← Previous day

Next day →
Day in brief

6 June 2025: act on Workload ID’s service-principal-less authentication retirement; other notable items are guidance updates

6 June was primarily a documentation-maintenance day rather than a broad Entra release: 208 of 213 records were updates, two were new, and no Message Center item was supplied. The clearest operational consequence is the Workload ID retirement notice, which requires action before 31 March 2026 to avoid application authentication failures. Other high-signal items are revised Security Copilot Conditional Access guidance, macOS passwordless capability documentation, Global Secure Access recovery guidance, and an Entitlement Management Dynamic Approval setup clarification. The evidence does not establish a preview, general availability release, or tenant-wide behavior change for those items.

  • The updated “Retire Service Principal Less Authentication” guidance gives a concrete deadline: administrators must act before 31 March 2026 or applications may experience authentication failure. This is an explicit retirement and application-owner action item, not a routine documentation edit.

  • The updated Microsoft Entra Conditional Access optimization-agent article says the agent recommends policies and changes intended to help protect all users, using best practices aligned with Zero Trust and Microsoft’s learnings. This record is updated guidance, not evidence that the capability newly entered preview or general availability.

  • The revised passwordless article describes users configuring Touch ID to unlock a macOS device, with phish-resistant credentials based on Windows Hello for Business technology and integration with the Secure Enclave. It documents capability behavior but does not identify a launch or a change to tenant defaults.

  • The updated sample covers recovery from a Global Secure Access break-glass scenario by re-enabling Conditional Access policies that were disabled. This is operational security and recovery guidance, not evidence of a Global Secure Access behavior change or new availability stage.

  • The updated Entitlement Management Dynamic Approval article says that after the Azure Logic App receives the catalog’s access package assignment manager role, the Logic App must be edited to communicate with Microsoft Entra. This is a concrete setup clarification for that workflow, not evidence of a tenant-wide service change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

213 updates

37

Configure Sso

Updated

Understand single sign-on with an on-premises app using application proxy.

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

30

Expression Builder

Updated

Understand how expression builder works with Application Provisioning in Microsoft Entra ID.

11

Assign Microsoft Entra roles

Updated

Learn how to assign Microsoft Entra roles to users and groups at tenant, application registration, administrative unit scopes using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.

Create a custom role in Microsoft Entra ID

Updated

Learn how to create a custom role to manage access to Microsoft Entra resources using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API

10

Copilot in Microsoft Entra

Updated

**Applies to:** Microsoft Entra ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png)

9

Authentication Passwordless

Updated

Platform Credential for macOS allows users to go passwordless by configuring Touch ID to unlock the device, and uses phish-resistant credentials, based on Windows Hello for Business technology. This saves customer organizations money by removing the need for security keys and advances Zero Trust objectives using integration with the Secure Enclave.

What Is App Proxy

Updated

Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.

9

Configure User Consent

Updated

- A user account. If you don't already have one, you can [create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).

Mysdworxcom Tutorial

Updated

* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.

6
6

Scim Graph Scenarios

Updated

Using SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.

Scim Validator Tutorial

Updated

This tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.

Use Scim To Provision Users And Groups

Updated

System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.

6
2
2

Roles across Microsoft services

Updated

Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services

1

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

2
2

Migrate From Sap Idm

Updated

Organizations that have SAP SuccessFactors could use SAP IDM to [bring in employee data](https://help.sap.com/docs/SAP_IDENTITY_MANAGEMENT/4773a9ae1296411a9d5c24873a8d418c/4c54e007ab414f7da3854952cad00221.html) from SAP SuccessFactors. Those organizations with SAP SuccessFactors can easily migrate to bring identities for employees [from SuccessFactors into Microsoft Entra ID](~/identity/saas-apps/sap-successfactors-inbound-provisioning-cloud-only-tutorial.md) or [from SuccessFactors into on-premises Active Directory](~/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial.md), by using Microsoft Entra ID connectors. The connectors support the following scenarios:

Entitlement Management Dynamic Approval

Updated

With the Azure Logic App given the access package assignment manager role for the catalog, you must now go to logic app to edit it to communicate with Microsoft Entra. To do this, you'd do the following steps:

4
1

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

1
4

Data Storage And Privacy

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

Points Of Presence

Updated

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.

2

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

Internet Access

Updated

Learn about how Microsoft Entra Internet Access secures access to the Internet.

1
1

Event Enrichment Logs

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

7

Configure Connectors

Updated

Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.

Configure Quick Access

Updated

Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.

3

Connector Groups

Updated

Learn how Microsoft Entra private network connector groups work and how they're used by Microsoft Entra Private Access and application proxy.

Connectors

Updated

Learn how Microsoft Entra private network connectors work and how they're used by Microsoft Entra Private Access and application proxy.

Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

1

Configure Per App Access

Updated

Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.

1

Entra Admin Center

Updated

* [Credentials](~/verified-id/verifiable-credentials-configure-tenant-quick.md)

1
1

Copilot Security Entra Investigate Risky Apps

Updated

Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.

24

Manage Microsoft Profile

Updated

Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.

Quickstart Install Client

Updated

Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.

Remote Network Configurations

Updated

Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.

Role Based Permissions

Updated

Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.

9

Cisco Coexistence

Updated

Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.

Netskope Coexistence

Updated

Microsoft and Netskope’s Security Service Edge (SSE) coexistence solution guide.

What Is Global Secure Access

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

Netskope Integration

Updated

A comprehensive guide for configuring and testing the integration between Microsoft's and Netskope's Secure Access Service Edge (SASE) solutions.

Partner Ecosystems Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

Remote Network Connectivity

Updated

Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.

Traffic Dashboard

Updated

Monitor the health and status of your network traffic with the Global Secure Access dashboard.

Traffic Forwarding

Updated

Learn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.

6

Access Audit Logs

Updated

Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.

View Traffic Logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

Remote Network Health Logs

Updated

Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.

Use Workbooks

Updated

Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.

View Enriched Logs

Updated

Learn how to use enriched Microsoft 365 logs for Global Secure Access.

3

Quickstart Remote Network

Updated

Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.

2

Troubleshoot Distributed File System

Updated

A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.

1
1

Palo Alto Coexistence

Updated

Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.

3

Microsoft Security Copilot agents in Microsoft Entra

Updated

Microsoft Entra agents work seamlessly with [Microsoft Security Copilot](/copilot/security/microsoft-security-copilot). Microsoft Security Copilot agents automate repetitive tasks and reduce manual workloads. They enhance security and IT operations across cloud, data security and privacy, identity, and network security. These agents handle high-volume, time-consuming tasks by pairing data and code with an AI language model. They respond to user requests and system events, helping teams work more efficiently and focus on higher-impact tasks.

2
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…