| **AADSTS500183: Certificate has been revoked. Please contact your administrator** | An Authentication attempt failed because the client device presented a certificate that was revoked by the issuing CA. | The certificate used for authentication is found in the Certificate Revocation List (CRL) or flagged as revoked by the CA. | - Tenant Administrator should ensure the new certificate is correctly provisioned and trusted by Microsoft Entra ID.<br/>- Verify that the CRLs and delta CRLs published by your CA are up to date and accessible for the devices. |
Entra ID documents non-interruptible Conditional Access agent runs; agent, certificate, Global Secure Access, and OIDC guidance also updated
19 May 2026 was a documentation-update day: all 10 tracked items were updates, with no new, removed, or Message Center entries. The most specific operational clarification is that an Entra ID Conditional Access Agent Optimization run cannot be stopped or paused after it starts and may take a few minutes. Other meaningful updates cover Conditional Access for Agent ID, certificate-revocation troubleshooting, Global Secure Access connector routing, and GitHub Enterprise Managed User OIDC provisioning. The evidence does not establish a new feature launch, preview, general availability milestone, retirement, or service-side behavior change.
- Conditional Access Agent Optimization: runs are non-interruptible once started
Entra ID · Conditional Access
The Entra ID documentation update states that after the agent starts, an optimization run cannot be stopped or paused and may take a few minutes. This is an operational documentation clarification, not evidence of a newly launched or generally available capability.
- Conditional Access for agent identities: Zero Trust guidance updated
Agent ID · Conditional Access
Updated Agent ID guidance describes applying Conditional Access to agent identities to extend Zero Trust principles to AI agents and support secure access and governance. The supplied record does not establish a preview, general availability status, or new control; administrators governing agent access should review the guidance.
- Certificate-based authentication: revoked-certificate troubleshooting is more explicit
Entra ID · Authentication
The updated Entra ID guidance maps AADSTS500183 to a client certificate revoked by its issuing CA and directs administrators to provision and trust a replacement certificate and keep published CRLs and delta CRLs current and accessible to devices. This is security and troubleshooting guidance rather than a reported service change.
- Global Secure Access connector groups: routing choices documented
Global Secure Access · Fundamentals
For connector groups with multiple connectors, the updated documentation says the group selects which connector handles each request and lists Random as the default routing option alongside Session persistence. Administrators should verify their intended routing configuration; the evidence does not say that the service default changed.
- GitHub Enterprise Managed User OIDC: provisioning test-app guidance
Entra ID · Provisioning
The updated Entra ID tutorial directs administrators to add GitHub Enterprise Managed User (OIDC) from the application gallery for provisioning. An existing SSO app can be reused, but the guidance recommends creating a separate app when initially testing the integration; this is tutorial guidance, not evidence of a new integration launch.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
10 updates
Microsoft Entra ID
5 updatesSspr Policy
Updated| Compliance Administrator | Knowledge Administrator | Teams Communications Administrator |
- After the agent starts, you can't stop or pause the run. It might take a few minutes to run.
Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).
Hr User Update Issues
UpdatedLearn how to troubleshoot user update issues with HR provisioning
Microsoft Entra Agent ID
1 updateLearn how Conditional Access for agent identities in Microsoft Entra ID extends Zero Trust principles to AI agents, ensuring secure access and governance.
Microsoft Entra External ID
2 updates|---------|-------|
Direct Federation
UpdatedTo enable domainless federation for a new SAML IdP, follow these steps:
Microsoft Entra Global Secure Access
2 updatesConnector Groups
UpdatedWhen you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.
Current Known Limitations
UpdatedFor usage in US Government community (GCC) cloud, known limitations/disclaimers include:
