Microsoft Entra will enable browser access by default for all Android users, retiring the "Enable Browser Access" feature in Microsoft Authenticator and Company Portal apps. This hardware-bound device registration change requires no admin action and will roll out automatically worldwide. Organizations not using Android can ignore this update.
Android browser access becomes the default; most other 24 July changes are documentation clarifications
The period's consequential change is a Microsoft Entra Android device-registration behavior change: browser access will be enabled by default, while the corresponding setting in Microsoft Authenticator and Company Portal is retired. The other supplied records are Microsoft Learn updates covering reference, role, licensing, how-to, managed identity, SSO, and API documentation. Token Protection is the main security-relevant documentation exception; no supplied item announces a new feature, preview, or general availability release.
- Android browser access default and setting retirement
Entra ID · Authentication
Microsoft Entra will enable browser access by default for all Android users. Microsoft Authenticator and Company Portal will retire the "Enable Browser Access" feature as part of a hardware-bound device-registration change. Microsoft says the rollout is automatic worldwide and requires no administrator action.
- Token Protection support guidance was updated
Entra ID · Conditional Access
The Entra ID Token Protection documentation was updated around the section identifying devices and applications that can access resources protected by a token protection Conditional Access policy. The supplied excerpt does not identify the entries or say that support expanded, so this is documentation clarification rather than evidence of a new feature, preview, general availability change, or confirmed policy behavior change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
11 updates
Microsoft Entra ID
8 updatesHowto Mfa Mfasettings
Updatedauthor: justinha
- A relying party STS, such as Active Directory Federation Services (AD FS) or PingFederate, with HTTPS endpoints
You can see a sample request to the REST API:
Global Reader
Updated> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |
Security Administrator
Updated> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |
Token Protection
UpdatedThe following devices and applications support accessing resources on which a token protection Conditional Access policy is applied:
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
Microsoft Entra ID Protection
2 updatesSecurity Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview](/microsoft-365/security/office-365-security/scc-permissions).
Microsoft Entra Workload ID
1 updateManaged Identities Faq
UpdatedYou can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:
