To create a PKI container object:
Microsoft Entra sign-in background scheduled for a visual refresh; authentication-flow and B2B security guidance were clarified
4 July was documentation-heavy: 16 Microsoft Learn articles were updated, with no new or removed items recorded, alongside one Message Center notice. The clearest operational change is a planned visual update to the Work or School sign-in experience. The most substantive documentation updates clarify protocol-tracked authentication sessions, reinforce tenant-restriction guidance for external accounts, and describe the Conditional Access optimization agent. The supplied evidence does not identify a preview, general availability launch, or retirement.
- Work or School sign-in background will receive a visual update
External ID · Authentication
Microsoft Entra is updating the default sign-in background for Work or School accounts to align with Microsoft’s Fluent design language. The rollout is stated to run from late September to early October 2025. This is a user-interface change rather than a new authentication capability; no action is required, although internal documentation and help-desk materials should be updated to reduce confusion.
- Protocol tracking clarifies authentication-flow policy enforcement
Entra ID · Conditional Access
The updated Entra ID Authentication Flows guidance explains that sessions using device code flow or authentication transfer are marked as protocol tracked, that this state persists through subsequent refreshes, and that later flows that are not themselves device-code or authentication-transfer flows can still be subject to authentication-flow policies. This is a documentation clarification of enforcement behavior, not evidence of a newly released policy feature.
- B2B guidance reinforces tenant restrictions for external accounts
External ID · Fundamentals
Updated Microsoft Entra External ID guidance says tenant restrictions can prevent users from using accounts created in unknown tenants or accounts received from external organizations. It recommends disallowing those accounts and using B2B collaboration instead. This is security guidance for reviewing external-account controls, not a reported product launch or tenant-wide policy change.
- Conditional Access optimization agent is documented without a stated release status
Entra ID · Conditional Access
The updated Entra ID Agent Optimization article describes a Conditional Access optimization agent that recommends policies and changes based on best practices aligned with Zero Trust and Microsoft’s experience. The supplied evidence identifies an updated article only; it does not establish that the capability is new, in preview, or generally available.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
16 updates
Microsoft Entra ID
12 updates- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.
How to configure certificate authorities for Microsoft Entra certificate-based authentication
Updatedauthor: vimrang
Howto Mfa Mfasettings
UpdatedFraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.
Agent Optimization
UpdatedThe Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
Authentication Flows
UpdatedTo ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.
This article shows the new and updated documentation for the Microsoft Entra application management.
Getty Images Tutorial
Updated1. If you wish to configure the application in **SP** initiated mode, then perform the following step:
Sla Performance
Updated| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |
| Attribute Name | User | Comment |
Configurable Token Lifetimes
UpdatedLearn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
> Error code 1002013 indicates an expected (and successful) interrupt of the sign-up flow. [Learn more](howto-troubleshoot-sign-up-errors.md#sign-up-error-codes)
Microsoft Entra External ID
3 updates1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
B2b Fundamentals
Updated| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
New and updated documentation for the Microsoft Entra External ID.
Configure Connectors
Updated- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).
