Week in brief

Conditional Access is the documented delivery path for web content filtering; Microsoft Rewards account linking retires 19 March

The week of 16 February 2026 was dominated by Learn maintenance—132 updates and six new pages, including many SSO and provisioning tutorials—rather than a broad release announcement. The main substantive thread is new cross-product guidance for web content filtering across Microsoft Entra ID, Internet Access, and Global Secure Access. The only explicit lifecycle event is the retirement of Azure AD Account Linking for Microsoft Rewards. The supplied evidence does not identify a preview or general-availability milestone for the new web-filtering or Agent ID material.

  • New Microsoft Entra ID pages describe Conditional Access integration, category-based rules, and links between web-content-filtering policies and security profiles. Updated Internet Access guidance says administrators create a Conditional Access policy for users or groups and use Conditional Access Session controls to deliver the security profile and user/context awareness. Companion Global Secure Access guidance records different propagation times for Global Secure Access and Conditional Access changes. This is a)

  • Entra ID / Microsoft Rewards integrationAzure AD Account Linking for Microsoft Rewards is retiring

    A 19 February Microsoft 365 Message Center major update says Microsoft is retiring Azure AD Account Linking for Microsoft Rewards by 19 March 2026. After retirement, work accounts will no longer be linkable for earning Rewards points; existing points and personal-account use are unaffected. The notice explicitly says that no administrator action is required.

  • Updated Agent ID guidance says a blueprint creates agent identities and supports token requests using those identities. It describes setting an owner and sponsor to establish accountability and administrative relationships, plus configuring an identifier URI and scope when agents created from the blueprint must receive incoming requests from other agents or users. The feed marks this as documentation updated, not as a stated availability milestone.

  • The updated Temporary Access Pass page includes a Minimum lifetime row that pairs a 1-hour value with a 10–43,200-minute range, or up to 30 days, and describes the setting as the number of minutes the TAP remains valid. The evidence does not say that existing tenant policies or service behavior changed, so this is best treated as a current reference for checking TAP configuration.

  • An updated Configure Quick Access page states that a Quick Access app can contain up to 500 application segments. The supplied change record does not establish that the limit was introduced or increased during this week; it should be treated as a documented capacity boundary rather than a feature launch.

For Entra administrators

Administrators implementing web content filtering should use the documented Conditional Access session-control path and plan around the stated propagation difference: typically less than five minutes for changes in the Global Secure Access experience and approximately one hour for Conditional Access changes. No tenant action is required for the Microsoft Rewards retirement. For Agent ID, Temporary Access Pass, and Quick Access, use the updated pages to validate designs and settings, but do not infer a new release or changed service behavior from documentation updates alone.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

39

Concur Tutorial

Updated

| `https://<customer-domain>.concursolutions.com` |

20 February 2026

Lensesio Tutorial

Updated

c. **Sign on URL**: Enter a URL that has the following pattern: `https://<CUSTOMER_LENSES_BASE_URL>`. An example is `https://lenses.my.company.com`.

20 February 2026

Sciforma Tutorial

Updated

`https://<SUBDOMAIN>.sciforma.net/sciforma/main.html`

20 February 2026

Docker Tutorial

Updated

The scenario outlined in this article assumes that you already have the following prerequisites:

20 February 2026

Ebsco Tutorial

Updated

o **Custid** = Enter unique EBSCO customer ID

20 February 2026

Mitel Connect Tutorial

Updated

In this section, you create a user named Britta Simon on your MiCloud Connect account. Users must be created and activated before using single sign-on.

20 February 2026

Sap Successfactors Writeback Tutorial

Updated

| 4 | true | emailIsPrimary | Use this attribute to set business email as primary in SuccessFactors. If business email isn't primary, set this flag to false. |

20 February 2026

Identifier Uri Restrictions

Updated

There are three possible ways that you can add an identifier URI to your app. We recommend them in the following order:

18 February 2026

Standards

14

Tripwire Enterprise Tutorial

Updated

To configure single sign-on in Tripwire Enterprise, please see **Using Tripwire Enterprise with SAML Authentication** section in the Tripwire Enterprise Hardening Guide, available for download on the Tripwire Customer Center. If you require assistance, contact [Tripwire Enterprise support team](mailto:[email protected]).

20 February 2026

Achieve3000 Tutorial

Updated

`https://saml.achieve3000.com/district/<District Identifier>`

20 February 2026

Crowd Log Tutorial

Updated

To perform the Single Sign-On configuration on the Crowd Log side, please refer to the Crowd Log SAML admin settings documentation.

20 February 2026

In Case Of Crisis Mobile Tutorial

Updated

To configure single sign-on on **In Case of Crisis - Mobile** side, you need to send the downloaded **Certificate (Raw)** and copied **User access URL** from Azure portal to In Case of Crisis - Mobile support team. They set this setting to have the SAML SSO connection set properly on both sides.

20 February 2026

Lexmark Cloud Services Tutorial

Updated

To configure single sign-on on **Lexmark Cloud Services (SAML)** side, you need to send the **App Federation Metadata Url** to Lexmark Cloud Services (SAML) support team. They set this setting to have the SAML SSO connection set properly on both sides. Also review the [Lexmark documentation](https://support.lexmark.com/en_us/manuals-guides/online/Lexmark-Cloud-Platform/configuring-microsoft-entra-id-federation-for-saml.html) on Configuring Microsoft Entra ID with SAML Federation

20 February 2026

On24 Tutorial

Updated

To configure single sign-on on **ON24 Virtual Environment SAML Connection** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to ON24 Virtual Environment SAML Connection support team. They set this setting to have the SAML SSO connection set properly on both sides.

20 February 2026

Gaggleamp Tutorial

Updated

1. In another browser instance, navigate to the SAML SSO page created for you by the Gaggle support team (for example: `https://accounts.gaggleamp.com/saml_configurations/oXH8sQcP79dOzgFPqrMTyw/edit`).

20 February 2026

Oreilly Learning Platform Provisioning Tutorial

Updated

Before you begin to configure the O'Reilly learning platform to support provisioning with Microsoft Entra ID, you’ll need to generate a SCIM API token within the O’Reilly Admin Console.

20 February 2026

Outsystems Tutorial

Updated

To configure single sign-on on OutSystems side, you need to download the IdP forge component, configure it as mentioned in the [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Configure_your_application_to_use_IdP_connector). After installing the component and do the necessary code changes, configure Microsoft Entra ID by downloading Federation Metadata XML from Azure portal and upload on OutSystems IdP component, according to the following [instructions](https://success.outsystems.com/Documentation/Development_FAQs/How_to_configure_OutSystems_to_use_identity_providers_using_SAML#Azure_AD_.2F_ADFS).

20 February 2026

Spectrumu Tutorial

Updated

To configure single sign-on on **SpectrumU** side, you need to send the downloaded **Federation Metadata XML** and appropriate copied URLs from the application configuration to SpectrumU support team. They set this setting to have the SAML SSO connection set properly on both sides.

20 February 2026

Use Scim To Provision Users And Groups

Updated

> **Test Connection** queries the SCIM endpoint for a user that doesn't exist, using a random GUID as the matching property selected in the Microsoft Entra configuration. The expected correct response is HTTP 200 OK with an empty SCIM ListResponse message.

19 February 2026

Fundamentals

9

Whats New Archive

Updated

In February 2024, we added the following 10 new applications in our App gallery with Federation support:

20 February 2026

Provisioning

9

Configure askSpoke for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both askSpoke and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to askSpoke using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

20 February 2026

Configure Whimsical for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both Whimsical and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Whimsical](https://whimsical.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

20 February 2026

Looop Provisioning Tutorial

Updated

Before configuring Looop for automatic user provisioning with Microsoft Entra ID, you need to retrieve some provisioning information from Looop.

20 February 2026

Authentication

5

Managed Policies

Updated

- [Multifactor authentication for all users](#multifactor-authentication-for-all-users)

21 February 2026

Secretless authentication in Azure

Updated

Learn about secretless authentication in Azure to reduce credential risks, enhance security, and streamline user experience with Zero Trust principles.

20 February 2026

Block Password Addition

Updated

1. Select Restricted Mode, find the **Block addition of new password credentials to apps** setting.

18 February 2026

Developer

5

Howto Add App Roles In Apps

Updated

After adding app roles in your application, you can assign an app role to a client app by using the Microsoft Entra admin center or programmatically by using [Microsoft Graph](/graph/api/serviceprincipal-post-approleassignments?tabs=http). Assigning an app role to an application shouldn't be confused with [assigning roles to users](../identity/role-based-access-control/manage-roles-portal.md).

18 February 2026

Prepare User Source Of Authority Environment

Updated

If you’re planning to only change the SOA for some Active Directory users, and all your users are currently in a single OU using Kerberos applications that don’t use LDAP, we recommend that you create a new AD DS OU for these objects. Having them in a separate OU will enable you to avoid inadvertently making updates to them in Active Directory after the SOA change. Users, whose SOA isn’t changing, can continue to be managed using Active Directory Users and Computers, Active Directory Module for PowerShell, or other Active Directory management tools. After creating an OU, move the objects to that OU. For more information, see: [Move-ADObject](/powershell/module/activedirectory/move-adobject?view=windowsserver2025-ps&preserve-view=true).

18 February 2026

Architecture

4

Security

4

Plan Connect Performance Factors

Updated

Microsoft Entra ID uses throttling to protect the cloud service from denial-of-service (DoS) attacks. Currently Microsoft Entra ID has a throttling limit of 6,000 writes per 5 minutes (72,000 per hour). For example, the following operations can be throttled:

20 February 2026

Conditional Access

3

Microsoft identity platform

3

Remove Microsoft Entra role assignments

Updated

Remove role assignments in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.

20 February 2026

Monitoring

2

Anaqua Tutorial

Updated

`https://<SUBDOMAIN>.anaqua.com/anaqua/Public/login.aspx`

20 February 2026

Roles across Microsoft services

Updated

Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services

20 February 2026

General

3

Create an agent identity blueprint

Updated

An [agent identity blueprint](agent-blueprint.md) is used to create agent identities and request tokens using those agent identities. During the process for creating an agent identity blueprint, you set the [owner and sponsor](agent-owners-sponsors-managers.md) of that blueprint, to establish accountability and administrative relationships. You also configure an identifier URI and define a scope for agents created from this blueprint if the agent is designed to receive incoming requests from other agents and users.

20 February 2026

Agent Access Packages

Updated

Agents can then be assigned access packages through three different request pathways.

18 February 2026

Fundamentals

1

Microsoft identity platform

1

Administrative relationships in Microsoft Entra Agent ID (Owners, sponsors, and managers)

Updated

The Microsoft agent identity platform introduces an administrative model that separates technical administration from business accountability, ensuring operational control and compliance oversight without excessive permissions. This document explains the administrative relationships for Microsoft Entra Agent ID identity types. This guidance applies to [agent identities](/graph/api/resources/agentidentity?view=graph-rest-beta&preserve-view=true), [agent identity blueprints](/graph/api/resources/agentidentityblueprint?view=graph-rest-beta&preserve-view=true), [agent identity blueprint principals](/graph/api/resources/agentidentityblueprintprincipal?view=graph-rest-beta&preserve-view=true), and [agent users](/graph/api/resources/agentuser?view=graph-rest-beta&preserve-view=true). The article covers owners, sponsors, and managers and their importance in maintaining secure operations.

18 February 2026

Fundamentals

1

Governance

8

Services And Integration Partners Governance

Updated

|[Edgile, a Wipro company](https://aka.ms/EdgileEntraIDGov) |"Edgile, a Wipro company is excited to be a Microsoft Launch Partner for Microsoft Entra ID Governance. Our deep and broad experience in IGA and security will ensure your project is a success. Our project accelerators will reduce your risk and deliver results faster." |

20 February 2026

Entitlement Management Dynamic Approval

Updated

:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::

18 February 2026

Entitlement Management Roles

Updated

First, call [Create accessPackageResourceRequest](/graph/api/entitlementmanagement-post-resourcerequests?tabs=http) to add the Microsoft Entra role as a resource to the catalog.

18 February 2026

Access Reviews Faqs

Updated

Once an access review starts, you can use the [contactedReviewers](/graph/api/resources/accessreviewreviewer) API to retrieve the list of all users who were, or would have been, notified via email to perform reviews. Even in scenarios where notifications were turned off, the API still provides the list of reviewers along with timestamps indicating when notification would happen.

18 February 2026

Entitlement Management Access Package Resources

Updated

:::image type="content" source="media/entitlement-management-access-package-create/api-permissions-roles.png" alt-text="Screenshot of adding API permissions as resource roles to an access package.":::

18 February 2026

Fundamentals

2

Entitlement Management Scenarios

Updated

You can also manage access packages, catalogs, policies, requests, and assignments using Microsoft Graph. A user in an appropriate role with an application that has the delegated `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` permission can call the [entitlement management API](/graph/api/resources/entitlementmanagement-overview). For more information, see the [Tutorial: manage access to resources - Microsoft Graph](/graph/tutorial-access-package-api?toc=/azure/active-directory/governance/toc.json&bc=/azure/active-directory/governance/breadcrumb/toc.json). An application with the `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` application permissions can also use many of those API functions, except for managing resources in catalogs and access packages. An application that only needs to operate within specific catalogs can be added to the **Catalog owner** or **Catalog reader** roles of a catalog to be authorized to update or read within that catalog.

18 February 2026

Architecture

1

Pim Deployment Plan

Updated

You assign users the role with the [least privileges necessary to perform their tasks](~/identity/role-based-access-control/delegate-by-task.md). This practice minimizes the number of Global Administrators and instead uses specific administrator roles for certain scenarios.

20 February 2026

Architecture

1

10 Secure Local Guest

Updated

Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)

18 February 2026

Fundamentals

1

Bring Your Own Device

Updated

| Windows Microsoft Entra Registered device | User selects a tenant at first sign-in; remains connected to that tenant. | ❌ | ❌ | ❌ | ✅ | Cannot switch to other registered tenants for now. Allows user to switch to a resource tenant using external user access(B2B). |

20 February 2026

General

1

Fundamentals

1

Configure Web Content Filtering

Updated

Create a Conditional Access policy for end users or groups and deliver your security profile through Conditional Access Session controls. Conditional Access is the delivery mechanism for user and context awareness for Internet Access policies. To learn more about session controls, see [Conditional Access: Session](/azure/active-directory/conditional-access/concept-conditional-access-session).

20 February 2026

General

7

Managed Identities Status

Updated

| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |

18 February 2026

Authentication

1

Microsoft identity platform

1

Security

1

Workload Identity Federation

Updated

Learn how workload identify federation enables secure access to Microsoft Entra protected resources from external software workloads without managing secrets.

17 February 2026

General

4

Compliant Network

Updated

> * Internet resources with Global Secure Access

18 February 2026

Fundamentals

2

Bring Your Own Device

Updated

| Platform/device state | Connection target | Entra tunnel | M365 tunnel | Internet tunnel | Private tunnel | Notes |

19 February 2026

Conditional Access

1

Configure Web Content Filtering

Updated

> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.

18 February 2026

Developer

1

Configure Quick Access

Updated

> You can add up to 500 application segments to your Quick Access app.

18 February 2026

Monitoring

1

Find Microsoft Services Partners

Updated

| **[BEMO](https://aka.ms/BemoSSELaunchPartner)** | BEMO is a trusted expert in delivering Microsoft's SSE solution to SMBs across the United States with up to 1,000 employees. BEMO specializes in Modern Work and Security, helping SMBs achieve their security and compliance (SOC 2, CMMC, ISO 27001, NIST 800-171, HIPAA) goals by leveraging Microsoft technologies. |

20 February 2026

Security

1

Standards

1