Learn best practices for migrating Source of Authority (SOA) from Active Directory to Microsoft Entra ID, including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
SOA migration and PIM/access-package guidance lead an otherwise maintenance-heavy Entra day
The clearest changes on 29 May are two documentation additions: an Entra ID guide for migrating Source of Authority (SOA) from Active Directory, and an ID Governance reference for access-package and PIM periods that do not align. Other notable updates clarify Universal tenant restrictions, Microsoft Graph activity-log schema selection, and recommendation-email behavior. No Message Center entry or supplied evidence announces a preview, general availability event, or service retirement. The single removed item is the Source Of Authority Overview documentation page, which signals documentation retirement rather than retirement of the SOA capability itself. Most remaining items are ordinary documentation maintenance or clarification.
- New Entra ID guidance for Source of Authority migration
Entra ID · Fundamentals
A new Microsoft Learn article covers migrating Source of Authority from Active Directory to Microsoft Entra ID, including prerequisites, supported scenarios, and step-by-step guidance for IT architects and administrators. This is a new documentation guide, not evidence of a new SOA feature, preview, or general-availability event.
- New ID Governance reference addresses PIM and access-package period mismatches
ID Governance · Governance
The new reference documents Microsoft Entra ID behavior when an access package's assignment period and a PIM policy do not align. Related eligibility guidance says to verify that the access package expiration period does not exceed the PIM-managed group's “Expire eligible assignments after” setting. This is configuration guidance for combined entitlement-management and PIM designs, not a new governance capability or availability change.
- Universal tenant restrictions guidance defines the external-tenant control model
Workload ID · Architecture
Updated Global Secure Access proof-of-concept material describes Universal tenant restrictions for unmanaged identities on company-managed devices and networks. It says Entra ID Tenant Restrictions can enforce the policy by blocking or allowing all traffic to an external tenant. This is access-control architecture guidance, not evidence of a rollout, preview, or general availability announcement.
- Production activity-log integrations are cautioned against using the Graph beta schema
Entra ID · Microsoft identity platform
The updated Activity Log Schemas guidance says the Microsoft Graph v1.0 endpoint is the most stable and commonly used for production, while beta may expose more properties but is subject to change. It explicitly advises against using the beta schema in production. This is operational guidance and documentation clarification, not a new logging feature.
- Recommendation email behavior is clarified as default-on
Entra ID · Monitoring
Updated Entra ID guidance says recommendation emails are enabled by default, summarize the specific recommendation, link to the relevant admin-center area and documentation, and contain no promotional or upselling content. The evidence supports a documentation clarification of the stated behavior, not a confirmed behavior change on 29 May.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
37 updates
Microsoft Entra ID
22 updates- *Who are the owners of the Finance Department group?*
Whats New Archive
Updated**Type:** New feature
Usage Insights Report
UpdatedTo access the data from Usage and insights you must have:
Identity Secure Score
Updatedauthor: shlipsey3
* The [**audit logs activity report**](concept-audit-logs.md) gives you access to the history of every task performed in your tenant.
Token Protection
Updatedauthor: MicrosoftGuyJFlo
Monitoring Health
UpdatedReviewing the data in the Microsoft Entra activity logs can provide helpful information for IT administrators. To streamline the process of reviewing data on key scenarios, we've created several reports on common scenarios that use the activity logs.
Source Of Authority Overview
RemovedA Microsoft Entra documentation page was updated: Source Of Authority Overview.
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
Learn how to add a redirect URI to your application in Microsoft Entra to securely handle authentication tokens and enhance app security.
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/validation-error.png" alt-text="Screenshot of a certificate validation error." :::
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::
Customize Branding
UpdatedOnce your default sign-in experience is created, select the **Edit** button to make any changes. You can't delete a default sign-in experience after it's created, but you can remove all custom settings.
As a developer, you want to run automated integration tests on the apps you develop. Calling your API protected by Microsoft identity platform (or other protected APIs such as [Microsoft Graph](/graph/)) in automated integration tests is a challenge. Microsoft Entra ID often requires an interactive user sign-in prompt, which is difficult to automate. This article describes how you can use a non-interactive flow, called [Resource Owner Password Credential Grant (ROPC)](v2-oauth-ropc.md), to automatically sign in users for testing.
PowerShell
Updated1. In the owner tenant, use the [Update-MgTenantRelationshipMultiTenantOrganization](/powershell/module/microsoft.graph.identity.signins/update-mgtenantrelationshipmultitenantorganization) command to create your multitenant organization. This operation can take a few minutes.
**Request**
Connect Version History
Updated>[!IMPORTANT]
The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, aren't promotional or marketing emails, and don't contain any upselling content. These emails are purely informational and designed to help you act quickly when a new recommendation is available.
A Microsoft Entra documentation page was updated: Howto Stream Logs To Event Hub.
Howto Use Workbooks
UpdatedA Microsoft Entra documentation page was updated: Howto Use Workbooks.
Activity Log Schemas
UpdatedThere are two endpoints for the Microsoft Graph API. The V1.0 endpoint is the most stable and is commonly used for production environments. The beta version often contains more properties, but they're subject to change. For this reason, we don't recommend using the beta version of the schema in production environments.
Microsoft Entra ID Protection
3 updatesauthor: shlipsey3
author: shlipsey3
Workload Identity Risk
UpdatedWorkload identity risk in Microsoft Entra ID Protection
Microsoft Entra ID Governance
4 updatesAs mentioned, custom extensions created with the request workflow type, which includes four associated policy stages, can be enabled with “*Launch and wait*” if desired.
This article serves as a reference for Microsoft Entra ID behavior when assignment periods of an access package and PIM policy dont allign.
1. Verify the Access Package expiration period doesn't exceed the **Expire eligible assignments after** setting in the PIM managed group.
manager: femila
Microsoft Entra External ID
3 updates> [!NOTE]
1. Select **Save changes**.
- Cross-tenant access partner configurations
Microsoft Entra Internet Access
1 updateGsa Poc Guidance Intro
Updated- **Do you need to override broad block or allow policies for certain users or specific circumstances?** If you want to allow specific users or groups to access a blocked website, consider testing the [Allow a user to access a blocked website](gsa-poc-internet-access.md#allow-a-user-to-access-a-blocked-website) use case.
Microsoft Entra Workload ID
1 updateGsa Poc Internet Access
Updated[Universal tenant restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md) enable you to control access to external tenants by unmanaged identities on company-managed devices and networks. You can enforce this restriction with Entra ID Tenant Restrictions, by either blocking or allowing all traffic to an external tenant.
Microsoft Entra Global Secure Access
3 updates|Use case|Recommended configuration|
Transport Layer Security
Updatedmanager: femila
author: HULKsmashGithub
