← Previous day

Next day →
Day in brief

Linux broker 2.0.2 now uses Entra join for device trust

The most consequential update affects Microsoft Single Sign-On for Linux: version 2.0.2 and later uses Microsoft Entra join instead of device registration for device trust, and existing upgraded devices must be re-joined and re-enrolled. New Entra ID guidance also details enhanced synchronization for sourcing sAMAccountName. Most remaining updates are mechanical example-ID, browser-reference, or wording changes.

  • Microsoft Single Sign-On for Linux version 2.0.2 and later uses Microsoft Entra join for device trust. Existing upgraded devices must be re-joined and re-enrolled, with the documented upgrade process covering broker-state removal, reinstallation, and device re-join.

  • New guidance documents sourcing hybrid users’ sAMAccountName from onPremisesSamAccountName. Existing domains retain current behavior until the setting is enabled; enabling it updates existing hybrid users during synchronization. Cloud-only users without the source value continue using mailNickname-based generation.

  • The revised guidance states that enabling sign-in joins an Arc-enabled machine to Microsoft Entra and is intended for machines not planned to join another domain, including on-premises Active Directory or Microsoft Entra Domain Services. Administrators should confirm domain-join plans before enabling the capability.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

14 updates

5

Howto Arc Sign In Windows

Doc update

The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.

Howto Arc Sign In Windows

Doc update

The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.

Howto Arc Sign In Windows

Doc update

The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.

Howto Arc Sign In Windows

Doc update

The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.

Howto Arc Sign In Windows

Doc update

The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.

1

Clean broker state including certificates (requires sudo)

Feature updateAction required

Microsoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.

1

Howto Update Permissions

Doc update

The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.

1

Primary Refresh Token

Doc update

The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.

1

Whats New Linux

Feature updateAction required

Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.

1

SAM Account Name

Public preview

Enhanced synchronization can source sAMAccountName for hybrid users from onPremisesSamAccountName in Microsoft Entra ID. Existing domains retain current behavior until enabled; enabling updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation.

1

Breaking Changes

Doc update

The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

1

Manage Device Identities

Feature update

The documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.

1
1

Netskope Integration

Doc update

The Netskope integration example now uses different values for the tenantId and userId fields.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…