← Previous day

Next day →
Day in brief

Security guidance leads 30 July: immutable GitHub Actions subjects, passkey migration, and Tenant Governance preview

30 July was primarily a Microsoft Learn documentation day, but it contained two important security threads. New Workload ID guidance covers the risk of mutable OIDC subjects and migration of GitHub Actions federated identity credentials to GitHub's immutable subject format; updated Entra ID guidance covers preparation for retiring Microsoft-provided SMS and voice authentication in favor of passkeys. ID Governance also added documented Microsoft Graph investigation guidance for related-tenant signals, explicitly in preview, and updated its delegated-administration guidance. The remaining edits, including Lifecycle Workflow email attributes, External ID OIDC setup, Global Secure Access tenant restrictions, and Cloud Sync prerequisites, are best read as instructional clarifications rather than confirmed launches or behavior changes.

  • Two new Workload ID pages form a related security guidance package: mutable OIDC subject claims can expose federated identity credentials to subject recycling, and GitHub Actions credentials can be migrated from mutable subjects to GitHub's immutable subject format. This is documentation and security guidance, not evidence of a new feature launch or an automatic tenant-wide change.

  • The updated page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. The supplied evidence does not provide a retirement date or establish that passkeys became the default, or that SMS and voice were disabled, on 30 July.

  • A new ID Governance page documents how Microsoft Graph can retrieve the underlying users and applications behind Tenant Governance related-tenant discovery signals. Because the route is explicitly preview, this is newly documented preview usage rather than evidence of general availability or a production behavior change.

  • Updated guidance describes cross-tenant delegated administration and its GDAP-based permission model for managing tenants in Microsoft Entra. This clarifies the documented operating model; the supplied evidence does not announce a new permission set or rollout on this date.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

15 updates

1
1

Prerequisites

Updated

- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).

8

Lifecycle Workflow Tasks

Updated

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:

Customize Workflow Email

Updated

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.

Interpret tenant discovery data

Updated

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

Related tenants in Tenant Governance

Updated

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

Governance Policy Templates

Updated

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

1

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

1

Gsa Poc Internet Access

Updated

1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

2
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…