Publish and manage multiple on-premises applications at once using wildcard URL patterns in Microsoft Entra application proxy.
Security Copilot’s Microsoft 365 E5 inclusion is the material change; Entra guidance was otherwise refreshed
26 March 2026 was dominated by documentation maintenance: 76 Microsoft Learn entries were updated, with no new or removed items, alongside one Message Center notice. The concrete service and licensing news is a phased Security Copilot rollout for Microsoft 365 E5. The Learn entries mainly clarify deployment, authentication, and security procedures for Global Secure Access, Private Access, Application Proxy, and External ID. Because these entries are marked as updates, the evidence does not establish a new feature launch, general availability change, retirement, or changed runtime behavior. The Global Secure Access traffic-logs entry still describes those logs as preview, without announcing a status change.
- Security Copilot is scheduled for phased inclusion in Microsoft 365 E5
ID Governance · Microsoft identity platform
Message Center notice MC1261596 schedules the rollout from April 20 through June 30, 2026. It describes 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products, while noting that additional advanced capabilities may incur extra costs. This is a rollout and licensing notice, not an Entra feature GA announcement.
- Global Secure Access guidance emphasizes scoped traffic-forwarding rollout
Global Secure Access · General
The updated assignment guidance documents assigning users and groups to traffic-forwarding profiles so administrators can limit scope during testing or deployment and stage a rollout. This is operational documentation; the entry does not say that the capability is newly available or that its behavior changed.
- Private Access guidance links Kerberos access to Conditional Access and MFA
Private Access · Conditional Access
The updated Active Directory Domain Controllers guide says to enforce Conditional Access and multifactor authentication for Kerberos authentication through Microsoft Entra Private Access. Organizations using Private Access for domain-controller access should compare their policy design with this guidance; the record does not indicate a new authentication protocol or availability milestone.
- Application Proxy documentation clarifies wildcard publishing
Entra ID · Developer
The updated wildcard applications article describes publishing and managing multiple on-premises applications with wildcard URL patterns. This is useful for administrators managing larger proxied application estates, but the record is a documentation update and provides no evidence of a new release or required migration.
- External ID cross-tenant synchronization procedures cover API and PowerShell operation
External ID · Microsoft identity platform
The updated guide covers enabling synchronization, configuring automatic redemption, creating provisioning jobs, and testing on-demand provisioning through Microsoft Graph PowerShell or the Microsoft Graph API. The administrator impact is procedural: use the revised reference when operating or validating cross-tenant synchronization; it does not state that the capability changed status.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
77 updates
Microsoft Entra ID
34 updatesAccess on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Configure Kerberos-based SSO for on-premises applications using Kerberos Constrained Delegation (KCD) with Microsoft Entra application proxy.
Understand complex applications in Microsoft Entra application proxy.
Configure Microsoft Entra private network connectors with outbound proxy servers. Covers bypassing proxies, routing through proxies, and proxy placement between connectors and backend apps.
Optimize performance for global connectivity scenarios using Azure Front Door for geo-acceleration with Microsoft Entra application proxy.
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
Configure Microsoft Entra application proxy to enable secure external access to on-premises SharePoint Server using Kerberos Constrained Delegation for single sign-on.
Combine Microsoft Entra application proxy with Azure Traffic Manager for geographic load balancing and high availability across multiple connector groups.
Configure and manage custom domains in Microsoft Entra application proxy to use your own domain name.
Grant Admin Consent
UpdatedLearn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedConfigure header-based single sign-on for on-premises applications published through Microsoft Entra application proxy. Pass user identity attributes as HTTP headers.
Integrate Microsoft Entra application proxy with Qlik Sense.
This section guides you through the necessary configurations on the **Stormshield Network Security (SNS) firewall** to enable **OIDC authentication** via **Microsoft Entra ID**.
Reports Data Retention
Updated| Risky sign-ins | 7 days | 30 days | 90 days |
Configure Microsoft Entra application proxy with SAML-based authentication for secure external access to on-premises SharePoint Server.
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
To call a web API from a web app on behalf of a user, use the authorization code flow and store the acquired tokens in the token cache. When needed, MSAL refreshes tokens and the controller silently acquires tokens from the cache.
Set a custom home page URL for applications published through Microsoft Entra application proxy so users land on the correct internal page after sign-in.
Every day, Microsoft processes more than 100 trillion security signals from endpoints, cloud services, identity systems, and more. We use this data shape how we respond to threats and inform how we innovate to help build a safer digital future. Read about the work we're doing in the [Microsoft Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1).
Publish Tableau Server through Microsoft Entra application proxy to provide secure remote access with preauthentication and Conditional Access.
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Clever Tutorial
Updated<a name='configure-and-test-azure-ad-sso-for-clever'></a>
Install the module.
Updated$tenantID = '<tenant-id>'
My Staff Configure
UpdatedAfter configuring administrative units, you can apply this scope to your users who access My Staff. Only users who are assigned an administrative role can access My Staff. To enable My Staff, complete the following steps:
Microsoft 365 group creation and editing in My Groups will be enhanced by late March 2026, allowing owners to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The update improves control and clarity without impacting existing groups or requiring admin setup.
Secure NDES certificate enrollment for mobile devices using Microsoft Entra application proxy. Includes connector setup and certificate request validation.
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
An end-to-end guide for planning the deployment of application proxy within your organization
Whats New
Updated```
Securely integrate Azure Logic Apps with on-premises APIs using Microsoft Entra application proxy
UpdatedMicrosoft Entra application proxy lets cloud-native logic apps securely access on-premises APIs to bridge your workload.
Optimize traffic flow and connector placement for Microsoft Entra application proxy. Covers bandwidth, latency, and network patterns including ExpressRoute and multi-region deployments.
Create and manage a multitenant organization using Microsoft Graph PowerShell or Microsoft Graph API. Covers creating the organization, adding tenants, joining, and managing roles.
Microsoft Entra ID Governance
1 updateGroups Assign Member Owner
UpdatedIn Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.
Microsoft Entra External ID
5 updatesConfigure cross-tenant synchronization using Microsoft Graph PowerShell or Microsoft Graph API. Includes enabling synchronization, setting up automatic redemption, creating provisioning jobs, and testing on-demand provisioning.
Configure cross-tenant access and identity synchronization policy templates for multitenant organizations using the Microsoft Graph API. Covers automatic redemption, inbound sync, and template management.
Configure cross-tenant synchronization using the Microsoft Entra admin center. Step-by-step guide covering trust settings, provisioning scope, attribute mappings, and testing.
Map custom directory extension attributes in cross-tenant synchronization. Covers creating extensions, adding them to attribute mappings, and manual schema editing.
View real-time insights on active devices, alerts, traffic patterns, and cross-tenant usage across Microsoft Entra Private Access and Internet Access services.
Microsoft Entra Internet Access
7 updatesDeploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Configure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Zscaler Coexistence
UpdatedLearn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Microsoft Entra Private Access
10 updatesSet up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
Configure Kerberos Sso
UpdatedEnable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Microsoft Entra Global Secure Access
20 updatesControl which users and groups receive traffic forwarding policies, enabling gradual rollout and limiting scope during testing or deployment phases.
Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.
Modify remote network configurations, delete unused networks, and manage device links and traffic profile assignments for Global Secure Access.
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Learn how to enable source IP restoration to ensure the source IP matches in downstream resources.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Create a PowerShell script for unattended installation and registration of the Microsoft Entra private network connector for bulk deployments or servers without a UI.
Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.
Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
View and review all remote networks in your Global Secure Access deployment using the Microsoft Entra admin center or Microsoft Graph API.
Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
Learn how to require known compliant network locations to connect to your secured resources with Conditional Access.
Learn how to apply Conditional Access policies to the Global Secure Access traffic.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Configure Microsoft Global Secure Access and Cisco Secure Access for unified SASE capabilities. Covers deployment steps, FQDN and IP bypasses, and client configuration.
Learn how to configure Microsoft Entra Private DNS for secure and efficient internal DNS query resolution, replacing legacy VPNs with granular access.
View Deployment Logs
UpdatedMonitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.
