Validate Oidc Multitenant App Gallery
Doc updateThe article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Microsoft Entra’s most user-visible update is a worldwide mid-September 2026 improvement to restoring Authenticator passkeys on iOS: users with iCloud backup get a clearer, guided device-migration flow, with no policy change or administrator action required. Global Secure Access also adds a new preview guide for Microsoft-managed certificates in Microsoft Entra Internet Access TLS inspection, alongside clarified bring-your-own-certificate instructions. The remaining updates are primarily documentation maintenance, troubleshooting guidance, and link or download-target changes.
The Microsoft Authenticator passkey restore experience will launch worldwide in mid-September 2026 with a clearer, guided device-migration flow for iOS users with iCloud backup. No user action, administrator action, or policy change is specified.
The new guide covers creating a tenant-specific Microsoft-managed root CA, deploying its public certificate to client devices, and enabling it for Microsoft Entra Internet Access TLS inspection. The private key remains protected by Microsoft, and the capability is in preview.
The updated guide focuses on using an administrator-provided certificate authority, including CSR creation, PKI signing, and certificate upload, and links to the separate Microsoft-managed certificate guidance.
After confirming that an application works through a single connector, the guide now recommends enabling session persistence so the same user and device remain routed through that connector during the session.
The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.
The SAML App Gallery validation article adds lightbox support to screenshots and a Next step link to the validation-results section.
The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”
Microsoft Entra improves the iOS Microsoft Authenticator app's passkey restore experience with a clearer, guided flow for device migration, launching worldwide mid-September 2026. It affects iOS users with iCloud backup, requires no action, and includes updated user guidance without policy changes.
The user provisioning validation guide now uses an updated Microsoft Entra admin center URL with additional parameters.
The hybrid join troubleshooting page was updated with revised guidance for AADSTS50034, and its date changed from July 27, 2025, to September 1, 2026.
The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.
The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.
The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.
The AI prompt injection protection documentation now explains that TLS inspection can use either a Microsoft-managed certificate or an administrator-provided certificate before configuring TLS inspection policies.
The page title now marks custom headers as preview and notes that rollout is expected to complete by September 10, 2026.
Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.
The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.
The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.
The documentation now provides separate links for configuring TLS inspection with a Microsoft-managed certificate and with your own certificate.