The same issue occurs when a server with Microsoft Entra Connect installed is cloned into another production server, which isn't a supported method of deploying this product as these servers with share the same machine identifier. In short, the server's identity conflicts because they get tied to one app registration. The Microsoft Entra Connect wizard by default uses unique accounts per server because it uses the server's name to identify the application registration instead of the Microsoft Entra connector's service account, which avoids this issue.
Conditional Access control retirement is the main actionable change
The period is mostly documentation maintenance, but it includes a concrete lifecycle change: Microsoft will retire the Microsoft Entra Conditional Access “Require approved client app” control in June 2026. A separate Microsoft Entra Connect update clarifies an unsupported server-cloning scenario and its application-identity consequences. The remaining supplied updates concern macOS onboarding and Global Secure Access or Internet Access documentation, with no evidence of a new feature, preview, general availability change, or changed behavior.
- “Require approved client app” control scheduled for retirement
Entra ID · Conditional Access
The Microsoft 365 Message Center says the Microsoft Entra Conditional Access “Require approved client app” control will retire in June 2026. Organizations should use “Require application protection policy” instead for equivalent and enhanced protection. After retirement, the old control will no longer be enforceable.
- Microsoft Entra Connect cloning guidance clarifies an application-identity conflict
Entra ID · Authentication
Updated troubleshooting guidance states that cloning a server with Microsoft Entra Connect into another production server is unsupported because cloned servers share a machine identifier and become tied to one app registration. It also explains that the Connect wizard normally avoids this issue by using the server name to identify the application registration and thereby providing unique accounts per server.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Entra ID
3 updatesThe "Require approved client app" control in Microsoft Entra Conditional Access will retire in June 2026. Organizations should update policies to use the "Require application protection policy" control for equivalent and enhanced protection. After retirement, the old control will no longer be enforceable.
Macos Get Started
UpdatedAdding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using applications such as Microsoft Outlook or Microsoft Edge.
Microsoft Entra Internet Access
1 update- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
Configure Domain Controllers
Updatedmanager: dougeby
