MondayMon
TuesdayTue
WednesdayWed
ThursdayThu
FridayFri
SaturdaySat
SundaySun
2414Entra IDID GovernanceGlobal Secure Access2514Entra IDExternal IDGlobal Secure Access2629Entra IDID GovernanceGlobal Secure Access2714Agent IDEntra IDExternal ID2841Entra IDWorkload IDID Governance2912Entra IDGlobal Secure Access303122Agent IDEntra IDID Governance17Global Secure Access
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
1
2
3
4
Month in brief

Global Secure Access documents preview workflow for Microsoft-managed TLS certificates

September’s substantive Global Secure Access work centered on TLS inspection certificate choices. A new guide documents a preview Microsoft-managed root CA path, while existing pages now separate that route from customer-provided PKI and carry the distinction into prompt-injection protection guidance. The remaining unrelated edit added consistent spacing to custom-header domain lists, with no administrator action indicated.

  • The new Global Secure Access guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. It states that the private key remains protected by Microsoft and identifies the capability as preview.

  • The TLS inspection fundamentals page now provides separate links for configuring inspection with a Microsoft-managed certificate and with an administrator’s own certificate, helping administrators select the applicable workflow.

  • The own-certificate article now focuses on bringing your own certificate authority and covers certificate signing request creation, PKI signing, and certificate upload, while linking to the separate Microsoft-managed certificate guidance.

  • The guidance for protecting enterprise generative AI apps now explains that TLS inspection can use either a Microsoft-managed certificate or an administrator-provided certificate before TLS inspection policies are configured.

For Entra administrators

Administrators choosing the Microsoft-managed certificate path must create the tenant-specific root CA and deploy its public certificate to client devices before enabling TLS inspection to avoid certificate errors; MDM solutions such as Intune can be used. Administrators using their own PKI can follow the clarified CSR, PKI-signing, and certificate-upload workflow, selecting the guide that matches their certificate choice.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

7 updates by product

4

Transport Layer Security

Doc update

The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.

1 September 2026

Configure TLS inspection with a Microsoft-managed certificate

New featureAction required

The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.

1 September 2026

Configure TLS inspection with your own certificate

Doc update

The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.

1 September 2026
1
1

Configure Custom Headers

Doc update

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

1 September 2026
1

Troubleshoot Transport Layer Security

Doc update

The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.

1 September 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…