Sspr Policy
Doc updateThe SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
The period’s substantive updates clarify two Global Secure Access capabilities. Universal Continuous Evaluation guidance now covers preview signals for deleted, disabled, or noncompliant devices, while Web Filtering (v2) guidance describes a preview Continue Evaluation action that passes unmatched traffic between profiles. Additional edits establish the Web Filtering (v2) prerequisite for custom HTTP headers, remove “preview” labels from two filtering conditions, and standardize SSPR terminology.
The Universal Continuous Evaluation guidance now covers preview signals for deleted, disabled, and noncompliant devices. Reauthentication uses a GSA client notification, and the tunnel disconnects after two minutes if reauthentication is incomplete. Device Compliance and User Risk signals should be paired with their corresponding Conditional Access policies.
The guidance now describes a preview Continue Evaluation default action: unmatched traffic passes to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.
The custom HTTP headers guidance now states that the capability is available only with Web Filtering (v2) policies and links to the related guidance. Administrators configuring headers must account for that policy prerequisite.
The web content filtering guidance removes “preview” from the source traffic type and HTTP method request filtering conditions, and updates their headings and links. Administrators with internal references to the former labels should update them.
The SSPR policy page now uses “Microsoft Entra administrators” instead of “Azure administrators.” No administrator action is required.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
The documentation removes “preview” from the source traffic type and HTTP method request filtering conditions, updates their headings and links, and refreshes the page date.
The documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.
The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.
The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.