Month in brief

February 2026: Entra adds Conditional Access web-filtering guidance, Global Secure Access flags a location limitation, and Rewards account linking is scheduled to retire

The month's most consequential items are a cross-product implementation path, a concrete Global Secure Access limitation, targeted External ID authentication clarifications, and one explicit retirement—not a broad release wave. The record contains 2,701 changes: 2,686 updates, 8 new items, 6 removals, and one Message Center notice. The new February 19 web-filtering page and February 27 Internet Access update describe integration with Microsoft Entra ID and Conditional Access, but the supplied evidence does not label the capability preview or generally available. The supplied briefs do identify prerelease or preview material for External ID B2B Guest Access and Prompt Shield, without providing scope or an availability commitment. Most remaining changes are ordinary Microsoft Learn maintenance, including broad Conditional Access reference refreshes and partner SSO and provisioning tutorials.

  • [New and updated documentation] Web content filtering is documented as a Conditional Access-integrated capabilityEntra ID Conditional Access; Internet Access; Global Secure Access

    A new February 19 Microsoft Entra Conditional Access page covers web content filtering integration. Related Microsoft Entra Internet Access guidance says its first Secure Web Gateway features include domain-name filtering and that granular policies integrate with Microsoft Entra ID and Conditional Access, making them user-aware and context-aware. This establishes an implementation path in the documentation, not a supplied preview or GA announcement.

  • [Known limitation and security guidance] Global Secure Access warns against strict location enforcement in a specific policy combinationGlobal Secure Access; Entra ID Conditional Access

    The February 10 update to Global Secure Access Current Known Limitations says not to enable strict location enforcement when IP location-based Conditional Access policies target non-Microsoft resources. This is an explicit operational guardrail for that configuration, not a general feature launch or tenant-wide behavior change.

  • [Retirement] Azure AD Account Linking for Microsoft Rewards ends by March 19, 2026Entra ID; Microsoft Rewards

    The sole supplied Microsoft 365 Message Center notice says users will no longer be able to link work accounts to earn Microsoft Rewards points by March 19, 2026. Existing points are unaffected, personal accounts continue to work, and the notice explicitly says no administrator action is required.

  • [Documentation clarification] External ID authentication guidance adds Graph-only validation and flow constraintsExternal ID

    The updated Sign In Alias guidance documents custom username validation through the validationRegEx setting, which is not available in the admin center and must be configured through Microsoft Graph using the authenticationAttributeCollectionInputConfiguration resource. External ID MFA guidance says SMS has an additional cost for second-factor verification and self-service password reset in external tenants and is not supported for first-factor authentication. The period's password-migration guidance also records a

  • [Security guidance] Agent ID documentation covers blocking high-risk agent identities with Conditional AccessAgent ID; Entra ID Conditional Access

    An updated February 4 Agent ID page explains how to configure Conditional Access policies to block risky agent identities and presents related best practices. The supplied record does not establish new enforcement, preview status, or GA; administrators should treat this as security guidance for Agent ID deployments.

For Entra administrators

Use targeted validation rather than a tenant-wide rollout. For web content filtering, follow the documented Conditional Access session-control path; the supplied guidance describes propagation as typically under five minutes for changes made in the Global Secure Access experience and about one hour for Conditional Access changes. Before enabling strict location enforcement, inspect IP location-based Conditional Access policies targeting non-Microsoft resources. External ID administrators who need custom alias validation must plan to configure it through Microsoft Graph, and should verify password-migration error handling and SMS cost and first-factor assumptions. Agent ID administrators can review the updated guidance for blocking risky agent identities. No administrator action is required

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

2701 updates by product

Microsoft Entra ID

1961 updates

General

1164

Purpose:

Updated

author: omondiatieno

27 February 2026

Purpose:

Updated

author: omondiatieno

27 February 2026

Purpose:

Updated

author: omondiatieno

27 February 2026

Manage Device Identities

Updated

Additionally, columns can be managed by selecting **Manage view > Columns** to toggle which columns you would like to export.

26 February 2026

Concur Tutorial

Updated

| `https://<customer-domain>.concursolutions.com` |

20 February 2026

Lensesio Tutorial

Updated

c. **Sign on URL**: Enter a URL that has the following pattern: `https://<CUSTOMER_LENSES_BASE_URL>`. An example is `https://lenses.my.company.com`.

20 February 2026

Sciforma Tutorial

Updated

`https://<SUBDOMAIN>.sciforma.net/sciforma/main.html`

20 February 2026

Docker Tutorial

Updated

The scenario outlined in this article assumes that you already have the following prerequisites:

20 February 2026

Ebsco Tutorial

Updated

o **Custid** = Enter unique EBSCO customer ID

20 February 2026

Mitel Connect Tutorial

Updated

In this section, you create a user named Britta Simon on your MiCloud Connect account. Users must be created and activated before using single sign-on.

20 February 2026

Sap Successfactors Writeback Tutorial

Updated

| 4 | true | emailIsPrimary | Use this attribute to set business email as primary in SuccessFactors. If business email isn't primary, set this flag to false. |

20 February 2026

Identifier Uri Restrictions

Updated

There are three possible ways that you can add an identifier URI to your app. We recommend them in the following order:

18 February 2026

include file

Updated

include file Microsoft Entra ID preview program information

4 February 2026

Controls

Updated

author: shlipsey3

4 February 2026

Users Close Account

Updated

How to close your work or school account in an unmanaged Microsoft Entra ID.

4 February 2026

Provisioning

409

Airbase Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Airbase.

27 February 2026

Airtable Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Airtable.

27 February 2026

Askspoke Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to askSpoke.

27 February 2026

Atea Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atea.

27 February 2026

Benq Iam Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BenQ IAM.

27 February 2026

Blink Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Blink.

27 February 2026

Bonusly Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Bonusly.

27 February 2026

Britive Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Britive.

27 February 2026

Chatwork Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Chatwork.

27 February 2026

Cinode Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cinode.

27 February 2026

Cisco Webex Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Cisco Webex.

27 February 2026

Elia Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to elia.

27 February 2026

Envoy Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Envoy.

27 February 2026

Fuze Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Fuze.

27 February 2026

Goto Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GoTo.

27 February 2026

Gtmhub Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Gtmhub.

27 February 2026

Helloid Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to HelloID.

27 February 2026

Hootsuite Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hootsuite.

27 February 2026

Howspace Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Howspace.

27 February 2026

Ideo Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to IDEO.

27 February 2026

Invision Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to InVision.

27 February 2026

Invitedesk Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to InviteDesk.

27 February 2026

Jostle Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Jostle.

27 February 2026

Keepabl Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Keepabl.

27 February 2026

Limblecmms Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LimbleCMMS.

27 February 2026

Litmos Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SAP Litmos.

27 February 2026

Logicgate Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LogicGate.

27 February 2026

Lucidchart Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Lucidchart.

27 February 2026

Lusid Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LUSID.

27 February 2026

M Files Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to M-Files.

27 February 2026

Maptician Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Maptician.

27 February 2026

Merchlogix Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to MerchLogix.

27 February 2026

Mixpanel Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Mixpanel.

27 February 2026

Mobileiron Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to MobileIron.

27 February 2026

Mondaycom Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to monday.com.

27 February 2026

Moqups Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Moqups.

27 February 2026

Mypolicies Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to myPolicies.

27 February 2026

N Able User Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to N-able User Provisioning.

27 February 2026

Notion Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Notion.

27 February 2026

Olfeo Saas Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Olfeo SAAS.

27 February 2026

Oneflow Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Oneflow.

27 February 2026

Openforms Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to OpenForms.

27 February 2026

Oracle Hcm Provisioning Tutorial

Updated

Integrating Oracle Fusion Cloud Human Capital Management (HCM) with Microsoft Entra ID and on-premises Active Directory using the Inbound Provisioning API.

27 February 2026

Parsable Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Parsable.

27 February 2026

Peripass Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Peripass.

27 February 2026

Pingboard Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Pingboard.

27 February 2026

Plandisc Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Plandisc.

27 February 2026

Playvox Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Playvox.

27 February 2026

Postman Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Postman.

27 February 2026

Preciate Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Preciate.

27 February 2026

Purpose:

Updated

author: omondiatieno

27 February 2026

Puzzel Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Puzzel.

27 February 2026

Quarem Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Quarem.

27 February 2026

Real Links Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Real Links.

27 February 2026

Recnice Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Recnice.

27 February 2026

Rollbar Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Rollbar.

27 February 2026

Rootly Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Rootly.

27 February 2026

Salesforce Provisioning Tutorial

Updated

Learn the steps required to perform in Salesforce and Microsoft Entra ID to automatically provision and de-provision user accounts from Microsoft Entra ID to Salesforce.

27 February 2026

Samanage Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SolarWinds Service Desk (previously Samanage).

27 February 2026

Sentry Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Sentry.

27 February 2026

Servicely Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Servicely.

27 February 2026

Servicenow Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ServiceNow.

27 February 2026

Smartsheet Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Smartsheet.

27 February 2026

Snowflake Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Snowflake.

27 February 2026

Sosafe Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SoSafe.

27 February 2026

Starmind Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Starmind.

27 February 2026

Swit Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Swit.

27 February 2026

Tailscale Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Tailscale.

27 February 2026

Talentech Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Talentech.

27 February 2026

Tanium Sso Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Tanium SSO.

27 February 2026

Team Today Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Team Today.

27 February 2026

Teamgo Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Teamgo.

27 February 2026

Teamviewer Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to TeamViewer.

27 February 2026

Thousandeyes Provisioning Tutorial

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to ThousandEyes.

27 February 2026

Torii Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Torii.

27 February 2026

Travelperk Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to TravelPerk.

27 February 2026

Tribeloo Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Tribeloo.

27 February 2026

Twingate Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Twingate.

27 February 2026

Uni Tel As Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Uni-tel A/S.

27 February 2026

Unifi Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to UNIFI.

27 February 2026

V Client Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to V-Client.

27 February 2026

Vonage Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Vonage.

27 February 2026

Wats Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to WATS.

27 February 2026

Wedo Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to WEDO.

27 February 2026

Whimsical Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Whimsical.

27 February 2026

Wiggledesk Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to WiggleDesk.

27 February 2026

Xledger Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Xledger.

27 February 2026

Yardione Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to YardiOne.

27 February 2026

Zello Provisioning Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zello.

27 February 2026

Zendesk Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Zendesk.

27 February 2026

Zero Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Zero.

27 February 2026

Zip Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Zip.

27 February 2026

Zoho One Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Zoho One.

27 February 2026

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

5. Under the **Admin Credentials** section, input your GitHub Enterprise Managed User (OIDC) Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to GitHub Enterprise Managed User (OIDC). If the connection fails, ensure your GitHub Enterprise Managed User (OIDC) account has created the secret token as an enterprise owner and try again.

25 February 2026

Configure askSpoke for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both askSpoke and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to askSpoke using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

20 February 2026

Configure Whimsical for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both Whimsical and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Whimsical](https://whimsical.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

20 February 2026

Looop Provisioning Tutorial

Updated

Before configuring Looop for automatic user provisioning with Microsoft Entra ID, you need to retrieve some provisioning information from Looop.

20 February 2026

Provision a User with Expression Builder

Updated

Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.

6 February 2026

Provisioning Workbook

Updated

This article describes the Azure Monitor workbook for provisioning.

6 February 2026

Tutorial Ecma Sql Connector

Updated

This tutorial describes how to provision users from Microsoft Entra ID into a SQL database.

6 February 2026

Workday Expression Mapping Functions for Microsoft Entra ID Provisioning

Updated

A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.

6 February 2026

Configure Akamai Enterprise Application Access for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both Akamai Enterprise Application Access and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Akamai Enterprise Application Access](https://www.akamai.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

5 February 2026

Developer

94

Howto Add App Roles In Apps

Updated

After adding app roles in your application, you can assign an app role to a client app by using the Microsoft Entra admin center or programmatically by using [Microsoft Graph](/graph/api/serviceprincipal-post-approleassignments?tabs=http). Assigning an app role to an application shouldn't be confused with [assigning roles to users](../identity/role-based-access-control/manage-roles-portal.md).

18 February 2026

Prepare User Source Of Authority Environment

Updated

If you’re planning to only change the SOA for some Active Directory users, and all your users are currently in a single OU using Kerberos applications that don’t use LDAP, we recommend that you create a new AD DS OU for these objects. Having them in a separate OU will enable you to avoid inadvertently making updates to them in Active Directory after the SOA change. Users, whose SOA isn’t changing, can continue to be managed using Active Directory Users and Computers, Active Directory Module for PowerShell, or other Active Directory management tools. After creating an OU, move the objects to that OU. For more information, see: [Move-ADObject](/powershell/module/activedirectory/move-adobject?view=windowsserver2025-ps&preserve-view=true).

18 February 2026

Application Proxy Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

6 February 2026

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

6 February 2026

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

6 February 2026

Deactivate Application Portal

Updated

Before deactivating the application, remove all owners from the application. This ensures only users with tenant-wide `microsoft.directory/applications/enable` scope can reactivate the application. This scope is restricted to administrative roles.

5 February 2026

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

4 February 2026

Configure Sso

Updated

Understand single sign-on with an on-premises app using application proxy.

4 February 2026

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

4 February 2026

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

4 February 2026

Standards

72

Lexmark Cloud Services Tutorial

Updated

If you want to configure the **SAML Authentication Provider** section with Metadata URL, then perform the following steps:

25 February 2026

Tripwire Enterprise Tutorial

Updated

To configure single sign-on in Tripwire Enterprise, please see **Using Tripwire Enterprise with SAML Authentication** section in the Tripwire Enterprise Hardening Guide, available for download on the Tripwire Customer Center. If you require assistance, contact [Tripwire Enterprise support team](mailto:[email protected]).

20 February 2026

Achieve3000 Tutorial

Updated

`https://saml.achieve3000.com/district/<District Identifier>`

20 February 2026

Crowd Log Tutorial

Updated

To perform the Single Sign-On configuration on the Crowd Log side, please refer to the Crowd Log SAML admin settings documentation.

20 February 2026

In Case Of Crisis Mobile Tutorial

Updated

To configure single sign-on on **In Case of Crisis - Mobile** side, you need to send the downloaded **Certificate (Raw)** and copied **User access URL** from Azure portal to In Case of Crisis - Mobile support team. They set this setting to have the SAML SSO connection set properly on both sides.

20 February 2026

Lexmark Cloud Services Tutorial

Updated

To configure single sign-on on **Lexmark Cloud Services (SAML)** side, you need to send the **App Federation Metadata Url** to Lexmark Cloud Services (SAML) support team. They set this setting to have the SAML SSO connection set properly on both sides. Also review the [Lexmark documentation](https://support.lexmark.com/en_us/manuals-guides/online/Lexmark-Cloud-Platform/configuring-microsoft-entra-id-federation-for-saml.html) on Configuring Microsoft Entra ID with SAML Federation

20 February 2026

On24 Tutorial

Updated

To configure single sign-on on **ON24 Virtual Environment SAML Connection** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to ON24 Virtual Environment SAML Connection support team. They set this setting to have the SAML SSO connection set properly on both sides.

20 February 2026

Gaggleamp Tutorial

Updated

1. In another browser instance, navigate to the SAML SSO page created for you by the Gaggle support team (for example: `https://accounts.gaggleamp.com/saml_configurations/oXH8sQcP79dOzgFPqrMTyw/edit`).

20 February 2026

Oreilly Learning Platform Provisioning Tutorial

Updated

Before you begin to configure the O'Reilly learning platform to support provisioning with Microsoft Entra ID, you’ll need to generate a SCIM API token within the O’Reilly Admin Console.

20 February 2026

Outsystems Tutorial

Updated

To configure single sign-on on OutSystems side, you need to download the IdP forge component, configure it as mentioned in the [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Configure_your_application_to_use_IdP_connector). After installing the component and do the necessary code changes, configure Microsoft Entra ID by downloading Federation Metadata XML from Azure portal and upload on OutSystems IdP component, according to the following [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Azure_AD_.2F_ADFS).

20 February 2026

Spectrumu Tutorial

Updated

To configure single sign-on on **SpectrumU** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to SpectrumU support team. They set this setting to have the SAML SSO connection set properly on both sides.

20 February 2026

Use Scim To Provision Users And Groups

Updated

> **Test Connection** queries the SCIM endpoint for a user that doesn't exist, using a random GUID as the matching property selected in the Microsoft Entra configuration. The expected correct response is HTTP 200 OK with an empty SCIM ListResponse message.

19 February 2026

Single Sign On Saml Protocol

Updated

| `ID` | Required | Microsoft Entra ID uses this attribute to populate the `InResponseTo` attribute of the returned response. ID must not begin with a number, so a common strategy is to prepend a string like "ID" to the string representation of a GUID. For example, `id6c1c178c166d486687be4aaf5e482730` is a valid ID. |

3 February 2026

Fundamentals

57

Configure Security

Updated

| [Quick Access has user or group assignments](zero-trust-protect-networks.md#quick-access-has-user-or-group-assignments) | Microsoft Entra Suite Add-on for Microsoft Entra ID P2 |

26 February 2026

Whats New

Updated

> Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your ![RSS feed reader icon](./media/whats-new/feed-icon-16x16.png) feed reader.

25 February 2026

What Is App Proxy

Updated

Another major benefit of implementing application proxy is extending Microsoft Entra ID to your on-premises environment. Implementing application proxy can be a key step in moving your organization and apps to the cloud. By moving to the cloud and away from on-premises authentication, you reduce your on-premises footprint and use Microsoft Entra identity management capabilities as your control plane.

24 February 2026

Whats New Archive

Updated

In February 2024, we added the following 10 new applications in our App gallery with Federation support:

20 February 2026

Configure Security

Updated

| [Privileged users sign in with phishing-resistant methods](zero-trust-monitor-detect.md#privileged-users-sign-in-with-phishing-resistant-methods) | Microsoft Entra ID P1 |

13 February 2026

Tokens Overview

Removed

A Microsoft Entra documentation page was updated: Tokens Overview.

7 February 2026

Federation Overview

Removed

A Microsoft Entra documentation page was updated: Federation Overview.

6 February 2026

Sso Overview

Removed

A Microsoft Entra documentation page was updated: Sso Overview.

6 February 2026

Sspr

Removed

A Microsoft Entra documentation page was updated: Sspr.

6 February 2026

Whats New

Updated

Restricted management administrative units enable you to easily restrict access to users, groups, or devices to the specific users or applications you specify. Tenant-level administrators (including Global Administrators) can't modify members of restricted management administrative units unless they're explicitly assigned a role scoped to the administrative unit. This makes it easy to lock down a set of sensitive groups or user accounts in your tenant without having to remove tenant-level role assignments. For more information, see: [Restricted management administrative units in Microsoft Entra ID](../identity/role-based-access-control/admin-units-restricted-management.md).

5 February 2026

Overview

Updated

author: shlipsey3

4 February 2026

Recommendations

Updated

| Group Policy Object (GPO) assigns unprivileged identities to local groups with elevated privileges | Users | Preview | Yes | N/A |

3 February 2026

Whats New

Updated

For guidance, see:

3 February 2026

Security

42

Plan Connect Performance Factors

Updated

Microsoft Entra ID uses throttling to protect the cloud service from denial-of-service (DoS) attacks. Currently Microsoft Entra ID has a throttling limit of 6,000 writes per 5 minutes (72,000 per hour). For example, the following operations can be throttled:

20 February 2026

Authentication

31

Managed Policies

Updated

- [Multifactor authentication for all users](#multifactor-authentication-for-all-users)

21 February 2026

Secretless authentication in Azure

Updated

Learn about secretless authentication in Azure to reduce credential risks, enhance security, and streamline user experience with Zero Trust principles.

20 February 2026

Block Password Addition

Updated

1. Select Restricted Mode, find the **Block addition of new password credentials to apps** setting.

18 February 2026

Whatis Phs

Updated

To use password hash synchronization in your environment, you need to:

7 February 2026

Monitoring

28

Purpose:

Updated

author: omondiatieno

27 February 2026

Anaqua Tutorial

Updated

`https://<SUBDOMAIN>.anaqua.com/anaqua/Public/login.aspx`

20 February 2026

Roles across Microsoft services

Updated

Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services

20 February 2026

Troubleshooting

25

Broken Links in an Application

Updated

Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.

6 February 2026

On Premises Ecma Troubleshoot

Updated

Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.

6 February 2026

Broken Links in an Application

Updated

Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.

4 February 2026

Microsoft identity platform

11

Remove Microsoft Entra role assignments

Updated

Remove role assignments in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.

20 February 2026

Sap Cloud Platform Identity Authentication Provisioning Tutorial

Updated

Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.

10 February 2026

Deactivate an app registration

New

Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.

5 February 2026

Deactivate App Registration

Updated

- [Delete an enterprise application](delete-application-portal.md) for permanent removal

5 February 2026

Sap Cloud Platform Identity Authentication Provisioning Tutorial

Updated

Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.

4 February 2026

Architecture

10

What Is App Proxy

Updated

Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.

4 February 2026

Architecture overview

Updated

Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.

4 February 2026

Conceptual Deployment Plan

Updated

An end-to-end guide for planning the deployment of application proxy within your organization

4 February 2026

Conditional Access

9

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

6 February 2026

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

4 February 2026

Governance

9

Plan cloud HR application to Microsoft Entra user provisioning

Updated

This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.

6 February 2026

Govern the existing users of an application that does not support provisioning in Microsoft Entra ID with Microsoft PowerShell

Updated

Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.

4 February 2026

General

13

Agent Id

Updated

1. Under **Target resources**, select the following options:

27 February 2026

Create an agent identity blueprint

Updated

An [agent identity blueprint](agent-blueprint.md) is used to create agent identities and request tokens using those agent identities. During the process for creating an agent identity blueprint, you set the [owner and sponsor](agent-owners-sponsors-managers.md) of that blueprint, to establish accountability and administrative relationships. You also configure an identifier URI and define a scope for agents created from this blueprint if the agent is designed to receive incoming requests from other agents and users.

20 February 2026

Agent Access Packages

Updated

Agents can then be assigned access packages through three different request pathways.

18 February 2026

Agent Id

Updated

author: shlipsey3

4 February 2026

Agent Lists

Updated

Access Microsoft Entra admin center to effortlessly view and filter agent identities. Streamline tenant oversight and take charge now.

4 February 2026

Agent metadata and discoverability patterns

Updated

Learn how to structure agent metadata for optimal discoverability in Microsoft Entra Agent Registry and understand how the collections model affects agent visibility.

4 February 2026

Manage Agent Blueprint

Updated

This article explains how to manage agent blueprints and registry-only agents using the Microsoft Entra Admin Center.

4 February 2026

Developer

4

Call Api Azure Services

Updated

Learn how to call Azure services using .NET Azure SDK from an agent using agent identities.

4 February 2026

Register Agents to the Agent Registry

Updated

Learn how to register agents to the Agent Registry in Microsoft Entra Agent ID through automatic registration or manual API calls for agent discovery and management.

4 February 2026

Microsoft identity platform

4

Administrative relationships in Microsoft Entra Agent ID (Owners, sponsors, and managers)

Updated

The Microsoft agent identity platform introduces an administrative model that separates technical administration from business accountability, ensuring operational control and compliance oversight without excessive permissions. This document explains the administrative relationships for Microsoft Entra Agent ID identity types. This guidance applies to [agent identities](/graph/api/resources/agentidentity?view=graph-rest-beta&preserve-view=true), [agent identity blueprints](/graph/api/resources/agentidentityblueprint?view=graph-rest-beta&preserve-view=true), [agent identity blueprint principals](/graph/api/resources/agentidentityblueprintprincipal?view=graph-rest-beta&preserve-view=true), and [agent users](/graph/api/resources/agentuser?view=graph-rest-beta&preserve-view=true). The article covers owners, sponsors, and managers and their importance in maintaining secure operations.

18 February 2026

Call Api Microsoft Graph

Updated

Learn how to call Microsoft Graph API from an agent using agent identities or agent users, including authentication configuration and implementation steps.

4 February 2026

What Is Agent Id Platform

Updated

Learn about the Microsoft Agent Identity Platform, a comprehensive identity, and authorization framework designed specifically for AI agents. Key concepts include agent registry, authentication protocols, tokens, claims, and agent discovery capabilities.

4 February 2026

Fundamentals

3

What Is Agent Id

Updated

Learn about agent identities, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.

4 February 2026

What Is Agent Registry

Updated

Learn about the Agent Registry, a centralized metadata repository that enables agent discovery, and secure communication in enterprise environments.

4 February 2026

Standards

3

Agent Autonomous App Oauth Flow

Updated

Learn how agent identities operate autonomously without user context using app-only protocol with OAuth 2.0 client credentials flows.

4 February 2026

Agent On Behalf Of Oauth Flow

Updated

Learn how agent applications operate on behalf of signed-in users using OAuth 2.0 On-Behalf-Of flows with agent identity blueprints and agent identities.

4 February 2026

Agent User Oauth Flow

Updated

Learn how agent identities operate with user context through agent users using the agent user impersonation protocol with OAuth 2.0 token exchange.

4 February 2026

Authentication

1

Agent Identities

Updated

Learn about agent identities in Microsoft Entra ID, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.

4 February 2026

Conditional Access

1

Security

1

Call Api Custom

Updated

Learn how to call custom protected APIs from an agent using different approaches including IDownstreamApi, MicrosoftIdentityMessageHandler, and IAuthorizationHeaderProvider.

4 February 2026

Troubleshooting

1

Preview Known Issues

Updated

Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.

4 February 2026

Security

17

Identity Risk Management Agent

Updated

Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.

11 February 2026

Fundamentals

15

ID Protection Risk Reports

Updated

Learn how to access, filter, and use the Microsoft Entra ID Protection risk reports to mark users and sign-ins as risky or confirmed compromised.

11 February 2026

Risk detection types and levels

Updated

Learn about risk detections and risk levels, including the difference between real-time and offline detections.

11 February 2026

What are risk detections?

Updated

Explore the full list of risk detections and their corresponding risk event types, along with a description of each risk event type.

11 February 2026

Authentication

2

Monitoring

2

Troubleshooting

2

Remediate risks and unblock users

Updated

Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.

11 February 2026

Governance

155

Delegated workflow management

Updated

Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.

25 February 2026

Use Custom attribute triggers in lifecycle workflows

Updated

Lifecycle Workflows allows you to trigger workflows to run automatically for users that meet the execution conditions of the workflow. There are many default attributes that you can use to trigger workflows, but sometimes you might require triggering a workflow based on a specific attribute not offered by default. Using custom attribute triggers, you can trigger a workflow to run for users based on when they move within your organization based on:

25 February 2026

Services And Integration Partners Governance

Updated

|[Edgile, a Wipro company](https://aka.ms/EdgileEntraIDGov) |"Edgile, a Wipro company is excited to be a Microsoft Launch Partner for Microsoft Entra ID Governance. Our deep and broad experience in IGA and security will ensure your project is a success. Our project accelerators will reduce your risk and deliver results faster." |

20 February 2026

Entitlement Management Dynamic Approval

Updated

:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::

18 February 2026

Entitlement Management Roles

Updated

First, call [Create accessPackageResourceRequest](/graph/api/entitlementmanagement-post-resourcerequests?tabs=http) to add the Microsoft Entra role as a resource to the catalog.

18 February 2026

Access Reviews Faqs

Updated

Once an access review starts, you can use the [contactedReviewers](/graph/api/resources/accessreviewreviewer) API to retrieve the list of all users who were, or would have been, notified via email to perform reviews. Even in scenarios where notifications were turned off, the API still provides the list of reviewers along with timestamps indicating when notification would happen.

18 February 2026

Entitlement Management Access Package Resources

Updated

:::image type="content" source="media/entitlement-management-access-package-create/api-permissions-roles.png" alt-text="Screenshot of adding API permissions as resource roles to an access package.":::

18 February 2026

Microsoft Entra Id Governance Licensing For Guest Users

Updated

Guest users are only billed when they actively use features that are exclusive to Microsoft Entra ID Governance. Microsoft Entra P2 features are not billed, and linking an Azure subscription is not required or enforced for P2 actions. Additionally, if a guest doesn't take any active governance-related action during a month, such as in cases where access was auto-assigned in a prior month, they won't be billed for that month.

14 February 2026

Entitlement Management Delegate

Updated

| Catalog owner | `ae79f266-94d4-4dab-b730-feca7e132178` | Edit and manage access packages and other resources in a catalog. Typically an IT administrator or resource owners, or an identity who the catalog owner chooses. |

6 February 2026

Govern access for applications in your environment

Updated

Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.

4 February 2026

Govern access with an organizational role model

Updated

Microsoft Entra ID Governance allows you to model organizational roles using access packages, so you can migrate your existing role definitions to entitlement management.

4 February 2026

Migrate identity management scenarios from SAP IDM to Microsoft Entra

Updated

Learn the detailed steps for how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and provision those identities with access to SAP ECC, SAP S/4HANA, and other SAP and non-SAP applications, for organizations that were previously using SAP IDM.

4 February 2026

Pim Powershell Migration

Updated

The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.

4 February 2026

Check Status Workflow

Updated

This article guides a user on checking the status of a Lifecycle workflow

4 February 2026

Check Workflow Insights

Updated

Learn how to check workflow insights within your Microsoft Entra tenant.

4 February 2026

Customize Workflow Email

Updated

Get a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.

4 February 2026

Governance Service Limits

Updated

This article details service limits for offerings within Microsoft Entra ID Governance

4 February 2026

Groups Activate Roles

Updated

Learn how to activate your group membership or ownership in Privileged

4 February 2026

Lifecycle Workflow Tasks

Updated

This article guides a user on Workflow task definitions and task parameters.

4 February 2026

Manage access to your SAP applications

Updated

Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.

4 February 2026

Manage access with access reviews

Updated

Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.

4 February 2026

Manage Workflow On Premises

Updated

A how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.

4 February 2026

Manage Workflow Properties

Updated

This article guides a user to editing a workflow's properties using Lifecycle Workflows.

4 February 2026

Manage Workflow Tasks

Updated

This article guides a user on managing workflow versions with Lifecycle Workflows.

4 February 2026

On Demand Workflow

Updated

This article guides a user to running a workflow on demand using Lifecycle Workflows.

4 February 2026

Pim Apis

Updated

Information for understanding the APIs in Microsoft Entra Privileged

4 February 2026

Pim Roles

Updated

Describes the roles you can't manage in Microsoft Entra Privileged Identity

4 February 2026

Provision Ldap

Updated

This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.

4 February 2026

Provision Sap

Updated

This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.

4 February 2026

Provision Sql

Updated

This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host

4 February 2026

Reprocess Workflow

Updated

This article guides a user on reprocessing workflow runs using Lifecycle Workflows

4 February 2026

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

4 February 2026

Entitlement Management Ticketed Provisioning

Updated

Scenario: In this scenario you learn how to use custom extensibility, and a Logic App, to automatically generate ServiceNow tickets for manual provisioning of users who have received assignments and need access to apps.

3 February 2026

Fundamentals

22

Entitlement Management Scenarios

Updated

You can also manage access packages, catalogs, policies, requests, and assignments using Microsoft Graph. A user in an appropriate role with an application that has the delegated `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` permission can call the [entitlement management API](/graph/api/resources/entitlementmanagement-overview). For more information, see the [Tutorial: manage access to resources - Microsoft Graph](/graph/tutorial-access-package-api?toc=/azure/active-directory/governance/toc.json&bc=/azure/active-directory/governance/breadcrumb/toc.json). An application with the `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` application permissions can also use many of those API functions, except for managing resources in catalogs and access packages. An application that only needs to operate within specific catalogs can be added to the **Catalog owner** or **Catalog reader** roles of a catalog to be authorized to update or read within that catalog.

18 February 2026

Microsoft Entra ID Governance

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

4 February 2026

What are access reviews? - Microsoft Entra

Updated

Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.

4 February 2026

Lifecycle Workflow On Premises

Updated

Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.

4 February 2026

What is entitlement management?

Updated

Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external identities.

4 February 2026

Architecture

3

Pim Deployment Plan

Updated

You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.

20 February 2026

Troubleshooting

2

Conditional Access

1

General

88

Migrate Users

Updated

Learn how to migrate users from another identity provider to Microsoft Entra External ID.

7 February 2026

Add and manage admin accounts

Updated

Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.

7 February 2026

Add custom attributes

Updated

Learn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.

7 February 2026

Add Facebook as an identity provider

Updated

Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.

7 February 2026

Allow or Block Invitations

Updated

Learn how an administrator creates a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.

7 February 2026

Applies To External Only

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to external tenants.](../media/common/applies-to-yes.png) External tenants ([learn more](/entra/external-id/tenant-configurations))

7 February 2026

Applies To Ios Macos

Updated

**Applies to**: ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) iOS (Swift) ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) macOS (Swift)

7 February 2026

Applies To Workforce Only

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to workforce tenants.](../media/common/applies-to-yes.png) Workforce tenants ([learn more](/entra/external-id/tenant-configurations))

7 February 2026

B2B Direct Connect Setup

Updated

Learn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.

7 February 2026

Bulk invite B2B users

Updated

Learn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.

7 February 2026

Configure external collaboration

Updated

Learn how to configure external collaboration settings in Microsoft Entra External ID. Control guest user access, specify who can invite guests, and manage domain restrictions for B2B collaboration.

7 February 2026

Cross Cloud Settings

Updated

Enable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.

7 February 2026

Dynamic groups setup

Updated

Learn how to create and manage dynamic membership groups in Microsoft Entra External ID. Set rules based on user attributes to automate group membership for B2B collaboration.

7 February 2026

External ID pricing

Updated

Learn about the pricing structure for Microsoft Entra External ID. Understand the monthly active users (MAU) billing model, core offering, and premium add-ons. Link your tenant to an Azure subscription for proper billing and feature access.

7 February 2026

Frequently asked questions

Updated

Find answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.

7 February 2026

Google identity provider

Updated

Learn how to add Google as an identity provider in Microsoft Entra External ID. Enable customers to sign in with their Google accounts and configure Google federation for seamless access.

7 February 2026

Leave an Organization

Updated

As a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.

7 February 2026

Tenant configurations

Updated

Learn about tenant configurations in Microsoft Entra External ID. Understand the differences between workforce and external tenants, and how to configure them for your organization's needs.

7 February 2026

Use Microsoft Accounts

Updated

Enable your external business partners and guest users to use their Microsoft Account (MSA) to sign in to your apps for B2B collaboration.

7 February 2026

Use Microsoft Entra Accounts

Updated

Enable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.

7 February 2026

Redemption Experience

Updated

When you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) that's initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.

6 February 2026

B2b Quickstart Add Guest Users Portal

Updated

If you don’t have an Azure subscription, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin.

6 February 2026

Authentication

29

Email OTP

Updated

Self-service password reset (SSPR) in Microsoft Entra External ID gives customers the ability to change or reset their password, with no administrator or help desk involvement. If a customer's account is locked or they forget their password, they can follow prompts to unblock themselves and get back to work.

28 February 2026

Sign In Alias

Updated

You can set a custom regular expression for input validation by configuring the `validationRegEx` for the username attribute. This setting isn't currently available in the admin center UI, but you can configure it using Microsoft Graph. To set this value, use the [authenticationAttributeCollectionInputConfiguration](/graph/api/resources/authenticationattributecollectioninputconfiguration) resource type. For reference, see the example on [updating the page layout of a self-service sign up user flow](/graph/api/authenticationeventsflow-update#example-2-update-the-page-layout-of-a-self-service-sign-up-user-flow).

25 February 2026

Add multifactor authentication (MFA) to a customer app

Updated

Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.

7 February 2026

B2B guest user properties

Updated

Learn about the properties of a B2B guest user in Microsoft Entra External ID. Understand user types, authentication methods, and how to manage guest user access and permissions.

7 February 2026

Customize the browser language

Updated

Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.

7 February 2026

Email one-time passcode authentication

Updated

Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.

7 February 2026

Training, demos, and videos

Updated

Explore Microsoft Entra External ID training, live demos, and videos. Learn to create secure sign-up experiences and protect access with multifactor authentication.

7 February 2026

Tutorial - multifactor authentication for B2B

Updated

In this tutorial, learn how to require multifactor authentication when you use Microsoft Entra B2B to collaborate with external users and partner organizations.

7 February 2026

About B2B Invitations

Updated

Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.

7 February 2026

Add an application to a user flow

Updated

Learn how to add an application to a user flow to associate the application with a sign-up and sign-in user experience. Get guidance for updating the application configuration with application registration and tenant information.

7 February 2026

Add Azure AD B2C for customer sign-in

Updated

Learn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

7 February 2026

Add Facebook for customer sign-in

Updated

Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.

7 February 2026

Create a User Flow

Updated

Add sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.

7 February 2026

Define custom attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

7 February 2026

External Tenant Quickstart

Updated

In this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.

7 February 2026

Invite internal users to B2B collaboration

Updated

If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can change to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials or sign-in. Use either PowerShell or the Microsoft Graph invitation API.

7 February 2026

Quickstart: Add a guest user with PowerShell

Updated

In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.

7 February 2026

Sign in with alias

Updated

Learn how to Sign in with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

7 February 2026

Test a user flow

Updated

Learn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.

7 February 2026

Visual Studio Code extension for External ID

Updated

Learn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.

7 February 2026

Developer

24

Add an enterprise application

Updated

Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.

7 February 2026

Add attributes to token claims

Updated

Learn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.

7 February 2026

Using role-based access control for apps

Updated

Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.

7 February 2026

Fundamentals

24

Multifactor Authentication Customers

Updated

SMS is available at an additional cost for second-factor verification and for self-service password reset in external tenants. It isn't currently supported for first-factor authentication.

28 February 2026

Supported Features Customers

Updated

| **Roles and administrators**| [Roles and administrators](~/fundamentals/how-subscriptions-associated-directory.md) are fully supported for administrative and user accounts. | Roles are supported for all users. All users in an external tenant have [default permissions](reference-user-permissions.md) unless they’re assigned an [admin role](how-to-manage-admin-accounts.md).|

28 February 2026

Bring Your Own Device

Updated

| Windows Microsoft Entra Registered device | User selects a tenant at first sign-in; remains connected to that tenant. | ❌ | ❌ | ❌ | ✅ | Cannot switch to other registered tenants for now. Allows user to switch to a resource tenant using external user access(B2B). |

20 February 2026

Security Features in External Tenants

Updated

Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.

7 February 2026

Tokens Overview

Updated

Microsoft Entra ID supports two tenant configurations: A workforce configuration that's intended for internal use and manages employees and business guests, and a [customer configuration](/entra/external-id/customers/concept-supported-features-customers) which is optimized for isolating consumers and partners in a restricted external-facing directory. While the underlying identity service is identical for both tenant configurations, the sign in domains and token issuing authority for external tenants is different. This allows applications to keep workforce and external ID workflows separated if needed.

7 February 2026

Custom authentication extensions

Updated

Learn how to use custom authentication extensions in Microsoft Entra External ID. Integrate with external systems, add custom logic to authentication flows, and enhance user experiences.

7 February 2026

Workforce Tenant Overview

Updated

Learn about B2B collaboration for sharing apps with external identities, business partners, and guests, using External ID for authentication and identity access management.

7 February 2026

B2b Guest Access

Updated

> This information relates to a prerelease product that might be substantially modified before its release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

7 February 2026

B2B direct connect Microsoft Entra overview

Updated

Microsoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.

7 February 2026

Cross-tenant access overview

Updated

Learn how to manage cross-tenant access in Microsoft Entra External ID. Configure B2B collaboration and direct connect settings to control access and trust for external organizations.

7 February 2026

External Tenant Features

Updated

Compare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.

7 February 2026

External Tenant Overview

Updated

Learn how Microsoft Entra External ID provides to manage your external identities scenarios, including guest user access and customer identity and access management (CIAM) for apps.

7 February 2026

MFA in external tenants

Updated

Learn about using MFA to secure apps in your external tenant and enabling email one-time passcodes (EOTP) or SMS as a second verification method for sign-up and sign-in.

7 February 2026

Microsoft Entra External ID overview

Updated

Microsoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.

7 February 2026

Plan a CIAM Deployment

Updated

Discover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.

7 February 2026

Self-service sign-up

Updated

Learn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.

7 February 2026

User Attributes

Updated

User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.

7 February 2026

B2b Guest Access

Updated

Learn how Global Secure Access enables secure B2B guest access for external partners through the Global Secure Access client and Azure Virtual Desktop.

4 February 2026

Standards

12

Direct Federation

Updated

- Review the configuration considerations in [SAML/WS-Fed identity providers](direct-federation-overview.md).

27 February 2026

Migrate Passwords Just In Time

Updated

**Password complexity mismatch in Native Auth**: During a Native Auth flow, if a user enters a password that is correct according to the legacy identity provider but is considered weak by External ID password complexity standards an error is returned instead of redirecting to SSPR.

7 February 2026

Whats New

Updated

We are pleased to announce the general availability of client credentials in Entra External ID. The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. Permissions are granted directly to the application itself by an administrator.

7 February 2026

Add a SAML/WS-Fed identity provider

Updated

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

7 February 2026

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

7 February 2026

Identity providers for external tenants

Updated

Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.

7 February 2026

Register a SAML app

Updated

Learn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.

7 February 2026

SAML/WS-Fed federation for self-service sign-up

Updated

Set up direct federation with SAML 2.0 or WS-Fed identity providers (IdP) and enable self-service sign-up for external users, who can sign in with their own work accounts.

7 February 2026

Set up AD FS federation

Updated

Learn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.

7 February 2026

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

7 February 2026

Security

5

Fraud Protection Integration

Updated

Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.

7 February 2026

Microsoft identity platform

4

Disable Sign Up User Flow

Updated

Disable sign-up in your user flow with Microsoft Graph API. Prevent new registrations and allow only sign-in for your external users.

7 February 2026

Reset guest redemption status

Updated

Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.

7 February 2026

Provisioning

4

Monitoring

2

Troubleshooting

2

Troubleshoot B2B issues

Updated

Learn how to troubleshoot common issues with Microsoft Entra B2B collaboration. Resolve guest sign-in errors, direct connect access problems, policy update failures, and encrypted email access issues.

7 February 2026

Architecture

1

10 Secure Local Guest

Updated

Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)

18 February 2026

Branding

1

General

12

Data Storage And Privacy

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

4 February 2026

Manage Internet Access Profile

Updated

Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.

4 February 2026

Points Of Presence

Updated

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.

4 February 2026

Fundamentals

5

Configure Web Content Filtering

Updated

Create a Conditional Access policy for end users or groups and deliver your security profile through Conditional Access Session controls. Conditional Access is the delivery mechanism for user and context awareness for Internet Access policies. To learn more about session controls, see [Conditional Access: Session](/azure/active-directory/conditional-access/concept-conditional-access-session).

20 February 2026

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

4 February 2026

Internet Access

Updated

Learn about how Microsoft Entra Internet Access secures access to the Internet.

4 February 2026

Conditional Access

2

Configure Web Content Filtering

Updated

Microsoft Entra Internet Access's first Secure Web Gateway (SWG) features include web content filtering based on domain names. Microsoft integrates granular filtering policies with Microsoft Entra ID and Microsoft Entra Conditional Access, which results in filtering policies that are user-aware, context-aware, and easy to manage.

27 February 2026

Monitoring

1

Event Enrichment Logs

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

4 February 2026

Provisioning

1

userimpact: Low

Updated

Global Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.

11 February 2026

Security

1

Configure Cloud Firewall

Updated

Learn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.

4 February 2026

General

18

Enable Intelligent Local Network

Updated

Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.

10 February 2026

Enable Multi Geo

Updated

Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.

10 February 2026

Ciphers

Updated

Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.

4 February 2026

Configure Connectors

Updated

Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.

4 February 2026

Configure Domain Controllers

Updated

Learn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.

4 February 2026

Configure Quick Access

Updated

Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.

4 February 2026

Enable Multi Geo

Updated

Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.

4 February 2026

Manage Private Access Profile

Updated

Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.

4 February 2026

Fundamentals

4

Learn about Microsoft Entra Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

10 February 2026

Connector Groups

Updated

Learn how Microsoft Entra private network connector groups work, and how Microsoft Entra Private Access and application proxy use them.

4 February 2026

Connectors

Updated

Learn how Microsoft Entra private network connectors work and how Microsoft Entra Private Access and application proxy use them.

4 February 2026

Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

4 February 2026

Developer

3

Configure Per App Access

Updated

Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.

4 February 2026

Source IP anchoring with Global Secure Access

Updated

Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.

4 February 2026

Security

2

Conditional Access

1

Security

17

Admin Api

Updated

Learn how to manage your verifiable credential deployment using Admin API.

11 February 2026

Use Quickstart

Updated

In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.

4 February 2026

General

14

Rotate signing keys

Updated

Learn how to rotate Microsoft Entra Verified ID signing keys.

11 February 2026

Upgrade signing keys

Updated

Learn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.

11 February 2026

Dnsbind

Updated

Learn how to link your domain to your decentralized identifier (DID).

4 February 2026

Architecture

4

Developer

2

Vc Network Api

Updated

Learn how to use the Microsoft Entra Verified ID Network API

11 February 2026

Authentication

1

Troubleshooting

1

Error Codes

Updated

Reference of error codes for Microsoft Entra Verified ID APIs

11 February 2026

General

9

Managed Identities Status

Updated

| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |

18 February 2026

Authentication

1

Microsoft identity platform

1

Security

1

Workload Identity Federation

Updated

Learn how workload identify federation enables secure access to Microsoft Entra protected resources from external software workloads without managing secrets.

17 February 2026

General

86

Configure Web Content Filtering

Updated

1. Enter a name, select a [web category](reference-web-content-filtering-categories.md), a valid URL (Preview), or a valid FQDN, and then select **Add**.

24 February 2026

Compliant Network

Updated

> * Internet resources with Global Secure Access

18 February 2026

Install Windows Client

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](/azure/active-directory/roles/permissions-reference#global-secure-access-administrator).

12 February 2026

Macos Client Release History

Updated

Track the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.

10 February 2026

Ciphers

Updated

author: HULKsmashGithub

10 February 2026

Remote Network Resilience

Updated

This article provides techniques to improve remote network resilience with Global Secure Access.

10 February 2026

Secure Web Ai Gateway Agents

Updated

Learn how to configure Secure Web and AI Gateway for Microsoft Copilot Studio agents using Global Secure Access.

10 February 2026

The Global Secure Access Client for Android

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Android client app.

10 February 2026

The Global Secure Access Client for macOS

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.

10 February 2026

The Global Secure Access Client for Windows

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.

10 February 2026

China User Support

Updated

Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.

4 February 2026

Create Remote Networks

Updated

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

4 February 2026

List Remote Networks

Updated

Learn how to list remote networks for Global Secure Access.

4 February 2026

Manage Microsoft Profile

Updated

Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.

4 February 2026

Manage Remote Networks

Updated

Learn how to update and delete remote networks for Global Secure Access.

4 February 2026

Quickstart Install Client

Updated

Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.

4 February 2026

Quickstart Per App Access

Updated

Learn how to configure per-app access to private resources in Global Secure Access.

4 February 2026

Quickstart Quick Access

Updated

Learn how to configure Quick Access to private resources in Global Secure Access.

4 February 2026

Remote Network Configurations

Updated

Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.

4 February 2026

Role Based Permissions

Updated

Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.

4 February 2026

Install Windows Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.

3 February 2026

Fundamentals

32

External User Access

Updated

To enable external user access with the Global Secure Access client, you must have:

23 February 2026

Bring Your Own Device

Updated

| Platform/device state | Connection target | Entra tunnel | M365 tunnel | Internet tunnel | Private tunnel | Notes |

19 February 2026

Alerts

Updated

Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.

10 February 2026

Application Usage Analytics

Updated

Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.

10 February 2026

Transport Layer Security

Updated

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

10 February 2026

What is Global Secure Access?

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

10 February 2026

Edr Antivirus Coexistence

Updated

Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.

10 February 2026

Netskope Integration

Updated

Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.

10 February 2026

Partner Ecosystem Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

10 February 2026

Transport Layer Security

Updated

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

4 February 2026

What Is Global Secure Access

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

4 February 2026

Alerts

Updated

ai-usage: ai-assisted

4 February 2026

Microsoft Traffic Profile

Updated

Learn about the capabilities and traffic handling in the Microsoft traffic profile

4 February 2026

Partner Ecosystems Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

4 February 2026

Remote Network Connectivity

Updated

Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.

4 February 2026

Traffic Dashboard

Updated

Monitor the health and status of your network traffic with the Global Secure Access dashboard.

4 February 2026

Traffic Forwarding

Updated

Learn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.

4 February 2026

Security

24

userimpact: Low

Updated

Comprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. If you don't deploy the Global Secure Access client to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.

11 February 2026

Find Microsoft Services Partners

Updated

Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.

10 February 2026

Powershell Open Secure Sockets Layer

Updated

Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.

10 February 2026

Sentinel Integration

Updated

Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.

10 February 2026

Transport Layer Security

Updated

Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.

10 February 2026

Full Data Loss Protection

Updated

Learn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.

10 February 2026

Cisco Coexistence

Updated

Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.

4 February 2026

Palo Alto Coexistence

Updated

Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.

4 February 2026

Powershell Open Secure Sockets Layer

Updated

Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.

4 February 2026

Transport Layer Security

Updated

Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.

4 February 2026

Troubleshooting

22

Troubleshoot App Access

Updated

Learn how to troubleshoot application access problems with the Global Secure Access Windows client.

10 February 2026

Troubleshoot Distributed File System

Updated

A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.

4 February 2026

Monitoring

13

Find Microsoft Services Partners

Updated

| **[BEMO](https://aka.ms/BemoSSELaunchPartner)** | BEMO is a trusted expert in delivering Microsoft's SSE solution to SMBs across the United States with up to 1,000 employees. BEMO specializes in Modern Work and Security, helping SMBs achieve their security and compliance (SOC 2, CMMC, ISO 27001, NIST 800-171, HIPAA) goals by leveraging Microsoft technologies. |

20 February 2026

Global Secure Access network traffic logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

10 February 2026

Access Audit Logs

Updated

Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.

4 February 2026

View Traffic Logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

4 February 2026

Remote Network Health Logs

Updated

Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.

4 February 2026

Use Workbooks

Updated

Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.

4 February 2026

View Enriched Logs

Updated

Learn how to use enriched Microsoft 365 logs for Global Secure Access.

4 February 2026

Conditional Access

6

Configure Web Content Filtering

Updated

> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.

18 February 2026

Current Known Limitations

Updated

- If you have IP location-based Conditional Access policies targeting non-Microsoft resources, don't enable strict location enforcement.

10 February 2026

Quickstart Remote Network

Updated

Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.

4 February 2026

Developer

6

Configure Quick Access

Updated

> You can add up to 500 application segments to your Quick Access app.

18 February 2026

Configure Domain Controllers

Updated

1. On the application settings page, Quick Access in this example, select **Users and groups**.

14 February 2026

Standards

1

Troubleshooting

1