Month in brief

September 2025: Azure DevOps Conditional Access changed, Azure-resource MFA is next, and cross-cloud sync is marked opt-in preview

September was primarily a Microsoft Learn maintenance month rather than a broad Entra launch cycle: 1,017 of 1,030 records were updates, with four new records, five removals, and four Message Center notices. The most consequential exceptions were the Azure DevOps Conditional Access targeting change, scheduled MFA enforcement for Azure resource management, a Microsoft Authenticator sign-in UX change, and the late-period cross-cloud synchronization notice. The specifically described new Global Secure Access pages were test-environment PowerShell samples for TLS certificates, not evidence of a product launch. The five removals also contain no detail that supports calling a capability retired. A separate Entra ID Free notice says the no-cost subscription will appear in portals for tenant-ownership tracking without changing billing or functionality.

  • Azure DevOps sign-ins moved off the Azure Resource Manager Conditional Access pathMicrosoft Entra ID — Conditional Access

    The Microsoft Entra notice said Conditional Access would stop being applied via Azure Resource Manager for Azure DevOps sign-ins starting 2 September, with full enforcement by 18 September. Policies must explicitly include the Azure DevOps application, App ID 499b84ac-1321-427f-aa17-267ca6975798. This is a changed targeting and enforcement behavior, not a feature launch.

  • Azure resource-management MFA enforcement is scheduled for 1 OctoberMicrosoft Entra MFA / Azure resource management

    The Message Center notice says MFA will be enforced for all Azure resource-management actions from 1 October 2025, with a postponement option until July 2026. It calls out enabling MFA, updating Azure CLI and PowerShell, and using Azure Policy to assess impact. Gallatin customers are advised to implement MFA without enforcement. This is scheduled security enforcement, not an Entra feature release.

  • Microsoft Authenticator removes number entry for same-device confirmationsMicrosoft Authenticator / Microsoft Entra ID authentication

    During the stated late-September-to-mid-October rollout, same-device sign-ins will require only a Yes/No confirmation instead of number entry. The first-run experience will also prioritize Microsoft Entra accounts and highlight QR-code scanning. The notice says no administrator action is required; this is a client UX behavior change rather than a change to Conditional Access semantics.

  • Cross-cloud synchronization is described as an opt-in public previewMicrosoft Entra cross-cloud synchronization

    The week-of-29-September briefing describes a 3 October Message Center notice for Microsoft Entra cross-cloud synchronization, covering user lifecycle management across Microsoft commercial, US Government, and China clouds. The notice calls it public preview and opt-in while also listing general availability for late September to early October, so the supplied evidence does not support treating it as an unqualified GA release. The summary refers to licensing and administrator-enablement prerequisites but does not s

  • Security guidance and retirement-related documentation changed without confirming service retirementsEntra ID, ID Protection, Permissions Management, and Workload ID

    Learn updates emphasize Conditional Access protection for MFA and self-service password-reset registration, controls for high-risk sign-ins, and blocking authentication transfer. Other guidance describes a dedicated first-party synchronization service principal for Entra Connect Sync, mitigation for retiring service-principal-less workload authentication, and offboarding for an anticipated Microsoft Entra Permissions Management deprecation. These are security, dependency, and planning signals; no retirement date,​​

For Entra administrators

Confirm that Conditional Access policies explicitly target the Azure DevOps application, and prepare users and automation for the 1 October Azure resource-management MFA requirement using the stated Azure CLI and PowerShell updates and Azure Policy assessment. The Authenticator and Entra ID Free notices state that no administrator action is required. Treat cross-cloud synchronization as opt-in public preview and verify the licensing and administrator-enablement prerequisites cited in the notice before considering it. For the Learn-only security and lifecycle material, review relevant Conditional Access, ID Protection, Entra Connect, and workload runbooks, but do not infer a broad policy rollout or a Permissions Management retirement date or replacement that the evidence does not provide.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

1030 updates by product

General

640

Prerequisites

Updated

- The Active Directory schema in the gMSA domain's forest needs to be updated to Windows Server 2012 or later.

30 September 2025

Prerequisites

Updated

|Requirement|Description and more requirements|

30 September 2025

Tutorial Basic Ad Azure

Updated

The following are prerequisites required for completing this tutorial

30 September 2025

Entra Cloud Sync How To Install

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).

24 September 2025

Access Tokens

Updated

eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6Imk2bEdrM0ZaenhSY1ViMkMzbkVRN3N5SEpsWSJ9.eyJhdWQiOiI2ZTc0MTcyYi1iZTU2LTQ4NDMtOWZmNC1lNjZhMzliYjEyZTMiLCJpc3MiOiJodHRwczovL2xvZ2luLm1pY3Jvc29mdG9ubGluZS5jb20vNzJmOTg4YmYtODZmMS00MWFmLTkxYWItMmQ3Y2QwMTFkYjQ3L3YyLjAiLCJpYXQiOjE1MzcyMzEwNDgsIm5iZiI6MTUzNzIzMTA0OCwiZXhwIjoxNTM3MjM0OTQ4LCJhaW8iOiJBWFFBaS84SUFBQUF0QWFaTG8zQ2hNaWY2S09udHRSQjdlQnE0L0RjY1F6amNKR3hQWXkvQzNqRGFOR3hYZDZ3TklJVkdSZ2hOUm53SjFsT2NBbk5aY2p2a295ckZ4Q3R0djMzMTQwUmlvT0ZKNGJDQ0dWdW9DYWcxdU9UVDIyMjIyZ0h3TFBZUS91Zjc5UVgrMEtJaWpkcm1wNjlSY3R6bVE9PSIsImF6cCI6IjZlNzQxNzJiLWJlNTYtNDg0My05ZmY0LWU2NmEzOWJiMTJlMyIsImF6cGFjciI6IjAiLCJuYW1lIjoiQWJlIExpbmNvbG4iLCJvaWQiOiI2OTAyMjJiZS1mZjFhLTRkNTYtYWJkMS03ZTRmN2QzOGU0NzQiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJhYmVsaUBtaWNyb3NvZnQuY29tIiwicmgiOiJJIiwic2NwIjoiYWNjZXNzX2FzX3VzZXIiLCJzdWIiOiJIS1pwZmFIeVdhZGVPb3VZbGl0anJJLUtmZlRtMjIyWDVyclYzeERxZktRIiwidGlkIjoiNzJmOTg4YmYtODZmMS00MWFmLTkxYWItMmQ3Y2QwMTFkYjQ3IiwidXRpIjoiZnFpQnFYTFBqMGVRYTgyUy1JWUZBQSIsInZlciI6IjIuMCJ9.pj4N-w_3Us9DrBLfpCt

23 September 2025

Agent Optimization Review Suggestions

Updated

- Policy details are provided as both a list of all the details that are changing and a JSON view of the entire policy, with the changes highlighted.

23 September 2025

Connect Emergency Ad Fs Certificate Rotation

Updated

To revoke the old Token Signing Certificate that AD FS is currently using, you need to determine the thumbprint of the token-signing certificate. From your ADFS Server do the following:

19 September 2025

Connect Fed O365 Certs

Updated

Check the certificates configured in AD FS and Microsoft Entra ID trust properties for the specified domain.

19 September 2025

Global Administrator

Updated

> | microsoft.hardware.support/shippingAddress/allProperties/allTasks | Create, read, update, and delete shipping addresses for Microsoft hardware warranty claims, including shipping addresses created by others |

12 September 2025

Global Reader

Updated

> | microsoft.hardware.support/shippingAddress/allProperties/read | Read shipping addresses for Microsoft hardware warranty claims, including existing shipping addresses created by others |

12 September 2025

Reply Url

Updated

1. `http` URI schemes are acceptable because the redirect never leaves the device. As such, both of these URIs are acceptable:

10 September 2025

4dx Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and 4DX.

3 September 2025

Adra By Trintech Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Adra by Trintech.

3 September 2025

Air Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Air.

3 September 2025

Alchemer Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Alchemer.

3 September 2025

Alexishr Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and AlexisHR.

3 September 2025

Alteryx Server Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Alteryx Server.

3 September 2025

Appian Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Appian.

3 September 2025

Arborxr Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and ArborXR.

3 September 2025

Aws Clientvpn Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and AWS ClientVPN.

3 September 2025

Aws Single Sign On Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and AWS IAM Identity Center (successor to AWS Single Sign-On).

3 September 2025

Balsamiq Wireframes Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Balsamiq Wireframes.

3 September 2025

Blinq Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Blinq.

3 September 2025

Broadcom Dx Saas Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Broadcom DX SaaS.

3 September 2025

Checkproof Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and CheckProof.

3 September 2025

Clebex Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Clebex.

3 September 2025

Cloudtamer Io Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Kion (formerly cloudtamer.io).

3 September 2025

Cognism Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Cognism.

3 September 2025

Contentstack Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Contentstack.

3 September 2025

Delivery Solutions Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Delivery Solutions.

3 September 2025

Descartes Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Descartes.

3 September 2025

Desknets Neo Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and desknets NEO.

3 September 2025

Digital Pigeon Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Digital Pigeon.

3 September 2025

Document360 Tutorial

Updated

Learn how to configure single sign-on (SSO) between Microsoft Entra ID and Document360.

3 September 2025

Documo Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Documo.

3 September 2025

Eflok Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and eFlok.

3 September 2025

Elium Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Elium.

3 September 2025

Embed Signage Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and embed signage.

3 September 2025

Exium Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Exium.

3 September 2025

Fax Plus Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and FAX.PLUS.

3 September 2025

Fortisase Sia Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and FortiSASE.

3 September 2025

Foundu Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and foundU.

3 September 2025

Fresh Relevance Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Fresh Relevance.

3 September 2025

Gainsight Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Gainsight.

3 September 2025

Guru Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Guru.

3 September 2025

Headspace Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Headspace.

3 September 2025

Hiretual Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and hireEZ-SSO.

3 September 2025

Idrive360 Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and IDrive360.

3 September 2025

Ihasco Training Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and iHASCO Training.

3 September 2025

Javelo Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Javelo.

3 September 2025

Kno2fy Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Kno2fy.

3 September 2025

Leadfamly Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Leadfamly.

3 September 2025

Mist Cloud Admin Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Mist Cloud Admin SSO.

3 September 2025

Mural Identity Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Mural Identity.

3 September 2025

Netmotion Mobility Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and NetMotion Mobility.

3 September 2025

Openlearning Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and OpenLearning.

3 September 2025

Palantir Foundry Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Palantir Foundry.

3 September 2025

Per Angusta Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Per Angusta.

3 September 2025

Perimeter 81 Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Perimeter 81.

3 September 2025

Perimeterx Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and PerimeterX.

3 September 2025

Phenom Txm Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Phenom TXM.

3 September 2025

Podbean Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Podbean.

3 September 2025

Pulse Secure Pcs Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Pulse Secure PCS.

3 September 2025

Reach 360 Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Reach 360.

3 September 2025

Readcube Papers Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and ReadCube Papers.

3 September 2025

Recurly Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Recurly.

3 September 2025

Rewatch Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Rewatch.

3 September 2025

Rhombus Systems Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Rhombus Systems.

3 September 2025

Saba Cloud Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Saba Cloud.

3 September 2025

Scilife Azure Ad Sso Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Scilife Microsoft Entra SSO.

3 September 2025

Servicessosafe Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and SoSafe.

3 September 2025

Servusconnect Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and ServusConnect.

3 September 2025

Sigma Computing Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Sigma Computing.

3 September 2025

Snackmagic Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Snackmagic.

3 September 2025

Software Ag Cloud Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Software AG Cloud.

3 September 2025

Swit Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Swit.

3 September 2025

Teamgo Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Teamgo.

3 September 2025

Terraform Cloud Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Terraform Cloud.

3 September 2025

Trendminer Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and TrendMiner.

3 September 2025

Truechoice Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and TrueChoice.

3 September 2025

Valid8me Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and valid8Me.

3 September 2025

Veza Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Veza.

3 September 2025

Vonage Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and vonage.

3 September 2025

Webcargo Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Webcargo.

3 September 2025

Workware Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Workware.

3 September 2025

Zero Networks Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Zero Networks.

3 September 2025

Zonka Feedback Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Zonka Feedback.

3 September 2025

Zylo Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Zylo.

3 September 2025

Places Administrator

Updated

Assign the Places Administrator role to users who need to do the following tasks:

2 September 2025

Provisioning

163

Uniflow Online Provisioning Tutorial

Updated

This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in TestApp based on user and/or group assignments in Microsoft Entra ID.

13 September 2025

Netpresenter Provisioning Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Netpresenter Next.

3 September 2025

Cofense Provision Tutorial

Updated

Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cofense Recipient Sync.

3 September 2025

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Corn…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cornerstone OnDemand so that I can streamline the user management process and ensure that users have the appropriate access to Cornerstone OnDemand..

3 September 2025

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoTo…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoToMeeting so that I can streamline the user management process and ensure that users have the appropriate access to GoToMeeting..

3 September 2025

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Sale…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Salesforce Sandbox so that I can streamline the user management process and ensure that users have the appropriate access to Salesforce Sandbox..

3 September 2025

Myday Provision Tutorial

Updated

Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to myday.

3 September 2025

Fundamentals

40

Tokens Microsoft Entra Id

Updated

| Token Type | Issued by | Purpose | Scoped to Resource | Lifetime | Revocable | Renewable |

27 September 2025

PowerShell

Updated

* Microsoft Entra Connect synchronizes identities from your on-premises directory

25 September 2025

Conditional Access Grant

Updated

Admins can choose to enforce one or more controls when granting access. These controls include the following options:

24 September 2025

Activity Log Schemas

Updated

- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).

18 September 2025

Activity Log Schemas

Updated

- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).

17 September 2025

Audit Logs

Updated

- Where applicable, old and new values for the changed properties

17 September 2025

Copilot Entra Security Scenarios

Updated

This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.

16 September 2025

Block authentication flows with Conditional Access policy

Updated

The following steps help create Conditional Access policies to restrict how [device code flow](concept-authentication-flows.md#device-code-flow) and [authentication transfer](concept-authentication-flows.md#authentication-transfer) are used within your organization.

9 September 2025

Plan Conditional Access

Updated

Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.

9 September 2025

Copilot Entra Agents

Updated

- You must have at least the [Microsoft Entra ID P1](licensing.md) license for the Conditional Access optimization agent.

6 September 2025

Microsoft Entra: Action Required – Update Conditional Access Policies for Azure DevOps Sign-ins

New

Microsoft Entra will stop applying Conditional Access policies via Azure Resource Manager for Azure DevOps sign-ins starting September 2, 2025, fully enforced by September 18. Organizations must update policies to explicitly include Azure DevOps (App ID: 499b84ac-1321-427f-aa17-267ca6975798) to maintain secure access.

5 September 2025
Message CenterMC1123830 on mc.merill.net ↗Major updatePlan for change

Group Source Of Authority Guidance

Updated

Discover how to manage and transition Active Directory groups to Microsoft Entra ID using Group Source of Authority (SOA). Learn best practices for group management, provisioning, restoring, and rolling back changes in hybrid and cloud environments.

5 September 2025

Group Source Of Authority How It Works

Updated

Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID using group source of authority (SOA).

5 September 2025

Govern On Premises Groups

Updated

This article provides an overview of how to use cloud sync to govern on-premises application access using groups.

5 September 2025

Whats New

Updated

**Type:** New feature

3 September 2025

Standards

32

Use Scim To Provision Users And Groups

Updated

> * Support at least 25 requests per second per tenant to ensure that users and groups are provisioned and deprovisioned without delay (Required)

20 September 2025

Use Scim To Provision Users And Groups

Updated

1. When the provisioning cycle begins, the service checks if the current access token is valid and exchanges it for a new token if needed. The access token is provided in each request made to the app and the validity of the request is checked before each request.

13 September 2025

21828

Updated

Blocking authentication transfer in Microsoft Entra ID is a critical security control. It helps protect against token theft and replay attacks by preventing the use of device tokens to silently authenticate on other devices or browsers. When authentication transfer is enabled, a threat actor who gains access to one device can access resources to nonapproved devices, bypassing standard authentication and device compliance checks. When administrators block this flow, organizations can ensure that each authentication request must originate from the original device, maintaining the integrity of the device compliance and user session context.

9 September 2025

userimpact: High

Updated

Assume high risk users are compromised by threat actors. Without investigation and remediation, threat actors can execute scripts, deploy malicious applications, or manipulate API calls to establish persistence, based on the potentially compromised user's permissions. Threat actors can then exploit misconfigurations or abuse OAuth tokens to move laterally across workloads like documents, SaaS applications, or Azure resources. Threat actors can gain access to sensitive files, customer records, or proprietary code and exfiltrate it to external repositories while maintaining stealth through legitimate cloud services. Finally, threat actors might disrupt operations by modifying configurations, encrypting data for ransom, or using the stolen information for further attacks, resulting in financial, reputational, and regulatory consequences.

9 September 2025

Fareharbor Saml Sso Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Fareharbor SAML SSO.

3 September 2025

Flipsnack Saml Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Flipsnack SAML.

3 September 2025

Oktopost Saml Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Oktopost SAML.

3 September 2025

Resource Central Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Resource Central – SAML SSO for Meeting Room Booking System.

3 September 2025

Standard For Success Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Standard for Success K-12.

3 September 2025

Timeclock 365 Saml Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and Timeclock 365 SAML.

3 September 2025

Authentication

24

Connect Pta Quick Start

Updated

1. Identify a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016 to run Microsoft Entra Connect. If not enabled already, [enable TLS 1.2 on the server](./how-to-connect-install-prerequisites.md#enable-tls-12-for-azure-ad-connect). Add the server to the same Active Directory forest as the users whose passwords you need to validate. It should be noted that installation of Pass-Through Authentication agent on Windows Server Core versions isn't supported.

30 September 2025

Howto Vm Sign In Azure Ad Windows

Updated

Sign in with the user account in a web browser. For instance, sign in to the [Azure portal](https://portal.azure.com) in a private browsing window. If you're prompted to change the password, set a new password. Then try connecting again.

29 September 2025

Protected Actions Add

Updated

Protected actions use a Conditional Access authentication context, so you must configure an authentication context and add it to a Conditional Access policy. If you already have a policy with an authentication context, you can skip to the next section.

27 September 2025

Howto Authentication Temporary Access Pass

Updated

For hybrid-joined devices, users must first authenticate with another method such as a password, smartcard or FIDO2 key, before using TAP to set up Windows Hello for Business.

23 September 2025

21806

Updated

Without Conditional Access policies protecting security information registration, threat actors can exploit unprotected registration flows to compromise authentication methods. When users register multifactor authentication and self-service password reset methods without proper controls, threat actors can intercept these registration sessions through adversary-in-the-middle attacks or exploit unmanaged devices accessing registration from untrusted locations. Once threat actors gain access to an unprotected registration flow, they can register their own authentication methods, effectively hijacking the target's authentication profile. The threat actors can bypass security controls and potentially escalate privileges throughout the environment because they can maintain persistent access by controlling the MFA methods. The compromised authentication methods then become the foundation for lateral movement as threat actors can authenticate as the legitimate user across multiple services and applications.

9 September 2025

21781

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

9 September 2025

21782

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

9 September 2025

21783

Updated

- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)

9 September 2025

21800

Updated

- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)

9 September 2025

21801

Updated

- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)

9 September 2025

Kerberos

Updated

>[!IMPORTANT]

6 September 2025

Authentication Track Linkable Identifiers

Updated

Discover how linkable identifiers like session IDs and unique token identifiers in Microsoft Entra help track and investigate identity-related activities, enhancing security and transparency.

5 September 2025

Security

20

21786

Updated

Token protection, also called token binding, helps prevent token theft by making sure a token is usable only from the intended device. Token protection uses cryptography so that without the client device key, no one can use the token.

9 September 2025

Tap App Security Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and TAP App Security.

3 September 2025

Monitoring

14

Groups Dynamic Membership

Updated

You can create a group that contains all direct reports of a manager. When the manager's direct reports change in the future, the group's membership is adjusted automatically.

23 September 2025

Agent Optimization Phased Rollout

Updated

1. [Agent creates a report-only policy with a phased rollout](#agent-creates-a-report-only-policy-with-a-phased-rollout)

6 September 2025

Lablog Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and LabLog.

3 September 2025

Safety Culture Tutorial

Updated

Learn how to configure single sign-on between Microsoft Entra ID and SafetyCulture (formerly iAuditor).

3 September 2025

Developer

10

Configure custom domains with Microsoft Entra application proxy

Updated

When you publish an application through Microsoft Entra application proxy, you create an external URL for your users. This URL gets the default domain *`yourtenant.msappproxy.net`*. For example, if you publish an app named *Expenses* in your tenant named *Contoso*, the external URL is *`https://expenses-contoso.msappproxy.net`*. If you want to use your own domain name instead of *`msappproxy.net`*, you can configure a custom domain for your application.

5 September 2025

Troubleshooting

8

Error Codes

Updated

| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |

30 September 2025

21796

Updated

**Remediation action**

9 September 2025

21808

Updated

**Remediation action**

9 September 2025

21851

Updated

**Remediation action**

9 September 2025

21872

Updated

**Remediation action**

9 September 2025

Troubleshoot Conditional Access What If

Updated

The [What If tool](what-if-tool.md) in Conditional Access is powerful when trying to understand why a policy was or wasn't applied to a user in a specific circumstance or if a policy would apply in a known state.

3 September 2025

Conditional Access

3

Governance

3

Connect Install Prerequisites

Updated

- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.

30 September 2025

Connect Install Prerequisites

Updated

- Microsoft Entra Connect must be installed on a domain-joined Windows Server 2016-2022. We recommend using domain-joined Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported Windows Server version may cause service failures or unexpected behavior.

20 September 2025

Microsoft identity platform

3

Accepted Token Versions

Updated

The Microsoft identity platform can issue v1.0 tokens and v2.0 tokens. For more information about these tokens, refer to [Access tokens](/entra/identity-platform/access-tokens).

12 September 2025

Group Source Of Authority Configure

Updated

| **Roles** | [Hybrid Administrator](/entra/identity/role-based-access-control/permissions-reference#hybrid-administrator) is required to call the Microsoft Graph APIs to read and update SOA of groups.<br>[Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator) or [Cloud Application Administrator](/entra/identity/role-based-access-control/permissions-reference#cloud-application-administrator) is required to grant user consent to the required permissions to Microsoft Graph Explorer or the app used to call the Microsoft Graph APIs. |

5 September 2025

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

4 September 2025

Architecture

2

Conditional Access Session

Updated

Conditional Access App Control uses a reverse proxy architecture and is uniquely integrated with Microsoft Entra Conditional Access. Microsoft Entra Conditional Access allows you to enforce access controls on your organization’s apps based on certain conditions. The conditions define what user or group of users, cloud apps, and locations and networks a Conditional Access policy applies to. After you determine the conditions, you can route users to Microsoft Defender for Cloud Apps where you can protect data with Conditional Access App Control by applying access and session controls.

3 September 2025

Branding

1

Troubleshoot Password Based Sso

Updated

Sign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps.

16 September 2025

Authentication

2

21799

Updated

When high-risk sign-ins are not properly restricted through Conditional Access policies, organizations expose themselves to security vulnerabilities. Threat actors can exploit these gaps for initial access through compromised credentials, credential stuffing attacks, or anomalous sign-in patterns that Microsoft Entra ID Protection identifies as risky behaviors. Without appropriate restrictions, threat actors who successfully authenticate during high-risk scenarios can perform privilege escalation by misusing the authenticated session to access sensitive resources, modify security configurations, or conduct reconnaissance activities within the environment. Once threat actors establish access through uncontrolled high-risk sign-ins, they can achieve persistence by creating additional accounts, installing backdoors, or modifying authentication policies to maintain long-term access to the organization's resources. The unrestricted access enables threat actors to conduct lateral movement across systems and applications using the authenticated session, potentially accessing sensitive data stores, administrative interfaces, or critical business applications. Finally, threat actors achieve impact through data exfiltration, or compromise business-critical systems while maintaining plausible deniability by exploiting the fact that their risky authentication was not properly challenged or blocked.

9 September 2025

Agent Optimization

Updated

- **Risky users**: The agent suggests a policy to require secure password change for high risk users. Requires Microsoft Entra ID P2 license.

6 September 2025

Governance

9

Lifecycle Workflow Templates

Updated

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

23 September 2025

Entitlement Management External Users

Updated

When using the [Microsoft Entra B2B](~/external-id/what-is-b2b.md) invite experience, you must already know the email addresses of the external guest users you want to bring into your resource directory and work with. Directly inviting each user works great when you're working on a smaller or short-term project and you already know all the participants. This process is harder to manage if you have lots of users you want to work with, or if the participants change over time. For example, you might be working with another organization and have one point of contact with that organization, but over time more users from that organization will also need access.

10 September 2025

Access Review Agent

Updated

Say goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.

6 September 2025

Create Access Review Pim For Groups

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

6 September 2025

Fundamentals

2

Access Review Agent

Updated

- You must have [Microsoft Entra ID Governance or Microsoft Entra Suite licenses](licensing-fundamentals.md).

27 September 2025

Access Review Agent Logs Metrics

Updated

To view information about the Access Review Agent, open up the Access Review Agent to get to the overview page. The highlight of the overview page is the Agent summary, which provides a quick summary of agent actions over the course of the last 30 days.

6 September 2025

General

6

Define Custom Attributes

Updated

An attribute with a Boolean data type has a user input type of CheckboxSingleSelect. You can modify the text that displays next to the checkbox and include hyperlinks.

17 September 2025

Training Videos

Updated

To start the training, go to [Guided project – Build a sample app to evaluate Microsoft Entra External ID](https://aka.ms/eeid/training-module) and follow the units in order.

17 September 2025

Tenant Restrictions V2

Updated

- Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.

16 September 2025

Authentication

5

Use App Roles Customers

Updated

When Microsoft Entra External ID issues a security token for an authenticated user, it includes the names of the roles you've assigned the user or group in the security token's roles claim. An application that receives that security token in a request can then make authorization decisions based on the values in the roles claim.

17 September 2025

Multifactor Authentication Customers

Updated

This article describes how to enforce MFA for your customers by creating a Microsoft Entra Conditional Access policy and adding MFA to your sign-up and sign-in user flow.

17 September 2025

User Flow Sign Up Sign In Customers

Updated

This article describes how to create a sign-in and sign-up user flow. After you create the user flow, the next step is to [add your application to the user flow](how-to-user-flow-add-application.md). You can create multiple user flows if you have multiple applications that you want to offer to customers. Or, you can use the same user flow for many applications. However, an application can have only one user flow.

17 September 2025

Enable Password Reset Customers

Updated

:::image type="content" source="media/how-to-enable-password-reset-customers/sspr-flow.png" alt-text="Screenshot that shows the self-service password rest flow.":::

17 September 2025

Fundamentals

5

Google Federation Customers

Updated

By setting up federation with Google, you allow customers to sign in to your applications with their own Google accounts. After you add Google as one of your user flow's sign-in options, customers can sign up and sign in to your application with a Google account. (Learn more about [authentication methods and identity providers for customers](concept-authentication-methods-customers.md).)

17 September 2025

Custom Url Domain

Updated

- It provides a more consistent user experience. From the user's perspective, they remain in your domain during the sign in process rather than redirecting to the default domain *&lt;tenant-name&gt;.ciamlogin.com*.

17 September 2025

Solutions Customers

Updated

When you enter an email address to create an account, your email is verified through a one-time passcode. Then you can create a new password and provide more details, such as your name, country or region, and other information. Once your account is created, your email becomes your sign-in ID.

17 September 2025

Azure Information Protection: Enable multifactor authentication for your Azure tenant by October 1, 2025

New

Microsoft will enforce multifactor authentication (MFA) for all Azure resource management actions starting October 1, 2025, with a postponement option until July 2026. Users must enable MFA, update Azure CLI/PowerShell, and can apply Azure Policy to assess impact. Gallatin customers are advised to implement MFA without enforcement.

6 September 2025
Message CenterMC1143999 on mc.merill.net ↗Stay informed

Branding

2

Facebook Federation Customers

Updated

By setting up federation with Facebook, you can allow customers to sign in to your applications with their own Facebook accounts. After you've added Facebook as one of your application's sign-in options, on the sign-in page, customers can sign-in to Microsoft Entra External ID with a Facebook account. (Learn more about [authentication methods and identity providers for customers](/entra/external-id/customers/concept-authentication-methods-customers).)

17 September 2025

Customize Branding Customers

Updated

After creating a new external tenant, you can customize the end-user experience. Create a custom look and feel for users signing in to your apps by configuring **Company branding** settings for your tenant. With these settings, you can add your own background images, colors, company logos, and text to customize the sign-in experiences across your apps.

17 September 2025

Developer

2

Add Attributes To Token

Updated

You can specify which built-in or custom attributes you want to include as claims in the token that Microsoft Entra ID sends to your application.

17 September 2025

User Insights

Updated

The Application user activity feature under Usage & insights provides data analytics on user activity and engagement for registered applications in your tenant. You can use this feature to view, query, and analyze user activity data in the Microsoft Entra admin center. This feature can help you uncover valuable insights that can aid strategic decisions and drive business growth.

17 September 2025

Provisioning

1

Permissions Reference

Updated

> | [Directory Synchronization Accounts](#directory-synchronization-accounts) | Only used by Microsoft Entra Connect service. | d29b2b05-8046-44ba-8758-1e26182fcf32 |

12 September 2025

Standards

1

Microsoft Accounts Federation Customers

Updated

By setting up federation with Microsoft account (live.com) using OpenID Connect (OIDC) identity provider, you enable users to sign up and sign in to your applications using their existing Microsoft accounts (MSA).

17 September 2025

General

5

Manage User Assigned Managed Identities Azure Cli

Updated

Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.

11 September 2025

Fundamentals

4

Grant Managed Identity Resource Access Azure Portal

Updated

The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure services are in the process of adopting Azure RBAC on the data plane.

11 September 2025

Provisioning

1

Hardening update to Microsoft Entra Connect Sync

Updated

As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `6bf85cfa-ac8a-4be5-b5de-425a0d0dc016`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.

26 September 2025

General

11

Customize Block Page

Updated

1. Navigate to **Global Secure Access** > **Settings** > **Session management** > **Custom Block Page**

27 September 2025

Configure Domain Controllers

Updated

- The client machine is at least Windows 10 and is Microsoft Entra joined or hybrid joined device. The client machine must also have line of sight to the private resources and DC (user is in a corporate network and accessing on-premises resources). User identity used for joining the device and accessing these resources was created in Active Directory (AD) and synced to Microsoft Entra ID using Microsoft Entra Connect.

25 September 2025

Configure Threat Intelligence

Updated

1. To test allow-listing, create a rule in the Threat Intelligence policy to allow access to the site. Within 2 minutes, you should be able to access it. (You may need to clear your browser cache.)

6 September 2025

Check Web Content Filtering Categories

Updated

GET hhttps://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=msn.com/en-us/sports

5 September 2025

Configure Web Content Filtering

Updated

1. Enter a name, select a [web category](reference-web-content-filtering-categories.md) or a valid FQDN, and then select **Add**.

5 September 2025

Install Android Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Android client app.

3 September 2025

Fundamentals

7

Private Name Resolution

Updated

1. User requests a DNS query for `app.contoso.com`. If not cached locally, the DNS query is sent to the DNS proxy at the GSA edge.

23 September 2025

Remote Network Connectivity

Updated

Guest devices on your network might not have the client installed. To ensure that those devices adhere to your network security policies, you need their traffic routed through the Global Secure Access endpoint. Remote network connectivity solves this problem. No clients need to be installed on guest devices. All outgoing traffic from the remote network is going through security evaluation by default.

4 September 2025

Security

4

Configure Threat Intelligence

Updated

Since threat intelligence is critical for users' basic security posture, you can alternatively link your threat intelligence policy to the baseline security profile, which applies policy to all users' traffic in your tenant.

24 September 2025

Netskope Coexistence

Updated

1. Create [Real-time Protection policy](https://docs.netskope.com/en/inline-policies/) to allow access to Private Apps.

24 September 2025