author: justinha
Retiring service-principal-less authentication is the week’s clearest Entra behavior change
The updated Workload ID guidance describes a security-by-default retirement of service-principal-less authentication: a client service principal will be required for all applications. Otherwise, the week of 16 June 2025 was mainly Microsoft Learn maintenance—184 updates, two new entries, seven removals, and no Message Center items. The two new Entra ID entries provide migration guidance for legacy MFA and SSPR, while the strongest additional signals are an ID Governance visibility notice effective 30 September 2025, telephony-fraud guidance, and a Global Secure Access/Conditional Access/Entitlement Management scenario. No supplied entry establishes a preview or general availability event; the seven removals lack item-level detail and cannot be treated as product retirements.
- Workload ID: service-principal-less authentication retirement
Workload ID · Authentication
The updated guidance says a client service principal will be required for all applications. It cites the risk of abuse when resource applications or APIs perform incomplete validation and frames the requirement as reducing the chance of that gap returning or being exploited in third-party resources. This is a stated retirement and authentication-behavior change, but no effective date or rollout status is supplied.
- ID Governance: My Access visibility changes are dated for 30 September 2025
ID Governance · Fundamentals
Updated Entitlement Management guidance explains that access-package visibility controls which packages users can discover and request in the My Access portal and highlights important changes effective 30 September 2025. The supplied text does not describe the altered rules, so this is a dated documentation notice rather than evidence of a specific configuration change.
Two records marked New add Microsoft Learn content for migrating from legacy MFA and self-service password reset policies. The evidence does not say that a policy was retired, enforcement changed, or a deadline was introduced; this is new migration documentation, not a feature launch. It aligns with separate updates to the Mandatory Multifactor Authentication material.
- Entra ID: telephony-fraud protections are documented as region-sensitive
Entra ID · Authentication
The updated Telephony Fraud Protections and Throttles guidance says Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. It also says some regions require opt-in through a support ticket because of elevated fraud risk. This is security guidance and a description of behavior, not evidence that a new control became generally available this week.
- Governed blocking pattern for unauthorized websites and unsanctioned AI apps
ID Governance · Conditional Access
An updated ID Governance scenario combines Global Secure Access and Conditional Access to block a specific unauthorized website, such as an unsanctioned AI app, while entitlement management provides governed exceptions for users who should be exempt. The scenario targets web applications that lack provisioning or federation and should be read as implementation guidance, not a launch or availability announcement.
Workload owners should identify applications that rely on service-principal-less authentication and assess the stated client-service-principal requirement; the record supplies no effective date. ID Governance teams using My Access discovery or request flows have a dated visibility item to review for 30 September 2025, but not enough detail to infer the new rules. MFA administrators can use the new migration pages and check whether their region requires support-ticket opt-in for telephony-fraud protections. The remaining sampled edits are reference or implementation guidance rather than confirmed tenant-wide changes.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
94 updates:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::
:::image type="content" border="false" source="./media/how-to-certificate-based-authentication/steps.png" alt-text="Diagram of the steps required to enable Microsoft Entra certificate-based authentication.":::
Delegate By Task
Updated> | Configure registration | [Authentication Policy Administrator](permissions-reference.md#authentication-policy-administrator) | |
author: justinha
Mfa Registration Campaign
Updatedauthor: mjsantani
manager: mwongerapk
Howto Mfa Mfasettings
Updatedauthor: justinha
Fido2 Hardware Vendor
UpdatedACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌
author: justinha
Authentication Qr Code
Updatedauthor: aanjusingh
Authentication Qr Code
Updatedauthor: aanjusingh
Authenticate Application Id
UpdatedSet-ADSyncScheduler -SyncCycleEnabled $true
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: barclayn
Authenticate Application Id
UpdatedMicrosoft Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Microsoft Entra Connect. This account uses a username and password to authenticate requests.
Howto Mfa Reporting
Updated<a name='view-the-azure-ad-sign-ins-report'></a>
One scenario that many organizations [building for resilience](resilience-overview.md) in their identity and access management architecture need to accommodate is continuity of application access during temporary site disconnection. The organization may have one or more physical sites at which their applications are deployed. Some of their users are colocated at those sites and need to be able to access local applications. For example, employees at a factory or at a store may need to be able to sign-in to in-house-developed business applications managing operations at that site.
Refresh Tokens
Updated| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |
Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.
This article describes how to allow the Microsoft Entra Connect application to authenticate with Microsoft Entra ID with modern, more secure credentials.
Monitor the health of your tenant through several identity scenarios and authentication availability rates with Microsoft Entra Health
Activity Log Schemas
UpdatedLearn how to interpret the details found in the Microsoft Entra audit and sign-in and logs schema.
Learn how to analyze audit, sign-in, and provisioning logs Microsoft Entra ID using Log Analytics queries.
Learn about the different types of sign-in logs that are available in Microsoft Entra monitoring and health.
Mfa Manage Oath Tokens
Updated>[!NOTE]
Connect Version History
Updated> [!IMPORTANT]
Configure Linked Sign On
Updatedmanager: mwongerapk
Configure User Consent
Updated:::zone-end
Mysdworxcom Tutorial
UpdatedYou can configure and test Microsoft Entra single sign-on for my.sdworx.com in a test environment (my.acc.sdworx.com) but not by using the gallery app (import SP metadata, to be provided by your my.sdworx.com contact). My.sdworx.com supports **IDP** and **SP** initiated single sign-on.
Appneta Tutorial
Updated| Email | user.userprincipalname |
| --- | --- |
This article describes how to enable group writeback in Microsoft Entra Connect by using PowerShell and a wizard.
Entra Service Limits Include
Updated- [How to: Customize claims with the claims mapping policy in Microsoft Graph](/graph/how-to-claims-customization)
author: HULKsmashGithub
author: barclayn
category: Privileged access
Updatedauthor: barclayn
ai-usage: ai-assisted
What If Tool
Updated| :---: | --- | :---: | :---: |
21912
RemovedA Microsoft Entra documentation page was updated: 21912.
category: Access control
Updatedauthor: HULKsmashGithub
category: Access control
Updatedauthor: HULKsmashGithub
A Microsoft Entra documentation page was updated: Cloudknox Permissions Management Platform Tutorial.
Secure Generative Ai
UpdatedMicrosoft Entra offers a comprehensive suite of capabilities to securely manage AI applications, appropriately control access, and protect sensitive data:
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide Alerts.
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide Intro.
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide One.
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide Three.
A Microsoft Entra documentation page was updated: Permissions Manage Ops Guide Two.
Locate Integration Partners
Updatedmanager: martinco
Locate Integration Partners
Updatedmanager: martinco
Migration Best Practices
Updatedauthor: MicrosoftGuyJFlo
author: MicrosoftGuyJFlo
Staged Rollout lets you gradually test cloud authentication features with selected user groups. These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains.
1. Review the audit logs to see what changes were made to your Conditional Access policies.
The Microsoft Entra ID authentication pipeline consists of several built-in authentication events, like the validation of user credentials, Conditional Access policies, multifactor authentication, self-service password reset, and more.
Sso Linux
UpdatedThis feature empowers users on Linux desktop clients to register their devices with Microsoft Entra ID, enroll into Intune management, and satisfy device-based Conditional Access policies when accessing their corporate resources.
Whats New
Updated**Service category:** Conditional Access
Learn how to view Conditional Access details in Microsoft Entra activity logs so that you can assess the effect of your policies.
author: MicrosoftGuyJFlo
Licensing
Updatedmanager: pmwongera
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
Whats New
UpdatedFor more information, see: [Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources](https://techcommunity.microsoft.com/blog/identity/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991).
Whats New Archive
Updated**Type:** New feature
- *List all Microsoft Entra recommendations*
Learn about the Microsoft Entra logs available for streaming to an endpoint for storage, analysis, or monitoring.
Introduction to the options and considerations for integrating Microsoft Entra activity logs with storage and analysis tools.
This article describes frequently asked questions for cloud provisioning.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Workday.
Integrating Rippling Human Capital Management (HCM) with Microsoft Entra ID/Active Directory.
Integrating Rippling Human Capital Management (HCM) with Microsoft Entra ID/Active Directory.
|name.givenName|String||✓|
Learn how to download, view, and analyze the details in the provisioning logs from Microsoft Entra ID.
Because secure applications are essential to the organization, any downtime to them because of security issues can affect the business or some critical service that the business depends upon. So, it's important to allocate time and resources to ensure applications always stay in a healthy and secure state. Conduct a periodic security and health assessment of applications, much like a Security Threat Model assessment for code. For a broader perspective on security for organizations, see the [security development lifecycle (SDL)](https://www.microsoft.com/securityengineering/sdl).
Go to the Entra portal, select **App Registrations**, and then select **New registration**. Create a single-tenant app as shown below.
Data Residency
UpdatedMicrosoft Entra ID is an Identity as a Service (IDaaS) solution that stores and manages identity and access data in the cloud. You can use the data to enable and manage access to cloud services, achieve mobility scenarios, and secure your organization. An instance of the Microsoft Entra ID service, called a [tenant](~/identity-platform/developer-glossary.md#tenant), is an isolated set of directory object data that the customer provisions and owns.
Entra Admin Center
Updated* [App registrations](~/identity-platform/application-model.md)
Learn how to use the AD FS application migration to migrate AD FS relying party applications from ADFS to Microsoft Entra ID. This guided experience provides one-click configuration for basic SAML URLs, claims mapping, and user assignments to integrate the application with Microsoft Entra ID.
Debug SAML-based single sign-on to applications in Microsoft Entra ID.
Getthere Tutorial
UpdatedTo configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
Error Codes
Updated| AADSTS50139 | SessionMissingMsaOAuth2RefreshToken - The session is invalid due to a missing external refresh token. |
author: HULKsmashGithub
author: barclayn
```
This article describes security improvements to Microsoft Entra Connect Sync and how to enable logging of administrator activities.
category: Monitoring
Updatedauthor: barclayn
Understand consent request evaluation and tenant-wide admin consent in Microsoft Entra ID. Essential guidance for administrators managing application permissions and security.
1. **[Configure Microsoft Entra SSO](#configure-microsoft-entra-sso)** - to enable your users to use this feature.
The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.
The basic steps for configuring diagnostics settings are as follows:
Microsoft Entra ID Protection
1 updateauthor: HULKsmashGithub
Microsoft Entra ID Governance
29 updatesCreate Access Review
Updated> Access reviews capture a snapshot of access at the beginning of each review instance. Any changes made during the review process will be reflected in the subsequent review cycle. Essentially, with the commencement of each new recurrence, pertinent data regarding the users, resources under review, and their respective reviewers is retrieved.
Review Your Access
UpdatedThe first step to perform an access review is to find and open the access review.
Complete Access Review
Updated> [!NOTE]
> [!NOTE]
Perform Access Review
UpdatedAfter it opens, you'll see the list of users in scope for the access review.
1. Select the **Review user access** link to open the access review.
1. Select the **Review access** link.
> [!NOTE]
The output also includes the individual domains for each of these external identities.
1. On the Access packages page, locate the access package you want to request for a direct report and select **Request**.
> [!NOTE]
A Microsoft Entra documentation page was updated: Access Reviews Downloadable Review History.
Access Reviews Faqs
UpdatedA Microsoft Entra documentation page was updated: Access Reviews Faqs.
A Microsoft Entra documentation page was updated: Create Access Review Pim For Groups.
The document provides a step-by-step guide for integrating Darwinbox with Microsoft Entra ID. The steps include establishing a connection, configuring attribute mapping, testing account provisioning, configuring account access rules, and monitoring provisioning. Use this integration to configure cloud-native users directly in Microsoft Entra ID. This integration allows IT admins to automate business processes using Microsoft Entra ID Governance Lifecycle Workflows.
Deploy Access Reviews
UpdatedA Microsoft Entra documentation page was updated: Deploy Access Reviews.
A Microsoft Entra documentation page was updated: Entitlement Management Access Reviews Create.
Manage Access Review
UpdatedA Microsoft Entra documentation page was updated: Manage Access Review.
A Microsoft Entra documentation page was updated: Manage User Access With Access Reviews.
Self Access Review
UpdatedA Microsoft Entra documentation page was updated: Self Access Review.
1. On the Add an Action pane, select **HTTP**.
Whatis
Updated- **Microsoft Entra ID Governance.** [Microsoft Entra ID Governance](~/id-governance/identity-governance-overview.md) is an advanced set of [identity governance capabilities](~/id-governance/licensing-fundamentals.md) for Microsoft Entra ID P1 and P2 customers.
Access Reviews Overview
Updated- **Have reviews recur periodically:** You can set up recurring access reviews of users at set frequencies such as weekly, monthly, quarterly or annually, and the reviewers are notified at the start of each review. Reviewers can approve or deny access with a friendly interface and with the help of smart recommendations.
A conceptual article describing access package visibility in the My Access portal.
When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and upcoming changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, outlines how it currently works, and highlights important changes effective September 30, 2025.
Conditional Access Exclusion
UpdatedA Microsoft Entra documentation page was updated: Conditional Access Exclusion.
In this scenario, you set up Global Secure Access and Conditional Access to block access to a specific unauthorized website such as an unsanctioned AI app, while using entitlement management to provide governed access to users who should be exempt from the policy. This scenario is useful for generative AI applications and other web applications that don't support provisioning or federation with Microsoft Entra.
Feature Availability
Updated[Microsoft Entra ID Governance](~/id-governance/licensing-fundamentals.md) is available in the US Government community cloud (GCC), GCC-High, and Department of Defense cloud environments. [Microsoft Entra Workload Identities Premium edition](~/workload-id/workload-identities-faqs.md#is-the-workload-id-premium-plan-available-on-azure-government-clouds) is available in the US government clouds.
Microsoft Entra External ID
11 updatesWhats New Overview
UpdatedNot all Microsoft Entra products are part of Microsoft 365 and Azure (for example, Microsoft Entra External ID). The What's new feature ensures transparency about new features and changes across all Microsoft Entra products in a centralized location.
Are there limitations for cross-cloud synchronization?
21790
Updated- [Cross-tenant access overview](../../external-id/cross-tenant-access-overview.md)
21790
Updated- [Cross-tenant access overview](../../external-id/cross-tenant-access-overview.md)
B2b Tutorial Require Mfa
Updated1. Access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.
Supported Features Customers
Updated| **Types of application registration** | <ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li><li>Enterprise applications offer [more options](../../identity/enterprise-apps/plan-sso-deployment.md), like password-based, linked, and header-based.</li></ul> |<ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li></ul>|
Claims Mapping
UpdatedIf you need to issue the UPN value as an application token claim, the actual claim mapping might behave differently for B2B users. If the B2B user authenticates with an external Microsoft Entra identity and you issue `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN attribute from the home tenant for this user.
Leave The Organization
Updated- If you're using a personal account or email one-time passcode, you'll need to use a My Account URL that includes your tenant name or tenant ID.
Quickstart Tenant Setup
Updated- An Azure subscription.
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
Faq Customers
UpdatedEffective May 1, 2025 Azure AD B2C P1 and P2 will no longer be available to purchase for new customers, but current Azure AD B2C customers can continue using the product. The product experience, including creating new tenants or user flows, remains unchanged. The operational commitments, including service level agreements (SLAs), security updates, and compliance, also remain unchanged. We'll continue supporting Azure AD B2C until at least May 2030. More information, including migration plans will be made available. Contact your account representative for more information and to learn more about Microsoft Entra External ID.
Microsoft Entra Private Access
1 updateConfigure Quick Access
UpdatedConfiguring your Quick Access settings is a major component to utilizing Microsoft Entra Private Access. When you configure Quick Access for the first time, Private Access creates a new enterprise application. The properties of this new app are automatically configured to work with Private Access.
Microsoft Entra Verified ID
37 updatesUse Quickstart Idtoken
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Issuer Revoke
Updated> If the verifiable credential is old and was issued during the preview period, this claim doesn't exist. Revocation doesn't work for this credential and you have to reissue it.
Use Quickstart
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Use Quickstart Presentation
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Use Quickstart Selfissued
UpdatedIn the **Azure portal**, when you select **Add credential**, you get the option to launch two quickstarts. Select **custom credential**, and then select **Next**.
Using Facecheck
UpdatedFace Check is a privacy-respecting facial matching. It allows enterprises to perform high-assurance verifications securely, simply, and at scale. Face Check adds a critical layer of trust by performing facial matching between a user’s real-time selfie and a photo. The facial matching is powered by Azure AI services. Face Check protects user privacy by sharing only the match results and not any sensitive identity data, while allowing organizations to be sure the person claiming an identity is really them.
Admin Api
UpdatedThe Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials and completely opt out the service as well.
Verifiable Credentials Faq
Updated1. In the [Azure portal](https://portal.azure.com), go to **Microsoft Entra ID** for the subscription you use for your Microsoft Entra Verified ID deployment.
To set up Verified ID, follow these steps:
| `type` | string (array) | a list of verifiable credential types this contract can issue |
Credential Design
UpdatedThe following four attestation types are currently available to be configured in the rules definition. They are different ways of providing claims used by the Microsoft Entra Verified ID issuing service to be inserted into a verifiable credential and attest to that information with your decentralized identifier (DID). Multiple attestation types can be used in the rules definition.
In this step, you create the verified credential expert card by using Microsoft Entra Verified ID. After you create the credential, your Microsoft Entra tenant can issue it to users who initiate the process.
How Use Vcnetwork
Updated1. On the start page of **Microsoft Entra Verified ID** in the **Azure portal**, you have a quickstart named **Verification request**. Selecting **start** takes you to a page where you can browse the Verifiable Credentials Network.
Opt Out
Updated1. From the **Azure portal**, search for verifiable credentials.
Plan Issuance Solution
UpdatedAll verifiable credentials must declare their *type* in their [rules definition](rules-and-display-definitions-model.md#rulesmodel-type). The credential type distinguishes a verifiable credentials schema from other credentials and it ensures interoperability between issuers and verifiers. To indicate a credential type, provide one or more credential types that the credential satisfies. Each type is a unique string. Often, a URI is used to ensure global uniqueness. The URI doesn't need to be addressable. It's treated as a string. As an example, a diploma credential issued by Contoso University might declare the following types:
Create a client secret for the registered application you created. The sample application uses the client secret to prove its identity when it requests tokens.
Issuance Request Api
UpdatedAuthorization: Bearer <token>
Presentation Request Api
UpdatedAuthorization: Bearer <token>
Get Started Request Api
UpdatedIssuance request using the `idTokenHint` attestation flow:
Vc Network Api
UpdatedServices Partners
UpdatedYou could select a partner from the list and build seamless end-user experiences for onboarding, secure access to critical services, self-service, and custom business application scenarios. If you're a Services or solution Partner and would like to be considered into Microsoft Entra Verified ID partner documentation, submit your application [request](https://forms.microsoft.com/r/AGVsXmf4EZ).
Whats New
UpdatedApplications that use the Microsoft Entra Verified ID service must use the Request API endpoint that corresponds to their Microsoft Entra tenant's region.
Idemia
UpdatedTo configure IDEMIA as your identity verification proofing solution, follow these steps:
Verified Id Pricing
UpdatedTo take advantage of the consumptive billing, your Verified ID authority must be linked to an Azure subscription.
Partner Gallery
UpdatedHeader: Algorithm and Token type
Register Didwebsite
Updated1. Go to the **Verified ID** page in the **Azure portal**.
Partner Vu
UpdatedIn this tutorial, you learn how to install the **Microsoft Authenticator** app and use it for the first time with Verified ID. You use the public end to end demo webapp to issue a verifiable credential to the **Authenticator** and present verifiable credentials from the **Authenticator**.
Issuer Openid
UpdatedTo receive a verifiable credential, your users need to sign into your IDP from the **Microsoft Authenticator** app.
Plan Verification Solution
Updated:::image type="content" source="media/plan-verification-solution/plan-verification-solution-authenticator.png" alt-text="Diagram of the components of a verification solution with Microsoft Authenticator application highlighted.":::
In order to be able to resolve DID documents, DIDs are typically recorded on an underlying network of some kind that represents a trust system. Microsoft currently supports DID:Web trust system. DID:Web is a permission based model that allows trust using a web domain’s existing reputation. DID:Web is in support status General Available.
Dnsbind
UpdatedThe domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.example.com/`.
In centralized identity systems, the identity provider (IDP) controls the lifecycle and usage of credentials.
Using Wallet Library
Updated- **[Android Studio](https://developer.android.com/studio)** installed on Mac/Windows and an Android test device. You need to enable [developer mode](https://developer.android.com/studio/debug/dev-options) on your Android test device.
Microsoft Entra Verified ID supports the following open standards:
Error Codes
Updated"message": "The request contains `includeQRCode`, but it is not boolean."
Microsoft Entra Workload ID
6 updatesIn addition to human and device identities, workload identities such as applications, services, and containers require authentication and authorization policies.
This change to service principal-less authentication will make client service principal a requirement for all applications in order to improve our "Security by default" ([See authentication behaviors](/graph/api/resources/authenticationbehaviors?view=graph-rest-beta&preserve-view=true)). Service principal-less authentication can be abused if the resource applications (i.e. APIs) perform incomplete validations. Microsoft has verified that validations aren't vulnerable to service principal-less authentication. However, with this action, the risk of this gap reappearing in future versions or being exploited in third-party resources outside Microsoft’s control is minimized.
Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>
Overview
Updated- A service principal of a special type is created in Microsoft Entra ID for the identity. The service principal is tied to the lifecycle of that Azure resource. When the Azure resource is deleted, Azure automatically deletes the service principal for you.
author: HULKsmashGithub
Microsoft Entra Global Secure Access
14 updatesCustomer intent: macOS users, I want to download and install the Global Secure Access client.
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
This article tracks the changes in each released version of the Global Secure Access client for macOS.
Next, we activate group membership using the Microsoft Entra admin center, and then attempt to connect with the new role activated.
Install Windows Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Next, we activate group membership using the Microsoft Entra admin center, and then attempt to connect with the new role activated.
Customer intent: Windows users, I want to download and install the Global Secure Access client.
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Secure Shell (SSH) is widely recognized across the IT industry as a critical service for system administrators. It provides a secure and encrypted method to access and manage remote systems over unsecured networks.
Configure Per App Access
Updated1. Select **Save**.
Configure Per App Access
UpdatedPer-App Access is configured by creating a new Global Secure Access app. You create the app, select a connector group, and add network access segments. These settings make up the individual app that you can assign users and groups to.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
1. Run the command `dsregcmd /status` and check the **AzureAdPrt** field.
Connectors
UpdatedYou don't have to manually delete connectors that are unused. When a connector is running, it remains active as it connects to the service. Unused connectors are tagged as `_inactive_` and are removed after 10 days of inactivity. If you do want to uninstall a connector, though, uninstall both the Connector service and the Updater service from the server. Restart the computer to fully remove the service.
Transport Layer Security
Updated:::image type="content" source="media/how-to-transport-layer-security/security-profile-baseline.png" alt-text="Screenshot of the Edit Baseline profile screen showing a list of policy names and their priorities.":::
