← Previous week
Week in brief

Global Secure Access connector guidance now specifies separate TCP port ranges

The period’s meaningful changes center on Global Secure Access connector configuration and Conditional Access risk guidance. Connector material now identifies non-overlapping dynamic and AutoReuse TCP ranges, while Conditional Access guidance warns that device-platform data from user-agent strings can be modified and is not verified. Other updates refine Exchange role-assignment and network-content-filtering descriptions. Several remaining edits are reference cleanup, removing Workplace by Facebook or Meta references from Entra integration, provisioning, governance, and lifecycle pages.

  • Global Secure Access connector guidance specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151. It adds configuration and verification commands, Windows Server 2016+ prerequisites, and the limitation that AutoReuse applies only to TCP. Administrators handling high-volume TCP workloads should review available and excluded ports before applying the settings.

  • The conditions guidance says device-platform information, including user-agent strings, can be modified and is not verified. It recommends combining device-platform conditions with Microsoft Intune device-compliance policies or using them in a block statement.

  • Groups guidance directs administrators to the Exchange admin center for role assignments through dynamic-membership groups. If the old Exchange admin center is required, it advises assigning the eligible role directly to the user rather than through role-assignable groups; Exchange PowerShell cmdlets continue to work as expected.

  • Global Secure Access guidance distinguishes Basic content filtering from Scan with Purview and explains that scanning can audit or block selected file and text content based on conditions.

For Entra administrators

Review connector servers against the specified port ranges and Windows Server 2016+ prerequisites; AutoReuse applies only to TCP, and the ranges must not overlap. For device-platform Conditional Access policies, consider pairing the condition with Microsoft Intune device-compliance or app-protection policies, or using it in a block statement. Follow the Exchange admin center guidance for dynamic-membership-group role assignments; if the old Exchange admin center is required, assign the eligible role directly to the user rather than through role-assignable groups. The supplied evidence indicates no administrator action for the Workplace reference removals or content-filtering wording updates.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

2

Backup Authentication System

Doc update

The backup authentication system documentation no longer lists Workplace from Facebook in its integration table.

28 September 2026

Provision On Demand

Doc update

The provision-on-demand article no longer includes references to Meta Workplace. The displayed guidance about stopping provisioning for OAuth-based applications remains unchanged.

28 September 2026
1
1

Conditional Access Conditions

Doc update

The documentation now warns that device platform information, such as user agent strings, can be modified and isn't verified. It recommends using device platform with Microsoft Intune device compliance policies or in a block statement.

28 September 2026
1

Groups Concept

Doc update

The guidance now directs administrators to the Exchange admin center for role assignments through dynamic membership groups. If the old Exchange admin center is required, assign the eligible role directly to the user rather than through role-assignable groups; Exchange PowerShell cmdlets work as expected.

28 September 2026
1

Policy All Users Device Unknown Unsupported

Doc update

The documentation now highlights that device platform conditions rely on user agent strings and recommends pairing them with policies requiring device compliance or app protection to reduce risk.

28 September 2026
1

Partner Driven Integrations

Doc update

The partner-driven integrations documentation now lists Dropbox and Snowflake as examples and no longer references Workplace by Facebook.

28 September 2026
1

Apps

Doc update

The Entra ID Governance apps page no longer lists Workplace from Meta in its application table.

28 September 2026
1

Create content policies for network content filtering

Doc update

The documentation now clarifies Basic content filtering and Scan with Purview descriptions, including that scanning can audit or block selected file and text content based on conditions.

28 September 2026
1

Connectors

Feature update

The documentation specifies non-overlapping dynamic TCP ports 49152–65535 and AutoReuse TCP ports 10000–49151, with new configuration and verification commands. It also adds Windows Server 2016+ prerequisites and clarifies that AutoReuse applies only to TCP.

28 September 2026
1

Configure Connectors

Doc update

The connector configuration guidance now refers to configuring dynamic and AutoReuse TCP port ranges instead of extending TCP and UDP ephemeral ports.

28 September 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…