ai-usage: ai-assisted
28 March 2026: DirectAccess migration guidance and a Global Secure Access DNS prerequisite lead a documentation-heavy Entra day
The clearest administrator-impacting updates are a new phased migration guide for Microsoft Entra Private Access and updated Global Secure Access threat-intelligence guidance stating that DNS over HTTPS must be disabled for tunneled traffic. Microsoft Entra External ID also refreshed B2B multifactor authentication and email one-time passcode guidance. Most remaining changes are Microsoft Learn maintenance, including multitenant organization, cross-tenant synchronization, PIM, and guest-administration content. The supplied evidence shows no preview, general availability announcement, retirement, Message Center notice, or confirmed service-behavior change.
- Global Secure Access threat-intelligence guidance specifies a DNS prerequisite
Global Secure Access · General
The updated configuration page states that DNS over HTTPS (Secure DNS) must be disabled to tunnel network traffic and directs administrators to use FQDN rules in the traffic forwarding profile. For deployments using this tunneling path, verify the DNS and forwarding-profile configuration. The record provides configuration guidance, not evidence that service behavior changed on this date.
- Microsoft Entra Private Access gains a new DirectAccess migration guide
Private Access · General
The only new item is a Microsoft Learn guide for migrating client devices from DirectAccess to Microsoft Entra Private Access through a phased approach intended to avoid tunnel conflicts and connectivity failures. This is migration documentation, not evidence of a new Private Access feature, a GA milestone, or a DirectAccess retirement. Organizations planning the transition now have a documented sequence to review.
- External ID B2B MFA and Conditional Access guidance was refreshed
External ID · Conditional Access
The updated page focuses on enforcing multifactor authentication policies for Microsoft Entra B2B users. This is refreshed guest-access security guidance; the supplied evidence does not say that Conditional Access enforcement or MFA requirements changed in the service. Administrators reviewing B2B access should compare their documented policy procedures with the updated instructions.
- External ID email one-time passcode fallback instructions were updated
External ID · Authentication
The updated page covers enabling and using email one-time passcode authentication for B2B guest users and describes it as a fallback sign-in method. The evidence supports a how-to refresh only; it does not establish a new preview or GA milestone or a change in availability. Review guest sign-in flows if email OTP is part of the tenant design.
- Multitenant organization and cross-tenant synchronization documentation was broadly refreshed
Entra ID · General
Updates cover multitenant organization capabilities, policy templates, provisioning, cross-tenant synchronization, topologies, and limitations. The supplied excerpts for this cluster provide little substantive change detail beyond an AI-use marker, so classify it as documentation maintenance rather than evidence of a new capability, preview, GA, retirement, or changed service limit. Teams implementing these patterns should recheck the relevant setup and limitations pages.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
36 updates
Microsoft Entra ID
14 updatesHow to identify and resolve license assignment problems when you're using Microsoft Entra group-based licensing.
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
Prepare Converted Groups
Updated$groupDisplayName = 'My Security Group'
ai-usage: ai-assisted
Recoverability Overview
Updated- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.
- make.gov.powerapps.us
ai-usage: ai-assisted
Policy Guests Mfa Strength
Updated1. Give your policy a name. Create a meaningful standard for the names of your policies.
Microsoft Entra ID Governance
3 updatesLearn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure Microsoft Entra role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Microsoft Entra External ID
16 updatesBulk invite B2B users
UpdatedLearn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.
Use Microsoft accounts
UpdatedEnable your external business partners and guest users to use their Microsoft account (MSA) to sign in to your apps for B2B collaboration.
Use Microsoft Entra accounts
UpdatedEnable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.
Cross-cloud settings
UpdatedEnable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.
Learn how to add Google as an identity provider for your external tenant.
B2b Tutorial Require Mfa
Updated1. Select **New policy**.
Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.
Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.
Define custom attributes
UpdatedLearn how to create and define new custom attributes to be collected from users during sign-up and sign-in.
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
Learn how to enforce multifactor authentication policies for Microsoft Entra B2B users.
ai-usage: ai-assisted
Learn to govern and manage identity and access lifecycles across multitenant organizations.
ai-usage: ai-assisted
Microsoft Entra Private Access
2 updatesLearn how to migrate client devices from DirectAccess to Microsoft Entra Private Access with a phased approach that avoids tunnel conflicts and connectivity failures.
DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.
- You must disable Domain Name System (DNS) over HTTPS (Secure DNS) to tunnel network traffic. Use the rules of the fully qualified domain names (FQDNs) in the traffic forwarding profile. For more information, see [Configure the DNS client to support DoH](/windows-server/networking/dns/doh-client-support#configure-the-dns-client-to-support-doh).
