← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Connect Sync guidance sets a 2.6.84.0 minimum and April 7, 2027 authentication deadline

Most of the period is low-impact documentation maintenance involving terminology, metadata, links, and examples. The meaningful administrator-facing changes are updated Connect Sync requirements, removal of the Cloud Sync device-sync Preview label, new GitHub federation claim guidance, clearer Kerberos prerequisites, and more precise PIM eligibility duration behavior.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

26 updates

10

Connect Version History

RetirementAction required

The documented deadline changed to April 7, 2027. Synchronization services require version 2.5.79.0 or later and application-based authentication after legacy authentication ends.

Connect Version History

RetirementAction required

The required Microsoft Entra Connect Sync version is now 2.6.84.0 or later, with application-based authentication configured by April 7, 2027. Legacy authentication retirement will stop synchronization services after that date if requirements are unmet.

Connect Install Prerequisites

RetirementAction required

The documentation now requires Microsoft Entra Connect Sync version 2.5.79.0 or later and application-based authentication by April 7, 2027. Synchronization services will stop working after that date if these requirements are unmet.

Connect Install Prerequisites

Feature updateAction required

The required minimum version changed from 2.5.79.0 to 2.6.84.0. Administrators must also configure application-based authentication by April 7, 2027.

Connect Install Prerequisites

Doc updateAction required

The prerequisites page now bolds the warning to upgrade Entra Connect Sync to version 2.5.79.0 or later and configure application-based authentication by April 7, 2027. Synchronization services will stop afterward if requirements are unmet.

Connect Version History

RetirementAction required

The documentation now bolds the warning that Microsoft Entra Connect Sync must be upgraded to version 2.5.79.0 or later and configured for application-based authentication by April 7, 2027. Synchronization services will stop afterward if requirements are unmet.

Tutorial Manage Certificates For Federated Single Sign On

Doc updateAction required

The instructions now say to verify notification email addresses configured through Microsoft Graph or PowerShell in the Microsoft Entra admin center. Opening the SAML certificate experience can initialize notification registration for custom signing certificates.

Scopes Oidc

Doc update

The documentation now uses clearer wording to describe fine-grained permissions, scopes, and how apps request them through the `scope` parameter.

6

Security Updates Pks

Feature updateAction required

The required Microsoft Entra Connect Sync version changed from 2.5.79.0 to 2.6.84.0 or later. Application-based authentication must still be configured by April 7, 2027.

Security Updates Pks

RetirementAction required

The deadline changed to April 7, 2027. Administrators must upgrade to version 2.5.79.0 or later and configure application-based authentication; synchronization stops after the deadline if requirements are unmet.

Security Updates Pks

Doc updateAction required

The warning is bolded: upgrade Microsoft Entra Connect Sync to version 2.5.79.0 or later and configure application-based authentication by April 7, 2027. Synchronization services will stop working after that date if these requirements are not met.

Upgrade Previous Version

RetirementAction required

The documentation now bolds the mandatory upgrade warning: upgrade Entra Connect Sync to version 2.5.79.0 or later and configure application-based authentication by April 7, 2027. Legacy authentication will be retired, and synchronization will stop after that date if requirements are unmet.

Upgrade Previous Version

RetirementAction required

The documentation now requires version 2.5.79.0 or later and application-based authentication by April 7, 2027. Synchronization services will stop afterward if these requirements are unmet.

Upgrade Previous Version

Feature updateAction required

The required Microsoft Entra Connect Sync version increased from 2.5.79.0 to 2.6.84.0. Administrators must also configure application-based authentication by April 7, 2027.

3

Introduction to Microsoft Entra Kerberos

New feature

The page now describes how Windows Hello for Business cloud Kerberos trust uses Microsoft Entra Kerberos to provide passwordless access to Active Directory resources and links to a deployment guide.

Kerberos

Doc updateAction required

The documentation now states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID, including required group memberships.

Sspr Howitworks

Doc update

The SSPR documentation now refers to a “Microsoft Entra administrator role” instead of an “Azure administrator role” when describing enforcement of the strong two-gate password policy.

1

Provision On Demand

Doc update

The sign-in step now lists Application Owners alongside Application Administrators as acceptable roles for accessing the Microsoft Entra admin center.

1
1
2

Managed Identities Status

Doc update

The managed identities status table now links to permissions and identity guidance for Chaos Studio Workspaces, while retaining a separate link for Azure Chaos Studio (classic).

1

Kerberos

Doc update

The page now explains how Microsoft Entra ID users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also clarifies that provisioning alone does not enable Kerberos or passwordless access.

1

Workload Identities Flexible Federated Identity Credentials

Doc update

The page now notes that, starting July 15, 2026, GitHub will automatically use immutable subject claims for newly created, renamed, or transferred repositories. Existing repositories will retain name-based claims unless opted in.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…