Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Teams for the web will honor Entra KMSI in late June; new Workload ID controls and Global Secure Access automation guidance are the main substantive changes
The clearest service-behavior change is Microsoft Teams for the web beginning to respect Microsoft Entra ID Keep Me Signed In (KMSI) settings in late June 2026. Users who opt to stay signed in can retain their session; otherwise, the session clears when the browser closes. The rest of the period is documentation-led: new Workload ID guidance covers restricting user-assigned managed identities to selected resource providers, and new Global Secure Access PowerShell samples cover monitoring, governance, backup, and recovery. An updated Entra Backup page clarifies roles for difference reports. No retirement or general-availability announcement is supplied; preview wording appears in recovery documentation without evidence of a new availability milestone.
- Teams for the web is changing its Entra session-persistence behavior
Entra ID · Conditional Access
Starting in late June 2026, Microsoft Teams for the web will respect Microsoft Entra ID Keep Me Signed In settings. Sessions persist only when users choose to stay signed in; otherwise, they clear when the browser closes. Microsoft describes the change as improving security on shared devices and states that no immediate action is required.
- New Workload ID guidance restricts user-assigned managed identity assignments
Workload ID · Security
Two new pages describe assignment restrictions that scope a user-assigned managed identity to one or more resource providers, including configuration through the Azure portal. The supplied evidence presents this as a security and resilience control and documentation addition; it does not establish a GA, Preview, or tenant-wide behavior change.
- Global Secure Access documentation expands PowerShell automation for operations and recovery
Global Secure Access · Monitoring
New samples cover shared authentication and alert-email helpers, Sentinel alert-noise monitoring, quarterly role-assignment reviews, backup snapshot listing and compliance checks, and non-destructive recovery preview followed by recovery execution for Global Secure Access-related directory objects. This expands documented automation; it is not evidence of a new Global Secure Access service launch or availability change.
- Entra Backup difference-report role requirements are clarified
Entra ID · Monitoring
The updated documentation states that Microsoft Entra Backup Reader is sufficient to review difference reports, while Microsoft Entra Backup Administrator is required to review and create them; Global Administrator also includes those permissions. This is a documentation clarification, not evidence of a change to service RBAC.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
28 updates
Microsoft Entra ID
16 updatesLearn how to configure single sign-on between Microsoft Entra ID and AlexisHR.
Tutorial Pilot Aadc Aadccp
UpdatedBefore you try this tutorial, consider the following items:
AI Administrator
UpdatedAI Administrator
> [!IMPORTANT]
Ai Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the AI Reader role to users who need to do the following tasks:
> [!NOTE]
Recover Objects
UpdatedKey details:
Describes the Microsoft Entra built-in roles and permissions.
Migrate Group Writeback
Updated- Cloud-created [security groups](../../../fundamentals/concept-learn-about-groups.md#group-types).
Overview
Updated> [!IMPORTANT]
You need at least the **Microsoft Entra Backup Reader** role to review difference reports. To review and create difference reports, you need the **Microsoft Entra Backup Administrator** role. The **Global Administrator** role also includes these permissions.
For a full list of supported attributes, see [Supported objects and attributes](scope-supported-objects-limitations.md).
ai-usage: ai-assisted
Tshoot Connect Sso
Updated1. Ensure Microsoft Entra Connect is installed. Download it from the [Microsoft Entra Admin Center](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/%7E/GetStarted).
Single Sign On Saml Protocol
Updated</AuthnContext>
Microsoft Entra Workload ID
2 updatesLearn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Microsoft Entra Global Secure Access
10 updatesCreate a non-destructive Microsoft Entra recovery preview job scoped to directory objects that affect Global Secure Access.
Run a Microsoft Entra recovery job for directory objects that affect Global Secure Access after reviewing a recovery preview.
Calculate the Microsoft Sentinel alert noise ratio for Global Secure Access detections and send an alert when false positives or informational closures exceed your threshold.
Check Global Secure Access-related administrator role assignments and identify accounts that need quarterly review.
Verify that your Global Secure Access configuration backup runbook ran successfully. Send an alert when the runbook fails or misses a scheduled run.
Use shared helper functions for authentication and alert email in Global Secure Access operations automation scripts.
Operations
Updated| --- | --- |
List Microsoft Entra Backup and Recovery snapshots that can help recover directory objects used by Global Secure Access.
Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.
Security Operations
Updated- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)
