Frequently asked questions about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions.
Conditional Access resource-exclusion enforcement is rolling out; most other changes are documentation maintenance
The most consequential item is a changed-behavior rollout in Microsoft Entra ID: Conditional Access policies targeting All resources with resource exclusions are being enforced more consistently. Related updates explain the affected sign-in scopes and how to assess or preview the impact. The remaining changes are mainly reference and how-to updates for provisioning, ID Governance, Verified ID, and Global Secure Access. The removed FAQ is a documentation-page removal; the supplied evidence does not indicate a product retirement, new GA launch, or message-center announcement.
- Conditional Access enforcement is changing for All resources policies with exclusions
Entra ID · Conditional Access
Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target All resources and include one or more resource exclusions. The documented effect is that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access. Treat this as a changed-beavior rollout rather than a stated GA announcement, and review the related guidance for impact assessment, preview, and retaining legacy behavior.
- Global Secure Access updates MCP traffic-log monitoring guidance
Global Secure Access · Monitoring
The updated Global Secure Access (Preview) page explains how to view and analyze Model Context Protocol traffic between AI agents and remote MCP servers through the Generative AI Insights page. This is operational guidance for a preview capability; the evidence does not establish a new launch or general availability change.
- Entra Kerberos documentation clarifies partial-TGT behavior
Entra ID · Authentication
The updated Kerberos reference states that Microsoft Entra Kerberos does not issue partial ticket-granting tickets to identities that are not synchronized to Microsoft Entra ID. This should be treated as a documentation clarification of an authentication boundary, so administrators should not design or troubleshoot around an expectation that unsynchronized identities will receive partial TGTs.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
22 updates
Microsoft Entra ID
15 updatesLearn about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions, including how to assess impact and retain legacy behavior.
Frequently asked questions about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions.
Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target **All resources** and include one or more **resource exclusions**. This change ensures that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access.
Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, are enforced in user sign-in flows where the client application requests only these scopes. There is no change in behavior when an application requests any additional scope beyond those listed above.
After migrating your users and groups to Microsoft Entra ID, you may be ready to decommission your on-premises Active Directory and uninstall sync tools. After turning off directory synchronization, you can manage these objects directly in Microsoft Entra ID.
1. Sign in to your [Leapsome Admin Console](https://www.Leapsome.com/app/#/login). Navigate to **Settings > Admin Settings**.
Jostle Provisioning Tutorial
UpdatedBefore you begin, you’ll need to create an **Automation user** in your Jostle intranet. This is the account you’ll use to configure with Azure. Automation users can be created in Admin **Settings > User accounts and data > Manage Automation users**.
```python
1. Sign in to [Keepabl Admin Portal](https://app.keepabl.com) and then navigate to **Account Settings > Your Organization**, where you’ll see the **Single Sign-On (SSO)** section.
Microsoft has decided not to proceed with adding Passkeys (FIDO2) as an authentication method in Microsoft Registration Campaigns starting April 2026. Previously planned changes, including automatic updates and nudges for MFA-capable users, will not be implemented at this time. Updates are available in MC1279092.
Kerberos
Updated- Microsoft Entra Kerberos doesn't issue partial TGTs to identities that aren't synced to Microsoft Entra ID.
You can preview the improved enforcement behavior before the rollout begins:
A Microsoft Entra documentation page was updated: Improved Enforcement Resource Exclusions Faq.
8. Leave the portal and open the provisioning agent installer, agree to the terms of service, and select **Install**.
Microsoft Entra ID Governance
4 updatesThis article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).
What Are Lifecycle Workflows
Updated- Manage user lifecycle at scale. As your organization grows, the need for other resources to manage user lifecycle decreases.
Entitlement Management Roles
Updated> [!NOTE]
| access package | A bundle of resources that a team or project needs and is governed with policies. An access package is always contained in a catalog. You would create a new access package for a scenario in which identities need to request access for themselves. |
Microsoft Entra Verified ID
1 updateThe issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.
Microsoft Entra Global Secure Access
2 updatesLicensing Guest Users
UpdatedGlobal Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).
Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
