← Previous day

Next day →
Day in brief

20 February 2026: documentation clarifies Internet Access, Agent ID, External ID, and PIM administration

This was a documentation-maintenance period: 83 updates were recorded, with no new or removed items and no Message Center notices. The most useful updates are implementation clarifications and security guidance—not evidence of a new feature launch, preview, general availability change, retirement, or changed service behavior. Most other supplied updates concern routine partner SSO and provisioning tutorials.

  • The updated guidance says administrators create a Conditional Access policy for users or groups and deliver Internet Access security profiles through Conditional Access session controls. It identifies Conditional Access as the mechanism that provides user and context awareness for Internet Access policies. This is an implementation clarification, not a launch announcement.

  • The Agent ID guidance describes an agent identity blueprint as the basis for creating agent identities and requesting tokens. It calls for assigning an owner and sponsor, and for configuring an identifier URI and scope when agents created from the blueprint will receive requests from other agents or users. The update does not establish preview or general availability status.

  • For a Windows Microsoft Entra registered device, the documented experience is that the user selects a tenant at first sign-in and remains connected to it; switching to other registered tenants is not currently supported. The guidance distinguishes this from switching to a resource tenant through external user access, or B2B. It clarifies expected behavior rather than stating that the service behavior changed.

  • The PIM Deployment Plan update advises assigning users the least-privileged role needed for their tasks, minimizing Global Administrator assignments, and using specific administrator roles for particular scenarios. This is security and deployment guidance, not evidence of a new PIM capability.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

83 updates

27

Lensesio Tutorial

Updated

c. **Sign on URL**: Enter a URL that has the following pattern: `https://<CUSTOMER_LENSES_BASE_URL>`. An example is `https://lenses.my.company.com`.

Docker Tutorial

Updated

The scenario outlined in this article assumes that you already have the following prerequisites:

Mitel Connect Tutorial

Updated

In this section, you create a user named Britta Simon on your MiCloud Connect account. Users must be created and activated before using single sign-on.

Sap Successfactors Writeback Tutorial

Updated

| 4 | true | emailIsPrimary | Use this attribute to set business email as primary in SuccessFactors. If business email isn't primary, set this flag to false. |

12

Crowd Log Tutorial

Updated

To perform the Single Sign-On configuration on the Crowd Log side, please refer to the Crowd Log SAML admin settings documentation.

In Case Of Crisis Mobile Tutorial

Updated

To configure single sign-on on **In Case of Crisis - Mobile** side, you need to send the downloaded **Certificate (Raw)** and copied **User access URL** from Azure portal to In Case of Crisis - Mobile support team. They set this setting to have the SAML SSO connection set properly on both sides.

Lexmark Cloud Services Tutorial

Updated

To configure single sign-on on **Lexmark Cloud Services (SAML)** side, you need to send the **App Federation Metadata Url** to Lexmark Cloud Services (SAML) support team. They set this setting to have the SAML SSO connection set properly on both sides. Also review the [Lexmark documentation](https://support.lexmark.com/en_us/manuals-guides/online/Lexmark-Cloud-Platform/configuring-microsoft-entra-id-federation-for-saml.html) on Configuring Microsoft Entra ID with SAML Federation

On24 Tutorial

Updated

To configure single sign-on on **ON24 Virtual Environment SAML Connection** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to ON24 Virtual Environment SAML Connection support team. They set this setting to have the SAML SSO connection set properly on both sides.

Gaggleamp Tutorial

Updated

1. In another browser instance, navigate to the SAML SSO page created for you by the Gaggle support team (for example: `https://accounts.gaggleamp.com/saml_configurations/oXH8sQcP79dOzgFPqrMTyw/edit`).

Oreilly Learning Platform Provisioning Tutorial

Updated

Before you begin to configure the O'Reilly learning platform to support provisioning with Microsoft Entra ID, you’ll need to generate a SCIM API token within the O’Reilly Admin Console.

Outsystems Tutorial

Updated

To configure single sign-on on OutSystems side, you need to download the IdP forge component, configure it as mentioned in the [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Configure_your_application_to_use_IdP_connector). After installing the component and do the necessary code changes, configure Microsoft Entra ID by downloading Federation Metadata XML from Azure portal and upload on OutSystems IdP component, according to the following [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Azure_AD_.2F_ADFS).

Spectrumu Tutorial

Updated

To configure single sign-on on **SpectrumU** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to SpectrumU support team. They set this setting to have the SAML SSO connection set properly on both sides.

9

Configure askSpoke for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both askSpoke and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to askSpoke using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

Configure Whimsical for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both Whimsical and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Whimsical](https://whimsical.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

Looop Provisioning Tutorial

Updated

Before configuring Looop for automatic user provisioning with Microsoft Entra ID, you need to retrieve some provisioning information from Looop.

4

Secretless authentication in Azure

Updated

Learn about secretless authentication in Azure to reduce credential risks, enhance security, and streamline user experience with Zero Trust principles.

Tripwire Enterprise Tutorial

Updated

To configure single sign-on in Tripwire Enterprise, please see **Using Tripwire Enterprise with SAML Authentication** section in the Tripwire Enterprise Hardening Guide, available for download on the Tripwire Customer Center. If you require assistance, contact [Tripwire Enterprise support team](mailto:support@tripwire.com).

4

Whats New Archive

Updated

In February 2024, we added the following 10 new applications in our App gallery with Federation support:

2
2
2

Anaqua Tutorial

Updated

`https://<SUBDOMAIN>.anaqua.com/anaqua/Public/login.aspx`

Roles across Microsoft services

Updated

Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services

2

Plan Connect Performance Factors

Updated

Microsoft Entra ID uses throttling to protect the cloud service from denial-of-service (DoS) attacks. Currently Microsoft Entra ID has a throttling limit of 6,000 writes per 5 minutes (72,000 per hour). For example, the following operations can be throttled:

1
2

Create an agent identity blueprint

Updated

An [agent identity blueprint](agent-blueprint.md) is used to create agent identities and request tokens using those agent identities. During the process for creating an agent identity blueprint, you set the [owner and sponsor](agent-owners-sponsors-managers.md) of that blueprint, to establish accountability and administrative relationships. You also configure an identifier URI and define a scope for agents created from this blueprint if the agent is designed to receive incoming requests from other agents and users.

1
1

Pim Deployment Plan

Updated

You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.

1
1

Services And Integration Partners Governance

Updated

|[Edgile, a Wipro company](https://aka.ms/EdgileEntraIDGov) |"Edgile, a Wipro company is excited to be a Microsoft Launch Partner for Microsoft Entra ID Governance. Our deep and broad experience in IGA and security will ensure your project is a success. Our project accelerators will reduce your risk and deliver results faster." |

1

Bring Your Own Device

Updated

| Windows Microsoft Entra Registered device | User selects a tenant at first sign-in; remains connected to that tenant. | ❌ | ❌ | ❌ | ✅ | Cannot switch to other registered tenants for now. Allows user to switch to a resource tenant using external user access(B2B). |

1
1

Configure Web Content Filtering

Updated

Create a Conditional Access policy for end users or groups and deliver your security profile through Conditional Access Session controls. Conditional Access is the delivery mechanism for user and context awareness for Internet Access policies. To learn more about session controls, see [Conditional Access: Session](/azure/active-directory/conditional-access/concept-conditional-access-session).

6
1
1
1

Find Microsoft Services Partners

Updated

| **[BEMO](https://aka.ms/BemoSSELaunchPartner)** | BEMO is a trusted expert in delivering Microsoft's SSE solution to SMBs across the United States with up to 1,000 employees. BEMO specializes in Modern Work and Security, helping SMBs achieve their security and compliance (SOC 2, CMMC, ISO 27001, NIST 800-171, HIPAA) goals by leveraging Microsoft technologies. |

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…