author: shlipsey3
August 2025: the confirmed Entra rollout is a November credential-UX refresh; the broader themes are previews and migration guidance
August was primarily a Microsoft Learn documentation period: 306 of 319 records were updates, alongside six new records, six removals, and one Message Center notice. That notice is the clearest product change: Microsoft Entra will roll out a refreshed credential enrollment and management experience in early November 2025, without changing functionality. The substantive documentation clusters covered the Conditional Access optimization agent preview, Group Source of Authority preview guidance, ID Protection risk-policy migration, and Apple/macOS registration troubleshooting. The supplied evidence does not support calling any August item a general-availability launch, retirement, or tenant-wide behavior change. The Mandatory Multifactor Authentication edits contain no substantive detail beyond authorship, and the removed entries provide no retirement evidence.
- Entra ID credential enrollment UX scheduled for an early-November refreshEntra ID
The sole Message Center notice says Microsoft Entra will introduce a refreshed credential enrollment and management experience in early November 2025. The stated improvements are usability and accessibility, with no functionality change, no required administrator action, and no compliance issue identified. Informing help-desk teams is the only recommended preparation.
- Conditional Access optimization agent documented as a phased-rollout previewEntra ID / Security Copilot
Updated Entra ID and Security Copilot material covers the Conditional Access optimization agent’s phased rollout, logs and metrics, and the process for reviewing and applying its suggestions. The feed does not establish general availability, automatic policy deployment, or tenant-wide rollout; the change is preview guidance for teams evaluating or operating the agent.
- ID Protection guidance directs legacy risk policies toward Conditional AccessID Protection / Conditional Access
Updated Microsoft Entra ID Protection guidance places sign-in-risk and user-risk policy configuration in Conditional Access and tells organizations using legacy risk policies to plan migration. This is security and configuration guidance, not evidence of an August enforcement change or a migration deadline. Affected tenants should review whether legacy policies remain in use and plan accordingly.
- Group Source of Authority documentation details a cloud-management previewEntra ID – Group Source of Authority
The Group Source of Authority preview material describes moving group management from AD DS to the cloud and covers prerequisites, cleanup, configuration, validation, rollback, auditing, preserved organizational units, and post-conversion self-service management. It is a preview workflow, not a general-availability announcement or evidence that tenant groups were changed. Evaluation teams can use the detail to assess operational readiness before changing their management model.
- Apple registration and macOS Platform SSO guidance adds concrete troubleshooting detailEntra ID – Apple device registration and Platform SSO
The August material documents a Secure Enclave requirement for new Apple device registrations and explains related re-registration behavior. Separate macOS Platform SSO troubleshooting identifies a macOS 15+ concurrency issue that can corrupt device configuration and trigger unexpected re-registration prompts. These are documentation and troubleshooting clarifications rather than evidence of a new August service behavior.
There is no broad tenant change to deploy based on this feed. Help-desk teams should be briefed about the November credential UX transition, while the notice says no administrator action is required. Tenants still using legacy ID Protection risk policies should review them and plan migration to Conditional Access; no deadline is supplied. Teams evaluating Group Source of Authority or the Conditional Access optimization agent should use the prerequisite, monitoring, validation, rollback, and suggestion-review guidance without treating either preview as generally available. Apple fleet and macOS Platform SSO administrators should review the Secure Enclave and macOS 15+ troubleshooting material for affected registrations.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
319 updates by product
Microsoft Entra ID
245 updatesGeneral
49Agent Optimization Chat
Updatedauthor: shlipsey3
Applies To External Only
Updatedauthor: garrodonnell
Connect Health Adfs
Updated| Requirement | Description |
Connect Health Agent Install
Updated| Requirement | Description |
Datawiza Configure Sha
UpdatedDatawiza integration includes the following components:
Tenant Installation Account
UpdatedBy default, the user who creates a Microsoft Entra tenant is automatically assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role.
Apple Sso Plugin
UpdatedIf for any reason Secure Enclave needs to be disabled, follow these recommended steps:
Groups Members Owners Search
UpdatedThese articles provide additional information on working with groups in Microsoft Entra ID.
Groups Naming Policy
UpdatedFor more information on Microsoft Entra groups, see:
Groups Restore Deleted
UpdatedFor more information on Microsoft Entra groups:
Prerequisites
Updated|-----|-----|
Manage App Consent Policies
Updated> [!WARNING]
:::image type="content" border="true" source="media/reference-domain-services-tls-enforcement/enable.png" alt-text="Screenshot that shows how to enable TLS 1.2 Only Mode for Domain Services.":::
Licensing Pim
Updatedauthor: barclayn
Places Administrator
Describes the Microsoft Entra built-in roles and permissions.
Single And Multi Tenant Apps
Updated| Audience | Single/multi-tenant | Who can sign in |
The following table explains the status for *isCloudManaged* and *onPremisesSyncEnabled* attributes after you convert the SOA of an object.
The following table explains the status for **isCloudManaged** and **onPremisesSyncEnabled** attributes after you convert the SOA of an object.
Intacct Tutorial
Updateda. In the **Identifier (Entity ID)** text box, type a unique identifier for your Sage Intacct company, with the following format:
Describes the deprecation of the app manifest (Azure AD Graph format) and attribute differences in the new format.
Manage app consent policies
Updatedzone_pivot_groups: enterprise-apps-minus-portal-aad
author: cilwerner
This article demonstrates how to customize claims in Microsoft Entra ID using the Custom Claims Policy.
This article describes how to customize claims in Microsoft Entra ID using PowerShell
Shows how to convert an existing single-tenant app to a multitenant app that can sign in a user from any Microsoft Entra tenant.
Reference documentation for custom claims providers
Learn how to configure a custom claims provider for a token issuance start event in Microsoft Entra ID. You can add custom claims to a token before it's issued.
author: cilwerner
author: cilwerner
author: cilwerner
Learn how to register your app in Microsoft Entra ID and configure it for single-tenant or multitenant use.
Learn how to restrict access to your apps registered in Microsoft Entra ID to a selected set of users.
Learn about the features and differences between single-tenant and multitenant apps in Microsoft Entra ID.
In this tutorial, you learn how to clean up the Azure resources allocated while creating the web app.
In this tutorial, you learn how to access data in Microsoft Graph from a web app for a signed-in user.
In this tutorial, you build a console daemon app for calling Microsoft Graph.
Apple Sso Plugin
Updated> For this flag to take effect, it must be applied to a new registration. It will not impact devices that have already been registered unless they re-register.
author: Justinha
Apple Sso Plugin
UpdatedIn March 2024, Microsoft announced that Microsoft Entra ID will transition from using Apple’s Keychain to Apple’s Secure Enclave for storing device identity keys. Beginning July 2025, new device registrations will require Secure Enclave for key storage.
Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID by using Group Source of Authority (SOA).
Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID by using Group Source of Authority (SOA), including prerequisites, setup, validation, and how to roll back.
manager: mwongerapk
author: Justinha
Gpad Prereqs
Updatedauthor: omondiatieno
author: Justinha
The goal for group analysis is to review and confirm which of the groups in a domain are:
author: Justinha
Fundamentals
48- Perform regular tests to verify that CRLs are downloadable and recognized correctly by Microsoft Entra ID.
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
```json
Find Tenant
Updated2. Browse to **Entra ID** > **Overview** > **Properties**.
author: justinha
Whats New Archive
UpdatedFor a more dynamic experience, you can now find the archive information in the Microsoft Entra admin center. To learn more, see [What's new (preview)](./whats-new-overview.md).
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
Recommendations
Updated
To ensure that the users can easily and securely access applications, your goal is to have a single set of access controls and policies across your on-premises and cloud environments.
When you target the Windows Azure Service Management API application, policy is enforced for tokens issued to a set of services closely bound to the portal. This grouping includes the application IDs of:
Microsoft Entra Conditional Access is a feature included in [Microsoft Entra ID P1 or P2](~/fundamentals/licensing.md). Customers with [Microsoft 365 Business licenses](/office365/servicedescriptions/office-365-service-descriptions-technet-library) also have access to Conditional Access features.
Groups Saasapps
Updated* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)
* [Manage access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)
Groups Troubleshooting
Updated* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)
For more information about Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).
This article introduces an administrator for Microsoft Entra ID, part of Microsoft Entra, to the relationship between top [identity management](~/fundamentals/what-is-entra.md?context=azure/active-directory/users-groups-roles/context/ugr-context) tasks for users in terms of their groups, licenses, deployed enterprise apps, and administrator roles. As your organization grows, you can use Microsoft Entra groups and administrator roles to:
Embrace cloud-first posture and convert Group Source of Authority (SOA) to the cloud (Preview)
UpdatedLearn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
Groups Change Type
Updated- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
Groups Create Rule
Updated- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
Groups Dynamic Membership
Updated- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
Whatis
RemovedA Microsoft Entra documentation page was updated: Whatis.
Bulk Operations
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/GroupsManagementMenuBlade) and in the left-hand navigation pane, select the **Groups** tab and then **All groups**.
A Microsoft Entra documentation page was updated: Scenario Azure First Sap Identity Integration.
Authentication Strengths
Updated- Microsoft Entra certificate-based authentication (Multifactor)
Agents
Updatedauthor: MicrosoftGuyJFlo
A Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
Zero Trust Protect Networks
RemovedA Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
A Microsoft Entra documentation page was updated: Zero Trust Protect Tenants.
Zero Trust Protect Tenants
RemovedA Microsoft Entra documentation page was updated: Zero Trust Protect Tenants.
A guide for architects and IT administrators on how to secure access to SAP platforms and applications
A Microsoft Entra documentation page was updated: Copilot Security Entra Responsible Ai Faq.
author: justinha
Copilot Security Entra
Updatedkeywords:
keywords:
Tokens and claims overview
UpdatedLearn how Microsoft Entra tenants publish metadata for authentication and authorization endpoints, scopes, and claims.
Use Microsoft Entra custom authentication extensions to customize your user's sign-in experience by using REST APIs or outbound webhooks.
Conceptual article describing the custom claims provider as part of the custom authentication extension framework.
Introduction to identity
UpdatedLearn the fundamental concepts of identity and access management (IAM). Learn about identities, resources, authentication, authorization, permissions, identity providers, and more.
In this tutorial, you learn how to build a web app by using Azure App Service, sign in users to the web app, call Azure Storage, and call Microsoft Graph.
- [Privileged Identity Management (PIM)](#privileged-identity-management-pim): Manage and monitor privileged access in your organization using natural language queries.
author: justinha
Whats New Archive
Updated**Type:** New feature
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory Domain Services (AD DS) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD DS to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.
author: justinha
Source Of Authority Overview
UpdatedLearn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
Whats New
Updated**Service category:** Group Management
author: justinha
Microsoft identity platform
48Whats New Docs
UpdatedWelcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
How to update your existing Node.js application to use the Microsoft Authentication Library (MSAL) for authentication and authorization instead of the Active Directory Authentication Library (ADAL).
Include file that explains the common steps you need to take for all public client apps when it comes to migration from ADAL to MSAL.
Learn about acquiring and caching tokens using MSAL.
Learn about the authentication flows supported by MSAL, such as authorization code, client credentials, and device code, to secure your apps effectively.
Understand the fundamentals of authentication, authorization, and how the Microsoft identity platform simplifies these processes for developers.
Learn about configuration options for public client and confidential client applications using the Microsoft Authentication Library (MSAL).
Developer guidance and scenarios for Microsoft Entra Conditional Access authentication context
Integrate
UpdatedLearn the benefits of integrating your application with the Microsoft identity platform, and get resources for features like simplified sign-in, identity management, multifactor authentication, and access control.
Learn about application scenarios for the Microsoft identity platform, including authenticating identities, acquiring tokens, and calling protected APIs.
List of client libraries and middleware compatible with the Microsoft identity platform. Use these libraries to add support for user sign-in (authentication) and protected web API access (authorization) to your applications.
Learn key terms used in Microsoft identity platform documentation, Microsoft Entra admin center, and authentication SDKs like the Microsoft Authentication Library (MSAL).
In this quickstart, you learn how to implement authentication with a Node.js web app and the Microsoft Authentication Library (MSAL) for Node.js.
Learn how to create and prepare an ASP.NET Core application for authentication with the Microsoft identity platform, and secure it with a self-signed certificate.
Learn about ID tokens used in the Microsoft identity platform.
In this quickstart, you learn how to register an application with the Microsoft identity platform.
Learn how to remove accounts from the token cache during global sign-out in web apps that call web APIs using the Microsoft identity platform.
Learn how to set up a Microsoft Entra test environment so you can test your application integrated with Microsoft identity platform. Evaluate whether you need a separate tenant for testing or if you can use your production tenant.
In this tutorial, you add support for signing-in users in a web app.
Claims reference with details on the claims included in access tokens issued by the Microsoft identity platform.
Learn about access tokens used in the Microsoft identity platform.
Learn about the sign-in flow of web, desktop, and mobile apps in Microsoft identity platform.
Application model
UpdatedLearn about the process of registering your application so it can integrate with the Microsoft identity platform.
The types of apps and scenarios supported by the Microsoft identity platform.
Learn how to build a web app that calls protected web APIs using the Microsoft identity platform. Explore options for ASP.NET Core, ASP.NET, Java, Node.js, and Python.
Explanation of claims challenges, claims requests, and client capabilities in the Microsoft identity platform.
Claims customization
UpdatedLearn about the custom claims policy and claims mapping policy types, which are used to modify the claims emitted in tokens in the Microsoft identity platform.
Configure optional claims
UpdatedLearn how to configure optional claims and attributes in access tokens issued by Microsoft identity platform; optional claims can add useful user information for your app.
Learn how to customize the claims issued by Microsoft identity platform in the JSON web token (JWT) token for enterprise applications.
As a developer, I want to learn how to acquire tokens for web APIs so that I can enable secure API calls in my application.
In this how-to guide, register a web API with the Microsoft identity platform and configure its scopes, exposing it to clients for permissions-based access to the API's resources.
Learn how to remove an application registered with the Microsoft identity platform.
How to: Restore or remove a recently deleted application with the Microsoft identity platform
UpdatedIn this how-to, you learn how to restore or permanently delete a recently deleted application registered with the Microsoft identity platform.
ID token claims reference
UpdatedLearn the details of the claims included in ID tokens issued by the Microsoft identity platform.
An overview of the Microsoft identity platform accounts for Android
author: cilwerner
Optional claims reference
UpdatedClaims reference with details on the optional claims that can be included in tokens in the Microsoft identity platform.
Learn how to build a protected web API and acquire all the information you need to register the app.
Quickstart V2 Nodejs Console
UpdatedIn this quickstart, you download and run a code sample that shows how a Node.js console application can get an access token and call an API protected by a Microsoft identity platform endpoint, using the app's own identity
Quickstart V2 Nodejs Desktop
UpdatedIn this quickstart, you learn how a Node.js Electron desktop application can sign-in users and get an access token to call an API protected by a Microsoft identity platform endpoint
Learn about refresh tokens that are used in the Microsoft identity platform.
Learn how to register a web app that calls web APIs. Configure client secrets and delegated permissions with the Microsoft identity platform.
Learn how to register a web app that signs in users using the Microsoft identity platform with step-by-step guidance for various frameworks.
Learn how to run automated integration tests as a user against APIs protected by the Microsoft identity platform. Use the Resource Owner Password Credential Grant (ROPC) auth flow to sign in as a user instead of automating the interactive sign-in prompt UI.
In this tutorial, you build an Electron desktop app that can sign in users and use the auth code flow to obtain an access token from the Microsoft identity platform and call the Microsoft Graph API.
Learn about the validation differences of various properties for different supported account types when registering your app with the Microsoft identity platform.
In this quickstart, you learn how to configure app registration and API permissions for a Web API, and how to grant admin consent to these permissions.
Web API that calls web APIs
UpdatedBuild a web API that calls other APIs using the Microsoft identity platform. Learn how to acquire tokens and make secure API calls.
Authentication
251. Create *reset-password/components/NewPasswordForm.tsx* file, then paste the code from [reset-password/components/NewPasswordForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/reset-password/components/NewPasswordForm.tsx). This component displays a form that collects a user's new password.
1. Create a *sign-up/components/CodeForm.tsx* file, then paste the code from [sign-up/components/CodeForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/sign-up/components/CodeForm.tsx). This component displays a form that collects a one-time passcode sent to the user. You require this form for either email with password or email with one-time passcode authentication method.
Choose Ad Authn
UpdatedIn today's world, threats are present 24 hours a day and come from everywhere. Implement the correct authentication method, and it will mitigate your security risks and protect your identities.
npx create-react-app reactspa --template typescript
1. Run `sudo apt remove --purge aadlogin` (Ubuntu/Debian), `sudo yum remove aadlogin` (RHEL), or `sudo zypper remove aadlogin` (openSUSE or SLES).
Connect Pta Quick Start
UpdatedMicrosoft Entra pass-through authentication allows your users to sign in to both on-premises and cloud-based applications by using the same passwords. Pass-through Authentication signs users in by validating their passwords directly against on-premises Active Directory.
To use the native authentication JavaScript SDK in your app, use your terminal to install it by using the following command:
Macos Psso
UpdatedmacOS Platform Single Sign-on (PSSO) is a new feature powered by Microsoft’s Enterprise SSO plug-in, Platform Credentials for macOS that enables users to sign in to Mac devices using their Microsoft Entra ID credentials. This feature provides benefits for admins by simplifying the sign-in process for users and reducing the number of passwords they need to remember. It also allows users to authenticate with Microsoft Entra ID with a smart card or hardware-bound key. This feature improves the end-user experience by not having to remember two separate passwords and diminishes the need for admins to manage the local account password.
author: justinha
Platform Single Sign-On (PSSO) for macOS devices is a feature that allows users to sign in to macOS devices using their Microsoft Entra credentials. This feature provides a seamless sign-in experience for users and helps organizations manage access to resources on macOS devices.
Howto Mfa Nps Extension
Updated* `https://onegetcdn.azureedge.net`
> [!div class="nextstepaction"]
> [!div class="nextstepaction"]
Staged rollout (SRO) is intended as a temporary testing mechanism for organizations with federated domains and allows to test cloud authentication with a group of users before [transitioning the entire domain from federated to managed](./migrate-from-federation-to-cloud-authentication.md#convert-domains-from-federated-to-managed). These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains from federated to managed.
Learn how to add a redirect URI to your application in Microsoft Entra to securely handle authentication tokens and enhance app security.
Learn to configure certificates, client secrets, and federated credentials in Microsoft Entra for secure app authentication.
Learn how to install identity packages and sign-in components to an ASP.NET Core application and enable user authentication.
Learn how to use the Authentication events trigger for Azure Functions library to create a trigger function that uses the token issuance start event.
Code snippet for a custom authentication extension using the Azure Functions client library in C#.
In this tutorial, you learn how to enable authentication for a web app running on Azure App Service. Limit access to the web app to users in your organization.
Authenticate Application Id
Updated- [Bring Your Own Application (BYOA)](#bring-your-own-application)
Learn how to build a web app that signs in/out users
Learn how to call the Microsoft Graph web API, sign-in, and display the profile information of the logged-in user
When a user signs in, a registration wizard helps them register the EAMs they're enabled to use. If they are enabled for other authentication methods, they might need to select **I want to set up a different method** > **External Auth methods** to proceed. They need to authenticate with their EAM provider to register the EAM in Microsoft Entra ID.
Default
UpdatedMicrosoft Entra Connect provides three options for application and certificate management:
Developer
19You need a license for PingAccess and Microsoft Entra ID. However, Microsoft Entra ID P1 or P2 subscriptions include a basic PingAccess license that covers up to 20 applications. If you need to publish more than 20 header-based applications, you can purchase more licenses from PingAccess.
The following articles discuss the different ways applications integrate with Microsoft Entra ID, and provide some guidance.
To assign a user account to an enterprise application:
Delete Application Portal
Updated- One of the following roles:
This article shows the new and updated documentation for the Microsoft Entra application management.
Learn how to add app roles to an application registered in Microsoft Entra ID. Assign users and groups to these roles, and receive them in the 'roles' claim in the token.
Learn about the relationship between application and service principal objects in Microsoft Entra ID.
Learn how to configure and set up a custom email provider with the One Time Passcode Send event type.
Learn how to build a web API that calls web APIs (app's code configuration)
Learn how to configure the code of a web app that calls web APIs
Learn how to build a web app that signs in users (code configuration)
Learn about multi-instancing, which is needed for configuring multiple instances of the same application within a tenant.
Describes directory extension attributes that are used for sending user data to applications in token claims.
Learn how to acquire a token for a web app that calls web APIs
What does it mean for an application to be added to Microsoft Entra ID and how do they get there?
Learn how to configure a web API to securely call downstream APIs by registering it as a confidential client application.
Describes the Microsoft Entra app manifest (Microsoft Graph format), which represents an application's identity configuration in a Microsoft Entra tenant.
Describes the Microsoft Entra app manifest, which represents an application's identity configuration in a Microsoft Entra tenant.
Learn how to configure and set up a custom email provider with the One Time Passcode Send event type.
Architecture
11Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)
Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.
Secure Fundamentals
UpdatedThese functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).
The following products and services appear in this guide:
The following products and services appear in this guide:
There are scenarios when it's necessary to allow access for a small, specific group.
The Microsoft Authentication Library (MSAL) enables application developers to acquire tokens in order to call secured web APIs. These web APIs can be the Microsoft Graph, other Microsoft APIs, third-party web APIs, or your own web API. MSAL supports multiple application architectures and platforms.
| - | - | - |
Standards
10ai-usage: ai-assisted
Hipaa Hitrust Controls
Updated|--|--|--|--|
Saml Tokens
Updated> |Name | `unique_name` |Provides a human readable value that identifies the subject of the token. This value is not guaranteed to be unique within a tenant and is designed to be used only for display purposes. | `<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">`<br>`<AttributeValue>[email protected]<AttributeValue>`|
Dmarcian Tutorial
Updated7. On the **Set up Single Sign-On with SAML** page, In the **SAML Signing Certificate** section, select copy button to copy **App Federation Metadata Url**, open it in a new browser tab, download the content of the page as an XML file and save it on your computer.
Configurable Token Lifetimes
UpdatedLearn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
Learn what identity and access management (IAM) is, why it's important, and how it works. Learn about authentication and authorization, single sign-on (SSO), and multifactor authentication (MFA). Learn about SAML, Open ID Connect (OIDC), and OAuth 2.0 and other authentication and authorization standards, tokens, and more.
Customize SAML token claims
UpdatedLearn how to customize the claims issued by Microsoft identity platform in the SAML token for enterprise applications.
Configure the role claim
UpdatedLearn how to configure the role claim issued in the SAML token for enterprise applications in Microsoft Entra ID.
Claims reference with details on the claims included in SAML 2.0 tokens issued by the Microsoft identity platform, including their JWT equivalents.
Troubleshooting
8There's a known concurrency issue on macOS 15+ (Sequoia) that can cause the PSSO device configuration to become corrupted. The device configuration can be corrupted by simultaneous updates from the system AppSSOAgent and AppSSODaemon processes. The corrupted configuration causes the operating system to trigger its re-registration remediation flow, resulting in unexpected registration prompts for users.
Troubleshoot and monitor your custom claims provider API. Learn how to use logging and Microsoft Entra sign-in logs to find errors and issues in your custom claims provider API.
Help Support Include
Updatedauthor: cilwerner
Purpose:
Updatedmanager: pmwongera
Purpose:
Updatedmanager: pmwongera
Purpose:
Updatedmanager: pmwongera
Purpose:
Updatedmanager: pmwongera
author: cilwerner
Provisioning
7S comprehensive guide to commonly used expression mapping functions when configuring SuccessFactors to Microsoft Entra ID user provisioning. These functions help transform and map data from SuccessFactors to create appropriate user attributes in Microsoft Entra ID.
A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.
- [Organizational unit (OU) assignment](#organizational-unit-ou-assignment)
A comprehensive guide to commonly used expression mapping functions when configuring SuccessFactors to Microsoft Entra ID user provisioning. These functions help transform and map data from SuccessFactors to create appropriate user attributes in Microsoft Entra ID.
Tutorial Group Provisioning
Updated:::image type="content" source="media/tutorial-group-provision/verify.png" alt-text="Screenshot of the newly provisioned group." lightbox="media/tutorial-group-provision/verify.png":::
Tutorial Group Provisioning
Updatedmanager: mwongerapk
Tutorial - Provision groups to Active Directory Domain Services by using Microsoft Entra Cloud Sync
Updatedmanager: mwongerapk
Security
7risklevel: High
UpdatedMicrosoft recommends that organizations have two cloud-only emergency access accounts permanently assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role. These accounts are highly privileged and aren't assigned to specific individuals. The accounts are limited to emergency or "break glass" scenarios where normal accounts can't be used or all other administrators are accidentally locked out.
Microsoft Entra will roll out a refreshed credential enrollment and management user experience in early November 2025, improving usability and accessibility without changing functionality. No action is required, but informing help desk teams is recommended to ease the transition. No compliance issues identified.
Identifier Uri Restrictions
Updated[Learn how to check if the protection has been enabled in your organization](https://aka.ms/check-identifier-uri-protection-state)
Learn how to build a protected web API and configure your application's code.
Verify that the API is only called by applications on behalf of users who have the right scopes and by daemon apps that have the right application roles.
Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
Monitoring
5Howto Use Recommendations
Updated
Learn about securing the business logic of your applications and APIs by validating claims in tokens.
Sla Performance
Updated| April | 99.999% | 99.999% | 99.999% | 99.999% | 99.999%*|
author: Justinha
author: Justinha
Governance
4Groups Lifecycle
UpdatedFor more information on Microsoft Entra groups, see:
Licensing Governance
Updatedauthor: billmath
author: justinha
author: justinha
Conditional Access
3A Microsoft Entra documentation page was updated: Conditional Access optimization agent phased rollout (preview).
author: shlipsey3
manager: pmwongera
Branding
1Learn about application branding guidelines for Microsoft identity platform.
Microsoft Entra ID Protection
24 updatesSecurity
10ZTLS
NewA Microsoft Entra documentation page was updated: ZTLS.
ZTLS
RemovedA Microsoft Entra documentation page was updated: ZTLS.
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Learn how notifications support your investigation activities.
author: shlipsey3
Deploy Identity Protection
UpdatedCreate a plan to deploy Microsoft Entra ID Protection.
author: shlipsey3
Fundamentals
8- Risk summary: summarize in natural language why the user risk level was elevated.
:::image type="content" source="./media/copilot-entra-risky-user-summarization/risky-user-details.png" alt-text="Screenshot that shows the ID Protection risky user summarization details.":::
Identity Protection Policies
UpdatedIdentifying risk-based Conditional Access policies
Identity Protection Risks
Updatedauthor: shlipsey3
keywords:
Workload Identity Risk
UpdatedWorkload identity risk in Microsoft Entra ID Protection
Identity Protection B2b
UpdatedLearn how to use Microsoft Entra ID Protection for B2B users to secure your organization. Discover benefits and steps to unblock accounts.
author: shlipsey3
Architecture
4Id Protection Guide Detect
UpdatedTo [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and User [risk policies](../id-protection/concept-identity-protection-policies.md) in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).
- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)
Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:
Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:
Authentication
1author: shlipsey3
Conditional Access
1Take a proactive look at the impact of risk-based Conditional Access policies in your environment.
Microsoft Entra ID Governance
17 updatesGovernance
12Pim How To Add Role To User
Updated- Select the role scope (in this case, administrative units)
Delegate Approvals My Access
UpdatedApproval delegation in My Access allows approvers to assign another individual to respond to access package approval requests on their behalf. This feature helps maintain productivity when approvers are unavailable due to leave, travel, or other commitments.
This article describes features and methods that allow you to pinpoint and select external identities so that you can review them and remove them from Microsoft Entra ID if they're no longer needed. The cloud makes it easier than ever to collaborate with internal or external users. When embracing Office 365, organizations start to see the proliferation of external identities (including guests), as users work together on data, documents, or digital workspaces such as Teams. Organizations need to balance, enabling collaboration and meeting security and governance requirements. Part of these efforts should include evaluating and cleaning out external users, who were invited for collaboration into your tenant, that originating from partner organizations, and removing them from your Microsoft Entra ID when they're no longer needed.
| | Description |
After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
1. Select **Request history** to confirm the request was canceled.
> [!IMPORTANT]
- For `Issuer`, ensure you included the slash after your Tenant ID
Pim How To Add Role To User
UpdatedFollow these steps to update or remove an existing role assignment.
We recommend requiring approval for activation of an eligible assignment. The approver doesn't have to have any roles. When you use this option, select at least one approver. We recommend that you select at least two approvers. If no specific approvers are selected, active Privileged Role Administrators/Global Administrators become the default approvers.
Entitlement Management Roles
Updated> [!NOTE]
Fundamentals
2Lifecycle Workflow Tasks
UpdatedAllows you to remove all access package assignments for users. For more information on access packages, see [What are access packages and what resources can I manage with them?](entitlement-management-overview.md#what-are-access-packages-and-what-resources-can-i-manage-with-them).
keywords:
Architecture
1* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
Authentication
1Feature Availability
Updated|| Entitlement management | ✅ |
Conditional Access
1Conditional Access Exclusion
UpdatedIn an ideal world, all users follow the access policies to secure access to your organization's resources. However, sometimes there are business cases that require you to make exceptions. This article goes over some examples of situations where exclusions could be necessary. You, as the IT administrator, can manage this task, avoid oversight of policy exceptions, and provide auditors with proof that these exceptions are reviewed regularly using Microsoft Entra access reviews.
Microsoft Entra External ID
11 updatesGeneral
5Applies To External Only
Updatedauthor: garrodonnell
**Applies to**:  Workforce tenants  External tenants ([learn more](/entra/external-id/tenant-configurations))
Applies To Workforce Only
Updatedauthor: garrodonnell
- Microsoft Azure global cloud and Microsoft Azure Government
Tenant Restrictions V2
UpdatedWhen you enable tenant restrictions on a Windows device, corporate proxies aren't required for policy enforcement. Devices don't need to be Microsoft Entra ID managed to enforce tenant restrictions v2. Domain-joined devices that are managed with Group Policy are also supported.
Developer
2Remove Client Secret
UpdatedIf you've a client secret already in place for your application, you need to delete it to avoid a malicious application for impersonating your application:
- [Supported features in workforce and external tenants](customers/how-to-add-enterprise-application.md)
Fundamentals
2Native authentication
UpdatedLearn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.
Cross Tenant Access Overview
UpdatedFor more information, see the [Configure Microsoft cloud settings for B2B collaboration](cross-cloud-settings.md) article.
Authentication
1* A user flow. For more information, see [create self-service sign-up user flows for apps in external tenants](../external-id/customers/how-to-user-flow-sign-up-sign-in-customers.md). Under **Identity providers**, select your preferred method of authentication, that's, **Email with password** or **Email one-time passcode**. For this code sample, you can include the following user attributes in your user flow as the app submit these attributes:
Security
1Transition to Microsoft Entra External ID for CIAM: Learn how to migrate your legacy customer identity solutions to enhance security, compliance, and scalability.
Microsoft Entra Internet Access
1 updateArchitecture
1Gsa Poc Private Access
UpdatedWhen customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).
Microsoft Entra Verified ID
1 updateSecurity
1manager: femila
Microsoft Entra Workload ID
6 updatesGeneral
41. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.
Managed identities glossary
Updated**Azure Instance Metadata Service (IMDS)**
Create a new Microsoft Entra app and service principal to manage access to resources with role-based access control in Azure Resource Manager.
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
Fundamentals
1Overview
UpdatedAt a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed identities.
Security
1Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
Microsoft Entra Global Secure Access
9 updatesGeneral
5Points Of Presence
UpdatedThe table lists the deployment status for the APAC region.
Enable Multi Geo
Updated:::image type="content" source="media/how-to-enable-multi-geo/multi-geo-support-diagram.svg" alt-text="Diagram that illustrates how Multi-Geo support routes traffic with Microsoft Entra private network connectors.":::
Macos Client Release History
UpdatedThis article tracks the changes in each released version of the Global Secure Access client for macOS.
Version History
UpdatedRole Based Permissions
Updatedmanager: dougeby
Security
2Transport Layer Security
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).
Transport Layer Security
Updated```openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCAchain.key -sha256 -days 370 -out rootCAchain.pem -subj "/C=US/ST=US/O=Self Signed/CN=Self Signed Root CA" -config openssl.cnf -extensions rootCA_ext```
Developer
1Application Discovery
UpdatedUse Application discovery to detect the applications accessed by users and create separate private applications.
Fundamentals
1- [Microsoft Entra ID license that includes Privileged Identity Management (PIM)](~/fundamentals/licensing.md)
Security Copilot + Entra
5 updatesFundamentals
4manager: pmwongera
Copilot Security Entra
UpdatedThis article introduces you to Security Copilot in Microsoft Entra.
manager: pmwongera
Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
Conditional Access
1manager: dougeby
