Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Explicit Forward Proxy guidance is expanding, but the capability remains in preview
30 April was a documentation-focused period: all 16 recorded items were updates, with no new or removed items and no Message Center announcements. The most consequential theme was a set of Global Secure Access and Microsoft Entra Internet Access updates clarifying Explicit Forward Proxy (EFP) for browser traffic when the GSA client cannot be installed, including PAC-based operation. The related Conditional Access guidance still identifies EFP as preview; the evidence does not indicate a general-availability launch. Two integration updates also provide concrete provisioning and recovery guidance for Entra ID administrators.
- Global Secure Access documents EFP as an option where the client cannot be installed
Global Secure Access · Authentication
The updated Explicit Forward Proxy overview describes EFP as a traffic-acquisition mechanism for scenarios in which installing the Global Secure Access client is difficult or not possible, and positions it for protecting browser internet traffic. This is clarified preview documentation, not evidence of a new launch or GA change.
- Microsoft Entra Internet Access can use EFP with PAC-capable browsers
Internet Access · General
The updated configuration guidance says EFP can provide Microsoft Entra Internet Access Secure Web and AI Gateway capabilities without installing the GSA client. It works with browsers that support proxy automatic configuration (PAC), making browser and PAC compatibility a key consideration for an EFP evaluation.
- Conditional Access guidance explicitly retains EFP preview status
Global Secure Access · Conditional Access
The updated Global Secure Access Conditional Access page states that Explicit Forward Proxy is currently in PREVIEW. Administrators should therefore treat Conditional Access planning for EFP as preview-stage guidance; the update does not announce general availability.
- Netskope provisioning guidance clarifies matching behavior for updates
Entra ID · Authentication
The updated Entra ID Netskope provisioning tutorial says attributes selected as Matching are used to match Netskope User Authentication accounts during update operations. If the matching target is changed, the Netskope User Authentication API must support filtering users on that attribute. This is an integration documentation clarification, but it gives admins a concrete dependency to validate before changing the mapping.
- Simple In/Out documentation emphasizes recovery-key custody
Entra ID · Provisioning
The updated Entra ID Simple In/Out tutorial instructs administrators to reveal and store the entire Recovery Key safely. It says that if administrators are locked out of their Microsoft accounts and need to disconnect SSO, they must relay the key to Simple In/Out technical support. This is operational and security guidance for that integration, not a platform-wide recovery change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
16 updates
Microsoft Entra ID
11 updatesAI Administrator
UpdatedAI Administrator
Entra Backup Administrator
UpdatedEntra Backup Administrator
Entra Backup Reader
UpdatedEntra Backup Reader
author: FaithOmbongi
Describes the Microsoft Entra built-in roles and permissions.
1. Select **Reveal** on your Recovery Key and store this entire key in a safe place. **IMPORTANT!** If you're ever locked out of your Microsoft accounts and need to disconnect SSO without access, you be required to relay the Recovery Key to Simple In/Out technical support.
The scenario outlined in this article assumes that you already have the following prerequisites:
1. In the **Tenant URL** field, enter your SAS Viya SSO Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to SAS Viya SSO. If the connection fails, ensure your SAS Viya SSO account has the required admin permissions and try again.
1. Review the user attributes that are synchronized from Microsoft Entra ID to Netskope User Authentication in the **Attribute-Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Netskope User Authentication for update operations. If you choose to change the [matching target attribute](~/identity/app-provisioning/customize-application-attributes.md), you need to ensure that the Netskope User Authentication API supports filtering users based on that attribute. Select the **Save** button to commit any changes.
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department|String||
Microsoft Entra Internet Access
1 updateExplicit Forward Proxy (EFP) allows you to use Secure Web and AI Gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access (GSA) client. EFP works with any browser that supports proxy automatic configuration (PAC).
Microsoft Entra Global Secure Access
4 updatesExplicit Forward Proxy (EFP) is one of the traffic acquisition mechanisms that's useful in scenarios where installation of the Global Secure Access (GSA) client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from:
> The Explicit Forward Proxy feature is currently in PREVIEW.
author: idmdev
A PAC file is a mechanism used to automatically determine which proxy server a web browser or application should use for a given request. PAC files are an integral part of Explicit Forward Proxy configuration, enabling flexible and dynamic traffic steering decisions. In the context of Global Secure Access, PAC files are similar to the traffic forwarding policies of the GSA client.
