What Is Cloud Sync
Updated| Support for US Government|● |● |
Daily.Entra.NewsThe supplied change set contains 153 items, all marked Updated, with no new or removed entries and no Message Center items. It is therefore an update-only documentation cycle rather than a release bulletin. The most actionable clarification is the Global Secure Access Conditional Access limitation for IP location-based policies targeting non-Microsoft resources. Other meaningful updates cover GSA client and licensing prerequisites, Verified ID implementation and key-management paths, SAP Cloud Identity Services provisioning, and ID Governance guest billing. ID Protection also received a broad risk-operations documentation refresh. The evidence does not establish a new feature, preview, GA milestone, retirement, or service-wide behavior change.
The updated Conditional Access limitation says not to enable strict location enforcement when an IP location-based Conditional Access policy targets non-Microsoft resources. Related pages cover Compliant Network Check, creating a remote network and reviewing logs, and applying Conditional Access to Private Access apps through Universal Conditional Access. Separate deployment and licensing guidance says endpoints without the Global Secure Access client remain outside SSE controls; missing licenses block traffic--
Updated Verified ID pages span the Admin API, Request Service, issuance, presentation, and Verified ID Network APIs; credential flows for ID-token hints and tokens, self-asserted claims, multiple attestations, and existing verifiable credentials; did:web:path and domain linking; and signing-key rotation and upgrade for FIPS compliance. Face Check guidance covers its billing model and describes enabling the add-on by linking an Azure subscription. These are refreshed how-to and reference paths; no supplied item is�
The updated ID Protection set covers MFA registration, risk-data export and reports, the distinction between real-time and offline detections, risk policies, simulated detections, risk feedback, remediation, and querying detections with Microsoft Graph PowerShell. The supplied summaries describe administration and troubleshooting guidance; they do not identify a new detector, changed risk-engine behavior, preview, or GA milestone.
The SAP Cloud Identity Services provisioning tutorial explicitly places one step before automatic provisioning: add SAP Cloud Identity Services from the Microsoft Entra application gallery to the tenant’s enterprise applications. The admin center or Graph API can be used for that step. A separate Entra ID integration update says GitHub Enterprise Server supports Just In Time user provisioning. These are setup and reference clarifications, not evidence of a new provisioning rollout.
The updated licensing text says guests are billed only when they actively use features exclusive to Microsoft Entra ID Governance. It also says Microsoft Entra P2 features are not billed, linking an Azure subscription is neither required nor enforced for P2 actions, and a month with no active governance action is not billed—even when access was auto-assigned in an earlier month. This is a licensing clarification, not a product launch.
Prioritize targeted validation rather than a broad tenant migration. For Global Secure Access, check any IP location-based Conditional Access policy aimed at non-Microsoft resources before enabling strict location enforcement. Also verify that the relevant Internet Access and Private Access licenses and Microsoft Entra ID P1 prerequisite are present, licenses are assigned to users, and the client is deployed to managed endpoints; the supplied guidance ties these conditions to traffic routing and SSE coverage. Teams using Verified ID should revisit key, Face Check, and did:web procedures. SAP setups need the gallery application added before automatic provisioning, while ID Governance teams can use the clarified guest-billing rules for planning. No broad configuration reset or migration is e
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
| Support for US Government|● |● |
| [Privileged users sign in with phishing-resistant methods](zero-trust-monitor-detect.md#privileged-users-sign-in-with-phishing-resistant-methods) | Microsoft Entra ID P1 |
author: barclayn
A Microsoft Entra documentation page was updated: Directory Service Limits Restrictions.
In this article, you can learn how to integrate SAP Cloud Identity Services with Microsoft Entra ID for single-sign on. When you integrate SAP Cloud Identity Services with Microsoft Entra ID, you can:
Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.
* GitHub Enterprise Server supports **Just In Time** user provisioning.
Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.
Query Microsoft Graph risk detections and associated information from Microsoft Entra ID
How and why should you provide feedback on ID Protection risk detections.
Enable and configure risk policies in Microsoft Entra ID Protection.
Learn how to simulate risk detections in Microsoft Entra ID Protection to enhance security. Test risk-based policies effectively.
Learn how to access, filter, and use the Microsoft Entra ID Protection risk reports to mark users and sign-ins as risky or confirmed compromised.
Learn about risk detections and risk levels, including the difference between real-time and offline detections.
Explore the full list of risk detections and their corresponding risk event types, along with a description of each risk event type.
Automation to detect, remediate, investigate, and analyze risk data with Microsoft Entra ID Protection
Learn how to configure the Microsoft Entra ID Protection multifactor authentication registration policy.
Learn about the many long-term data storage and monitoring options for exporting risk data from Microsoft Entra ID Protection.
Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Guest users are only billed when they actively use features that are exclusive to Microsoft Entra ID Governance. Microsoft Entra P2 features are not billed, and linking an Azure subscription is not required or enforced for P2 actions. Additionally, if a guest doesn't take any active governance-related action during a month, such as in cases where access was auto-assigned in a prior month, they won't be billed for that month.
|---------|---------|---------|
ai-usage: ai-assisted
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
PowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Learn about how Microsoft Entra Internet Access and Microsoft Entra Private Access secures access to your resources through Conditional Access.
Learn about how Microsoft Entra Internet Access secures access to the Internet.
Global Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.
Learn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.
Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
How to apply Conditional Access policies to Microsoft Entra Private Access apps.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Learn how to manage your verifiable credential deployment using Admin API.
In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.
Learn how to use a quickstart to create custom credentials for ID tokens
Learn how to use a quickstart to create custom credentials for self-issued claims.
Learn how to use a quickstart to create custom credentials with multiple attestations.
Learn how to issue a verifiable credential.
Learn how to use a quickstart to create custom credentials for from other Verifiable Credential attestation.
Learn how to start a presentation request in Verifiable Credentials
Learn how to revoke an issued verifiable credential.
In this tutorial, you learn how to manually configure your tenant to support the Verified ID service.
In this tutorial, you learn how to configure your tenant to verify credentials.
In this tutorial, you learn how to issue verifiable credentials, from directory based claims, by using a sample app.
In this tutorial, you learn how to issue verifiable credentials by using a sample app.
In this tutorial, you learn how to quickly configure your tenant to support the Verified ID service.
In this article, you learn how to use the Microsoft Entra Verified ID Network to verify credentials.
Learn about Face Check with Microsoft Entra Verified ID billing model. Learn how to enable the Face Check add-on in your tenant by linking your Microsoft Azure subscription.
Learn how to enable support for did:web:path
Learn how to link your domain to your decentralized identifier (DID).
Learn how to opt out of Microsoft Entra Verified ID.
Learn to plan your end-to-end issuance solution.
Learn foundational information to plan and design your verification solution.
Learn how to register your website ID for did:web.
Learn how to rotate Microsoft Entra Verified ID signing keys.
Rules and Display Definition Reference
In this tutorial, you learn how to use Face Check with Microsoft Entra Verified ID.
Learn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.
Recent updates for Microsoft Entra Verified ID
Learn foundational information to plan and design your solution
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Learn how to issue and verify by using the Request Service REST API.
Learn how to use the Microsoft Entra Verified ID Network API
In this tutorial, you learn how to install and use Microsoft Authenticator for VerifiedID.
Reference of error codes for Microsoft Entra Verified ID APIs
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](/azure/active-directory/roles/permissions-reference#global-secure-access-administrator).
A Microsoft Entra documentation page was updated: Public Preview Important Note.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.
Track the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.
author: fgomulka
author: HULKsmashGithub
author: jenniferf-skc
A Microsoft Entra documentation page was updated: Configure Threat Intelligence.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: fgomulka
Learn how to enable source IP restoration to ensure the source IP matches in downstream resources.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
author: HULKsmashGithub
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Learn how to configure per-app access to private resources in Global Secure Access.
Learn how to configure Quick Access to private resources in Global Secure Access.
Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
This article provides techniques to improve remote network resilience with Global Secure Access.
Learn how to configure Secure Web and AI Gateway for Microsoft Copilot Studio agents using Global Secure Access.
Use Global Secure Access to configure Azure and Microsoft Entra resources to create a virtual wide area network to connect to your resources in Azure.
author: jricketts
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Android client app.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Comprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. If you don't deploy the Global Secure Access client to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.
Learn how to configure Microsoft and Zscaler SSE for unified SASE solutions to enhance security and connectivity in your organization.
Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.
Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Microsoft and Cisco’s Secure Access coexistence solution guide.
Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
Microsoft and Cisco VPNs coexistence solution guide.
Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway Prompt Shield.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.
Learn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.
Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.
Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.
This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.
Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
Learn about Universal Continuous Evaluation concepts
Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.
A Microsoft Entra documentation page was updated: Microsoft Traffic Profile.
Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
Install the Global Secure Access Windows client as a proof of concept. This script automates installation and applies essential configurations.
author: garrodonnell
Learn how to troubleshoot and resolve Transport Layer Security (TLS) inspection errors in Global Secure Access.
ai-usage: ai-assisted
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
This document provides troubleshooting guidance for the Global Secure Access client when it shows the "disabled by your organization" error message.
Discover how to use advanced diagnostics to resolve issues with the Global Secure Access mobile client for Android and iOS.
Troubleshoot the macOS Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the Health check tab in the Advanced diagnostics utility.
Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.
Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Extract connector logs and send those logs to the Log Analytics workspace in the customer’s Azure subscription.
Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.
Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
- If you have IP location-based Conditional Access policies targeting non-Microsoft resources, don't enable strict location enforcement.
Learn how to require known compliant network locations in order to connect to your secured resources with Conditional Access.
Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
1. On the application settings page, Quick Access in this example, select **Users and groups**.
Use Application discovery to detect the applications accessed by users and create separate private applications.
Learn how to secure highly valued private application access with Privileged Identity Management (PIM) and Global Secure Access