← Previous day

Next day →
Day in brief

Conditional Access Agent permissions clarified; Lifecycle Workflows previews gain sharper administration guidance

The 1 November period was documentation-led: all 11 recorded changes were updates, with no new or removed items and no Message Center notices. The most consequential update clarifies that the Conditional Access Agent needs Global Administrator or Conditional Access Administrator together with Global Reader to identify Intune policies. ID Governance documentation also describes two preview capabilities—Administrative Unit-scoped workflow management and custom-attribute workflow triggers. The remaining updates appear to be page maintenance or status/table clarification rather than evidence of broad product launches.

  • The updated documentation states that, to identify Intune device-compliance and app-protection policies, the agent must run as a Global Administrator or Conditional Access Administrator and also have Global Reader. Conditional Access Administrator alone is not sufficient. This is a concrete prerequisite to verify when the agent is expected to produce Intune suggestions; the evidence supports a documentation clarification, not a confirmed service-behavior change.

  • The preview guidance explains how Administrative Units can scope workflow management so specific administrators manage only the workflows within their assigned scope. Without such scoping, workflows are managed by users with Lifecycle Workflows or Global administrator roles unless another arrangement is specified during creation. This gives administrators a least-privilege design option to evaluate, but the record does not indicate general availability.

  • The updated article explains using Custom Attribute Triggers as an attribute-change trigger within a Lifecycle Workflows workflow. The page is explicitly labeled Preview, so this update provides implementation guidance for evaluation rather than evidence of a generally available capability or a required production change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

11 updates

3

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

1
1

Conditional Access Agent Optimization

Updated

To identify Intune device compliance and app protection policies, the agent must be running as a Global Administrator or Conditional Access Administrator AND Global Reader. Conditional Access Administrator isn't sufficient on its own for the agent to produce Intune suggestions.

1
3

Delegated workflow management (preview)

Updated

Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…