Week in brief

1 July B2B sharing impact and 15 August access-review deadline outweigh a documentation-heavy Entra week

The week of 23 June 2025 is dominated by Microsoft Learn maintenance—504 updated records, 116 new records, and no removals—rather than evidenced product launches. The consequential changes are a SharePoint and OneDrive B2B access impact for pre-integration OTP shares on 1 July, a phased B2B guest sign-in change from July through December, and reduced access-review history to the latest 12 months through the UI and APIs from 15 August. The remaining high-signal items are RBAC and authentication guidance clarifications. No retirement or GA announcement is identified in the supplied evidence; the PKI-based trust store is labeled Preview only within an updated certificate-authority article.

  • Effective 1 July 2025, external users will lose access to content shared through SharePoint One Time Passcode before Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B was enabled. Resharing is required to restore access. The notice explicitly calls for notifying users and updating internal documentation. This is changed integration behavior, not a product launch.

  • Microsoft Entra ID will update the guest authentication experience for B2B collaboration starting in July 2025, with completion by December 2025. Guests will sign in through their home organization’s sign-in page. Message Center says no administrative action is required, while asking administrators to review B2B configuration. This is a phased behavior change; no preview or GA status is stated.

  • Starting 15 August 2025, only the last 12 months of Microsoft Entra ID access-review data will be available through the user interface and APIs. Administrators are instructed to export historical data before the cutoff and establish an annual data-storage routine. The notice describes an availability and retention-policy change, not deletion of older records.

  • On 26 June, Microsoft Learn added pages for roles including Authentication Administrator, Privileged Authentication Administrator, Authentication Policy Administrator, Authentication Extensibility Administrator, Application Administrator, Global Administrator, Global Reader, Security Administrator, User Administrator, Hybrid Identity Administrator, Directory Readers, and Lifecycle Workflows Administrator. Related updates to Permissions Reference and role pages clarify scopes—for example, Authentication Administrat​

  • Updated guidance says Android QR code PIN authentication’s `getPreferredAuthConfiguration` requires Microsoft Authenticator; without the app it returns `None`. Managed Android Enterprise devices use an Intune app configuration policy with `sdm_suppress_camera_consent=true`, configured by the Authentication Policy Administrator. For hybrid-joined devices, TAP setup of Windows Hello for Business requires a prior password, smartcard, or FIDO2 authentication; federated identity providers with directly integrated MFA ​​

For Entra administrators

For tenants enabling Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B, identify content previously shared through SharePoint One Time Passcode, plan to reshare it, notify affected external users, and update internal documentation. Export historical access-review data before 15 August and establish an annual storage routine. Microsoft says no administrative action is required for the guest sign-in rollout, but recommends reviewing B2B configuration. Treat the Learn additions and edits as reference or security guidance: use them when reviewing delegated roles and deployed authentication flows, but do not infer a new role, permission change, GA release, or retirement from a page being marked New or Updated.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

281

Global Administrator

Updated

> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |

29 June 2025

User Administrator

Updated

> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |

29 June 2025

Directory Writers

Updated

> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |

29 June 2025

Permissions Reference

Updated

A Microsoft Entra documentation page was updated: Permissions Reference.

29 June 2025

Cloud Device Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

29 June 2025

Agent Optimization

Updated

You can tailor the policy to your needs using the optional **Custom Instructions** field. This setting allows you to provide a prompt to the agent as part of its execution. For example: "The user "Break Glass" should be excluded from policies created." Custom instructions can be used to include or exclude users, groups, and roles. This can be used to exclude them from consideration entirely or for a specific scenario and can also be used to add exceptions to the suggested policy.

29 June 2025

Global Administrator

Updated

> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |

28 June 2025

User Administrator

Updated

> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |

28 June 2025

Directory Writers

Updated

> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |

28 June 2025

Cloud Device Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

28 June 2025

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

28 June 2025

Attack Payload Author

Updated

A Microsoft Entra documentation page was updated: Attack Payload Author.

28 June 2025

Billing Administrator

Updated

A Microsoft Entra documentation page was updated: Billing Administrator.

28 June 2025

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

28 June 2025

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

28 June 2025

Exchange Administrator

Updated

A Microsoft Entra documentation page was updated: Exchange Administrator.

28 June 2025

Fabric Administrator

Updated

A Microsoft Entra documentation page was updated: Fabric Administrator.

28 June 2025

Groups Administrator

Updated

A Microsoft Entra documentation page was updated: Groups Administrator.

28 June 2025

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

28 June 2025

Insights Administrator

Updated

A Microsoft Entra documentation page was updated: Insights Administrator.

28 June 2025

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

28 June 2025

Kaizala Administrator

Updated

A Microsoft Entra documentation page was updated: Kaizala Administrator.

28 June 2025

Knowledge Administrator

Updated

A Microsoft Entra documentation page was updated: Knowledge Administrator.

28 June 2025

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

28 June 2025

License Administrator

Updated

A Microsoft Entra documentation page was updated: License Administrator.

28 June 2025

Message Center Reader

Updated

A Microsoft Entra documentation page was updated: Message Center Reader.

28 June 2025

Network Administrator

Updated

A Microsoft Entra documentation page was updated: Network Administrator.

28 June 2025

People Administrator

Updated

A Microsoft Entra documentation page was updated: People Administrator.

28 June 2025

Printer Administrator

Updated

A Microsoft Entra documentation page was updated: Printer Administrator.

28 June 2025

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

28 June 2025

Search Administrator

Updated

A Microsoft Entra documentation page was updated: Search Administrator.

28 June 2025

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

28 June 2025

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

28 June 2025

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

28 June 2025

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

28 June 2025

Yammer Administrator

Updated

A Microsoft Entra documentation page was updated: Yammer Administrator.

28 June 2025

User Administrator

Updated

> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |

27 June 2025

Directory Writers

Updated

> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |

27 June 2025

Cloud Device Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

27 June 2025

Iot Device Administrator

Updated

Assign the IoT Device Administrator role to users who need to do the following tasks:

27 June 2025

Teams Reader

Updated

> [!div class="mx-tableFixed"]

27 June 2025

Partner Tier2 Support

Updated

This is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.

26 June 2025

Partner Tier1 Support

Updated

This is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.

26 June 2025

Permissions Reference

Updated

This article lists the Microsoft Entra built-in roles you can assign to allow management of Microsoft Entra resources. For information about how to assign roles, see [Assign Microsoft Entra roles](manage-roles-portal.md). If you are looking for roles to manage Azure resources, see [Azure built-in roles](/azure/role-based-access-control/built-in-roles).

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

Dynamics 365 Administrator

New

Assign the Dynamics 365 Administrator role to users who need to manage all aspects of Dynamics 365 services, including configuration, user management, and support tickets.

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

role

New

role

26 June 2025

User Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the User Administrator role to users who need to do the following:

26 June 2025

Cloud Device Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can enable, disable, and delete devices in Microsoft Entra ID and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.

26 June 2025

Privileged Role Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage role assignments in Microsoft Entra ID, as well as within Microsoft Entra Privileged Identity Management. They can create and manage groups that can be assigned to Microsoft Entra roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units.

26 June 2025

Ai Administrator

Updated

A Microsoft Entra documentation page was updated: Ai Administrator.

26 June 2025

Attack Payload Author

Updated

A Microsoft Entra documentation page was updated: Attack Payload Author.

26 June 2025

Billing Administrator

Updated

A Microsoft Entra documentation page was updated: Billing Administrator.

26 June 2025

Directory Readers

Updated

A Microsoft Entra documentation page was updated: Directory Readers.

26 June 2025

Edge Administrator

Updated

A Microsoft Entra documentation page was updated: Edge Administrator.

26 June 2025

Exchange Administrator

Updated

A Microsoft Entra documentation page was updated: Exchange Administrator.

26 June 2025

Fabric Administrator

Updated

A Microsoft Entra documentation page was updated: Fabric Administrator.

26 June 2025

Groups Administrator

Updated

A Microsoft Entra documentation page was updated: Groups Administrator.

26 June 2025

Guest Inviter

Updated

A Microsoft Entra documentation page was updated: Guest Inviter.

26 June 2025

Insights Administrator

Updated

A Microsoft Entra documentation page was updated: Insights Administrator.

26 June 2025

Insights Analyst

Updated

A Microsoft Entra documentation page was updated: Insights Analyst.

26 June 2025

Kaizala Administrator

Updated

A Microsoft Entra documentation page was updated: Kaizala Administrator.

26 June 2025

Knowledge Administrator

Updated

A Microsoft Entra documentation page was updated: Knowledge Administrator.

26 June 2025

Knowledge Manager

Updated

A Microsoft Entra documentation page was updated: Knowledge Manager.

26 June 2025

License Administrator

Updated

A Microsoft Entra documentation page was updated: License Administrator.

26 June 2025

Message Center Reader

Updated

A Microsoft Entra documentation page was updated: Message Center Reader.

26 June 2025

Network Administrator

Updated

A Microsoft Entra documentation page was updated: Network Administrator.

26 June 2025

People Administrator

Updated

A Microsoft Entra documentation page was updated: People Administrator.

26 June 2025

Printer Administrator

Updated

A Microsoft Entra documentation page was updated: Printer Administrator.

26 June 2025

Printer Technician

Updated

A Microsoft Entra documentation page was updated: Printer Technician.

26 June 2025

Search Administrator

Updated

A Microsoft Entra documentation page was updated: Search Administrator.

26 June 2025

Search Editor

Updated

A Microsoft Entra documentation page was updated: Search Editor.

26 June 2025

Teams Administrator

Updated

A Microsoft Entra documentation page was updated: Teams Administrator.

26 June 2025

Teams Reader

Updated

A Microsoft Entra documentation page was updated: Teams Reader.

26 June 2025

Tenant Creator

Updated

A Microsoft Entra documentation page was updated: Tenant Creator.

26 June 2025

Yammer Administrator

Updated

A Microsoft Entra documentation page was updated: Yammer Administrator.

26 June 2025

Connect Group Writeback Enable

Updated

When you configure group writeback, a checkbox appears at the bottom of the configuration window. Select it to enable this feature.

25 June 2025

category:

Updated

manager: pmwongera

25 June 2025

Digicert Tutorial

Updated

To configure the integration of DigiCert into Microsoft Entra ID, you need to add DigiCert from the gallery to your list of managed SaaS apps.

25 June 2025
78

Authentication Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

29 June 2025

Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

29 June 2025

Cloud Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

29 June 2025

Sspr Policy

Updated

| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |

29 June 2025

Microsoft Entra data retention

Updated

Learn about the data retention policies for the Microsoft Entra audit, sign-in, and provisioning logs.

29 June 2025

Authentication Administrator

Updated

> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |

28 June 2025

Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

28 June 2025

Cloud Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

28 June 2025

Permissions Reference

Updated

> | [Authentication Administrator](#authentication-administrator) | Can access to view, set and reset authentication method information for any non-admin user.<br/>[![Privileged label icon.](./media/permissions-reference/privileged-label.png)](privileged-roles-permissions.md) | c4e39bd9-1100-46d3-8c65-fb160da0071f |

28 June 2025

Howto Authentication Temporary Access Pass

Updated

For hybrid-joined devices, users must first authenticate with another method such as a password, smartcard or FIDO2 key, before using TAP to set up Windows Hello for Business.

28 June 2025

Customize Branding

Updated

The default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).

28 June 2025

Mandatory Multifactor Authentication

Updated

If you're using a federated Identity Provider (IdP), such as Active Directory Federation Services, and your MFA provider is integrated directly with this federated IdP, the federated IdP must be configured to send an MFA claim. For more information, see [Expected inbound assertions for Microsoft Entra MFA](how-to-mfa-expected-inbound-assertions.md).

27 June 2025

Authentication Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:

27 June 2025

Android Qr Code Pin Authentication

Updated

This is configured by the Authentication Policy Administrator through an [app configuration policy for managed Android Enterprise devices](/mem/intune/apps/app-configuration-policies-use-android) on the Microsoft Authenticator App, setting `sdm_suppress_camera_consent` equal to `true`, similar to how the `preferred_auth_method` is configured.

27 June 2025

Cloud Application Administrator

Updated

> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |

27 June 2025

Global Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.

27 June 2025

Helpdesk Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).

27 June 2025

Refresh Tokens

Updated

| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |

27 June 2025

Password Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).

27 June 2025

category: Credential management

Updated

Microsoft Entra seamless single sign-on (Seamless SSO) is a legacy authentication feature designed to provide passwordless access for domain-joined devices that are not hybrid Microsoft Entra ID joined. Seamless SSO relies on Kerberos authentication and is primarily beneficial for older operating systems like Windows 7 and Windows 8.1, which do not support Primary Refresh Tokens (PRT). If these legacy systems are no longer present in the environment, continuing to use Seamless SSO introduces unnecessary complexity and potential security exposure. Threat actors could exploit misconfigured or stale Kerberos tickets, or compromise the `AZUREADSSOACC` computer account in Active Directory, which holds the Kerberos decryption key used by Microsoft Entra ID. Once compromised, attackers could impersonate users, bypass modern authentication controls, and gain unauthorized access to cloud resources. Disabling Seamless SSO in environments where it is no longer needed reduces the attack surface and enforces the use of modern, token-based authentication mechanisms that offer stronger protections.

26 June 2025

Authenticate Application Id

Updated

To enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Microsoft Entra or an administrator creates a single tenant non-Microsoft application in Microsoft Entra ID and uses one of the following relevant certificate management options for the credentials.

26 June 2025

Android Qr Code Pin Authentication

Updated

The `getPreferredAuthConfiguration` method requires the Microsoft Authenticator app to be installed on the device. If the Microsoft Authenticator app isn't installed, the method returns `None`.

26 June 2025

Privileged Authentication Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Privileged Authentication Administrator role to users who need to do the following:

26 June 2025

Authentication Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:

26 June 2025

Hybrid Identity Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create, manage and deploy provisioning configuration setup from Active Directory to Microsoft Entra ID using Cloud Provisioning as well as manage Microsoft Entra Connect, pass-through authentication (PTA), password hash synchronization (PHS), seamless single sign-on (seamless SSO), and federation settings. Does not have access to manage Microsoft Entra Connect Health. Users can also troubleshoot and monitor logs using this role.

26 June 2025

Authentication Extensibility Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Extensibility Administrator role to users who need to do the following tasks:

26 June 2025

Global Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.

26 June 2025

Import and export Microsoft Entra Connect configuration settings

Updated

Microsoft Entra Connect deployments vary from a single forest Express mode installation to complex deployments that are synced across multiple forests by using custom synchronization rules. Because of the large number of configuration options and mechanisms, it's essential to understand what settings are in effect and be able to quickly deploy a server with an identical configuration. This feature introduces the ability to catalog the configuration of a specific synchronization server and import the settings into a new deployment. You can compare different synchronization settings snapshots to easily visualize the differences between two servers or the same server over time.

26 June 2025

Helpdesk Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).

26 June 2025

Domain Name Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage (read, add, verify, update, and delete) domain names. They can also read directory information about users, groups, and applications, as these objects possess domain dependencies. For on-premises environments, users with this role can configure domain names for federation so that associated users are always authenticated on-premises. These users can then sign into Microsoft Entra based services with their on-premises passwords via single sign-on. Federation settings need to be synced via Microsoft Entra Connect, so users also have permissions to manage Microsoft Entra Connect.

26 June 2025

Password Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).

26 June 2025

Customize Branding

Updated

The default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).

26 June 2025

How to configure certificate authorities for Microsoft Entra certificate-based authentication

Updated

The best way to configure the certificate authorities (CAs) is with the PKI-based trust store (Preview). You can delegate configuration with a PKI-based trust store to least privileged roles. For more information see, [Step 1: Configure the certificate authorities with PKI-based trust store (Preview)](how-to-certificate-based-authentication.md#step-1-configure-the-certificate-authorities-with-pki-based-trust-store).

25 June 2025
39

Workbook Risk Analysis

Updated

Learn how to use the identity protection risk analysis workbook in Microsoft Entra ID to explore trends and gaps in your risk policies.

29 June 2025

Workbook Mfa Gaps

Updated

Learn how to use the MFA Gaps workbook in Microsoft Entra ID to identify apps and users who aren't protected by MFA.

29 June 2025

Attribute Log Reader

Updated

A Microsoft Entra documentation page was updated: Attribute Log Reader.

28 June 2025

How to manage inactive user accounts

Updated

Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.

28 June 2025

Howto Use Workbooks

Updated

Learn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.

28 June 2025

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

28 June 2025

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

28 June 2025

Attack Payload Author

Updated

Users in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation. Access to reports is limited to simulations executed by the user, and this role doesn't grant access to aggregate reports such as Training efficacy, Repeat offenders, Training completion, or User coverage.

27 June 2025

How to manage inactive user accounts

Updated

Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.

27 June 2025

Howto Use Workbooks

Updated

Learn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.

27 June 2025

Admin Audit Logging

Updated

The following table is a list of events that are logged with the new auditing feature. To view the events, use the Event Viewer and view the Application log.

26 June 2025

Global Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview compliance portal, Azure portal, and Device Management admin center.

26 June 2025

Power Platform Administrator

Updated

Users in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.

26 June 2025

Reports Reader

Updated

A Microsoft Entra documentation page was updated: Reports Reader.

26 June 2025

Recommendation Renew Expiring Application Credential

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).

25 June 2025
26

Audit Activities

Updated

Get an overview of the audit activities that can be logged in your audit logs in Microsoft Entra ID.

29 June 2025

Overview

Updated

author: owinfreyATL

29 June 2025

Whats New

Updated

>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your ![RSS feed reader icon](./media/whats-new/feed-icon-16x16.png) feed reader.

28 June 2025

Monitoring Health

Updated

Learn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.

28 June 2025

Workbooks

Updated

Learn how to create and work with Microsoft Entra workbooks, for identity monitoring, alerts, and data visualization.

28 June 2025

Configure Security

Updated

A Microsoft Entra documentation page was updated: Configure Security.

27 June 2025

Intune Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).

27 June 2025

Monitoring Health

Updated

Learn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.

27 June 2025

Usage and insights report

Updated

Learn about the information you can explore using the Usage and insights report in Microsoft Entra ID.

27 June 2025

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

27 June 2025

Attribute Assignment Administrator

Updated

For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).

26 June 2025

Attribute Assignment Reader

Updated

For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).

26 June 2025

Attribute Definition Administrator

Updated

For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).

26 June 2025

Attribute Definition Reader

Updated

For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).

26 June 2025

Attribute Log Administrator

Updated

For more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).

26 June 2025

Attribute Log Reader

Updated

For more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).

26 June 2025

Intune Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).

26 June 2025
16

Security Administrator

Updated

> | microsoft.directory/applications/policies/update | Update policies of applications |

29 June 2025

Security Administrator

Updated

> | microsoft.directory/applications/policies/update | Update policies of applications |

28 June 2025

Security Administrator

Updated

> | microsoft.directory/applications/policies/update | Update policies of applications |

27 June 2025

Attribute Assignment Reader

Updated

Users with this role can read custom security attribute keys and values for supported Microsoft Entra objects.

27 June 2025

Attribute Definition Administrator

Updated

Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.

27 June 2025

role

New

role

26 June 2025
15

Attribute Provisioning Reader

Updated

Users with this role cannot read audit logs for other events. This role must be used in conjunction with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.

27 June 2025

Provision Custom Security Attributes

Updated

This example includes custom security attributes that you could add to your tenant. Use the attribute set `HRConfidentialData` and then add the following attributes to:

26 June 2025

Attribute Provisioning Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Administrator role to users who need to do the following tasks:

26 June 2025

Attribute Provisioning Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Reader role to users who need to do the following tasks:

26 June 2025
14

Partner Tier2 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

29 June 2025

Partner Tier1 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

29 June 2025

Hybrid Identity Administrator

Updated

> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |

29 June 2025

Partner Tier2 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

28 June 2025

Partner Tier1 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

28 June 2025

Hybrid Identity Administrator

Updated

> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |

28 June 2025

Partner Tier2 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

27 June 2025

Partner Tier1 Support

Updated

> | microsoft.directory/applications/audience/update | Update the audience property for applications |

27 June 2025

Application Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.

27 June 2025

Hybrid Identity Administrator

Updated

> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |

27 June 2025

role

New

role

26 June 2025

Application Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.

26 June 2025

Cloud Application Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role have the same permissions as the Application Administrator role, excluding the ability to manage application proxy. This role grants the ability to create and manage all aspects of enterprise applications and application registrations. Users assigned to this role are not added as owners when creating new application registrations or enterprise applications.

26 June 2025
11

Security Operator

Updated

> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |

29 June 2025

Global Reader

Updated

> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |

29 June 2025

Security Operator

Updated

> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |

28 June 2025

Global Reader

Updated

> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |

28 June 2025

Security Operator

Updated

> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |

27 June 2025

Global Reader

Updated

> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |

27 June 2025

Getthere Tutorial

Updated

To configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.

26 June 2025
10

Conditional Access Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have the ability to manage Microsoft Entra Conditional Access settings.

26 June 2025

Conditional Access Report Only

Updated

- Results are logged in the **Conditional Access** and **Report-only** tabs of the Sign-in log details.

26 June 2025
8

Application Developer

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create application registrations when the "Users can register applications" setting is set to No. This role also grants permission to consent on one's own behalf when the "Users can consent to apps accessing company data on their behalf" setting is set to No. Users assigned to this role are added as owners when creating new application registrations.

26 June 2025
8

Attribute Log Reader

Updated

- Configure diagnostic settings for custom security attributes

27 June 2025
3

role

New

role

26 June 2025
3
1
2

Security Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

26 June 2025

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, as well as the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

26 June 2025
1

Azure Information Protection Administrator

Updated

Users with this role have all permissions in the Azure Information Protection service. This role allows configuring labels for the Azure Information Protection policy, managing protection templates, and activating protection. This role doesn't grant any permissions in Microsoft Entra ID Protection, Privileged Identity Management, Monitor Microsoft 365 Service Health, Microsoft Defender XDR portal, or Microsoft Purview portal.

27 June 2025
1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

26 June 2025
45

Security Reader

Updated

> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |

29 June 2025

Privileged Role Administrator

Updated

> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |

29 June 2025

Security Reader

Updated

> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |

28 June 2025

Entitlement Management Access Package Request Policy

Updated

When you create an access package, you can specify the request, approval and lifecycle settings, which are stored on the first policy of the access package. Most access packages have a single policy for users to request access, but a single access package can have multiple policies. You would create multiple policies for an access package if you want to allow different sets of users to be granted assignments with different request and approval settings.

28 June 2025

Entitlement Management Access Package First

Updated

:::image type="content" source="./media/entitlement-management-access-package-first/resource-roles.png" alt-text="Screenshot the shows how to select the member role." lightbox="./media/entitlement-management-access-package-first/resource-roles.png":::

28 June 2025

Privileged Role Administrator

Updated

> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |

28 June 2025

Security Reader

Updated

> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |

27 June 2025

Understanding access package visibility in the My Access portal

Updated

The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.

27 June 2025

Privileged Role Administrator

Updated

> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |

27 June 2025

On Demand Workflow

Updated

A Microsoft Entra documentation page was updated: On Demand Workflow.

27 June 2025

Workflows Faqs

Updated

A Microsoft Entra documentation page was updated: Workflows Faqs.

27 June 2025

Lifecycle Workflows Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Assign the Lifecycle Workflows Administrator role to users who need to do the following tasks:

26 June 2025
2

Licensing Fundamentals

Updated

Microsoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees and requires an Azure subscription.

25 June 2025
16

Training Videos

Updated

> [!VIDEO https://www.youtube.com/embed/_CD3shvqpx4?si=cYvAO8CyXuI9YPiS]

26 June 2025
4

B2c Ief Policy Administrator

Updated

Users in this role have the ability to create, read, update, and delete all custom policies in Azure AD B2C and therefore have full control over the Identity Experience Framework in the relevant Azure AD B2C organization. By editing policies, this user can establish direct federation with external identity providers, change the directory schema, change all user-facing content (HTML, CSS, JavaScript), change the requirements to complete an authentication, create new users, send user data to external systems including full migrations, and edit all user information including sensitive fields like passwords and phone numbers. Conversely, this role cannot change the encryption keys or edit the secrets used for federation in the organization.

27 June 2025

Training Videos

Updated

The video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verifications.

27 June 2025

External Identity Provider Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:

27 June 2025

External Identity Provider Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:

26 June 2025
4

External Collaboration Settings Configure

Updated

For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.

29 June 2025

B2c Ief Keyset Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users assigned to this role can create and manage policy keys and secrets used for token encryption, token signing, and claim encryption/decryption. They can add new keys to existing key containers, enabling secret rollover without affecting existing applications. Additionally, users in this role can view the complete details of these secrets, including their expiration dates, even after creation.

27 June 2025

External Id User Flow Attribute Administrator

Updated

Users with this role add or delete custom attributes available to all user flows in the Microsoft Entra organization. As such, users with this role can change or add new elements to the end-user schema and impact the behavior of all user flows, and indirectly result in changes to what data may be asked of end users and ultimately sent as claims to applications. This role can't edit user flows.

27 June 2025

B2c Ief Keyset Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). User can create and manage policy keys and secrets for token encryption, token signatures, and claim encryption/decryption. By adding new keys to existing key containers, this limited administrator can roll over secrets as needed without impacting existing applications. This user can see the full content of these secrets and their expiration dates even after their creation.

26 June 2025
4

B2b Fundamentals

Updated

| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |

29 June 2025

What Is B2b

Updated

- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.

29 June 2025

Cross Tenant Synchronization Overview

Updated

- Organizations that own multiple Microsoft Entra tenants and want to streamline intra-organization cross-tenant application access.

27 June 2025
2

Cross Tenant Synchronization Configure

Updated

This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.

25 June 2025
1

Service Limits

Updated

|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |

29 June 2025
1

Cross-tenant access activity workbook

Updated

Learn how to use the cross-tenant access activity workbook in Microsoft Entra ID to monitor the resources your external users are accessing.

29 June 2025
1
1
1
2

Service Principal Table

Updated

Reference table that maps application IDs to applications and their service principal usage from the sign-in logs.

29 June 2025

Managed identity sign-in logs

Updated

Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.

27 June 2025
2

Workbook Sensitive Operations Report

Updated

Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.

29 June 2025
1
1

Copilot Security Entra Investigate Risky Apps

Updated

Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.

28 June 2025
1

Directory Writers

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.

26 June 2025
1

Attribute Assignment Administrator

Updated

Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.

27 June 2025
9

Install Macos Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.

26 June 2025

Windows Client Release History

Updated

This article tracks the changes in each released version of the Global Secure Access client for Windows.

26 June 2025

Install Macos Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.

25 June 2025

Macos Client Release History

Updated

This article tracks the changes in each released version of the Global Secure Access client for macOS.

25 June 2025
4
1

Global Secure Access Administrator

Updated

- Cannot manage enterprise applications, application registrations, Conditional Access, or application proxy settings

27 June 2025
1

Version History

Updated

| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |

27 June 2025
1