The documentation corrects an internal section link and improves grammar, spelling, punctuation, and wording throughout the rollout guidance.
Keep up with Microsoft Entra
Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Chatwork SCIM provisioning ends October 1, 2026 as Entra sharpens agent-access guidance
Administrators using the Chatwork Enterprise App Gallery integration face a stated October 1, 2026 cutoff: SCIM provisioning will stop, and the integration will no longer provision users. The period also substantially expands Agent ID Conditional Access guidance around token subjects, agent-user targeting, prerequisites, and report-only rollout. Global Secure Access guidance records a Secure DNS limitation, while most remaining edits cover wording, links, terminology, or role documentation.
- Chatwork provisioning support has a firm October 1 cutoff
Entra ID · Provisioning
The Chatwork Provisioning Tutorial now states that SCIM provisioning support will end on October 1, 2026. After that date, the Microsoft Entra Enterprise App Gallery integration will stop provisioning users. The page also standardizes the product name to “Chatwork.”
- Agent Conditional Access guidance now separates three identity patterns
Agent ID · Conditional Access
The guidance distinguishes agents acting for signed-in users, agents using their own identity, and agents using an agent user account. It adds separate guidance links for autonomous agents and agent users and updates the listed licensing combinations, giving administrators a basis for selecting the relevant policy guidance.
- Autonomous-agent policy guidance adds prerequisites and report-only rollout
Agent ID · Conditional Access
The updated autonomous-agent guidance presents Conditional Access as a scenario-based pattern, adds prerequisites, and recommends starting block policies in report-only mode. It also states that an Agent 365 license will soon be required.
- Broad Conditional Access targeting does not include agent users
Entra ID · Conditional Access
New guidance for securing agent users states that all-user and group targeting do not include agent users. It documents prerequisites, risk controls, device and network conditions, and blocking risky agent user accounts, so administrators should use the dedicated agent-user pattern rather than assume broad targeting covers these accounts.
- Global Secure Access documents Secure DNS and macOS tunneling limits
Global Secure Access · General
The known-limitations guidance now states that the Global Secure Access client does not support Secure DNS variants including DoH, DoT, and DNSSEC. It also says the macOS client bypasses Secure DNS to enforce FQDN-based tunneling.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
10 updates
Microsoft Entra ID
4 updatesThe guidance explains prerequisites, policy targeting, risk controls, device and network conditions, and blocking risky agent user accounts. It notes that all-user and group targeting don't include agent users.
Adsync Service Account
Doc updateThe table now explicitly labels Group Managed Service Account (gMSA) and Standalone Managed Service Account (sMSA), with corresponding installation guidance.
Chatwork Provisioning Tutorial
RetirementThe documentation standardizes the product name to “Chatwork” and states that SCIM provisioning support will end on October 1, 2026. The Entra Enterprise App Gallery integration will then stop provisioning users.
Microsoft Entra Agent ID
5 updatesThe article now presents Conditional Access for autonomous agents as a scenario-based pattern, adds prerequisites, and recommends starting block policies in report-only mode. It also notes that an Agent 365 license will soon be required.
Conditional Access for Agents in Microsoft Entra
Feature updateThe documentation now distinguishes agents acting for signed-in users, using their own identity, or using an agent user account. It adds separate guidance links for autonomous agents and agent users and updates the listed licensing combinations.
The article now uses a scenario-based structure, explains that conditions and controls depend on the token subject, and links separately to guidance for agent identities and agent user accounts. Terminology, metadata, and related links were also updated.
Agent Users
Feature updateThe documentation now states that agent user accounts can be assigned custom roles, while privileged administrator roles remain restricted.
Authorization Agent Id
Doc updateThe authorization documentation now states that custom roles can be assigned to agents.
The known limitations article now states that the client doesn't support Secure DNS variants such as DoH, DoT, or DNSSEC, and that the macOS client bypasses Secure DNS to enforce FQDN-based tunneling.
