← Previous week
Next week →
Week in brief

Global Secure Access has the week’s clearest deployment signal: Windows client guidance states a managed, tenant-joined device prerequisite

The week of 29 December 2025 contains four Microsoft Learn updates: two for Entra ID, one for Global Secure Access, and one for External ID. There are no new or removed entries and no Message Center items. The supplied evidence supports one concrete installation preflight for Global Secure Access and documentation clarifications for macOS PSSO and Lexmark integration tutorials; it does not establish a new feature, preview, GA release, retirement, security advisory, or changed product behavior.

  • The updated Install Windows Client entry specifies that the device must be managed and joined to the onboarded tenant, with either Microsoft Entra joined or Microsoft Entra hybrid joined status. This is the period’s clearest deployment-relevant content. The evidence shows updated guidance, not proof that a new client version or product behavior was released.

  • The Device Join Macos Platform Single Sign On Kerberos Configuration update says macOS Platform SSO is enabled through the Microsoft Enterprise Single Sign-on Extension. It describes Entra join and sign-in using a hardware-bound key, smart card, or Microsoft Entra ID password through a PSSO Primary Refresh Token. The supplied text supports a documentation clarification, not a new availability or Kerberos behavior change.

  • The supplied change is a SAML assertion consumer service URL: https://lexmarkb2ceu.b2clogin.com/LexmarkB2CEU.onmicrosoft.com/B2C_1A_TrustFrameworkBase_ciam/samlp/sso/assertionconsumer. Administrators implementing the Lexmark Cloud Services SAML flow can compare this exact endpoint with their tenant configuration. The evidence does not show whether the URL was added, corrected, or changed, and does not indicate a service rollout.

  • The Lexmark Cloud Services OIDC Tutorial is listed as updated, but its supplied summary is empty. No change to endpoints, claims, scopes, redirect URIs, requirements, or availability can be identified, so this should be treated as an uncharacterized documentation edit rather than a confirmed OIDC capability change.

For Entra administrators

Before installing the Global Secure Access Windows client, validate that target devices are managed, joined to the onboarded tenant, and either Microsoft Entra joined or Microsoft Entra hybrid joined. For macOS PSSO, the updated guidance identifies the Microsoft Enterprise Single Sign-on Extension and the supported sign-in paths. Administrators implementing the Lexmark SAML tutorial can compare their federation configuration with the documented ACS URL; the OIDC update has no supplied content delta from which to derive an action.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Authentication

1

Device Join Macos Platform Single Sign On Kerberos Configuration

Updated

The macOS Platform single sign-on (PSSO) is a capability on macOS that is enabled using the [Microsoft Enterprise Single Sign-on Extension](../../identity-platform/apple-sso-plugin.md). Platform SSO enables users to Entra join their macOS devices and sign in using a hardware-bound key, smart card, or their Microsoft Entra ID password through a PSSO Primary Refresh Token (PRT).

1 January 2026

General

1

Standards

1

Lexmark Cloud Services Tutorial

Updated

| `https://lexmarkb2ceu.b2clogin.com/LexmarkB2CEU.onmicrosoft.com/B2C_1A_TrustFrameworkBase_ciam/samlp/sso/assertionconsumer` |

30 December 2025

General

1

Install Windows Client

Updated

- A managed device joined to the onboarded tenant. The device must be either Microsoft Entra joined or Microsoft Entra hybrid joined.

31 December 2025