← Previous day

Next day →
Day in brief

1 July 2026: Global Secure Access publishes Microsoft-traffic guidance and calls out HTTP-method filtering in preview; ID Protection documents unified risk

This is a Microsoft Learn-led update rather than a release bulletin, with no Message Center item. The meaningful changes are a new set of Global Secure Access tutorials for Microsoft traffic controls, an updated Web Content Filtering page that explicitly labels HTTP method request filtering as preview, new ID Protection guidance for correlated risk, and Entra ID documentation for OIDC extensibility and SCIM API setup. The supplied evidence does not establish general availability, retirement, or an automatic tenant behavior change; the remaining edits are mainly standards, integration, logging, Security Copilot, and troubleshooting documentation maintenance.

  • The new tutorial brings source IP restoration, compliant network checks, and universal tenant restrictions into a Microsoft traffic lab path. Related new tutorials add the steps for enabling the Microsoft traffic profile, assigning users, installing the client, verifying forwarding, validating restored source IP in Entra sign-in logs, and configuring a Conditional Access policy that requires a compliant network. This is a new how-to set, not evidence of general availability or automatic changes to existing policies

  • The updated guidance identifies HTTP method request filtering as preview and describes blocking or allowing methods including GET, POST, PUT, PATCH, and DELETE. The evidence supports a documented preview capability, not general availability or a change to existing content policies; administrators should account for that status when assessing the option

  • A new fundamentals article explains that identity-risk signals from Microsoft Entra ID Protection and Microsoft Defender are correlated to calculate compounded user risk. Related dashboard guidance describes correlation across other Microsoft security products within the same time window, and the Risky User Report update documents an option to aggregate risk signals by risky sign-ins. This clarifies risk interpretation and reporting; it does not announce a new tenant setting or scoring rollout

  • A new Microsoft identity platform reference maps each OpenID Connect extensibility surface to its configuration article and the Microsoft Graph API resource that programs it. Alongside updates to the OAuth and OIDC protocol pages, this is a navigation and implementation clarification for application and identity-platform owners, not evidence of a new protocol capability or availability change

  • The updated SCIM API reference states that callers must enable the SCIM Provisioning API, configure billing, set up credentials, and obtain an access token before calling the documented endpoints. A related enablement-page update points readers to API-call pricing. This is a documentation clarification with planning implications for SCIM API adopters; it does not state that existing integrations changed

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

20 updates

4

Enable Scim Api

Updated

- **Cost:** See [API call pricing](https://aka.ms/EntraSCIMAPIPricing).

Entra Id Scim Api Reference

Updated

Before you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).

1

OAuth 2.0 and OpenID Connect protocols

Updated

Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.

1
1
1

Troubleshooting

Updated

- The object or property isn't supported for preview in the current release.

1

Risky User Report

Updated

To see risk sign-in events together with risky user events, select the **Aggregate risk signals by risky sign-ins** checkbox.

1
1

Id Protection Dashboard

Updated

Microsoft Entra ID Protection provides unified risk signals that aggregate correlated risk signals from Microsoft Entra ID Protection, Microsoft Defender, and other Microsoft security products. Instead of evaluating alerts in isolation, this capability correlates identity-related signals across products and evaluates them together within the same time window to calculate a compounded user risk score.

4

Configure Web Content Filtering

Updated

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

1
1
1
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…