← Previous day

Day in brief

LES Writeback, Android Play Integrity, and SCIM mailNickname rules sharpen Entra guidance

The period was dominated by ordinary documentation maintenance—sample GUIDs, example identifiers, a corrected link, and PowerShell example syntax. The substantive updates were clearer Conditional Access guidance for Android integrity checks, new Exchange Hybrid detail on LES Writeback, and a precise SCIM description of how Entra ID handles mailNickname during user creation.

  • The Assignment Network guidance now says Microsoft Authenticator for Android uses the Google Play Integrity API for jailbreak detection and denies access when the API is unavailable, unless the policy is disabled. Use this detail when troubleshooting blocked Android access under Conditional Access.

  • The article now documents Entra2ADExchangeOnlineAttributeWriteback, also called LES Writeback, including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.

  • When creating a user, mailNickname may be omitted, null, or empty. Entra ID derives it from the characters before the first @ in userName, and after creation it cannot be removed with PATCH.

  • The Manage App Consent Policies guidance replaces the application IDs shown for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird. Administrators using those identifiers in consent-policy rules should verify them against the updated examples.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

14 updates

3

Assignment Network

Doc update

A link was fixed on the Conditional Access network assignment page.

Assignment Network

Doc update

The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.

3

What If Tool

Doc update

The Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.

Manage App Consent Policies

Doc update

The documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.

Grant Admin Consent

Doc update

The grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.

3

Manage App Consent Policies

Doc update

The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.

Exchange Hybrid

Doc update

The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.

Assign App Owners

Doc update

The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.

1
1

Entra Id Scim Api Reference

Feature update

The SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.

1
1

Agent Token Claims

Doc update

The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.

1

Create Service Principal Cross Tenant

Doc update

The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…