Dragon Administrator
Entra ID token/API guidance and role-permission references changed; 12 September was otherwise documentation-led
The clearest administrator-relevant edits were updates to Entra ID guidance for protected web APIs and token versions, along with permission-reference updates for Global Administrator and Global Reader. External ID documentation also clarified that Directory Synchronization Accounts are used only by the Microsoft Entra Connect service. These records show documentation updates, not a confirmed new feature, preview, general-availability release, retirement, or service-side behavior change. The one item marked New, "Dragon Administrator," has no supplied detail beyond its title, so its purpose and administrative impact cannot be assessed from this feed.
- Protected web API app-configuration guidance now covers bearer tokens
Entra ID · Security
The Entra ID "Scenario Protected Web Api App Configuration" page was updated with guidance on how to configure a bearer token. This is a configuration-documentation update; the record does not establish a new API capability or an availability change.
- Token-version guidance states that both v1.0 and v2.0 tokens can be issued
Entra ID · Microsoft identity platform
The updated "Accepted Token Versions" page states that the Microsoft identity platform can issue v1.0 and v2.0 tokens and links to the access-token reference. It clarifies the documented token-version model but does not indicate a change to issuance defaults or service behavior.
- Global Administrator permission documentation covers full shipping-address task access
Entra ID · General
The updated Global Administrator reference lists microsoft.hardware.support/shippingAddress/allProperties/allTasks, covering create, read, update, and delete operations for Microsoft hardware warranty shipping addresses, including addresses created by others. This is evidence of a role-reference update, not proof that the underlying role grant changed on this date.
- Global Reader permission documentation covers read access to hardware-warranty shipping addresses
Entra ID · General
The updated Global Reader reference lists microsoft.hardware.support/shippingAddress/allProperties/read for reading Microsoft hardware warranty shipping addresses, including existing addresses created by others. The supplied evidence describes the documented permission scope but does not establish a service-side permission change.
- External ID clarifies the scope of Directory Synchronization Accounts
External ID · Provisioning
The updated Permissions Reference identifies Directory Synchronization Accounts as being used only by the Microsoft Entra Connect service and records the associated identifier d29b2b05-8046-44ba-8758-1e26182fcf32. The change is a permission-reference clarification; no account-behavior change is stated.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Entra ID
5 updatesGlobal Administrator
Updated> | microsoft.hardware.support/shippingAddress/allProperties/allTasks | Create, read, update, and delete shipping addresses for Microsoft hardware warranty claims, including shipping addresses created by others |
Global Reader
Updated> | microsoft.hardware.support/shippingAddress/allProperties/read | Read shipping addresses for Microsoft hardware warranty claims, including existing shipping addresses created by others |
Accepted Token Versions
UpdatedThe Microsoft identity platform can issue v1.0 tokens and v2.0 tokens. For more information about these tokens, refer to [Access tokens](/entra/identity-platform/access-tokens).
- How to configure a bearer token.
Microsoft Entra External ID
1 updatePermissions Reference
Updated> | [Directory Synchronization Accounts](#directory-synchronization-accounts) | Only used by Microsoft Entra Connect service. | d29b2b05-8046-44ba-8758-1e26182fcf32 |
