Month in brief

What changed in March

643 documentation updates and 5 Message Center announcements were tracked during March. Activity centred on General, Fundamentals, and Authentication, with the most changes affecting Entra ID and Global Secure Access.

648 updates by product

Fundamentals

73

Whats New

Updated

**What’s changing**

25 March 2026

Filter For Applications

Updated

Follow the instructions in the article, [Add or deactivate custom security attributes in Microsoft Entra ID](~/fundamentals/custom-security-attributes-add.md) to add the following **Attribute set** and **New attributes**.

24 March 2026

Conditional Access Cloud Apps

Updated

Microsoft 365 offers cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. In Conditional Access, the Microsoft 365 suite of applications appears under 'Office 365'. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration might cause confusion when creating policies because some apps, like Microsoft Teams, depend on others, like SharePoint or Exchange.

24 March 2026

Authentication Flows

Updated

If you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, selecting the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.

24 March 2026

Conditional Access Users Groups

Updated

To prevent admin lockout, when creating a policy applied to **All users** and **All apps**, the following warning appears.

24 March 2026

Plan Conditional Access

Updated

- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).

24 March 2026

Policy All Users Approved App Or App Protection

Updated

With Conditional Access, organizations can restrict access to [approved (modern authentication capable) client apps with Intune app protection policies](concept-conditional-access-grant.md#require-app-protection-policy). For older client apps that may not support app protection policies, administrators can restrict access to [approved client apps](concept-conditional-access-grant.md#require-approved-client-app).

24 March 2026

Condition Filters For Devices

Updated

There are multiple scenarios that organizations can now enable using filter for devices condition. The following scenarios provide examples of how to use this new condition.

24 March 2026

View Available Backups

Updated

1. Browse to **Backup and recovery**. The **Overview** page shows feature highlights, alerts, and recent activity.

21 March 2026

Whats New

Updated

**Service category:** MFA

21 March 2026

Create New Tenant

Updated

- **Delegated administration**: Select one or more Microsoft Entra built-in roles and assign them to a role assignable security group in the governing tenant. Members of this group can use their governing tenant credentials to sign in to the governed tenant without needing an account in the governed tenant. Each group can have multiple role assignments, and each policy template can have multiple groups defined.

20 March 2026

Application Gallery

Updated

- **Provisioning** - Microsoft Entra ID to SaaS [application provisioning](~/identity/app-provisioning/user-provisioning.md) refers to automatically creating user identities and roles in the SaaS applications that users need access to.

20 March 2026

What is delegated administration?

Updated

Managing permissions for external partners is a key part of your security posture. The administrator portal experience in Microsoft Entra ID, part of Microsoft Entra, now includes capabilities so that an administrator can see the relationships that their Microsoft Entra tenant has with Microsoft Cloud Service Providers (CSP) who can manage the tenant. This permissions model is called delegated administration. This article introduces the Microsoft Entra administrator to the relationship between the old Delegated Admin Permissions (DAP) permission model and the new [Granular Delegated Admin Permissions (GDAP)](/partner-center/gdap-introduction) permission model.

18 March 2026

Certificate Based Authentication Technical Deep Dive

Updated

:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png" alt-text="Screenshot that shows how to turn on issuer hints." lightbox="media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png":::

18 March 2026

Directory Overview User Model

Updated

You can use groups in Microsoft Entra ID to assign licenses, or deployed enterprise apps, to large numbers of users. You can also use groups to assign all administrator roles except for Microsoft Entra Global Administrator, or you can grant access to external resources, such as SaaS applications or SharePoint sites.

18 March 2026

Associate or add an Azure subscription to your Microsoft Entra tenant

Updated

All Azure subscriptions have a trust relationship with a Microsoft Entra tenant. Subscriptions rely on this tenant (directory) to authenticate and authorize security principals and devices. When a subscription expires, the trusted instance remains, but the security principals lose access to Azure resources. Subscriptions can only trust a single directory while one Microsoft Entra tenant might be trusted by multiple subscriptions.

17 March 2026

Licensing

Updated

This article discusses licensing options for the Microsoft Entra product family. It's intended for security decision makers, identity and network access administrators, and IT professionals who are considering Microsoft Entra solutions for their organizations.

17 March 2026

Define the Group ID

Updated

> A new bulk operations experience is now available in preview that provides enhanced performance and removes scaling limitations for large tenants. For more information, see [Bulk operations in Microsoft Entra ID (Preview)](bulk-operations.md).

17 March 2026

Whats New Overview

Updated

The **Roadmap** tab lists the details of public preview and recent general availability releases in a sortable table. From the table, you can select a release to view the release **Details**, which includes an overview and a link to learn more.

17 March 2026

Manage User Profile Info

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](../identity/role-based-access-control/permissions-reference.md#user-administrator).

17 March 2026

Add Custom Domain

Updated

1. Create your new directory by following the steps in [Create a new tenant for your organization](./create-new-tenant.md#create-a-new-tenant-for-your-organization).

17 March 2026

Reset a user's password

Updated

Administrators can reset a user's password if the user forgets the password, if the user gets locked out, or if the user never received a password.

17 March 2026

Bulk Operations

Updated

The new bulk operations experience in Microsoft Entra ID provides enhanced capabilities for managing **Groups**, **Devices, Administrative Unit and Role assignments.** This service enables bulk actions including create, update, and delete operations. The improved service delivers better performance, reduces timeouts, and removes scaling limitations for large tenants.

17 March 2026

How to find your tenant ID

Updated

Instructions about how to find your Microsoft Entra tenant ID for an existing Azure subscription.

17 March 2026

Users Restore

Updated

After you delete a user, the account remains in a suspended state for 30 days. During that 30-day window, the user account can be restored, along with all its properties.

17 March 2026

Create New Tenant

Updated

In this quickstart article, you learn how to create a basic tenant for your organization.

17 March 2026

Try Microsoft Entra Suite

Updated

Welcome to the Microsoft Entra Suite trial user guide. Make the most of your free trial by discovering the robust and comprehensive capabilities of [Microsoft Entra](what-is-entra.md).

17 March 2026

Get Started Premium

Updated

You can purchase and associate Microsoft Entra ID P1 or P2 editions with your Azure subscription. If you need to create a new Azure subscription, you also need to [activate your licensing plan](#activate-your-new-license-plan) and your [Microsoft Entra ID service access](#activate-your-microsoft-entra-id-access). For information about obtaining a free trial, see [Microsoft Entra ID P2 Trial](https://signup.microsoft.com/get-started/signup?products=FAF849AB-BD30-42B2-856C-8F1EDC230CE9).

17 March 2026

Entra Admin Center

Updated

The Microsoft Entra admin center is organized by product. Access the products through the search bar or left-hand menu.

17 March 2026

Identity data storage for Australian and New Zealand customers in Microsoft Entra ID

Updated

Microsoft Entra ID stores identity data in a location chosen based on the address provided by your organization when subscribing to a Microsoft service like Microsoft 365 or Azure. For information on where your Identity Customer Data is stored, review the Microsoft Trust Center section titled [Where is your data located?](https://www.microsoft.com/trustcenter/privacy/where-your-data-is-located).

17 March 2026

Sign up for Microsoft Entra ID

Updated

Discover how to sign up for Microsoft Entra ID and Azure. Start using enterprise cloud services today.

17 March 2026

System Preferred Multifactor Authentication

Updated

When a user signs in, the authentication process checks which authentication methods are registered for the user. The user is prompted to sign-in with the most secure method according to the following order. The order of authentication methods is dynamic. It's updated as the security landscape changes, and as better authentication methods emerge. Users can always cancel and choose a different available sign in method if needed. If your organization has Conditional Access policies that require specific authentication methods, those policies will continue to take priority over the system preferred MFA order. Click the link for more information about each method.

14 March 2026

What Is Cloud Sync

Updated

Cloud Sync solves common challenges organizations face with hybrid identity infrastructure by eliminating single points of failure, reducing on-premises management overhead, and enabling complex multi-forest scenarios that support organizational growth and change.

14 March 2026

Native Authentication

Updated

The following table shows the availability of features for browser-delegated and native authentication.

13 March 2026

Whats New

Updated

**Service category:** Entra Connect

13 March 2026

Configure Security

Updated

| [TLS inspection is enabled and correctly configured for outbound traffic](zero-trust-protect-networks.md#tls-inspection-is-enabled-and-correctly-configured-for-outbound-traffic) | Microsoft Entra ID P1 |

12 March 2026

Overview

Updated

:::image type="content" source="media/overview/conditional-access-overview.png" alt-text="Screenshot of the Conditional Access overview page." lightbox="media/overview/conditional-access-overview.png":::

7 March 2026

Whats New

Updated

**Note:** Currently, the new Bulk Operations service supports **Groups**, **Devices**, and **User Export** only. Support for additional entities, such as **Enterprise Applications**, is coming soon. For more information, see: [Bulk operations in Microsoft Entra ID (Preview)](../fundamentals/bulk-operations.md).

6 March 2026

Token Protection

Updated

- For detailed steps on how to register your device, see [Register your personal device on your work or school network](https://support.microsoft.com/account-billing/register-your-personal-device-on-your-work-or-school-network-8803dd61-a613-45e3-ae6c-bd1ab25bf8a8).

6 March 2026

Overview of Microsoft Entra ID Account Recovery

Updated

Learn about Microsoft Entra ID Account Recovery, which enables users to regain access to their accounts through identity verification when they've lost all authentication methods.

4 March 2026

Custom Extension Email Otp Get Started

Updated

- A familiarity and understanding of the concepts covered in [custom authentication extensions](/entra/identity-platform/custom-extension-overview).

4 March 2026

Overview

Updated

Take a look at our short video to learn more about Microsoft Entra Domain Services.

4 March 2026

Configure Security

Updated

Learn how to improve your security posture with Microsoft Entra.

3 March 2026

Zero Trust Protect Networks

Updated

Improve your security posture with the Microsoft Entra Zero Trust assessment to protect networks.

3 March 2026

General

69

Migrate Group Writeback

Updated

- A Microsoft Entra account with at least a [Hybrid Identity administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.

27 March 2026

Clever Tutorial

Updated

<a name='configure-and-test-azure-ad-sso-for-clever'></a>

26 March 2026

My Staff Configure

Updated

After configuring administrative units, you can apply this scope to your users who access My Staff. Only users who are assigned an administrative role can access My Staff. To enable My Staff, complete the following steps:

26 March 2026

Terms Of Use

Updated

* Microsoft Entra ID P1 licenses.

24 March 2026

Review Recovery History

Updated

If a recovery operation partially succeeds, the **Status** column shows **Completed with warnings**, allowing you to identify objects that weren't recovered. Select **Completed with warnings** to view the details of the changes that were not recovered.

21 March 2026

Prerequisites

Updated

- Nested OUs are supported (that is, you **can** sync an OU that has 130 nested OUs, but you **can't** sync 60 separate OUs in the same configuration).

20 March 2026

Groups Dynamic Rule Member Of

Updated

This feature preview in Microsoft Entra ID enables admins to create dynamic membership groups and administrative units that populate by adding members of other groups using the `memberOf` attribute. Apps that couldn't read group-based membership previously in Microsoft Entra ID can now read the entire membership of these new `memberOf` groups. Not only can these groups be used for apps but they can also be used for licensing assignments.

18 March 2026

Users Bulk Download

Updated

1. Select **Users** > **All users** > **Download users**. By default, all user profiles are exported.

18 March 2026

Groups Dynamic Tutorial

Updated

You're not required to assign licenses to the users for them to be members in dynamic membership groups. You only need the minimum number of available Microsoft Entra ID P1 licenses in the organization to cover all such users.

18 March 2026

Bulk create users in Microsoft Entra ID

Updated

Microsoft Entra ID, part of Microsoft Entra, supports bulk user create and delete operations and supports downloading lists of users. Just fill out the comma-separated values (CSV) template you can download from Microsoft Entra ID.

18 March 2026

Groups Bulk Download

Updated

:::image type="content" source="media/bulk-operations/groups-management-page.png" alt-text="Screenshot of the Microsoft Entra admin center Groups blade showing the All groups list with column headers and actions.":::

18 March 2026

Groups Quickstart Naming Policy

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).

18 March 2026

Users Bulk Restore

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

18 March 2026

Groups Bulk Import Members

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).

18 March 2026

Close your work or school account in an unmanaged Microsoft Entra organization

Updated

If you're a user in an unmanaged organization (tenant) in Microsoft Entra ID, and you no longer need to use apps from that organization or maintain any association with it, you can close your account at any time. An unmanaged organization doesn't have an administrator. Users in an unmanaged organization can close their accounts on their own, without contacting an administrator.

18 March 2026

Groups Change Type

Updated

Creating dynamic membership groups eliminates the management overhead of adding and removing users. This article shows you how to convert existing membership groups from static to dynamic, by using either the Azure portal or PowerShell cmdlets. In Microsoft Entra, a single tenant can have a maximum of 15,000 dynamic membership groups.

18 March 2026

Groups Members Owners Search

Updated

On the **All groups** page, when you enter a search string, you can toggle between **contains** and **starts with** searches on the **All groups** page only.

18 March 2026

Groups Saasapps

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

18 March 2026

Whats New Linux

Updated

This article provides information about the latest updates to Microsoft single sign-on for Linux.

17 March 2026

Admin Units Members Add

Updated

To create a new group directly in an administrative unit, use the following request. To add an existing group instead, see **Add groups to an administrative unit** earlier in this article.

10 March 2026

Licensing Group Advanced

Updated

More scenarios limitations, and known issues for Microsoft Entra group-based licensing

7 March 2026

Custom Extension Attribute Collection

Updated

- To use Azure services, including Azure Functions, you need an Azure subscription. If you don't have an existing Azure account, you can sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).

4 March 2026

Custom Extension Tokenissuancestart Configuration

Updated

- An Azure subscription with the ability to create Azure Functions. If you don't have an existing Azure account, sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).

4 March 2026

Get Signed In Identity

Updated

- An Azure account with an active subscription. [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).

4 March 2026

Authentication

49

Stormshield Network Security Tutorial

Updated

This section guides you through the necessary configurations on the **Stormshield Network Security (SNS) firewall** to enable **OIDC authentication** via **Microsoft Entra ID**.

26 March 2026

Privileged Authentication Administrator

Updated

>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

25 March 2026

Howto Conditional Access Session Lifetime

Updated

The system accounts for five minutes of clock skew when **every time** is selected in policy, so users aren’t prompted more often than once every five minutes. If the user completes MFA in the last 5 minutes and encounters another Conditional Access policy that requires reauthentication, we don't prompt the user. Prompting users too often for reauthentication can affect their productivity and increase the risk of users approving MFA requests they didn’t initiate. Use "Sign-in frequency – every time" only when there are specific business needs.

24 March 2026

Policy All Users Copilot Ai Security

Updated

The following steps help create a Conditional Access policy to require all users to perform multifactor authentication using the authentication strength policy.

24 March 2026

Policy Block Legacy Authentication

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Sharing accounts and credentials

Updated

Learn how to configure shared accounts in Microsoft Entra ID using password-based single sign-on so multiple users can securely access apps without sharing passwords directly.

19 March 2026

Github Tutorial

Updated

* You can use Microsoft My Apps. When you select the GitHub tile in the My Apps, this option redirects to GitHub Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).

19 March 2026

Share accounts with Microsoft Entra ID

Updated

In Microsoft Entra ID, part of Microsoft Entra, sometimes organizations need to use a single username and password for multiple people, which often happens in the following cases:

18 March 2026

Get all application proxy apps and list extended information

Updated

PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).

12 March 2026

Howto Authentication Passwordless Security Key Windows

Updated

- OOBE sign-in with a passkey is supported. You can use Web sign-in to unlock a Windows device. For more information, see [Use Web Sign-In To Enable Passwordless Sign-In In Windows](/windows/security/identity-protection/web-sign-in).

11 March 2026

Tutorial: Add SMS one-time passcode MFA to your iOS/macOS app

Updated

This tutorial shows you how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to your iOS/macOS app using native authentication. MFA adds an extra layer of security by requiring a second verification step during sign-in.

7 March 2026

Tutorial: Add Email strong authentication method registration to your Android app

Updated

This tutorial demonstrates how to implement Email strong authentication method registration into your Android app using native authentication. At least one strong authentication is mandatory for multifactor authentication (MFA) enabled users. Currently, we only support Email and SMS one-time passcode as strong authentication method.

7 March 2026

Native Authentication Api

Updated

| `continuation_token` | [Continuation token](#continuation-token) that Microsoft Entra returns. |

7 March 2026

Domains Verify Custom Subdomain

Updated

Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.

7 March 2026

Howto Authentication Temporary Access Pass

Updated

Users with a TAP can navigate the setup process on Windows 10 and 11 to perform device join operations and configure Windows Hello for Business. TAP usage for setting up Windows Hello for Business varies based on the devices joined state.

5 March 2026

Developer

48

Application Proxy Configure Complex Application

Updated

:::image type="content" source="./media/application-proxy-configure-complex-application/complex-app-structure-1.png" alt-text="Diagram of domain structure for a complex application showing resource sharing between primary and secondary application.":::

27 March 2026

Application Proxy Integrate With Remote Desktop Services

Updated

8. Run this command for each collection. Replace *\<yourcollectionname\>* and *\<proxyfrontendurl\>* with your own information. This command enables single sign-on between RD Web and RD Gateway, and optimizes performance.

27 March 2026

Application Proxy Qlik

Updated

Follow the same steps as for Application #1, with the following exceptions:

27 March 2026

Application Proxy Configure Cookie Settings

Updated

Cookies that don't specify the [SameSite](https://web.dev/articles/samesite-cookies-explained) attribute are treated as if they're set to **SameSite=Lax**. The `SameSite` attribute declares how cookies should be restricted to a same-site context. When set to `Lax`, the cookie is only sent to same-site requests or top-level navigation. However, application proxy requires these cookies to be preserved in the third-party context to keep users signed in during their session. Due to the requirement, updates were made:

27 March 2026

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

26 March 2026

Grant Admin Consent

Updated

Learn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.

26 March 2026

Add Application Portal Setup Sso

Updated

- Completion of the steps in [Quickstart: Create and assign a user account](add-application-portal-assign-users.md).

20 March 2026

Review Admin Consent Requests

Updated

For instance, if an application is found to be non-compliant with company policies, an administrator might choose to 'Block' it. Conversely, if an application is legitimate but requires further review, the administrator may opt to 'Deny' the request temporarily while seeking more information.

20 March 2026

Groups Naming Policy

Updated

You can use attributes that can help you and your users identify which department, office, or geographic region for which the group was created. For example, if you define your naming policy as `PrefixSuffixNamingRequirement = "GRP [GroupName] [Department]"` and `User's department = Engineering`, then an enforced group name might be `"GRP My Group Engineering."` Supported Microsoft Entra attributes are `\[Department\]`, `\[Company\]`, `\[Office\]`, `\[StateOrProvince\]`, `\[CountryOrRegion\]`, and `\[Title\]`. Unsupported user attributes are treated as fixed strings. An example is `"\[postalCode\]"`. Extension attributes and custom attributes aren't supported.

18 March 2026

Users Revoke Access

Updated

Access tokens and refresh tokens are frequently used with thick client applications, and also used in browser-based applications such as single page apps.

18 March 2026

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

12 March 2026

Provisioning

34

Tap App Security Provisioning Tutorial

Updated

1. After entering the domain, a new line in the table appears showing domain name and its status as **initialize**. Select the gear icon to reveal technical data about TAP app Security server and to complete initialization.

27 March 2026

Provision Microsoft Entra ID to Active Directory - Configuration

Updated

The following document will guide you through configuring Microsoft Entra Cloud Sync for provisioning groups from Microsoft Entra ID to Active Directory. If you are looking for information on provisioning from AD to Microsoft Entra ID, see [Configure - Provisioning Active Directory to Microsoft Entra ID using Microsoft Entra Cloud Sync](how-to-configure.md).

20 March 2026

Looop Provisioning Tutorial

Updated

![Screenshot of the Manage options with the Provisioning option called out.](common/provisioning.png)

19 March 2026

Open Text Directory Services Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

17 March 2026

G Suite Provisioning Tutorial

Updated

1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).

13 March 2026

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

This article describes the steps you need to perform in both GitHub Enterprise Managed User (OIDC) and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to GitHub Enterprise Managed User (OIDC) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

13 March 2026

Connect Version History

Updated

- Fixed a [known issue](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified) where auto-upgrade could stop your Microsoft Entra Connect server unexpectedly. Auto-upgrade now detects modifications to the `miiserver.exe.config` and `miisclient.exe.config` configuration files and skips automatic upgrade on those servers. If you manually upgrade and previously modified these configuration files, you might encounter installation failures. To resolve the issue, see the [known issues section](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified).

12 March 2026

Citrixgotomeeting Provisioning Tutorial

Updated

This section guides you through connecting your Microsoft Entra ID to GoToMeeting's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in GoToMeeting based on user and group assignment in Microsoft Entra ID.

6 March 2026

Gpad Prereqs

Updated

- The provisioning agent must be installed on a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016.

5 March 2026

Conditional Access

26

Microsoft-managed Conditional Access policies

Updated

Every day, Microsoft processes more than 100 trillion security signals from endpoints, cloud services, identity systems, and more. We use this data shape how we respond to threats and inform how we innovate to help build a safer digital future. Read about the work we're doing in the [Microsoft Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1).

26 March 2026

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

26 March 2026

Migrate Approved Client App

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Agent Block High Risk

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Risk Based Insider Block

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Deployment Guide Token Protection Apple

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Block By Location

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Block Example

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Howto Conditional Access Insights Reporting

Updated

![Screenshot showing a workbook breakdown per condition and status.](./media/howto-conditional-access-insights-reporting/workbook-breakdown-condition-and-status.png)

24 March 2026

Policy All Users App Enforced Restrictions

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Device Compliance

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Device Registration

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Device Unknown Unsupported

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Mfa Strength

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Persistent Browser

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Alt Admin Device Compliand Hybrid

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Alt All Users Compliant Hybrid Or Mfa

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Guests Mfa Strength

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Admin

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Admin Portals

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Azure Mgmt

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Guest

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

12 March 2026

Conditional Access Agent Optimization Phased Rollout

Updated

Once you start a phased rollout, the agent helps you progress. The phased rollout suggestion is present throughout the rollout process and can show no action needed, suggest progressing to the next phase, or suggest rolling back.

3 March 2026

Security

17

New M365 group creation and editing in My Groups

New

Microsoft 365 group creation and editing in My Groups will be enhanced by late March 2026, allowing owners to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The update improves control and clarity without impacting existing groups or requiring admin setup.

26 March 2026
Message CenterMC1262589 on mc.merill.net ↗Stay informed

Helpdesk Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

25 March 2026

User Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

25 March 2026

Policy All Users Windows App Protection

Updated

- Policy can be applied to the Microsoft Edge browser on devices running Windows 11 and Windows 10 version 20H2 and higher with KB5031445.

24 March 2026

Security Store In Entra

Updated

Security Store is embedded in the Microsoft Entra admin center, so you can discover and deploy agents and solutions without leaving your identity management workflow.

21 March 2026

Groups Restore Deleted

Updated

User Administrator and Partner Tier 1 Support | Can restore any deleted Microsoft 365 group or cloud security group except those groups assigned to the Global Administrator role

18 March 2026

Groups Settings Cmdlets

Updated

For more information on how to prevent nonadministrator users from creating security groups, set the `AllowedToCreateSecurityGroups` property to False as described in [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy).

18 March 2026

Groups Dynamic Membership

Updated

When you create a dynamic membership rule, the security of that group's membership depends on who can modify the attributes referenced in the rule. Before selecting an attribute, review the write permissions for that attribute—both in Microsoft Entra ID and in any connected source directories.

7 March 2026

Microsoft identity platform

13

Authentication Flows App Scenarios

Updated

To call a web API from a web app on behalf of a user, use the authorization code flow and store the acquired tokens in the token cache. When needed, MSAL refreshes tokens and the controller silently acquires tokens from the cache.

26 March 2026

Apple Sso Plugin

Updated

If your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.

24 March 2026

Conditional Access Conditions

Updated

- Admins can apply policy only to supported platforms (such as iOS, Android, and Windows) through the Conditional Access Microsoft Graph API.

24 March 2026

Microsoft Graph

Updated

To manage custom security attribute assignments for users in your Microsoft Entra organization, you can use PowerShell or Microsoft Graph API. The following examples can be used to manage assignments.

18 March 2026

Tenant inaccessible due to inactivity

Updated

Configured tenants no longer in use might still generate costs for your organization. Making a tenant inaccessible due to inactivity helps reduce unnecessary expenses. This article discusses how to handle an inaccessible tenant, reactivation, and guidance for both administrators and application developers.

17 March 2026

Deactivate an app registration

Updated

Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.

17 March 2026

Msal Compare Msal Js And Adal Js

Updated

Yet another common error you might face is `consent_required`, which occurs when permissions required for obtaining an access token for a protected resource aren't consented by the user. As in `interaction_required`, the solution for `consent_required` error is often initiating an interactive token acquisition prompt, using either `acquireTokenPopup` or `acquireTokenRedirect`.

6 March 2026

Monitoring

11

Application Proxy Network Topology

Updated

Place the connector close to the target application in the customer network. This configuration minimizes step 3 in the topography diagram, because the connector and application are close.

27 March 2026

Permissions Reference

Updated

> | [Compliance Administrator](#compliance-administrator) | Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |

24 March 2026

What If Tool

Updated

Start an evaluation by selecting **What If**. The evaluation result provides you with a report that consists of:

24 March 2026

Create Review Difference Reports

Updated

1. Go to **Backup and recovery** > **Backups**. Select a backup from the list, and then select **Create difference report**.

21 March 2026

Recover Applications

Updated

After you determine the cause of the changes, validate whether the secrets for applications were impacted. Find changes to application secrets in the audit log. Look for events that indicate the application secret was changed or updated.

21 March 2026

Recover Objects

Updated

1. Go to **Backup and recovery** > **Difference reports**. Select a completed difference report.

21 March 2026

Sla Performance

Updated

| Month | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 |

11 March 2026

Reports Data Retention

Updated

**No**, you can't. Azure stores up to seven days of activity data for a free version. When you switch from a free to a premium version, you can only see up to 7 days of data.

5 March 2026

Standards

10

Policy Guests Mfa Strength

Updated

1. Give your policy a name. Create a meaningful standard for the names of your policies.

28 March 2026

Segment Provisioning Tutorial

Updated

1. The Tenant URL is `https://scim.segmentapis.com/scim/v2`. This value is entered in the **Tenant URL** field in the Provisioning tab of your Segment application.

27 March 2026

Snowflake Provisioning Tutorial

Updated

The Microsoft Entra provisioning service currently operates under particular [IP ranges](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md#ip-ranges). If necessary, you can restrict other IP ranges and add these particular IP ranges to the allow list of your application. That technique will allow traffic flow from the Microsoft Entra provisioning service to your application.

27 March 2026

Continuous access evaluation

Updated

Token expiration and refresh are a standard mechanism in the industry. When a client application like Outlook connects to a service like Exchange Online, the API requests are authorized using OAuth 2.0 access tokens. By default, access tokens are valid for one hour, when they expire the client is redirected to Microsoft Entra to refresh them. That refresh period provides an opportunity to reevaluate policies for user access. For example: the token might not be refreshed because of a Conditional Access policy, or because the user is disabled in the directory.

24 March 2026

Tutorial Manage Certificates For Federated Single Sign On

Updated

This section will outline best practices independent software vendors (ISV’s) can adopt to enable automated certificate rollover when SAML certificates are near expiry and when applications federated with Microsoft Entra ID. SAML certificates in Entra ID are used for signing assertions in federated single sign-on (SSO). These certificates expire (typically every 1-3 years) and rotation requires a Customer and SaaS ISV coordination to update a mutual certificate in both systems without downtime. Industry trends are shortening certificate lifetimes, manual rollover processes increasingly create operational burden and risk service disruption — especially in large organizations with many SAML enterprise applications.

12 March 2026

Troubleshooting

6

Troubleshoot Conditional Access

Updated

To get detailed information about the sign-in interruption, review the Microsoft Entra sign-in events to see which Conditional Access policy or policies applied and why.

24 March 2026

Troubleshooting

Updated

**If the difference report is running for a long time:**

21 March 2026

Troubleshoot Alerts

Updated

Upon successful onboarding, Domain Services back fills synchronized users and groups with the onboarded custom attribute values. The custom attribute values appear gradually, depending on the size of the tenant. To check the backfill status, go to [Domain Services Health](check-health.md) and verify the **Synchronization with Microsoft Entra ID** monitor timestamp has updated within the last hour.

17 March 2026

Troubleshoot Application Proxy

Updated

Learn how to troubleshoot common errors and configuration problems with Microsoft Entra application proxy.

11 March 2026

Architecture

3

Recoverability Overview

Updated

- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.

28 March 2026

Governance

2

General

5

Agent Lists

Updated

To view agent identities in your Microsoft Entra tenant, you need:

4 March 2026

Developer

2

Agent ID Setup Instructions

New

This file is used by an AI coding agent (such as GitHub Copilot in VS Code Agent mode) to automate onboarding to Microsoft Entra Agent ID.

12 March 2026

Conditional Access

1

Agent Id

Updated

There are two key business scenarios where Conditional Access policies can help you manage agents effectively.

24 March 2026

Fundamentals

1

Security for AI agents with Microsoft Entra Agent ID

Updated

AI agents are autonomous software systems that can perceive their environment, make decisions, and take action. AI agents can expand organizational capabilities but also introduce security challenges that differ from traditional application security. This introduction explains why AI security matters, the challenges AI agents present, the concept of agent sprawl, and how Microsoft provides security mechanisms for AI agents in enterprise environments.

27 March 2026

Microsoft identity platform

1

Provisioning

1

AI-guided setup for Microsoft Entra Agent ID

New

Use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.

12 March 2026

Security

1

Fundamentals

4

Managed Policies

Updated

This policy covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. High-risk in this case means something about the way the user signed in is out of the ordinary. These high-risk sign-ins might include travel that is highly abnormal, password spray attacks, or token replay attacks. For more information, see [What are risk detections](/entra/id-protection/concept-identity-protection-risks#sign-in-risk-detections).

24 March 2026

Conditional Access Grant

Updated

When user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation with Microsoft-managed remediation (preview)](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control-preview).

21 March 2026

AI Admin RBAC updates

New

The AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Admin involvement for routine tasks. Rollout starts March 2026. AI Admins gain expanded permissions for agent lifecycle management, tenant-wide consent (excluding Microsoft Graph app permissions), and risk monitoring via Identity Protection, enhancing security and compliance.

6 March 2026
Message CenterMC1245636 on mc.merill.net ↗Stay informed

Authentication

2

Security Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

25 March 2026

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

25 March 2026

Security

1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

25 March 2026

Governance

49

Groups Assign Member Owner

Updated

In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.

26 March 2026

Licensing Tenant Governance

Updated

| Feature | Free | Microsoft Entra P1 | Microsoft Entra P2 | Microsoft Entra ID Governance |

20 March 2026

Governance Policy Templates

Updated

- Cross-tenant delegated administration roles - Specify which Microsoft Entra built-in roles users from the governing tenant have in the governed tenant.

20 March 2026

Update Governance Relationship

Updated

This article describes how to update an existing governance relationship between a governing tenant and a governed tenant. You might need to update a governance relationship to add or modify delegated administration roles or multitenant application configurations.

20 March 2026

Create Monitor

Updated

- [Configuration management](configuration-management.md)

20 March 2026

Delegated Administration

Updated

- [Monitor governing tenant admin activity](how-to-monitor-governing-activity.md)

20 March 2026

Enable Tenant Discovery

Updated

- [Review the list of related tenants](related-tenants.md) surfaced by discovery.

20 March 2026

Simulate Workflow Execution

Updated

Learn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.

11 March 2026

Entitlement Management Catalog Create

Updated

1. If you want to allow users in external directories from connected organizations to be able to request access packages in this catalog, set **Enabled for external users** to **Yes**. The access packages must also have a policy allowing users from connected organizations to request. If the access packages in this catalog are intended only for users already in the directory, then set **Enabled for external users** to **No**.

10 March 2026

Perform Access Review

Updated

Microsoft Entra ID simplifies how enterprises manage access to groups and applications in Microsoft Entra ID and other Microsoft web services with a feature called access reviews. This article covers how a designated reviewer performs an access review for members of a group or users with access to an application. If you want to review access to an access package, read [Review access of an access package in entitlement management](entitlement-management-access-reviews-review-access.md).

10 March 2026

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

7 March 2026

Fundamentals

6

Overview

Updated

- Automatically detect tenants that are related to your tenant based on one or more discovery signals.

20 March 2026

Microsoft identity platform

2

Authentication

1

Delegated Administration

Updated

1. After successful sign-in, perform administrative tasks in the governed tenant based on the roles assigned to your security group.

31 March 2026

General

8

Bulk invite B2B users

Updated

Learn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.

28 March 2026

Use Microsoft accounts

Updated

Enable your external business partners and guest users to use their Microsoft account (MSA) to sign in to your apps for B2B collaboration.

28 March 2026

Use Microsoft Entra accounts

Updated

Enable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.

28 March 2026

Cross-cloud settings

Updated

Enable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.

28 March 2026

Clean Up Unmanaged Accounts

Updated

Prior to August 2022, Microsoft Entra B2B supported self-service sign-up for email-verified users. With this feature, users create Microsoft Entra accounts, when they verify email ownership. These accounts were created in unmanaged (or viral) tenants: users created accounts with an organization domain, not under IT team management. Access persists after users leave the organization.

18 March 2026

Cross Cloud Settings

Updated

The following scenarios are supported when collaborating with an organization from a different Microsoft cloud:

6 March 2026

Provisioning

8

Configure cross-tenant synchronization

Updated

Configure cross-tenant synchronization using the Microsoft Entra admin center. Step-by-step guide covering trust settings, provisioning scope, attribute mappings, and testing.

26 March 2026

Known Issues

Updated

- B2B users are unable to manage certain Microsoft 365 services in remote tenants (such as Exchange Online), as there's no directory picker.

6 March 2026

Authentication

4

Email one-time passcode authentication

Updated

Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.

28 March 2026

Define custom attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

28 March 2026

Tenant Restrictions V2

Updated

- TRv2 does not enforce restrictions on cross-cloud requests at the authentication plane, so access is permitted during authentication. However, TRv2 does block cross-cloud requests at the data plane. As a result, when using Windows Group Policy (GPO), users will be unable to access TRv2-enlightened resources across cloud boundaries.

25 March 2026

Fundamentals

3

Microsoft identity platform

3

Security

2

Tutorial Configure External Id Web App Firewall

Updated

To enable WAF for protection, configure a WAF policy and associate it with Azure Front Door Premium. Microsoft optimizes Azure Front Door premium for security and manages the rule sets provided by the WAF to protect against common vulnerabilities including cross-site scripting and JavaScript exploits. Additionally, Azure WAF provides rule sets that help protect against malicious bot activity and provide layer 7 DDoS protection for your application.

21 March 2026

Architecture

1

B2c Deployment Plans

Updated

- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)

4 March 2026

Governance

1

Standards

1

Identity providers for external tenants

Updated

Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.

28 March 2026

General

22

Zscaler Coexistence

Updated

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

26 March 2026

Configure Microsoft and Zscaler for a Unified SASE Solution

Updated

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

19 March 2026

Security

7

Netskope Coexistence

Updated

Learn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.

14 March 2026

Fundamentals

5

Configure Security

Updated

| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |

27 March 2026

Traffic Forwarding

Updated

With the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.

25 March 2026

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

25 March 2026

What is Transport Layer Security Inspection?

Updated

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

17 March 2026

Conditional Access

2

Troubleshooting

2

How to use enriched Microsoft 365 logs

Updated

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

26 March 2026

How to use enriched Microsoft 365 logs

Updated

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

19 March 2026

General

12

How to Manage the Private Access Profile

Updated

Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.

26 March 2026

How to Manage the Private Access Profile

Updated

Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.

19 March 2026

Developer

5

Configure Global Access With Pim

Updated

Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.

26 March 2026

Authentication

4

Configure Kerberos Sso

Updated

Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.

26 March 2026

Conditional Access

2

Target Resource Private Access Apps

Updated

Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.

26 March 2026

Fundamentals

1

Connectors

Updated

After a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.

25 March 2026

Monitoring

1

Migrate from DirectAccess to Microsoft Entra Private Access

Updated

DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.

28 March 2026

Security

9

Verifiable credentials admin API

Updated

The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials, and completely opt out of the service.

17 March 2026

Plan Verification Solution

Updated

Microsoft’s Microsoft Entra Verified ID (Microsoft Entra VC) service enables you to trust proofs of user identity without expanding your trust boundary. With Microsoft Entra VC, you create accounts or federate with another identity provider. When a solution implements a verification exchange using verifiable credentials, it enables applications to request credentials that aren't bound to a specific domain. This approach makes it easier to request and verify credentials at scale.

17 March 2026

Architecture

3

General

3

Whats New

Updated

- Entra Verified ID is supported on Microsoft GCC environments.

17 March 2026

Authentication

1

Developer

1

Fundamentals

1

Microsoft identity platform

1

Create A Free Developer Account

Updated

- **Free Microsoft Entra tenant** — [Create a new tenant](~/identity-platform/quickstart-create-new-tenant.md) with an [Azure free account](https://azure.microsoft.com/pricing/purchase-options/azure-account). This gives you Entra ID Free tier. You can then [activate a free trial of Microsoft Entra ID P1 or P2](~/fundamentals/get-started-premium.md) if needed for testing.

10 March 2026

Fundamentals

2

What Is Entra

Updated

**For example**, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.

17 March 2026

Conditional Access

1

Workload Identity

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Developer

1

Scope Supported Objects Limitations

Updated

An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resource type](/graph/api/resources/approleassignment).

21 March 2026

General

1

Qs Configure Portal Windows Vmss

Updated

- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).

6 March 2026

General

44

How to configure Global Secure Access threat intelligence

Updated

- You must disable Domain Name System (DNS) over HTTPS (Secure DNS) to tunnel network traffic. Use the rules of the fully qualified domain names (FQDNs) in the traffic forwarding profile. For more information, see [Configure the DNS client to support DoH](/windows-server/networking/dns/doh-client-support#configure-the-dns-client-to-support-doh).

28 March 2026

Install Ios Client

Updated

Because the Global Secure Access client for iOS is integrated with Microsoft Defender for Endpoint, it's helpful to understand the end user experience. The client appears in the Defender dashboard after onboarding to Global Secure Access.

27 March 2026

How to Enable and Manage the Microsoft Profile

Updated

Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.

26 March 2026

The Global Secure Access Client for iOS

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.

26 March 2026

Configure Quick Access

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with the appropriate roles.

25 March 2026

How to Enable and Manage the Microsoft Profile

Updated

Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.

19 March 2026

Powershell Samples

Updated

Use these PowerShell samples for Global Secure Access.

7 March 2026

Security

14

Zscaler Coexistence

Updated

Learn how to configure Microsoft and Zscaler SSE for unified SASE solutions to enhance security and connectivity in your organization.

14 March 2026

27014

Updated

The Global Secure Access Secure Web Gateway (SWG) implements defense-in-depth through five security layers that together create a comprehensive inspection chain for internet-bound traffic. Each layer serves a distinct protective function:

12 March 2026

Troubleshooting

12

View Deployment Logs

Updated

Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.

26 March 2026

Troubleshoot Connectors

Updated

![Screenshot showing an example of the expected final configuration file.](media/troubleshoot-connectors/connector-logging-config-final-example.png)

25 March 2026

Zscaler Coexistence

Updated

1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.

24 March 2026

Fundamentals

6

View Enriched Logs

Updated

- **Microsoft Profile** - Ensure the Microsoft traffic profile is enabled. Microsoft traffic forwarding profile is required to capture traffic directed to Microsoft 365 services, which is fundamental for log enrichment.

27 March 2026

Understand Microsoft Entra Private DNS

Updated

Learn how to configure Microsoft Entra Private DNS for secure and efficient internal DNS query resolution, replacing legacy VPNs with granular access.

26 March 2026

What is Global Secure Access?

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

14 March 2026

Partner Ecosystem Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

14 March 2026

Microsoft identity platform

6

How to use the remote network health logs

Updated

Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.

26 March 2026

How to use the remote network health logs

Updated

Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.

19 March 2026

Conditional Access

5

Target Resource Microsoft Profile

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

25 March 2026

Monitoring

3

Authentication

1

userimpact: Low

Updated

When organizations deploy Global Secure Access as their cloud-based network proxy, Microsoft's Secure Service Edge infrastructure routes user traffic. If you don't enable source IP restoration, all authentication requests come from the proxy's IP address instead of the user's actual public egress IP.

3 March 2026

Architecture

1