← Previous day

Next day →
Day in brief

29 June: External ID B2B controls, Agent Optimization exceptions, and security guidance were clarified

The supplied feed is update-only: 89 items were updated, with no new or removed items and no Message Center notices. The strongest changes are documentation clarifications and security or operational guidance—not evidence of a new feature, preview, general-availability release, retirement, or broad behavior change. A large share of the remaining edits concern role and permissions reference pages.

  • The B2B example states that allowing Fabrikam in cross-tenant access settings while blocking fabrikam.com prevents new Fabrikam business-guest invitations, but existing Fabrikam guests can continue using B2B collaboration. This is a documentation clarification of policy interaction, not evidence of newly changed enforcement behavior.

  • The updated Service Limits page lists 300,000 total user accounts and applications per tenant and directs administrators to Microsoft Support if an increase is needed. The evidence supports a published-limit clarification, not a quota change.

  • The Entra ID Agent Optimization update describes an optional Custom Instructions field that supplies a prompt to the agent. It can be used to include or exclude users, groups, and roles, or to add exceptions to a suggested policy. This is capability guidance in an updated page, not a launch or availability announcement.

  • The updated Sign-ins using legacy authentication workbook page explains that the workbook can identify applications using legacy methods. This is security and operational guidance; the supplied evidence does not announce a legacy-authentication retirement or enforcement date.

  • The SSPR Policy update states that Password expiry, or Let passwords never expire, has a default value of false, meaning passwords have an expiration date, and that the value can be configured for individual accounts with Update-MgUser. This is documentation clarification and does not show that existing accounts were changed.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

89 updates

26

Global Administrator

Updated

> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |

User Administrator

Updated

> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |

Directory Writers

Updated

> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |

Cloud Device Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

Agent Optimization

Updated

You can tailor the policy to your needs using the optional **Custom Instructions** field. This setting allows you to provide a prompt to the agent as part of its execution. For example: "The user "Break Glass" should be excluded from policies created." Custom instructions can be used to include or exclude users, groups, and roles. This can be used to exclude them from consideration entirely or for a specific scenario and can also be used to add exceptions to the suggested policy.

14

Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

Sspr Policy

Updated

| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |

9

Workbook Risk Analysis

Updated

Learn how to use the identity protection risk analysis workbook in Microsoft Entra ID to explore trends and gaps in your risk policies.

Workbook Mfa Gaps

Updated

Learn how to use the MFA Gaps workbook in Microsoft Entra ID to identify apps and users who aren't protected by MFA.

7

Audit Activities

Updated

Get an overview of the audit activities that can be logged in your audit logs in Microsoft Entra ID.

6
3

Partner Tier2 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

Partner Tier1 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

Hybrid Identity Administrator

Updated

> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |

2
2
2

Security Administrator

Updated

> | microsoft.directory/applications/policies/update | Update policies of applications |

2

Security Operator

Updated

> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |

Global Reader

Updated

> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |

1
1
4

Security Reader

Updated

> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |

Privileged Role Administrator

Updated

> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |

2

B2b Fundamentals

Updated

| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |

What Is B2b

Updated

- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.

2
1

External Collaboration Settings Configure

Updated

For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.

1

Service Limits

Updated

|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |

1
2

Workbook Sensitive Operations Report

Updated

Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.

1

Service Principal Table

Updated

Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…