Account Discovery
Updated- Atlassian Cloud
Daily.Entra.NewsThe week of 13 April 2026 was mainly a documentation-maintenance cycle—75 updates, two new entries, and one removal—but its meaningful exceptions are operationally important. New and revised Conditional Access guidance describes a behavior rollout; Message Center updates cover a guest-governance subscription prerequisite and the withdrawal of planned passkey registration-campaign changes; and targeted updates add a regional External ID SMS requirement and a provisioning security warning. The supplied evidence does not state a general-availability launch. Account Discovery and Global Secure Access MCP traffic logs are explicitly marked preview, while many remaining edits are tutorials, cross-links, or setup clarification.
Changed behavior / rollout. Microsoft Entra ID is rolling out improved enforcement for policies that target 'All resources' and include one or more resource exclusions. The stated target behavior gives sign-ins requesting only baseline scopes the same Conditional Access protections as other resource access. Related guidance says the only-scope flow also applies to policies explicitly targeting Azure AD Graph; when an application requests any additional scope, behavior is unchanged. Administrators can preview the改行为
Message Center major update, not a feature launch. The item says Microsoft Entra ID Governance requires a tenant to link an Azure subscription, beginning January 30, 2026, to use guest governance features. Without the link, creating or updating guest-scoped policies is blocked; existing policies continue to run, while new actions need subscription-linked billing under the Monthly Active User model. The feed supplies no broader billing requirement for other Governance features.
Message Center plan withdrawal. Microsoft says it will not proceed with adding Passkeys (FIDO2) as an authentication method in Microsoft Registration Campaigns starting April 2026. The previously planned automatic updates and nudges for MFA-capable users are also not being implemented at this time. This changes the campaign plan; it is not a statement that passkeys generally are retired from Microsoft Entra ID.
Preview documentation for Microsoft Entra External ID says some regions require administrators to enable country codes before external tenants can receive SMS telephony verification. The supplied summary does not identify the regions or the exact setting, so this is a regional requirement rather than evidence of a tenant-wide change.
Security guidance in the Entra ID provisioning tutorial says Global Relay Identity Sync uses a SCIM authorization method that is no longer supported because of security concerns. It also says work is underway with Global Relay to move to a more secure authorization method. The supplied update does not announce a connector shutdown, retirement date, or replacement procedure.
Assess Conditional Access policies that target All resources with resource exclusions; the supplied guidance supports previewing the improved behavior and retaining legacy behavior, but provides no rollout date. Tenants using guest governance should verify the required Azure subscription linkage because guest-scoped policy creation or updates can be blocked without it. Registration-campaign plans should not depend on the planned passkey additions or MFA nudges. External ID tenants using SMS should check regional country-code requirements, and organizations using Global Relay Identity Sync should flag the connector's SCIM authorization warning for vendor follow-up. The evidence supplies no affected-region list or Global Relay deadline.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
- Atlassian Cloud
After migrating your users and groups to Microsoft Entra ID, you may be ready to decommission your on-premises Active Directory and uninstall sync tools. After turning off directory synchronization, you can manage these objects directly in Microsoft Entra ID.
1. Sign in to your [Leapsome Admin Console](https://www.Leapsome.com/app/#/login). Navigate to **Settings > Admin Settings**.
Before you begin, you’ll need to create an **Automation user** in your Jostle intranet. This is the account you’ll use to configure with Azure. Automation users can be created in Admin **Settings > User accounts and data > Manage Automation users**.
```python
1. Sign in to [Keepabl Admin Portal](https://app.keepabl.com) and then navigate to **Account Settings > Your Organization**, where you’ll see the **Single Sign-On (SSO)** section.
[Append](#append) [AppRoleAssignmentsComplex](#approleassignmentscomplex) [BitAnd](#bitand) [CBool](#cbool) [CDate](#cdate) [Coalesce](#coalesce) [ConvertToBase64](#converttobase64) [ConvertToUTF8Hex](#converttoutf8hex) [Count](#count) [CStr](#cstr) [DateAdd](#dateadd) [DateDiff](#datediff) [DateFromNum](#datefromnum) [DefaultDomain](#defaultdomain) [FormatDateTime](#formatdatetime) [Guid](#guid) [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty) [IIF](#iif) [InStr](#instr) [IsNull](#isnull) [IsNullOrEmpty](#isnullorempty) [IsPresent](#ispresent) [IsString](#isstring) [Item](#item) [Join](#join) [Left](#left) [Len](#len) [Mid](#mid) [NormalizeDiacritics](#normalizediacritics) [Not](#not) [Now](#now) [NumFromDate](#numfromdate) [PCase](#pcase) [RandomString](#randomstring) [Redact](#redact) [RemoveDuplicates](#removeduplicates) [Replace](#replace) [SelectUniqueValue](#selectuniquevalue) [SingleAppRoleAssignment](#singleapproleassignment) [Split](#split) [StripSpaces](#stripspaces) [Switch](#switch) [ToLower](#tolower) [ToUpper](#toupper) [Word](#word)
1. Under **Enterprise portal**, select **Single Sign On**.
1. In the **Tenant URL** field, input your Cisco User Management for Secure Access Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Cisco User Management for Secure Access. If the connection fails, ensure your Cisco User Management for Secure Access account has the required admin permissions and try again.
1. Under **Mappings**, select the object (user or group) for which you'd like to add a custom attribute.
1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. In the **Tenant URL** field, input your Chaos Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Chaos. If the connection fails, ensure your Chaos account has the required admin permissions and try again.
1. In the **Tenant URL** field, input your Chatwork Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Chatwork. If the connection fails, ensure your Chatwork account has the required admin permissions and try again.
1. In the **Tenant URL** field, input your CheckProof Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to CheckProof. If the connection fails, ensure your CheckProof account has the required admin permissions and try again.
1. In the **Tenant URL** field, input your Cinode Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Cinode. If the connection fails, ensure your Cinode account has the required admin permissions and try again.
- clicktale
You can preview the improved enforcement behavior before the rollout begins:
Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, are enforced in user sign-in flows where the client application requests only these scopes. There is no change in behavior when an application requests any additional scope beyond those listed above.
For more information about how to sign in with FIDO2 security keys on a Windows device, see [Enable FIDO2 security key sign-in to Windows 10 and 11 devices with Microsoft Entra ID](howto-authentication-passwordless-security-key-windows.md).
For more information about passkey authentication, see [Support for FIDO2 authentication with Microsoft Entra ID](~/identity/authentication/concept-fido2-compatibility.md).
Microsoft Entra ID uses a concept called *assignments* to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users or groups that were assigned to an application in Microsoft Entra ID are synchronized.
author: MicrosoftGuyJFlo
- [Attribute Definition Administrator](/entra/identity/role-based-access-control/permissions-reference#attribute-definition-administrator)
You receive the notification email from [email protected]. To avoid the email going to your spam location, add this email to your contacts.
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: Improved Enforcement Resource Exclusions Faq.
8. Leave the portal and open the provisioning agent installer, agree to the terms of service, and select **Install**.
> Global Relay Identity Sync provisioning connector utilizes a SCIM authorization method that's no longer supported due to security concerns. Efforts are underway with Global Relay to switch to a more secure authorization method.


Microsoft has decided not to proceed with adding Passkeys (FIDO2) as an authentication method in Microsoft Registration Campaigns starting April 2026. Previously planned changes, including automatic updates and nudges for MFA-capable users, will not be implemented at this time. Updates are available in MC1279092.
Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target **All resources** and include one or more **resource exclusions**. This change ensures that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access.
- Microsoft Entra Kerberos doesn't issue partial TGTs to identities that aren't synced to Microsoft Entra ID.
Frequently asked questions about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions.
Learn about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions, including how to assess impact and retain legacy behavior.
Frequently asked questions about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions.
Here's the quick checklist for you before you submit the application request to list your application in Microsoft Entra App Gallery.
Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.
$response = Invoke-MgGraphRequest `
The blueprint principal must be created as a separate step after the blueprint. Run:
If you defined a default [governance policy template](governance-policy-templates.md), a new governance relationship forms between the home (governing) tenant and the newly created add-on (governed) tenant, using the default policy template.
Starting January 30, 2026, Microsoft Entra ID Governance requires tenants to link an Azure subscription to use guest governance features. Without this, creating or updating guest-scoped policies will be blocked. Existing policies run, but new actions need subscription-linked billing under the Monthly Active User model.
This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).
- Manage user lifecycle at scale. As your organization grows, the need for other resources to manage user lifecycle decreases.
> [!NOTE]
Learn how to use the license usage insights page in the Microsoft Entra admin center to monitor license usage and entitlements.
| access package | A bundle of resources that a team or project needs and is governed with policies. An access package is always contained in a catalog. You would create a new access package for a scenario in which identities need to request access for themselves. |
To protect customers, some regions require you to enable the country codes to receive SMS telephony verification for Microsoft Entra External ID external tenants.
Learn how to add MSA as an identity provider for your external tenant.
In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.
Learn how to add Apple as an identity provider for your external tenant.
Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.
Learn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.
Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.
Learn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.
Use Microsoft Entra API connectors to customize and extend your self-service sign-up user flows by using web APIs.
Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.
If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can move to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials. Use either PowerShell or the Microsoft Graph invitation API.
Learn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
The issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.
- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).
**Q: Is this feature supported from a windows Entra registered device(BYOD)?**
Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.
Global Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).
Global Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).
author: HULKsmashGithub
author: HULKsmashGithub
Use Global Secure Access to configure Azure and Microsoft Entra resources to create a virtual wide area network to connect to your resources in Azure.
Use Application discovery to detect the applications accessed by users and create separate private applications.
Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.