Msal Migration
UpdatedA Microsoft Entra documentation page was updated: Msal Migration.
Daily.Entra.NewsThis was primarily a documentation-maintenance day: 66 items were updated, none were marked new, one was removed, and no Message Center changes were supplied. The strongest updates provide specific preview, security, governance, and configuration guidance rather than evidence of feature launches or general availability. The supplied representative changes do not identify the removed item, so no retirement conclusion is supported.
The updated Microsoft Entra Internet Access page describes TLS inspection as decrypting and inspecting encrypted traffic at service-edge locations, allowing Global Secure Access to apply threat detection, content filtering, and granular access policies. Because the page is explicitly labeled Preview and the change is marked Updated, this supports a preview-guidance classification only—not a general-availability or tenant-wide behavior announcement.
The updated procedure explains that an access package manager can assign a group role, enable Privileged Identity Management for the group, add the group to an access package, and verify that eligible assignments are available. It frames group membership or ownership as just-in-time access. The evidence is procedural guidance and does not establish a new feature or availability change on 24 May.
The updated Identity Protection guidance states that when user remediation is not enabled, an administrator must manually review risks in the portal, through the API, or in Microsoft Defender XDR. The documented actions are to dismiss the risk, confirm the user is safe, or confirm compromise. This is a security-operations and behavior clarification, not evidence that the remediation model changed.
For passwordless security-key and on-premises Kerberos configuration, the updated guidance says Set-AzureADKerberosServer defaults to Commercial cloud endpoints. Administrators configuring another cloud environment need to set the cmdlet to use the specified cloud. This is a concrete multi-cloud configuration clarification, not a new passwordless capability.
The updated Microsoft Entra External ID deployment guide covers edge protection, domains, subscriptions, consumer-app security, and fraud tactics. It is security guidance for operating external or customer-facing applications; the supplied evidence names no newly required control, product launch, or availability change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A Microsoft Entra documentation page was updated: Msal Migration.
manager: CelesteDG
manager: CelesteDG
manager: CelesteDG
A Microsoft Entra documentation page was updated: Msal Error Handling Js.
A Microsoft Entra documentation page was updated: Msal Js Avoid Page Reloads.
A Microsoft Entra documentation page was updated: Msal Js Known Issues Ie Edge Browsers.
A Microsoft Entra documentation page was updated: Msal Js Prompt Behavior.
A Microsoft Entra documentation page was updated: Msal Js Sso.
A Microsoft Entra documentation page was updated: Msal Js Use Ie Browser.
A Microsoft Entra documentation page was updated: Msal Logging Js.
A Microsoft Entra documentation page was updated: Msal Net System Browser Android Considerations.
A Microsoft Entra documentation page was updated: Msal Net Xamarin Android Considerations.
A Microsoft Entra documentation page was updated: Msal Overview.
manager: CelesteDG
A Microsoft Entra documentation page was updated: Scenario Mobile App Registration.
Discusses new feature releases of Microsoft Single Sign-on for Linux
- With their work or school or personal Microsoft accounts.
manager: CelesteDG
A Microsoft Entra documentation page was updated: Apple Sso Plugin.
author: joflore
A Microsoft Entra documentation page was updated: Howto Create Self Signed Certificate.
A Microsoft Entra documentation page was updated: Mobile App Quickstart Portal Ios.
A Microsoft Entra documentation page was updated: Quickstart V2 Ios.
A Microsoft Entra documentation page was updated: Remind Not To Relay Token Nonaud.
A Microsoft Entra documentation page was updated: Scenario Mobile Acquire Token.
A Microsoft Entra documentation page was updated: V2 Libraries.
By default the `Set-AzureADKerberosServer` cmdlet will use the Commercial cloud endpoints. If you are configuring Kerberos in another cloud environment, you need to set the cmdlet to use the specified cloud.
The Microsoft identity platform supports authentication for modern application types such as web applications, single-page applications (SPA) and mobile and desktop apps. Once you register your app in the Microsoft Entra admin center, you need to specify the app type by configuring an app platform along with other authentication settings specific to each platform.
manager: martinco
manager: martinco
A Microsoft Entra documentation page was updated: Authentication Vs Authorization.
manager: CelesteDG
A Microsoft Entra documentation page was updated: Msal Js Pass Custom State Authentication Request.
A Microsoft Entra documentation page was updated: App Sign In Flow.
manager: martinco
A Microsoft Entra documentation page was updated: Deployment External Audit Monitor.
A Microsoft Entra documentation page was updated: Developer Guide Conditional Access Authentication Context.
A Microsoft Entra documentation page was updated: V2 Conditional Access Dev Guide.
A Microsoft Entra documentation page was updated: Application Model.
A Microsoft Entra documentation page was updated: Scenario Mobile Call Api.
Overview of Single Sign-on for Linux for Microsoft Entra ID registered devices.
manager: CelesteDG
{
manager: femila
author: shlipsey3
author: shlipsey3
When user remediation isn't enabled, an admin must manually review them in the reports in the portal, through the API, or in Microsoft Defender XDR. Admins can perform manual actions to dismiss, confirm safe, or confirm compromise on the risks.
As an access package manager, you can assign which role you want to provide a user for a group within an access package. By [managing groups with Privileged Identity Management](../id-governance/privileged-identity-management/groups-discover-groups.md), you're able to enhance security by designating that group access happens just-in-time. This article describes how to enable pim for a group, adding the group to an access package, and verifying eligible assignments are available.
> [!NOTE]
- **Google**: Google federation allows external users to redeem invitations from you by signing in to your apps with their own Gmail accounts. Google federation can also be used in your self-service sign-up user flows. See how to [add Google as an identity provider](google-federation.md).
When you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) that’s initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.
1. Select **Save changes**.
Azure Active Directory B2C (Azure AD B2C) is Microsoft's legacy solution for customer identity and access management. Azure AD B2C includes a separate consumer-based directory that you manage in the Azure portal through the Azure AD B2C service. Each Azure AD B2C tenant is separate and distinct from other Microsoft Entra ID and Azure AD B2C tenants. The Azure AD B2C portal experience is similar to Microsoft Entra ID, but there are key differences, such as the ability to customize your user journeys using the Identity Experience Framework.
When you create an external tenant, you can set your correct geographic location and your domain name. If you currently use Azure AD B2C, the new workforce and external tenant model doesn't affect your existing Azure AD B2C tenants.
[Azure Active Directory B2C](/azure/active-directory-b2c/overview) provides business-to-customer identity as a service. Given that the integration with Azure AD B2C is similar to how you would allow enterprise users to sign in with Microsoft Entra ID, the recommendations above still mostly apply when you want to use Azure AD B2C for your customers, consumers or citizens and allow them to use their preferred social, enterprise, or local account identities.
To protect customers, some regions require you to enable the country codes to receive SMS telephony verification for Microsoft Entra External ID external tenants.
External ID supports server-side integrations with external systems via [custom authentication extensions](~/identity-platform/custom-extension-overview.md). This capability allows developers to implement their own logic and invoke it via real-time API calls during sign-in/up flows.
Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.
Learn how to configure cross-tenant synchronization in Microsoft Entra ID using Microsoft Graph PowerShell or Microsoft Graph API.
- **Do you need to override broad block or allow policies for certain users or specific circumstances?** If you want to allow specific users or groups to access a blocked website, consider testing the [Allow a user to access a blocked website](gsa-poc-internet-access.md#allow-a-user-to-access-a-blocked-website) use case.
1. View activity in the [traffic log](../global-secure-access/how-to-view-traffic-logs.md) to confirm that Global Secure Access enabled access. Verify in the sign-in logs that **Through Global Secure Access** shows as **Yes**.
Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access enables decryption and inspection of encrypted traffic at service edge locations. This capability lets Global Secure Access apply advanced security controls like threat detection, content filtering, and granular access policies. Organizations use these access policies to protect against threats that might be hidden in encrypted communications.
|Use case|Recommended configuration|
| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |
A Microsoft Entra documentation page was updated: Learn about Security Service Edge (SSE) coexistence with Microsoft and Palo Alto Networks.