What changed on this day
38 changes were tracked across 5 Microsoft Entra products. The leading updates include Security for AI agents with Microsoft Entra Agent ID; Configure Security; Migrate Group Writeback.
Daily.Entra.News38 changes were tracked across 5 Microsoft Entra products. The leading updates include Security for AI agents with Microsoft Entra Agent ID; Configure Security; Migrate Group Writeback.
:::image type="content" source="./media/application-proxy-configure-complex-application/complex-app-structure-1.png" alt-text="Diagram of domain structure for a complex application showing resource sharing between primary and secondary application.":::
8. Run this command for each collection. Replace *\<yourcollectionname\>* and *\<proxyfrontendurl\>* with your own information. This command enables single sign-on between RD Web and RD Gateway, and optimizes performance.
- Internal URL:
Follow the same steps as for Application #1, with the following exceptions:
Cookies that don't specify the [SameSite](https://web.dev/articles/samesite-cookies-explained) attribute are treated as if they're set to **SameSite=Lax**. The `SameSite` attribute declares how cookies should be restricted to a same-site context. When set to `Lax`, the cookie is only sent to same-site requests or top-level navigation. However, application proxy requires these cookies to be preserved in the third-party context to keep users signed in during their session. Due to the requirement, updates were made:
1. After entering the domain, a new line in the table appears showing domain name and its status as **initialize**. Select the gear icon to reveal technical data about TAP app Security server and to complete initialization.
There are two ways to provision users from Microsoft Entra into SAP Cloud Identity Services.
* [A Microsoft Entra tenant](~/identity-platform/quickstart-create-new-tenant.md).

Place the connector close to the target application in the customer network. This configuration minimizes step 3 in the topography diagram, because the connector and application are close.
1. *Authority*: Enter *https://login.windows.net*.
1. The Tenant URL is `https://scim.segmentapis.com/scim/v2`. This value is entered in the **Tenant URL** field in the Provisioning tab of your Segment application.
The Microsoft Entra provisioning service currently operates under particular [IP ranges](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md#ip-ranges). If necessary, you can restrict other IP ranges and add these particular IP ranges to the allow list of your application. That technique will allow traffic flow from the Microsoft Entra provisioning service to your application.
5. Select **Use any authentication protocol**.
- A Microsoft Entra account with at least a [Hybrid Identity administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
include file
_api = api;
AI agents are autonomous software systems that can perceive their environment, make decisions, and take action. AI agents can expand organizational capabilities but also introduce security challenges that differ from traditional application security. This introduction explains why AI security matters, the challenges AI agents present, the concept of agent sprawl, and how Microsoft provides security mechanisms for AI agents in enterprise environments.
identityParentId = "<associated-agent-identity-id>"
This article explains how to call a Microsoft Graph API from an agent using agent identities or an agent's user account.
_credential = credential;
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access.
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |
manager: dougeby
manager: dougeby
>
Because the Global Secure Access client for iOS is integrated with Microsoft Defender for Endpoint, it's helpful to understand the end user experience. The client appears in the Defender dashboard after onboarding to Global Secure Access.
- **Microsoft Profile** - Ensure the Microsoft traffic profile is enabled. Microsoft traffic forwarding profile is required to capture traffic directed to Microsoft 365 services, which is fundamental for log enrichment.