← Previous day

Next day →
Day in brief

Entra documentation refresh reinforces MFA, federation, and API migration guidance

On 29 April, all 12 recorded changes were updates to Microsoft Learn documentation for Microsoft Entra ID. No new or removed items and no Message Center announcements were supplied, so the evidence does not indicate a new feature launch, preview, general-availability change, retirement, or automatic tenant-behavior change. The substantive updates are revised security and modernization recommendations, plus a concrete certificate-based authentication troubleshooting clarification; other edits appear to be ordinary reference or compatibility documentation maintenance.

  • The Entra ID customer-intent guidance emphasizes migrating users to the Microsoft Authenticator app as the secure MFA direction. This is updated security guidance, not evidence of a newly released authentication method or an automatic user migration; compare it with existing MFA rollout plans.

  • The updated guidance recommends moving application authentication from Active Directory Federation Services to Microsoft Entra ID. Administrators with AD FS-dependent applications should use it for dependency and migration planning; no retirement date or enforced behavior change is stated in the supplied evidence.

  • The recommendation page covers migrating from MFA Server to Microsoft Entra multifactor authentication. It provides planning guidance for tenants that still use MFA Server, but the update itself is not presented as a retirement announcement or a service rollout.

  • Entra ID · Microsoft identity platform
    Azure AD Graph migration guidance was updated

    Microsoft Entra’s recommendation now covered by the updated page is to migrate applications and automation from Azure Active Directory Graph APIs to Microsoft Graph APIs. Administrators should identify remaining Azure AD Graph dependencies; the supplied change does not specify a new API capability or migration deadline.

  • The Certificate Based Authentication Certificate Revocation List page states that failed CRL downloads are often caused by firewall restrictions and directs administrators to allow the required IP addresses so Microsoft Entra can retrieve the CRL. This is operational troubleshooting guidance, relevant when CBA encounters CRL download failures rather than evidence of changed authentication behavior.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

12 updates

5

Certificate Based Authentication Certificate Revocation List

Updated

When a problem prevents Microsoft Entra from downloading the CRL, the cause is often firewall restrictions. In most cases, you can resolve the issue by updating firewall rules to allow the required IP addresses so Microsoft Entra can successfully download the CRL. For more information, see [Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=56519).

3

Sso Linux

Updated

Microsoft single sign-on for Linux is supported on the following operating systems (physical or Hyper-V machines with x86/64 CPUs):

Whats New Linux

Updated

- Ensure that all browser calls are done in the same thread

Connect Install Roadmap

Updated

* Make sure that you [satisfy the requirements](how-to-connect-health-agent-install.md#requirements) for Microsoft Entra Connect Health.

2

Directory Join

Updated

| **Definition** | <ul><li>Joined only to Microsoft Entra ID requiring organizational account to sign in to the device</li></ul> |

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…