← Previous day

Next day →
Day in brief

3 July 2025: Agent ID MFA-policy guidance and Microsoft.Identity.Client deprecation notes lead a documentation-heavy Entra update

All 125 reported items were updates; none were new or removed, and there were no Message Center entries. The most consequential content is in existing guidance: Agent ID’s Agent Optimization page describes finding users outside MFA-requiring Conditional Access coverage and updating the policy, while Entra ID guidance calls out required application changes around Microsoft.Identity.Client and a public-client API deprecated as of release 4.73.1. Other specific updates clarify ROPC flow behavior, Verified ID policy matching, and External ID logout semantics. The supplied evidence contains no preview or general-availability announcement, retirement, or tenant-wide behavior change; many remaining representative updates are generic built-in-role reference-page refreshes.

  • Classification: documentation describing an agent workflow, not a reported launch. The updated Agent Optimization page says the agent identifies users who are not covered by a Conditional Access policy requiring MFA and can update that policy. Tenants considering the workflow should review the target policies and expected MFA coverage before applying it; the item does not report an automatic tenant change.

  • Classification: application compatibility and deprecation guidance. The updated Mandatory Multifactor Authentication page says changes are required when an application uses the Microsoft.Identity.Client package with one of the affected APIs, and identifies the public client API as deprecated as of the 4.73.1 release. This is application-maintenance guidance, not evidence of a tenant-side MFA policy change.

  • Classification: protocol-behavior documentation clarification. The updated MSAL Authentication Flows page describes the OAuth 2.0 resource owner password credentials grant as an application directly handling the user’s password, and says a desktop application can acquire a token silently through the username/password flow without UI. The update does not state that ROPC was newly introduced, recommended, or retired.

  • Classification: policy-semantics clarification. Selecting multiple credential types from one issuer requires users to present all selected types; selecting multiple issuers requires credentials from each included issuer. The documented way to offer alternatives is to configure separate policies for each issuer or credential type.

  • Classification: supported-behavior clarification. The updated supported-features information states that when a SAML or OpenID Connect application directs a user to the logout endpoint, Microsoft Entra ID removes and invalidates the user’s browser session, matching workforce behavior. No rollout or newly changed service behavior is reported.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

126 updates

83

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

Directory Writers

Updated

A Microsoft Entra documentation page was updated: Directory Writers.

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

8

Mandatory Multifactor Authentication

Updated

Changes are required if you use the [Microsoft.Identity.Client](https://www.nuget.org/packages/Microsoft.Identity.Client) package and one of the following APIs in your application. The public client API is **deprecated** [as of the 4.73.1 release](https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/main/CHANGELOG.md):

Msal Authentication Flows

Updated

The [OAuth 2.0 resource owner password credentials](v2-oauth-ropc.md) (ROPC) grant allows an application to sign in the user by directly handling their password. In your desktop application, you can use the username/password flow to acquire a token silently. No UI is required when using the application.

5

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

5

Security Operator

Updated

A Microsoft Entra documentation page was updated: Security Operator.

Security Reader

Updated

A Microsoft Entra documentation page was updated: Security Reader.

3
2
1
1
1
1
1
1
1

Agent Optimization

Updated

- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.

2

Entitlement Management Verified Id Settings

Updated

> If you select multiple credential types from one issuer, users will be required to present credentials of all selected types. Similarly, if you include multiple issuers, users will be required to present credentials from each of the issuers you include in the policy. To give users the option of presenting different credentials from various issuers, configure separate policies for each issuer/credential type you’ll accept.

6
1
1
1

Supported Features Customers

Updated

| **Sign-out** | When a [SAML](../../identity-platform/single-sign-out-saml-protocol.md) or [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#send-a-sign-out-request) application directs the user to the logout endpoint, Microsoft Entra ID removes and invalidates the user's session from the browser. | Same as workforce.|

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…