← Previous day

Next day →
Day in brief

ID Protection risk guidance and External ID monitoring setup were clarified; Global Secure Access documentation details connector-log export and a Graph-based category checker in​

1 October was a documentation-focused day: all nine supplied changes were Microsoft Learn updates, with no new or removed items and no Message Center entries. The most actionable updates concern ID Protection risk interpretation and reporting, External ID-to-Log Analytics integration, and Global Secure Access operations. The evidence does not support calling any item a GA launch, retirement, or mandatory tenant change; the web category checker is explicitly labeled preview.

  • The updated guidance states that Microsoft Entra ID Protection risk detections get a consistent view of the original user source IP address when assessing various risk scores. This is security and risk-interpretation guidance; the supplied evidence does not establish a change to scoring algorithms or tenant configuration.

  • The Azure Monitor documentation explains that an external tenant uses Microsoft Entra monitoring but cannot have an associated subscription, so additional steps are needed to integrate it with Log Analytics, where the logs are sent. This is an operational setup clarification, not evidence of a newly launched monitoring capability.

  • The updated export guidance directs administrators to additional queries and visual insights based on the AADUserRiskEvents and AADRisky Users logs in the Impact analysis of risk-based access policies workbook. The evidence supports a monitoring and reporting clarification, not a confirmed change to logging or risk-policy behavior.

  • The revised Export Connector Logs procedure explicitly includes downloading the Azure Arc agent setup script from the Azure portal. Administrators performing connector-log exports should account for this documented prerequisite or step; the update does not indicate a change to connector functionality.

  • The updated preview guidance describes using a web category checker to determine which web content category a URL belongs to through Microsoft Graph. This is preview tooling for URL classification, not evidence of general availability or a change to web-content-filtering enforcement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

9 updates

2
1
1

Source Ip Restoration

Updated

- [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks) get a consistent view of original user Source IP address for assessing various risk scores.

1

Howto Export Risk Data

Updated

Access more queries and visual insights based on AADUserRiskEvents and AADRisky Users logs in the [Impact analysis of risk-based access policies workbook](workbook-risk-based-policy-impact.md).

2

Azure Monitor

Updated

TThe external tenant uses [Microsoft Entra monitoring](/entra/identity/monitoring-health/overview-monitoring-health). Unlike Microsoft Entra tenants, an external tenant can't have a subscription associated with it. So, we need to take extra steps to enable the integration between external tenant and Log Analytics, which is where we send the logs.

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…