← Previous day

Next day →
Day in brief

Documentation-heavy day: ID Governance and workload-identity guidance sharpened, with new Global Secure Access mobile diagnostics

20 March 2026 was primarily a Microsoft Learn documentation refresh rather than a product-release day: 31 items were updated, one troubleshooting article was added, and one iOS-specific Global Secure Access page was removed. The most substantive updates concern cross-tenant governance relationships, Continuous Access Evaluation for workload identities, and mobile-client connectivity diagnostics. The supplied evidence does not establish a preview, general availability announcement, feature retirement, or tenant-wide behavior change. Most other updates appear to be ordinary procedural clarification or documentation maintenance.

  • The updated Update Governance Relationship article explains how to modify an existing relationship between a governing tenant and a governed tenant, including adding or changing delegated administration roles and multitenant application configurations. This is an updated procedural article, not evidence of a new governance capability or changed permissions; administrators operating these relationships should verify their procedures against the revised guidance.

  • The updated article describes enabling Continuous Access Evaluation for workload identities so Conditional Access policies can be enforced and tokens can be revoked instantly. Because the record is marked Updated and provides no preview or general-availability notice, treat this as refreshed security and implementation guidance rather than evidence of a new availability milestone.

  • A new troubleshooting page explains how to use the health-check utility to determine whether a device can communicate with the Global Secure Access service and tunnel traffic. It provides a diagnostic path for support and administration teams; the record does not say that the utility or mobile client itself is newly available or generally available.

  • The period includes a Removed record for “Troubleshoot Global Secure Access Client Ios Health Check Utility.” This establishes a page removal, not retirement of iOS support, the health-check utility, or client behavior. Administrators with internal links or runbooks pointing to the page should verify the current troubleshooting documentation.

  • The updated prerequisites state that nested OUs are supported—even an OU with 130 nested OUs—but that 60 separate OUs cannot be synchronized in the same configuration. This is a documentation clarification, not evidence that the synchronization engine’s limits changed; use the stated constraint when validating a Cloud Sync design.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

33 updates

5

Prerequisites

Updated

- Nested OUs are supported (that is, you **can** sync an OU that has 130 nested OUs, but you **can't** sync 60 separate OUs in the same configuration).

2

Review Admin Consent Requests

Updated

For instance, if an application is found to be non-compliant with company policies, an administrator might choose to 'Block' it. Conversely, if an application is legitimate but requires further review, the administrator may opt to 'Deny' the request temporarily while seeking more information.

2

Create New Tenant

Updated

- **Delegated administration**: Select one or more Microsoft Entra built-in roles and assign them to a role assignable security group in the governing tenant. Members of this group can use their governing tenant credentials to sign in to the governed tenant without needing an account in the governed tenant. Each group can have multiple role assignments, and each policy template can have multiple groups defined.

Application Gallery

Updated

- **Provisioning** - Microsoft Entra ID to SaaS [application provisioning](~/identity/app-provisioning/user-provisioning.md) refers to automatically creating user identities and roles in the SaaS applications that users need access to.

2

Provision Microsoft Entra ID to Active Directory - Configuration

Updated

The following document will guide you through configuring Microsoft Entra Cloud Sync for provisioning groups from Microsoft Entra ID to Active Directory. If you are looking for information on provisioning from AD to Microsoft Entra ID, see [Configure - Provisioning Active Directory to Microsoft Entra ID using Microsoft Entra Cloud Sync](how-to-configure.md).

14

Governance Policy Templates

Updated

- Cross-tenant delegated administration roles - Specify which Microsoft Entra built-in roles users from the governing tenant have in the governed tenant.

Update Governance Relationship

Updated

This article describes how to update an existing governance relationship between a governing tenant and a governed tenant. You might need to update a governance relationship to add or modify delegated administration roles or multitenant application configurations.

Create Monitor

Updated

- [Configuration management](configuration-management.md)

1

Overview

Updated

- Automatically detect tenants that are related to your tenant based on one or more discovery signals.

1
1
4
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…