Learn how to attach custom x-* headers to native authentication requests in a React or Angular SPA to integrate fraud-detection SDKs with Microsoft Entra External ID.
Action required: actionable-message tokens are being retired; one External ID integration guide was updated
22 May was a quiet period with one consequential Entra ID standards retirement and one External ID documentation update. The token retirement is the material administrator concern; the SPA change is guidance for a specific application-integration scenario, not evidence of a new service launch.
- External access tokens for actionable messages are being retired
Entra ID · Authentication
Microsoft 365 Message Center identifies a major standards update: external access tokens for actionable messages are being replaced by Microsoft Entra authentication to improve security. Organizations must update affected integrations; messages using the legacy tokens will fail. The stated retirement deadline was 15 May 2026, with the phase-out completing by 8 June 2026.
- External ID guidance now covers custom headers in native-authentication SPA requests
External ID · Authentication
The updated Microsoft Learn article explains how React and Angular single-page applications can attach custom x-* headers to native authentication requests, including for integration with fraud-detection SDKs. This is a documentation update for application owners rather than a reported availability or tenant-configuration change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
