← Previous day

Next day →
Day in brief

Microsoft Authenticator will remove same-device number entry; the rest of the period is primarily documentation clarification.

The most consequential change is an Entra ID Message Center notice for Microsoft Authenticator: same-device sign-ins will use a Yes/No confirmation instead of number entry, while the first-run experience will prioritize Microsoft Entra accounts and QR-code scanning. Rollout is scheduled from late September to mid-October 2025, with no admin action required. The other supplied records are Microsoft Learn updates, chiefly for External ID customer authentication, plus Entra ID audit-log guidance; they do not establish new launches, previews, retirements, or security changes.

  • Changed user behavior—not a new tenant capability: same-device sign-ins will no longer require users to enter a number and will instead require a Yes/No confirmation. The first-run experience will prioritize Microsoft Entra accounts and highlight QR-code scanning. Microsoft states that rollout begins in late September and runs to mid-October 2025, with no admin action needed.

  • The updated Learn content is reference documentation for a custom authentication extension that invokes the emailOtpSend event in External ID customer configurations. The supplied evidence describes documentation maintenance only; it does not indicate a new feature, preview, general availability change, retirement, or changed runtime behavior.

  • The Audit Logs documentation update notes that, where applicable, audit entries include old and new values for changed properties. This is ordinary schema and documentation clarification, not evidence of a change to audit-log collection, retention, or behavior.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

24 updates

4
3

Activity Log Schemas

Updated

- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).

Audit Logs

Updated

- Where applicable, old and new values for the changed properties

8

Use App Roles Customers

Updated

When Microsoft Entra External ID issues a security token for an authenticated user, it includes the names of the roles you've assigned the user or group in the security token's roles claim. An application that receives that security token in a request can then make authorization decisions based on the values in the roles claim.

Google Federation Customers

Updated

By setting up federation with Google, you allow customers to sign in to your applications with their own Google accounts. After you add Google as one of your user flow's sign-in options, customers can sign up and sign in to your application with a Google account. (Learn more about [authentication methods and identity providers for customers](concept-authentication-methods-customers.md).)

Facebook Federation Customers

Updated

By setting up federation with Facebook, you can allow customers to sign in to your applications with their own Facebook accounts. After you've added Facebook as one of your application's sign-in options, on the sign-in page, customers can sign-in to Microsoft Entra External ID with a Facebook account. (Learn more about [authentication methods and identity providers for customers](/entra/external-id/customers/concept-authentication-methods-customers).)

User Flow Sign Up Sign In Customers

Updated

This article describes how to create a sign-in and sign-up user flow. After you create the user flow, the next step is to [add your application to the user flow](how-to-user-flow-add-application.md). You can create multiple user flows if you have multiple applications that you want to offer to customers. Or, you can use the same user flow for many applications. However, an application can have only one user flow.

Customize Branding Customers

Updated

After creating a new external tenant, you can customize the end-user experience. Create a custom look and feel for users signing in to your apps by configuring **Company branding** settings for your tenant. With these settings, you can add your own background images, colors, company logos, and text to customize the sign-in experiences across your apps.

Enable Password Reset Customers

Updated

:::image type="content" source="media/how-to-enable-password-reset-customers/sspr-flow.png" alt-text="Screenshot that shows the self-service password rest flow.":::

Solutions Customers

Updated

When you enter an email address to create an account, your email is verified through a one-time passcode. Then you can create a new password and provide more details, such as your name, country or region, and other information. Once your account is created, your email becomes your sign-in ID.

3

Define Custom Attributes

Updated

An attribute with a Boolean data type has a user input type of CheckboxSingleSelect. You can modify the text that displays next to the checkbox and include hyperlinks.

Training Videos

Updated

To start the training, go to [Guided project – Build a sample app to evaluate Microsoft Entra External ID](https://aka.ms/eeid/training-module) and follow the units in order.

2

Add Attributes To Token

Updated

You can specify which built-in or custom attributes you want to include as claims in the token that Microsoft Entra ID sends to your application.

User Insights

Updated

The Application user activity feature under Usage & insights provides data analytics on user activity and engagement for registered applications in your tenant. You can use this feature to view, query, and analyze user activity data in the Microsoft Entra admin center. This feature can help you uncover valuable insights that can aid strategic decisions and drive business growth.

2

Custom Url Domain

Updated

- It provides a more consistent user experience. From the user's perspective, they remain in your domain during the sign in process rather than redirecting to the default domain *<tenant-name>.ciamlogin.com*.

1

Multifactor Authentication Customers

Updated

This article describes how to enforce MFA for your customers by creating a Microsoft Entra Conditional Access policy and adding MFA to your sign-up and sign-in user flow.

1

Microsoft Accounts Federation Customers

Updated

By setting up federation with Microsoft account (live.com) using OpenID Connect (OIDC) identity provider, you enable users to sign up and sign in to your applications using their existing Microsoft accounts (MSA).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…