ai-usage: ai-assisted
What changed in March
643 documentation updates and 5 Message Center announcements were tracked during March. Activity centred on General, Fundamentals, and Authentication, with the most changes affecting Entra ID and Global Secure Access.
648 updates by product
Microsoft Entra ID
361 updatesFundamentals
73How to identify and resolve license assignment problems when you're using Microsoft Entra group-based licensing.
ai-usage: ai-assisted
An end-to-end guide for planning the deployment of application proxy within your organization
Whats New
Updated```
Whats New
Updated**What’s changing**
Filter For Applications
UpdatedFollow the instructions in the article, [Add or deactivate custom security attributes in Microsoft Entra ID](~/fundamentals/custom-security-attributes-add.md) to add the following **Attribute set** and **New attributes**.
Understand the phases of Conditional Access policy enforcement in Microsoft Entra and how to apply them to secure user access.
Microsoft 365 offers cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. In Conditional Access, the Microsoft 365 suite of applications appears under 'Office 365'. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration might cause confusion when creating policies because some apps, like Microsoft Teams, depend on others, like SharePoint or Exchange.
Authentication Flows
UpdatedIf you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, selecting the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.
> [!IMPORTANT]
To prevent admin lockout, when creating a policy applied to **All users** and **All apps**, the following warning appears.
Plan Conditional Access
Updated- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).
With Conditional Access, organizations can restrict access to [approved (modern authentication capable) client apps with Intune app protection policies](concept-conditional-access-grant.md#require-app-protection-policy). For older client apps that may not support app protection policies, administrators can restrict access to [approved client apps](concept-conditional-access-grant.md#require-approved-client-app).
There are multiple scenarios that organizations can now enable using filter for devices condition. The following scenarios provide examples of how to use this new condition.
View Available Backups
Updated1. Browse to **Backup and recovery**. The **Overview** page shows feature highlights, alerts, and recent activity.
Whats New
Updated**Service category:** MFA
Create New Tenant
Updated- **Delegated administration**: Select one or more Microsoft Entra built-in roles and assign them to a role assignable security group in the governing tenant. Members of this group can use their governing tenant credentials to sign in to the governed tenant without needing an account in the governed tenant. Each group can have multiple role assignments, and each policy template can have multiple groups defined.
Application Gallery
Updated- **Provisioning** - Microsoft Entra ID to SaaS [application provisioning](~/identity/app-provisioning/user-provisioning.md) refers to automatically creating user identities and roles in the SaaS applications that users need access to.
Managing permissions for external partners is a key part of your security posture. The administrator portal experience in Microsoft Entra ID, part of Microsoft Entra, now includes capabilities so that an administrator can see the relationships that their Microsoft Entra tenant has with Microsoft Cloud Service Providers (CSP) who can manage the tenant. This permissions model is called delegated administration. This article introduces the Microsoft Entra administrator to the relationship between the old Delegated Admin Permissions (DAP) permission model and the new [Granular Delegated Admin Permissions (GDAP)](/partner-center/gdap-introduction) permission model.
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png" alt-text="Screenshot that shows how to turn on issuer hints." lightbox="media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png":::
Whats New
Updated- clicktale
You can use groups in Microsoft Entra ID to assign licenses, or deployed enterprise apps, to large numbers of users. You can also use groups to assign all administrator roles except for Microsoft Entra Global Administrator, or you can grant access to external resources, such as SaaS applications or SharePoint sites.
All Azure subscriptions have a trust relationship with a Microsoft Entra tenant. Subscriptions rely on this tenant (directory) to authenticate and authorize security principals and devices. When a subscription expires, the trusted instance remains, but the security principals lose access to Azure resources. Subscriptions can only trust a single directory while one Microsoft Entra tenant might be trusted by multiple subscriptions.
Licensing
UpdatedThis article discusses licensing options for the Microsoft Entra product family. It's intended for security decision makers, identity and network access administrators, and IT professionals who are considering Microsoft Entra solutions for their organizations.
Define the Group ID
Updated> A new bulk operations experience is now available in preview that provides enhanced performance and removes scaling limitations for large tenants. For more information, see [Bulk operations in Microsoft Entra ID (Preview)](bulk-operations.md).
Whats New Overview
UpdatedThe **Roadmap** tab lists the details of public preview and recent general availability releases in a sortable table. From the table, you can select a release to view the release **Details**, which includes an overview and a link to learn more.
In this article, learn about the terms in effect when participating in Microsoft Entra ID preview programs.
> [!IMPORTANT]
Manage User Profile Info
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](../identity/role-based-access-control/permissions-reference.md#user-administrator).
How to identify and resolve license assignment problems when you're using Microsoft Entra group-based licensing.
Add Custom Domain
Updated1. Create your new directory by following the steps in [Create a new tenant for your organization](./create-new-tenant.md#create-a-new-tenant-for-your-organization).
Reset a user's password
UpdatedAdministrators can reset a user's password if the user forgets the password, if the user gets locked out, or if the user never received a password.
Bulk Operations
UpdatedThe new bulk operations experience in Microsoft Entra ID provides enhanced capabilities for managing **Groups**, **Devices, Administrative Unit and Role assignments.** This service enables bulk actions including create, update, and delete operations. The improved service delivers better performance, reduces timeouts, and removes scaling limitations for large tenants.
How to find your tenant ID
UpdatedInstructions about how to find your Microsoft Entra tenant ID for an existing Azure subscription.
Users Restore
UpdatedAfter you delete a user, the account remains in a suspended state for 30 days. During that 30-day window, the user account can be restored, along with all its properties.
This article explains how an administrator can add privacy-related info to an organization's directory through the Microsoft Entra admin center.
Create New Tenant
UpdatedIn this quickstart article, you learn how to create a basic tenant for your organization.
Try Microsoft Entra Suite
UpdatedWelcome to the Microsoft Entra Suite trial user guide. Make the most of your free trial by discovering the robust and comprehensive capabilities of [Microsoft Entra](what-is-entra.md).
Get Started Premium
UpdatedYou can purchase and associate Microsoft Entra ID P1 or P2 editions with your Azure subscription. If you need to create a new Azure subscription, you also need to [activate your licensing plan](#activate-your-new-license-plan) and your [Microsoft Entra ID service access](#activate-your-microsoft-entra-id-access). For information about obtaining a free trial, see [Microsoft Entra ID P2 Trial](https://signup.microsoft.com/get-started/signup?products=FAF849AB-BD30-42B2-856C-8F1EDC230CE9).
Users Default Permissions
UpdatedYou can restrict default permissions for member users in the following ways:
Microsoft Entra ID stores identity data in a location chosen based on the address provided by your organization when subscribing to a Microsoft service like Microsoft 365 or Azure. Microsoft Online Services include Microsoft 365 and Azure.
Entra Admin Center
UpdatedThe Microsoft Entra admin center is organized by product. Access the products through the search bar or left-hand menu.
Microsoft Entra ID stores identity data in a location chosen based on the address provided by your organization when subscribing to a Microsoft service like Microsoft 365 or Azure. For information on where your Identity Customer Data is stored, review the Microsoft Trust Center section titled [Where is your data located?](https://www.microsoft.com/trustcenter/privacy/where-your-data-is-located).
Discover how to sign up for Microsoft Entra ID and Azure. Start using enterprise cloud services today.
Learn about Microsoft Entra group-based licensing, including how it works,
When a user signs in, the authentication process checks which authentication methods are registered for the user. The user is prompted to sign-in with the most secure method according to the following order. The order of authentication methods is dynamic. It's updated as the security landscape changes, and as better authentication methods emerge. Users can always cancel and choose a different available sign in method if needed. If your organization has Conditional Access policies that require specific authentication methods, those policies will continue to take priority over the system preferred MFA order. Click the link for more information about each method.
What Is Cloud Sync
UpdatedCloud Sync solves common challenges organizations face with hybrid identity infrastructure by eliminating single points of failure, reducing on-premises management overhead, and enabling complex multi-forest scenarios that support organizational growth and change.
Native Authentication
UpdatedThe following table shows the availability of features for browser-delegated and native authentication.
Whats New
Updated**Service category:** Entra Connect
Configure Security
Updated| [TLS inspection is enabled and correctly configured for outbound traffic](zero-trust-protect-networks.md#tls-inspection-is-enabled-and-correctly-configured-for-outbound-traffic) | Microsoft Entra ID P1 |
Zero Trust Protect Networks
UpdatedA Microsoft Entra documentation page was updated: Zero Trust Protect Networks.
An end-to-end guide for planning the deployment of application proxy within your organization
author: shlipsey3
A Microsoft Entra documentation page was updated: Find help and get support for Microsoft Entra.
- Your native application integrates with a third‑party fraud protection provider to securely evaluate risk signals before issuing an SMS one‑time passcode (OTP).
Overview
Updated:::image type="content" source="media/overview/conditional-access-overview.png" alt-text="Screenshot of the Conditional Access overview page." lightbox="media/overview/conditional-access-overview.png":::
A Microsoft Entra documentation page was updated: Licensing Groups Resolve Problems.
Management concepts and how-tos for managing a domain name in Microsoft Entra ID
Learn about Microsoft Entra bulk operations related to users, groups,
Use Microsoft Entra groups to simplify role assignment management in Microsoft Entra ID.
Whats New
Updated**Note:** Currently, the new Bulk Operations service supports **Groups**, **Devices**, and **User Export** only. Support for additional entities, such as **Enterprise Applications**, is coming soon. For more information, see: [Bulk operations in Microsoft Entra ID (Preview)](../fundamentals/bulk-operations.md).
Whats New Archive
Updatedauthor: owinfreyATL
Token Protection
Updated- For detailed steps on how to register your device, see [Register your personal device on your work or school network](https://support.microsoft.com/account-billing/register-your-personal-device-on-your-work-or-school-network-8803dd61-a613-45e3-ae6c-bd1ab25bf8a8).
New values are added when native authentication supports new authentication methods.
- A basic understanding of the concepts covered in [Custom authentication extensions overview](custom-extension-overview.md).
New values are added when native authentication supports new authentication methods.
Learn about Microsoft Entra ID Account Recovery, which enables users to regain access to their accounts through identity verification when they've lost all authentication methods.
- A familiarity and understanding of the concepts covered in [custom authentication extensions](/entra/identity-platform/custom-extension-overview).
Token Protection
Updated- sfi-image-nochange
Overview
UpdatedTake a look at our short video to learn more about Microsoft Entra Domain Services.
Configure Security
UpdatedLearn how to improve your security posture with Microsoft Entra.
Zero Trust Protect Networks
UpdatedImprove your security posture with the Microsoft Entra Zero Trust assessment to protect networks.
General
69This article describes how to install cloud sync.
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
Migrate Group Writeback
Updated- A Microsoft Entra account with at least a [Hybrid Identity administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
Clever Tutorial
Updated<a name='configure-and-test-azure-ad-sso-for-clever'></a>
Install the module.
Updated$tenantID = '<tenant-id>'
My Staff Configure
UpdatedAfter configuring administrative units, you can apply this scope to your users who access My Staff. Only users who are assigned an administrative role can access My Staff. To enable My Staff, complete the following steps:
Compliance Administrator
UpdatedCompliance Administrator
Global Reader
UpdatedGlobal Reader
Global Administrator
UpdatedGlobal Administrator
minimumlicense: Free
Updatedauthor: MicrosoftGuyJFlo
- Manage Teams external collaboration settings that govern the organization's interactions with external users in chats, meetings, and calls.
Terms Of Use
Updated* Microsoft Entra ID P1 licenses.
Review Recovery History
UpdatedIf a recovery operation partially succeeds, the **Status** column shows **Completed with warnings**, allowing you to identify objects that weren't recovered. Select **Completed with warnings** to view the details of the changes that were not recovered.
Learn how to configure single sign-on between Microsoft Entra ID and KnowledgeOwl.
Learn how to configure single sign-on between Microsoft Entra ID and Veza.
- You make a change to proxyAddresses or userPrincipalName.
Home Realm Discovery Policy
Updated- If no domain hint or policies are assigned, default HRD behavior applies.
Prerequisites
Updated- Nested OUs are supported (that is, you **can** sync an OU that has 130 nested OUs, but you **can't** sync 60 separate OUs in the same configuration).
author: HULKsmashGithub
Bynder Tutorial
Updated2. Add the Bynder app from the gallery.
This feature preview in Microsoft Entra ID enables admins to create dynamic membership groups and administrative units that populate by adding members of other groups using the `memberOf` attribute. Apps that couldn't read group-based membership previously in Microsoft Entra ID can now read the entire membership of these new `memberOf` groups. Not only can these groups be used for apps but they can also be used for licensing assignments.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Users Bulk Download
Updated1. Select **Users** > **All users** > **Download users**. By default, all user profiles are exported.
Groups Dynamic Tutorial
UpdatedYou're not required to assign licenses to the users for them to be members in dynamic membership groups. You only need the minimum number of available Microsoft Entra ID P1 licenses in the organization to cover all such users.
Groups Quickstart Expiration
UpdatedExpiration policy is simple:
Learn how to manage rules for dynamic membership groups to automatically populate group members and rule references.
Learn how to test members against a rule for dynamic membership groups in Microsoft Entra ID.
Download group members in bulk in the Microsoft Entra admin center.
If you're performing these Microsoft 365 operations from 21Vianet:
Users Search Enhanced
UpdatedEnhancements include:
Users Bulk Delete
Updated> [!IMPORTANT]
Microsoft Entra ID, part of Microsoft Entra, supports bulk user create and delete operations and supports downloading lists of users. Just fill out the comma-separated values (CSV) template you can download from Microsoft Entra ID.
Groups Bulk Download
Updated:::image type="content" source="media/bulk-operations/groups-management-page.png" alt-text="Screenshot of the Microsoft Entra admin center Groups blade showing the All groups list with column headers and actions.":::
1. Select **External collaboration settings**.
You can use rules to determine dynamic membership groups based on user or device properties in Microsoft Entra ID. This article describes how to set up a rule for dynamic membership groups in the Azure portal.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).
Users Bulk Restore
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
Groups Bulk Import Members
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).
If you're a user in an unmanaged organization (tenant) in Microsoft Entra ID, and you no longer need to use apps from that organization or maintain any association with it, you can close your account at any time. An unmanaged organization doesn't have an administrator. Users in an unmanaged organization can close their accounts on their own, without contacting an administrator.
> [!NOTE]
Learn how dynamic group management works.
You can remove a large number of members from a group by using a comma-separated values (CSV) file in the portal for Microsoft Entra ID.
Groups Change Type
UpdatedCreating dynamic membership groups eliminates the management overhead of adding and removing users. This article shows you how to convert existing membership groups from static to dynamic, by using either the Azure portal or PowerShell cmdlets. In Microsoft Entra, a single tenant can have a maximum of 15,000 dynamic membership groups.
Groups Members Owners Search
UpdatedOn the **All groups** page, when you enter a search string, you can toggle between **contains** and **starts with** searches on the **All groups** page only.
Groups Saasapps
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
Usage constraints and other service limits for the Microsoft Entra service
Learn how to optimize your membership rules to automatically populate groups.
Global Administrator
UpdatedGlobal Administrator
Whats New Linux
UpdatedThis article provides information about the latest updates to Microsoft single sign-on for Linux.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
Admin Units Members Add
UpdatedTo create a new group directly in an administrative unit, use the following request. To add an existing group instead, see **Add groups to an administrative unit** earlier in this article.
Directory Delete Howto
Updated3. Create or use a managed administrative account from the tenant that you want to delete. For example: `[email protected]`.
$groupInfo | Add-Member -MemberType NoteProperty -Name "Group ID" -Value $group.Id
Privileged roles and permissions in Microsoft Entra ID.
Licensing Group Advanced
UpdatedMore scenarios limitations, and known issues for Microsoft Entra group-based licensing
How to take over a Domain name DNS domain name in an unmanaged Microsoft Entra organization (shadow tenant).
A Microsoft Entra documentation page was updated: Understand how multiple Microsoft Entra tenant organizations interact.
Use restricted management administrative units for more sensitive resources in Microsoft Entra ID.
Delete users in bulk in Microsoft Entra ID
Peoplecart Tutorial
Updated`https://<tenantname>.peoplecart.com/SignIn.aspx`
Connect Sync Whatis
Updated<a name='azure-ad-connect-sync-topics'></a>
- To use Azure services, including Azure Functions, you need an Azure subscription. If you don't have an existing Azure account, you can sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).
- An Azure subscription with the ability to create Azure Functions. If you don't have an existing Azure account, sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).
Get Signed In Identity
Updated- An Azure account with an active subscription. [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
Authentication
49Configure Sso With Kcd
Updated5. Select **Use any authentication protocol**.
This section guides you through the necessary configurations on the **Stormshield Network Security (SNS) firewall** to enable **OIDC authentication** via **Microsoft Entra ID**.
Reports Data Retention
Updated| Risky sign-ins | 7 days | 30 days | 90 days |
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Publish Tableau Server through Microsoft Entra application proxy to provide secure remote access with preauthentication and Conditional Access.
Set a custom home page URL for applications published through Microsoft Entra application proxy so users land on the correct internal page after sign-in.
Learn how to use the Conditional Access Optimization Agent to safely deploy a passkey program to roll out phishing-resistant authentication methods.
>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
The system accounts for five minutes of clock skew when **every time** is selected in policy, so users aren’t prompted more often than once every five minutes. If the user completes MFA in the last 5 minutes and encounters another Conditional Access policy that requires reauthentication, we don't prompt the user. Prompting users too often for reauthentication can affect their productivity and increase the risk of users approving MFA requests they didn’t initiate. Use "Sign-in frequency – every time" only when there are specific business needs.
The following steps help create a Conditional Access policy to require all users to perform multifactor authentication using the authentication strength policy.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
This guide covers the steps required to deploy and enforce Token Protection for sign-in session tokens on Windows platform.
Secure your resources with Microsoft-managed Conditional Access policies. Require multifactor authentication to reduce compromise risks.
Learn how to configure shared accounts in Microsoft Entra ID using password-based single sign-on so multiple users can securely access apps without sharing passwords directly.
Github Tutorial
Updated* You can use Microsoft My Apps. When you select the GitHub tile in the My Apps, this option redirects to GitHub Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).
Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on both managed and unmanaged devices. Public preview runs from late March to May 2026. Organizations must opt in and configure passkey policies; existing security policies remain unchanged. No compliance issues identified.
In Microsoft Entra ID, part of Microsoft Entra, sometimes organizations need to use a single username and password for multiple people, which often happens in the following cases:
Native Authentication Api
Updated|-----------------------|-------------------------|------------------------|
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
- Store refresh tokens in encrypted, platform‑protected storage.
- OOBE sign-in with a passkey is supported. You can use Web sign-in to unlock a Windows device. For more information, see [Use Web Sign-In To Enable Passwordless Sign-In In Windows](/windows/security/identity-protection/web-sign-in).
- S/MIME using a security key.
This tutorial shows you how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to your iOS/macOS app using native authentication. MFA adds an extra layer of security by requiring a second verification step during sign-in.
This tutorial demonstrates how to implement Email strong authentication method registration into your Android app using native authentication. At least one strong authentication is mandatory for multifactor authentication (MFA) enabled users. Currently, we only support Email and SMS one-time passcode as strong authentication method.
1. Enroll in a Private Preview of SMS and Email OTP MFA on Native Authentication – [Fill out form](https://forms.office.com/r/P3m1q2j3hg)
Learn how to add multi-factor authentication (MFA) with email and SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add email one-time passcode (OTP) multi-factor authentication (MFA) to an iOS or macOS app by using native authentication and enforce MFA with authentication context.
Add email strong authentication method registration to an Android app using native authentication
NewLearn how to register an email one-time passcode as a strong authentication method for MFA-enabled users in an Android app using Microsoft Entra native authentication.
Learn how to register an email strong authentication method for MFA-enabled users in an iOS or macOS app by using native authentication.
Learn how to register phone SMS as a strong authentication method for MFA-enabled users in an iOS or macOS app using native authentication, including configuring client capabilities and handling registration challenges.
Learn how to add multi-factor authentication (MFA) with SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to register an SMS one-time passcode as a strong authentication method for MFA-enabled users in an Android app using Microsoft Entra native authentication.
To support multi-factor authentication (MFA), update the Android client configuration to include the required MFA capabilities.
To support multi-factor authentication (MFA), update the Android client configuration to include the required MFA capabilities.
To support strong authentication method, update the Android client configuration to include the required registration capabilities.
Set the registrationRequired capability during client initialization to support strong authentication method registration.
Learn how to add multifactor authentication (MFA) with SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add multifactor authentication (MFA) with email and SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add email one-time passcode (OTP) multifactor authentication (MFA) to an iOS or macOS app by using native authentication and enforce MFA with authentication context.
1. Complete the steps in [Tutorial: Add sign-in in Android app by using native authentication](tutorial-native-authentication-android-sign-in-sign-out.md).
Native Authentication Api
Updated| `continuation_token` | [Continuation token](#continuation-token) that Microsoft Entra returns. |
Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.
Before enforcing the policy, deploy it in report-only mode to assess the effect and identify noncompliant sign-in sessions.
Use Vm Sign In
Updated> [!IMPORTANT]
Users with a TAP can navigate the setup process on Windows 10 and 11 to perform device join operations and configure Windows Hello for Business. TAP usage for setting up Windows Hello for Business varies based on the devices joined state.
Learn how to configure and enable users to sign-in to Microsoft Entra ID using SMS
Tutorial: Enable cloud sync self-service password reset writeback to an on-premises environment
Updated> [!NOTE]
Disable User Sign In Portal
UpdatedTo disable user sign-in, you need:
Developer
48- make.gov.powerapps.us
:::image type="content" source="./media/application-proxy-configure-complex-application/complex-app-structure-1.png" alt-text="Diagram of domain structure for a complex application showing resource sharing between primary and secondary application.":::
8. Run this command for each collection. Replace *\<yourcollectionname\>* and *\<proxyfrontendurl\>* with your own information. This command enables single sign-on between RD Web and RD Gateway, and optimizes performance.
Application Proxy Wildcard
Updated- Internal URL:
Application Proxy Qlik
UpdatedFollow the same steps as for Application #1, with the following exceptions:
Cookies that don't specify the [SameSite](https://web.dev/articles/samesite-cookies-explained) attribute are treated as if they're set to **SameSite=Lax**. The `SameSite` attribute declares how cookies should be restricted to a same-site context. When set to `Lax`, the cookie is only sent to same-site requests or top-level navigation. However, application proxy requires these cookies to be preserved in the third-party context to keep users signed in during their session. Due to the requirement, updates were made:
Publish and manage multiple on-premises applications at once using wildcard URL patterns in Microsoft Entra application proxy.
Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Configure Kerberos-based SSO for on-premises applications using Kerberos Constrained Delegation (KCD) with Microsoft Entra application proxy.
Understand complex applications in Microsoft Entra application proxy.
Configure Microsoft Entra private network connectors with outbound proxy servers. Covers bypassing proxies, routing through proxies, and proxy placement between connectors and backend apps.
Optimize performance for global connectivity scenarios using Azure Front Door for geo-acceleration with Microsoft Entra application proxy.
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
Configure Microsoft Entra application proxy to enable secure external access to on-premises SharePoint Server using Kerberos Constrained Delegation for single sign-on.
Combine Microsoft Entra application proxy with Azure Traffic Manager for geographic load balancing and high availability across multiple connector groups.
Configure and manage custom domains in Microsoft Entra application proxy to use your own domain name.
Grant Admin Consent
UpdatedLearn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedConfigure header-based single sign-on for on-premises applications published through Microsoft Entra application proxy. Pass user identity attributes as HTTP headers.
Integrate Microsoft Entra application proxy with Qlik Sense.
- Completion of the steps in [Quickstart: Create and assign a user account](add-application-portal-assign-users.md).
For instance, if an application is found to be non-compliant with company policies, an administrator might choose to 'Block' it. Conversely, if an application is legitimate but requires further review, the administrator may opt to 'Deny' the request temporarily while seeking more information.
Groups Naming Policy
UpdatedYou can use attributes that can help you and your users identify which department, office, or geographic region for which the group was created. For example, if you define your naming policy as `PrefixSuffixNamingRequirement = "GRP [GroupName] [Department]"` and `User's department = Engineering`, then an enforced group name might be `"GRP My Group Engineering."` Supported Microsoft Entra attributes are `\[Department\]`, `\[Company\]`, `\[Office\]`, `\[StateOrProvince\]`, `\[CountryOrRegion\]`, and `\[Title\]`. Unsupported user attributes are treated as fixed strings. An example is `"\[postalCode\]"`. Extension attributes and custom attributes aren't supported.
Users Revoke Access
UpdatedAccess tokens and refresh tokens are frequently used with thick client applications, and also used in browser-based applications such as single page apps.
Learn how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to configure application proxy with Remote Desktop Services (RDS)
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Get all Microsoft Entra application proxy apps that are published with the identical certificate
UpdatedPowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
Add an on-premises application for remote access through application proxy in Microsoft Entra ID
UpdatedLearn how to prepare your environment for application proxy and add an on-premises application to your Microsoft Entra tenant.
Configure and manage custom domains in Microsoft Entra application proxy to use your own domain name.
Learn how to configure single sign-on for on-premises apps published through Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Delete Application Portal
UpdatedTo delete an enterprise application, you need:
Provisioning
34ai-usage: ai-assisted
1. After entering the domain, a new line in the table appears showing domain name and its status as **initialize**. Select the gear icon to reveal technical data about TAP app Security server and to complete initialization.
There are two ways to provision users from Microsoft Entra into SAP Cloud Identity Services.
Sentry Provisioning Tutorial
Updated* [A Microsoft Entra tenant](~/identity-platform/quickstart-create-new-tenant.md).


The following document will guide you through configuring Microsoft Entra Cloud Sync for provisioning groups from Microsoft Entra ID to Active Directory. If you are looking for information on provisioning from AD to Microsoft Entra ID, see [Configure - Provisioning Active Directory to Microsoft Entra ID using Microsoft Entra Cloud Sync](how-to-configure.md).

author: jeevansd




Litmos Provisioning Tutorial
Updated

Looop Provisioning Tutorial
Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
This article describes the steps you need to perform in both GitHub Enterprise Managed User (OIDC) and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to GitHub Enterprise Managed User (OIDC) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
Connect Version History
Updated- Fixed a [known issue](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified) where auto-upgrade could stop your Microsoft Entra Connect server unexpectedly. Auto-upgrade now detects modifications to the `miiserver.exe.config` and `miisclient.exe.config` configuration files and skips automatic upgrade on those servers. If you manually upgrade and previously modified these configuration files, you might encounter installation failures. To resolve the issue, see the [known issues section](#known-issue-synchronization-fails-after-upgrade-if-miiserverexeconfig-was-previously-modified).
author: jeevansd
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Dialpad.
author: jeevansd
author: jeevansd
manager: pmwongera

This section guides you through connecting your Microsoft Entra ID to GoToMeeting's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in GoToMeeting based on user and group assignment in Microsoft Entra ID.
Gpad Prereqs
Updated- The provisioning agent must be installed on a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AWS IAM Identity Center.
author: jeevansd
author: jeevansd
author: jeevansd
author: jeevansd
Conditional Access
26Every day, Microsoft processes more than 100 trillion security signals from endpoints, cloud services, identity systems, and more. We use this data shape how we respond to threats and inform how we innovate to help build a safer digital future. Read about the work we're doing in the [Microsoft Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1).
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Migrate Approved Client App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Agent Block High Risk
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Block By Location
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Block Example
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
**To configure your Conditional Access policy:**
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Guests Mfa Strength
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Old Require Mfa Admin
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Policy Old Require Mfa Guest
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Between November 2025 and February 2026, Microsoft Baseline Security Mode automatically created two disabled draft Entra Conditional Access policies in some tenants. This is not a security issue, requires no action, and a fix will remove unintended drafts and prevent automatic creation.
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Once you start a phased rollout, the agent helps you progress. The phased rollout suggestion is present throughout the rollout process and can show no action needed, suggest progressing to the next phase, or suggest rolling back.
Security
17Prepare Converted Groups
Updated$groupDisplayName = 'My Security Group'
ai-usage: ai-assisted
Microsoft 365 group creation and editing in My Groups will be enhanced by late March 2026, allowing owners to configure usage guidelines, email aliases, sensitivity labels, Exchange settings, and security options. The update improves control and clarity without impacting existing groups or requiring admin setup.
Secure NDES certificate enrollment for mobile devices using Microsoft Entra application proxy. Includes connector setup and certificate request validation.
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
Helpdesk Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
User Administrator
Updated>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.
- Policy can be applied to the Microsoft Edge browser on devices running Windows 11 and Windows 10 version 20H2 and higher with KB5031445.
Security Store In Entra
UpdatedSecurity Store is embedded in the Microsoft Entra admin center, so you can discover and deploy agents and solutions without leaving your identity management workflow.
Groups Restore Deleted
UpdatedUser Administrator and Partner Tier 1 Support | Can restore any deleted Microsoft 365 group or cloud security group except those groups assigned to the Global Administrator role
Groups Settings Cmdlets
UpdatedFor more information on how to prevent nonadministrator users from creating security groups, set the `AllowedToCreateSecurityGroups` property to False as described in [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy).
Learn how to restore a deleted group, view restorable groups, and permanently delete a group in Microsoft Entra ID.
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
Groups Dynamic Membership
UpdatedWhen you create a dynamic membership rule, the security of that group's membership depends on who can modify the attributes referenced in the rule. Before selecting an attribute, review the write permissions for that attribute—both in Microsoft Entra ID and in any connected source directories.
Token Protection on Windows platforms can be used to protect the following resources:
Deploy Defender XDR workloads to alert on suspicious or anomalous behaviors surrounding token theft.
Microsoft identity platform
13ai-usage: ai-assisted
ai-usage: ai-assisted
To call a web API from a web app on behalf of a user, use the authorization code flow and store the acquired tokens in the token cache. When needed, MSAL refreshes tokens and the controller silently acquires tokens from the cache.
Create and manage a multitenant organization using Microsoft Graph PowerShell or Microsoft Graph API. Covers creating the organization, adding tenants, joining, and managing roles.
Apple Sso Plugin
UpdatedIf your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.
- Admins can apply policy only to supported platforms (such as iOS, Android, and Windows) through the Conditional Access Microsoft Graph API.
Microsoft Graph
UpdatedTo manage custom security attribute assignments for users in your Microsoft Entra organization, you can use PowerShell or Microsoft Graph API. The following examples can be used to manage assignments.
Configured tenants no longer in use might still generate costs for your organization. Making a tenant inaccessible due to inactivity helps reduce unnecessary expenses. This article discusses how to handle an inaccessible tenant, reactivation, and guidance for both administrators and application developers.
Delegate custom administrator role permissions for managing app registrations.
Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.
> [!NOTE]
Msal Node Migration
Updated});
Yet another common error you might face is `consent_required`, which occurs when permissions required for obtaining an access token for a protected resource aren't consented by the user. As in `interaction_required`, the solution for `consent_required` error is often initiating an interactive token acquisition prompt, using either `acquireTokenPopup` or `acquireTokenRedirect`.
Monitoring
11Place the connector close to the target application in the customer network. This configuration minimizes step 3 in the topography diagram, because the connector and application are close.
1. *Authority*: Enter *https://login.windows.net*.
Securely integrate Azure Logic Apps with on-premises APIs using Microsoft Entra application proxy
UpdatedMicrosoft Entra application proxy lets cloud-native logic apps securely access on-premises APIs to bridge your workload.
Optimize traffic flow and connector placement for Microsoft Entra application proxy. Covers bandwidth, latency, and network patterns including ExpressRoute and multi-region deployments.
Permissions Reference
Updated> | [Compliance Administrator](#compliance-administrator) | Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365. | 17315797-102d-40b4-93e0-432062caca18 |
What If Tool
UpdatedStart an evaluation by selecting **What If**. The evaluation result provides you with a report that consists of:
1. Go to **Backup and recovery** > **Backups**. Select a backup from the list, and then select **Create difference report**.
Recover Applications
UpdatedAfter you determine the cause of the changes, validate whether the secrets for applications were impacted. Find changes to application secrets in the audit log. Look for events that indicate the application secret was changed or updated.
Recover Objects
Updated1. Go to **Backup and recovery** > **Difference reports**. Select a completed difference report.
Sla Performance
Updated| Month | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 |
Reports Data Retention
Updated**No**, you can't. Azure stores up to seven days of activity data for a free version. When you switch from a free to a premium version, you can only see up to 7 days of data.
Standards
10Policy Guests Mfa Strength
Updated1. Give your policy a name. Create a meaningful standard for the names of your policies.
1. The Tenant URL is `https://scim.segmentapis.com/scim/v2`. This value is entered in the **Tenant URL** field in the Provisioning tab of your Segment application.
The Microsoft Entra provisioning service currently operates under particular [IP ranges](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md#ip-ranges). If necessary, you can restrict other IP ranges and add these particular IP ranges to the allow list of your application. That technique will allow traffic flow from the Microsoft Entra provisioning service to your application.
Configure Microsoft Entra application proxy with SAML-based authentication for secure external access to on-premises SharePoint Server.
Continuous access evaluation
UpdatedToken expiration and refresh are a standard mechanism in the industry. When a client application like Outlook connects to a service like Exchange Online, the API requests are authorized using OAuth 2.0 access tokens. By default, access tokens are valid for one hour, when they expire the client is redirected to Microsoft Entra to refresh them. That refresh period provides an opportunity to reevaluate policies for user access. For example: the token might not be refreshed because of a Conditional Access policy, or because the user is disabled in the directory.

Everbridge Tutorial
Updated
Learn how to integrate an on-premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
This section will outline best practices independent software vendors (ISV’s) can adopt to enable automated certificate rollover when SAML certificates are near expiry and when applications federated with Microsoft Entra ID. SAML certificates in Entra ID are used for signing assertions in federated single sign-on (SSO). These certificates expire (typically every 1-3 years) and rotation requires a Customer and SaaS ISV coordination to update a mutual certificate in both systems without downtime. Industry trends are shortening certificate lifetimes, manual rollover processes increasingly create operational burden and risk service disruption — especially in large organizations with many SAML enterprise applications.
Blackboard Learn Tutorial
Updated`https://<subdomain>.blackboard.com/auth-saml/saml/SSO/entity-id/SAML_AD`
Troubleshooting
6To get detailed information about the sign-in interruption, review the Microsoft Entra sign-in events to see which Conditional Access policy or policies applied and why.
Troubleshooting
Updated**If the difference report is running for a long time:**
Groups Troubleshooting
UpdatedTo disable group creation for nonadmin users in PowerShell:
Troubleshoot Alerts
UpdatedUpon successful onboarding, Domain Services back fills synchronized users and groups with the onboarded custom attribute values. The custom attribute values appear gradually, depending on the size of the tenant. To check the backfill status, go to [Domain Services Health](check-health.md) and verify the **Synchronization with Microsoft Entra ID** monitor timestamp has updated within the last hour.
Learn how to troubleshoot common errors and configuration problems with Microsoft Entra application proxy.
Learn how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to an iOS or macOS app using native authentication, including enforcing MFA with authentication context and handling MFA errors.
Architecture
3Recoverability Overview
Updated- Use a least privilege model. Ensure that each member of your team has the least privileges necessary to complete their usual tasks. Require a process to escalate privileges for more unusual tasks.
Learn about the architecture, connectors, authentication methods, and security benefits of Microsoft Entra application proxy.
Learn about security considerations and architecture for using Microsoft Entra application proxy.
Governance
2include file
Updatedinclude file
Groups Lifecycle
Updated- **Teams**: Visit a Teams channel.
Microsoft Entra Agent ID
12 updatesGeneral
5Learn how agent registry experiences are converging under Microsoft Agent 365, what the change means for Microsoft Entra Agent ID, and how to view all agents in your organization.
identityParentId = "<associated-agent-identity-id>"
Agent Id Setup Instructions
Updated- Execute each step **sequentially** and don't skip ahead.
Agent Id Ai Guided Setup
Updatedauthor: arlucaID
Agent Lists
UpdatedTo view agent identities in your Microsoft Entra tenant, you need:
Developer
2Call Api Custom
Updated_api = api;
This file is used by an AI coding agent (such as GitHub Copilot in VS Code Agent mode) to automate onboarding to Microsoft Entra Agent ID.
Conditional Access
1Agent Id
UpdatedThere are two key business scenarios where Conditional Access policies can help you manage agents effectively.
Fundamentals
1AI agents are autonomous software systems that can perceive their environment, make decisions, and take action. AI agents can expand organizational capabilities but also introduce security challenges that differ from traditional application security. This introduction explains why AI security matters, the challenges AI agents present, the concept of agent sprawl, and how Microsoft provides security mechanisms for AI agents in enterprise environments.
Microsoft identity platform
1This article explains how to call a Microsoft Graph API from an agent using agent identities or an agent's user account.
Provisioning
1Use an AI coding agent to automate the onboarding process for Microsoft Entra Agent ID, including blueprint creation, credential configuration, and agent identity provisioning.
Security
1Call Api Azure Services
Updated_credential = credential;
Microsoft Entra ID Protection
7 updatesFundamentals
4Managed Policies
UpdatedThis policy covers all users and requires multifactor authentication and reauthentication when high-risk sign-ins are detected. High-risk in this case means something about the way the user signed in is out of the ordinary. These high-risk sign-ins might include travel that is highly abnormal, password spray attacks, or token replay attacks. For more information, see [What are risk detections](/entra/id-protection/concept-identity-protection-risks#sign-in-risk-detections).
Conditional Access Grant
UpdatedWhen user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation with Microsoft-managed remediation (preview)](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control-preview).
Identity Protection Policies
UpdatedIdentifying risk-based Conditional Access policies
The AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Admin involvement for routine tasks. Rollout starts March 2026. AI Admins gain expanded permissions for agent lifecycle management, tenant-wide consent (excluding Microsoft Graph app permissions), and risk monitoring via Identity Protection, enhancing security and compliance.
Authentication
2Security Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security
1Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Microsoft Entra ID Governance
58 updatesGovernance
49Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure Microsoft Entra role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Groups Assign Member Owner
UpdatedIn Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn about the signals and metrics used in Microsoft Entra Tenant Governance to identify and evaluate related tenants
Licensing Tenant Governance
Updated| Feature | Free | Microsoft Entra P1 | Microsoft Entra P2 | Microsoft Entra ID Governance |
Signals Metrics
UpdatedThis article focuses exclusively on:
1. Select **Terminate governance**.
Governance Policy Templates
Updated- Cross-tenant delegated administration roles - Specify which Microsoft Entra built-in roles users from the governing tenant have in the governed tenant.
This article describes how to update an existing governance relationship between a governing tenant and a governed tenant. You might need to update a governance relationship to add or modify delegated administration roles or multitenant application configurations.
Deployment Guide
Updated1. Configure the template:
Governance Relationships
Updated| Scenario | Description |
Create Monitor
Updated- [Configuration management](configuration-management.md)
- [Set up a governance relationship](how-to-set-up-governance-relationship.md)
Delegated Administration
Updated- [Monitor governing tenant admin activity](how-to-monitor-governing-activity.md)
Enable Tenant Discovery
Updated- [Review the list of related tenants](related-tenants.md) surfaced by discovery.
Monitor Governing Activity
Updated- [Use cross-tenant delegated administration](how-to-delegated-administration.md)
See Monitor Results
Updated- [Create a monitor](how-to-create-monitor.md)
Update Delete Monitor
Updated- [Create a monitor](how-to-create-monitor.md)
Simulate Workflow Execution
UpdatedLearn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.
1. If you want to allow users in external directories from connected organizations to be able to request access packages in this catalog, set **Enabled for external users** to **Yes**. The access packages must also have a policy allowing users from connected organizations to request. If the access packages in this catalog are intended only for users already in the directory, then set **Enabled for external users** to **No**.
Perform Access Review
UpdatedMicrosoft Entra ID simplifies how enterprises manage access to groups and applications in Microsoft Entra ID and other Microsoft web services with a feature called access reviews. This article covers how a designated reviewer performs an access review for members of a group or users with access to an application. If you want to review access to an access package, read [Review access of an access package in entitlement management](entitlement-management-access-reviews-review-access.md).
Discovery and insights (formerly Security Wizard) help you convert permanent Microsoft Entra role assignments to just-in-time assignments with Privileged Identity Management.
Learn how to configure security alerts for Azure resource roles in Privileged
Configure security alerts for Microsoft Entra roles Privileged Identity Management.
The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.
Learn how to approve or deny requests for Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to approve or deny requests for Azure resource roles in Privileged
Learn how to assign Azure resource roles in Privileged Identity Management (PIM).
Learn how to bring groups into Privileged Identity Management.
Learn how to complete an access review of Azure resource and Microsoft Entra roles Privileged Identity Management.
Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Learn how to create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to discover Azure resources to manage in Privileged Identity Management (PIM).
Learn how to extend or renew PIM for groups assignments.
Learn how to review access of Azure resource and Microsoft Entra roles
Learn how to extend or renew Azure resource role assignments in Privileged Identity Management (PIM).
Learn how to extend or renew Microsoft Entra role assignments in Microsoft Entra Privileged Identity Management (PIM)
Start using PIM
UpdatedLearn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.
Learn how to use Azure custom roles in Microsoft Entra Privileged Identity Management (PIM).
Learn how to view the audit log history for Microsoft Entra roles in
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
Learn how to activate your group membership or ownership in Privileged
Describes the roles you can't manage in Microsoft Entra Privileged Identity
Learn how Microsoft Entra ID is licensed for guest users.
Simulate Workflow Execution
RemovedA Microsoft Entra documentation page was updated: Simulate Workflow Execution.
Access Review Agent
Updated> [!NOTE]
Fundamentals
6Learn about Microsoft Entra Tenant Governance and how it helps organizations discover, manage, and govern tenants across their environment
Overview
Updated- Automatically detect tenants that are related to your tenant based on one or more discovery signals.
How to manage Microsoft Entra Privileged Identity Management (PIM) for Groups.
Describes how to use a resource dashboard to perform an access review
Provides an overview of Microsoft Entra Privileged Identity Management (PIM).
Information for understanding the APIs in Microsoft Entra Privileged
Microsoft identity platform
2Security Copilot will be included with Microsoft 365 E5 via a phased rollout from April 20 to June 30, 2026, providing 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products. Additional advanced capabilities may incur extra costs.
Interpret Discovery Data
Updated- Investigate ownership (business unit, team, or developer).
Authentication
1Delegated Administration
Updated1. After successful sign-in, perform administrative tasks in the governed tenant based on the roles assigned to your security group.
Microsoft Entra External ID
31 updatesGeneral
8Bulk invite B2B users
UpdatedLearn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.
Use Microsoft accounts
UpdatedEnable your external business partners and guest users to use their Microsoft account (MSA) to sign in to your apps for B2B collaboration.
Use Microsoft Entra accounts
UpdatedEnable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.
Cross-cloud settings
UpdatedEnable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.
Learn how to add Google as an identity provider for your external tenant.
B2b Tutorial Require Mfa
Updated1. Select **New policy**.
Clean Up Unmanaged Accounts
UpdatedPrior to August 2022, Microsoft Entra B2B supported self-service sign-up for email-verified users. With this feature, users create Microsoft Entra accounts, when they verify email ownership. These accounts were created in unmanaged (or viral) tenants: users created accounts with an organization domain, not under IT team management. Access persists after users leave the organization.
Cross Cloud Settings
UpdatedThe following scenarios are supported when collaborating with an organization from a different Microsoft cloud:
Provisioning
8ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
Configure cross-tenant synchronization using the Microsoft Entra admin center. Step-by-step guide covering trust settings, provisioning scope, attribute mappings, and testing.
Map custom directory extension attributes in cross-tenant synchronization. Covers creating extensions, adding them to attribute mappings, and manual schema editing.
<br/>**Target tenant**
<br/>**Source tenant**
Known Issues
Updated- B2B users are unable to manage certain Microsoft 365 services in remote tenants (such as Exchange Online), as there's no directory picker.
Authentication
4Learn how to enforce multifactor authentication policies for Microsoft Entra B2B users.
Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.
Define custom attributes
UpdatedLearn how to create and define new custom attributes to be collected from users during sign-up and sign-in.
Tenant Restrictions V2
Updated- TRv2 does not enforce restrictions on cross-cloud requests at the authentication plane, so access is permitted during authentication. However, TRv2 does block cross-cloud requests at the data plane. As a result, when using Windows Group Policy (GPO), users will be unable to access TRv2-enlightened resources across cloud boundaries.
Fundamentals
3ai-usage: ai-assisted
View real-time insights on active devices, alerts, traffic patterns, and cross-tenant usage across Microsoft Entra Private Access and Internet Access services.
View real-time insights on active devices, alerts, traffic patterns, and cross-tenant usage across Microsoft Entra Private Access and Internet Access services.
Microsoft identity platform
3ai-usage: ai-assisted
Configure cross-tenant synchronization using Microsoft Graph PowerShell or Microsoft Graph API. Includes enabling synchronization, setting up automatic redemption, creating provisioning jobs, and testing on-demand provisioning.
Configure cross-tenant access and identity synchronization policy templates for multitenant organizations using the Microsoft Graph API. Covers automatic redemption, inbound sync, and template management.
Security
2Learn how to integrate third-party bot protection providers with Native API sign-up flows in Microsoft Entra External ID by using a Web Application Firewall.
To enable WAF for protection, configure a WAF policy and associate it with Azure Front Door Premium. Microsoft optimizes Azure Front Door premium for security and manages the rule sets provided by the WAF to protect against common vulnerabilities including cross-site scripting and JavaScript exploits. Additionally, Azure WAF provides rule sets that help protect against malicious bot activity and provide layer 7 DDoS protection for your application.
Architecture
1B2c Deployment Plans
Updated- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)
Governance
1Learn to govern and manage identity and access lifecycles across multitenant organizations.
Standards
1Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.
Microsoft Entra Internet Access
38 updatesGeneral
22A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access.
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
A Microsoft Entra documentation page was updated: minimumlicense: Microsoft Entra Internet Access or Microsoft Entra Private Access.
manager: dougeby
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Zscaler Coexistence
UpdatedLearn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
Learn how to configure threat intelligence in Microsoft Entra Internet Access.
ai-usage: ai-assisted
ai-usage: ai-assisted
Use custom block pages to display organization-specific messaging internet access policies block users from accessing websites.
Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
Security
7Deploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Configure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
Configure Microsoft Global Secure Access alongside Cisco AnyConnect and ASA VPNs for unified SASE. Covers deployment scenarios with step-by-step configuration for private access, Microsoft 365 traffic, and internet access.
Deploy Microsoft Entra Private Access alongside Palo Alto Prisma Access. Includes configuration steps for secure internet access and private application connectivity.
Deploy Global Secure Access alongside Cisco Umbrella with DNS security. Includes step-by-step configuration for both platforms to support private access, Microsoft 365 traffic, and internet access.
Netskope Coexistence
UpdatedLearn how to configure and deploy Microsoft Entra and Netskope Security Service Edge (SSE) solutions together for optimized security and connectivity across private applications, Microsoft 365, and internet access.
Fundamentals
5Configure Security
Updated| [Global Secure Access cloud firewall protects branch office internet traffic](zero-trust-protect-networks.md#global-secure-access-cloud-firewall-protects-branch-office-internet-traffic) | Microsoft Entra Internet Access |
Traffic Forwarding
UpdatedWith the internet access profile, you can route traffic to the public internet, including traffic to SaaS apps. This traffic forwarding profile consists of a prepopulated list of regular expressions for fully qualified domain names (FQDNs) and IP addresses representing the public internet.
Clients
UpdatedLearn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Internet Access
Updatedai-usage: ai-assisted
The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.
Conditional Access
2Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
Control internet access based on website categories, URLs, and FQDNs. Configure granular, user-aware filtering policies using security profiles and Conditional Access.
Troubleshooting
2View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.
Microsoft Entra Private Access
25 updatesGeneral
12Learn how to migrate client devices from DirectAccess to Microsoft Entra Private Access with a phased approach that avoids tunnel conflicts and connectivity failures.
manager: dougeby
manager: dougeby
Set up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Configure direct connectivity between your virtual network and Azure SQL using service endpoints with Microsoft Entra Private Access for secure database access.
Set up private network connectors that enable outbound connections from your private network to Global Secure Access. Includes installation, connector groups, and high availability.
Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
Developer
5Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Add just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Configure Microsoft Entra Private Access to securely connect remote users to Azure Storage accounts through Azure Private Link. Covers prerequisites, Quick Access application setup, and connectivity verification.
Secure private application access with Privileged Identity Management and Global Secure Access
UpdatedAdd just-in-time privileged access for critical servers and applications using Privileged Identity Management (PIM) with Microsoft Entra Private Access.
Authentication
4Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Configure Kerberos Sso
UpdatedEnable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Enforce Conditional Access and multifactor authentication for Kerberos authentication to Active Directory Domain Controllers through Microsoft Entra Private Access.
Enable single sign-on to on-premises resources published through Microsoft Entra Private Access using Kerberos authentication. Optionally integrate Windows Hello for Business cloud Kerberos trust.
Conditional Access
2Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
Configure Conditional Access policies for Quick Access and Private Access apps to control access to internal resources based on user, device, and location conditions.
Fundamentals
1Connectors
UpdatedAfter a connector is enrolled, it establishes outbound TLS tunnels to the Private Access cloud infrastructure. These tunnels handle all data path traffic. In addition, the control plane channel uses minimal bandwidth to drive keep-alive heartbeat, health reporting, connector updates, and other functions.
Monitoring
1DirectAccess provides remote connectivity to internal resources but relies on IPv6 transition technologies, requires domain-joined Windows Enterprise clients, and grants full network-level access once connected. However, these architectural constraints don't meet the needs of modern hybrid and cloud-first environments.
Microsoft Entra Verified ID
19 updatesSecurity
9The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials, and completely opt out of the service.
Plan Verification Solution
UpdatedMicrosoft’s Microsoft Entra Verified ID (Microsoft Entra VC) service enables you to trust proofs of user identity without expanding your trust boundary. With Microsoft Entra VC, you create accounts or federate with another identity provider. When a solution implements a verification exchange using verifiable credentials, it enables applications to request credentials that aren't bound to a specific domain. This approach makes it easier to request and verify credentials at scale.
In this tutorial, you learn how to issue verifiable credentials, from directory based claims, by using a sample app.
Learn how to start a presentation request in Verifiable Credentials.
- [Set up a tenant for Microsoft Entra Verified ID](./verifiable-credentials-configure-tenant.md).
Advanced setup involves the following steps:
Learn how to issue and verify credentials by using the Request Service REST API.
Architecture
3A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
General
3In this tutorial, you learn how to use Face Check with Microsoft Entra Verified ID.
Whats New
Updated- Entra Verified ID is supported on Microsoft GCC environments.
Plan Issuance Solution
UpdatedAuthentication
1In this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.
Developer
1Fundamentals
1An overview of Microsoft Entra Verified ID.
Microsoft identity platform
1- **Free Microsoft Entra tenant** — [Create a new tenant](~/identity-platform/quickstart-create-new-tenant.md) with an [Azure free account](https://azure.microsoft.com/pricing/purchase-options/azure-account). This gives you Entra ID Free tier. You can then [activate a free trial of Microsoft Entra ID P1 or P2](~/fundamentals/get-started-premium.md) if needed for testing.
Microsoft Entra Workload ID
5 updatesFundamentals
2Learn how to enable continuous access evaluation for workload identities to enforce Conditional Access policies and instantly revoke tokens.
What Is Entra
Updated**For example**, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.
Conditional Access
1Workload Identity
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
Developer
1An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resource type](/graph/api/resources/approleassignment).
General
1- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).
Microsoft Entra Global Secure Access
91 updatesGeneral
44author: HULKsmashGithub
- You must disable Domain Name System (DNS) over HTTPS (Secure DNS) to tunnel network traffic. Use the rules of the fully qualified domain names (FQDNs) in the traffic forwarding profile. For more information, see [Configure the DNS client to support DoH](/windows-server/networking/dns/doh-client-support#configure-the-dns-client-to-support-doh).
Configure Connectors
Updated>
Install Ios Client
UpdatedBecause the Global Secure Access client for iOS is integrated with Microsoft Defender for Endpoint, it's helpful to understand the end user experience. The client appears in the Defender dashboard after onboarding to Global Secure Access.
Control which users and groups receive traffic forwarding policies, enabling gradual rollout and limiting scope during testing or deployment phases.
Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.
The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the iOS client app.
Modify remote network configurations, delete unused networks, and manage device links and traffic profile assignments for Global Secure Access.
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Learn how to enable source IP restoration to ensure the source IP matches in downstream resources.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Create a PowerShell script for unattended installation and registration of the Microsoft Entra private network connector for bulk deployments or servers without a UI.
Use the web category checker to find which web content category a URL belongs to via Microsoft Graph.
|Nudity | Sites that contain full or partial nudity that aren't necessarily overtly sexual in intent.|
Cisco Vpn Coexistence
Updated> [!IMPORTANT]
Configure Kerberos Sso
Updated|49152-65535 |UDP/TCP |Ephemeral ports |
Configure Per App Access
Updated1. Enter a name for the app.
Configure Quick Access
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with the appropriate roles.
author: HULKsmashGithub
ai-usage: ai-assisted
Modify remote network configurations, delete unused networks, and manage device links and traffic profile assignments for Global Secure Access.
Control which users and groups receive traffic forwarding policies, enabling gradual rollout and limiting scope during testing or deployment phases.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.
Create a PowerShell script for unattended installation and registration of the Microsoft Entra private network connector for bulk deployments or servers without a UI.
This article lists all releases of Microsoft Entra private network connector and describes new features and fixed issues.
Learn how to roll out traffic forwarding profiles to users and groups with Global Secure Access
Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.
Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Learn how to configure per-app access to private resources in Global Secure Access.
Learn how to configure Quick Access to private resources in Global Secure Access.
Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.
Global Secure Access Threat intelligence threat types
Global Secure Access Web content filtering categories
Learn how to assign a remote network to a traffic forwarding profile for Global Secure Access.
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Learn how to list remote networks for Global Secure Access.
Learn how to update and delete remote networks for Global Secure Access.
Use these PowerShell samples for Global Secure Access.
```powershell
Enable Multi Geo
Updatedauthor: HULKsmashGithub
Powershell Samples
UpdatedUse these PowerShell samples for Global Secure Access.
Security
14Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Configure Microsoft Global Secure Access and Cisco Secure Access for unified SASE capabilities. Covers deployment steps, FQDN and IP bypasses, and client configuration.
- A **Global Secure Access Administrator** role in Microsoft Entra ID.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Configure Microsoft Global Secure Access and Cisco Secure Access for unified SASE capabilities. Covers deployment steps, FQDN and IP bypasses, and client configuration.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Zscaler Coexistence
UpdatedLearn how to configure Microsoft and Zscaler SSE for unified SASE solutions to enhance security and connectivity in your organization.
Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Learn how to apply security policies like web content filtering, threat intelligence, and cloud firewall to remote network traffic in Global Secure Access.
Microsoft and Cisco’s Secure Access coexistence solution guide.
Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
Microsoft and Cisco VPNs coexistence solution guide.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
27014
UpdatedThe Global Secure Access Secure Web Gateway (SWG) implements defense-in-depth through five security layers that together create a comprehensive inspection chain for internet-bound traffic. Each layer serves a distinct protective function:
Troubleshooting
12View Deployment Logs
UpdatedMonitor and troubleshoot configuration changes in Global Secure Access using deployment logs. Learn how to view logs, configure settings, and analyze fields.
Troubleshoot Connectors
Updated
The proposed workaround for the above-mentioned scenario is as follows.
Zscaler Coexistence
Updated1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. Select the **Traffic** tab and select **Start collecting**.
Learn if a device can communicate with the Global Secure Access service and tunnel traffic, by using the health check utility.
A Microsoft Entra documentation page was updated: Troubleshoot Global Secure Access Client Ios Health Check Utility.
In the [Microsoft Intune admin center](https://intune.microsoft.com/), confirm the following criteria:
Troubleshoot problems installing the Microsoft Entra private network connector.
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Fundamentals
6View Enriched Logs
Updated- **Microsoft Profile** - Ensure the Microsoft traffic profile is enabled. Microsoft traffic forwarding profile is required to capture traffic directed to Microsoft 365 services, which is fundamental for log enrichment.
Learn how to configure Microsoft Entra Private DNS for secure and efficient internal DNS query resolution, replacing legacy VPNs with granular access.
Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Partner Ecosystem Overview
UpdatedLearn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
$RegistrySettings = @(
Monitor the health and status of your network traffic with the Global Secure Access dashboard.
Microsoft identity platform
6Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.
Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
View and review all remote networks in your Global Secure Access deployment using the Microsoft Entra admin center or Microsoft Graph API.
Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
View and review all remote networks in your Global Secure Access deployment using the Microsoft Entra admin center or Microsoft Graph API.
Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.
Conditional Access
5Learn how to require known compliant network locations to connect to your secured resources with Conditional Access.
Learn how to apply Conditional Access policies to the Global Secure Access traffic.
Learn how to require known compliant network locations to connect to your secured resources with Conditional Access.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
Monitoring
3Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
Authentication
1userimpact: Low
UpdatedWhen organizations deploy Global Secure Access as their cloud-based network proxy, Microsoft's Secure Service Edge infrastructure routes user traffic. If you don't enable source IP restoration, all authentication requests come from the proxy's IP address instead of the user's actual public egress IP.
