← Previous day

Next day →
Day in brief

Internet Access licensing and Global Secure Access endpoint coverage are the clearest admin signals in a Verified ID-heavy documentation refresh

The 11 February record contains 48 updates, with no new or removed entries and no message-center announcements. The most operationally specific items are updated Internet Access provisioning guidance and Global Secure Access security guidance. The remaining changes are mainly how-to and reference updates for Verified ID and Microsoft Entra ID Protection. Nothing supplied indicates a new feature, preview, general availability milestone, retirement, or changed service behavior.

  • The updated provisioning guidance states that Microsoft Entra Internet Access and Microsoft Entra Private Access require Microsoft Entra ID P1. It also describes the operational consequences of missing licenses: administrators can't configure traffic-forwarding profiles, security policies, or remote network connections, and traffic from users without assigned licenses doesn't route through Global Secure Access. This is updated provisioning guidance, not evidence that the licensing model changed on this date.

  • The updated security guidance says managed endpoints without the Global Secure Access client operate outside the organization's Security Service Edge controls, leaving network-level policies unable to protect those devices. This is security guidance rather than evidence of a new client capability or deployment change. Deployment owners should use it when assessing coverage of managed endpoints.

  • The updated risk-policies article covers enabling and configuring Microsoft Entra ID Protection risk policies. Related ID Protection updates address risk detection types and levels, reports, remediation, feedback, simulation, data export, Graph PowerShell, and MFA registration. The supplied records identify documentation maintenance, not a change to risk-policy behavior or enforcement. Administrators can compare current policy and incident-response runbooks with the revised instructions.

  • The updated Admin API article covers managing a verifiable-credential deployment. The same update set includes Request Service REST API, issuance and presentation, tenant setup, credential revocation, signing-key rotation, DID and domain configuration, and error-code guidance. The evidence supports a documentation refresh for existing issuer and verifier implementations, not a new API surface, preview, GA announcement, or confirmed contract change.

  • The Face Check pricing article was updated to cover its billing model and enabling the add-on by linking an Azure subscription. No price, billing amount, or availability change is supplied, so administrators should treat this as documentation clarification and recheck the instructions if their tenant uses Face Check.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

48 updates

5

Identity Risk Management Agent

Updated

Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.

3

What are risk detections?

Updated

Explore the full list of risk detections and their corresponding risk event types, along with a description of each risk event type.

2

ID Protection Risk Reports

Updated

Learn how to access, filter, and use the Microsoft Entra ID Protection risk reports to mark users and sign-ins as risky or confirmed compromised.

1
1
1

userimpact: Low

Updated

Global Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.

15

Admin Api

Updated

Learn how to manage your verifiable credential deployment using Admin API.

12

Upgrade signing keys

Updated

Learn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.

3
2

Vc Network Api

Updated

Learn how to use the Microsoft Entra Verified ID Network API

1
1

Error Codes

Updated

Reference of error codes for Microsoft Entra Verified ID APIs

1

userimpact: Low

Updated

Comprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. If you don't deploy the Global Secure Access client to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…