Plan your Conditional Access policies to balance security and productivity. Learn how to design and deploy effective policies for your organization.
2 June 2026: documentation updates sharpen Global Secure Access filtering and SSPR bootstrap guidance; device soft delete is described as a preview
This was a documentation-only day: all 11 recorded changes were Microsoft Learn updates, with no new or removed items and no Message Center entries. The most substantive updates cover existing implementation and operations guidance for Global Secure Access web filtering, SSPR authentication-data synchronization, Private Access, and Entra RBAC. The supplied evidence does not announce a new feature, general-availability milestone, retirement, or service-behavior change.
- Global Secure Access web content filtering guidance
Internet Access · Conditional Access
The updated Microsoft Entra Internet Access how-to describes user-aware internet filtering by website category, URL, and FQDN, using security profiles and Conditional Access. This is an implementation-guidance update; the evidence does not establish that the filtering capability itself launched, changed behavior, or reached general availability.
- SSPR bootstrap can use synchronized AD DS authentication data
Entra ID · Authentication
The updated Entra ID SSPR guidance explains that existing authentication data from Active Directory Domain Services can be synchronized into Microsoft Entra ID and SSPR. Users can then change or reset a password without first registering contact information. The feed presents this as documentation guidance, not a new availability announcement.
- Device soft delete is explicitly scoped as a preview
Entra ID · Fundamentals
The updated Entra ID device-soft-delete page says preview support applies to specified device types. The supplied summary does not name those types or report a scope expansion or general-availability transition, so administrators should verify the current preview scope before relying on the capability.
- Private Access operations guidance is structured around checks and failure handling
Private Access · General
The updated Microsoft Entra Private Access operations page lays out checks with the responsible role, whether the step is automated, the procedure, and what to do if it fails. This is runbook and operational guidance; no Private Access behavior or rollout change is indicated.
- RBAC reference guidance focuses on role assignments and restricted scope
Entra ID · Fundamentals
The updated Entra ID RBAC overview focuses on understanding the components of a role assignment and restricted scope. This is ordinary reference clarification; the supplied evidence does not indicate a change to the permissions model, roles, or assignment behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
11 updates
Microsoft Entra ID
8 updatesai-usage: ai-assisted
Soft Delete Devices
UpdatedDuring the preview, device soft delete is supported for the following device types:
Learn how to understand the parts of a role assignment and restricted scope in Microsoft Entra ID.
Connect Sso How It Works
Updated>[!IMPORTANT]
Best practices for using Microsoft Entra roles.
Some organizations prefer to bootstrap this process through synchronization of authentication data that already exists in Active Directory Domain Services. This synchronized data is made available to Microsoft Entra ID and SSPR without requiring user interaction. When users need to change or reset their password, they can do so even if they haven't previously registered their contact information.
A Microsoft Entra documentation page was updated: Add a Microsoft Entra ID tenant as an OpenID Connect identity provider.
Microsoft Entra External ID
1 update> [!NOTE]
Microsoft Entra Internet Access
1 updateControl internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
Microsoft Entra Private Access
1 updateOperate Private Access
Updated| Check | Role | Automated by | Procedure | What to do if it fails |
