author: justinha
25 June 2025: Entra guidance sharpens PKI-based authentication, cross-cloud synchronization, and guest licensing—without signaling a new rollout
All 19 recorded changes were updates to Microsoft Learn documentation; there were no new or removed items and no Message Center announcements. The clearest substantive updates clarify Entra ID certificate-based authentication, External ID cross-tenant synchronization between Microsoft clouds, and Microsoft Entra ID Governance licensing for guests. The supplied evidence does not indicate a general-availability launch, retirement, or tenant-wide behavior change. The updated Mandatory Multifactor Authentication page contains no substantive change detail beyond author metadata, so no MFA policy or rollout change can be inferred.
- Entra certificate-based authentication guidance emphasizes the PKI-based trust store (Preview)
Entra ID · Authentication
The updated CA-configuration article calls the PKI-based trust store the best way to configure certificate authorities and notes that configuration can be delegated to least-privileged roles. This is a documentation and security-guidance clarification; the evidence does not show that the preview became generally available or that service behavior changed.
- External ID documentation covers cross-tenant synchronization between commercial and Azure Government clouds
External ID · Provisioning
The updated configuration guidance describes synchronization between Microsoft clouds, including Microsoft Azure commercial and Azure Government, and says Microsoft Entra ID provisions and de-provisions B2B users in the target tenant. This clarifies documented scope and setup rather than announcing a new launch.
- ID Governance licensing guidance calls out guest MAU licensing
ID Governance · Fundamentals
The updated fundamentals page states that guest users use Monthly Active User licensing rather than employee licensing and that an Azure subscription is required. The supplied evidence supports a licensing-documentation clarification, not a pricing or entitlement change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
19 updates
Microsoft Entra ID
14 updatesHow to configure certificate authorities for Microsoft Entra certificate-based authentication
UpdatedThe best way to configure the certificate authorities (CAs) is with the PKI-based trust store (Preview). You can delegate configuration with a PKI-based trust store to least privileged roles. For more information see, [Step 1: Configure the certificate authorities with PKI-based trust store (Preview)](how-to-certificate-based-authentication.md#step-1-configure-the-certificate-authorities-with-pki-based-trust-store).
Whats New Archive
Updated**Service category:** Authentications (Logins)
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Authenticate Application Id
UpdatedEntra Connect provides three options for application and certificate management:
When you configure group writeback, a checkbox appears at the bottom of the configuration window. Select it to enable this feature.
category:
Updatedmanager: pmwongera
Configure User Consent
Updated:::zone pivot="ms-powershell"
Confluencemicrosoft Tutorial
Updated- Confluence: 6.0.1 to 6.15.9
Digicert Tutorial
UpdatedTo configure the integration of DigiCert into Microsoft Entra ID, you need to add DigiCert from the gallery to your list of managed SaaS apps.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).
Admin Audit Logging
Updated|Event ID|Event name|Description|
|name.givenName|String||✓|
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber|String||✓
Microsoft Entra ID Governance
1 updateLicensing Fundamentals
UpdatedMicrosoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees and requires an Azure subscription.
Microsoft Entra External ID
2 updates- Cross-tenant synchronization is supported within the commercial cloud and Azure Government.
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
Microsoft Entra Global Secure Access
2 updatesInstall Macos Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
Macos Client Release History
UpdatedThis article tracks the changes in each released version of the Global Secure Access client for macOS.
