← Previous day

Day in brief

Global Secure Access connector guidance defines non-overlapping TCP ranges

All 11 entries were Microsoft Learn updates. The substantive changes tighten Global Secure Access connector port guidance, clarify the weakness of device-platform signals in Conditional Access, and revise Exchange role-assignment instructions; several other pages contain Workplace or Meta Workplace reference cleanup.

  • Global Secure Access connector guidance specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151. It adds Windows Server 2016+ prerequisites and configuration and verification commands, and clarifies that AutoReuse applies only to TCP.

  • The conditions guidance says device-platform information, including user-agent strings, can be modified and is not verified. It recommends combining device-platform conditions with Microsoft Intune device-compliance policies or using them in a block statement.

  • The groups guidance directs administrators to the Exchange admin center for role assignments through dynamic membership groups. When the old Exchange admin center is required, it says to assign the eligible role directly to the user rather than through role-assignable groups; Exchange PowerShell cmdlets continue to work as expected.

  • The partner-driven integrations page now lists Dropbox and Snowflake as examples and removes its reference to Workplace by Facebook. No configuration change is indicated.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

11 updates

2

Backup Authentication System

Doc update

The backup authentication system documentation no longer lists Workplace from Facebook in its integration table.

Provision On Demand

Doc update

The provision-on-demand article no longer includes references to Meta Workplace. The displayed guidance about stopping provisioning for OAuth-based applications remains unchanged.

1
1

Conditional Access Conditions

Doc update

The documentation now warns that device platform information, such as user agent strings, can be modified and isn't verified. It recommends using device platform with Microsoft Intune device compliance policies or in a block statement.

1

Groups Concept

Doc update

The guidance now directs administrators to the Exchange admin center for role assignments through dynamic membership groups. If the old Exchange admin center is required, assign the eligible role directly to the user rather than through role-assignable groups; Exchange PowerShell cmdlets work as expected.

1

Policy All Users Device Unknown Unsupported

Doc update

The documentation now highlights that device platform conditions rely on user agent strings and recommends pairing them with policies requiring device compliance or app protection to reduce risk.

1

Partner Driven Integrations

Doc update

The partner-driven integrations documentation now lists Dropbox and Snowflake as examples and no longer references Workplace by Facebook.

1

Apps

Doc update

The Entra ID Governance apps page no longer lists Workplace from Meta in its application table.

1
1

Connectors

Feature update

The documentation specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151, with new configuration and verification commands. It also adds Windows Server 2016+ prerequisites and clarifies that AutoReuse applies only to TCP.

1

Configure Connectors

Doc update

The connector configuration guidance now refers to configuring dynamic and AutoReuse TCP port ranges instead of extending TCP and UDP ephemeral ports.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…