Explore Conditional Access conditions, including user risk, sign-in risk, and insider risk, to secure your organization's resources with tailored policies.
24 September 2025: Conditional Access guidance refresh dominates; Global Secure Access security procedures also changed
This was a documentation-led day rather than a product-release event: all 14 supplied records were updates, with no new or removed items and no Message Center entry. Most updates refreshed Microsoft Entra Conditional Access fundamentals, covering the Zero Trust policy engine, resource targeting, conditions, network signals, session controls, grants, and workload-identity scope. Global Secure Access also received threat-intelligence and Netskope coexistence guidance updates. The evidence identifies no new feature, preview, general-availability milestone, retirement, or runtime behavior change.
- Conditional Access policy-engine guidance was updated
Entra ID · Conditional Access
The updated Microsoft Entra Conditional Access: Zero Trust Policy Engine page describes Conditional Access as the Zero Trust policy engine that integrates signals to secure access to resources. Because the record is an updated documentation item, it should be treated as conceptual guidance—not evidence of a new engine or changed enforcement behavior.
- Conditional Access resource-targeting guidance was updated
Entra ID · Conditional Access
The refreshed guidance covers configuring policies to target specific resources, actions, and authentication contexts. Administrators using those scopes should compare their policy design with the updated page; the supplied record does not state that a new targeting capability or enforcement change was released.
- Workload-identity scope guidance in Conditional Access was updated
Workload ID · Conditional Access
The updated setup guidance addresses including or excluding users, groups, and workload identities in Conditional Access policies. Workload ID administrators using this pattern should recheck policy scope and exclusions, although no change to workload-identity enforcement is reported.
- Global Secure Access threat-intelligence guidance was updated
Global Secure Access · Security
The updated Configure Threat Intelligence guidance says a threat-intelligence policy can alternatively be linked to the baseline security profile, applying the policy to all users’ traffic in the tenant. This is security guidance; the record does not establish a new default or availability milestone.
- Global Secure Access–Netskope coexistence guidance was updated
Global Secure Access · Security
The updated coexistence procedure instructs administrators to create a Netskope Real-time Protection policy that allows access to Private Apps. This is an interoperability documentation update, and the supplied evidence does not establish a change in product behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
14 updates
Microsoft Entra ID
11 updatesExplore Microsoft Entra Conditional Access, the Zero Trust policy engine that integrates signals to secure access to resources.
Learn how to configure Conditional Access policies to target specific resources, actions, and authentication contexts in Microsoft Entra ID.
Discover how to configure Conditional Access policies with network-based signals, including trusted locations, IP ranges, and GPS-based settings.
Learn how session controls in Microsoft Entra Conditional Access policies enable secure, limited experiences for cloud apps based on device compliance.
Conditional Access Grant
UpdatedAdmins can choose to enforce one or more controls when granting access. These controls include the following options:
Include file
UpdatedInclude file
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
Include file
UpdatedInclude file
Use the following steps to configure and start the provisioning:
Microsoft Entra Workload ID
1 updateLearn how to include or exclude users, groups, and workload identities in Conditional Access policies for secure and flexible access management.
Microsoft Entra Global Secure Access
2 updatesSince threat intelligence is critical for users' basic security posture, you can alternatively link your threat intelligence policy to the baseline security profile, which applies policy to all users' traffic in your tenant.
Netskope Coexistence
Updated1. Create [Real-time Protection policy](https://docs.netskope.com/en/inline-policies/) to allow access to Private Apps.
