
Windows passkeys are announced for public preview; Baseline Security Mode CA-draft issue is being fixed
The most consequential 19 March items are two Entra ID Message Center notices: a phishing-resistant, passwordless Windows Hello passkey public preview scheduled for late March through May 2026, and a service correction for unintended disabled Conditional Access drafts. The remaining material is chiefly updated operational and security guidance for Microsoft Entra Private Access and Global Secure Access/Internet Access. Nothing supplied announces a general-availability release or retirement.
- Microsoft Entra passkeys on Windows enter a phishing-resistant public preview
Entra ID · Conditional Access
The Message Center notice describes passwordless, phishing-resistant sign-in through Windows Hello on managed and unmanaged devices. The preview is scheduled for late March through May 2026 and requires organizational opt-in and passkey-policy configuration. This is a preview, not a general-availability announcement.
- Baseline Security Mode unintentionally created disabled Conditional Access drafts
Entra ID · Conditional Access
Microsoft reports that, between November 2025 and February 2026, Baseline Security Mode automatically created two disabled draft Entra Conditional Access policies in some tenants. The drafts were unintended; a fix will remove them and prevent automatic creation. Microsoft says this is not a security issue and requires no action.
- Private Access guidance covers Conditional Access and MFA for Kerberos to domain controllers
Private Access · Conditional Access
An updated Private Access procedure explains how to enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Private Access. This is deployment and security guidance; the supplied evidence does not identify a new capability or availability change.
- Global Secure Access web-content-filtering guidance becomes more specific
Internet Access · Conditional Access
The updated guidance describes controlling Internet Access by website category, URL, and FQDN, with granular, user-aware filtering policies built from security profiles and Conditional Access. It is a documentation clarification rather than a stated preview or GA release.
- Global Secure Access traffic-forwarding assignments support scoped rollout
Global Secure Access · General
Updated guidance documents assigning users and groups to traffic-forwarding profiles, allowing administrators to limit scope during testing or deployment and roll out policies gradually. No separate feature-release status is stated.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
43 updates
Microsoft Entra ID
16 updatesauthor: jeevansd




Litmos Provisioning Tutorial
Updated

Looop Provisioning Tutorial
Updated

Learn how to configure shared accounts in Microsoft Entra ID using password-based single sign-on so multiple users can securely access apps without sharing passwords directly.
Github Tutorial
Updated* You can use Microsoft My Apps. When you select the GitHub tile in the My Apps, this option redirects to GitHub Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).
author: HULKsmashGithub
Bynder Tutorial
Updated2. Add the Bynder app from the gallery.
Secure your resources with Microsoft-managed Conditional Access policies. Require multifactor authentication to reduce compromise risks.

Microsoft Entra External ID
1 updateView real-time insights on active devices, alerts, traffic patterns, and cross-tenant usage across Microsoft Entra Private Access and Internet Access services.
Microsoft Entra Internet Access
6 updatesConfigure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
Deploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Microsoft Entra Private Access
9 updatesLearn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Set up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Secure private application access with Privileged Identity Management and Global Secure Access
UpdatedAdd just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Microsoft Entra Global Secure Access
11 updatesModify remote network configurations, delete unused networks, and manage device links and traffic profile assignments for Global Secure Access.
Control which users and groups receive traffic forwarding policies, enabling gradual rollout and limiting scope during testing or deployment phases.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.
Create a PowerShell script for unattended installation and registration of the Microsoft Entra private network connector for bulk deployments or servers without a UI.
Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
View and review all remote networks in your Global Secure Access deployment using the Microsoft Entra admin center or Microsoft Graph API.
Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.
Configure Microsoft Global Secure Access and Cisco Secure Access for unified SASE capabilities. Covers deployment steps, FQDN and IP bypasses, and client configuration.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
In the [Microsoft Intune admin center](https://intune.microsoft.com/), confirm the following criteria:
