Backup Authentication System
Doc updateThe backup authentication system documentation no longer lists Workplace from Facebook in its integration table.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
All 11 entries were Microsoft Learn updates. The substantive changes tighten Global Secure Access connector port guidance, clarify the weakness of device-platform signals in Conditional Access, and revise Exchange role-assignment instructions; several other pages contain Workplace or Meta Workplace reference cleanup.
Global Secure Access connector guidance specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151. It adds Windows Server 2016+ prerequisites and configuration and verification commands, and clarifies that AutoReuse applies only to TCP.
The conditions guidance says device-platform information, including user-agent strings, can be modified and is not verified. It recommends combining device-platform conditions with Microsoft Intune device-compliance policies or using them in a block statement.
The groups guidance directs administrators to the Exchange admin center for role assignments through dynamic membership groups. When the old Exchange admin center is required, it says to assign the eligible role directly to the user rather than through role-assignable groups; Exchange PowerShell cmdlets continue to work as expected.
The partner-driven integrations page now lists Dropbox and Snowflake as examples and removes its reference to Workplace by Facebook. No configuration change is indicated.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The backup authentication system documentation no longer lists Workplace from Facebook in its integration table.
The provision-on-demand article no longer includes references to Meta Workplace. The displayed guidance about stopping provisioning for OAuth-based applications remains unchanged.
The employee lifecycle documentation no longer links to the Workplace by Facebook provisioning tutorial.
The documentation now warns that device platform information, such as user agent strings, can be modified and isn't verified. It recommends using device platform with Microsoft Intune device compliance policies or in a block statement.
The guidance now directs administrators to the Exchange admin center for role assignments through dynamic membership groups. If the old Exchange admin center is required, assign the eligible role directly to the user rather than through role-assignable groups; Exchange PowerShell cmdlets work as expected.
The documentation now highlights that device platform conditions rely on user agent strings and recommends pairing them with policies requiring device compliance or app protection to reduce risk.
The partner-driven integrations documentation now lists Dropbox and Snowflake as examples and no longer references Workplace by Facebook.
The Entra ID Governance apps page no longer lists Workplace from Meta in its application table.
The documentation now clarifies Basic content filtering and Scan with Purview descriptions, including that scanning can audit or block selected file and text content based on conditions.
The documentation specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151, with new configuration and verification commands. It also adds Windows Server 2016+ prerequisites and clarifies that AutoReuse applies only to TCP.
The connector configuration guidance now refers to configuring dynamic and AutoReuse TCP port ranges instead of extending TCP and UDP ephemeral ports.