Month in brief

July 2025 Entra briefing: secure defaults tighten access, Android browser access becomes automatic, and Workload ID retires service-principal-less authentication

July was overwhelmingly a documentation month: 1,047 of 1,060 records were updates, compared with seven new items and four Message Center notices. The meaningful exceptions were concrete behavior or security changes rather than broad launches. Microsoft 365 is changing Entra-related defaults to block legacy authentication and require admin consent for third-party app access; Entra ID is making browser access the Android default while retiring its old toggle; and Workload ID is closing remaining non-Microsoft multitenant service-principal-less authentication cases. The Conditional Access optimization agent received substantial cross-product operating and telemetry guidance, while Group Source of Authority is explicitly documented as Preview. No supplied entry identifies a general-availability launch. Large Conditional Access, Entra Connect, Cloud Sync, and hybrid-identity edits should therefore be read primarily as procedure and reference maintenance. Other Message Center items, including the September Authenticator backup change on iOS and a later sign-in-background refresh, require no administrator action.

  • Secure-by-default settings change legacy authentication and third-party app consentEntra ID — authentication and admin consent

    Change type: Message Center behavior and security rollout, not a general-availability feature launch. Microsoft 365 says the new defaults begin rolling out in mid-July 2025 and complete by August 2025: legacy authentication protocols will be blocked and third-party app access will require admin consent. The notice directs organizations to assess configurations, notify stakeholders, update documentation, and configure the Admin Consent workflow.

  • Android browser access becomes the default as the old toggle is retiredEntra ID — Android device registration, Microsoft Authenticator, and Company Portal

    Change type: behavior change and retirement. Microsoft Entra will enable browser access by default for all Android users and retire the “Enable Browser Access” feature in Microsoft Authenticator and Company Portal. The notice describes this as a hardware-bound device-registration change that will roll out automatically worldwide, with no administrator action required; organizations that do not use Android can ignore it.

  • Service-principal-less authentication is being retired for remaining non-Microsoft multitenant appsWorkload ID / Entra ID

    Change type: security behavior change and retirement in Workload ID guidance. Entra ID will block authentication when a non-Microsoft multitenant application has no service principal in the tenant where it authenticates. The documentation says service-principal-less authentication is already disabled for most non-Microsoft applications and that this change addresses the remaining exceptions. No cutover date or remediation procedure is supplied.

  • Conditional Access optimization-agent guidance expands across Security Copilot, Agent ID, and Entra IDMicrosoft Security Copilot / Agent ID / Entra ID — Conditional Access optimization agent

    Change type: coordinated documentation and security guidance, not evidence of a preview, GA release, or product launch. New and updated pages describe an agent that analyzes sign-in patterns, identifies unprotected users and applications, recommends policy improvements such as MFA coverage, and exposes metrics and audit events. Administrators must review and approve suggestions; the guidance states that no changes are made without approval. The supplied weekly material also documents a 30-day summary, security-com-

  • Group Source of Authority documentation fills out the Preview conversion pathEntra ID — Group Source of Authority (Preview)

    Change type: preview guidance, not a GA announcement. Late-July Entra ID updates cover moving group management from AD DS to the cloud, prerequisites and cleanup, configuration, validation, auditing, preserved organizational units, post-conversion self-service management, and rollback. The feed does not establish a required migration or a new runtime behavior; it gives evaluators an end-to-end operating path.

For Entra administrators

Prioritize the secure-default rollout by assessing configurations for legacy-authentication dependencies and third-party app access, notifying stakeholders, updating internal documentation, and configuring the Admin Consent workflow as recommended in the notice. No Entra configuration change is required for the Android browser-access change or the iOS Authenticator backup update; organizations not using Android can ignore the former. For Workload ID, identify non-Microsoft multitenant applications authenticating without a service principal in the authenticating tenant. The supplied evidence provides no deadline or remediation procedure, so treat this as an exposure check rather than a mandated migration. If using the Conditional Access optimization agent, verify the documented Entra ID P1,

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

1060 updates by product

General

312

Apple Sso Plugin

Updated

( ** ) You only need to allow sovereign cloud domains if you rely on those in your environment.

31 July 2025

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

26 July 2025

Global Administrator

Updated

> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices<br/>[![Privileged label icon.](../media/permissions-reference/privileged-label.png)](../privileged-roles-permissions.md) |

26 July 2025

Controls

Updated

author: MicrosoftGuyJFlo

25 July 2025

Licensing Service Plan Reference

Updated

- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID

24 July 2025

Connect Fed Sha256 Guidance

Updated

This page provides guidelines for changing SHA algorithm for federation trust with Microsoft 365.

18 July 2025

Connect Sync Recycle Bin

Updated

This topic recommends the use of AD Recycle Bin feature with Microsoft Entra Connect.

18 July 2025

Microsoft Entra seamless single sign-on

Updated

This topic describes Microsoft Entra seamless single sign-on and how it allows you to provide true single sign-on for corporate desktop users inside your corporate network.

18 July 2025

Licensing Service Plan Reference

Updated

- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID

15 July 2025

Licensing Service Plan Reference

Updated

- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID

13 July 2025

category:

Updated

manager: pmwongera

12 July 2025

Connect Microsoft Graph

Updated

After enabling this feature, existing userPrincipalName values remain as-is. On next change of the userPrincipalName attribute on-premises, the normal delta sync on users updates the UPN. Once this feature is enabled, it's not possible to disable it.

11 July 2025

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

11 July 2025

Attack Payload Author

Updated

A Microsoft Entra documentation page was updated: Attack Payload Author.

11 July 2025

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

11 July 2025

Directory Writers

Updated

A Microsoft Entra documentation page was updated: Directory Writers.

11 July 2025

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

11 July 2025

Exchange Administrator

Updated

A Microsoft Entra documentation page was updated: Exchange Administrator.

11 July 2025

Fabric Administrator

Updated

A Microsoft Entra documentation page was updated: Fabric Administrator.

11 July 2025

Global Administrator

Updated

A Microsoft Entra documentation page was updated: Global Administrator.

11 July 2025

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

11 July 2025

Groups Administrator

Updated

A Microsoft Entra documentation page was updated: Groups Administrator.

11 July 2025

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

11 July 2025

Helpdesk Administrator

Updated

A Microsoft Entra documentation page was updated: Helpdesk Administrator.

11 July 2025

Insights Administrator

Updated

A Microsoft Entra documentation page was updated: Insights Administrator.

11 July 2025

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

11 July 2025

Intune Administrator

Updated

A Microsoft Entra documentation page was updated: Intune Administrator.

11 July 2025

Kaizala Administrator

Updated

A Microsoft Entra documentation page was updated: Kaizala Administrator.

11 July 2025

Knowledge Administrator

Updated

A Microsoft Entra documentation page was updated: Knowledge Administrator.

11 July 2025

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

11 July 2025

License Administrator

Updated

A Microsoft Entra documentation page was updated: License Administrator.

11 July 2025

Message Center Reader

Updated

A Microsoft Entra documentation page was updated: Message Center Reader.

11 July 2025

Partner Tier1 Support

Updated

A Microsoft Entra documentation page was updated: Partner Tier1 Support.

11 July 2025

Partner Tier2 Support

Updated

A Microsoft Entra documentation page was updated: Partner Tier2 Support.

11 July 2025

People Administrator

Updated

A Microsoft Entra documentation page was updated: People Administrator.

11 July 2025

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

11 July 2025

Printer Administrator

Updated

A Microsoft Entra documentation page was updated: Printer Administrator.

11 July 2025

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

11 July 2025

Search Administrator

Updated

A Microsoft Entra documentation page was updated: Search Administrator.

11 July 2025

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

11 July 2025

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

11 July 2025

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

11 July 2025

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

11 July 2025

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

11 July 2025

Yammer Administrator

Updated

A Microsoft Entra documentation page was updated: Yammer Administrator.

11 July 2025

Connect Version History

Updated

> New Microsoft Entra Connect Sync Versions are only available via the Microsoft Entra admin center

11 July 2025

Assign Local Admin

Updated

You can manage the [Microsoft Entra Joined Device Local Administrator](~/identity/role-based-access-control/permissions-reference.md#microsoft-entra-joined-device-local-administrator) role from **Device settings**.

10 July 2025

Best Practices

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).

10 July 2025

Groups Dynamic Rule Member Of

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

10 July 2025

Sharefile Tutorial

Updated

To configure the integration of Citrix ShareFile into Microsoft Entra ID, you need to add Citrix ShareFile from the gallery to your list of managed SaaS apps.

10 July 2025

Microsoft Entra federation metadata

Updated

This article describes the federation metadata document that Microsoft Entra ID publishes for services that accept Microsoft Entra tokens.

9 July 2025

Tutorial - Clean up resources

Updated

In this tutorial, you learn how to clean up the Azure resources allocated while creating the web app.

9 July 2025

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

3 July 2025

Attack Payload Author

Updated

A Microsoft Entra documentation page was updated: Attack Payload Author.

3 July 2025

Billing Administrator

Updated

A Microsoft Entra documentation page was updated: Billing Administrator.

3 July 2025

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

3 July 2025

Directory Writers

Updated

A Microsoft Entra documentation page was updated: Directory Writers.

3 July 2025

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

3 July 2025

Exchange Administrator

Updated

A Microsoft Entra documentation page was updated: Exchange Administrator.

3 July 2025

Fabric Administrator

Updated

A Microsoft Entra documentation page was updated: Fabric Administrator.

3 July 2025

Global Administrator

Updated

A Microsoft Entra documentation page was updated: Global Administrator.

3 July 2025

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

3 July 2025

Groups Administrator

Updated

A Microsoft Entra documentation page was updated: Groups Administrator.

3 July 2025

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

3 July 2025

Helpdesk Administrator

Updated

A Microsoft Entra documentation page was updated: Helpdesk Administrator.

3 July 2025

Insights Administrator

Updated

A Microsoft Entra documentation page was updated: Insights Administrator.

3 July 2025

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

3 July 2025

Intune Administrator

Updated

A Microsoft Entra documentation page was updated: Intune Administrator.

3 July 2025

Kaizala Administrator

Updated

A Microsoft Entra documentation page was updated: Kaizala Administrator.

3 July 2025

Knowledge Administrator

Updated

A Microsoft Entra documentation page was updated: Knowledge Administrator.

3 July 2025

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

3 July 2025

License Administrator

Updated

A Microsoft Entra documentation page was updated: License Administrator.

3 July 2025

Message Center Reader

Updated

A Microsoft Entra documentation page was updated: Message Center Reader.

3 July 2025

Network Administrator

Updated

A Microsoft Entra documentation page was updated: Network Administrator.

3 July 2025

Partner Tier1 Support

Updated

A Microsoft Entra documentation page was updated: Partner Tier1 Support.

3 July 2025

Partner Tier2 Support

Updated

A Microsoft Entra documentation page was updated: Partner Tier2 Support.

3 July 2025

People Administrator

Updated

A Microsoft Entra documentation page was updated: People Administrator.

3 July 2025

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

3 July 2025

Printer Administrator

Updated

A Microsoft Entra documentation page was updated: Printer Administrator.

3 July 2025

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

3 July 2025

Search Administrator

Updated

A Microsoft Entra documentation page was updated: Search Administrator.

3 July 2025

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

3 July 2025

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

3 July 2025

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

3 July 2025

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

3 July 2025

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

3 July 2025

Yammer Administrator

Updated

A Microsoft Entra documentation page was updated: Yammer Administrator.

3 July 2025

Tutorial Create Forest Trust

Updated

Before you configure a forest trust in Domain Services, make sure your networking between Azure and on-premises environment meets the following requirements:

2 July 2025

Manage Dns

Updated

Refrain from redirecting DNS zones related to windowsazure.com or core.windows.net. If DNS redirection is required, limit the redirection to individual host names instead of zones. For example, use server1.file.core.windows.net instead of file.core.windows.net.

2 July 2025

Provisioning

227

Inbound Provisioning Api Faqs

Updated

Learn more about the capabilities and integration scenarios supported by API-driven inbound provisioning.

23 July 2025

Provision a User with Expression Builder

Updated

Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.

23 July 2025

Factors influencing the performance of Microsoft Entra Connect

Updated

This document explains how various factors influence the Microsoft Entra Connect provisioning engine. These factors help organizations to plan their Microsoft Entra Connect deployment to make sure it meets their sync requirements.

18 July 2025

Tools used for synchronization

Updated

This article introduces the various tools that can be used to synchronize the cloud with on-premises environments.

18 July 2025

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Corn…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cornerstone OnDemand so that I can streamline the user management process and ensure that users have the appropriate access to Cornerstone OnDemand..

18 July 2025

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Sale…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Salesforce Sandbox so that I can streamline the user management process and ensure that users have the appropriate access to Salesforce Sandbox..

18 July 2025

21869

Updated

When enterprise applications lack both explicit assignment requirements AND scoped provisioning controls, threat actors can exploit this dual weakness to gain unauthorized access to sensitive applications and data. The highest risk occurs when applications are configured with the default setting: "Assignment required" is set to "No" *and* provisioning isn't required or scoped. This dangerous combination allows threat actors who compromise any user account within the tenant to immediately access applications with broad user bases, expanding their attack surface and potential for lateral movement within the organization.

15 July 2025

Fundamentals

82

Inbound Provisioning Api Concepts

Updated

- Tenant admins must grant API clients interacting with this provisioning app the Graph permissions `SynchronizationData-User.Upload`, `SynchronizationData-User.Upload.OwnedBy` (for ISVs), and `ProvisioningLog.Read.All`.

25 July 2025

Users Default Permissions

Updated

| **Allow users to connect work or school account with LinkedIn** | Setting this option to **No** prevents users from connecting their work or school account with their LinkedIn account. For more information, see [LinkedIn account connections data sharing and consent](~/identity/users/linkedin-user-consent.md). |

25 July 2025

Token Protection

Updated

The following devices and applications support accessing resources on which a token protection Conditional Access policy is applied:

24 July 2025

Secure Your Workforce with Microsoft Entra ID

Updated

Learn how to protect organizational identities with Microsoft Entra ID. Discover security recommendations, multifactor authentication setup, and Zero Trust implementation strategies.

22 July 2025

Conditional Access Grant

Updated

Organizations that deploy Intune can use the information returned from their devices to identify devices that meet specific policy compliance requirements. Intune sends compliance information to Microsoft Entra ID so Conditional Access can decide to grant or block access to resources. For more information about compliance policies, see [Set rules on devices to allow access to resources in your organization by using Intune](/mem/intune/protect/device-compliance-get-started).

22 July 2025

Mobile Sso Support Overview

Updated

In addition, enabling single sign-on in your app unlocks new authentication mechanisms that come with modern authentication, like [passwordless logins](~/identity/authentication/concept-authentication-passwordless.md). Usernames and passwords are one of the most popular attack vectors against applications, and enabling SSO allows you to mitigate this risk by enforcing Conditional Access or passwordless logins that add extra security or rely on more secure authentication mechanisms. Finally, enabling single sign-on also enables [single sign-out](v2-protocols-oidc.md#single-sign-out). This is useful in situations like work applications that will be used on shared devices.

17 July 2025

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

16 July 2025

Enable Passkey Fido2

Updated

- Metadata for FIDO2 security keys needs to be published and verified with the FIDO Alliance Metadata Service, and also pass another set of validation testing by Microsoft. For more information, see [Become a Microsoft-compatible FIDO2 security key vendor](/entra/identity/authentication/concept-fido2-hardware-vendor).

15 July 2025

Howto Use Recommendations

Updated

Most recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.

10 July 2025

Authentication Flows

Updated

To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.

4 July 2025

Mandatory Multifactor Authentication

Updated

Changes are required if you use the [Microsoft.Identity.Client](https://www.nuget.org/packages/Microsoft.Identity.Client) package and one of the following APIs in your application. The public client API is **deprecated** [as of the 4.73.1 release](https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/main/CHANGELOG.md):

3 July 2025

Overview

Updated

author: MicrosoftGuyJFlo

3 July 2025

Audit Logs

Updated

A Microsoft Entra documentation page was updated: Audit Logs.

2 July 2025

Sign Ins

Updated

A Microsoft Entra documentation page was updated: Sign Ins.

2 July 2025

Sign Ups

Updated

A Microsoft Entra documentation page was updated: Sign Ups.

2 July 2025

Howto Use Recommendations

Updated

Most recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.

1 July 2025

Concepts Forest Trust

Updated

A Microsoft Entra documentation page was updated: Concepts Forest Trust.

1 July 2025

Whats New

Updated

- US Gov -> Commercial

1 July 2025

Security

71

Policy All Users Copilot Ai Security

Updated

- [Manage Microsoft 365 for iOS and Android with Microsoft Intune](/intune/intune-service/apps/manage-microsoft-office#copilot-with-enterprise-data-protection)

17 July 2025

Network Considerations

Updated

Get-AzNetworkSecurityGroup -Name "nsg-name" -ResourceGroupName "resource-group-name" | Add-AzNetworkSecurityRuleConfig -Name "new-rule-name" -Access "Allow" -Protocol "TCP" -Direction "Inbound" -Priority "priority-number" -SourceAddressPrefix "CorpNetSaw" -SourcePortRange "*" -DestinationPortRange "3389" -DestinationAddressPrefix "*" | Set-AzNetworkSecurityGroup

15 July 2025

Security Administrator

Updated

A Microsoft Entra documentation page was updated: Security Administrator.

11 July 2025

Security Operator

Updated

A Microsoft Entra documentation page was updated: Security Operator.

11 July 2025

Security Reader

Updated

A Microsoft Entra documentation page was updated: Security Reader.

11 July 2025

Security Administrator

Updated

A Microsoft Entra documentation page was updated: Security Administrator.

3 July 2025

Security Operator

Updated

A Microsoft Entra documentation page was updated: Security Operator.

3 July 2025

Security Reader

Updated

A Microsoft Entra documentation page was updated: Security Reader.

3 July 2025

Authentication

63

Microsoft Entra: Browser access will be enabled by default for all Android users

New

Microsoft Entra will enable browser access by default for all Android users, retiring the "Enable Browser Access" feature in Microsoft Authenticator and Company Portal apps. This hardware-bound device registration change requires no admin action and will roll out automatically worldwide. Organizations not using Android can ignore this update.

24 July 2025
Message CenterMC1024404 on mc.merill.net ↗Major updatePlan for change

Add Application Portal Setup Oidc Sso

Updated

After entering the sign-in credentials, the consent screen appears. The consent screen provides information about the application and the permissions it requires.

23 July 2025

Microsoft 365 Upcoming Secure by Default Settings Changes

New

Microsoft 365 will update default settings to enhance security by blocking legacy authentication protocols and requiring admin consent for third-party app access. Changes start mid-July 2025 and complete by August 2025. Organizations should assess configurations, notify stakeholders, update documentation, and configure the Admin Consent workflow.

19 July 2025
Message CenterMC1097272 on mc.merill.net ↗Major updatePlan for change

Connect Password Hash Synchronization

Updated

The Cloud Password Policy for Password-Synced Users feature ensures that Microsoft Entra ID enforces its native password policies (such as expiration and lockout), for users whose passwords are synchronized from on-premises Active Directory. This feature enables you to align the same on-premises Active Directory password policy with the Microsoft Entra password policy, for synchronized users.

19 July 2025

Authentication for Microsoft Entra hybrid identity solutions

Updated

This guide helps CEOs, CIOs, CISOs, Chief Identity Architects, Enterprise Architects, and Security and IT decision makers responsible for choosing an authentication method for their Microsoft Entra hybrid identity solution in medium to large organizations.

18 July 2025

Connect Pta

Updated

This article describes Microsoft Entra pass-through authentication and how it allows Microsoft Entra sign-ins by validating users' passwords against on-premises Active Directory.

18 July 2025

Connect Pta User Privacy

Updated

This article deals with Microsoft Entra pass-through authentication and GDPR compliance.

18 July 2025

Connect Sync Change Addsacct Pass

Updated

This topic document describes how to update Microsoft Entra Connect after the password of the AD DS account is changed.

18 July 2025

Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Agile Provisioning so that I…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Agile Provisioning so that I can control who has access to Agile Provisioning, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location..

18 July 2025

Authorization Basics

Updated

Authorization logic is often implemented within the applications or solutions where access control is required. In many cases, application development platforms offer middleware or other API solutions that simplify the implementation of authorization. Examples include use of the [AuthorizeAttribute](/aspnet/core/security/authorization/simple?view=aspnetcore-5.0&preserve-view=true) in ASP.NET or [Route Guards](./scenario-spa-sign-in.md?tabs=angular2#sign-in-with-a-pop-up-window) in Angular.

17 July 2025

Connect Sso

Updated

- It's supported on web browser-based clients and Office clients that support [modern authentication](/microsoft-365/enterprise/modern-auth-for-office-2013-and-2016) on platforms and browsers capable of Kerberos authentication:

12 July 2025

Password Administrator

Updated

A Microsoft Entra documentation page was updated: Password Administrator.

11 July 2025

Policy Block Authentication Flows

Updated

For organizations that have no established use of device code flow, blocking can be done with the following Conditional Access policy:

10 July 2025

Test Automate Integration Testing

Updated

If you don't plan on testing your app in the same tenant you registered it in, or you aren't an administrator in your tenant, you can't consent to the permissions from the [Microsoft Entra admin center](https://entra.microsoft.com). You can still consent to some permissions, however, by triggering a sign-in prompt in a web browser.

10 July 2025

Howto Mfa Userstates

Updated

The per-user MFA administration experience in the Microsoft Entra admin center is recently improved. To view and manage user states, complete the following steps:

10 July 2025

Tutorial Enable Sspr

Updated

In this tutorial, set up SSPR for a set of users in a test group. Use the *SSPR-Test-Group* and provide your own Microsoft Entra group as needed:

10 July 2025

Howto Vm Sign In Azure Ad Windows

Updated

A User account in Microsoft Entra must be added to a role assignment in Azure before the user is allowed to sign in to Azure virtual machines or Arc-connected Windows Server. The same roles are used for both Azure virtual machines and Arc-enabled Windows Server.

5 July 2025

Howto Vm Sign In Azure Ad Windows

Updated

- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.

4 July 2025

Howto Mfa Mfasettings

Updated

Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.

4 July 2025

Password Administrator

Updated

A Microsoft Entra documentation page was updated: Password Administrator.

3 July 2025

Troubleshooting

49

21788

Updated

**Remediation action**

2 July 2025

21803

Updated

**Remediation action**

2 July 2025

21804

Updated

**Remediation action**

2 July 2025

21888

Updated

**Remediation action**

2 July 2025

Monitoring

44

Admin Audit Logging

Updated

|2507|Enable/Disable sync start after installation.| Event is logged when sync is enabled or disabled after the installation is finished.|

31 July 2025

Global Reader

Updated

> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |

24 July 2025

Security Administrator

Updated

> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |

24 July 2025

Agent Optimization Logs Metrics

Updated

- To view the Microsoft Entra audit logs, you need at least the [Reports reader](../../identity/role-based-access-control/permissions-reference.md#reports-reader) role.

11 July 2025

Attribute Log Reader

Updated

A Microsoft Entra documentation page was updated: Attribute Log Reader.

11 July 2025

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

11 July 2025

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

11 July 2025

Recommendation Renew Expiring Application Credential

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).

10 July 2025

Sla Performance

Updated

| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |

4 July 2025

Attribute Log Reader

Updated

A Microsoft Entra documentation page was updated: Attribute Log Reader.

3 July 2025

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

3 July 2025

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

3 July 2025

Developer

21

Manage Consent Requests

Updated

After disabling or restricting user consent, you have several important steps to take to help keep your organization secure as you continue to allow business-critical applications to be used. These steps are crucial to minimize impact on your organization's support team and IT administrators, and to help prevent the use of unmanaged accounts in non-Microsoft applications.

11 July 2025

Delete Application Portal

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

10 July 2025

Getty Images Tutorial

Updated

1. If you wish to configure the application in **SP** initiated mode, then perform the following step:

4 July 2025

Standards

21

Domain Services Tls Enforcement

Updated

Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.

15 July 2025

Domain Services Tls Enforcement

Updated

Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.

12 July 2025

Add Application Portal Setup Sso

Updated

Microsoft Entra ID has a gallery that contains thousands of preintegrated applications that use SSO. This article uses an enterprise application named **Microsoft Entra SAML Toolkit 1** as an example, but the concepts apply for most preconfigured enterprise applications in the Microsoft Entra application gallery.

11 July 2025

Configurable Token Lifetimes

Updated

Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.

4 July 2025

Msal Authentication Flows

Updated

The [OAuth 2.0 resource owner password credentials](v2-oauth-ropc.md) (ROPC) grant allows an application to sign in the user by directly handling their password. In your desktop application, you can use the username/password flow to acquire a token silently. No UI is required when using the application.

3 July 2025

V2 Oauth2 Auth Code Flow

Updated

Redirect URIs for SPAs that use the auth code flow require special configuration.

3 July 2025

How to migrate to Transport Layer Security (TLS) 1.2 enforcement for Microsoft Entra Domain Services

Updated

Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions is not known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.

1 July 2025

Conditional Access

20

Agent Optimization

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

10 July 2025

Managed Policies

Updated

Administrators with at least the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role assigned find these policies in the [Microsoft Entra admin center](https://entra.microsoft.com) under **Entra ID** > **Conditional Access** > **Policies**.

10 July 2025

Scenario Health Conditional Access Block Policy

Updated

1. Sign into the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Reports Reader](../role-based-access-control/permissions-reference.md#reports-reader).

10 July 2025

Agent Optimization Logs Metrics

Updated

The **Agent summary** at the top of the Conditional Access optimization agent page provides a quick summary of what the agent has discovered in the last 30 days. The total number of [security compute units (SCU)](/copilot/security/manage-usage) consumed by the agent is also provided.

9 July 2025

Agent Optimization

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

5 July 2025

Agent Optimization

Updated

The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.

4 July 2025

Microsoft identity platform

20

Ios Qr Code Pin Authentication

Updated

It's advised to call the `getDeviceInformationWithParameters` API in MSAL to find out if the admin has configured QR code authentication method. If it has, an app can update its UI to indicate that QR code authentication method is available as a sign-in option.

25 July 2025

Msal Authentication Flows

Updated

| [Implicit grant](#implicit-grant) | User sign-in and access to web APIs on behalf of the user. *Do not use this flow - use authorization code with PKCE instead.* | * [Single-page app (SPA)](scenario-spa-app-registration.md) <br /> * [Web](scenario-web-api-call-api-app-registration.md) |

17 July 2025

Application Developer

Updated

A Microsoft Entra documentation page was updated: Application Developer.

11 July 2025

Deploy a web app with App Service auth in a pipeline

Updated

Describes how to set up a pipeline in Azure Pipelines to build and deploy a web app to Azure and enable the Azure App Service built-in authentication. The article provides step-by-step instructions on how to configure Azure resources, build and deploy a web application, create a Microsoft Entra app registration, and configure App Service built-in authentication using Azure Pipelines.

9 July 2025

Microsoft Identity Platform Glossary

Updated

Learn key terms used in Microsoft identity platform documentation, Microsoft Entra admin center, and authentication SDKs like the Microsoft Authentication Library (MSAL).

9 July 2025

Application model

Updated

Learn about the process of registering your application so it can integrate with the Microsoft identity platform.

9 July 2025

Application Developer

Updated

A Microsoft Entra documentation page was updated: Application Developer.

3 July 2025

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

2 July 2025

Architecture

7

Recoverability Overview

Updated

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

12 July 2025

Plan Connect Performance Factors

Updated

The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.

5 July 2025

Governance

4

Plan Cloud Hr Provision

Updated

This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.

25 July 2025

Plan Cloud Hr Provision

Updated

This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.

23 July 2025

Branding

3

Authentication

1

View logs and metrics for the Conditional Access optimization agent

Updated

The Conditional Access optimization agent helps organizations improve their security posture by automatically analyzing sign-in patterns and suggesting policy optimizations. This Microsoft Security Copilot agent identifies unprotected users and applications, recommends policy improvements, and helps consolidate redundant policies.

10 July 2025

Conditional Access

1

Agent Optimization

Updated

- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.

3 July 2025

General

1

Agent Optimization

Updated

If the agent identifies something that wasn't previously suggested, it takes the following steps. **The agent action steps consume SCUs.**

22 July 2025

Authentication

1

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

24 July 2025

Fundamentals

1

Investigate risky users with Copilot

Updated

Use Copilot in Microsoft Entra to quickly respond to identity threats by summarizing the risk level for a user and receiving insights relevant to the incident.

9 July 2025

Security

1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview](/microsoft-365/security/office-365-security/scc-permissions).

24 July 2025

Governance

18

Entitlement Management Access Package Visibility

Updated

The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."

22 July 2025

Customize Workflow Email

Updated

1. On the pane that lists tasks, select the task for which you want to customize the email.

16 July 2025

Lifecycle Workflows Tasks Table

Updated

| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |

16 July 2025

Pim Create Roles And Resource Roles Review

Updated

:::image type="content" source="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png" alt-text="Screenshot of the settings page under access reviews." lightbox="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png":::

15 July 2025

Entitlement Management Access Package Visibility

Updated

The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."

11 July 2025

Microsoft Entra Id Governance Licensing For Guest Users

Updated

2. Select the directory you want to link: In the Microsoft Entra admin center toolbar, select the **Settings** icon in the portal toolbar. Then on the **Portal settings \| Directories + subscriptions** page, find your workforce tenant in the **Directory name** list, and then select **Switch**.

10 July 2025

Entitlement Management Verified Id Settings

Updated

> If you select multiple credential types from one issuer, users will be required to present credentials of all selected types. Similarly, if you include multiple issuers, users will be required to present credentials from each of the issuers you include in the policy. To give users the option of presenting different credentials from various issuers, configure separate policies for each issuer/credential type you’ll accept.

3 July 2025

Fundamentals

3

Whats New

Updated

**Service category:** Lifecycle Workflows

16 July 2025

Manage lifecycle workflows with Microsoft Security Copilot

Updated

Use Microsoft Security Copilot in the Microsoft Entra admin center to create lifecycle workflows for Joiner, Mover, and Leaver scenarios. Execute workflows on-demand and use workflow insights to monitor execution and troubleshoot as needed.

9 July 2025

Troubleshooting

1

Complete Access Review

Updated

> - User not found / other errors can also result in an apply result not being supported.

15 July 2025

General

19

Facebook Federation

Updated

Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.

9 July 2025

Custom Url Domain

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Domain Name Administrator](~/identity/role-based-access-control/permissions-reference.md#domain-name-administrator).

1 July 2025

Developer

5

Add an enterprise application

Updated

Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.

30 July 2025

Migrate Users

Updated

- If you are migrating from Azure AD B2C, the [seamless user migration sample](https://github.com/azure-ad-b2c/samples/tree/master/policies/migrate-to-entra-external-id-for-customers) repository on GitHub contains a seamless migration custom policy example and REST API code sample.

17 July 2025

External Collaboration Settings Configure

Updated

For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.

10 July 2025

Microsoft Accounts Federation Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

4 July 2025

Fundamentals

4

What Is B2b

Updated

- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.

10 July 2025

B2b Direct Connect Overview

Updated

Microsoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.

9 July 2025

B2b Fundamentals

Updated

| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |

4 July 2025

Provisioning

4

Known Issues

Updated

Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.

23 July 2025

Authentication

2

Branding

2

Customize Branding Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Organizational Branding Administrator](~/identity/role-based-access-control/permissions-reference.md#organizational-branding-administrator).

10 July 2025

Standards

2

Licensing Service Plan Reference

Updated

| Microsoft 365 A3 student use benefits | M365EDU_A3_STUUSEBNFT | 18250162-5d87-4436-a834-d795c15c80f3 | AAD_BASIC_EDU (1d0f309f-fdf9-4b2a-9ae7-9c48b91f1426)<br/>RMS_S_ENTERPRISE (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>EducationAnalyticsP1 (a9b86446-fa4e-498f-a92a-41b447e03337)<br/>EXCHANGE_S_ENTERPRISE (efb87545-963c-4e0d-99df-69c6916d9eb0)<br/>INFORMATION_BARRIERS (c4801e8a-cb58-4c35-aca6-f2dcc106f287)<br/>MIP_S_CLP1 (5136a095-5cf0-4aff-bec3-e84448b38ea5)<br/>OFFICESUBSCRIPTION (43de0ff5-c92c-492b-9116-175376d08c38)<br/>MICROSOFTBOOKINGS (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>OFFICE_FORMS_PLAN_2 (9b5de886-f035-4ff2-b3d8-c9127bea3620)<br/>KAIZALA_O365_P3 (aebd3021-9f8f-4bf8-bbe3-0ed2f4f047a1)<br/>PROJECTWORKMANAGEMENT (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>MICROSOFT_SEARCH (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Deskless (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>STREAM_O365_E3 (9e700747-8b1d-45e5-ab8d-ef187ceec156)<br/>TEAMS1 (57ff2da0-773e-42df-b2af-ffb7a2317929)<br/>MINECRAFT_EDUCATION_EDITION (4c246bbc-f513-4311-beff-eba54c353256)<br/>INTUNE_O365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>ADALLOM_S_O365 (8c098270-9dd4-4350-9b30-ba4703f3b36b)<br/>SHAREPOINTWAC_EDU (e03c7e47-402c-463c-ab25-949079bedb21)<br/>PROJECT_O365_P2 (31b4e2fc-4cd6-4e7d-9c1b-41407303bd66)<br/>SCHOOL_DATA_SYNC_P2 (500b6a2a-7a50-4f40-b5f9-160e5b8c2f48)<br/>SHAREPOINTENTERPRISE_EDU (63038b2c-28d0-45f6-bc36-33062963b498)<br/>MCOSTANDARD (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>SWAY (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>BPOS_S_TODO_2 (c87f142c-d1e9-4363-8630-aaea9c4d9ae5)<br/>WHITEBOARD_PLAN2 (94a54592-cd8b-425e-87c6-97868b000b91)<br/>YAMMER_EDU (2078e8df-cff6-4290-98cb-5408261a760a)<br/>UNIVERSAL_PRINT_NO_SEEDING (b67adbaf-a096-42c9-967e-5a84edbe0086)<br/>Virtualization Rights for Windows 10 (E3/E5+VDA) (e7c91390-7625-45be-94e0-e16907e03118)<br/>AAD_PREMIUM (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>DYN365_CDS_O365_P2 (4ff01e01-1ba7-4d71-8cf8-ce96c3bbcf14)<br/>MFA_PREMIUM (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>ADALLOM_S_DISCOVERY (932ad362-64a8-4783-9106-97849a1a30b9)<br/>INTUNE_A (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>INTUNE_EDU (da24caf9-af8e-485c-b7c8-e73336da2693)<br/>POWERAPPS_O365_P2 (c68f8d98-5534-41c8-bf36-22fa496fa792)<br/>FLOW_O365_P2 (76846ad7-7776-4c40-a281-a386362dd1b9) | Microsoft Entra Basic for Education (1d0f309f-fdf9-4b2a-9ae7-9c48b91f1426)<br/>Azure Rights Management (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>Education Analytics (a9b86446-fa4e-498f-a92a-41b447e03337)<br/>Exchange Online (Plan 2) (efb87545-963c-4e0d-99df-69c6916d9eb0)<br/>Information Barriers (c4801e8a-cb58-4c35-aca6-f2dcc106f287)<br/>Information Protection for Office 365 - Standard (5136a095-5cf0-4aff-bec3-e84448b38ea5)<br/>Microsoft 365 Apps for enterprise (43de0ff5-c92c-492b-9116-175376d08c38)<br/>Microsoft Bookings (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>Microsoft Forms (Plan 2) (9b5de886-f035-4ff2-b3d8-c9127bea3620)<br/>Microsoft Kaizala Pro (aebd3021-9f8f-4bf8-bbe3-0ed2f4f047a1)<br/>Microsoft Planner (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>Microsoft Search (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Microsoft StaffHub (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>Microsoft Stream for Office 365 E3 (9e700747-8b1d-45e5-ab8d-ef187ceec156)<br/>Microsoft Teams (57ff2da0-773e-42df-b2af-ffb7a2317929)<br/>Minecraft Education Edition (4c246bbc-f513-4311-beff-eba54c353256)<br/>Mobile Device Management for Office 365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Office 365 Cloud App Security (8c098270-9dd4-4350-9b30-ba4703f3b36b)<br/>Office for the Web for Education (e03c7e47-402c-463c-ab25-949079bedb21)<br/>Project for Office (Plan E3) (31b4e2fc-4cd6-4e7d-9c1b-41407303bd66)<br/>School Data Sync (Plan 2) (500b6a2a-7a50-4f40-b5f9-160e5b8c2f48)<br/>SharePoint (Plan 2) for Education (63038b2c-28d0-45f6-bc36-33062963b498)<br/>Skype for Business Online (Plan 2) (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>Sway (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>To-Do (Plan 2) (c87f142c-d1e9-4363-8630-aaea9c4d9ae5)<br/>Whiteboard (Plan 2) (94a54592-cd8b-425e-87c6-97868b000b91)<br/>Yammer for Academic (2078e8df-cff6-4290-98cb-5408261a760a)<br/>Universal Print Without Seeding (b67adbaf-a096-42c9-967e-5a84edbe0086)<br/>Windows 10/11 Enterprise (e7c91390-7625-45be-94e0-e16907e03118)<br/>Microsoft Entra ID P1 (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>Common Data Service (4ff01e01-1ba7-4d71-8cf8-ce96c3bbcf14)<br/>Microsoft Azure Multi-Factor Authentication (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>Microsoft Defender for Cloud Apps Discovery (932ad362-64a8-4783-9106-97849a1a30b9)<br/>Microsoft Intune (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>Microsoft Intune for Education (da24caf9-af8e-485c-b7c8-e73336da2693)<br/>Power Apps for Office 365 (c68f8d98-5534-41c8-bf36-22fa496fa792)<br/>Power Automate for Office 365 (76846ad7-7776-4c40-a281-a386362dd1b9) |

10 July 2025

Supported Features Customers

Updated

| **Sign-out** | When a [SAML](../../identity-platform/single-sign-out-saml-protocol.md) or [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#send-a-sign-out-request) application directs the user to the logout endpoint, Microsoft Entra ID removes and invalidates the user's session from the browser. | Same as workforce.|

3 July 2025

Troubleshooting

2

Azure Monitor

Updated

To stop collecting logs to your Log Analytics workspace, delete the diagnostic settings you created. You'll continue to incur charges for retaining log data you've already collected into your workspace. If you no longer need the monitoring data you've collected, you can delete your Log Analytics workspace and the resource group you created for Azure Monitor. Deleting the Log Analytics workspace deletes all data in the workspace and prevents you from incurring other data retention charges.

9 July 2025

General

2

General

1

Fundamentals

4

Configure Managed Identities Isolation Scope

Updated

- Read the [Isolation scope for user-assigned managed identities](managed-identities-isolation-scope.md) concept article to understand the benefits and implications.

18 July 2025

General

3

Managed Identities Faq

Updated

You can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:

24 July 2025

Security

3

Authentication

2

Retire Service Principal Less Authentication

Updated

Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.

16 July 2025

Create an Azure app identity (PowerShell)

Updated

Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.

9 July 2025

Conditional Access

1

Developer

1

Workload Identity Federation Config App Trust Managed Identity

Updated

The audience value must be set to one of the following values:<br/> &#8226; **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>&#8226; **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>&#8226; **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>

9 July 2025

Microsoft identity platform

1

Workload Identity Federation Config App Trust Managed Identity

Updated

- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* values of the federated identity credential are checked against the `issuer` and `subject` claims provided in the Managed Identity token. If that validation check passes, Microsoft identity platform issues an access token to the external software workload.

1 July 2025

Fundamentals

8

Connector Groups

Updated

You must have multiple connectors to use connector groups. New connectors are automatically added to the **Default** connector group. For more information on installing connectors, see [configure connectors](how-to-configure-connectors.md).

12 July 2025

Configure Connectors

Updated

For information about connectors, capacity planning, and how they stay up-to-date, see [Understand Microsoft Entra private network connectors](concept-connectors.md).

2 July 2025

General

5

Install Macos Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.

31 July 2025

Macos Client Release History

Updated

This article tracks the changes in each released version of the Global Secure Access client for macOS.

31 July 2025

Monitoring

3

Configure Connectors

Updated

- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).

4 July 2025

Security

2

Conditional Access

1

Compliant Network

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with an account which has the [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) and [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role activated.

10 July 2025

Developer

1

Conditional Access

4

Agent Optimization

Updated

Learn how the Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot can help secure your organization.

9 July 2025

Fundamentals

3

Authentication

1

Agent Optimization

Updated

The Security Administrator and Global Administrator roles have access to Security Copilot by default. You can assign Conditional Access Administrators with Security Copilot access. This authorization gives your Conditional Access Administrators the ability to use the agent as well. For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access).

15 July 2025

Security

1

Troubleshooting

1