If you're using a federated Identity Provider (IdP), such as Active Directory Federation Services, and your MFA provider is integrated directly with this federated IdP, the federated IdP must be configured to send an MFA claim. For more information, see [Expected inbound assertions for Microsoft Entra MFA](how-to-mfa-expected-inbound-assertions.md).
Action required: reshare SharePoint OTP content shared before Entra B2B integration
The period's most consequential item is a Microsoft 365 Message Center major update for External ID: effective 1 July 2025, external users will lose access to content shared through SharePoint One Time Passcode before SharePoint and OneDrive integration with Microsoft Entra B2B was enabled. Resharing is required to restore access. The other supplied evidence consists of 100 documentation updates, with no new or removed entries, primarily clarifying authentication procedures and delegated role scope rather than announcing a new feature, preview, GA release, or retirement.
- SharePoint OTP shares are subject to a changed access behavior
External ID · Troubleshooting
Major update: effective 1 July 2025, external users will lose access to content shared via SharePoint One Time Passcode before Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B was enabled. Resharing is required to restore access; the notice also calls for user notification and internal documentation updates.
- Federated MFA guidance requires an MFA claim
Entra ID · Authentication
Security guidance clarification: when a federated identity provider such as AD FS is used and the MFA provider is integrated directly with that provider, the federated IdP must send an MFA claim. The supplied update points administrators to the expected inbound assertions guidance; it does not establish a newly shipped enforcement change.
- Android QR-code PIN authentication documentation adds the policy setting
Entra ID · Authentication
Implementation guidance identifies the Authentication Policy Administrator as configuring an Intune app configuration policy for Microsoft Authenticator on managed Android Enterprise devices, with `sdm_suppress_camera_consent` set to `true`, alongside the documented `preferred_auth_method` configuration. This is setup documentation, not evidence of a changed default or a new availability event.
- Global Secure Access administrator boundaries are clarified
Global Secure Access · Conditional Access
The updated role reference explicitly lists enterprise applications, application registrations, Conditional Access, and application proxy settings as areas the Global Secure Access Administrator cannot manage. Use this clarification when reviewing delegated administration; the item is a documentation update and does not by itself prove a change to the permission model.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
100 updates
Microsoft Entra ID
62 updatesAuthentication Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
This is configured by the Authentication Policy Administrator through an [app configuration policy for managed Android Enterprise devices](/mem/intune/apps/app-configuration-policies-use-android) on the Microsoft Authenticator App, setting `sdm_suppress_camera_consent` equal to `true`, similar to how the `preferred_auth_method` is configured.
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
- Create and manage all aspects of custom authentication extensions.
Global Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Helpdesk Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).
Refresh Tokens
Updated| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |
Password Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).
Learn how to access and analyze Microsoft Entra sign-in and audit logs with the Microsoft Graph reporting APIs.
How to download the audit, sign-in, and provisioning log data for manual storage in Microsoft Entra ID.
Learn how to troubleshoot sign-in errors using Microsoft Entra reports in the Microsoft Entra admin center
How to use the Sign-in diagnostic in tool Microsoft Entra ID to troubleshoot sign-in related scenarios.
Learn about how flagged the sign-ins feature can be used for troubleshooting sign-in issues in Microsoft Entra ID.
Learn about the information available on each of the tabs on the Microsoft Entra sign-in log activity details.
author: msmimart
author: msmimart
User Administrator
Updated> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
Directory Writers
Updated> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
Cloud Device Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Domain Name Administrator
Updated> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
Iot Device Administrator
UpdatedAssign the IoT Device Administrator role to users who need to do the following tasks:
> [!div class="mx-tableFixed"]
Teams Reader
Updated> [!div class="mx-tableFixed"]
Attack Payload Author
UpdatedUsers in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation. Access to reports is limited to simulations executed by the user, and this role doesn't grant access to aggregate reports such as Training efficacy, Repeat offenders, Training completion, or User coverage.
Learn how to configure the Microsoft Entra health monitoring email notifications to monitor and improve the health of your tenant.
Attribute Log Administrator
UpdatedUsers with this role **cannot** read audit logs for other events.
How to choose the right method for accessing and integrating the activity logs in Microsoft Entra ID.
Learn how to customize the columns and filter of the Microsoft Entra activity logs so you can analyze the results.
Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.
Learn how to use the Microsoft Entra recommendations to monitor and improve the health of your tenant.
Howto Use Workbooks
UpdatedLearn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.
Learn how to stream Microsoft Entra activity logs to an event hub for SIEM tool integration and analysis.
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
Custom Extension Overview
Updatedmanager: CelesteDG
Intune Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).
Learn about the types of activities and events that are captured in Microsoft Entra audit logs and how you can use the logs for troubleshooting.
Monitoring Health
UpdatedLearn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.
Usage and insights report
UpdatedLearn about the information you can explore using the Usage and insights report in Microsoft Entra ID.
Learn about the details included in the user provisioning logs in Microsoft Entra ID when a non-Microsoft service provisions users.
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
Partner Tier2 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Partner Tier1 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Application Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
Security Administrator
Updated> | microsoft.directory/applications/policies/update | Update policies of applications |
Attribute Assignment Reader
UpdatedUsers with this role can read custom security attribute keys and values for supported Microsoft Entra objects.
Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.
Attribute Definition Reader
UpdatedUsers with this role can read the definition of custom security attributes.
Security Operator
Updated> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
Learn how to configure SAML single sign-on between Microsoft Entra ID and a GitHub enterprise with Enterprise Managed Users.
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String||
Global Reader
Updated> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
author: MicrosoftGuyJFlo
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
> [!IMPORTANT]
Users with this role cannot read audit logs for other events. This role must be used in conjunction with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.
Attribute Log Reader
Updated- Configure diagnostic settings for custom security attributes
Learn how to archive Microsoft Entra activity logs to a storage account through Diagnostic settings.
Application Developer
Updated> | Actions | Description |
Microsoft Entra ID Protection
1 updateUsers with this role have all permissions in the Azure Information Protection service. This role allows configuring labels for the Azure Information Protection policy, managing protection templates, and activating protection. This role doesn't grant any permissions in Microsoft Entra ID Protection, Privileged Identity Management, Monitor Microsoft 365 Service Health, Microsoft Defender XDR portal, or Microsoft Purview portal.
Microsoft Entra ID Governance
22 updatesSecurity Reader
Updated> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
A Microsoft Entra documentation page was updated: Check Workflow Execution Scope.
Create Lifecycle Workflow
UpdatedA Microsoft Entra documentation page was updated: Create Lifecycle Workflow.
Customize Workflow Email
UpdatedA Microsoft Entra documentation page was updated: Customize Workflow Email.
Customize Workflow Schedule
UpdatedA Microsoft Entra documentation page was updated: Customize Workflow Schedule.
Delete Lifecycle Workflow
UpdatedA Microsoft Entra documentation page was updated: Delete Lifecycle Workflow.
Download Workflow History
UpdatedA Microsoft Entra documentation page was updated: Download Workflow History.
Lifecycle Workflow Audits
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Audits.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Execution Conditions.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Extensibility.
Lifecycle Workflow History
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow History.
Lifecycle Workflow Insights
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Insights.
A Microsoft Entra documentation page was updated: Lifecycle Workflow On Premises.
Lifecycle Workflow Tasks
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Tasks.
Lifecycle Workflow Templates
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Templates.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Versioning.
> | --- | --- |
On Demand Workflow
UpdatedA Microsoft Entra documentation page was updated: On Demand Workflow.
What Are Lifecycle Workflows
UpdatedA Microsoft Entra documentation page was updated: What Are Lifecycle Workflows.
Workflows Faqs
UpdatedA Microsoft Entra documentation page was updated: Workflows Faqs.
Microsoft Entra External ID
7 updatesB2c Ief Policy Administrator
UpdatedUsers in this role have the ability to create, read, update, and delete all custom policies in Azure AD B2C and therefore have full control over the Identity Experience Framework in the relevant Azure AD B2C organization. By editing policies, this user can establish direct federation with external identity providers, change the directory schema, change all user-facing content (HTML, CSS, JavaScript), change the requirements to complete an authentication, create new users, send user data to external systems including full migrations, and edit all user information including sensitive fields like passwords and phone numbers. Conversely, this role cannot change the encryption keys or edit the secrets used for federation in the organization.
Training Videos
UpdatedThe video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verifications.
This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:
B2c Ief Keyset Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users assigned to this role can create and manage policy keys and secrets used for token encryption, token signing, and claim encryption/decryption. They can add new keys to existing key containers, enabling secret rollover without affecting existing applications. Additionally, users in this role can view the complete details of these secrets, including their expiration dates, even after creation.
Users with this role add or delete custom attributes available to all user flows in the Microsoft Entra organization. As such, users with this role can change or add new elements to the end-user schema and impact the behavior of all user flows, and indirectly result in changes to what data may be asked of end users and ultimately sent as claims to applications. This role can't edit user flows.
- Organizations that own multiple Microsoft Entra tenants and want to streamline intra-organization cross-tenant application access.
> Cross-cloud synchronization is currently in PREVIEW.
Microsoft Entra Verified ID
2 updatesmanager: femila
Issuer Revoke
Updatedmanager: femila
Microsoft Entra Workload ID
3 updatesLearn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.
author: barclayn
Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
Microsoft Entra Global Secure Access
3 updates- Cannot manage enterprise applications, application registrations, Conditional Access, or application proxy settings
Version History
Updated| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |
Assign the Global Secure Access Log Reader role to users who need to do the following:
