← Previous day

Next day →
Day in brief

Agent ID blueprint limit clarified; 27 May otherwise centers on Entra Connect Health documentation

27 May 2026 was primarily a documentation-maintenance day. The clearest administrator-facing update is an Agent ID boundary of no more than 50 resource apps per agent identity blueprint. The larger Entra ID cluster refreshes Connect Health installation, AD FS, Sync and AD DS monitoring, reporting, data freshness, ports, topology and PTA guidance; an updated Groups page restates the dynamic-membership licensing prerequisite. The supplied evidence contains no Message Center item or removal and does not establish a new preview, general-availability release, retirement, security advisory or product-behavior change. Four new Entra ID entries titled “Purpose:” contain only an author string and provide no actionable release detail.

  • The updated blueprint guidance sets a maximum of 50 resource apps per agent identity blueprint, including entries in the inheritablePermissions collection. It explicitly says to reduce the number of resource apps if the limit is exceeded. This is a supported-boundary clarification, not evidence of a new Agent ID preview or generally available capability.

  • The page describes integrating AD FS sign-ins with the Microsoft Entra Connect Health sign-ins report. A related same-day update covers the AD FS risky IP report in Azure Monitor Workbooks. These are monitoring and security-documentation updates; the supplied evidence does not establish a new report launch or changed sign-in behavior.

  • The updated PTA page says that installing multiple agents provides high availability of sign-in requests. This is operational guidance for PTA deployments, not evidence of a newly introduced feature or a mandated topology change.

  • The updated Connect Health with AD DS page lists Windows Server 2016, 2019, 2022 and 2025 as supported versions. The supplied record does not say whether this list changed during the period, so this should be treated as a documentation clarification and support reference rather than a newly announced compatibility change.

  • The updated Groups Create Rule page says dynamic membership groups require a Microsoft Entra ID P1 license or an Intune for Education license. It does not indicate a new licensing policy or entitlement change; it provides the prerequisite to use when reviewing dynamic-group deployments.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

18 updates

10

Groups Create Rule

Updated

Using dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).

Connect Health Data Freshness

Updated

* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.

Connect Ports

Updated

<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>

5

Using Microsoft Entra Connect Health with AD DS

Updated

The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.

2

Connect Pta

Updated

- Installing multiple agents provides high availability of sign-in requests.

1

Configure Inheritable Permissions Blueprints

Updated

- Maximum of 50 resource apps per agent identity blueprint (for example, up to 50 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…