Week in brief

Security Copilot’s E5 rollout and My Groups enhancements headline a documentation-heavy Entra week

Of 236 entries for the week of 23 March 2026, 233 were updates, one was new, none were removed, and two were Message Center notices. The most substantive items are the planned Microsoft 365 E5 inclusion of Security Copilot, expanded Microsoft 365 group owner controls in My Groups, and a new phased migration guide from DirectAccess to Microsoft Entra Private Access. Most other representative changes are ordinary documentation maintenance—policy steps, role prerequisites, screenshots, troubleshooting, and explanatory text around Conditional Access, Global Secure Access, Internet Access, and External ID. None of the supplied entries identifies a preview, general availability release, or retirement.

  • Security Copilot is scheduled for phased inclusion in Microsoft 365 E5Security Copilot / Microsoft 365 E5

    A Message Center notice says the rollout will run from 20 April through 30 June 2026. The E5 inclusion provides 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products; additional advanced capabilities may incur extra costs. This is a Microsoft 365 and Security Copilot service-entitlement notice, not evidence of an Entra ID feature launch or preview/GA change.

  • My Groups is expanding Microsoft 365 group owner self-serviceEntra ID — My Groups / Microsoft 365 Groups

    The Message Center says the enhancement will arrive by late March 2026. Group owners will be able to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The notice says existing groups are unaffected and no admin setup is required, making this a management-experience change rather than a new Conditional Access or access-control policy.

  • A new Learn page documents a phased DirectAccess-to-Private Access migrationMicrosoft Entra Private Access

    The new Microsoft Entra Private Access page explains how to move client devices from DirectAccess in phases while avoiding tunnel conflicts and connectivity failures. Companion material describes DirectAccess as relying on IPv6 transition technologies, domain-joined Windows Enterprise clients, and full network-level access. This is migration guidance, not a product launch and not a stated DirectAccess retirement.

  • Conditional Access guidance clarifies session behavior and Global Secure Access targetingEntra ID Conditional Access; Global Secure Access; Internet Access

    Updated Entra ID documentation states that Sign-in frequency – every time allows five minutes of clock skew; when MFA was completed within the previous five minutes, another Conditional Access policy requiring reauthentication does not prompt again. It also advises using every-time reauthentication only for specific business needs and directs administrators to sign-in logs and the Conditional Access tab to diagnose authentication-flow policy matches. Related Global Secure Access and Internet Access pages document22

For Entra administrators

For Microsoft 365 E5 tenants, note the Security Copilot rollout window of 20 April through 30 June 2026, the stated allocation of 400 Security Compute Units per 1,000 users, and the possibility of additional charges for advanced capabilities; the notice does not specify an Entra configuration step. My Groups requires no admin setup according to the notice and does not affect existing groups, but owners will gain more self-service controls. Organizations still using DirectAccess have a concrete migration reference, though it is not a retirement announcement. The remaining documentation changes warrant targeted review only where relevant to existing Conditional Access, Global Secure Access, Internet Access, or External ID designs.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Conditional Access

23

Microsoft-managed Conditional Access policies

Updated

Every day, Microsoft processes more than 100 trillion security signals from endpoints, cloud services, identity systems, and more. We use this data shape how we respond to threats and inform how we innovate to help build a safer digital future. Read about the work we're doing in the [Microsoft Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1).

26 March 2026

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

26 March 2026

Migrate Approved Client App

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Agent Block High Risk

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Risk Based Insider Block

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Deployment Guide Token Protection Apple

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Block By Location

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Block Example

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Howto Conditional Access Insights Reporting

Updated

![Screenshot showing a workbook breakdown per condition and status.](./media/howto-conditional-access-insights-reporting/workbook-breakdown-condition-and-status.png)

24 March 2026

Policy All Users App Enforced Restrictions

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Device Compliance

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Device Registration

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Device Unknown Unsupported

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Mfa Strength

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy All Users Persistent Browser

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Alt Admin Device Compliand Hybrid

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Alt All Users Compliant Hybrid Or Mfa

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Guests Mfa Strength

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Admin

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Admin Portals

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Azure Mgmt

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Policy Old Require Mfa Guest

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Developer

20

Application Proxy Configure Complex Application

Updated

:::image type="content" source="./media/application-proxy-configure-complex-application/complex-app-structure-1.png" alt-text="Diagram of domain structure for a complex application showing resource sharing between primary and secondary application.":::

27 March 2026

Application Proxy Integrate With Remote Desktop Services

Updated

8. Run this command for each collection. Replace *\<yourcollectionname\>* and *\<proxyfrontendurl\>* with your own information. This command enables single sign-on between RD Web and RD Gateway, and optimizes performance.

27 March 2026

Application Proxy Qlik

Updated

Follow the same steps as for Application #1, with the following exceptions:

27 March 2026

Application Proxy Configure Cookie Settings

Updated

Cookies that don't specify the [SameSite](https://web.dev/articles/samesite-cookies-explained) attribute are treated as if they're set to **SameSite=Lax**. The `SameSite` attribute declares how cookies should be restricted to a same-site context. When set to `Lax`, the cookie is only sent to same-site requests or top-level navigation. However, application proxy requires these cookies to be preserved in the third-party context to keep users signed in during their session. Due to the requirement, updates were made:

27 March 2026

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

26 March 2026

Grant Admin Consent

Updated

Learn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.

26 March 2026

Fundamentals

15

Whats New

Updated

**What’s changing**

25 March 2026

Filter For Applications

Updated

Follow the instructions in the article, [Add or deactivate custom security attributes in Microsoft Entra ID](~/fundamentals/custom-security-attributes-add.md) to add the following **Attribute set** and **New attributes**.

24 March 2026

Conditional Access Cloud Apps

Updated

Microsoft 365 offers cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. In Conditional Access, the Microsoft 365 suite of applications appears under 'Office 365'. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration might cause confusion when creating policies because some apps, like Microsoft Teams, depend on others, like SharePoint or Exchange.

24 March 2026

Authentication Flows

Updated

If you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, selecting the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.

24 March 2026

Conditional Access Users Groups

Updated

To prevent admin lockout, when creating a policy applied to **All users** and **All apps**, the following warning appears.

24 March 2026

Plan Conditional Access

Updated

- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).

24 March 2026

Policy All Users Approved App Or App Protection

Updated

With Conditional Access, organizations can restrict access to [approved (modern authentication capable) client apps with Intune app protection policies](concept-conditional-access-grant.md#require-app-protection-policy). For older client apps that may not support app protection policies, administrators can restrict access to [approved client apps](concept-conditional-access-grant.md#require-approved-client-app).

24 March 2026

Condition Filters For Devices

Updated

There are multiple scenarios that organizations can now enable using filter for devices condition. The following scenarios provide examples of how to use this new condition.

24 March 2026

General

13

Migrate Group Writeback

Updated

- A Microsoft Entra account with at least a [Hybrid Identity administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.

27 March 2026

Clever Tutorial

Updated

<a name='configure-and-test-azure-ad-sso-for-clever'></a>

26 March 2026

My Staff Configure

Updated

After configuring administrative units, you can apply this scope to your users who access My Staff. Only users who are assigned an administrative role can access My Staff. To enable My Staff, complete the following steps:

26 March 2026

Terms Of Use

Updated

* Microsoft Entra ID P1 licenses.

24 March 2026

Authentication

12

Stormshield Network Security Tutorial

Updated

This section guides you through the necessary configurations on the **Stormshield Network Security (SNS) firewall** to enable **OIDC authentication** via **Microsoft Entra ID**.

26 March 2026

Privileged Authentication Administrator

Updated

>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

25 March 2026

Howto Conditional Access Session Lifetime

Updated

The system accounts for five minutes of clock skew when **every time** is selected in policy, so users aren’t prompted more often than once every five minutes. If the user completes MFA in the last 5 minutes and encounters another Conditional Access policy that requires reauthentication, we don't prompt the user. Prompting users too often for reauthentication can affect their productivity and increase the risk of users approving MFA requests they didn’t initiate. Use "Sign-in frequency – every time" only when there are specific business needs.

24 March 2026

Policy All Users Copilot Ai Security

Updated

The following steps help create a Conditional Access policy to require all users to perform multifactor authentication using the authentication strength policy.

24 March 2026

Policy Block Legacy Authentication

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

Security

8

New M365 group creation and editing in My Groups

New

Microsoft 365 group creation and editing in My Groups will be enhanced by late March 2026, allowing owners to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The update improves control and clarity without impacting existing groups or requiring admin setup.

27 March 2026
Message CenterMC1262589 on mc.merill.net ↗Stay informed

Helpdesk Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

25 March 2026

User Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

25 March 2026

Policy All Users Windows App Protection

Updated

- Policy can be applied to the Microsoft Edge browser on devices running Windows 11 and Windows 10 version 20H2 and higher with KB5031445.

24 March 2026

Microsoft identity platform

6

Authentication Flows App Scenarios

Updated

To call a web API from a web app on behalf of a user, use the authorization code flow and store the acquired tokens in the token cache. When needed, MSAL refreshes tokens and the controller silently acquires tokens from the cache.

26 March 2026

Apple Sso Plugin

Updated

If your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.

24 March 2026

Conditional Access Conditions

Updated

- Admins can apply policy only to supported platforms (such as iOS, Android, and Windows) through the Conditional Access Microsoft Graph API.

24 March 2026

Monitoring

6

Application Proxy Network Topology

Updated

Place the connector close to the target application in the customer network. This configuration minimizes step 3 in the topography diagram, because the connector and application are close.

27 March 2026

Permissions Reference

Updated

> | [Compliance Administrator](#compliance-administrator) | Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |

24 March 2026

What If Tool

Updated

Start an evaluation by selecting **What If**. The evaluation result provides you with a report that consists of:

24 March 2026

Provisioning

5

Tap App Security Provisioning Tutorial

Updated

1. After entering the domain, a new line in the table appears showing domain name and its status as **initialize**. Select the gear icon to reveal technical data about TAP app Security server and to complete initialization.

27 March 2026

Standards

5

Policy Guests Mfa Strength

Updated

1. Give your policy a name. Create a meaningful standard for the names of your policies.

28 March 2026

Segment Provisioning Tutorial

Updated

1. The Tenant URL is `https://scim.segmentapis.com/scim/v2`. This value is entered in the **Tenant URL** field in the Provisioning tab of your Segment application.

27 March 2026

Snowflake Provisioning Tutorial

Updated

The Microsoft Entra provisioning service currently operates under particular [IP ranges](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md#ip-ranges). If necessary, you can restrict other IP ranges and add these particular IP ranges to the allow list of your application. That technique will allow traffic flow from the Microsoft Entra provisioning service to your application.

27 March 2026

Continuous access evaluation

Updated

Token expiration and refresh are a standard mechanism in the industry. When a client application like Outlook connects to a service like Exchange Online, the API requests are authorized using OAuth 2.0 access tokens. By default, access tokens are valid for one hour, when they expire the client is redirected to Microsoft Entra to refresh them. That refresh period provides an opportunity to reevaluate policies for user access. For example: the token might not be refreshed because of a Conditional Access policy, or because the user is disabled in the directory.

24 March 2026

Architecture

1

Recoverability Overview

Updated

- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.

28 March 2026

Governance

1

Troubleshooting

1

Troubleshoot Conditional Access

Updated

To get detailed information about the sign-in interruption, review the Microsoft Entra sign-in events to see which Conditional Access policy or policies applied and why.

24 March 2026

Conditional Access

1

Agent Id

Updated

There are two key business scenarios where Conditional Access policies can help you manage agents effectively.

24 March 2026

Developer

1

Fundamentals

1

Security for AI agents with Microsoft Entra Agent ID

Updated

AI agents are autonomous software systems that can perceive their environment, make decisions, and take action. AI agents can expand organizational capabilities but also introduce security challenges that differ from traditional application security. This introduction explains why AI security matters, the challenges AI agents present, the concept of agent sprawl, and how Microsoft provides security mechanisms for AI agents in enterprise environments.

27 March 2026

General

1

Microsoft identity platform

1

Security

1

Authentication

2

Security Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

25 March 2026

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

25 March 2026

Fundamentals

1

Managed Policies

Updated

This policy covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. High-risk in this case means something about the way the user signed in is out of the ordinary. These high-risk sign-ins might include travel that is highly abnormal, password spray attacks, or token replay attacks. For more information, see [What are risk detections](/entra/id-protection/concept-identity-protection-risks#sign-in-risk-detections).

24 March 2026

Security

1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

25 March 2026

Governance

4

Groups Assign Member Owner

Updated

In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.

26 March 2026

Microsoft identity platform

1

General

6

Bulk invite B2B users

Updated

Learn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.

28 March 2026

Use Microsoft accounts

Updated

Enable your external business partners and guest users to use their Microsoft account (MSA) to sign in to your apps for B2B collaboration.

28 March 2026

Use Microsoft Entra accounts

Updated

Enable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.

28 March 2026

Cross-cloud settings

Updated

Enable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.

28 March 2026

Provisioning

6

Configure cross-tenant synchronization

Updated

Configure cross-tenant synchronization using the Microsoft Entra admin center. Step-by-step guide covering trust settings, provisioning scope, attribute mappings, and testing.

26 March 2026

Authentication

4

Email one-time passcode authentication

Updated

Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.

28 March 2026

Define custom attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

28 March 2026

Tenant Restrictions V2

Updated

- TRv2 does not enforce restrictions on cross-cloud requests at the authentication plane, so access is permitted during authentication. However, TRv2 does block cross-cloud requests at the data plane. As a result, when using Windows Group Policy (GPO), users will be unable to access TRv2-enlightened resources across cloud boundaries.

25 March 2026

Microsoft identity platform

3

Fundamentals

2

Governance

1

Security

1

Standards

1

Identity providers for external tenants

Updated

Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.

28 March 2026

General

17

Zscaler Coexistence

Updated

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

26 March 2026

Fundamentals

4

Configure Security

Updated

| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |

27 March 2026

Traffic Forwarding

Updated

With the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.

25 March 2026

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

25 March 2026

Security

3

Conditional Access

1

Troubleshooting

1

How to use enriched Microsoft 365 logs

Updated

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

26 March 2026

General

7

How to Manage the Private Access Profile

Updated

Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.

26 March 2026

Developer

3

Configure Global Access With Pim

Updated

Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.

26 March 2026

Authentication

2

Configure Kerberos Sso

Updated

Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.

26 March 2026

Conditional Access

1

Target Resource Private Access Apps

Updated

Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.

26 March 2026

Fundamentals

1

Connectors

Updated

After a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.

25 March 2026

Monitoring

1

Migrate from DirectAccess to Microsoft Entra Private Access

Updated

DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.

28 March 2026

Conditional Access

1

Workload Identity

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

24 March 2026

General

19

How to configure Global Secure Access threat intelligence

Updated

- You must disable Domain Name System (DNS) over HTTPS (Secure DNS) to tunnel network traffic. Use the rules of the fully qualified domain names (FQDNs) in the traffic forwarding profile. For more information, see [Configure the DNS client to support DoH](/windows-server/networking/dns/doh-client-support#configure-the-dns-client-to-support-doh).

28 March 2026

Install Ios Client

Updated

Because the Global Secure Access client for iOS is integrated with Microsoft Defender for Endpoint, it's helpful to understand the end user experience. The client appears in the Defender dashboard after onboarding to Global Secure Access.

27 March 2026

How to Enable and Manage the Microsoft Profile

Updated

Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.

26 March 2026

The Global Secure Access Client for iOS

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.

26 March 2026

Configure Quick Access

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with the appropriate roles.

25 March 2026

Conditional Access

4

Target Resource Microsoft Profile

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).

25 March 2026

Security

4

Troubleshooting

4

View Deployment Logs

Updated

Monitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.

26 March 2026

Troubleshoot Connectors

Updated

![Screenshot showing an example of the expected final configuration file.](media/troubleshoot-connectors/connector-logging-config-final-example.png)

25 March 2026

Zscaler Coexistence

Updated

1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.

24 March 2026

Microsoft identity platform

3

How to use the remote network health logs

Updated

Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.

26 March 2026

Monitoring

3

Fundamentals

2

View Enriched Logs

Updated

- **Microsoft Profile** - Ensure the Microsoft traffic profile is enabled. Microsoft traffic forwarding profile is required to capture traffic directed to Microsoft 365 services, which is fundamental for log enrichment.

27 March 2026

Understand Microsoft Entra Private DNS

Updated

Learn how to configure Microsoft Entra Private DNS for secure and efficient internal DNS query resolution, replacing legacy VPNs with granular access.

26 March 2026