Learn how admins can create custom authentication strengths with advanced options for passkey (FIDO2) security keys and certificate-based authentication.
Tenant Restrictions v2 gets a critical cross-cloud clarification; the rest is documentation guidance
The 16 September record contains documentation updates only: all six entries are marked Updated, with no new or removed items and no Message Center notices. The most consequential clarification is in External ID Tenant Restrictions v2: support across all clouds does not mean enforcement for cross-cloud requests. Other updates cover Entra monitoring, authentication-strength configuration, Copilot network-log analysis, and password-based SSO troubleshooting. The evidence does not establish a new launch, preview, general availability milestone, retirement, or required tenant behavior change.
- External ID Tenant Restrictions v2 clarifies the cross-cloud enforcement limit
External ID · General
The updated guidance says Tenant Restrictions v2 is supported on all clouds but is not enforced with cross-cloud requests. This is a documented behavior and security clarification, not evidence of expanded cross-cloud enforcement.
- Copilot Entra security scenarios describe interactive network-log analysis
Entra ID · Fundamentals
The update describes an interactive way to analyze network traffic logs without writing complex queries, including user, device, and branch usage as well as network issues, threats, and policy violations in real time. It does not state a preview or general availability status.
- Custom authentication-strength guidance covers advanced passkey and certificate options
Entra ID · Authentication
The updated overview explains how administrators can create custom authentication strengths with advanced options for passkey (FIDO2) security keys and certificate-based authentication. The record provides configuration guidance but does not establish a newly released capability or required rollout.
- Conditional Access Policy Insights guidance points to Azure Monitor and insights workbooks
Entra ID · Conditional Access
The documentation now directs administrators to analyze Conditional Access policy results with Azure Monitor and insights workbooks for policy management. This is monitoring and evaluation guidance, not evidence of a new Conditional Access feature or changed enforcement.
- Password-based SSO troubleshooting clarifies the HTML-only field-capture boundary
Entra ID · Authentication
The update states that sign-in field capture works only on HTML-enabled sign-in pages, not on non-standard pages such as Adobe Flash, and includes guidance for custom apps. This is a troubleshooting clarification rather than a retirement or sign-in behavior change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
7 updates
Microsoft Entra ID
5 updatesSign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps.
Microsoft Authenticator will streamline same-device sign-ins by removing number entry, requiring only a Yes/No confirmation, and improve onboarding by prioritizing Microsoft Entra accounts and highlighting QR code scanning. Rollout begins late September to mid-October 2025, with no admin action needed.
Discover how to analyze Conditional Access policy results with tools like Azure Monitor and insights workbooks for better policy management.
This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.
Microsoft Entra External ID
2 updatesTenant Restrictions V2
Updated- Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.
