There might be situations while configuring or managing an application where you don't want tokens to be issued for an application. Or, you might want to block an application that you don't want your employees to try to access, like the deprecated Azure AD PowerShell modules (AppID 1b730954-1685-4b74-9bfd-dac224a7b894). To block user access to an application, you can disable user sign-in for the application, which prevents all tokens from being issued for that application.
PIM Iteration 2 beta APIs face an October 2026 retirement; the remaining updates are targeted administrator guidance
The 29 October 2025 feed contains no new feature or general-availability launch. Its most consequential change is a Microsoft Entra Privileged Identity Management notice that Iteration 2 beta APIs will be retired on 28 October 2026, after which dependent applications will fail. Documentation updates also clarify application blocking, external-method policy testing, and consent-policy notice timing.
- PIM Iteration 2 beta APIs will be phased out by 28 October 2026
ID Governance · Fundamentals
This is a future retirement notice, not an immediate outage: applications using the Iteration 2 beta APIs will fail after the deadline. Microsoft directs organizations to migrate to the more reliable Iteration 3 GA APIs and stop new development on Iteration 2.
- Disabling application sign-in prevents all tokens from being issued
Entra ID · Authentication
Updated Entra ID guidance explains that disabling user sign-in for an application blocks all token issuance. It specifically identifies deprecated Azure AD PowerShell modules as an example of an application administrators may want to block; this is security and configuration guidance, not a newly announced feature.
- External-method policy testing requires non-overlapping user groups
Entra ID · Authentication
The authentication guidance clarifies that test users should be assigned to one policy or the other, not both. If a user is covered by both policies or both conditions, sign-in requires MFA and the custom control, causing a second redirect to the external provider.
- Consent-policy updates are documented as having at least 30 days’ notice
Entra ID · General
The Manage App Consent Policies documentation states that updates to the consent policy will have at least 30 days of notice. The entry represents a policy-timing clarification and does not describe a new consent capability or an immediate change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
7 updates
Microsoft Entra ID
4 updatesInclude a test group of users for each policy, but not both. If a user is included in both policies, or any policy with both conditions, the user has to satisfy MFA during sign-in. They also have to satisfy the custom control, which makes them redirected to the external provider a second time.
Overview
UpdatedA Microsoft Entra documentation page was updated: Overview.
Manage App Consent Policies
UpdatedUpdates to this consent policy will have at least 30 days of given notice.
Microsoft Entra ID Governance
1 updateMicrosoft Entra Privileged Identity Management (PIM) Iteration 2 (beta) APIs will be retired on October 28, 2026. Applications using these APIs will fail after this date. Organizations should migrate to the more reliable Iteration 3 (GA) APIs and stop new development on Iteration 2 APIs.
Microsoft Entra External ID
1 updateSign In Alias
Updated{
Microsoft Entra Workload ID
1 updateManaged Identity Libraries
UpdatedA Microsoft Entra documentation page was updated: Managed Identity Libraries.
