What changed on this day
10 changes were tracked across 4 Microsoft Entra products. The leading updates include Default application; Conditional Access Cloud Apps; Kerberos.
Daily.Entra.News10 changes were tracked across 4 Microsoft Entra products. The leading updates include Default application; Conditional Access Cloud Apps; Kerberos.
manager: mwongerapk
For example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Microsoft Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.
- [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 groups, and SharePoint sites](/purview/sensitivity-labels-teams-groups-sites)
- Windows Server 2019 or newer that are hybrid Microsoft Entra joined.
- Microsoft Entra groups deployed to a device with this policy don't apply to remote desktop connections. To control remote desktop permissions for Microsoft Entra joined devices, you need to add the individual user's SID to the appropriate group.
Applications using the Microsoft Entra identity platform can [expose APIs for other client applications to call](../../identity-platform/quickstart-configure-app-expose-web-apis.md#register-the-web-api). The application with the API can expose OAuth scopes for those API calls. The tool's service principal can be consented permission to those scopes, allowing it to call the APIs.
After you create the access package, you can directly assign specific internal and external users to it. If you specify an external user, a guest user account is created in your directory. For information about directly assigning a user, see [View, add, and remove assignments for an access package](~/id-governance/entitlement-management-access-package-assignments.md).
> [!NOTE]
1. Select **New assignment** to open Add user to access package.
Creation of federated identity credentials is currently **not supported** on user-assigned managed identities created in the following regions: