← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Global Secure Access TLS inspection gains preview Microsoft-managed certificate guidance

The substantive work on 1 September centers on Global Secure Access TLS inspection. A new guide documents the preview Microsoft-managed certificate route: create a tenant-specific root CA, deploy its public certificate to client devices, and then enable inspection. Related guidance separates that workflow from bringing your own certificate authority. The day's other notable operational change replaces both AD FS and AD DS Connect Health roadmap download ID 108565 with 108777.

  • The new guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The private key remains protected by Microsoft, and MDM such as Intune can be used for deployment.

  • The updated article focuses on bringing your own certificate authority, including creating a certificate signing request, having it signed by PKI, and uploading the certificate. It also links to the separate Microsoft-managed certificate guidance; the update requires no administrator action for existing users.

  • The TLS inspection setup guidance for enterprise generative AI prompt-injection protection now explains that administrators can use either a Microsoft-managed certificate or an administrator-provided certificate before configuring TLS inspection policies.

  • The Connect Install Roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

8 updates

1

Connect Install Roadmap

Doc update

The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.

4

Transport Layer Security

Doc update

The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.

Configure TLS inspection with a Microsoft-managed certificate

New featureAction required

The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.

Configure TLS inspection with your own certificate

Doc update

The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.

1
1

Configure Custom Headers

Doc update

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

1

Troubleshoot Transport Layer Security

Doc update

The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…