- Contractors are governed by their own policies separate from the baseline
29 May 2026: device-code-flow security guidance leads; other edits clarify policy scope and documentation
All four records are updates to Microsoft Learn documentation, with no new, removed, or Message Center items. The most consequential update is security guidance for the Entra ID Microsoft-managed policy covering device code flow. A second meaningful clarification says contractors are governed by policies separate from the Conditional Access baseline. The Workload ID assignment instruction and External ID supported-features material appear to be procedural or reference documentation maintenance; the supplied evidence does not indicate a new feature, preview, general availability release, retirement, or changed service behavior.
- Managed Policies documentation highlights device code flow as an attack vector
Entra ID · Developer
The updated Entra ID Managed Policies page says device code flow is rarely used by customers but frequently used by attackers, and states that enabling the Microsoft-managed policy helps remove this attack vector. This is updated security guidance, not evidence of a newly launched policy or an automatic enforcement change.
- Conditional Access guidance separates contractor coverage from the baseline
Entra ID · Conditional Access
The updated Conditional Access Agent Optimization Knowledge Base states that contractors are governed by their own policies, separate from the baseline. Administrators should check contractor-specific policy coverage rather than assume the baseline applies; the record does not show that Conditional Access enforcement behavior itself changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Entra ID
3 updatesConditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.
Managed Policies
UpdatedDevice code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.
Microsoft Entra External ID
1 updateSupported Features Customers
Updated| Feature | Workforce tenant | External tenant |
Microsoft Entra Workload ID
1 update1. Under **Assignments**, select **Users or workload identities**.
