← Previous day

Next day →
Day in brief

Graph-based External ID username validation and scoped Lifecycle Workflows are the key exceptions in a documentation-maintenance day

25 February was quiet in release terms: all 20 recorded items were Microsoft Learn updates, with no new or removed entries and no Message Center notices. The substantive content is concentrated in ID Governance guidance for delegated workflow management and custom-attribute triggers, an External ID clarification that custom username regex validation is configured through Microsoft Graph rather than the admin center, and an explicitly preview Global Secure Access Prompt Shield page. The remaining updates are largely app-integration tutorials and troubleshooting or reference edits; the supplied evidence does not indicate a GA launch, retirement, service-behavior change, or mandatory tenant action.

  • The updated guidance says admins can set a custom regular expression through validationRegEx on the username attribute. The setting is not currently available in the admin center UI; the documented route is Microsoft Graph's authenticationAttributeCollectionInputConfiguration resource, with an example tied to a self-service sign-up user flow. This is a documentation clarification and configuration constraint, not evidence of a new External ID rollout.

  • The updated page describes delegated workflow management: by default, workflows are managed by users with Lifecycle Workflows or Global administrator roles, while Administrative Unit scoping can limit specific admins to specific workflows. This provides a least-privilege administration option; the record does not say the capability launched or changed behavior on this date.

  • The page documents using custom attributes as execution conditions for automatic workflow runs when the default attribute set is insufficient, including scenarios involving users moving within the organization. Administrators reviewing workflow design can use the guidance to identify where a custom attribute is needed; the update itself does not establish a new availability milestone.

  • The updated security page describes protecting enterprise generative AI applications from prompt-injection attacks with Microsoft's AI Gateway Prompt Shield. Because the title explicitly labels the capability as preview, this should be treated as preview guidance rather than a GA announcement; the supplied record gives no rollout or configuration requirements.

  • The updated Windows client troubleshooting page directs administrators to use the Health check tab in the Advanced diagnostics utility. This is an operational documentation clarification for diagnosing client issues, not evidence of a client feature change or availability event.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

20 updates

6
5

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

5. Under the **Admin Credentials** section, input your GitHub Enterprise Managed User (OIDC) Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to GitHub Enterprise Managed User (OIDC). If the connection fails, ensure your GitHub Enterprise Managed User (OIDC) account has created the secret token as an enterprise owner and try again.

1

Lexmark Cloud Services Tutorial

Updated

If you want to configure the **SAML Authentication Provider** section with Metadata URL, then perform the following steps:

1

Whats New

Updated

> Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your ![RSS feed reader icon](./media/whats-new/feed-icon-16x16.png) feed reader.

2

Delegated workflow management

Updated

Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.

Use Custom attribute triggers in lifecycle workflows

Updated

Lifecycle Workflows allows you to trigger workflows to run automatically for users that meet the execution conditions of the workflow. There are many default attributes that you can use to trigger workflows, but sometimes you might require triggering a workflow based on a specific attribute not offered by default. Using custom attribute triggers, you can trigger a workflow to run for users based on when they move within your organization based on:

1

Sign In Alias

Updated

You can set a custom regular expression for input validation by configuring the `validationRegEx` for the username attribute. This setting isn't currently available in the admin center UI, but you can configure it using Microsoft Graph. To set this value, use the [authenticationAttributeCollectionInputConfiguration](/graph/api/resources/authenticationattributecollectioninputconfiguration) resource type. For reference, see the example on [updating the page layout of a self-service sign up user flow](/graph/api/authenticationeventsflow-update#example-2-update-the-page-layout-of-a-self-service-sign-up-user-flow).

2
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…