Sspr Policy
Doc updateThe SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Daily.Entra.NewsSeptember reset Entra authentication: passkeys became the default Microsoft Entra authentication on September 1, while Microsoft-provided SMS and voice authentication face retirement deadlines beginning February 1, 2027. Microsoft also narrowed the Microsoft Graph User.ReadBasic.All permission, documented an External ID system-browser handoff for brokered identity providers, and described preview Continue Evaluation behavior in Global Secure Access Web Filtering v2. A phased rollout from October 2026 through February 2027 will let users register passkeys or passwordless sign-in as their first MFA method. Most remaining activity was documentation maintenance; notable operational exceptions included the removal of Enterprise State Roaming management from the Entra admin center and a newly documented Cloud Sync migration workflow.
The detailed guidance sets February 1, 2027, for users including internal guests, and July 1, 2027, for Global Administrators and external users. After the applicable date, users whose only MFA method is SMS or voice receive a blocking passkey-registration prompt; a customer-managed telecom provider is the documented option where those methods must remain available.
Beginning in mid-September, the permission no longer grants access to user app role assignments or license details as part of a security fix. Applications that need this data must switch to User.Read.All or LicenseAssignment.Read.All to avoid disruption.
Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and providers that block WebViews. Before using the flow, administrators should check the listed platform, broker, application-version, federation-protocol, and cloud support.
With the preview Continue Evaluation action, unmatched traffic passes to the next applicable security profile, while a matching rule or an Allow or Block action stops evaluation. The Baseline Profile must use Allow or Block, which matters when composing or migrating overlapping profiles.
A phased rollout from October 2026 through February 2027 lets users register passkeys or passwordless sign-in as their first multifactor authentication method, removing the need to establish a weaker method first.
Inventory applications using User.ReadBasic.All and replace it with User.Read.All or LicenseAssignment.Read.All where the removed data is required. Plan SMS and voice migration by user category, moving users to phishing-resistant methods or a customer-managed telecom provider where necessary. If adopting External ID browser authentication, verify the listed platform, broker, application-version, federation-protocol, and cloud prerequisites. For Web Filtering v2, review overlapping profile defaults and ensure the Baseline Profile uses Allow or Block.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.
The documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.
A how-to article explains how to enable FIDO2 and passkey methods, register credentials, configure a registry setting, and sign in to Microsoft Entra Connect Sync without a password.
The procedure now uses revised Microsoft Entra Connect paths and module-import commands, including the ADSync module and the AzureADSSO module. Step numbering and wording were also updated.
The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.
The Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.
The authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.
The documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.
The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.
The documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.
The version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.
The version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.
The Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.
The documentation now distinguishes Microsoft-managed and enabled campaigns. It specifies the MFA method required for each targeted authentication method and broadens eligible users from SMS or voice sign-ins to users signing in with any MFA method.
The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.
The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.
The documentation now explains how supported audit events can include DUSI, maps linkable identifiers to audit-log attributes, and provides steps for correlating sign-ins with administrative activity. Some events may not include DUSI.
The documentation now states that when Cloud Sync and Connect Sync are configured for the same domain, Cloud Sync processes password writeback for users synchronized from that domain.
The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.
The role description now states that Security Administrators can perform identity containment actions during security incidents.
Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.
The page title and heading no longer include “(preview).”
The documented password example now includes an exclamation mark at the end.
A new article explains how to diagnose intermittent STATUS_ACCOUNT_DISABLED sign-in and unlock errors on Microsoft Entra hybrid joined Windows devices, including relevant event logs and the stale-cache and connectivity conditions that can cause them.
The documentation now states that Microsoft-managed system-preferred authentication deployment will continue through September 2026, rather than August 2026.
Microsoft Entra improves the iOS Microsoft Authenticator app's passkey restore experience with a clearer, guided flow for device migration, launching worldwide mid-September 2026. It affects iOS users with iCloud backup, requires no action, and includes updated user guidance without policy changes.
The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.
The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.
The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.
The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.
The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.
The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.
The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.
Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.
The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.
The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.
The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.
The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.
As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.
The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.
The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.
My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.
Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.
Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.
The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.
The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.
The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.
The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.
The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.
The documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.
The app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.
The app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.
The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.
The article now documents configuring a SCIM endpoint that uses an OAuth2 client-credentials grant from a non-Entra issuer, including the token endpoint, client credentials, credential placement, and scopes.
The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.
The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.
The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.
The reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.
The permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.
The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.
The permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.
The schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.
The SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.
A new how-to explains registering an MCP server as an OAuth 2.0 protected resource, enabling v2 access tokens, and connecting MCP clients through Microsoft Entra Agent ID.
The app gallery publishing documentation now refers to the required identifier as a Partner One ID and notes that it was formerly called the Microsoft Partner Network (MPN) ID.
The SAML App Gallery validation article adds lightbox support to screenshots and a Next step link to the validation-results section.
The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”
Microsoft added documentation for using the guided migration tool to assess an environment, create Cloud Sync configurations, run a preactivation check, and validate synchronization after migration.
Microsoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.
The version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.
The page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.
The documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.
The documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.
The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.
The documentation now explains how optional single-valued source attributes can clear mapped target attributes when SAP SuccessFactors returns null or empty values.
The tutorial now requires Microsoft Entra ID P1, P2, or Governance licenses for every identity sourced through API-driven provisioning.
The documentation and screenshot alt text now refer to the field as “Submission ID” instead of “submission request ID.”
New documentation explains how HiBob can provision and update users in on-premises Active Directory through Microsoft Entra API-driven provisioning and the provisioning agent. It covers prerequisites, permissions, configuration, and synchronization flow.
The user provisioning validation guide now uses an updated Microsoft Entra admin center URL with additional parameters.
The procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.
The documentation now explains how to configure attribute value clearing, fallback values, or ignored values when HR applications return null or empty attributes during provisioning.
The documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.
The troubleshooting guidance for SEC_E_NO_AUTHENTICATING_AUTHORITY now links to Windows Server 2025 build 26100.6905 information.
The troubleshooting guide now uses `-vAuth` instead of `-v` when starting `Start-auth.ps1`.
The hybrid join troubleshooting page was updated with revised guidance for AADSTS50034, and its date changed from July 27, 2025, to September 1, 2026.
The version history entry now links readers to the latest available Microsoft Entra Connect Sync version.
The Windows token protection guide now refers to Microsoft Copilot instead of Microsoft 365 Copilot.
The Microsoft Entra External ID credential management API reference was deleted. It previously documented how applications let signed-in customers list, register, and delete passkeys.
Starting late September 2026, Microsoft Viva Engage will require Microsoft Entra permissions—Yammer Administrator role or Community Admin assignment—for community and membership management tasks previously allowed to Verified or Network Admins. Administrators should review and update role assignments accordingly.
Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.
Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.
Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out in phases from October 2026 to February 2027, aims to increase adoption of phishing-resistant sign-in.
The documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.
The app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.
The documentation now instructs app publishers to provide a Partner One ID associated with their Microsoft AI Cloud Partner Program organization and explains how to find help if they do not know it.
The instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.
The guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.
The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.
Account discovery now covers users and groups, classifying them as local, unassigned, or assigned identities. Group discovery is identified as being in preview, and correlation requires a direct matching attribute.
The documentation now explains how Entitlement Management integrates with ServiceNow for access package requests, request history, and approvals. It covers licensing, installation, configuration, and user workflows.
User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a security issue. Applications needing this data must switch to User.Read.All or LicenseAssignment.Read.All permissions and update accordingly to avoid disruptions.
The Node.js Express and web application entries in the sample code documentation were updated, including their linked sample resources.
The tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”
The page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.
The AI Administrator and AI Reader descriptions were updated from “Microsoft 365 Copilot” to “Microsoft Copilot.” Their role IDs remain unchanged.
Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.
The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.
The page now distinguishes diagnostic setting categories from KQL table names and maps six ID Protection signals to their corresponding AAD-prefixed Log Analytics tables.
The documentation now uses clearer wording for configuring LCW extensibility workflow mappings, creating an Azure Logic App and workflow, and configuring provisioning jobs with attribute mappings.
The Tenant Governance licensing page now links to Microsoft Agent 365 licensing FAQs and guidance for using governance relationships with Microsoft Defender.
The access package creation documentation now explains that the search box can find matching SharePoint Online roles that are not initially displayed, especially on sites with many roles.
The documentation now recommends using the search box to find SharePoint Online roles when adding them to an access package. Search returns matching roles even when they are not initially displayed.
The licensing documentation’s Microsoft author alias was updated from `tafra00` to `tazkiaafra`.
The documentation now specifies that existing guest users can be directly assigned, but external users who are not yet in the directory cannot be invited through direct assignment when access is limited to administrator direct assignments.
The HR integrations table now includes a link for HiBob to Microsoft Entra ID/Active Directory and updates the Rippling provisioning link text.
The documentation explains that related PIM activation and deactivation events can have different CorrelationId values. It recommends using roleAssignmentRequestId to trace a complete request and adds Log Analytics query examples.
The documentation now directs administrators to the **Who can request access** section on the **Requests** tab, where selecting **Manager** enables managers to request access packages for employees.
The licensing fundamentals page was updated to align the Account Discovery section and state that the feature requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite.
The page now lists the Microsoft Agent 365 Licensing FAQs and governance relationships links without the previous section heading and introductory text.
Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.
The article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.
A single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.
The article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.
The article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.
The article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.
The article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.
The documentation no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and states that low-privilege passkey credential management APIs are on the roadmap.
The article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.
The External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.
The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.
The user profile information documentation no longer includes guidance that users can use My Apps preview features or that administrators can access My Staff.
The user profile information guidance no longer includes the “Manage user feature settings” reference.
The documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.
The new article explains how to use Quick setup, register applications, create credentials, and issue and verify credentials in a Microsoft Entra External ID tenant. It documents prerequisites and limits, including custom-domain requirements, shared signing keys, two requests per second per tenant, and six-month credential validity.
The documentation removes “preview” from the source traffic type and HTTP method request filtering conditions, updates their headings and links, and refreshes the page date.
Microsoft Purview DLP integrates with Entra Global Secure Access Internet Access to filter sensitive files at the network layer, preventing data leaks to unmanaged cloud apps. Public preview starts mid-November 2025; general availability by October 2026. Admins must configure policies, TLS inspection, and activate Purview pay-as-you-go.
The documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.
The Internet Access health-signal article now lists licensing, roles, Microsoft Graph permissions, and log access requirements. It also adds steps for investigating alerts and reviewing filtering and forwarding policies.
The documentation now requires a non-trial Microsoft Entra P1 or P2 license plus at least 100 monthly active users to view alerts and receive notifications. It also clarifies Private Access licensing, least-privilege roles, Graph permissions, and expanded signal and alert investigation guidance.
The documentation now clarifies that Azure CLI commands and IaC templates must use the provider namespace Microsoft.Storage, while Microsoft.Storage/* is only an Azure portal display convention.
The documentation now clarifies that Azure CLI commands and IaC templates must use Microsoft.Storage. The Microsoft.Storage/* format shown in the portal is only a display convention and is not accepted by the API.
The documentation now states that creating a managed identity is blocked when the resulting directory usage reaches or exceeds 98% of the tenant quota. This applies to new or recreated service principals; existing identities and assignments continue to work.
The article now provides explicit prerequisites, required Microsoft Entra and SAP permissions, SAP IAS OIDC and JWT Trust-by-Issuer configuration details, and a clearer token flow and revocation explanation.
The Entra documentation now uses the singular verb “needs” for “GitHub Actions” in an example about workload identities accessing Azure subscriptions.
The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.
The page title now marks custom headers as preview and notes that rollout is expected to complete by September 10, 2026.
Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.
The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.
The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.
The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.
The AI prompt injection protection documentation now explains that TLS inspection can use either a Microsoft-managed certificate or an administrator-provided certificate before configuring TLS inspection policies.
The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.
The documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”
The documentation now provides separate links for configuring TLS inspection with a Microsoft-managed certificate and with your own certificate.
The article now distinguishes tunnel and BGP connectivity scenarios and adds investigation steps, licensing requirements, least-privilege roles, and Microsoft Graph permissions for viewing and managing signals and alerts.
The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.
The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.
The guidance now labels the link “Microsoft Copilot requirements” instead of “Microsoft 365 Copilot requirements.”