← Previous day

Next day →
Day in brief

Entra ID documents non-interruptible Conditional Access agent runs; agent, certificate, Global Secure Access, and OIDC guidance also updated

19 May 2026 was a documentation-update day: all 10 tracked items were updates, with no new, removed, or Message Center entries. The most specific operational clarification is that an Entra ID Conditional Access Agent Optimization run cannot be stopped or paused after it starts and may take a few minutes. Other meaningful updates cover Conditional Access for Agent ID, certificate-revocation troubleshooting, Global Secure Access connector routing, and GitHub Enterprise Managed User OIDC provisioning. The evidence does not establish a new feature launch, preview, general availability milestone, retirement, or service-side behavior change.

  • The Entra ID documentation update states that after the agent starts, an optimization run cannot be stopped or paused and may take a few minutes. This is an operational documentation clarification, not evidence of a newly launched or generally available capability.

  • Updated Agent ID guidance describes applying Conditional Access to agent identities to extend Zero Trust principles to AI agents and support secure access and governance. The supplied record does not establish a preview, general availability status, or new control; administrators governing agent access should review the guidance.

  • The updated Entra ID guidance maps AADSTS500183 to a client certificate revoked by its issuing CA and directs administrators to provision and trust a replacement certificate and keep published CRLs and delta CRLs current and accessible to devices. This is security and troubleshooting guidance rather than a reported service change.

  • For connector groups with multiple connectors, the updated documentation says the group selects which connector handles each request and lists Random as the default routing option alongside Session persistence. Administrators should verify their intended routing configuration; the evidence does not say that the service default changed.

  • The updated Entra ID tutorial directs administrators to add GitHub Enterprise Managed User (OIDC) from the application gallery for provisioning. An existing SSO app can be reused, but the guidance recommends creating a separate app when initially testing the integration; this is tutorial guidance, not evidence of a new integration launch.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

2

Certificate Based Authentication Certificate Revocation List

Updated

| **AADSTS500183: Certificate has been revoked. Please contact your administrator** | An Authentication attempt failed because the client device presented a certificate that was revoked by the issuing CA. | The certificate used for authentication is found in the Certificate Revocation List (CRL) or flagged as revoked by the CA. | - Tenant Administrator should ensure the new certificate is correctly provisioned and trusted by Microsoft Entra ID.<br/>- Verify that the CRLs and delta CRLs published by your CA are up to date and accessible for the devices. |

Sspr Policy

Updated

| Compliance Administrator | Knowledge Administrator | Teams Communications Administrator |

1
1

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).

1
1
1
1

Direct Federation

Updated

To enable domainless federation for a new SAML IdP, follow these steps:

1

Connector Groups

Updated

When you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…