← Previous day

Next day →
Day in brief

Permissions Management publishes offboarding guidance for an anticipated deprecation; 2 October is otherwise a documentation-heavy day

The clearest lifecycle signal is a new Microsoft Entra Permissions Management article explaining how to transition off the product for an anticipated deprecation. The same period adds a broad Learn runbook covering quickstart onboarding, AWS/Azure/GCP onboarding, analytics, alerts, remediation, and administration, but no supplied entry identifies a specific new feature, preview, or general-availability change. With 68 new and 68 removed records, 14 updates, and no Message Center entries, this is primarily Learn-content movement rather than evidence of a broad feature release. The meaningful exceptions are the deprecation guidance, updated ID Protection risk-based access guidance, and External ID Azure Monitor deployment instructions.

  • A new Microsoft Learn article explains how to transition off Microsoft Entra Permissions Management and explicitly ties that transition to an anticipated product deprecation. This is the period’s strongest retirement signal, but it does not establish that the service is already retired or provide a date or migration deadline.

  • The new Quickstart Guide describes how to quickly onboard Microsoft Entra Permissions Management. Related new pages cover AWS accounts, Azure subscriptions, GCP projects, and adding resources after onboarding. These are documentation additions and operational reference material, not evidence of a newly launched onboarding capability or changed availability.

  • A new procedure covers revoking access to high-risk and unused tasks or assigning read-only status for Azure and GCP identities. It gives administrators a documented remediation workflow; the supplied record does not show that the underlying controls themselves are newly available.

  • The updated article explains how to use Conditional Access with Microsoft Entra ID Protection to require secure password changes for users with elevated user risk. This supports a security-guidance update only; it does not establish a change to policy behavior or defaults.

  • The updated article says logs and the Log Analytics workspace are configured in the external tenant; the relevant external-tenant accounts should have Global Administrator, the deployment account should have Owner in the Microsoft Entra subscription, and operators must sign into the correct directory at each step. This is configuration guidance, not evidence of a new monitoring feature.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

151 updates

103

Teams Reader

Updated

Assign the Teams Reader role to users who need to do the following tasks:

Dragon Administrator

Updated

Assign the Dragon Administrator role to users who need to do the following tasks:

Whats New

Updated

| Date | Area | Description |

Clone Role Policy

Removed

A Microsoft Entra documentation page was updated: Clone Role Policy.

Configure Aws Iam

Removed

A Microsoft Entra documentation page was updated: Configure Aws Iam.

Create Folders

Removed

A Microsoft Entra documentation page was updated: Create Folders.

Create Role Policy

Removed

A Microsoft Entra documentation page was updated: Create Role Policy.

Create Rule

Removed

A Microsoft Entra documentation page was updated: Create Rule.

Delete Role Policy

Removed

A Microsoft Entra documentation page was updated: Delete Role Policy.

Faqs

Removed

A Microsoft Entra documentation page was updated: Faqs.

Modify Role Policy

Removed

A Microsoft Entra documentation page was updated: Modify Role Policy.

Onboard Aws

Removed

A Microsoft Entra documentation page was updated: Onboard Aws.

Onboard Azure

Removed

A Microsoft Entra documentation page was updated: Onboard Azure.

Onboard Gcp

Removed

A Microsoft Entra documentation page was updated: Onboard Gcp.

Partner List

Removed

A Microsoft Entra documentation page was updated: Partner List.

Product Dashboard

Removed

A Microsoft Entra documentation page was updated: Product Dashboard.

Ui Autopilot

Removed

A Microsoft Entra documentation page was updated: Ui Autopilot.

Ui Dashboard

Removed

A Microsoft Entra documentation page was updated: Ui Dashboard.

Ui Tasks

Removed

A Microsoft Entra documentation page was updated: Ui Tasks.

Ui Triggers

Removed

A Microsoft Entra documentation page was updated: Ui Triggers.

Ui User Management

Removed

A Microsoft Entra documentation page was updated: Ui User Management.

View Role Policy

Removed

A Microsoft Entra documentation page was updated: View Role Policy.

17

All Reports

Removed

A Microsoft Entra documentation page was updated: All Reports.

Audit Trail Results

Removed

A Microsoft Entra documentation page was updated: Audit Trail Results.

Product Audit Trail

Removed

A Microsoft Entra documentation page was updated: Product Audit Trail.

Product Reports

Removed

A Microsoft Entra documentation page was updated: Product Reports.

Ui Audit Trail

Removed

A Microsoft Entra documentation page was updated: Ui Audit Trail.

15

Troubleshoot

Removed

A Microsoft Entra documentation page was updated: Troubleshoot.

Ui Remediation

Removed

A Microsoft Entra documentation page was updated: Ui Remediation.

5

Integration Api

Removed

A Microsoft Entra documentation page was updated: Integration Api.

2

Overview

Removed

A Microsoft Entra documentation page was updated: Overview.

1

Require device compliance with Conditional Access

Updated

Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.

1

How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain

Updated

Objects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.

1
2
1

Microsoft Entra: Cross-cloud synchronization now available

New

Microsoft Entra's cross-cloud synchronization, in public preview and opt-in, automates user lifecycle management across Microsoft commercial, US Government, and China clouds. General availability is late September to early October 2025. It requires specific licenses, admin enablement, and supports configuration via portal, PowerShell, and API.

Message CenterMC1124558 on mc.merill.net ↗Stay informed
1

B2b Guest Access

Updated

To enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:

1

Azure Monitor

Updated

During this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.

1

External ID in workforce tenants

Updated

- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…