← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Key rotation reaches general availability while baseline enforcement guidance adds a Graph query

The strongest changes affect trust authentication, Conditional Access scoping, and Agent ID troubleshooting. Updated What's New guidance describes key rotation for incoming trust referral flows as generally available, improving reliability and addressing failures when referral tickets use a secondary key. Enforcement Resource Exclusions guidance records that baseline-scope enforcement rollout began June 15, 2026, and adds a Microsoft Graph query. New Agent ID how-to articles cover autonomous and interactive sign-ins, while a separate Kerberos trust guide details setup and lifecycle operations. The standalone Kerberos Server Key Rotation article was removed, and access-package guidance now clarifies a limitation on overlapping automatic-assignment policies.

  • The updated What's New guidance says key rotation for incoming trust referral flows is generally available. It describes the change as improving reliability and addressing authentication failures caused when referral tickets use a secondary key; no required administrator action is stated.

  • Enforcement Resource Exclusions guidance now states that baseline-scope enforcement rollout began June 15, 2026. It adds a Microsoft Graph query for finding affected Conditional Access policies and clarifies customization and sign-in review guidance.

  • A new how-to explains Health Monitoring signals and alerts, impact criteria, log correlation, troubleshooting, and prerequisites for autonomous agent sign-ins. The monitoring and alerts are documented as being in preview, with guidance for identifying affected applications and investigating application-only authentication failures.

  • The new guide documents prerequisites, PowerShell module installation, Trusted Domain Object creation, client ticket configuration, key rotation, trust removal, and required permissions for managing trust between Microsoft Entra ID and on-premises AD DS.

  • Entitlement Management guidance now clarifies that multiple automatic assignment policies for one access package are supported only when users do not match multiple policies simultaneously. Administrators should review overlapping policy scopes to avoid duplicate assignment paths.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

9 updates

4

Configure Microsoft Entra Kerberos trust

Doc update

The documentation now covers prerequisites, PowerShell module installation, Trusted Domain Object creation, client ticket configuration, key rotation, and trust removal.

Whats New

Generally available

The documentation states that generally available key rotation improves reliability for incoming trust referral flows and addresses authentication failures caused when referral tickets used a secondary key.

Kerberos Server Key Rotation

Doc update

The standalone article describing Kerberos server-key rotation, prerequisites, dual-key behavior, and the Set-AzureADKerberosServer procedure was deleted.

1

Enforcement Resource Exclusions

Doc update

The documentation now states that baseline-scope enforcement rollout began June 15, 2026. It adds a Microsoft Graph query for finding affected Conditional Access policies and clarifies customization and sign-in review guidance.

1

Manage Device Identities

Feature update

The documentation now states that any user can use **Download devices** to export a CSV of devices, with optional filters; without filters, all devices are included.

2

Investigate Agent ID autonomous sign-ins

Doc update

Adds a how-to article explaining Health Monitoring signals and alerts, log correlation, impact criteria, troubleshooting, and prerequisites for autonomous agent sign-ins. The monitoring and alerts are documented as being in preview.

Investigate Agent ID interactive sign-ins

Doc update

A new how-to explains how to interpret Health Monitoring signals, correlate agent properties with sign-in and audit logs, and mitigate common failures. It also identifies the relevant non-interactive sign-in logs and documents licensing and role prerequisites.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…