Cross-product topic

General

A cross-product view of Microsoft Entra changes related to General.

Latest General changes

Connect Version History

General

The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.

Connect Version History

General

The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.

Connect Version History

General

The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.

Connect Version History

General

The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.

Connect Version History

General

The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.

Connect Version History

General

Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.

Connect Version History

General

The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.

Connect Version History

General

The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.

Connect Version History

General

The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.

Connect Version History

General

The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.

Connect Version History

General

The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.

Using single sign-on with cloud sync

General

The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.

Configure

General

The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.

Migrate Microsoft Entra Enterprise State Roaming

General

As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.

Validate Oidc Multitenant App Gallery

General

The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.

How to configure custom headers (preview)

General

The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.

Licensing Service Plan Reference

General

Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.

Licensing Service Plan Reference

General

Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.

My Staff Configure

General

The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.

Use My Staff to delegate user management

General

My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.

Set up B2B direct connect

General

The documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.

Configure Managed Identities Assignment Restriction

General

The documentation now clarifies that Azure CLI commands and IaC templates must use the provider namespace Microsoft.Storage, while Microsoft.Storage/* is only an Azure portal display convention.

Managed Identities Assignment Restriction

General

The documentation now clarifies that Azure CLI commands and IaC templates must use Microsoft.Storage. The Microsoft.Storage/* format shown in the portal is only a display convention and is not accepted by the API.

Delegate By Task

General

The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.

Least privileged roles by task

General

The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.

Manage Agent Identities End User

General

The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.

Permissions Reference

General

The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.

Whats New

General

The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.

Managed Identities Faq

General

The documentation now states that creating a managed identity is blocked when the resulting directory usage reaches or exceeds 98% of the tenant quota. This applies to new or recreated service principals; existing identities and assignments continue to work.

Publish App Gallery

General

The documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.

V2 Howto App Gallery Listing

General

The app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.

V2 Howto App Gallery Listing

General

The app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.

Configure Custom Headers

General

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

Connect Install Roadmap

General

The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.

Validate Oidc Multitenant App Gallery

General

The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.

Validate Oidc Multitenant App Gallery

General

The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.

Agent Access Packages

General

The documentation now provides step-by-step My Access portal instructions for authorized users to request an access package for another user, including the US Government portal URL.

Group Source Of Authority Configure

General

The documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.

How to configure custom HTTP headers in Global Secure Access

General

New documentation describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. The capability is currently in preview and supports tenant restrictions and other header-aware services.

Publish App Gallery

General

The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.

Version History

General

The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.

Group Source Of Authority Configure

General

The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.

How Managed Identities Work Vm

General

The curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.

How Managed Identities Work Vm

General

The VM managed identity documentation changes the client_id value in its curl token-request example.

Preserve a group's organizational unit (Preview)

General

A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.

Sap Netweaver Tutorial

General

Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.

Sap Netweaver Tutorial

General

The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.

Version History

General

The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.

Agent Token Claims

General

The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.

Assign App Owners

General

The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.

Create Service Principal Cross Tenant

General

The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.

Exchange Hybrid

General

The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.

Manage App Consent Policies

General

The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.

Current Known Limitations

General

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

Current Known Limitations

General

The documentation received a minor formatting change with no substantive content changes identified.

Current Known Limitations

General

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

Global Secure Access Client Release Notes

General

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

Microsoft Entra: Domain update for My Account and identity self-service experiences

Message CenterMC1462460 on mc.merill.net ↗Plan for change
General

Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.

Plan Sso Deployment

General

Removed an extra space from the Help desk admin row in the documentation table.

Publish your app to Microsoft Entra App Gallery

General

A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.

Whats New Linux

General

Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.

Connect Health Agent Install

General

The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.

Connect Health Version History

General

The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.

Global Secure Access Client for macOS Release Notes

General

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

Install the Global Secure Access Client for macOS

General

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

Macos Client Release History

General

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

Global Secure Access Client for macOS Release Notes

General

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

Install Macos Client

General

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

Install Macos Client

General

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

Install Macos Client

General

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

Install the Global Secure Access Client for macOS

General

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

Macos Client Release History

General

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

Optional Claims Reference

General

The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.

Licensing Service Plan Reference

General

The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.

Licensing Service Plan Reference

General

The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.

Licensing Service Plan Reference

General

The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.

Licensing Service Plan Reference

General

The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.

Licensing Service Plan Reference

General

The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.

Migrate web content filtering policies from V1 to V2

General

A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.

Allow Deny List

General

The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.

Create Delete Agent Identities

General

The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.

Howto Delete Agent Identity

General

The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.

Integrate Aws Bedrock Agent

General

The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.

Manage agents in end user experience

General

The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.

Manage rules for dynamic membership groups in Microsoft Entra ID

General

The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.

Federate a Google Cloud workload identity

General

Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.

Federate a SPIFFE/SPIRE workload identity

General

Adds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.

Manage Microsoft Profile

General

The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”

Manage Microsoft Profile

General

The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.

Custom Proxy File Hosting

General

The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.

Howto Target Agent Identities

General

The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.

Howto Target Agent Identities

General

The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.

Import ADSyncTools module

General

The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.

Import ADSyncTools module

General

The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.

Provide the user's identity.

General

The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.

Whats New

General

The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.

Network Content Filtering

General

The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.

How to manage the Internet Access profile

General

The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.

Global Secure Access egress IP ranges

General

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

Agent Owners Sponsors Managers

General

In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.

Configure Web Content Filtering

General

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

Configure Explicit Forward Proxy

General

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

Admin Control for SSO prompts

General

IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…