How to configure custom HTTP headers in Global Secure Access
The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to General.
The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.
The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.
The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.
The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.
The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.
Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.
The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.
The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.
The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.
The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.
The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.
The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.
The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.
As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.
The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.
The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.
Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.
Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.
The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.
My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.
The documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.
The documentation now clarifies that Azure CLI commands and IaC templates must use the provider namespace Microsoft.Storage, while Microsoft.Storage/* is only an Azure portal display convention.
The documentation now clarifies that Azure CLI commands and IaC templates must use Microsoft.Storage. The Microsoft.Storage/* format shown in the portal is only a display convention and is not accepted by the API.
The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.
The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.
The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.
The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.
The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.
The documentation now states that creating a managed identity is blocked when the resulting directory usage reaches or exceeds 98% of the tenant quota. This applies to new or recreated service principals; existing identities and assignments continue to work.
The documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.
The app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.
The app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.
Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.
The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
The page title now marks custom headers as preview and notes that rollout is expected to complete by September 10, 2026.
The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.
The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
The documentation now provides step-by-step My Access portal instructions for authorized users to request an access package for another user, including the US Government portal URL.
The documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.
New documentation describes adding custom HTTP headers to matching outbound web requests through Web Content Filtering v2 rules. The capability is currently in preview and supports tenant restrictions and other header-aware services.
The article describing the preview GroupDN setup for preserving a group’s organizational unit and name during Source of Authority conversion was deleted.
The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.
The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.
The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.
The curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.
The VM managed identity documentation changes the client_id value in its curl token-request example.
A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.
Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.
The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.
The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.
The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.
The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.
The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.
The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.
The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.
The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.
The documentation received a minor formatting change with no substantive content changes identified.
The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.
Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.
Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.
Removed an extra space from the Help desk admin row in the documentation table.
The page title now says “Microsoft Entra ID,” and several table separators were reformatted for consistent Markdown presentation.
A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.
The documentation now explains that Agent ID objects are covered through their underlying directory object types, including user accounts as user objects and identity blueprints as application objects.
Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.
The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.
The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.
The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.
The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.
The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.
The release-history page no longer includes version 1.1.26060207 or its listed changes, and its document date changed from August 21, 2026, to April 16, 2026.
The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.
The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.
The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.
The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.
The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.
Starting with version 1.1.26060207, the app package includes com.microsoft.autoupdate2 for future use cases.
The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.
The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.
The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.
The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.
The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.
The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.
The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.
A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.
The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.
The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.
The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.
The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.
The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.
The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.
Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.
Adds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.
The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”
The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.
We are announcing the ability to enable on-behalf-of ordering for Microsoft Entra External ID (EEID) in Dynamics 365 Commerce. This feature will reach general availability on September 11, 2026 How does this affect me?
The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.
The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.
The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.
The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.
The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.
The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.
The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.
The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.
The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.
Learn how to configure Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps side by side without proxying traffic twice.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.
In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.
Learn how to upload and host your own Proxy Auto-Configuration (PAC) files
Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.