Week in brief

Tenant Governance preview documentation expands across discovery and drift control; Agent ID’s GA capability set and Explicit Forward Proxy are the week’s other substantive signals

The week of 27 April 2026 was primarily documentation-led rather than a product-release record: 127 pages were updated, one Agent ID page was new, and there were no removals or Message Center entries. The most meaningful change was a coordinated set of Microsoft Entra Tenant Governance preview pages covering tenant discovery, governance relationships, secure tenant creation, licensing, permissions, and configuration drift. Agent ID documentation now describes a general-availability capability set and related administration and integration workflows. Global Secure Access and Internet Access documentation identifies Explicit Forward Proxy as preview. Entra ID updates mainly refresh security and migration recommendations, while Workload ID adds a concrete Conditional Access scope and licensing clarification. Other supplied edits are largely provisioning tutorials, troubleshooting content, and reference clarifications.

  • Tenant Governance (preview) now has documentation for the full operating workflowMicrosoft Entra ID Governance — Tenant Governance (preview)

    A coordinated set of 1 May updates covers secure add-on tenant creation, automatic governance relationships, tenant discovery, relationship updates and termination, configuration baselines, drift monitoring, monitor management, permissions, licensing, and end-to-end deployment. The documentation says discovery uses identity, application, and billing signals, and that secure tenant creation can automatically establish governance relationships. This is an expansion of preview guidance, not evidence of general‌‎-‎

  • Agent ID documentation moves from overview material to GA-era administration and integrationMicrosoft Entra Agent ID

    The new “What’s new in Microsoft Entra Agent ID” page labels its covered capabilities as generally available and highlights third-party integrations, migration guides, and enterprise governance. Related updates describe two integration patterns—the Microsoft Entra Auth SDK sidecar and federation—for platforms such as AWS Bedrock and n8n, allowing third-party agents to authenticate to APIs without handling credentials directly. Administration pages cover centralized agent search, filtering, sorting, registry-only एज

  • Explicit Forward Proxy is documented as a preview path for Entra Internet AccessMicrosoft Entra Global Secure Access / Internet Access

    Updates in Global Secure Access and Internet Access state that Explicit Forward Proxy is currently in preview. The Internet Access guidance describes using Secure Web and AI Gateway capabilities without installing the Global Secure Access client when a browser supports proxy automatic configuration (PAC). Companion material covers Conditional Access policy configuration and configuring Microsoft Edge through an Intune Mobile Application Management policy. The evidence supports an evaluation path, not a general-

  • Authentication updates reinforce migration and MFA security guidanceMicrosoft Entra ID — Authentication and Security Defaults

    Several Entra ID recommendation pages were refreshed to promote migration to Microsoft Authenticator, migration of application authentication from AD FS to Microsoft Entra ID, migration from MFA Server to Microsoft Entra MFA, minimizing prompts from known devices, and turning off per-user MFA. Security Defaults guidance adds a specific procedure: revoke existing tokens with Revoke-MgUserSignInSession so previously authenticated users must authenticate and register for MFA. Combined registration guidance says MFA‎-‎

  • Workload ID guidance clarifies Conditional Access boundaries and license behaviorMicrosoft Entra Workload ID

    Updated Workload ID pages state that Conditional Access policies can apply to single-tenant service principals registered in the tenant. Non-Microsoft SaaS and multitenant applications are out of scope, and managed identities are not covered. In directories without appropriate licenses, existing workload-identity policies continue to function but cannot be modified. This is a scope and licensing clarification; the supplied evidence does not show a new enforcement change.

For Entra administrators

Do not treat the volume of Learn updates as evidence of a tenant-wide behavior change. Administrators evaluating Tenant Governance or Explicit Forward Proxy should use the relevant preview documentation, including its licensing, permissions, Conditional Access, browser/PAC, and Intune Mobile Application Management guidance. Workload ID teams should verify whether their service principals fall within the stated Conditional Access scope and whether they can modify policies under their licensing. Identity teams should review the refreshed MFA, AD FS, MFA Server, and per-user MFA guidance; if enabling Security Defaults, note the documented instruction to revoke existing tokens. Agent ID owners have new material for agent inventory, third-party integration, audit visibility, and owner or end‎-‎

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Provisioning

28

Simple In Out Provisioning Tutorial

Updated

1. Select **Reveal** on your Recovery Key and store this entire key in a safe place. **IMPORTANT!** If you're ever locked out of your Microsoft accounts and need to disconnect SSO without access, you be required to relay the Recovery Key to Simple In/Out technical support.

30 April 2026

Sas Viya Sso Provisioning Tutorial

Updated

1. In the **Tenant URL** field, enter your SAS Viya SSO Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to SAS Viya SSO. If the connection fails, ensure your SAS Viya SSO account has the required admin permissions and try again.

30 April 2026

Preciate Provisioning Tutorial

Updated

1. Sign in to [Preciate Admin Portal](https://preciate.com/web/admin/keys) and navigate to the **Integrations** page.

28 April 2026

Dropboxforbusiness Provisioning Tutorial

Updated

The objective of this article is to demonstrate the steps to be performed in Dropbox for Business and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Dropbox for Business.

28 April 2026

Druva Provisioning Tutorial

Updated

1. Sign in to your [Druva Admin Console](https://console.druva.com). Navigate to **Druva** > **inSync**.

28 April 2026

Documo Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

28 April 2026

Rfpio Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

28 April 2026

Ringcentral Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

28 April 2026

Moqups Provisioning Tutorial

Updated

1. In the **Tenant URL** field, enter your Moqups Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Moqups. If the connection fails, ensure your Moqups account has the required admin permissions and try again.

28 April 2026

Recnice Provisioning Tutorial

Updated

1. Select the pencil to edit the properties. Enable notification emails and provide an email to receive quarantine emails. Enable accidental deletions prevention. Select **Apply** to save the changes.

28 April 2026

Rhombus Systems Provisioning Tutorial

Updated

1. Select the pencil to edit the properties. Enable notification emails and provide an email to receive quarantine emails. Enable accidental deletions prevention. Select **Apply** to save the changes.

28 April 2026

Fundamentals

14

Security Defaults

Updated

As part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.

1 May 2026

Registration Mfa Sspr Combined

Updated

By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.

1 May 2026

Whats New

Updated

**Service category:** User Experience and Management

1 May 2026

Five Steps To Full Application Integration

Updated

In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.

1 May 2026

Multi Tenant Organization Overview

Updated

- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)

1 May 2026

Certificate Based Authentication Certificate Revocation List

Updated

When a problem prevents Microsoft Entra from downloading the CRL, the cause is often firewall restrictions. In most cases, you can resolve the issue by updating firewall rules to allow the required IP addresses so Microsoft Entra can successfully download the CRL. For more information, see [Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=56519).

29 April 2026

Directory Join

Updated

| **Definition** | <ul><li>Joined only to Microsoft Entra ID requiring organizational account to sign in to the device</li></ul> |

29 April 2026

Fido2 Hardware Vendor

Updated

Passkeys (FIDO2) enable phishing-resistant authentication. They can replace weak credentials with strong phishing-resistant public/private-key credentials that can't be reused, replayed, or shared across services. They can be stored securely on a device or synced across trusted devices through an encrypted cloud service.

28 April 2026

Data Storage Eu

Updated

A Microsoft Entra documentation page was updated: Data Storage Eu.

28 April 2026

General

11

Sso Linux

Updated

Microsoft single sign-on for Linux is supported on the following operating systems (physical or Hyper-V machines with x86/64 CPUs):

29 April 2026

Whats New Linux

Updated

- Ensure that all browser calls are done in the same thread

29 April 2026

Connect Install Roadmap

Updated

* Make sure that you [satisfy the requirements](how-to-connect-health-agent-install.md#requirements) for Microsoft Entra Connect Health.

29 April 2026

Authentication

7

Netskope Administrator Console Provisioning Tutorial

Updated

1. Review the user attributes that are synchronized from Microsoft Entra ID to Netskope User Authentication in the **Attribute-Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Netskope User Authentication for update operations. If you choose to change the [matching target attribute](~/identity/app-provisioning/customize-application-attributes.md), you need to ensure that the Netskope User Authentication API supports filtering users based on that attribute. Select the **Save** button to commit any changes.

30 April 2026

Standards

3

Lucidchart Provisioning Tutorial

Updated

:::image type="content" source="./media/lucidchart-provisioning-tutorial/scim.png" alt-text="Screenshot of the Lucidchart admin console. Within a large S C I M button, the text S C I M is highlighted, and an enabled banner is visible." border="false":::

28 April 2026

Developer

2

Microsoft identity platform

2

Frontline Worker Management

Updated

Frontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).

1 May 2026

Monitoring

2

Entra Service Limits Include

Updated

| Reports | A maximum of 1,000 rows can be viewed or downloaded in any report. Any additional data is truncated. |

2 May 2026

Security

2

Policy All Users Windows App Protection

Updated

There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

1 May 2026

Branding

1

Customize Branding Themes Apps

Updated

Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.

28 April 2026

General

9

Whats New Agent Id

Updated

This article summarizes the key capabilities and documentation currently available.

2 May 2026

Agent Lists

Updated

Access Microsoft Entra admin center to view and filter agent identities. Streamline tenant oversight with search, filters, and column customization.

2 May 2026

Manage Agent Identities Admin

Updated

The Microsoft Entra admin center provides a centralized interface to view all agent identities in your tenant. You can search, filter, sort, and customize columns to find specific agents.

2 May 2026

Manage agents in end user experience

Updated

Learn how to manage agent identities in the end user experience within Microsoft Entra. View, control, and take action on agents you own or sponsor with ease.

2 May 2026

Authentication

2

Integrate third-party agents with Microsoft Entra Agent ID

Updated

Microsoft Entra Agent ID enables AI agents from third-party platforms to authenticate and access your APIs securely without handling credentials directly. This article covers two integration patterns - the Microsoft Entra Auth SDK (sidecar) and federation - for platforms such as Amazon Web Service (AWS) Bedrock and n8n.

2 May 2026

Microsoft Entra Agent ID logs

Updated

Learn how audit and sign-in activities associated with agent identities are logged in Microsoft Entra ID.

2 May 2026

Governance

2

What's new in Microsoft Entra Agent ID

New

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.

2 May 2026

Fundamentals

1

Whats New Ignite 2025

Updated

- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)

1 May 2026

Microsoft identity platform

1

Create an agent identity blueprint

Updated

Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.

2 May 2026

Security

1

Governance

23

Create a monitor (preview)

Updated

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

1 May 2026

Enable tenant discovery (preview)

Updated

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

1 May 2026

Update or delete a monitor (preview)

Updated

Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change

1 May 2026

Pim How To Add Role To User

Updated

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

1 May 2026

Microsoft Entra Id Governance Licensing For Guest Users

Updated

| Access Reviews | [Access Review – inactive users](../identity/users/clean-up-stale-guest-accounts.md#monitor-guest-accounts-at-scale-with-inactive-guest-insights) | Bill when guest user is included in review.<br><br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/accessReviews/definitions where inactive guest reviews are included in the policy for a group resource. | Decision item summary. |

28 April 2026

Authentication

1

Fundamentals

1

Provisioning

1

General

1

How to Configure Explicit Forward Proxy (preview)

Updated

Explicit Forward Proxy (EFP) allows you to use Secure Web and AI Gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access (GSA) client. EFP works with any browser that supports proxy automatic configuration (PAC).

30 April 2026

General

1

Security

1

Troubleshooting

1

Register Didwebsite

Updated

The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.

1 May 2026

Conditional Access

1

Workload Identity

Updated

> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).

1 May 2026

Fundamentals

1

Conditional Access Users Groups

Updated

A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.

1 May 2026

Fundamentals

3

Bring Your Own Device

Updated

1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).

1 May 2026

Explicit Forward Proxy (preview) overview

Updated

Explicit Forward Proxy (EFP) is one of the traffic acquisition mechanisms that's useful in scenarios where installation of the Global Secure Access (GSA) client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from:

30 April 2026

Introduction to Proxy Automatic Configuration (PAC) files

Updated

A PAC file is a mechanism used to automatically determine which proxy server a web browser or application should use for a given request. PAC files are an integral part of Explicit Forward Proxy configuration, enabling flexible and dynamic traffic steering decisions. In the context of Global Secure Access, PAC files are similar to the traffic forwarding policies of the GSA client.

30 April 2026

General

2

PowerShell samples for Global Secure Access

Updated

Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, and TLS certificate creation.

28 April 2026

Conditional Access

1

Developer

1

Security

1