← Previous day

Next day →
Day in brief

4 June was documentation-led: Entra ID clarifies telephony-fraud throttling, subdomain authentication, and tenant quarantine

The supplied evidence points to a documentation-maintenance period: 82 items were updated, compared with 4 new and 5 removed, and there were no Message Center entries. The representative items are all Microsoft Learn updates rather than launch notices. The most useful administrator-facing material covers Entra ID telephony-fraud controls, custom-subdomain authentication inheritance, tenant quarantine, and delegated-administration permissions; Global Secure Access also calls out a CSR step in its TLS procedure. The evidence does not establish a preview, general availability event, retirement, or tenant-wide behavior change, and it provides no detail about the four new or five removed records.

  • The updated page describes heuristics and machine learning that detect and throttle suspicious telephony activity during MFA, and notes that some regions require opt-in through a support ticket because of elevated fraud risk. This is security and behavior guidance, not evidence of a new MFA rollout or changed tenant default.

  • The Entra ID domain guidance covers changing default authentication settings on a custom subdomain when those settings are inherited from the root domain. This is a configuration clarification, not a stated new custom-domain capability or global default change.

  • Entra ID · Fundamentals
    Quarantine unsanctioned tenants

    The updated guidance provides steps to isolate unapproved tenants using Microsoft Entra features. It is operational security guidance; the record does not announce new enforcement availability or a mandatory tenant-control change.

  • Global Secure Access · Security
    Global Secure Access TLS setup

    The updated Transport Layer Security procedure explicitly calls out selecting Create CSR. This is a concrete implementation detail for Global Secure Access, not a preview or general availability announcement.

  • The Entra ID primer clarifies the relationship between older delegated admin permissions and newer granular delegated admin permissions. It helps administrators interpret the two models, but the item does not announce a migration, retirement, or required permission change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

91 updates

49

Groups Bulk Download

Updated

Download group properties in bulk in the Azure admin center in Microsoft Entra ID.

Groups Dynamic Membership

Updated

Learn how to manage rules for dynamic membership groups to automatically populate group members and rule references.

Linkedin User Consent

Updated

Explains how LinkedIn integration shares data via Microsoft apps in Microsoft Entra ID

Users Bulk Download

Updated

Download user records in bulk in the Azure admin center in Microsoft Entra ID.

Users Bulk Restore

Updated

Restore deleted users in bulk in the Azure portal in Microsoft Entra ID

Users Sharing Accounts

Updated

Describes how Microsoft Entra ID enables organizations to securely share accounts for on-premises apps and consumer cloud services.

21

Quarantine unsanctioned tenants

Updated

Isolate unsanctioned tenants using Microsoft Entra features. Follow steps to quarantine unapproved tenants and strengthen security.

Licensing Preview Info

Updated

In this article we go over the information in effect when participating in Microsoft Entra ID preview programs.

Recommendations

Updated

| Recommendation | Impacted resources | Availability | Identity Secure Score | Target roles for email notifications |

Default user permissions

Updated

Compare the default user permissions available in Microsoft Entra ID and learn how to restrict access.

Directory Overview User Model

Updated

The relationship between users and licenses assigned, administrator roles, dynamic membership groups in Microsoft Entra ID

What is Microsoft Entra ID?

Updated

Learn about Microsoft Entra ID, including terminology, available licenses, and a list of associated features.

7

Telephony Fraud Protections and Throttles

Updated

Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.

Non-interactive sign-in logs

Updated

Learn about the type of activity captured in the non-interactive sign-in logs in Microsoft Entra monitoring and health.

Interactive user sign-in logs

Updated

Learn about the type of information captured in the interactive user sign-in logs in Microsoft Entra monitoring and health.

Sspr Policy

Updated

| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |

3

Enterprise State Roaming Troubleshooting

Updated

1. After joining your Windows 10 or newer PC to a domain that is configured to allow Enterprise State Roaming, sign on with your work account. Go to **Settings** > **Accounts** > **Sync Your Settings** and confirm that sync and the individual settings are on, and that the top of the settings page indicates that you're syncing with your work account. Confirm the same account is also used as your account in **Settings** > **Accounts** > **Your Info**.

2
2

Groups Self Service Management

Updated

Create and manage security groups or Microsoft 365 groups in Microsoft Entra ID and request security group or Microsoft 365 group memberships.

1
1

Enterprise State Roaming Group Policy Settings

Updated

The MDM policy settings apply to Windows 10 or newer. Refer to [Enterprise State Roaming settings catalog](/windows/configuration/windows-backup/catalog-esr) for details on what devices are supported for Microsoft Entra ID-based syncing.

1
1

Verified helpdesk with Microsoft Entra Verified ID

Updated

An ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Traditional methods such as personally identifiable information (PII) and knowledge-based authentication are no match for today’s sophisticated attackers, who use phishing, social engineering, and even AI-powered voice cloning to bypass defenses. The consequences are serious: under pressure, helpdesk agents may unintentionally expose sensitive data or authorize fraudulent actions.

1

Microsoft Entra Verified ID Identity Verification partners

Updated

Our Identity Verification (IDV) partner network extends Microsoft Entra Verified ID capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable scenarios like remote onboarding with government ID checks using identity verification and proofing services.

1

Transport Layer Security

Updated

To get started with TLS inspection, see [Configure Transport Layer Security](how-to-transport-layer-security.md).

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…