Week in brief

External ID’s Akamai WAF verification and CIAM guidance lead an update-only Entra week

For the week of 26 January 2026, the supplied record shows 184 updates, with no new or removed items and no Message Center entries. The record is dominated by routine Microsoft Learn maintenance, especially a broad refresh of built-in role pages whose supplied summaries often contain only author metadata. The meaningful exceptions are documentation clarifications and security guidance around External ID, Conditional Access, privileged application credentials, Kerberos compatibility, and GitHub Enterprise Managed Users; no supplied item establishes a preview, general availability release, retirement, or service-behavior change.

  • The updated Akamai integration guidance calls for a post-configuration check: verify that Akamai WAF is protecting the external tenant by connecting the authentication credentials to the WAF configuration. The updated customer-security guide also names credential stuffing, automated bot sign-ups, account takeover attempts, and high-volume traffic spikes as CIAM threats, and points to layered controls and integrations. These are security and operational guidance updates, not evidence of a new feature or availability

  • Several Entra ID Conditional Access Cloud Apps passages address resource exclusions for a custom enterprise application and Exchange Online, with a note and a tenant-policy example; the Conditional Access Session page includes a screenshot of a policy using an MFA grant control. The supplied evidence points to examples and presentation being refined, not to a change in Conditional Access policy evaluation. Recheck the revised guidance when designing exclusions or session controls, but do not infer a tenant-wide beh

  • The updated role guidance notes that owners of app registrations and enterprise applications can manage credentials for apps they own, including apps that may have privileged permissions. It describes how an Authentication Administrator could use that ownership path to assume the app owner’s identity by updating credentials and then assume a privileged application’s identity. This is a security and least-privilege clarification in role documentation; the record does not show that role permissions changed. Review

  • The updated Entra ID Kerberos page states that cloud-only user accounts managed solely in Microsoft Entra ID are supported for Kerberos authentication with Azure Files, Azure Virtual Desktop, and Windows authentication access to Azure SQL Managed Instance. This is a compatibility clarification in the supplied update; it does not identify the support as newly launched, preview, or generally available. Teams assessing these workloads can use the statement in architecture and compatibility checks.

  • The updated Entra ID tutorial says an Enterprise Managed Users enterprise requires an authentication integration—SAML or OIDC—in addition to SCIM provisioning, and supports both service-provider- and identity-provider-initiated SSO. This is a setup prerequisite clarification, not evidence of a new SAML or OIDC capability. For Enterprise Managed Users deployments, plan authentication and SCIM as a combined implementation.

For Entra administrators

Treat this as a validation and reference-update week rather than a rollout. External ID operators using Akamai should perform the documented WAF protection and credential-link check and review the CIAM threat guidance; administrators working on Conditional Access exclusions, privileged app ownership, the listed Kerberos workloads, or GitHub Enterprise Managed Users should consult the revised pages for those scenarios. The role-page refresh alone is not evidence that role assignments or permissions need to change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

100

Entra Offerings

Updated

**Microsoft Entra ID P2** - Microsoft Entra ID P2 is available as a standalone product. It is also included with the following offers for enterprise customers:

30 January 2026

Attack Payload Author

Updated

- [Get started using Attack simulation training](/defender-office-365/attack-simulation-training-get-started)

29 January 2026

Groups Dynamic Rule Member Of

Updated

- The `memberOf` attribute can't be used with other operators. For example, you can't create a rule that states "Members Of group A can't be in Dynamic group B."

28 January 2026

Fundamentals

14

Configure Security

Updated

| [Applications don't have client secrets configured](zero-trust-protect-identities.md#applications-dont-have-client-secrets-configured) | None (included with Microsoft Entra ID) |

29 January 2026

Conditional Access Session

Updated

![Screenshot of a Conditional Access policy with a grant control requiring multifactor authentication.](./media/concept-conditional-access-session/conditional-access-session.png)

29 January 2026

Conditional Access Cloud Apps

Updated

In the following example, the tenant has a Conditional Access policy with the following details:

29 January 2026

Groups Concept

Updated

- *Microsoft Entra ID P2 licensed customers only*: Even after deleting the group, it's still shown as an eligible member of the role in PIM UI. Functionally there's no problem; it's just a cache issue in the Microsoft Entra admin center.

29 January 2026

Security Defaults

Updated

If your tenant was created on or after October 22, 2019, security defaults might be enabled in your tenant. To protect all of our users, security defaults are being rolled out to all new tenants at creation.

27 January 2026

Add Your Work or School Account to a macOS Device

Updated

Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using browsers such as Microsoft Edge or Google Chrome.

26 January 2026

Authentication

11

Kerberos

Updated

Cloud-only user accounts managed solely in Microsoft Entra ID are supported for Kerberos authentication by workloads like Azure Files, Azure Virtual Desktop and Windows authentication access to Azure SQL Managed Instance.

31 January 2026

Manage Roles Portal

Updated

| [User Administrator](permissions-reference.md#user-administrator) | Can manage all aspects of users and groups, including resetting passwords for limited admins within the assigned administrative unit only. Cannot currently manage users' profile photographs. |

31 January 2026

Privileged Authentication Administrator

Updated

>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

29 January 2026

Customer Lockbox Access Approver

Updated

Manages [Microsoft Purview Customer Lockbox requests](/purview/customer-lockbox-requests) in your organization. They receive email notifications for Customer Lockbox requests and can approve and deny requests from the Microsoft 365 admin center. They can also turn the Customer Lockbox feature on or off. Only Global Administrators can reset the passwords of people assigned to this role.

29 January 2026

Global Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.

29 January 2026

Security

10

Manage Device Identities

Updated

`id,deviceId,displayName,accountEnabled,operatingSystem,operatingSystemVersion,trustType(joinType),mdm,securitySettingsManagement,isCompliant,registrationDateTime,approximateLastSignInDateTime,owner,upnName`

30 January 2026

Compliance Administrator

Updated

Users with this role have permissions to manage compliance-related features in the Microsoft Purview portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Compliance Data Administrator

Updated

Users with this role have permissions to track data in the Microsoft Purview portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Helpdesk Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

29 January 2026

User Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

29 January 2026

Standards

6

Hipaa Audit Controls

Updated

| Configure Azure Monitor | [Use Azure Monitor Logs](/azure/azure-monitor/logs/data-security) collects and organizes logs, expanding to cloud and hybrid environments. It provides recommendations on key areas on how to protect resources combined with Azure trust center. |

29 January 2026

Configure a GitHub enterprise with Enterprise Managed Users for SAML Single sign-on with Microsoft Entra ID

Updated

In this article, you learn how to set up a SAML integration for a GitHub enterprise with Enterprise Managed Users with Microsoft Entra ID. Setting up a SAML or [OIDC](https://docs.github.com/enterprise-cloud@latest/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-oidc-for-enterprise-managed-users) authentication integration, in addition to setting up [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md), is required for a GitHub enterprise with Enterprise Managed Users. Setting up authentication and [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md) for a GitHub enterprise with Enterprise Managed Users allows an admin to:

29 January 2026

Monitoring

5

Global Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview portal, Azure portal, and Device Management admin center.

29 January 2026

Provisioning

3

Branding

2

Developer

2

Architecture

1

Conditional Access

1

Governance

1

Microsoft identity platform

1

General

1

Microsoft identity platform

1

Authentication

2

Security Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Security

1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Governance

4

Pim Roles

Updated

> For information about delays activating the Microsoft Entra Joined Device Local Administrator role, see [How to manage the local administrators group on Microsoft Entra joined devices](../../identity/devices/assign-local-admin.md#manage-the-microsoft-entra-joined-device-local-administrator-role).

29 January 2026

Fundamentals

1

Pim For Groups

Updated

1. Make active assignments of users to the group, and then assign the group to a role as eligible for activation.

29 January 2026

General

5

Fundamentals

4

Microsoft Entra External ID overview

Updated

Microsoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.

31 January 2026

Security Customers

Updated

External-facing identity systems support a wide range of customer experiences. That wide range also makes them attractive targets for common customer identity and access management (CIAM) attack patterns such as credential stuffing, automated bot sign-ups, account takeover attempts, and high-volume traffic spikes. Understanding these threats helps explain why a clear, layered security approach is essential. Microsoft Entra External ID provides foundational capabilities you can build on. This guide helps you understand how to strengthen that foundation with recommended controls and integrations based on common CIAM threat patterns.

29 January 2026

Supported Features Customers

Updated

|**Target resources**|<ul><li>[Cloud apps](~/identity/conditional-access/concept-conditional-access-cloud-apps.md)</li><li>[User actions](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#user-actions)</li><li>[Global Secure Access](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#traffic-forwarding-profiles)</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|<ul><li>[All resources, selected apps](./how-to-multifactor-authentication-customers.md), or [filter applications](~/identity/conditional-access/concept-filter-for-applications.md).</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|

29 January 2026

Authentication

1

Configure Akamai Integration

Updated

After completing the configuration steps, verify that Akamai WAF is protecting your external tenant by connecting the authentication credentials to the WAF configuration.

30 January 2026

Branding

1

Standards

1

Monitoring

1

General

2

Powershell Get Token

Updated

Write-Output "Access Token that you acquired is available in C:\token.txt. "

30 January 2026

Monitoring

1

Security

1

Network Content Filtering

Updated

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.

27 January 2026