← Previous day

Next day →
Day in brief

11 June 2025: Workload ID retirement and Global Secure Access lockout guidance are the actionable exceptions

This was primarily a Microsoft Learn documentation day: 2 new, 55 updated, and 7 removed records were reported, with no Message Center items. The evidence supports three concrete themes: an explicit Workload ID authentication-retirement deadline; updated Global Secure Access Internet Access guidance for Intune device-compliance bypasses and Universal Conditional Access tunnel limits; and new Microsoft–Netskope Security Service Edge coexistence guidance. The remaining representative Entra ID changes are mainly security-control and authentication documentation updates; nothing supplied establishes a feature launch, preview, GA change, or changed tenant enforcement.

  • The updated page carries an explicit requirement to act before March 31, 2026 to avoid application authentication failure. This is a retirement notice with a concrete deadline; the supplied evidence does not identify the replacement or migration method.

  • The updated Internet Access documentation addresses Intune device-compliance bypasses and links them to Universal Conditional Access tunnel-authorization limitations. It warns that blocking a forwarding profile in Conditional Access can inadvertently lock users out of anything on their machine. This is a configuration and safety clarification, not evidence of a new feature or enforcement rollout.

  • A new page explains how to configure and deploy Microsoft Entra and Netskope Security Service Edge solutions together across private applications, Microsoft 365, and internet access. The period also includes a new Global Secure Access/Netskope integration guide and an updated Netskope Coexistence page. These are documentation additions and updates; the supplied records do not announce preview or GA status.

  • An Entra ID page was updated on targeting privileged Microsoft Entra built-in roles with Conditional Access policies to enforce phishing-resistant methods. The supplied summary identifies a documentation update but does not say that policies were automatically created, modified, or newly enforced in tenants, so treat this as security guidance clarification.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

64 updates

17

Kontiki Tutorial

Removed

A Microsoft Entra documentation page was updated: Kontiki Tutorial.

Promapp Tutorial

Removed

A Microsoft Entra documentation page was updated: Promapp Tutorial.

11
8
4

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

3
2
2

Identifier Uri Restrictions

Updated

```Failed to add identifier URI {uri}. All newly added URIs must contain a tenant verified domain, tenant ID, or app ID, as per the default tenant policy of your organization. See https://aka.ms/identifier-uri-addition-error for more information on this error.```

1
1
1
1

Security Features in External Tenants

Updated

Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.

4

Netskope Coexistence

Updated

1. **[Configuration 1: Microsoft Entra Private Access with Netskope Internet Access](#configuration-1-microsoft-entra-private-access-with-netskope-internet-access)**

1

Add Intune device compliance bypasses to Global Secure Access Internet Access

Updated

The [Universal Conditional Access documentation](/entra/global-secure-access/concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authorization limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertently lock users out from accessing anything on their machine.

1
2

userimpact: Low

Updated

Microsoft services applications that operate in your tenant are identified as service principals with the owner organization ID "f8cdef31-a31e-4b4a-93e4-5f571e91255a". When these service principals have credentials configured in your tenant, they might create potential attack vectors that threat actors can exploit. If the credentials were added by an administrator and are no longer needed, they can become a target for attackers. Although less likely when proper preventive and detective controls are in place on privileged activities, credentials can also be added maliciously by threat actors. In either case, threat actors can use these credentials to authenticate as the service principal, gaining the same permissions and access rights as the Microsoft service application. This initial access can lead to privilege escalation if the application has high-level permissions, allowing lateral movement across the tenant. Attackers can then proceed to data exfiltration or persistence establishment through creating additional backdoor credentials.

1
4
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…