What changed on this day
30 changes were tracked across 6 Microsoft Entra products. The leading updates include Microsoft Rewards: Retirement of Azure AD Account Linking; Configure App Management Policies; Apply Security Policies Remote Network.
Daily.Entra.News30 changes were tracked across 6 Microsoft Entra products. The leading updates include Microsoft Rewards: Retirement of Azure AD Account Linking; Configure App Management Policies; Apply Security Policies Remote Network.
Microsoft is retiring the Azure AD Account Linking feature for Microsoft Rewards by March 19, 2026. Users can no longer link work accounts to earn Rewards points. Existing points remain unaffected, personal accounts work as usual, and no admin actions are required.
There are three possible ways that you can add an identifier URI to your app. We recommend them in the following order:
> [!div class="mx-tableFixed"]
manager: pmwongera
Consider using the knowledge base of your organization:
After adding app roles in your application, you can assign an app role to a client app by using the Microsoft Entra admin center or programmatically by using [Microsoft Graph](/graph/api/serviceprincipal-post-approleassignments?tabs=http). Assigning an app role to an application shouldn't be confused with [assigning roles to users](../identity/role-based-access-control/manage-roles-portal.md).
If you’re planning to only change the SOA for some Active Directory users, and all your users are currently in a single OU using Kerberos applications that don’t use LDAP, we recommend that you create a new AD DS OU for these objects. Having them in a separate OU will enable you to avoid inadvertently making updates to them in Active Directory after the SOA change. Users, whose SOA isn’t changing, can continue to be managed using Active Directory Users and Computers, Active Directory Module for PowerShell, or other Active Directory management tools. After creating an OU, move the objects to that OU. For more information, see: [Move-ADObject](/powershell/module/activedirectory/move-adobject?view=windowsserver2025-ps&preserve-view=true).
1. Select Restricted Mode, find the **Block addition of new password credentials to apps** setting.
- One of the following Microsoft Entra roles:
| Restriction name | Description | Security value | Availability |
Agents can then be assigned access packages through three different request pathways.
Agents can then be assigned access packages through three different request pathways.
The Microsoft agent identity platform introduces an administrative model that separates technical administration from business accountability, ensuring operational control and compliance oversight without excessive permissions. This document explains the administrative relationships for Microsoft Entra Agent ID identity types. This guidance applies to [agent identities](/graph/api/resources/agentidentity?view=graph-rest-beta&preserve-view=true), [agent identity blueprints](/graph/api/resources/agentidentityblueprint?view=graph-rest-beta&preserve-view=true), [agent identity blueprint principals](/graph/api/resources/agentidentityblueprintprincipal?view=graph-rest-beta&preserve-view=true), and [agent users](/graph/api/resources/agentuser?view=graph-rest-beta&preserve-view=true). The article covers owners, sponsors, and managers and their importance in maintaining secure operations.
1. Select **Create**.
:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::
First, call [Create accessPackageResourceRequest](/graph/api/entitlementmanagement-post-resourcerequests?tabs=http) to add the Microsoft Entra role as a resource to the catalog.
Once an access review starts, you can use the [contactedReviewers](/graph/api/resources/accessreviewreviewer) API to retrieve the list of all users who were, or would have been, notified via email to perform reviews. Even in scenarios where notifications were turned off, the API still provides the list of reviewers along with timestamps indicating when notification would happen.
1. Select **Create** to finalize the access review.
:::image type="content" source="media/entitlement-management-access-package-create/api-permissions-roles.png" alt-text="Screenshot of adding API permissions as resource roles to an access package.":::
If these users are brought in with a userType of **guest** they accrue to the meter, however you can avoid being charged by setting up
You can also manage access packages, catalogs, policies, requests, and assignments using Microsoft Graph. A user in an appropriate role with an application that has the delegated `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` permission can call the [entitlement management API](/graph/api/resources/entitlementmanagement-overview). For more information, see the [Tutorial: manage access to resources - Microsoft Graph](/graph/tutorial-access-package-api?toc=/azure/active-directory/governance/toc.json&bc=/azure/active-directory/governance/breadcrumb/toc.json). An application with the `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` application permissions can also use many of those API functions, except for managing resources in catalogs and access packages. An application that only needs to operate within specific catalogs can be added to the **Catalog owner** or **Catalog reader** roles of a catalog to be authorized to update or read within that catalog.
Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)
| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |
> * Internet resources with Global Secure Access
Released for download on December 3, 2025.
> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.
> You can add up to 500 application segments to your Quick Access app.
- A **Global Secure Access Administrator** role in Microsoft Entra ID.