Agent Optimization
Updatedauthor: MicrosoftGuyJFlo
Daily.Entra.NewsThis was primarily a Microsoft Learn documentation day: 2 new, 55 updated, and 7 removed records were reported, with no Message Center items. The evidence supports three concrete themes: an explicit Workload ID authentication-retirement deadline; updated Global Secure Access Internet Access guidance for Intune device-compliance bypasses and Universal Conditional Access tunnel limits; and new Microsoft–Netskope Security Service Edge coexistence guidance. The remaining representative Entra ID changes are mainly security-control and authentication documentation updates; nothing supplied establishes a feature launch, preview, GA change, or changed tenant enforcement.
The updated page carries an explicit requirement to act before March 31, 2026 to avoid application authentication failure. This is a retirement notice with a concrete deadline; the supplied evidence does not identify the replacement or migration method.
The updated Internet Access documentation addresses Intune device-compliance bypasses and links them to Universal Conditional Access tunnel-authorization limitations. It warns that blocking a forwarding profile in Conditional Access can inadvertently lock users out of anything on their machine. This is a configuration and safety clarification, not evidence of a new feature or enforcement rollout.
A new page explains how to configure and deploy Microsoft Entra and Netskope Security Service Edge solutions together across private applications, Microsoft 365, and internet access. The period also includes a new Global Secure Access/Netskope integration guide and an updated Netskope Coexistence page. These are documentation additions and updates; the supplied records do not announce preview or GA status.
An Entra ID page was updated on targeting privileged Microsoft Entra built-in roles with Conditional Access policies to enforce phishing-resistant methods. The supplied summary identifies a documentation update but does not say that policies were automatically created, modified, or newly enforced in tenants, so treat this as security guidance clarification.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
author: MicrosoftGuyJFlo
`https://<subdomain>.pm.appneta.com`
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
> [!IMPORTANT]
A Microsoft Entra documentation page was updated: Illumio Sso Tutorial.
A Microsoft Entra documentation page was updated: Kontiki Tutorial.
A Microsoft Entra documentation page was updated: Promapp Tutorial.
A Microsoft Entra documentation page was updated: Webmethods Integration Cloud Tutorial.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: justinha
1. To start the server, run the following commands from within the project directory:
zone_pivot_groups: enterprise-apps-minus-legacy-powershell
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
`https://<ApplicationURL>/portal`
This article describes security best practices for the following application properties:
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
Learn how to provision custom security attributes from HR sources.
A Microsoft Entra documentation page was updated: Veritas Provisioning Tutorial.
author: barclayn
```Failed to add identifier URI {uri}. All newly added URIs must contain a tenant verified domain, tenant ID, or app ID, as per the default tenant policy of your organization. See https://aka.ms/identifier-uri-addition-error for more information on this error.```
author: barclayn
author: cilwerner
Learn how to integrate Darwinbox HR with Microsoft Entra ID to automate user provisioning, manage lifecycle workflows, and streamline HR-driven processes.
Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.
1. **[Configuration 1: Microsoft Entra Private Access with Netskope Internet Access](#configuration-1-microsoft-entra-private-access-with-netskope-internet-access)**
ai-usage: ai-assisted
ai-usage: ai-assisted
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
The [Universal Conditional Access documentation](/entra/global-secure-access/concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authorization limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertently lock users out from accessing anything on their machine.
Learn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.
You must act **before March 31, 2026**, to avoid authentication failure of applications.
Microsoft services applications that operate in your tenant are identified as service principals with the owner organization ID "f8cdef31-a31e-4b4a-93e4-5f571e91255a". When these service principals have credentials configured in your tenant, they might create potential attack vectors that threat actors can exploit. If the credentials were added by an administrator and are no longer needed, they can become a target for attackers. Although less likely when proper preventive and detective controls are in place on privileged activities, credentials can also be added maliciously by threat actors. In either case, threat actors can use these credentials to authenticate as the service principal, gaining the same permissions and access rights as the Microsoft service application. This initial access can lead to privilege escalation if the application has high-level permissions, allowing lateral movement across the tenant. Attackers can then proceed to data exfiltration or persistence establishment through creating additional backdoor credentials.
author: barclayn
A comprehensive guide for configuring and testing the integration between Microsoft's and Netskope's Secure Access Service Edge (SASE) solutions.
author: kenwith
A Microsoft Entra documentation page was updated: Netskope Coexistence.
A Microsoft Entra documentation page was updated: Netskope Integration.