- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
Entra update: CBA documentation refresh and SCIM token-handling clarification
13 September was a documentation-focused day for Microsoft Entra ID: all 10 recorded changes were updates to Microsoft Learn pages, with no new or removed items and no Message Center entries. Eight updates covered certificate-based authentication (CBA), while two covered provisioning and SCIM. The evidence supports documentation clarification and maintenance, not a confirmed feature launch, retirement, or service-behavior change.
- Microsoft Entra certificate-based authentication guidance was refreshed
Entra ID · Authentication
Eight Entra ID fundamentals pages were updated across CBA topics, including certificate revocation lists, the technical deep dive, certificateUserIds, limitations, migration, Android and iOS support, and smart-card use. The surfaced revocation-list guidance states that a CA-issued certificate remains valid until expiration unless revoked earlier; each certificate contains a public key and is signed by the CA. The record does not establish a change to CBA behavior, availability, or tenant settings.
- SCIM guidance documents token validation during provisioning requests
Entra ID · Standards
The updated SCIM guidance describes the provisioning cycle checking whether the current access token is valid, exchanging it for a new token when needed, sending the token with each request to the application, and checking request validity before each request. This supports an integration-documentation review; it does not by itself indicate a new provisioning capability or a change in service behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
10 updates
Microsoft Entra ID
10 updates- **Certificate Issuance:** When a certificate is issued by a CA, it is valid until its expiration date unless it is revoked earlier. Each certificate contains a public key and is signed by the CA.
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Technical deep dive for Microsoft Entra CBA](concept-certificate-based-authentication-technical-deep-dive.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in TestApp based on user and/or group assignments in Microsoft Entra ID.
1. When the provisioning cycle begins, the service checks if the current access token is valid and exchanges it for a new token if needed. The access token is provided in each request made to the app and the validity of the request is checked before each request.
