Licensing
UpdatedA Microsoft Entra documentation page was updated: Licensing.
Daily.Entra.NewsDecember was predominantly a documentation-maintenance month: 135 of 149 records were Learn updates, rather than broad general-availability launches or retirements. The meaningful exceptions were the Microsoft Entra certificate switch due by January 7, 2026, registration enforcement in External Authentication Methods public preview, the ongoing Baseline Security Mode rollout, and a future Content Security Policy change for Entra ID browser sign-ins. New ID Protection and Agent ID material, along with Global Secure Access updates, add operational guidance but do not establish GA or a mandatory migration. The five removals include no supplied retirement announcement; the named removal was an External ID Quickstart Trial Setup page.
This is a service-continuity change, not a documentation clarification. Microsoft Entra says it will switch from DigiCert Global Root G1 to G2 certificates by January 7, 2026. Organizations must trust the G2 root CA, and any pinning to G1 must be removed or updated to avoid authentication failures with Entra services.
This is a preview behavior change beginning December 8, 2025. Users existing by December 2 are pre-registered, while users added afterward must complete inline setup; administrators can register users. Related provider documentation also makes the OIDC Discovery URL contract explicit: it must use HTTPS, end exactly in `/.well-known/openid-configuration`, contain no additional path, query string, or fragment, and be supplied in full when the EAM is created. Nothing supplied indicates GA.
Baseline Security Mode is rolling out from November 2025 through March 2026 across Office, SharePoint, Exchange, Teams, and Entra. It provides a dashboard with impact reports and risk-based recommendations, and the notice says it causes no immediate user impact. Separately, Entra ID is scheduled to enforce a Content Security Policy beginning in mid-October 2026 for browser-based sign-ins on login.microsoftonline.com, blocking external script injection and allowing only trusted Microsoft scripts. The notice excludes
New Microsoft Entra ID Protection pages cover the Identity Risk Management Agent in Preview, its settings, and review of its findings in the Risky user report. Separate Agent ID governance updates describe agent identity blueprint, blueprint principal, agent identity, and agent user objects, and how lifecycle and access features can govern them. These are new or expanded documentation and preview materials; the supplied evidence gives no GA date, licensing change, or mandatory enablement.
These are operational documentation clarifications rather than evidence of changed runtime behavior. Web content-filtering changes made in the Global Secure Access experience typically take less than five minutes, corresponding Conditional Access changes take approximately one hour, and new threat-intelligence security profiles can take 60–90 minutes to apply. Windows client guidance requires target devices to be managed, joined to the onboarded tenant, and Microsoft Entra joined or hybrid joined. TLS inspection—ac
Prioritize the certificate change: verify that affected environments trust DigiCert Global Root G2, remove any pinning to G1, and update trust settings before January 7, 2026. For External Authentication Methods, prepare for inline registration by users added after December 2, communicate the public-preview change, use the administrator registration option where needed, and validate that configured OIDC Discovery URLs use HTTPS and exactly end in `/.well-known/openid-configuration`. Use the Baseline Security Mode dashboard, impact reports, and risk-based recommendations as the rollout proceeds; the notice says there is no immediate user impact. If browser-based sign-ins on login.microsoftonline.com depend on external scripts, assess them ahead of the mid-October 2026 CSP rollout; the cited
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A Microsoft Entra documentation page was updated: Licensing.
| Metadata value | Value | Comments |
1. Create or modify an existing policy.
By January 7, 2026, Microsoft Entra will switch from DigiCert Global Root G1 to G2 certificates. Organizations must trust the DigiCert G2 root CA to avoid authentication failures with Entra services. Remove any pinning to G1 and update trust settings to prevent service disruption.
Microsoft Entra ID allows the use of a range of authentication methods to support a wide variety of sign-in scenarios. For an overview of the available options, see [Authentication methods in Microsoft Entra ID](overview-authentication.md). Administrators can specifically configure each method to meet their goals for user experience and security. This topic explains how to manage authentication methods for Microsoft Entra ID, and how configuration options affect user sign-in and password reset scenarios.
External Authentication Methods (EAM) Public Preview will enforce registration starting December 8, 2025. Existing users are pre-registered; new users after December 2, 2025, must complete in-line setup. Admins can register users. Organizations should prepare by communicating changes and reviewing configurations.
* [Software OATH tokens](concept-authentication-oath-tokens.md#software-oath-tokens)
The following authentication methods are available for SSPR:
1. Under **Include**, select **Directory roles**, then all roles with administrator in the name.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Security questions aren't used as an authentication method during a sign-in event. Instead, security questions can be used during the self-service password reset (SSPR) process to confirm who you are. Administrator accounts can't use security questions as verification method with SSPR.
| [Short Message Service (SMS) sign-in](howto-authentication-sms-signin.md) | Yes | MFA and SSPR |
Learn to configure Conditional Access adaptive session lifetime policies to protect critical apps, sensitive data, and high-impact users in your organization.
To start receiving notifications, your application sends a `POST` request to the /`subscriptions` endpoint to subscribe to a specific resource, in this case, health monitoring alerts. Microsoft Graph then validates the request and confirms the subscription. Once the subscription is active, Microsoft Graph sends a notification to your designated endpoint whenever the subscribed resource is created. For more information, see [Microsoft Graph change notifications](/graph/change-notifications-overview).
| Metadata value | Value | Comments |
- **Multifactor authentication:** When a user signs in with MFA, several separate MFA events are actually taking place. For example, if a user enters the wrong validation code or doesn't respond in time, more MFA events are sent to reflect the latest status of the sign-in attempt. These sign-in events appear as one line item in the Microsoft Entra sign-in logs. That same sign-in event in Azure Monitor, however, appears as multiple line items. These events all have the same `correlationId`.
manager: pmwongera
A Microsoft Entra documentation page was updated: Secure Remote Workers.
Microsoft 365 Support Engineer
> | [Message Center Reader](#message-center-reader) | Can read messages and updates for their organization in Office 365 Message Center only. | 790c1fb9-7f7d-4f88-86a1-ef1f95c05c1b |
| Date | Area | Description |
In this article, you learn how to integrate [Shopify Plus](https://www.shopify.com/plus) with Microsoft Entra ID. When you integrate Shopify Plus with Microsoft Entra ID, you can:
|Scoping Mode |Number of in-scope groups | Number of membership links (Direct members only) |Notes |
The setting labeled "Let Microsoft manage your consent settings," the Microsoft managed policy, will update with Microsoft's latest recommended default consent settings. This is also the default for a new tenant. The setting's rules are currently: End users can consent for any user consentable delegated permissions EXCEPT: `Files.Read.All`, `Files.ReadWrite.All`, `Sites.Read.All`, `Sites.ReadWrite.All`, `Mail.Read`, `Mail.ReadWrite`, `Mail.ReadBasic`, `Mail.Read.Shared`, `Mail.ReadBasic.Shared`, `Mail.ReadWrite.Shared`, `MailboxItem.Read`, `Calendars.Read`, `Calendars.ReadBasic`, `Calendars.ReadWrite`, `Calendars.Read.Shared`, `Calendars.ReadBasic.Shared`, `Calendars.ReadWrite.Shared`, `Chat.Read`, `Chat.ReadWrite`, `ChannelMessage.Read.All`, `OnlineMeetings.Read`, `OnlineMeetings.ReadWrite`, `OnlineMeetingTranscript.Read.All`, `OnlineMeetingsRecording.Read.All`. Updates to this consent policy will have at least 30 days of given notice.
1. Under **Include**, select **Selected networks and locations**
Get notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Get notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Get notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Google Cloud or Google Workspace.
Integrating Oracle Fusion Cloud Human Capital Management (HCM) with Microsoft Entra ID and on-premises Active Directory using the Inbound Provisioning API.
This article describes the steps you need to perform in both AWS IAM Identity Center(successor to AWS single sign-On) and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [AWS IAM Identity Center](https://console.aws.amazon.com/singlesignon) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md). You can then use those users and groups in AWS IAM Admin Center for user access to other Amazon Web Services (AWS) applications or accounts.
* [A Microsoft Entra tenant](~/identity-platform/quickstart-create-new-tenant.md).
1. Next, a system account must be created for Microsoft Entra ID. Use the instructions below to request a System Account for your sandbox and production environments.
This article describes the steps you need to perform in both Shopify Plus and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Shopify Plus](https://www.shopify.com/plus) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
The objective of this article is to demonstrate the steps to be performed in Dropbox for Business and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Dropbox for Business.
This is a current list of known limitations with the Microsoft Entra ECMA Connector Host and on-premises application provisioning.
12. Select **OK** twice. Close the ODBC Data Source Administrator. The DSN connection file is saved by default to your **Documents** folder.
ai-usage: ai-assisted
Use case | Parent group type | User member group type | Sync Direction | How sync works
author: mjsantani
In this article, you learn how to prevent users from signing in to an application in Microsoft Entra ID through both the Microsoft Entra admin center and PowerShell. If you're looking for how to block specific users from accessing an application, use [user or group assignment](./assign-user-or-group-access-portal.md).
> [!NOTE]
```
HttpClient client = new HttpClient();
| Attribute | Description |
author: shlipsey3
* [A Microsoft Entra tenant](~/identity-platform/quickstart-create-new-tenant.md).
This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md) and [Configure OIDC SSO for custom (non-gallery) applications](~/identity/enterprise-apps/add-application-portal-setup-oidc-sso.md?#configure-oidc-sso-for-custom-non-gallery-applications).
Baseline Security Mode centralizes Microsoft’s recommended security standards for Office, SharePoint, Exchange, Teams, and Entra. Rolling out from November 2025 to March 2026, it provides admins with a dashboard to assess and improve security posture using impact reports and risk-based recommendations, with no immediate user impact.
|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.
- **Custom CSS:** Upload a custom CSS file to replace the Microsoft default style of the page.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
GET https://graph.microsoft.com/beta/applications/{application-id}?$select=displayName,isDisabled,appId
This article shows the new and updated documentation for the Microsoft Entra application management.
|AzureActiveDirectoryInvalidCredential|Error Message: We found an issue with the service account that is used to run Microsoft Entra Cloud Sync. You can repair the cloud service account by following the instructions at [here](./how-to-troubleshoot.md). If the error persists, please contact support with Job ID (from status pane of your configuration). Additional Error Details: CredentialsInvalid AADSTS50034: The user account {EmailHidden} doesn't exist in the skydrive365.onmicrosoft.com directory. To sign into this application, the account must be added to the directory. Trace ID: 0000aaaa-11bb-cccc-dd22-eeeeee333333 Correlation ID: aaaa0000-bb11-2222-33cc-444444dddddd Timestamp: 2021-01-12 21:08:29Z |This error is thrown when the sync service account ADToAADSyncServiceAccount doesn't exist in the tenant. It can be due to accidental deletion of the account.|Use [Repair-AADCloudSyncToolsAccount](reference-powershell.md#repair-aadcloudsynctoolsaccount) to fix the service account.|
If you're locked out because of an incorrect setting in a Conditional Access policy:
Once you configure AWS IAM Identity Center you can enforce session control, which protects exfiltration and infiltration of your organization’s sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Defender for Cloud Apps](/cloud-app-security/proxy-deployment-any-app).
include file
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
| August | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
Historically, AI agents would rely upon tools to interact with various applications and systems, and each of those tools would have their own identities in those applications and systems. Some of those tools would use service principals to authenticate to Microsoft services via Microsoft Graph or Microsoft Azure APIs. [Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) introduces support for identities for the agents themselves, with four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Through the [agent identity blueprint](../agent-id/identity-platform/agent-blueprint.md), the agent can create one or more agent identities, and optionally an agent user for each agent identity. Each agent identity and agent user can have distinct access rights.
[Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) includes four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. These can be created in [Microsoft Foundry](/azure/ai-foundry/agents/concepts/agent-identity), [Microsoft Copilot Studio](/microsoft-copilot-studio/admin-use-entra-agent-identities), or other platforms. The agent identity, and optionally the agent user, allows AI agents to take on digital identities within Microsoft Entra. Once a digital identity is established, these agent identities are able to be governed using lifecycle and access features. Sponsors can be assigned to agent identities after creation. Sponsors of agent identities are human users accountable for making decisions about its lifecycle and access. For more information about the role of a sponsor of agent identities, see: [Administrative relationships for agent IDs](../agent-id/identity-platform/agent-owners-sponsors-managers.md).
The Manage Agents feature in Microsoft Entra lets you view, and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-is-agent-id.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
manager: mwongerapk
Learn about the Agent ID, Agent Blueprint, and Agent Identity error codes.
This article provides a comprehensive reference for error codes you might encounter when working with the Microsoft agent identity platform.
As an admin, you want to have a 360-degree view of your agents for both security and operational efficiency. Some agents will be represented in Microsoft Entra with an agent identity blueprint principal and agent identities, or as a service principal. It isn't uncommon to also have agents that are registered in the agent registry but don't have an associated Microsoft Entra agent identity. These agents are referred to as registry-only agents. They might be in the process of being onboarded or they may have registered in the registry without needing to use Microsoft Entra Agent ID as the agent's identity provider.
author: shlipsey3
The Identity Risk Management Agent in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing user behavior and suggesting actions to mitigate potential identity risks. You can configure the settings to meet your organization's needs, such as how often it runs, and email notifications.
Learn how to configure the settings for the Identity Risk Management Agent in Microsoft Entra ID Protection.
Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.
A Microsoft Entra documentation page was updated: Identity Risk Management Agent Get Started.
A Microsoft Entra documentation page was updated: Identity Risk Management Agent Settings.
Knowing which users are at risk and *why* they're at risk is a key responsibility of security and identity administrators. The Risky user report in Microsoft Entra ID Protection provides the full report, along with a risk data summary, and an activity timeline.
author: shlipsey3
Learn about how the Identity Risk Management Agent works with the Risky user report in Microsoft Entra ID Protection
A Microsoft Entra documentation page was updated: Identity Risk Management Agent Risky User Report.
The Identity Risk Management Agent (Preview) in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing the risky identities and suggesting actions to remediate them. By using a Large Language Model, the agent helps security administrators review and respond to risky activities before they lead to security incidents.
In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.
|Feature|Free|Microsoft Entra ID P1|Microsoft Entra ID P2|Microsoft Entra ID Governance| Microsoft Entra Suite |
The first step to perform an access review is to find and open the access review.
Maintaining and classifying data within your environment is an important part in maintaining a secure environment. Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization's data, while making sure that user productivity and their ability to collaborate isn't hindered. With sensitivity labels in Lifecycle Workflows, administrators are able to quickly view the sensitivity labels of groups and teams during workflow creation, and editing.
```
| [Disable user account](../id-governance/lifecycle-workflow-tasks.md#disable-user-account) | 1dfdfcc7-52fa-4c2e-bf3a-e3919cc12950 | Leaver |
<a name='entra-identity-governance-integrations'></a>
This article provides best practices for securing deploying Microsoft Entra ID Governance.
This article describes how to set up a lab environment with SAP ECC for testing.
Describes how to use Entitlement Management with Private Access
This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host
This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.
This article describes use cases Microsoft Entra ID Governance.
documentationcenter: ''
author: owinfreyATL
Catalog access reviews in Microsoft Entra ID Governance enables organizations to simplify how managers can review users access to multiple resource types, such as groups, applications and custom disconnected resource at once. This helps ensure only the right people retain access, while enabling managers and resource owners to review access efficiently through a multi-stage process.
This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).
If you do not yet have a catalog, then create a new catalog. If you have a catalog already, then continue at the [next section](#add-a-custom-data-provided-resource-to-a-catalog).
- To review access package assignments, see [configure an access review in entitlement management](entitlement-management-access-reviews-create.md).
Approval delegation in My Access allows approvers to assign another individual to respond to access package approval requests on their behalf. This feature helps maintain productivity when approvers are unavailable due to leave, travel, or other commitments.

1. Select a group in Microsoft Entra ID that has one or more members. Or select an application connected to Microsoft Entra ID that has one or more users assigned to it.
1. If the application was using AD security groups, and those groups were created in AD, then once the review is complete, you need to manually update the AD groups to remove memberships of those users who were denied. Subsequently, to have denied access rights removed automatically, you can either update the application to use an AD group that was created in Microsoft Entra ID and [written back to Microsoft Entra ID](~/identity/hybrid/cloud-sync/how-to-configure-entra-to-active-directory.md), or move the membership from the AD group to the Microsoft Entra group, and [nest the written back group as the only member of the AD group](~/identity/hybrid/cloud-sync/govern-on-premises-groups.md).
1. Select **Create**.
There are four common scenarios in which it's necessary to populate Microsoft Entra ID with existing access rights and users of an application before you use the application with a Microsoft Entra ID Governance feature such as [access reviews](access-reviews-application-preparation.md).
| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |
The Access Review Agent assists you in completing your pending access reviews by guiding you in Microsoft Teams with natural language, insights, and recommendations.
For more information on those first two scenarios, where the application supports provisioning, or uses an LDAP directory, SQL database, has a SOAP or REST API or relies upon Microsoft Entra ID as its identity provider, see the article [govern an application's existing users](identity-governance-applications-existing-users.md). That article covers how to use identity governance features for existing users of those categories of applications.
- [Complete an access review of groups or applications](complete-access-review.md)
Describes overview of identity lifecycle management for Microsoft Entra ID Governance.
| Microsoft Entra role | Specified reviewers</br>Self-review | [PIM](../id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json) | Microsoft Entra admin center |
Organizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.
>[!NOTE]
1. In the DNS console, for CNAME, enable the proxy setting.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
|Limits based on phone number |15 texts |20 texts |30 texts |50 texts |
A Microsoft Entra documentation page was updated: Quickstart Trial Setup.
New and updated documentation for the Microsoft Entra External ID.
> [!NOTE]
<a name="b2b-guest-access-limitations"></a>
:::image type="content" source="media/concept-guide-explained/trial-creation.png" alt-text="Flowchart that shows the trial tenant creation step in the guide.":::
**Q: Can I configure MFA on the resource tenant?**
| `https://lexmarkb2ceu.b2clogin.com/LexmarkB2CEU.onmicrosoft.com/B2C_1A_TrustFrameworkBase_ciam/samlp/sso/assertionconsumer` |
An external identity provider needs to provide an [OIDC Discovery endpoint](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig). This endpoint is used to get more configuration data. The Discovery URL **MUST** use the `https` scheme and **MUST** end with `/.well-known/openid-configuration`. No additional path segments, query strings, or fragments are permitted after this segment. The full Discovery URL must be included in the Discovery URL configured when the EAM is created.
Learn how to migrate passwords from another identity provider to Microsoft Entra External ID using Just-In-Time (JIT) Migration.
Microsoft Entra ID will enhance authentication security by enforcing a Content Security Policy that blocks external script injection, allowing only trusted Microsoft scripts. This rollout begins mid-October 2026, affecting browser-based sign-ins on login.microsoftonline.com, with no impact on Entra External ID tenants.
This extension provides a basic setup that automatically creates a tenant for applications and prepares it for users. It also streamlines your workflow by automatically populating values such as application IDs into your configuration file for a smoother setup process.
1. Select the **Protect apps from DDoS with WAF** tile by selecting **Get started**.
Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access uses a two-tier Intermediate certificate model to issue dynamically generated leaf certificates for decrypting traffic. This article explains how to configure the Certificate Authority (CA) that serves as the Global Secure Access intermediate CA, including signing and uploading the certificate.
:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::
author: barclayn
author: barclayn
The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.contoso.com/`.
2. Now delete the old application and object using the following PowerShell cmdlets:
| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
- A managed device joined to the onboarded tenant. The device must be either Microsoft Entra joined or Microsoft Entra hybrid joined.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).
3. Use the following request format, replacing example.com with the host/path you want to check (for example, `msn.com/en-us/sports`):
ai-usage: ai-assisted
- For guidance on configuring web content filtering, see [Configure web content filtering](./how-to-configure-web-content-filtering.md).
1. On the **Review** tab, review your settings.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
manager: dougeby
- TLS inspection supports up to 100 policies, 1000 rules, and 8000 destinations.
> Applying a new security profile can take up to 60-90 minutes because security profiles are enforced via access tokens.
1. Select **Create CSR**. This step creates a .csr file and saves it to your default download folder.
> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.