Apple Sso Plugin
Updated( ** ) You only need to allow sovereign cloud domains if you rely on those in your environment.
Daily.Entra.NewsJuly was overwhelmingly a documentation month: 1,047 of 1,060 records were updates, compared with seven new items and four Message Center notices. The meaningful exceptions were concrete behavior or security changes rather than broad launches. Microsoft 365 is changing Entra-related defaults to block legacy authentication and require admin consent for third-party app access; Entra ID is making browser access the Android default while retiring its old toggle; and Workload ID is closing remaining non-Microsoft multitenant service-principal-less authentication cases. The Conditional Access optimization agent received substantial cross-product operating and telemetry guidance, while Group Source of Authority is explicitly documented as Preview. No supplied entry identifies a general-availability launch. Large Conditional Access, Entra Connect, Cloud Sync, and hybrid-identity edits should therefore be read primarily as procedure and reference maintenance. Other Message Center items, including the September Authenticator backup change on iOS and a later sign-in-background refresh, require no administrator action.
Change type: Message Center behavior and security rollout, not a general-availability feature launch. Microsoft 365 says the new defaults begin rolling out in mid-July 2025 and complete by August 2025: legacy authentication protocols will be blocked and third-party app access will require admin consent. The notice directs organizations to assess configurations, notify stakeholders, update documentation, and configure the Admin Consent workflow.
Change type: behavior change and retirement. Microsoft Entra will enable browser access by default for all Android users and retire the “Enable Browser Access” feature in Microsoft Authenticator and Company Portal. The notice describes this as a hardware-bound device-registration change that will roll out automatically worldwide, with no administrator action required; organizations that do not use Android can ignore it.
Change type: security behavior change and retirement in Workload ID guidance. Entra ID will block authentication when a non-Microsoft multitenant application has no service principal in the tenant where it authenticates. The documentation says service-principal-less authentication is already disabled for most non-Microsoft applications and that this change addresses the remaining exceptions. No cutover date or remediation procedure is supplied.
Change type: coordinated documentation and security guidance, not evidence of a preview, GA release, or product launch. New and updated pages describe an agent that analyzes sign-in patterns, identifies unprotected users and applications, recommends policy improvements such as MFA coverage, and exposes metrics and audit events. Administrators must review and approve suggestions; the guidance states that no changes are made without approval. The supplied weekly material also documents a 30-day summary, security-com-
Change type: preview guidance, not a GA announcement. Late-July Entra ID updates cover moving group management from AD DS to the cloud, prerequisites and cleanup, configuration, validation, auditing, preserved organizational units, post-conversion self-service management, and rollback. The feed does not establish a required migration or a new runtime behavior; it gives evaluators an end-to-end operating path.
Prioritize the secure-default rollout by assessing configurations for legacy-authentication dependencies and third-party app access, notifying stakeholders, updating internal documentation, and configuring the Admin Consent workflow as recommended in the notice. No Entra configuration change is required for the Android browser-access change or the iOS Authenticator backup update; organizations not using Android can ignore the former. For Workload ID, identify non-Microsoft multitenant applications authenticating without a service principal in the authenticating tenant. The supplied evidence provides no deadline or remediation procedure, so treat this as an exposure check rather than a mandated migration. If using the Conditional Access optimization agent, verify the documented Entra ID P1,
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
( ** ) You only need to allow sovereign cloud domains if you rely on those in your environment.
author: MicrosoftGuyJFlo
manager: pmwongera
author: MicrosoftGuyJFlo
A Microsoft Entra documentation page was updated: Permissions Reference.
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices<br/>[](../privileged-roles-permissions.md) |
author: MicrosoftGuyJFlo
author: shlipsey3
author: MicrosoftGuyJFlo
author: omondiatieno
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
A Microsoft Entra documentation page was updated: Common include file for referencing highly privileged roles accounts..
A Microsoft Entra documentation page was updated: Emergency Access Accounts.
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
author: MicrosoftGuyJFlo
manager: mwongerapk
author: shlipsey3
This article describes Azure AD Connect V1 decommissioning and how to migrate to V2.
This article describes the steps needed to successfully migrate groups from one forest to another for Microsoft Entra Connect.
Explains the different methods to upgrade to the latest release of Microsoft Entra Connect, including an in-place upgrade and a swing migration.
This article describes how to migrate groups that were initially set up for Group Writeback by using Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync.
Describes steps to migrate Microsoft Entra Connect to Microsoft Entra Cloud Sync.
This article describes what to do if you find that you're running a deprecated version.
This topic describes in more detail features which are in preview in Microsoft Entra Connect.
This article describes how to use the cloud sync feature of Microsoft Entra Connect to map attributes.
This article describes the common scenarios for using Microsoft Entra Cloud Sync and Microsoft Entra Connect.
This page provides guidelines for changing SHA algorithm for federation trust with Microsoft 365.
In this document, you'll learn how to federate multiple Microsoft Entra IDs with a single AD FS.
This topic recommends the use of AD Recycle Bin feature with Microsoft Entra Connect.
This article explains the custom installation options for Microsoft Entra Connect. Use these instructions to install Active Directory through Microsoft Entra Connect.
This article describes the steps required to integrate with Active Directory.
This article describes how to enable group writeback in Microsoft Entra Connect by using PowerShell and a wizard.
Learn how to fix modified default rules that come with Microsoft Entra Connect.
This article describes how to install and use single sign-on with cloud sync.
This page is a technical reference page for ports that are required to be open for Microsoft Entra Connect
Learn about the next version of Microsoft Entra Connect.
This article provides information on custom attribute mapping in cloud sync.
reference
This article describes how to use transformations to alter the default attribute mappings.
Operational details of Microsoft Entra ID trust handling by Microsoft Entra Connect.
This page is the central location for all documentation regarding AD FS operations that use Microsoft Entra Connect.
This document describes how to obtain GDPR compliancy with Microsoft Entra Connect.
Learn about user privacy and data collection with Microsoft Entra Connect Health.
Describes service side features for Microsoft Entra Connect Sync service.
Describes how shadow attributes work in Microsoft Entra Connect Sync service.
This topic describes the built-in scheduler feature in Microsoft Entra Connect Sync.
This document provides reference information for the ADConnectivityTools.psm1 PowerShell module.
This topic describes the built-in automatic upgrade feature in Microsoft Entra Connect Sync.
This document details device options available in Microsoft Entra Connect
Special considerations for deploying Microsoft Entra Connect with the Azure Government cloud.
This topic describes attribute behavior of the msExchUserHoldPolicies and cloudMsExchUserHoldPolicies attributes
This article describes how the Microsoft Entra seamless single sign-on feature works.
This topic walks you through how to select the installation type to use for Microsoft Entra Connect
This page documents special considerations for Microsoft Entra instances.
This page has non-Microsoft identity providers that can be used to implement single sign-on.
This topic describes Microsoft Entra seamless single sign-on and how it allows you to provide true single sign-on for corporate desktop users inside your corporate network.
This article describes the prerequisites required to integrate with Active Directory.
This article describes the prerequisites and hardware requirements you need for cloud sync.
Learn how to get started with Microsoft Entra seamless single sign-on by using Microsoft Entra Connect.
Explains how the installation wizard works the second time you run it.
This topic describes the pre-requisites and the hardware requirements cloud sync.
Learn how to add cloud sync to an existing hybrid identity environment.
This document describes how to uninstall Microsoft Entra Connect.
This article describes how to use the expression builder with cloud sync.
This article deals with Microsoft Entra seamless SSO and GDPR compliance.
This document describes the releases for Microsoft Entra Connect Health and what has been included in those releases.
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
manager: pmwongera
Template ID: d24aef57-1500-4070-84db-2666f29cf966
manager: pmwongera
A Microsoft Entra documentation page was updated: Microsoft 365 Migration Administrator.
After enabling this feature, existing userPrincipalName values remain as-is. On next change of the userPrincipalName attribute on-premises, the normal delta sync on users updates the UPN. Once this feature is enabled, it's not possible to disable it.
Template ID: d24aef57-1500-4070-84db-2666f29cf966
Billing Administrator
Cloud Device Administrator
Compliance Administrator
Compliance Data Administrator
Customer LockBox Access Approver
Network Administrator
Office Apps Administrator
Organizational Messages Approver
Organizational Messages Writer
A Microsoft Entra documentation page was updated: Ai Administrator.
A Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
A Microsoft Entra documentation page was updated: Attribute Assignment Administrator.
A Microsoft Entra documentation page was updated: Attribute Assignment Reader.
A Microsoft Entra documentation page was updated: Attribute Definition Administrator.
A Microsoft Entra documentation page was updated: Attribute Definition Reader.
A Microsoft Entra documentation page was updated: Azure Devops Administrator.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
A Microsoft Entra documentation page was updated: Directory Readers.
A Microsoft Entra documentation page was updated: Directory Writers.
A Microsoft Entra documentation page was updated: Domain Name Administrator.
Dynamics 365 Administrator
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
A Microsoft Entra documentation page was updated: Edge Administrator.
A Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
A Microsoft Entra documentation page was updated: Fabric Administrator.
A Microsoft Entra documentation page was updated: Global Administrator.
A Microsoft Entra documentation page was updated: Global Reader.
A Microsoft Entra documentation page was updated: Groups Administrator.
A Microsoft Entra documentation page was updated: Guest Inviter.
A Microsoft Entra documentation page was updated: Helpdesk Administrator.
A Microsoft Entra documentation page was updated: Hybrid Identity Administrator.
A Microsoft Entra documentation page was updated: Insights Administrator.
A Microsoft Entra documentation page was updated: Insights Analyst.
A Microsoft Entra documentation page was updated: Insights Business Leader.
A Microsoft Entra documentation page was updated: Intune Administrator.
A Microsoft Entra documentation page was updated: Iot Device Administrator.
A Microsoft Entra documentation page was updated: Kaizala Administrator.
A Microsoft Entra documentation page was updated: Knowledge Administrator.
A Microsoft Entra documentation page was updated: Knowledge Manager.
A Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
A Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
A Microsoft Entra documentation page was updated: Microsoft Entra Joined Device Local Administrator.
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
A Microsoft Entra documentation page was updated: Partner Tier1 Support.
A Microsoft Entra documentation page was updated: Partner Tier2 Support.
A Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
A Microsoft Entra documentation page was updated: Permissions Reference.
A Microsoft Entra documentation page was updated: Printer Administrator.
A Microsoft Entra documentation page was updated: Printer Technician.
A Microsoft Entra documentation page was updated: Privileged Role Administrator.
A Microsoft Entra documentation page was updated: Search Administrator.
A Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
A Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
A Microsoft Entra documentation page was updated: Teams Devices Administrator.
A Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
A Microsoft Entra documentation page was updated: Tenant Creator.
A Microsoft Entra documentation page was updated: User Administrator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
A Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
A Microsoft Entra documentation page was updated: Viva Goals Administrator.
A Microsoft Entra documentation page was updated: Viva Pulse Administrator.
A Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
A Microsoft Entra documentation page was updated: Yammer Administrator.
> New Microsoft Entra Connect Sync Versions are only available via the Microsoft Entra admin center
You can manage the [Microsoft Entra Joined Device Local Administrator](~/identity/role-based-access-control/permissions-reference.md#microsoft-entra-joined-device-local-administrator) role from **Device settings**.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
To configure the integration of Citrix ShareFile into Microsoft Entra ID, you need to add Citrix ShareFile from the gallery to your list of managed SaaS apps.
auth: {
Describes the deprecation of the app manifest (Azure AD Graph format) and attribute differences in the new format.
This article describes the federation metadata document that Microsoft Entra ID publishes for services that accept Microsoft Entra tokens.
Learn about the features and differences between single-tenant and multitenant apps in Microsoft Entra ID.
Learn how you can configure the terms of service and privacy statement for apps registered to use Microsoft Entra ID.
In this tutorial, you learn how to clean up the Azure resources allocated while creating the web app.
In this tutorial, you learn how to access data in Microsoft Graph from a web app for a signed-in user.
How to transition off of Microsoft Entra Permissions Management for the anticipated product deprecation.
View the latest public preview and general availability of features in Permissions Management.
How to add an account/subscription/project to Permissions Management after onboarding is complete.
How to add or remove a user in Microsoft Entra Permissions Management through the Microsoft Enter admin center.
How to configure AWS IAM Identity Center as an identity provider.
How to configure Okta as an identity provider in Microsoft Entra Permissions Management.
How to create a rule in the Autopilot dashboard in Microsoft Entra Permissions Management.
How to create and view activity alerts and alert triggers in Microsoft Entra Permissions Management.
How to create and view permission analytics triggers in the Permission analytics tab in Permissions Management.
How to create and view rule-based anomaly alerts and alert triggers in Permissions Management.
How to create and view statistical anomaly alerts and alert triggers in the Statistical Anomaly tab in Permissions Management.
How to create folders to organize Authorization Systems - accounts, subscriptions, and projects - in Microsoft Entra Permissions Management.
How to define and manage users, roles, and access levels in the Permissions Management User management dashboard.
How to enable Microsoft Entra Permissions Management in your organization.
How to enable or disable the controller in Permissions Management after onboarding is complete.
Frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
How to generate, view, and apply rule recommendations in the Microsoft Entra Permissions Management Autopilot dashboard.
How to manage users and groups in the User management dashboard in Permissions Management.
Microsoft Entra Permissions Management glossary
View current Microsoft Entra Permissions Management partners and their websites.
Quickstart guide - How to quickly onboard your Microsoft Entra Permissions Management product
Review roles and the level of permissions assigned in Microsoft Entra Permissions Management.
How to onboard a Google Cloud Platform (GCP) project on Permissions Management.
How to a Microsoft Azure subscription on Permissions Management.
How to onboard an Amazon Web Services (AWS) account to Permissions Management.
How to select group-based permissions settings with the User management dashboard.
How to view analytic information about access keys in Permissions Management.
How to view usage analytics about active resources in Permissions Management.
How to view analytic information about active tasks in Permissions Management.
How to view analytic information about groups in Permissions Management.
How to view analytic information about serverless functions in Permissions Management.
How to view analytic information about users in Permissions Management.
How to use the Analytics dashboard in Permissions Management to view details about users, groups, active resources, active tasks, access keys, and serverless functions.
How to view and configure settings for collecting data from your authorization system.
How to view current billable resources in your authorization system in Microsoft Entra Permissions Management.
How to view data about the activity in your authorization system in the Microsoft Entra Permissions Management Dashboard.
How to view information about active and completed tasks in the Activities pane in Permissions Management.
How to view information about alerts and alert triggers in the Alerts dashboard in Permissions Management.
How to view information about rules in the Autopilot dashboard in Permissions Management.
How to view statistics and data about your authorization system in the Permissions Management.
How to view personal and organization information in the Account settings dashboard in Microsoft Entra Permissions Management.
How to view current privileged role assignments in the Microsoft Entra Insights tab.
How to view information about identities that can access accounts from an external account in Permissions Management.
A Microsoft Entra documentation page was updated: Microsoft 365 Migration Administrator.
A Microsoft Entra documentation page was updated: Ai Administrator.
A Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
A Microsoft Entra documentation page was updated: Attribute Assignment Administrator.
A Microsoft Entra documentation page was updated: Attribute Assignment Reader.
A Microsoft Entra documentation page was updated: Attribute Definition Administrator.
A Microsoft Entra documentation page was updated: Attribute Definition Reader.
A Microsoft Entra documentation page was updated: Azure Devops Administrator.
A Microsoft Entra documentation page was updated: Billing Administrator.
A Microsoft Entra documentation page was updated: Cloud Device Administrator.
A Microsoft Entra documentation page was updated: Compliance Administrator.
A Microsoft Entra documentation page was updated: Compliance Data Administrator.
A Microsoft Entra documentation page was updated: Customer Lockbox Access Approver.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
A Microsoft Entra documentation page was updated: Directory Readers.
A Microsoft Entra documentation page was updated: Directory Writers.
A Microsoft Entra documentation page was updated: Domain Name Administrator.
A Microsoft Entra documentation page was updated: Dynamics 365 Administrator.
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
A Microsoft Entra documentation page was updated: Edge Administrator.
A Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
A Microsoft Entra documentation page was updated: Fabric Administrator.
A Microsoft Entra documentation page was updated: Global Administrator.
A Microsoft Entra documentation page was updated: Global Reader.
A Microsoft Entra documentation page was updated: Groups Administrator.
A Microsoft Entra documentation page was updated: Guest Inviter.
A Microsoft Entra documentation page was updated: Helpdesk Administrator.
A Microsoft Entra documentation page was updated: Hybrid Identity Administrator.
A Microsoft Entra documentation page was updated: Insights Administrator.
A Microsoft Entra documentation page was updated: Insights Analyst.
A Microsoft Entra documentation page was updated: Insights Business Leader.
A Microsoft Entra documentation page was updated: Intune Administrator.
A Microsoft Entra documentation page was updated: Iot Device Administrator.
A Microsoft Entra documentation page was updated: Kaizala Administrator.
A Microsoft Entra documentation page was updated: Knowledge Administrator.
A Microsoft Entra documentation page was updated: Knowledge Manager.
A Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
A Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
A Microsoft Entra documentation page was updated: Microsoft Entra Joined Device Local Administrator.
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
A Microsoft Entra documentation page was updated: Network Administrator.
A Microsoft Entra documentation page was updated: Office Apps Administrator.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
A Microsoft Entra documentation page was updated: Organizational Messages Approver.
A Microsoft Entra documentation page was updated: Organizational Messages Writer.
A Microsoft Entra documentation page was updated: Partner Tier1 Support.
A Microsoft Entra documentation page was updated: Partner Tier2 Support.
A Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
A Microsoft Entra documentation page was updated: Permissions Reference.
A Microsoft Entra documentation page was updated: Printer Administrator.
A Microsoft Entra documentation page was updated: Printer Technician.
A Microsoft Entra documentation page was updated: Privileged Role Administrator.
A Microsoft Entra documentation page was updated: Search Administrator.
A Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
A Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
A Microsoft Entra documentation page was updated: Teams Devices Administrator.
A Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
A Microsoft Entra documentation page was updated: Tenant Creator.
A Microsoft Entra documentation page was updated: User Administrator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
A Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
A Microsoft Entra documentation page was updated: Viva Goals Administrator.
A Microsoft Entra documentation page was updated: Viva Pulse Administrator.
A Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
A Microsoft Entra documentation page was updated: Yammer Administrator.
Before you configure a forest trust in Domain Services, make sure your networking between Azure and on-premises environment meets the following requirements:
Refrain from redirecting DNS zones related to windowsazure.com or core.windows.net. If DNS redirection is required, limit the redirection to individual host names instead of zones. For example, use server1.file.core.windows.net instead of file.core.windows.net.
A Microsoft Entra documentation page was updated: Compare Identity Solutions.
A Microsoft Entra documentation page was updated: Create Forest Trust Powershell.
A Microsoft Entra documentation page was updated: Tutorial Create Forest Trust.
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID

Learn how to get index the employeeId attribute to automate user account creation and updates from Inbound Provisioning to Active Directory
1. From the context menu **API permissions**, select the option **Add a permission**.
This article lists all releases of Microsoft Entra Connect Provisioning Agent and describes new features and fixed issues.
author: jenniferf-skc
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID
Describes how to create and export a connector from MIM Sync to be used with the Microsoft Entra ECMA Connector Host.
Learn how to export your Application Provisioning configuration and roll back to a known good state for disaster recovery in Microsoft Entra ID.
How to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
Technical deep dive into SAP SuccessFactors-HR driven provisioning for Microsoft Entra ID.
This document describes how to configure Microsoft Entra ID to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer REST and SOAP APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer web services based APIs.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory.
This tutorial describes how to provision users from Microsoft Entra ID into a SQL database.
This document describes how to configure Microsoft Entra ID to provision users into Active Directory Lightweight Directory Services as an example of an LDAP directory.
Learn how to provision users on demand in Microsoft Entra ID.
Provisioning users into SQL based applications using the ECMA Connector host
When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
Learn how to retrieve pronoun information from Workday
Learn which attributes from SuccessFactors are supported by SuccessFactors-HR driven provisioning in Microsoft Entra ID.
Learn how to use scoping filters to define attribute-based rules that determine which users or groups are provisioned in Microsoft Entra ID.
Learn how to override the default behavior of deprovisioning out of scope users in Microsoft Entra ID.
When configuring user provisioning with Microsoft Entra ID and SaaS apps, use the directory extension feature to add source attributes that aren't synchronized by default.
Understand how Application Provisioning works in Microsoft Entra ID.
Understand how expression builder works with Application Provisioning in Microsoft Entra ID.
Use partner driven integrations to provision accounts into all your applications.
Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
Learn which attributes that you can fetch from Workday using XPATH queries in Microsoft Entra ID.
Learn how to implement API-driven inbound provisioning with Azure Logic Apps.
Learn how to implement API-driven inbound provisioning with a PowerShell script.
Learn how to configure API-driven inbound provisioning app.
Learn how to extend API-driven inbound provisioning to sync custom attributes.
Learn how to grant access to the inbound provisioning API.
This tutorial provides step-by-step instructions so you can get started with API-driven inbound provisioning using cURL.
Learn more about the capabilities and integration scenarios supported by API-driven inbound provisioning.
Learn how to get started quickly with API-driven inbound provisioning using Graph Explorer
The Microsoft Entra provisioning service matches users in Microsoft Entra ID with users already in an application. In some cases, an application may have users that do not match with any in Microsoft Entra ID.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer Windows PowerShell based APIs.
Guidance for planning and executing automatic user provisioning in Microsoft Entra ID
Learn how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and give them access to SAP ECC, SAP S/4HANA, and other apps.
Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.
This article describes the Azure Monitor workbook for provisioning.
Learn how to use expression mappings to transform attribute values into an acceptable format during automated provisioning of SaaS app objects in Microsoft Entra ID. Includes a reference list of functions.
Learn about attribute mappings for Software as a Service (SaaS) apps in Microsoft Entra Application Provisioning. Learn what attributes are and how you can modify them to address your business needs.
Technical deep dive into Workday-HR driven provisioning in Microsoft Entra ID
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kisi Physical Security.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Webroot Security Awareness Training.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to KnowBe4 Security Awareness Training.
This article lists all releases of Microsoft Entra provisioning agent and describes new features and fixed issues
This article describes how to install the Microsoft Entra Connect cloud provisioning agent.
This article describes the required accounts for each of the synchronization tools.
This article describes how the attribute mapping and how to configure attributes when provisioning from Microsoft Entra ID to Active Directory.
Lists the attributes that are synchronized to Microsoft Entra ID.
This article describes how you can configure accidental deletion prevention for the synchronization tools with Active Directory.
This article describes how you can configure the synchronization tools with Active Directory.
This document explains how various factors influence the Microsoft Entra Connect provisioning engine. These factors help organizations to plan their Microsoft Entra Connect deployment to make sure it meets their sync requirements.
This article describes how you can configure the synchronization tools to use single sign-on.
Learn how to install the Microsoft Entra Connect cloud provisioning agent by using PowerShell cmdlets.
This article describes the steps required to install either cloud sync or Microsoft Entra Connect.
This article describes the built-in automatic upgrade feature in the Microsoft Entra Connect cloud provisioning agent.
This article describes how to manage registry options in the Microsoft Entra Connect cloud provisioning agent.
Understand the Metaverse Designer tab in the Synchronization Service Manager for Microsoft Entra Connect.
Reference of declarative provisioning expressions in Microsoft Entra Connect Sync.
Understand Synchronization Service Manager for Microsoft Entra Connect.
Explains how Microsoft Entra Connect Sync works and how to customize.
This topic describes how to recover Microsoft Entra Connect Synchronization Service when it encounters LocalDB 10GB limit issue.
Learn how to use the Microsoft Entra provisioning agent gMSA PowerShell cmdlets.
This article describes how to use the cloud sync feature of Microsoft Entra Connect to test configuration changes.
This article describes how to use on-demand provisioning with Microsoft Entra Cloud Sync.
Understand the Metaverse Search tab in the Synchronization Service Manager for Microsoft Entra Connect.
This article introduces the various tools that can be used to synchronize the cloud with on-premises environments.
This article describes the steps to verify the version of the provisioning agent or connect sync.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Slack.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Acunetix 360.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Airbase.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Airtable.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Akamai Enterprise Application Access.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Albert.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlexisHR.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Alohi.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to ALVAO.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Amazon Business.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Appaegis Isolation Access Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Ardoq.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Asana.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Astro.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atmos.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Autodesk SSO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Axiad Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Better Stack.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BLDNG APP.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Blink.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Blinq.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Bonusly.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Bustle B2B Transport Systems.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Canva.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cerby.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Chaos.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Cisco Webex.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail Swiss.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ClearView Trade.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Colloquial.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Connecter.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ContractS CLM.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to CultureHQ.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cybozu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CybSafe.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Dagster Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Datadog.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Diffchecker.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Documo.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Egnyte.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Envoy.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Evercate.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Fortes Change Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Funnel Leasing.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Fuze.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Genesys Cloud for Azure.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Managed User (OIDC).
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GitHub Enterprise Managed User.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoSkills.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GroupTalk.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Headspace.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hootsuite.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hoxhunt.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Humbol.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Hypervault.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to IDEO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to InformaCast.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Insight4GRC.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insite LMS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to introDus Pre and Onboarding Platform.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Iris Intranet.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Island.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Jellyfish.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Juno Journey.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Keystone.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kintone.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kno2fy.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to kpifire.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LawVu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Lucidchart.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Mixpanel.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to myPolicies.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to New Relic by Organization.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to NordPass.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to PrinterLogic SaaS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to ProdPad.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Proware.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to RingCentral.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Rollbar.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Segment.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Shopify Plus.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Sigma Computing.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Smallstep SSH.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Snowflake.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SolarWinds Service Desk (previously Samanage).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Splashtop.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SurveyMonkey Enterprise.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to TeamViewer.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to TerraTrue.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Thrive LXP.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Tic-Tac Mobile.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Uber.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Visibly.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Yellowbox.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zoom.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlertMedia.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atlassian Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AuditBoard.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AWS IAM Identity Center.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bentley - Automatic User Provisioning.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIC Cloud Design.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to BlogIn.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Boxcryptor.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bpanda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BrowserStack Single Sign-on.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BullseyeTDP.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CheckProof.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cisco User Management for Secure Access.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Clarizen One.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Clebex.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Coda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Code42.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Contentful.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to directprint.io.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Eletive.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to embed signage.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Exium.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Freshservice Provisioning.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to getAbstract.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub AE.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Global Relay Identity Sync.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GoLinks.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Gong.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Grammarly.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to H5mag.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Joyn FSM.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to KPN Grip.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LanSchool Air.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to QA.
Describes how to use BypassDirSyncOverridesEnabled tenant feature to restore synchronization of Mobile and OtherMobile attributes from on-premises Active Directory.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to ThousandEyes.
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Box so that I can streamline the user management process and ensure that users have the appropriate access to Box..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cornerstone OnDemand so that I can streamline the user management process and ensure that users have the appropriate access to Cornerstone OnDemand..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to DocuSign so that I can streamline the user management process and ensure that users have the appropriate access to DocuSign..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoToMeeting so that I can streamline the user management process and ensure that users have the appropriate access to GoToMeeting..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Jive so that I can streamline the user management process and ensure that users have the appropriate access to Jive..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Merchlogix so that I can streamline the user management process and ensure that users have the appropriate access to Merchlogix..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Salesforce Sandbox so that I can streamline the user management process and ensure that users have the appropriate access to Salesforce Sandbox..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Velpic so that I can streamline the user management process and ensure that users have the appropriate access to Velpic..
author: nguhiu
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Netpresenter Next.
When enterprise applications lack both explicit assignment requirements AND scoped provisioning controls, threat actors can exploit this dual weakness to gain unauthorized access to sensitive applications and data. The highest risk occurs when applications are configured with the default setting: "Assignment required" is set to "No" *and* provisioning isn't required or scoped. This dangerous combination allows threat actors who compromise any user account within the tenant to immediately access applications with broad user bases, expanding their attack surface and potential for lateral movement within the organization.
A Microsoft Entra documentation page was updated: Attribute Provisioning Administrator.
A Microsoft Entra documentation page was updated: Attribute Provisioning Reader.
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
| Attribute Name | User | Comment |
A Microsoft Entra documentation page was updated: Attribute Provisioning Administrator.
A Microsoft Entra documentation page was updated: Attribute Provisioning Reader.
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
author: justinha
Learn how to configure Conditional Access policies to target specific resources, actions, and authentication contexts in Microsoft Entra ID.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: aanjusingh
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
- Tenant admins must grant API clients interacting with this provisioning app the Graph permissions `SynchronizationData-User.Upload`, `SynchronizationData-User.Upload.OwnedBy` (for ISVs), and `ProvisioningLog.Read.All`.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
| **Allow users to connect work or school account with LinkedIn** | Setting this option to **No** prevents users from connecting their work or school account with their LinkedIn account. For more information, see [LinkedIn account connections data sharing and consent](~/identity/users/linkedin-user-consent.md). |
The following devices and applications support accessing resources on which a token protection Conditional Access policy is applied:
Learn how Conditional Access templates provide preconfigured policies to secure your environment, aligned with Microsoft recommendations.
Discover how to use Conditional Access filters for applications to streamline policy management and enhance security in Microsoft Entra ID.
Learn how continuous access evaluation in Microsoft Entra enhances security by responding to user state changes in near real time.
Understand the phases of Conditional Access policy enforcement in Microsoft Entra and how to apply them to secure user access.
author: ploegert
An introduction to how you can use Microsoft Entra ID to automatically provision, deprovision, and continuously update user accounts across multiple third-party applications.
Describes overview of HR driven provisioning.
An overview of API-driven inbound provisioning.
author: MicrosoftGuyJFlo
Enable Microsoft Entra ID security defaults to strengthen your organization's security posture with preconfigured MFA requirements and legacy authentication protection.
Learn how to protect organizational identities with Microsoft Entra ID. Discover security recommendations, multifactor authentication setup, and Zero Trust implementation strategies.
Organizations that deploy Intune can use the information returned from their devices to identify devices that meet specific policy compliance requirements. Intune sends compliance information to Microsoft Entra ID so Conditional Access can decide to grant or block access to resources. For more information about compliance policies, see [Set rules on devices to allow access to resources in your organization by using Intune](/mem/intune/protect/device-compliance-get-started).
author: justinha
Hybrid identity is having a common user identity for authentication and authorization both on-premises and in the cloud.
This topic provides deep dive information on how cloud sync works.
This document provides an overview of the installation options and paths available for installing Microsoft Entra Connect and Connect Health.
Explains the technical concepts of Microsoft Entra Connect Sync.
Explains users, groups, and contacts in Microsoft Entra Connect Sync.
Explains the declarative provisioning expressions.
Explains the declarative provisioning configuration model in Microsoft Entra Connect.
This document introduces the new ADConnectivity PowerShell module and how it can be used to help troubleshoot.
Describes federation with Microsoft Entra ID.
Describes overview of identity provisioning.
Describes overview of identity inter-directory provisioning.
Describes Microsoft Entra Cloud Sync.
Learn about the tools used to synchronize and monitor your on-premises environment with Microsoft Entra ID.
Describes the tools that are used to synchronize and monitor your on-premises environment with Microsoft Entra ID.
This article describes the provisioning agent used by cloud sync and on-premsises app provisioning.
In addition, enabling single sign-on in your app unlocks new authentication mechanisms that come with modern authentication, like [passwordless logins](~/identity/authentication/concept-authentication-passwordless.md). Usernames and passwords are one of the most popular attack vectors against applications, and enabling SSO allows you to mitigate this risk by enforcing Conditional Access or passwordless logins that add extra security or rely on more secure authentication mechanisms. Finally, enabling single sign-on also enables [single sign-out](v2-protocols-oidc.md#single-sign-out). This is useful in situations like work applications that will be used on shared devices.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
A Microsoft Entra documentation page was updated: Configure Security.
- Metadata for FIDO2 security keys needs to be published and verified with the FIDO Alliance Metadata Service, and also pass another set of validation testing by Microsoft. For more information, see [Become a Microsoft-compatible FIDO2 security key vendor](/entra/identity/authentication/concept-fido2-hardware-vendor).
author: MicrosoftGuyJFlo
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
>[!Important]
By default, system-preferred MFA is Microsoft managed and enabled for all users.
Most recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.
author: justinha
Use Copilot in Microsoft Entra to investigate identity risks and troubleshoot identity tasks quickly.
In this tutorial, you learn how to build a web app by using Azure App Service, sign in users to the web app, call Azure Storage, and call Microsoft Graph.
- You must have at least the [Microsoft Entra ID P1](overview.md#license-requirements) license.
An introduction to Microsoft Entra Permissions Management.
To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.
Changes are required if you use the [Microsoft.Identity.Client](https://www.nuget.org/packages/Microsoft.Identity.Client) package and one of the following APIs in your application. The public client API is **deprecated** [as of the 4.73.1 release](https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/main/CHANGELOG.md):
Learn about the information available on each of the tabs on the Microsoft Entra sign-in log activity details.
author: MicrosoftGuyJFlo
- **Success:** The Conditional Access policy was applied successfully to the sign-in attempt.
- Provectus - Secure Contacts
We're continually adding more administrative portals to the list.
A Microsoft Entra documentation page was updated: Audit Logs.
> [!IMPORTANT]
A Microsoft Entra documentation page was updated: Sign Ins.
A Microsoft Entra documentation page was updated: Sign Ups.
Most recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.
A Microsoft Entra documentation page was updated: Concepts Forest Trust.
- US Gov -> Commercial
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
manager: dougeby
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect engineering systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
manager: dougeby
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
manager: dougeby
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
manager: dougeby
A Microsoft Entra documentation page was updated: sfipillar: Protect identities and secrets.
A Microsoft Entra documentation page was updated: sfipillar: Protect networks.
A Microsoft Entra documentation page was updated: sfipillar: Protect networks.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
manager: dougeby
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
Learn how to force your Microsoft Entra Connect server to use only Transport Layer Security (TLS) 1.2.
- [Manage Microsoft 365 for iOS and Android with Microsoft Intune](/intune/intune-service/apps/manage-microsoft-office#copilot-with-enterprise-data-protection)
author: shlipsey3
author: shlipsey3
author: barclayn
Get-AzNetworkSecurityGroup -Name "nsg-name" -ResourceGroupName "resource-group-name" | Add-AzNetworkSecurityRuleConfig -Name "new-rule-name" -Access "Allow" -Protocol "TCP" -Direction "Inbound" -Priority "priority-number" -SourceAddressPrefix "CorpNetSaw" -SourcePortRange "*" -DestinationPortRange "3389" -DestinationAddressPrefix "*" | Set-AzNetworkSecurityGroup
Cloud App Security Administrator
A Microsoft Entra documentation page was updated: Security Administrator.
A Microsoft Entra documentation page was updated: Security Operator.
A Microsoft Entra documentation page was updated: Security Reader.
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
Learn how Microsoft Entra Permissions Management helps strengthen security in cloud environments as an enhancement for Defender for Cloud
A Microsoft Entra documentation page was updated: Cloud App Security Administrator.
A Microsoft Entra documentation page was updated: Security Administrator.
A Microsoft Entra documentation page was updated: Security Operator.
A Microsoft Entra documentation page was updated: Security Reader.
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Microsoft Entra will enable browser access by default for all Android users, retiring the "Enable Browser Access" feature in Microsoft Authenticator and Company Portal apps. This hardware-bound device registration change requires no admin action and will roll out automatically worldwide. Organizations not using Android can ignore this update.
author: justinha
author: shlipsey3
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory so that the users can then sign into a Linux or other POSIX system using pluggable authentication.
After entering the sign-in credentials, the consent screen appears. The consent screen provides information about the application and the permissions it requires.
1. When you see the configuration finish, select **Exit**.
Microsoft 365 will update default settings to enhance security by blocking legacy authentication protocols and requiring admin consent for third-party app access. Changes start mid-July 2025 and complete by August 2025. Organizations should assess configurations, notify stakeholders, update documentation, and configure the Admin Consent workflow.
1. Is the Connect server in [staging mode](how-to-connect-sync-staging-server.md)? A server in staging mode does not synchronize any passwords.
The Cloud Password Policy for Password-Synced Users feature ensures that Microsoft Entra ID enforces its native password policies (such as expiration and lockout), for users whose passwords are synchronized from on-premises Active Directory. This feature enables you to align the same on-premises Active Directory password policy with the Microsoft Entra password policy, for synchronized users.
This guide helps CEOs, CIOs, CISOs, Chief Identity Architects, Enterprise Architects, and Security and IT decision makers responsible for choosing an authentication method for their Microsoft Entra hybrid identity solution in medium to large organizations.
Learn how Microsoft Entra pass-through authentication protects your on-premises accounts.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forcepoint Cloud Security Gateway - User Authentication.
author: gargi-sinha
This article describes how to upgrade your Microsoft Entra pass-through authentication configuration.
This article describes Microsoft Entra pass-through authentication and how it allows Microsoft Entra sign-ins by validating users' passwords against on-premises Active Directory.
This article describes the current limitations of Microsoft Entra pass-through authentication
This article deals with Microsoft Entra pass-through authentication and GDPR compliance.
This article describes how to disable pass-through authentication by using the Microsoft Entra Connect Do Not Configure feature or by using PowerShell.
This article describes how Microsoft Entra pass-through authentication works
This article describes how to get started with Microsoft Entra pass-through authentication.
This article lists all releases of the Microsoft Entra pass-through authentication agent
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks Cloud Identity Engine - Cloud Authentication Service.
This article describes how to allow the Microsoft Entra Connect application to authenticate with Microsoft Entra ID with modern, more secure credentials.
This topic document describes how to update Microsoft Entra Connect after the password of the AD DS account is changed.
This article discusses how to manage AD FS with Microsoft Entra Connect and customize the AD FS user sign-in experience with Microsoft Entra Connect and PowerShell.
This topic document describes the encryption key and how to abandon it after the password is changed.
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Agile Provisioning so that I can control who has access to Agile Provisioning, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location..
Authorization logic is often implemented within the applications or solutions where access control is required. In many cases, application development platforms offer middleware or other API solutions that simplify the implementation of authorization. Examples include use of the [AuthorizeAttribute](/aspnet/core/security/authorization/simple?view=aspnetcore-5.0&preserve-view=true) in ASP.NET or [Route Guards](./scenario-spa-sign-in.md?tabs=angular2#sign-in-with-a-pop-up-window) in Angular.
author: shlipsey3
- It's supported on web browser-based clients and Office clients that support [modern authentication](/microsoft-365/enterprise/modern-auth-for-office-2013-and-2016) on platforms and browsers capable of Kerberos authentication:
A Microsoft Entra documentation page was updated: Authentication Administrator.
A Microsoft Entra documentation page was updated: Authentication Extensibility Administrator.
A Microsoft Entra documentation page was updated: Authentication Policy Administrator.
A Microsoft Entra documentation page was updated: Privileged Authentication Administrator.
A Microsoft Entra documentation page was updated: Password Administrator.
For organizations that have no established use of device code flow, blocking can be done with the following Conditional Access policy:
If you don't plan on testing your app in the same tenant you registered it in, or you aren't an administrator in your tenant, you can't consent to the permissions from the [Microsoft Entra admin center](https://entra.microsoft.com). You can still consent to some permissions, however, by triggering a sign-in prompt in a web browser.
The per-user MFA administration experience in the Microsoft Entra admin center is recently improved. To view and manage user states, complete the following steps:
In this tutorial, set up SSPR for a set of users in a test group. Use the *SSPR-Test-Group* and provide your own Microsoft Entra group as needed:
In this tutorial, you learn how to enable authentication for a web app running on Azure App Service. Limit access to the web app to users in your organization.
To create a PKI container object:
A User account in Microsoft Entra must be added to a role assignment in Azure before the user is allowed to sign in to Azure virtual machines or Arc-connected Windows Server. The same roles are used for both Azure virtual machines and Arc-enabled Windows Server.
To create a PKI container object:
- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.
author: vimrang
Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.
A Microsoft Entra documentation page was updated: Authentication Administrator.
A Microsoft Entra documentation page was updated: Authentication Extensibility Administrator.
A Microsoft Entra documentation page was updated: Authentication Policy Administrator.
A Microsoft Entra documentation page was updated: Privileged Authentication Administrator.
A Microsoft Entra documentation page was updated: Password Administrator.
manager: pmwongera
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.
Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
Learn how to check the status of automatic user account provisioning jobs, and how to troubleshoot the provisioning of individual users.
Learn how to troubleshoot attribute retrieval issues with HR provisioning
Learn how to troubleshoot InsufficientAccessRights error when provisioning to on-premises Active Directory.
This article provides potential issues and resolutions that guide you in how to troubleshoot issues with the inbound provisioning API.
This article provides potential issues and resolutions that show you how to troubleshoot manager update issues with HR provisioning
How to troubleshoot common issues faced when configuring user provisioning to an application already listed in the Microsoft Entra application gallery.
Learn how to troubleshoot user creation issues with HR provisioning
Learn how to troubleshoot user update issues with HR provisioning
This article provides potential issues and resolutions so you can troubleshoot writeback issues with HR provisioning.
Set up Microsoft Entra terms of use with Conditional Access to require policy acceptance before resource access. Complete guide with prerequisites, step-by-step configuration, and troubleshooting tips.
A Microsoft Entra documentation page was updated: sfipillar: Accelerate response and remediation.
A Microsoft Entra documentation page was updated: sfipillar: Accelerate response and remediation.
manager: dougeby
This article describes how to troubleshoot Microsoft Entra pass-through authentication.
reference article for cloud sync error codes
This article describes how to troubleshoot problems that might arise with the cloud provisioning agent.
This topic provides the remediation steps for LargeObject errors caused by userCertificate attribute.
This document describes the diagnosis process of duplicated attribute synchronization errors and a potential fix of the orphaned object scenarios directly from the [Microsoft Entra admin center](https://entra.microsoft.com).
Learn how to synchronize one object from Active Directory to Microsoft Entra ID for troubleshooting.
This article explains how to troubleshoot errors that occur during synchronization with Microsoft Entra Connect.
This topic provides steps for how to troubleshoot issues with attribute synchronization using the troubleshooting task.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to MX3 Diagnostics Connector.
Learn about the AADSTS error codes that are returned from the Microsoft Entra security token service (STS).
author: OwenRichards1
How to revoke access to high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard.
How to attach and detach permissions for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management.
How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
How to clone a role/policy in Microsoft Entra Permissions Management.
How to create a role/policy in the Remediation dashboard.
How to create or approve a request for permissions in the Remediation dashboard.
How to delete a role/policy in the Microsoft Entra Permissions Management Remediation dashboard.
Understand potential error codes that may appear during onboarding of Microsoft Entra Permissions Management
How to modify a role/policy in the Remediation dashboard in Microsoft Entra Permissions Management.
Troubleshoot issues with Permissions Management
How to view existing roles/policies and requests for permission in the Remediation dashboard in Permissions Management.
How to view and filter information about roles/policies in the Microsoft Entra Permissions Management Remediation dashboard.
> Error code 1002013 indicates an expected (and successful) interrupt of the sign-up flow. [Learn more](howto-troubleshoot-sign-up-errors.md#sign-up-error-codes)
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
A Microsoft Entra documentation page was updated: Customer intent: As an IT admin, I want to learn how to troubleshoot sign-up errors for various scenarios and using different tools so that I can resolve sign-up issues quickly..
|2507|Enable/Disable sync start after installation.| Event is logged when sync is enabled or disabled after the installation is finished.|
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |
> | microsoft.directory/auditLogs/allProperties/read | Read all properties on audit logs, excluding custom security attributes audit logs |
author: shlipsey3
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
manager: dougeby
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
A Microsoft Entra documentation page was updated: sfipillar: Monitor and detect cyberthreats.
This article describes the Microsoft Entra Connect Health AD FS Risky IP report.
Learn about various on-premises and Microsoft Entra topologies that use Microsoft Entra Cloud Sync.
This document shows the catalog of all alerts in Microsoft Entra Connect Health.
This is the Microsoft Entra Connect Health page how to monitor your on-premises AD FS infrastructure.
This article explains how to monitor changes to your federation configuration with Microsoft Entra ID.
- To view the Microsoft Entra audit logs, you need at least the [Reports reader](../../identity/role-based-access-control/permissions-reference.md#reports-reader) role.
author: barclayn
A Microsoft Entra documentation page was updated: Attribute Log Administrator.
A Microsoft Entra documentation page was updated: Attribute Log Reader.
Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
A Microsoft Entra documentation page was updated: Reports Reader.
A Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).
Tenants are opted in to receive Microsoft Entra recommendation emails by default. To turn off these emails, follow these steps:
How to create a custom query in the Audit dashboard in Microsoft Entra Permissions Management.
How to create, view, and share a custom report in the Permissions Management.
How to filter and query user activity in Microsoft Entra Permissions Management.
How to generate an on-demand report from a query in the **Audit** dashboard in Permissions Management.
How to generate and view a system report in the Permissions Management.
How to use queries to see how users access information in an authorization system in Permissions Management.
View a list and description of all system reports available in Permissions Management.
How to view and download the Permissions Analytics Report in Permissions Management.
How to view system reports in the Reports dashboard in Permissions Management.
| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |
A Microsoft Entra documentation page was updated: Attribute Log Administrator.
A Microsoft Entra documentation page was updated: Attribute Log Reader.
Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
A Microsoft Entra documentation page was updated: Reports Reader.
A Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
- To find sign-up attempts that failed during email validation:
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
- A relying party STS, such as Active Directory Federation Services (AD FS) or PingFederate, with HTTPS endpoints
You can see a sample request to the REST API:
Get information on how to configure group claims for use with Microsoft Entra ID.
This document covers updates to the Microsoft Entra Connect Sync v2 endpoints API.
author: barclayn
Cloud Application Administrator
After disabling or restricting user consent, you have several important steps to take to help keep your organization secure as you continue to allow business-critical applications to be used. These steps are crucial to minimize impact on your organization's support team and IT administrators, and to help prevent the use of unmanaged accounts in non-Microsoft applications.
A Microsoft Entra documentation page was updated: Application Administrator.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Learn about the relationship between application and service principal objects in Microsoft Entra ID.
Learn how to implement role-based access control in your applications.
Describes the Microsoft Entra app manifest (Microsoft Graph format), which represents an application's identity configuration in a Microsoft Entra tenant.
Describes the Microsoft Entra app manifest, which represents an application's identity configuration in a Microsoft Entra tenant.
How to configure ServiceNow with Microsoft Entra Permissions Management.
How to view the Permissions Management API integration settings and create service accounts and roles.
This article shows the new and updated documentation for the Microsoft Entra application management.
1. If you wish to configure the application in **SP** initiated mode, then perform the following step:
A Microsoft Entra documentation page was updated: Application Administrator.
A Microsoft Entra documentation page was updated: Cloud Application Administrator.
| Parameter | Type | Description |
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.
This tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.
Using SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.
This article describes how to use the Microsoft Entra provisioning service to provision users into an on-premises app that's SCIM enabled.
This document describes using a SAML 2.0 compliant Idp for single sign-on.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insightly SAML.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks SCIM Connector.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon SAML.
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
author: OwenRichards1
manager: mwongerapk
Learn how to use advanced certificate signing options in the SAML token for preintegrated apps in Microsoft Entra ID
Microsoft Entra ID has a gallery that contains thousands of preintegrated applications that use SSO. This article uses an enterprise application named **Microsoft Entra SAML Toolkit 1** as an example, but the concepts apply for most preconfigured enterprise applications in the Microsoft Entra application gallery.
Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
The [OAuth 2.0 resource owner password credentials](v2-oauth-ropc.md) (ROPC) grant allows an application to sign in the user by directly handling their password. In your desktop application, you can use the username/password flow to acquire a token silently. No UI is required when using the application.
Redirect URIs for SPAs that use the auth code flow require special configuration.
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions is not known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Create a custom Conditional Access policy to block access to resources by IP location.
Create a custom Conditional Access policy require approved app or app protection policy
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Microsoft Entra ID returns an HTTP response with some interesting data:
The Microsoft Entra Conditional Access optimization agent provides suggestions for your Conditional Access policies. The suggestions vary based on what the agent finds. As the administrator, you need to review the suggestions and decide what to do.
Conditional Access Administrator
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
The Microsoft Entra Conditional Access optimization agent provides suggestions for your Conditional Access policies. The suggestions vary based on what the agent finds. As the administrator, you need to review the suggestions and decide what to do. No changes are made without your approval.
Administrators with at least the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role assigned find these policies in the [Microsoft Entra admin center](https://entra.microsoft.com) under **Entra ID** > **Conditional Access** > **Policies**.
1. Sign into the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Reports Reader](../role-based-access-control/permissions-reference.md#reports-reader).
The **Agent summary** at the top of the Conditional Access optimization agent page provides a quick summary of what the agent has discovered in the last 30 days. The total number of [security compute units (SCU)](/copilot/security/manage-usage) consumed by the agent is also provided.
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
A Microsoft Entra documentation page was updated: Conditional Access Administrator.
It's advised to call the `getDeviceInformationWithParameters` API in MSAL to find out if the admin has configured QR code authentication method. If it has, an app can update its UI to indicate that QR code authentication method is available as a sign-in option.
Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
This topic describes how to enable inbound synchronization using just the Graph API
- **C2** – Require compliant devices
| [Implicit grant](#implicit-grant) | User sign-in and access to web APIs on behalf of the user. *Do not use this flow - use authorization code with PKCE instead.* | * [Single-page app (SPA)](scenario-spa-app-registration.md) <br /> * [Web](scenario-web-api-call-api-app-registration.md) |
This topic covers how to manage hardware oath tokens in Microsoft Entra ID, including Microsoft Graph APIs that you can use to upload, activate, and assign hardware OATH tokens.
A Microsoft Entra documentation page was updated: Application Developer.
Learn about changes to the Microsoft identity platform that can impact your application.
Describes how to set up a pipeline in Azure Pipelines to build and deploy a web app to Azure and enable the Azure App Service built-in authentication. The article provides step-by-step instructions on how to configure Azure resources, build and deploy a web application, create a Microsoft Entra app registration, and configure App Service built-in authentication using Azure Pipelines.
Developer guidance and scenarios for Microsoft Entra Conditional Access and Microsoft identity platform.
Learn key terms used in Microsoft identity platform documentation, Microsoft Entra admin center, and authentication SDKs like the Microsoft Authentication Library (MSAL).
Learn about the sign-in flow of web, desktop, and mobile apps in Microsoft identity platform.
Learn about the process of registering your application so it can integrate with the Microsoft identity platform.
Learn about best practices, recommendations, and common oversights when integrating with the Microsoft identity platform.
Learn about what custom RBAC is and why it's important to implement in applications.
In this how-to, you configure an application registered with the Microsoft identity platform to change who, or what accounts, can access the application.
A description of authorization in the Microsoft identity platform, including scopes, permissions, and consent.
This article discusses the best practices for signing key rollover in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Application Developer.
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Explore the resilience features of Microsoft Entra ID's backup authentication system, designed to maintain authentication availability for users and services.
Presents an overview of on-premises application provisioning architecture.
This topic describes the architecture of Microsoft Entra Connect Sync and explains the terms used.
- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.
This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.
This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
Organizational Branding Administrator
Learn about application branding guidelines for Microsoft identity platform.
A Microsoft Entra documentation page was updated: Organizational Branding Administrator.
The Conditional Access optimization agent helps organizations improve their security posture by automatically analyzing sign-in patterns and suggesting policy optimizations. This Microsoft Security Copilot agent identifies unprotected users and applications, recommends policy improvements, and helps consolidate redundant policies.
- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.
If the agent identifies something that wasn't previously suggested, it takes the following steps. **The agent action steps consume SCUs.**
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Use Copilot in Microsoft Entra to quickly respond to identity threats by summarizing the risk level for a user and receiving insights relevant to the incident.
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview](/microsoft-365/security/office-365-security/scc-permissions).
}
1. Select **Add** to add the verified ID requirement to the access package policy.
In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports dynamically determining approvers such as the requestors manager, their second-level manager, or a sponsor from a connected organization:
- Tailspin creates a second access review for a security group with 300 guest users with the user-to-group affiliation feature enabled.
This approval will use the same approval settings that you specified on the **Requests** tab.
The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."
1. On the pane that lists tasks, select the task for which you want to customize the email.
}
|Item|Description|
| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |
:::image type="content" source="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png" alt-text="Screenshot of the settings page under access reviews." lightbox="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png":::
A Microsoft Entra documentation page was updated: Lifecycle Workflows Administrator.
The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."
> [!IMPORTANT]
2. Select the directory you want to link: In the Microsoft Entra admin center toolbar, select the **Settings** icon in the portal toolbar. Then on the **Portal settings \| Directories + subscriptions** page, find your workforce tenant in the **Directory name** list, and then select **Switch**.
[Learn more](../../id-governance/entitlement-management-organization.md)
> If you select multiple credential types from one issuer, users will be required to present credentials of all selected types. Similarly, if you include multiple issuers, users will be required to present credentials from each of the issuers you include in the policy. To give users the option of presenting different credentials from various issuers, configure separate policies for each issuer/credential type you’ll accept.
A Microsoft Entra documentation page was updated: Lifecycle Workflows Administrator.
**Service category:** Lifecycle Workflows
A conceptual article describing access package visibility in the My Access portal.
Use Microsoft Security Copilot in the Microsoft Entra admin center to create lifecycle workflows for Joiner, Mover, and Leaver scenarios. Execute workflows on-demand and use workflow insights to monitor execution and troubleshoot as needed.
> - User not found / other errors can also result in an apply result not being supported.
A Microsoft Entra documentation page was updated: B2c Ief Keyset Administrator.
A Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
A Microsoft Entra documentation page was updated: External Identity Provider Administrator.
Learn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.
Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.
A Microsoft Entra documentation page was updated: Cross Tenant Custom Roles.
New and updated documentation for the Microsoft Entra External ID.
A Microsoft Entra documentation page was updated: B2c Ief Keyset Administrator.
A Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
A Microsoft Entra documentation page was updated: External Identity Provider Administrator.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Domain Name Administrator](~/identity/role-based-access-control/permissions-reference.md#domain-name-administrator).
Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.
- If you are migrating from Azure AD B2C, the [seamless user migration sample](https://github.com/azure-ad-b2c/samples/tree/master/policies/migrate-to-entra-external-id-for-customers) repository on GitHub contains a seamless migration custom policy example and REST API code sample.
Create an enterprise application using the client ID for a multitenant application.
For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Feature |Workforce tenant | External tenant |
- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.
Microsoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.
| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) of the source tenant.
<br/>**Target tenant**
Starting September 2025, Microsoft Authenticator on iOS will use iCloud and iCloud Keychain for backup and restore, eliminating the need for a Microsoft personal account. This update simplifies setup on new devices, with automatic backup of account names and third-party TOTP credentials. No admin action is required.
Learn how to enforce multifactor authentication policies for Microsoft Entra B2B users.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Organizational Branding Administrator](~/identity/role-based-access-control/permissions-reference.md#organizational-branding-administrator).
Microsoft Entra is updating the default sign-in background for Work or School accounts to align with Microsoft's Fluent design language. This visual update will roll out from late September to early October 2025. No action is required, but internal documentation and help desks should be updated to reduce confusion.
| Microsoft 365 A3 student use benefits | M365EDU_A3_STUUSEBNFT | 18250162-5d87-4436-a834-d795c15c80f3 | AAD_BASIC_EDU (1d0f309f-fdf9-4b2a-9ae7-9c48b91f1426)<br/>RMS_S_ENTERPRISE (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>EducationAnalyticsP1 (a9b86446-fa4e-498f-a92a-41b447e03337)<br/>EXCHANGE_S_ENTERPRISE (efb87545-963c-4e0d-99df-69c6916d9eb0)<br/>INFORMATION_BARRIERS (c4801e8a-cb58-4c35-aca6-f2dcc106f287)<br/>MIP_S_CLP1 (5136a095-5cf0-4aff-bec3-e84448b38ea5)<br/>OFFICESUBSCRIPTION (43de0ff5-c92c-492b-9116-175376d08c38)<br/>MICROSOFTBOOKINGS (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>OFFICE_FORMS_PLAN_2 (9b5de886-f035-4ff2-b3d8-c9127bea3620)<br/>KAIZALA_O365_P3 (aebd3021-9f8f-4bf8-bbe3-0ed2f4f047a1)<br/>PROJECTWORKMANAGEMENT (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>MICROSOFT_SEARCH (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Deskless (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>STREAM_O365_E3 (9e700747-8b1d-45e5-ab8d-ef187ceec156)<br/>TEAMS1 (57ff2da0-773e-42df-b2af-ffb7a2317929)<br/>MINECRAFT_EDUCATION_EDITION (4c246bbc-f513-4311-beff-eba54c353256)<br/>INTUNE_O365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>ADALLOM_S_O365 (8c098270-9dd4-4350-9b30-ba4703f3b36b)<br/>SHAREPOINTWAC_EDU (e03c7e47-402c-463c-ab25-949079bedb21)<br/>PROJECT_O365_P2 (31b4e2fc-4cd6-4e7d-9c1b-41407303bd66)<br/>SCHOOL_DATA_SYNC_P2 (500b6a2a-7a50-4f40-b5f9-160e5b8c2f48)<br/>SHAREPOINTENTERPRISE_EDU (63038b2c-28d0-45f6-bc36-33062963b498)<br/>MCOSTANDARD (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>SWAY (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>BPOS_S_TODO_2 (c87f142c-d1e9-4363-8630-aaea9c4d9ae5)<br/>WHITEBOARD_PLAN2 (94a54592-cd8b-425e-87c6-97868b000b91)<br/>YAMMER_EDU (2078e8df-cff6-4290-98cb-5408261a760a)<br/>UNIVERSAL_PRINT_NO_SEEDING (b67adbaf-a096-42c9-967e-5a84edbe0086)<br/>Virtualization Rights for Windows 10 (E3/E5+VDA) (e7c91390-7625-45be-94e0-e16907e03118)<br/>AAD_PREMIUM (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>DYN365_CDS_O365_P2 (4ff01e01-1ba7-4d71-8cf8-ce96c3bbcf14)<br/>MFA_PREMIUM (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>ADALLOM_S_DISCOVERY (932ad362-64a8-4783-9106-97849a1a30b9)<br/>INTUNE_A (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>INTUNE_EDU (da24caf9-af8e-485c-b7c8-e73336da2693)<br/>POWERAPPS_O365_P2 (c68f8d98-5534-41c8-bf36-22fa496fa792)<br/>FLOW_O365_P2 (76846ad7-7776-4c40-a281-a386362dd1b9) | Microsoft Entra Basic for Education (1d0f309f-fdf9-4b2a-9ae7-9c48b91f1426)<br/>Azure Rights Management (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>Education Analytics (a9b86446-fa4e-498f-a92a-41b447e03337)<br/>Exchange Online (Plan 2) (efb87545-963c-4e0d-99df-69c6916d9eb0)<br/>Information Barriers (c4801e8a-cb58-4c35-aca6-f2dcc106f287)<br/>Information Protection for Office 365 - Standard (5136a095-5cf0-4aff-bec3-e84448b38ea5)<br/>Microsoft 365 Apps for enterprise (43de0ff5-c92c-492b-9116-175376d08c38)<br/>Microsoft Bookings (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>Microsoft Forms (Plan 2) (9b5de886-f035-4ff2-b3d8-c9127bea3620)<br/>Microsoft Kaizala Pro (aebd3021-9f8f-4bf8-bbe3-0ed2f4f047a1)<br/>Microsoft Planner (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>Microsoft Search (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Microsoft StaffHub (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>Microsoft Stream for Office 365 E3 (9e700747-8b1d-45e5-ab8d-ef187ceec156)<br/>Microsoft Teams (57ff2da0-773e-42df-b2af-ffb7a2317929)<br/>Minecraft Education Edition (4c246bbc-f513-4311-beff-eba54c353256)<br/>Mobile Device Management for Office 365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Office 365 Cloud App Security (8c098270-9dd4-4350-9b30-ba4703f3b36b)<br/>Office for the Web for Education (e03c7e47-402c-463c-ab25-949079bedb21)<br/>Project for Office (Plan E3) (31b4e2fc-4cd6-4e7d-9c1b-41407303bd66)<br/>School Data Sync (Plan 2) (500b6a2a-7a50-4f40-b5f9-160e5b8c2f48)<br/>SharePoint (Plan 2) for Education (63038b2c-28d0-45f6-bc36-33062963b498)<br/>Skype for Business Online (Plan 2) (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>Sway (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>To-Do (Plan 2) (c87f142c-d1e9-4363-8630-aaea9c4d9ae5)<br/>Whiteboard (Plan 2) (94a54592-cd8b-425e-87c6-97868b000b91)<br/>Yammer for Academic (2078e8df-cff6-4290-98cb-5408261a760a)<br/>Universal Print Without Seeding (b67adbaf-a096-42c9-967e-5a84edbe0086)<br/>Windows 10/11 Enterprise (e7c91390-7625-45be-94e0-e16907e03118)<br/>Microsoft Entra ID P1 (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>Common Data Service (4ff01e01-1ba7-4d71-8cf8-ce96c3bbcf14)<br/>Microsoft Azure Multi-Factor Authentication (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>Microsoft Defender for Cloud Apps Discovery (932ad362-64a8-4783-9106-97849a1a30b9)<br/>Microsoft Intune (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>Microsoft Intune for Education (da24caf9-af8e-485c-b7c8-e73336da2693)<br/>Power Apps for Office 365 (c68f8d98-5534-41c8-bf36-22fa496fa792)<br/>Power Automate for Office 365 (76846ad7-7776-4c40-a281-a386362dd1b9) |
| **Sign-out** | When a [SAML](../../identity-platform/single-sign-out-saml-protocol.md) or [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#send-a-sign-out-request) application directs the user to the logout endpoint, Microsoft Entra ID removes and invalidates the user's session from the browser. | Same as workforce.|
To stop collecting logs to your Log Analytics workspace, delete the diagnostic settings you created. You'll continue to incur charges for retaining log data you've already collected into your workspace. If you no longer need the monitoring data you've collected, you can delete your Log Analytics workspace and the resource group you created for Azure Monitor. Deleting the Log Analytics workspace deletes all data in the workspace and prevents you from incurring other data retention charges.
manager: dougeby
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
A Microsoft Entra documentation page was updated: Linkedin Employment Verification.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Configure Conditional Access user assignments in Microsoft Entra ID. Target specific users, groups, directory roles, and workload identities while avoiding administrator lockout with proper exclusions.
- Read the [Isolation scope for user-assigned managed identities](managed-identities-isolation-scope.md) concept article to understand the benefits and implications.
You can find the list of resources that have a system-assigned managed identity by using the following Azure CLI Command:
A Microsoft Entra documentation page was updated: Enable Managed Identities Regional Isolation.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
Learn about isolation scope for user-assigned managed identities and how it improves security and resilience.
Learn how to configure isolation scope for user-assigned managed identities to improve security and resilience.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.
Describes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.
author: MicrosoftGuyJFlo
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>
- *issuer*, *subject* are the key pieces of information needed to set up the trust relationship. When the Azure workload requests Microsoft identity platform to exchange the managed identity token for an Entra app access token, the *issuer* and *subject* values of the federated identity credential are checked against the `issuer` and `subject` claims provided in the Managed Identity token. If that validation check passes, Microsoft identity platform issues an access token to the external software workload.
manager: dougeby
manager: dougeby
author: kenwith
You must have multiple connectors to use connector groups. New connectors are automatically added to the **Default** connector group. For more information on installing connectors, see [configure connectors](how-to-configure-connectors.md).
manager: dougeby
Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
author: kenwith
For information about connectors, capacity planning, and how they stay up-to-date, see [Understand Microsoft Entra private network connectors](concept-connectors.md).
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
This article tracks the changes in each released version of the Global Secure Access client for macOS.
manager: dougeby
A Microsoft Entra documentation page was updated: Global Secure Access Administrator.
A Microsoft Entra documentation page was updated: Global Secure Access Administrator.
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
```
author: kenwith
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with an account which has the [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) and [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role activated.
Use Application discovery to detect the applications accessed by users and create separate private applications.
The Conditional Access optimization agent helps you ensure all users and applications are protected by Conditional Access policies. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
Learn how the Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot can help secure your organization.
Learn how to review and apply suggestions provided by the Security Copilot for Microsoft Entra optimization agent.
Learn about the Security Copilot for Microsoft Entra optimization agent metrics and events in audit logs.
Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate potential risky applications.
Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate identity-based security incident.
Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
The Security Administrator and Global Administrator roles have access to Security Copilot by default. You can assign Conditional Access Administrators with Security Copilot access. This authorization gives your Conditional Access Administrators the ability to use the agent as well. For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access).
Learn how to review and apply suggestions provided by the Security Copilot for Microsoft Entra optimization agent.
author: MicrosoftGuyJFlo