A Microsoft Entra documentation page was updated: Create a security plan for external access to resources.
Week of 5 May 2025: a global Defender for Identity sensor notice leads a largely documentation-driven Entra update
The period was principally documentation maintenance: 138 of 145 records were updates, with three new and three removed entries. The clearest operational notice was the 9 May Microsoft 365 Message Center item for deploying the Defender for Identity sensor on Microsoft Entra Connect servers; it says the update is globally available, recommends installation for monitoring, and says no action is required before rollout. The most meaningful Learn changes are scope and behavior clarifications for Workload ID token lifetimes, External ID passkeys, and Access Reviews, plus preview setup guidance for Security Copilot. Other clusters, including phishing-resistant passwordless planning and custom authentication-extension documentation, are guidance updates rather than evidence of launches. The three removals have no supplied detail, so no retirement can be characterized.
- Defender for Identity sensor on Entra Connect servers is described as globally available
Entra ID · Authentication
The 9 May Message Center entry instructs organizations to deploy a Defender for Identity sensor on Microsoft Entra Connect servers and describes the update as globally available for hybrid-identity monitoring and threat detection. It also says no admin action is required before rollout while recommending installation. Because the supplied summary uses both new and classic sensor terminology, the evidence supports an operational availability notice, not a clear retirement or breaking change.
- Configurable token lifetimes remain explicitly scoped as a Workload ID preview
Workload ID · Standards
The updated page says access, ID, and SAML token lifetimes can be configured for all apps in an organization, multitenant applications, or specific service principals. It explicitly excludes managed identity service principals. This is a supported-scope clarification for a preview, not evidence of general availability or a newly changed limit.
- External ID documentation clarifies the guest passkey limitation
External ID · Authentication
The updated passkey and FIDO2 guidance states that internal or external guest users, including B2B collaboration users in the resource tenant, cannot register passkey credentials. This establishes a documented support boundary; the supplied evidence does not show that guest behavior changed during the week.
- Access Reviews use a snapshot taken when each review instance starts
ID Governance · Governance
The updated Microsoft Entra ID Governance FAQ says that an access review captures user assignments, group membership, and reviewer configuration at the start of the review. Changes made after the instance begins are not reflected in that instance, clarifying runtime behavior rather than announcing a new governance feature.
- Security Copilot preview guidance sets the initial setup role boundary
Security Copilot · Conditional Access
The updated Agent Optimization guidance says initial agent enablement and setup during the preview requires either the Security Administrator or Global Administrator role, which have Security Copilot access by default. After setup, Conditional Access Administrators can be assigned Security Copilot access and use the agent. This is preview onboarding and delegation guidance, not a general-availability announcement.
Do not treat this as a broad tenant-reconfiguration week. For hybrid identity, no pre-rollout action is called for by the sensor notice, but teams should evaluate the recommended sensor installation on Entra Connect servers. Anyone using or evaluating the Workload ID token-lifetime preview must account for its managed-identity exclusion; External ID designs must not assume guest or B2B users in the resource tenant can register FIDO2 passkeys; and Access Review operators must remember that mid-review changes do not update the running instance. For the Security Copilot agent preview, initial enablement requires a Security Administrator or Global Administrator; Conditional Access Administrators can be delegated access after setup when they have Security Copilot access.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
106 updatesA Microsoft Entra documentation page was updated: Determine your security posture for external access with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Microsoft Entra security operations for Privileged Identity Management.
Locate Integration Partners
Updatedmanager: martinco
Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/whatis.md)
A Microsoft Entra documentation page was updated: Best practices for all isolation architectures.
A Microsoft Entra documentation page was updated: Control external access to resources in Microsoft Entra ID with sensitivity labels.
Directory synchronization
UpdatedA Microsoft Entra documentation page was updated: Directory synchronization.
A Microsoft Entra documentation page was updated: Discover the current state of external collaboration in your organization.
A Microsoft Entra documentation page was updated: Govern on-premises service accounts.
Govern Service Accounts
UpdatedA Microsoft Entra documentation page was updated: Govern Service Accounts.
A Microsoft Entra documentation page was updated: Introduction to delegated administration and isolated environments.
A Microsoft Entra documentation page was updated: LDAP synchronization with Microsoft Entra ID.
Microsoft Entra fundamentals
UpdatedA Microsoft Entra documentation page was updated: Microsoft Entra fundamentals.
A Microsoft Entra documentation page was updated: Microsoft Entra integrations with synchronization protocols.
A Microsoft Entra documentation page was updated: OAuth 2.0 authorization with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Remote Desktop Gateway Services.
A Microsoft Entra documentation page was updated: Resource isolation with multiple tenants.
A Microsoft Entra documentation page was updated: SCIM synchronization with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Secure external access to Microsoft Teams, SharePoint, and OneDrive with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Secure external access with groups in Microsoft Entra ID and Microsoft 365.
A Microsoft Entra documentation page was updated: Secure group managed service accounts.
A Microsoft Entra documentation page was updated: Secure on-premises computer accounts with Active Directory.
A Microsoft Entra documentation page was updated: Secure standalone managed service accounts.
A Microsoft Entra documentation page was updated: Secure user-based service accounts in Active Directory.
A Microsoft Entra documentation page was updated: Securing cloud-based service accounts.
A Microsoft Entra documentation page was updated: Securing on-premises service accounts.
A Microsoft Entra documentation page was updated: Securing service principals in Microsoft Entra ID .
- it-pro
Resilience Overview
Updated- it-pro
author: rwike77
author: rwike77
|IssuerAndSubject | `X509:<I>DC=com,DC=contoso,CN=CONTOSO-DC-CA<S>DC=com,DC=contoso,OU=UserAccounts,CN=mfatest` | certificateUserIds | low-affinity |
1. Authenticate with a certificate that has policy OID of 3.4.5.6 and Issued by CN=CBATestRootProd. Authentication should pass and get a multifactor claim.
Deploy the new Defender for Identity sensor on Microsoft Entra Connect servers. The classic sensor is now available, enhancing visibility and security for hybrid identity environments. This update is available globally, and organizations should install the sensor for comprehensive monitoring and threat detection. No admin action is required before the rollout.
1. There are two tabs in the report: **Registration** and **Usage**.
To synchronize users from Microsoft Entra to SAP Cloud Identity Services, enable [automated user provisioning](sap-cloud-platform-identity-authentication-provisioning-tutorial.md).
* By default, the value of the Microsoft Entra user `userPrincipalName` attribute is mapped to both the `userName` and `emails[type eq "work"].value` attributes of SAP Cloud Identity Services. If user's email addresses are different from their user principal names, then you may need to change this mapping.
>[!Important]
A Microsoft Entra documentation page was updated: Header-based authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: LDAP authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Microsoft Entra integrations with authentication protocols.
A Microsoft Entra documentation page was updated: OpenID Connect authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Password-based authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: RADIUS authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: SAML authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: SSH authentication with Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Windows authentication - Kerberos constrained delegation with Microsoft Entra ID.
Howto Mfa Userstates
UpdatedThe per-user MFA administration experience in the Microsoft Entra admin center is recently improved. To view and manage user states, complete the following steps:
A Microsoft Entra documentation page was updated: Monitoring application sign-in health for resilience.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Usage Insights Report
Updated
Organizations deploying phishing-resistant passwordless typically have a need for some of their personas to use remote desktop technology to facilitate productivity, security, or administration. The two basic use cases are:
[Deploy a phishing-resistant passwordless authentication deployment in Microsoft Entra ID](how-to-deploy-phishing-resistant-passwordless-authentication.md)
[Considerations for specific personas in a phishing-resistant passwordless authentication deployment in Microsoft Entra ID](how-to-plan-persona-phishing-resistant-passwordless-authentication.md)
[Deploy a phishing-resistant passwordless authentication deployment in Microsoft Entra ID](how-to-deploy-phishing-resistant-passwordless-authentication.md)
$certHash = ($hashBytes|ForEach-Object ToString X2) -join ''
Custom Extension Overview
UpdatedThis section lists the custom authentication extensions events available in Microsoft Entra ID workforce and external tenants. For detailed information about the events, refer to the respective documentation.
- A familiarity and understanding of the concepts covered in [custom authentication extensions](/entra/identity-platform/custom-extension-overview).
Custom Extension Overview
UpdatedThis video provides detailed instructions on configuring Microsoft Entra custom authentication extensions and offers best practices and valuable tips for optimal implementation.
Sso Linux
Updated- Support for Bash scripts for custom compliance policies
This article provides information about the latest updates to Microsoft Single Sign-on for Linux.
# Add a meaningful description for search results
Freshdesk Tutorial
Updated1. **Create a Microsoft Entra test user** - to test Microsoft Entra single sign-on with Britta Simon.
Learn how to configure single sign-on between Microsoft Entra ID and Freshdesk.
Learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks Captive Portal.
Learn how to configure single sign-on between Microsoft Entra ID and Adaptive Insights.
9. Click the folder icon to upload your **Configuration profile file**. Choose the *kerberos.mobileconfig* file you [saved previously](#Kerberos SSO MDM profile configuration for on-premises Active Directory) after customizing the template.
Aws Clientvpn Tutorial
Updated> [!NOTE]
Identifier Uri Restrictions
UpdatedWhen this setting is enabled, the secure patterns are strictly enforced.
A Microsoft Entra documentation page was updated: Adobe Creative Cloud Tutorial.
Kao Navi Tutorial
RemovedA Microsoft Entra documentation page was updated: Kao Navi Tutorial.
Tutorial V2 Android
RemovedA Microsoft Entra documentation page was updated: Tutorial V2 Android.
Open Darwinbox studio and navigate to Connector Library. Search for and install the “Microsoft” and “Microsoft Entra” connectors:
</plist>
Refer to the [Microsoft Entra ID macOS Platform SSO documentation](./macos-psso.md) to learn how to configure and deploy Platform SSO. Platform SSO should be deployed on Enterprise-managed Macs regardless of whether you choose to deploy Kerberos SSO using this guide.
Hybrid Join Plan
Updated- Windows Server 2016
Sharefile Tutorial
UpdatedTo configure the integration of Citrix ShareFile into Microsoft Entra ID, you need to add Citrix ShareFile from the gallery to your list of managed SaaS apps.
Best Practices
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
manager: CelesteDG
manager: CelesteDG
- Sign-in logs
A Microsoft Entra documentation page was updated: Manage external access to resources with Conditional Access policies.
author: MicrosoftGuyJFlo
Managed Policies
UpdatedAdministrators with at least the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role assigned find these policies in the [Microsoft Entra admin center](https://entra.microsoft.com) under **Protection** > **Conditional Access** > **Policies**.
Delete Application Portal
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Hootsuite Tutorial
Updated1. Perform the following step, if you wish to configure the application in **SP** initiated mode:
This article shows the new and updated documentation for the Microsoft Entra application management.
Hootsuite Tutorial
Updated1. Perform the following step, if you wish to configure the application in **SP** initiated mode:
Hybrid Join
Updatedauthor: owinfreyATL
Overview
Updatedauthor: owinfreyATL
New Name
Updated| Identity and access management | New identity categories | Network access |
manager: CelesteDG
The provisioning summary report and Provisioning logs play a key role helping admins troubleshoot various user account provisioning issues.
Plan Auto User Provisioning
UpdatedRefer to the following links to troubleshoot any issues that may turn up during provisioning:
Plan Cloud Hr Provision
UpdatedTo troubleshoot any issues that might turn up during provisioning, see the following articles:
Provision On Demand
Updated* [Troubleshooting provisioning](troubleshoot.md)
- [Check the status of user provisioning](../app-provisioning/application-provisioning-when-will-provisioning-finish-specific-user.md)
Whats New Docs
Updated- [Skip deletion of user accounts that go out of scope in Azure Active Directory](skip-out-of-scope-deletions.md)
Connect Fed Group Claims
Updated- Support for use of `sAMAccountName` and security identifier (SID) attributes synced from on-premises is designed to enable moving existing applications from Active Directory Federation Services (AD FS) and other identity providers. Groups managed in Microsoft Entra ID don't contain the attributes necessary to emit these claims.
If an adversary is able to successfully steal a token, organizations can enable certain capabilities to automatically reduce the
How Provisioning Works
Updated[Build a SCIM endpoint and configure provisioning when creating your own app](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)
V2 Oauth2 Auth Code Flow
UpdatedRedirect URIs for SPAs that use the auth code flow require special configuration.
Learn how to integrate Darwinbox HR with Microsoft Entra ID to automate user provisioning, manage lifecycle workflows, and streamline HR-driven processes.
Msal Shared Devices
Updatedauthor: henrymbuguakiarie
A Microsoft Entra documentation page was updated: Howto Configure Recommendation Email Notifications.
Microsoft Entra ID Protection
2 updatesIdentity Protection Risks
Updatedauthor: shlipsey3
Identity Protection Risks
Updatedauthor: shlipsey3
Microsoft Entra ID Governance
7 updates1. Select **My Access settings for end users**.
$createdDateTime = $_.CreatedDateTime -replace "\\/Date\((\d+)\)\\/", '$1'
1. On the Add an Action pane, select **HTTP**.
- At least the [Entitlement Management Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) role of the catalog where the custom extension will be created.
Assigning Microsoft Entra roles through access packages helps to efficiently manage role assignments at scale and improves the role assignment lifecycle.
Access Reviews Faqs
UpdatedNo. Access reviews capture a snapshot of access at the start of each review instance. Any changes made to user assignments, group membership, or reviewer configuration after the review begins won't be reflected in that instance.
Access reviews - FAQs
UpdatedIn this article, you find questions to commonly asked questions about [access reviews](access-reviews-overview.md). Check back to this page frequently as changes happen often, and answers are continually being added.
Microsoft Entra External ID
17 updatesB2b Fundamentals
Updatedauthor: csmulligan
Supported Features Customers
UpdatedDirect Federation Overview
UpdatedWithin the same cloud, which clouds can cross-tenant synchronization be used in?
Quickstart Trial Setup
UpdatedDirect Federation
Updatedauthor: msmimart
Quickstart Trial Setup
UpdatedAdd Attributes To Token
Updated1. Select **Add**.
A Microsoft Entra documentation page was updated: Onboard external users to line of business applications using Microsoft Entra B2B.
A Microsoft Entra documentation page was updated: Plan a Microsoft Entra B2B collaboration deployment.
A Microsoft Entra documentation page was updated: Transition to governed collaboration with Microsoft Entra B2B collaboration.
Enable Passkey Fido2
UpdatedRegistration of passkey (FIDO2) credentials isn't supported for internal or external guest users, including B2B collaboration users in the resource tenant.
Training Videos
UpdatedThe video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verification.
Customize Branding Customers
Updated::: zone-end
Microsoft Entra Workload ID
6 updatesauthor: rwike77
internal class Program
A Microsoft Entra documentation page was updated: Service Accounts Managed Identities.
Service Principal Table
UpdatedA Microsoft Entra documentation page was updated: Service Principal Table.
Workload Identity Federation
UpdatedLearn how workload identify federation enables secre access to Microsoft Entra protected resources from external software workloads without managing secrets.
You can configure the lifetime of access, ID, or Security Assertion Markup Language (SAML) tokens issued by the Microsoft identity platform. Token lifetimes can be set for all apps in your organization, multitenant applications, or specific service principals. Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.
Microsoft Entra Global Secure Access
6 updatesThis article provides troubleshooting guidance for the Global Secure Access client for Windows. It explores each tab of the Advanced diagnostics utility.
Troubleshoot Connectors
Updated**Objective:** Verify that the connector machine, backend proxy, and firewall support the certificate the connector created. Also, verify the certificate is valid.
View Enriched Logs
Updated- A **Security Administrator** role is required to export Global Secure Access Network Traffic Logs in Diagnostic Settings.
Enable Multi Geo
UpdatedContent-type: application/json
Remote Network Connectivity
Updatedmanager: femila
Role Based Permissions
Updated| View traffic logs and alerts | ✅ | ✅ | ✅ | | | | | ✅ |
Security Copilot + Entra
1 updateAgent Optimization
Updated- For the initial agent enablement/setup, you will need to be either a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview. These roles also have [access to Security Copilot by default](/copilot/security/authentication). After setup, you can assign Conditional Access Administrators with Security Copilot access. This will give your Conditional Access Administrators the ability to use the agent as well.
