author: barclayn
Workload ID moves to mandatory client service principals; External ID clarifies Azure AD B2C’s lifecycle
19 June was primarily a Microsoft Learn documentation-maintenance day: 34 updates, two new pages, one removal, and no Message Center items. The two new Entra ID pages concern migration from legacy MFA and SSPR policies, but their supplied summaries contain no procedure or deadline. The highest-consequence material is instead a stated Workload ID authentication retirement and an External ID purchase/support clarification; the other notable items are updated guidance or scenarios, not confirmed preview or GA launches.
- Workload ID: retirement of service principal-less authentication
Workload ID · Authentication
The updated authentication guidance says a client service principal will be required for every application, as a Security by default measure. It says Microsoft has verified its own resource-application validations, while removing the service-principal-less path reduces exposure if validation gaps reappear in future or third-party resources. This is a stated authentication behavior change and retirement, not a preview or GA notice; no enforcement date is supplied.
- External ID: Azure AD B2C P1/P2 purchase boundary clarified
External ID · Security
The updated FAQ says Azure AD B2C P1 and P2 were no longer available for purchase by new customers from 1 May 2025. Current customers can continue using B2C; the FAQ says the product experience, including creating new tenants or user flows, and operational commitments remain unchanged, with support continuing until at least May 2030. This is lifecycle guidance, not an immediate retirement for existing tenants.
- Entra ID Staged Rollout guidance for cloud-authentication migration
Entra ID · Conditional Access
The updated page describes using selected user groups to validate cloud authentication and user experience before transitioning domains. Its listed scenarios include Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, and Identity Governance. This is updated rollout guidance, not evidence that these capabilities were newly launched or reached GA on this date.
- Governed exceptions for Global Secure Access website blocking
ID Governance · Conditional Access
The updated ID Governance scenario combines Global Secure Access and Conditional Access to block a specified unauthorized website, such as an unsanctioned AI app, while entitlement management provides governed access to users who should be exempt. It is a documented configuration pattern for web applications without provisioning or federation support, not a standalone feature announcement.
- Linux SSO guidance connects device registration to device-based Conditional Access
Entra ID · Conditional Access
The updated Entra ID page describes Linux desktop users registering devices with Entra ID, enrolling those devices into Intune, and satisfying device-based Conditional Access when accessing corporate resources. Because the record is marked Updated and gives no availability label, treat it as implementation guidance rather than a new preview or GA claim.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
37 updates
Microsoft Entra ID
26 updatesAuthenticate Application Id
UpdatedMicrosoft Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Microsoft Entra Connect. This account uses a username and password to authenticate requests.
Howto Mfa Reporting
Updated<a name='view-the-azure-ad-sign-ins-report'></a>
One scenario that many organizations [building for resilience](resilience-overview.md) in their identity and access management architecture need to accommodate is continuity of application access during temporary site disconnection. The organization may have one or more physical sites at which their applications are deployed. Some of their users are colocated at those sites and need to be able to access local applications. For example, employees at a factory or at a store may need to be able to sign-in to in-house-developed business applications managing operations at that site.
Refresh Tokens
Updated| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |
Staged Rollout lets you gradually test cloud authentication features with selected user groups. These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains.
1. Review the audit logs to see what changes were made to your Conditional Access policies.
The Microsoft Entra ID authentication pipeline consists of several built-in authentication events, like the validation of user credentials, Conditional Access policies, multifactor authentication, self-service password reset, and more.
Sso Linux
UpdatedThis feature empowers users on Linux desktop clients to register their devices with Microsoft Entra ID, enroll into Intune management, and satisfy device-based Conditional Access policies when accessing their corporate resources.
Whats New
Updated**Service category:** Conditional Access
author: barclayn
category: Privileged access
Updatedauthor: barclayn
ai-usage: ai-assisted
What If Tool
Updated| :---: | --- | :---: | :---: |
21912
RemovedA Microsoft Entra documentation page was updated: 21912.
author: barclayn
```
Data Residency
UpdatedMicrosoft Entra ID is an Identity as a Service (IDaaS) solution that stores and manages identity and access data in the cloud. You can use the data to enable and manage access to cloud services, achieve mobility scenarios, and secure your organization. An instance of the Microsoft Entra ID service, called a [tenant](~/identity-platform/developer-glossary.md#tenant), is an isolated set of directory object data that the customer provisions and owns.
Entra Admin Center
Updated* [App registrations](~/identity-platform/application-model.md)
This article describes security improvements to Microsoft Entra Connect Sync and how to enable logging of administrator activities.
category: Monitoring
Updatedauthor: barclayn
Getthere Tutorial
UpdatedTo configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:dataintegration@serko.com). They set this setting to have the SAML SSO connection set properly on both sides.
Error Codes
Updated| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |
Locate Integration Partners
Updatedmanager: martinco
- *List all Microsoft Entra recommendations*
Integrating Rippling Human Capital Management (HCM) with Microsoft Entra ID/Active Directory.
Microsoft Entra ID Governance
2 updatesIn this scenario, you set up Global Secure Access and Conditional Access to block access to a specific unauthorized website such as an unsanctioned AI app, while using entitlement management to provide governed access to users who should be exempt from the policy. This scenario is useful for generative AI applications and other web applications that don't support provisioning or federation with Microsoft Entra.
A conceptual article describing access package visibility in the My Access portal.
Microsoft Entra External ID
4 updatesB2b Tutorial Require Mfa
Updated1. Access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.
Supported Features Customers
Updated| **Types of application registration** | <ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li><li>Enterprise applications offer [more options](../../identity/enterprise-apps/plan-sso-deployment.md), like password-based, linked, and header-based.</li></ul> |<ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li></ul>|
Leave The Organization
Updated- If you're using a personal account or email one-time passcode, you'll need to use a My Account URL that includes your tenant name or tenant ID.
Faq Customers
UpdatedEffective May 1, 2025 Azure AD B2C P1 and P2 will no longer be available to purchase for new customers, but current Azure AD B2C customers can continue using the product. The product experience, including creating new tenants or user flows, remains unchanged. The operational commitments, including service level agreements (SLAs), security updates, and compliance, also remain unchanged. We'll continue supporting Azure AD B2C until at least May 2030. More information, including migration plans will be made available. Contact your account representative for more information and to learn more about Microsoft Entra External ID.
Microsoft Entra Workload ID
1 updateThis change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-rest-beta&preserve-view=true)). Service principal-less authentication can be abused if the resource applications (i.e. APIs) perform incomplete validations. Microsoft has verified that validations aren't vulnerable to service principal-less authentication. However, with this action, the risk of this gap reappearing in future versions or being exploited in third-party resources outside Microsoft’s control is minimized.
Microsoft Entra Global Secure Access
4 updatesSecure Shell (SSH) is widely recognized across the IT industry as a critical service for system administrators. It provides a secure and encrypted method to access and manage remote systems over unsecured networks.
Configure Per App Access
Updated1. Select **Save**.
Transport Layer Security
Updated:::image type="content" source="media/how-to-transport-layer-security/security-profile-baseline.png" alt-text="Screenshot of the Edit Baseline profile screen showing a list of policy names and their priorities.":::
1. Run the command `dsregcmd /status` and check the **AzureAdPrt** field.
