To scope a group for Source of Authority operations within an Administrative Unit, do the following steps:
A future passkey-policy API retirement is the day’s material Entra change
The 20 November evidence is led by a Microsoft 365 Message Center major update: Microsoft plans to retire two duplicative properties from the Microsoft Entra ID passkey (FIDO2) policy API in the October–November 2027 window. The other substantive entries are updated TLS inspection guidance for Global Secure Access and Microsoft Entra Internet Access, plus Entra Connect certificate-monitoring guidance. The supplied record contains no new-feature, preview, or general-availability announcement; the latter items are documentation clarifications.
- Microsoft Entra ID schedules retirement of two passkey-policy API properties
Entra ID · Authentication
Retirement and future API schema change: Microsoft plans to retire isAttestationEnforced and keyRestrictions from the fido2AuthenticationMethodConfiguration API from October through November 2027. During the transition, the notice says these properties will sync with new properties in the updated passkey policy API schema. Administrators must update configurations, automations, and integrations that depend on them; the notice does not announce an immediate change to end-user authentication behavior.
- TLS inspection policy-assignment guidance was updated
Global Secure Access · Security
Documentation clarification and security guidance: the updated Global Secure Access page covers configuring a TLS inspection policy and assigning it to users. Related updates cover inspection certificate-authority settings and explain that Microsoft Entra Internet Access can make encrypted-traffic content available for malware detection, data loss prevention, prompt inspection, and other advanced controls. The supplied evidence does not identify this as a new preview or general-availability milestone.
- Entra Connect certificate-rotation monitoring guidance was clarified
Entra ID · Authentication
Ordinary troubleshooting documentation, not a behavior-change announcement: Microsoft Entra Connect warns when a certificate expires in 30 days or less, logs warning Event ID 1011, and emits error Event ID 1012 when the certificate is already expired. Both signals are available in the Application event log, giving operators concrete monitoring points for certificate rotation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
21 updates
Microsoft Entra ID
15 updatesTo scope a user for Source of Authority operations within an Administrative Unit, do the following steps:
Sharepoint Administrator
Updated> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
> | microsoft.backup/siteRestoreArtifacts/allProperties/allTasks | Manage sites added to restore session for SharePoint in Microsoft 365 Backup |
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
Agent Registry Administrator
Updated> | Actions | Description |
Connect Version History
Updated11/19/2025: Released for download via the Microsoft Entra admin center.
Dragon Administrator
UpdatedA Microsoft Entra documentation page was updated: Dragon Administrator.
Global Administrator
UpdatedA Microsoft Entra documentation page was updated: Global Administrator.
Global Reader
UpdatedA Microsoft Entra documentation page was updated: Global Reader.
Permissions Reference
Updated> [!div class="mx-tableFixed"]
User Administrator
UpdatedA Microsoft Entra documentation page was updated: User Administrator.
1. To add a redirect URI to the app that you registered earlier, use the steps in [Add a platform redirect URL](quickstart-mobile-app-sign-in.md#add-a-redirect-uri).
Authenticate Application Id
UpdatedMicrosoft Entra Connect warns if the certificate rotation is due. That is, if expiration is less than or equal to 30 days. It emits an error if the certificate is already expired. You can find these warnings (Event ID 1011) and errors (Event ID 1012) in the Application event log.
Bis Tutorial
Updated1. On the **Basic SAML Configuration** section, perform the following step:
Microsoft Entra Agent ID
2 updatesAgent Id Administrator
Updated> | --- | --- |
Agent Id Developer
Updated> | Actions | Description |
Microsoft Entra External ID
1 updateSecurity Customers
UpdatedMicrosoft Entra Internet Access
1 updateThe Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.
Microsoft Entra Global Secure Access
2 updatesLearn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
