author: justinha
Workload ID retirement sets a 31 March 2026 authentication deadline; Conditional Access safety guidance is the main operational theme
Among the supplied changes for the week of 2 June 2025, the updated Workload ID page "Retire Service Principal Less Authentication" is the clearest administrator-impacting item: it says action is required before 31 March 2026 to avoid application authentication failure. Other meaningful exceptions are Security Copilot's Conditional Access agent and troubleshooting material, Global Secure Access's forwarding-profile lockout warning paired with an Internet Access break-glass sample, and Entra Health and ID Governance guidance. The record is otherwise documentation-heavy—924 updates, 21 new items, 9 removals, and no Message Center entries. The supplied MFA, passwordless, certificate-authentication, and External ID entries do not establish a new feature, Preview, GA release, or tenant-wide behavior change.
- Workload ID documents a service-principal authentication retirement
Workload ID · Authentication
The updated page titled "Retire Service Principal Less Authentication" explicitly says administrators must act before March 31, 2026 to avoid application authentication failure. This is a retirement and potential behavior-change item rather than ordinary documentation maintenance. The supplied evidence does not identify the affected application patterns or migration steps, so the supported action is to identify dependencies and consult the full retirement guidance.
- Security Copilot documents a Conditional Access optimization and troubleshooting path
Security Copilot · Conditional Access
A new page covers troubleshooting Conditional Access policies and Security Copilot, while related updates describe an optimization agent that recommends policies and changes aligned with Zero Trust guidance. The troubleshooting material also covers creating, assigning, and diagnosing policies with custom security attributes, and the agents overview says the agents use SCUs within Microsoft Security workflows. These records document use of the capability; they do not state that it is a Preview or GA launch.
- Global Secure Access documents a forwarding-profile lockout risk, with related Internet Access break-glass guidance
Internet Access · General
The updated Global Secure Access guidance calls out known tunnel-authorization limitations: blocking a forwarding profile in Conditional Access can inadvertently prevent users from accessing anything on their machine. A related Internet Access PowerShell sample covers disabling traffic forwarding and Conditional Access policies using the compliant-network condition in a break-glass scenario. This is a safety clarification and recovery reference, not evidence that the limitation was newly introduced.
- Entra Health guidance focuses on MFA, SAML, and Conditional Access policy health scenarios
Entra ID · Conditional Access
Updated Entra ID pages describe Microsoft Entra Health signals and alerts for sign-ins requiring MFA, sign-ins to SAML-authenticated applications, and Conditional Access block-policy health. A related Security Copilot scenario describes monthly look-back reporting for Microsoft Entra authentication availability and SLA attainment through Microsoft Graph. The supplied records provide monitoring guidance but no evidence of a new signal, SLA change, or availability milestone.
- ID Governance links access reviews to Conditional Access exclusions
ID Governance · Conditional Access
The updated "Manage users excluded from Conditional Access policies" guidance directs administrators to use access reviews to manage excluded users. This is concrete governance and security guidance for an existing Conditional Access control, not a stated new enforcement behavior or rollout. Organizations that permit such exclusions should consult this procedure when managing them.
Identify applications that depend on the Workload ID behavior named in the retirement page and follow the full guidance before the stated deadline; the supplied record does not provide migration steps. For Global Secure Access and Internet Access, account for the forwarding-profile Conditional Access limitation and use the documented break-glass procedure when relevant. If the tenant uses Security Copilot's Conditional Access agent or maintains Conditional Access exclusions, the new troubleshooting and access-review pages are the relevant operational references. Nothing in the supplied updates supports a blanket tenant configuration change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
505 updatesauthor: justinha
Migrate applications away from secret-based authentication to improve security and user experience.
Learn about the differences between the Microsoft Authentication Library (MSAL) and Azure AD Authentication Library (ADAL) and how to migrate to MSAL.
author: justinha
author: justinha
author: justinha
author: justinha
author: najshahid
author: justinha
author: najshahid
Deployment frequently asked questions (FAQs) for hybrid FIDO2 security keys in Microsoft Entra ID
Updatedauthor: justinha
author: justinha
author: justinha
Mfa Server Migration Utility
Updatedauthor: justinha
author: justinha
author: camilasinelli
author: justinha
Learn about the Microsoft Entra Health signals and alerts for sign-ins that require Microsoft Entra multifactor authentication
Learn about the Microsoft Entra Health signals and alerts for sign-ins to applications that use SAML authentication
Learn how to build a desktop app that calls web APIs to acquire a token for the app using integrated Windows authentication
author: justinha
author: inbarckMS
Authentication Passwordless
Updatedauthor: justinha
author: aanjusingh
author: inbarckms
author: justinha
author: vimrang
author: vimrang
author: vimrang
author: vimrang
author: justinha
author: vimrang
author: justinha
author: justinha
author: vimrang
author: justinha
author: justinha
author: justinha
author: gregkmsft
author: justinha
author: aanjusingh
author: justinha
author: aanjusingh
author: justinha
author: justinha
author: justinha
author: mepples21
Learn how to edit profile with multifactor authentication protection in your external-facing Node.js web app
Enforce Microsoft Entra multifactor authentication with legacy applications using app passwords
Updatedauthor: justinha
author: justinha
author: justinha
author: justinha
author: sopand
author: justinha
author: justinha
author: justinha
author: tilarso
author: justinha
author: justinha
author: justinha
Microsoft Entra user data collection for multifactor authentication and self-service password reset
Updatedauthor: justinha
Find out how to use native authentication APIs to authenticate users into your customer-facing apps with the external tenant.
Learn how apps that use native authentication notify Microsoft Entra about the authentication methods that they support.
Learn how to use native authentication Android and iOS SDK attribute builders to prepare built-in and custom attributes.
Learn how you can use web fallback to improve the resilience of your customer apps that use native authentication.
author: justinha
author: mepples21
author: mepples21
Learn how to configure a sample web app to edit user's profile. The edit profile operation requires a customer user to complete multifactor authentication (MFA)
Register Passkey
Updatedauthor: justinha
author: justinha
Register Passkey Mobile
Updatedauthor: justinha
author: brozbab
Learn how to secure remote access to VMs using Network Policy Server (NPS) and Microsoft Entra multifactor authentication with a Remote Desktop Services deployment in a Microsoft Entra Domain Services managed domain.
Learn how to set up your Node.js web application for profile editing with multifactor authentication protection in your external tenant
Learn how to set up a reverse proxy for a single-page app that calls native authentication API by using Azure Function App.
Sign In Passkey
Updatedauthor: justinha
author: justinha
Learn how to configure a sample React single-page app (SPA) that uses native authentication API to sign up users.
author: justinha
author: inbarckms
Learn how to acquire multiple access tokens and call an API in Android app by using native authentication.
Learn how to build a React single-page app that reset password for users in an external tenant by using native authentication.
Learn how to set up a CORS proxy server for single-page application that uses native authentication API.
Learn how to build a React single-page app that signs in users in a React single-page app into an external tenant by using native authentication.
Learn how to build a React single-page application that uses native authentication API to sign up users.
Learn how to build a Node.js CLI app that signs in users in an external tenant
Prepare an Angular single-page app (SPA) in a Microsoft Entra tenant to manage authentication and secure user access.
Sign in user in an Angular single-page app (SPA) in a Microsoft Entra tenant to manage authentication and secure user access.
Learn how to set up Azure Front Door as a reverse proxy in a production environment for a single-page app that uses native authentication.
Learn how to use client certificate instead of secrets for authentication in your Node.js web app
Use Custom Domain Url
UpdatedUse a custom domain to fully brand the authentication URL. From a user perspective, users remain on your domain during the authentication process, rather than being redirected to *ciamlogin.com* domain name.
In this quickstart, you learn how to implement authentication with a Node.js web app and the Microsoft Authentication Library (MSAL) for Node.js.
author: justinha
author: HULKsmashGithub
Howto Mfa Mfasettings
Updatedauthor: justinha
Mfa Data Residency
UpdatedMicrosoft Entra ID stores customer data in a geographical location based on the address an organization provides when subscribing to a Microsoft online service such as Microsoft 365 or Azure. For information on where your customer data is stored, see [Where your data is located](https://www.microsoft.com/trust-center/privacy/data-location) in the Microsoft Trust Center.
Fido2 Compatibility
Updatedauthor: justinha
Learn about the Microsoft Entra Health signals and alerts for sign-ins that require a compliant or managed device
author: justinha
Learn how to build a desktop app that calls web APIs to acquire a token for the app using username and password.
author: justinha
author: vimrang
Learn how and why to use fine-grained password policies to secure and control account passwords in a Domain Services managed domain.
author: justinha
author: justinha
author: efdake
author: justinha
author: justinha
In this tutorial, learn how to enable password hash synchronization using Microsoft Entra Connect to a Microsoft Entra Domain Services managed domain.
Feature Availability
Updatedauthor: justinha
author: justinha
Howto Mfa Adfs
Updatedauthor: justinha
Howto Mfa Nps Extension
Updatedauthor: justinha
Howto Mfa Nps Extension Vpn
Updatedauthor: justinha
Howto Mfa Reporting
Updatedauthor: justinha
Howto Mfa Userstates
Updatedauthor: justinha
author: justinha
author: justinha
author: justinha
Howto Password Smart Lockout
Updatedauthor: justinha
Howto Sspr Customization
Updatedauthor: justinha
Howto Sspr Reporting
Updatedauthor: justinha
Howto Sspr Windows
Updatedauthor: justinha
author: justinha
author: justinha
Learn about how to administer a Microsoft Entra Domain Services managed domain and the behavior of user accounts and passwords
Mfa Licensing
Updatedauthor: justinha
Mfa Regional Opt In
Updatedauthor: justinha
Mfa Registration Campaign
Updatedauthor: mjsantani
Mfa Telephony Fraud
Updatedauthor: aloom3
author: justinha
Password Ban Bad
Updatedauthor: justinha
Password Ban Bad On Premises
Updatedauthor: justinha
Learn how to prepare your external tenant to sign in users and call an API in your Node.js web application.
Learn how to configure a Node.js web app code sample to sign in users and call an API in an external tenant.
Learn how to authenticate users in a sample Node.js Command Line Interface (CLI) application in your external tenant
Web app quickstart that shows how to configure a sample web app that signs in employees in workforce tenant or customers in external tenant
Quickstart V2 Java Webapp
UpdatedIn this quickstart, you'll learn how to add sign-in with Microsoft to a Java web application by using OpenID Connect.
author: justinha
Learn how to disable weak ciphers, old protocols, and NTLM password hash synchronization for a Microsoft Entra Domain Services managed domain.
Set up node web app project that signs in users into customer facing app by in an external tenant or employees in a workforce tenant
Sspr Policy
Updatedauthor: justinha
Learn how to troubleshoot common problems when you try to domain-join a VM or connect an application to Microsoft Entra Domain Services and you can't connect or authenticate to the managed domain.
Learn how to troubleshoot common user sign-in problems and errors in Microsoft Entra Domain Services.
Troubleshoot Sspr Writeback
Updatedauthor: justinha
author: justinha
Tutorial: Add add sign-in in your Node/Express.js web app by using Microsoft identity platform
UpdatedLearn how to add sign-in in your Node.js web app with an external tenant or workforce tenant by using Microsoft identity platform.
In this tutorial, learn how to add Shared Device Mode support to an Android device using the Microsoft Authenticator App or Intune
Learn how to authenticate users in a Node.js CLI application registered in an external tenant
Two-way SMS unsupported
Updatedauthor: rhicock
Learn how to acquire an access token for calling an API in your own Node.js web application.
In this quickstart, you learn how an app implements Microsoft sign-in on an ASP.NET Core web app by using OpenID Connect
In this quickstart, you'll learn how to add sign-in with Microsoft to a Java web application by using OpenID Connect.
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/exempted.png" alt-text="Screenshot of CAs that are exempted from CRL validation." :::
author: justinha
Authentication Passwordless
UpdatedPlatform Credential for macOS allows users to go passwordless by configuring Touch ID to unlock the device, and uses phish-resistant credentials, based on Windows Hello for Business technology. This saves customer organizations money by removing the need for security keys and advances Zero Trust objectives using integration with the Secure Enclave.
Learn how to provide single sign-on (SSO) for on-premises applications that are secured with Security Assertion Markup Language (SAML) authentication. Provide remote access to on-premises apps with application proxy.
What Is App Proxy
UpdatedUnderstand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedLearn how to provide single sign-on for on-premises applications that are secured with header-based authentication.
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
Learn how to resolve common access issues with Microsoft Entra application proxy applications.
Turn on single sign-on for your published on-premises applications with Microsoft Entra application proxy in the Microsoft Entra admin center.
author: justinha
Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.
Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.
Non-interactive sign-in logs
UpdatedLearn about the type of activity captured in the non-interactive sign-in logs in Microsoft Entra monitoring and health.
Learn about the type of information captured in the interactive user sign-in logs in Microsoft Entra monitoring and health.
Signin Account Support
UpdatedHow on-screen messaging reflects username lookup during sign-in
Sspr Policy
Updated| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |
How on-screen messaging reflects username lookup during sign-in in Microsoft Entra ID
In this article, learn how to create and configure a Microsoft Entra Domain Services forest trust to an on-premises Active Directory Domain Services environment using Azure PowerShell.
author: shlipsey3
author: shlipsey3
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: shlipsey3
author: shlipsey3
author: HULKsmashGithub
Agent Optimization
Updatedauthor: MicrosoftGuyJFlo
Delegate By Task
Updated> [!div class="mx-tableFixed"]
Learn how to the SKU tier for a Microsoft Entra Domain Services managed domain if your business requirements change
Learn how to check fleet metrics of a Microsoft Entra Domain Services managed domain.
Learn how to check the health of a Microsoft Entra Domain Services managed domain and understand status messages.
Learn about some of the common scenarios and use-cases for Microsoft Entra Domain Services to provide value and meet business needs.
Learn how to configure an app's publisher domain to let users know where their information is being sent.
Learn how to create and manage a custom Organizational Unit (OU) in a Microsoft Entra Domain Services managed domain.
Learn how to disable, or delete, a Microsoft Entra Domain Services managed domain
Learn how to configure email notifications to alert you about issues in a Microsoft Entra Domain Services managed domain
Learn how to configure and enable Microsoft Entra Domain Services using an Azure Resource Manager template.
Learn how to configure and enable Microsoft Entra Domain Services using Microsoft Graph PowerShell and Azure PowerShell.
Feature Availability
Updatedauthor: justinha
author: kengaderdus
Learn how to create a group managed service account (gMSA) for use with Microsoft Entra Domain Services managed domains
How It Works Daemon App
Updatedauthor: kengaderdus
author: Dickson-Mwendia
include file
Learn how to retrieve data from Microsoft Entra Domain Services.
Learn how to configure and join a CoreOS virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to configure and join a Red Hat Enterprise Linux virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to configure and join a SUSE Linux Enterprise virtual machine to a Microsoft Entra Domain Services managed domain.
Join a Windows Server VM to a Microsoft Entra Domain Services managed domain | Microsoft Docs
UpdatedIn this tutorial, learn how to join a Windows Server virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to configure and join an Ubuntu Linux virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to enable resource-based Kerberos constrained delegation (KCD) in a Microsoft Entra Domain Services managed domain.
Known Limitations Include
Updatedauthor: HULKsmashGithub
Macos Psso
Updatedauthor: garrodonnell
author: garrodonnell
Learn how to install the DNS Server Tools to manage DNS and create conditional forwarders for a Microsoft Entra Domain Services managed domain.
Learn about some of the virtual network design considerations and resources used for connectivity when you run Microsoft Entra Domain Services.
Sample Daemon App Output
Updatedauthor: kengaderdus
Select Tenant Type Statement
Updatedauthor: kengaderdus
Learn about the different health states for a Microsoft Entra Domain Services managed domain and how to restore a suspended domain.
In this tutorial, you learn how to configure secure lightweight directory access protocol (LDAPS) for a Microsoft Entra Domain Services managed domain.
In this tutorial, you learn how to create and configure an Azure virtual network subnet or network peering for a Microsoft Entra Domain Services managed domain using the Microsoft Entra admin center.
Tutorial - Create a customized Microsoft Entra Domain Services managed domain | Microsoft Docs
UpdatedIn this tutorial, you learn how to create and configure a customized Microsoft Entra Domain Services managed domain and specify advanced configuration options using the Microsoft Entra admin center.
In this tutorial, you learn how to create and configure a Windows virtual machine that you use to administer Microsoft Entra Domain Services managed domain.
In this tutorial, you learn how to create and configure a Microsoft Entra Domain Services managed domain using the Microsoft Entra admin center.
Learn how to create and use replica sets in the Microsoft Entra admin center for service resiliency with Microsoft Entra Domain Services
Tutorial - Perform a disaster recovery drill in Microsoft Entra Domain Services | Microsoft Docs
UpdatedLearn how to perform a disaster recovery drill using replica sets in Microsoft Entra Domain Services
Tutorial Create Forest Trust
UpdatedLearn how to create a one-way outbound forest to an on-premises AD DS domain in the Microsoft Entra admin center for Microsoft Entra Domain Services
Learn how extract user data using an Angular single-page app (SPA).
Learn how to use Azure Resource Manager templates to join a new or existing Windows Server VM to a Microsoft Entra Domain Services managed domain.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Configure User Consent
Updated- A user account. If you don't already have one, you can [create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
Mysdworxcom Tutorial
Updated* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.
Use administrative units for more granular delegation of permissions in Microsoft Entra ID.
Prerequisites to use PowerShell or Graph Explorer for Microsoft Entra roles.
Use restricted management administrative units for more sensitive resources in Microsoft Entra ID.
Learn about the limitations when you work with multitenant organizations in Microsoft Entra ID.
Learn about multitenant organization optional policy templates in Microsoft Entra ID.
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
Mysdworxcom Tutorial
Updated* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.
A Microsoft Entra documentation page was updated: Licensing Groups Migrate Users.
A Microsoft Entra documentation page was updated: Licensing Groups Migrate Users.
Search and filter groups members and owners in Microsoft Entra.
Add users to a dynamic group
UpdatedUse groups with user membership rules to add or remove users automatically
Explains how to enable or disable LinkedIn integration account connections in Microsoft apps in Microsoft Entra ID
How to take over a Domain name DNS domain name in an unmanaged Microsoft Entra organization (shadow tenant).
Learn how to convert existing membership groups from static to dynamic by using either the Azure portal or PowerShell cmdlets.
Understanding the data independence of your Microsoft Entra organizations
You can convert users from external to internal without the need to recreate them.
Learn how to create or update rules for dynamic membership groups in the Azure portal and check their processing status.
Learn how to prepare a Microsoft Entra tenant, including a self-service tenant, for deletion.
The relationship between older delegated admin permissions and new granular delegated admin permissions in Microsoft Entra ID
Usage constraints and other service limits for the Microsoft Entra service
Learn how to set up a naming policy for Microsoft 365 groups in Microsoft Entra ID.
* [Settings and data roaming FAQ](enterprise-state-roaming-faqs.yml)
To configure Single Sign-On on **Equinix Federation App** side, please follow the [link](https://docs.equinix.com).
Groups Bulk Download
UpdatedDownload group properties in bulk in the Azure admin center in Microsoft Entra ID.
Groups Bulk Download Members
Updatedauthor: barclayn
Groups Bulk Import Members
UpdatedAdd group members in bulk by using a comma-separated values (CSV) file.
Groups Bulk Remove Members
UpdatedRemove group members in bulk operations by using a comma-separated values (CSV) file.
Groups Dynamic Membership
UpdatedLearn how to manage rules for dynamic membership groups to automatically populate group members and rule references.
Learn how to optimize your membership rules to automatically populate groups.
Learn how to test members against a rule for a dynamic membership groups in Microsoft Entra ID.
Groups Quickstart Expiration
UpdatedExpiration for Microsoft 365 groups
Explains how to add new users or delete existing users in Microsoft Entra ID
Groups Settings Cmdlets
UpdatedHow to manage the settings for groups using Microsoft Entra cmdlets
Groups Settings V2 Cmdlets
UpdatedThis page provides PowerShell examples to help you manage your groups in Microsoft Entra ID
Licensing Admin Center
Updatedkeywords: Azure AD licensing
keywords: Entra ID licensing
Linkedin User Consent
UpdatedExplains how LinkedIn integration shares data via Microsoft apps in Microsoft Entra ID
Learn how to restore a deleted group, view restorable groups, and permanently delete a group in Microsoft Entra ID.
Scenarios, limitations, and known issues using groups to manage licensing in Microsoft Entra ID
UpdatedMore scenarios limitations, and known issues for Microsoft Entra group-based licensing
Use self-service sign-up in a Microsoft Entra organization
Learn how dynamic group management works.
User management enhancements
UpdatedDescribes how Microsoft Entra ID enables user search, filtering, and more information about your users.
Users Bulk Add
UpdatedAdd users in bulk in Microsoft Entra ID
Users Bulk Delete
UpdatedDelete users in bulk in Microsoft Entra ID
Users Bulk Download
UpdatedDownload user records in bulk in the Azure admin center in Microsoft Entra ID.
Users Bulk Restore
UpdatedRestore deleted users in bulk in the Azure portal in Microsoft Entra ID
Restrict guest user access permissions using the Azure portal, PowerShell, or Microsoft Graph in Microsoft Entra ID
Users Revoke Access
Updatedauthor: barclayn
Users Sharing Accounts
UpdatedDescribes how Microsoft Entra ID enables organizations to securely share accounts for on-premises apps and consumer cloud services.
A Microsoft Entra documentation page was updated: Enterprise State Roaming Windows Settings Reference.
A Microsoft Entra documentation page was updated: Licensing Groups Assign.
Licensing Groups Assign
RemovedA Microsoft Entra documentation page was updated: Licensing Groups Assign.
A Microsoft Entra documentation page was updated: Licensing Groups Resolve Problems.
A Microsoft Entra documentation page was updated: Licensing Groups Resolve Problems.
A Microsoft Entra documentation page was updated: Licensing Ps Examples.
Licensing Ps Examples
RemovedA Microsoft Entra documentation page was updated: Licensing Ps Examples.
Microsoft Edge browser setting group (favorites, reading list) syncing is managed through the Microsoft Edge browser Settings menu option.
author: HULKsmashGithub
Learn how to build a desktop app that calls web APIs to acquire a token for the app by using Web Account Manager.
Learn how to build a desktop app that calls web APIs to acquire a token for the app interactively.
Learn how to build a desktop app that calls web APIs to acquire a token for the app using device code flow
Learn how to build a daemon app that calls web APIs (acquiring tokens)
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
Deploy Azure App Proxy
UpdatedWith Microsoft Entra Domain Services, you can lift-and-shift legacy applications running on-premises into Azure. Microsoft Entra application proxy then helps you support remote workers by securely publishing those internal applications part of a Domain Services managed domain so they can be accessed over the internet.
Learn how to build a daemon app that calls a web API.
Learn how to configure the code for your daemon application that calls web APIs (app configuration)
In this quickstart, learn how a JavaScript single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow.
In this quickstart, learn how a JavaScript Angular single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
In this quickstart, learn how a JavaScript React single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
Learn about how to prepare your Node.js client daemon app, then configure it to acquire an access token for calling a web API.
Download and run a code sample that shows how an ASP.NET web app can sign in Microsoft Entra users.
Grant permissions for application access management in Microsoft Entra ID
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Add an on-premises application for remote access through application proxy in Microsoft Entra ID.
UpdatedMicrosoft Entra ID has an application proxy service that enables users to access on-premises applications by signing in with their Microsoft Entra account. This tutorial shows you how to prepare your environment for use with application proxy. Then, it uses the Microsoft Entra admin center to add an on-premises application to your Microsoft Entra tenant.
How to publish on-premises ASP.NET applications that accept Active Directory Federation Services claims for secure remote access by your users.
Understand complex applications in Microsoft Entra application proxy.
Configure Sso
UpdatedUnderstand single sign-on with an on-premises app using application proxy.
Configure and manage custom domains in Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Learn about debugging issues that occur when configuring Microsoft Entra application proxy.
Covers the basics about how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Covers the basics about how to integrate on-premises SharePoint Server with Microsoft Entra application proxy.
How traffic distribution works with your application proxy deployment. Includes tips for how to optimize connector performance and use load balancing for back-end servers.
Covers how to provide single sign-on using Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Publish native client apps
UpdatedCovers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.
Covers how to configure application proxy with Remote Desktop Services (RDS)
Remove personal data from connectors installed on devices for Microsoft Entra application proxy.
Learn how to identify and resolve cross-origin resource sharing (CORS) issues in Microsoft Entra application proxy.
Learn how to redirect hard coded links for applications published with Microsoft Entra application proxy.
Learn how to use Wildcard applications in Microsoft Entra application proxy.
Covers how to work with existing on-premises proxy servers with Microsoft Entra ID.
This article shows the new and updated documentation for the Microsoft Entra application management.
Learn how to use groups in Microsoft Entra ID to assign access to SaaS applications that are integrated with Microsoft Entra ID.
Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.
Learn more about how forest trust work with Microsoft Entra Domain Services
The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.
In this overview, you compare the different identity offerings for Active Directory Domain Services, Microsoft Entra ID, and Microsoft Entra Domain Services.
Learn how to create and manage custom attributes in a Domain Services managed domain.
Learn about where Microsoft Entra ID stores identity-related data for its European customers.
Learn about where Microsoft Entra ID stores customer-related data for its Japan customers.
Frontline Worker Management
Updatedauthor: csmulligan
In this overview, learn what Microsoft Entra Domain Services provides and how to use it in your organization to provide identity services to applications and services in the cloud.
Learn what replica sets are in Microsoft Entra Domain Services and how they provide redundancy to applications that require identity services.
Use Microsoft Entra groups to simplify role assignment management in Microsoft Entra ID.
Learn about protected actions in Microsoft Entra ID.
Describes overview of HR driven provisioning.
Copilot in Microsoft Entra
Updated**Applies to:** Microsoft Entra 
Learn about the multitenant organization scenario and capabilities in Microsoft Entra ID.
Learn how to use Microsoft Entra application proxy connectors.
Learn about cross-tenant synchronization in Microsoft Entra ID.
Learn about multitenant organizations in Microsoft Entra ID and Microsoft 365.
An introduction to how you can use Microsoft Entra ID to automatically provision, deprovision, and continuously update user accounts across multiple third-party applications.
A Microsoft Entra documentation page was updated: Copilot Entra Recommendations.
>
Describes overview of identity provisioning and the ILM scenarios.
author: shlipsey3
Isolate unsanctioned tenants using Microsoft Entra features. Follow steps to quarantine unapproved tenants and strengthen security.
Licensing Preview Info
UpdatedIn this article we go over the information in effect when participating in Microsoft Entra ID preview programs.
Whats New
Updated**Type:** New feature
Recommendations
Updated| Recommendation | Impacted resources | Availability | Identity Secure Score | Target roles for email notifications |
Management concepts and how-tos for managing a domain name in Microsoft Entra ID
and devices in the Microsoft Entra admin portal could time out and fail on large
Data Storage Australia
UpdatedLearn about where Microsoft Entra ID stores identity-related data for
Learn about where Microsoft Entra ID stores customer-related data for
Default user permissions
UpdatedCompare the default user permissions available in Microsoft Entra ID and learn how to restrict access.
The relationship between users and licenses assigned, administrator roles, dynamic membership groups in Microsoft Entra ID
Group Based Licensing
UpdatedLearn about Microsoft Entra group-based licensing, including how it works,
How to identify and resolve license assignment problems when you're using Microsoft Entra group-based licensing.
Microsoft Entra licensing
UpdatedThis article documents licensing requirements for Microsoft Entra features.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Instructions about how to search for and view your organization's groups
Sign up for premium editions
UpdatedInstructions about how to sign up for Microsoft Entra ID P1 or P2 editions.
Sign Up Organization
UpdatedLearn about the options to sign up your organization to use Azure and
Instructions about how to unblock a tenant.
Try Microsoft Entra Suite
UpdatedMake the most of your Microsoft Entra Suite trial. Try out some of the
What is Microsoft Entra ID?
UpdatedLearn about Microsoft Entra ID, including terminology, available licenses, and a list of associated features.
- Except for credentials information, the synchronization configuration stored in the ADSync database is automatically recovered and used during installation. This includes custom synchronization rules, connectors, filtering, and optional features configuration.
Learn how to configure a Microsoft Entra Domain Services managed domain to support profile synchronization for SharePoint Server
Learn how the synchronization process works between Microsoft Entra ID or an on-premises environment to a Microsoft Entra Domain Services managed domain.
Learn how to use the Microsoft Entra admin center to configure scoped synchronization from Microsoft Entra ID to a Microsoft Entra Domain Services managed domain
Learn how to use Microsoft Graph PowerShell to configure scoped synchronization from Microsoft Entra ID to a Microsoft Entra Domain Services managed domain
This article lists all releases of Microsoft Entra Connect Provisioning Agent and describes new features and fixed issues.
Export a Microsoft Identity Manager connector for use with the Microsoft Entra ECMA Connector Host
UpdatedDescribes how to create and export a connector from MIM Sync to be used with the Microsoft Entra ECMA Connector Host.
This document describes how to configure Microsoft Entra ID to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer REST and SOAP APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer web services based APIs.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory.
This tutorial describes how to provision users from Microsoft Entra ID into a SQL database.
Preparing for Microsoft Entra provisioning to Active Directory Lightweight Directory Services
UpdatedThis document describes how to configure Microsoft Entra ID to provision users into Active Directory Lightweight Directory Services as an example of an LDAP directory.
Provisioning users into SQL based applications using the ECMA Connector host
Use partner driven integrations to provision accounts into all your applications.
When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
Learn how to use scoping filters to define attribute-based rules that determine which users or groups are provisioned in Microsoft Entra ID.
Learn how to export your Application Provisioning configuration and roll back to a known good state for disaster recovery in Microsoft Entra ID.
Expression Builder
UpdatedUnderstand how expression builder works with Application Provisioning in Microsoft Entra ID.
Find out when a specific user is able to access an app in Microsoft Entra Application Provisioning
UpdatedHow to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
How Provisioning Works
UpdatedUnderstand how Application Provisioning works in Microsoft Entra ID.
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID
Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
The Microsoft Entra provisioning service matches users in Microsoft Entra ID with users already in an application. In some cases, an application may have users that do not match with any in Microsoft Entra ID.
Learn how multitenant organizations identity provisioning and Microsoft 365 work together.
Learn how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and give them access to SAP ECC, SAP S/4HANA, and other apps.
Learn how to provision users on demand in Microsoft Entra ID.
Learn how to retrieve pronoun information from Workday
Learn which attributes from SuccessFactors are supported by SuccessFactors-HR driven provisioning in Microsoft Entra ID.
Technical deep dive into SAP SuccessFactors-HR driven provisioning for Microsoft Entra ID.
Learn how to override the default behavior of deprovisioning out of scope users in Microsoft Entra ID.
Learn about attribute mappings for Software as a Service (SaaS) apps in Microsoft Entra Application Provisioning. Learn what attributes are and how you can modify them to address your business needs.
Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
When configuring user provisioning with Microsoft Entra ID and SaaS apps, use the directory extension feature to add source attributes that aren't synchronized by default.
Workday Attribute Reference
UpdatedLearn which attributes that you can fetch from Workday using XPATH queries in Microsoft Entra ID.
In this quickstart, learn how a Universal Windows Platform (UWP) application can get an access token and call an API protected by Microsoft identity platform.
Learn how to build a daemon app that calls web APIs - app registration
Learn how to log errors and exceptions in MSAL.js
Describes how to mark an app as publisher verified. When an application is marked as publisher verified, it means that the publisher (application developer) verified the authenticity of their organization using a Cloud Partner Program (CPP) account that completed the verification process and associated this CPP account with that application registration.
Learn about the UserInfo endpoint on the Microsoft identity platform.
Learn about benefits, program requirements, and frequently asked questions in the publisher verification program for the Microsoft identity platform.
A daemon app code sample quickstart that shows how to acquire an access token to call a protected web API by using Microsoft identity platform
Quickstart V2 Java Daemon
UpdatedIn this quickstart, you learn how a Java app can get an access token and call an API protected by Microsoft identity platform endpoint, using the app's own identity
Describes how to troubleshoot publisher verification for the Microsoft identity platform by calling Microsoft Graph APIs.
Learn how to acquire an access token in a Node/Express.js web to read user's profile detail from Microsoft Graph API
Protect the endpoint of an API, then run it to ensure it's listening for HTTP requests.
Learn how to call a web API whose endpoints are protected using the Microsoft identity platform
In this quickstart, you download and modify a code sample that demonstrates how to protect an ASP.NET Core web API by using the Microsoft identity platform for authorization.
In this quickstart, learn how to call an ASP.NET web API that's protected by the Microsoft identity platform from a Windows Desktop (WPF) application.
In this quickstart, learn how a Python web app can sign in users, get an access token from the Microsoft identity platform, and call the Microsoft Graph API.
- Application ID URI
App consent permissions for custom Microsoft Entra roles in the Microsoft Entra admin center, PowerShell, or Graph API.
Enterprise app permissions for custom Microsoft Entra roles in the Microsoft Entra admin center, PowerShell, or Graph API.
Assign Microsoft Entra roles
UpdatedLearn how to assign Microsoft Entra roles to users and groups at tenant, application registration, administrative unit scopes using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
Learn how to create a custom role to manage access to Microsoft Entra resources using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API
Learn how to a role-assignable group in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
Group management permissions for Microsoft Entra custom roles in the Microsoft Entra admin center, PowerShell, or Microsoft Graph API.
Remove role assignments in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
User management permissions for Microsoft Entra custom roles in the Microsoft Entra admin center, PowerShell, or Microsoft Graph API.
Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
Learn how to configure a multitenant organization in Microsoft Entra ID using Microsoft Graph PowerShell or Microsoft Graph API.
Learn how to configure multitenant organization policy templates in Microsoft Entra ID using the Microsoft Graph API.
Learn how to troubleshoot and resolve network security group configuration alerts for Microsoft Entra Domain Services
Learn how to resolve common alerts generated as part of the health status for Microsoft Entra Domain Services
Learn what a mismatched directory error means and how to resolve it in Microsoft Entra Domain Services
Learn how to troubleshoot common errors when you create or manage Microsoft Entra Domain Services
Learn how to troubleshoot and resolve common alerts with secure LDAP for Microsoft Entra Domain Services.
Learn how to troubleshoot common problems that cause user accounts to be locked out in Microsoft Entra Domain Services.
Learn how to troubleshoot secure LDAP (LDAPS) for a Microsoft Entra Domain Services managed domain
Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.
Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
How to troubleshoot common issues faced when configuring user provisioning to an application already listed in the Microsoft Entra application gallery.
Learn how to assign sensitivity labels to groups. See troubleshooting information and view more resources.
1. After joining your Windows 10 or newer PC to a domain that is configured to allow Enterprise State Roaming, sign on with your work account. Go to **Settings** > **Accounts** > **Sync Your Settings** and confirm that sync and the individual settings are on, and that the top of the settings page indicates that you're syncing with your work account. Confirm the same account is also used as your account in **Settings** > **Accounts** > **Your Info**.
Groups Troubleshooting
UpdatedTroubleshooting tips for dynamic membership groups in Microsoft Entra ID
Transport Layer Security (TLS) 1.2 enforcement for Microsoft Entra Domain Services | Microsoft Learn
UpdatedLearn how to enforce TLS 1.2 for a Microsoft Entra Domain Services managed domain.
Learn how to configure groups and user roles in your external tenant, so you can receive them as claims in a security token for your Node.js application
author: shlipsey3
Learn about the best practices and general guidance for protecting frontline workers in an organization
Client Credential Advice
Updatedauthor: kengaderdus
Learn how to provide security operations analysts access to resources across tenants.
Covers security considerations for using Microsoft Entra application proxy
Learn how to add, test, or remove protected actions in Microsoft Entra ID.
This article describes how to use emergency access accounts to help prevent being inadvertently locked out of your Microsoft Entra organization.
Ensure that your organization's administrative access and administrator accounts are secure. For system architects and IT pros who configure Microsoft Entra ID, Azure, and Microsoft Online Services.
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
Connect Health Agent Install
Updated> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.
Create and manage security groups or Microsoft 365 groups in Microsoft Entra ID and request security group or Microsoft 365 group memberships.
Learn how to configure single sign-on between Microsoft Entra ID and Acronis Cyber Protect Cloud.
Learn how to enable security audits to centralize the logging of events for analysis and alerts in Microsoft Entra Domain Services
Learn how to use Azure Monitor Workbooks to review security audits and understand issues in a Microsoft Entra Domain Services managed domain.
Learn how to investigate Microsoft Entra health monitoring alerts to monitor and improve the health of your tenant.
userimpact: Low
UpdatedOrganizations without proper activation alerts for highly privileged roles lack visibility into when users access these critical permissions. Threat actors can exploit this monitoring gap to perform privilege escalation by activating highly privileged roles without detection, then establish persistence through admin account creation or security policy modifications. The absence of real-time alerts enables attackers to conduct lateral movement, modify audit configurations, and disable security controls without triggering immediate response procedures.
Sla Performance
Updated| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |
Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services
Covers network topology considerations when using Microsoft Entra application proxy.
Sla Performance
Updated| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |
The MDM policy settings apply to Windows 10 or newer. Refer to [Enterprise State Roaming settings catalog](/windows/configuration/windows-backup/catalog-esr) for details on what devices are supported for Microsoft Entra ID-based syncing.
Learn about the Microsoft Entra Health signals and alerts for Conditional Access block policy health scenarios
author: inbarckms
Learn how to handle errors and exceptions, Conditional Access claims challenges, and retries in MSAL.js applications.
author: inbarckms
1. **Conditional Access** to see policy failure and success. Scope your filter to show only failures to limit results.
author: MicrosoftGuyJFlo
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
author: MicrosoftGuyJFlo
Learn how to enforce secret and certificate standards using application management policies in Microsoft Entra ID.
Learn how to integrate an on premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
Scim Graph Scenarios
UpdatedUsing SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.
Scim Validator Tutorial
UpdatedThis tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can use entitlement management and other identity governance features to enforce the policies for access.
Describes how to check the users who fall into the execution scope of a Lifecycle Workflow.
Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID.
Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.
Learn how to set up group writeback in entitlement management.
Learn how to set up expiration for Microsoft 365 groups in Microsoft Entra ID.
Presents an overview of on-premises application provisioning architecture.
Conceptual Deployment Plan
UpdatedAn end-to-end guide for planning the deployment of application proxy within your organization
Microsoft Entra ID Protection
1 updateauthor: justinha
Microsoft Entra ID Governance
159 updatesLearn how Microsoft Entra ID is licensed for guest users.
In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports approvers when they are the requestors manager, their second-level manager, or a sponsor from a connected organization:
Migrate From Sap Idm
UpdatedOrganizations that have SAP SuccessFactors could use SAP IDM to [bring in employee data](https://help.sap.com/docs/SAP_IDENTITY_MANAGEMENT/4773a9ae1296411a9d5c24873a8d418c/4c54e007ab414f7da3854952cad00221.html) from SAP SuccessFactors. Those organizations with SAP SuccessFactors can easily migrate to bring identities for employees [from SuccessFactors into Microsoft Entra ID](~/identity/saas-apps/sap-successfactors-inbound-provisioning-cloud-only-tutorial.md) or [from SuccessFactors into on-premises Active Directory](~/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial.md), by using Microsoft Entra ID connectors. The connectors support the following scenarios:
With the Azure Logic App given the access package assignment manager role for the catalog, you must now go to logic app to edit it to communicate with Microsoft Entra. To do this, you'd do the following steps:
Discovery and insights (formerly Security Wizard) help you convert permanent Microsoft Entra role assignments to just-in-time assignments with Privileged Identity Management.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can define policies for how users should obtain access to your business critical applications integrated with Microsoft Entra ID Governance.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.
Microsoft Entra ID Governance allows you to model organizational roles using access packages, so you can migrate your existing role definitions to entitlement management.
Integrate your applications for identity governance and establishing a baseline of reviewed access
UpdatedMicrosoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can integrate your existing business critical third party on-premises and cloud-based applications with Microsoft Entra ID for identity governance scenarios.
Pim Powershell Migration
UpdatedThe following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.
Learn how to configure security alerts for Azure resource roles in Privileged
Configure security alerts for Microsoft Entra roles Privileged Identity Management.
Learn how to use custom security attribute to configure the scope of a workflow with lifecycle workflows.
Learn how to assign Microsoft Entra roles with access packages.
Learn how to create an access review of PIM for Groups in Microsoft Entra ID.
Learn how to show suggested access packages to users in My Access so they can quickly find the most relevant access packages.
Access Reviews FAQs
UpdatedFrequently asked questions about Access Reviews.
Learn how to approve activation requests for group members and owners in Microsoft Entra Privileged Identity Management (PIM).
Learn how to use the My Access portal to approve or deny requests to an access package in Microsoft Entra entitlement management.
Learn how to approve or deny requests for Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to archive logs and create reports with Azure Monitor in entitlement management.
Learn how to assign eligibility for a group in Privileged Identity Management.
Learn how to assign Microsoft Entra roles in Privileged Identity Management (PIM).
View activity and audit activity history for group assignments in Privileged Identity Management (PIM).
Tutorial for moving users that change jobs using Lifecycle workflows with the Microsoft Entra admin center.
Tutorial for post off-boarding users from an organization using Lifecycle workflows with the Microsoft Entra admin center.
Tutorial for onboarding users to an organization using Lifecycle workflows with the Microsoft Entra admin center.
Automate Identity Lifecycle
Updatedauthor: billmath
Learn how to write PowerShell scripts in Azure Automation to interact with Microsoft Entra entitlement management and other features.
services: entra-id-governance
Learn how to bring groups into Privileged Identity Management.
Learn how to change approval and requestor information settings for an access package in entitlement management.
Learn how to change requestor information & lifecycle settings for an access package in entitlement management.
Learn how to change request settings for an access package in entitlement management.
Learn how to change the resource roles for an existing access package in entitlement management.
Check Status Workflow
UpdatedThis article guides a user on checking the status of a Lifecycle workflow
Check Workflow Insights
UpdatedLearn how to check workflow insights within your Microsoft Entra tenant.
Learn the high-level steps you should follow for common scenarios in Microsoft Entra entitlement management.
Learn how to complete an access review of Azure resource and Microsoft Entra roles Privileged Identity Management.
Learn how to complete an access review of group members or application access in Microsoft Entra access reviews.
Learn how to configure automatic assignments based on rules for an access package in entitlement management.
Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure Microsoft Entra role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Learn how to configure separation of duties enforcement for requests for an access package in entitlement management.
Learn how to configure verified ID settings for an access package in entitlement management.
Learn how to convert guest user access package assignments for an access package in entitlement management.
You can use Microsoft Entra entitlement management to enforce the policies for who can get assigned access to an application.
Learn how to create an access package of resources that you want to share in Microsoft Entra entitlement management.
Learn how to set up an access review in a policy for entitlement management access packages in Microsoft Entra ID part of Microsoft Entra.
Learn how to create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to create an access review of group members or application access in Microsoft Entra ID.
Learn how to create a new container of resources and access packages in entitlement management.
Using Microsoft Entra access reviews, you can download a review history for access reviews in your organization.
This tutorial describes how to create customized reports in Azure Data Explorer by using data from more sources in addition to Microsoft Entra
This tutorial describes how to create customized reports in Azure Data Explorer by using data from Microsoft Entra.
Create Lifecycle Workflow
UpdatedThis article guides you in creating a lifecycle workflow.
Learn how to customize the schedule of a lifecycle workflow.
Customize Workflow Email
UpdatedGet a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.
Learn how to delegate access governance from IT administrators to access package managers and project managers so that they can manage access themselves.
Learn how to delegate access governance from IT administrators to catalog creators and project managers so that they can manage access themselves.
Learn how to delegate access governance from IT administrators to department managers and project managers so that they can manage access themselves.
Delete a lifecycle workflow
UpdatedLearn how to delete a lifecycle workflow.
Learn how to discover Azure resources to manage in Privileged Identity Management (PIM).
Describes email notifications in Microsoft Entra Privileged Identity Management (PIM).
This article serves as a reference for Microsoft Entra ID behavior when assignment periods of an access package and PIM policy don't align.
author: billmath
Learn how to remove users from an organization in real time on their last day of work by using lifecycle workflows in the Microsoft Entra admin center.
Learn how to extend or renew PIM for groups assignments.
Learn about the settings you can specify to govern access for external users in entitlement management.
Govern cloud users and groups with provisioning from on-premises and Entra Connect Cloud Sync
UpdatedThis article a tutorial on how to provision users and groups using cloud sync.
Governance Service Limits
UpdatedThis article details service limits for offerings within Microsoft Entra ID Governance
Groups Activate Roles
UpdatedLearn how to activate your group membership or ownership in Privileged
Learn how to hide or delete an access package in Microsoft Entra entitlement management.
This article shows how to create custom alerts with Microsoft Entra ID Governance
This article shows how to use the new identity governance dashboard
This article describes use cases Microsoft Entra ID Governance.
Include file
UpdatedInclude file
Least Privileged
Updatedauthor: billmath
Lifecycle Workflow Audits
UpdatedInformation about audit logs with Lifecycle Workflows
Lifecycle Workflow Tasks
UpdatedThis article guides a user on Workflow task definitions and task parameters.
An article discussing Lifecycle workflow versioning and history
Lifecycle workflows FAQs
UpdatedFrequently asked questions about Lifecycle workflows.
Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.
Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.
Learn how to allow people outside your organization to request access packages so that you can collaborate on projects.
Manage guest users as members of a group or assigned to an application with Microsoft Entra access reviews.
Learn how to manage users' access as membership of a group or assignment to an application with Microsoft Entra access reviews
Manage Workflow On Premises
UpdatedA how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.
Manage Workflow Properties
UpdatedThis article guides a user to editing a workflow's properties using Lifecycle Workflows.
Manage Workflow Tasks
UpdatedThis article guides a user on managing workflow versions with Lifecycle Workflows.
Learn how you can use entitlement management and Global Secure Access to restrict employee access to cloud apps.
On Demand Workflow
UpdatedThis article guides a user to running a workflow on demand using Lifecycle Workflows.
Learn how to simplify approving access to applications and resources for onboarding external users to your organization.
Pim Apis
UpdatedInformation for understanding the APIs in Microsoft Entra Privileged
Pim How To Use Audit Log
UpdatedLearn how to view the audit log history for Microsoft Entra roles in
Learn how to review access of Azure resource and Microsoft Entra roles
Learn how to approve or deny requests for Azure resource roles in Privileged
Learn how to assign Azure resource roles in Privileged Identity Management (PIM).
Pim Roles
UpdatedDescribes the roles you can't manage in Microsoft Entra Privileged Identity
Learn how to deploy Privileged Identity Management (PIM) in your Microsoft Entra organization.
Planning for a successful access reviews campaign for a particular application starts with understanding how to model access for that application in Microsoft Entra ID.
Learn how to extend or renew Azure resource role assignments in Privileged Identity Management (PIM).
Learn how to extend or renew Microsoft Entra role assignments in Microsoft Entra Privileged Identity Management (PIM)
Learn how to reprocess assignments for an access package in entitlement management.
Learn how to reprocess a request for an access package in entitlement management.
Learn how to use the My Access portal to request access to an access package in Microsoft Entra entitlement management.
Learn about the request process for an access package and when email notifications are sent in entitlement management.
Learn how to complete an access review of entitlement management access packages in access reviews.
Learn how to review access of group members or application access in Microsoft Entra access reviews.
Learn how to review access of group members with review recommendations in Microsoft Entra access reviews.
Learn how to review your own access to groups or applications in access reviews.
Learn how to review your own access to resources in access reviews.
Learn how to review user access of entitlement management access packages in access reviews.
Learn about partners who can help with deployment and integration of identity management (IAM) and identity governance scenarios.
Learn how to share link to request an access package in entitlement management.
Start using PIM
UpdatedLearn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.
Trigger Custom Task
UpdatedTrigger Logic Apps based on custom task extensions
Learn how to configure and use custom logic app workflows in entitlement management.
Step-by-step tutorial for how to create your first access package using the Microsoft Entra admin center in entitlement management.
Tutorial for preparing user accounts for Lifecycle workflows.
Learn how to use Azure custom roles in Microsoft Entra Privileged Identity Management (PIM).
Use Access Reviews to extend of remove access from members of partner organizations.
Learn how to use multi-stage reviews to design more efficient reviews with Microsoft Entra.
Learn how to view requests and remove for an access package in entitlement management.
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
Learn how to view the user assignments report and audit logs in entitlement management.
View, add, and remove assignments for an access package in entitlement management - Microsoft Entra
UpdatedLearn how to view, add, and remove assignments for an access package in entitlement management.
For a workflow to run for users based on a schedule, they must first meet its execution conditions. The execution conditions consist of:
- [Investigate insights within entitlements management](#investigate-insights-within-entitlements-management): Get quick access to information about access packages, policies, connected organizations, and catalog resources.
Microsoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees. See [Microsoft Entra ID Governance licensing fundamentals](/entra/id-governance/licensing-fundamentals) for complete details on licensing for employees.
Copilot Entra Access Reviews
RemovedA Microsoft Entra documentation page was updated: Copilot Entra Access Reviews.
A Microsoft Entra documentation page was updated: Copilot Entra Entitlement Management.
Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.
In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. While entitlement management natively supports dynamic approvers such as the requestor's manager, second-level manager, or sponsor from a connected organization, these options don't cover all scenarios. With [custom extensions](entitlement-management-logic-apps-integration.md) calling out to [Azure Logic Apps](/azure/logic-apps/logic-apps-overview), you're able to determine approval requirements for access packages at the time of request through an external system. For example, if the user requesting an access package is in a department where leadership has recently changed, dynamic approvals can query the system and assign the new department head as the approver. With this external call, you're able to determine approval requirements based on each of the [ApprovalStage properties](/graph/api/resources/approvalstage?view=graph-rest-beta#properties). This article walks you through making a custom extension, its underlying Azure Logic App, setting its system-assigned identity and role in the catalog, editing the logic app action to perform business logic, and testing to see if it runs successfully.
Copilot Entra Access Reviews
Updated>
Describes overview of identity lifecycle management and what is meant by governing the employee lifecycle.
Describes overview of Lifecycle workflow attributes.
Conceptual article discussing workflow extensibility with Lifecycle Workflows
Lifecycle Workflow History
UpdatedConceptual article about Lifecycle Workflows reporting and history capabilities
Lifecycle Workflow Insights
UpdatedConceptual article about Lifecycle Workflows reporting and history capabilities.
Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.
Lifecycle Workflow Templates
UpdatedConceptual article discussing workflow templates and categories with Lifecycle Workflows.
This page provides an overview of the Microsoft Entra ID Governance integrations available to automate provisioning and governance controls.
This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
Describes how to use a resource dashboard to perform an access review
Plan new governance scenarios for business partners and external users with Microsoft ID Governance
UpdatedDescribes overview of getting started with new business partner and external user scenarios.
How to manage Microsoft Entra Privileged Identity Management (PIM) for Groups.
Describes an overview of Lifecycle workflows and the various parts.
Get an overview of the lifecycle workflow feature of Microsoft Entra ID.
Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external users.
Provides an overview of Microsoft Entra Privileged Identity Management (PIM).
Pim Troubleshoot
UpdatedLearn how to troubleshoot system errors with roles in Microsoft Entra Privileged Identity Management (PIM).
Learn about some items you should check to help you troubleshoot Microsoft Entra entitlement management.
A Microsoft Entra documentation page was updated: Entitlement Management Troubleshoot.
Planning guide for a successful Lifecycle Workflow deployment.
Planning guide for a successful access reviews deployment.
Learn how to use access reviews to manage users that have been excluded from Conditional Access policies
Microsoft Entra External ID
181 updatesMigrate Users
UpdatedLearn how to migrate users from another identity provider to Microsoft Entra External ID.
Preview Alert Ciam
Updated> [!IMPORTANT]
author: shlipsey3
About Redirect Url
UpdatedA Microsoft Entra documentation page was updated: About Redirect Url.
Add Client App Certificate
UpdatedTo use your client app certificate, you need to associate the app you registered in the Microsoft Entra admin center with the certificate:
Add Optional Claims Id
Updated1. Under **Manage**, select the **Token configuration**.
Allow Deny List
Updatedauthor: csmulligan
Applies To External Only
Updated**Applies to**:  Workforce tenants  External tenants ([learn more](../tenant-configurations.md))
author: csmulligan
Applies To Workforce Only
Updated**Applies to**:  Workforce tenants  External tenants ([learn more](../tenant-configurations.md))
author: csmulligan
Use this quickstart to learn how Microsoft Entra admins can add B2B guest users in the Microsoft Entra admin center and walk through the B2B invitation workflow.
B2c Federation Customers
UpdatedLearn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Create an External Tenant
UpdatedCreate an external tenant to get started with Microsoft Entra External ID as your customer identity and access management (CIAM) service.
Cross Cloud Settings
Updatedauthor: csmulligan
author: csmulligan
Current Limitations
Updatedauthor: csmulligan
Learn how your organization can define custom roles to manage cross-tenant access settings, allowing for precise control without relying on built-in management roles.
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
Declare App Roles
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Privileged Role Administrator](../../../../identity/role-based-access-control/permissions-reference.md#privileged-role-administrator).
Default Account
Updatedauthor: csmulligan
Delete an external tenant
UpdatedLearn how to delete an external tenant in the Microsoft Entra admin center.
Direct Federation
Updatedauthor: csmulligan
Direct Federation Adfs
Updatedauthor: csmulligan
Enable Implicit Hybrid Flows
UpdatedA Microsoft Entra documentation page was updated: Enable Implicit Hybrid Flows.
Enable Public Client Flow
UpdatedTo identify your app as a public client, follow these steps:
author: csmulligan
External Identities Pricing
Updatedauthor: csmulligan
Facebook Federation
Updatedauthor: csmulligan
Faq Customers
UpdatedGoogle Federation
Updatedauthor: csmulligan
Google Federation Customers
UpdatedLearn how to add Google as an identity provider for your external tenant.
Hybrid Cloud To On Premises
Updatedauthor: csmulligan
Identity Providers
Updatedauthor: csmulligan
Leave The Organization
Updatedauthor: csmulligan
Manage Admin Accounts
UpdatedManage Customer Accounts
UpdatedMicrosoft Account
Updatedauthor: csmulligan
Quickstart - Get started
UpdatedLearn how to get started with Microsoft Entra External ID. Customize your apps' look and feel, set up a user to test the sign-up flow, and configure a sample app in just a few minutes.
Quickstart Trial Setup
UpdatedUse our quickstart to set up the external tenant free trial.
Register Client App Common
UpdatedA Microsoft Entra documentation page was updated: Register Client App Common.
Register Daemon App
UpdatedThe following steps show you how to register your daemon app in the Microsoft Entra admin center:
Self Service Portal
Updatedauthor: csmulligan
author: csmulligan
Service Limits
UpdatedLearn about the service limits and restrictions in an external tenant.
Learn how to run a sample Angular SPA to sign in users
Learn how to run a sample React SPA to sign in users
Learn how to run a sample JavaScript SPA to sign in users
A Microsoft Entra documentation page was updated: Support Custom Claims Provider.
Tenant Configurations
UpdatedTenant Restrictions V2
Updatedauthor: csmulligan
Training Videos
Updatedauthor: csmulligan
1. Locate, then open *auth_config_native_auth.json*.
Use Custom Domain Url
UpdatedA Microsoft Entra documentation page was updated: Use Custom Domain Url.
A Microsoft Entra documentation page was updated: Use Custom Domain Url Android.
Use Dynamic Groups
Updatedauthor: csmulligan
User Flow Customize Language
UpdatedUser Permissions
UpdatedLearn about the default permissions for users in an external tenant.
Learn how to run a sample ASP.NET web app to sign in users
Learn how to run a sample Node.js/Express web app to sign in users
Allow or Block Invitations
UpdatedLearn how an administrator create a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.
author: csmulligan
Custom Url Domain
UpdatedLearn about setting up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.
Custom Url Domain
UpdatedLearn how to set up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.
author: gregkmsft
author: csmulligan
Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
Enable Native Authentication
UpdatedTo specify that this app is a public client and can use native authentication, enable public client and native authentication flows:
Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.
Native Authentication
UpdatedLearn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.
Test User Flow
UpdatedTo test a [user flow](/entra/external-id/customers/how-to-user-flow-sign-up-sign-in-customers) with this app registration, enable the implicit grant flow for authentication.
Use Custom Domain Url Python
UpdatedUse a custom URL domain to fully brand the authentication URL. From a user perspective, users remain on your domain during the authentication process, rather than being redirected to *ciamlogin.com* domain name.
Add App Role
UpdatedAn API needs to publish a minimum of one app role for applications, also called [Application permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token as themselves. Application permissions are the type of permissions that APIs should publish when they want to enable client applications to successfully authenticate as themselves and not need to sign-in users. To publish an application permission, follow these steps:
Add App User Flow
UpdatedFor the customer users to see the sign-up or sign-in experience when they use your app, you need to associate your app with a user flow. Although many applications can be associated with your user flow, a single application can only be associated with one user flow.
Learn how to add Apple as an identity provider for your external tenant.
Add MSA for customer sign-in
UpdatedLearn how to add MSA as an identity provider for your external tenant.
Learn how to call a protected API in your Node.js web application using access tokens from Microsoft Entra External ID.
Learn how to prepare your Node.js client web app to call a protected API using access tokens from Microsoft Entra External ID.
Follow these steps to create a user flow a customer can use to sign in or sign up for an application.
Learn how to customize the sign-in and sign-up experiences for your customers.
Learn how to customize the look and feel of your customers' sign-in experiences.
Define Custom Attributes
UpdatedLearn how to create and define new custom attributes to be collected from users during sign-up and sign-in.
Learn how to enable self-service password reset so your customers can reset their own passwords without admin assistance.
Grant Api Permission Sign In
UpdatedOnce you register your application, it gets assigned the **User.Read** permission. However, since the tenant is an external tenant, the customer users themselves can't consent to this permission. You as the tenant administrator must consent to this permission on behalf of all the users in the tenant:
Quickstart Tenant Setup
UpdatedIn this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.
Test User Flows
UpdatedLearn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.
Add sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.
Visual Studio Code Extension
UpdatedLearn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.
Supported Features Customers
Updated| **Authentication** > **Redirect URIs**| The URIs Microsoft Entra ID accepts as destinations when returning authentication responses (tokens) after successfully authenticating or signing out users. | Same as workforce.|
Migrate To Xtap V2 Api
Updatedauthor: csmulligan
Add App Client Secret
UpdatedCreate a client secret for the registered application. The application uses the client secret to prove its identity when it requests for tokens:
Add Attributes To Token
UpdatedLearn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.
Create a client secret for the registered application. The application uses the client secret to prove its identity when it requests for tokens.
Add Optional Claims Access
UpdatedYou can add the **idtyp** optional claim to help the web API to determine whether a token is an **app** token or an **app + user** token. Although you can use a combination of **scp** and **roles** claims for the same purpose, using the **idtyp** claim is the easiest way to tell an app token and an app + user token apart. For example, the value of this claim is *app* when the token is an app-only token.
Assign Users Groups Roles
UpdatedOnce you've added app roles in your application, administrator can assign users and groups to the roles. Assignment of users and groups to roles can be done through the admin center, or programmatically using [Microsoft Graph](/graph/api/user-post-approleassignments). When the users assigned to the various app roles sign in to the application, their tokens have their assigned roles in the `roles` claim.
Learn how to manage your external tenant by calling the Azure REST API.
Code Samples
Updatedauthor: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.
Find Application Id
UpdatedA Microsoft Entra documentation page was updated: Find Application Id.
To grant your client app (*ciam-client-app*) API permissions, follow these steps:
Group App Roles Support
UpdatedFind out which core Microsoft Entra features related to the user and group management model and application assignment are available in external tenants.
One Time Passcode
Updatedauthor: csmulligan
Once your app acquires an ID token, you can retrieve the claims associated with the current account. To do so, use the following code snippet.
Region Code Opt In
Updatedauthor: csmulligan
Samples Ciam All
UpdatedLearn how to build and integrate apps with external tenants with scenarios such as sign-up, sign in, and getting an access token to call an API.
author: csmulligan
author: csmulligan
Use App Roles Customers
UpdatedLearn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.
User Flow Add Application
UpdatedUser Insights
UpdatedLearn about how to analyze user activity and engagement for your registered application in the external tenant.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Add Member To Group
UpdatedNow that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.yml#create-a-basic-group-and-add-members).
Security Customers
UpdatedAdd Api Mfa Scopes
UpdatedAn API needs to publish a minimum of one scope, also called [Delegated Permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token for a user successfully. To publish a scope, follow these steps:
Add Api Scopes
UpdatedAn API needs to publish a minimum of one scope, also called [Delegated Permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token for a user successfully. To publish a scope, follow these steps:
Api Connectors Overview
Updatedauthor: csmulligan
B2b Fundamentals
Updatedauthor: csmulligan
Custom Extensions
Updatedauthor: csmulligan
author: csmulligan
Customers Ciam
UpdatedDirect Federation Overview
Updatedauthor: csmulligan
External Identities Overview
Updatedauthor: csmulligan
Guide Explained
UpdatedLearn about the features you set up with the get started guide.
Planning Your Solution
Updatedauthor: csmulligan
author: csmulligan
Solutions Customers
UpdatedLearn about the customer identity and access management solutions for your consumer and business customer apps that are provided by Microsoft Entra External ID.
Supported Features Customers
UpdatedCompare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.
User Attributes
UpdatedUser profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.
Cross Tenant Access Overview
Updated- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.
Cross Tenant Access Overview
Updated- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.
Cross Tenant Access Overview
Updated- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
Learn how to use Visual Studio Connected Services to integrate Microsoft Entra ID into your applications right from your development environment.
Grant Api Access App
UpdatedFor your application to access data in Microsoft Graph API, grant the registered application the relevant application permissions. The effective permissions of your application are the full level of privileges implied by the permission. For example, to create, read, update, and delete every user in your external tenant, add the User.ReadWrite.All permission.
1. From the **App registrations** page, select the application that you created (such as *ciam-client-app*) to open its **Overview** page.
1. From the **App registrations** page, select the application that you created (such as *edit-profile-service*) to open its **Overview** page.
1. From the **App registrations** page, select the application that you created, such as *ciam-client-app*.
Register Api App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Developer](~/identity/role-based-access-control/permissions-reference.md#application-developer).
Register Mfa Api App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Developer](~/identity/role-based-access-control/permissions-reference.md#application-developer).
A Microsoft Entra documentation page was updated: Configure cross-tenant synchronization using PowerShell or Microsoft Graph API.
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
author: csmulligan
Register Saml App
UpdatedLearn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.
author: csmulligan
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Learn how to configure cross-tenant synchronization in Microsoft Entra ID using the Microsoft Entra admin center.
Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
Learn how to map directory extensions in cross-tenant synchronization using the Microsoft Entra admin center.
Learn about topologies for cross-tenant synchronization in Microsoft Entra ID.
Learn how to set up Azure Monitor in external tenants to collect and analyze data in your tenant.
author: csmulligan
author: csmulligan
Add Group Claim In Token
UpdatedTo emit the group membership claims in security tokens, follow these steps:
Troubleshooting Known Issues
UpdatedMicrosoft Entra Internet Access
10 updatesPowerShell example that bypasses a certain fqdn or IP from being acquired by the GSA Client in the Internet Access forwarding profile.
PowerShell sample - Add Intune device compliance bypasses to Global Secure Access Internet Access
NewPowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Data Storage And Privacy
UpdatedGlobal Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Points Of Presence
UpdatedGlobal Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
Clients
UpdatedLearn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Internet Access
UpdatedLearn about how Microsoft Entra Internet Access secures access to the Internet.
PowerShell examples for use in a Microsoft Entra Internet Access break glass scenario.
Event Enrichment Logs
UpdatedGlobal Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.
Microsoft Entra Private Access
13 updatesCiphers
UpdatedLearn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Enable Multi Geo
UpdatedLearn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Configure Connectors
UpdatedLearn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Configure Quick Access
UpdatedLearn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
author: kenwith
Covers how to provide single sign-on using Kerberos with Microsoft Entra Private Access.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
Connector Groups
UpdatedLearn how Microsoft Entra private network connector groups work and how they're used by Microsoft Entra Private Access and application proxy.
Connectors
UpdatedLearn how Microsoft Entra private network connectors work and how they're used by Microsoft Entra Private Access and application proxy.
Private Access
UpdatedLearn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Configure Per App Access
UpdatedLearn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Microsoft Entra Verified ID
4 updatesAn ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Traditional methods such as personally identifiable information (PII) and knowledge-based authentication are no match for today’s sophisticated attackers, who use phishing, social engineering, and even AI-powered voice cloning to bypass defenses. The consequences are serious: under pressure, helpdesk agents may unintentionally expose sensitive data or authorize fraudulent actions.
Entra Admin Center
Updated* [Credentials](~/verified-id/verifiable-credentials-configure-tenant-quick.md)
Our Identity Verification (IDV) partner network extends Microsoft Entra Verified ID capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable scenarios like remote onboarding with government ID checks using identity verification and proofing services.
Partner Gallery
Updated1. Set up Microsoft Entra Verified ID Service: using [Quick setup](verifiable-credentials-configure-tenant-quick.md) or [Advanced setup instructions](verifiable-credentials-configure-tenant.md).
Microsoft Entra Workload ID
5 updatesYou must act **before March 31, 2026**, to avoid authentication failure of applications.
Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.
manager: CelesteDG
userimpact: Low
UpdatedAzure Logic Apps integrated with Microsoft Entra Identity Governance create a significant attack surface when access controls are inadequate. Threat actors can exploit misaligned permissions between Logic Apps management roles and Microsoft Entra directory roles to gain initial access through compromised accounts with excessive Azure RBAC permissions. With access, threat actors can modify workflow logic to insert malicious automation into provisioning processes, then use managed identities and existing connections for lateral movement across connected systems.
Learn how to troubleshoot service principal configuration alerts for Microsoft Entra Domain Services
Microsoft Entra Global Secure Access
66 updatesChina User Support
UpdatedLearn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.
Learn how to set up the bidirectional communication tunnel between Global Secure Access and your router.
Create Remote Networks
UpdatedLearn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.
Current Known Limitations
Updatedauthor: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
Customer intent: macOS users, I want to download and install the Global Secure Access client.
Updatedauthor: HULKsmashGithub
Customer intent: Windows users, I want to download and install the Global Secure Access client.
Updatedauthor: HULKsmashGithub
Learn how to add and delete customer premises equipment device links to remote networks for Global Secure Access.
author: HULKsmashGithub
This article lists all releases of Microsoft Entra private network connector and describes new features and fixed issues.
author: kenwith
Learn how to assign a remote network to a traffic forwarding profile for Global Secure Access.
Compliant Network
Updatedauthor: kenwith
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
List Remote Networks
UpdatedLearn how to list remote networks for Global Secure Access.
Manage Microsoft Profile
UpdatedLearn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.
Manage Remote Networks
UpdatedLearn how to update and delete remote networks for Global Secure Access.
Learn how to roll out traffic forwarding profiles to users and groups with Global Secure Access
PowerShell example that gets the Auth Token for registering your Microsoft Entra private network connector through Azure, AWS, or GCP Marketplaces.
Use these PowerShell samples for Global Secure Access.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Quickstart Install Client
UpdatedLearn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
Quickstart Per App Access
UpdatedLearn how to configure per-app access to private resources in Global Secure Access.
Quickstart Quick Access
UpdatedLearn how to configure Quick Access to private resources in Global Secure Access.
Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.
Role Based Permissions
UpdatedLearn about the built-in administrator roles you can assign to manage Global Secure Access permissions.
Covers how to perform an unattended installation of the Microsoft Entra private network connector.
Simulate Remote Network
Updatedauthor: kenwith
Source Ip Restoration
Updatedauthor: kenwith
author: kenwith
author: kenwith
Global Secure Access Web content filtering categories
Zscaler Coexistence
Updatedauthor: kenwith
Cisco Coexistence
UpdatedMicrosoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
Netskope Coexistence
UpdatedMicrosoft and Netskope’s Security Service Edge (SSE) coexistence solution guide.
What Is Global Secure Access
UpdatedLearn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Learn about the available Global Secure Access logs and monitoring options.
Netskope Integration
UpdatedA comprehensive guide for configuring and testing the integration between Microsoft's and Netskope's Secure Access Service Edge (SASE) solutions.
Partner Ecosystems Overview
UpdatedLearn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
Remote Network Connectivity
UpdatedLearn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.
Traffic Dashboard
UpdatedMonitor the health and status of your network traffic with the Global Secure Access dashboard.
Traffic Forwarding
UpdatedLearn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.
Connectors
UpdatedFor more information about optimizing your network, see [Network topology considerations when using Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).
Transport Layer Security
UpdatedTo get started with TLS inspection, see [Configure Transport Layer Security](how-to-transport-layer-security.md).
Access Audit Logs
UpdatedLearn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
View Traffic Logs
UpdatedLearn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Remote Network Health Logs
UpdatedLearn how to check the health of your remote networks with the Global Secure Access remote network health logs.
Use Workbooks
UpdatedWorkbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
View Deployment Logs
Updatedauthor: kenwith
View Enriched Logs
UpdatedLearn how to use enriched Microsoft 365 logs for Global Secure Access.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Troubleshoot problems installing the Microsoft Entra private network connector.
The [Universal Conditional Access documentation](../concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authoriziation limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertenty lock users out from accessing anything on their machine.
PowerShell examples that re-enable any Conditional Access policies that were disabled in a break glass scenario.
Quickstart Remote Network
UpdatedLearn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
Universal Conditional Access
Updatedauthor: kenwith
author: HULKsmashGithub
Secure private application access with Privileged Identity Management (PIM) and Global Secure Access
UpdatedLearn how to secure highly valued private application access with Privileged Identity Management (PIM) and Global Secure Access
Palo Alto Coexistence
UpdatedMicrosoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Transport Layer Security
Updated1. Select **Create CSR**.
Security Copilot + Entra
10 updatesSecurity Copilot Conditional Access - Learn to create, assign, and troubleshoot policies using custom security attributes for better protection.
ms.service: entra-id
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
Agents fit naturally into existing workflows. You don't need special training or other licensing to use them. Agents utilize SCUs to operate just like other features in the product. They integrate seamlessly with Microsoft Security solutions and the broader supported partner ecosystem. Agents learn based on feedback and keep you in control on the actions it takes. They handle resource-intensive tasks like threat intelligence briefings, and Conditional Access optimization. With Microsoft Security Copilot agents, you can scale up your teams, people, and processes.
Learn how to use Microsoft Security Copilot with Microsoft Entra identity scenarios
Learn how to use Microsoft Security Copilot in the Microsoft Entra admin center for identity and security scenarios.
Microsoft Entra agents work seamlessly with [Microsoft Security Copilot](/copilot/security/microsoft-security-copilot). Microsoft Security Copilot agents automate repetitive tasks and reduce manual workloads. They enhance security and IT operations across cloud, data security and privacy, identity, and network security. These agents handle high-volume, time-consuming tasks by pairing data and code with an AI language model. They respond to user requests and system events, helping teams work more efficiently and focus on higher-impact tasks.
Microsoft Entra Health provides look-back reporting on Service Level Agreements (SLA) for authentication availability for your Microsoft Entra tenant. The SLA Attainment is a monthly look-back solution that shows the core authentication availability of Microsoft Entra ID each month. IT admins often need to review the SLA reports in conjuntion with service outages. Security Copilot interacts with the Microsoft Entra SLA using the Microsoft Graph API.
A Microsoft Entra documentation page was updated: Policy All Users Security Copilot.
- bb3d68c2-d09e-4455-94a0-e323996dbaa3 - Security Copilot API
