The article title no longer includes “(preview)” for custom call-outs using LCW extensibility workflows.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Flexible federated credential guidance adds managed identity setup and claims-matching details
The period is dominated by documentation maintenance, with the most substantive update expanding Flexible federated identity credential guidance for applications and user-assigned managed identities. The guidance now distinguishes Microsoft Graph setup for applications from Azure Resource Manager setup for managed identities and documents properties such as claimsMatchingExpression. Other changes refine Rootly SSO and SCIM procedures, clarify protection coverage for role-assignable groups, and update LCW article terminology.
- Flexible credential guidance covers applications and user-assigned managed identities
Workload ID · Security
The setup guidance now covers applications and user-assigned managed identities, using Microsoft Graph for applications and Azure Resource Manager for managed identities. It also adds credential-property details, including `claimsMatchingExpression`.
- Rootly SSO setup now maps Entra values to explicit fields
Entra ID · General
The Rootly tutorial now lists fields for the Entra identifier, login and logout URLs, PEM certificate, and domain, followed by instructions to enable and save required SSO. The previous instruction to send these details to Rootly support was removed.
- Rootly SCIM provisioning switches to the rootly.com Tenant URL
Entra ID · Provisioning
The documented Tenant URL changed from `https://docs.rootly.com/integrations/scim` to `https://rootly.com/scim`.
- PIM for Groups wording expands credential-protection coverage
ID Governance · Fundamentals
The guidance now states that credential protection covers role-assignable group members and owners, including eligible members and owners who have not activated their assignments.
- LCW custom-call-out guidance drops “(preview)” from its title
Entra ID · Provisioning
The article title for extending Entra attribute mappings with custom call-outs using LCW extensibility workflows no longer includes “(preview)”.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
9 updates
Microsoft Entra ID
5 updatesRootly Provisioning Tutorial
Doc updateThe documented Tenant URL changed from `https://docs.rootly.com/integrations/scim` to `https://rootly.com/scim`.
Rootly Provisioning Tutorial
Doc updateThe tutorial now specifies `https://rootly.com/scim` as the Tenant URL instead of `https://docs.rootly.com/integrations/scim`.
Rootly Tutorial
Doc updateThe guide now provides explicit Rootly fields for the Entra identifier, login and logout URLs, PEM certificate, and domain, followed by enabling and saving the SSO configuration.
Rootly Tutorial
Doc updateThe tutorial now lists the Rootly fields to populate with the copied URLs and PEM certificate, then instructs administrators to enable and save required SSO. The previous instruction to send these details to Rootly support was removed.
Microsoft Entra ID Governance
2 updatesPim For Groups
Doc updateThe documentation now states that credential protection covers group members and owners, including eligible members and owners who have not yet activated.
Pim For Groups
Doc updateThe role-assignable groups description now includes members and owners, including eligible members and owners who have not activated their assignments.
Microsoft Entra Workload ID
2 updatesThe documentation now explains setup for applications and user-assigned managed identities, using Microsoft Graph for applications and Azure Resource Manager for managed identities. It also adds details about credential properties, including claimsMatchingExpression.
Flexible federated identity credentials (preview)
Feature updateThe guidance now covers applications and user-assigned managed identities, including Azure Resource Manager setup instructions and updated GitLab claim-matching requirements.
