Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.
18 June: no new Entra entries; notable updates clarify MFA fraud controls, B2B claims, workload federation, and access-package visibility
This was a documentation-led day: 19 items were updated, no items were new, and the Cloudknox Permissions Management Platform Tutorial was removed from the Entra ID documentation set. The most consequential content is guidance or behavior clarification rather than a feature launch, preview, or general-availability announcement. Highlights include regional telephony-fraud protections, the home-tenant UPN behavior for B2B token claims, cloud-specific workload-federation audiences, and an access-package visibility notice for changes effective September 30, 2025. The large group of activity, sign-in, provisioning, streaming, and Log Analytics updates appears to clarify existing monitoring and analysis paths.
- Entra ID telephony-fraud guidance documents regional opt-in requirements
Entra ID · Authentication
Security guidance explains that Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. It also states that some regions require opt-in through a support ticket because of elevated fraud risk. This is an updated guidance page, not evidence of a newly launched or generally available feature.
- External ID clarifies the UPN claim issued for B2B users
External ID · Authentication
The Claims Mapping update clarifies that when a B2B user authenticates with an external Microsoft Entra identity and an application uses `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN from the user’s home tenant. Applications that depend on a particular UPN value for B2B identities should verify their token-handling assumptions.
- Workload ID federation guidance lists cloud-specific audience values
Workload ID · Developer
The updated managed-identity app-trust guidance says the audience must match the cloud: `api://AzureADTokenExchange` for the global service, `api://AzureADTokenExchangeUSGov` for US Government, or `api://AzureADTokenExchangeChina` for China operated by 21Vianet. Workload identity federation owners should validate the configured audience for each target cloud.
- ID Governance documentation flags access-package visibility changes for September 30
ID Governance · Fundamentals
The revised Entitlement Management guidance explains that which access packages users can discover and request in the My Access portal depends on several settings, and highlights important changes effective September 30, 2025. The supplied evidence does not specify the new rules, so this is an advance notice to review current visibility configuration rather than a basis for assuming a particular setting will change.
- Entra Connect authentication guidance points to modern credentials
Entra ID · Authentication
The updated Entra ID article explains how the Microsoft Entra Connect application can authenticate to Microsoft Entra ID using modern, more secure credentials. The evidence identifies an implementation-guidance update but does not name a credential type or migration deadline, so Connect administrators should review the revised procedure before changing configuration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
20 updates
Microsoft Entra ID
16 updatesThis article describes how to allow the Microsoft Entra Connect application to authenticate with Microsoft Entra ID with modern, more secure credentials.
Monitor the health of your tenant through several identity scenarios and authentication availability rates with Microsoft Entra Health
Activity Log Schemas
UpdatedLearn how to interpret the details found in the Microsoft Entra audit and sign-in and logs schema.
Learn how to analyze audit, sign-in, and provisioning logs Microsoft Entra ID using Log Analytics queries.
Learn about the different types of sign-in logs that are available in Microsoft Entra monitoring and health.
category: Access control
Updatedauthor: HULKsmashGithub
category: Access control
Updatedauthor: HULKsmashGithub
A Microsoft Entra documentation page was updated: Cloudknox Permissions Management Platform Tutorial.
Learn how to view Conditional Access details in Microsoft Entra activity logs so that you can assess the effect of your policies.
author: MicrosoftGuyJFlo
Learn about the Microsoft Entra logs available for streaming to an endpoint for storage, analysis, or monitoring.
Introduction to the options and considerations for integrating Microsoft Entra activity logs with storage and analysis tools.
|name.givenName|String||✓|
Learn how to download, view, and analyze the details in the provisioning logs from Microsoft Entra ID.
The basic steps for configuring diagnostics settings are as follows:
Microsoft Entra ID Governance
1 updateWhen you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and upcoming changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, outlines how it currently works, and highlights important changes effective September 30, 2025.
Microsoft Entra External ID
1 updateClaims Mapping
UpdatedIf you need to issue the UPN value as an application token claim, the actual claim mapping might behave differently for B2B users. If the B2B user authenticates with an external Microsoft Entra identity and you issue `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN attribute from the home tenant for this user.
Microsoft Entra Workload ID
2 updatesLearn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>
