← Previous day

Next day →
Day in brief

A future passkey-policy API retirement is the day’s material Entra change

The 20 November evidence is led by a Microsoft 365 Message Center major update: Microsoft plans to retire two duplicative properties from the Microsoft Entra ID passkey (FIDO2) policy API in the October–November 2027 window. The other substantive entries are updated TLS inspection guidance for Global Secure Access and Microsoft Entra Internet Access, plus Entra Connect certificate-monitoring guidance. The supplied record contains no new-feature, preview, or general-availability announcement; the latter items are documentation clarifications.

  • Retirement and future API schema change: Microsoft plans to retire isAttestationEnforced and keyRestrictions from the fido2AuthenticationMethodConfiguration API from October through November 2027. During the transition, the notice says these properties will sync with new properties in the updated passkey policy API schema. Administrators must update configurations, automations, and integrations that depend on them; the notice does not announce an immediate change to end-user authentication behavior.

  • Documentation clarification and security guidance: the updated Global Secure Access page covers configuring a TLS inspection policy and assigning it to users. Related updates cover inspection certificate-authority settings and explain that Microsoft Entra Internet Access can make encrypted-traffic content available for malware detection, data loss prevention, prompt inspection, and other advanced controls. The supplied evidence does not identify this as a new preview or general-availability milestone.

  • Ordinary troubleshooting documentation, not a behavior-change announcement: Microsoft Entra Connect warns when a certificate expires in 30 days or less, logs warning Event ID 1011, and emits error Event ID 1012 when the certificate is already expired. Both signals are available in the Application event log, giving operators concrete monitoring points for certificate rotation.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

21 updates

12

Sharepoint Administrator

Updated

> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

2

Authenticate Application Id

Updated

Microsoft Entra Connect warns if the certificate rotation is due. That is, if expiration is less than or equal to 30 days. It emits an error if the certificate is already expired. You can find these warnings (Event ID 1011) and errors (Event ID 1012) in the Application event log.

1

Bis Tutorial

Updated

1. On the **Basic SAML Configuration** section, perform the following step:

1
1
1
1

What is Transport Layer Security inspection?

Updated

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

2
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…