Month in brief

August 2025: the confirmed Entra rollout is a November credential-UX refresh; the broader themes are previews and migration guidance

August was primarily a Microsoft Learn documentation period: 306 of 319 records were updates, alongside six new records, six removals, and one Message Center notice. That notice is the clearest product change: Microsoft Entra will roll out a refreshed credential enrollment and management experience in early November 2025, without changing functionality. The substantive documentation clusters covered the Conditional Access optimization agent preview, Group Source of Authority preview guidance, ID Protection risk-policy migration, and Apple/macOS registration troubleshooting. The supplied evidence does not support calling any August item a general-availability launch, retirement, or tenant-wide behavior change. The Mandatory Multifactor Authentication edits contain no substantive detail beyond authorship, and the removed entries provide no retirement evidence.

  • Entra ID credential enrollment UX scheduled for an early-November refreshEntra ID

    The sole Message Center notice says Microsoft Entra will introduce a refreshed credential enrollment and management experience in early November 2025. The stated improvements are usability and accessibility, with no functionality change, no required administrator action, and no compliance issue identified. Informing help-desk teams is the only recommended preparation.

  • Conditional Access optimization agent documented as a phased-rollout previewEntra ID / Security Copilot

    Updated Entra ID and Security Copilot material covers the Conditional Access optimization agent’s phased rollout, logs and metrics, and the process for reviewing and applying its suggestions. The feed does not establish general availability, automatic policy deployment, or tenant-wide rollout; the change is preview guidance for teams evaluating or operating the agent.

  • ID Protection guidance directs legacy risk policies toward Conditional AccessID Protection / Conditional Access

    Updated Microsoft Entra ID Protection guidance places sign-in-risk and user-risk policy configuration in Conditional Access and tells organizations using legacy risk policies to plan migration. This is security and configuration guidance, not evidence of an August enforcement change or a migration deadline. Affected tenants should review whether legacy policies remain in use and plan accordingly.

  • Group Source of Authority documentation details a cloud-management previewEntra ID – Group Source of Authority

    The Group Source of Authority preview material describes moving group management from AD DS to the cloud and covers prerequisites, cleanup, configuration, validation, rollback, auditing, preserved organizational units, and post-conversion self-service management. It is a preview workflow, not a general-availability announcement or evidence that tenant groups were changed. Evaluation teams can use the detail to assess operational readiness before changing their management model.

  • Apple registration and macOS Platform SSO guidance adds concrete troubleshooting detailEntra ID – Apple device registration and Platform SSO

    The August material documents a Secure Enclave requirement for new Apple device registrations and explains related re-registration behavior. Separate macOS Platform SSO troubleshooting identifies a macOS 15+ concurrency issue that can corrupt device configuration and trigger unexpected re-registration prompts. These are documentation and troubleshooting clarifications rather than evidence of a new August service behavior.

For Entra administrators

There is no broad tenant change to deploy based on this feed. Help-desk teams should be briefed about the November credential UX transition, while the notice says no administrator action is required. Tenants still using legacy ID Protection risk policies should review them and plan migration to Conditional Access; no deadline is supplied. Teams evaluating Group Source of Authority or the Conditional Access optimization agent should use the prerequisite, monitoring, validation, rollback, and suggestion-review guidance without treating either preview as generally available. Apple fleet and macOS Platform SSO administrators should review the Secure Enclave and macOS 15+ troubleshooting material for affected registrations.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

319 updates by product

General

49

Tenant Installation Account

Updated

By default, the user who creates a Microsoft Entra tenant is automatically assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role.

22 August 2025

Apple Sso Plugin

Updated

If for any reason Secure Enclave needs to be disabled, follow these recommended steps:

21 August 2025

Groups Members Owners Search

Updated

These articles provide additional information on working with groups in Microsoft Entra ID.

21 August 2025

Domain Services Tls Enforcement

Updated

:::image type="content" border="true" source="media/reference-domain-services-tls-enforcement/enable.png" alt-text="Screenshot that shows how to enable TLS 1.2 Only Mode for Domain Services.":::

16 August 2025

Group Source Of Authority Configure

Updated

The following table explains the status for *isCloudManaged* and *onPremisesSyncEnabled* attributes after you convert the SOA of an object.

12 August 2025

Group Source Of Authority Configure

Updated

The following table explains the status for **isCloudManaged** and **onPremisesSyncEnabled** attributes after you convert the SOA of an object.

8 August 2025

Intacct Tutorial

Updated

a. In the **Identifier (Entity ID)** text box, type a unique identifier for your Sage Intacct company, with the following format:

8 August 2025

Tutorial - Clean up resources

Updated

In this tutorial, you learn how to clean up the Azure resources allocated while creating the web app.

7 August 2025

Apple Sso Plugin

Updated

> For this flag to take effect, it must be applied to a new registration. It will not impact devices that have already been registered unless they re-register.

6 August 2025

Apple Sso Plugin

Updated

In March 2024, Microsoft announced that Microsoft Entra ID will transition from using Apple’s Keychain to Apple’s Secure Enclave for storing device identity keys. Beginning July 2025, new device registrations will require Secure Enclave for key storage.

5 August 2025

Fundamentals

48

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

29 August 2025

Find Tenant

Updated

2. Browse to **Entra ID** > **Overview** > **Properties**.

29 August 2025

Whats New Archive

Updated

For a more dynamic experience, you can now find the archive information in the Microsoft Entra admin center. To learn more, see [What's new (preview)](./whats-new-overview.md).

26 August 2025

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

26 August 2025

Recommendations

Updated

![Screenshot of the Overview page of the tenant with the Recommendations option highlighted.](./media/overview-recommendations/recommendations-overview.png)

23 August 2025

Migrate Adfs Apps Phases Overview

Updated

To ensure that the users can easily and securely access applications, your goal is to have a single set of access controls and policies across your on-premises and cloud environments.

22 August 2025

Conditional Access Cloud Apps

Updated

When you target the Windows Azure Service Management API application, policy is enforced for tokens issued to a set of services closely bound to the portal. This grouping includes the application IDs of:

22 August 2025

V2 Conditional Access Dev Guide

Updated

Microsoft Entra Conditional Access is a feature included in [Microsoft Entra ID P1 or P2](~/fundamentals/licensing.md). Customers with [Microsoft 365 Business licenses](/office365/servicedescriptions/office-365-service-descriptions-technet-library) also have access to Conditional Access features.

22 August 2025

Groups Saasapps

Updated

* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)

22 August 2025

Groups Self Service Management

Updated

* [Manage access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)

22 August 2025

Groups Troubleshooting

Updated

* [Managing access to resources with Microsoft Entra groups](~/fundamentals/concept-learn-about-groups.md)

22 August 2025

Howto Vm Sign In Azure Ad Windows

Updated

For more information about Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).

22 August 2025

What is enterprise user management?

Updated

This article introduces an administrator for Microsoft Entra ID, part of Microsoft Entra, to the relationship between top [identity management](~/fundamentals/what-is-entra.md?context=azure/active-directory/users-groups-roles/context/ugr-context) tasks for users in terms of their groups, licenses, deployed enterprise apps, and administrator roles. As your organization grows, you can use Microsoft Entra groups and administrator roles to:

22 August 2025

Groups Change Type

Updated

- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)

21 August 2025

Groups Create Rule

Updated

- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)

21 August 2025

Groups Dynamic Membership

Updated

- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)

21 August 2025

Whatis

Removed

A Microsoft Entra documentation page was updated: Whatis.

21 August 2025

Bulk Operations

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/GroupsManagementMenuBlade) and in the left-hand navigation pane, select the **Groups** tab and then **All groups**.

20 August 2025

Agents

Updated

author: MicrosoftGuyJFlo

13 August 2025

Tokens and claims overview

Updated

Learn how Microsoft Entra tenants publish metadata for authentication and authorization endpoints, scopes, and claims.

7 August 2025

Custom claims provider overview

Updated

Conceptual article describing the custom claims provider as part of the custom authentication extension framework.

7 August 2025

Introduction to identity

Updated

Learn the fundamental concepts of identity and access management (IAM). Learn about identities, resources, authentication, authorization, permissions, identity providers, and more.

7 August 2025

Copilot Entra Security Scenarios

Updated

- [Privileged Identity Management (PIM)](#privileged-identity-management-pim): Manage and monitor privileged access in your organization using natural language queries.

6 August 2025

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

5 August 2025

Guidance for using Group Source of Authority (SOA) (Preview)

Updated

Managing groups across hybrid environments is essential for organizations that transition from on-premises Active Directory Domain Services (AD DS) to the cloud. Group Source of Authority (SOA) in Microsoft Entra ID enables you to transfer group management from AD DS to the cloud, providing greater flexibility, modern governance, and streamlined administration. This guidance explains how to use Group SOA to manage, provision, restore, and roll back groups in hybrid and cloud environments. It explains best practices to clean up groups, convert group management, and ensure secure, efficient access control as you modernize your identity infrastructure.

2 August 2025

Source Of Authority Overview

Updated

Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.

2 August 2025

Whats New

Updated

**Service category:** Group Management

2 August 2025

Microsoft identity platform

48

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

9 August 2025

Migrate your Node.js application from ADAL to MSAL

Updated

How to update your existing Node.js application to use the Microsoft Authentication Library (MSAL) for authentication and authorization instead of the Active Directory Authentication Library (ADAL).

7 August 2025

Msal Net Adoption Steps Public Clients

Updated

Include file that explains the common steps you need to take for all public client apps when it comes to migration from ADAL to MSAL.

7 August 2025

Authentication flow support in MSAL

Updated

Learn about the authentication flows supported by MSAL, such as authorization code, client credentials, and device code, to secure your apps effectively.

7 August 2025

Authentication vs. authorization

Updated

Understand the fundamentals of authentication, authorization, and how the Microsoft identity platform simplifies these processes for developers.

7 August 2025

Client application configuration (MSAL)

Updated

Learn about configuration options for public client and confidential client applications using the Microsoft Authentication Library (MSAL).

7 August 2025

Integrate

Updated

Learn the benefits of integrating your application with the Microsoft identity platform, and get resources for features like simplified sign-in, identity management, multifactor authentication, and access control.

7 August 2025

Microsoft identity platform authentication libraries

Updated

List of client libraries and middleware compatible with the Microsoft identity platform. Use these libraries to add support for user sign-in (authentication) and protected web API access (authorization) to your applications.

7 August 2025

Microsoft Identity Platform Glossary

Updated

Learn key terms used in Microsoft identity platform documentation, Microsoft Entra admin center, and authentication SDKs like the Microsoft Authentication Library (MSAL).

7 August 2025

Quickstart V2 Nodejs Webapp Msal

Updated

In this quickstart, you learn how to implement authentication with a Node.js web app and the Microsoft Authentication Library (MSAL) for Node.js.

7 August 2025

Set up a test environment for your app

Updated

Learn how to set up a Microsoft Entra test environment so you can test your application integrated with Microsoft identity platform. Evaluate whether you need a separate tenant for testing or if you can use your production tenant.

7 August 2025

Access token claims reference

Updated

Claims reference with details on the claims included in access tokens issued by the Microsoft identity platform.

7 August 2025

Application model

Updated

Learn about the process of registering your application so it can integrate with the Microsoft identity platform.

7 August 2025

Call a web API from a web app

Updated

Learn how to build a web app that calls protected web APIs using the Microsoft identity platform. Explore options for ASP.NET Core, ASP.NET, Java, Node.js, and Python.

7 August 2025

Claims customization

Updated

Learn about the custom claims policy and claims mapping policy types, which are used to modify the claims emitted in tokens in the Microsoft identity platform.

7 August 2025

Configure optional claims

Updated

Learn how to configure optional claims and attributes in access tokens issued by Microsoft identity platform; optional claims can add useful user information for your app.

7 August 2025

ID token claims reference

Updated

Learn the details of the claims included in ID tokens issued by the Microsoft identity platform.

7 August 2025

Optional claims reference

Updated

Claims reference with details on the optional claims that can be included in tokens in the Microsoft identity platform.

7 August 2025

Quickstart V2 Nodejs Console

Updated

In this quickstart, you download and run a code sample that shows how a Node.js console application can get an access token and call an API protected by a Microsoft identity platform endpoint, using the app's own identity

7 August 2025

Quickstart V2 Nodejs Desktop

Updated

In this quickstart, you learn how a Node.js Electron desktop application can sign-in users and get an access token to call an API protected by a Microsoft identity platform endpoint

7 August 2025

Register a web app that calls web APIs

Updated

Learn how to register a web app that calls web APIs. Configure client secrets and delegated permissions with the Microsoft identity platform.

7 August 2025

Register a web app that signs in users

Updated

Learn how to register a web app that signs in users using the Microsoft identity platform with step-by-step guidance for various frameworks.

7 August 2025

Run automated integration tests

Updated

Learn how to run automated integration tests as a user against APIs protected by the Microsoft identity platform. Use the Resource Owner Password Credential Grant (ROPC) auth flow to sign in as a user instead of automating the interactive sign-in prompt UI.

7 August 2025

Web API that calls web APIs

Updated

Build a web API that calls other APIs using the Microsoft identity platform. Learn how to acquire tokens and make secure API calls.

7 August 2025

Authentication

25

Tutorial Native Authentication Single Page App React Sdk Reset Password

Updated

1. Create *reset-password/components/NewPasswordForm.tsx* file, then paste the code from [reset-password/components/NewPasswordForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/reset-password/components/NewPasswordForm.tsx). This component displays a form that collects a user's new password.

27 August 2025

Tutorial Native Authentication Single Page App React Sdk Sign Up

Updated

1. Create a *sign-up/components/CodeForm.tsx* file, then paste the code from [sign-up/components/CodeForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/sign-up/components/CodeForm.tsx). This component displays a form that collects a one-time passcode sent to the user. You require this form for either email with password or email with one-time passcode authentication method.

27 August 2025

Choose Ad Authn

Updated

In today's world, threats are present 24 hours a day and come from everywhere. Implement the correct authentication method, and it will mitigate your security risks and protect your identities.

22 August 2025

Howto Vm Sign In Azure Ad Linux

Updated

1. Run `sudo apt remove --purge aadlogin` (Ubuntu/Debian), `sudo yum remove aadlogin` (RHEL), or `sudo zypper remove aadlogin` (openSUSE or SLES).

21 August 2025

Connect Pta Quick Start

Updated

Microsoft Entra pass-through authentication allows your users to sign in to both on-premises and cloud-based applications by using the same passwords. Pass-through Authentication signs users in by validating their passwords directly against on-premises Active Directory.

20 August 2025

Macos Psso

Updated

macOS Platform Single Sign-on (PSSO) is a new feature powered by Microsoft’s Enterprise SSO plug-in, Platform Credentials for macOS that enables users to sign in to Mac devices using their Microsoft Entra ID credentials. This feature provides benefits for admins by simplifying the sign-in process for users and reducing the number of passwords they need to remember. It also allows users to authenticate with Microsoft Entra ID with a smart card or hardware-bound key. This feature improves the end-user experience by not having to remember two separate passwords and diminishes the need for admins to manage the local account password.

14 August 2025

Integrate macOS Platform Single Sign-On (PSSO) into your MDM solution

Updated

Platform Single Sign-On (PSSO) for macOS devices is a feature that allows users to sign in to macOS devices using their Microsoft Entra credentials. This feature provides a seamless sign-in experience for users and helps organizations manage access to resources on macOS devices.

14 August 2025

Migrate to cloud authentication using Staged Rollout

Updated

Staged rollout (SRO) is intended as a temporary testing mechanism for organizations with federated domains and allows to test cloud authentication with a group of users before [transitioning the entire domain from federated to managed](./migrate-from-federation-to-cloud-authentication.md#convert-domains-from-federated-to-managed). These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains from federated to managed.

7 August 2025

Authentication External Method Manage

Updated

When a user signs in, a registration wizard helps them register the EAMs they're enabled to use. If they are enabled for other authentication methods, they might need to select **I want to set up a different method** > **External Auth methods** to proceed. They need to authenticate with their EAM provider to register the EAM in Microsoft Entra ID.

6 August 2025

Default

Updated

Microsoft Entra Connect provides three options for application and certificate management:

2 August 2025

Developer

19

Application Proxy Ping Access Publishing Guide

Updated

You need a license for PingAccess and Microsoft Entra ID. However, Microsoft Entra ID P1 or P2 subscriptions include a basic PingAccess license that covers up to 20 applications. If you need to publish more than 20 header-based applications, you can purchase more licenses from PingAccess.

22 August 2025

Plan An Application Integration

Updated

The following articles discuss the different ways applications integrate with Microsoft Entra ID, and provide some guidance.

22 August 2025

Add app roles and get them from a token

Updated

Learn how to add app roles to an application registered in Microsoft Entra ID. Assign users and groups to these roles, and receive them in the 'roles' claim in the token.

7 August 2025

Configure app multi-instancing

Updated

Learn about multi-instancing, which is needed for configuring multiple instances of the same application within a tenant.

7 August 2025

Architecture

11

What is the Microsoft Entra architecture?

Updated

Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)

22 August 2025

Microsoft Entra deployment plans

Updated

Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.

22 August 2025

Secure Fundamentals

Updated

These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).

22 August 2025

Overview of the Microsoft Authentication Library (MSAL)

Updated

The Microsoft Authentication Library (MSAL) enables application developers to acquire tokens in order to call secured web APIs. These web APIs can be the Microsoft Graph, other Microsoft APIs, third-party web APIs, or your own web API. MSAL supports multiple application architectures and platforms.

7 August 2025

Standards

10

Saml Tokens

Updated

> |Name | `unique_name` |Provides a human readable value that identifies the subject of the token. This value is not guaranteed to be unique within a tenant and is designed to be used only for display purposes. | `<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">`<br>`<AttributeValue>[email protected]<AttributeValue>`|

13 August 2025

Dmarcian Tutorial

Updated

7. On the **Set up Single Sign-On with SAML** page, In the **SAML Signing Certificate** section, select copy button to copy **App Federation Metadata Url**, open it in a new browser tab, download the content of the page as an XML file and save it on your computer.

8 August 2025

Configurable Token Lifetimes

Updated

Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.

7 August 2025

What is identity and access management (IAM)?

Updated

Learn what identity and access management (IAM) is, why it's important, and how it works. Learn about authentication and authorization, single sign-on (SSO), and multifactor authentication (MFA). Learn about SAML, Open ID Connect (OIDC), and OAuth 2.0 and other authentication and authorization standards, tokens, and more.

7 August 2025

Customize SAML token claims

Updated

Learn how to customize the claims issued by Microsoft identity platform in the SAML token for enterprise applications.

7 August 2025

Configure the role claim

Updated

Learn how to configure the role claim issued in the SAML token for enterprise applications in Microsoft Entra ID.

7 August 2025

SAML 2.0 token claims reference

Updated

Claims reference with details on the claims included in SAML 2.0 tokens issued by the Microsoft identity platform, including their JWT equivalents.

7 August 2025

Troubleshooting

8

Troubleshoot Macos Platform Single Sign On Extension

Updated

There's a known concurrency issue on macOS 15+ (Sequoia) that can cause the PSSO device configuration to become corrupted. The device configuration can be corrupted by simultaneous updates from the system AppSSOAgent and AppSSODaemon processes. The corrupted configuration causes the operating system to trigger its re-registration remediation flow, resulting in unexpected registration prompts for users.

14 August 2025

Troubleshoot a custom authentication extension

Updated

Troubleshoot and monitor your custom claims provider API. Learn how to use logging and Microsoft Entra sign-in logs to find errors and issues in your custom claims provider API.

7 August 2025

Purpose:

Updated

manager: pmwongera

7 August 2025

Purpose:

Updated

manager: pmwongera

7 August 2025

Purpose:

Updated

manager: pmwongera

7 August 2025

Purpose:

Updated

manager: pmwongera

7 August 2025

Provisioning

7

Workday expression mapping functions for Microsoft Entra ID provisioning

New

A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.

13 August 2025

Tutorial Group Provisioning

Updated

:::image type="content" source="media/tutorial-group-provision/verify.png" alt-text="Screenshot of the newly provisioned group." lightbox="media/tutorial-group-provision/verify.png":::

8 August 2025

Security

7

risklevel: High

Updated

Microsoft recommends that organizations have two cloud-only emergency access accounts permanently assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role. These accounts are highly privileged and aren't assigned to specific individuals. The accounts are limited to emergency or "break glass" scenarios where normal accounts can't be used or all other administrators are accidentally locked out.

29 August 2025

Identifier Uri Restrictions

Updated

[Learn how to check if the protection has been enabled in your organization](https://aka.ms/check-identifier-uri-protection-state)

13 August 2025

Monitoring

5

Howto Use Recommendations

Updated

![Screenshot of the list of recommendations.](media/howto-use-recommendations/recommendations-list.png)

23 August 2025

Sla Performance

Updated

| April | 99.999% | 99.999% | 99.999% | 99.999% | 99.999%*|

5 August 2025

Governance

4

Groups Lifecycle

Updated

For more information on Microsoft Entra groups, see:

21 August 2025

Conditional Access

3

Branding

1

Security

10

ZTLS

New

A Microsoft Entra documentation page was updated: ZTLS.

9 August 2025

ZTLS

Removed

A Microsoft Entra documentation page was updated: ZTLS.

9 August 2025

Fundamentals

8

Copilot Entra Security Scenarios

Updated

:::image type="content" source="./media/copilot-entra-risky-user-summarization/risky-user-details.png" alt-text="Screenshot that shows the ID Protection risky user summarization details.":::

9 August 2025

Identity Protection B2b

Updated

Learn how to use Microsoft Entra ID Protection for B2B users to secure your organization. Discover benefits and steps to unblock accounts.

7 August 2025

Architecture

4

Id Protection Guide Detect

Updated

To [configure and enable risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md), factor Sign-in risk and User [risk policies](../id-protection/concept-identity-protection-policies.md) in Microsoft Entra Conditional Access. If you enabled legacy risk policies in Microsoft Entra ID Protection, plan to [migrate them to Conditional Access](../id-protection/howto-identity-protection-configure-risk-policies.md#migrate-to-conditional-access).

23 August 2025

Id Protection Guide Remediate

Updated

- [Use real-time risk detection to grant access to protected resources](id-protection-guide-detect.md)

23 August 2025

Id Protection Guide Introduction

Updated

Understanding the products and their core concepts is the first step toward running a successful PoC. Start with learning about the product features in this section:

23 August 2025

Id Protection Guide Investigate

Updated

Detect and investigate identity threats in the Microsoft Entra admin center or with Microsoft Graph APIs:

23 August 2025

Authentication

1

Conditional Access

1

Governance

12

Delegate Approvals My Access

Updated

Approval delegation in My Access allows approvers to assign another individual to respond to access package approval requests on their behalf. This feature helps maintain productivity when approvers are unavailable due to leave, travel, or other commitments.

27 August 2025

Access Reviews External Users

Updated

This article describes features and methods that allow you to pinpoint and select external identities so that you can review them and remove them from Microsoft Entra ID if they're no longer needed. The cloud makes it easier than ever to collaborate with internal or external users. When embracing Office 365, organizations start to see the proliferation of external identities (including guests), as users work together on data, documents, or digital workspaces such as Teams. Organizations need to balance, enabling collaboration and meeting security and governance requirements. Part of these efforts should include evaluating and cleaning out external users, who were invited for collaboration into your tenant, that originating from partner organizations, and removing them from your Microsoft Entra ID when they're no longer needed.

22 August 2025

Entitlement Management Access Package Approval Policy

Updated

After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).

21 August 2025

Entitlement Management Access Package Approval Policy

Updated

After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).

20 August 2025

Pim How To Change Default Settings

Updated

We recommend requiring approval for activation of an eligible assignment. The approver doesn't have to have any roles. When you use this option, select at least one approver. We recommend that you select at least two approvers. If no specific approvers are selected, active Privileged Role Administrators/Global Administrators become the default approvers.

14 August 2025

Fundamentals

2

Lifecycle Workflow Tasks

Updated

Allows you to remove all access package assignments for users. For more information on access packages, see [What are access packages and what resources can I manage with them?](entitlement-management-overview.md#what-are-access-packages-and-what-resources-can-i-manage-with-them).

30 August 2025

Architecture

1

Authentication

1

Conditional Access

1

Conditional Access Exclusion

Updated

In an ideal world, all users follow the access policies to secure access to your organization's resources. However, sometimes there are business cases that require you to make exceptions. This article goes over some examples of situations where exclusions could be necessary. You, as the IT administrator, can manage this task, avoid oversight of policy exceptions, and provide auditors with proof that these exceptions are reviewed regularly using Microsoft Entra access reviews.

22 August 2025

General

5

Applies To Workforce External

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to workforce tenants.](../media/common/applies-to-yes.png) Workforce tenants ![Green circle with a white check mark symbol that indicates the following content applies to external tenants.](../media/common/applies-to-yes.png) External tenants ([learn more](/entra/external-id/tenant-configurations))

26 August 2025

Tenant Restrictions V2

Updated

When you enable tenant restrictions on a Windows device, corporate proxies aren't required for policy enforcement. Devices don't need to be Microsoft Entra ID managed to enforce tenant restrictions v2. Domain-joined devices that are managed with Group Policy are also supported.

7 August 2025

Developer

2

Remove Client Secret

Updated

If you've a client secret already in place for your application, you need to delete it to avoid a malicious application for impersonating your application:

7 August 2025

External ID in external tenants

Updated

- [Supported features in workforce and external tenants](customers/how-to-add-enterprise-application.md)

2 August 2025

Fundamentals

2

Native authentication

Updated

Learn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.

13 August 2025

Cross Tenant Access Overview

Updated

For more information, see the [Configure Microsoft cloud settings for B2B collaboration](cross-cloud-settings.md) article.

7 August 2025

Authentication

1

Quickstart Native Authentication Single Page App Sdk Sign In

Updated

* A user flow. For more information, see [create self-service sign-up user flows for apps in external tenants](../external-id/customers/how-to-user-flow-sign-up-sign-in-customers.md). Under **Identity providers**, select your preferred method of authentication, that's, **Email with password** or **Email one-time passcode**. For this code sample, you can include the following user attributes in your user flow as the app submit these attributes:

9 August 2025

Security

1

Architecture

1

Gsa Poc Private Access

Updated

When customers deploy the 3P solution, they might want to use Microsoft Entra Private Access while using other solutions for internet access. For guidance, see [Partner ecosystem overview](../global-secure-access/partner-ecosystems-overview.md).

29 August 2025

Security

1

General

4

Managed Identity Regional Move

Updated

1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.

21 August 2025

Fundamentals

1

Overview

Updated

At a high level, there are two types of identities: human and machine/non-human identities. Machine / non-human identities consist of device and workload identities. In Microsoft Entra, workload identities are applications, service principals, and managed identities.

20 August 2025

Security

1

General

5

Points Of Presence

Updated

The table lists the deployment status for the APAC region.

29 August 2025

Enable Multi Geo

Updated

:::image type="content" source="media/how-to-enable-multi-geo/multi-geo-support-diagram.svg" alt-text="Diagram that illustrates how Multi-Geo support routes traffic with Microsoft Entra private network connectors.":::

20 August 2025

Macos Client Release History

Updated

This article tracks the changes in each released version of the Global Secure Access client for macOS.

20 August 2025

Security

2

Transport Layer Security

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).

19 August 2025

Transport Layer Security

Updated

```openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCAchain.key -sha256 -days 370 -out rootCAchain.pem -subj "/C=US/ST=US/O=Self Signed/CN=Self Signed Root CA" -config openssl.cnf -extensions rootCA_ext```

13 August 2025

Developer

1

Application Discovery

Updated

Use Application discovery to detect the applications accessed by users and create separate private applications.

13 August 2025

Fundamentals

1

Configure Global Access With Pim

Updated

- [Microsoft Entra ID license that includes Privileged Identity Management (PIM)](~/fundamentals/licensing.md)

22 August 2025

Fundamentals

4

Conditional Access

1