← Previous day

Next day →
Day in brief

Workload ID moves to mandatory client service principals; External ID clarifies Azure AD B2C’s lifecycle

19 June was primarily a Microsoft Learn documentation-maintenance day: 34 updates, two new pages, one removal, and no Message Center items. The two new Entra ID pages concern migration from legacy MFA and SSPR policies, but their supplied summaries contain no procedure or deadline. The highest-consequence material is instead a stated Workload ID authentication retirement and an External ID purchase/support clarification; the other notable items are updated guidance or scenarios, not confirmed preview or GA launches.

  • The updated authentication guidance says a client service principal will be required for every application, as a Security by default measure. It says Microsoft has verified its own resource-application validations, while removing the service-principal-less path reduces exposure if validation gaps reappear in future or third-party resources. This is a stated authentication behavior change and retirement, not a preview or GA notice; no enforcement date is supplied.

  • The updated FAQ says Azure AD B2C P1 and P2 were no longer available for purchase by new customers from 1 May 2025. Current customers can continue using B2C; the FAQ says the product experience, including creating new tenants or user flows, and operational commitments remain unchanged, with support continuing until at least May 2030. This is lifecycle guidance, not an immediate retirement for existing tenants.

  • The updated page describes using selected user groups to validate cloud authentication and user experience before transitioning domains. Its listed scenarios include Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, and Identity Governance. This is updated rollout guidance, not evidence that these capabilities were newly launched or reached GA on this date.

  • The updated ID Governance scenario combines Global Secure Access and Conditional Access to block a specified unauthorized website, such as an unsanctioned AI app, while entitlement management provides governed access to users who should be exempt. It is a documented configuration pattern for web applications without provisioning or federation support, not a standalone feature announcement.

  • The updated Entra ID page describes Linux desktop users registering devices with Entra ID, enrolling those devices into Intune, and satisfying device-based Conditional Access when accessing corporate resources. Because the record is marked Updated and gives no availability label, treat it as implementation guidance rather than a new preview or GA claim.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

37 updates

5

Authenticate Application Id

Updated

Microsoft Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Microsoft Entra Connect. This account uses a username and password to authenticate requests.

Resilience For Federated Applications With Colocated Users

Updated

One scenario that many organizations [building for resilience](resilience-overview.md) in their identity and access management architecture need to accommodate is continuity of application access during temporary site disconnection. The organization may have one or more physical sites at which their applications are deployed. Some of their users are colocated at those sites and need to be able to access local applications. For example, employees at a factory or at a store may need to be able to sign-in to in-house-developed business applications managing operations at that site.

Refresh Tokens

Updated

| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |

5

Migrate to cloud authentication using Staged Rollout

Updated

Staged Rollout lets you gradually test cloud authentication features with selected user groups. These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains.

Custom authentication extensions overview

Updated

The Microsoft Entra ID authentication pipeline consists of several built-in authentication events, like the validation of user credentials, Conditional Access policies, multifactor authentication, self-service password reset, and more.

Sso Linux

Updated

This feature empowers users on Linux desktop clients to register their devices with Microsoft Entra ID, enroll into Intune management, and satisfy device-based Conditional Access policies when accessing their corporate resources.

Whats New

Updated

**Service category:** Conditional Access

5

21912

Removed

A Microsoft Entra documentation page was updated: 21912.

2
2

Data Residency

Updated

Microsoft Entra ID is an Identity as a Service (IDaaS) solution that stores and manages identity and access data in the cloud. You can use the data to enable and manage access to cloud services, achieve mobility scenarios, and secure your organization. An instance of the Microsoft Entra ID service, called a [tenant](~/identity-platform/developer-glossary.md#tenant), is an isolated set of directory object data that the customer provisions and owns.

2
2

Getthere Tutorial

Updated

To configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:dataintegration@serko.com). They set this setting to have the SAML SSO connection set properly on both sides.

Error Codes

Updated

| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |

1
1
1
1

Entitlement Management Global Secure Access Restrict Employee Access

Updated

In this scenario, you set up Global Secure Access and Conditional Access to block access to a specific unauthorized website such as an unsanctioned AI app, while using entitlement management to provide governed access to users who should be exempt from the policy. This scenario is useful for generative AI applications and other web applications that don't support provisioning or federation with Microsoft Entra.

1
2

B2b Tutorial Require Mfa

Updated

1. Access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.

Supported Features Customers

Updated

| **Types of application registration** | <ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li><li>Enterprise applications offer [more options](../../identity/enterprise-apps/plan-sso-deployment.md), like password-based, linked, and header-based.</li></ul> |<ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li></ul>|

1

Leave The Organization

Updated

- If you're using a personal account or email one-time passcode, you'll need to use a My Account URL that includes your tenant name or tenant ID.

1

Faq Customers

Updated

Effective May 1, 2025 Azure AD B2C P1 and P2 will no longer be available to purchase for new customers, but current Azure AD B2C customers can continue using the product. The product experience, including creating new tenants or user flows, remains unchanged. The operational commitments, including service level agreements (SLAs), security updates, and compliance, also remain unchanged. We'll continue supporting Azure AD B2C until at least May 2030. More information, including migration plans will be made available. Contact your account representative for more information and to learn more about Microsoft Entra External ID.

1

Retire Service Principal Less Authentication

Updated

This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-rest-beta&preserve-view=true)). Service principal-less authentication can be abused if the resource applications (i.e. APIs) perform incomplete validations. Microsoft has verified that validations aren't vulnerable to service principal-less authentication. However, with this action, the risk of this gap reappearing in future versions or being exploited in third-party resources outside Microsoft’s control is minimized.

2

Manage Ssh Server Administration

Updated

Secure Shell (SSH) is widely recognized across the IT industry as a critical service for system administrators. It provides a secure and encrypted method to access and manage remote systems over unsecured networks.

1

Transport Layer Security

Updated

:::image type="content" source="media/how-to-transport-layer-security/security-profile-baseline.png" alt-text="Screenshot of the Edit Baseline profile screen showing a list of policy names and their priorities.":::

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…