← Previous day

Day in brief

Global Secure Access sets November date for automatic upgrades on eligible Windows clients

The period's clearest operational change is in Global Secure Access release guidance: starting November 2026, eligible Windows clients will receive GSA upgrades through Windows Update. Version 2.32.294 also adds Prefer local network and faster tunnel creation. Other meaningful updates clarify government-cloud eligibility, tenant-creation permissions, SSGM scope, and separate SSO and SCIM App Gallery validation paths.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

28 updates

9

Breaking Changes

Doc update

The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.

Breaking Changes

Doc update

The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.

SSO requirements for Microsoft Entra App Gallery

Doc update

Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.

Groups Settings V2 Cmdlets

Doc update

The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.

7

Prerequisites to validate and publish your app

Doc update

The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.

Prerequisites to validate and publish your app

Doc update

The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.

Howto Update Permissions

Doc update

The permission-addition and permission-removal examples now use different sample object and client IDs.

Howto Update Permissions

Doc update

The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

Howto Update Permissions

Doc update

The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.

Howto Update Permissions

Doc update

The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.

4

Publish your app to Microsoft Entra App Gallery

Doc update

A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.

Plan Sso Deployment

Doc update

Removed an extra space from the Help desk admin row in the documentation table.

1

Strengthen federated sign-in security

Doc update

The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.

1
2

Create Tenant

Doc update

The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.

Create Tenant

Feature updateAction required

The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.

4

Global Secure Access Client Release Notes

New feature

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

Current Known Limitations

Doc update

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

Current Known Limitations

Doc update

The documentation received a minor formatting change with no substantive content changes identified.

Current Known Limitations

Doc update

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…