Configure Adobe Identity Management (OIDC) for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (OIDC).
Daily.Entra.NewsThis was primarily a documentation-led period. The substantive Entra ID changes are new guidance for deactivating app registrations, related clarification of who can reactivate them, and updated security guidance for restricted management administrative units. Partner provisioning how-to pages were also refreshed, while the Global Secure Access connector update contains only an author note. The feed contains no Message Center item and does not establish preview, general availability, a product retirement, or a behavior rollout. A Deactivate Application Portal page is marked removed while another item with the same title is marked updated, but no reason is supplied, so this is not evidence of a capability retirement.
A new Microsoft Learn article explains how to deactivate an app registration so token issuance is prevented while the application configuration is preserved. This is a new documentation item describing a lifecycle operation, not a supplied preview, general-availability, or launch announcement.
An updated Deactivate Application Portal page says to remove all application owners before deactivation. That leaves reactivation to users with the tenant-wide microsoft.directory/applications/enable scope, which the page says is restricted to administrative roles. The evidence shows a documented security and permission boundary, not a confirmed enforcement change on this date.
The updated Entra ID What's New entry describes restricted management administrative units that limit management of users, groups, or devices to specified users or applications. Tenant-level administrators, including Global Administrators, cannot modify members unless they are explicitly assigned a role scoped to the administrative unit. No preview or general-availability status is provided.
Updates cover automatic provisioning and deprovisioning guidance for Adobe Identity Management using OIDC and SAML, Cofense Recipient Sync, myday, and Akamai Enterprise Application Access. The supplied summaries describe existing setup flows and identify no new connector, changed provisioning behavior, or required migration, so these are ordinary documentation updates.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (OIDC).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cofense Recipient Sync.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to myday.
This article describes the steps you need to perform in both Akamai Enterprise Application Access and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Akamai Enterprise Application Access](https://www.akamai.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
Before deactivating the application, remove all owners from the application. This ensures only users with tenant-wide `microsoft.directory/applications/enable` scope can reactivate the application. This scope is restricted to administrative roles.
A Microsoft Entra documentation page was updated: Deactivate Application Portal.
Restricted management administrative units enable you to easily restrict access to users, groups, or devices to the specific users or applications you specify. Tenant-level administrators (including Global Administrators) can't modify members of restricted management administrative units unless they're explicitly assigned a role scoped to the administrative unit. This makes it easy to lock down a set of sensitive groups or user accounts in your tenant without having to remove tenant-level role assignments. For more information, see: [Restricted management administrative units in Microsoft Entra ID](../identity/role-based-access-control/admin-units-restricted-management.md).
Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.
- [Delete an enterprise application](delete-application-portal.md) for permanent removal
A Microsoft Entra documentation page was updated: Multi Tenant Common Considerations.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML).
author: kenwith