Week in brief

Global Secure Access strict-location warning leads an otherwise documentation-led Entra week

The supplied change set contains 153 items, all marked Updated, with no new or removed entries and no Message Center items. It is therefore an update-only documentation cycle rather than a release bulletin. The most actionable clarification is the Global Secure Access Conditional Access limitation for IP location-based policies targeting non-Microsoft resources. Other meaningful updates cover GSA client and licensing prerequisites, Verified ID implementation and key-management paths, SAP Cloud Identity Services provisioning, and ID Governance guest billing. ID Protection also received a broad risk-operations documentation refresh. The evidence does not establish a new feature, preview, GA milestone, retirement, or service-wide behavior change.

  • Microsoft Entra Global Secure Access; Conditional Access; Internet Access; Private AccessGlobal Secure Access: Conditional Access and deployment guardrails are explicit

    The updated Conditional Access limitation says not to enable strict location enforcement when an IP location-based Conditional Access policy targets non-Microsoft resources. Related pages cover Compliant Network Check, creating a remote network and reviewing logs, and applying Conditional Access to Private Access apps through Universal Conditional Access. Separate deployment and licensing guidance says endpoints without the Global Secure Access client remain outside SSE controls; missing licenses block traffic-​​-

  • Updated Verified ID pages span the Admin API, Request Service, issuance, presentation, and Verified ID Network APIs; credential flows for ID-token hints and tokens, self-asserted claims, multiple attestations, and existing verifiable credentials; did:web:path and domain linking; and signing-key rotation and upgrade for FIPS compliance. Face Check guidance covers its billing model and describes enabling the add-on by linking an Azure subscription. These are refreshed how-to and reference paths; no supplied item is�

  • The updated ID Protection set covers MFA registration, risk-data export and reports, the distinction between real-time and offline detections, risk policies, simulated detections, risk feedback, remediation, and querying detections with Microsoft Graph PowerShell. The supplied summaries describe administration and troubleshooting guidance; they do not identify a new detector, changed risk-engine behavior, preview, or GA milestone.

  • Microsoft Entra ID; SAP Cloud Identity Services; GitHub Enterprise ServerEntra ID provisioning guidance clarifies SAP setup and GitHub JIT support

    The SAP Cloud Identity Services provisioning tutorial explicitly places one step before automatic provisioning: add SAP Cloud Identity Services from the Microsoft Entra application gallery to the tenant’s enterprise applications. The admin center or Graph API can be used for that step. A separate Entra ID integration update says GitHub Enterprise Server supports Just In Time user provisioning. These are setup and reference clarifications, not evidence of a new provisioning rollout.

  • The updated licensing text says guests are billed only when they actively use features exclusive to Microsoft Entra ID Governance. It also says Microsoft Entra P2 features are not billed, linking an Azure subscription is neither required nor enforced for P2 actions, and a month with no active governance action is not billed—even when access was auto-assigned in an earlier month. This is a licensing clarification, not a product launch.

For Entra administrators

Prioritize targeted validation rather than a broad tenant migration. For Global Secure Access, check any IP location-based Conditional Access policy aimed at non-Microsoft resources before enabling strict location enforcement. Also verify that the relevant Internet Access and Private Access licenses and Microsoft Entra ID P1 prerequisite are present, licenses are assigned to users, and the client is deployed to managed endpoints; the supplied guidance ties these conditions to traffic routing and SSE coverage. Teams using Verified ID should revisit key, Face Check, and did:web procedures. SAP setups need the gallery application added before automatic provisioning, while ID Governance teams can use the clarified guest-billing rules for planning. No broad configuration reset or migration is e

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

2

Configure Security

Updated

| [Privileged users sign in with phishing-resistant methods](zero-trust-monitor-detect.md#privileged-users-sign-in-with-phishing-resistant-methods) | Microsoft Entra ID P1 |

13 February 2026

General

2

Authentication

1

Microsoft identity platform

1

Sap Cloud Platform Identity Authentication Provisioning Tutorial

Updated

Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.

10 February 2026

Provisioning

1

Security

5

Identity Risk Management Agent

Updated

Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.

11 February 2026

Fundamentals

4

ID Protection Risk Reports

Updated

Learn how to access, filter, and use the Microsoft Entra ID Protection risk reports to mark users and sign-ins as risky or confirmed compromised.

11 February 2026

Risk detection types and levels

Updated

Learn about risk detections and risk levels, including the difference between real-time and offline detections.

11 February 2026

What are risk detections?

Updated

Explore the full list of risk detections and their corresponding risk event types, along with a description of each risk event type.

11 February 2026

Authentication

1

Monitoring

1

Troubleshooting

1

Remediate risks and unblock users

Updated

Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.

11 February 2026

Governance

1

Microsoft Entra Id Governance Licensing For Guest Users

Updated

Guest users are only billed when they actively use features that are exclusive to Microsoft Entra ID Governance. Microsoft Entra P2 features are not billed, and linking an Azure subscription is not required or enforced for P2 actions. Additionally, if a guest doesn't take any active governance-related action during a month, such as in cases where access was auto-assigned in a prior month, they won't be billed for that month.

14 February 2026

Fundamentals

2

General

4

Fundamentals

2

Provisioning

1

userimpact: Low

Updated

Global Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.

11 February 2026

General

8

Enable Intelligent Local Network

Updated

Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.

10 February 2026

Enable Multi Geo

Updated

Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.

10 February 2026

Conditional Access

1

Developer

1

Fundamentals

1

Learn about Microsoft Entra Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

10 February 2026

Security

1

Security

15

Admin Api

Updated

Learn how to manage your verifiable credential deployment using Admin API.

11 February 2026

General

12

Rotate signing keys

Updated

Learn how to rotate Microsoft Entra Verified ID signing keys.

11 February 2026

Upgrade signing keys

Updated

Learn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.

11 February 2026

Architecture

3

Developer

2

Vc Network Api

Updated

Learn how to use the Microsoft Entra Verified ID Network API

11 February 2026

Authentication

1

Troubleshooting

1

Error Codes

Updated

Reference of error codes for Microsoft Entra Verified ID APIs

11 February 2026

General

30

Install Windows Client

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](/azure/active-directory/roles/permissions-reference#global-secure-access-administrator).

12 February 2026

Macos Client Release History

Updated

Track the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.

10 February 2026

Ciphers

Updated

author: HULKsmashGithub

10 February 2026

Remote Network Resilience

Updated

This article provides techniques to improve remote network resilience with Global Secure Access.

10 February 2026

Secure Web Ai Gateway Agents

Updated

Learn how to configure Secure Web and AI Gateway for Microsoft Copilot Studio agents using Global Secure Access.

10 February 2026

The Global Secure Access Client for Android

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Android client app.

10 February 2026

The Global Secure Access Client for macOS

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.

10 February 2026

The Global Secure Access Client for Windows

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.

10 February 2026

Security

15

userimpact: Low

Updated

Comprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. If you don't deploy the Global Secure Access client to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.

11 February 2026

Find Microsoft Services Partners

Updated

Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.

10 February 2026

Powershell Open Secure Sockets Layer

Updated

Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.

10 February 2026

Sentinel Integration

Updated

Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.

10 February 2026

Transport Layer Security

Updated

Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.

10 February 2026

Full Data Loss Protection

Updated

Learn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.

10 February 2026

Fundamentals

12

Alerts

Updated

Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.

10 February 2026

Application Usage Analytics

Updated

Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.

10 February 2026

Transport Layer Security

Updated

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

10 February 2026

What is Global Secure Access?

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

10 February 2026

Edr Antivirus Coexistence

Updated

Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.

10 February 2026

Netskope Integration

Updated

Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.

10 February 2026

Partner Ecosystem Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

10 February 2026

Troubleshooting

10

Troubleshoot App Access

Updated

Learn how to troubleshoot application access problems with the Global Secure Access Windows client.

10 February 2026

Monitoring

5

Global Secure Access network traffic logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

10 February 2026

Conditional Access

3

Current Known Limitations

Updated

- If you have IP location-based Conditional Access policies targeting non-Microsoft resources, don't enable strict location enforcement.

10 February 2026

Developer

3

Configure Domain Controllers

Updated

1. On the application settings page, Quick Access in this example, select **Users and groups**.

14 February 2026