author: shlipsey3
Workload ID retires service principal-less authentication; Entra ID adds security guidance
The most consequential 16 July change affects Microsoft Entra Workload ID: authentication will be blocked for non-Microsoft multitenant applications that lack a service principal in the tenant where they authenticate. The behavior is already disabled for most non-Microsoft applications, and this update addresses the remaining exceptions as a preventive security measure. Two distinct new Entra ID security pages cover securing the MFA registration (My Security Info) page and restricting high-risk sign-ins, but the supplied records contain no procedures or enforcement details, so they should not be treated as feature launches. The remaining entries are primarily documentation maintenance for ID Governance Lifecycle Workflows, Entra security topics, and Microsoft Entra Private Access Multi-Geo guidance.
- Workload ID: service principal-less authentication is being retired
Workload ID · Authentication
Microsoft Entra Workload ID will block authentication for non-Microsoft multitenant applications that do not have a service principal in the tenant where they authenticate. The entry says this behavior has already been disabled for most non-Microsoft applications and that the change addresses a few remaining exceptions as a preventive security measure. This is a security-related behavior retirement, not merely a documentation clarification.
- New guidance covers securing the MFA registration page
Entra ID · Security
A new Microsoft Learn page titled Secure the MFA registration (My Security Info) page was recorded under Entra ID Security. Its supplied summary contains only author metadata, so the evidence supports a new documentation page—not a claim that MFA registration behavior, a default, or a new control changed.
- New Entra ID page covers restricting high-risk sign-ins
Entra ID · Authentication
A new Microsoft Learn page titled Restrict high risk sign-ins was recorded under Entra ID Authentication. The supplied record provides no steps or policy details, so it does not establish a new risk-based sign-in feature, an enforcement change, or preview or general-availability status.
- Private Access Multi-Geo enablement guidance was updated
Private Access · General
The Microsoft Entra Private Access Multi-Geo page was updated with guidance on enabling Multi-Geo Capability to optimize traffic flow from Microsoft Entra clients to Microsoft Entra apps. The evidence describes updated enablement guidance; it does not establish that Multi-Geo is newly launched or that its availability changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
12 updates
Microsoft Entra ID
5 updatesauthor: shlipsey3
author: barclayn
author: shlipsey3
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
Microsoft Entra ID Governance
5 updatesCustomize Workflow Email
Updated1. On the pane that lists tasks, select the task for which you want to customize the email.
Lifecycle Workflow Tasks
Updated}
|Item|Description|
| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |
Whats New
Updated**Service category:** Lifecycle Workflows
Microsoft Entra Private Access
1 updateLearn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Microsoft Entra Workload ID
1 updateMicrosoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.
