← Previous day

Next day →
Day in brief

Entra guidance clarifies Conditional Access reauthentication and diagnostics, while affected Apple SSO clients face a compatibility migration

24 March was a documentation-only update day: all 48 supplied changes were updates, with no new or removed items and no Message Center entries. Entra ID accounted for 42 updates, heavily concentrated on Conditional Access. The most consequential material clarifies existing policy behavior, troubleshooting paths, app-targeting dependencies, and Apple SSO compatibility; the supplied evidence does not identify a new feature launch, preview, general availability milestone, retirement, or tenant-wide configuration change.

  • Documentation clarification: when “every time” is selected, the service accounts for five minutes of clock skew, so users are not prompted more often than once every five minutes. If MFA was completed within the previous five minutes, another Conditional Access policy requiring reauthentication does not prompt the user again. The guidance warns that excessive prompts can reduce productivity and encourage approval of unsolicited MFA requests, and recommends using this setting only for specific business needs. This��

  • Updated operational guidance directs administrators investigating an unexpected Conditional Access block or device sign-out to open the relevant sign-in event, inspect the Conditional Access tab in Activity details, and determine whether an authentication flows policy was enforced. Selecting that policy shows which authentication flow matched. This is a troubleshooting clarification, not evidence of a new policy capability or changed rollout status.

  • The Conditional Access Cloud Apps guidance clarifies that the Microsoft 365 suite appears as “Office 365” in Conditional Access and that services are deeply integrated. For example, Teams can depend on SharePoint or Exchange, which may make policy targeting and results less obvious. Administrators should account for those dependencies when reviewing policy scope and troubleshooting outcomes; the evidence describes documentation clarification rather than a change to app targeting.

  • Compatibility guidance says applications or MDM solutions that depend on accessing Microsoft Entra device-registration keys through Keychain must update to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform. Owners of affected apps and device-management integrations have a concrete assessment and migration action, but the supplied update gives no deadline or separate retirement announcement.

  • Security guidance describes a managed policy that covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. Examples include highly abnormal travel, password-spray attacks, and token-replay attacks. The update explains the managed policy’s coverage and response; it does not indicate that a new policy was introduced or that administrators must change configuration.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

48 updates

34

Howto Conditional Access Session Lifetime

Updated

The system accounts for five minutes of clock skew when **every time** is selected in policy, so users aren’t prompted more often than once every five minutes. If the user completes MFA in the last 5 minutes and encounters another Conditional Access policy that requires reauthentication, we don't prompt the user. Prompting users too often for reauthentication can affect their productivity and increase the risk of users approving MFA requests they didn’t initiate. Use "Sign-in frequency – every time" only when there are specific business needs.

Migrate Approved Client App

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Agent Block High Risk

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy All Users Copilot Ai Security

Updated

The following steps help create a Conditional Access policy to require all users to perform multifactor authentication using the authentication strength policy.

Policy Risk Based Insider Block

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Conditional Access Cloud Apps

Updated

Microsoft 365 offers cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. In Conditional Access, the Microsoft 365 suite of applications appears under 'Office 365'. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration might cause confusion when creating policies because some apps, like Microsoft Teams, depend on others, like SharePoint or Exchange.

Continuous access evaluation

Updated

Token expiration and refresh are a standard mechanism in the industry. When a client application like Outlook connects to a service like Exchange Online, the API requests are authorized using OAuth 2.0 access tokens. By default, access tokens are valid for one hour, when they expire the client is redirected to Microsoft Entra to refresh them. That refresh period provides an opportunity to reevaluate policies for user access. For example: the token might not be refreshed because of a Conditional Access policy, or because the user is disabled in the directory.

Authentication Flows

Updated

If you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, selecting the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.

Deployment Guide Token Protection Apple

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Block By Location

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Block Example

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Block Legacy Authentication

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Troubleshoot Conditional Access

Updated

To get detailed information about the sign-in interruption, review the Microsoft Entra sign-in events to see which Conditional Access policy or policies applied and why.

Conditional Access Conditions

Updated

- Admins can apply policy only to supported platforms (such as iOS, Android, and Windows) through the Conditional Access Microsoft Graph API.

Conditional Access Users Groups

Updated

To prevent admin lockout, when creating a policy applied to **All users** and **All apps**, the following warning appears.

Howto Conditional Access Insights Reporting

Updated

![Screenshot showing a workbook breakdown per condition and status.](./media/howto-conditional-access-insights-reporting/workbook-breakdown-condition-and-status.png)

Plan Conditional Access

Updated

- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).

Policy All Users App Enforced Restrictions

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy All Users Approved App Or App Protection

Updated

With Conditional Access, organizations can restrict access to [approved (modern authentication capable) client apps with Intune app protection policies](concept-conditional-access-grant.md#require-app-protection-policy). For older client apps that may not support app protection policies, administrators can restrict access to [approved client apps](concept-conditional-access-grant.md#require-approved-client-app).

Policy All Users Device Compliance

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy All Users Device Registration

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy All Users Device Unknown Unsupported

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy All Users Mfa Strength

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy All Users Persistent Browser

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Alt Admin Device Compliand Hybrid

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Alt All Users Compliant Hybrid Or Mfa

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Guests Mfa Strength

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Old Require Mfa Admin

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Old Require Mfa Admin Portals

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Old Require Mfa Azure Mgmt

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

Policy Old Require Mfa Guest

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

2

Apple Sso Plugin

Updated

If your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.

2

Filter For Applications

Updated

Follow the instructions in the article, [Add or deactivate custom security attributes in Microsoft Entra ID](~/fundamentals/custom-security-attributes-add.md) to add the following **Attribute set** and **New attributes**.

Condition Filters For Devices

Updated

There are multiple scenarios that organizations can now enable using filter for devices condition. The following scenarios provide examples of how to use this new condition.

2

Permissions Reference

Updated

> | [Compliance Administrator](#compliance-administrator) | Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |

What If Tool

Updated

Start an evaluation by selecting **What If**. The evaluation result provides you with a report that consists of:

1
1
1

Agent Id

Updated

There are two key business scenarios where Conditional Access policies can help you manage agents effectively.

1

Managed Policies

Updated

This policy covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. High-risk in this case means something about the way the user signed in is out of the ordinary. These high-risk sign-ins might include travel that is highly abnormal, password spray attacks, or token replay attacks. For more information, see [What are risk detections](/entra/id-protection/concept-identity-protection-risks#sign-in-risk-detections).

1
1
1

Workload Identity

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

1

Zscaler Coexistence

Updated

1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…