Breaking Changes
Doc updateThe breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
The period's clearest operational change is in Global Secure Access release guidance: starting November 2026, eligible Windows clients will receive GSA upgrades through Windows Update. Version 2.32.294 also adds Prefer local network and faster tunnel creation. Other meaningful updates clarify government-cloud eligibility, tenant-creation permissions, SSGM scope, and separate SSO and SCIM App Gallery validation paths.
The release notes state that starting in November 2026, eligible Windows clients will automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 adds Prefer local network, faster tunnel creation, and other fixes; administrators opting out must use the documented installer parameter and update manually.
Current Known Limitations now explicitly says Global Secure Access is available in GCC but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.
The Create Tenant guidance now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting. Accounts creating add-on tenants therefore need that role.
Groups Settings V2 documentation now says standard users can create groups by default regardless of SSGM, while SSGM controls behavior only in the My Groups portal. The MSODS reference was also removed.
The revised prerequisites guidance separates shared prerequisites from SSO and SCIM requirements and states that applications supporting both capabilities must complete validation for both.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.
The new page lists SCIM API, authentication, testing, support, documentation, customer deployment, and cloud compliance requirements for publishing user provisioning integrations in Microsoft Entra App Gallery.
A tutorial now explains how to use the Microsoft Entra App Validator browser extension with non-gallery enterprise applications, including IdP- and SP-initiated SSO, certificate scenarios, optional Single Logout, and result submission.
The documentation explains how to use the Microsoft Entra App Validator browser extension to test an OIDC multitenant app, review fixes, and generate the Test ID required for gallery publishing.
Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.
The guide title now uses quoted punctuation, and the table separator spacing was standardized.
The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.
The page title changed from “What is single sign-on (SSO) in Microsoft Entra ID?” to “What is single sign-on in Microsoft Entra ID?”
The documentation explains how to access the Microsoft Application Network portal and submit requests to update SSO, MDM, or user provisioning details, upgrade SSO, or remove an application listing.
The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.
The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.
The permission-addition and permission-removal examples now use different sample object and client IDs.
The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.
The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.
A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.
The page title now says “Microsoft Entra ID,” and several table separators were reformatted for consistent Markdown presentation.
The documentation now explains that Agent ID objects are covered through their underlying directory object types, including user accounts as user objects and identity blueprints as application objects.
Removed an extra space from the Help desk admin row in the documentation table.
The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.
The recovery model documentation now lists agent user accounts, agent identity blueprints, agent identities, and agent identity blueprint principals among covered objects.
The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.
The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.
Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.
The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.
The documentation received a minor formatting change with no substantive content changes identified.
The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.