← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Purview DLP targets network-level file filtering for Entra Internet Access

Purview DLP is being integrated with Entra Global Secure Access Internet Access to filter sensitive files at the network layer and prevent leaks to unmanaged cloud apps; the announcement lists public preview from mid-November 2025 and general availability by October 2026. Entra is also retiring legacy app-launcher and My Staff feature settings, while External ID consolidates identity-provider setup into a central user-flow procedure. Most remaining changes are documentation consolidation, Copilot naming cleanup, and more explicit integration guidance.

  • The Message Center announcement describes filtering sensitive files at the network layer to prevent data leaks to unmanaged cloud apps. It lists public preview from mid-November 2025 and general availability by October 2026; deployment requires policies, TLS inspection, and Purview pay-as-you-go activation.

  • The documentation now states that legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center. Administrators should use application assignments and My Apps collections to control visibility.

  • My Staff access is now determined by administrative role assignments and their administrative-unit scope. The legacy controls under Manage user feature settings no longer affect behavior and are being removed.

  • A new central article documents how to add configured OIDC, SAML/WS-Fed, or social identity providers to an External ID user flow, including prerequisites, permissions, portal steps, and testing.

  • The integration guide now spells out required Microsoft Entra and SAP permissions, SAP IAS OIDC and JWT Trust-by-Issuer configuration, and the token flow and revocation process. Administrators should review these requirements before configuring the integration.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

32 updates

4

Use My Staff to delegate user management

Retirement

My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.

Licensing Service Plan Reference

Doc update

Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.

Licensing Service Plan Reference

Doc update

Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.

My Staff Configure

Doc update

The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.

3

Validate User Provisioning App Gallery

Doc update

The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.

Validate Saml Single Sign On App Gallery

Doc update

The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.

Validate Saml Single Sign On App Gallery

Doc update

The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.

2

Authentication Qr Code

Doc update

The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.

Fido2 Compatibility

Doc update

The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.

2

End-user experiences for applications

Retirement

The documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.

Publish App Gallery

Doc update

The app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.

1

Tenant Estate Primary

Doc update

The tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

1
1
1

Permissions Reference

Doc update

The AI Administrator and AI Reader descriptions were updated from “Microsoft 365 Copilot” to “Microsoft Copilot.” Their role IDs remain unchanged.

1

Entitlement Management Access Package Request Policy

Doc update

The documentation now specifies that existing guest users can be directly assigned, but external users who are not yet in the directory cannot be invited through direct assignment when access is limited to administrator direct assignments.

6

Apple Federation Customers

Doc update

The article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.

Add an identity provider to a user flow

Doc update

A single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.

Entra Id Federation Customers

Doc update

The article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.

Custom Oidc Federation Customers

Doc update

The article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.

Facebook Federation Customers

Doc update

The article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.

Google Federation Customers

Doc update

The article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.

3

Microsoft Accounts Federation Customers

Doc update

The article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.

Direct Federation

Doc update

The External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.

Saml Ws Federation Self Service Sign Up

Doc update

The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.

2

Manage User Profile Info

Doc update

The user profile information documentation no longer includes guidance that users can use My Apps preview features or that administrators can access My Staff.

Manage User Profile Info

Doc update

The user profile information guidance no longer includes the “Manage user feature settings” reference.

1

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

New

Microsoft Purview DLP integrates with Entra Global Secure Access Internet Access to filter sensitive files at the network layer, preventing data leaks to unmanaged cloud apps. Public preview starts mid-November 2025; general availability by October 2026. Admins must configure policies, TLS inspection, and activate Purview pay-as-you-go.

Message CenterMC1181769 on mc.merill.net ↗Stay informed
1
1

Generative Ai Insights

Doc update

The documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

1

How to configure custom headers (preview)

Doc update

The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.

1

Secure Generative Ai

Doc update

The guidance now labels the link “Microsoft Copilot requirements” instead of “Microsoft 365 Copilot requirements.”

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…