author: HULKsmashGithub
External ID’s Akamai WAF verification and CIAM guidance lead an update-only Entra week
For the week of 26 January 2026, the supplied record shows 184 updates, with no new or removed items and no Message Center entries. The record is dominated by routine Microsoft Learn maintenance, especially a broad refresh of built-in role pages whose supplied summaries often contain only author metadata. The meaningful exceptions are documentation clarifications and security guidance around External ID, Conditional Access, privileged application credentials, Kerberos compatibility, and GitHub Enterprise Managed Users; no supplied item establishes a preview, general availability release, retirement, or service-behavior change.
The updated Akamai integration guidance calls for a post-configuration check: verify that Akamai WAF is protecting the external tenant by connecting the authentication credentials to the WAF configuration. The updated customer-security guide also names credential stuffing, automated bot sign-ups, account takeover attempts, and high-volume traffic spikes as CIAM threats, and points to layered controls and integrations. These are security and operational guidance updates, not evidence of a new feature or availability
Several Entra ID Conditional Access Cloud Apps passages address resource exclusions for a custom enterprise application and Exchange Online, with a note and a tenant-policy example; the Conditional Access Session page includes a screenshot of a policy using an MFA grant control. The supplied evidence points to examples and presentation being refined, not to a change in Conditional Access policy evaluation. Recheck the revised guidance when designing exclusions or session controls, but do not infer a tenant-wide beh
The updated role guidance notes that owners of app registrations and enterprise applications can manage credentials for apps they own, including apps that may have privileged permissions. It describes how an Authentication Administrator could use that ownership path to assume the app owner’s identity by updating credentials and then assume a privileged application’s identity. This is a security and least-privilege clarification in role documentation; the record does not show that role permissions changed. Review
The updated Entra ID Kerberos page states that cloud-only user accounts managed solely in Microsoft Entra ID are supported for Kerberos authentication with Azure Files, Azure Virtual Desktop, and Windows authentication access to Azure SQL Managed Instance. This is a compatibility clarification in the supplied update; it does not identify the support as newly launched, preview, or generally available. Teams assessing these workloads can use the statement in architecture and compatibility checks.
The updated Entra ID tutorial says an Enterprise Managed Users enterprise requires an authentication integration—SAML or OIDC—in addition to SCIM provisioning, and supports both service-provider- and identity-provider-initiated SSO. This is a setup prerequisite clarification, not evidence of a new SAML or OIDC capability. For Enterprise Managed Users deployments, plan authentication and SCIM as a combined implementation.
Treat this as a validation and reference-update week rather than a rollout. External ID operators using Akamai should perform the documented WAF protection and credential-link check and review the CIAM threat guidance; administrators working on Conditional Access exclusions, privileged app ownership, the listed Kerberos workloads, or GitHub Enterprise Managed Users should consult the revised pages for those scenarios. The role-page refresh alone is not evidence that role assignments or permissions need to change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
157 updatesGeneral
100Entra Offerings
Updated**Microsoft Entra ID P2** - Microsoft Entra ID P2 is available as a standalone product. It is also included with the following offers for enterprise customers:
author: HULKsmashGithub
Microsoft Entra ID supports applying [sensitivity labels](/purview/sensitivity-labels) to Microsoft 365 groups when those labels are published in the [Microsoft Purview portal](/purview/purview-portal) and the labels are configured for groups and sites.
* GitHub Enterprise Managed User supports both **SP and IDP** initiated SSO.
Attack Payload Author
Updated- [Get started using Attack simulation training](/defender-office-365/attack-simulation-training-get-started)
For more information, see these articles:
author: shlipsey3
- The `memberOf` attribute can't be used with other operators. For example, you can't create a rule that states "Members Of group A can't be in Dynamic group B."
author: FaithOmbongi
Agent Registry Administrator
Updatedauthor: FaithOmbongi
Ai Administrator
Updatedauthor: FaithOmbongi
Attack Payload Author
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Attribute Assignment Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Attribute Definition Reader
Updatedauthor: FaithOmbongi
Azure Devops Administrator
Updatedauthor: FaithOmbongi
Billing Administrator
Updatedauthor: FaithOmbongi
Cloud Device Administrator
Updatedauthor: FaithOmbongi
Compliance Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Directory Readers
Updatedauthor: FaithOmbongi
Directory Writers
Updatedauthor: FaithOmbongi
Domain Name Administrator
Updatedauthor: FaithOmbongi
Dragon Administrator
Updatedauthor: FaithOmbongi
Dynamics 365 Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Edge Administrator
Updatedauthor: FaithOmbongi
Exchange Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Fabric Administrator
Updatedauthor: FaithOmbongi
Global Administrator
Updatedauthor: FaithOmbongi
Global Reader
Updatedauthor: FaithOmbongi
Groups Administrator
Updatedauthor: FaithOmbongi
Guest Inviter
Updatedauthor: FaithOmbongi
Helpdesk Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Insights Administrator
Updatedauthor: FaithOmbongi
Insights Analyst
Updatedauthor: FaithOmbongi
Insights Business Leader
Updatedauthor: FaithOmbongi
Intune Administrator
Updatedauthor: FaithOmbongi
Iot Device Administrator
Updatedauthor: FaithOmbongi
Kaizala Administrator
Updatedauthor: FaithOmbongi
Knowledge Administrator
Updatedauthor: FaithOmbongi
Knowledge Manager
Updatedauthor: FaithOmbongi
License Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Message Center Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: rolyon
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: rolyon
Network Administrator
Updatedauthor: FaithOmbongi
Office Apps Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Partner Tier1 Support
Updatedauthor: FaithOmbongi
Partner Tier2 Support
Updatedauthor: FaithOmbongi
People Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Places Administrator
Updatedauthor: FaithOmbongi
Power Platform Administrator
Updatedauthor: FaithOmbongi
Printer Administrator
Updatedauthor: FaithOmbongi
Printer Technician
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Search Administrator
Updatedauthor: FaithOmbongi
Search Editor
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Sharepoint Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Teams Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Teams Devices Administrator
Updatedauthor: FaithOmbongi
Teams Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Tenant Creator
Updatedauthor: FaithOmbongi
User Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Virtual Visits Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Viva Goals Administrator
Updatedauthor: FaithOmbongi
Viva Pulse Administrator
Updatedauthor: FaithOmbongi
Windows 365 Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Yammer Administrator
Updatedauthor: FaithOmbongi
Fundamentals
14author: justinha
Configure Security
Updated| [Applications don't have client secrets configured](zero-trust-protect-identities.md#applications-dont-have-client-secrets-configured) | None (included with Microsoft Entra ID) |
Conditional Access Session
Updated
In the following example, the tenant has a Conditional Access policy with the following details:
A Microsoft Entra documentation page was updated: Zero Trust Protect Identities.
Groups Concept
Updated- *Microsoft Entra ID P2 licensed customers only*: Even after deleting the group, it's still shown as an eligible member of the role in PIM UI. Functionally there's no problem; it's just a cache issue in the Microsoft Entra admin center.
Whats New Archive
Updated- Microsoft 365 Defender portal
Zero Trust Monitor Detect
UpdatedA Microsoft Entra documentation page was updated: Zero Trust Monitor Detect.
A Microsoft Entra documentation page was updated: Zero Trust Protect Engineering Systems.
A Microsoft Entra documentation page was updated: Zero Trust Response Remediation.
- Resource exclusions for a custom enterprise application and Exchange Online
Security Defaults
UpdatedIf your tenant was created on or after October 22, 2019, security defaults might be enabled in your tenant. To protect all of our users, security defaults are being rolled out to all new tenants at creation.
> [!NOTE]
Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using browsers such as Microsoft Edge or Google Chrome.
Authentication
11Kerberos
UpdatedCloud-only user accounts managed solely in Microsoft Entra ID are supported for Kerberos authentication by workloads like Azure Files, Azure Virtual Desktop and Windows authentication access to Azure SQL Managed Instance.
Manage Roles Portal
Updated| [User Administrator](permissions-reference.md#user-administrator) | Can manage all aspects of users and groups, including resetting passwords for limited admins within the assigned administrative unit only. Cannot currently manage users' profile photographs. |
>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
Manages [Microsoft Purview Customer Lockbox requests](/purview/customer-lockbox-requests) in your organization. They receive email notifications for Customer Lockbox requests and can approve and deny requests from the Microsoft 365 admin center. They can also turn the Customer Lockbox feature on or off. Only Global Administrators can reset the passwords of people assigned to this role.
Global Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Enable Authenticator Passkey
Updatedauthor: justinha
Authentication Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Password Administrator
Updatedauthor: FaithOmbongi
Security
10Manage Device Identities
Updated`id,deviceId,displayName,accountEnabled,operatingSystem,operatingSystemVersion,trustType(joinType),mdm,securitySettingsManagement,isCompliant,registrationDateTime,approximateLastSignInDateTime,owner,upnName`
Compliance Administrator
UpdatedUsers with this role have permissions to manage compliance-related features in the Microsoft Purview portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Users with this role have permissions to track data in the Microsoft Purview portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Helpdesk Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
User Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
author: FaithOmbongi
Security Administrator
Updatedauthor: FaithOmbongi
Security Operator
Updatedauthor: FaithOmbongi
Security Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Standards
6author: OwenRichards1
Hipaa Audit Controls
Updated| Configure Azure Monitor | [Use Azure Monitor Logs](/azure/azure-monitor/logs/data-security) collects and organizes logs, expanding to cloud and hybrid environments. It provides recommendations on key areas on how to protect resources combined with Azure trust center. |
In this article, you learn how to set up a SAML integration for a GitHub enterprise with Enterprise Managed Users with Microsoft Entra ID. Setting up a SAML or [OIDC](https://docs.github.com/enterprise-cloud@latest/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-oidc-for-enterprise-managed-users) authentication integration, in addition to setting up [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md), is required for a GitHub enterprise with Enterprise Managed Users. Setting up authentication and [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md) for a GitHub enterprise with Enterprise Managed Users allows an admin to:
Configure GitHub Enterprise Cloud - Enterprise Account for Single sign-on with Microsoft Entra ID
UpdatedIn this article, you learn how to set up a Microsoft Entra SAML integration with a GitHub Enterprise Cloud - Enterprise Account. When you integrate GitHub Enterprise Cloud - Enterprise Account with Microsoft Entra ID, you can:
* [FedRAMP High Azure Policy built-in initiative definition](/azure/governance/policy/samples/fedramp-high)
Hipaa Other Controls
Updated| Recommendation | Action |
Monitoring
5Global Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview portal, Azure portal, and Device Management admin center.
Attribute Log Administrator
Updatedauthor: FaithOmbongi
Attribute Log Reader
Updatedauthor: FaithOmbongi
Reports Reader
Updatedauthor: FaithOmbongi
Usage Summary Reports Reader
Updatedauthor: FaithOmbongi
Provisioning
3author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Branding
2Use the following CSS selectors to configure the details of the sign-in experience.
author: FaithOmbongi
Developer
2Application Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Architecture
1Team members who need to create sensitivity labels require permissions to:
Conditional Access
1author: FaithOmbongi
Governance
1author: FaithOmbongi
Microsoft identity platform
1Application Developer
Updatedauthor: FaithOmbongi
Microsoft Entra Agent ID
2 updatesGeneral
1Agent Id Administrator
Updatedauthor: FaithOmbongi
Microsoft identity platform
1Agent Id Developer
Updatedauthor: FaithOmbongi
Microsoft Entra ID Protection
3 updatesAuthentication
2Security Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security
1Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Microsoft Entra ID Governance
5 updatesGovernance
41. Once you select a policy, you are able to add users to select the users you want to assign this access package to, under the chosen policy.
Pim Roles
Updated> For information about delays activating the Microsoft Entra Joined Device Local Administrator role, see [How to manage the local administrators group on Microsoft Entra joined devices](../../identity/devices/assign-local-admin.md#manage-the-microsoft-entra-joined-device-local-administrator-role).
1. Once you select a policy, you are able to add users to select the users you want to assign this access package to, under the chosen policy.
author: FaithOmbongi
Fundamentals
1Pim For Groups
Updated1. Make active assignments of users to the group, and then assign the group to a role as eligible for activation.
Microsoft Entra External ID
12 updatesGeneral
5B2c Ief Keyset Administrator
Updatedauthor: FaithOmbongi
B2c Ief Policy Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Fundamentals
4Customers Ciam
UpdatedMicrosoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.
Security Customers
UpdatedExternal-facing identity systems support a wide range of customer experiences. That wide range also makes them attractive targets for common customer identity and access management (CIAM) attack patterns such as credential stuffing, automated bot sign-ups, account takeover attempts, and high-volume traffic spikes. Understanding these threats helps explain why a clear, layered security approach is essential. Microsoft Entra External ID provides foundational capabilities you can build on. This guide helps you understand how to strengthen that foundation with recommended controls and integrations based on common CIAM threat patterns.
Supported Features Customers
Updated|**Target resources**|<ul><li>[Cloud apps](~/identity/conditional-access/concept-conditional-access-cloud-apps.md)</li><li>[User actions](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#user-actions)</li><li>[Global Secure Access](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#traffic-forwarding-profiles)</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|<ul><li>[All resources, selected apps](./how-to-multifactor-authentication-customers.md), or [filter applications](~/identity/conditional-access/concept-filter-for-applications.md).</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|
Authentication
1Configure Akamai Integration
UpdatedAfter completing the configuration steps, verify that Akamai WAF is protecting your external tenant by connecting the authentication credentials to the WAF configuration.
Branding
1Customize the sign-in experience for your application with branding themes in external tenants
UpdatedLearn about how to create branding themes and apply them to the sign-in experience for your application in Microsoft External ID for external tenants.
Standards
1Supported Features Customers
Updated|[OpenID Connect](../../identity-platform/v2-protocols-oidc.md)| Yes| Yes|
Microsoft Entra Workload ID
1 updateMonitoring
1> [!NOTE]
Microsoft Entra Global Secure Access
4 updatesGeneral
2Powershell Get Token
UpdatedWrite-Output "Access Token that you acquired is available in C:\token.txt. "
author: FaithOmbongi
Monitoring
1author: FaithOmbongi
Security
1Network Content Filtering
UpdatedDiscover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.
