:::image type="content" border="true" source="media/reference-domain-services-tls-enforcement/enable.png" alt-text="Screenshot that shows how to enable TLS 1.2 Only Mode for Domain Services.":::
October 2025 Entra briefing: PIM API retirement and Purview eDiscovery enforcement lead a documentation-heavy month
October’s clearest operational changes are a dated retirement and an access-enforcement rollout. Microsoft Entra Privileged Identity Management (PIM) Iteration 2 beta APIs are scheduled for retirement on 28 October 2026, while Microsoft Purview is applying Entra Conditional Access compliance to eDiscovery administrators’ SharePoint access through November 2025. Cross-cloud synchronization and Teams group-chat authentication also have staged availability signals, but neither should be summarized more broadly than the supplied notices support. The cross-cloud notice calls the capability public preview and opt-in while also listing general availability for late September to early October 2025; the Teams notice schedules default-on support for 3–6 November.
- PIM Iteration 2 beta APIs are on a dated retirement pathMicrosoft Entra ID Governance — Privileged Identity Management
The 29 October Message Center notice says Microsoft Entra PIM Iteration 2 beta APIs will be retired on 28 October 2026 and that applications using them will fail afterward. It directs organizations to stop new development on Iteration 2 and migrate to the Iteration 3 APIs, identified in the notice as GA. This is a concrete API retirement, not routine documentation maintenance.
- Purview eDiscovery access will be enforced through Entra Conditional AccessMicrosoft Entra Conditional Access and Microsoft Purview eDiscovery
Microsoft Purview will enforce Entra Conditional Access policies for eDiscovery administrators accessing SharePoint content. Non-compliant users will be blocked, with rollout beginning in October and completing by November 2025. The change also adds FilePreviewed as an audit activity, making this both a behavior-enforcement and monitoring change.
- Cross-cloud synchronization is available, but its status is not an unqualified GA announcementMicrosoft Entra cross-cloud synchronization
Microsoft Entra cross-cloud synchronization automates user lifecycle management across Microsoft commercial, US Government, and China clouds and supports configuration through the portal, PowerShell, and API. The notice requires specific licensing and administrator enablement, but describes the capability as public preview and opt-in while also listing GA for late September to early October 2025. Administrators should preserve that status distinction when assessing adoption.
- Teams group-chat agents and bots are scheduled to support Entra authenticationMicrosoft Teams group-chat agents and bots with Microsoft Entra authentication
Beginning 3–6 November 2025, Microsoft Teams agents and bots in group chats will support Microsoft Entra authentication. The notice says the capability is enabled by default and requires no admin action. Users who lack the Teams app or have not granted Entra consent will receive a private prompt to install the app and provide permissions.
- External ID fraud protection and Application Proxy CAE remain explicitly preview capabilitiesMicrosoft Entra External ID; Global Secure Access Application Proxy
The October documentation signals identify Microsoft Entra External ID integrations with Arkose Labs and HUMAN Security for sign-up fraud protection, and Continuous Access Evaluation for Application Proxy under Global Secure Access, as preview topics. The supplied evidence does not establish a GA date or changed tenant default for either capability, so these updates should not be treated as launch announcements.
Prioritize an inventory of applications using PIM Iteration 2 beta APIs and plan migration to the Iteration 3 GA APIs before 28 October 2026; the notice says applications will fail after retirement. For eDiscovery, review the Conditional Access compliance path for administrators accessing SharePoint content and account for the new FilePreviewed audit activity. For cross-cloud synchronization, confirm the applicable licensing and administrator-enablement prerequisites before opting in. Teams requires no admin enablement, but users without the Teams app or Entra consent may receive a private installation and consent prompt. If service principal-less authentication is in scope, review the Workload ID mitigation guidance, although no retirement deadline is supplied. The updated ID Protection,
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
530 updates by product
Microsoft Entra ID
471 updatesGeneral
301minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
Updatedmanager: dougeby
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: Free
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: Free.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
Updatedmanager: dougeby
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
Updatedmanager: dougeby
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
Updatedmanager: dougeby
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
Updatedmanager: dougeby
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P1
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P1.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
Updatedmanager: dougeby
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: P2
UpdatedA Microsoft Entra documentation page was updated: minimumlicense: P2.
minimumlicense: Workload
Updatedmanager: dougeby
Manage App Consent Policies
UpdatedUpdates to this consent policy will have at least 30 days of given notice.
To assign a group to an enterprise app, replace `Get-EntraUser` with `Get-EntraGroup` and replace `New-EntraUserAppRoleAssignment` with `New-EntraGroupAppRoleAssignment`.
include file
Updatedinclude file
| App or service | Limitations |
SharePoint Backup Administrator
Exchange Backup Administrator
Permissions Reference
Updated> | [Dynamics 365 Business Central Administrator](#dynamics-365-business-central-administrator) | Access and perform all administrative tasks on Dynamics 365 Business Central environments. | 963797fb-eb3b-4cde-8ce3-5878b3f32a3f |
Connect Staged Rollout
Updatedmanager: mwongerapk
Manage App Consent Policies
UpdatedUpdates to this consent policy will have at least 30 days of given notice.
:::image type="content" border="true" source="media/how-to-user-source-of-authority-configure/event-6956.png" alt-text="Screenshot of event ID 6956.":::
Check backup location
Updated- **Primary Path**: `F:\\GPO\\Backups`
Prerequisites
UpdatedYou need the following to use Microsoft Entra Cloud Sync:
Agent Optimization
Updatedmanager: dougeby
F5 Big Ip Kerberos Advanced
Updated* A Microsoft Entra ID Free account, or higher
* A Microsoft Entra ID Free account, or higher
A Microsoft Entra documentation page was updated: Take over an unmanaged directory as administrator in Microsoft Entra ID.
author: MicrosoftGuyJFlo
Prepare Converted Groups
Updatedauthor: omondiatieno
Custom Attribute Mapping
Updated|Method|Description|URL|
Gpad Prereqs
Updated>
21822
RemovedA Microsoft Entra documentation page was updated: 21822.
Connect Health Agent Install
Updated- Make sure that you satisfy the [requirements](how-to-connect-health-agent-install.md#requirements) to install Microsoft Entra Connect Health.
Once you identify the employees for SOA conversion, follow these steps:
:::image type="content" source="media/how-to-user-source-of-authority-configure/try-update.png" alt-text="Screenshot of an attempt to update a user to verify it's read-only.":::
> [!NOTE]
> [!NOTE]
Develop Preview
Updatedmanager: pmwongera
A Microsoft Entra documentation page was updated: Multi Service Web App Access Storage.
author: cilwerner
Access Tokens
Updatedauthor: cilwerner
> [!NOTE]
Add and remove roles and tasks for Microsoft Azure and Google Cloud Platform (GCP) identities
Updated> [!NOTE]
> [!NOTE]
author: kengaderdus
> [!NOTE]
Claims Customization
Updatedauthor: cilwerner
Claims Validation
Updatedauthor: cilwerner
author: cilwerner
Create a custom query
Updated> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
Id Token Claims Reference
Updatedauthor: cilwerner
Id Tokens
Updatedauthor: cilwerner
Jwt Claims Customization
UpdatedA Microsoft Entra documentation page was updated: Jwt Claims Customization.
Libraries Daemon
Updatedmanager: pmwongera
Libraries Desktop
Updatedmanager: pmwongera
Libraries Mobile
Updatedmanager: pmwongera
Libraries Spa
Updatedmanager: pmwongera
Libraries Webapp
Updatedmanager: pmwongera
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
A Microsoft Entra documentation page was updated: Multi Service Web App Access Microsoft Graph As App.
A Microsoft Entra documentation page was updated: Multi Service Web App Access Microsoft Graph As User.
A Microsoft Entra documentation page was updated: Multi Service Web App Clean Up Resources.
> [!NOTE]
> [!NOTE]
> [!NOTE]
Optional Claims
Updatedauthor: cilwerner
Optional Claims Reference
Updatedauthor: cilwerner
> [!NOTE]
Refresh Tokens
Updatedauthor: cilwerner
Schema Extensions
Updatedauthor: cilwerner
> [!NOTE]
> [!NOTE]
A Microsoft Entra documentation page was updated: Tutorial V2 Shared Device Mode.
Use Custom Domain Url
Updatedmanager: dougeby
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
How to transition off of Microsoft Entra Permissions Management for the anticipated product deprecation.
View the latest public preview and general availability of features in Permissions Management.
How to add an account/subscription/project to Permissions Management after onboarding is complete.
How to configure Okta as an identity provider in Microsoft Entra Permissions Management.
How to create and view activity alerts and alert triggers in Microsoft Entra Permissions Management.
How to create and view permission analytics triggers in the Permission analytics tab in Permissions Management.
How to create and view rule-based anomaly alerts and alert triggers in Permissions Management.
How to create and view statistical anomaly alerts and alert triggers in the Statistical Anomaly tab in Permissions Management.
How to define and manage users, roles, and access levels in the Permissions Management User management dashboard.
How to enable or disable the controller in Permissions Management after onboarding is complete.
Frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
Quickstart guide - How to quickly onboard your Microsoft Entra Permissions Management product
How to onboard a Google Cloud Platform (GCP) project on Permissions Management.
How to a Microsoft Azure subscription on Permissions Management.
How to onboard an Amazon Web Services (AWS) account to Permissions Management.
How to view analytic information about access keys in Permissions Management.
How to view usage analytics about active resources in Permissions Management.
How to view analytic information about active tasks in Permissions Management.
How to view analytic information about groups in Permissions Management.
How to view analytic information about serverless functions in Permissions Management.
How to view analytic information about users in Permissions Management.
How to view and configure settings for collecting data from your authorization system.
How to view statistics and data about your authorization system in the Permissions Management.
Microsoft Entra Permissions Management glossary
How to generate, view, and apply rule recommendations in the Microsoft Entra Permissions Management Autopilot dashboard.
How to manage users and groups in the User management dashboard in Permissions Management.
How to view information about alerts and alert triggers in the Alerts dashboard in Permissions Management.
How to view data about the activity in your authorization system in the Microsoft Entra Permissions Management Dashboard.
How to view information about rules in the Autopilot dashboard in Permissions Management.
How to view information about identities that can access accounts from an external account in Permissions Management.
How to enable Microsoft Entra Permissions Management in your organization.
Review roles and the level of permissions assigned in Microsoft Entra Permissions Management.
How to create a rule in the Autopilot dashboard in Microsoft Entra Permissions Management.
How to configure AWS IAM Identity Center as an identity provider.
View current Microsoft Entra Permissions Management partners and their websites.
How to select group-based permissions settings with the User management dashboard.
How to add or remove a user in Microsoft Entra Permissions Management through the Microsoft Enter admin center.
How to use the Analytics dashboard in Permissions Management to view details about users, groups, active resources, active tasks, access keys, and serverless functions.
How to view current billable resources in your authorization system in Microsoft Entra Permissions Management.
How to view personal and organization information in the Account settings dashboard in Microsoft Entra Permissions Management.
How to view current privileged role assignments in the Microsoft Entra Insights tab.
How to view information about active and completed tasks in the Activities pane in Permissions Management.
How to create folders to organize Authorization Systems - accounts, subscriptions, and projects - in Microsoft Entra Permissions Management.
Teams Reader
UpdatedAssign the Teams Reader role to users who need to do the following tasks:
Dragon Administrator
UpdatedAssign the Dragon Administrator role to users who need to do the following tasks:
Agent Optimization
Updatedmanager: dougeby
Whats New
Updated| Date | Area | Description |
Tutorial Create Instance
Updated>
Add Remove Role Task
RemovedA Microsoft Entra documentation page was updated: Add Remove Role Task.
Add Remove User To Group
RemovedA Microsoft Entra documentation page was updated: Add Remove User To Group.
Attach Detach Permissions
RemovedA Microsoft Entra documentation page was updated: Attach Detach Permissions.
Clone Role Policy
RemovedA Microsoft Entra documentation page was updated: Clone Role Policy.
Configure Aws Iam
RemovedA Microsoft Entra documentation page was updated: Configure Aws Iam.
A Microsoft Entra documentation page was updated: Configure Okta As An Identity Provider.
Create Alert Trigger
RemovedA Microsoft Entra documentation page was updated: Create Alert Trigger.
A Microsoft Entra documentation page was updated: Create Approve Privilege Request.
Create Custom Queries
RemovedA Microsoft Entra documentation page was updated: Create Custom Queries.
Create Folders
RemovedA Microsoft Entra documentation page was updated: Create Folders.
A Microsoft Entra documentation page was updated: Create Group Based Permissions.
Create Role Policy
RemovedA Microsoft Entra documentation page was updated: Create Role Policy.
Create Rule
RemovedA Microsoft Entra documentation page was updated: Create Rule.
Delete Role Policy
RemovedA Microsoft Entra documentation page was updated: Delete Role Policy.
Faqs
RemovedA Microsoft Entra documentation page was updated: Faqs.
Modify Role Policy
RemovedA Microsoft Entra documentation page was updated: Modify Role Policy.
Multi Cloud Glossary
RemovedA Microsoft Entra documentation page was updated: Multi Cloud Glossary.
A Microsoft Entra documentation page was updated: Offboard Permissions Management.
A Microsoft Entra documentation page was updated: Onboard Add Account After Onboarding.
Onboard Aws
RemovedA Microsoft Entra documentation page was updated: Onboard Aws.
Onboard Azure
RemovedA Microsoft Entra documentation page was updated: Onboard Azure.
A Microsoft Entra documentation page was updated: Onboard Enable Controller After Onboarding.
Onboard Enable Tenant
RemovedA Microsoft Entra documentation page was updated: Onboard Enable Tenant.
Onboard Gcp
RemovedA Microsoft Entra documentation page was updated: Onboard Gcp.
Partner List
RemovedA Microsoft Entra documentation page was updated: Partner List.
A Microsoft Entra documentation page was updated: Permissions Management For Defender For Cloud.
A Microsoft Entra documentation page was updated: Permissions Management Quickstart Guide.
Permissions Reference
UpdatedA Microsoft Entra documentation page was updated: Permissions Reference.
Product Account Explorer
RemovedA Microsoft Entra documentation page was updated: Product Account Explorer.
Product Account Settings
RemovedA Microsoft Entra documentation page was updated: Product Account Settings.
Product Dashboard
RemovedA Microsoft Entra documentation page was updated: Product Dashboard.
A Microsoft Entra documentation page was updated: Product Data Billable Resources.
Product Data Sources
RemovedA Microsoft Entra documentation page was updated: Product Data Sources.
A Microsoft Entra documentation page was updated: Product Define Permission Levels.
Product Permission Analytics
RemovedA Microsoft Entra documentation page was updated: Product Permission Analytics.
A Microsoft Entra documentation page was updated: Product Privileged Role Insights.
Product Roles Permissions
RemovedA Microsoft Entra documentation page was updated: Product Roles Permissions.
Product Rule Based Anomalies
RemovedA Microsoft Entra documentation page was updated: Product Rule Based Anomalies.
A Microsoft Entra documentation page was updated: Product Statistical Anomalies.
Recommendations Rule
RemovedA Microsoft Entra documentation page was updated: Recommendations Rule.
Revoke Task Readonly Status
RemovedA Microsoft Entra documentation page was updated: Revoke Task Readonly Status.
Ui Autopilot
RemovedA Microsoft Entra documentation page was updated: Ui Autopilot.
Ui Dashboard
RemovedA Microsoft Entra documentation page was updated: Ui Dashboard.
Ui Tasks
RemovedA Microsoft Entra documentation page was updated: Ui Tasks.
Ui Triggers
RemovedA Microsoft Entra documentation page was updated: Ui Triggers.
Ui User Management
RemovedA Microsoft Entra documentation page was updated: Ui User Management.
Usage Analytics Access Keys
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Access Keys.
A Microsoft Entra documentation page was updated: Usage Analytics Active Resources.
Usage Analytics Active Tasks
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Active Tasks.
Usage Analytics Groups
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Groups.
Usage Analytics Home
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Home.
A Microsoft Entra documentation page was updated: Usage Analytics Serverless Functions.
Usage Analytics Users
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Users.
View Role Policy
RemovedA Microsoft Entra documentation page was updated: View Role Policy.
A Microsoft Entra documentation page was updated: Whats New In Permissions Management.
Agent Optimization
Updatedmanager: dougeby
Authentication
43There might be situations while configuring or managing an application where you don't want tokens to be issued for an application. Or, you might want to block an application that you don't want your employees to try to access, like the deprecated Azure AD PowerShell modules (AppID 1b730954-1685-4b74-9bfd-dac224a7b894). To block user access to an application, you can disable user sign-in for the application, which prevents all tokens from being issued for that application.
Include a test group of users for each policy, but not both. If a user is included in both policies, or any policy with both conditions, the user has to satisfy MFA during sign-in. They also have to satisfy the custom control, which makes them redirected to the external provider a second time.
Import Groups module
UpdatedYou can use the following PowerShell script to automate Group SOA updates by using app-based authentication.
author: justinha
Password scrambling guidance to deploy passwordless and phishing-resistant authentication for organizations that use Microsoft Entra ID.
- An Azure subscription. [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
21953
UpdatedWithout Local Admin Password Solution (LAPS) deployed, threat actors exploit static local administrator passwords to establish initial access. After threat actors compromise a single device with a shared local administrator credential, they can move laterally across the environment and authenticate to other systems sharing the same password. Compromised local administrator access gives threat actors system-level privileges, letting them disable security controls, install persistent backdoors, exfiltrate sensitive data, and establish command and control channels.
author: MicrosoftGuyJFlo
For feature feedback, vote at [Connect Health User Voice channel](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789)
- **LDAP Authentication/Queries** – Applications can have LDAP server settings pointing to AD and perform binds or lookups, custom-developed or third-party products prompting users for AD credentials.
A Microsoft Entra documentation page was updated: Multi Service Web App Authentication App Service.
Native Authentication Api
Updatedauthor: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
manager: pmwongera
author: kengaderdus
author: kengaderdus
manager: pmwongera
manager: pmwongera
author: kengaderdus
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
author: henrymbuguakiarie
manager: pmwongera
manager: pmwongera
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
Monitoring
27Tutorial Govern Monitor
Updated> [!div class="checklist"]
Sla Performance
Updated| June | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
How to create a custom query in the Audit dashboard in Microsoft Entra Permissions Management.
How to create, view, and share a custom report in the Permissions Management.
How to filter and query user activity in Microsoft Entra Permissions Management.
How to view and download the Permissions Analytics Report in Permissions Management.
How to view system reports in the Reports dashboard in Permissions Management.
Use queries to see how users access information in an authorization system in Permissions Management
NewHow to use queries to see how users access information in an authorization system in Permissions Management.
How to generate and view a system report in the Permissions Management.
View a list and description of all system reports available in Permissions Management.
How to generate an on-demand report from a query in the **Audit** dashboard in Permissions Management.
All Reports
RemovedA Microsoft Entra documentation page was updated: All Reports.
Audit Trail Results
RemovedA Microsoft Entra documentation page was updated: Audit Trail Results.
Product Audit Trail
RemovedA Microsoft Entra documentation page was updated: Product Audit Trail.
A Microsoft Entra documentation page was updated: Product Permissions Analytics Reports.
Product Reports
RemovedA Microsoft Entra documentation page was updated: Product Reports.
Report Create Custom Report
RemovedA Microsoft Entra documentation page was updated: Report Create Custom Report.
Report View System Report
RemovedA Microsoft Entra documentation page was updated: Report View System Report.
Ui Audit Trail
RemovedA Microsoft Entra documentation page was updated: Ui Audit Trail.
Troubleshooting
2521837
Updated**Remediation action**
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
Purpose:
Updatedmanager: pmwongera
> [!NOTE]
> [!NOTE]
> [!NOTE]
How to revoke access to high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard.
How to attach and detach permissions for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management.
How to create a role/policy in the Remediation dashboard.
How to create or approve a request for permissions in the Remediation dashboard.
Understand potential error codes that may appear during onboarding of Microsoft Entra Permissions Management
How to view existing roles/policies and requests for permission in the Remediation dashboard in Permissions Management.
How to view and filter information about roles/policies in the Microsoft Entra Permissions Management Remediation dashboard.
How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
How to clone a role/policy in Microsoft Entra Permissions Management.
How to delete a role/policy in the Microsoft Entra Permissions Management Remediation dashboard.
How to modify a role/policy in the Remediation dashboard in Microsoft Entra Permissions Management.
Troubleshoot issues with Permissions Management
Error Codes Onboarding
RemovedA Microsoft Entra documentation page was updated: Error Codes Onboarding.
Troubleshoot
RemovedA Microsoft Entra documentation page was updated: Troubleshoot.
Ui Remediation
RemovedA Microsoft Entra documentation page was updated: Ui Remediation.
Fundamentals
22Configure Security
Updated| Check | Minimum required license |
Overview
UpdatedA Microsoft Entra documentation page was updated: Overview.
There are several ways that you might manage applications in Microsoft Entra ID. The easiest way to start managing an application is to use a preintegrated application from the Microsoft Entra gallery, for both SaaS and on-premises or private cloud hosted applications. Developing your own application and registering it in Microsoft Entra ID is an option.
Whats New Archive
UpdatedA Microsoft Entra documentation page was updated: Whats New Archive.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Sspr Writeback
Updatedauthor: justinha
For a list of common hybrid synchronization scenarios, see [Common scenarios](common-scenarios.md).
Configure Security
Updated| Check | Minimum required license |
A Microsoft Entra documentation page was updated: Zero Trust Protect Identities.
A Microsoft Entra documentation page was updated: Zero Trust Protect Engineering Systems.
Zero Trust Protect Tenants
UpdatedA Microsoft Entra documentation page was updated: Zero Trust Protect Tenants.
Source Of Authority Overview
UpdatedOne AD DS minimization approach is to convert the Group Source of Authority (SOA) to Microsoft Entra ID. This approach lets you directly manage those groups in the cloud. You can delete AD DS groups that you no longer need on-premises. If you need to keep a group on-premises, you can configure security group provisioning from Microsoft Entra ID to AD DS. Then you can make changes to the group in Microsoft Entra ID and have those changes reflected in the on-premises group.
Whats New
Updated**Type:** New feature
|Edge browser with profile login | ✅ |
Assignment Network
UpdatedSome IP addresses can't be mapped to a specific country or region. To capture these IP locations, select the box **Include unknown countries/regions** when defining a geographic location. This option allows you to choose if these IP addresses should be included in the named location. Use this setting when the policy using the named location should apply to unknown locations.
Plan Conditional Access
UpdatedStart with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
author: cilwerner
> [!NOTE]
An introduction to Microsoft Entra Permissions Management.
Overview
RemovedA Microsoft Entra documentation page was updated: Overview.
- [Microsoft Entra Domain Services](/entra/identity/domain-services/overview)
Developer
16Before integrating applications with Microsoft Entra ID, it's important to know where you are and where you want to go. The following questions are intended to help you think about your Microsoft Entra application integration project.
View Applications Portal
Updated- **Enterprise Applications** shows non-Microsoft applications.
> [!NOTE]
Continuation Token
Updatedauthor: kengaderdus
Custom Attributes Note
Updatedauthor: kengaderdus
author: kengaderdus
Native Auth Api Cors Note
Updatedauthor: kengaderdus
Native Auth Challenge Type
Updatedauthor: kengaderdus
> [!NOTE]
author: kengaderdus
User Attribute Format
Updatedauthor: kengaderdus
How to view the Permissions Management API integration settings and create service accounts and roles.
How to configure ServiceNow with Microsoft Entra Permissions Management.
4. Select the app, then click **Install**.
A Microsoft Entra documentation page was updated: Configure Servicenow Application.
Integration Api
RemovedA Microsoft Entra documentation page was updated: Integration Api.
Conditional Access
7With the Conditional Access optimization agent chat interface, you can use natural language to get more information on a policy suggestion or have the agent present the suggestions in a different order.
:::image type="content" source="media/conditional-access-agent-optimization-review-suggestions/review-suggestions-details.png" alt-text="Screenshot of the agent with the policy suggestion details open." lightbox="media/conditional-access-agent-optimization-review-suggestions/review-suggestions-details-expanded.png":::
1. At the bottom of the main **Settings** page, select the **Save** button.
author: MicrosoftGuyJFlo
Delegate By Task
Updated> | Create terms of use | [Conditional Access Administrator](permissions-reference.md#conditional-access-administrator) | [Security Administrator](permissions-reference.md#security-administrator) |
Plan Conditional Access
Updated- If a policy is disabled and no longer needed, **delete it**.
Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.
Architecture
6Backup Authentication System
UpdatedTo enhance its resilience posture, the backup authentication system can't perform fresh revocation checks. Instead, it relies on the state of the certificate revocation list (CRL) check that's performed when the session was last backed up. If you need to revoke before this backup expires, you should explicitly revoke the session instead of waiting for the CRL.
Recover From Deletions
Updated* A soft-deleted object isn't restored within 30 days.
Backup Authentication System
Updatedauthor: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
manager: martinco
Microsoft identity platform
6Microsoft Teams group chat agents and bots will support Entra authentication starting November 3-6, 2025. Users without the Teams app or Entra consent receive a private prompt to install the app and grant permissions. This feature is enabled by default, requiring no admin action.
Quickstarts Free Trial Note
UpdatedIf you don't have an [Azure subscription](/azure/guides/developer/azure-developer-guide#understanding-accounts-subscriptions-and-billing), create an [Azure free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin.
Adal Msal Migration
Updatedmanager: pmwongera
Learn how to add authentication to a React single-page app (SPA) using the Microsoft identity platform.
Whats New Docs
UpdatedWelcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
Learn how to test sign-in and sign-out in a React single-page app (SPA) using the Microsoft identity platform.
Provisioning
5Enable Termination Lookahead query for your Workday-to-AD/Microsoft Entra ID provisioning job.
- References:
If you want to provision the group back to AD DS, plan to complete the following steps to preserve the OU Path and set it in the **Group Provision to AD** configuration with the right mapping:
Tutorial Group Provisioning
Updated9. There are two possible approaches to set the OU:
How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain
UpdatedObjects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.
Governance
4A Microsoft Entra documentation page was updated: minimumlicense: P2, Governance.
A Microsoft Entra documentation page was updated: minimumlicense: P2, Governance.
A Microsoft Entra documentation page was updated: minimumlicense: P2, Governance.
- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.
Security
4A Microsoft Entra documentation page was updated: sfipillar: Protect tenants and isolate production systems.
> [!NOTE]
Certificate Credentials
UpdatedA Microsoft Entra documentation page was updated: Certificate Credentials.
Learn how Microsoft Entra Permissions Management helps strengthen security in cloud environments as an enhancement for Defender for Cloud
Standards
4In a production environment, we recommended using [Azure Front Door with a Standard/Premium subscription](/azure/frontdoor/standard-premium/troubleshoot-cross-origin-resources) as a reverse proxy.
Scim Validator Tutorial
Updatedai-usage: ai-assisted
"members": []
Saml Claims Customization
Updatedauthor: cilwerner
Branding
1Howto Add Branding In Apps
Updatedauthor: cilwerner
Microsoft Entra Agent ID
1 updateTroubleshooting
1The Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion, you can have the agent update the associated policy with one click-remediation.
Microsoft Entra ID Protection
7 updatesAuthentication
3Microsoft Purview will enforce Entra conditional access policies for eDiscovery admins by blocking non-compliant users from accessing SharePoint content and adding a new ‘FilePreviewed’ audit log activity. Rollout begins now and completes by November 2025, enhancing security and compliance monitoring.
Learn how to create Conditional Access policies using Microsoft Entra ID Protection to enforce secure password changes for users with elevated risk.
Protect your organization by implementing Conditional Access policies that address sign-in risks using Microsoft Entra ID Protection.
Fundamentals
3- Add corporate VPNs and IP address ranges to [named locations](../identity/conditional-access/concept-assignment-network.md) in your Conditional Access policies to reduce false positives.
Identity Protection Risks
UpdatedAlso referred to as Adversary in the Middle, this high precision detection is triggered when an authentication session is linked to a malicious reverse proxy. In this kind of attack, the adversary can intercept the user's credentials, including tokens issued to the user. The Microsoft Security Research team uses Microsoft Defender for Cloud Apps to capture the identified risk and raises the user to **High** risk. We recommend administrators manually investigate the user when this detection is triggered to ensure the risk is cleared. Clearing this risk might require secure password reset or revocation of existing sessions.
Source Ip Restoration
Updated- [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks) get a consistent view of original user Source IP address for assessing various risk scores.
Monitoring
1Howto Export Risk Data
UpdatedAccess more queries and visual insights based on AADUserRiskEvents and AADRisky Users logs in the [Impact analysis of risk-based access policies workbook](workbook-risk-based-policy-impact.md).
Microsoft Entra ID Governance
10 updatesGovernance
6Learn how to show suggested access packages to users in My Access so they can quickly find the most relevant access packages.
This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.
Access Review Agent
UpdatedSay goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.
Licensing Governance
UpdatedThe following table shows the licensing requirements for Microsoft Entra ID Governance features for member users. Microsoft Entra Suite includes all features of Microsoft Entra ID Governance. Licensing information and example license scenarios for Entitlement management, Access reviews, and Lifecycle Workflows are provided following the table.
Apps
Updated| [Genesys Cloud for Azure](../identity/saas-apps/purecloud-by-genesys-provisioning-tutorial.md) | ● | ● |
1. Sign in to the My Access portal at [https://myaccess.microsoft.com](https://myaccess.microsoft.com) as the direct manager of the team who you want to manage access package assignments for. For US Government, the domain in the My Access portal link is `myaccess.microsoft.us`.
Fundamentals
2Microsoft Entra Privileged Identity Management (PIM) Iteration 2 (beta) APIs will be retired on October 28, 2026. Applications using these APIs will fail after this date. Organizations should migrate to the more reliable Iteration 3 (GA) APIs and stop new development on Iteration 2 APIs.
Licensing Fundamentals
Updated- **Free** - Included with Microsoft cloud subscriptions such as Microsoft Azure, Microsoft 365, and others.
Conditional Access
1Plan Conditional Access
Updated- Admins who interact with Conditional Access need one of the following role assignments, depending on the tasks they're performing. To follow the [Zero Trust principle of least privilege](/security/zero-trust/), consider using [Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) to activate privileged role assignments just in time.
Microsoft identity platform
1Microsoft Entra's cross-cloud synchronization, in public preview and opt-in, automates user lifecycle management across Microsoft commercial, US Government, and China clouds. General availability is late September to early October 2025. It requires specific licenses, admin enablement, and supports configuration via portal, PowerShell, and API.
Microsoft Entra External ID
19 updatesFundamentals
6Solutions Customers
UpdatedMicrosoft Entra External ID offers solutions that let you quickly add intuitive, user-friendly sign-up and sign-up experiences for your consumer and business customer apps. The Woodgrove Groceries demo environment illustrates several of the most common authentication experiences that can be configured for your apps.
Security Customers
UpdatedPlanning Your Solution
Updated- [Start a free trial](https://aka.ms/ciam-free-trial?wt.mc_id=ciamcustomertenantfreetrial_linkclick_content_cnl) or [create your external tenant](how-to-create-external-tenant-portal.md).
B2b Guest Access
UpdatedTo enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
Azure Monitor
UpdatedTThe external tenant uses [Microsoft Entra monitoring](/entra/identity/monitoring-health/overview-monitoring-health). Unlike Microsoft Entra tenants, an external tenant can't have a subscription associated with it. So, we need to take extra steps to enable the integration between external tenant and Log Analytics, which is where we send the logs.
B2b Guest Access
Updatedmanager: dougeby
Branding
3The following screenshots show the sign-in with Google experience. In the sign-in page, users select **Sign-in with Google**. At that point, the user is redirected to the Google identity provider to complete the sign-in.
The following screenshots show the sign-in with Apple experience. In the sign-in page, users select **Sign-in with Apple**. Then the user is redirected to the Apple identity provider to complete the sign-in.
When you use identity providers such as Facebook, Google, Apple, custom OIDC, or SAML, users usually see the Microsoft sign-in page first. From there, they choose their identity provider. To simplify this experience, you can use the `domain_hint` parameter in the sign-in URL. This parameter lets you skip the Microsoft sign-in page and go directly to the selected identity provider’s sign-in page.
Authentication
2Sign In Alias
Updated{
Integrate Fraud Protection
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Extensibility Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-extensibility-administrator) or [Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator).
General
2> [!TIP]
> [!TIP]
Security
2A Microsoft Entra documentation page was updated: Integrate Microsoft Entra External ID with Arkose Labs and HUMAN Security for fraud protection (preview).
Fraud Protection Integration
UpdatedLearn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.
Standards
2Register Saml App
UpdatedThis article describes how to register your own SAML application in your external tenant by creating a *non-gallery* app in **Enterprise applications**.
- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available
Monitoring
1Azure Monitor
UpdatedDuring this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.
Provisioning
1Known Issues
Updatedzone_pivot_groups: app-provisioning-cross-tenant-synchronization
Microsoft Entra Internet Access
4 updatesGeneral
2Points Of Presence
UpdatedThe Global Secure Access service is accessed from the Global Secure Access client and is used for Microsoft Entra Internet Access (including Microsoft 365) and Microsoft Entra Private Access traffic. The Internet Protocol (IP) addresses are listed.
Cisco Vpn Coexistence
Updated1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**
Developer
1Zscaler Coexistence
UpdatedIn this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
Security
1Netskope Coexistence
UpdatedThis guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
Microsoft Entra Private Access
2 updatesGeneral
2Configure Domain Controllers
UpdatedTo configure Microsoft Entra Private Access for Active Directory Domain Controllers, you must have the following:
Cisco Coexistence
Updated5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.
Microsoft Entra Workload ID
3 updatesGeneral
2Managed Identity Libraries
UpdatedA Microsoft Entra documentation page was updated: Managed Identity Libraries.
A Microsoft Entra documentation page was updated: Howto Create Service Principal Portal.
Authentication
1Learn about the mitigation steps tenant administrators should perform for the retirement of service principal-less authentication.
Microsoft Entra Global Secure Access
13 updatesGeneral
5Configure Domain Controllers
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
Install Windows Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
China User Support
UpdatedThere are two scenarios that are applicable to Global Secure Access in China:
Palo Alto Coexistence
Updatedmanager: dougeby
Use the web category checker to find which web content category a URL belongs to via Microsoft Graph.
Troubleshooting
3Troubleshoot Connectors
Updatedmanager: dougeby
Troubleshoot Connectors
UpdatedSample User Interface Output (Starting version 1.5.4522.0):
Troubleshoot Connectors
UpdatedThe tool also provides additional information, such as certificate details (if the cert is valid), tenant and connector ID, and TLS versions. To ensure that no checks are missed due to network or intermittent issues, the tool contains retries and prints out exception messages for any connectivity failures.
Fundamentals
2Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
Traffic Dashboard
Updatedmanager: dougeby
Monitoring
2<summary>PowerShell installation script</summary>
Export Connector Logs
Updated1. Download the Azure Arc agent setup script from the Azure portal.
Security
1Transport Layer Security
Updated```openssl x509 -req -in <CSR file> -CA rootCAchain.pem -CAkey rootCAchain.key -CAcreateserial -out signedcertificate.pem -days 370 -sha256 -extfile openssl.cnf -extensions signedCA_ext```
