← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Shared 700-definition and 1,200-entry limits added to Entra app-manifest guidance

All eight recorded changes are Microsoft Learn updates, but several add concrete administrator-facing limits and filtering guidance. The most consequential clarification documents a shared default of 700 app roles and exposed delegated permission scopes per application or service principal, alongside a 1,200-entry aggregate manifest limit. Global Secure Access guidance adds Basic-filtering warnings, changes the condition name from Source type to Session type, and describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations. FIDO2 attestation references move from MDS 275 to 279 and add the FEITIAN FT-JCOS BioCard.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

8 updates

1
1

Add app roles and get them from a token

Doc update

The page now documents a shared default limit of 700 app roles and exposed delegated permission scopes per application or service principal, including counting rules, existing objects above the limit, and design guidance.

1

Supported Accounts Validation

Doc update

The documentation now lists a default limit of 700 shared permission definitions for app roles and exposed delegated scopes, plus an aggregate manifest limit of 1,200 collection entries.

2

App Manifest

Doc update

The documentation now states that app roles and exposed delegated permission scopes share a default limit of 700 permission definitions per application or service principal. Disabled definitions count, and this limit is separate from the aggregate manifest limit.

Microsoft Graph App Manifest

Doc update

The documentation now states that app roles and exposed delegated permission scopes share a default limit of 700 definitions per application or service principal. Disabled definitions count, and this limit is separate from the aggregate manifest limit.

2

Network Content Filtering

Doc update

The documentation now describes Basic content filtering for supported file and text types using Allow or Block without Purview. It adds a warning that blocking HTML or JSON can disrupt normal web and API traffic, and updates the stated coverage from HTTP/1.1 to HTTP/S.

Network Content Filtering

Feature update

The documentation replaces the Source type condition with Session type, adds a known internet access limitations reference, and revises guidance for WebSocket filtering, API rate limiting, and Purview inspection failures.

1

Create content policies for network content filtering

Doc update

The documentation now describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations. It adds details about Basic content filtering and Purview-based inspection of files and text.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…