← Previous day

Next day →
Day in brief

5 June 2025: Conditional Access exclusion governance and Security Copilot agent guidance are the clearest changes

This was a documentation-refresh day rather than a product-release day: 167 entries were updates, with no new or removed items and no Message Center notices; 149 were tagged ID Governance. The most useful exceptions are specific guidance updates covering access reviews for users excluded from Conditional Access, the SCU and control model for Security Copilot agents in Entra, and External ID redirect-URI support documented as “Same as workforce.” An entitlement-management article about assigning Entra roles through access packages is explicitly marked Preview. Nothing supplied evidences a GA transition, retirement, or changed enforcement behavior.

  • The updated ID Governance page explains how to use access reviews to manage users excluded from Conditional Access policies. This is security and governance guidance; the change record does not say that Conditional Access policy evaluation or exclusion behavior itself changed.

  • The updated Microsoft Security Copilot agents in Microsoft Entra page says agents fit existing workflows, use Security Compute Units (SCUs) like other product features, require no special training or other licensing, integrate with Microsoft Security solutions and supported partners, and keep the operator in control through feedback. It names threat intelligence briefings and Conditional Access optimization as resource-intensive tasks. This is operating-model documentation, not evidence of a new launch, Preview, or

  • The updated Supported Features Customers page includes an Authentication > Redirect URIs entry defining the URIs accepted as destinations for authentication responses after successful authentication or sign-out, with support labeled “Same as workforce.” This is an ordinary documentation clarification; the record does not establish that accepted-URI behavior changed.

  • The updated entitlement-management article covers assigning Microsoft Entra roles with access packages and retains “Preview” in its title. The record therefore supports preview documentation only; it supplies no evidence of general availability, new prerequisites, or a rollout change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

167 updates

5

Govern the existing users of an application that does not support provisioning in Microsoft Entra ID with Microsoft PowerShell

Updated

Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.

2
1
1
1

Mysdworxcom Tutorial

Updated

* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.

1

Sla Performance

Updated

| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |

1

Connect Health Agent Install

Updated

> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.

124

Govern access for applications in your environment

Updated

Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.

Pim Powershell Migration

Updated

The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.

Customize Workflow Email

Updated

Get a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.

Manage access to your SAP applications

Updated

Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.

Manage access with access reviews

Updated

Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.

Manage Workflow On Premises

Updated

A how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.

Manage Workflow Tasks

Updated

This article guides a user on managing workflow versions with Lifecycle Workflows.

On Demand Workflow

Updated

This article guides a user to running a workflow on demand using Lifecycle Workflows.

Pim Apis

Updated

Information for understanding the APIs in Microsoft Entra Privileged

Pim Roles

Updated

Describes the roles you can't manage in Microsoft Entra Privileged Identity

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

20

Microsoft Entra ID Governance

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

What are access reviews? - Microsoft Entra

Updated

Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.

Externally determine the approval requirements for an access package using custom extensions (Preview)

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. While entitlement management natively supports dynamic approvers such as the requestor's manager, second-level manager, or sponsor from a connected organization, these options don't cover all scenarios. With [custom extensions](entitlement-management-logic-apps-integration.md) calling out to [Azure Logic Apps](/azure/logic-apps/logic-apps-overview), you're able to determine approval requirements for access packages at the time of request through an external system. For example, if the user requesting an access package is in a department where leadership has recently changed, dynamic approvals can query the system and assign the new department head as the approver. With this external call, you're able to determine approval requirements based on each of the [ApprovalStage properties](/graph/api/resources/approvalstage?view=graph-rest-beta#properties). This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.

Lifecycle Workflow On Premises

Updated

Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.

What is entitlement management?

Updated

Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external users.

2
2

Pim Troubleshoot

Updated

Learn how to troubleshoot system errors with roles in Microsoft Entra Privileged Identity Management (PIM).

1
1

Supported Features Customers

Updated

| **Authentication** > **Redirect URIs**| The URIs Microsoft Entra ID accepts as destinations when returning authentication responses (tokens) after successfully authenticating or signing out users. | Same as workforce.|

1

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

1

Allow or Block Invitations

Updated

Learn how an administrator create a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.

1

Partner Gallery

Updated

1. Set up Microsoft Entra Verified ID Service: using [Quick setup](verifiable-credentials-configure-tenant-quick.md) or [Advanced setup instructions](verifiable-credentials-configure-tenant.md).

1

Connectors

Updated

For more information about optimizing your network, see [Network topology considerations when using Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).

1

Microsoft Security Copilot agents in Microsoft Entra

Updated

Agents fit naturally into existing workflows. You don't need special training or other licensing to use them. Agents utilize SCUs to operate just like other features in the product. They integrate seamlessly with Microsoft Security solutions and the broader supported partner ecosystem. Agents learn based on feedback and keep you in control on the actions it takes. They handle resource-intensive tasks like threat intelligence briefings, and Conditional Access optimization. With Microsoft Security Copilot agents, you can scale up your teams, people, and processes.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…