author: owinfreyATL
29 June: External ID B2B controls, Agent Optimization exceptions, and security guidance were clarified
The supplied feed is update-only: 89 items were updated, with no new or removed items and no Message Center notices. The strongest changes are documentation clarifications and security or operational guidance—not evidence of a new feature, preview, general-availability release, retirement, or broad behavior change. A large share of the remaining edits concern role and permissions reference pages.
- External ID clarifies cross-tenant access and blocked-domain interaction
External ID · Fundamentals
The B2B example states that allowing Fabrikam in cross-tenant access settings while blocking fabrikam.com prevents new Fabrikam business-guest invitations, but existing Fabrikam guests can continue using B2B collaboration. This is a documentation clarification of policy interaction, not evidence of newly changed enforcement behavior.
- External ID service-limits documentation lists 300,000 total objects per tenant
External ID · Microsoft identity platform
The updated Service Limits page lists 300,000 total user accounts and applications per tenant and directs administrators to Microsoft Support if an increase is needed. The evidence supports a published-limit clarification, not a quota change.
- Agent Optimization guidance documents optional custom instructions
Entra ID · General
The Entra ID Agent Optimization update describes an optional Custom Instructions field that supplies a prompt to the agent. It can be used to include or exclude users, groups, and roles, or to add exceptions to a suggested policy. This is capability guidance in an updated page, not a launch or availability announcement.
- Legacy-authentication workbook guidance supports application discovery
Entra ID · Authentication
The updated Sign-ins using legacy authentication workbook page explains that the workbook can identify applications using legacy methods. This is security and operational guidance; the supplied evidence does not announce a legacy-authentication retirement or enforcement date.
- SSPR documentation clarifies the password-expiry default and per-user setting
Entra ID · Authentication
The SSPR Policy update states that Password expiry, or Let passwords never expire, has a default value of false, meaning passwords have an expiration date, and that the value can be configured for individual accounts with Update-MgUser. This is documentation clarification and does not show that existing accounts were changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
89 updates
Microsoft Entra ID
75 updatesGlobal Administrator
Updated> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |
User Administrator
Updated> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
Directory Writers
Updated> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
Permissions Reference
UpdatedA Microsoft Entra documentation page was updated: Permissions Reference.
Cloud Device Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Helpdesk Administrator
Updated> | --- | --- |
author: MicrosoftGuyJFlo
Agent Optimization
UpdatedYou can tailor the policy to your needs using the optional **Custom Instructions** field. This setting allows you to provide a prompt to the agent as part of its execution. For example: "The user "Break Glass" should be excluded from policies created." Custom instructions can be used to include or exclude users, groups, and roles. This can be used to exclude them from consideration entirely or for a specific scenario and can also be used to add exceptions to the suggested policy.
Assign Local Admin
Updatedauthor: owinfreyATL
Connect Version History
Updated> [!IMPORTANT]
Device Join Out Of Box
Updatedauthor: owinfreyATL
Device Join Plan
Updatedauthor: owinfreyATL
author: owinfreyATL
Device Registration Tls 1 2
Updatedauthor: owinfreyATL
author: owinfreyATL
Domain Name Administrator
Updated> [!div class="mx-tableFixed"]
author: owinfreyATL
author: owinfreyATL
Hybrid Join
Updatedauthor: owinfreyATL
Hybrid Join Control
Updatedauthor: owinfreyATL
Hybrid Join Manual
Updatedauthor: owinfreyATL
Hybrid Join Plan
Updatedauthor: owinfreyATL
Intune Administrator
Updated> | --- | --- |
Manage Device Identities
Updatedauthor: owinfreyATL
Manage Stale Devices
Updatedauthor: owinfreyATL
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Authentication Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Application Administrator
Updated> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> [!div class="mx-tableFixed"]
Learn how to use the authentication prompts analysis workbook in Microsoft Entra ID to investigate users getting too many MFA prompts.
Learn about the service level agreement performance and attainment for authentication services in Microsoft Entra ID
Learn how to use the sign-ins using legacy authentication workbook in Microsoft Entra ID to identify apps using legacy methods.
Sspr Policy
Updated| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |
author: owinfreyATL
author: owinfreyATL
Reference information for the factors that drive sign-in and audit log latency in Microsoft Entra ID
Learn about the data retention policies for the Microsoft Entra audit, sign-in, and provisioning logs.
Password Administrator
Updated> [!div class="mx-tableFixed"]
Workbook Risk Analysis
UpdatedLearn how to use the identity protection risk analysis workbook in Microsoft Entra ID to explore trends and gaps in your risk policies.
author: shlipsey3
author: shlipsey3
Reference information for Microsoft Graph PowerShell cmdlets for Microsoft Entra monitoring and health.
Learn how the Microsoft Entra recommendation to remove unused apps works and why you should follow the guidance.
Learn how the Microsoft Entra recommendation to remove unused credentials from apps works and why it's important.
Learn how the Microsoft Entra recommendation to renew expiring application credentials works and why it's important.
Learn why you should turn off per user MFA in Microsoft Entra ID with Microsoft Entra recommendations
Workbook Mfa Gaps
UpdatedLearn how to use the MFA Gaps workbook in Microsoft Entra ID to identify apps and users who aren't protected by MFA.
Whats New
UpdatedAudit Activities
UpdatedGet an overview of the audit activities that can be logged in your audit logs in Microsoft Entra ID.
Device Registration
Updatedauthor: owinfreyATL
Directory Join
Updatedauthor: owinfreyATL
Hybrid Join
Updatedauthor: owinfreyATL
Overview
Updatedauthor: owinfreyATL
Primary Refresh Token
Updatedauthor: owinfreyATL
author: owinfreyATL
Learn how Microsoft Entra audit logs display UserManagement updates from Core Directory during verified domain changes.
Troubleshoot Device Dsregcmd
Updatedauthor: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
Partner Tier2 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Partner Tier1 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
Learn how to use the Conditional Access gap analyzer workbook in Microsoft Entra ID to ensure resources are properly protected.
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
Security Administrator
Updated> | microsoft.directory/applications/policies/update | Update policies of applications |
author: shlipsey3
Security Operator
Updated> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
Global Reader
Updated> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
manager: dougeby
Application Developer
Updated> | Actions | Description |
Microsoft Entra ID Governance
4 updatesSecurity Reader
Updated> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
Entitlement Management Roles
Updated> [!NOTE]
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
> | --- | --- |
Microsoft Entra External ID
7 updatesB2b Fundamentals
Updated| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
What Is B2b
Updated- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.
> [!div class="mx-tableFixed"]
B2c Ief Keyset Administrator
Updated> [!div class="mx-tableFixed"]
For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.
Service Limits
Updated|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |
Learn how to use the cross-tenant access activity workbook in Microsoft Entra ID to monitor the resources your external users are accessing.
Microsoft Entra Workload ID
3 updatesLearn how the Microsoft Entra recommendation to renew expiring service principal credentials work and why it's important.
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
Service Principal Table
UpdatedReference table that maps application IDs to applications and their service principal usage from the sign-in logs.
