← Previous day

Next day →
Day in brief

My Groups gains owner controls; the rest of 27 March is targeted documentation guidance

The clearest service change is an Entra ID My Groups enhancement: Microsoft 365 group owners will gain controls for usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options when creating or editing groups. The Message Center notice says existing groups are unaffected and no admin setup is required. The other meaningful updates are documentation clarifications for Global Secure Access enriched logs, Application Proxy cookie handling, and Entra Agent ID security. The supplied evidence shows no preview, general-availability announcement, retirement, or broad tenant configuration change.

  • The Entra ID Message Center notice says My Groups creation and editing will be enhanced by late March 2026. Owners will be able to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The notice explicitly says existing groups are unaffected and no administrator setup is required. This is a service behavior enhancement, not a stated preview or retirement.

  • The updated View Enriched Logs guidance says the Microsoft traffic forwarding profile must be enabled to capture traffic directed to Microsoft 365 services, which is required for log enrichment. This is operational documentation guidance; the supplied update does not announce a new Global Secure Access capability or rollout.

  • The updated guidance explains that cookies without a SameSite attribute are treated as SameSite=Lax, while Application Proxy requires cookies to be preserved in a third-party context to keep users signed in. The supplied excerpt says updates were made for that requirement but does not specify a new runtime behavior, so this should be treated as configuration and troubleshooting clarification.

  • The updated Entra Agent ID security article introduces the security differences between autonomous AI agents and traditional applications, including agent sprawl, and describes Microsoft’s security mechanisms for agents. It is foundational security guidance rather than evidence of a new Agent ID feature, preview, or enforcement change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

38 updates

5

Application Proxy Configure Complex Application

Updated

:::image type="content" source="./media/application-proxy-configure-complex-application/complex-app-structure-1.png" alt-text="Diagram of domain structure for a complex application showing resource sharing between primary and secondary application.":::

Application Proxy Integrate With Remote Desktop Services

Updated

8. Run this command for each collection. Replace *\<yourcollectionname\>* and *\<proxyfrontendurl\>* with your own information. This command enables single sign-on between RD Web and RD Gateway, and optimizes performance.

Application Proxy Configure Cookie Settings

Updated

Cookies that don't specify the [SameSite](https://web.dev/articles/samesite-cookies-explained) attribute are treated as if they're set to **SameSite=Lax**. The `SameSite` attribute declares how cookies should be restricted to a same-site context. When set to `Lax`, the cookie is only sent to same-site requests or top-level navigation. However, application proxy requires these cookies to be preserved in the third-party context to keep users signed in during their session. Due to the requirement, updates were made:

4

Tap App Security Provisioning Tutorial

Updated

1. After entering the domain, a new line in the table appears showing domain name and its status as **initialize**. Select the gear icon to reveal technical data about TAP app Security server and to complete initialization.

2

Application Proxy Network Topology

Updated

Place the connector close to the target application in the customer network. This configuration minimizes step 3 in the topography diagram, because the connector and application are close.

2

Segment Provisioning Tutorial

Updated

1. The Tenant URL is `https://scim.segmentapis.com/scim/v2`. This value is entered in the **Tenant URL** field in the Provisioning tab of your Segment application.

Snowflake Provisioning Tutorial

Updated

The Microsoft Entra provisioning service currently operates under particular [IP ranges](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md#ip-ranges). If necessary, you can restrict other IP ranges and add these particular IP ranges to the allow list of your application. That technique will allow traffic flow from the Microsoft Entra provisioning service to your application.

1
1

Migrate Group Writeback

Updated

- A Microsoft Entra account with at least a [Hybrid Identity administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.

1
1

Security for AI agents with Microsoft Entra Agent ID

Updated

AI agents are autonomous software systems that can perceive their environment, make decisions, and take action. AI agents can expand organizational capabilities but also introduce security challenges that differ from traditional application security. This introduction explains why AI security matters, the challenges AI agents present, the concept of agent sprawl, and how Microsoft provides security mechanisms for AI agents in enterprise environments.

1
1
1
1
11
1

Configure Security

Updated

| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |

2
2

Install Ios Client

Updated

Because the Global Secure Access client for iOS is integrated with Microsoft Defender for Endpoint, it's helpful to understand the end user experience. The client appears in the Defender dashboard after onboarding to Global Secure Access.

1

View Enriched Logs

Updated

- **Microsoft Profile** - Ensure the Microsoft traffic profile is enabled. Microsoft traffic forwarding profile is required to capture traffic directed to Microsoft 365 services, which is fundamental for log enrichment.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…