Validate Oidc Multitenant App Gallery
Doc updateThe article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
Daily.Entra.NewsGlobal Secure Access was September’s main capability story. Microsoft added preview guidance for a tenant-specific Microsoft-managed root CA for Entra Internet Access TLS inspection, while clarifying the alternative customer-provided CA workflow. Entra ID also announced a mid-September improvement to iOS Authenticator passkey restoration. Other notable updates refined the custom-headers preview timeline and added a session-persistence step to app-access troubleshooting; remaining edits were largely navigation and documentation maintenance.
A new Global Secure Access guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. Microsoft protects the private key. The guide says the certificate must be deployed before enabling inspection to avoid certificate errors, and identifies Intune as one deployment option.
The Global Secure Access article now focuses on bringing your own certificate authority, including certificate-signing request creation, PKI signing, and certificate upload, while linking to separate Microsoft-managed certificate guidance.
Microsoft’s Message Center says the iOS Microsoft Authenticator app will receive a clearer, guided passkey-restore flow for users with iCloud backup, launching worldwide in mid-September 2026. No administrator action or policy change is required.
The custom-headers page title now identifies the capability as preview and says rollout is expected to complete by September 10, 2026. The date helps administrators set availability expectations; the update specifies no required action.
The troubleshooting guide now recommends enabling session persistence after confirming that an application works through a single connector. The same user and device should remain routed through that connector during the session, with linked traffic-routing guidance for configuration.
TLS inspection administrators can choose between a Microsoft-managed certificate and their own certificate authority. With the managed option, the root CA’s public certificate must be deployed to client devices before TLS inspection is enabled to avoid certificate errors; Intune or another MDM can perform the deployment. Administrators using their own PKI can follow the documented CSR, signing, and certificate-upload workflow. The Authenticator improvement requires no administrator action or policy change. For app-access troubleshooting, administrators should enable session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.
The SAML App Gallery validation article adds lightbox support to screenshots and a Next step link to the validation-results section.
The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”
Microsoft Entra improves the iOS Microsoft Authenticator app's passkey restore experience with a clearer, guided flow for device migration, launching worldwide mid-September 2026. It affects iOS users with iCloud backup, requires no action, and includes updated user guidance without policy changes.
The user provisioning validation guide now uses an updated Microsoft Entra admin center URL with additional parameters.
The hybrid join troubleshooting page was updated with revised guidance for AADSTS50034, and its date changed from July 27, 2025, to September 1, 2026.
The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.
The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.
The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.
The AI prompt injection protection documentation now explains that TLS inspection can use either a Microsoft-managed certificate or an administrator-provided certificate before configuring TLS inspection policies.
The page title now marks custom headers as preview and notes that rollout is expected to complete by September 10, 2026.
Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.
The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.
The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.
The documentation now provides separate links for configuring TLS inspection with a Microsoft-managed certificate and with your own certificate.