← Previous day

Next day →
Day in brief

28 March 2026: DirectAccess migration guidance and a Global Secure Access DNS prerequisite lead a documentation-heavy Entra day

The clearest administrator-impacting updates are a new phased migration guide for Microsoft Entra Private Access and updated Global Secure Access threat-intelligence guidance stating that DNS over HTTPS must be disabled for tunneled traffic. Microsoft Entra External ID also refreshed B2B multifactor authentication and email one-time passcode guidance. Most remaining changes are Microsoft Learn maintenance, including multitenant organization, cross-tenant synchronization, PIM, and guest-administration content. The supplied evidence shows no preview, general availability announcement, retirement, Message Center notice, or confirmed service-behavior change.

  • The updated configuration page states that DNS over HTTPS (Secure DNS) must be disabled to tunnel network traffic and directs administrators to use FQDN rules in the traffic forwarding profile. For deployments using this tunneling path, verify the DNS and forwarding-profile configuration. The record provides configuration guidance, not evidence that service behavior changed on this date.

  • The only new item is a Microsoft Learn guide for migrating client devices from DirectAccess to Microsoft Entra Private Access through a phased approach intended to avoid tunnel conflicts and connectivity failures. This is migration documentation, not evidence of a new Private Access feature, a GA milestone, or a DirectAccess retirement. Organizations planning the transition now have a documented sequence to review.

  • The updated page focuses on enforcing multifactor authentication policies for Microsoft Entra B2B users. This is refreshed guest-access security guidance; the supplied evidence does not say that Conditional Access enforcement or MFA requirements changed in the service. Administrators reviewing B2B access should compare their documented policy procedures with the updated instructions.

  • The updated page covers enabling and using email one-time passcode authentication for B2B guest users and describes it as a fallback sign-in method. The evidence supports a how-to refresh only; it does not establish a new preview or GA milestone or a change in availability. Review guest sign-in flows if email OTP is part of the tenant design.

  • Updates cover multitenant organization capabilities, policy templates, provisioning, cross-tenant synchronization, topologies, and limitations. The supplied excerpts for this cluster provide little substantive change detail beyond an AI-use marker, so classify it as documentation maintenance rather than evidence of a new capability, preview, GA, retirement, or changed service limit. Teams implementing these patterns should recheck the relevant setup and limitations pages.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

36 updates

3
3
2
2
1

Recoverability Overview

Updated

- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.

1
1
1
3
6

Bulk invite B2B users

Updated

Learn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.

Use Microsoft accounts

Updated

Enable your external business partners and guest users to use their Microsoft account (MSA) to sign in to your apps for B2B collaboration.

Use Microsoft Entra accounts

Updated

Enable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.

Cross-cloud settings

Updated

Enable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.

3

Email one-time passcode authentication

Updated

Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.

Identity providers for external tenants

Updated

Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.

Define custom attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

3
1
1
1
1
1
1

Migrate from DirectAccess to Microsoft Entra Private Access

Updated

DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.

1

How to configure Global Secure Access threat intelligence

Updated

- You must disable Domain Name System (DNS) over HTTPS (Secure DNS) to tunnel network traffic. Use the rules of the fully qualified domain names (FQDNs) in the traffic forwarding profile. For more information, see [Configure the DNS client to support DoH](/windows-server/networking/dns/doh-client-support#configure-the-dns-client-to-support-doh).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…