← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Chatwork SCIM provisioning ends October 1, 2026 as Entra sharpens agent-access guidance

Administrators using the Chatwork Enterprise App Gallery integration face a stated October 1, 2026 cutoff: SCIM provisioning will stop, and the integration will no longer provision users. The period also substantially expands Agent ID Conditional Access guidance around token subjects, agent-user targeting, prerequisites, and report-only rollout. Global Secure Access guidance records a Secure DNS limitation, while most remaining edits cover wording, links, terminology, or role documentation.

  • The Chatwork Provisioning Tutorial now states that SCIM provisioning support will end on October 1, 2026. After that date, the Microsoft Entra Enterprise App Gallery integration will stop provisioning users. The page also standardizes the product name to “Chatwork.”

  • The guidance distinguishes agents acting for signed-in users, agents using their own identity, and agents using an agent user account. It adds separate guidance links for autonomous agents and agent users and updates the listed licensing combinations, giving administrators a basis for selecting the relevant policy guidance.

  • The updated autonomous-agent guidance presents Conditional Access as a scenario-based pattern, adds prerequisites, and recommends starting block policies in report-only mode. It also states that an Agent 365 license will soon be required.

  • New guidance for securing agent users states that all-user and group targeting do not include agent users. It documents prerequisites, risk controls, device and network conditions, and blocking risky agent user accounts, so administrators should use the dedicated agent-user pattern rather than assume broad targeting covers these accounts.

  • The known-limitations guidance now states that the Global Secure Access client does not support Secure DNS variants including DoH, DoT, and DNSSEC. It also says the macOS client bypasses Secure DNS to enforce FQDN-based tunneling.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

1
1
1

Adsync Service Account

Doc update

The table now explicitly labels Group Managed Service Account (gMSA) and Standalone Managed Service Account (sMSA), with corresponding installation guidance.

1

Chatwork Provisioning Tutorial

Retirement

The documentation standardizes the product name to “Chatwork” and states that SCIM provisioning support will end on October 1, 2026. The Entra Enterprise App Gallery integration will then stop provisioning users.

3

Secure autonomous agents with Conditional Access

Doc update

The article now presents Conditional Access for autonomous agents as a scenario-based pattern, adds prerequisites, and recommends starting block policies in report-only mode. It also notes that an Agent 365 license will soon be required.

Conditional Access for Agents in Microsoft Entra

Feature update

The documentation now distinguishes agents acting for signed-in users, using their own identity, or using an agent user account. It adds separate guidance links for autonomous agents and agent users and updates the listed licensing combinations.

Target agents in Microsoft Entra Conditional Access policies

Doc update

The article now uses a scenario-based structure, explains that conditions and controls depend on the token subject, and links separately to guidance for agent identities and agent user accounts. Terminology, metadata, and related links were also updated.

1

Agent Users

Feature update

The documentation now states that agent user accounts can be assigned custom roles, while privileged administrator roles remain restricted.

1

Authorization Agent Id

Doc update

The authorization documentation now states that custom roles can be assigned to agents.

1

Known limitations for Global Secure Access

Doc update

The known limitations article now states that the client doesn't support Secure DNS variants such as DoH, DoT, or DNSSEC, and that the macOS client bypasses Secure DNS to enforce FQDN-based tunneling.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…