author: MicrosoftGuyJFlo
Microsoft Rewards account linking retires on 19 March; new Entra web-filtering guidance is the main documentation thread
The clearest operational event on 19 February is the retirement of Azure AD Account Linking for Microsoft Rewards, rather than a change to Entra sign-in or access-policy behavior. Work-account linking will stop by 19 March 2026, while existing points and personal accounts remain unaffected. Most other notable entries are documentation additions or clarifications: new Web content filtering material, a revised passkey support matrix, updated Application Proxy and Traffic Manager guidance, and a documented Global Secure Access port limitation. No supplied item establishes preview, general availability, or broader service-behavior changes.
- Microsoft Rewards retires Azure AD Account Linking
Entra ID · General
This Message Center major update says Azure AD Account Linking for Microsoft Rewards will retire by 19 March 2026. Users will no longer be able to link work accounts to earn Rewards points; existing points and personal-account use are unaffected. Microsoft states that no administrator action is required. This is a feature retirement in the Rewards experience, not an announced change to Entra authentication or access controls.
- New Web content filtering documentation connects rules, security profiles, and Conditional Access
Entra ID · Conditional Access
A set of new Entra ID documentation pages covers category-based Web content filtering rules, policy linkage to security profiles, and integration with Conditional Access. The supplied evidence identifies documentation additions only; it does not establish preview, general availability, a launch, or changed service behavior.
- The passkey/FIDO2 authentication matrix was updated
Entra ID · Authentication
The revised Microsoft Entra ID matrix addresses web-browser and native-app support for FIDO2 passwordless authentication. This is a compatibility-documentation update, not evidence that new client support or a tenant configuration change became available on this date.
- Application Proxy guidance specifies regional Traffic Manager endpoints
Entra ID · Developer
Updated Microsoft Entra Application Proxy guidance says that, in a Traffic Manager solution, each app's regional Application Proxy URL should be added as an endpoint. This is an implementation clarification for administrators using that architecture; the evidence does not announce a change to Application Proxy availability or runtime behavior.
- Global Secure Access documentation records an HTTP/S port limitation
Global Secure Access · Standards
The updated Current Known Limitations page states that Global Secure Access assumes standard HTTP/S ports 80 and 443. Administrators whose designs depend on nonstandard HTTP/S ports should treat this as an operational constraint to review. The update does not say that the platform newly imposed this limitation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
20 updates
Microsoft Entra ID
17 updatesauthor: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: HULKsmashGithub
Configure Custom Domain
Updated> [!IMPORTANT]
Write-Host " "
onPremisesPublishing = @{
Learn about using security questions in Microsoft Entra ID to help improve and secure sign-in events
Web browser and native app support for FIDO2 passwordless authentication using Microsoft Entra ID.
1. In the Traffic Manager solution, add the application proxy regional URLs that were created for each app as an endpoint.
> [!IMPORTANT]
Configure Security
Updated|---|---|
Zero Trust Protect Networks
UpdatedA Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
> **Test Connection** queries the SCIM endpoint for a user that doesn't exist, using a random GUID as the matching property selected in the Microsoft Entra configuration. The expected correct response is HTTP 200 OK with an empty SCIM ListResponse message.
Microsoft Entra Global Secure Access
3 updatesBring Your Own Device
Updated| Platform/device state | Connection target | Entra tunnel | M365 tunnel | Internet tunnel | Private tunnel | Notes |
External User Access
Updated**Q: Can I configure MFA on the resource tenant?**
Current Known Limitations
Updated- The platform assumes standard ports for HTTP/S traffic (ports 80 and 443).
