Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.
Global Secure Access strict-location guidance leads an otherwise documentation-heavy day
On 10 February 2026, all 96 recorded changes were Microsoft Learn updates; there were no new or removed items and no Message Center notices. The clearest administrator-relevant content is a Global Secure Access Conditional Access limitation. The other selected items are integration or configuration guidance for Entra ID, Global Secure Access, and Private Access. The supplied evidence does not establish a new feature launch, preview or GA transition, retirement, or service-behavior change.
- Global Secure Access documents a strict-location Conditional Access limitation
Global Secure Access · Conditional Access
The updated Current Known Limitations page explicitly says not to enable strict location enforcement when IP location-based Conditional Access policies target non-Microsoft resources. This is security and rollout guidance, not a new feature announcement or evidence of changed enforcement behavior. Check this policy combination before enabling the setting.
- Entra ID/SAP provisioning guidance specifies an enterprise-application prerequisite
Entra ID · Authentication
The updated tutorial says that automatic provisioning into SAP Cloud Identity Services requires first adding SAP Cloud Identity Services from the Microsoft Entra application gallery to the tenant’s enterprise applications. The admin center or Graph API can be used. This is ordinary integration documentation clarification, not evidence of a new provisioning capability.
- Global Secure Access compliant-network check instructions were updated
Global Secure Access · Conditional Access
The updated guide explains how Conditional Access can require known compliant network locations before users connect to secured resources. It is configuration guidance; the supplied entry does not identify a new capability, preview, GA milestone, or changed enforcement semantics. Review it when validating a network-based Global Secure Access rollout.
- Private Access enablement guidance covers Intelligent Local Access
Private Access · General
The updated page explains how to enable Intelligent Local Access (ILA), described as optimizing traffic flow for clients accessing Microsoft Entra apps through private networks. The evidence does not identify this as a new launch or establish an availability change, so it should be treated as updated enablement guidance for relevant Private Access deployments.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
96 updates
Microsoft Entra ID
2 updatesIn this article, you can learn how to integrate SAP Cloud Identity Services with Microsoft Entra ID for single-sign on. When you integrate SAP Cloud Identity Services with Microsoft Entra ID, you can:
Microsoft Entra External ID
1 updateB2b Guest Access
Updatedai-usage: ai-assisted
Microsoft Entra Internet Access
6 updatesLearn how to configure web content filtering in Microsoft Entra Internet Access.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
PowerShell sample - Add Intune device compliance bypasses to Global Secure Access Internet Access
UpdatedPowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Learn about how Microsoft Entra Internet Access and Microsoft Entra Private Access secures access to your resources through Conditional Access.
Learn about how Microsoft Entra Internet Access secures access to the Internet.
Microsoft Entra Private Access
12 updatesLearn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.
Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
Enable Multi Geo
UpdatedLearn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
How to apply Conditional Access policies to Microsoft Entra Private Access apps.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Microsoft Entra Global Secure Access
75 updatesA Microsoft Entra documentation page was updated: Public Preview Important Note.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.
Macos Client Release History
UpdatedTrack the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.
author: fgomulka
Ciphers
Updatedauthor: HULKsmashGithub
Configure Cloud Firewall
Updatedauthor: jenniferf-skc
A Microsoft Entra documentation page was updated: Configure Threat Intelligence.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
Customize Block Page
Updatedauthor: fgomulka
Learn how to enable source IP restoration to ensure the source IP matches in downstream resources.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
author: HULKsmashGithub
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Learn how to configure per-app access to private resources in Global Secure Access.
Learn how to configure Quick Access to private resources in Global Secure Access.
Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
Remote Network Resilience
UpdatedThis article provides techniques to improve remote network resilience with Global Secure Access.
Secure Web Ai Gateway Agents
UpdatedLearn how to configure Secure Web and AI Gateway for Microsoft Copilot Studio agents using Global Secure Access.
Use Global Secure Access to configure Azure and Microsoft Entra resources to create a virtual wide area network to connect to your resources in Azure.
Source Ip Anchoring
Updatedauthor: jricketts
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Android client app.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Learn how to configure Microsoft and Zscaler SSE for unified SASE solutions to enhance security and connectivity in your organization.
Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.
Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Microsoft and Cisco’s Secure Access coexistence solution guide.
Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
Microsoft and Cisco VPNs coexistence solution guide.
Sentinel Integration
UpdatedStrengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Transport Layer Security
UpdatedLearn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway Prompt Shield.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.
Full Data Loss Protection
UpdatedLearn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.
Alerts
UpdatedLearn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.
Application Usage Analytics
UpdatedGain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.
Transport Layer Security
UpdatedThis article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.
Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
Learn about Universal Continuous Evaluation concepts
Edr Antivirus Coexistence
UpdatedLearn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.
Microsoft Traffic Profile
UpdatedA Microsoft Entra documentation page was updated: Microsoft Traffic Profile.
Netskope Integration
UpdatedLearn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
Partner Ecosystem Overview
UpdatedLearn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
Install the Global Secure Access Windows client as a proof of concept. This script automates installation and applies essential configurations.
Secure Web Ai Gateway Agents
Updatedauthor: garrodonnell
Learn how to troubleshoot and resolve Transport Layer Security (TLS) inspection errors in Global Secure Access.
ai-usage: ai-assisted
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Troubleshoot App Access
UpdatedLearn how to troubleshoot application access problems with the Global Secure Access Windows client.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
This document provides troubleshooting guidance for the Global Secure Access client when it shows the "disabled by your organization" error message.
Discover how to use advanced diagnostics to resolve issues with the Global Secure Access mobile client for Android and iOS.
Troubleshoot the macOS Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.
Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.
Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.
Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
Current Known Limitations
Updated- If you have IP location-based Conditional Access policies targeting non-Microsoft resources, don't enable strict location enforcement.
Learn how to require known compliant network locations in order to connect to your secured resources with Conditional Access.
Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
Use Application discovery to detect the applications accessed by users and create separate private applications.
Secure private application access with Privileged Identity Management (PIM) and Global Secure Access
UpdatedLearn how to secure highly valued private application access with Privileged Identity Management (PIM) and Global Secure Access
