Microsoft is retiring the Azure AD Account Linking feature for Microsoft Rewards by March 19, 2026. Users can no longer link work accounts to earn Rewards points. Existing points remain unaffected, personal accounts work as usual, and no admin actions are required.
Global Secure Access timing and Agent ID governance guidance lead a documentation-heavy 18 February
The most actionable clarification is in Global Secure Access: web content filtering changes made in the Global Secure Access experience typically take effect in less than five minutes, while related Conditional Access changes take approximately one hour. Other meaningful updates cover Agent ID administrative relationships, the Entra ID control for blocking new app password credentials, and Access Reviews API behavior when notifications are disabled. All 29 tracked entries are marked Updated, with no new or removed items and no Message Center entries. The supplied record therefore supports documentation clarification, security guidance, and governance/API guidance—not a confirmed feature launch, preview, GA release, or retirement.
- Global Secure Access: web content filtering propagation expectations are explicit
Global Secure Access · Conditional Access
Classification: ordinary operational documentation clarification. The updated page distinguishes changes made in the Global Secure Access experience, which typically take effect in less than five minutes, from Conditional Access changes related to web content filtering, which take approximately one hour. The evidence clarifies expected timing but does not say that the timings themselves changed.
- Agent ID guidance separates technical administration from business accountability
Agent ID · Microsoft identity platform
Classification: governance guidance. The updated administrative-relationships page describes a model separating technical administration from business accountability and applies it to agent identities, agent identity blueprints, and agent identity blueprint principals. This gives administrators a more specific framework for reviewing Agent ID accountability; it is not presented as a new availability milestone.
- Entra ID documents the app password-credential restriction control
Entra ID · Authentication
Classification: security and configuration guidance. The update directs administrators to select Restricted Mode and locate the setting "Block addition of new password credentials to apps." It clarifies the control's location and name, but the supplied evidence does not establish that the control is newly introduced or that tenant settings changed.
- Access Reviews clarifies reviewer-notification API semantics
ID Governance · Governance
Classification: API behavior documentation clarification. The FAQ states that the contactedReviewers API returns users who were, or would have been, notified to perform a review, even when notifications were disabled, and includes timestamps indicating when notification would occur. Audit and automation workflows can use this behavior when reconciling reviewer populations and notification schedules; the entry does not claim a new API release.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
30 updates
Microsoft Entra ID
12 updatesIdentifier Uri Restrictions
UpdatedThere are three possible ways that you can add an identifier URI to your app. We recommend them in the following order:
Delegate By Task
Updated> [!div class="mx-tableFixed"]
manager: pmwongera
Consider using the knowledge base of your organization:
Howto Add App Roles In Apps
UpdatedAfter adding app roles in your application, you can assign an app role to a client app by using the Microsoft Entra admin center or programmatically by using [Microsoft Graph](/graph/api/serviceprincipal-post-approleassignments?tabs=http). Assigning an app role to an application shouldn't be confused with [assigning roles to users](../identity/role-based-access-control/manage-roles-portal.md).
If you’re planning to only change the SOA for some Active Directory users, and all your users are currently in a single OU using Kerberos applications that don’t use LDAP, we recommend that you create a new AD DS OU for these objects. Having them in a separate OU will enable you to avoid inadvertently making updates to them in Active Directory after the SOA change. Users, whose SOA isn’t changing, can continue to be managed using Active Directory Users and Computers, Active Directory Module for PowerShell, or other Active Directory management tools. After creating an OU, move the objects to that OU. For more information, see: [Move-ADObject](/powershell/module/activedirectory/move-adobject?view=windowsserver2025-ps&preserve-view=true).
Block Password Addition
Updated1. Select Restricted Mode, find the **Block addition of new password credentials to apps** setting.
Whats New
UpdatedDeactivate App Registration
Updated- One of the following Microsoft Entra roles:
| Restriction name | Description | Security value | Availability |
Microsoft Entra Agent ID
3 updatesAgent Id Governance Overview
UpdatedAgents can then be assigned access packages through three different request pathways.
Agent Access Packages
UpdatedAgents can then be assigned access packages through three different request pathways.
The Microsoft agent identity platform introduces an administrative model that separates technical administration from business accountability, ensuring operational control and compliance oversight without excessive permissions. This document explains the administrative relationships for Microsoft Entra Agent ID identity types. This guidance applies to [agent identities](/graph/api/resources/agentidentity?view=graph-rest-beta&preserve-view=true), [agent identity blueprints](/graph/api/resources/agentidentityblueprint?view=graph-rest-beta&preserve-view=true), [agent identity blueprint principals](/graph/api/resources/agentidentityblueprintprincipal?view=graph-rest-beta&preserve-view=true), and [agent users](/graph/api/resources/agentuser?view=graph-rest-beta&preserve-view=true). The article covers owners, sponsors, and managers and their importance in maintaining secure operations.
Microsoft Entra ID Governance
8 updates1. Select **Create**.
:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::
Entitlement Management Roles
UpdatedFirst, call [Create accessPackageResourceRequest](/graph/api/entitlementmanagement-post-resourcerequests?tabs=http) to add the Microsoft Entra role as a resource to the catalog.
Access Reviews Faqs
UpdatedOnce an access review starts, you can use the [contactedReviewers](/graph/api/resources/accessreviewreviewer) API to retrieve the list of all users who were, or would have been, notified via email to perform reviews. Even in scenarios where notifications were turned off, the API still provides the list of reviewers along with timestamps indicating when notification would happen.
Catalog Access Reviews
Updated1. Select **Create** to finalize the access review.
:::image type="content" source="media/entitlement-management-access-package-create/api-permissions-roles.png" alt-text="Screenshot of adding API permissions as resource roles to an access package.":::
If these users are brought in with a userType of **guest** they accrue to the meter, however you can avoid being charged by setting up
You can also manage access packages, catalogs, policies, requests, and assignments using Microsoft Graph. A user in an appropriate role with an application that has the delegated `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` permission can call the [entitlement management API](/graph/api/resources/entitlementmanagement-overview). For more information, see the [Tutorial: manage access to resources - Microsoft Graph](/graph/tutorial-access-package-api?toc=/azure/active-directory/governance/toc.json&bc=/azure/active-directory/governance/breadcrumb/toc.json). An application with the `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` application permissions can also use many of those API functions, except for managing resources in catalogs and access packages. An application that only needs to operate within specific catalogs can be added to the **Catalog owner** or **Catalog reader** roles of a catalog to be authorized to update or read within that catalog.
Microsoft Entra External ID
1 update10 Secure Local Guest
UpdatedLearn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)
Microsoft Entra Workload ID
1 updateManaged Identities Status
Updated| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |
Microsoft Entra Global Secure Access
5 updatesCompliant Network
Updated> * Internet resources with Global Secure Access
Released for download on December 3, 2025.
> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.
Configure Quick Access
Updated> You can add up to 500 application segments to your Quick Access app.
- A **Global Secure Access Administrator** role in Microsoft Entra ID.
