← Previous day

Next day →
Day in brief

Apple SSO compatibility guidance is the main action item; AI security guidance was updated and a Copilot security page was removed

The 3 April 2026 Entra ID record is documentation-led rather than a feature-release day: it contains 10 updates and one removal, with no new feature, preview, general-availability announcement, or Message Center item evidenced. The clearest administrator action concerns applications and MDM solutions that access Microsoft Entra device-registration keys through Keychain. Other notable changes are updated Conditional Access guidance for generative-AI security, a documented provisioning limitation, and removal of one Copilot security documentation page.

  • Updated Microsoft identity platform guidance says applications or MDM solutions that depend on accessing Microsoft Entra device-registration keys through Keychain must be updated to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility. This is compatibility guidance for an existing integration path, not evidence of a new Apple SSO feature launch.

  • The updated Secure Generative AI architecture guidance directs organizations to enforce least privilege and use Conditional Access policies as the access-control mechanism, with examples such as requiring MFA or device compliance. The evidence supports a security-guidance clarification, not a new policy template, default, or availability change.

  • The Entra ID security page titled Policy All Users Copilot Ai Security is marked Removed. No replacement, rationale, or product retirement is supplied, so administrators should classify this as a documentation removal rather than evidence that the underlying Copilot policy or capability was retired.

  • An updated Entra ID Known Issues page states that provisioning passwords aren't supported. This documents a limitation rather than announcing a behavior change or feature; provisioning owners should not assume password provisioning is available, and the supplied evidence does not identify the affected connector scope or a workaround.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

11 updates

4

Apple Sso Plugin

Updated

If your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.

Known Issues

Updated

- Provisioning passwords isn't supported.

3
1

Secure Generative Ai

Updated

Enforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements where identities that meet certain criteria can only access resources if they meet specific requirements such as MFA or device compliance status.

1
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…