author: HULKsmashGithub
January 2026: two Entra authentication retirements outweigh a month of documentation maintenance
January’s consequential administrator work is deadline-driven rather than a feature-release cycle. The record contains 299 changes—292 updates, one new page, three removals, and three Message Center notices. The notices announce the retirement of Conditional Access’s “Require approved client app” control in June 2026 and custom greetings for voice-call MFA on February 28, 2026. Microsoft Purview DLP also renamed its Enforcement plane from “Entra” to “Application,” without functional or user impact. The supplied evidence establishes no new preview or general-availability release. The sole new page is an EcoOnline Info Exchange SSO configuration tutorial, not evidence of a new Entra capability; the three removed Purview workload-content pages have no stated retirement rationale.
- Conditional Access will retire the “Require approved client app” controlMicrosoft Entra ID — Conditional Access
Retirement notice: Microsoft says the control will retire in June 2026 and will no longer be enforceable afterward. The stated replacement is “Require application protection policy,” described as providing equivalent and enhanced protection. Administrators should identify policies using the old control and update them ahead of the retirement.
- Custom voice-MFA greetings will be replaced by default recordingsMicrosoft Entra ID — voice-call authentication
Retirement notice: custom greetings in voice-call authentication end on February 28, 2026. Voice MFA calls will use Microsoft’s default recordings after that date. The notice concerns the greeting experience, not a stated retirement of voice MFA itself; the supported preparation is to inform users and review relevant MFA configurations.
- Purview DLP’s Enforcement plane label changes from “Entra” to “Application”Microsoft Purview DLP — Enforcement plane
Naming clarification: Microsoft Purview DLP began renaming the Enforcement plane in mid-January. There is no stated functional, user, or compliance impact. New audit logs use “Application,” while existing logs retain “Entra,” so scripts and documentation that depend on the label may need updating.
- Conditional Access Optimization Agent guidance documents an activator-identity distinctionMicrosoft Entra ID — Conditional Access Optimization Agent
A coordinated update to five Entra Conditional Access Optimization Agent pages records that agents enabled after November 17, 2025 no longer use the identity of the user who activated them. Earlier agents may fail when the activating account relied on Privileged Identity Management but lacked the required permissions when the agent ran. This is operational documentation and troubleshooting guidance; it does not establish a preview, general-availability event, or January-wide rollout.
- External ID guidance adds an explicit Akamai WAF verification stepMicrosoft Entra External ID
The updated Akamai integration guidance tells administrators to verify after configuration that Akamai WAF is protecting the external tenant by connecting the authentication credentials to the WAF configuration. Related External ID security guidance frames credential stuffing, automated bot sign-ups, account takeover, and traffic spikes as CIAM threats requiring layered controls and integrations. These are implementation and security clarifications, not evidence of a new External ID capability or availability shift
Inventory Conditional Access policies that use “Require approved client app” and plan migration to “Require application protection policy” before the June retirement. Prepare voice-MFA users for Microsoft’s default recordings and review relevant configurations before February 28. Update Purview DLP scripts and internal documentation to recognize “Application” in new audit logs while retaining “Entra” for existing logs. For deployments in scope, review the revised Conditional Access Optimization Agent, ID Protection, Microsoft Entra Connect Sync, and External ID/Akamai WAF guidance. The evidence supports targeted runbook checks, not a blanket tenant reconfiguration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
299 updates by product
Microsoft Entra ID
248 updatesGeneral
116Entra Offerings
Updated**Microsoft Entra ID P2** - Microsoft Entra ID P2 is available as a standalone product. It is also included with the following offers for enterprise customers:
author: HULKsmashGithub
Microsoft Entra ID supports applying [sensitivity labels](/purview/sensitivity-labels) to Microsoft 365 groups when those labels are published in the [Microsoft Purview portal](/purview/purview-portal) and the labels are configured for groups and sites.
* GitHub Enterprise Managed User supports both **SP and IDP** initiated SSO.
Attack Payload Author
Updated- [Get started using Attack simulation training](/defender-office-365/attack-simulation-training-get-started)
For more information, see these articles:
author: shlipsey3
- The `memberOf` attribute can't be used with other operators. For example, you can't create a rule that states "Members Of group A can't be in Dynamic group B."
author: FaithOmbongi
Agent Registry Administrator
Updatedauthor: FaithOmbongi
Ai Administrator
Updatedauthor: FaithOmbongi
Attack Payload Author
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Attribute Assignment Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Attribute Definition Reader
Updatedauthor: FaithOmbongi
Azure Devops Administrator
Updatedauthor: FaithOmbongi
Billing Administrator
Updatedauthor: FaithOmbongi
Cloud Device Administrator
Updatedauthor: FaithOmbongi
Compliance Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Directory Readers
Updatedauthor: FaithOmbongi
Directory Writers
Updatedauthor: FaithOmbongi
Domain Name Administrator
Updatedauthor: FaithOmbongi
Dragon Administrator
Updatedauthor: FaithOmbongi
Dynamics 365 Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Edge Administrator
Updatedauthor: FaithOmbongi
Exchange Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Fabric Administrator
Updatedauthor: FaithOmbongi
Global Administrator
Updatedauthor: FaithOmbongi
Global Reader
Updatedauthor: FaithOmbongi
Groups Administrator
Updatedauthor: FaithOmbongi
Guest Inviter
Updatedauthor: FaithOmbongi
Helpdesk Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Insights Administrator
Updatedauthor: FaithOmbongi
Insights Analyst
Updatedauthor: FaithOmbongi
Insights Business Leader
Updatedauthor: FaithOmbongi
Intune Administrator
Updatedauthor: FaithOmbongi
Iot Device Administrator
Updatedauthor: FaithOmbongi
Kaizala Administrator
Updatedauthor: FaithOmbongi
Knowledge Administrator
Updatedauthor: FaithOmbongi
Knowledge Manager
Updatedauthor: FaithOmbongi
License Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Message Center Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: rolyon
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: rolyon
Network Administrator
Updatedauthor: FaithOmbongi
Office Apps Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Partner Tier1 Support
Updatedauthor: FaithOmbongi
Partner Tier2 Support
Updatedauthor: FaithOmbongi
People Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Places Administrator
Updatedauthor: FaithOmbongi
Power Platform Administrator
Updatedauthor: FaithOmbongi
Printer Administrator
Updatedauthor: FaithOmbongi
Printer Technician
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Search Administrator
Updatedauthor: FaithOmbongi
Search Editor
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Sharepoint Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Teams Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Teams Devices Administrator
Updatedauthor: FaithOmbongi
Teams Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Tenant Creator
Updatedauthor: FaithOmbongi
User Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Virtual Visits Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Viva Goals Administrator
Updatedauthor: FaithOmbongi
Viva Pulse Administrator
Updatedauthor: FaithOmbongi
Windows 365 Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
Yammer Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
21793
UpdatedIf this check passes, your tenant has a TRv2 policy configured but more steps are required to validate the scenario end-to-end.
21824
UpdatedWithout proper session controls, threat actors can achieve lateral movement across the organization's infrastructure, accessing critical data and systems that extend far beyond the original guest account's intended scope of access.
A Microsoft Entra documentation page was updated: Purview Workload Content Administrator.
A Microsoft Entra documentation page was updated: Purview Workload Content Reader.
A Microsoft Entra documentation page was updated: Purview Workload Content Writer.
Learn how to configure single sign-on between Microsoft Entra ID and EcoOnline Info Exchange.
Ecoonline Info Tutorial
UpdatedIn this article, you configure and test Microsoft Entra single sign-on in a test environment.
Connect Install Roadmap
Updated> [!IMPORTANT]
Connect Accounts Permissions
Updated|Topic |Link|
Connect Health Adfs
Updated- [Download the Microsoft Entra Connect Health agent for AD FS](https://go.microsoft.com/fwlink/?LinkID=518973).
Connect Version History
UpdatedYou can upgrade your Microsoft Entra Connect server from all supported versions with the latest versions:
Dirsync Upgrade Get Started
UpdatedDirSync and Azure AD Sync aren't supported and no longer work. If you're still using DirSync or Azure AD Sync, you *must* upgrade to Microsoft Entra Connect to resume your sync process.
Device Join Out Of Box
Updated> [!TIP]
Troubleshooting
2821790
Updated**Remediation action**
21804
Updated**Remediation action**
21806
Updated**Remediation action**
21884
Updated**Remediation action**
21985
Updated**Remediation action**
21817
Updated**Remediation action**
21825
Updated**Remediation action**
21776
Updated**Remediation action**
21777
Updated**Remediation action**
21786
Updated**Remediation action**
21798
Updated**Remediation action**
21799
Updated**Remediation action**
21802
Updated**Remediation action**
21812
Updated**Remediation action**
21818
Updated**Remediation action**
21828
Updated**Remediation action**
21847
Updated**Remediation action**
21865
Updated**Remediation action**
21867
Updated**Remediation action**
21868
Updated**Remediation action**
21870
Updated**Remediation action**
21877
Updated**Remediation action**
21883
Updated**Remediation action**
21886
Updated**Remediation action**
21891
Updated**Remediation action**
22128
Updated**Remediation action**
22659
Updated**Remediation action**
Troubleshoot Sspr Writeback
Updated> [!WARNING]
Authentication
20Kerberos
UpdatedCloud-only user accounts managed solely in Microsoft Entra ID are supported for Kerberos authentication by workloads like Azure Files, Azure Virtual Desktop and Windows authentication access to Azure SQL Managed Instance.
Manage Roles Portal
Updated| [User Administrator](permissions-reference.md#user-administrator) | Can manage all aspects of users and groups, including resetting passwords for limited admins within the assigned administrative unit only. Cannot currently manage users' profile photographs. |
>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
Manages [Microsoft Purview Customer Lockbox requests](/purview/customer-lockbox-requests) in your organization. They receive email notifications for Customer Lockbox requests and can approve and deny requests from the Microsoft 365 admin center. They can also turn the Customer Lockbox feature on or off. Only Global Administrators can reset the passwords of people assigned to this role.
Global Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Enable Authenticator Passkey
Updatedauthor: justinha
Authentication Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
Password Administrator
Updatedauthor: FaithOmbongi
In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.
When you map authorization rules, apps that authenticate with AD FS may use Active Directory groups for permissions. In such a case, use [Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) to sync these groups with Microsoft Entra ID before migrating the applications. Make sure that you verify those groups and membership before migration so that you can grant access to the same users when the application is migrated.
Connect Install Express
UpdatedIf you have a single-forest topology and use [password hash sync](how-to-connect-password-hash-synchronization.md) for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.
author: justinha
Learn which Microsoft Entra features are available in Azure for US Government.
Howto Password Smart Lockout
Updated> [!NOTE]
Reports Data Retention
UpdatedLog storage within Microsoft Entra varies by report type and license type. You can retain the audit and sign-in activity data for longer than the default retention period outlined in the previous table by routing it to an Azure storage account using Azure Monitor. For more information, see [Archive Microsoft Entra logs to an Azure storage account](./howto-archive-logs-to-storage-account.md).
- Users can authenticate
The macOS Platform single sign-on (PSSO) is a capability on macOS that is enabled using the [Microsoft Enterprise Single Sign-on Extension](../../identity-platform/apple-sso-plugin.md). Platform SSO enables users to Entra join their macOS devices and sign in using a hardware-bound key, smart card, or their Microsoft Entra ID password through a PSSO Primary Refresh Token (PRT).
Fundamentals
20author: justinha
Configure Security
Updated| [Applications don't have client secrets configured](zero-trust-protect-identities.md#applications-dont-have-client-secrets-configured) | None (included with Microsoft Entra ID) |
Conditional Access Session
Updated
In the following example, the tenant has a Conditional Access policy with the following details:
A Microsoft Entra documentation page was updated: Zero Trust Protect Identities.
Groups Concept
Updated- *Microsoft Entra ID P2 licensed customers only*: Even after deleting the group, it's still shown as an eligible member of the role in PIM UI. Functionally there's no problem; it's just a cache issue in the Microsoft Entra admin center.
Whats New Archive
Updated- Microsoft 365 Defender portal
Zero Trust Monitor Detect
UpdatedA Microsoft Entra documentation page was updated: Zero Trust Monitor Detect.
A Microsoft Entra documentation page was updated: Zero Trust Protect Engineering Systems.
A Microsoft Entra documentation page was updated: Zero Trust Response Remediation.
- Resource exclusions for a custom enterprise application and Exchange Online
Security Defaults
UpdatedIf your tenant was created on or after October 22, 2019, security defaults might be enabled in your tenant. To protect all of our users, security defaults are being rolled out to all new tenants at creation.
> [!NOTE]
Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using browsers such as Microsoft Edge or Google Chrome.
Macos Get Started
UpdatedAdding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using applications such as Microsoft Outlook or Microsoft Edge.
Add Custom Domain
Updated> [!TIP]
Assignment Network
Updated- The country code returned depends on the device platform API: For example one platform might report US for Puerto Rico, while another reports PR.
Primary Refresh Token
UpdatedOnce issued, a PRT is valid for 90 days and is continuously renewed as long as the user actively uses the device. Organizations can require users re-authenticate in order to access resources using the Sign-in [frequency session control](../conditional-access/concept-conditional-access-session.md).
Application Gallery
Updated- **Risk Score** – View applications by their calculated security risk score from 1 (highest risk) to 10 (lowest risk). This score helps identify applications that meet your organization's security requirements.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Security
12Manage Device Identities
Updated`id,deviceId,displayName,accountEnabled,operatingSystem,operatingSystemVersion,trustType(joinType),mdm,securitySettingsManagement,isCompliant,registrationDateTime,approximateLastSignInDateTime,owner,upnName`
Compliance Administrator
UpdatedUsers with this role have permissions to manage compliance-related features in the Microsoft Purview portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Users with this role have permissions to track data in the Microsoft Purview portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Helpdesk Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
User Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
author: FaithOmbongi
Security Administrator
Updatedauthor: FaithOmbongi
Security Operator
Updatedauthor: FaithOmbongi
Security Reader
Updatedauthor: FaithOmbongi
author: FaithOmbongi
21830
Updated- [Deploy a privileged access workstation solution](/security/privileged-access-workstations/privileged-access-deployment)
21823
UpdatedAdditionally, compromised guest identities can be used to establish credential persistence and potentially escalate privileges. Attackers can exploit trust relationships between guest accounts and internal resources, or use the guest account as a staging ground for lateral movement toward more privileged organizational assets.
Monitoring
11Global Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview portal, Azure portal, and Device Management admin center.
Attribute Log Administrator
Updatedauthor: FaithOmbongi
Attribute Log Reader
Updatedauthor: FaithOmbongi
Reports Reader
Updatedauthor: FaithOmbongi
Usage Summary Reports Reader
Updatedauthor: FaithOmbongi
21773
Updated- [Define certificate based application configuration](https://devblogs.microsoft.com/identity/app-management-policy/)
21858
UpdatedThe prolonged dormancy of these accounts provides attackers with extended dwell time to conduct reconnaissance, exfiltrate sensitive data, and establish backdoors without detection, as organizations typically focus monitoring efforts on active internal users rather than external guest accounts.
The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, aren't promotional or marketing emails, and don't contain any upselling content. These emails are purely informational and designed to help you act quickly when a new recommendation is available.
Connect Install Custom
UpdatedUse *custom settings* in Microsoft Entra Connect when you want more options for the installation. Use these settings, for example, if you have multiple forests or if you want to configure optional features. Use custom settings in all cases where [express installation](how-to-connect-install-express.md) doesn't satisfy your deployment or topology needs.
Microsoft Purview DLP is renaming the Enforcement plane from "Entra" to "Application" starting mid-January 2026, with no functional or user impact. Admins should update scripts and documentation accordingly. New audit logs will reflect "Application," while existing logs keep "Entra." No compliance issues identified.
Sla Performance
Updated| September | 99.999% | 99.998% | 99.999% | 99.999% | 99.999% |
Conditional Access
9author: FaithOmbongi
Managed Policies
UpdatedThese Microsoft-managed policies allow administrators to make simple modifications like excluding users or turning them from report-only mode to on or off. Organizations can't rename or delete any Microsoft-managed policies. As administrators get more comfortable with Conditional Access policy, they might choose to duplicate the policy to create custom versions.
The "Require approved client app" control in Microsoft Entra Conditional Access will retire in June 2026. Organizations should update policies to use the "Require application protection policy" control for equivalent and enhanced protection. After retirement, the old control will no longer be enforceable.
It's possible that the agent was enabled before Microsoft Ignite 2025 with an account that required role activation with Privileged Identity Management (PIM). So when the agent attempted to run, it failed because the account didn't have the required permissions at that time. Conditional Access Optimization Agents that were turned on after November 17, 2025 no longer use the identity of the user who activated the agent.
manager: pmwongera
author: shlipsey3
manager: pmwongera
author: shlipsey3
manager: pmwongera
Provisioning
8author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
- SOAP Discovery: Allows the administrator to enter the WSDL path exposed by the target web service. Discovery produces a tree structure of the application's hosted web services with their inner endpoints or operations along with the operation’s Meta data description. There's no limit to the number of discovery operations that can be done (step by step). The discovered operations are used later to configure the flow of operations that implement the connector’s operations against the data-source (as Import/Export).
[Append](#append) [AppRoleAssignmentsComplex](#approleassignmentscomplex) [BitAnd](#bitand) [CBool](#cbool) [CDate](#cdate) [Coalesce](#coalesce) [ConvertToBase64](#converttobase64) [ConvertToUTF8Hex](#converttoutf8hex) [Count](#count) [CStr](#cstr) [DateAdd](#dateadd) [DateDiff](#datediff) [DateFromNum](#datefromnum) [FormatDateTime](#formatdatetime) [Guid](#guid) [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty) [IIF](#iif) [InStr](#instr) [IsNull](#isnull) [IsNullOrEmpty](#isnullorempty) [IsPresent](#ispresent) [IsString](#isstring) [Item](#item) [Join](#join) [Left](#left) [Len](#len) [Mid](#mid) [NormalizeDiacritics](#normalizediacritics) [Not](#not) [Now](#now) [NumFromDate](#numfromdate) [PCase](#pcase) [RandomString](#randomstring) [Redact](#redact) [RemoveDuplicates](#removeduplicates) [Replace](#replace) [SelectUniqueValue](#selectuniquevalue) [SingleAppRoleAssignment](#singleapproleassignment) [Split](#split) [StripSpaces](#stripspaces) [Switch](#switch) [ToLower](#tolower) [ToUpper](#toupper) [Word](#word)
App Provisioning Sap
Updated> - Keep user attributes synchronized between Microsoft Entra ID and SAP ECC.
Configuring Microsoft Entra ID to provision users into SAP ECC with NetWeaver AS ABAP 7.0 or later
UpdatedThe following documentation provides configuration and tutorial information demonstrating how to provision users from Microsoft Entra ID into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver 7.0 or later. If you're using other versions of SAP R/3, you can still use the guides provided in the [Connectors for Microsoft Identity Manager 2016](https://www.microsoft.com/download/details.aspx?id=51495) download as a reference to build your own template for provisioning.
The Microsoft Entra provisioning agent and generic web services connector provides connectivity to on-premises SAP ECC SOAP endpoints, including SAP BAPIs.
Standards
7author: OwenRichards1
Hipaa Audit Controls
Updated| Configure Azure Monitor | [Use Azure Monitor Logs](/azure/azure-monitor/logs/data-security) collects and organizes logs, expanding to cloud and hybrid environments. It provides recommendations on key areas on how to protect resources combined with Azure trust center. |
In this article, you learn how to set up a SAML integration for a GitHub enterprise with Enterprise Managed Users with Microsoft Entra ID. Setting up a SAML or [OIDC](https://docs.github.com/enterprise-cloud@latest/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-oidc-for-enterprise-managed-users) authentication integration, in addition to setting up [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md), is required for a GitHub enterprise with Enterprise Managed Users. Setting up authentication and [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md) for a GitHub enterprise with Enterprise Managed Users allows an admin to:
Configure GitHub Enterprise Cloud - Enterprise Account for Single sign-on with Microsoft Entra ID
UpdatedIn this article, you learn how to set up a Microsoft Entra SAML integration with a GitHub Enterprise Cloud - Enterprise Account. When you integrate GitHub Enterprise Cloud - Enterprise Account with Microsoft Entra ID, you can:
* [FedRAMP High Azure Policy built-in initiative definition](/azure/governance/policy/samples/fedramp-high)
Hipaa Other Controls
Updated| Recommendation | Action |

Microsoft identity platform
5Application Developer
Updatedauthor: FaithOmbongi
The same issue occurs when a server with Microsoft Entra Connect installed is cloned into another production server, which isn't a supported method of deploying this product as these servers with share the same machine identifier. In short, the server's identity conflicts because they get tied to one app registration. The Microsoft Entra Connect wizard by default uses unique accounts per server because it uses the server's name to identify the application registration instead of the Microsoft Entra connector's service account, which avoids this issue.
:::image type="content" source="./media/application-registration-best-practices/implict-grant-flow.png" alt-text="Screenshot that shows where the implicit flow property is located.":::
 If your app is registered in a directory, minimize and manually monitor the list of app registration owners.
1. Select the **Resource** link to go directly to the app registration for the app.
Developer
4Application Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
This article shows the new and updated documentation for the Microsoft Entra application management.
Manage App Consent Policies
UpdatedEvery tenant comes with a set of app consent policies that are the same across all tenants. Some of these built-in policies are used in existing built-in directory roles. For example, the `microsoft-application-admin` app consent policy describes the conditions under which the Application Administrator and Cloud Application Administrator roles are allowed to grant tenant-wide admin consent. Built-in policies can be used in custom directory roles or to configure an organization's default consent policy. These policies can't be edited. A list of the built-in policies are:
Branding
3Use the following CSS selectors to configure the details of the sign-in experience.
author: FaithOmbongi
Custom greetings in voice call authentication will retire on February 28, 2026. After this date, voice calls for multifactor authentication will use Microsoft’s default recordings. Organizations should prepare users for this change and review their MFA configurations accordingly.
Governance
3author: FaithOmbongi
21869
UpdatedWhile an application with open assignment but proper provisioning scoping (such as department-based filters or group membership requirements) maintains security controls through the provisioning layer, applications lacking both controls create unrestricted access pathways that threat actors can exploit. When applications provision accounts for all users without assignment restrictions, threat actors can abuse compromised accounts to conduct reconnaissance activities, enumerate sensitive data across multiple systems, or use the applications as staging points for further attacks against connected resources. This unrestricted access model is dangerous for applications that have elevated permissions or are connected to critical business systems. Threat actors can use any compromised user account to access sensitive information, modify data, or perform unauthorized actions that the application's permissions allow. The absence of both assignment controls and provisioning scoping also prevents organizations from implementing proper access governance. Without proper governance, it's difficult to track who has access to which applications, when access was granted, and whether access should be revoked based on role changes or employment status. Furthermore, applications with broad provisioning scopes can create cascading security risks where a single compromised account provides access to an entire ecosystem of connected applications and services.
Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.
Architecture
2Team members who need to create sensitivity labels require permissions to:
A Microsoft Entra documentation page was updated: Road To The Cloud Ad Minimization.
Microsoft Entra Agent ID
3 updatesGeneral
1Agent Id Administrator
Updatedauthor: FaithOmbongi
Microsoft identity platform
1Agent Id Developer
Updatedauthor: FaithOmbongi
Standards
1Agent Id Governance Overview
UpdatedWhen created, agent identities have limited permissions, such as OAuth 2 delegated permission scopes [inherited from their parent agent identity blueprint](../agent-id/identity-professional/configure-inheritable-permissions-blueprints.md). In addition, agent identities can have resource access assigned to them directly via access packages. Agent identities can request an access package for themselves, or have their owner or sponsor request one on their behalf. With access packages, you're able to assign agent identities access to the following resources:
Microsoft Entra ID Protection
9 updatesFundamentals
4Identity Protection Policies
UpdatedThe Microsoft-managed remediation risk-based Conditional Access policy lets you author a risk policy that accommodates all authentication methods, including password-based and passwordless. This means that when you select "Require risk remediation" in your policy's grant controls, Microsoft Entra ID Protection manages the appropriate remediation flow based on the threat observed and the user's authentication method. For detailed steps on how to enable Microsoft-managed remediation, see [Configure risk policies](howto-identity-protection-configure-risk-policies.md#microsoft-recommendations).
Identity Protection Policies
UpdatedIdentifying risk-based Conditional Access policies
Identity Protection Risks
Updatedauthor: shlipsey3
If a user is prompted to use self-service password reset (SSPR) to remediate user risk, they are prompted to update their password as shown in the [Microsoft Entra ID Protection user experience](concept-identity-protection-user-experience.md) article. Once they update their password, the user risk is remediated. A secure password change (MFA and password change) can also remediate user risk. The user can then proceed to sign in with their new password. The risk state and risk details for the user, sign-ins, and corresponding risk detections are updated as follows:
Authentication
3Security Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Learn how to investigate risky users, detections, and sign-ins in Microsoft Entra ID Protection.
Security
1Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Troubleshooting
1Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Microsoft Entra ID Governance
12 updatesGovernance
81. Once you select a policy, you are able to add users to select the users you want to assign this access package to, under the chosen policy.
Pim Roles
Updated> For information about delays activating the Microsoft Entra Joined Device Local Administrator role, see [How to manage the local administrators group on Microsoft Entra joined devices](../../identity/devices/assign-local-admin.md#manage-the-microsoft-entra-joined-device-local-administrator-role).
1. Once you select a policy, you are able to add users to select the users you want to assign this access package to, under the chosen policy.
author: FaithOmbongi
Delegate Approvals My Access
UpdatedA Microsoft Entra documentation page was updated: Delegate Approvals My Access.
- Attribute Changes
- The Microsoft Entra User Account configuring the connector and Access Packages must be synced to SAP Cloud Identity Services (IAS) and SAP IAG.
Sap
UpdatedOnce you have users in Microsoft Entra ID, you can provision those users from Microsoft Entra ID to SAP Cloud Identity Services or SAP ECC, to enable them to sign in to SAP applications. If you have [`SAP S/4HANA On-Premise`](https://help.sap.com/docs/identity-provisioning/identity-provisioning/target-sap-s-4hana-on-premise), then provision users from Microsoft Entra ID to SAP Cloud Identity Directory. SAP Cloud Identity Services then provisions the users originating from Microsoft Entra ID that are in the SAP Cloud Identity Directory into the downstream SAP applications to SAP S/4HANA On-Premise through the SAP cloud connector.
Fundamentals
4Pim For Groups
Updated1. Make active assignments of users to the group, and then assign the group to a role as eligible for activation.
Identity Governance Overview
UpdatedIn Microsoft Entra ID Governance, you can enable business groups to determine which of these guests should have access, and for how long, using:
Apps
Updated| HR | [API-driven connector from any HR source](../identity/app-provisioning/inbound-provisioning-api-concepts.md)<br>[Rippling HCM integration with Microsoft Entra ID/Active Directory](../identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md)<br>[Oracle HCM API-driven connector](../identity/saas-apps/oracle-hcm-provisioning-tutorial.md)<br>[Darwinbox to Microsoft Entra ID](../identity/saas-apps/darwinbox-entra-integration-tutorial.md)<br>[SAP HCM to Microsoft Entra ID](../identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) |
What Is Provisioning
Updated1. For organizations with a single subscription to Workday or SuccessFactors, and don't use Active Directory
Microsoft Entra External ID
16 updatesGeneral
8B2c Ief Keyset Administrator
Updatedauthor: FaithOmbongi
B2c Ief Policy Administrator
Updatedauthor: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
author: FaithOmbongi
External Identities Pricing
Updated- External users in Microsoft Entra [external tenants](tenant-configurations.md#external-tenants), which includes consumers and business guests (users without directory roles), and admins (users with directory roles). MAU billing applies to all users in an external tenant regardless of their **UserType** setting.
Connect Health Agent Install
Updated- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
Faq Customers
UpdatedFundamentals
4Customers Ciam
UpdatedMicrosoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.
Security Customers
UpdatedExternal-facing identity systems support a wide range of customer experiences. That wide range also makes them attractive targets for common customer identity and access management (CIAM) attack patterns such as credential stuffing, automated bot sign-ups, account takeover attempts, and high-volume traffic spikes. Understanding these threats helps explain why a clear, layered security approach is essential. Microsoft Entra External ID provides foundational capabilities you can build on. This guide helps you understand how to strengthen that foundation with recommended controls and integrations based on common CIAM threat patterns.
Supported Features Customers
Updated|**Target resources**|<ul><li>[Cloud apps](~/identity/conditional-access/concept-conditional-access-cloud-apps.md)</li><li>[User actions](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#user-actions)</li><li>[Global Secure Access](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#traffic-forwarding-profiles)</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|<ul><li>[All resources, selected apps](./how-to-multifactor-authentication-customers.md), or [filter applications](~/identity/conditional-access/concept-filter-for-applications.md).</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|
Standards
2Supported Features Customers
Updated|[OpenID Connect](../../identity-platform/v2-protocols-oidc.md)| Yes| Yes|
- [Configure a new OpenID connect identity provider in the admin center](customers/how-to-custom-oidc-federation-customers.md) - Client secret updates
Authentication
1Configure Akamai Integration
UpdatedAfter completing the configuration steps, verify that Akamai WAF is protecting your external tenant by connecting the authentication credentials to the WAF configuration.
Branding
1Customize the sign-in experience for your application with branding themes in external tenants
UpdatedLearn about how to create branding themes and apply them to the sign-in experience for your application in Microsoft External ID for external tenants.
Microsoft Entra Internet Access
2 updatesArchitecture
1- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
Fundamentals
1Traffic Forwarding
UpdatedInternet access traffic can be forwarded to the service by connecting through the [Global Secure Access desktop client](how-to-install-windows-client.md).
Microsoft Entra Private Access
1 updateMonitoring
1Configure Domain Controllers
Updated- Use **Event Viewer** from **Application and Service Logs** > **Microsoft** > **Windows** > **Private Access Sensor** to review Private Access Sensor logs.
Microsoft Entra Workload ID
2 updatesMonitoring
2> [!NOTE]
21836
UpdatedIf administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.
Microsoft Entra Global Secure Access
6 updatesGeneral
4Powershell Get Token
UpdatedWrite-Output "Access Token that you acquired is available in C:\token.txt. "
author: FaithOmbongi
Configure Domain Controllers
Updatedmanager: dougeby
try {
Monitoring
1author: FaithOmbongi
Security
1Network Content Filtering
UpdatedDiscover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.
