← Previous day

Next day →
Day in brief

24 May 2025: TLS inspection preview, PIM-for-Groups access packages, and Identity Protection guidance are the clearest admin signals

This was primarily a documentation-maintenance day: 66 items were updated, none were marked new, one was removed, and no Message Center changes were supplied. The strongest updates provide specific preview, security, governance, and configuration guidance rather than evidence of feature launches or general availability. The supplied representative changes do not identify the removed item, so no retirement conclusion is supported.

  • The updated Microsoft Entra Internet Access page describes TLS inspection as decrypting and inspecting encrypted traffic at service-edge locations, allowing Global Secure Access to apply threat detection, content filtering, and granular access policies. Because the page is explicitly labeled Preview and the change is marked Updated, this supports a preview-guidance classification only—not a general-availability or tenant-wide behavior announcement.

  • The updated procedure explains that an access package manager can assign a group role, enable Privileged Identity Management for the group, add the group to an access package, and verify that eligible assignments are available. It frames group membership or ownership as just-in-time access. The evidence is procedural guidance and does not establish a new feature or availability change on 24 May.

  • The updated Identity Protection guidance states that when user remediation is not enabled, an administrator must manually review risks in the portal, through the API, or in Microsoft Defender XDR. The documented actions are to dismiss the risk, confirm the user is safe, or confirm compromise. This is a security-operations and behavior clarification, not evidence that the remediation model changed.

  • For passwordless security-key and on-premises Kerberos configuration, the updated guidance says Set-AzureADKerberosServer defaults to Commercial cloud endpoints. Administrators configuring another cloud environment need to set the cmdlet to use the specified cloud. This is a concrete multi-cloud configuration clarification, not a new passwordless capability.

  • The updated Microsoft Entra External ID deployment guide covers edge protection, domains, subscriptions, consumer-app security, and fraud tactics. It is security guidance for operating external or customer-facing applications; the supplied evidence names no newly required control, product launch, or availability change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

67 updates

16

Msal Migration

Updated

A Microsoft Entra documentation page was updated: Msal Migration.

Msal Js Sso

Updated

A Microsoft Entra documentation page was updated: Msal Js Sso.

Msal Logging Js

Updated

A Microsoft Entra documentation page was updated: Msal Logging Js.

Msal Overview

Updated

A Microsoft Entra documentation page was updated: Msal Overview.

11

Apple Sso Plugin

Updated

A Microsoft Entra documentation page was updated: Apple Sso Plugin.

Quickstart V2 Ios

Updated

A Microsoft Entra documentation page was updated: Quickstart V2 Ios.

V2 Libraries

Updated

A Microsoft Entra documentation page was updated: V2 Libraries.

8

Add Redirect Uri

Updated

The Microsoft identity platform supports authentication for modern application types such as web applications, single-page applications (SPA) and mobile and desktop apps. Once you register your app in the Microsoft Entra admin center, you need to specify the app type by configuring an app platform along with other authentication settings specific to each platform.

App Sign In Flow

Updated

A Microsoft Entra documentation page was updated: App Sign In Flow.

3
2
2

Application Model

Updated

A Microsoft Entra documentation page was updated: Application Model.

2
1
1
2
1

Identity Protection

Updated

When user remediation isn't enabled, an admin must manually review them in the reports in the portal, through the API, or in Microsoft Defender XDR. Admins can perform manual actions to dismiss, confirm safe, or confirm compromise on the risks.

1

Assign eligible group membership and ownership in access packages via PIM for Groups

Updated

As an access package manager, you can assign which role you want to provide a user for a group within an access package. By [managing groups with Privileged Identity Management](../id-governance/privileged-identity-management/groups-discover-groups.md), you're able to enhance security by designating that group access happens just-in-time. This article describes how to enable pim for a group, adding the group to an access package, and verifying eligible assignments are available.

4

Identity Providers

Updated

- **Google**: Google federation allows external users to redeem invitations from you by signing in to your apps with their own Gmail accounts. Google federation can also be used in your self-service sign-up user flows. See how to [add Google as an identity provider](google-federation.md).

Redemption Experience

Updated

When you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) that’s initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.

3

External Identities Overview

Updated

Azure Active Directory B2C (Azure AD B2C) is Microsoft's legacy solution for customer identity and access management. Azure AD B2C includes a separate consumer-based directory that you manage in the Azure portal through the Azure AD B2C service. Each Azure AD B2C tenant is separate and distinct from other Microsoft Entra ID and Azure AD B2C tenants. The Azure AD B2C portal experience is similar to Microsoft Entra ID, but there are key differences, such as the ability to customize your user journeys using the Identity Experience Framework.

Planning Your Solution

Updated

When you create an external tenant, you can set your correct geographic location and your domain name. If you currently use Azure AD B2C, the new workforce and external tenant model doesn't affect your existing Azure AD B2C tenants.

Scenario Azure First Sap Identity Integration

Updated

[Azure Active Directory B2C](/azure/active-directory-b2c/overview) provides business-to-customer identity as a service. Given that the integration with Azure AD B2C is similar to how you would allow enterprise users to sign in with Microsoft Entra ID, the recommendations above still mostly apply when you want to use Azure AD B2C for your customers, consumers or citizens and allow them to use their preferred social, enterprise, or local account identities.

2

Faq Customers

Updated

External ID supports server-side integrations with external systems via [custom authentication extensions](~/identity-platform/custom-extension-overview.md). This capability allows developers to implement their own logic and invoke it via real-time API calls during sign-in/up flows.

1
1
1

Gsa Poc Guidance Intro

Updated

- **Do you need to override broad block or allow policies for certain users or specific circumstances?** If you want to allow specific users or groups to access a blocked website, consider testing the [Allow a user to access a blocked website](gsa-poc-internet-access.md#allow-a-user-to-access-a-blocked-website) use case.

1

Gsa Poc Internet Access

Updated

1. View activity in the [traffic log](../global-secure-access/how-to-view-traffic-logs.md) to confirm that Global Secure Access enabled access. Verify in the sign-in logs that **Through Global Secure Access** shows as **Yes**.

1

Configure Transport Layer Security inspection (Preview)

Updated

Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access enables decryption and inspection of encrypted traffic at service edge locations. This capability lets Global Secure Access apply advanced security controls like threat detection, content filtering, and granular access policies. Organizations use these access policies to protect against threats that might be hidden in encrypted communications.

1
1

Version History

Updated

| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…