When a problem prevents Microsoft Entra from downloading the CRL, the cause is often firewall restrictions. In most cases, you can resolve the issue by updating firewall rules to allow the required IP addresses so Microsoft Entra can successfully download the CRL. For more information, see [Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=56519).
What changed in April
396 documentation updates and 7 Message Center announcements were tracked during April. Activity centred on Fundamentals, Provisioning, and General, with the most changes affecting Entra ID and ID Governance.
403 updates by product
Microsoft Entra ID
262 updatesFundamentals
98Provides a general overview of Microsoft Entra recommendations so you can keep your tenant secure and healthy.
Directory Join
Updated| **Definition** | <ul><li>Joined only to Microsoft Entra ID requiring organizational account to sign in to the device</li></ul> |
Explore Microsoft Entra Conditional Access, the Zero Trust policy engine that integrates signals to secure access to resources.
Fido2 Hardware Vendor
UpdatedPasskeys (FIDO2) enable phishing-resistant authentication. They can replace weak credentials with strong phishing-resistant public/private-key credentials that can't be reused, replayed, or shared across services. They can be stored securely on a device or synced across trusted devices through an encrypted cloud service.
Depending on the environment, synced users might also be subject to Microsoft Entra ID restrictions such as the global banned password list. For more information, see the [FAQ section](#faq).
Learn about cross-tenant synchronization in Microsoft Entra ID.
Data Storage Eu
UpdatedA Microsoft Entra documentation page was updated: Data Storage Eu.
All accounts that sign in to perform operations cited in the [applications section](#application-ids-and-urls) must complete MFA when the enforcement begins. Users aren't required to use MFA if they access other applications, websites, or services hosted on Azure. Each application, website, or service owner listed earlier controls the authentication requirements for users.
- [Choosing authentication methods for your organization](concept-authentication-methods.md)
Fido2 Hardware Vendor
UpdatedIn the Microsoft Entra ID authentication methods policy, administrators can enforce attestation for FIDO2 security keys. When **Enforce attestation** is set to **Yes**, Microsoft requires extra metadata from passkeys (FIDO2) that are registered with the tenant. As a vendor, your passkey (FIDO2) is usable when attestation is enforced if the following requirements are met.
Whats New Archive
Updated**Product capability:** Identity Security & Protection
- Users are **3x more successful signing-in with synced passkey than legacy authentication methods (95% vs 30%)**
Whats New Ignite 2025
Updated- [Account recovery cost savings estimator](../identity/authentication/how-to-account-recovery-cost-savings-estimator.md) (New)
| Windows Server 2019 | Microsoft Edge, [Chrome](#chrome-support) |
Whats New
Updated**Service category:** Authentications (Logins)
- You must have at least the [Microsoft Entra ID P1](../identity/conditional-access/overview.md#license-requirements) license.
Learn how authentication transfer connects users to apps across desktop and mobile devices, including supported apps, end-user experience, limitations, and troubleshooting.
Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled for text message and voice call users |
Whats New
Updated**Service category:** Identity Protection
Fido2 Hardware Vendor
UpdatedFeitian ePass FIDO Authenticator (CTAP2.1, CTAP2.0, U2F)|12755c32-8ad1-46eb-881c-e0b38d848b09|❌|✅|❌|❌
Whats New Archive
Updated**Service category:** Authentications (Login)
Whats New
Updated- clicktale
You can preview the improved enforcement behavior before the rollout begins:
Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, are enforced in user sign-in flows where the client application requests only these scopes. There is no change in behavior when an application requests any additional scope beyond those listed above.
Fido2 Compatibility
UpdatedFor more information about how to sign in with FIDO2 security keys on a Windows device, see [Enable FIDO2 security key sign-in to Windows 10 and 11 devices with Microsoft Entra ID](howto-authentication-passwordless-security-key-windows.md).
For more information about passkey authentication, see [Support for FIDO2 authentication with Microsoft Entra ID](~/identity/authentication/concept-fido2-compatibility.md).
Wrike Provisioning Tutorial
UpdatedMicrosoft Entra ID uses a concept called *assignments* to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users or groups that were assigned to an application in Microsoft Entra ID are synchronized.
author: MicrosoftGuyJFlo
What Is Entra
UpdatedThe Microsoft Entra product family spans identity, access, governance, and security. It covers secure end-to-end access for employees, customers, partners, workloads, and AI agents across any cloud environment.
A Microsoft Entra documentation page was updated: Add or deactivate custom security attribute definitions in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Manage access to custom security attributes in Microsoft Entra ID.
- ai-gen-title
A Microsoft Entra documentation page was updated: Troubleshoot custom security attributes in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: What are custom security attributes in Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: Customer intent: As an IT admin responsible for application integration, I want to learn how to integrate my company's applications with Microsoft Entra ID, so that I can improve security, reduce costs, increase productivity, and enable compliance through centralized Identity and Access Management..
A Microsoft Entra documentation page was updated: Bulk operations in Microsoft Entra ID (Preview).
A Microsoft Entra documentation page was updated: Customer intent: I am trying to find information on the terms and conditions for Microsoft Entra ID preview programs..
- To learn about access management, see [Azure role-based access control (RBAC)](/azure/role-based-access-control/overview) and [Conditional Access](~/identity/conditional-access/overview.md) to help manage your organization's application and resource access.
author: shlipsey
- [Microsoft Entra releases and announcements](./whats-new.md)
Each assistant response includes a feedback prompt for rating, comments, or suggestions. Use the "thumbs up" or "thumbs down" buttons to provide feedback on the responses. This feedback is important and is used to improve the accuracy of Self-Service Support.
Inaccessible Tenant
Updated- [Quickstart: Create a new tenant in Microsoft Entra ID](create-new-tenant.md)
- [Microsoft Entra Suite now generally available - Microsoft Community Hub](https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-suite-now-generally-available/ba-p/2520427)
author: shlipsey
A Microsoft Entra documentation page was updated: Add or update a user's profile information and settings in the Microsoft Entra admin center.
A Microsoft Entra documentation page was updated: Add your custom domain name to your tenant.
A Microsoft Entra documentation page was updated: Add your organization's privacy information to Microsoft Entra.
A Microsoft Entra documentation page was updated: Associate or add an Azure subscription to your Microsoft Entra tenant.
A Microsoft Entra documentation page was updated: Bulk operations service limitations.
author: shlipsey
author: shlipsey
author: shlipsey
author: shlipsey
A Microsoft Entra documentation page was updated: Customer data storage for Australian and New Zealand customers in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Customer data storage for Japan customers in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Find help and get support for Microsoft Entra.
A Microsoft Entra documentation page was updated: How to find your Microsoft Entra tenant ID.
Identify and resolve license assignment problems for a group in the Microsoft 365 Admin Portal
UpdatedA Microsoft Entra documentation page was updated: Identify and resolve license assignment problems for a group in the Microsoft 365 Admin Portal.
- ai-gen-title
A Microsoft Entra documentation page was updated: Identity data storage for Australian and New Zealand customers in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Learn about group types, membership types, and access management .
ai-usage: ai-assisted
Microsoft Entra licensing
UpdatedThis article documents licensing requirements for Microsoft Entra features.
A Microsoft Entra documentation page was updated: Microsoft Entra releases and announcements.
Reset a user's password
UpdatedA Microsoft Entra documentation page was updated: Reset a user's password.
A Microsoft Entra documentation page was updated: Restore or remove a recently deleted user.
A Microsoft Entra documentation page was updated: What are the default user permissions in Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: What is group-based licensing in Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: What's new at Microsoft Ignite 2025 - Microsoft Entra.
Whats New Archive
UpdatedIn January 2024, we added the following new applications in our App gallery with Federation support:
A Microsoft Entra documentation page was updated: Customer intent: As a cloud administrator, I want to understand how Microsoft Entra ID handles data residency, so that I can ensure compliance with data residency requirements and make informed decisions about storing and managing identity and access data in the cloud..
A Microsoft Entra documentation page was updated: Customer intent: As a new or existing customer, I want to learn more about the new name for Azure Active Directory (Azure AD) and understand the impact the name change may have on other products, new or existing license(s), what I need to do, and where I can learn more about Microsoft Entra products..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to compare Active Directory to Microsoft Entra ID, so that I can understand the differences and similarities between the on-premises and cloud identity and access management solutions..
Continuous Access Evaluation
Updated- has-adal-ref
Policy Block By Location
Updated- [Conditional Access templates](concept-conditional-access-policy-common.md)
Admins can select published authentication contexts in Conditional Access policies by going to **Assignments** > **Target resources** and selecting **Authentication context** from the **Select what this policy applies to** menu.
- [Conditional Access: Target resources](concept-conditional-access-cloud-apps.md)
[Conditional Access templates](concept-conditional-access-policy-common.md)
- [Conditional Access templates](concept-conditional-access-policy-common.md)
[Conditional Access templates](concept-conditional-access-policy-common.md)
[Conditional Access templates](concept-conditional-access-policy-common.md)
Policy Old Require Mfa Guest
Updated[Conditional Access templates](concept-conditional-access-policy-common.md)
Whats New
Updated**Type:** Plan for change
- [App protection policies overview](/mem/intune/apps/app-protection-policy)
Filter For Applications
Updated1. Under **Exclude**, select **Users and groups** and choose your organization's emergency access or break-glass accounts.
Microsoft Entra admin center
UpdatedOverview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.
Microsoft Entra admin center
UpdatedOverview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.
Authentication
Updated| [Authenticator Lite](/entra/identity/authentication/how-to-mfa-authenticator-lite) | No | MFA |
Mfa Howitworks
Updated* Passkey in Microsoft Authenticator
Whats New
Updated- clicktale
Overview of Microsoft single sign-on for Linux that enables Microsoft Entra ID integration and seamless authentication.
Native Authentication
Updated| **Custom claims provider** | :heavy_check_mark: | :heavy_check_mark: |
<sup>3</sup>Includes SMS and voice calls.
Provisioning
641. Select **Reveal** on your Recovery Key and store this entire key in a safe place. **IMPORTANT!** If you're ever locked out of your Microsoft accounts and need to disconnect SSO without access, you be required to relay the Recovery Key to Simple In/Out technical support.
The scenario outlined in this article assumes that you already have the following prerequisites:
1. In the **Tenant URL** field, enter your SAS Viya SSO Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to SAS Viya SSO. If the connection fails, ensure your SAS Viya SSO account has the required admin permissions and try again.
1. Sign in to [Preciate Admin Portal](https://preciate.com/web/admin/keys) and navigate to the **Integrations** page.
1. Sign in to [Plandisc](https://create.plandisc.com) and navigate to **Enterprise**
2. Select **Create API Key**.
The objective of this article is to demonstrate the steps to be performed in Dropbox for Business and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Dropbox for Business.
The scenario outlined in this article assumes that you already have the following prerequisites:
1. Select the **Provisioning** tab.
1. Log on to the Oracle Cloud Infrastructure Console admin portal. On the top left corner of the screen navigate to **Identity > Federation**.
1. log into your [directprint.io account](https://directprint.io/login/).
Druva Provisioning Tutorial
Updated1. Sign in to your [Druva Admin Console](https://console.druva.com). Navigate to **Druva** > **inSync**.
1. Select your instance of Pingboard, and then select the **Provisioning** tab.
1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
Documo Provisioning Tutorial
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Rfpio Provisioning Tutorial
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

1. Select the **Provisioning** tab.




1. Select **+ New configuration**.
Humbol Provisioning Tutorial
Updated1. Select **+ New configuration**.
Moqups Provisioning Tutorial
Updated1. In the **Tenant URL** field, enter your Moqups Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Moqups. If the connection fails, ensure your Moqups account has the required admin permissions and try again.
1. Select the pencil to edit the properties. Enable notification emails and provide an email to receive quarantine emails. Enable accidental deletions prevention. Select **Apply** to save the changes.
1. Select the pencil to edit the properties. Enable notification emails and provide an email to receive quarantine emails. Enable accidental deletions prevention. Select **Apply** to save the changes.
1. Log in to [Shopify Plus organization admin](https://shopify.plus). Navigate to **Users > Security**.
The Microsoft Entra Workday provisioning connector retrieves worker data using the Workday Integration System User (ISU) account via the `Get_Workers` SOAP API. However, the Workday ISU account always operates in the Pacific Time Zone (PT), causing delays in processing termination events for workers in time zones ahead of PT.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forms & Workflow.
1. Navigate to the **User Management > User Provisioning** section of your settings.
1. Log into LanSchool Air as Site Admin.
1. Sign in to https://app.kpifire.com with admin rights
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Kno2fy Provisioning Tutorial
Updated1. Select **+ New configuration**.
Account Discovery
Updated- Atlassian Cloud
After migrating your users and groups to Microsoft Entra ID, you may be ready to decommission your on-premises Active Directory and uninstall sync tools. After turning off directory synchronization, you can manage these objects directly in Microsoft Entra ID.
1. Sign in to your [Leapsome Admin Console](https://www.Leapsome.com/app/#/login). Navigate to **Settings > Admin Settings**.
Jostle Provisioning Tutorial
UpdatedBefore you begin, you’ll need to create an **Automation user** in your Jostle intranet. This is the account you’ll use to configure with Azure. Automation users can be created in Admin **Settings > User accounts and data > Manage Automation users**.
```python
1. Sign in to [Keepabl Admin Portal](https://app.keepabl.com) and then navigate to **Account Settings > Your Organization**, where you’ll see the **Single Sign-On (SSO)** section.
[Append](#append) [AppRoleAssignmentsComplex](#approleassignmentscomplex) [BitAnd](#bitand) [CBool](#cbool) [CDate](#cdate) [Coalesce](#coalesce) [ConvertToBase64](#converttobase64) [ConvertToUTF8Hex](#converttoutf8hex) [Count](#count) [CStr](#cstr) [DateAdd](#dateadd) [DateDiff](#datediff) [DateFromNum](#datefromnum) [DefaultDomain](#defaultdomain) [FormatDateTime](#formatdatetime) [Guid](#guid) [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty) [IIF](#iif) [InStr](#instr) [IsNull](#isnull) [IsNullOrEmpty](#isnullorempty) [IsPresent](#ispresent) [IsString](#isstring) [Item](#item) [Join](#join) [Left](#left) [Len](#len) [Mid](#mid) [NormalizeDiacritics](#normalizediacritics) [Not](#not) [Now](#now) [NumFromDate](#numfromdate) [PCase](#pcase) [RandomString](#randomstring) [Redact](#redact) [RemoveDuplicates](#removeduplicates) [Replace](#replace) [SelectUniqueValue](#selectuniquevalue) [SingleAppRoleAssignment](#singleapproleassignment) [Split](#split) [StripSpaces](#stripspaces) [Switch](#switch) [ToLower](#tolower) [ToUpper](#toupper) [Word](#word)
Foodee Provisioning Tutorial
Updated1. Under **Enterprise portal**, select **Single Sign On**.
1. In the **Tenant URL** field, input your Cisco User Management for Secure Access Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Cisco User Management for Secure Access. If the connection fails, ensure your Cisco User Management for Secure Access account has the required admin permissions and try again.
1. Under **Mappings**, select the object (user or group) for which you'd like to add a custom attribute.
1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
Figma Provisioning Tutorial
Updated1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
Flock Provisioning Tutorial
Updated1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Gong Provisioning Tutorial
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Chaos Provisioning Tutorial
Updated1. In the **Tenant URL** field, input your Chaos Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Chaos. If the connection fails, ensure your Chaos account has the required admin permissions and try again.
1. In the **Tenant URL** field, input your Chatwork Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Chatwork. If the connection fails, ensure your Chatwork account has the required admin permissions and try again.
1. In the **Tenant URL** field, input your CheckProof Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to CheckProof. If the connection fails, ensure your CheckProof account has the required admin permissions and try again.
Cinode Provisioning Tutorial
Updated1. In the **Tenant URL** field, input your Cinode Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Cinode. If the connection fails, ensure your Cinode account has the required admin permissions and try again.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Velpic.
|name.givenName|String|
Unifi Provisioning Tutorial
Updated
Vonage Provisioning Tutorial
Updated1. Log in to [Vonage admin portal](http://admin.vonage.com) with an admin user.
Gtmhub Provisioning Tutorial
UpdatedThis article describes the steps you need to perform in both Gtmhub and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Gtmhub](https://www.gtmhub.com/) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
H5mag Provisioning Tutorial
Updated1. Select the **Save** button to store the generated token.
* GitHub Enterprise Server supports [Automated user provisioning](./github-enterprise-server-provisioning-tutorial.md).
Tutorial Group Provisioning
UpdatedDisplay name | Distinguished name
Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.
Authentication
291. Review the user attributes that are synchronized from Microsoft Entra ID to Netskope User Authentication in the **Attribute-Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Netskope User Authentication for update operations. If you choose to change the [matching target attribute](~/identity/app-provisioning/customize-application-attributes.md), you need to ensure that the Netskope User Authentication API supports filtering users based on that attribute. Select the **Save** button to commit any changes.
Learn the importance of migrating your users to the Microsoft authenticator app in Microsoft Entra ID.
Learn about the recommendation to migrate application authentication from AD FS to Microsoft Entra ID
Learn about the Microsoft Entra recommendation to migrate to Microsoft Entra multifactor authentication from MFA server
Learn about the recommendation to minimize multifactor authentication prompts from known devices in Microsoft Entra ID.
In this article, you add an admin system in SAP Cloud Identity Services and then configure Microsoft Entra.
V2 Protocols Oidc
Updated| `redirect_uri` | Recommended | The redirect URI of your app, where authentication responses can be sent and received by your app. It must exactly match one of the redirect URIs you registered in the portal, except that it must be URL-encoded. If not present, the endpoint picks one registered `redirect_uri` at random to send the user back to. |
Security Emergency Access
Updated1. [Configure your emergency access accounts](#configuration-requirements) to use passwordless authentication.
To simplify and secure sign-in to applications and services, Microsoft Entra ID provides SMS-based authentication. This method lets users such as frontline workers sign in using only a registered phone number and a one-time passcode (OTP) sent via SMS, without needing a username or password.
- [Enable passkeys (FIDO2) for your organization](how-to-authentication-passkeys-fido2.md)
Microsoft Entra will continue supporting Passkeys (FIDO2) in Enabled and Microsoft-managed states for Registration Campaigns, rolling out worldwide from mid-May to late June 2026. Eligible tenants will see automatic updates to campaign settings and passkey registration nudges after MFA, with no immediate action required.
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
You can continue to sign in to your cloud services by using a synchronized password that is expired in your on-premises environment. Your cloud password is updated the next time you change the password in the on-premises environment.
Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target **All resources** and include one or more **resource exclusions**. This change ensures that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access.
Microsoft has decided not to proceed with adding Passkeys (FIDO2) as an authentication method in Microsoft Registration Campaigns starting April 2026. Previously planned changes, including automatic updates and nudges for MFA-capable users, will not be implemented at this time. Updates are available in MC1279092.
Kerberos
Updated- Microsoft Entra Kerberos doesn't issue partial TGTs to identities that aren't synced to Microsoft Entra ID.
Optional Claims Reference
Updated| `acrs` | Auth Context IDs | JWT | Microsoft Entra ID | Indicates the Auth Context IDs of the operations that the bearer is eligible to perform. Auth Context IDs can be used to trigger a demand for step-up authentication from within your application and services. Often used along with the `xms_cc` claim. |
1. Confirm your settings and set **Enable policy** to **Enabled**.
:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png" alt-text="Screenshot that shows how to delete a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png":::
The prompt for authentication usually occurs when a device is offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired.
Block Password Addition
Updated1. Go to the admin center and select Org settings.
Managed Policies
Updated[Custom controls don't satisfy multifactor authentication claim requirements](controls.md#creating-custom-controls). If your organization uses custom controls you should [migrate to external authentication methods](/entra/identity/authentication/how-to-authentication-external-method-manage), the replacement of custom controls. Your external authentication provider must support external authentication methods and provide the necessary configuration guidance for integration.
This feature currently supports the following Windows Server distributions:
Howto Arc Sign In Windows
UpdatedThis feature currently supports the following Windows Server distributions:
Known Issues
Updated- Provisioning passwords isn't supported.
Learn how to add social sign-in with Apple, Facebook and Google identity providers to your React SPA using native authentication JavaScript SDK.
Learn how to add social sign-in with Apple, Facebook and Google identity providers to your Angular SPA using native authentication JavaScript SDK.
Microsoft Entra ID audit logs for Authentication Methods Policy updates will now show only changed properties with old and new values, improving readability. Rollout begins April 2026 worldwide. No changes to event names or policy enforcement. Organizations using automated log processing should review related logic.
General
25Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
AI Administrator
UpdatedAI Administrator
Entra Backup Administrator
UpdatedEntra Backup Administrator
Entra Backup Reader
UpdatedEntra Backup Reader
author: FaithOmbongi
Describes the Microsoft Entra built-in roles and permissions.
Sso Linux
UpdatedMicrosoft single sign-on for Linux is supported on the following operating systems (physical or Hyper-V machines with x86/64 CPUs):
Whats New Linux
Updated- Ensure that all browser calls are done in the same thread
Connect Install Roadmap
Updated* Make sure that you [satisfy the requirements](how-to-connect-health-agent-install.md#requirements) for Microsoft Entra Connect Health.
- User Administrator
Learn how to configure single sign-on between Microsoft Entra ID and STACKIT Cloud.
- onPremisesDistinguishedName
author: MicrosoftGuyJFlo
- [Attribute Definition Administrator](/entra/identity/role-based-access-control/permissions-reference#attribute-definition-administrator)
You receive the notification email from [email protected]. To avoid the email going to your spam location, add this email to your contacts.
manager: dougeby
manager: dougeby
A Microsoft Entra documentation page was updated: Improved Enforcement Resource Exclusions Faq.
Policy Block Example
Updated> [!NOTE]
Learn how to assign Azure roles to the local administrators group of a Windows device.
Users Revoke Access
UpdatedHow to revoke all access for a user in Microsoft Entra ID
Connect Sync Staging Server
UpdatedStaging mode can be used for several scenarios, including:
Groups Settings V2 Cmdlets
UpdatedThis page provides PowerShell examples to help you manage your groups in Microsoft Entra ID
Discusses new feature releases of Microsoft single sign-on for Linux
Standards
17|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department|String||
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
:::image type="content" source="./media/lucidchart-provisioning-tutorial/scim.png" alt-text="Screenshot of the Lucidchart admin console. Within a large S C I M button, the text S C I M is highlighted, and an enabled banner is visible." border="false":::
author: garrodonnell
8. Leave the portal and open the provisioning agent installer, agree to the terms of service, and select **Install**.
> Global Relay Identity Sync provisioning connector utilizes a SCIM authorization method that's no longer supported due to security concerns. Efforts are underway with Global Relay to switch to a more secure authorization method.


A Microsoft Entra documentation page was updated: Add a Microsoft Entra ID tenant as an OpenID Connect identity provider (Preview).
Entra Id Scim Api Reference
Updatedai-usage: ai-assisted
ai-usage: ai-assisted
Entra Id Scim Api Reference
Updated| Endpoint | Supported HTTP methods | Description |
Disable Scim Api
Updated1. Confirm the action when prompted. After the feature is turned off, all SCIM API calls to the tenant return an error and billing stops.
author: jenniferf-skc
| SCIM Attribute | Microsoft Entra ID Attribute | Notes / Restrictions |
Enable Scim Api
Updatedai-usage: ai-assisted
Troubleshoot Scim Api Errors
Updatedauthor: jenniferf-skc
Conditional Access
6Frequently asked questions about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions.
Learn about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions, including how to assess impact and retain legacy behavior.
Frequently asked questions about the improved Conditional Access enforcement behavior for policies that target All resources with resource exclusions.
The **Capabilities** category includes important settings that you should review.
Learn how custom controls in Microsoft Entra Conditional Access work.
Plan Conditional Access
UpdatedCreating a policy for each app isn't efficient and makes managing policies difficult. Conditional Access has a limit of 240 policies per tenant. This 240-policy limit includes Conditional Access policies in any state, including report-only mode, on, or off.
Security
5Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Group Policy
UpdatedThe backup location and network share are configured with appropriate Active Directory security groups to ensure only authorized administrators can access the backup data. The ACL model aligns with the permissions used in Group Policy Management Console (GPMC), maintaining consistency with existing GPO management practices.
There's a known issue where there's a pre-existing, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
A Microsoft Entra documentation page was updated: Policy All Users Copilot Ai Security.
Entra Agents
UpdatedThe following agents are currently available for Microsoft Entra. Due to the fast pace at which these agents are released and updated, each agent might have features at various stages of availability. Preview features are added frequently.
Branding
4Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Now that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.yml).
CSS template reference guide
UpdatedA Microsoft Entra documentation page was updated: CSS template reference guide.
A Microsoft Entra documentation page was updated: Customer intent: As a Microsoft Entra administrator, I want to customize the sign-in experience for my organization's users so that I can provide a consistent look and feel across all sign-ins..
Microsoft identity platform
4Learn about the Microsoft Entra recommendation to migrate from Azure Active Directory Graph APIs to Microsoft Graph APIs.
SMS-based authentication is available to Microsoft apps integrated with the Microsoft identity platform (Microsoft Entra ID). This article lists the web and mobile apps that support SMS-based authentication.
Mfa Authenticator Lite
Updated- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
Apple Sso Plugin
UpdatedIf your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.
Monitoring
3Learn why you should turn off per user MFA in Microsoft Entra ID with Microsoft Entra recommendations
To test your policy, try to sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a test account. You should see a dialog that requires you to accept your terms of use.
Sla Performance
Updated| --- | --- | --- | --- | --- | --- | --- |
Architecture
2Resilience In Credentials
Updated|Certificate Based Authentication (CBA)|In most cases (depending on configuration) CBA will require a revocation check. This adds an external dependency on the CRL distribution point (CDP) |[Understanding the certificate revocation process](~/identity/authentication/concept-certificate-based-authentication-certificate-revocation-list.md#enforce-crl-validation-for-cas)|
Secure Generative Ai
UpdatedEnforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements where identities that meet certain criteria can only access resources if they meet specific requirements such as MFA or device compliance status.
Developer
2V2 Howto App Gallery Listing
UpdatedHere's the quick checklist for you before you submit the application request to list your application in Microsoft Entra App Gallery.
- App Studio for Microsoft Teams
Governance
2Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.
Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.
Troubleshooting
1If you still can't resolve your problem, contact ServiceNow support, and ask them to turn on SOAP debugging to help troubleshoot.
Microsoft Entra Agent ID
14 updatesArchitecture
4Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
Agent Id Design Patterns
UpdatedThis article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.
1. **How many blueprints** your system requires.
General
4Create Blueprint
Updated$response = Invoke-MgGraphRequest `
Agent Id Ai Guided Setup
UpdatedThe blueprint principal must be created as a separate step after the blueprint. Run:
The Manage Agents feature in Microsoft Entra lets you view and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-are-agent-identities.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
Agent Id Ai Guided Setup
Updated1. **Validate prerequisites**: Confirms Frontier is enabled, checks Microsoft Entra roles, validates that PowerShell 7+ and the Microsoft Graph beta module are installed.
Fundamentals
3Whats New
UpdatedMicrosoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.
Discover the role of agent identities in AI authentication. Understand their unique identifiers, token usage, and how they enable secure access to systems.
Security For Ai Overview
Updated- **External accessibility**: Many AI agents interact with external users, third-party systems, or the public internet. This exposure creates potential pathways for adversaries to compromise agents and access organizational systems.
Authentication
2Learn about agent service principals in Microsoft Entra and how they differ from traditional service principals in authentication, permissions, and lifecycle management.
Understand agent identity blueprints, how agents are defined, and how authentication works within the Agent ID platform.
Microsoft identity platform
1Starting May 1, 2026, Microsoft is retiring the Agent registry and Agent collections blades in the Microsoft Entra admin center. Agent 365 will be the unified platform for agent management, with a new API replacing the existing one. No immediate admin action is required.
Microsoft Entra ID Protection
3 updatesFundamentals
2Identity Protection Risks
Updated| Sign-in risk detection | Detection type | Type | riskEventType |
Conditional Access Grant
UpdatedWhen user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation control](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control).
Troubleshooting
1Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Microsoft Entra ID Governance
55 updatesGovernance
43| Access Reviews | [Access Review – inactive users](../identity/users/clean-up-stale-guest-accounts.md#monitor-guest-accounts-at-scale-with-inactive-guest-insights) | Bill when guest user is included in review.<br><br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/accessReviews/definitions where inactive guest reviews are included in the policy for a group resource. | Decision item summary. |
If you're starting out using Privileged Identity Management (PIM) in Microsoft Entra ID to manage role assignments in your organization, you can use the **Discovery and insights (preview)** page to get started. This feature shows you who is assigned to privileged roles in your organization and how to use PIM to quickly change permanent role assignments into just-in-time assignments. You can view or make changes to your permanent privileged role assignments in **Discovery and insights (preview)**. It's an analysis tool and an action tool.
Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Alerts page.
Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Privileged Identity Management dashboard. Select the alert to see a report that lists the users or roles that triggered the alert.
The need for access to privileged Azure resource and Microsoft Entra roles by your users changes over time. To reduce the risk associated with stale role assignments, you should regularly review access. You can use Microsoft Entra Privileged Identity Management (PIM) to create access reviews for privileged access to Azure resource and Microsoft Entra roles. You can also configure recurring access reviews that occur automatically. This article describes how to create one or more access reviews.
The following table provides guidance on using the new PowerShell cmdlets in the newer Azure PowerShell module.
**Privileged Identity Management (PIM)** provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune.
You can use Privileged Identity Management (PIM) in Microsoft Entra ID to have just-in-time membership in the group or just-in-time ownership of the group.
With Privileged Identity Management (PIM) and Microsoft Entra ID, you can configure activation of group membership and ownership to require approval. You can also choose users or groups from your Microsoft Entra organization as delegated approvers.
Microsoft Entra Privileged Identity Management (PIM) enables you to configure roles so that they require approval for activation, and choose users or groups from your Microsoft Entra organization as delegated approvers. Select two or more approvers for each role to reduce workload for the Privileged Role Administrator. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must resubmit a new request. The 24-hour approval time window isn't configurable.
Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure roles to require approval for activation, and choose one or multiple users or groups as delegated approvers. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must re-submit a new request. The 24-hour approval time window isn't configurable.
With Microsoft Entra Privileged Identity Management (PIM), you can manage the built-in Azure resource roles, and custom roles, including (but not limited to):
In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.
With Microsoft Entra ID, a Global Administrator can make **permanent** Microsoft Entra admin role assignments. These role assignments can be created using the [Microsoft Entra admin center](~/identity/role-based-access-control/permissions-reference.md) or using [PowerShell commands](/powershell/module/azuread/#directory_roles).
When working with your organization's groups in Privileged Identity Management (PIM), you can view activity, activations, and audit history for Microsoft Entra group membership or ownership changes.
In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group. Use groups to provide access to Microsoft Entra roles, Azure roles, and various other scenarios. To manage a Microsoft Entra group in PIM, you must bring it under management in PIM.
Privileged Role Administrators can review privileged access once an [access review starts](./pim-create-roles-and-resource-roles-review.md). Privileged Identity Management (PIM) in Microsoft Entra ID automatically sends an email that prompts users to review their access. If a user doesn't receive an email, you can send them the instructions for [how to perform an access review](./pim-perform-roles-and-resource-roles-review.md).
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
You can use Privileged Identity Management (PIM) in Microsoft Entra ID, to improve the protection of your Azure resources. This helps:
Email notifications in PIM
UpdatedPrivileged Identity Management (PIM) lets you know when important events occur in your Microsoft Entra organization, such as when a role is assigned or activated. Privileged Identity Management keeps you informed by sending you and other participants email notifications. These emails might also include links to relevant tasks, such as activating or renewing a role. This article describes what these emails look like, when they are sent, and who receives them.
Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for Azure resources. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for roles in Microsoft Entra ID. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to Microsoft Entra administrators to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Privileged Identity Management (PIM) in Microsoft Entra ID provides controls to manage the access and assignment lifecycle for group membership and ownership. Administrators can assign start and end date-time properties for group membership and ownership. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Privileged Identity Management (PIM) simplifies how enterprises manage privileged access to resources in Microsoft Entra ID, and other Microsoft online services like Microsoft 365 or Microsoft Intune. Follow the steps in this article to perform reviews of access to roles.
Privileged Identity Management (PIM), part of Microsoft Entra, includes three providers:
You can manage just-in-time assignments to all [Microsoft Entra roles](~/identity/role-based-access-control/permissions-reference.md) and all [Azure roles](/azure/role-based-access-control/built-in-roles) using Privileged Identity Management (PIM) in Microsoft Entra ID. Azure roles include built-in and custom roles attached to your management groups, subscriptions, resource groups, and resources. However, there are a few roles that you can't manage. This article describes the roles you can't manage in Privileged Identity Management.
Use Privileged Identity Management (PIM) to manage, control, and monitor access within your Microsoft Entra organization. With PIM you can provide as-needed and just-in-time access to Azure resources, Microsoft Entra resources, and other Microsoft online services like Microsoft 365 or Microsoft Intune.
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
1. If your scenario requires the ability to override a separation of duties check, then you can also [set up additional access packages for those override scenarios](entitlement-management-access-package-incompatible.md#configuring-multiple-access-packages-for-override-scenarios).
Microsoft Entra ID Governance introduces Account Discovery to identify local and orphaned application accounts outside Entra ID, improving access visibility and control. Public preview starts mid-April 2026; general availability begins August 2026. The feature is off by default and requires admin opt-in, with no user impact unless acted upon.
If you defined a default [governance policy template](governance-policy-templates.md), a new governance relationship forms between the home (governing) tenant and the newly created add-on (governed) tenant, using the default policy template.
Starting January 30, 2026, Microsoft Entra ID Governance requires tenants to link an Azure subscription to use guest governance features. Without this, creating or updating guest-scoped policies will be blocked. Existing policies run, but new actions need subscription-linked billing under the Monthly Active User model.
This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).
What Are Lifecycle Workflows
Updated- Manage user lifecycle at scale. As your organization grows, the need for other resources to manage user lifecycle decreases.
Entitlement Management Roles
Updated> [!NOTE]
- Tailspin creates a second access review for a security group with 300 guest users with the user-to-group affiliation feature enabled.
Access Review Agent
RemovedA Microsoft Entra documentation page was updated: Access Review Agent.
A Microsoft Entra documentation page was updated: Access Review Agent Logs Metrics.
Create Access Review
Updated- **Reminders**: Select this checkbox to have Microsoft Entra ID send reminders of access reviews in progress to all reviewers. Reviewers receive the reminders halfway through the review, no matter if they've finished their review or not.
Deploy Access Reviews
Updated| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |
- **approve** the review if the user has signed-in at least once during the last 30 days.
Fundamentals
11You can use the Microsoft Entra Privileged Identity Management (PIM) audit history to see the role assignment changes and activations done through PIM. Data is available for the past 30 days. If you want to retain audit data for longer than the default retention period, you can use Azure Monitor to route it to an Azure storage account. For more information, see [Archive Microsoft Entra logs to an Azure storage account](~/identity/monitoring-health/howto-archive-logs-to-storage-account.md). To see full audit history of Microsoft Entra ID activity including administrator, end user, and synchronization activity, you can use the [Microsoft Entra security and activity reports](~/identity/monitoring-health/overview-monitoring-health.md).
Microsoft Entra ID allows you to grant users just-in-time membership and ownership of groups through Privileged Identity Management (PIM) for Groups. Groups can be used to control access to a variety of scenarios, including Microsoft Entra roles, Azure roles, Azure SQL, Azure Key Vault, Intune, other application roles, and third-party applications.
You can use a resource dashboard to perform an access review in Privileged Identity Management (PIM). The Admin View dashboard in Microsoft Entra ID, part of Microsoft Entra, has three primary components:
Privileged Identity Management (PIM) is a service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune. The following video explains important PIM concepts and features.
Now that you have provided the connectivity details and matching attribute as part of your provisioning configuration, Microsoft Entra can discover the existing users in your application. Click on the [discover identities](~/identity/app-provisioning/how-to-account-discovery.md) button in the provisioning overview page. Once the report is generated, you will have a view of all the users in your application, which users in the application match with a Microsoft Entra ID user, which users are already assigned to the enterprise application in Microsoft Entra ID, and which users in the application are not matched with a Microsoft Entra ID user).
Microsoft Entra introduces cross-tenant security group synchronization to simplify collaboration and centralize group management across tenants. Public preview starts late January 2026; general availability by end of May 2026. Admins can enable sync by updating attribute mappings and access policies. No compliance issues identified.
Learn how to use the license usage insights page in the Microsoft Entra admin center to monitor license usage and entitlements.
| access package | A bundle of resources that a team or project needs and is governed with policies. An access package is always contained in a catalog. You would create a new access package for a scenario in which identities need to request access for themselves. |
Lifecycle Workflow Templates
UpdatedConceptual article discussing workflow templates and categories with Lifecycle Workflows.
Identity Governance Overview
UpdatedOrganizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.
Access Reviews Overview
Updated>[!NOTE]
Troubleshooting
1If you're experiencing issues with Privileged Identity Management (PIM) in Microsoft Entra ID, the information included in this article can help you resolve these issues.
Microsoft Entra External ID
31 updatesGeneral
10Shows how an admin can add sponsors to guest users in Microsoft Entra B2B collaboration.
Learn about customizing the language experience in your user flows in Microsoft Entra External ID.
Learn how to give cloud B2B users access to on-premises apps with Microsoft Entra B2B collaboration.
Current limitations for Microsoft Entra B2B collaboration
> [!NOTE]
Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.
Add custom attributes
UpdatedLearn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.
Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.
|[Grit](https://www.gritiam.com/migration.html) |"Grit Software has deep expertise in consumer identity and access management, with a strong track record of helping Fortune 500 and mid-market companies execute complex transformation projects successfully and on time. For Azure AD B2C to Microsoft Entra External ID migrations, Grit's AI-powered migration service uses advanced coding agents to deliver accurate migrations in days, while ensuring customer data isn't sent to the underlying AI models." | [email protected] |
Learn about partners who can help with deployment and integration of customer identity and access management (CIAM) scenarios using Microsoft Entra External ID.
Authentication
7Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
- Authentication context or step-up authentication.
To protect customers, some regions require you to enable the country codes to receive SMS telephony verification for Microsoft Entra External ID external tenants.
Add MSA for customer sign-in
UpdatedLearn how to add MSA as an identity provider for your external tenant.
In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.
Learn how to add Apple as an identity provider for your external tenant.
ai-usage: ai-assisted
Fundamentals
5Compare solutions for using Microsoft Entra External ID to work with people outside your organization, including B2B collaboration and Azure AD B2C.
Use Microsoft Entra API connectors to customize and extend your self-service sign-up user flows by using web APIs.
Customers Ciam
UpdatedYou can create a simple sign-up and sign-in experience for your customers by adding a user flow to your application. The user flow defines the series of sign-up steps customers follow and the sign-in methods they can use (such as email and password, one-time passcodes, social accounts from [Google](how-to-google-federation-customers.md), [Facebook](how-to-facebook-federation-customers.md), or [Apple](how-to-apple-federation-customers.md), [Microsoft Entra ID](how-to-entra-id-federation-customers.md) federation, as well as [custom OIDC](how-to-custom-oidc-federation-customers.md) identity providers). You can also collect information from customers during sign-up by selecting from a series of user built-in attributes or adding your own custom attributes.
Planning Your Solution
Updated- **Requirements for token claims**. If your application requires specific user attributes, you can include them in the token sent to your application.
Supported Features Customers
UpdatedCompare features and capabilities of a workforce versus an external tenant configuration. Determine which tenant type applies to your external identities scenario.
Standards
3To federate users to your identity provider, first prepare your identity provider to accept federation requests from your external tenant. To do this preparation, add your redirect URIs and register your identity provider to be recognized.
Set up AD FS federation
UpdatedLearn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Microsoft identity platform
2author: garrodonnell
Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.
Security
2Give locally managed external partners access to both local and cloud resources using the same credentials with Microsoft Entra B2B collaboration.
If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can move to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials. Use either PowerShell or the Microsoft Graph invitation API.
Developer
1Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.
Provisioning
1|externalId|String||✓|
Microsoft Entra Internet Access
8 updatesGeneral
4Explicit Forward Proxy (EFP) allows you to use Secure Web and AI Gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access (GSA) client. EFP works with any browser that supports proxy automatic configuration (PAC).
| Aspect | FQDN filtering | URL filtering |
- **100 = highest priority**: Evaluated first.
> 1. Client sees a certificate signed by your enterprise CA.
Security
3*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.
Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.
Learn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Fundamentals
11. Download the GSA client for Windows 11 from one of the following links. You can also use the [sample PowerShell script](scripts/powershell-windows-client-install-proof-of-concept.md).
Microsoft Entra Verified ID
2 updatesAuthentication
1- [Face Check with Microsoft Entra Verified ID pricing](~/verified-id/verified-id-pricing.md)
Fundamentals
1The issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.
Microsoft Entra Workload ID
3 updatesFundamentals
2Configurable Token Lifetimes
Updated- **Managed identities**: Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.
Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md).
Conditional Access
1Plan Conditional Access
Updated- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?
Microsoft Entra Global Secure Access
24 updatesFundamentals
9Explicit Forward Proxy (EFP) is one of the traffic acquisition mechanisms that's useful in scenarios where installation of the Global Secure Access (GSA) client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from:
A PAC file is a mechanism used to automatically determine which proxy server a web browser or application should use for a given request. PAC files are an integral part of Explicit Forward Proxy configuration, enabling flexible and dynamic traffic steering decisions. In the context of Global Secure Access, PAC files are similar to the traffic forwarding policies of the GSA client.
Install Android Client
Updated- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).
External User Access
Updated**Q: Is this feature supported from a windows Entra registered device(BYOD)?**
Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Remote Network Connectivity
UpdatedLearn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.
Licensing Guest Users
UpdatedGlobal Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).
Licensing Guest Users
UpdatedGlobal Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).
author: jenniferf-skc
General
7Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, and TLS certificate creation.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Current Known Limitations
Updatedauthor: HULKsmashGithub
author: HULKsmashGithub
Use Global Secure Access to configure Azure and Microsoft Entra resources to create a virtual wide area network to connect to your resources in Azure.
Licensing Guest Users
Updated> [!NOTE]
Network Content Filtering
Updated:::image type="content" source="media/how-to-network-content-filtering/file-rule-content-types.png" alt-text="Screenshot of the Add Content Rule page showing the Matching conditions section with Activities set to Upload, and the Content types dropdown expanded with PDF selected." lightbox="media/how-to-network-content-filtering/file-rule-content-types.png":::
Security
3Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Developer
2author: idmdev
Use Application discovery to detect the applications accessed by users and create separate private applications.
Conditional Access
1> The Explicit Forward Proxy feature is currently in PREVIEW.
Microsoft identity platform
1Assign remote networks to traffic forwarding profiles through the Microsoft Entra admin center or Microsoft Graph API to route branch office traffic through Global Secure Access.
Monitoring
1Learn how to monitor and analyze Model Context Protocol (MCP) traffic between AI agents and remote MCP servers using the Global Secure Access Generative AI Insights page.
Security Copilot + Entra
1 updateTroubleshooting
11. Browse to **Entra ID** > **Conditional Access**.
