Default application
Updatedmanager: mwongerapk
Daily.Entra.NewsAll 10 supplied records are Microsoft Learn updates; there are no new or removed records and no Message Center item. The period therefore reflects documentation clarification rather than a feature launch, preview, general-availability change, or retirement. The most consequential details concern a regional Workload ID restriction, an Entra ID Remote Desktop access limitation, the Agent ID API-consent model, and the guest-account consequence of external access-package assignment.
The updated Workload Identity Federation Considerations guidance says federated identity credentials cannot currently be created on user-assigned managed identities in certain regions. The supplied extract does not include the region names, so administrators should use the page’s region list when planning deployments. This is a documented constraint, not evidence of an availability expansion.
The updated Assign Local Admin guidance states that Microsoft Entra groups deployed to a device through this policy do not apply to Remote Desktop connections. To control RDP permissions on Microsoft Entra joined devices, it directs administrators to add the individual user’s SID to the appropriate group. This is a documented behavior caveat, not a reported new policy feature.
The assignment guidance explains that an application can expose an API and OAuth scopes, while the tool’s service principal can be granted consent to those scopes to call the API. For agent integrations, the concrete administrative concern is which scopes and consent are assigned; the update does not by itself establish a new release or availability stage.
The updated Kerberos page describes an Entra ID-joined Windows client accessing a file share or application over the internet, with Microsoft Entra ID issuing the necessary Kerberos tickets as a KDC associated with the resource. This is an architecture and scenario clarification; the supplied evidence does not say that tenant configuration or availability changed.
The access-package request-policy guidance says that, after an access package is created, administrators can directly assign internal or external users and that specifying an external user creates a guest user account in the directory. This is a lifecycle detail to account for when managing external assignments, not evidence of a new entitlement-management policy.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
manager: mwongerapk
For example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Microsoft Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.
- [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 groups, and SharePoint sites](/purview/sensitivity-labels-teams-groups-sites)
- Windows Server 2019 or newer that are hybrid Microsoft Entra joined.
- Microsoft Entra groups deployed to a device with this policy don't apply to remote desktop connections. To control remote desktop permissions for Microsoft Entra joined devices, you need to add the individual user's SID to the appropriate group.
Applications using the Microsoft Entra identity platform can [expose APIs for other client applications to call](../../identity-platform/quickstart-configure-app-expose-web-apis.md#register-the-web-api). The application with the API can expose OAuth scopes for those API calls. The tool's service principal can be consented permission to those scopes, allowing it to call the APIs.
After you create the access package, you can directly assign specific internal and external users to it. If you specify an external user, a guest user account is created in your directory. For information about directly assigning a user, see [View, add, and remove assignments for an access package](~/id-governance/entitlement-management-access-package-assignments.md).
> [!NOTE]
1. Select **New assignment** to open Add user to access package.
Creation of federated identity credentials is currently **not supported** on user-assigned managed identities created in the following regions: