For feature feedback, vote at [Connect Health User Voice channel](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789)
Security-response guidance is the main substance in an otherwise documentation-only Entra update day
For 8 October 2025, the supplied set contains 16 updated items and no new, removed, or Message Center items. The strongest changes are guidance updates: Identity Protection now documents response to adversary-in-the-middle risk and named-location tuning, while coexistence and External ID articles provide configuration detail. No feature launch, general availability milestone, retirement, or changed service behavior is evidenced. The Continuous Access Evaluation for Application Proxy entry remains explicitly marked preview, but its record gives no milestone or availability change.
- Identity Protection guidance specifies a response path for adversary-in-the-middle risk
ID Protection · Authentication
The updated risks article describes a high-precision Adversary in the Middle detection caused by a malicious reverse proxy; it raises the user to High risk. It recommends manual investigation and says clearing the risk may require a secure password reset or revoking existing sessions. This is security guidance in the article, not evidence that a new detection or enforcement behavior shipped on this date.
- Conditional Access named-location guidance targets VPN-related false positives
ID Protection · Conditional Access
The Identity Protection investigation how-to adds guidance to put corporate VPNs and IP address ranges into Conditional Access named locations to reduce false positives. Administrators can review those definitions where corporate egress is being misclassified; the supplied record does not say that Conditional Access behavior changed.
- The Zscaler coexistence scenario spells out traffic ownership
Internet Access · Developer
The updated guide says Global Secure Access handles private applications in Microsoft Entra Private Access, Zscaler Private Access handles private applications in Zscaler, and Zscaler Internet Access handles internet traffic. This gives mixed-deployment teams a concrete client and service split to validate; it is coexistence guidance, not a new capability announcement.
- External ID documentation covers Arkose Labs and Human fraud protection
External ID · Security
The updated integration guide explains configuring Arkose Labs and Human with Microsoft Entra External ID to block bot attacks and fake account creation during sign-up. Administrators running External ID registration flows can use it as configuration guidance; the record does not establish that either integration is newly available or that sign-up behavior changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
16 updates
Microsoft Entra ID
3 updatesDelegate By Task
Updated> | Create terms of use | [Conditional Access Administrator](permissions-reference.md#conditional-access-administrator) | [Security Administrator](permissions-reference.md#security-administrator) |
Connect Health Agent Install
Updated- Make sure that you satisfy the [requirements](how-to-connect-health-agent-install.md#requirements) to install Microsoft Entra Connect Health.
Microsoft Entra ID Protection
2 updatesIdentity Protection Risks
UpdatedAlso referred to as Adversary in the Middle, this high precision detection is triggered when an authentication session is linked to a malicious reverse proxy. In this kind of attack, the adversary can intercept the user's credentials, including tokens issued to the user. The Microsoft Security Research team uses Microsoft Defender for Cloud Apps to capture the identified risk and raises the user to **High** risk. We recommend administrators manually investigate the user when this detection is triggered to ensure the risk is cleared. Clearing this risk might require secure password reset or revocation of existing sessions.
- Add corporate VPNs and IP address ranges to [named locations](../identity/conditional-access/concept-assignment-network.md) in your Conditional Access policies to reduce false positives.
Microsoft Entra ID Governance
2 updatesPlan Conditional Access
Updated- Admins who interact with Conditional Access need one of the following role assignments, depending on the tasks they're performing. To follow the [Zero Trust principle of least privilege](/security/zero-trust/), consider using [Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) to activate privileged role assignments just in time.
1. Sign in to the My Access portal at [https://myaccess.microsoft.com](https://myaccess.microsoft.com) as the direct manager of the team who you want to manage access package assignments for. For US Government, the domain in the My Access portal link is `myaccess.microsoft.us`.
Microsoft Entra External ID
2 updatesFraud Protection Integration
UpdatedLearn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.
Register Saml App
UpdatedThis article describes how to register your own SAML application in your external tenant by creating a *non-gallery* app in **Enterprise applications**.
Microsoft Entra Internet Access
3 updatesZscaler Coexistence
UpdatedIn this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
Cisco Vpn Coexistence
Updated1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**
Netskope Coexistence
UpdatedThis guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
Microsoft Entra Private Access
1 updateCisco Coexistence
Updated5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.
Microsoft Entra Global Secure Access
3 updatesLearn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
Traffic Dashboard
Updatedmanager: dougeby
Palo Alto Coexistence
Updatedmanager: dougeby
