← Previous day

Next day →
Day in brief

Security Copilot’s Microsoft 365 E5 inclusion is the material change; Entra guidance was otherwise refreshed

26 March 2026 was dominated by documentation maintenance: 76 Microsoft Learn entries were updated, with no new or removed items, alongside one Message Center notice. The concrete service and licensing news is a phased Security Copilot rollout for Microsoft 365 E5. The Learn entries mainly clarify deployment, authentication, and security procedures for Global Secure Access, Private Access, Application Proxy, and External ID. Because these entries are marked as updates, the evidence does not establish a new feature launch, general availability change, retirement, or changed runtime behavior. The Global Secure Access traffic-logs entry still describes those logs as preview, without announcing a status change.

  • Message Center notice MC1261596 schedules the rollout from April 20 through June 30, 2026. It describes 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products, while noting that additional advanced capabilities may incur extra costs. This is a rollout and licensing notice, not an Entra feature GA announcement.

  • The updated assignment guidance documents assigning users and groups to traffic-forwarding profiles so administrators can limit scope during testing or deployment and stage a rollout. This is operational documentation; the entry does not say that the capability is newly available or that its behavior changed.

  • The updated Active Directory Domain Controllers guide says to enforce Conditional Access and multifactor authentication for Kerberos authentication through Microsoft Entra Private Access. Organizations using Private Access for domain-controller access should compare their policy design with this guidance; the record does not indicate a new authentication protocol or availability milestone.

  • The updated wildcard applications article describes publishing and managing multiple on-premises applications with wildcard URL patterns. This is useful for administrators managing larger proxied application estates, but the record is a documentation update and provides no evidence of a new release or required migration.

  • The updated guide covers enabling synchronization, configuring automatic redemption, creating provisioning jobs, and testing on-demand provisioning through Microsoft Graph PowerShell or the Microsoft Graph API. The administrator impact is procedural: use the revised reference when operating or validating cross-tenant synchronization; it does not state that the capability changed status.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

77 updates

14

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

Grant Admin Consent

Updated

Learn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.

6

Stormshield Network Security Tutorial

Updated

This section guides you through the necessary configurations on the **Stormshield Network Security (SNS) firewall** to enable **OIDC authentication** via **Microsoft Entra ID**.

Authentication Flows App Scenarios

Updated

To call a web API from a web app on behalf of a user, use the authorization code flow and store the acquired tokens in the token cache. When needed, MSAL refreshes tokens and the controller silently acquires tokens from the cache.

3

Microsoft-managed Conditional Access policies

Updated

Every day, Microsoft processes more than 100 trillion security signals from endpoints, cloud services, identity systems, and more. We use this data shape how we respond to threats and inform how we innovate to help build a safer digital future. Read about the work we're doing in the [Microsoft Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1).

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

3

Clever Tutorial

Updated

<a name='configure-and-test-azure-ad-sso-for-clever'></a>

My Staff Configure

Updated

After configuring administrative units, you can apply this scope to your users who access My Staff. Only users who are assigned an administrative role can access My Staff. To enable My Staff, complete the following steps:

3

New M365 group creation and editing in My Groups

New

Microsoft 365 group creation and editing in My Groups will be enhanced by late March 2026, allowing owners to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The update improves control and clarity without impacting existing groups or requiring admin setup.

Message CenterMC1262589 on mc.merill.net ↗Stay informed
2
2
1
1

Groups Assign Member Owner

Updated

In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.

2
2

Configure cross-tenant synchronization

Updated

Configure cross-tenant synchronization using the Microsoft Entra admin center. Step-by-step guide covering trust settings, provisioning scope, attribute mappings, and testing.

1
3
2

Zscaler Coexistence

Updated

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

1
1

How to use enriched Microsoft 365 logs

Updated

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

4
3

Configure Global Access With Pim

Updated

Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.

2

Target Resource Private Access Apps

Updated

Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.

1

Configure Kerberos Sso

Updated

Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.

8

The Global Secure Access Client for iOS

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.

3
3
2
2
1

Understand Microsoft Entra Private DNS

Updated

Learn how to configure Microsoft Entra Private DNS for secure and efficient internal DNS query resolution, replacing legacy VPNs with granular access.

1

View Deployment Logs

Updated

Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…