What If Tool
Doc updateThe Conditional Access What If tool table now uses a different sample UserId in all four examples.
Daily.Entra.NewsThis was a documentation-heavy day led by an explicit Global Secure Access connector support warning and clearer Conditional Access guidance on Android Microsoft Authenticator’s Google Play Integrity dependency. The remaining updates mostly revise example identifiers, consent-policy application IDs, links, or sample values across Entra ID, Workload ID, and ID Governance. All 19 supplied changes were updates; there were no new, removed, or Message Center items.
Versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 are marked deprecated. Users of version 1.5.612.0 or earlier are instructed to update immediately to the latest version to retain fully supported features.
Conditional Access guidance states that Android Microsoft Authenticator uses the Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled, giving administrators a specific path for investigating Android access denials.
The Manage App Consent Policies guidance now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird. Administrators using these entries should compare the documented IDs with their consent-policy configurations.
The endpoint URI, calling application claim, and resourceId examples now consistently use a different application client ID. Administrators configuring Privileged Identity Management custom extensions should use the updated identifier values.
The Workload Identity Federation guidance changes the example Subject used in the New-AzADAppFederatedCredential command for a managed identity. Administrators copying the command should use the updated Subject value.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The Conditional Access What If tool table now uses a different sample UserId in all four examples.
The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.
The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.
The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.
Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.
The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.
The Linux device registration troubleshooting documentation now shows a different tenant ID in its example output.
The documentation now consistently uses a different application client ID in the endpoint URI, calling application claim, and `resourceId` examples.
The documentation now uses revised Application (client) ID examples in the endpoint URI and `resourceId` configuration sample.
The PowerShell example now uses a different Subject value for the managed identity federated credential.
The documentation changes the example `-Subject` value in the `New-AzADAppFederatedCredential` command.
The curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.
The VM managed identity documentation changes the client_id value in its curl token-request example.
The documentation updates the name or identifier of the dedicated first-party service principal used to synchronize Active Directory with Microsoft Entra ID.
The documentation wording about the dedicated first-party application and service principal used for synchronization between Active Directory and Microsoft Entra ID was revised.
The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.