The article explains how to inspect failed Azure Logic Apps validation runs, identify root causes, and resolve common SCIM endpoint, authentication, permissions, filtering, and conflict errors.
System-preferred authentication rolls out to first-factor sign-ins for managed Entra tenants
The clearest service change is an ongoing rollout that makes system-preferred authentication select the most secure registered method for first-factor sign-ins in tenants in Microsoft's managed state, running through late September 2026. Major documentation work covers Cloud Sync provisioning to AD DS, while Linux broker 2.0.2 and Global Secure Access connector guidance carry direct operational implications. Many remaining edits are routine sample-ID, author, link, and formatting maintenance; App Gallery guidance also documents a 25-test Logic Apps workflow for SCIM validation.
- System-preferred authentication now covers first-factor sign-ins
Entra ID · Authentication
For tenants in the Microsoft-managed state, Microsoft Entra applies system-preferred authentication to first-factor sign-ins and selects the most secure registered method. Rollout runs from late June through late September 2026; tenants can retain or change the setting and should update user guidance.
- Cloud Sync guidance covers Entra-to-AD provisioning
Entra ID · Fundamentals
New overview content explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. Group provisioning is identified as generally available, while user provisioning is in preview.
- Linux broker 2.0.2 switches device trust to Microsoft Entra join
Entra ID · General
Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of device registration for device trust. Existing upgraded devices must be re-joined and re-enrolled; deployment procedures should allow device joins, remove broker state, reinstall the broker, and re-join devices.
- Global Secure Access marks four connector versions deprecated
Global Secure Access · General
The version history marks 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and tells administrators running version 1.5.612.0 or earlier to update immediately.
- My Account identity self-service moves to cloud.microsoft
Entra ID · General
Microsoft Entra is moving self-service identity management from myaccount.microsoft.com to myaccount.cloud.microsoft worldwide in late November 2026 as related sites are consolidated. Users need no action, but network policies should allow *.cloud.microsoft.
Review sign-in guidance and the system-preferred authentication setting during the rollout. For Cloud Sync, distinguish generally available group provisioning from preview user provisioning and plan against the documented constraints. Linux broker 2.0.2 deployments need device-join permission plus rejoin and re-enrollment procedures. Global Secure Access administrators should update deprecated connector versions, and network teams should allow *.cloud.microsoft before the late-November self-service domain transition if those domains are filtered.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
91 updatesA new guide explains how ISVs create an Entra Gallery Provisioning Test App, deploy the Azure Logic Apps validation template, configure permissions and parameters, and run SCIM provisioning tests.
A new article explains how to validate SCIM user and group provisioning with an Azure Logic Apps template, run 25 tests, and submit the results with a Logic App run ID for App Gallery review. It covers both AI-agent and Azure portal setup methods.
The page author changed from hsaini to himanshusainig.
The document’s author metadata changed from hsaini to himanshusainig.
The page author changed from `hsaini` to `himanshusainig`.
The documentation replaces its embedded onboarding checklist with links to current requirements and validation instructions. App publishers validate their SCIM integration and submit the results with their gallery application; customers obtain OAuth configuration values from the app’s admin experience.
Scim Validator Tutorial
Doc updateAction requiredThe tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.
Use Scim To Provision Users And Groups
Doc updateThe SCIM provisioning documentation now links to guidance for the OAuth 2.0 client credentials grant.
Entra Id Scim Api Reference
Feature updateThe SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.
Breaking Changes
Doc updateThe breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
Breaking Changes
Doc updateThe breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.
The new page lists SCIM API, authentication, testing, support, documentation, customer deployment, and cloud compliance requirements for publishing user provisioning integrations in Microsoft Entra App Gallery.
A tutorial now explains how to use the Microsoft Entra App Validator browser extension with non-gallery enterprise applications, including IdP- and SP-initiated SSO, certificate scenarios, optional Single Logout, and result submission.
Validate an OIDC multitenant app for Microsoft Entra App Gallery onboarding
Doc updateAction requiredThe documentation explains how to use the Microsoft Entra App Validator browser extension to test an OIDC multitenant app, review fixes, and generate the Test ID required for gallery publishing.
Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.
The guide title now uses quoted punctuation, and the table separator spacing was standardized.
Groups Settings V2 Cmdlets
Doc updateThe documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.
The page title changed from “What is single sign-on (SSO) in Microsoft Entra ID?” to “What is single sign-on in Microsoft Entra ID?”
Breaking Changes
Doc updateThe example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
What If Tool
Doc updateThe Conditional Access What If tool table now uses a different sample UserId in all four examples.
Manage App Consent Policies
Doc updateThe consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
Manage App Consent Policies
Doc updateThe consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
Grant Admin Consent
Doc updateThe documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.
Grant Admin Consent
Doc updateThe guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.
What If Tool
Doc updateThe Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.
Manage App Consent Policies
Doc updateThe documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.
Grant Admin Consent
Doc updateThe grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.
The documentation explains how to access the Microsoft Application Network portal and submit requests to update SSO, MDM, or user provisioning details, upgrade SSO, or remove an application listing.
The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.
The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.
Howto Update Permissions
Doc updateThe permission-addition and permission-removal examples now use different sample object and client IDs.
Howto Update Permissions
Doc updateThe add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
Howto Update Permissions
Doc updateThe examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.
Howto Update Permissions
Doc updateThe Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.
Howto Update Permissions
Doc updateThe permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.
Publish App Gallery
Doc updateThe documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.
Preserve a group's organizational unit (Preview)
New featureAction requiredA new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.
Group Source Of Authority Configure
Doc updateThe page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.
Sap Netweaver Tutorial
Doc updateTwo SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.
Sap Netweaver Tutorial
Doc updateThe tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.
Manage App Consent Policies
Doc updateThe examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.
Exchange Hybrid
Doc updateThe article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.
Assign App Owners
Doc updateThe PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.
A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.
The page title now says “Microsoft Entra ID,” and several table separators were reformatted for consistent Markdown presentation.
The documentation now explains that Agent ID objects are covered through their underlying directory object types, including user accounts as user objects and identity blueprints as application objects.
Plan Sso Deployment
Doc updateRemoved an extra space from the Help desk admin row in the documentation table.
Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.
Whats New Linux
Feature updateAction requiredStarting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.
Connect Health Version History
Doc updateThe version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.
Connect Health Agent Install
Doc updateThe installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.
App Gallery User Provisioning Requirements
Doc updateAction requiredThe App Gallery provisioning requirements now instruct integrators to validate SCIM endpoints against the Microsoft Entra provisioning service and submit the results with their gallery submission.
The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.
Plan Cloud Sync Topologies
Doc updateThe documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.
A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.
Microsoft Entra provisioning setup (Preview)
New featureThe article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.
Test Microsoft Entra provisioning (Preview)
New featureA new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.
Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.
The article now explains using directory extensions to filter groups for provisioning and to map attribute values to Active Directory users. It adds separate Groups and Users examples, prerequisites, and related guidance.
The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.
The article now covers directory extensions for users and groups when provisioning from Microsoft Entra ID to Active Directory, with updated examples, prerequisite wording, links, and related content.
The documentation removed the Repair-AADCloudSyncToolsAccount section because the cmdlet is obsolete.
On Demand Provision
Doc updateThe article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.
Tutorial Group Provisioning
Doc updateThe tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.
The documented ServicePrincipalId example was replaced with a generic UUID.
Assignment Network
Doc updateThe Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
Assignment Network
Doc updateThe updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.
Assignment Network
Doc updateA link was fixed on the Conditional Access network assignment page.
Assignment Network
Doc updateThe Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.
The documented query now filters for UserId `00aa00aa-bb11-cc22-dd33-44ee44ee44ee` instead of the previous identifier.
Strengthen federated sign-in security
Doc updateThe documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.
Howto Arc Sign In Windows
Doc updateThe documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.
Howto Arc Sign In Windows
Doc updateThe how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.
Howto Arc Sign In Windows
Doc updateThe guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.
Howto Arc Sign In Windows
Doc updateThe documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.
Howto Arc Sign In Windows
Doc updateThe documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.
Microsoft Entra now applies system-preferred authentication to first-factor sign-ins for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout is from late June to late September 2026. Tenants can keep or change this setting and should update user guidance accordingly.
The AzureActiveDirectoryInvalidCredential and AzureActiveDirectoryExpiredCredentials entries no longer reference the cloud service-account repair cmdlet.
The troubleshooting article no longer documents the Repair-AADCloudSyncToolsAccount cmdlet or its usage steps.
The Linux device registration troubleshooting documentation now shows a different tenant ID in its example output.
The example Tenant ID was changed from 12345678-90ab-cdef-1234-567890abcdef to aaaabbbb-0000-cccc-1111-dddd2222eeee.
Manage Device Identities
Feature updateThe documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.
A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.
Provision Microsoft Entra ID objects to AD
New featureA new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.
Group Source Of Authority Guidance
Doc updateThe guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.
Primary Refresh Token
Doc updateThe documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.
Protect M365 From On Premises Attacks
Doc updateThe guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.
Clean broker state including certificates (requires sudo)
Feature updateAction requiredMicrosoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.
The recovery model documentation now lists agent user accounts, agent identity blueprints, agent identities, and agent identity blueprint principals among covered objects.
SAM Account Name
Public previewEnhanced synchronization can source sAMAccountName for hybrid users from onPremisesSamAccountName in Microsoft Entra ID. Existing domains retain current behavior until enabled; enabling updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation.
Microsoft Entra Agent ID
1 updateAgent Token Claims
Doc updateThe documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.
Microsoft Entra ID Governance
14 updatesCreate Tenant
Doc updateThe article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.
Create Tenant
Feature updateAction requiredThe documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.
Understanding Lifecycle Workflows
Public previewThe documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.
Create Lifecycle Workflow
Public previewAdministrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.
Lifecycle Workflow Execution Conditions
Public previewDocumentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.
Entitlement Management Request Behalf
Doc updateThe documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.
Lifecycle Workflow Execution Conditions
Feature updateThe allowed offset for Days from event, and Days to event when using Between, increased from 180 to 365 days.
Lifecycle Workflow Execution Conditions
Doc updateThe Event user attribute description in the lifecycle workflow execution conditions documentation was reformatted.
Create Lifecycle Workflow
Doc updateThe page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.
Source Of Authority Overview
Doc updateThe documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.
Understanding Lifecycle Workflows
Public previewThe documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.
The documentation now consistently uses a different application client ID in the endpoint URI, calling application claim, and `resourceId` examples.
The documentation now uses revised Application (client) ID examples in the endpoint URI and `resourceId` configuration sample.
Road To The Cloud Implement
Doc updateThe guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.
Microsoft Entra External ID
2 updatesMigrate Passwords Just In Time
Doc updateThe password migration documentation now uses a different example API application identifier.
Create Service Principal Cross Tenant
Doc updateThe cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.
Microsoft Entra Workload ID
6 updatesThe PowerShell example now uses a different Subject value for the managed identity federated credential.
The documentation changes the example `-Subject` value in the `New-AzADAppFederatedCredential` command.
How Managed Identities Work Vm
Doc updateThe curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.
How Managed Identities Work Vm
Doc updateThe VM managed identity documentation changes the client_id value in its curl token-request example.
The documentation updates the name or identifier of the dedicated first-party service principal used to synchronize Active Directory with Microsoft Entra ID.
The documentation wording about the dedicated first-party application and service principal used for synchronization between Active Directory and Microsoft Entra ID was revised.
Microsoft Entra Global Secure Access
10 updatesVersion History
Doc updateAction requiredThe version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.
Version History
RetirementAction requiredThe version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.
Global Secure Access Client Release Notes
New featureStarting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.
Current Known Limitations
Doc updateThe documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.
Current Known Limitations
Doc updateThe documentation received a minor formatting change with no substantive content changes identified.
Current Known Limitations
Doc updateThe documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.
The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.
The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.
Macos Client Release History
Doc updateThe release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.
Netskope Integration
Doc updateThe Netskope integration example now uses different values for the tenantId and userId fields.
