📋 Microsoft Entra Documentation Changes

Daily summary for changes since May 25th 2026, 11:36 PM PDT

Report generated on May 26th 2026, 11:36 PM PDT

📊 Summary

42
Total Commits
4
New Files
14
Modified Files
0
Deleted Files
12
Contributors

🆕 New Documentation Files

+13 lines added
Commit: Add national cloud deployments include files for SaaS app tutorials
+13 lines added
Commit: Add national cloud deployments include files for SaaS app tutorials
+13 lines added
Commit: Add national cloud deployments include files for SaaS app tutorials
+13 lines added
Commit: Add national cloud deployments include files for SaaS app tutorials

📝 Modified Documentation Files

+18 / -15 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
---
title: Install the Microsoft Entra Connect Health agents in Microsoft Entra ID
description: Learn how to install the Microsoft Entra Connect Health agents for Active Directory Federation Services (AD FS) and for sync.
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.date: 05/15/2026
ms.topic: how-to
ms.custom: sfi-ga-nochange
---
# Install the Microsoft Entra Connect Health agents
 
> [!NOTE]
> Microsoft Entra Connect Health is not available in the China sovereign cloud.
 
## Requirements
 
The following table lists requirements for using Microsoft Entra Connect Health:
 
| You have a Microsoft Entra ID P1 or P2 subscription. |Microsoft Entra Connect Health is a feature of Microsoft Entra ID P1 or P2. For more information, see [Sign up for Microsoft Entra ID P1 or P2](~/fundamentals/get-started-premium.md). <br /><br />To start a free 30-day trial, see [Start a trial](https://azure.microsoft.com/trial/get-started-active-directory/). |
| You're either a [Global Administrator](../../role-based-access-control/permissions-reference.md#global-administrator) or a [Hybrid Identity Administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) in Microsoft Entra ID. | By using Azure role-based access control (Azure RBAC), you can allow other users in your organization to access Microsoft Entra Connect Health. For more information, see [Azure RBAC for Microsoft Entra Connect Health](how-to-connect-health-operations.md#manage-access-with-azure-rbac). <br /><br />**Important**: Use a work or school account to install the agents. You can't use a Microsoft account to install the agents. For more information, see [Sign up for Azure as an organization](~/fundamentals/sign-up-organization.md). |
---
title: Install the Microsoft Entra Connect Health agents in Microsoft Entra ID
description: Learn how to install the Microsoft Entra Connect Health agents for Active Directory Federation Services (AD FS) and for sync.
author: omondiatieno
ms.author: jomondi
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.date: 05/15/2026
ms.topic: how-to
ms.custom: sfi-ga-nochange, msecd-doc-authoring-1012
#customer intent: As an identity administrator, I want to install the Microsoft Entra Connect Health agents on my on-premises servers so that I can monitor the health of my hybrid identity infrastructure (AD FS, sync, and AD DS) from the Microsoft Entra admin center.
---
# Install the Microsoft Entra Connect Health agents
 
> [!NOTE]
> Microsoft Entra Connect Health is not available in the China sovereign cloud.
 
## Prerequisites
 
The following table lists requirements for using Microsoft Entra Connect Health:
Modified by omondiatieno on May 26, 2026 1:38 PM
📖 View on learn.microsoft.com
+10 / -7 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
---
title: Microsoft Entra Connect Health agents for AD FS
description: This is the Microsoft Entra Connect Health page how to monitor your on-premises AD FS infrastructure.
ms.reviewer: zhiweiwangmsft
ms.assetid: dc0e53d8-403e-462a-9543-164eaa7dd8b3
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: H1Hack27Feb2017, sfi-ga-nochange, sfi-image-nochange
---
 
# Microsoft Entra Connect Health agents for AD FS
> [!NOTE]
> Microsoft Entra Connect Health is not available in the China sovereign cloud.
 
## Requirements
 
The following table lists requirements for using Microsoft Entra Connect Health:
 
---
title: Microsoft Entra Connect Health agents for AD FS
description: This is the Microsoft Entra Connect Health page how to monitor your on-premises AD FS infrastructure.
author: omondiatieno
ms.author: jomondi
ms.reviewer: zhiweiwangmsft
ms.assetid: dc0e53d8-403e-462a-9543-164eaa7dd8b3
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: H1Hack27Feb2017, sfi-ga-nochange, sfi-image-nochange, msecd-doc-authoring-1012
#customer intent: As an identity administrator, I want to install the Microsoft Entra Connect Health agent on my AD FS and Web Application Proxy servers so that I can monitor my federation infrastructure from the Microsoft Entra admin center.
---
 
# Microsoft Entra Connect Health agents for AD FS
> [!NOTE]
> Microsoft Entra Connect Health is not available in the China sovereign cloud.
 
## Prerequisites
+10 / -7 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
---
title: AD FS sign-ins in Microsoft Entra ID with Connect Health
description: This document describes how to integrate AD FS sign-ins with the Microsoft Entra Connect Health sign-ins report.
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: sfi-ga-nochange, sfi-ropc-nochange
---
 
# AD FS sign-ins in Microsoft Entra ID with Connect Health - preview
The Connect Health for AD FS agent correlates multiple Event IDs from AD FS, dependent on the server version, to provide information about the request and error details if the request fails. This information is correlated to the Microsoft Entra sign-in report schema and displayed in the Microsoft Entra sign-in report UX. Alongside the report, a new Log Analytics stream is available with the AD FS data and a new Azure Monitor Workbook template. The template can be used and modified for an in-depth analysis for scenarios such as AD FS account lockouts, bad password attempts, and spikes of unexpected sign-in attempts.
 
## Prerequisites
* Microsoft Entra Connect Health for AD FS installed and upgraded to the latest version (4.5.2466.0 or later).
* Reports Reader role to view the Microsoft Entra sign-ins
 
## What data is displayed in the report?
The data available mirrors the same data available for Microsoft Entra sign-ins. Five tabs with information are available based on the type of sign-in, either Microsoft Entra ID or AD FS. Connect Health correlates events from AD FS, dependent on the server version, and matches them to the AD FS schema.
 
---
title: AD FS sign-ins in Microsoft Entra ID with Connect Health
description: This document describes how to integrate AD FS sign-ins with the Microsoft Entra Connect Health sign-ins report.
author: omondiatieno
ms.author: jomondi
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: sfi-ga-nochange, sfi-ropc-nochange, msecd-doc-authoring-1012
#customer intent: As an IT administrator, I want to integrate AD FS sign-ins into the Microsoft Entra sign-ins report so that I can review federated and cloud authentication events in a single report.
---
 
# AD FS sign-ins in Microsoft Entra ID with Connect Health - preview
The Connect Health for AD FS agent correlates multiple Event IDs from AD FS, dependent on the server version, to provide information about the request and error details if the request fails. This information is correlated to the Microsoft Entra sign-in report schema and displayed in the Microsoft Entra sign-in report UX. Alongside the report, a new Log Analytics stream is available with the AD FS data and a new Azure Monitor Workbook template. The template can be used and modified for an in-depth analysis for scenarios such as AD FS account lockouts, bad password attempts, and spikes of unexpected sign-in attempts.
 
## Prerequisites
* Microsoft Entra Connect Health for AD FS installed and upgraded to the latest version (4.5.2466.0 or higher).
* Reports Reader role to view the Microsoft Entra sign-ins report.
 
Modified by omondiatieno on May 26, 2026 1:38 PM
📖 View on learn.microsoft.com
+6 / -3 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
---
title: Using Microsoft Entra Connect Health with sync
description: This is the Microsoft Entra Connect Health page that discusses how to monitor Microsoft Entra Connect Sync.
ms.assetid: 1dfbeaba-bda2-4f68-ac89-1dbfaf5b4015
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: H1Hack27Feb2017, sfi-image-nochange
---
# Monitor Microsoft Entra Connect Sync with Microsoft Entra Connect Health
The following documentation is specific to monitoring Microsoft Entra Connect (Sync) with Microsoft Entra Connect Health. For information on monitoring AD FS with Microsoft Entra Connect Health see [Using Microsoft Entra Connect Health with AD FS](how-to-connect-health-adfs.md). Additionally, for information on monitoring Active Directory Domain Services with Microsoft Entra Connect Health see [Using Microsoft Entra Connect Health with AD DS](how-to-connect-health-adds.md).
## Object Level Synchronization Error Report
This feature provides a report about synchronization errors that can occur when identity data is synchronized between Windows Server AD and Microsoft Entra ID using Microsoft Entra Connect.
 
* The report covers errors recorded by the sync client (Microsoft Entra Connect version 2.5.79.0 or higher)
* It includes the errors that occurred in the last synchronization operation on the sync engine. ("Export" on the Microsoft Entra Connector.)
* Microsoft Entra Connect Health agent for sync must have outbound connectivity to the required end points for the report to include the latest data.
* The report is **updated after every 30 minutes** using the data uploaded by Microsoft Entra Connect Health agent for sync.
For specific duplicated attribute sync error scenario involving user Source Anchor update, you can fix them directly from the portal.
---
title: Using Microsoft Entra Connect Health with sync
description: This is the Microsoft Entra Connect Health page that discusses how to monitor Microsoft Entra Connect Sync.
author: omondiatieno
ms.author: jomondi
ms.assetid: 1dfbeaba-bda2-4f68-ac89-1dbfaf5b4015
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: H1Hack27Feb2017, sfi-image-nochange, msecd-doc-authoring-1012
#customer intent: As an identity administrator, I want to monitor my Microsoft Entra Connect Sync deployment with Microsoft Entra Connect Health so that I can identify and resolve synchronization alerts and errors.
---
# Monitor Microsoft Entra Connect Sync with Microsoft Entra Connect Health
The following documentation is specific to monitoring Microsoft Entra Connect (Sync) with Microsoft Entra Connect Health. For information on monitoring AD FS with Microsoft Entra Connect Health see [Using Microsoft Entra Connect Health with AD FS](how-to-connect-health-adfs.md). Additionally, for information on monitoring Active Directory Domain Services with Microsoft Entra Connect Health see [Using Microsoft Entra Connect Health with AD DS](how-to-connect-health-adds.md).
## Object Level Synchronization Error Report
This feature provides a report about synchronization errors that can occur when identity data is synchronized between Windows Server AD and Microsoft Entra ID using Microsoft Entra Connect.
 
* The report covers errors recorded by the sync client (Microsoft Entra Connect version [2.5.79.0 or higher](reference-connect-version-history.md))
* It includes the errors that occurred in the last synchronization operation on the sync engine. ("Export" on the Microsoft Entra Connector.)
+6 / -3 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
---
title: Microsoft Entra Connect Health with AD FS risky IP report workbook
description: Describes the Microsoft Entra Connect Health AD FS risky IP report with Azure Monitor Workbooks.
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: sfi-image-nochange
ms.collection:
---
 
 
- Customizable queries and expanded visualizations for further analysis
- Expanded functionality from the previous Risky IP report, which was deprecated after January 24, 2022.
 
## Requirements
1. Connect Health for AD FS installed and updated to the latest agent.
2. A Log Analytics Workspace with the "ADFSSignInLogs" stream enabled.
3. Permissions to use the Microsoft Entra ID Monitor Workbooks. To use Workbooks, you need:
- Ensure no "Health service isn't up to date" alert active in your AD FS server list. Read more about [how to troubleshoot this alert](how-to-connect-health-data-freshness.md)
---
title: Microsoft Entra Connect Health with AD FS risky IP report workbook
description: Describes the Microsoft Entra Connect Health AD FS risky IP report with Azure Monitor Workbooks.
author: omondiatieno
ms.author: jomondi
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/15/2026
ms.custom: sfi-image-nochange, msecd-doc-authoring-1012
ms.collection:
#customer intent: As an identity administrator, I want to use the Risky IP report workbook in Microsoft Entra Connect Health so that I can detect and respond to password spray or brute-force attacks against my AD FS endpoints.
---
 
 
- Customizable queries and expanded visualizations for further analysis
- Expanded functionality from the previous Risky IP report, which was deprecated after January 24, 2022.
 
## Prerequisites
1. Connect Health for AD FS installed and updated to the latest agent.
Modified by mbhargav9 on May 26, 2026 7:35 PM
📖 View on learn.microsoft.com
+4 / -0 lines changed
Commit: Enhance dynamic group rules section with cleanup note
Changes:
Before
After
 
Using dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).
 
## Rule builder in the Azure portal
 
Microsoft Entra ID provides a rule builder to create and update your important rules more quickly. The rule builder supports the construction of up to five expressions.
 
 
 
 
 
Using dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).
 
>[!NOTE]
> Dynamic group rules evaluate every user and device in your tenant, including objects that are inactive or no longer in use. Stale devices and stale users can inflate group membership and slow dynamic membership group processing. Before you create a rule, clean-up stale devices[stale devices](/entra/identity/devices/manage-stale-devices) and inactive users[inactive users](/entra/identity/monitoring-health/howto-manage-inactive-user-accounts) so your group reflects only the objects you intend to manage.
 
 
## Rule builder in the Azure portal
 
Microsoft Entra ID provides a rule builder to create and update your important rules more quickly. The rule builder supports the construction of up to five expressions.
+0 / -4 lines changed
Commit: Remove stale YouTube video from cloud sync topologies page
Changes:
Before
After
> [!IMPORTANT]
> Microsoft doesn't support modifying or operating Microsoft Entra Cloud Sync outside of the configurations or actions that are formally documented. Any of these configurations or actions might result in an inconsistent or unsupported state of Microsoft Entra Cloud Sync. As a result, Microsoft can't provide technical support for such deployments.
 
For more information, see the following video.
 
> [!VIDEO https://learn-video.azurefd.net/vod/player?id=2b0047aa-84ba-430d-8ce9-39cfdc55276d]
 
## Things to remember about all scenarios and topologies
The following information should be kept in mind, when selecting a solution.
 
> [!IMPORTANT]
> Microsoft doesn't support modifying or operating Microsoft Entra Cloud Sync outside of the configurations or actions that are formally documented. Any of these configurations or actions might result in an inconsistent or unsupported state of Microsoft Entra Cloud Sync. As a result, Microsoft can't provide technical support for such deployments.
 
## Things to remember about all scenarios and topologies
The following information should be kept in mind, when selecting a solution.
 
 
 
 
 
Modified by omondiatieno on May 26, 2026 2:12 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Add Windows Server 2025 support to agent-install, AD DS, and Sync pages
Changes:
Before
After
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 04/09/2025
ms.custom: sfi-image-nochange
---
# Using Microsoft Entra Connect Health with AD DS
The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are: Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016.
 
For more information on monitoring AD FS with Microsoft Entra Connect Health, see [Using Microsoft Entra Connect Health with AD FS](how-to-connect-health-adfs.md). Additionally, for information on monitoring Microsoft Entra Connect (Sync) with Microsoft Entra Connect Health see [Using Microsoft Entra Connect Health for Sync](how-to-connect-health-sync.md).
 
ms.subservice: hybrid-connect
ms.tgt_pltfrm: na
ms.topic: how-to
ms.date: 05/26/2026
ms.custom: sfi-image-nochange
---
# Using Microsoft Entra Connect Health with AD DS
The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.
 
For more information on monitoring AD FS with Microsoft Entra Connect Health, see [Using Microsoft Entra Connect Health with AD FS](how-to-connect-health-adfs.md). Additionally, for information on monitoring Microsoft Entra Connect (Sync) with Microsoft Entra Connect Health see [Using Microsoft Entra Connect Health for Sync](how-to-connect-health-sync.md).
 
Modified by Faith Moraa Ombongi on May 26, 2026 1:51 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Remove EM action from user admin
Changes:
Before
After
title: User Administrator
description: User Administrator
ms.topic: include
ms.date: 05/21/2026
ms.custom: include file
---
 
> | microsoft.directory/contacts/delete | Delete contacts |
> | microsoft.directory/deletedItems.groups/restore | Restore soft deleted groups to original state |
> | microsoft.directory/deletedItems.users/restore | Restore soft deleted users to original state |
> | microsoft.directory/entitlementManagement/allProperties/allTasks | Create and delete resources, and read and update all properties in Microsoft Entra entitlement management<br/>[![Privileged label icon.](../media/permissions-reference/privileged-label.png)](../privileged-roles-permissions.md) |
> | microsoft.directory/groups.unified/assignedLabels/update | Update the assigned labels property on Microsoft 365 groups of assigned membership type, excluding role-assignable groups |
> | microsoft.directory/groups/assignLicense | Assign product licenses to groups for group-based licensing |
> | microsoft.directory/groups/basic/update | Update basic properties on Security groups and Microsoft 365 groups, excluding role-assignable groups |
title: User Administrator
description: User Administrator
ms.topic: include
ms.date: 01/26/2026
ms.custom: include file
---
 
> | microsoft.directory/contacts/delete | Delete contacts |
> | microsoft.directory/deletedItems.groups/restore | Restore soft deleted groups to original state |
> | microsoft.directory/deletedItems.users/restore | Restore soft deleted users to original state |
> | microsoft.directory/entitlementManagement/allProperties/allTasks | Create and delete resources, and read and update all properties in Microsoft Entra entitlement management |
> | microsoft.directory/groups.unified/assignedLabels/update | Update the assigned labels property on Microsoft 365 groups of assigned membership type, excluding role-assignable groups |
> | microsoft.directory/groups/assignLicense | Assign product licenses to groups for group-based licensing |
> | microsoft.directory/groups/basic/update | Update basic properties on Security groups and Microsoft 365 groups, excluding role-assignable groups |
+1 / -1 lines changed
Commit: edit
Changes:
Before
After
 
## Inheritable permissions limitations
 
- Maximum of 50 resource apps per agent identity blueprint (for example, up to 60 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.
 
Regularly review and monitor your inheritable permissions configuration. Reevaluate inherited scopes and roles to ensure they remain appropriate for your use case. Audit which inherited scopes and roles are being used by agents and remove any unused permissions from both the agent identity blueprint principal and the inheritable permissions list to maintain security hygiene.
 
 
## Inheritable permissions limitations
 
- Maximum of 50 resource apps per agent identity blueprint (for example, up to 50 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.
 
Regularly review and monitor your inheritable permissions configuration. Reevaluate inherited scopes and roles to ensure they remain appropriate for your use case. Audit which inherited scopes and roles are being used by agents and remove any unused permissions from both the agent identity blueprint principal and the inheritable permissions list to maintain security hygiene.
 
Modified by egreenberg14 on May 26, 2026 5:31 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/identity/hybrid/connect/how-to-connect-pta.md
Changes:
Before
After
- Installing multiple agents provides high availability of sign-in requests.
- It [protects](~/identity/authentication/howto-password-smart-lockout.md) your on-premises accounts against brute force password attacks in the cloud.
 
## Privacy Considerations
 
When a pass-through sign-in attempt from Tenant A (for example, Contoso) to Tenant B (for example, Fabrikam) fails, Microsoft Entra ID publishes the sign-in log to both tenants. For failed attempts, Microsoft Entra ID doesn't expose personally identifiable information (PII) to Tenant B, because the user in Tenant A never consented to share their identity with Tenant B. In these cases, attributes like the user principal name (UPN) are replaced with unresolved GUIDs.
 
- Installing multiple agents provides high availability of sign-in requests.
- It [protects](~/identity/authentication/howto-password-smart-lockout.md) your on-premises accounts against brute force password attacks in the cloud.
 
## Privacy considerations
 
When a pass-through sign-in attempt from Tenant A (for example, Contoso) to Tenant B (for example, Fabrikam) fails, Microsoft Entra ID publishes the sign-in log to both tenants. For failed attempts, Microsoft Entra ID doesn't expose personally identifiable information (PII) to Tenant B, because the user in Tenant A never consented to share their identity with Tenant B. In these cases, attributes like the user principal name (UPN) are replaced with unresolved GUIDs.
 
+1 / -1 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.
![Verify Microsoft Entra Connect Health](./media/how-to-connect-health-agent-install/install5.png)
 
* Make sure to go over and meet the [requirements section](how-to-connect-health-agent-install.md#requirements).
* Use [test connectivity tool](how-to-connect-health-agent-install.md#test-connectivity-to-azure-ad-connect-health-service) to discover connectivity issues.
* If you have an HTTP Proxy, follow these [configuration steps](how-to-connect-health-agent-install.md#configure-azure-ad-connect-health-agents-to-use-http-proxy).
 
* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.
![Verify Microsoft Entra Connect Health](./media/how-to-connect-health-agent-install/install5.png)
 
* Make sure to go over and meet the [prerequisites](how-to-connect-health-agent-install.md#prerequisites).
* Use [test connectivity tool](how-to-connect-health-agent-install.md#test-connectivity-to-azure-ad-connect-health-service) to discover connectivity issues.
* If you have an HTTP Proxy, follow these [configuration steps](how-to-connect-health-agent-install.md#configure-azure-ad-connect-health-agents-to-use-http-proxy).
 
+1 / -1 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
<a name='download-and-install-azure-ad-connect-health-agent'></a>
 
## Download and install Microsoft Entra Connect Health Agent
* Make sure that you [satisfy the requirements](how-to-connect-health-agent-install.md#requirements) for Microsoft Entra Connect Health.
* Get started using Microsoft Entra Connect Health for AD FS
* [Download Microsoft Entra Connect Health Agent for AD FS.](https://www.microsoft.com/en-us/download/details.aspx?id=108565)
* [See the installation instructions](how-to-connect-health-agent-install.md#install-the-agent-for-ad-fs).
<a name='download-and-install-azure-ad-connect-health-agent'></a>
 
## Download and install Microsoft Entra Connect Health Agent
* Make sure that you [satisfy the prerequisites](how-to-connect-health-agent-install.md#prerequisites) for Microsoft Entra Connect Health.
* Get started using Microsoft Entra Connect Health for AD FS
* [Download Microsoft Entra Connect Health Agent for AD FS.](https://www.microsoft.com/en-us/download/details.aspx?id=108565)
* [See the installation instructions](how-to-connect-health-agent-install.md#install-the-agent-for-ad-fs).
Modified by omondiatieno on May 26, 2026 1:38 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Apply copy-edit conventions across Connect Health audit articles
Changes:
Before
After
<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>
 
### 7b - Endpoints for Microsoft Entra Connect Health agent for (AD FS/Sync) and Microsoft Entra ID
For a list of endpoints, see [the Requirements section for the Microsoft Entra Connect Health agent](how-to-connect-health-agent-install.md#requirements).
<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>
 
### 7b - Endpoints for Microsoft Entra Connect Health agent for (AD FS/Sync) and Microsoft Entra ID
For a list of endpoints, see [the Prerequisites section for the Microsoft Entra Connect Health agent](how-to-connect-health-agent-install.md#prerequisites).