Connect Version History
RetirementAction requiredThe documented deadline changed to April 7, 2027. Synchronization services require version 2.5.79.0 or later and application-based authentication after legacy authentication ends.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Most of the period is low-impact documentation maintenance involving terminology, metadata, links, and examples. The meaningful administrator-facing changes are updated Connect Sync requirements, removal of the Cloud Sync device-sync Preview label, new GitHub federation claim guidance, clearer Kerberos prerequisites, and more precise PIM eligibility duration behavior.
The updated Security Updates Pks guidance changes the stated required version from 2.5.79.0 to 2.6.84.0 or later. It also requires application-based authentication by April 7, 2027; synchronization services stop after that date when either requirement is unmet.
The device-sync article removes the Preview label and preview legal notice, while also updating its publication date. The supplied guidance specifies no administrator action.
Starting July 15, 2026, GitHub automatically uses immutable subject claims for newly created, renamed, or transferred repositories. Existing repositories retain name-based claims unless they opt in.
Users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. Provisioning alone does not enable Kerberos or passwordless access.
The `duration: P365D` value makes an eligible assignment expire after 365 days. Permanent eligibility requires the target scope's role-management policy to allow it.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documented deadline changed to April 7, 2027. Synchronization services require version 2.5.79.0 or later and application-based authentication after legacy authentication ends.
The required Microsoft Entra Connect Sync version is now 2.6.84.0 or later, with application-based authentication configured by April 7, 2027. Legacy authentication retirement will stop synchronization services after that date if requirements are unmet.
The documentation now requires Microsoft Entra Connect Sync version 2.5.79.0 or later and application-based authentication by April 7, 2027. Synchronization services will stop working after that date if these requirements are unmet.
The required minimum version changed from 2.5.79.0 to 2.6.84.0. Administrators must also configure application-based authentication by April 7, 2027.
The prerequisites page now bolds the warning to upgrade Entra Connect Sync to version 2.5.79.0 or later and configure application-based authentication by April 7, 2027. Synchronization services will stop afterward if requirements are unmet.
The documentation now bolds the warning that Microsoft Entra Connect Sync must be upgraded to version 2.5.79.0 or later and configured for application-based authentication by April 7, 2027. Synchronization services will stop afterward if requirements are unmet.
The tutorial now uses `https://account.samsung.com/` instead of `https://accounts.samsung.com/` and includes updated documentation metadata.
The instructions now say to verify notification email addresses configured through Microsoft Graph or PowerShell in the Microsoft Entra admin center. Opening the SAML certificate experience can initialize notification registration for custom signing certificates.
The documentation now uses clearer wording to describe fine-grained permissions, scopes, and how apps request them through the `scope` parameter.
The Viva Glint entry now includes WORKPLACE_ANALYTICS_INSIGHTS_BACKEND and its associated identifier.
The required Microsoft Entra Connect Sync version changed from 2.5.79.0 to 2.6.84.0 or later. Application-based authentication must still be configured by April 7, 2027.
The deadline changed to April 7, 2027. Administrators must upgrade to version 2.5.79.0 or later and configure application-based authentication; synchronization stops after the deadline if requirements are unmet.
The warning is bolded: upgrade Microsoft Entra Connect Sync to version 2.5.79.0 or later and configure application-based authentication by April 7, 2027. Synchronization services will stop working after that date if these requirements are not met.
The documentation now bolds the mandatory upgrade warning: upgrade Entra Connect Sync to version 2.5.79.0 or later and configure application-based authentication by April 7, 2027. Legacy authentication will be retired, and synchronization will stop after that date if requirements are unmet.
The documentation now requires version 2.5.79.0 or later and application-based authentication by April 7, 2027. Synchronization services will stop afterward if these requirements are unmet.
The required Microsoft Entra Connect Sync version increased from 2.5.79.0 to 2.6.84.0. Administrators must also configure application-based authentication by April 7, 2027.
The page now describes how Windows Hello for Business cloud Kerberos trust uses Microsoft Entra Kerberos to provide passwordless access to Active Directory resources and links to a deployment guide.
The documentation now states that users accessing Active Directory-protected resources need corresponding Active Directory accounts. Cloud-managed users should be provisioned from Microsoft Entra ID, including required group memberships.
The SSPR documentation now refers to a “Microsoft Entra administrator role” instead of an “Azure administrator role” when describing enforcement of the strong two-gate password policy.
The sign-in step now lists Application Owners alongside Application Administrators as acceptable roles for accessing the Microsoft Entra admin center.
The article no longer labels Microsoft Entra Cloud Sync device sync as preview and removes the preview legal notice. Its publication date was also updated.
The documentation now explains that `duration: P365D` makes an eligible assignment expire after 365 days. Permanent eligibility requires the target scope’s role management policy to allow it.
The workload identity federation documentation now uses Microsoft Graph Bicep extension version 1.0.0 instead of 0.1.8-preview.
The managed identities status table now links to permissions and identity guidance for Chaos Studio Workspaces, while retaining a separate link for Azure Chaos Studio (classic).
The page now explains how Microsoft Entra ID users and groups provisioned to Active Directory with Cloud Sync can access Kerberos-protected resources through Microsoft Entra Kerberos, Windows Hello for Business, or FIDO2. It also clarifies that provisioning alone does not enable Kerberos or passwordless access.
The page now notes that, starting July 15, 2026, GitHub will automatically use immutable subject claims for newly created, renamed, or transferred repositories. Existing repositories will retain name-based claims unless opted in.