Week in brief

Application Proxy and Global Secure Access dominate the week’s documentation refresh; Agent ID adds new AI-guided setup documentation

The week of 9 March was primarily a Microsoft Learn maintenance and expansion cycle: 103 entries, including 5 new pages and 98 updates, with no removals or Message Center notices. The most consequential content is a coordinated refresh for Microsoft Entra application proxy and a broad set of Global Secure Access, Internet Access, and Private Access deployment and inspection guides. Two new Agent ID pages document AI-assisted onboarding. Authentication material also clarifies system-preferred MFA behavior and native/passwordless implementation guidance. The supplied record contains no explicit preview, general-availability, retirement, or required tenant-change announcement.

  • Microsoft Entra application proxy received a substantial operational documentation refreshEntra ID — Microsoft Entra application proxy

    Updated pages span deployment planning, architecture and security, connector troubleshooting, custom domains and home pages, single sign-on, PingAccess header-based authentication, Defender for Cloud Apps Conditional Access App Control, and publishing SharePoint, Power BI, Remote Desktop Services, Qlik Sense, and NDES applications. The same update cluster covers Application Gateway WAF protection and PowerShell samples for inventory, assignments, connector groups, wildcard and default domains, token-lifetime policy

  • Global Secure Access guidance now connects rollout, policy, and inspection proceduresGlobal Secure Access / Microsoft Entra Internet Access / Private Access

    Updated Global Secure Access and Microsoft Entra Internet Access and Private Access pages cover remote networks with Conditional Access and logs, traffic-forwarding profile management, user and group assignment, Windows client installation, per-app and Quick Access to private resources, web content filtering, built-in roles, and coexistence with Zscaler, Netskope, and Palo Alto Networks. Three new pages filed under Entra ID describe inspection across all Secure Web Gateway defense layers, a TLS inspection failure-r

  • Agent ID adds a documented AI-guided onboarding workflowMicrosoft Entra Agent ID

    Two pages were marked New: Agent ID Setup Instructions and AI-guided setup for Microsoft Entra Agent ID. Their summaries describe using an AI coding agent to automate blueprint creation, credential configuration, and agent identity provisioning. A related update emphasizes executing the setup steps sequentially without skipping ahead. This is new setup documentation, not a stated preview or general-availability announcement.

  • System-preferred MFA guidance clarifies dynamic ordering and Conditional Access precedenceEntra ID — System-preferred multifactor authentication

    The updated Entra ID guidance says the preferred method is selected dynamically from a user’s registered methods and may evolve as the security landscape and authentication methods change. Users can cancel and choose another available method, but Conditional Access policies requiring specific authentication methods continue to take priority. This is a documentation clarification of the described sign-in behavior, not evidence that the MFA order changed during the week.

  • Native Authentication and Windows passwordless guidance added implementation detailEntra ID — Native Authentication and passwordless security keys

    Native Authentication updates include a feature-availability table comparing browser-delegated and native authentication. iOS and macOS guidance says to store refresh tokens in encrypted, platform-protected storage. Updated Windows security-key guidance includes OOBE sign-in with a passkey and Web sign-in to unlock a Windows device. These are implementation and security guidance updates; the entries do not announce a separate API launch or availability milestone.

For Entra administrators

Treat this as a capability-specific documentation review rather than a tenant-wide rollout. Application Proxy owners can compare current deployment, connector, certificate, assignment, and publishing procedures with the revised guidance. Global Secure Access operators can review profile assignment, Conditional Access and logging, client, inspection, and coexistence material. Agent ID development teams can evaluate the documented sequential setup path, while authentication teams can align policy and application guidance with the stated MFA precedence and token-storage recommendations. The evidence supports review where these capabilities are in use, not a blanket configuration change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Developer

23

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

12 March 2026

Fundamentals

9

System Preferred Multifactor Authentication

Updated

When a user signs in, the authentication process checks which authentication methods are registered for the user. The user is prompted to sign-in with the most secure method according to the following order. The order of authentication methods is dynamic. It's updated as the security landscape changes, and as better authentication methods emerge. Users can always cancel and choose a different available sign in method if needed. If your organization has Conditional Access policies that require specific authentication methods, those policies will continue to take priority over the system preferred MFA order. Click the link for more information about each method.

14 March 2026

What Is Cloud Sync

Updated

Cloud Sync solves common challenges organizations face with hybrid identity infrastructure by eliminating single points of failure, reducing on-premises management overhead, and enabling complex multi-forest scenarios that support organizational growth and change.

14 March 2026

Native Authentication

Updated

The following table shows the availability of features for browser-delegated and native authentication.

13 March 2026

Whats New

Updated

**Service category:** Entra Connect

13 March 2026

Configure Security

Updated

| [TLS inspection is enabled and correctly configured for outbound traffic](zero-trust-protect-networks.md#tls-inspection-is-enabled-and-correctly-configured-for-outbound-traffic) | Microsoft Entra ID P1 |

12 March 2026

General

7

Admin Units Members Add

Updated

To create a new group directly in an administrative unit, use the following request. To add an existing group instead, see **Add groups to an administrative unit** earlier in this article.

10 March 2026

Authentication

6

Get all application proxy apps and list extended information

Updated

PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).

12 March 2026

Howto Authentication Passwordless Security Key Windows

Updated

- OOBE sign-in with a passkey is supported. You can use Web sign-in to unlock a Windows device. For more information, see [Use Web Sign-In To Enable Passwordless Sign-In In Windows](/windows/security/identity-protection/web-sign-in).

11 March 2026

Provisioning

3

G Suite Provisioning Tutorial

Updated

1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).

13 March 2026

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

This article describes the steps you need to perform in both GitHub Enterprise Managed User (OIDC) and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to GitHub Enterprise Managed User (OIDC) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

13 March 2026

Connect Version History

Updated

- Fixed a [known issue](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified) where auto-upgrade could stop your Microsoft Entra Connect server unexpectedly. Auto-upgrade now detects modifications to the `miiserver.exe.config` and `miisclient.exe.config` configuration files and skips automatic upgrade on those servers. If you manually upgrade and previously modified these configuration files, you might encounter installation failures. To resolve the issue, see the [known issues section](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified).

12 March 2026

Security

3

Architecture

2

Standards

2

Tutorial Manage Certificates For Federated Single Sign On

Updated

This section will outline best practices independent software vendors (ISV’s) can adopt to enable automated certificate rollover when SAML certificates are near expiry and when applications federated with Microsoft Entra ID. SAML certificates in Entra ID are used for signing assertions in federated single sign-on (SSO). These certificates expire (typically every 1-3 years) and rotation requires a Customer and SaaS ISV coordination to update a mutual certificate in both systems without downtime. Industry trends are shortening certificate lifetimes, manual rollover processes increasingly create operational burden and risk service disruption — especially in large organizations with many SAML enterprise applications.

12 March 2026

Conditional Access

1

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

12 March 2026

Monitoring

1

Sla Performance

Updated

| Month | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 |

11 March 2026

Troubleshooting

1

Troubleshoot Application Proxy

Updated

Learn how to troubleshoot common errors and configuration problems with Microsoft Entra application proxy.

11 March 2026

General

2

Developer

1

Agent ID Setup Instructions

New

This file is used by an AI coding agent (such as GitHub Copilot in VS Code Agent mode) to automate onboarding to Microsoft Entra Agent ID.

12 March 2026

Provisioning

1

AI-guided setup for Microsoft Entra Agent ID

New

Use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.

12 March 2026

Governance

3

Simulate Workflow Execution

Updated

Learn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.

11 March 2026

Entitlement Management Catalog Create

Updated

1. If you want to allow users in external directories from connected organizations to be able to request access packages in this catalog, set **Enabled for external users** to **Yes**. The access packages must also have a policy allowing users from connected organizations to request. If the access packages in this catalog are intended only for users already in the directory, then set **Enabled for external users** to **No**.

10 March 2026

Perform Access Review

Updated

Microsoft Entra ID simplifies how enterprises manage access to groups and applications in Microsoft Entra ID and other Microsoft web services with a feature called access reviews. This article covers how a designated reviewer performs an access review for members of a group or users with access to an application. If you want to review access to an access package, read [Review access of an access package in entitlement management](entitlement-management-access-reviews-review-access.md).

10 March 2026

General

4

Security

1

Netskope Coexistence

Updated

Learn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.

14 March 2026

General

1

Microsoft identity platform

1

Create A Free Developer Account

Updated

- **Free Microsoft Entra tenant** — [Create a new tenant](~/identity-platform/quickstart-create-new-tenant.md) with an [Azure free account](https://azure.microsoft.com/pricing/purchase-options/azure-account). This gives you Entra ID Free tier. You can then [activate a free trial of Microsoft Entra ID P1 or P2](~/fundamentals/get-started-premium.md) if needed for testing.

10 March 2026

General

16

Security

8

Zscaler Coexistence

Updated

Learn how to configure Microsoft and Zscaler SSE for unified SASE solutions to enhance security and connectivity in your organization.

14 March 2026

27014

Updated

The Global Secure Access Secure Web Gateway (SWG) implements defense-in-depth through five security layers that together create a comprehensive inspection chain for internet-bound traffic. Each layer serves a distinct protective function:

12 March 2026

Fundamentals

4

What is Global Secure Access?

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

14 March 2026

Partner Ecosystem Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

14 March 2026

Troubleshooting

2

Conditional Access

1