← Previous day

Next day →
Day in brief

18 June: no new Entra entries; notable updates clarify MFA fraud controls, B2B claims, workload federation, and access-package visibility

This was a documentation-led day: 19 items were updated, no items were new, and the Cloudknox Permissions Management Platform Tutorial was removed from the Entra ID documentation set. The most consequential content is guidance or behavior clarification rather than a feature launch, preview, or general-availability announcement. Highlights include regional telephony-fraud protections, the home-tenant UPN behavior for B2B token claims, cloud-specific workload-federation audiences, and an access-package visibility notice for changes effective September 30, 2025. The large group of activity, sign-in, provisioning, streaming, and Log Analytics updates appears to clarify existing monitoring and analysis paths.

  • Security guidance explains that Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. It also states that some regions require opt-in through a support ticket because of elevated fraud risk. This is an updated guidance page, not evidence of a newly launched or generally available feature.

  • The Claims Mapping update clarifies that when a B2B user authenticates with an external Microsoft Entra identity and an application uses `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN from the user’s home tenant. Applications that depend on a particular UPN value for B2B identities should verify their token-handling assumptions.

  • The updated managed-identity app-trust guidance says the audience must match the cloud: `api://AzureADTokenExchange` for the global service, `api://AzureADTokenExchangeUSGov` for US Government, or `api://AzureADTokenExchangeChina` for China operated by 21Vianet. Workload identity federation owners should validate the configured audience for each target cloud.

  • The revised Entitlement Management guidance explains that which access packages users can discover and request in the My Access portal depends on several settings, and highlights important changes effective September 30, 2025. The supplied evidence does not specify the new rules, so this is an advance notice to review current visibility configuration rather than a basis for assuming a particular setting will change.

  • The updated Entra ID article explains how the Microsoft Entra Connect application can authenticate to Microsoft Entra ID using modern, more secure credentials. The evidence identifies an implementation-guidance update but does not name a credential type or migration deadline, so Connect administrators should review the revised procedure before changing configuration.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

20 updates

6

Telephony Fraud Protections and Throttles

Updated

Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.

Activity Log Schemas

Updated

Learn how to interpret the details found in the Microsoft Entra audit and sign-in and logs schema.

3
2
2
2
1
1

Entitlement Management Access Package Visibility

Updated

When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and upcoming changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, outlines how it currently works, and highlights important changes effective September 30, 2025.

1

Claims Mapping

Updated

If you need to issue the UPN value as an application token claim, the actual claim mapping might behave differently for B2B users. If the B2B user authenticates with an external Microsoft Entra identity and you issue `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN attribute from the home tenant for this user.

1

Service principal sign-in logs

Updated

Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.

1

Workload Identity Federation Config App Trust Managed Identity

Updated

The audience value must be set to one of the following values:<br/> &#8226; **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>&#8226; **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>&#8226; **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…