← Previous day

Next day →
Day in brief

3 March 2026: Global Secure Access source-IP behavior and Conditional Access rollout guidance clarified

This was a documentation-only day: all 10 recorded changes were updates, with no new or removed items and no Message Center notices. Two updates have clear operational relevance. Global Secure Access guidance explains how source IP restoration affects the origin seen for authentication requests, while Entra ID Conditional Access guidance describes the agent’s suggestions throughout a phased rollout. The remaining provisioning, governance, and security-page edits do not, in the supplied evidence, establish a new feature, preview, general availability event, retirement, or changed tenant requirement.

  • Updated authentication guidance says that when Global Secure Access is deployed as a cloud-based network proxy, failing to enable source IP restoration causes all authentication requests to come from the proxy’s IP address rather than the user’s actual public egress IP. This is a security-relevant behavior clarification, not evidence of a new feature or availability milestone. Administrators should verify that authentication designs relying on source-IP visibility account for this behavior.

  • Updated Conditional Access documentation says the phased-rollout suggestion remains present throughout the rollout and can report no action needed, recommend progressing to the next phase, or suggest rolling back. This clarifies the agent’s operational guidance for an in-progress rollout; it is not presented as a new launch, preview, or GA change. Administrators running a phased rollout should review the suggestion as they move through its phases, with no separate tenant configuration change identified here.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

5
2
1

Conditional Access Agent Optimization Phased Rollout

Updated

Once you start a phased rollout, the agent helps you progress. The phased rollout suggestion is present throughout the rollout process and can show no action needed, suggest progressing to the next phase, or suggest rolling back.

1
1

userimpact: Low

Updated

When organizations deploy Global Secure Access as their cloud-based network proxy, Microsoft's Secure Service Edge infrastructure routes user traffic. If you don't enable source IP restoration, all authentication requests come from the proxy's IP address instead of the user's actual public egress IP.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…