← Previous day

Next day →
Day in brief

Workload ID retires service principal-less authentication; Entra ID adds security guidance

The most consequential 16 July change affects Microsoft Entra Workload ID: authentication will be blocked for non-Microsoft multitenant applications that lack a service principal in the tenant where they authenticate. The behavior is already disabled for most non-Microsoft applications, and this update addresses the remaining exceptions as a preventive security measure. Two distinct new Entra ID security pages cover securing the MFA registration (My Security Info) page and restricting high-risk sign-ins, but the supplied records contain no procedures or enforcement details, so they should not be treated as feature launches. The remaining entries are primarily documentation maintenance for ID Governance Lifecycle Workflows, Entra security topics, and Microsoft Entra Private Access Multi-Geo guidance.

  • Microsoft Entra Workload ID will block authentication for non-Microsoft multitenant applications that do not have a service principal in the tenant where they authenticate. The entry says this behavior has already been disabled for most non-Microsoft applications and that the change addresses a few remaining exceptions as a preventive security measure. This is a security-related behavior retirement, not merely a documentation clarification.

  • A new Microsoft Learn page titled Secure the MFA registration (My Security Info) page was recorded under Entra ID Security. Its supplied summary contains only author metadata, so the evidence supports a new documentation page—not a claim that MFA registration behavior, a default, or a new control changed.

  • A new Microsoft Learn page titled Restrict high risk sign-ins was recorded under Entra ID Authentication. The supplied record provides no steps or policy details, so it does not establish a new risk-based sign-in feature, an enforcement change, or preview or general-availability status.

  • The Microsoft Entra Private Access Multi-Geo page was updated with guidance on enabling Multi-Geo Capability to optimize traffic flow from Microsoft Entra clients to Microsoft Entra apps. The evidence describes updated enablement guidance; it does not establish that Multi-Geo is newly launched or that its availability changed.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

12 updates

3
1
1

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

4

Customize Workflow Email

Updated

1. On the pane that lists tasks, select the task for which you want to customize the email.

Lifecycle Workflows Tasks Table

Updated

| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |

1

Whats New

Updated

**Service category:** Lifecycle Workflows

1
1

Retire Service Principal Less Authentication

Updated

Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…