← Previous day

Next day →
Day in brief

External ID client credentials are documented as generally available, while Native Auth guidance flags a password-migration edge case

7 February was overwhelmingly a documentation-maintenance day: 179 of 183 recorded changes were for Microsoft Entra External ID, with one new Entra ID item and one removal whose details are not supplied. The substantive exceptions are an updated External ID announcement describing client credentials as generally available, explicit Native Auth migration behavior for weak legacy passwords, and a new Microsoft identity platform token guide. Most other representative updates refresh existing CIAM, B2B, and authentication setup guidance without establishing additional launches or behavior changes.

  • An updated What's New page announces general availability for the OAuth 2.0 client credentials grant in Microsoft Entra External ID. It describes confidential web services authenticating with their own credentials, rather than impersonating a user, when calling another service; an administrator grants permissions directly to the application. Because this is an updated announcement page, it should be read as availability documentation, not evidence that the capability first launched on this date.

  • The updated just-in-time password migration guidance says that a password valid at a legacy identity provider but weak under External ID password-complexity rules causes a Native Auth error instead of a redirect to SSPR. The record documents this runtime behavior; it does not say that the behavior changed on this date.

  • Entra ID · Microsoft identity platform
    Entra ID adds a comprehensive token reference

    The new Microsoft identity platform guide covers access, ID, and refresh tokens, claims, validation, configuration, and token security. This is new reference documentation for implementation and security work, not a stated change to token issuance or tenant settings.

  • The updated External ID page explains how to add multifactor authentication to consumer and business-customer CIAM applications, including email one-time passcode as a second factor in sign-up and sign-in user flows. It is a configuration-guide refresh; the supplied record does not claim a new MFA capability or altered availability.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

183 updates

1

Whatis Phs

Updated

To use password hash synchronization in your environment, you need to:

1

Tokens Overview

Removed

A Microsoft Entra documentation page was updated: Tokens Overview.

1
1
85

Migrate Users

Updated

Learn how to migrate users from another identity provider to Microsoft Entra External ID.

Add custom attributes

Updated

Learn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.

Allow or Block Invitations

Updated

Learn how an administrator creates a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.

Applies To External Only

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to external tenants.](../media/common/applies-to-yes.png) External tenants ([learn more](/entra/external-id/tenant-configurations))

Applies To Ios Macos

Updated

**Applies to**: ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) iOS (Swift) ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) macOS (Swift)

Applies To Workforce Only

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to workforce tenants.](../media/common/applies-to-yes.png) Workforce tenants ([learn more](/entra/external-id/tenant-configurations))

B2B Direct Connect Setup

Updated

Learn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.

Bulk invite B2B users

Updated

Learn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.

Configure external collaboration

Updated

Learn how to configure external collaboration settings in Microsoft Entra External ID. Control guest user access, specify who can invite guests, and manage domain restrictions for B2B collaboration.

Cross Cloud Settings

Updated

Enable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.

Dynamic groups setup

Updated

Learn how to create and manage dynamic membership groups in Microsoft Entra External ID. Set rules based on user attributes to automate group membership for B2B collaboration.

External ID pricing

Updated

Learn about the pricing structure for Microsoft Entra External ID. Understand the monthly active users (MAU) billing model, core offering, and premium add-ons. Link your tenant to an Azure subscription for proper billing and feature access.

Frequently asked questions

Updated

Find answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.

Google identity provider

Updated

Learn how to add Google as an identity provider in Microsoft Entra External ID. Enable customers to sign in with their Google accounts and configure Google federation for seamless access.

Leave an Organization

Updated

As a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.

Tenant configurations

Updated

Learn about tenant configurations in Microsoft Entra External ID. Understand the differences between workforce and external tenants, and how to configure them for your organization's needs.

Use Microsoft Accounts

Updated

Enable your external business partners and guest users to use their Microsoft Account (MSA) to sign in to your apps for B2B collaboration.

Use Microsoft Entra Accounts

Updated

Enable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.

38

Migrate Passwords Just In Time

Updated

**Password complexity mismatch in Native Auth**: During a Native Auth flow, if a user enters a password that is correct according to the legacy identity provider but is considered weak by External ID password complexity standards an error is returned instead of redirecting to SSPR.

Whats New

Updated

We are pleased to announce the general availability of client credentials in Entra External ID. The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. Permissions are granted directly to the application itself by an administrator.

Add multifactor authentication (MFA) to a customer app

Updated

Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.

B2B guest user properties

Updated

Learn about the properties of a B2B guest user in Microsoft Entra External ID. Understand user types, authentication methods, and how to manage guest user access and permissions.

Custom authentication extensions

Updated

Learn how to use custom authentication extensions in Microsoft Entra External ID. Integrate with external systems, add custom logic to authentication flows, and enhance user experiences.

Customize the browser language

Updated

Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.

Email one-time passcode authentication

Updated

Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.

Training, demos, and videos

Updated

Explore Microsoft Entra External ID training, live demos, and videos. Learn to create secure sign-up experiences and protect access with multifactor authentication.

Workforce Tenant Overview

Updated

Learn about B2B collaboration for sharing apps with external identities, business partners, and guests, using External ID for authentication and identity access management.

About B2B Invitations

Updated

Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.

Add an application to a user flow

Updated

Learn how to add an application to a user flow to associate the application with a sign-up and sign-in user experience. Get guidance for updating the application configuration with application registration and tenant information.

Add Azure AD B2C for customer sign-in

Updated

Learn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Add Facebook for customer sign-in

Updated

Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Create a User Flow

Updated

Add sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.

Define custom attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

Disable Sign Up User Flow

Updated

Disable sign-up in your user flow with Microsoft Graph API. Prevent new registrations and allow only sign-in for your external users.

External Tenant Quickstart

Updated

In this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.

Identity providers for external tenants

Updated

Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.

Invite internal users to B2B collaboration

Updated

If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can change to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials or sign-in. Use either PowerShell or the Microsoft Graph invitation API.

MFA in external tenants

Updated

Learn about using MFA to secure apps in your external tenant and enabling email one-time passcodes (EOTP) or SMS as a second verification method for sign-up and sign-in.

Plan a CIAM Deployment

Updated

Discover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.

Quickstart: Add a guest user with PowerShell

Updated

In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.

Sign in with alias

Updated

Learn how to Sign in with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

Test a user flow

Updated

Learn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.

Troubleshoot B2B issues

Updated

Learn how to troubleshoot common issues with Microsoft Entra B2B collaboration. Resolve guest sign-in errors, direct connect access problems, policy update failures, and encrypted email access issues.

Visual Studio Code extension for External ID

Updated

Learn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.

24

Add an enterprise application

Updated

Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.

Add attributes to token claims

Updated

Learn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.

Using role-based access control for apps

Updated

Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.

13

Security Features in External Tenants

Updated

Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.

Tokens Overview

Updated

Microsoft Entra ID supports two tenant configurations: A workforce configuration that's intended for internal use and manages employees and business guests, and a [customer configuration](/entra/external-id/customers/concept-supported-features-customers) which is optimized for isolating consumers and partners in a restricted external-facing directory. While the underlying identity service is identical for both tenant configurations, the sign in domains and token issuing authority for external tenants is different. This allows applications to keep workforce and external ID workflows separated if needed.

B2b Guest Access

Updated

> This information relates to a prerelease product that might be substantially modified before its release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

B2B direct connect Microsoft Entra overview

Updated

Microsoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.

Cross-tenant access overview

Updated

Learn how to manage cross-tenant access in Microsoft Entra External ID. Configure B2B collaboration and direct connect settings to control access and trust for external organizations.

External Tenant Features

Updated

Compare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.

External Tenant Overview

Updated

Learn how Microsoft Entra External ID provides to manage your external identities scenarios, including guest user access and customer identity and access management (CIAM) for apps.

Microsoft Entra External ID overview

Updated

Microsoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.

Self-service sign-up

Updated

Learn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.

User Attributes

Updated

User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.

7

Add a SAML/WS-Fed identity provider

Updated

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Register a SAML app

Updated

Learn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.

Set up AD FS federation

Updated

Learn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

5

Fraud Protection Integration

Updated

Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.

3

Reset guest redemption status

Updated

Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.

2
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…