← Previous day

Next day →
Day in brief

4 February 2026: an update-only period, with Agent ID risk and Global Secure Access recovery guidance standing out

The period contains 514 updated items, with no new or removed items and no Message Center notices. The supplied representative records are Microsoft Learn documentation updates rather than release announcements. The most actionable items cover Conditional Access for high-risk Agent ID identities, Global Secure Access break-glass recovery, governance of Conditional Access exclusions, and an SAP provisioning prerequisite. Nothing supplied establishes a new feature, preview, general availability milestone, retirement, or runtime behavior change; many other entries expose only generic author or page-update text.

  • The updated page explains how to configure Conditional Access policies to block risky agent identities and emphasizes security best practices. This is security guidance in Agent ID documentation, not evidence of a new control or changed enforcement. Teams using agent identities should compare their current policies and runbooks with the guidance.

  • Global Secure Access · Conditional Access
    Global Secure Access: break-glass recovery sample updated

    The updated PowerShell sample documents recovery from a Global Secure Access break-glass scenario by re-enabling Conditional Access policies that were disabled during the scenario. This is operational recovery guidance, not evidence of a new Global Secure Access feature or changed Conditional Access behavior. Global Secure Access operators should validate their recovery runbooks against the sample.

  • The updated guidance explains how to use access reviews to manage users excluded from Conditional Access policies. This is governance and security guidance; it does not indicate that exclusions or access reviews now behave differently. Tenants that maintain Conditional Access exclusion lists should review the process described.

  • The updated SAP Cloud Platform provisioning tutorial states that, before configuring automatic provisioning into SAP Cloud Identity Services, administrators must add the service from the Microsoft Entra application gallery to the tenant’s enterprise applications. The tutorial identifies both the Microsoft Entra admin center and Graph API as ways to do this. This is an ordinary setup clarification, not evidence of a new provisioning capability.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

514 updates

45

include file

Updated

include file Microsoft Entra ID preview program information

Users Close Account

Updated

How to close your work or school account in an unmanaged Microsoft Entra ID.

39

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

Configure Sso

Updated

Understand single sign-on with an on-premises app using application proxy.

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

17

What Is App Proxy

Updated

Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.

Sap Cloud Platform Identity Authentication Provisioning Tutorial

Updated

Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.

17
14

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

10
8
7
6

Govern the existing users of an application that does not support provisioning in Microsoft Entra ID with Microsoft PowerShell

Updated

Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.

3
2

Architecture overview

Updated

Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.

1
9

Agent Lists

Updated

Access Microsoft Entra admin center to effortlessly view and filter agent identities. Streamline tenant oversight and take charge now.

Agent metadata and discoverability patterns

Updated

Learn how to structure agent metadata for optimal discoverability in Microsoft Entra Agent Registry and understand how the collections model affects agent visibility.

Manage Agent Blueprint

Updated

This article explains how to manage agent blueprints and registry-only agents using the Microsoft Entra Admin Center.

4

Agent Identities

Updated

Learn about agent identities in Microsoft Entra ID, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.

Call Api Microsoft Graph

Updated

Learn how to call Microsoft Graph API from an agent using agent identities or agent users, including authentication configuration and implementation steps.

What Is Agent Id

Updated

Learn about agent identities, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.

What Is Agent Id Platform

Updated

Learn about the Microsoft Agent Identity Platform, a comprehensive identity, and authorization framework designed specifically for AI agents. Key concepts include agent registry, authentication protocols, tokens, claims, and agent discovery capabilities.

4

Call Api Azure Services

Updated

Learn how to call Azure services using .NET Azure SDK from an agent using agent identities.

Register Agents to the Agent Registry

Updated

Learn how to register agents to the Agent Registry in Microsoft Entra Agent ID through automatic registration or manual API calls for agent discovery and management.

3

Agent Autonomous App Oauth Flow

Updated

Learn how agent identities operate autonomously without user context using app-only protocol with OAuth 2.0 client credentials flows.

Agent On Behalf Of Oauth Flow

Updated

Learn how agent applications operate on behalf of signed-in users using OAuth 2.0 On-Behalf-Of flows with agent identity blueprints and agent identities.

Agent User Oauth Flow

Updated

Learn how agent identities operate with user context through agent users using the agent user impersonation protocol with OAuth 2.0 token exchange.

1
1

What Is Agent Registry

Updated

Learn about the Agent Registry, a centralized metadata repository that enables agent discovery, and secure communication in enterprise environments.

1
1

Call Api Custom

Updated

Learn how to call custom protected APIs from an agent using different approaches including IDownstreamApi, MicrosoftIdentityMessageHandler, and IAuthorizationHeaderProvider.

1

Preview Known Issues

Updated

Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.

12
10
1
1
1
141

Govern access for applications in your environment

Updated

Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.

Migrate identity management scenarios from SAP IDM to Microsoft Entra

Updated

Learn the detailed steps for how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and provision those identities with access to SAP ECC, SAP S/4HANA, and other SAP and non-SAP applications, for organizations that were previously using SAP IDM.

Pim Powershell Migration

Updated

The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.

Customize Workflow Email

Updated

Get a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.

Manage access to your SAP applications

Updated

Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.

Manage access with access reviews

Updated

Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.

Manage Workflow On Premises

Updated

A how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.

Manage Workflow Tasks

Updated

This article guides a user on managing workflow versions with Lifecycle Workflows.

On Demand Workflow

Updated

This article guides a user to running a workflow on demand using Lifecycle Workflows.

Pim Apis

Updated

Information for understanding the APIs in Microsoft Entra Privileged

Pim Roles

Updated

Describes the roles you can't manage in Microsoft Entra Privileged Identity

Provision Ldap

Updated

This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.

Provision Sap

Updated

This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.

Provision Sql

Updated

This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host

Reprocess Workflow

Updated

This article guides a user on reprocessing workflow runs using Lifecycle Workflows

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

20

Microsoft Entra ID Governance

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

What are access reviews? - Microsoft Entra

Updated

Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.

Lifecycle Workflow On Premises

Updated

Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.

What is entitlement management?

Updated

Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external identities.

2
2
1
2
1

B2b Guest Access

Updated

Learn how Global Secure Access enables secure B2B guest access for external partners through the Global Secure Access client and Azure Virtual Desktop.

7

Data Storage And Privacy

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

Points Of Presence

Updated

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.

2

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

Internet Access

Updated

Learn about how Microsoft Entra Internet Access secures access to the Internet.

1
1

Event Enrichment Logs

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

1

Configure Cloud Firewall

Updated

Learn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.

10

Ciphers

Updated

Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.

Configure Connectors

Updated

Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.

Configure Quick Access

Updated

Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.

Enable Multi Geo

Updated

Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.

3

Connector Groups

Updated

Learn how Microsoft Entra private network connector groups work, and how Microsoft Entra Private Access and application proxy use them.

Connectors

Updated

Learn how Microsoft Entra private network connectors work and how Microsoft Entra Private Access and application proxy use them.

Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

2

Configure Per App Access

Updated

Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.

1
2

Dnsbind

Updated

Learn how to link your domain to your decentralized identifier (DID).

2

Use Quickstart

Updated

In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.

1
2
46

China User Support

Updated

Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.

Create Remote Networks

Updated

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

Manage Microsoft Profile

Updated

Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.

Quickstart Install Client

Updated

Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.

Remote Network Configurations

Updated

Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.

Role Based Permissions

Updated

Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.

16

Transport Layer Security

Updated

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

What Is Global Secure Access

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

Alerts

Updated

ai-usage: ai-assisted

Partner Ecosystems Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

Remote Network Connectivity

Updated

Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.

Traffic Dashboard

Updated

Monitor the health and status of your network traffic with the Global Secure Access dashboard.

Traffic Forwarding

Updated

Learn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.

9

Troubleshoot Distributed File System

Updated

A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.

7

Access Audit Logs

Updated

Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.

View Traffic Logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

Remote Network Health Logs

Updated

Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.

Use Workbooks

Updated

Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.

View Enriched Logs

Updated

Learn how to use enriched Microsoft 365 logs for Global Secure Access.

7

Cisco Coexistence

Updated

Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.

Palo Alto Coexistence

Updated

Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.

Transport Layer Security

Updated

Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.

3

Quickstart Remote Network

Updated

Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.

2
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…