The Microsoft Entra FIDO2 hardware vendor documentation now references MDS version 279 instead of 275 and adds the FEITIAN FT-JCOS BioCard, including its AAGUID and feature capabilities. The page date was also updated.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Shared 700-definition and 1,200-entry limits added to Entra app-manifest guidance
All eight recorded changes are Microsoft Learn updates, but several add concrete administrator-facing limits and filtering guidance. The most consequential clarification documents a shared default of 700 app roles and exposed delegated permission scopes per application or service principal, alongside a 1,200-entry aggregate manifest limit. Global Secure Access guidance adds Basic-filtering warnings, changes the condition name from Source type to Session type, and describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations. FIDO2 attestation references move from MDS 275 to 279 and add the FEITIAN FT-JCOS BioCard.
- Shared permission-definition and manifest ceilings are now explicit
Entra ID · Microsoft identity platform
Supported Accounts Validation now lists a default limit of 700 shared permission definitions—app roles plus exposed delegated permission scopes—per application or service principal, and an aggregate manifest limit of 1,200 collection entries.
- Basic content filtering guidance warns against blocking HTML or JSON
Global Secure Access · Security
Network Content Filtering guidance describes Basic filtering for supported file and text types with Allow or Block controls without Purview. It updates coverage language from HTTP/1.1 to HTTP/S and warns that blocking HTML or JSON can disrupt GET, POST, and PUT traffic.
- Network content filtering replaces Source type with Session type
Global Secure Access · Security
The condition formerly labeled Source type is now Session type. The guidance also adds an internet-access limitations reference and revises operational guidance for WebSocket filtering, API rate limiting, and Purview inspection failures.
- Real-time policy guidance covers generative AI and unmanaged cloud content
Global Secure Access · Developer
Create content policies guidance now describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations, with added details for Basic filtering and Purview-based inspection of files and text.
- FIDO2 attestation data moves to MDS 279 and adds a BioCard entry
Entra ID · Authentication
The FIDO2 hardware-vendor guidance now references MDS version 279 instead of 275 and adds the FEITIAN FT-JCOS BioCard, including its AAGUID and feature capabilities.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
8 updates
Microsoft Entra ID
3 updatesAdd app roles and get them from a token
Doc updateThe page now documents a shared default limit of 700 app roles and exposed delegated permission scopes per application or service principal, including counting rules, existing objects above the limit, and design guidance.
Supported Accounts Validation
Doc updateThe documentation now lists a default limit of 700 shared permission definitions for app roles and exposed delegated scopes, plus an aggregate manifest limit of 1,200 collection entries.
Microsoft Entra Workload ID
2 updatesApp Manifest
Doc updateThe documentation now states that app roles and exposed delegated permission scopes share a default limit of 700 permission definitions per application or service principal. Disabled definitions count, and this limit is separate from the aggregate manifest limit.
Microsoft Graph App Manifest
Doc updateThe documentation now states that app roles and exposed delegated permission scopes share a default limit of 700 definitions per application or service principal. Disabled definitions count, and this limit is separate from the aggregate manifest limit.
Microsoft Entra Global Secure Access
3 updatesNetwork Content Filtering
Doc updateThe documentation now describes Basic content filtering for supported file and text types using Allow or Block without Purview. It adds a warning that blocking HTML or JSON can disrupt normal web and API traffic, and updates the stated coverage from HTTP/1.1 to HTTP/S.
Network Content Filtering
Feature updateThe documentation replaces the Source type condition with Session type, adds a known internet access limitations reference, and revises guidance for WebSocket filtering, API rate limiting, and Purview inspection failures.
The documentation now describes real-time controls for content shared with generative AI applications, unmanaged cloud apps, and other internet destinations. It adds details about Basic content filtering and Purview-based inspection of files and text.
