What changed on this day
29 changes were tracked across 3 Microsoft Entra products. The leading updates include Assignment restriction for managed identities; Migrate Group Writeback; Security Operations.
Daily.Entra.News29 changes were tracked across 3 Microsoft Entra products. The leading updates include Assignment restriction for managed identities; Migrate Group Writeback; Security Operations.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Learn how to configure single sign-on between Microsoft Entra ID and AlexisHR.
Before you try this tutorial, consider the following items:
AI Administrator
> [!IMPORTANT]
This is a [privileged role](../privileged-roles-permissions.md). Assign the AI Reader role to users who need to do the following tasks:
> [!NOTE]
Key details:
Describes the Microsoft Entra built-in roles and permissions.
- Cloud-created [security groups](../../../fundamentals/concept-learn-about-groups.md#group-types).
Microsoft Teams for the web will respect Microsoft Entra ID's "Keep Me Signed In" (KMSI) settings starting late June 2026. Sessions will persist only if users choose to stay signed in; otherwise, sessions clear on browser close, enhancing security on shared devices. No immediate action is required.
> [!IMPORTANT]
You need at least the **Microsoft Entra Backup Reader** role to review difference reports. To review and create difference reports, you need the **Microsoft Entra Backup Administrator** role. The **Global Administrator** role also includes these permissions.
For a full list of supported attributes, see [Supported objects and attributes](scope-supported-objects-limitations.md).
ai-usage: ai-assisted
1. Ensure Microsoft Entra Connect is installed. Download it from the [Microsoft Entra Admin Center](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/%7E/GetStarted).
</AuthnContext>
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Create a non-destructive Microsoft Entra recovery preview job scoped to directory objects that affect Global Secure Access.
Run a Microsoft Entra recovery job for directory objects that affect Global Secure Access after reviewing a recovery preview.
Calculate the Microsoft Sentinel alert noise ratio for Global Secure Access detections and send an alert when false positives or informational closures exceed your threshold.
Check Global Secure Access-related administrator role assignments and identify accounts that need quarterly review.
Verify that your Global Secure Access configuration backup runbook ran successfully. Send an alert when the runbook fails or misses a scheduled run.
Use shared helper functions for authentication and alert email in Global Secure Access operations automation scripts.
| --- | --- |
List Microsoft Entra Backup and Recovery snapshots that can help recover directory objects used by Global Secure Access.
Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, TLS certificate creation, operations monitoring, and recovery.
- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)