Connect Install Roadmap
Updated> [!IMPORTANT]
Daily.Entra.NewsThe week of 12 January 2026 was dominated by documentation maintenance: 29 items were updated, with no new or removed entries, alongside one Message Center notice. The clearest operational change is a Microsoft Purview DLP naming transition, not an Entra feature launch. Other meaningful updates clarify the supported Microsoft Entra Connect path, ID Protection remediation behavior, Agent ID access governance, and application-owner security practices. The supplied evidence does not establish a new preview, general-availability event, or retirement occurring this week.
The Message Center notice says the rename starts in mid-January 2026. It specifies no functional or user impact: new audit logs will use “Application,” while existing logs retain “Entra.” This is a naming and logging transition, not a capability launch.
Related updates describe Express settings as the default for a single-forest, password-hash-sync deployment and Custom settings as the option for multiple forests or optional features. The upgrade guidance states that DirSync and Azure AD Sync are unsupported and no longer work, requiring an upgrade to Microsoft Entra Connect to resume synchronization. AD FS migration guidance also calls for syncing and verifying groups and membership before application migration. These are support and deployment clarifications,ไม่
The updated policy guidance says the Microsoft-managed remediation risk-based Conditional Access policy accommodates password-based and passwordless authentication. When “Require risk remediation” is selected, ID Protection manages the remediation flow based on the observed threat and the user’s authentication method. The evidence describes a documentation update, not a new preview or general-availability announcement.
The updated overview says newly created agent identities have limited permissions, including OAuth 2 delegated scopes inherited from the parent agent identity blueprint. Resource access can also be assigned through access packages, which an agent identity, its owner, or its sponsor can request. This clarifies the governance model without establishing a new availability milestone.
The Identity Platform Integration Checklist now advises minimizing and manually monitoring the owners of applications registered in a directory. This is security guidance for ownership hygiene, not a reported platform behavior change; administrators can apply it when reviewing app-registration governance.
Update scripts and internal documentation that reference the Purview DLP Enforcement plane, and account for new audit logs using “Application” while existing logs retain “Entra.” Check for any remaining DirSync or Azure AD Sync deployment: the revised guidance says those services are unsupported and no longer work, and directs administrators to Microsoft Entra Connect. The ID Protection, application-management, and Agent ID entries support targeted policy and governance reviews, but do not by themselves indicate a blanket tenant reconfiguration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
> [!IMPORTANT]
|Topic |Link|
- [Download the Microsoft Entra Connect Health agent for AD FS](https://go.microsoft.com/fwlink/?LinkID=518973).
You can upgrade your Microsoft Entra Connect server from all supported versions with the latest versions:
DirSync and Azure AD Sync aren't supported and no longer work. If you're still using DirSync or Azure AD Sync, you *must* upgrade to Microsoft Entra Connect to resume your sync process.
> [!TIP]
When you map authorization rules, apps that authenticate with AD FS may use Active Directory groups for permissions. In such a case, use [Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) to sync these groups with Microsoft Entra ID before migrating the applications. Make sure that you verify those groups and membership before migration so that you can grant access to the same users when the application is migrated.
If you have a single-forest topology and use [password hash sync](how-to-connect-password-hash-synchronization.md) for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.
author: justinha
Learn which Microsoft Entra features are available in Azure for US Government.
> [!TIP]
- The country code returned depends on the device platform API: For example one platform might report US for Puerto Rico, while another reports PR.
Once issued, a PRT is valid for 90 days and is continuously renewed as long as the user actively uses the device. Organizations can require users re-authenticate in order to access resources using the Sign-in [frequency session control](../conditional-access/concept-conditional-access-session.md).
:::image type="content" source="./media/application-registration-best-practices/implict-grant-flow.png" alt-text="Screenshot that shows where the implicit flow property is located.":::
 If your app is registered in a directory, minimize and manually monitor the list of app registration owners.
Use *custom settings* in Microsoft Entra Connect when you want more options for the installation. Use these settings, for example, if you have multiple forests or if you want to configure optional features. Use custom settings in all cases where [express installation](how-to-connect-install-express.md) doesn't satisfy your deployment or topology needs.
Microsoft Purview DLP is renaming the Enforcement plane from "Entra" to "Application" starting mid-January 2026, with no functional or user impact. Admins should update scripts and documentation accordingly. New audit logs will reflect "Application," while existing logs keep "Entra." No compliance issues identified.
- SOAP Discovery: Allows the administrator to enter the WSDL path exposed by the target web service. Discovery produces a tree structure of the application's hosted web services with their inner endpoints or operations along with the operation’s Meta data description. There's no limit to the number of discovery operations that can be done (step by step). The discovered operations are used later to configure the flow of operations that implement the connector’s operations against the data-source (as Import/Export).
[Append](#append) [AppRoleAssignmentsComplex](#approleassignmentscomplex) [BitAnd](#bitand) [CBool](#cbool) [CDate](#cdate) [Coalesce](#coalesce) [ConvertToBase64](#converttobase64) [ConvertToUTF8Hex](#converttoutf8hex) [Count](#count) [CStr](#cstr) [DateAdd](#dateadd) [DateDiff](#datediff) [DateFromNum](#datefromnum) [FormatDateTime](#formatdatetime) [Guid](#guid) [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty) [IIF](#iif) [InStr](#instr) [IsNull](#isnull) [IsNullOrEmpty](#isnullorempty) [IsPresent](#ispresent) [IsString](#isstring) [Item](#item) [Join](#join) [Left](#left) [Len](#len) [Mid](#mid) [NormalizeDiacritics](#normalizediacritics) [Not](#not) [Now](#now) [NumFromDate](#numfromdate) [PCase](#pcase) [RandomString](#randomstring) [Redact](#redact) [RemoveDuplicates](#removeduplicates) [Replace](#replace) [SelectUniqueValue](#selectuniquevalue) [SingleAppRoleAssignment](#singleapproleassignment) [Split](#split) [StripSpaces](#stripspaces) [Switch](#switch) [ToLower](#tolower) [ToUpper](#toupper) [Word](#word)
This article shows the new and updated documentation for the Microsoft Entra application management.
Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.

> [!WARNING]
When created, agent identities have limited permissions, such as OAuth 2 delegated permission scopes [inherited from their parent agent identity blueprint](../agent-id/identity-professional/configure-inheritable-permissions-blueprints.md). In addition, agent identities can have resource access assigned to them directly via access packages. Agent identities can request an access package for themselves, or have their owner or sponsor request one on their behalf. With access packages, you're able to assign agent identities access to the following resources:
The Microsoft-managed remediation risk-based Conditional Access policy lets you author a risk policy that accommodates all authentication methods, including password-based and passwordless. This means that when you select "Require risk remediation" in your policy's grant controls, Microsoft Entra ID Protection manages the appropriate remediation flow based on the threat observed and the user's authentication method. For detailed steps on how to enable Microsoft-managed remediation, see [Configure risk policies](howto-identity-protection-configure-risk-policies.md#microsoft-recommendations).
| HR | [API-driven connector from any HR source](../identity/app-provisioning/inbound-provisioning-api-concepts.md)<br>[Rippling HCM integration with Microsoft Entra ID/Active Directory](../identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md)<br>[Oracle HCM API-driven connector](../identity/saas-apps/oracle-hcm-provisioning-tutorial.md)<br>[Darwinbox to Microsoft Entra ID](../identity/saas-apps/darwinbox-entra-integration-tutorial.md)<br>[SAP HCM to Microsoft Entra ID](../identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) |
1. For organizations with a single subscription to Workday or SuccessFactors, and don't use Active Directory
- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
Internet access traffic can be forwarded to the service by connecting through the [Global Secure Access desktop client](how-to-install-windows-client.md).
try {