← Previous day

Next day →
Day in brief

Conditional Access guidance changes for patched Windows 11 23H2; the rest is targeted administrator documentation

8 April was a documentation-maintenance period rather than a release day: all 24 supplied records are updates, with no new or removed items and no Message Center notices. The most consequential item is revised Entra ID Conditional Access guidance for Windows 11 version 23H2 with KB5034848 or later. Other substantive updates cover a Windows App Protection/MAM enrollment caveat, break-glass account exclusions, and the location of authentication-context targeting controls. The page titled “Add a Microsoft Entra ID tenant as an OpenID Connect identity provider (Preview)” was updated, but the evidence does not establish a new preview rollout, general availability, retirement, or changed availability.

  • The updated Entra ID authentication guidance says the authentication prompt normally occurs after a device has been offline for an extended period, and that Windows 11 version 23H2 with KB5034848 or later no longer needs an exclusion in the Conditional Access policy. It also says a policy can still be used when the administrator does not want the authentication prompt delivered as a toast notification. This documents a behavior change; it is not evidence of a new Entra feature launch.

  • The updated Entra ID policy guidance identifies a known issue: a pre-existing, unregistered account in Microsoft Edge, or a user who signs in without registering through the Heads Up Page, is not properly enrolled in MAM; this configuration blocks proper enrollment. Administrators relying on Windows app protection should validate the affected sign-in and enrollment paths.

  • The updated Filter For Applications instructions direct administrators to use Exclude > Users and groups and select the organization’s emergency-access or break-glass accounts. This is security configuration guidance for protecting recovery access, not evidence of a new filtering capability or enforcement change.

  • The Conditional Access cloud-apps documentation states that administrators select published authentication contexts under Assignments > Target resources, using the Select what this policy applies to menu. This is a navigation and configuration clarification; the supplied evidence does not indicate that authentication contexts entered preview or general availability on this date.

  • The updated Policy Block By Location page shows a link to the shared Conditional Access templates reference, and similar link-only updates appear on several other policy-example pages. This is ordinary documentation organization; the supplied evidence does not show a change to those policies’ defaults or enforcement behavior.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

24 updates

9

Conditional Access Cloud Apps

Updated

Admins can select published authentication contexts in Conditional Access policies by going to **Assignments** > **Target resources** and selecting **Authentication context** from the **Select what this policy applies to** menu.

Policy Alt All Users Compliant Hybrid Or Mfa

Updated

The prompt for authentication usually occurs when a device is offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired.

3

Authentication Passkeys Fido2

Updated

:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png" alt-text="Screenshot that shows how to delete a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png":::

3

Filter For Applications

Updated

1. Under **Exclude**, select **Users and groups** and choose your organization's emergency access or break-glass accounts.

2
1
1
1

Policy All Users Require Terms Of Use

Updated

To test your policy, try to sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a test account. You should see a dialog that requires you to accept your terms of use.

1

Policy All Users Windows App Protection

Updated

There's a known issue where there's a pre-existing, unregistered account, like `user@contoso.com` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

1
1

Plan Conditional Access

Updated

- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…