Week in brief

Entra ID backup authentication guidance clarifies CRL revocation limits; most other updates are procedural

The week of 20 October 2025 is a documentation-only period in the supplied data: 20 Microsoft Learn records were updated, with no new or removed items and no Message Center notices. The most consequential update is an Entra ID resilience and security clarification: the backup authentication system cannot perform a fresh certificate revocation list (CRL) check and instead uses the CRL state from the last backed-up session. Other substantive updates describe ID Governance workflows and a Workday provisioning setting. The evidence does not establish any launch, preview, general availability, retirement, or underlying service-behavior change.

  • The updated Entra ID architecture guidance says the backup authentication system cannot perform fresh CRL checks. It relies on the CRL result recorded when the session was last backed up; when revocation is needed before that backup expires, administrators should explicitly revoke the session. This is security guidance describing the documented fallback behavior, not evidence that the service behavior changed.

  • The ID Governance article describes an Access Review Agent that gathers insights, generates recommendations, and guides reviewers in Microsoft Teams with natural-language summaries and proposed decisions. Reviewers still make the final call. The supplied update provides capability documentation but gives no preview, general availability, or rollout information.

  • The updated ID Governance guidance covers creating a custom extension backed by an Azure Logic App, assigning its system-assigned identity a role in the catalog, editing the Logic App action to perform the business logic, and testing the workflow. This is implementation guidance; the record does not indicate a newly released capability or changed availability.

  • The Entra ID provisioning article specifically instructs administrators to enable the Termination Lookahead query for a Workday-to-AD or Workday-to-Microsoft Entra ID provisioning job. The evidence supports treating this as integration configuration guidance rather than a new provisioning-feature announcement.

For Entra administrators

If a session must be revoked before the backup expires, the documented action is to explicitly revoke the session rather than wait for a fresh CRL check. Administrators configuring Workday provisioning or entitlement-management dynamic approval can use the specific procedure updates, while the Access Review Agent article should not be treated as evidence of a tenant-wide rollout or availability status. Several remaining edits are ordinary documentation clarification, including External ID sign-in screenshots, a Conditional Access Save-button step, Global Secure Access sign-in and script instructions, and author, include-file, or checklist changes.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Architecture

4

Backup Authentication System

Updated

To enhance its resilience posture, the backup authentication system can't perform fresh revocation checks. Instead, it relies on the state of the certificate revocation list (CRL) check that's performed when the session was last backed up. If you need to revoke before this backup expires, you should explicitly revoke the session instead of waiting for the CRL.

25 October 2025

General

3

Assign User Or Group Access Portal

Updated

To assign a group to an enterprise app, replace `Get-EntraUser` with `Get-EntraGroup` and replace `New-EntraUserAppRoleAssignment` with `New-EntraGroupAppRoleAssignment`.

25 October 2025

Conditional Access

2

Fundamentals

2

What Is Application Management

Updated

There are several ways that you might manage applications in Microsoft Entra ID. The easiest way to start managing an application is to use a preintegrated application from the Microsoft Entra gallery, for both SaaS and on-premises or private cloud hosted applications. Developing your own application and registering it in Microsoft Entra ID is an option.

25 October 2025

Whats New Archive

Updated

A Microsoft Entra documentation page was updated: Whats New Archive.

22 October 2025

Developer

1

Plan An Application Integration

Updated

Before integrating applications with Microsoft Entra ID, it's important to know where you are and where you want to go. The following questions are intended to help you think about your Microsoft Entra application integration project.

25 October 2025

Monitoring

1

Provisioning

1

Governance

3

Entitlement Management Dynamic Approval

Updated

This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.

22 October 2025

Access Review Agent

Updated

Say goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.

22 October 2025

Branding

1

Authentication Methods Customers

Updated

The following screenshots show the sign-in with Google experience. In the sign-in page, users select **Sign-in with Google**. At that point, the user is redirected to the Google identity provider to complete the sign-in.

23 October 2025

General

1

Monitoring

1