← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. About this project →

Day in brief

Global Secure Access V2 web filtering guidance defines policies, rules, and V1 coexistence

The main substantive addition is a Microsoft Entra Internet Access concept article describing the V2 web-filtering model: one policy per security profile, rule-level actions, a default action, URL-based FQDN destinations, and coexistence with V1 until migration. Other updates clarify granular AMR configuration, Staged Rollout sign-in troubleshooting, and MCP setup links. An ID Protection edit only retitles a workaround and changes no procedure.

  • A new concept article explains V2 policies, destination matching, and coexistence with V1 web content filtering. It specifies one policy per security profile, multiple rules with individual actions, a default action, and FQDN destinations configured as URLs. The supplied evidence describes a documentation addition, not a release or availability milestone.

  • The updated article explains that SAML applications must configure include_granular_amr through the application manifest or Microsoft Graph because the admin center has no corresponding UI option. It also documents adding the amr claim to OIDC token types and clarifies that include_granular_amr applies only to SAML, while preserving existing optional-claim settings remains important.

  • General transition text was replaced with scenarios covering extra federated or Microsoft Entra sign-ins when users are added to or removed from Staged Rollout. The update also covers Microsoft Entra ID Protection remediation events, including SSPR and risk remediation, giving administrators more specific troubleshooting context rather than announcing a new rollout feature.

  • The Microsoft MCP Server for Enterprise overview and setup links now point to the EnterpriseMCP GitHub repository. The article still describes the service as preview, global-service-only, and read-only, so this is a reference-location update rather than a change to service availability or capability.

  • The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” The supplied diff contains no procedural change, so administrators should not infer a new remediation step.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

5 updates

1

Microsoft Entra Connect: Cloud authentication via Staged Rollout

Updated

The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.

1

Optional Claims

Updated

The documentation now explains how to configure granular AMR values for SAML applications through the manifest or Microsoft Graph, since the admin center has no UI option for `include_granular_amr`. It also documents adding the `amr` claim to OIDC token types and clarifies that `include_granular_amr` applies only to SAML.

1

Howto Analyze Provisioning Logs

Updated

The article’s Microsoft MCP Server for Enterprise overview and setup links changed from Microsoft Learn paths to the EnterpriseMCP GitHub repository. The article continues to describe the service as preview, global-service-only, and read-only.

1

Connect Staged Rollout

Updated

The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” No procedural content changed in the supplied diff.

1

Web filtering in Global Secure Access (V2)

New

A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…