← Previous day

Next day →
Day in brief

Tenant Governance preview gets end-to-end documentation; risk and recovery guidance sharpen

The 21 March period was documentation-led. Microsoft added new preview Learn content for Microsoft Entra Tenant Governance covering its purpose, deployment, tenant discovery, governance, and configuration monitoring. The most actionable revised guidance clarifies risk remediation across authentication methods, makes incomplete recovery and application-secret checks explicit, and details WAF configuration for External ID. The supplied evidence supports documentation additions and clarifications, not a general-availability announcement, retirement, or confirmed service launch.

  • A new ID Governance page covers deployment from setup through tenant discovery, governance, and configuration monitoring. Companion new pages define the capability and describe the signals and metrics used to identify and evaluate related tenants. This is a documentation addition for a preview capability, not evidence of general availability.

  • Updated Conditional Access Grant guidance says that when user risk is detected, users can self-remediate through the appropriate flow regardless of authentication method. It specifically states that the Microsoft-managed remediation policy accommodates password-based and passwordless methods and links to the risk-remediation control marked preview. The evidence describes documented behavior; it does not establish a new policy rollout.

  • The updated Entra ID guidance states that a partially successful recovery appears as “Completed with warnings.” Selecting that status displays the changes that were not recovered, giving recovery operators a documented way to identify incomplete outcomes.

  • Updated guidance tells administrators to validate whether application secrets were affected after determining the cause of changes. It directs them to the audit log and to events showing that an application secret was changed or updated. This is security-oriented recovery guidance, not a claim of automatic secret remediation.

  • The updated tutorial says to enable WAF protection by configuring a WAF policy and associating it with Azure Front Door Premium. It describes rule sets for common vulnerabilities, malicious bot activity, and layer 7 DDoS protection. This is configuration guidance rather than a launch notice.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

17 updates

3

Create Review Difference Reports

Updated

1. Go to **Backup and recovery** > **Backups**. Select a backup from the list, and then select **Create difference report**.

Recover Applications

Updated

After you determine the cause of the changes, validate whether the secrets for applications were impacted. Find changes to application secrets in the audit log. Look for events that indicate the application secret was changed or updated.

Recover Objects

Updated

1. Go to **Backup and recovery** > **Difference reports**. Select a completed difference report.

2

View Available Backups

Updated

1. Browse to **Backup and recovery**. The **Overview** page shows feature highlights, alerts, and recent activity.

1

Review Recovery History

Updated

If a recovery operation partially succeeds, the **Status** column shows **Completed with warnings**, allowing you to identify objects that weren't recovered. Select **Completed with warnings** to view the details of the changes that were not recovered.

1

Security Store In Entra

Updated

Security Store is embedded in the Microsoft Entra admin center, so you can discover and deploy agents and solutions without leaving your identity management workflow.

1

Troubleshooting

Updated

**If the difference report is running for a long time:**

2

Conditional Access Grant

Updated

When user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation with Microsoft-managed remediation (preview)](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control-preview).

2
1
1
1

Tutorial Configure External Id Web App Firewall

Updated

To enable WAF for protection, configure a WAF policy and associate it with Azure Front Door Premium. Microsoft optimizes Azure Front Door premium for security and manages the rule sets provided by the WAF to protect against common vulnerabilities including cross-site scripting and JavaScript exploits. Additionally, Azure WAF provides rule sets that help protect against malicious bot activity and provide layer 7 DDoS protection for your application.

1

Scope Supported Objects Limitations

Updated

An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resource type](/graph/api/resources/approleassignment).

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…