Workload Identities Federated Credential Mutable Subjects
"audiences": ["api://AzureADTokenExchange"]
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Security.
"audiences": ["api://AzureADTokenExchange"]
Learn how to migrate a Microsoft Entra federated identity credential for GitHub Actions from a mutable subject to GitHub's immutable subject format.
Learn how mutable OIDC subject claims expose Microsoft Entra federated identity credentials to subject recycling, and how immutable claims reduce the risk.
> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
We are announcing the ability to manage users through Microsoft Entra security groups in Dynamics 365 Contact Center. This feature will reach general availability on July 24, 2026.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time.
Microsoft Entra ID Protection provides unified risk signals that aggregate correlated risk signals from Microsoft Entra ID Protection, Microsoft Defender, and other Microsoft security products. Instead of evaluating alerts in isolation, this capability correlates identity-related signals across products and evaluates them together within the same time window to calculate a compounded user risk score.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
- [Microsoft Entra Security Operations Guide](https://aka.ms/AzureADSecOps)
Security operations guide for Microsoft Entra Global Secure Access covering detection patterns and Sentinel analytics for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.
>The licensing options on this page aren't comprehensive. You can get detailed information about the various options at the [Microsoft Entra pricing page](https://www.microsoft.com/security/business/microsoft-entra-pricing) and at the [Compare Microsoft 365 Enterprise plans and pricing page](https://www.microsoft.com/microsoft-365/enterprise/microsoft365-plans-and-pricing).
Starting soon, ID Protection for agents will require a [Microsoft Agent 365 license](https://www.microsoft.com/microsoft-agent-365#plans-and-pricing) to extend protection to agents through [Microsoft Entra Agent ID](../agent-id/what-is-microsoft-entra-agent-id.md#how-to-get-started).
- The Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.
Starting soon, ID Protection for agents will require a [Microsoft Agent 365 license](https://www.microsoft.com/microsoft-agent-365#plans-and-pricing) to extend protection to agents through [Microsoft Entra Agent ID](../agent-id/what-is-microsoft-entra-agent-id.md#how-to-get-started).
**Has filter** indicates whether the policy has app filters that use custom security attributes.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Understand consent request evaluation and tenant-wide admin consent in Microsoft Entra ID. Essential guidance for administrators managing application permissions and security.
Learn about the best practices and general guidance for protecting frontline workers in an organization
Include file with a common configuration in web apps and web APIs calling downstream web APIs (ASP.NET Core and ASP.NET OWIN).
A Microsoft Entra documentation page was updated: Configure Acronis Cyber Protect Cloud for Single Sign-On with Microsoft Entra ID.
Learn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Learn how to build a protected web API and configure your application's code.
Learn how to disable and enable risk-based step-up consent to reduce user exposure to malicious apps that make illicit consent requests.
Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Learn how to protect your organization with a custom Data Loss Prevention (DLP) profile powered by Netskope.
In this article, you learn how to integrate IMPAC Risk Manager with Microsoft Entra ID. When you integrate IMPAC Risk Manager with Microsoft Entra ID, you can:
In this article, you learn how to integrate IriusRisk with Microsoft Entra ID. When you integrate IriusRisk with Microsoft Entra ID, you can:
In this article, you learn how to integrate KnowBe4 Security Awareness Training with Microsoft Entra ID. When you integrate KnowBe4 Security Awareness Training with Microsoft Entra ID, you can:
In this article, you learn how to integrate Menlo Security with Microsoft Entra ID. When you integrate Menlo Security with Microsoft Entra ID, you can:
In this article, you learn how to integrate Riskware with Microsoft Entra ID. When you integrate Riskware with Microsoft Entra ID, you can:
Learn how to use Security Store in Microsoft Entra to discover, purchase, and deploy AI agents and security solutions for identity and access management.
Enable HSC mode on your Azure AD B2C tenant to adopt Microsoft Entra External ID endpoints while keeping existing users and credentials in place.
Enable single sign-on for an enterprise application that has a relying party security token service in Microsoft Entra ID.
Learn how you can adopt Microsoft's Security Service Edge (SSE) solution via Microsoft services partners.
Learn about Microsoft Entra Workload ID Flexible federated identity credentials and its capabilities.
How to increase app security by configuring property modification locks for sensitive properties of the application.
Learn how to enforce TLS 1.2 for a Microsoft Entra Domain Services managed domain.
Increase app security and resilience by adding support for Continuous Access Evaluation, enabling long-lived access tokens that can be revoked based on critical events and policy evaluation.
Learn how the principle of least privilege can help increase the security of an application and its data.
Integrate F5 BIG-IP with Microsoft Entra ID for secure hybrid access (SHA) to improve access and security.
Strengthen your organization's security posture by integrating Global Secure Access with Microsoft Sentinel using preconfigured workbooks and analytics rules.
Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate potential risky applications.
Learn about Microsoft Entra agents, AI-powered automation tools that enhance identity and access management operations.
Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Learn ways of mitigating against application-based consent phishing attacks using Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Protecting Tokens Microsoft Entra Id.
In this quickstart, you learn how a .NET sample app can use the client credentials flow to get a token and call Microsoft Graph.
Find partner solutions to integrate your legacy on-premises, public cloud, or private cloud applications with Microsoft Entra ID.
Learn about the best practices and general guidance for security related application properties in Microsoft Entra ID.
Learn how to set up a Flexible Federated identity credential in the Azure portal or Microsoft Graph Explorer.
Transition to Microsoft Entra External ID for CIAM: Learn how to migrate your legacy customer identity solutions to enhance security, compliance, and scalability.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
Learn how to configure groups and user roles in your external tenant, so you can receive them as claims in a security token for your Node.js application
Verify that the API is only called by applications on behalf of users who have the right scopes and by daemon apps that have the right application roles.
Important considerations and restrictions for creating a federated identity credential on an app.
Learn how to configure single sign-on between Microsoft Entra ID and Acronis Cyber Protect Cloud.
Learn how to configure single sign-on between Microsoft Entra ID and Banyan Security Zero Trust Remote Access Platform.
Learn how to configure single sign-on between Microsoft Entra ID and Cequence Application Security Platform.
Learn how to configure single sign-on between Microsoft Entra ID and Contrast Security.
Learn how to configure single sign-on between Microsoft Entra ID and Coupa Risk Assess.
Learn how to configure single sign-on between Microsoft Entra ID and Coverity Static Application Security Testing.
Learn how to configure single sign-on between Microsoft Entra ID and CylancePROTECT.
Learn how to configure single sign-on between Microsoft Entra ID and Datto File Protection Single Sign On.
Learn how to configure single sign-on between Microsoft Entra ID and Directory Services Protector.
Learn how to configure single sign-on between Microsoft Entra ID and Guardium Data Protection.
Learn how to configure single sign-on between Microsoft Entra ID and IMPAC Risk Manager.
Learn how to configure single sign-on between Microsoft Entra ID and Imperva Data Security.
Learn how to configure single sign-on between Microsoft Entra ID and IriusRisk.
Learn how to configure single sign-on between Microsoft Entra ID and Kisi Physical Security.
Learn how to configure single sign-on between Microsoft Entra ID and KnowBe4 Security Awareness Training.
Learn how to configure single sign-on between Microsoft Entra ID and Menlo Security.
Learn how to configure single sign-on between Microsoft Entra ID and Netskope Administrator Console.
Learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks - GlobalProtect.
Learn how to configure single sign-on between Microsoft Entra ID and Proofpoint Security Awareness Training.
Learn how to configure single sign-on between Microsoft Entra ID and Riskware.
Learn how to configure single sign-on between Microsoft Entra ID and Rivial Cybersecurity Management Platform.
Learn how to configure single sign-on between Microsoft Entra ID and SailPoint Identity Security Cloud.
Learn how to configure single sign-on between Microsoft Entra ID and SecurityStudio.
Learn how to configure single sign-on between Microsoft Entra ID and Symantec Web Security Service (WSS).
Learn how to configure single sign-on between Microsoft Entra ID and TAP App Security.
Learn how to configure single sign-on between Microsoft Entra ID and Terranova Security Awareness Platform.
Learn how to configure single sign-on between Microsoft Entra ID and The Cloud Security Fabric.
Learn how to configure single sign-on between Microsoft Entra ID and TINFOIL SECURITY.
Learn how to configure single sign-on between Microsoft Entra ID and Trend Micro Web Security (TMWS).
Learn how to configure single sign-on between Microsoft Entra ID and Valence Security Platform.
Learn how to configure single sign-on between Microsoft Entra ID and Virtual Risk Manager - USA.
Learn how to configure single sign-on between Microsoft Entra ID and Virtual Risk Manager.
Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
Learn how to set up and use Face Check with Microsoft Entra Verified ID for high-assurance facial matching verifications that protect user privacy at enterprise scale.
Learn how to manage agent identity blueprints in the Microsoft Entra admin center, including viewing permissions, managing credentials, and configuring owners and sponsors.
There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Give locally managed external partners access to both local and cloud resources using the same credentials with Microsoft Entra B2B collaboration.
*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.
Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.
The backup location and network share are configured with appropriate Active Directory security groups to ensure only authorized administrators can access the backup data. The ACL model aligns with the permissions used in Group Policy Management Console (GPMC), maintaining consistency with existing GPO management practices.
Learn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can move to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials. Use either PowerShell or the Microsoft Graph invitation API.
Configure Azure resources to simulate remote network connectivity to Microsoft's Security Edge Solutions with Global Secure Access.
Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
There's a known issue where there's a pre-existing, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
A Microsoft Entra documentation page was updated: Policy All Users Copilot Ai Security.
The following agents are currently available for Microsoft Entra. Due to the fast pace at which these agents are released and updated, each agent might have features at various stages of availability. Preview features are added frequently.
ai-usage: ai-assisted