Learn how to configure single sign-on between Microsoft Entra ID and KnowledgeOwl.
Documentation-heavy day: ID Governance and workload-identity guidance sharpened, with new Global Secure Access mobile diagnostics
20 March 2026 was primarily a Microsoft Learn documentation refresh rather than a product-release day: 31 items were updated, one troubleshooting article was added, and one iOS-specific Global Secure Access page was removed. The most substantive updates concern cross-tenant governance relationships, Continuous Access Evaluation for workload identities, and mobile-client connectivity diagnostics. The supplied evidence does not establish a preview, general availability announcement, feature retirement, or tenant-wide behavior change. Most other updates appear to be ordinary procedural clarification or documentation maintenance.
- ID Governance relationship guidance covers delegated roles and multitenant application configuration
ID Governance · Governance
The updated Update Governance Relationship article explains how to modify an existing relationship between a governing tenant and a governed tenant, including adding or changing delegated administration roles and multitenant application configurations. This is an updated procedural article, not evidence of a new governance capability or changed permissions; administrators operating these relationships should verify their procedures against the revised guidance.
- Workload ID documentation refreshes Continuous Access Evaluation guidance
Workload ID · Conditional Access
The updated article describes enabling Continuous Access Evaluation for workload identities so Conditional Access policies can be enforced and tokens can be revoked instantly. Because the record is marked Updated and provides no preview or general-availability notice, treat this as refreshed security and implementation guidance rather than evidence of a new availability milestone.
- Global Secure Access publishes a mobile-client health-check article
Global Secure Access · Troubleshooting
A new troubleshooting page explains how to use the health-check utility to determine whether a device can communicate with the Global Secure Access service and tunnel traffic. It provides a diagnostic path for support and administration teams; the record does not say that the utility or mobile client itself is newly available or generally available.
- An iOS-specific Global Secure Access health-check page is marked removed
Global Secure Access · Troubleshooting
The period includes a Removed record for “Troubleshoot Global Secure Access Client Ios Health Check Utility.” This establishes a page removal, not retirement of iOS support, the health-check utility, or client behavior. Administrators with internal links or runbooks pointing to the page should verify the current troubleshooting documentation.
- Entra Cloud Sync prerequisites clarify supported OU structures
Entra ID · General
The updated prerequisites state that nested OUs are supported—even an OU with 130 nested OUs—but that 60 separate OUs cannot be synchronized in the same configuration. This is a documentation clarification, not evidence that the synchronization engine’s limits changed; use the stated constraint when validating a Cloud Sync design.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
33 updates
Microsoft Entra ID
11 updatesLearn how to configure single sign-on between Microsoft Entra ID and Veza.
- You make a change to proxyAddresses or userPrincipalName.
Home Realm Discovery Policy
Updated- If no domain hint or policies are assigned, default HRD behavior applies.
Prerequisites
Updated- Nested OUs are supported (that is, you **can** sync an OU that has 130 nested OUs, but you **can't** sync 60 separate OUs in the same configuration).
- Completion of the steps in [Quickstart: Create and assign a user account](add-application-portal-assign-users.md).
For instance, if an application is found to be non-compliant with company policies, an administrator might choose to 'Block' it. Conversely, if an application is legitimate but requires further review, the administrator may opt to 'Deny' the request temporarily while seeking more information.
Create New Tenant
Updated- **Delegated administration**: Select one or more Microsoft Entra built-in roles and assign them to a role assignable security group in the governing tenant. Members of this group can use their governing tenant credentials to sign in to the governed tenant without needing an account in the governed tenant. Each group can have multiple role assignments, and each policy template can have multiple groups defined.
Application Gallery
Updated- **Provisioning** - Microsoft Entra ID to SaaS [application provisioning](~/identity/app-provisioning/user-provisioning.md) refers to automatically creating user identities and roles in the SaaS applications that users need access to.

The following document will guide you through configuring Microsoft Entra Cloud Sync for provisioning groups from Microsoft Entra ID to Active Directory. If you are looking for information on provisioning from AD to Microsoft Entra ID, see [Configure - Provisioning Active Directory to Microsoft Entra ID using Microsoft Entra Cloud Sync](how-to-configure.md).
Microsoft Entra ID Governance
16 updatesLicensing Tenant Governance
Updated| Feature | Free | Microsoft Entra P1 | Microsoft Entra P2 | Microsoft Entra ID Governance |
Signals Metrics
UpdatedThis article focuses exclusively on:
1. Select **Terminate governance**.
Governance Policy Templates
Updated- Cross-tenant delegated administration roles - Specify which Microsoft Entra built-in roles users from the governing tenant have in the governed tenant.
This article describes how to update an existing governance relationship between a governing tenant and a governed tenant. You might need to update a governance relationship to add or modify delegated administration roles or multitenant application configurations.
Deployment Guide
Updated1. Configure the template:
Governance Relationships
Updated| Scenario | Description |
Create Monitor
Updated- [Configuration management](configuration-management.md)
- [Set up a governance relationship](how-to-set-up-governance-relationship.md)
Delegated Administration
Updated- [Monitor governing tenant admin activity](how-to-monitor-governing-activity.md)
Enable Tenant Discovery
Updated- [Review the list of related tenants](related-tenants.md) surfaced by discovery.
Monitor Governing Activity
Updated- [Use cross-tenant delegated administration](how-to-delegated-administration.md)
See Monitor Results
Updated- [Create a monitor](how-to-create-monitor.md)
Update Delete Monitor
Updated- [Create a monitor](how-to-create-monitor.md)
Overview
Updated- Automatically detect tenants that are related to your tenant based on one or more discovery signals.
Interpret Discovery Data
Updated- Investigate ownership (business unit, team, or developer).
Microsoft Entra Workload ID
1 updateLearn how to enable continuous access evaluation for workload identities to enforce Conditional Access policies and instantly revoke tokens.
Microsoft Entra Global Secure Access
4 updatesLearn if a device can communicate with the Global Secure Access service and tunnel traffic, by using the health check utility.
A Microsoft Entra documentation page was updated: Troubleshoot Global Secure Access Client Ios Health Check Utility.
