← Previous day

Next day →
Day in brief

Conditional Access resource-exclusion enforcement is rolling out; most other changes are documentation maintenance

The most consequential item is a changed-behavior rollout in Microsoft Entra ID: Conditional Access policies targeting All resources with resource exclusions are being enforced more consistently. Related updates explain the affected sign-in scopes and how to assess or preview the impact. The remaining changes are mainly reference and how-to updates for provisioning, ID Governance, Verified ID, and Global Secure Access. The removed FAQ is a documentation-page removal; the supplied evidence does not indicate a product retirement, new GA launch, or message-center announcement.

  • Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target All resources and include one or more resource exclusions. The documented effect is that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access. Treat this as a changed-beavior rollout rather than a stated GA announcement, and review the related guidance for impact assessment, preview, and retaining legacy behavior.

  • The updated Global Secure Access (Preview) page explains how to view and analyze Model Context Protocol traffic between AI agents and remote MCP servers through the Generative AI Insights page. This is operational guidance for a preview capability; the evidence does not establish a new launch or general availability change.

  • The updated Kerberos reference states that Microsoft Entra Kerberos does not issue partial ticket-granting tickets to identities that are not synchronized to Microsoft Entra ID. This should be treated as a documentation clarification of an authentication boundary, so administrators should not design or troubleshoot around an expectation that unsynchronized identities will receive partial TGTs.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

22 updates

5

Improved Enforcement Resource Exclusions

Updated

Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target **All resources** and include one or more **resource exclusions**. This change ensures that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access.

Conditional Access Cloud Apps

Updated

Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, are enforced in user sign-in flows where the client application requests only these scopes. There is no change in behavior when an application requests any additional scope beyond those listed above.

5

Leapsome Provisioning Tutorial

Updated

1. Sign in to your [Leapsome Admin Console](https://www.Leapsome.com/app/#/login). Navigate to **Settings > Admin Settings**.

Jostle Provisioning Tutorial

Updated

Before you begin, you’ll need to create an **Automation user** in your Jostle intranet. This is the account you’ll use to configure with Azure. Automation users can be created in Admin **Settings > User accounts and data > Manage Automation users**.

Keepabl Provisioning Tutorial

Updated

1. Sign in to [Keepabl Admin Portal](https://app.keepabl.com) and then navigate to **Account Settings > Your Organization**, where you’ll see the **Single Sign-On (SSO)** section.

2

Kerberos

Updated

- Microsoft Entra Kerberos doesn't issue partial TGTs to identities that aren't synced to Microsoft Entra ID.

1
1
1

On Premises Scim Provisioning

Updated

8. Leave the portal and open the provisioning agent installer, agree to the terms of service, and select **Install**.

3

Entitlement Management Catalog Create

Updated

This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).

What Are Lifecycle Workflows

Updated

- Manage user lifecycle at scale. As your organization grows, the need for other resources to manage user lifecycle decreases.

1

Entitlement Management Overview

Updated

| access package | A bundle of resources that a team or project needs and is governed with policies. An access package is always contained in a catalog. You would create a new access package for a scenario in which identities need to request access for themselves. |

1

Decentralized Identifier Overview

Updated

The issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.

1

Licensing Guest Users

Updated

Global Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…