user to High risk and may require manual investigation, a secure password reset, or revocation of existing sessions; named locations can include corporate VPNs and IP ranges to reduce false positives. Administrators planning Source of Authority conversion should check LDAP, AD bind/query, and AD-credential dependencies first. Organizations using Cisco coexistence with Private Access should review the DNS-suffix requirement when the Private Access traffic-forwarding profile is enabled. External ID fraud protection remains preview material in the supplied evidence. Conditional Access edits about deleting unused disabled4
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
| Check | Minimum required license |
A Microsoft Entra documentation page was updated: Zero Trust Protect Identities.
A Microsoft Entra documentation page was updated: Zero Trust Protect Engineering Systems.
A Microsoft Entra documentation page was updated: Zero Trust Protect Tenants.
One AD DS minimization approach is to convert the Group Source of Authority (SOA) to Microsoft Entra ID. This approach lets you directly manage those groups in the cloud. You can delete AD DS groups that you no longer need on-premises. If you need to keep a group on-premises, you can configure security group provisioning from Microsoft Entra ID to AD DS. Then you can make changes to the group in Microsoft Entra ID and have those changes reflected in the on-premises group.
**Type:** New feature
Some IP addresses can't be mapped to a specific country or region. To capture these IP locations, select the box **Include unknown countries/regions** when defining a geographic location. This option allows you to choose if these IP addresses should be included in the named location. Use this setting when the policy using the named location should apply to unknown locations.
author: MicrosoftGuyJFlo
author: omondiatieno
|Method|Description|URL|
>
A Microsoft Entra documentation page was updated: 21822.
- Make sure that you satisfy the [requirements](how-to-connect-health-agent-install.md#requirements) to install Microsoft Entra Connect Health.
Once you identify the employees for SOA conversion, follow these steps:
:::image type="content" source="media/how-to-user-source-of-authority-configure/try-update.png" alt-text="Screenshot of an attempt to update a user to verify it's read-only.":::
Without Local Admin Password Solution (LAPS) deployed, threat actors exploit static local administrator passwords to establish initial access. After threat actors compromise a single device with a shared local administrator credential, they can move laterally across the environment and authenticate to other systems sharing the same password. Compromised local administrator access gives threat actors system-level privileges, letting them disable security controls, install persistent backdoors, exfiltrate sensitive data, and establish command and control channels.
author: MicrosoftGuyJFlo
For feature feedback, vote at [Connect Health User Voice channel](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789)
- **LDAP Authentication/Queries** – Applications can have LDAP server settings pointing to AD and perform binds or lookups, custom-developed or third-party products prompting users for AD credentials.
|Edge browser with profile login | ✅ |
> | Create terms of use | [Conditional Access Administrator](permissions-reference.md#conditional-access-administrator) | [Security Administrator](permissions-reference.md#security-administrator) |
- If a policy is disabled and no longer needed, **delete it**.
ai-usage: ai-assisted
"members": []
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
9. There are two possible approaches to set the OU:
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
**Remediation action**
Also referred to as Adversary in the Middle, this high precision detection is triggered when an authentication session is linked to a malicious reverse proxy. In this kind of attack, the adversary can intercept the user's credentials, including tokens issued to the user. The Microsoft Security Research team uses Microsoft Defender for Cloud Apps to capture the identified risk and raises the user to **High** risk. We recommend administrators manually investigate the user when this detection is triggered to ensure the risk is cleared. Clearing this risk might require secure password reset or revocation of existing sessions.
- Add corporate VPNs and IP address ranges to [named locations](../identity/conditional-access/concept-assignment-network.md) in your Conditional Access policies to reduce false positives.
The following table shows the licensing requirements for Microsoft Entra ID Governance features for member users. Microsoft Entra Suite includes all features of Microsoft Entra ID Governance. Licensing information and example license scenarios for Entitlement management, Access reviews, and Lifecycle Workflows are provided following the table.
| [Genesys Cloud for Azure](../identity/saas-apps/purecloud-by-genesys-provisioning-tutorial.md) | ● | ● |
1. Sign in to the My Access portal at [https://myaccess.microsoft.com](https://myaccess.microsoft.com) as the direct manager of the team who you want to manage access package assignments for. For US Government, the domain in the My Access portal link is `myaccess.microsoft.us`.
- Admins who interact with Conditional Access need one of the following role assignments, depending on the tasks they're performing. To follow the [Zero Trust principle of least privilege](/security/zero-trust/), consider using [Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) to activate privileged role assignments just in time.
- **Free** - Included with Microsoft cloud subscriptions such as Microsoft Azure, Microsoft 365, and others.
> [!TIP]
> [!TIP]
A Microsoft Entra documentation page was updated: Integrate Microsoft Entra External ID with Arkose Labs and HUMAN Security for fraud protection (preview).
Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.
When you use identity providers such as Facebook, Google, Apple, custom OIDC, or SAML, users usually see the Microsoft sign-in page first. From there, they choose their identity provider. To simplify this experience, you can use the `domain_hint` parameter in the sign-in URL. This parameter lets you skip the Microsoft sign-in page and go directly to the selected identity provider’s sign-in page.
This article describes how to register your own SAML application in your external tenant by creating a *non-gallery* app in **Enterprise applications**.
In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
To configure Microsoft Entra Private Access for Active Directory Domain Controllers, you must have the following:
5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.
Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
manager: dougeby
There are two scenarios that are applicable to Global Secure Access in China:
manager: dougeby