Week in brief

Workload ID retirement sets a 31 March 2026 authentication deadline; Conditional Access safety guidance is the main operational theme

Among the supplied changes for the week of 2 June 2025, the updated Workload ID page "Retire Service Principal Less Authentication" is the clearest administrator-impacting item: it says action is required before 31 March 2026 to avoid application authentication failure. Other meaningful exceptions are Security Copilot's Conditional Access agent and troubleshooting material, Global Secure Access's forwarding-profile lockout warning paired with an Internet Access break-glass sample, and Entra Health and ID Governance guidance. The record is otherwise documentation-heavy—924 updates, 21 new items, 9 removals, and no Message Center entries. The supplied MFA, passwordless, certificate-authentication, and External ID entries do not establish a new feature, Preview, GA release, or tenant-wide behavior change.

  • The updated page titled "Retire Service Principal Less Authentication" explicitly says administrators must act before March 31, 2026 to avoid application authentication failure. This is a retirement and potential behavior-change item rather than ordinary documentation maintenance. The supplied evidence does not identify the affected application patterns or migration steps, so the supported action is to identify dependencies and consult the full retirement guidance.

  • A new page covers troubleshooting Conditional Access policies and Security Copilot, while related updates describe an optimization agent that recommends policies and changes aligned with Zero Trust guidance. The troubleshooting material also covers creating, assigning, and diagnosing policies with custom security attributes, and the agents overview says the agents use SCUs within Microsoft Security workflows. These records document use of the capability; they do not state that it is a Preview or GA launch.

  • The updated Global Secure Access guidance calls out known tunnel-authorization limitations: blocking a forwarding profile in Conditional Access can inadvertently prevent users from accessing anything on their machine. A related Internet Access PowerShell sample covers disabling traffic forwarding and Conditional Access policies using the compliant-network condition in a break-glass scenario. This is a safety clarification and recovery reference, not evidence that the limitation was newly introduced.

  • Updated Entra ID pages describe Microsoft Entra Health signals and alerts for sign-ins requiring MFA, sign-ins to SAML-authenticated applications, and Conditional Access block-policy health. A related Security Copilot scenario describes monthly look-back reporting for Microsoft Entra authentication availability and SLA attainment through Microsoft Graph. The supplied records provide monitoring guidance but no evidence of a new signal, SLA change, or availability milestone.

  • The updated "Manage users excluded from Conditional Access policies" guidance directs administrators to use access reviews to manage excluded users. This is concrete governance and security guidance for an existing Conditional Access control, not a stated new enforcement behavior or rollout. Organizations that permit such exclusions should consult this procedure when managing them.

For Entra administrators

Identify applications that depend on the Workload ID behavior named in the retirement page and follow the full guidance before the stated deadline; the supplied record does not provide migration steps. For Global Secure Access and Internet Access, account for the forwarding-profile Conditional Access limitation and use the documented break-glass procedure when relevant. If the tenant uses Security Copilot's Conditional Access agent or maintains Conditional Access exclusions, the new troubleshooting and access-review pages are the relevant operational references. Nothing in the supplied updates supports a blanket tenant configuration change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

173

Quickstart Web App Node Sign In Edit Profile

Updated

Learn how to configure a sample web app to edit user's profile. The edit profile operation requires a customer user to complete multifactor authentication (MFA)

8 June 2025

Use Custom Domain Url

Updated

Use a custom domain to fully brand the authentication URL. From a user perspective, users remain on your domain during the authentication process, rather than being redirected to *ciamlogin.com* domain name.

8 June 2025

Web App Quickstart Portal Node Js

Updated

In this quickstart, you learn how to implement authentication with a Node.js web app and the Microsoft Authentication Library (MSAL) for Node.js.

8 June 2025

Mfa Data Residency

Updated

Microsoft Entra ID stores customer data in a geographical location based on the address an organization provides when subscribing to a Microsoft online service such as Microsoft 365 or Azure. For information on where your customer data is stored, see [Where your data is located](https://www.microsoft.com/trust-center/privacy/data-location) in the Microsoft Trust Center.

8 June 2025

Quickstart V2 Java Webapp

Updated

In this quickstart, you'll learn how to add sign-in with Microsoft to a Java web application by using OpenID Connect.

8 June 2025

Web App Quickstart Portal Java

Updated

In this quickstart, you'll learn how to add sign-in with Microsoft to a Java web application by using OpenID Connect.

8 June 2025

Certificate Based Authentication Technical Deep Dive

Updated

:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/exempted.png" alt-text="Screenshot of CAs that are exempted from CRL validation." :::

7 June 2025

Authentication Passwordless

Updated

Platform Credential for macOS allows users to go passwordless by configuring Touch ID to unlock the device, and uses phish-resistant credentials, based on Windows Hello for Business technology. This saves customer organizations money by removing the need for security keys and advances Zero Trust objectives using integration with the Secure Enclave.

6 June 2025

What Is App Proxy

Updated

Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.

6 June 2025

Telephony Fraud Protections and Throttles

Updated

Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.

4 June 2025

Domains Verify Custom Subdomain

Updated

Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.

4 June 2025

Non-interactive sign-in logs

Updated

Learn about the type of activity captured in the non-interactive sign-in logs in Microsoft Entra monitoring and health.

4 June 2025

Interactive user sign-in logs

Updated

Learn about the type of information captured in the interactive user sign-in logs in Microsoft Entra monitoring and health.

4 June 2025

Sspr Policy

Updated

| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |

4 June 2025
112

Tutorial Create Forest Trust

Updated

Learn how to create a one-way outbound forest to an on-premises AD DS domain in the Microsoft Entra admin center for Microsoft Entra Domain Services

8 June 2025

Configure User Consent

Updated

- A user account. If you don't already have one, you can [create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).

6 June 2025

Mysdworxcom Tutorial

Updated

* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.

6 June 2025

Mysdworxcom Tutorial

Updated

* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.

5 June 2025

Equinix Federation App Tutorial

Updated

To configure Single Sign-On on **Equinix Federation App** side, please follow the [link](https://docs.equinix.com).

4 June 2025

Groups Bulk Download

Updated

Download group properties in bulk in the Azure admin center in Microsoft Entra ID.

4 June 2025

Groups Dynamic Membership

Updated

Learn how to manage rules for dynamic membership groups to automatically populate group members and rule references.

4 June 2025

Groups Settings V2 Cmdlets

Updated

This page provides PowerShell examples to help you manage your groups in Microsoft Entra ID

4 June 2025

Linkedin User Consent

Updated

Explains how LinkedIn integration shares data via Microsoft apps in Microsoft Entra ID

4 June 2025

User management enhancements

Updated

Describes how Microsoft Entra ID enables user search, filtering, and more information about your users.

4 June 2025

Users Bulk Add

Updated

Add users in bulk in Microsoft Entra ID

4 June 2025

Users Bulk Download

Updated

Download user records in bulk in the Azure admin center in Microsoft Entra ID.

4 June 2025

Users Bulk Restore

Updated

Restore deleted users in bulk in the Azure portal in Microsoft Entra ID

4 June 2025

Users Restrict Guest Permissions

Updated

Restrict guest user access permissions using the Azure portal, PowerShell, or Microsoft Graph in Microsoft Entra ID

4 June 2025

Users Sharing Accounts

Updated

Describes how Microsoft Entra ID enables organizations to securely share accounts for on-premises apps and consumer cloud services.

4 June 2025

Licensing Groups Assign

Removed

A Microsoft Entra documentation page was updated: Licensing Groups Assign.

4 June 2025

Licensing Ps Examples

New

A Microsoft Entra documentation page was updated: Licensing Ps Examples.

4 June 2025

Licensing Ps Examples

Removed

A Microsoft Entra documentation page was updated: Licensing Ps Examples.

4 June 2025
53

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

8 June 2025

Deploy Azure App Proxy

Updated

With Microsoft Entra Domain Services, you can lift-and-shift legacy applications running on-premises into Azure. Microsoft Entra application proxy then helps you support remote workers by securely publishing those internal applications part of a Domain Services managed domain so they can be accessed over the internet.

8 June 2025

Spa Quickstart Portal Javascript Auth Code

Updated

In this quickstart, learn how a JavaScript single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow.

8 June 2025

Spa Quickstart Portal Javascript Auth Code Angular

Updated

In this quickstart, learn how a JavaScript Angular single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.

8 June 2025

Spa Quickstart Portal Javascript Auth Code React

Updated

In this quickstart, learn how a JavaScript React single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.

8 June 2025

Configure Sso

Updated

Understand single sign-on with an on-premises app using application proxy.

6 June 2025

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

6 June 2025

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

6 June 2025
43

Archive for Microsoft Entra releases and announcements

Updated

The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.

8 June 2025

Copilot in Microsoft Entra

Updated

**Applies to:** Microsoft Entra ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png)

6 June 2025

Quarantine unsanctioned tenants

Updated

Isolate unsanctioned tenants using Microsoft Entra features. Follow steps to quarantine unapproved tenants and strengthen security.

4 June 2025

Licensing Preview Info

Updated

In this article we go over the information in effect when participating in Microsoft Entra ID preview programs.

4 June 2025

Whats New

Updated

**Type:** New feature

4 June 2025

Recommendations

Updated

| Recommendation | Impacted resources | Availability | Identity Secure Score | Target roles for email notifications |

4 June 2025

Default user permissions

Updated

Compare the default user permissions available in Microsoft Entra ID and learn how to restrict access.

4 June 2025

Directory Overview User Model

Updated

The relationship between users and licenses assigned, administrator roles, dynamic membership groups in Microsoft Entra ID

4 June 2025

Group Based Licensing

Updated

Learn about Microsoft Entra group-based licensing, including how it works,

4 June 2025

Sign Up Organization

Updated

Learn about the options to sign up your organization to use Azure and

4 June 2025

What is Microsoft Entra ID?

Updated

Learn about Microsoft Entra ID, including terminology, available licenses, and a list of associated features.

4 June 2025
35

Connect Install Existing Database

Updated

- Except for credentials information, the synchronization configuration stored in the ADSync database is automatically recovered and used during installation. This includes custom synchronization rules, connectors, filtering, and optional features configuration.

8 June 2025

Expression Builder

Updated

Understand how expression builder works with Application Provisioning in Microsoft Entra ID.

6 June 2025

User Provisioning Sync Attributes For Mapping

Updated

When configuring user provisioning with Microsoft Entra ID and SaaS apps, use the directory extension feature to add source attributes that aren't synchronized by default.

6 June 2025

Workday Attribute Reference

Updated

Learn which attributes that you can fetch from Workday using XPATH queries in Microsoft Entra ID.

6 June 2025
27

Desktop Quickstart Portal Uwp

Updated

In this quickstart, learn how a Universal Windows Platform (UWP) application can get an access token and call an API protected by Microsoft identity platform.

8 June 2025

Mark an app as publisher verified

Updated

Describes how to mark an app as publisher verified. When an application is marked as publisher verified, it means that the publisher (application developer) verified the authenticity of their organization using a Cloud Partner Program (CPP) account that completed the verification process and associated this CPP account with that application registration.

8 June 2025

Publisher verification overview

Updated

Learn about benefits, program requirements, and frequently asked questions in the publisher verification program for the Microsoft identity platform.

8 June 2025

Quickstart V2 Java Daemon

Updated

In this quickstart, you learn how a Java app can get an access token and call an API protected by Microsoft identity platform endpoint, using the app's own identity

8 June 2025

Web Api Quickstart Portal Aspnet Core

Updated

In this quickstart, you download and modify a code sample that demonstrates how to protect an ASP.NET Core web API by using the Microsoft identity platform for authorization.

8 June 2025

Web App Quickstart Portal Python

Updated

In this quickstart, learn how a Python web app can sign in users, get an access token from the Microsoft identity platform, and call the Microsoft Graph API.

8 June 2025

Assign Microsoft Entra roles

Updated

Learn how to assign Microsoft Entra roles to users and groups at tenant, application registration, administrative unit scopes using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.

6 June 2025

Create a custom role in Microsoft Entra ID

Updated

Learn how to create a custom role to manage access to Microsoft Entra resources using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API

6 June 2025
16

Broken Links in an Application

Updated

Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.

6 June 2025

Enterprise State Roaming Troubleshooting

Updated

1. After joining your Windows 10 or newer PC to a domain that is configured to allow Enterprise State Roaming, sign on with your work account. Go to **Settings** > **Accounts** > **Sync Your Settings** and confirm that sync and the individual settings are on, and that the top of the settings page indicates that you're syncing with your work account. Confirm the same account is also used as your account in **Settings** > **Accounts** > **Your Info**.

4 June 2025

Groups Troubleshooting

Updated

Troubleshooting tips for dynamic membership groups in Microsoft Entra ID

4 June 2025
14

Web App Role Based Access Control

Updated

Learn how to configure groups and user roles in your external tenant, so you can receive them as claims in a security token for your Node.js application

8 June 2025

Manage emergency access admin accounts

Updated

This article describes how to use emergency access accounts to help prevent being inadvertently locked out of your Microsoft Entra organization.

6 June 2025

Connect Health Agent Install

Updated

> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.

5 June 2025

Groups Self Service Management

Updated

Create and manage security groups or Microsoft 365 groups in Microsoft Entra ID and request security group or Microsoft 365 group memberships.

4 June 2025
9

userimpact: Low

Updated

Organizations without proper activation alerts for highly privileged roles lack visibility into when users access these critical permissions. Threat actors can exploit this monitoring gap to perform privilege escalation by activating highly privileged roles without detection, then establish persistence through admin account creation or security policy modifications. The absence of real-time alerts enables attackers to conduct lateral movement, modify audit configurations, and disable security controls without triggering immediate response procedures.

7 June 2025

Sla Performance

Updated

| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |

7 June 2025

Roles across Microsoft services

Updated

Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services

6 June 2025

Sla Performance

Updated

| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |

5 June 2025

Enterprise State Roaming Group Policy Settings

Updated

The MDM policy settings apply to Windows 10 or newer. Refer to [Enterprise State Roaming settings catalog](/windows/configuration/windows-backup/catalog-esr) for details on what devices are supported for Microsoft Entra ID-based syncing.

4 June 2025
8

Troubleshoot Conditional Access

Updated

1. **Conditional Access** to see policy failure and success. Scope your filter to show only failures to limit results.

8 June 2025

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

6 June 2025
7

Scim Graph Scenarios

Updated

Using SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.

6 June 2025

Scim Validator Tutorial

Updated

This tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.

6 June 2025

Use Scim To Provision Users And Groups

Updated

System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.

6 June 2025
6

Govern the existing users of an application that does not support provisioning in Microsoft Entra ID with Microsoft PowerShell

Updated

Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.

5 June 2025
2

Conceptual Deployment Plan

Updated

An end-to-end guide for planning the deployment of application proxy within your organization

6 June 2025
1
129

Entitlement Management Dynamic Approval

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports approvers when they are the requestors manager, their second-level manager, or a sponsor from a connected organization:

7 June 2025

Migrate From Sap Idm

Updated

Organizations that have SAP SuccessFactors could use SAP IDM to [bring in employee data](https://help.sap.com/docs/SAP_IDENTITY_MANAGEMENT/4773a9ae1296411a9d5c24873a8d418c/4c54e007ab414f7da3854952cad00221.html) from SAP SuccessFactors. Those organizations with SAP SuccessFactors can easily migrate to bring identities for employees [from SuccessFactors into Microsoft Entra ID](~/identity/saas-apps/sap-successfactors-inbound-provisioning-cloud-only-tutorial.md) or [from SuccessFactors into on-premises Active Directory](~/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial.md), by using Microsoft Entra ID connectors. The connectors support the following scenarios:

6 June 2025

Entitlement Management Dynamic Approval

Updated

With the Azure Logic App given the access package assignment manager role for the catalog, you must now go to logic app to edit it to communicate with Microsoft Entra. To do this, you'd do the following steps:

6 June 2025

Govern access for applications in your environment

Updated

Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.

5 June 2025

Govern access with an organizational role model

Updated

Microsoft Entra ID Governance allows you to model organizational roles using access packages, so you can migrate your existing role definitions to entitlement management.

5 June 2025

Pim Powershell Migration

Updated

The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.

5 June 2025

Check Status Workflow

Updated

This article guides a user on checking the status of a Lifecycle workflow

5 June 2025

Customize Workflow Email

Updated

Get a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.

5 June 2025

Governance Service Limits

Updated

This article details service limits for offerings within Microsoft Entra ID Governance

5 June 2025

Groups Activate Roles

Updated

Learn how to activate your group membership or ownership in Privileged

5 June 2025

Manage access to your SAP applications

Updated

Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.

5 June 2025

Manage access with access reviews

Updated

Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.

5 June 2025

Manage Workflow On Premises

Updated

A how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.

5 June 2025

Manage Workflow Properties

Updated

This article guides a user to editing a workflow's properties using Lifecycle Workflows.

5 June 2025

Manage Workflow Tasks

Updated

This article guides a user on managing workflow versions with Lifecycle Workflows.

5 June 2025

On Demand Workflow

Updated

This article guides a user to running a workflow on demand using Lifecycle Workflows.

5 June 2025

Pim Apis

Updated

Information for understanding the APIs in Microsoft Entra Privileged

5 June 2025

Pim Roles

Updated

Describes the roles you can't manage in Microsoft Entra Privileged Identity

5 June 2025

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

5 June 2025
24

Copilot Entra Security Scenarios

Updated

- [Investigate insights within entitlements management](#investigate-insights-within-entitlements-management): Get quick access to information about access packages, policies, connected organizations, and catalog resources.

7 June 2025

Microsoft Entra Id Governance Licensing For Guest Users

Updated

Microsoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees. See [Microsoft Entra ID Governance licensing fundamentals](/entra/id-governance/licensing-fundamentals) for complete details on licensing for employees.

7 June 2025

Microsoft Entra ID Governance

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

5 June 2025

What are access reviews? - Microsoft Entra

Updated

Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.

5 June 2025

Externally determine the approval requirements for an access package using custom extensions (Preview)

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. While entitlement management natively supports dynamic approvers such as the requestor's manager, second-level manager, or sponsor from a connected organization, these options don't cover all scenarios. With [custom extensions](entitlement-management-logic-apps-integration.md) calling out to [Azure Logic Apps](/azure/logic-apps/logic-apps-overview), you're able to determine approval requirements for access packages at the time of request through an external system. For example, if the user requesting an access package is in a department where leadership has recently changed, dynamic approvals can query the system and assign the new department head as the approver. With this external call, you're able to determine approval requirements based on each of the [ApprovalStage properties](/graph/api/resources/approvalstage?view=graph-rest-beta#properties). This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.

5 June 2025

Lifecycle Workflow On Premises

Updated

Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.

5 June 2025

What is entitlement management?

Updated

Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external users.

5 June 2025
3

Pim Troubleshoot

Updated

Learn how to troubleshoot system errors with roles in Microsoft Entra Privileged Identity Management (PIM).

5 June 2025
2
1
74

Migrate Users

Updated

Learn how to migrate users from another identity provider to Microsoft Entra External ID.

8 June 2025

About Redirect Url

Updated

A Microsoft Entra documentation page was updated: About Redirect Url.

8 June 2025

Add Client App Certificate

Updated

To use your client app certificate, you need to associate the app you registered in the Microsoft Entra admin center with the certificate:

8 June 2025

Applies To External Only

Updated

**Applies to**: ![White circle with a gray X symbol.](../media/common/applies-to-no.png) Workforce tenants ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) External tenants ([learn more](../tenant-configurations.md))

8 June 2025

Applies To Workforce Only

Updated

**Applies to**: ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) Workforce tenants ![White circle with a gray X symbol.](../media/common/applies-to-no.png) External tenants ([learn more](../tenant-configurations.md))

8 June 2025

B2b Quickstart Add Guest Users Portal

Updated

Use this quickstart to learn how Microsoft Entra admins can add B2B guest users in the Microsoft Entra admin center and walk through the B2B invitation workflow.

8 June 2025

B2c Federation Customers

Updated

Learn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

8 June 2025

Create an External Tenant

Updated

Create an external tenant to get started with Microsoft Entra External ID as your customer identity and access management (CIAM) service.

8 June 2025

Custom roles for cross-tenant access settings

Updated

Learn how your organization can define custom roles to manage cross-tenant access settings, allowing for precise control without relying on built-in management roles.

8 June 2025

Declare App Roles

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Privileged Role Administrator](../../../../identity/role-based-access-control/permissions-reference.md#privileged-role-administrator).

8 June 2025

Quickstart - Get started

Updated

Learn how to get started with Microsoft Entra External ID. Customize your apps' look and feel, set up a user to test the sign-up flow, and configure a sample app in just a few minutes.

8 June 2025

Register Daemon App

Updated

The following steps show you how to register your daemon app in the Microsoft Entra admin center:

8 June 2025

Service Limits

Updated

Learn about the service limits and restrictions in an external tenant.

8 June 2025

Use Custom Domain Url

Updated

A Microsoft Entra documentation page was updated: Use Custom Domain Url.

8 June 2025

User Permissions

Updated

Learn about the default permissions for users in an external tenant.

8 June 2025

Allow or Block Invitations

Updated

Learn how an administrator create a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.

5 June 2025
29

Custom Url Domain

Updated

Learn about setting up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.

8 June 2025

Custom Url Domain

Updated

Learn how to set up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.

8 June 2025

Customize Languages Customers

Updated

Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.

8 June 2025

Enable Native Authentication

Updated

To specify that this app is a public client and can use native authentication, enable public client and native authentication flows:

8 June 2025

Multifactor Authentication Customers

Updated

Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.

8 June 2025

Native Authentication

Updated

Learn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.

8 June 2025

Test User Flow

Updated

To test a [user flow](/entra/external-id/customers/how-to-user-flow-sign-up-sign-in-customers) with this app registration, enable the implicit grant flow for authentication.

8 June 2025

Use Custom Domain Url Python

Updated

Use a custom URL domain to fully brand the authentication URL. From a user perspective, users remain on your domain during the authentication process, rather than being redirected to *ciamlogin.com* domain name.

8 June 2025

Add App Role

Updated

An API needs to publish a minimum of one app role for applications, also called [Application permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token as themselves. Application permissions are the type of permissions that APIs should publish when they want to enable client applications to successfully authenticate as themselves and not need to sign-in users. To publish an application permission, follow these steps:

8 June 2025

Add App User Flow

Updated

For the customer users to see the sign-up or sign-in experience when they use your app, you need to associate your app with a user flow. Although many applications can be associated with your user flow, a single application can only be associated with one user flow.

8 June 2025

Define Custom Attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

8 June 2025

Enable self-service password reset

Updated

Learn how to enable self-service password reset so your customers can reset their own passwords without admin assistance.

8 June 2025

Grant Api Permission Sign In

Updated

Once you register your application, it gets assigned the **User.Read** permission. However, since the tenant is an external tenant, the customer users themselves can't consent to this permission. You as the tenant administrator must consent to this permission on behalf of all the users in the tenant:

8 June 2025

Quickstart Tenant Setup

Updated

In this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.

8 June 2025

Test User Flows

Updated

Learn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.

8 June 2025

User Flow Sign Up Sign In Customers

Updated

Add sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.

8 June 2025

Visual Studio Code Extension

Updated

Learn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.

8 June 2025

Supported Features Customers

Updated

| **Authentication** > **Redirect URIs**| The URIs Microsoft Entra ID accepts as destinations when returning authentication responses (tokens) after successfully authenticating or signing out users. | Same as workforce.|

5 June 2025
26

Add App Client Secret

Updated

Create a client secret for the registered application. The application uses the client secret to prove its identity when it requests for tokens:

8 June 2025

Add Attributes To Token

Updated

Learn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.

8 June 2025

Add Mfa Api App Client Secret

Updated

Create a client secret for the registered application. The application uses the client secret to prove its identity when it requests for tokens.

8 June 2025

Add Optional Claims Access

Updated

You can add the **idtyp** optional claim to help the web API to determine whether a token is an **app** token or an **app + user** token. Although you can use a combination of **scp** and **roles** claims for the same purpose, using the **idtyp** claim is the easiest way to tell an app token and an app + user token apart. For example, the value of this claim is *app* when the token is an app-only token.

8 June 2025

Assign Users Groups Roles

Updated

Once you've added app roles in your application, administrator can assign users and groups to the roles. Assignment of users and groups to roles can be done through the admin center, or programmatically using [Microsoft Graph](/graph/api/user-post-approleassignments). When the users assigned to the various app roles sign in to the application, their tokens have their assigned roles in the `roles` claim.

8 June 2025

Facebook Federation Customers

Updated

Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.

8 June 2025

Find Application Id

Updated

A Microsoft Entra documentation page was updated: Find Application Id.

8 June 2025

Group App Roles Support

Updated

Find out which core Microsoft Entra features related to the user and group management model and application assignment are available in external tenants.

8 June 2025

Read Id Token Claims Android Kotlin

Updated

Once your app acquires an ID token, you can retrieve the claims associated with the current account. To do so, use the following code snippet.

8 June 2025

Samples Ciam All

Updated

Learn how to build and integrate apps with external tenants with scenarios such as sign-up, sign in, and getting an access token to call an API.

8 June 2025

Use App Roles Customers

Updated

Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.

8 June 2025

User Insights

Updated

Learn about how to analyze user activity and engagement for your registered application in the external tenant.

8 June 2025

Microsoft Accounts Federation Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

7 June 2025
21

Add Member To Group

Updated

Now that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.yml#create-a-basic-group-and-add-members).

8 June 2025

Add Api Mfa Scopes

Updated

An API needs to publish a minimum of one scope, also called [Delegated Permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token for a user successfully. To publish a scope, follow these steps:

8 June 2025

Add Api Scopes

Updated

An API needs to publish a minimum of one scope, also called [Delegated Permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token for a user successfully. To publish a scope, follow these steps:

8 June 2025

Guide Explained

Updated

Learn about the features you set up with the get started guide.

8 June 2025

Solutions Customers

Updated

Learn about the customer identity and access management solutions for your consumer and business customer apps that are provided by Microsoft Entra External ID.

8 June 2025

Supported Features Customers

Updated

Compare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.

8 June 2025

User Attributes

Updated

User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.

8 June 2025

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

7 June 2025

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

6 June 2025

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

5 June 2025
17

Grant Api Access App

Updated

For your application to access data in Microsoft Graph API, grant the registered application the relevant application permissions. The effective permissions of your application are the full level of privileges implied by the permission. For example, to create, read, update, and delete every user in your external tenant, add the User.ReadWrite.All permission.

8 June 2025

Grant Api Permission Call Api Common

Updated

1. From the **App registrations** page, select the application that you created (such as *ciam-client-app*) to open its **Overview** page.

8 June 2025

Grant Api Permission Edit Profile

Updated

1. From the **App registrations** page, select the application that you created (such as *edit-profile-service*) to open its **Overview** page.

8 June 2025

Register Api App

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Developer](~/identity/role-based-access-control/permissions-reference.md#application-developer).

8 June 2025

Register Mfa Api App

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Developer](~/identity/role-based-access-control/permissions-reference.md#application-developer).

8 June 2025
5

Custom Oidc Federation Customers

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

8 June 2025

Register Saml App

Updated

Learn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.

8 June 2025

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

8 June 2025
4
2
1
1
1
6

Data Storage And Privacy

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

6 June 2025

Manage Internet Access Profile

Updated

Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.

6 June 2025

Points Of Presence

Updated

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.

6 June 2025
2

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

6 June 2025

Internet Access

Updated

Learn about how Microsoft Entra Internet Access secures access to the Internet.

6 June 2025
1
1

Event Enrichment Logs

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

6 June 2025
9

Ciphers

Updated

Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.

8 June 2025

Enable Multi Geo

Updated

Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.

8 June 2025

Configure Connectors

Updated

Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.

6 June 2025

Configure Quick Access

Updated

Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.

6 June 2025

Manage Private Access Profile

Updated

Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.

6 June 2025
3

Connector Groups

Updated

Learn how Microsoft Entra private network connector groups work and how they're used by Microsoft Entra Private Access and application proxy.

6 June 2025

Connectors

Updated

Learn how Microsoft Entra private network connectors work and how they're used by Microsoft Entra Private Access and application proxy.

6 June 2025

Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

6 June 2025
1

Configure Per App Access

Updated

Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.

6 June 2025
1

Verified helpdesk with Microsoft Entra Verified ID

Updated

An ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Traditional methods such as personally identifiable information (PII) and knowledge-based authentication are no match for today’s sophisticated attackers, who use phishing, social engineering, and even AI-powered voice cloning to bypass defenses. The consequences are serious: under pressure, helpdesk agents may unintentionally expose sensitive data or authorize fraudulent actions.

4 June 2025
1

Entra Admin Center

Updated

* [Credentials](~/verified-id/verifiable-credentials-configure-tenant-quick.md)

6 June 2025
1

Microsoft Entra Verified ID Identity Verification partners

Updated

Our Identity Verification (IDV) partner network extends Microsoft Entra Verified ID capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable scenarios like remote onboarding with government ID checks using identity verification and proofing services.

4 June 2025
1

Partner Gallery

Updated

1. Set up Microsoft Entra Verified ID Service: using [Quick setup](verifiable-credentials-configure-tenant-quick.md) or [Advanced setup instructions](verifiable-credentials-configure-tenant.md).

5 June 2025
1
1

Copilot Security Entra Investigate Risky Apps

Updated

Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.

6 June 2025
1
1

userimpact: Low

Updated

Azure Logic Apps integrated with Microsoft Entra Identity Governance create a significant attack surface when access controls are inadequate. Threat actors can exploit misaligned permissions between Logic Apps management roles and Microsoft Entra directory roles to gain initial access through compromised accounts with excessive Azure RBAC permissions. With access, threat actors can modify workflow logic to insert malicious automation into provisioning processes, then use managed identities and existing connections for lateral movement across connected systems.

7 June 2025
1
35

China User Support

Updated

Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.

8 June 2025

Create Remote Networks

Updated

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

8 June 2025

Manage Microsoft Profile

Updated

Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.

6 June 2025

Manage Remote Networks

Updated

Learn how to update and delete remote networks for Global Secure Access.

6 June 2025

Quickstart Install Client

Updated

Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.

6 June 2025

Quickstart Per App Access

Updated

Learn how to configure per-app access to private resources in Global Secure Access.

6 June 2025

Quickstart Quick Access

Updated

Learn how to configure Quick Access to private resources in Global Secure Access.

6 June 2025

Remote Network Configurations

Updated

Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.

6 June 2025

Role Based Permissions

Updated

Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.

6 June 2025
11

Cisco Coexistence

Updated

Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.

6 June 2025

Netskope Coexistence

Updated

Microsoft and Netskope’s Security Service Edge (SSE) coexistence solution guide.

6 June 2025

What Is Global Secure Access

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

6 June 2025

Netskope Integration

Updated

A comprehensive guide for configuring and testing the integration between Microsoft's and Netskope's Secure Access Service Edge (SASE) solutions.

6 June 2025

Partner Ecosystems Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

6 June 2025

Remote Network Connectivity

Updated

Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.

6 June 2025

Traffic Dashboard

Updated

Monitor the health and status of your network traffic with the Global Secure Access dashboard.

6 June 2025

Traffic Forwarding

Updated

Learn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.

6 June 2025

Connectors

Updated

For more information about optimizing your network, see [Network topology considerations when using Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).

5 June 2025

Transport Layer Security

Updated

To get started with TLS inspection, see [Configure Transport Layer Security](how-to-transport-layer-security.md).

4 June 2025
6

Access Audit Logs

Updated

Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.

6 June 2025

View Traffic Logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

6 June 2025

Remote Network Health Logs

Updated

Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.

6 June 2025

Use Workbooks

Updated

Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.

6 June 2025

View Enriched Logs

Updated

Learn how to use enriched Microsoft 365 logs for Global Secure Access.

6 June 2025
6

Troubleshoot Distributed File System

Updated

A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.

6 June 2025
4

Powershell Add Ia Devicecompliance Bypasses

Updated

The [Universal Conditional Access documentation](../concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authoriziation limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertenty lock users out from accessing anything on their machine.

8 June 2025

Quickstart Remote Network

Updated

Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.

6 June 2025
2
2

Palo Alto Coexistence

Updated

Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.

6 June 2025
4

Microsoft Security Copilot agents in Microsoft Entra

Updated

Agents fit naturally into existing workflows. You don't need special training or other licensing to use them. Agents utilize SCUs to operate just like other features in the product. They integrate seamlessly with Microsoft Security solutions and the broader supported partner ecosystem. Agents learn based on feedback and keep you in control on the actions it takes. They handle resource-intensive tasks like threat intelligence briefings, and Conditional Access optimization. With Microsoft Security Copilot agents, you can scale up your teams, people, and processes.

5 June 2025
3

Microsoft Security Copilot agents in Microsoft Entra

Updated

Microsoft Entra agents work seamlessly with [Microsoft Security Copilot](/copilot/security/microsoft-security-copilot). Microsoft Security Copilot agents automate repetitive tasks and reduce manual workloads. They enhance security and IT operations across cloud, data security and privacy, identity, and network security. These agents handle high-volume, time-consuming tasks by pairing data and code with an AI language model. They respond to user requests and system events, helping teams work more efficiently and focus on higher-impact tasks.

6 June 2025
1

Copilot Entra Security Scenarios

Updated

Microsoft Entra Health provides look-back reporting on Service Level Agreements (SLA) for authentication availability for your Microsoft Entra tenant. The SLA Attainment is a monthly look-back solution that shows the core authentication availability of Microsoft Entra ID each month. IT admins often need to review the SLA reports in conjuntion with service outages. Security Copilot interacts with the Microsoft Entra SLA using the Microsoft Graph API.

8 June 2025
1
1