MondayMon
TuesdayTue
WednesdayWed
ThursdayThu
FridayFri
SaturdaySat
SundaySun
2414Entra IDID GovernanceGlobal Secure Access2514Entra IDExternal IDGlobal Secure Access2629Entra IDID GovernanceGlobal Secure Access2714Agent IDEntra IDExternal ID2841Entra IDWorkload IDID Governance2912Entra IDGlobal Secure Access303122Agent IDEntra IDID Governance117Global Secure AccessEntra ID
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
1
2
3
4
Month in brief

Microsoft-managed root CA preview expands Global Secure Access TLS inspection options

Global Secure Access was September’s main capability story. Microsoft added preview guidance for a tenant-specific Microsoft-managed root CA for Entra Internet Access TLS inspection, while clarifying the alternative customer-provided CA workflow. Entra ID also announced a mid-September improvement to iOS Authenticator passkey restoration. Other notable updates refined the custom-headers preview timeline and added a session-persistence step to app-access troubleshooting; remaining edits were largely navigation and documentation maintenance.

  • A new Global Secure Access guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. Microsoft protects the private key. The guide says the certificate must be deployed before enabling inspection to avoid certificate errors, and identifies Intune as one deployment option.

  • The Global Secure Access article now focuses on bringing your own certificate authority, including certificate-signing request creation, PKI signing, and certificate upload, while linking to separate Microsoft-managed certificate guidance.

  • Microsoft’s Message Center says the iOS Microsoft Authenticator app will receive a clearer, guided passkey-restore flow for users with iCloud backup, launching worldwide in mid-September 2026. No administrator action or policy change is required.

  • The custom-headers page title now identifies the capability as preview and says rollout is expected to complete by September 10, 2026. The date helps administrators set availability expectations; the update specifies no required action.

  • The troubleshooting guide now recommends enabling session persistence after confirming that an application works through a single connector. The same user and device should remain routed through that connector during the session, with linked traffic-routing guidance for configuration.

For Entra administrators

TLS inspection administrators can choose between a Microsoft-managed certificate and their own certificate authority. With the managed option, the root CA’s public certificate must be deployed to client devices before TLS inspection is enabled to avoid certificate errors; Intune or another MDM can perform the deployment. Administrators using their own PKI can follow the documented CSR, signing, and certificate-upload workflow. The Authenticator improvement requires no administrator action or policy change. For app-access troubleshooting, administrators should enable session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

17 updates by product

3

Validate Oidc Multitenant App Gallery

Doc update

The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.

1 September 2026

Connect Install Roadmap

Doc update

The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.

1 September 2026

Validate Oidc Multitenant App Gallery

Doc update

The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.

1 September 2026
2

Validate Saml Single Sign On App Gallery

Doc update

The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”

1 September 2026
1
1
1
4

Transport Layer Security

Doc update

The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.

1 September 2026

Configure TLS inspection with a Microsoft-managed certificate

New featureAction required

The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.

1 September 2026

Configure TLS inspection with your own certificate

Doc update

The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.

1 September 2026
2

Configure Custom Headers

Doc update

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

1 September 2026
2

Troubleshoot Transport Layer Security

Doc update

The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.

1 September 2026

Troubleshoot App Access

Doc update

The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.

1 September 2026
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…