← Previous day

Next day →
Day in brief

Documentation, not rollout: Conditional Access agent guidance and a one-way Graph-sync caveat lead 11 July

The 11 July 2025 record contains 130 updates and no new, removed, or Message Center entries. The most consequential material is specific documentation guidance: administrators are told to review Conditional Access optimization-agent suggestions, the Connect Microsoft Graph page clarifies UPN synchronization and an irreversible enablement constraint, and updated Entra ID pages cover consent follow-up and hardware OATH-token operations. Nothing supplied establishes a new feature, preview, general-availability milestone, retirement, or service-side behavior change; the remaining examples are largely role-reference or other low-detail maintenance updates.

  • The updated Entra ID how-to says suggestions vary with what the agent finds and that the administrator must review them and decide what to do. A related Security Copilot page describes the agent as recommending policies and changes aligned with Zero Trust to help protect users and applications. Because both records are documentation updates, they should not be read as evidence of a new launch, preview, or availability change.

  • The page says existing userPrincipalName values remain unchanged when the documented feature is enabled; a later on-premises change to userPrincipalName causes normal delta sync to update the UPN. It also states that the feature cannot be disabled after enablement. This is a behavior clarification with a concrete rollout-planning consequence, not a reported service change.

  • The updated Manage Consent Requests guidance calls for follow-up steps after disabling or restricting user consent: keep business-critical applications usable, limit impact on support and IT administrators, and help prevent unmanaged accounts in non-Microsoft applications. This is security and operational guidance; the record does not indicate that the consent setting itself changed.

  • The updated Entra ID topic covers hardware OATH tokens and identifies Microsoft Graph APIs to upload, activate, and assign them. That is a useful reference clarification for token administrators, but the supplied evidence does not claim a new API, changed availability, or a required tenant configuration change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

130 updates

86

Connect Microsoft Graph

Updated

After enabling this feature, existing userPrincipalName values remain as-is. On next change of the userPrincipalName attribute on-premises, the normal delta sync on users updates the UPN. Once this feature is enabled, it's not possible to disable it.

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

Directory Writers

Updated

A Microsoft Entra documentation page was updated: Directory Writers.

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

Connect Version History

Updated

> New Microsoft Entra Connect Sync Versions are only available via the Microsoft Entra admin center

8
7

Agent Optimization Logs Metrics

Updated

- To view the Microsoft Entra audit logs, you need at least the [Reports reader](../../identity/role-based-access-control/permissions-reference.md#reports-reader) role.

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

5

Security Operator

Updated

A Microsoft Entra documentation page was updated: Security Operator.

Security Reader

Updated

A Microsoft Entra documentation page was updated: Security Reader.

3

Manage Consent Requests

Updated

After disabling or restricting user consent, you have several important steps to take to help keep your organization secure as you continue to allow business-critical applications to be used. These steps are crucial to minimize impact on your organization's support team and IT administrators, and to help prevent the use of unmanaged accounts in non-Microsoft applications.

3
2
2

Add Application Portal Setup Sso

Updated

Microsoft Entra ID has a gallery that contains thousands of preintegrated applications that use SSO. This article uses an enterprise application named **Microsoft Entra SAML Toolkit 1** as an example, but the concepts apply for most preconfigured enterprise applications in the Microsoft Entra application gallery.

1
1
1
2

Entitlement Management Access Package Visibility

Updated

The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."

5
1
1
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…