← Previous day

Day in brief

Global Secure Access documents a preview Microsoft-managed TLS inspection certificate path

Global Secure Access was the sole focus of the period, centered on TLS inspection. A new preview guide covers a tenant-specific Microsoft-managed root CA for Microsoft Entra Internet Access TLS inspection, while related guidance separates managed-certificate and customer-provided certificate procedures. The remaining custom-header update only standardized spacing in domain lists.

  • The new guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The private key remains protected by Microsoft.

  • The main TLS inspection page now explains how to configure TLS inspection with either a Microsoft-managed certificate or an administrator-provided certificate.

  • The updated guide focuses on creating a certificate signing request, having it signed by the organization’s PKI, and uploading the resulting certificate, while linking to the separate Microsoft-managed certificate guidance.

  • The guidance now explains that TLS inspection for enterprise generative AI app prompt-injection protection can use either a Microsoft-managed certificate or an administrator-provided certificate before TLS inspection policies are configured.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

7 updates

4

Transport Layer Security

Doc update

The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.

Configure TLS inspection with a Microsoft-managed certificate

New featureAction required

The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.

Configure TLS inspection with your own certificate

Doc update

The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.

1
1

Configure Custom Headers

Doc update

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

1

Troubleshoot Transport Layer Security

Doc update

The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…