Every day, Microsoft processes more than 100 trillion security signals from endpoints, cloud services, identity systems, and more. We use this data shape how we respond to threats and inform how we innovate to help build a safer digital future. Read about the work we're doing in the [Microsoft Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1).
Security Copilot’s E5 rollout and My Groups enhancements headline a documentation-heavy Entra week
Of 236 entries for the week of 23 March 2026, 233 were updates, one was new, none were removed, and two were Message Center notices. The most substantive items are the planned Microsoft 365 E5 inclusion of Security Copilot, expanded Microsoft 365 group owner controls in My Groups, and a new phased migration guide from DirectAccess to Microsoft Entra Private Access. Most other representative changes are ordinary documentation maintenance—policy steps, role prerequisites, screenshots, troubleshooting, and explanatory text around Conditional Access, Global Secure Access, Internet Access, and External ID. None of the supplied entries identifies a preview, general availability release, or retirement.
- Security Copilot is scheduled for phased inclusion in Microsoft 365 E5Security Copilot / Microsoft 365 E5
A Message Center notice says the rollout will run from 20 April through 30 June 2026. The E5 inclusion provides 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products; additional advanced capabilities may incur extra costs. This is a Microsoft 365 and Security Copilot service-entitlement notice, not evidence of an Entra ID feature launch or preview/GA change.
- My Groups is expanding Microsoft 365 group owner self-serviceEntra ID — My Groups / Microsoft 365 Groups
The Message Center says the enhancement will arrive by late March 2026. Group owners will be able to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The notice says existing groups are unaffected and no admin setup is required, making this a management-experience change rather than a new Conditional Access or access-control policy.
- A new Learn page documents a phased DirectAccess-to-Private Access migrationMicrosoft Entra Private Access
The new Microsoft Entra Private Access page explains how to move client devices from DirectAccess in phases while avoiding tunnel conflicts and connectivity failures. Companion material describes DirectAccess as relying on IPv6 transition technologies, domain-joined Windows Enterprise clients, and full network-level access. This is migration guidance, not a product launch and not a stated DirectAccess retirement.
- Conditional Access guidance clarifies session behavior and Global Secure Access targetingEntra ID Conditional Access; Global Secure Access; Internet Access
Updated Entra ID documentation states that Sign-in frequency – every time allows five minutes of clock skew; when MFA was completed within the previous five minutes, another Conditional Access policy requiring reauthentication does not prompt again. It also advises using every-time reauthentication only for specific business needs and directs administrators to sign-in logs and the Conditional Access tab to diagnose authentication-flow policy matches. Related Global Secure Access and Internet Access pages document22
For Microsoft 365 E5 tenants, note the Security Copilot rollout window of 20 April through 30 June 2026, the stated allocation of 400 Security Compute Units per 1,000 users, and the possibility of additional charges for advanced capabilities; the notice does not specify an Entra configuration step. My Groups requires no admin setup according to the notice and does not affect existing groups, but owners will gain more self-service controls. Organizations still using DirectAccess have a concrete migration reference, though it is not a retirement announcement. The remaining documentation changes warrant targeted review only where relevant to existing Conditional Access, Global Secure Access, Internet Access, or External ID designs.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
116 updatesConditional Access
23Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Migrate Approved Client App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Agent Block High Risk
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Block By Location
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Block Example
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
**To configure your Conditional Access policy:**
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Guests Mfa Strength
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Old Require Mfa Admin
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Old Require Mfa Guest
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Developer
20- make.gov.powerapps.us
:::image type="content" source="./media/application-proxy-configure-complex-application/complex-app-structure-1.png" alt-text="Diagram of domain structure for a complex application showing resource sharing between primary and secondary application.":::
8. Run this command for each collection. Replace *\<yourcollectionname\>* and *\<proxyfrontendurl\>* with your own information. This command enables single sign-on between RD Web and RD Gateway, and optimizes performance.
Application Proxy Wildcard
Updated- Internal URL:
Application Proxy Qlik
UpdatedFollow the same steps as for Application #1, with the following exceptions:
Cookies that don't specify the [SameSite](https://web.dev/articles/samesite-cookies-explained) attribute are treated as if they're set to **SameSite=Lax**. The `SameSite` attribute declares how cookies should be restricted to a same-site context. When set to `Lax`, the cookie is only sent to same-site requests or top-level navigation. However, application proxy requires these cookies to be preserved in the third-party context to keep users signed in during their session. Due to the requirement, updates were made:
Publish and manage multiple on-premises applications at once using wildcard URL patterns in Microsoft Entra application proxy.
Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Configure Kerberos-based SSO for on-premises applications using Kerberos Constrained Delegation (KCD) with Microsoft Entra application proxy.
Understand complex applications in Microsoft Entra application proxy.
Configure Microsoft Entra private network connectors with outbound proxy servers. Covers bypassing proxies, routing through proxies, and proxy placement between connectors and backend apps.
Optimize performance for global connectivity scenarios using Azure Front Door for geo-acceleration with Microsoft Entra application proxy.
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
Configure Microsoft Entra application proxy to enable secure external access to on-premises SharePoint Server using Kerberos Constrained Delegation for single sign-on.
Combine Microsoft Entra application proxy with Azure Traffic Manager for geographic load balancing and high availability across multiple connector groups.
Configure and manage custom domains in Microsoft Entra application proxy to use your own domain name.
Grant Admin Consent
UpdatedLearn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedConfigure header-based single sign-on for on-premises applications published through Microsoft Entra application proxy. Pass user identity attributes as HTTP headers.
Integrate Microsoft Entra application proxy with Qlik Sense.
Fundamentals
15ai-usage: ai-assisted
How to identify and resolve license assignment problems when you're using Microsoft Entra group-based licensing.
ai-usage: ai-assisted
An end-to-end guide for planning the deployment of application proxy within your organization
Whats New
Updated```
Whats New
Updated**What’s changing**
Filter For Applications
UpdatedFollow the instructions in the article, [Add or deactivate custom security attributes in Microsoft Entra ID](~/fundamentals/custom-security-attributes-add.md) to add the following **Attribute set** and **New attributes**.
Understand the phases of Conditional Access policy enforcement in Microsoft Entra and how to apply them to secure user access.
Microsoft 365 offers cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. In Conditional Access, the Microsoft 365 suite of applications appears under 'Office 365'. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration might cause confusion when creating policies because some apps, like Microsoft Teams, depend on others, like SharePoint or Exchange.
Authentication Flows
UpdatedIf you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, selecting the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.
> [!IMPORTANT]
To prevent admin lockout, when creating a policy applied to **All users** and **All apps**, the following warning appears.
Plan Conditional Access
Updated- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).
With Conditional Access, organizations can restrict access to [approved (modern authentication capable) client apps with Intune app protection policies](concept-conditional-access-grant.md#require-app-protection-policy). For older client apps that may not support app protection policies, administrators can restrict access to [approved client apps](concept-conditional-access-grant.md#require-approved-client-app).
There are multiple scenarios that organizations can now enable using filter for devices condition. The following scenarios provide examples of how to use this new condition.
General
13ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
Migrate Group Writeback
Updated- A Microsoft Entra account with at least a [Hybrid Identity administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
Clever Tutorial
Updated<a name='configure-and-test-azure-ad-sso-for-clever'></a>
Install the module.
Updated$tenantID = '<tenant-id>'
My Staff Configure
UpdatedAfter configuring administrative units, you can apply this scope to your users who access My Staff. Only users who are assigned an administrative role can access My Staff. To enable My Staff, complete the following steps:
Compliance Administrator
UpdatedCompliance Administrator
Global Reader
UpdatedGlobal Reader
Global Administrator
UpdatedGlobal Administrator
minimumlicense: Free
Updatedauthor: MicrosoftGuyJFlo
- Manage Teams external collaboration settings that govern the organization's interactions with external users in chats, meetings, and calls.
Terms Of Use
Updated* Microsoft Entra ID P1 licenses.
Authentication
12Configure Sso With Kcd
Updated5. Select **Use any authentication protocol**.
This section guides you through the necessary configurations on the **Stormshield Network Security (SNS) firewall** to enable **OIDC authentication** via **Microsoft Entra ID**.
Reports Data Retention
Updated| Risky sign-ins | 7 days | 30 days | 90 days |
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Publish Tableau Server through Microsoft Entra application proxy to provide secure remote access with preauthentication and Conditional Access.
Set a custom home page URL for applications published through Microsoft Entra application proxy so users land on the correct internal page after sign-in.
Learn how to use the Conditional Access Optimization Agent to safely deploy a passkey program to roll out phishing-resistant authentication methods.
>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
The system accounts for five minutes of clock skew when **every time** is selected in policy, so users aren’t prompted more often than once every five minutes. If the user completes MFA in the last 5 minutes and encounters another Conditional Access policy that requires reauthentication, we don't prompt the user. Prompting users too often for reauthentication can affect their productivity and increase the risk of users approving MFA requests they didn’t initiate. Use "Sign-in frequency – every time" only when there are specific business needs.
The following steps help create a Conditional Access policy to require all users to perform multifactor authentication using the authentication strength policy.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
This guide covers the steps required to deploy and enforce Token Protection for sign-in session tokens on Windows platform.
Security
8Prepare Converted Groups
Updated$groupDisplayName = 'My Security Group'
ai-usage: ai-assisted
Microsoft 365 group creation and editing in My Groups will be enhanced by late March 2026, allowing owners to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The update improves control and clarity without impacting existing groups or requiring admin setup.
Secure NDES certificate enrollment for mobile devices using Microsoft Entra application proxy. Includes connector setup and certificate request validation.
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
Helpdesk Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
User Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
- Policy can be applied to the Microsoft Edge browser on devices running Windows 11 and Windows 10 version 20H2 and higher with KB5031445.
Microsoft identity platform
6ai-usage: ai-assisted
ai-usage: ai-assisted
To call a web API from a web app on behalf of a user, use the authorization code flow and store the acquired tokens in the token cache. When needed, MSAL refreshes tokens and the controller silently acquires tokens from the cache.
Create and manage a multitenant organization using Microsoft Graph PowerShell or Microsoft Graph API. Covers creating the organization, adding tenants, joining, and managing roles.
Apple Sso Plugin
UpdatedIf your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.
- Admins can apply policy only to supported platforms (such as iOS, Android, and Windows) through the Conditional Access Microsoft Graph API.
Monitoring
6Place the connector close to the target application in the customer network. This configuration minimizes step 3 in the topography diagram, because the connector and application are close.
1. *Authority*: Enter *https://login.windows.net*.
Securely integrate Azure Logic Apps with on-premises APIs using Microsoft Entra application proxy
UpdatedMicrosoft Entra application proxy lets cloud-native logic apps securely access on-premises APIs to bridge your workload.
Optimize traffic flow and connector placement for Microsoft Entra application proxy. Covers bandwidth, latency, and network patterns including ExpressRoute and multi-region deployments.
Permissions Reference
Updated> | [Compliance Administrator](#compliance-administrator) | Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |
What If Tool
UpdatedStart an evaluation by selecting **What If**. The evaluation result provides you with a report that consists of:
Provisioning
5ai-usage: ai-assisted
1. After entering the domain, a new line in the table appears showing domain name and its status as **initialize**. Select the gear icon to reveal technical data about TAP app Security server and to complete initialization.
There are two ways to provision users from Microsoft Entra into SAP Cloud Identity Services.
Sentry Provisioning Tutorial
Updated* [A Microsoft Entra tenant](~/identity-platform/quickstart-create-new-tenant.md).

Standards
5Policy Guests Mfa Strength
Updated1. Give your policy a name. Create a meaningful standard for the names of your policies.
1. The Tenant URL is `https://scim.segmentapis.com/scim/v2`. This value is entered in the **Tenant URL** field in the Provisioning tab of your Segment application.
The Microsoft Entra provisioning service currently operates under particular [IP ranges](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md#ip-ranges). If necessary, you can restrict other IP ranges and add these particular IP ranges to the allow list of your application. That technique will allow traffic flow from the Microsoft Entra provisioning service to your application.
Configure Microsoft Entra application proxy with SAML-based authentication for secure external access to on-premises SharePoint Server.
Continuous access evaluation
UpdatedToken expiration and refresh are a standard mechanism in the industry. When a client application like Outlook connects to a service like Exchange Online, the API requests are authorized using OAuth 2.0 access tokens. By default, access tokens are valid for one hour, when they expire the client is redirected to Microsoft Entra to refresh them. That refresh period provides an opportunity to reevaluate policies for user access. For example: the token might not be refreshed because of a Conditional Access policy, or because the user is disabled in the directory.
Architecture
1Recoverability Overview
Updated- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.
Governance
1include file
Updatedinclude file
Troubleshooting
1To get detailed information about the sign-in interruption, review the Microsoft Entra sign-in events to see which Conditional Access policy or policies applied and why.
Microsoft Entra Agent ID
6 updatesConditional Access
1Agent Id
UpdatedThere are two key business scenarios where Conditional Access policies can help you manage agents effectively.
Developer
1Call Api Custom
Updated_api = api;
Fundamentals
1AI agents are autonomous software systems that can perceive their environment, make decisions, and take action. AI agents can expand organizational capabilities but also introduce security challenges that differ from traditional application security. This introduction explains why AI security matters, the challenges AI agents present, the concept of agent sprawl, and how Microsoft provides security mechanisms for AI agents in enterprise environments.
General
1identityParentId = "<associated-agent-identity-id>"
Microsoft identity platform
1This article explains how to call a Microsoft Graph API from an agent using agent identities or an agent's user account.
Security
1Call Api Azure Services
Updated_credential = credential;
Microsoft Entra ID Protection
4 updatesAuthentication
2Security Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Fundamentals
1Managed Policies
UpdatedThis policy covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. High-risk in this case means something about the way the user signed in is out of the ordinary. These high-risk sign-ins might include travel that is highly abnormal, password spray attacks, or token replay attacks. For more information, see [What are risk detections](/entra/id-protection/concept-identity-protection-risks#sign-in-risk-detections).
Security
1Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Microsoft Entra ID Governance
5 updatesGovernance
4Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure Microsoft Entra role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Groups Assign Member Owner
UpdatedIn Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.
Microsoft identity platform
1Security Copilot will be included with Microsoft 365 E5 via a phased rollout from April 20 to June 30, 2026, providing 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products. Additional advanced capabilities may incur extra costs.
Microsoft Entra External ID
24 updatesGeneral
6Bulk invite B2B users
UpdatedLearn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.
Use Microsoft accounts
UpdatedEnable your external business partners and guest users to use their Microsoft account (MSA) to sign in to your apps for B2B collaboration.
Use Microsoft Entra accounts
UpdatedEnable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.
Cross-cloud settings
UpdatedEnable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.
Learn how to add Google as an identity provider for your external tenant.
B2b Tutorial Require Mfa
Updated1. Select **New policy**.
Provisioning
6ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
Configure cross-tenant synchronization using the Microsoft Entra admin center. Step-by-step guide covering trust settings, provisioning scope, attribute mappings, and testing.
Map custom directory extension attributes in cross-tenant synchronization. Covers creating extensions, adding them to attribute mappings, and manual schema editing.
<br/>**Target tenant**
Authentication
4Learn how to enforce multifactor authentication policies for Microsoft Entra B2B users.
Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.
Define custom attributes
UpdatedLearn how to create and define new custom attributes to be collected from users during sign-up and sign-in.
Tenant Restrictions V2
Updated- TRv2 does not enforce restrictions on cross-cloud requests at the authentication plane, so access is permitted during authentication. However, TRv2 does block cross-cloud requests at the data plane. As a result, when using Windows Group Policy (GPO), users will be unable to access TRv2-enlightened resources across cloud boundaries.
Microsoft identity platform
3ai-usage: ai-assisted
Configure cross-tenant synchronization using Microsoft Graph PowerShell or Microsoft Graph API. Includes enabling synchronization, setting up automatic redemption, creating provisioning jobs, and testing on-demand provisioning.
Configure cross-tenant access and identity synchronization policy templates for multitenant organizations using the Microsoft Graph API. Covers automatic redemption, inbound sync, and template management.
Fundamentals
2ai-usage: ai-assisted
View real-time insights on active devices, alerts, traffic patterns, and cross-tenant usage across Microsoft Entra Private Access and Internet Access services.
Governance
1Learn to govern and manage identity and access lifecycles across multitenant organizations.
Security
1Learn how to integrate third-party bot protection providers with Native API sign-up flows in Microsoft Entra External ID by using a Web Application Firewall.
Standards
1Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.
Microsoft Entra Internet Access
26 updatesGeneral
17A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access.
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Zscaler Coexistence
UpdatedLearn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
Learn how to configure threat intelligence in Microsoft Entra Internet Access.
ai-usage: ai-assisted
ai-usage: ai-assisted
Use custom block pages to display organization-specific messaging internet access policies block users from accessing websites.
Fundamentals
4Configure Security
Updated| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |
Traffic Forwarding
UpdatedWith the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.
Clients
UpdatedLearn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Internet Access
Updatedai-usage: ai-assisted
Security
3Deploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Configure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
Conditional Access
1Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
Troubleshooting
1View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Microsoft Entra Private Access
15 updatesGeneral
7Learn how to migrate client devices from DirectAccess to Microsoft Entra Private Access with a phased approach that avoids tunnel conflicts and connectivity failures.
manager: dougeby
manager: dougeby
Set up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Developer
3Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Authentication
2Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Configure Kerberos Sso
UpdatedEnable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Conditional Access
1Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
Fundamentals
1Connectors
UpdatedAfter a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.
Monitoring
1DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.
Microsoft Entra Workload ID
1 updateConditional Access
1Workload Identity
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Microsoft Entra Global Secure Access
39 updatesGeneral
19- You must disable Domain Name System (DNS) over HTTPS (Secure DNS) to tunnel network traffic. Use the rules of the fully qualified domain names (FQDNs) in the traffic forwarding profile. For more information, see [Configure the DNS client to support DoH](/windows-server/networking/dns/doh-client-support#configure-the-dns-client-to-support-doh).
Configure Connectors
Updated>
Install Ios Client
UpdatedBecause the Global Secure Access client for iOS is integrated with Microsoft Defender for Endpoint, it's helpful to understand the end user experience. The client appears in the Defender dashboard after onboarding to Global Secure Access.
Control which users and groups receive traffic forwarding policies, enabling gradual rollout and limiting scope during testing or deployment phases.
Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.
Modify remote network configurations, delete unused networks, and manage device links and traffic profile assignments for Global Secure Access.
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Learn how to enable source IP restoration to ensure the source IP matches in downstream resources.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Create a PowerShell script for unattended installation and registration of the Microsoft Entra private network connector for bulk deployments or servers without a UI.
Use the web category checker to find which web content category a URL belongs to via Microsoft Graph.
|Nudity | Sites that contain full or partial nudity that aren't necessarily overtly sexual in intent.|
Cisco Vpn Coexistence
Updated> [!IMPORTANT]
Configure Kerberos Sso
Updated|49152-65535 |UDP/TCP |Ephemeral ports |
Configure Per App Access
Updated1. Enter a name for the app.
Configure Quick Access
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with the appropriate roles.
author: HULKsmashGithub
ai-usage: ai-assisted
Conditional Access
4Learn how to require known compliant network locations to connect to your secured resources with Conditional Access.
Learn how to apply Conditional Access policies to the Global Secure Access traffic.
Learn how to require known compliant network locations to connect to your secured resources with Conditional Access.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Security
4Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Configure Microsoft Global Secure Access and Cisco Secure Access for unified SASE capabilities. Covers deployment steps, FQDN and IP bypasses, and client configuration.
- A **Global Secure Access Administrator** role in Microsoft Entra ID.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Troubleshooting
4View Deployment Logs
UpdatedMonitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.
Troubleshoot Connectors
Updated
The proposed workaround for the above-mentioned scenario is as follows.
Zscaler Coexistence
Updated1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.
Microsoft identity platform
3Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.
Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
View and review all remote networks in your Global Secure Access deployment using the Microsoft Entra admin center or Microsoft Graph API.
Monitoring
3Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
Fundamentals
2View Enriched Logs
Updated- **Microsoft Profile** - Ensure the Microsoft traffic profile is enabled. Microsoft traffic forwarding profile is required to capture traffic directed to Microsoft 365 services, which is fundamental for log enrichment.
Learn how to configure Microsoft Entra Private DNS for secure and efficient internal DNS query resolution, replacing legacy VPNs with granular access.
