Publish App Gallery
The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to General.
The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.
The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.
The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.
The curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.
The VM managed identity documentation changes the client_id value in its curl token-request example.
A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.
Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.
The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.
The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.
The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.
The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.
The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.
The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.
The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.
The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.
The documentation received a minor formatting change with no substantive content changes identified.
The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.
Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.
Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.
Removed an extra space from the Help desk admin row in the documentation table.
The page title now says “Microsoft Entra ID,” and several table separators were reformatted for consistent Markdown presentation.
A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.
The documentation now explains that Agent ID objects are covered through their underlying directory object types, including user accounts as user objects and identity blueprints as application objects.
Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.
The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.
The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.
The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.
The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.
The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.
The release-history page no longer includes version 1.1.26060207 or its listed changes, and its document date changed from August 21, 2026, to April 16, 2026.
The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.
The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.
The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.
The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.
The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.
Starting with version 1.1.26060207, the app package includes com.microsoft.autoupdate2 for future use cases.
The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.
The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.
The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.
The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.
The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.
The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.
The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.
A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.
The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.
The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.
The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.
The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.
The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.
The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.
Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.
Adds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.
The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”
The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.
We are announcing the ability to enable on-behalf-of ordering for Microsoft Entra External ID (EEID) in Dynamics 365 Commerce. This feature will reach general availability on September 11, 2026 How does this affect me?
The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.
The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.
The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.
The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.
The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.
The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.
The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.
The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.
The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.
Learn how to configure Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps side by side without proxying traffic twice.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.
In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.
Learn how to upload and host your own Proxy Auto-Configuration (PAC) files
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Use the Migration Policy Analyzer to scan Azure AD B2C custom policies and generate a detailed migration assessment for Microsoft Entra External ID. Start your migration today.
This article lists all releases of Microsoft Entra Connect and Azure AD Sync.
Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.
* [Federated MFA](/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa)
Learn to migrate from Amazon Cognito to Microsoft Entra External ID with step-by-step guidance, feature mapping, and validation strategies.
A Microsoft Entra documentation page was updated: Entra Customer Lockbox Approver.
- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
Learn how to configure universal tenant restrictions with Global Secure Access for Microsoft traffic.
Learn how to enable the Microsoft traffic profile in Global Secure Access, assign users, install the client, and verify traffic forwarding.
Learn about Microsoft traffic labs for Global Secure Access, including source IP restoration, compliant network checks, and universal tenant restrictions.
This article lists all releases of Microsoft Entra Connect and Azure AD Sync.
Learn how to retrieve data from Microsoft Entra Domain Services.
Learn about some of the virtual network design considerations and resources used for connectivity when you run Microsoft Entra Domain Services.
keywords: Azure Active Directory licensing service plans
Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.
This is a [privileged role](../privileged-roles-permissions.md). Assign the AI Reader role to users who need to do the following tasks:
Learn how to configure single sign-on between Microsoft Entra ID and AlexisHR.
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Calculate the Microsoft Sentinel alert noise ratio for Global Secure Access detections and send an alert when false positives or informational closures exceed your threshold.
Check Global Secure Access-related administrator role assignments and identify accounts that need quarterly review.
Create a non-destructive Microsoft Entra recovery preview job scoped to directory objects that affect Global Secure Access.
Run a Microsoft Entra recovery job for directory objects that affect Global Secure Access after reviewing a recovery preview.
Verify that your Global Secure Access configuration backup runbook ran successfully. Send an alert when the runbook fails or misses a scheduled run.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
This article lists all releases of Microsoft Entra Connect and Azure AD Sync.
These articles provide additional information on working with groups in Microsoft Entra ID.
High-level planning and decision guide for Independent Software Vendors (ISVs) preparing to integrate single sign-on (SSO) with Microsoft Entra ID.