The Microsoft Entra FIDO2 hardware vendor documentation now references MDS version 279 instead of 275 and adds the FEITIAN FT-JCOS BioCard, including its AAGUID and feature capabilities. The page date was also updated.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Defender App Governance permissions change for three Entra roles in mid-October
Microsoft’s main operational notice is a mid-October 2026 Defender for Cloud Apps App Governance permission update for three Microsoft Entra roles. The other substantive entries are documentation updates: Global Secure Access now spells out Basic filtering risks and policy coverage, identity guidance records 700- and 1,200-entry manifest limits, and FIDO2 attestation references MDS version 279 plus a new FEITIAN model.
- App Governance RBAC permissions change for three Entra roles
Entra ID · Governance
Defender for Cloud Apps is updating App Governance permissions to align with Defender XDR Unified RBAC. The change affects the Cloud App Security, Compliance Administrator, and Compliance Data Administrator roles starting in mid-October 2026.
- Basic content filtering warns against blocking HTML or JSON
Global Secure Access · Security
Global Secure Access guidance now describes Basic content filtering for supported file and text types using Allow or Block without Purview. It warns that blocking HTML or JSON may disrupt normal web and API traffic and updates the stated coverage from HTTP/1.1 to HTTP/S.
- Validation guidance lists 700 permission definitions and 1,200 manifest entries
Entra ID · Microsoft identity platform
The updated Supported Accounts Validation page lists a default limit of 700 shared permission definitions for app roles and exposed delegated scopes, plus an aggregate manifest limit of 1,200 collection entries.
- Policy guidance details real-time controls for AI and unmanaged apps
Global Secure Access · Developer
The create-content-policies guidance now describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations. It adds details on Basic content filtering and Purview-based inspection of files and text.
- FIDO2 attestation data adds the FEITIAN FT-JCOS BioCard
Entra ID · Authentication
The FIDO2 hardware vendor reference now uses MDS version 279 instead of 275 and adds the FEITIAN FT-JCOS BioCard, including its AAGUID and feature capabilities. Administrators checking attestation support have updated reference data; no action is required.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
9 updates
Microsoft Entra ID
4 updatesAdd app roles and get them from a token
Doc updateThe page now documents a shared default limit of 700 app roles and exposed delegated permission scopes per application or service principal, including counting rules, existing objects above the limit, and design guidance.
Microsoft Defender for Cloud Apps is updating App Governance permissions for select Microsoft Entra roles to align with Defender XDR Unified RBAC. Changes affect Cloud App Security, Compliance Administrator, and Compliance Data Administrator roles starting mid-October 2026. Admins should review and adjust role assignments accordingly.
Supported Accounts Validation
Doc updateThe documentation now lists a default limit of 700 shared permission definitions for app roles and exposed delegated scopes, plus an aggregate manifest limit of 1,200 collection entries.
Microsoft Entra Workload ID
2 updatesApp Manifest
Doc updateThe documentation now states that app roles and exposed delegated permission scopes share a default limit of 700 permission definitions per application or service principal. Disabled definitions count, and this limit is separate from the aggregate manifest limit.
Microsoft Graph App Manifest
Doc updateThe documentation now states that app roles and exposed delegated permission scopes share a default limit of 700 definitions per application or service principal. Disabled definitions count, and this limit is separate from the aggregate manifest limit.
Microsoft Entra Global Secure Access
3 updatesNetwork Content Filtering
Doc updateThe documentation now describes Basic content filtering for supported file and text types using Allow or Block without Purview. It adds a warning that blocking HTML or JSON can disrupt normal web and API traffic, and updates the stated coverage from HTTP/1.1 to HTTP/S.
Network Content Filtering
Feature updateThe documentation replaces the Source type condition with Session type, adds a known internet access limitations reference, and revises guidance for WebSocket filtering, API rate limiting, and Purview inspection failures.
The documentation now describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations. It adds details about Basic content filtering and Purview-based inspection of files and text.
