Mfa Number Match Preview
RemovedA Microsoft Entra documentation page was updated: Mfa Number Match Preview.
Daily.Entra.NewsThe period was chiefly documentation maintenance: no new documentation entries were recorded, while 28 were updated and one was removed. The two Microsoft 365 Message Center notices carry the clearest product-level implications: a November preview of passkey profiles in the Microsoft Entra ID authentication methods policy and a staged rollout of soft deletion and restoration for cloud security groups. Other notable entries are documentation clarifications or procedures for preview and integration scenarios, not evidence of new launches. The removed Mfa Number Match Preview page, alongside an updated article on same-device number matching, does not by itself establish that the Authenticator capability was retired.
A 6 November Message Center major update says Microsoft Entra ID will preview passkey profiles in November 2025. The capability enables group-based passkey controls and introduces a new API schema. The notice describes worldwide rollout in early November and GCC rollout in mid-November. No preparation is required before rollout, although administrators should review existing configurations and update internal documentation.
A 6 November Message Center notice describes recovery of deleted cloud security groups within 30 days while preserving settings, ownership, and membership. Deleted groups remove access until they are restored, and audit logs track the actions. The notice places the preview rollout in late October 2025 and general availability in February 2026, so this is a preview-to-GA rollout rather than a GA change during the supplied week.
Updates on 6 and 7 November state that guest-user governance requires a tenant linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. They also document that, when the guest billing meter is not enabled, new access reviews scoped to guest users cannot be created when any of the specified features is selected. The supplied evidence presents this as clarified guidance, not as an announced new licensing-policy change.
An 8 November update explains how to enable Intelligent Local Access for Microsoft Entra Private Access. The preview capability is described as optimizing traffic flow for clients accessing Entra apps through private networks. Because the record is an updated enablement guide and provides no rollout or GA date, it should not be treated as a new launch this week.
A 6 November External ID security article documents integration with Arkose Labs and HUMAN Security. Its supplied procedure specifically says Arkose Labs can be configured through the Security Store wizard in the Microsoft Entra admin center to create a fraud protection provider policy. The evidence establishes setup guidance, but not a new provider launch or availability milestone.
The passkey notice explicitly says no action is needed before rollout, but asks administrators to review configurations and update documentation. For cloud security groups, deletion removes access until restoration, and the recovery window is 30 days; audit logs record the related actions. Guest-governance tenants must account for the stated Azure subscription, add-on, and billing-meter conditions. The Private Access and External ID items provide enablement or integration guidance, with no supplied GA or rollout announcement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A Microsoft Entra documentation page was updated: Mfa Number Match Preview.
author: justinha
Learn about improvemenst to number matching in for Microsoft Authenticator.
- [Deploy Conditional Access policy to target privileged accounts and require phishing resistant credentials using authentication strengths](/entra/identity/conditional-access/policy-admin-phish-resistant-mfa)
Manually checking this guidance against a tenant's configuration can be time-consuming and error-prone. The Zero Trust Assessment transforms this process with automation to test for these security configuration items and more. Learn more in [What is the Zero Trust Assessment?](/security/zero-trust/assessment/overview)
A Microsoft Entra documentation page was updated: Customer intent: As a cloud administrator, I want to understand how Microsoft Entra ID handles data residency, so that I can ensure compliance with data residency requirements and make informed decisions about storing and managing identity and access data in the cloud..
author: justinha
|---|---|
> [!IMPORTANT]
Assign the Exchange Backup Administrator role to users who need to do the following tasks:
Assign the SharePoint Backup Administrator role to users who need to do the following tasks:
| Date | Area | Description |
author: cilwerner
| Requirement | Description |
Microsoft Entra introduces soft deletion and restoration for cloud security groups, allowing recovery within 30 days while preserving settings, ownership, and membership. Rollout begins in late October 2025 (preview) and February 2026 (general availability). Deleted groups remove access until restored; audit logs track actions.
In November 2025, Microsoft Entra ID will preview passkey profiles in the authentication methods policy, enabling group-based passkey controls and new API schema. Rollout occurs worldwide early November and GCC mid-November. No admin action is needed before rollout; admins should review configurations and update documentation.
A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.
- You won't be able to create new access reviews scoped to guest users if any of the following features are selected:
To use Microsoft Entra ID Governance features for guest users, your tenant must be linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. If the guest billing meter isn't enabled, the following behavior applies:
A Microsoft Entra documentation page was updated: Create External Tenant Portal.
> If you select **Review** before adding settings, the **Subscription** and **Resource group** appear on the right-hand side. These fields are read-only. To make changes, remove the existing service provider information and restart the wizard.
To integrate Arkose Labs with Microsoft Entra External ID, you can use the Security Store wizard in Microsoft Entra admin center to create a fraud protection provider policy.
Known limitations for Internet Access include:
Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
author: barclayn
This article lists the latest features, improvements, and changes in the Microsoft Entra Verified ID service.
| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |
|AES256-SHA |
manager: sineado
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).