Week in brief

Entra will block new Partner Tier1/Tier2 Support assignments on 3 August; Global Secure Access guidance expands

The period’s clearest administrator-impacting change is a Microsoft Entra retirement notice: new assignments to the Partner Tier1 and Tier2 Support roles will be blocked starting 3 August 2026, while existing assignments remain valid. The Learn entries are otherwise predominantly procedural or reference maintenance, with a connected set of Global Secure Access tutorials, substantive ID Protection risk-signal documentation, and OIDC security guidance as the main exceptions. The supplied evidence does not identify a general-availability release for those new pages; HTTP method request filtering is explicitly marked preview. The removed Entra Customer Lockbox Approver item is identified only as a page removal, not as evidence of a corresponding capability retirement.

  • Microsoft Entra’s Message Center notice says the Partner Tier1 and Partner Tier2 Support roles are being retired. Starting 3 August 2026, new assignments will be blocked, but existing assignments remain valid. The notice specifically calls for updating scripts and using alternatives such as User Administrator; tenants that do not use these roles are unaffected. This is the period’s concrete retirement and behavior change.

  • New tutorials cover enabling the Microsoft traffic profile, assigning users, installing the client, and verifying traffic forwarding; enabling source IP restoration and checking Microsoft Entra sign-in logs; requiring a compliant network through Conditional Access; and configuring universal tenant restrictions. A separate Microsoft traffic labs tutorial groups source IP restoration, compliant network checks, and tenant restrictions. These are procedural Learn additions, not an announced GA release or product launch

  • An updated Global Secure Access web-content-filtering page explicitly lists HTTP method request filtering as preview, with GET, POST, PUT, PATCH, and DELETE as examples of methods that can be blocked or allowed. Related content-policy documentation describes real-time protection for file and text content. No GA date or broader availability statement is supplied.

  • New and updated ID Protection pages describe unified risk signals: correlated identity-risk signals from Entra ID Protection, Microsoft Defender, and other Microsoft security products are evaluated within the same time window to calculate a compounded user-risk score. The Risky User Report update documents an `Aggregate risk signals by risky sign-ins` option, and the dashboard documentation carries the same model. The record does not label this as preview or GA.

  • A new OIDC extensibility reference maps each Microsoft identity platform OIDC extensibility surface to the relevant configuration article and Microsoft Graph resource. Related Entra ID updates say the implicit-flow ID-token manifest flag defaults to false, discourage implicit grant even for JavaScript SPAs, and recommend authorization code flow with PKCE; OIDC setup guidance also reiterates adding a redirect URI. This is security and developer guidance, not an announced protocol-enforcement change.

For Entra administrators

If these partner roles are used, update scripts that make future assignments and select alternatives such as User Administrator before 3 August. Existing assignments remain valid, and tenants that do not use the roles are unaffected. Use the new Global Secure Access pages as configuration and validation procedures, but do not treat their new-document status as proof of a launch or GA availability; treat HTTP method filtering as preview. Analysts using ID Protection reports should account for the documented correlation of signals and the risky-user report aggregation option, without assuming a new policy requirement. Application owners should review SPA registrations that rely on implicit grant against the documented authorization-code-with-PKCE guidance; the evidence does not say that En.{

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

5

App Manifest

Updated

Specifies whether this web app can request OAuth2.0 implicit flow ID tokens. The default is false. This flag is used for browser-based apps, like JavaScript single-page apps. We, however, discourage the use of implicit grant even in SPAs and recommend using the [authorization code flow](./v2-oauth2-auth-code-flow.md) with PKCE.

4 July 2026

Enable Scim Api

Updated

- **Cost:** See [API call pricing](https://aka.ms/EntraSCIMAPIPricing).

1 July 2026

Entra Id Scim Api Reference

Updated

Before you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).

1 July 2026
4
4
2

V2 Protocols Oidc

Updated

1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.

4 July 2026
2
2

Troubleshooting

Updated

- The object or property isn't supported for preview in the current release.

1 July 2026
1

OAuth 2.0 and OpenID Connect protocols

Updated

Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.

1 July 2026
1
1
1

Risky User Report

Updated

To see risk sign-in events together with risky user events, select the **Aggregate risk signals by risky sign-ins** checkbox.

1 July 2026
1
1

Id Protection Dashboard

Updated

Microsoft Entra ID Protection provides unified risk signals that aggregate correlated risk signals from Microsoft Entra ID Protection, Microsoft Defender, and other Microsoft security products. Instead of evaluating alerts in isolation, this capability correlates identity-related signals across products and evaluates them together within the same time window to calculate a compounded user risk score.

1 July 2026
1

Governance Policy Templates

Updated

Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra

2 July 2026
1
5

Configure Web Content Filtering

Updated

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

1 July 2026
1
1
1
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…