Secure add-on tenant creation
Doc updateThe page title no longer includes “(preview),” and the prerelease product notice was removed.
Daily.Entra.NewsA new External ID reference describes delegated credential management for signed-in customers’ passkeys, while ID Governance guidance now spells out the billing, role, and policy prerequisites for governed workforce tenant creation. Global Secure Access also records macOS client version 1.1.26060207, including Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and fixes. Most remaining changes refine terminology, links, and procedures; one Rouse Sales provisioning tutorial was removed.
Applications can use delegated access tokens to list, register, and delete signed-in customers’ passkeys. The service principal must be provisioned manually, and app-only tokens aren't supported.
The guidance specifies a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, along with the required tenant-creation permission, role, and default governance-policy prerequisites. Free or trial tenants cannot create additional tenants.
The governing tenant’s default governance policy template is labeled optional rather than required. The tenant-creation service still uses only the template with ID `default`.
The release notes document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes. The Intune deployment guidance says to remove `com.microsoft.autoupdate2` from detection rules.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The page title no longer includes “(preview),” and the prerelease product notice was removed.
The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.
The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.
The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.
The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.
The Microsoft Entra tutorial for configuring automatic user provisioning to Rouse Sales has been deleted.
The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.
The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.
The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.
The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.
The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.
The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.
The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).
The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.
The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.
The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.
The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.
The document’s `ms.author` metadata changed from `tafra00` to `tazkiaafra`.
The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.
The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.
The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.
The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.
The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.
The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.
The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.
Microsoft Entra External ID now documents an API that lets applications list, register, and delete signed-in customers’ passkeys using delegated access tokens.
The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.
Starting with version 1.1.26060207, the app package includes com.microsoft.autoupdate2 for future use cases.
The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.
The release-history page no longer includes version 1.1.26060207 or its listed changes, and its document date changed from August 21, 2026, to April 16, 2026.
The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.
The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.
The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.
The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.