← Previous day

Next day →
Day in brief

External ID guidance details delegated API for customer-owned passkeys

A new External ID reference describes delegated credential management for signed-in customers’ passkeys, while ID Governance guidance now spells out the billing, role, and policy prerequisites for governed workforce tenant creation. Global Secure Access also records macOS client version 1.1.26060207, including Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and fixes. Most remaining changes refine terminology, links, and procedures; one Rouse Sales provisioning tutorial was removed.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

34 updates

5

Quickstart - Access and create new tenant

Feature update

The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.

Create New Tenant

Doc update

The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.

Create New Tenant

Doc update

The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.

Create New Tenant

Doc update

The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.

1
15

Deploy Microsoft Entra Tenant Governance end to end

Feature update

The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.

Create Lifecycle Workflow

New feature

The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.

Create a governed workforce tenant

Feature update

The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.

Automatic formation of governance relationships

Feature updateAction required

The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.

Automatic formation of governance relationships

Feature update

The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.

Create Tenant

Doc update

The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.

Create Tenant

Feature update

The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).

Create Tenant

Feature update

The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.

Automatic Governance Relationships

Doc update

The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.

Create Tenant

Doc update

The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.

Create Tenant

Doc update

The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.

Create Tenant

Doc update

The document’s `ms.author` metadata changed from `tafra00` to `tazkiaafra`.

Create Tenant

Doc update

The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.

Create Tenant

Doc update

The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.

Create Tenant

Doc update

The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.

3

Deployment Guide

Doc update

The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.

Deployment Guide

Doc update

The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.

Deployment Guide

Doc update

The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.

2

Sign In With Passkey

New feature

The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.

8

Global Secure Access Client for macOS Release Notes

Feature updateAction required

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

Install the Global Secure Access Client for macOS

Doc update

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

Install Macos Client

Doc update

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

Install Macos Client

Doc update

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

Install Macos Client

Doc update

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

Macos Client Release History

Doc update

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…