← Previous day

Next day →
Day in brief

Teams for the web will honor Entra KMSI in late June; new Workload ID controls and Global Secure Access automation guidance are the main substantive changes

The clearest service-behavior change is Microsoft Teams for the web beginning to respect Microsoft Entra ID Keep Me Signed In (KMSI) settings in late June 2026. Users who opt to stay signed in can retain their session; otherwise, the session clears when the browser closes. The rest of the period is documentation-led: new Workload ID guidance covers restricting user-assigned managed identities to selected resource providers, and new Global Secure Access PowerShell samples cover monitoring, governance, backup, and recovery. An updated Entra Backup page clarifies roles for difference reports. No retirement or general-availability announcement is supplied; preview wording appears in recovery documentation without evidence of a new availability milestone.

  • Starting in late June 2026, Microsoft Teams for the web will respect Microsoft Entra ID Keep Me Signed In settings. Sessions persist only when users choose to stay signed in; otherwise, they clear when the browser closes. Microsoft describes the change as improving security on shared devices and states that no immediate action is required.

  • Two new pages describe assignment restrictions that scope a user-assigned managed identity to one or more resource providers, including configuration through the Azure portal. The supplied evidence presents this as a security and resilience control and documentation addition; it does not establish a GA, Preview, or tenant-wide behavior change.

  • New samples cover shared authentication and alert-email helpers, Sentinel alert-noise monitoring, quarterly role-assignment reviews, backup snapshot listing and compliance checks, and non-destructive recovery preview followed by recovery execution for Global Secure Access-related directory objects. This expands documented automation; it is not evidence of a new Global Secure Access service launch or availability change.

  • The updated documentation states that Microsoft Entra Backup Reader is sufficient to review difference reports, while Microsoft Entra Backup Administrator is required to review and create them; Global Administrator also includes those permissions. This is a documentation clarification, not evidence of a change to service RBAC.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

28 updates

9

Ai Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the AI Reader role to users who need to do the following tasks:

2

Migrate Group Writeback

Updated

- Cloud-created [security groups](../../../fundamentals/concept-learn-about-groups.md#group-types).

2

Create Review Difference Reports

Updated

You need at least the **Microsoft Entra Backup Reader** role to review difference reports. To review and create difference reports, you need the **Microsoft Entra Backup Administrator** role. The **Global Administrator** role also includes these permissions.

1
1

Tshoot Connect Sso

Updated

1. Ensure Microsoft Entra Connect is installed. Download it from the [Microsoft Entra Admin Center](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/%7E/GetStarted).

1
1
1
5
1
1
1
1

PowerShell samples for Global Secure Access

Updated

Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.

1

Security Operations

Updated

- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…