Week in brief

Updated Global Secure Access TLS inspection guidance is the week’s clearest operational item; no launch is evidenced

The week of 15 December 2025 is dominated by Microsoft Learn maintenance: 30 entries were updated, none were new, one External ID page was removed, and no Message Center item was supplied. The strongest administrator-facing change is updated TLS inspection material for Global Secure Access and Microsoft Entra Internet Access. Other notable items are preview guidance, integration procedures, and External ID onboarding-page changes. The evidence does not establish a feature launch, general availability transition, runtime behavior change, or Entra product retirement.

  • Updated pages describe Microsoft Entra Internet Access TLS inspection as using a two-tier intermediate-certificate model that issues dynamically generated leaf certificates for traffic decryption. They explain configuring the CA that serves as the Global Secure Access intermediate CA, including CSR creation and certificate signing or upload, and state support for up to 100 policies, 1,000 rules, and 8,000 destinations. This is security configuration guidance; the supplied evidence does not say that the limits or‑—

  • The updated Just-In-Time Password Migration article describes migrating passwords from another identity provider to Microsoft Entra External ID through JIT Migration. Its title explicitly labels the capability Preview, and the record is an updated Learn page rather than a new item or GA notice. Administrators should therefore treat it as preview guidance, not evidence of a new rollout or changed migration behavior.

  • The updated Entitlement Management Access Package Assignments article covers viewing assignees, policy, status, and identity lifecycle; adding or removing assignments; and directly assigning identities when an access package has an appropriate policy. The supplied summary marks identity lifecycle as preview. This clarifies the documented workflow but does not show that the broader capability moved to general availability.

  • The updated WAF integration guidance says to enable the proxy setting for the DNS CNAME, while the Akamai integration guide directs administrators to the Protect apps from DDoS with WAF tile and Get started. These are integration and security-configuration procedures in the documentation; no evidence indicates a new WAF integration or a change in protection behavior.

  • The External ID entry titled Quickstart Trial Setup is marked Removed. Related onboarding material was updated: Quickstart Get Started Guide points administrators to sign in to the Microsoft Entra admin center, and Guide Explained includes a trial-tenant-creation flow illustration. The supplied data does not establish that either page replaces the removed one, so this is documentation-path maintenance rather than a product retirement.

For Entra administrators

Treat this as a documentation-review period rather than a broad deployment announcement. Administrators using or evaluating TLS inspection should validate the CA/CSR process and the stated 100-policy, 1,000-rule, and 8,000-destination limits. Teams evaluating External ID JIT migration, WAF integrations, or ID Governance assignment workflows should review the refreshed procedures and preserve the explicit preview boundaries. Owners of internal External ID onboarding links should check references to the removed Quickstart Trial Setup page. The licensing and pricing edits do not, by themselves, establish an entitlement or price change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

3

Licensing

Updated

A Microsoft Entra documentation page was updated: Licensing.

20 December 2025

Provisioning

3

Known Issues

Updated

This is a current list of known limitations with the Microsoft Entra ECMA Connector Host and on-premises application provisioning.

18 December 2025

App Provisioning Sql

Updated

12. Select **OK** twice. Close the ODBC Data Source Administrator. The DSN connection file is saved by default to your **Documents** folder.

18 December 2025

Branding

2

Customize Branding

Updated

- **Custom CSS:** Upload a custom CSS file to replace the Microsoft default style of the page.

17 December 2025

Architecture

1

Licensing Governance

Updated

|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |

19 December 2025

Governance

1

Security

1

Standards

1

Configure an OpenID Connect OAuth application from Microsoft Entra app gallery

Updated

This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md) and [Configure OIDC SSO for custom (non-gallery) applications](~/identity/enterprise-apps/add-application-portal-setup-oidc-sso.md?#configure-oidc-sso-for-custom-non-gallery-applications).

19 December 2025

Troubleshooting

1

Error Codes

Updated

|AzureActiveDirectoryInvalidCredential|Error Message: We found an issue with the service account that is used to run Microsoft Entra Cloud Sync. You can repair the cloud service account by following the instructions at [here](./how-to-troubleshoot.md). If the error persists, please contact support with Job ID (from status pane of your configuration). Additional Error Details: CredentialsInvalid AADSTS50034: The user account {EmailHidden} doesn't exist in the skydrive365.onmicrosoft.com directory. To sign into this application, the account must be added to the directory. Trace ID: 0000aaaa-11bb-cccc-dd22-eeeeee333333 Correlation ID: aaaa0000-bb11-2222-33cc-444444dddddd Timestamp: 2021-01-12 21:08:29Z |This error is thrown when the sync service account ADToAADSyncServiceAccount doesn't exist in the tenant. It can be due to accidental deletion of the account.|Use [Repair-AADCloudSyncToolsAccount](reference-powershell.md#repair-aadcloudsynctoolsaccount) to fix the service account.|

18 December 2025

Governance

2

Entitlement Management Access Package Assignments

Updated

In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.

18 December 2025

Licensing Governance

Updated

|Feature|Free|Microsoft Entra ID P1|Microsoft Entra ID P2|Microsoft Entra ID Governance| Microsoft Entra Suite |

18 December 2025

General

5

Service Limits

Updated

|Limits based on phone number |15 texts |20 texts |30 texts |50 texts |

18 December 2025

Quickstart Trial Setup

Removed

A Microsoft Entra documentation page was updated: Quickstart Trial Setup.

18 December 2025

Authentication

1

Developer

1

Visual Studio Code Extension

Updated

This extension provides a basic setup that automatically creates a tenant for applications and prepares it for users. It also streamlines your workflow by automatically populating values such as application IDs into your configuration file for a smoother setup process.

18 December 2025

Fundamentals

1

Guide Explained

Updated

:::image type="content" source="media/concept-guide-explained/trial-creation.png" alt-text="Flowchart that shows the trial tenant creation step in the guide.":::

18 December 2025

Security

1

Security

1

Configure Transport Layer Security inspection settings

Updated

Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access uses a two-tier Intermediate certificate model to issue dynamically generated leaf certificates for decrypting traffic. This article explains how to configure the Certificate Authority (CA) that serves as the Global Secure Access intermediate CA, including signing and uploading the certificate.

17 December 2025

Developer

1

Alert Service Principal

Updated

2. Now delete the old application and object using the following PowerShell cmdlets:

16 December 2025

Fundamentals

2

Transport Layer Security

Updated

- TLS inspection supports up to 100 policies, 1000 rules, and 8000 destinations.

18 December 2025

General

2

Secure Web Ai Gateway Agents

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).

19 December 2025

Check Web Content Filtering Categories

Updated

3. Use the following request format, replacing example.com with the host/path you want to check (for example, `msn.com/en-us/sports`):

19 December 2025

Security

1