Day in brief

Tenant Governance (preview) documentation dominates the day; Entra ID guidance sharpens MFA and workload-identity boundaries

All 41 recorded changes for 1 May were Microsoft Learn documentation updates; there were no new, removed, or Message Center records. The main substantive thread is a coordinated Microsoft Entra ID Governance refresh for Tenant Governance (preview), covering setup, tenant discovery, governance relationships, and configuration monitoring. This indicates expanded preview guidance, not general availability or a product launch. Other notable updates clarify Security Defaults token revocation, Workload ID Conditional Access scope, Combined registration behavior, and an Agent ID logging capability listed as new without availability details.

  • Updated ID Governance guidance describes Tenant Governance from setup through tenant discovery, governance, and configuration monitoring. The wider preview documentation set adds material on governance relationships, related-tenant signals, monitors, configuration drift, and licensing. These are documentation updates for a capability explicitly labeled preview; the evidence does not establish GA or a production rollout.

  • The updated Entra ID guidance says administrators should revoke all existing tokens when enabling Security Defaults. This forces previously authenticated users to authenticate again and register for multifactor authentication, using the documented Revoke-MgUserSignInSession cmdlet in Microsoft Graph PowerShell. This is security guidance and documentation clarification, not a new feature announcement.

  • The updated guidance says Conditional Access can apply to single-tenant service principals registered in the tenant. Non-Microsoft SaaS and multitenant apps are out of scope, and managed identities are not covered. A separate Workload ID update also states that, without appropriate licenses, existing workload-identity policies continue to function but cannot be modified.

  • Updated Entra ID guidance states that Combined registration requires all MFA-capable users to strongly authenticate before registering or managing security information. The record presents this as a documented default behavior and does not say that the behavior changed during this period.

  • The updated Ignite 2025 What's New page lists sign-in and audit logs for agents as New. This is an explicit new-capability reference, but the supplied record is only a documentation entry and provides no preview or GA status, availability date, prerequisites, or rollout details.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

41 updates

4

Security Defaults

Updated

As part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.

Registration Mfa Sspr Combined

Updated

By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.

Frontline Worker Management

Updated

Frontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).

4

Whats New

Updated

**Service category:** User Experience and Management

Five Steps To Full Application Integration

Updated

In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.

2
1

Policy All Users Windows App Protection

Updated

There's a known issue where there's a preexisting, unregistered account, like `user@contoso.com` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

1

Whats New Ignite 2025

Updated

- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)

22

Create a monitor (preview)

Updated

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

Enable tenant discovery (preview)

Updated

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

Pim How To Add Role To User

Updated

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

1
1
1
1

Register Didwebsite

Updated

The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.

2

Workload Identity

Updated

> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).

Conditional Access Users Groups

Updated

A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.

1

Bring Your Own Device

Updated

1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…