← Previous day

Next day →
Day in brief

Microsoft Entra Connect and PTA deployment guidance is the day’s main change; no feature rollout is evidenced

30 September was a documentation-only Entra ID day: all 14 supplied changes were Microsoft Learn updates, with no new or removed items and no Message Center changes. The meaningful edits clarify hybrid identity prerequisites—supported Connect hosts, TLS 1.2, PTA agent host limits, and gMSA schema level—rather than announce a new capability or change tenant behavior.

  • The updated prerequisites state that Microsoft Entra Connect must run on a domain-joined Windows Server 2022, 2019, or 2016 server, with Windows Server 2022 recommended. Windows Server 2016 is in extended support and may require a paid support program for supported configurations; unsupported server versions may cause failures or unexpected behavior. This is deployment guidance, not evidence of a new product capability or retirement.

  • The updated quick start directs administrators to enable TLS 1.2 when it is not already enabled, use a server in the same Active Directory forest as the users whose passwords need validation, and notes that installing the Pass-through Authentication agent on Windows Server Core is unsupported. The evidence documents deployment prerequisites; it does not show a change to PTA runtime behavior.

  • A prerequisites update states that the Active Directory schema in the gMSA domain’s forest needs to be updated to Windows Server 2012 or later. Administrators using the affected gMSA-based setup should verify the schema level before deployment; the supplied change is a documentation clarification rather than a feature announcement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

14 updates

8

Prerequisites

Updated

- The Active Directory schema in the gMSA domain's forest needs to be updated to Windows Server 2012 or later.

Prerequisites

Updated

|Requirement|Description and more requirements|

2

Connect Pta Quick Start

Updated

1. Identify a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016 to run Microsoft Entra Connect. If not enabled already, [enable TLS 1.2 on the server](./how-to-connect-install-prerequisites.md#enable-tls-12-for-azure-ad-connect). Add the server to the same Active Directory forest as the users whose passwords you need to validate. It should be noted that installation of Pass-Through Authentication agent on Windows Server Core versions isn't supported.

1
1
1

Connect Install Prerequisites

Updated

- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.

1

Error Codes

Updated

| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…