Migrate Group Writeback
Updatedmanager: mwongerapk
Daily.Entra.NewsSeptember was primarily a Microsoft Learn maintenance month rather than a broad Entra launch cycle: 1,017 of 1,030 records were updates, with four new records, five removals, and four Message Center notices. The most consequential exceptions were the Azure DevOps Conditional Access targeting change, scheduled MFA enforcement for Azure resource management, a Microsoft Authenticator sign-in UX change, and the late-period cross-cloud synchronization notice. The specifically described new Global Secure Access pages were test-environment PowerShell samples for TLS certificates, not evidence of a product launch. The five removals also contain no detail that supports calling a capability retired. A separate Entra ID Free notice says the no-cost subscription will appear in portals for tenant-ownership tracking without changing billing or functionality.
The Microsoft Entra notice said Conditional Access would stop being applied via Azure Resource Manager for Azure DevOps sign-ins starting 2 September, with full enforcement by 18 September. Policies must explicitly include the Azure DevOps application, App ID 499b84ac-1321-427f-aa17-267ca6975798. This is a changed targeting and enforcement behavior, not a feature launch.
The Message Center notice says MFA will be enforced for all Azure resource-management actions from 1 October 2025, with a postponement option until July 2026. It calls out enabling MFA, updating Azure CLI and PowerShell, and using Azure Policy to assess impact. Gallatin customers are advised to implement MFA without enforcement. This is scheduled security enforcement, not an Entra feature release.
During the stated late-September-to-mid-October rollout, same-device sign-ins will require only a Yes/No confirmation instead of number entry. The first-run experience will also prioritize Microsoft Entra accounts and highlight QR-code scanning. The notice says no administrator action is required; this is a client UX behavior change rather than a change to Conditional Access semantics.
The week-of-29-September briefing describes a 3 October Message Center notice for Microsoft Entra cross-cloud synchronization, covering user lifecycle management across Microsoft commercial, US Government, and China clouds. The notice calls it public preview and opt-in while also listing general availability for late September to early October, so the supplied evidence does not support treating it as an unqualified GA release. The summary refers to licensing and administrator-enablement prerequisites but does not s
Learn updates emphasize Conditional Access protection for MFA and self-service password-reset registration, controls for high-risk sign-ins, and blocking authentication transfer. Other guidance describes a dedicated first-party synchronization service principal for Entra Connect Sync, mitigation for retiring service-principal-less workload authentication, and offboarding for an anticipated Microsoft Entra Permissions Management deprecation. These are security, dependency, and planning signals; no retirement date,
Confirm that Conditional Access policies explicitly target the Azure DevOps application, and prepare users and automation for the 1 October Azure resource-management MFA requirement using the stated Azure CLI and PowerShell updates and Azure Policy assessment. The Authenticator and Entra ID Free notices state that no administrator action is required. Treat cross-cloud synchronization as opt-in public preview and verify the licensing and administrator-enablement prerequisites cited in the notice before considering it. For the Learn-only security and lifecycle material, review relevant Conditional Access, ID Protection, Entra Connect, and workload runbooks, but do not infer a broad policy rollout or a Permissions Management retirement date or replacement that the evidence does not provide.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
manager: mwongerapk
- The Active Directory schema in the gMSA domain's forest needs to be updated to Windows Server 2012 or later.
|Requirement|Description and more requirements|
To complete the tutorial, you need these items:
manager: mwongerapk
author: omondiatieno
The following are prerequisites required for completing this tutorial
manager: mwongerapk
> [!WARNING]
Include file
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
Include file
eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6Imk2bEdrM0ZaenhSY1ViMkMzbkVRN3N5SEpsWSJ9.eyJhdWQiOiI2ZTc0MTcyYi1iZTU2LTQ4NDMtOWZmNC1lNjZhMzliYjEyZTMiLCJpc3MiOiJodHRwczovL2xvZ2luLm1pY3Jvc29mdG9ubGluZS5jb20vNzJmOTg4YmYtODZmMS00MWFmLTkxYWItMmQ3Y2QwMTFkYjQ3L3YyLjAiLCJpYXQiOjE1MzcyMzEwNDgsIm5iZiI6MTUzNzIzMTA0OCwiZXhwIjoxNTM3MjM0OTQ4LCJhaW8iOiJBWFFBaS84SUFBQUF0QWFaTG8zQ2hNaWY2S09udHRSQjdlQnE0L0RjY1F6amNKR3hQWXkvQzNqRGFOR3hYZDZ3TklJVkdSZ2hOUm53SjFsT2NBbk5aY2p2a295ckZ4Q3R0djMzMTQwUmlvT0ZKNGJDQ0dWdW9DYWcxdU9UVDIyMjIyZ0h3TFBZUS91Zjc5UVgrMEtJaWpkcm1wNjlSY3R6bVE9PSIsImF6cCI6IjZlNzQxNzJiLWJlNTYtNDg0My05ZmY0LWU2NmEzOWJiMTJlMyIsImF6cGFjciI6IjAiLCJuYW1lIjoiQWJlIExpbmNvbG4iLCJvaWQiOiI2OTAyMjJiZS1mZjFhLTRkNTYtYWJkMS03ZTRmN2QzOGU0NzQiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJhYmVsaUBtaWNyb3NvZnQuY29tIiwicmgiOiJJIiwic2NwIjoiYWNjZXNzX2FzX3VzZXIiLCJzdWIiOiJIS1pwZmFIeVdhZGVPb3VZbGl0anJJLUtmZlRtMjIyWDVyclYzeERxZktRIiwidGlkIjoiNzJmOTg4YmYtODZmMS00MWFmLTkxYWItMmQ3Y2QwMTFkYjQ3IiwidXRpIjoiZnFpQnFYTFBqMGVRYTgyUy1JWUZBQSIsInZlciI6IjIuMCJ9.pj4N-w_3Us9DrBLfpCt
- Policy details are provided as both a list of all the details that are changing and a JSON view of the entire policy, with the changes highlighted.
This document describes setting up and configuring multiple top level domains with Microsoft 365 and Microsoft Entra ID.
To revoke the old Token Signing Certificate that AD FS is currently using, you need to determine the thumbprint of the token-signing certificate. From your ADFS Server do the following:
Check the certificates configured in AD FS and Microsoft Entra ID trust properties for the specified domain.
|------|
author: msmimart
author: msmimart
author: msmimart
Dragon Administrator
> | microsoft.hardware.support/shippingAddress/allProperties/allTasks | Create, read, update, and delete shipping addresses for Microsoft hardware warranty claims, including shipping addresses created by others |
> | microsoft.hardware.support/shippingAddress/allProperties/read | Read shipping addresses for Microsoft hardware warranty claims, including existing shipping addresses created by others |
A Microsoft Entra documentation page was updated: Assign Access Azure Resource.
1. `http` URI schemes are acceptable because the redirect never leaves the device. As such, both of these URIs are acceptable:
* GitHub Enterprise Server supports **SP** and **IDP** initiated SSO.
You can use the Azure portal or PowerShell to enable **TLS 1.2 Only Mode**.
In this section, you populate the relevant SSO values in the Timetabling Solutions Management Portal.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Learn how to configure single sign-on between Microsoft Entra ID and 4DX.
Learn how to configure single sign-on between Microsoft Entra ID and 8x8.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and ADP EMEA French HR Portal mon.adp.com.
Learn how to configure single sign-on between Microsoft Entra ID and Adra by Trintech.
author: nguhiu
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Air.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Alchemer.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and AlexisHR.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Alteryx Server.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Amazon Managed Grafana.
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Appaegis Isolation Access Cloud.
Learn how to configure single sign-on between Microsoft Entra ID and Appian.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and ArborXR.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and AWS ClientVPN.
Learn how to configure single sign-on between Microsoft Entra ID and AWS IAM Identity Center (successor to AWS Single Sign-On).
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Balsamiq Wireframes.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Blinq.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Broadcom DX SaaS.
Learn how to configure single sign-on between Microsoft Entra ID and Brocade SANnav Global View.
Learn how to configure single sign-on between Microsoft Entra ID and Brocade SANnav Management Portal.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Check Point Harmony Connect.
Learn how to configure single sign-on between Microsoft Entra ID and Check Point Identity Awareness.
Learn how to configure single sign-on between Microsoft Entra ID and Check Point Remote Secure Access VPN.
Learn how to configure single sign-on between Microsoft Entra ID and Check Point Infinity Portal.
Learn how to configure single sign-on between Microsoft Entra ID and CheckProof.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Clebex.
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Kion (formerly cloudtamer.io).
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Cognism.
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Contentstack.
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Delivery Solutions.
Learn how to configure single sign-on between Microsoft Entra ID and Descartes.
Learn how to configure single sign-on between Microsoft Entra ID and desknets NEO.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Digital Pigeon.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on (SSO) between Microsoft Entra ID and Document360.
Learn how to configure single sign-on between Microsoft Entra ID and Documo.
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Eccentex AppBase for Azure.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and eFlok.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Elium.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and embed signage.
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Exium.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and FAX.PLUS.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and FortiSASE.
Learn how to configure single sign-on between Microsoft Entra ID and foundU.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Fresh Relevance.
Learn how to configure single sign-on between Microsoft Entra ID and Gainsight.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
services: active-directory
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and Guru.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Headspace.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and hireEZ-SSO.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and HPE Aruba Networking EdgeConnect Orchestrator.
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and IDrive360.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and iHASCO Training.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Informatica Intelligent Data Management Cloud.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Infrascale Cloud Backup.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Javelo.
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Kendis - Microsoft Entra Integration.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Kno2fy.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Leadfamly.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and LinkedIn Talent Solutions.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Looker Analytics Platform.
Learn how to configure single sign-on between Microsoft Entra ID and Lookout Secure Access.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Mist Cloud Admin SSO.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and Mural Identity.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and NetMotion Mobility.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Invicti.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
services: active-directory
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and OpenLearning.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Othership Workplace Scheduler.
Learn how to configure single sign-on between Microsoft Entra ID and Palantir Foundry.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Parkalot - Car park management.
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Per Angusta.
Learn how to configure single sign-on between Microsoft Entra ID and Perimeter 81.
Learn how to configure single sign-on between Microsoft Entra ID and PerimeterX.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Phenom TXM.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Podbean.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Pulse Secure PCS.
Learn how to configure single sign-on between Microsoft Entra ID and Pulse Secure Virtual Traffic Manager.
services: active-directory
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Reach 360.
Learn how to configure single sign-on between Microsoft Entra ID and ReadCube Papers.
Learn how to configure single sign-on between Microsoft Entra ID and Recurly.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Rewatch.
Learn how to configure single sign-on between Microsoft Entra ID and Rhombus Systems.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Saba Cloud.
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Samsung Knox and Business Services.
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Scilife Microsoft Entra SSO.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and SoSafe.
Learn how to configure single sign-on between Microsoft Entra ID and ServusConnect.
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and Sigma Computing.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Snackmagic.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Software AG Cloud.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Swit.
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Synerise AI Growth Operating System.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and Teamgo.
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Terraform Cloud.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and The People Experience Hub.
author: nguhiu
services: active-directory
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Tonichi Nexta Meishi.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and TrendMiner.
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and TrueChoice.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and valid8Me.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
Learn how to configure single sign-on between Microsoft Entra ID and Veza.
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and vonage.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Webcargo.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Workware.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Zero Networks.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Zonka Feedback.
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Zylo.
Assign the Places Administrator role to users who need to do the following tasks:
manager: mwongerapk
This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in TestApp based on user and/or group assignments in Microsoft Entra ID.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Server.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Server.
Learn how to preserve and use the original organizational unit (OU) for group provisioning in Microsoft Entra ID.
| --- |:---:| --- |
A Microsoft Entra documentation page was updated: Github Ae Provisioning Tutorial.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kisi Physical Security.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Webroot Security Awareness Training.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to KnowBe4 Security Awareness Training.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Slack.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Acunetix 360.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Airbase.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Airtable.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Akamai Enterprise Application Access.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Albert.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlexisHR.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Alohi.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Amazon Business.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Appaegis Isolation Access Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Ardoq.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Asana.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Astro.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atmos.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Autodesk SSO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Axiad Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BLDNG APP.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Blinq.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Bustle B2B Transport Systems.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Canva.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cerby.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Chaos.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail Swiss.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ClearView Trade.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Colloquial.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Connecter.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ContractS CLM.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to CultureHQ.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cybozu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CybSafe.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Dagster Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Datadog.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Diffchecker.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Documo.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Egnyte.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Evercate.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Fortes Change Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Funnel Leasing.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Managed User (OIDC).
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GitHub Enterprise Managed User.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoSkills.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GroupTalk.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Headspace.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hoxhunt.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Humbol.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Hypervault.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to InformaCast.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insite LMS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to introDus Pre and Onboarding Platform.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Iris Intranet.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Island.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Jellyfish.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Keystone.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kintone.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to kpifire.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LawVu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to NordPass.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to PrinterLogic SaaS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to ProdPad.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Proware.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Segment.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Shopify Plus.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Sigma Computing.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Smallstep SSH.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Splashtop.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SurveyMonkey Enterprise.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to TerraTrue.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Thrive LXP.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Tic-Tac Mobile.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Uber.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Visibly.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Yellowbox.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zoom.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlertMedia.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atlassian Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AuditBoard.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AWS IAM Identity Center.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bentley - Automatic User Provisioning.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIC Cloud Design.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to BlogIn.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Boxcryptor.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bpanda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BrowserStack Single Sign-on.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BullseyeTDP.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CheckProof.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cisco User Management for Secure Access.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Clarizen One.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Clebex.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Coda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Code42.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Contentful.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to directprint.io.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Eletive.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to embed signage.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Exium.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Freshservice Provisioning.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to getAbstract.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub AE.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Global Relay Identity Sync.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GoLinks.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Gong.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Grammarly.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to H5mag.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Joyn FSM.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to KPN Grip.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LanSchool Air.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to QA.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP Analytics Cloud using SAP Cloud Identity Services.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP BTP using SAP Cloud Identity Services.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP Concur using SAP Cloud Identity Services.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP HANA using SAP Cloud Identity Services.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP S/4HANA using SAP Cloud Identity Services.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP Spend Management solutions using SAP Cloud Identity Services.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to SAP SuccessFactors Learning using SAP Cloud Identity Services.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to ThousandEyes.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to ALVAO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Better Stack.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Blink.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Bonusly.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Cisco Webex.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Envoy.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Fuze.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Genesys Cloud for Azure.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hootsuite.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to IDEO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Insight4GRC.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Juno Journey.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kno2fy.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Lucidchart.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Mixpanel.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to myPolicies.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to New Relic by Organization.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to RingCentral.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Rollbar.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Snowflake.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SolarWinds Service Desk (previously Samanage).
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to TeamViewer.
author: nguhiu
author: nguhiu
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Netpresenter Next.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (OIDC).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cofense Recipient Sync.
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Box so that I can streamline the user management process and ensure that users have the appropriate access to Box..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cornerstone OnDemand so that I can streamline the user management process and ensure that users have the appropriate access to Cornerstone OnDemand..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to DocuSign so that I can streamline the user management process and ensure that users have the appropriate access to DocuSign..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoToMeeting so that I can streamline the user management process and ensure that users have the appropriate access to GoToMeeting..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Jive so that I can streamline the user management process and ensure that users have the appropriate access to Jive..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Merchlogix so that I can streamline the user management process and ensure that users have the appropriate access to Merchlogix..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Salesforce Sandbox so that I can streamline the user management process and ensure that users have the appropriate access to Salesforce Sandbox..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Velpic so that I can streamline the user management process and ensure that users have the appropriate access to Velpic..
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to myday.
- Azure CLI
manager: mwongerapk
| Token Type | Issued by | Purpose | Scoped to Resource | Lifetime | Revocable | Renewable |
author: justinha
* Microsoft Entra Connect synchronizes identities from your on-premises directory
Explore Conditional Access conditions, including user risk, sign-in risk, and insider risk, to secure your organization's resources with tailored policies.
Explore Microsoft Entra Conditional Access, the Zero Trust policy engine that integrates signals to secure access to resources.
Learn how to configure Conditional Access policies to target specific resources, actions, and authentication contexts in Microsoft Entra ID.
Discover how to configure Conditional Access policies with network-based signals, including trusted locations, IP ranges, and GPS-based settings.
Learn how session controls in Microsoft Entra Conditional Access policies enable secure, limited experiences for cloud apps based on device compliance.
Admins can choose to enforce one or more controls when granting access. These controls include the following options:
- *Show the top 5 users with the highest data consumption in the last day.*
Microsoft is rolling out the no-cost Microsoft Entra ID Free subscription to track Entra tenant ownership via billing accounts. It will appear in Microsoft 365 and Azure portals starting October, requires no action, does not affect billing or functionality, and helps manage tenant ownership securely.
>
- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).
- `category`: Indicates which resource category that's targeted by the activity. For example: `UserManagement`, `GroupManagement`, `ApplicationManagement`, `RoleManagement`. For more information, see [Audit log activities](reference-audit-activities.md).
- Where applicable, old and new values for the changed properties
manager: pmwongera
Learn how admins can create custom authentication strengths with advanced options for passkey (FIDO2) security keys and certificate-based authentication.
This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.
Discover how to analyze Conditional Access policy results with tools like Azure Monitor and insights workbooks for better policy management.
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- **Certificate Issuance:** When a certificate is issued by a CA, it is valid until its expiration date unless it is revoked earlier. Each certificate contains a public key and is signed by the CA.
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Technical deep dive for Microsoft Entra CBA](concept-certificate-based-authentication-technical-deep-dive.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
- [Overview of Microsoft Entra CBA](concept-certificate-based-authentication.md)
author: justinha
The following steps help create Conditional Access policies to restrict how [device code flow](concept-authentication-flows.md#device-code-flow) and [authentication transfer](concept-authentication-flows.md#authentication-transfer) are used within your organization.
Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
author: shlipsey3
- You must have at least the [Microsoft Entra ID P1](licensing.md) license for the Conditional Access optimization agent.
Microsoft Entra will stop applying Conditional Access policies via Azure Resource Manager for Azure DevOps sign-ins starting September 2, 2025, fully enforced by September 18. Organizations must update policies to explicitly include Azure DevOps (App ID: 499b84ac-1321-427f-aa17-267ca6975798) to maintain secure access.
author: justinha
Discover how to manage and transition Active Directory groups to Microsoft Entra ID using Group Source of Authority (SOA). Learn best practices for group management, provisioning, restoring, and rolling back changes in hybrid and cloud environments.
Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID using group source of authority (SOA).
This article provides an overview of how to use cloud sync to govern on-premises application access using groups.
**Type:** New feature
> * Support at least 25 requests per second per tenant to ensure that users and groups are provisioned and deprovisioned without delay (Required)
1. When the provisioning cycle begins, the service checks if the current access token is valid and exchanges it for a new token if needed. The access token is provided in each request made to the app and the validity of the request is checked before each request.
Blocking authentication transfer in Microsoft Entra ID is a critical security control. It helps protect against token theft and replay attacks by preventing the use of device tokens to silently authenticate on other devices or browsers. When authentication transfer is enabled, a threat actor who gains access to one device can access resources to nonapproved devices, bypassing standard authentication and device compliance checks. When administrators block this flow, organizations can ensure that each authentication request must originate from the original device, maintaining the integrity of the device compliance and user session context.
Assume high risk users are compromised by threat actors. Without investigation and remediation, threat actors can execute scripts, deploy malicious applications, or manipulate API calls to establish persistence, based on the potentially compromised user's permissions. Threat actors can then exploit misconfigurations or abuse OAuth tokens to move laterally across workloads like documents, SaaS applications, or Azure resources. Threat actors can gain access to sensitive files, customer records, or proprietary code and exfiltrate it to external repositories while maintaining stealth through legitimate cloud services. Finally, threat actors might disrupt operations by modifying configurations, encrypting data for ransom, or using the stolen information for further attacks, resulting in financial, reputational, and regulatory consequences.
author: nguhiu
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insightly SAML.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks SCIM Connector.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon SAML.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML).
Learn how to configure single sign-on between Microsoft Entra ID and Adobe Identity Management (SAML).
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Citrix Cloud SAML SSO.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Fareharbor SAML SSO.
Learn how to configure single sign-on between Microsoft Entra ID and Flipsnack SAML.
services: active-directory
Learn how to configure SAML single sign-on between Microsoft Entra ID and a GitHub enterprise with Enterprise Managed Users.
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Oktopost SAML.
Learn how to configure single sign-on between Microsoft Entra ID and Resource Central – SAML SSO for Meeting Room Booking System.
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Standard for Success Accreditation.
Learn how to configure single sign-on between Microsoft Entra ID and Standard for Success K-12.
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Timeclock 365 SAML.
author: nguhiu
author: nguhiu
author: nguhiu
1. Identify a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016 to run Microsoft Entra Connect. If not enabled already, [enable TLS 1.2 on the server](./how-to-connect-install-prerequisites.md#enable-tls-12-for-azure-ad-connect). Add the server to the same Active Directory forest as the users whose passwords you need to validate. It should be noted that installation of Pass-Through Authentication agent on Windows Server Core versions isn't supported.
manager: mwongerapk
Sign in with the user account in a web browser. For instance, sign in to the [Azure portal](https://portal.azure.com) in a private browsing window. If you're prompted to change the password, set a new password. Then try connecting again.
Protected actions use a Conditional Access authentication context, so you must configure an authentication context and add it to a Conditional Access policy. If you already have a policy with an authentication context, you can skip to the next section.
Include file
For hybrid-joined devices, users must first authenticate with another method such as a password, smartcard or FIDO2 key, before using TAP to set up Windows Hello for Business.
Microsoft Authenticator will streamline same-device sign-ins by removing number entry, requiring only a Yes/No confirmation, and improve onboarding by prioritizing Microsoft Entra accounts and highlighting QR code scanning. Rollout begins late September to mid-October 2025, with no admin action needed.
Without Conditional Access policies protecting security information registration, threat actors can exploit unprotected registration flows to compromise authentication methods. When users register multifactor authentication and self-service password reset methods without proper controls, threat actors can intercept these registration sessions through adversary-in-the-middle attacks or exploit unmanaged devices accessing registration from untrusted locations. Once threat actors gain access to an unprotected registration flow, they can register their own authentication methods, effectively hijacking the target's authentication profile. The threat actors can bypass security controls and potentially escalate privileges throughout the environment because they can maintain persistent access by controlling the MFA methods. The compromised authentication methods then become the foundation for lateral movement as threat actors can authenticate as the legitimate user across multiple services and applications.
- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)
- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)
- [Get started with a phishing-resistant passwordless authentication deployment](/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication)
- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)
- [Deploy multifactor authentication](/entra/identity/authentication/howto-mfa-getstarted)
>[!IMPORTANT]
Discover how linkable identifiers like session IDs and unique token identifiers in Microsoft Entra help track and investigate identity-related activities, enhancing security and transparency.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forcepoint Cloud Security Gateway - User Authentication.
Learn how to configure single sign-on between Microsoft Entra ID and Forcepoint Cloud Security Gateway - User Authentication.
Learn how to configure adaptive session lifetime policies in Microsoft Entra to manage sign-in frequency and browser session persistence effectively.
author: MicrosoftGuyJFlo
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks Cloud Identity Engine - Cloud Authentication Service.
Learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks Cloud Identity Engine - Cloud Authentication Service.
author: nguhiu
author: nguhiu
};
- How to configure a bearer token.
Token protection, also called token binding, helps prevent token theft by making sure a token is usable only from the intended device. Token protection uses cryptography so that without the client device key, no one can use the token.
Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and TAP App Security.
author: nguhiu
author: nguhiu
author: nguhiu
services: active-directory
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Directory Services Protector.
author: nguhiu
You can create a group that contains all direct reports of a manager. When the manager's direct reports change in the future, the group's membership is adjusted automatically.
1. [Agent creates a report-only policy with a phased rollout](#agent-creates-a-report-only-policy-with-a-phased-rollout)
Step-by-step guide to identifying, triaging, and removing unused security and distribution groups in Active Directory Domain Services (AD DS) using a structured scream test methodology. Improve security and reduce administrative burden by cleaning up groups no longer needed in your domain.
author: Justinha
services: active-directory
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and LabLog.
Learn how to configure single sign-on between Microsoft Entra ID and SafetyCulture (formerly iAuditor).
author: nguhiu
author: nguhiu
- Augmentation Loop
When you publish an application through Microsoft Entra application proxy, you create an external URL for your users. This URL gets the default domain *`yourtenant.msappproxy.net`*. For example, if you publish an app named *Expenses* in your tenant named *Contoso*, the external URL is *`https://expenses-contoso.msappproxy.net`*. If you want to use your own domain name instead of *`msappproxy.net`*, you can configure a custom domain for your application.
This article shows the new and updated documentation for the Microsoft Entra application management.
Learn how to configure single sign-on between Microsoft Entra ID and FortiWeb Web Application Firewall.
author: nguhiu
author: nguhiu
author: nguhiu
Learn how to configure single sign-on between Microsoft Entra ID and Maximo Application Suite.
services: active-directory
author: nguhiu
| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |
**Remediation action**
**Remediation action**
**Remediation action**
**Remediation action**
Learn how to use Microsoft Entra audit logs to identify and troubleshoot Conditional Access policy modifications in your environment.
The [What If tool](what-if-tool.md) in Conditional Access is powerful when trying to understand why a policy was or wasn't applied to a user in a specific circumstance or if a policy would apply in a known state.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to MX3 Diagnostics Connector.
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.
Use the following steps to configure and start the provisioning:
- Microsoft Entra Connect must be installed on a domain-joined Windows Server 2016-2022. We recommend using domain-joined Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported Windows Server version may cause service failures or unexpected behavior.
The Microsoft identity platform can issue v1.0 tokens and v2.0 tokens. For more information about these tokens, refer to [Access tokens](/entra/identity-platform/access-tokens).
| **Roles** | [Hybrid Administrator](/entra/identity/role-based-access-control/permissions-reference#hybrid-administrator) is required to call the Microsoft Graph APIs to read and update SOA of groups.<br>[Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator) or [Cloud Application Administrator](/entra/identity/role-based-access-control/permissions-reference#cloud-application-administrator) is required to grant user consent to the required permissions to Microsoft Graph Explorer or the app used to call the Microsoft Graph APIs. |
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
manager: martinco
Conditional Access App Control uses a reverse proxy architecture and is uniquely integrated with Microsoft Entra Conditional Access. Microsoft Entra Conditional Access allows you to enforce access controls on your organization’s apps based on certain conditions. The conditions define what user or group of users, cloud apps, and locations and networks a Conditional Access policy applies to. After you determine the conditions, you can route users to Microsoft Defender for Cloud Apps where you can protect data with Conditional Access App Control by applying access and session controls.
Sign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps.
When high-risk sign-ins are not properly restricted through Conditional Access policies, organizations expose themselves to security vulnerabilities. Threat actors can exploit these gaps for initial access through compromised credentials, credential stuffing attacks, or anomalous sign-in patterns that Microsoft Entra ID Protection identifies as risky behaviors. Without appropriate restrictions, threat actors who successfully authenticate during high-risk scenarios can perform privilege escalation by misusing the authenticated session to access sensitive resources, modify security configurations, or conduct reconnaissance activities within the environment. Once threat actors establish access through uncontrolled high-risk sign-ins, they can achieve persistence by creating additional accounts, installing backdoors, or modifying authentication policies to maintain long-term access to the organization's resources. The unrestricted access enables threat actors to conduct lateral movement across systems and applications using the authenticated session, potentially accessing sensitive data stores, administrative interfaces, or critical business applications. Finally, threat actors achieve impact through data exfiltration, or compromise business-critical systems while maintaining plausible deniability by exploiting the fact that their risky authentication was not properly challenged or blocked.
- **Risky users**: The agent suggests a policy to require secure password change for high risk users. Requires Microsoft Entra ID P2 license.
1. On the left menu, select the **Approvals** page.
|---------|---------|
- Message body
- [Manage workflow versions](manage-workflow-tasks.md)
The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.
When using the [Microsoft Entra B2B](~/external-id/what-is-b2b.md) invite experience, you must already know the email addresses of the external guest users you want to bring into your resource directory and work with. Directly inviting each user works great when you're working on a smaller or short-term project and you already know all the participants. This process is harder to manage if you have lots of users you want to work with, or if the participants change over time. For example, you might be working with another organization and have one point of contact with that organization, but over time more users from that organization will also need access.
Say goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
1. On the Execution conditions page, select the **Execution User Scope** tab.
- You must have [Microsoft Entra ID Governance or Microsoft Entra Suite licenses](licensing-fundamentals.md).
To view information about the Access Review Agent, open up the Access Review Agent to get to the overview page. The highlight of the overview page is the Agent summary, which provides a quick summary of agent actions over the course of the last 30 days.
An attribute with a Boolean data type has a user input type of CheckboxSingleSelect. You can modify the text that displays next to the checkbox and include hyperlinks.
To start the training, go to [Guided project – Build a sample app to evaluate Microsoft Entra External ID](https://aka.ms/eeid/training-module) and follow the units in order.
- Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.
> [!NOTE]
When Microsoft Entra External ID issues a security token for an authenticated user, it includes the names of the roles you've assigned the user or group in the security token's roles claim. An application that receives that security token in a request can then make authorization decisions based on the values in the roles claim.
Reference documentation for a custom authentication extension that invokes the emailOtpSend event for External ID customer configurations.
This article describes how to enforce MFA for your customers by creating a Microsoft Entra Conditional Access policy and adding MFA to your sign-up and sign-in user flow.
This article describes how to create a sign-in and sign-up user flow. After you create the user flow, the next step is to [add your application to the user flow](how-to-user-flow-add-application.md). You can create multiple user flows if you have multiple applications that you want to offer to customers. Or, you can use the same user flow for many applications. However, an application can have only one user flow.
:::image type="content" source="media/how-to-enable-password-reset-customers/sspr-flow.png" alt-text="Screenshot that shows the self-service password rest flow.":::
By setting up federation with Google, you allow customers to sign in to your applications with their own Google accounts. After you add Google as one of your user flow's sign-in options, customers can sign up and sign in to your application with a Google account. (Learn more about [authentication methods and identity providers for customers](concept-authentication-methods-customers.md).)
- It provides a more consistent user experience. From the user's perspective, they remain in your domain during the sign in process rather than redirecting to the default domain *<tenant-name>.ciamlogin.com*.
When you enter an email address to create an account, your email is verified through a one-time passcode. Then you can create a new password and provide more details, such as your name, country or region, and other information. Once your account is created, your email becomes your sign-in ID.
Microsoft will enforce multifactor authentication (MFA) for all Azure resource management actions starting October 1, 2025, with a postponement option until July 2026. Users must enable MFA, update Azure CLI/PowerShell, and can apply Azure Policy to assess impact. Gallatin customers are advised to implement MFA without enforcement.
By setting up federation with Facebook, you can allow customers to sign in to your applications with their own Facebook accounts. After you've added Facebook as one of your application's sign-in options, on the sign-in page, customers can sign-in to Microsoft Entra External ID with a Facebook account. (Learn more about [authentication methods and identity providers for customers](/entra/external-id/customers/concept-authentication-methods-customers).)
After creating a new external tenant, you can customize the end-user experience. Create a custom look and feel for users signing in to your apps by configuring **Company branding** settings for your tenant. With these settings, you can add your own background images, colors, company logos, and text to customize the sign-in experiences across your apps.
You can specify which built-in or custom attributes you want to include as claims in the token that Microsoft Entra ID sends to your application.
The Application user activity feature under Usage & insights provides data analytics on user activity and engagement for registered applications in your tenant. You can use this feature to view, query, and analyze user activity data in the Microsoft Entra admin center. This feature can help you uncover valuable insights that can aid strategic decisions and drive business growth.
> | [Directory Synchronization Accounts](#directory-synchronization-accounts) | Only used by Microsoft Entra Connect service. | d29b2b05-8046-44ba-8758-1e26182fcf32 |
By setting up federation with Microsoft account (live.com) using OpenID Connect (OIDC) identity provider, you enable users to sign up and sign in to your applications using their existing Microsoft accounts (MSA).
Step-by-step instructions on using PowerShell to assign a managed identity access to an Azure resource or another resource.
Deleting a user-assigned managed identity won't remove the reference from any resource it was assigned to. Remove those from the resource itself. For example, for a VM or virtual machine scale set, use the `az vm/vmss identity remove` command.
A Microsoft Entra documentation page was updated: Assign App Role Managed Identity.
A Microsoft Entra documentation page was updated: How Manage User Assigned Managed Identities.
Learn how to include or exclude users, groups, and workload identities in Conditional Access policies for secure and flexible access management.
- If you're unfamiliar with managed identities for Azure resources, see [Managed identity for Azure resources overview](./overview.md).
- If you're unfamiliar with managed identities for Azure resources, see [Managed identity for Azure resources overview](./overview.md).
The steps outlined below show how you grant access to a service using Azure RBAC. Check specific service documentation on how to grant access; for example, check [Azure Data Explorer](/azure/data-explorer/data-explorer-overview) for instructions. Some Azure services are in the process of adopting Azure RBAC on the data plane.
As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `6bf85cfa-ac8a-4be5-b5de-425a0d0dc016`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.
1. Navigate to **Global Secure Access** > **Settings** > **Session management** > **Custom Block Page**
- The client machine is at least Windows 10 and is Microsoft Entra joined or hybrid joined device. The client machine must also have line of sight to the private resources and DC (user is in a corporate network and accessing on-premises resources). User identity used for joining the device and accessing these resources was created in Active Directory (AD) and synced to Microsoft Entra ID using Microsoft Entra Connect.
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
manager: dougeby
manager: dougeby
1. To test allow-listing, create a rule in the Threat Intelligence policy to allow access to the site. Within 2 minutes, you should be able to access it. (You may need to clear your browser cache.)
GET hhttps://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=msn.com/en-us/sports
1. Enter a name, select a [web category](reference-web-content-filtering-categories.md) or a valid FQDN, and then select **Add**.
A Microsoft Entra documentation page was updated: Configure Threat Intelligence.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Android client app.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.
manager: dougeby
manager: dougeby
ai-usage: ai-assisted
1. User requests a DNS query for `app.contoso.com`. If not cached locally, the DNS query is sent to the DNS proxy at the GSA edge.
> [!IMPORTANT]
manager: dougeby
Guest devices on your network might not have the client installed. To ensure that those devices adhere to your network security policies, you need their traffic routed through the Global Secure Access endpoint. Remote network connectivity solves this problem. No clients need to be installed on guest devices. All outgoing traffic from the remote network is going through security evaluation by default.
Since threat intelligence is critical for users' basic security posture, you can alternatively link your threat intelligence policy to the baseline security profile, which applies policy to all users' traffic in your tenant.
1. Create [Real-time Protection policy](https://docs.netskope.com/en/inline-policies/) to allow access to Private Apps.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.