Entra Service Limits Include
Updated| Category | Limit |
Daily.Entra.NewsThe week of 16 February 2026 was dominated by Learn maintenance—132 updates and six new pages, including many SSO and provisioning tutorials—rather than a broad release announcement. The main substantive thread is new cross-product guidance for web content filtering across Microsoft Entra ID, Internet Access, and Global Secure Access. The only explicit lifecycle event is the retirement of Azure AD Account Linking for Microsoft Rewards. The supplied evidence does not identify a preview or general-availability milestone for the new web-filtering or Agent ID material.
New Microsoft Entra ID pages describe Conditional Access integration, category-based rules, and links between web-content-filtering policies and security profiles. Updated Internet Access guidance says administrators create a Conditional Access policy for users or groups and use Conditional Access Session controls to deliver the security profile and user/context awareness. Companion Global Secure Access guidance records different propagation times for Global Secure Access and Conditional Access changes. This is a)
A 19 February Microsoft 365 Message Center major update says Microsoft is retiring Azure AD Account Linking for Microsoft Rewards by 19 March 2026. After retirement, work accounts will no longer be linkable for earning Rewards points; existing points and personal-account use are unaffected. The notice explicitly says that no administrator action is required.
Updated Agent ID guidance says a blueprint creates agent identities and supports token requests using those identities. It describes setting an owner and sponsor to establish accountability and administrative relationships, plus configuring an identifier URI and scope when agents created from the blueprint must receive incoming requests from other agents or users. The feed marks this as documentation updated, not as a stated availability milestone.
The updated Temporary Access Pass page includes a Minimum lifetime row that pairs a 1-hour value with a 10–43,200-minute range, or up to 30 days, and describes the setting as the number of minutes the TAP remains valid. The evidence does not say that existing tenant policies or service behavior changed, so this is best treated as a current reference for checking TAP configuration.
An updated Configure Quick Access page states that a Quick Access app can contain up to 500 application segments. The supplied change record does not establish that the limit was introduced or increased during this week; it should be treated as a documented capacity boundary rather than a feature launch.
Administrators implementing web content filtering should use the documented Conditional Access session-control path and plan around the stated propagation difference: typically less than five minutes for changes in the Global Secure Access experience and approximately one hour for Conditional Access changes. No tenant action is required for the Microsoft Rewards retirement. For Agent ID, Temporary Access Pass, and Quick Access, use the updated pages to validate designs and settings, but do not infer a new release or changed service behavior from documentation updates alone.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
| Category | Limit |
>
>[!Note]
| `https://<customer-domain>.concursolutions.com` |
```
c. **Sign on URL**: Enter a URL that has the following pattern: `https://<CUSTOMER_LENSES_BASE_URL>`. An example is `https://lenses.my.company.com`.
`https://<companyname-pricing>.ordering.predictix.com/sso/request`
`https://<servername>.sapbydesign.com`
`https://<SUBDOMAIN>.sciforma.net/sciforma/main.html`
The scenario outlined in this article assumes that you already have the following prerequisites:
o **Custid** = Enter unique EBSCO customer ID
In this section, you create a user named Britta Simon on your MiCloud Connect account. Users must be created and activated before using single sign-on.
| 4 | true | emailIsPrimary | Use this attribute to set business email as primary in SuccessFactors. If business email isn't primary, set this flag to false. |
- devx-track-arm-template
Prerequisites to use PowerShell or Graph Explorer for Microsoft Entra roles.
A Microsoft Entra documentation page was updated: Qs Configure Cli Windows Vm.
A Microsoft Entra documentation page was updated: Qs Configure Cli Windows Vmss.
A Microsoft Entra documentation page was updated: Qs Configure Portal Windows Vm.
A Microsoft Entra documentation page was updated: Qs Configure Portal Windows Vmss.
A Microsoft Entra documentation page was updated: Qs Configure Powershell Windows Vm.
A Microsoft Entra documentation page was updated: Qs Configure Powershell Windows Vmss.
A Microsoft Entra documentation page was updated: Qs Configure Template Windows Vm.
A Microsoft Entra documentation page was updated: Qs Configure Template Windows Vmss.
A tutorial that shows you how to use a Linux VM/VMSS to access Azure resources.
A tutorial that shows you how to use a Windows VM/VMSS to access Azure resources.
- devx-track-arm-template
- devx-track-arm-template
- devx-track-arm-template
Microsoft is retiring the Azure AD Account Linking feature for Microsoft Rewards by March 19, 2026. Users can no longer link work accounts to earn Rewards points. Existing points remain unaffected, personal accounts work as usual, and no admin actions are required.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: HULKsmashGithub
> [!IMPORTANT]
Write-Host " "
onPremisesPublishing = @{
There are three possible ways that you can add an identifier URI to your app. We recommend them in the following order:
> [!div class="mx-tableFixed"]
* [Federal Risk and Authorization Management Program](https://www.fedramp.gov/)
To configure single sign-on in Tripwire Enterprise, please see **Using Tripwire Enterprise with SAML Authentication** section in the Tripwire Enterprise Hardening Guide, available for download on the Tripwire Customer Center. If you require assistance, contact [Tripwire Enterprise support team](mailto:[email protected]).
`https://saml.achieve3000.com/district/<District Identifier>`
To perform the Single Sign-On configuration on the Crowd Log side, please refer to the Crowd Log SAML admin settings documentation.
To configure single sign-on on **In Case of Crisis - Mobile** side, you need to send the downloaded **Certificate (Raw)** and copied **User access URL** from Azure portal to In Case of Crisis - Mobile support team. They set this setting to have the SAML SSO connection set properly on both sides.
To configure single sign-on on **Lexmark Cloud Services (SAML)** side, you need to send the **App Federation Metadata Url** to Lexmark Cloud Services (SAML) support team. They set this setting to have the SAML SSO connection set properly on both sides. Also review the [Lexmark documentation](https://support.lexmark.com/en_us/manuals-guides/online/Lexmark-Cloud-Platform/configuring-microsoft-entra-id-federation-for-saml.html) on Configuring Microsoft Entra ID with SAML Federation
To configure single sign-on on **ON24 Virtual Environment SAML Connection** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to ON24 Virtual Environment SAML Connection support team. They set this setting to have the SAML SSO connection set properly on both sides.
`https://<tenant-name>.instructure.com/saml2`
1. In another browser instance, navigate to the SAML SSO page created for you by the Gaggle support team (for example: `https://accounts.gaggleamp.com/saml_configurations/oXH8sQcP79dOzgFPqrMTyw/edit`).
Before you begin to configure the O'Reilly learning platform to support provisioning with Microsoft Entra ID, you’ll need to generate a SCIM API token within the O’Reilly Admin Console.
To configure single sign-on on OutSystems side, you need to download the IdP forge component, configure it as mentioned in the [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Configure_your_application_to_use_IdP_connector). After installing the component and do the necessary code changes, configure Microsoft Entra ID by downloading Federation Metadata XML from Azure portal and upload on OutSystems IdP component, according to the following [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Azure_AD_.2F_ADFS).
To configure single sign-on on **SpectrumU** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to SpectrumU support team. They set this setting to have the SAML SSO connection set properly on both sides.
`https://<companyname>.attasksandbox.com/SAML2`
> **Test Connection** queries the SCIM endpoint for a user that doesn't exist, using a random GUID as the matching property selected in the Microsoft Entra configuration. The expected correct response is HTTP 200 OK with an empty SCIM ListResponse message.
manager: pmwongera
In February 2024, we added the following 10 new applications in our App gallery with Federation support:
Use Microsoft Entra groups to simplify role assignment management in Microsoft Entra ID.
Learn about protected actions in Microsoft Entra ID.
Learn about using security questions in Microsoft Entra ID to help improve and secure sign-in events
|---|---|
Web browser and native app support for FIDO2 passwordless authentication using Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
**To get a user provisioned, perform the following steps:**
1. Select one of the four following Tenant URLs according to your Clarizen One environment and data center:

* [A Microsoft Entra tenant](~/identity-platform/quickstart-create-new-tenant.md)
This article describes the steps you need to perform in both askSpoke and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to askSpoke using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
This article describes the steps you need to perform in both Whimsical and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Whimsical](https://whimsical.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
Before configuring Looop for automatic user provisioning with Microsoft Entra ID, you need to retrieve some provisioning information from Looop.
The scenario outlined in this article assumes that you already have the following prerequisites:

- [Multifactor authentication for all users](#multifactor-authentication-for-all-users)
Learn about secretless authentication in Azure to reduce credential risks, enhance security, and streamline user experience with Zero Trust principles.
This article provides information that you need to synchronize your user passwords from an on-premises Active Directory instance to a cloud-based Microsoft Entra instance.
1. Select Restricted Mode, find the **Block addition of new password credentials to apps** setting.
| Minimum lifetime | 1 hour | 10 – 43,200 Minutes (30 days) | Minimum number of minutes that the TAP is valid. |
Grant permissions for application access management in Microsoft Entra ID
1. In the Traffic Manager solution, add the application proxy regional URLs that were created for each app as an endpoint.
> [!IMPORTANT]
After adding app roles in your application, you can assign an app role to a client app by using the Microsoft Entra admin center or programmatically by using [Microsoft Graph](/graph/api/serviceprincipal-post-approleassignments?tabs=http). Assigning an app role to an application shouldn't be confused with [assigning roles to users](../identity/role-based-access-control/manage-roles-portal.md).
If you’re planning to only change the SOA for some Active Directory users, and all your users are currently in a single OU using Kerberos applications that don’t use LDAP, we recommend that you create a new AD DS OU for these objects. Having them in a separate OU will enable you to avoid inadvertently making updates to them in Active Directory after the SOA change. Users, whose SOA isn’t changing, can continue to be managed using Active Directory Users and Computers, Active Directory Module for PowerShell, or other Active Directory management tools. After creating an OU, move the objects to that OU. For more information, see: [Move-ADObject](/powershell/module/activedirectory/move-adobject?view=windowsserver2025-ps&preserve-view=true).
|Partner|Description|
- Always test alerts.
Microsoft Entra ID uses throttling to protect the cloud service from denial-of-service (DoS) attacks. Currently Microsoft Entra ID has a throttling limit of 6,000 writes per 5 minutes (72,000 per hour). For example, the following operations can be throttled:
Ensure that your organization's administrative access and administrator accounts are secure. For system architects and IT pros who configure Microsoft Entra ID, Azure, and Microsoft Online Services.
author: MicrosoftGuyJFlo
| Restriction name | Description | Security value | Availability |
author: MicrosoftGuyJFlo
manager: pmwongera
Consider using the knowledge base of your organization:
Learn how to a role-assignable group in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
Remove role assignments in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
- One of the following Microsoft Entra roles:
`https://<SUBDOMAIN>.anaqua.com/anaqua/Public/login.aspx`
Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services
An [agent identity blueprint](agent-blueprint.md) is used to create agent identities and request tokens using those agent identities. During the process for creating an agent identity blueprint, you set the [owner and sponsor](agent-owners-sponsors-managers.md) of that blueprint, to establish accountability and administrative relationships. You also configure an identifier URI and define a scope for agents created from this blueprint if the agent is designed to receive incoming requests from other agents and users.
A Microsoft Entra documentation page was updated: Create Delete Agent Identities.
Agents can then be assigned access packages through three different request pathways.
Agents can then be assigned access packages through three different request pathways.
The Microsoft agent identity platform introduces an administrative model that separates technical administration from business accountability, ensuring operational control and compliance oversight without excessive permissions. This document explains the administrative relationships for Microsoft Entra Agent ID identity types. This guidance applies to [agent identities](/graph/api/resources/agentidentity?view=graph-rest-beta&preserve-view=true), [agent identity blueprints](/graph/api/resources/agentidentityblueprint?view=graph-rest-beta&preserve-view=true), [agent identity blueprint principals](/graph/api/resources/agentidentityblueprintprincipal?view=graph-rest-beta&preserve-view=true), and [agent users](/graph/api/resources/agentuser?view=graph-rest-beta&preserve-view=true). The article covers owners, sponsors, and managers and their importance in maintaining secure operations.
Learn how to use Microsoft Entra ID Protection for B2B users to secure your organization. Discover benefits and steps to unblock accounts.
|[Edgile, a Wipro company](https://aka.ms/EdgileEntraIDGov) |"Edgile, a Wipro company is excited to be a Microsoft Launch Partner for Microsoft Entra ID Governance. Our deep and broad experience in IGA and security will ensure your project is a success. Our project accelerators will reduce your risk and deliver results faster." |
1. Select **Create**.
:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::
First, call [Create accessPackageResourceRequest](/graph/api/entitlementmanagement-post-resourcerequests?tabs=http) to add the Microsoft Entra role as a resource to the catalog.
Once an access review starts, you can use the [contactedReviewers](/graph/api/resources/accessreviewreviewer) API to retrieve the list of all users who were, or would have been, notified via email to perform reviews. Even in scenarios where notifications were turned off, the API still provides the list of reviewers along with timestamps indicating when notification would happen.
1. Select **Create** to finalize the access review.
:::image type="content" source="media/entitlement-management-access-package-create/api-permissions-roles.png" alt-text="Screenshot of adding API permissions as resource roles to an access package.":::
If these users are brought in with a userType of **guest** they accrue to the meter, however you can avoid being charged by setting up
A conceptual article describing access package visibility in the My Access portal.
You can also manage access packages, catalogs, policies, requests, and assignments using Microsoft Graph. A user in an appropriate role with an application that has the delegated `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` permission can call the [entitlement management API](/graph/api/resources/entitlementmanagement-overview). For more information, see the [Tutorial: manage access to resources - Microsoft Graph](/graph/tutorial-access-package-api?toc=/azure/active-directory/governance/toc.json&bc=/azure/active-directory/governance/breadcrumb/toc.json). An application with the `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` application permissions can also use many of those API functions, except for managing resources in catalogs and access packages. An application that only needs to operate within specific catalogs can be added to the **Catalog owner** or **Catalog reader** roles of a catalog to be authorized to update or read within that catalog.
You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.
Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)
| Windows Microsoft Entra Registered device | User selects a tenant at first sign-in; remains connected to that tenant. | ❌ | ❌ | ❌ | ✅ | Cannot switch to other registered tenants for now. Allows user to switch to a resource tenant using external user access(B2B). |
author: MicrosoftGuyJFlo
Create a Conditional Access policy for end users or groups and deliver your security profile through Conditional Access Session controls. Conditional Access is the delivery mechanism for user and context awareness for Internet Access policies. To learn more about session controls, see [Conditional Access: Session](/azure/active-directory/conditional-access/concept-conditional-access-session).
Step-by-step instructions for configuring managed identities for Azure resources on a virtual machine scale set using the Azure portal.
Step-by-step instructions for configuring system and user-assigned managed identities on an Azure VMs.
A tutorial that walks you through the process of using a system-assigned managed identity on a virtual machine (VM) to access Azure Resource Manager.
Learn how to use managed identities with Windows VMs using the Azure portal, CLI, PowerShell, Azure Resource Manager template
Step-by-step instructions for viewing the Azure resources that are associated with a user-assigned managed identity
Step-by-step instructions for viewing the service principal of a managed identity.
| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |
Step-by-step instructions and examples for using an Azure VM-managed identities for Azure resources service principal for script client sign-in and resource access.
An overview how developers can use managed identities for Azure resources.
Learn how workload identify federation enables secure access to Microsoft Entra protected resources from external software workloads without managing secrets.
- Azure Virtual Desktop single-session is supported.
`nltest /dsgetdc:contoso /keylist /kdc`
> * Internet resources with Global Secure Access
Released for download on December 3, 2025.
| Platform/device state | Connection target | Entra tunnel | M365 tunnel | Internet tunnel | Private tunnel | Notes |
**Q: Can I configure MFA on the resource tenant?**
> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.
> You can add up to 500 application segments to your Quick Access app.
| **[BEMO](https://aka.ms/BemoSSELaunchPartner)** | BEMO is a trusted expert in delivering Microsoft's SSE solution to SMBs across the United States with up to 1,000 employees. BEMO specializes in Modern Work and Security, helping SMBs achieve their security and compliance (SOC 2, CMMC, ISO 27001, NIST 800-171, HIPAA) goals by leveraging Microsoft technologies. |
- A **Global Secure Access Administrator** role in Microsoft Entra ID.
- The platform assumes standard ports for HTTP/S traffic (ports 80 and 443).