← Previous day

Next day →
Day in brief

Temporary Access Pass prerequisite clarified; RBAC, security, and governance guidance refreshed

28 June 2025 was primarily a documentation-maintenance day: all 154 recorded changes were updates, with no new or removed items and no Message Center announcements. The supplied representative changes are dominated by Entra role and permissions reference edits, alongside a few more substantive clarifications covering Temporary Access Pass enrollment, Insider Risk in Conditional Access, access-package access removal, and sign-in branding. Nothing in the evidence identifies a new preview, general-availability release, retirement, or tenant-wide rollout.

  • The updated Temporary Access Pass guidance states that users on hybrid-joined devices must first authenticate with another method, such as a password, smartcard, or FIDO2 key, before using TAP to set up Windows Hello for Business. This is an operational documentation clarification, not evidence of a new feature or policy rollout. Update enrollment and support procedures that cover this flow.

  • The updated Permissions Reference states that Authentication Administrator can view, set, and reset authentication-method information for any non-admin user. The supplied record shows a reference-page update, but does not establish that the underlying built-in role permissions or existing assignments changed. Administrators relying on delegated authentication support should verify the current role definition before making access changes.

  • The updated guidance explains how to protect a tenant by enabling the Insider Risk condition in Conditional Access integrated with Microsoft Purview Adaptive Protection. This is security guidance; the evidence does not identify the capability as a new preview or generally available release. Security teams evaluating this integration should review the updated instructions.

  • The Access Package Resources documentation states that when an access package assignment is lost, the user is removed from all resource roles in that access package. This clarifies the documented access-removal semantics; it does not show that the product behavior changed on 28 June. Governance owners can use the rule when validating expected access removal.

  • The Customize Branding page announces a future change to the default background image behind the sign-in box. It explicitly says the change is image-only, requires no action, and does not affect functionality. The practical consideration is to refresh training or documentation screenshots that need to match the exact sign-in experience.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

154 updates

77

Global Administrator

Updated

> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |

User Administrator

Updated

> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |

Directory Writers

Updated

> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |

Cloud Device Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

19

Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

Permissions Reference

Updated

> | [Authentication Administrator](#authentication-administrator) | Can access to view, set and reset authentication method information for any non-admin user.<br/>[![Privileged label icon.](./media/permissions-reference/privileged-label.png)](privileged-roles-permissions.md) | c4e39bd9-1100-46d3-8c65-fb160da0071f |

Howto Authentication Temporary Access Pass

Updated

For hybrid-joined devices, users must first authenticate with another method such as a password, smartcard or FIDO2 key, before using TAP to set up Windows Hello for Business.

Customize Branding

Updated

The default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).

10

How to manage inactive user accounts

Updated

Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.

Howto Use Workbooks

Updated

Learn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

3

Partner Tier2 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

Partner Tier1 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

Hybrid Identity Administrator

Updated

> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |

3

Whats New

Updated

>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your ![RSS feed reader icon](./media/whats-new/feed-icon-16x16.png) feed reader.

Monitoring Health

Updated

Learn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.

Workbooks

Updated

Learn how to create and work with Microsoft Entra workbooks, for identity monitoring, alerts, and data visualization.

3
3
3

Security Administrator

Updated

> | microsoft.directory/applications/policies/update | Update policies of applications |

3

Security Operator

Updated

> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |

Global Reader

Updated

> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |

2
1
1
17

Security Reader

Updated

> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |

Entitlement Management Access Package Request Policy

Updated

When you create an access package, you can specify the request, approval and lifecycle settings, which are stored on the first policy of the access package. Most access packages have a single policy for users to request access, but a single access package can have multiple policies. You would create multiple policies for an access package if you want to allow different sets of users to be granted assignments with different request and approval settings.

Entitlement Management Access Package First

Updated

:::image type="content" source="./media/entitlement-management-access-package-first/resource-roles.png" alt-text="Screenshot the shows how to select the member role." lightbox="./media/entitlement-management-access-package-first/resource-roles.png":::

Privileged Role Administrator

Updated

> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |

1
5
1

Copilot Security Entra Investigate Risky Apps

Updated

Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…