Licensing
UpdatedA Microsoft Entra documentation page was updated: Licensing.
Daily.Entra.NewsThe week of 15 December 2025 is dominated by Microsoft Learn maintenance: 30 entries were updated, none were new, one External ID page was removed, and no Message Center item was supplied. The strongest administrator-facing change is updated TLS inspection material for Global Secure Access and Microsoft Entra Internet Access. Other notable items are preview guidance, integration procedures, and External ID onboarding-page changes. The evidence does not establish a feature launch, general availability transition, runtime behavior change, or Entra product retirement.
Updated pages describe Microsoft Entra Internet Access TLS inspection as using a two-tier intermediate-certificate model that issues dynamically generated leaf certificates for traffic decryption. They explain configuring the CA that serves as the Global Secure Access intermediate CA, including CSR creation and certificate signing or upload, and state support for up to 100 policies, 1,000 rules, and 8,000 destinations. This is security configuration guidance; the supplied evidence does not say that the limits or‑—
The updated Just-In-Time Password Migration article describes migrating passwords from another identity provider to Microsoft Entra External ID through JIT Migration. Its title explicitly labels the capability Preview, and the record is an updated Learn page rather than a new item or GA notice. Administrators should therefore treat it as preview guidance, not evidence of a new rollout or changed migration behavior.
The updated Entitlement Management Access Package Assignments article covers viewing assignees, policy, status, and identity lifecycle; adding or removing assignments; and directly assigning identities when an access package has an appropriate policy. The supplied summary marks identity lifecycle as preview. This clarifies the documented workflow but does not show that the broader capability moved to general availability.
The updated WAF integration guidance says to enable the proxy setting for the DNS CNAME, while the Akamai integration guide directs administrators to the Protect apps from DDoS with WAF tile and Get started. These are integration and security-configuration procedures in the documentation; no evidence indicates a new WAF integration or a change in protection behavior.
The External ID entry titled Quickstart Trial Setup is marked Removed. Related onboarding material was updated: Quickstart Get Started Guide points administrators to sign in to the Microsoft Entra admin center, and Guide Explained includes a trial-tenant-creation flow illustration. The supplied data does not establish that either page replaces the removed one, so this is documentation-path maintenance rather than a product retirement.
Treat this as a documentation-review period rather than a broad deployment announcement. Administrators using or evaluating TLS inspection should validate the CA/CSR process and the stated 100-policy, 1,000-rule, and 8,000-destination limits. Teams evaluating External ID JIT migration, WAF integrations, or ID Governance assignment workflows should review the refreshed procedures and preserve the explicit preview boundaries. Owners of internal External ID onboarding links should check references to the removed Quickstart Trial Setup page. The licensing and pricing edits do not, by themselves, establish an entitlement or price change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
A Microsoft Entra documentation page was updated: Licensing.
| Metadata value | Value | Comments |
1. Create or modify an existing policy.
This is a current list of known limitations with the Microsoft Entra ECMA Connector Host and on-premises application provisioning.
12. Select **OK** twice. Close the ODBC Data Source Administrator. The DSN connection file is saved by default to your **Documents** folder.
ai-usage: ai-assisted
- **Custom CSS:** Upload a custom CSS file to replace the Microsoft default style of the page.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
include file
HttpClient client = new HttpClient();
This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md) and [Configure OIDC SSO for custom (non-gallery) applications](~/identity/enterprise-apps/add-application-portal-setup-oidc-sso.md?#configure-oidc-sso-for-custom-non-gallery-applications).
|AzureActiveDirectoryInvalidCredential|Error Message: We found an issue with the service account that is used to run Microsoft Entra Cloud Sync. You can repair the cloud service account by following the instructions at [here](./how-to-troubleshoot.md). If the error persists, please contact support with Job ID (from status pane of your configuration). Additional Error Details: CredentialsInvalid AADSTS50034: The user account {EmailHidden} doesn't exist in the skydrive365.onmicrosoft.com directory. To sign into this application, the account must be added to the directory. Trace ID: 0000aaaa-11bb-cccc-dd22-eeeeee333333 Correlation ID: aaaa0000-bb11-2222-33cc-444444dddddd Timestamp: 2021-01-12 21:08:29Z |This error is thrown when the sync service account ADToAADSyncServiceAccount doesn't exist in the tenant. It can be due to accidental deletion of the account.|Use [Repair-AADCloudSyncToolsAccount](reference-powershell.md#repair-aadcloudsynctoolsaccount) to fix the service account.|
In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.
|Feature|Free|Microsoft Entra ID P1|Microsoft Entra ID P2|Microsoft Entra ID Governance| Microsoft Entra Suite |
1. In the DNS console, for CNAME, enable the proxy setting.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
|Limits based on phone number |15 texts |20 texts |30 texts |50 texts |
A Microsoft Entra documentation page was updated: Quickstart Trial Setup.
Learn how to migrate passwords from another identity provider to Microsoft Entra External ID using Just-In-Time (JIT) Migration.
This extension provides a basic setup that automatically creates a tenant for applications and prepares it for users. It also streamlines your workflow by automatically populating values such as application IDs into your configuration file for a smoother setup process.
:::image type="content" source="media/concept-guide-explained/trial-creation.png" alt-text="Flowchart that shows the trial tenant creation step in the guide.":::
1. Select the **Protect apps from DDoS with WAF** tile by selecting **Get started**.
Transport Layer Security (TLS) inspection in Microsoft Entra Internet Access uses a two-tier Intermediate certificate model to issue dynamically generated leaf certificates for decrypting traffic. This article explains how to configure the Certificate Authority (CA) that serves as the Global Secure Access intermediate CA, including signing and uploading the certificate.
2. Now delete the old application and object using the following PowerShell cmdlets:
manager: dougeby
- TLS inspection supports up to 100 policies, 1000 rules, and 8000 destinations.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).
3. Use the following request format, replacing example.com with the host/path you want to check (for example, `msn.com/en-us/sports`):
1. Select **Create CSR**. This step creates a .csr file and saves it to your default download folder.