Week in brief

Week of 28 April 2025: Power Automate hybrid join gets a 31 May GA date as Entra documents a Connect identity rollout and CA-agent preview

The period was dominated by documentation maintenance: 258 updates, seven new entries, two removals, and one Message Center notice. The clearest product-availability change is the announcement that Entra hybrid join for Power Automate hosted machine groups reaches general availability on 31 May 2025. Other substantive signals are a certificate-based application-identity rollout for Entra Connect, preview setup guidance for the Conditional Access optimization agent, and updated authentication behavior and security guidance. The two removals are not described, and the Workload ID page titled “Retire Service Principal Less Authentication” provides no retirement scope or date, so no deprecation action can be established. Most other named edits—vendor provisioning tutorials, protocol references, Application Proxy troubleshooting, and similar pages—are ordinary documentation clarification.

  • The Microsoft 365 Message Center announces the ability to configure Entra hybrid join for hosted machine groups in Power Automate and explicitly dates general availability to 31 May 2025. This is an availability announcement, not merely a Learn-page edit; the evidence does not indicate a wider change to other Entra hybrid-join scenarios.

  • Updated Entra ID and Workload ID guidance contrasts the current Entra Connect connector account, which authenticates with a username and password, with a new OAuth 2.0 client-credential flow using certificate credentials. The documented setup has the customer administrator create a single-tenant application or service principal and manage its application permissions and certificate. The material describes a rollout, not general availability or a mandatory migration. A related page title mentions retiring service-pr

  • A new Conditional Access article and updated Agent Optimization instructions describe the first run as selecting View details and then Start agent. During the preview, an account that must activate its role through Privileged Identity Management can cause authentication failures, so the documentation says to avoid that pattern and use an account with standing permissions. This is preview guidance, not a GA announcement.

  • The updated System Preferred MFA page says the method order is dynamic and places certificate-based authentication at the bottom because of known CBA issues; this is documented authentication behavior, not a new method. Separately, Session Lifetime guidance tells administrators to limit “reauthenticate every time” policies, warns that excessive prompts can contribute to MFA fatigue and phishing, notes that web applications are less disruptive, and says five minutes of clock skew prevents prompts more often thanonce

  • The updated Enable Passkey FIDO2 guidance states that administrator provisioning of security keys is in preview and points to Microsoft Graph and custom clients for provisioning on behalf of users. The record supports evaluation against preview guidance only; it does not establish general availability, portal support, or a required migration.

For Entra administrators

Administrators using Power Automate hosted machine groups should track the stated 31 May GA date. Entra Connect owners should monitor whether the application-identity rollout reaches their deployment and, if it does, be prepared to manage the single-tenant application or service principal, its permissions, and its certificate credential; no universal cutover date is supplied. For the Conditional Access optimization agent preview, avoid using a setup account that requires PIM role activation. Tenants relying on certificate-based authentication should review the updated system-preferred MFA ordering, while administrators using broad “reauthenticate every time” policies should consider the documented MFA-fatigue and phishing risks. Administrator provisioning of FIDO2 security keys is marked계예

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

39

Enable Passkey Fido2

Updated

Administrator provisioning of security keys is in preview. See [Microsoft Graph and custom clients to provision FIDO2 security keys on behalf of users](https://aka.ms/passkeyprovision).

4 May 2025

Configure Sso With Kcd

Updated

You can enable single sign-on to your applications using integrated Windows authentication (IWA) by giving private network connectors permission in Active Directory to impersonate users. The connectors use this permission to send and receive tokens on their behalf.

4 May 2025

Application Proxy Secure Api Access

Updated

Business logic often lives in a private Application Programming Interface (API). The API runs on premises or in a private cloud. Your native Android, iOS, Mac, or Windows apps need to interact with the API endpoints to use data or provide user interaction. Microsoft Entra application proxy and the [Microsoft Authentication Library (MSAL)](~/identity-platform/reference-v2-libraries.md) let your native apps securely access your private cloud APIs. Microsoft Entra application proxy is a faster and more secure solution than opening firewall ports and controlling authentication and authorization at the app layer.

4 May 2025

Application Proxy Sign In Bad Gateway Timeout Error

Updated

Next, open a browser and try again to access the application. You should be prompted for authentication and be able to sign in the application. If you can authenticate, the problem is with the KCD configuration that enables SSO.

4 May 2025

Jitbit Helpdesk Tutorial

Updated

![Authentication settings](./media/jitbit-helpdesk-tutorial/authentication.png "Authentication settings")

3 May 2025

Sspr Deploy

Updated

| |[What is self-service password reset?](https://youtu.be/hc97Yx5PJiM)|

3 May 2025

System Preferred Multifactor Authentication

Updated

When a user signs in, the authentication process checks which authentication methods are registered for the user. The user is prompted to sign-in with the most secure method according to the following order. The order of authentication methods is dynamic. It's updated as the security landscape changes, and as better authentication methods emerge. Due to known issues with certificate-based authentication (CBA) and system-preferred MFA, we moved CBA to the bottom of the list. Click the link for more information about each method.

2 May 2025

Agent Optimization

Updated

- During the preview, avoid using an account to set up the agent that requires role activation with Privileged Identity Management. Using an account that doesn't have standing permissions might cause authentication failures for the agent.

2 May 2025

Sign Ins

Updated

A Microsoft Entra documentation page was updated: Sign Ins.

2 May 2025

Add a platform to your app registration

Updated

Learn how to add a platform to your app in Microsoft Entra to securely handle authentication tokens and enhance your application's security.

1 May 2025

Session Lifetime

Updated

Administrators should limit the number of applications they enforce a policy requiring users to reauthenticate every time with. Triggering reauthentication too frequently can increase security friction to a point that it causes users to experience MFA fatigue and open the door to phishing. Web applications usually provide a less disruptive experience than their desktop counterparts when require reauthentication every time is enabled. We factor for five minutes of clock skew when every time is selected in policy, so that we don’t prompt users more often than once every five minutes.

1 May 2025

Authenticate Application Id

Updated

Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Entra ID. This account uses username and password to authenticate requests. To enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Entra or Administrator creates a single tenant third party application in Entra ID and use one of the relevant certificate management options below for the credentials.

1 May 2025

Native Authentication

Updated

If your team has determined that native authentication is necessary for your application, follow these steps to enable native authentication in the Microsoft Entra admin center:

1 May 2025

Usage Insights Report

Updated

![Screenshot of the sign-in activity details for a selected application.](./media/concept-usage-insights-report/application-activity-sign-in-detail.png)

1 May 2025

Howto Mfa Nps Extension

Updated

Open PowerShell and run the following command. Replace the fictitious app ID with the correct ID.

1 May 2025

Troubleshoot App Publishing

Updated

- MFA registered guest users remediate their own user risk. The guest user [resets or changes a secured password](https://aka.ms/sspr) at their home tenant (this needs MFA and self service password reset (SSPR) at the home tenant). The secured password change or reset must be initiated on Microsoft Entra ID and not on-premises.

30 April 2025

Access Token Claims Reference

Updated

| `acrs` | JSON array of strings | Indicates the Auth Context IDs of the operations that the bearer is eligible to perform. Auth Context IDs can be used to trigger a demand for step-up authentication from within your application and services. Often used along with the `xms_cc` claim. |

30 April 2025

Usage Insights Report

Updated

![Screenshot of the sign-in activity details for a selected application.](./media/concept-usage-insights-report/application-activity-sign-in-detail.png)

30 April 2025

Authenticate to Microsoft Entra ID using Application Identity

Updated

Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions#accounts-used-for-microsoft-entra-connect.md) to authenticate and sync identities from Active Directorty to Entra ID. This account uses username and password to authenticate requests. To enhance the security of the service, we are rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Entra or Administrator will create a single tenant 3rd party application in Entra ID and use one of the relevant certificate management options below for the credentials.

29 April 2025

OAuth 2.0 and OpenID Connect protocols

Updated

Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.

29 April 2025

Howto Mfa Reporting

Updated

The **Authentication Details** tab provides the following information, for each authentication attempt:

29 April 2025

Admin Audit Logging

Updated

|2519|Reinitialize Entra ID Connector account password| Shows that the AD Sync service account password was reset|

29 April 2025
36

Add Remove User To Group

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#home) as at least a [Billing Administrator](https://go.microsoft.com/fwlink/?linkid=2254515).

4 May 2025

Whats New

Updated

| Date | Area | Description |

3 May 2025

Groups Settings Cmdlets

Updated

| **GuestUsageGuidelinesUrl**<br>Type: `String`<br>Default: `""` | The URL of a link to the guest usage guidelines. |

2 May 2025

Connect Version History

Updated

This article helps you keep track of the versions that have released and the changes in those versions.

30 April 2025

Jiramicrosoft Tutorial

Updated

![Screenshot for claim conditions.](./media/jiramicrosoft-tutorial/claim-conditions.png)

28 April 2025
36

Salesforce Provisioning Tutorial

Updated

If you're using a Salesforce Sandbox environment, see the [Salesforce Sandbox integration article](./salesforce-sandbox-tutorial.md).

2 May 2025

Configure Entra To Active Directory

Updated

|5. Enable [your configuration](#enable-your-configuration)|Once ready, enable the configuration and users/groups will begin synchronizing|

30 April 2025

Group Writeback Cloud Sync

Updated

- [Provision groups to Active Directory using Microsoft Entra Cloud Sync](cloud-sync/how-to-configure-entra-to-active-directory.md)

30 April 2025

Frankli Io Provisioning Tutorial

Updated

1. Review the user attributes that are synchronized from Microsoft Entra ID to frankli in the **Attribute-Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in frankli for update operations. If you choose to change the [matching target attribute](~/identity/app-provisioning/customize-application-attributes.md), you need to ensure that the frankli API supports filtering users based on that attribute. Select the **Save** button to commit any changes.

28 April 2025

Hoxhunt Provisioning Tutorial

Updated

9. Review the user attributes that are synchronized from Microsoft Entra ID to Hoxhunt in the **Attribute-Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Hoxhunt for update operations. If you choose to change the [matching target attribute](~/identity/app-provisioning/customize-application-attributes.md), you need to ensure that the Hoxhunt API supports filtering users based on that attribute. Select the **Save** button to commit any changes.

28 April 2025

Insight4grc Provisioning Tutorial

Updated

![Screenshot of the Provisioning Mode dropdown list with the Automatic option called out.](common/provisioning-automatic.png)

28 April 2025
27

Configure Sso

Updated

1. Select your username in the upper-right corner. Verify you're signed in to a directory that uses application proxy. If you need to change directories, select **Switch directory** and choose a directory that uses application proxy.

4 May 2025

Application Proxy Configure Single Sign On With Headers

Updated

|Fine grained authorization |Provides access control at the URL level. Added policies can be enforced based on the URL being accessed. The internal URL configured for the app defines the scope of the app that the policy is applied to. The policy configured for the most granular path is enforced. |

4 May 2025

Application Proxy Integrate With Remote Desktop Services

Updated

- RD Gateway comes into the picture once a user launches the RDP connection. The RD Gateway handles encrypted RDP traffic coming over the internet and translates it to the on-premises server that the user is connecting to. In this scenario, the traffic the RD Gateway is receiving comes from the Microsoft Entra application proxy.

3 May 2025

Application Proxy Back End Kerberos Constrained Delegation How To

Updated

- Cross-domain scenarios rely on referrals that direct a connector host to DCs that might be outside of the local network perimeter. In these cases, it's equally important to send traffic onward to DCs that represent other respective domains. If you don't, delegation fails.

3 May 2025

Application Proxy Configure Hard Coded Link Translation

Updated

If you can't use custom domains in your tenant, there are several other options for providing this functionality. All of the other options are also compatible with custom domains and each other, so you can configure custom domains and other solutions.

3 May 2025

Application Proxy Add On Premises Application

Updated

Public Domain Name System (DNS) records for Microsoft Entra application proxy endpoints are chained CNAME records pointing to an A record. Setting up the records this way ensures fault tolerance and flexibility. The Microsoft Entra private network connector always accesses host names with the domain suffixes `*.msappproxy.net` or `*.servicebus.windows.net`. However, during the name resolution the CNAME records might contain DNS records with different host names and suffixes. Due to the difference, you must ensure that the device (depending on your setup - connector server, firewall, outbound proxy) can resolve all the records in the chain and allows connection to the resolved IP addresses. Since the DNS records in the chain might be changed from time to time, we can't provide you with any list DNS records.

3 May 2025

Application Proxy High Availability Load Balancing

Updated

The simplest scenario is where the back-end web application doesn’t require session stickiness (session persistence). A back-end application instance handles user requests in the server farm. You can use a layer 4 load balancer and configure it with no affinity. Some options include Microsoft Network Load Balancing and Azure Load Balancer or a load balancer from another vendor. Alternatively, configure a round-robin Domain Name System (DNS) strategy.

3 May 2025

Configure how users consent to applications

Updated

Configure user consent settings in Microsoft Entra ID to control when and how users grant permissions to your organization's data. Secure your environment with step‑by‑step guidance.

1 May 2025

Manage Self Service Access

Updated

In this article, you learn how to enable self-service application access using the Microsoft Entra admin center.

30 April 2025

Id Token Claims Reference

Updated

|`aud` | String, an App ID GUID | Identifies the intended recipient of the token. In `id_tokens`, the audience is your app's Application ID, assigned to your app in the Azure portal. This value should be validated. The token should be rejected if it fails to match your app's Application ID. |

30 April 2025
14

Wildcard applications in the Microsoft Entra application proxy

Updated

In Microsoft Entra ID, configuring a large number of on-premises applications can quickly become unmanageable and introduces unnecessary risks for configuration errors if many of them require the same settings. With [Microsoft Entra application proxy](overview-what-is-app-proxy.md), you can address this issue by using wildcard application publishing to publish and manage many applications at once. The solution provides:

4 May 2025

What Is App Proxy

Updated

- **Cost-effective**. On-premises solutions typically require you to setup and maintain demilitarized zones (DMZs), edge servers, or other complex infrastructures. Application proxy runs in the cloud, which makes it easy to use. To use application proxy, you don't need to change the network infrastructure or install more appliances in your on-premises environment.

4 May 2025

Conceptual Sso Apps

Updated

1. In the Microsoft Entra admin center, select **Microsoft Entra ID > Enterprise applications** and select **New application**.

4 May 2025

Whats New

Updated

**Type:** New feature

3 May 2025

Navigate

Removed

A Microsoft Entra documentation page was updated: Navigate.

3 May 2025

Audit Logs

Updated

A Microsoft Entra documentation page was updated: Audit Logs.

2 May 2025

Sign Ups

Updated

A Microsoft Entra documentation page was updated: Sign Ups.

2 May 2025

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

29 April 2025

Whats New

Updated

**Type:** New feature

29 April 2025
8

Sla Performance

Updated

| January | | 99.998% | 99.998% | 99.999% | 99.998% |

4 May 2025

Application Proxy Integrate With Logic Apps

Updated

![Diagram that shows Logic App to API connection via Azure application proxy.](./media/application-proxy-integrate-with-logic-apps/azure-logic-app-to-api-connection-app-proxy.png)

3 May 2025

View activity logs of application permissions

Updated

Microsoft Entra is a platform that allows you to create and manage applications for your organization. You can grant different permissions to your applications, such as accessing data, or performing actions. It's important to review these permissions periodically to ensure they remain appropriate and secure.

30 April 2025
8

My Ibisworld Tutorial

Updated

To configure single sign-on on **My IBISWorld** side, you need to send the **App Federation Metadata Url** to your IBISWorld Client Relationship Manager. We'll need this to have the SAML SSO connection set properly on both sides.

3 May 2025

Harness Provisioning Tutorial

Updated

> You may also choose to enable SAML-based single sign-on for Harness by following the instructions in the [Harness single sign-on article](./harness-tutorial.md). You can configure single sign-on independent of automatic user provisioning, although these two features complement each other.

3 May 2025

Jitbit Helpdesk Tutorial

Updated

1. On the **Basic SAML Configuration** section, perform the following steps:

28 April 2025
8

Application Proxy Troubleshoot

Updated

The first thing to check is the connector. To learn how to debug a private network connector, see [Debug private network connector issues](application-proxy-debug-connectors.md). If you still have issues connecting to your application, return to this article to troubleshoot the application.

4 May 2025

Debug application proxy issues

Updated

This article explains how to troubleshoot issues with Microsoft Entra application proxy. Use the flowchart to fix remote access issues for an on-premises web application.

3 May 2025

Error Codes

Updated

| AADSTS50102 | Unable to load CustomClaimsTransformer '{type}' was specified for principal '{principalId}'. |

2 May 2025

Troubleshoot Macos Platform Single Sign On Extension

Updated

Apple's app-site-association domains are critical for SSO extension functioning. (*) You only need to allow sovereign cloud domains if you rely on those in your environment. (**) Maintaining communications with the Experimentation Configuration Service (ECS) ensures that Microsoft can respond to a severe bug in a timely manner.

2 May 2025

Error Codes

Updated

| AADSTS50088 | Limit on telecom MFA calls reached. Please try again in a few minutes. |

30 April 2025

Troubleshoot Macos Platform Single Sign On Extension

Updated

Apple's app-site-association domains are critical for SSO extension functioning. (*) You only need to allow sovereign cloud domains if you rely on those in your environment. (**) Maintaining communications with the Experimentation Configuration Service (ECS) ensures that Microsoft can respond to a severe bug in a timely manner.

30 April 2025

21809

Updated

**Remediation action**

29 April 2025
6

Road To The Cloud Migrate

Updated

| Management area | On-premises (Active Directory) feature | Equivalent Microsoft Entra feature |

4 May 2025

Plan a single sign-on deployment

Updated

Plan your single sign‑on deployment in Microsoft Entra ID. Streamline role assignments, certificate management, and licensing to ensure uninterrupted access.

1 May 2025

Governance Deployment Employee Lifecycle

Updated

Use custom extensions to create workflows using tools like Azure Logic Apps. For workflows, you can enable custom task extensions to call out to external systems. For example, a Joiner workflow with a custom task extension assigns a Microsoft Teams number. Or, when a user becomes a Leaver, a separate workflow grants access to an email account for their manager.

30 April 2025
6

Application Proxy Integrate With Sharepoint Server

Updated

- A Microsoft Entra tenant with a plan that includes application proxy. Learn more about [Microsoft Entra ID plans and pricing](https://www.microsoft.com/security/business/identity-access-management/azure-ad-pricing).

3 May 2025

App Proxy Protect Ndes

Updated

Provide the credentials for an Application Administrator in your Microsoft Entra directory. The Microsoft Entra Application Administrator credentials are often different from your Azure credentials in the portal.

3 May 2025
3

What If Tool

Updated

The following conditions are required: identity, target resource, device platform, and client app. All other conditions are optional and are assumed to be set to **none** by default if no value is provided. For definitions of these conditions, see the article [Building a Conditional Access policy](concept-conditional-access-policies.md).

30 April 2025

Agent Optimization

Updated

1. Select **View details** under the Conditional Access Optimization Agent, then select **Start agent** to begin your first run.

28 April 2025
2
1

Configure Custom Domain

Updated

- You can control your branding and create the URLs you want. A custom domain can help build your users' confidence, because users see and use a familiar name instead of *`msappproxy.net`*.

4 May 2025
3
17

Access Reviews Faqs

Updated

While there's no direct "**Stop**" button for a series, you can edit the series to set an earlier end date. This prevents new review instances from being generated after that date.

4 May 2025

View activity and audit history for Azure resource roles in Privileged Identity Management

Updated

Privileged Identity Management (PIM) in Microsoft Entra ID, enables you to view activity, activations, and audit history for Azure resources roles within your organization. This includes subscriptions, resource groups, and even virtual machines. Any resource within the Microsoft Entra admin center that uses the Azure role-based access control functionality can take advantage of the security and lifecycle management capabilities in Privileged Identity Management. If you want to keep, audit data for longer than the default retention period, you can use Azure Monitor to route it to an Azure storage account. For more information, see [Archive Microsoft Entra logs to an Azure storage account](~/identity/monitoring-health/howto-archive-logs-to-storage-account.md).

2 May 2025

Suggested access packages in My Access (Preview)

Updated

In My Access, Microsoft Entra ID Governance users can see a curated list of suggested access packages in My Access. This capability allows users to quickly view the most relevant access packages for them based off their peers' access packages and previous assignments without scrolling through all their available access packages.

2 May 2025

Groups Assign Member Owner

Updated

Follow these steps to make a user eligible member or owner of a group. You need permissions to manage groups. For role-assignable groups, you need to be at least a Privileged Role Administrator role or be an Owner of the group. For non-role-assignable groups, you need to be at least a Directory Writer, Groups Administrator, or Identity Governance Administrator, User Administrator role, or be an Owner of the group. Role assignments for administrators should be scoped at directory level (not administrative unit level).

2 May 2025

Groups Role Settings

Updated

A Microsoft Entra documentation page was updated: Groups Role Settings.

2 May 2025

Pim Apis

Updated

A Microsoft Entra documentation page was updated: Pim Apis.

2 May 2025
2

Pim Deployment Plan

Updated

* **Groups**- Anyone in a group to get just-in-time access to Microsoft Entra roles and Azure roles. For Microsoft Entra roles, the group must be a newly created cloud group that’s marked as assignable to a role while for Azure roles, the group can be any Microsoft Entra security group. We don't recommend assigning/nesting a group to a PIM for Groups.

2 May 2025
1

Create a custom extension to externally determine the approval requirements for an entitlement management access package

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. While entitlement management natively supports dynamic approvers such as the requestor's manager, second-level manager, or sponsor from a connected organization, these options don't cover all scenarios. With [custom extensions](entitlement-management-logic-apps-integration.md) calling out to [Azure Logic Apps](/azure/logic-apps/logic-apps-overview), you're able to determine approval requirements for access packages at the time of request through an external system. With this external call, you're able to determine approval requirements based on each of the [ApprovalStage properties](/graph/api/resources/approvalstage?view=graph-rest-beta#properties). This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.

2 May 2025
7

Whats New Docs

Updated

- [Microsoft Entra External ID frequently asked questions](faq-customers.md) - Added clarification on tenant creation

3 May 2025

Whats New Docs

Updated

Welcome to what's new in documentation for Microsoft Entra External ID in external tenants. This article lists new docs that were added and docs that were significantly updated in the last three months.

2 May 2025

Tenant Restrictions V2

Updated

Tenant Restrictions v2 is supported on all clouds however TRv2 is not enforced with request going across cross clouds.

1 May 2025

Tenant Restrictions V2

Updated

- Allow the use of unenlightened apps, but block them from accessing Microsoft resources using a special WDAC policy, called an “AppIdTagging policy”.

29 April 2025
3

Tutorial - multifactor authentication for B2B

Updated

In this tutorial, learn how to require multifactor authentication when you use Microsoft Entra B2B to collaborate with external users and partner organizations.

30 April 2025
2
2
2

Tenant Restrictions V2

Updated

1. Install the [WDAC wizard](/windows/security/application-security/application-control/app-control-for-business/design/appcontrol-wizard)

2 May 2025

Tenant Restrictions V2

Updated

- Enable client signaling using Windows GPO. You need to check 'Enable firewall protection on MIcrosoft endpoints' and WDAC enablement. See [Block Chrome, Firefox and .NET applications like PowerShell](#block-chrome-firefox-and-net-applications-like-powershell).

30 April 2025
1
1

What Is Global Secure Access

Updated

Microsoft Entra Internet Access protects access to internet and SaaS apps with an identity-based Secure Web Gateway (SWG), blocking threats, unsafe content, and malicious traffic.

2 May 2025
1
5
4
2
2
3

Convert hash to bytes for older PowerShell:

Updated

In this set up, the customer administrator manages the application that is used by Entra Connect Sync to authenticate to Entra, the application permissions and certificate credential used by the application. The administrator [registers a Microsoft Entra app and creates a service principal.](graph/tutorial-applications-basics?tabs=http#register-an-application-with-microsoft-entra-id.md). The application should be assigned the required [permissions](#microsoft-graph-permissions-for-byoa)

2 May 2025
7

Enable Multi Geo

Updated

> - Mulit-Geo doesn't support Japan region selection through Microsoft Entra admin center.

2 May 2025

Current Known Limitations

Updated

- Only the Global Secure Access client for Windows, starting with version 1.8.239.0, is aware of Universal CAE. On other platforms, the Global Secure Access client uses regular access tokens.

30 April 2025
4

Assignment Network

Updated

Administrators can create policies that target specific network locations as a signal along with other conditions in their decision making process. They can include or exclude these network locations as part of their policy configuration. These network locations might include public IPv4 or IPv6 network information, countries/regions, unknown areas that don't map to specific countries/regions, or [Global Secure Access' compliant network](../../global-secure-access/how-to-compliant-network.md).

30 April 2025

Private Name Resolution

Updated

1. User requests a DNS query for `app.contoso.com`. If not cached locally, the DNS query is sent to the DNS proxy at the GSA edge.

29 April 2025
2

View Deployment Logs

Updated

![Screenshot of the deployment log activity details.](media/how-to-view-deployment-logs/traffic-activity-details.png)

4 May 2025

View Deployment Logs

Updated

1. Navigate to **Global Secure Access** > **Monitor** > **Deployment logs**.

2 May 2025
2
1

Compliant Network

Updated

Organizations who use Conditional Access along with the Global Secure Access, can prevent malicious access to Microsoft apps, third-party SaaS apps, and private line-of-business (LoB) apps using multiple conditions to provide defense-in-depth. These conditions might include device compliance, location, and more to provide protection against user identity or token theft. Global Secure Access introduces the concept of a compliant network within Microsoft Entra ID Conditional Access. This compliant network check ensures users connect via the Global Secure Access service for their specific tenant and are compliant with security policies enforced by administrators.

4 May 2025