Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Server.
Action required: explicitly target Azure DevOps in Conditional Access before 18 September; most other changes are documentation guidance.
The period’s consequential product change is a Microsoft Entra Conditional Access behavior update for Azure DevOps sign-ins. Microsoft says policies applied via Azure Resource Manager will no longer cover those sign-ins, with full enforcement by 18 September 2025. Other notable entries are documentation work: refreshed Group Source of Authority guidance, a new GitHub Enterprise Server provisioning guide, and updated Global Secure Access web-content filtering instructions. Two documentation pages were removed, but the evidence does not establish retirement of the underlying capabilities.
- Conditional Access handling for Azure DevOps is changing
Entra ID · Conditional Access
A Microsoft 365 Message Center major update says Microsoft Entra will stop applying Conditional Access policies via Azure Resource Manager for Azure DevOps sign-ins from 2 September 2025, with full enforcement by 18 September. Organizations must explicitly include Azure DevOps, App ID 499b84ac-1321-427f-aa17-267ca6975798, in affected policies. This is an action-required behavior change, not a documentation clarification.
- Group Source of Authority guidance was refreshed for hybrid group operations
Entra ID · Fundamentals
The updated guidance describes transitioning AD DS group management to Microsoft Entra ID and covers group management, provisioning, restoration, and rollback in hybrid and cloud environments. The record supports updated operational guidance, not a new feature launch or general-availability change.
- New documentation covers GitHub Enterprise Server provisioning
Entra ID · Provisioning
A new Microsoft Learn page documents automatic provisioning and de-provisioning of user accounts from Microsoft Entra ID to GitHub Enterprise Server. This supports the addition of an implementation guide; it does not by itself establish that the integration launched or changed availability.
- Global Secure Access web-content filtering setup guidance was updated
Global Secure Access · General
The updated configuration instructions tell administrators to name a rule and add either a web category or a valid FQDN. This is a procedure-level documentation update; the supplied evidence does not state a change to web-filtering behavior or availability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
22 updates
Microsoft Entra ID
18 updatesLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Server.
Learn how to preserve and use the original organizational unit (OU) for group provisioning in Microsoft Entra ID.
| --- |:---:| --- |
A Microsoft Entra documentation page was updated: Github Ae Provisioning Tutorial.
Discover how to manage and transition Active Directory groups to Microsoft Entra ID using Group Source of Authority (SOA). Learn best practices for group management, provisioning, restoring, and rolling back changes in hybrid and cloud environments.
Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID using group source of authority (SOA).
Govern On Premises Groups
UpdatedThis article provides an overview of how to use cloud sync to govern on-premises application access using groups.
author: justinha
Discover how linkable identifiers like session IDs and unique token identifiers in Microsoft Entra help track and investigate identity-related activities, enhancing security and transparency.
- Augmentation Loop
When you publish an application through Microsoft Entra application proxy, you create an external URL for your users. This URL gets the default domain *`yourtenant.msappproxy.net`*. For example, if you publish an app named *Expenses* in your tenant named *Contoso*, the external URL is *`https://expenses-contoso.msappproxy.net`*. If you want to use your own domain name instead of *`msappproxy.net`*, you can configure a custom domain for your application.
* GitHub Enterprise Server supports **SP** and **IDP** initiated SSO.
Step-by-step guide to identifying, triaging, and removing unused security and distribution groups in Active Directory Domain Services (AD DS) using a structured scream test methodology. Improve security and reduce administrative burden by cleaning up groups no longer needed in your domain.
author: Justinha
| **Roles** | [Hybrid Administrator](/entra/identity/role-based-access-control/permissions-reference#hybrid-administrator) is required to call the Microsoft Graph APIs to read and update SOA of groups.<br>[Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator) or [Cloud Application Administrator](/entra/identity/role-based-access-control/permissions-reference#cloud-application-administrator) is required to grant user consent to the required permissions to Microsoft Graph Explorer or the app used to call the Microsoft Graph APIs. |
Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
Microsoft Entra External ID
1 updateMicrosoft will enforce multifactor authentication (MFA) for all Azure resource management actions starting October 1, 2025, with a postponement option until July 2026. Users must enable MFA, update Azure CLI/PowerShell, and can apply Azure Policy to assess impact. Gallatin customers are advised to implement MFA without enforcement.
Microsoft Entra Global Secure Access
3 updatesGET hhttps://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=msn.com/en-us/sports
1. Enter a name, select a [web category](reference-web-content-filtering-categories.md) or a valid FQDN, and then select **Add**.
A Microsoft Entra documentation page was updated: Configure Threat Intelligence.
