Cross-product topic

General

A cross-product view of Microsoft Entra changes related to General.

Latest General changes

Publish App Gallery

General

The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.

Version History

General

The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.

Group Source Of Authority Configure

General

The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.

How Managed Identities Work Vm

General

The curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.

How Managed Identities Work Vm

General

The VM managed identity documentation changes the client_id value in its curl token-request example.

Preserve a group's organizational unit (Preview)

General

A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.

Sap Netweaver Tutorial

General

Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.

Sap Netweaver Tutorial

General

The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.

Version History

General

The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.

Agent Token Claims

General

The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.

Assign App Owners

General

The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.

Create Service Principal Cross Tenant

General

The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.

Exchange Hybrid

General

The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.

Manage App Consent Policies

General

The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.

Current Known Limitations

General

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

Current Known Limitations

General

The documentation received a minor formatting change with no substantive content changes identified.

Current Known Limitations

General

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

Global Secure Access Client Release Notes

General

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

Microsoft Entra: Domain update for My Account and identity self-service experiences

Message CenterMC1462460 on mc.merill.net ↗Plan for change
General

Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.

Plan Sso Deployment

General

Removed an extra space from the Help desk admin row in the documentation table.

Publish your app to Microsoft Entra App Gallery

General

A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.

Whats New Linux

General

Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.

Connect Health Agent Install

General

The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.

Connect Health Version History

General

The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.

Global Secure Access Client for macOS Release Notes

General

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

Install the Global Secure Access Client for macOS

General

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

Macos Client Release History

General

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

Global Secure Access Client for macOS Release Notes

General

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

Install Macos Client

General

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

Install Macos Client

General

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

Install Macos Client

General

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

Install the Global Secure Access Client for macOS

General

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

Macos Client Release History

General

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

Optional Claims Reference

General

The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.

Licensing Service Plan Reference

General

The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.

Licensing Service Plan Reference

General

The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.

Licensing Service Plan Reference

General

The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.

Licensing Service Plan Reference

General

The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.

Licensing Service Plan Reference

General

The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.

Migrate web content filtering policies from V1 to V2

General

A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.

Allow Deny List

General

The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.

Create Delete Agent Identities

General

The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.

Howto Delete Agent Identity

General

The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.

Integrate Aws Bedrock Agent

General

The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.

Manage agents in end user experience

General

The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.

Manage rules for dynamic membership groups in Microsoft Entra ID

General

The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.

Federate a Google Cloud workload identity

General

Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.

Federate a SPIFFE/SPIRE workload identity

General

Adds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.

Manage Microsoft Profile

General

The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”

Manage Microsoft Profile

General

The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.

Custom Proxy File Hosting

General

The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.

Howto Target Agent Identities

General

The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.

Howto Target Agent Identities

General

The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.

Import ADSyncTools module

General

The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.

Import ADSyncTools module

General

The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.

Provide the user's identity.

General

The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.

Whats New

General

The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.

Network Content Filtering

General

The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.

How to manage the Internet Access profile

General

The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.

Global Secure Access egress IP ranges

General

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

Agent Owners Sponsors Managers

General

In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.

Configure Web Content Filtering

General

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

Configure Explicit Forward Proxy

General

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

Admin Control for SSO prompts

General

IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.

Connect Version History

General

This article lists all releases of Microsoft Entra Connect and Azure AD Sync.

Licensing Guest Users

General

Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.

Configure Web Content Filtering

General

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

Ai Administrator

General

- Manage all aspects of Microsoft 365 Copilot

Ai Reader

General

- Read all aspects of Microsoft 365 Copilot

Connect Version History

General

This article lists all releases of Microsoft Entra Connect and Azure AD Sync.

Tenant Configurations

General

Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.

Ai Reader

General

This is a [privileged role](../privileged-roles-permissions.md). Assign the AI Reader role to users who need to do the following tasks:

Connect Version History

General

This article lists all releases of Microsoft Entra Connect and Azure AD Sync.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…