1. Is the Connect server in [staging mode](how-to-connect-sync-staging-server.md)? A server in staging mode does not synchronize any passwords.
Microsoft Entra secure-by-default changes will block legacy authentication and tighten third-party app consent
The most consequential item on 19 July is a Microsoft 365 Message Center major update affecting Entra ID defaults: legacy authentication protocols will be blocked and admin consent will be required for third-party app access, with rollout starting in mid-July and completing by August 2025. The other two entries are ordinary Microsoft Entra Connect password hash synchronization documentation updates, clarifying staging-mode behavior and password-policy enforcement rather than announcing a new feature, preview, GA release, or retirement.
- Upcoming defaults will block legacy authentication and require admin consent for third-party apps
Entra ID · Authentication
The Microsoft 365 Message Center labels this a Major update. Microsoft plans to change default settings so legacy authentication protocols are blocked and third-party app access requires admin consent. The rollout is scheduled to begin in mid-July 2025 and complete by August 2025; this is an upcoming security-default behavior change, not evidence that the rollout is already complete.
- Password hash synchronization troubleshooting clarifies that staging servers sync no passwords
Entra ID · Authentication
An updated Microsoft Entra Connect troubleshooting page explicitly states that a server in staging mode does not synchronize any passwords. This is documentation clarification of an operational condition, not a reported change to Connect behavior; it is relevant when investigating missing password synchronization or validating a staged-server rollout.
- Updated guidance explains password-policy enforcement for password-synced users
Entra ID · Authentication
The updated Password Hash Synchronization documentation describes the Cloud Password Policy for Password-Synced Users capability: Microsoft Entra ID enforces native policies such as expiration and lockout for users whose passwords are synchronized from on-premises Active Directory, enabling alignment with the on-premises policy. The entry provides clarified capability guidance and does not announce new availability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
2 updates
Microsoft Entra ID
2 updatesThe Cloud Password Policy for Password-Synced Users feature ensures that Microsoft Entra ID enforces its native password policies (such as expiration and lockout), for users whose passwords are synchronized from on-premises Active Directory. This feature enables you to align the same on-premises Active Directory password policy with the Microsoft Entra password policy, for synchronized users.
