← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

GitHub federation guidance details immutable subject claims for repository changes

Most of the day's 11 updates are documentation maintenance, but several add concrete guidance for federation, Kerberos access, governance, and certificate operations. The GitHub note records a July 15, 2026 subject-claim transition; Kerberos pages clarify both the Cloud Sync authentication path and the need for matching Active Directory accounts. PIM guidance makes a 365-day eligibility value explicit, and SAML certificate instructions add a notification-email verification step. The remaining edits mainly adjust wording, links, references, or documented roles.

  • The Workload ID page now says that, starting July 15, 2026, GitHub automatically uses immutable subject claims for newly created, renamed, or transferred repositories. Existing repositories retain name-based claims unless opted in.

  • The Workload ID Kerberos page now explains that Microsoft Entra ID users and groups provisioned to Active Directory through Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also states that provisioning alone does not enable Kerberos or passwordless access.

  • The Entra ID Kerberos guidance now states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID with required group memberships so domain controllers can authorize access.

  • The Privileged Identity Management guidance explains that `duration: P365D` makes an eligible assignment expire after 365 days. Permanent eligibility requires the target scope's role management policy to allow it.

  • The federated SSO instructions now tell administrators to verify notification email addresses configured through Microsoft Graph or PowerShell in the Microsoft Entra admin center. Opening the SAML certificate experience can initialize notification registration for custom signing certificates; without the correct address, expiration emails might not be sent.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

11 updates

3

Tutorial Manage Certificates For Federated Single Sign On

Doc updateAction required

The instructions now say to verify notification email addresses configured through Microsoft Graph or PowerShell in the Microsoft Entra admin center. Opening the SAML certificate experience can initialize notification registration for custom signing certificates.

Scopes Oidc

Doc update

The documentation now uses clearer wording to describe fine-grained permissions, scopes, and how apps request them through the `scope` parameter.

2

Introduction to Microsoft Entra Kerberos

New feature

The page now describes how Windows Hello for Business cloud Kerberos trust uses Microsoft Entra Kerberos to provide passwordless access to Active Directory resources and links to a deployment guide.

Kerberos

Doc updateAction required

The documentation now states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID, including required group memberships.

1

Provision On Demand

Doc update

The sign-in step now lists Application Owners alongside Application Administrators as acceptable roles for accessing the Microsoft Entra admin center.

1
2

Managed Identities Status

Doc update

The managed identities status table now links to permissions and identity guidance for Chaos Studio Workspaces, while retaining a separate link for Azure Chaos Studio (classic).

1

Kerberos

Doc update

The page now explains how Microsoft Entra ID users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also clarifies that provisioning alone does not enable Kerberos or passwordless access.

1

Workload Identities Flexible Federated Identity Credentials

Doc update

The page now notes that, starting July 15, 2026, GitHub will automatically use immutable subject claims for newly created, renamed, or transferred repositories. Existing repositories will retain name-based claims unless opted in.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…