The system accounts for five minutes of clock skew when **every time** is selected in policy, so users aren’t prompted more often than once every five minutes. If the user completes MFA in the last 5 minutes and encounters another Conditional Access policy that requires reauthentication, we don't prompt the user. Prompting users too often for reauthentication can affect their productivity and increase the risk of users approving MFA requests they didn’t initiate. Use "Sign-in frequency – every time" only when there are specific business needs.
Entra guidance clarifies Conditional Access reauthentication and diagnostics, while affected Apple SSO clients face a compatibility migration
24 March was a documentation-only update day: all 48 supplied changes were updates, with no new or removed items and no Message Center entries. Entra ID accounted for 42 updates, heavily concentrated on Conditional Access. The most consequential material clarifies existing policy behavior, troubleshooting paths, app-targeting dependencies, and Apple SSO compatibility; the supplied evidence does not identify a new feature launch, preview, general availability milestone, retirement, or tenant-wide configuration change.
- Conditional Access documents a five-minute floor for “Sign-in frequency — every time”
Entra ID · Conditional Access
Documentation clarification: when “every time” is selected, the service accounts for five minutes of clock skew, so users are not prompted more often than once every five minutes. If MFA was completed within the previous five minutes, another Conditional Access policy requiring reauthentication does not prompt the user again. The guidance warns that excessive prompts can reduce productivity and encourage approval of unsolicited MFA requests, and recommends using this setting only for specific business needs. This��
- Authentication-flow policy troubleshooting is made explicit
Entra ID · Conditional Access
Updated operational guidance directs administrators investigating an unexpected Conditional Access block or device sign-out to open the relevant sign-in event, inspect the Conditional Access tab in Activity details, and determine whether an authentication flows policy was enforced. Selecting that policy shows which authentication flow matched. This is a troubleshooting clarification, not evidence of a new policy capability or changed rollout status.
- Office 365 app targeting requires awareness of service dependencies
Entra ID · Conditional Access
The Conditional Access Cloud Apps guidance clarifies that the Microsoft 365 suite appears as “Office 365” in Conditional Access and that services are deeply integrated. For example, Teams can depend on SharePoint or Exchange, which may make policy targeting and results less obvious. Administrators should account for those dependencies when reviewing policy scope and troubleshooting outcomes; the evidence describes documentation clarification rather than a change to app targeting.
- Apple SSO guidance requires affected consumers to move to MSAL and the Enterprise SSO plug-in
Entra ID · Authentication
Compatibility guidance says applications or MDM solutions that depend on accessing Microsoft Entra device-registration keys through Keychain must update to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform. Owners of affected apps and device-management integrations have a concrete assessment and migration action, but the supplied update gives no deadline or separate retirement announcement.
- ID Protection guidance spells out managed-policy response to high-risk sign-ins
ID Protection · Authentication
Security guidance describes a managed policy that covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. Examples include highly abnormal travel, password-spray attacks, and token-replay attacks. The update explains the managed policy’s coverage and response; it does not indicate that a new policy was introduced or that administrators must change configuration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
48 updates
Microsoft Entra ID
42 updatesMigrate Approved Client App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Agent Block High Risk
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
The following steps help create a Conditional Access policy to require all users to perform multifactor authentication using the authentication strength policy.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Understand the phases of Conditional Access policy enforcement in Microsoft Entra and how to apply them to secure user access.
Microsoft 365 offers cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. In Conditional Access, the Microsoft 365 suite of applications appears under 'Office 365'. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration might cause confusion when creating policies because some apps, like Microsoft Teams, depend on others, like SharePoint or Exchange.
Continuous access evaluation
UpdatedToken expiration and refresh are a standard mechanism in the industry. When a client application like Outlook connects to a service like Exchange Online, the API requests are authorized using OAuth 2.0 access tokens. By default, access tokens are valid for one hour, when they expire the client is redirected to Microsoft Entra to refresh them. That refresh period provides an opportunity to reevaluate policies for user access. For example: the token might not be refreshed because of a Conditional Access policy, or because the user is disabled in the directory.
Authentication Flows
UpdatedIf you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, selecting the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Block By Location
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Block Example
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
To get detailed information about the sign-in interruption, review the Microsoft Entra sign-in events to see which Conditional Access policy or policies applied and why.
- Admins can apply policy only to supported platforms (such as iOS, Android, and Windows) through the Conditional Access Microsoft Graph API.
> [!IMPORTANT]
To prevent admin lockout, when creating a policy applied to **All users** and **All apps**, the following warning appears.

Plan Conditional Access
Updated- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
With Conditional Access, organizations can restrict access to [approved (modern authentication capable) client apps with Intune app protection policies](concept-conditional-access-grant.md#require-app-protection-policy). For older client apps that may not support app protection policies, administrators can restrict access to [approved client apps](concept-conditional-access-grant.md#require-approved-client-app).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
**To configure your Conditional Access policy:**
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Guests Mfa Strength
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Old Require Mfa Admin
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Old Require Mfa Guest
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Apple Sso Plugin
UpdatedIf your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.
This guide covers the steps required to deploy and enforce Token Protection for sign-in session tokens on Windows platform.
Filter For Applications
UpdatedFollow the instructions in the article, [Add or deactivate custom security attributes in Microsoft Entra ID](~/fundamentals/custom-security-attributes-add.md) to add the following **Attribute set** and **New attributes**.
There are multiple scenarios that organizations can now enable using filter for devices condition. The following scenarios provide examples of how to use this new condition.
Permissions Reference
Updated> | [Compliance Administrator](#compliance-administrator) | Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |
What If Tool
UpdatedStart an evaluation by selecting **What If**. The evaluation result provides you with a report that consists of:
Terms Of Use
Updated* Microsoft Entra ID P1 licenses.
- Policy can be applied to the Microsoft Edge browser on devices running Windows 11 and Windows 10 version 20H2 and higher with KB5031445.
Microsoft Entra Agent ID
1 updateAgent Id
UpdatedThere are two key business scenarios where Conditional Access policies can help you manage agents effectively.
Microsoft Entra ID Protection
1 updateManaged Policies
UpdatedThis policy covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. High-risk in this case means something about the way the user signed in is out of the ordinary. These high-risk sign-ins might include travel that is highly abnormal, password spray attacks, or token replay attacks. For more information, see [What are risk detections](/entra/id-protection/concept-identity-protection-risks#sign-in-risk-detections).
Microsoft Entra External ID
2 updates<br/>**Target tenant**
Learn how to integrate third-party bot protection providers with Native API sign-up flows in Microsoft Entra External ID by using a Web Application Firewall.
Microsoft Entra Workload ID
1 updateWorkload Identity
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Zscaler Coexistence
Updated1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.
