← Previous day

Next day →
Day in brief

Microsoft Entra sign-in background scheduled for a visual refresh; authentication-flow and B2B security guidance were clarified

4 July was documentation-heavy: 16 Microsoft Learn articles were updated, with no new or removed items recorded, alongside one Message Center notice. The clearest operational change is a planned visual update to the Work or School sign-in experience. The most substantive documentation updates clarify protocol-tracked authentication sessions, reinforce tenant-restriction guidance for external accounts, and describe the Conditional Access optimization agent. The supplied evidence does not identify a preview, general availability launch, or retirement.

  • Microsoft Entra is updating the default sign-in background for Work or School accounts to align with Microsoft’s Fluent design language. The rollout is stated to run from late September to early October 2025. This is a user-interface change rather than a new authentication capability; no action is required, although internal documentation and help-desk materials should be updated to reduce confusion.

  • The updated Entra ID Authentication Flows guidance explains that sessions using device code flow or authentication transfer are marked as protocol tracked, that this state persists through subsequent refreshes, and that later flows that are not themselves device-code or authentication-transfer flows can still be subject to authentication-flow policies. This is a documentation clarification of enforcement behavior, not evidence of a newly released policy feature.

  • Updated Microsoft Entra External ID guidance says tenant restrictions can prevent users from using accounts created in unknown tenants or accounts received from external organizations. It recommends disallowing those accounts and using B2B collaboration instead. This is security guidance for reviewing external-account controls, not a reported product launch or tenant-wide policy change.

  • The updated Entra ID Agent Optimization article describes a Conditional Access optimization agent that recommends policies and changes based on best practices aligned with Zero Trust and Microsoft’s experience. The supplied evidence identifies an updated article only; it does not establish that the capability is new, in preview, or generally available.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

16 updates

4

Howto Vm Sign In Azure Ad Windows

Updated

- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.

Howto Mfa Mfasettings

Updated

Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.

2

Agent Optimization

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

Authentication Flows

Updated

To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.

2

Getty Images Tutorial

Updated

1. If you wish to configure the application in **SP** initiated mode, then perform the following step:

1

Sla Performance

Updated

| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |

1
1

Configurable Token Lifetimes

Updated

Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.

1
1

Microsoft Accounts Federation Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

1

B2b Fundamentals

Updated

| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |

1
1

Configure Connectors

Updated

- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…