← Previous day

Next day →
Day in brief

Entra Connect’s upgrade safeguard and new Agent ID onboarding stand out in an otherwise Application Proxy-heavy documentation day

The 12 March feed is dominated by Microsoft Learn maintenance: a large set of updated Microsoft Entra Application Proxy PowerShell samples and integration guides. The clearest operational change is Entra Connect’s handling of servers with customized configuration files, while Agent ID receives new AI-assisted onboarding guidance covering blueprint creation, credentials, and identity provisioning. Separate updates add federated SSO certificate-rollover and Global Secure Access Secure Web Gateway guidance. The supplied evidence does not establish preview, general availability, retirement, or a tenant-wide rollout for these items.

  • The Connect Version History update describes changed upgrade behavior: auto-upgrade detects edits to `miiserver.exe.config` and `miisclient.exe.config` and skips automatic upgrade on those servers, addressing an issue in which auto-upgrade could stop the server unexpectedly. A manual upgrade can still fail when those files were previously modified, so the linked known-issues guidance remains relevant. This is an operational behavior change, not a retirement or availability announcement.

  • New Agent ID guidance describes using an AI coding agent, such as GitHub Copilot in VS Code Agent mode, to automate onboarding. The workflow includes blueprint creation, credential configuration, and agent identity provisioning. The evidence establishes new setup documentation, but does not identify the workflow as preview or generally available and is not evidence of a product launch.

  • The updated PowerShell sample set documents inventorying Application Proxy apps and private network connectors, assigning users and groups, and retrieving certificate information. Related examples cover connector-group moves, custom and default domains, wildcard publishing, token-lifetime policies, and bulk certificate replacement. These are documentation and scripting updates; the supplied evidence does not describe a new Application Proxy service capability.

  • The updated federated SSO certificate tutorial gives ISVs best practices for automated rollover as SAML certificates approach expiry. It notes that Entra signing certificates typically expire every one to three years and that customer and SaaS-provider coordination is needed to avoid downtime. This is security and operational guidance, not evidence that Entra changed certificate lifetimes or introduced automatic rollover.

  • Global Secure Access Secure Web Gateway material describes five security layers forming an inspection chain for internet-bound traffic. Same-day pages frame checks around keeping TLS inspection failures below 1% and preventing custom bypass rules from duplicating system bypass destinations. This is security and configuration documentation; no new SWG availability milestone or behavior change is supplied.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

40 updates

19
4
3

Get all application proxy apps and list extended information

Updated

PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).

3
2

Configure Security

Updated

| [TLS inspection is enabled and correctly configured for outbound traffic](zero-trust-protect-networks.md#tls-inspection-is-enabled-and-correctly-configured-for-outbound-traffic) | Microsoft Entra ID P1 |

2

Tutorial Manage Certificates For Federated Single Sign On

Updated

This section will outline best practices independent software vendors (ISV’s) can adopt to enable automated certificate rollover when SAML certificates are near expiry and when applications federated with Microsoft Entra ID. SAML certificates in Entra ID are used for signing assertions in federated single sign-on (SSO). These certificates expire (typically every 1-3 years) and rotation requires a Customer and SaaS ISV coordination to update a mutual certificate in both systems without downtime. Industry trends are shortening certificate lifetimes, manual rollover processes increasingly create operational burden and risk service disruption — especially in large organizations with many SAML enterprise applications.

1

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

1

Connect Version History

Updated

- Fixed a [known issue](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified) where auto-upgrade could stop your Microsoft Entra Connect server unexpectedly. Auto-upgrade now detects modifications to the `miiserver.exe.config` and `miisclient.exe.config` configuration files and skips automatic upgrade on those servers. If you manually upgrade and previously modified these configuration files, you might encounter installation failures. To resolve the issue, see the [known issues section](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified).

2
1

Agent ID Setup Instructions

New

This file is used by an AI coding agent (such as GitHub Copilot in VS Code Agent mode) to automate onboarding to Microsoft Entra Agent ID.

1

AI-guided setup for Microsoft Entra Agent ID

New

Use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.

1

27014

Updated

The Global Secure Access Secure Web Gateway (SWG) implements defense-in-depth through five security layers that together create a comprehensive inspection chain for internet-bound traffic. Each layer serves a distinct protective function:

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…