What changed on this day
40 changes were tracked across 3 Microsoft Entra products. The leading updates include Publish an on-premises SharePoint farm with Microsoft Entra application proxy; 27014; Configure Security.
Daily.Entra.News40 changes were tracked across 3 Microsoft Entra products. The leading updates include Publish an on-premises SharePoint farm with Microsoft Entra application proxy; 27014; Configure Security.
Learn how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to configure application proxy with Remote Desktop Services (RDS)
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
- Store refresh tokens in encrypted, platform‑protected storage.
Learn how to restore a deleted group, view restorable groups, and permanently delete a group in Microsoft Entra ID.
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
| [TLS inspection is enabled and correctly configured for outbound traffic](zero-trust-protect-networks.md#tls-inspection-is-enabled-and-correctly-configured-for-outbound-traffic) | Microsoft Entra ID P1 |
A Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
Learn how to integrate an on-premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
This section will outline best practices independent software vendors (ISV’s) can adopt to enable automated certificate rollover when SAML certificates are near expiry and when applications federated with Microsoft Entra ID. SAML certificates in Entra ID are used for signing assertions in federated single sign-on (SSO). These certificates expire (typically every 1-3 years) and rotation requires a Customer and SaaS ISV coordination to update a mutual certificate in both systems without downtime. Industry trends are shortening certificate lifetimes, manual rollover processes increasingly create operational burden and risk service disruption — especially in large organizations with many SAML enterprise applications.
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
- Fixed a [known issue](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified) where auto-upgrade could stop your Microsoft Entra Connect server unexpectedly. Auto-upgrade now detects modifications to the `miiserver.exe.config` and `miisclient.exe.config` configuration files and skips automatic upgrade on those servers. If you manually upgrade and previously modified these configuration files, you might encounter installation failures. To resolve the issue, see the [known issues section](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified).
- Execute each step **sequentially** and don't skip ahead.
author: arlucaID
This file is used by an AI coding agent (such as GitHub Copilot in VS Code Agent mode) to automate onboarding to Microsoft Entra Agent ID.
Use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.
The Global Secure Access Secure Web Gateway (SWG) implements defense-in-depth through five security layers that together create a comprehensive inspection chain for internet-bound traffic. Each layer serves a distinct protective function: