← Previous day

Next day →
Day in brief

14 May: Conditional Access documentation details P2-required high-risk MFA guidance; Private Access documents connector-capacity thresholds

This was a documentation-only period: all six supplied entries were Microsoft Learn updates, with no new or removed items and no Message Center notices. The most consequential updates clarify Conditional Access agent guidance for risky sign-ins and policy coverage, Private Access connector-capacity response, Entra schema-extension limits, and the licensing prerequisite for ID Governance Account Discovery. The evidence does not identify a preview, general-availability release, retirement, or tenant-wide configuration change. The separate Agent ID update is setup guidance for users with the GitHub Copilot for Azure extension, not evidence of a launch.

  • Security guidance clarification: the updated page says the agent suggests a policy requiring multifactor authentication for high-risk sign-ins and states that Microsoft Entra ID P2 is required for this scenario. This describes agent guidance, not evidence that a policy was automatically created or deployed; administrators evaluating the suggestion should confirm the licensing dependency and validate the policy before rollout.

  • Conditional Access analysis guidance clarification: deep analysis is documented as reviewing policies that block legacy authentication or device control flow and those requiring device or MFA controls. It evaluates user, group, and role coverage for gaps, redundant or overlapping policies, and consolidation opportunities, while also flagging broad exclusions and recommending explicit break-glass exclusions to reduce accidental-lockout risk. The update does not report changes to existing tenant policies.

  • Operational guidance: the updated Operate Private Access page documents a connector-host alert condition of CPU above 80% or memory above 85% sustained for more than 15 minutes. The associated response is to check active sessions, redistribute load by adding another connector to the group, and investigate applications generating unusual traffic; Azure Monitor alerting is identified as the monitoring path.

  • Service-limit clarification: string extensions are limited to 256 characters and binary extensions to 256 bytes; no more than 100 extension values across all types and applications can be written to one resource. The page also limits string or binary single-valued attributes to User, Group, TenantDetail, Device, Application, and ServicePrincipal entities, and states that DateTime extensions support only the equals operator, not range operators.

  • Licensing clarification: the updated ID Governance guidance states that Account Discovery requires either the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. The feature is described as finding existing accounts in target applications and identifying matching Entra accounts or orphan accounts, so teams planning that use should verify entitlement before proceeding.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

6 updates

2

Conditional Access Agent Optimization

Updated

- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.

Conditional Access Agent Optimization Review Suggestions

Updated

Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.

1

Entra Service Limits Include

Updated

| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li> Only the "equals" operator is supported for DateTime-type extensions. Range operators like "greater than" or "less than" are not supported.</li></ul> |

1

Agent Id Ai Guided Setup

Updated

If you have the GitHub Copilot for Azure extension installed, ask Copilot to set up Agent ID. For example:

1

Licensing Fundamentals

Updated

Account Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).

1

Operate Private Access

Updated

| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…