Connect Health Operations
Feature updateThe documentation now identifies Microsoft Entra Global Administrators, rather than Hybrid Identity Administrators, in the default Connect Health RBAC guidance and Owner role description.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
This period was dominated by targeted documentation guidance rather than a broad rollout. The most consequential edits clarify that app instance property locks apply to both single-tenant and multitenant applications, record that Enable property lock is enabled by default for new applications since June 2026, and document External ID's credential-management API for customer passkeys. Connect Health guidance also now identifies Global Administrator for agent registration and tenant-wide data-collection procedures. The remaining updates are mainly a cross-reference change, a corrected claims example, and procedural text such as the AD DS connector module path.
The configuration guidance now states that locks apply to an application's service principal for both single-tenant and multitenant applications. It also states that Enable property lock has been enabled by default for new applications since June 2026 and identifies servicePrincipalLockConfiguration for management.
A new credential-management API reference covers delegated authentication, permissions, and setup for signed-in customers to list and register passkeys. It requires the API service principal to be provisioned manually and granted the appropriate delegated permission.
The agent-installation guidance now says that, by default, a Global Administrator account has permission to register the agent, replacing the previous Hybrid Identity Administrator wording.
The procedure for stopping data collection for all registered services now recommends acknowledgment from Global Administrators rather than Hybrid Identity Administrators.
The instructions now list the module at C:\Program Files\Microsoft Azure Active Directory Connect\AdSyncConfig\ADSyncConfig.psm1. Administrators copying the module to a domain controller should use this path.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation now identifies Microsoft Entra Global Administrators, rather than Hybrid Identity Administrators, in the default Connect Health RBAC guidance and Owner role description.
The documentation now lists the module under `C:\Program Files\Microsoft Azure Active Directory Connect\AdSyncConfig\ADSyncConfig.psm1`.
The documentation now states that, by default, a Global Administrator account has permission to register the agent, replacing Hybrid Identity Administrator.
The documentation now says app instance property lock can be enabled for both single-tenant and multitenant apps.
The documentation now says the lock is configured for all applications, rather than all multitenant applications.
The documentation now emphasizes app instance lock for multitenant applications and also mentions single-tenant applications.
The documentation now states that locks apply to an application's service principal for both single-tenant and multitenant applications. Since June 2026, Enable property lock is enabled by default for new applications.
The documentation changes the recommended acknowledgment role from Hybrid Identity Administrators to Global Administrators before stopping data collection for all registered services.
The documentation link was updated from guidance for all multitenant applications to guidance for all applications.
Microsoft Entra External ID applications can use the credential management API to let signed-in customers list and register passkeys. The reference covers delegated authentication, permissions, and setup.
The documentation now directs applications to use the credential management API, with low-privilege delegated permissions, so signed-in customers can list and register their own passkeys.
Example 3 now clearly describes creating the `JoinedData` claim by joining `extensionattribute1` with `-ext` for JWTs issued to linked service principals.