← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

External ID adds a consolidated identity-provider guide as legacy Entra settings lose effect

External ID introduced a single procedure for adding configured OIDC, SAML/WS-Fed, and social identity providers to user flows, while provider-specific pages now point to it and the standalone SAML/WS-Fed procedure has been removed. Entra guidance also clarifies that legacy My Staff settings no longer control access. The remaining substantive updates improve SAP SuccessFactors workload-identity prerequisites, provisioning-validation troubleshooting, and SAML security checks; most other edits are link consolidation, terminology cleanup, or Microsoft Copilot renaming.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

31 updates

4

Use My Staff to delegate user management

Retirement

My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.

Licensing Service Plan Reference

Doc update

Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.

Licensing Service Plan Reference

Doc update

Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.

My Staff Configure

Doc update

The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.

3

Validate User Provisioning App Gallery

Doc update

The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.

Validate Saml Single Sign On App Gallery

Doc update

The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.

Validate Saml Single Sign On App Gallery

Doc update

The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.

2

Authentication Qr Code

Doc update

The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.

Fido2 Compatibility

Doc update

The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.

2

End-user experiences for applications

Retirement

The documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.

Publish App Gallery

Doc update

The app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.

1

Tenant Estate Primary

Doc update

The tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

1
1
1

Permissions Reference

Doc update

The AI Administrator and AI Reader descriptions were updated from “Microsoft 365 Copilot” to “Microsoft Copilot.” Their role IDs remain unchanged.

1

Entitlement Management Access Package Request Policy

Doc update

The documentation now specifies that existing guest users can be directly assigned, but external users who are not yet in the directory cannot be invited through direct assignment when access is limited to administrator direct assignments.

6

Apple Federation Customers

Doc update

The article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.

Add an identity provider to a user flow

Doc update

A single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.

Entra Id Federation Customers

Doc update

The article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.

Custom Oidc Federation Customers

Doc update

The article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.

Facebook Federation Customers

Doc update

The article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.

Google Federation Customers

Doc update

The article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.

3

Microsoft Accounts Federation Customers

Doc update

The article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.

Direct Federation

Doc update

The External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.

Saml Ws Federation Self Service Sign Up

Doc update

The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.

2

Manage User Profile Info

Doc update

The user profile information documentation no longer includes guidance that users can use My Apps preview features or that administrators can access My Staff.

Manage User Profile Info

Doc update

The user profile information guidance no longer includes the “Manage user feature settings” reference.

1
1

Generative Ai Insights

Doc update

The documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

1

How to configure custom headers (preview)

Doc update

The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.

1

Secure Generative Ai

Doc update

The guidance now labels the link “Microsoft Copilot requirements” instead of “Microsoft 365 Copilot requirements.”

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…