author: owinfreyATL
1 July B2B sharing impact and 15 August access-review deadline outweigh a documentation-heavy Entra week
The week of 23 June 2025 is dominated by Microsoft Learn maintenance—504 updated records, 116 new records, and no removals—rather than evidenced product launches. The consequential changes are a SharePoint and OneDrive B2B access impact for pre-integration OTP shares on 1 July, a phased B2B guest sign-in change from July through December, and reduced access-review history to the latest 12 months through the UI and APIs from 15 August. The remaining high-signal items are RBAC and authentication guidance clarifications. No retirement or GA announcement is identified in the supplied evidence; the PKI-based trust store is labeled Preview only within an updated certificate-authority article.
- SharePoint and OneDrive B2B integration creates an access impact for pre-integration OTP shares on 1 July
External ID · Troubleshooting
Effective 1 July 2025, external users will lose access to content shared through SharePoint One Time Passcode before Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B was enabled. Resharing is required to restore access. The notice explicitly calls for notifying users and updating internal documentation. This is changed integration behavior, not a product launch.
- B2B guests will authenticate through their home organization’s sign-in page
Entra ID · Authentication
Microsoft Entra ID will update the guest authentication experience for B2B collaboration starting in July 2025, with completion by December 2025. Guests will sign in through their home organization’s sign-in page. Message Center says no administrative action is required, while asking administrators to review B2B configuration. This is a phased behavior change; no preview or GA status is stated.
- Access-review data older than 12 months will no longer be available through the UI and APIs
Entra ID · Microsoft identity platform
Starting 15 August 2025, only the last 12 months of Microsoft Entra ID access-review data will be available through the user interface and APIs. Administrators are instructed to export historical data before the cutoff and establish an annual data-storage routine. The notice describes an availability and retention-policy change, not deletion of older records.
- Built-in role pages and permission references were expanded without evidence of new role launches
Entra ID · Authentication
On 26 June, Microsoft Learn added pages for roles including Authentication Administrator, Privileged Authentication Administrator, Authentication Policy Administrator, Authentication Extensibility Administrator, Application Administrator, Global Administrator, Global Reader, Security Administrator, User Administrator, Hybrid Identity Administrator, Directory Readers, and Lifecycle Workflows Administrator. Related updates to Permissions Reference and role pages clarify scopes—for example, Authentication Administrat
- Authentication guidance adds concrete prerequisites and legacy-SSO security context
Entra ID · Authentication
Updated guidance says Android QR code PIN authentication’s `getPreferredAuthConfiguration` requires Microsoft Authenticator; without the app it returns `None`. Managed Android Enterprise devices use an Intune app configuration policy with `sdm_suppress_camera_consent=true`, configured by the Authentication Policy Administrator. For hybrid-joined devices, TAP setup of Windows Hello for Business requires a prior password, smartcard, or FIDO2 authentication; federated identity providers with directly integrated MFA
For tenants enabling Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B, identify content previously shared through SharePoint One Time Passcode, plan to reshare it, notify affected external users, and update internal documentation. Export historical access-review data before 15 August and establish an annual storage routine. Microsoft says no administrative action is required for the guest sign-in rollout, but recommends reviewing B2B configuration. Treat the Learn additions and edits as reference or security guidance: use them when reviewing delegated roles and deployed authentication flows, but do not infer a new role, permission change, GA release, or retirement from a page being marked New or Updated.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
513 updatesGlobal Administrator
Updated> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |
User Administrator
Updated> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
Directory Writers
Updated> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
Permissions Reference
UpdatedA Microsoft Entra documentation page was updated: Permissions Reference.
Cloud Device Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Helpdesk Administrator
Updated> | --- | --- |
author: MicrosoftGuyJFlo
Agent Optimization
UpdatedYou can tailor the policy to your needs using the optional **Custom Instructions** field. This setting allows you to provide a prompt to the agent as part of its execution. For example: "The user "Break Glass" should be excluded from policies created." Custom instructions can be used to include or exclude users, groups, and roles. This can be used to exclude them from consideration entirely or for a specific scenario and can also be used to add exceptions to the suggested policy.
Assign Local Admin
Updatedauthor: owinfreyATL
Connect Version History
Updated> [!IMPORTANT]
Device Join Out Of Box
Updatedauthor: owinfreyATL
Device Join Plan
Updatedauthor: owinfreyATL
author: owinfreyATL
Device Registration Tls 1 2
Updatedauthor: owinfreyATL
author: owinfreyATL
Domain Name Administrator
Updated> [!div class="mx-tableFixed"]
author: owinfreyATL
author: owinfreyATL
Hybrid Join
Updatedauthor: owinfreyATL
Hybrid Join Control
Updatedauthor: owinfreyATL
Hybrid Join Manual
Updatedauthor: owinfreyATL
Hybrid Join Plan
Updatedauthor: owinfreyATL
Intune Administrator
Updated> | --- | --- |
Manage Device Identities
Updatedauthor: owinfreyATL
Manage Stale Devices
Updatedauthor: owinfreyATL
Microsoft 365 Migration Administrator
Global Administrator
Updated> | microsoft.directory/adminConsentRequestPolicy/allProperties/allTasks | Manage admin consent request policies in Microsoft Entra ID |
User Administrator
Updated> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
Directory Writers
Updated> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
Cloud Device Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Helpdesk Administrator
Updated> | --- | --- |
Domain Name Administrator
Updated> [!div class="mx-tableFixed"]
Intune Administrator
Updated> | --- | --- |
Ai Administrator
UpdatedA Microsoft Entra documentation page was updated: Ai Administrator.
Attack Payload Author
UpdatedA Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
A Microsoft Entra documentation page was updated: Attribute Assignment Administrator.
Attribute Assignment Reader
UpdatedA Microsoft Entra documentation page was updated: Attribute Assignment Reader.
A Microsoft Entra documentation page was updated: Attribute Definition Administrator.
Attribute Definition Reader
UpdatedA Microsoft Entra documentation page was updated: Attribute Definition Reader.
Azure Devops Administrator
UpdatedA Microsoft Entra documentation page was updated: Azure Devops Administrator.
Billing Administrator
UpdatedA Microsoft Entra documentation page was updated: Billing Administrator.
Compliance Administrator
UpdatedA Microsoft Entra documentation page was updated: Compliance Administrator.
A Microsoft Entra documentation page was updated: Compliance Data Administrator.
A Microsoft Entra documentation page was updated: Customer Lockbox Access Approver.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
Directory Readers
UpdatedA Microsoft Entra documentation page was updated: Directory Readers.
Dynamics 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Dynamics 365 Administrator.
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
Edge Administrator
UpdatedA Microsoft Entra documentation page was updated: Edge Administrator.
Exchange Administrator
UpdatedA Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
Fabric Administrator
UpdatedA Microsoft Entra documentation page was updated: Fabric Administrator.
Groups Administrator
UpdatedA Microsoft Entra documentation page was updated: Groups Administrator.
Guest Inviter
UpdatedA Microsoft Entra documentation page was updated: Guest Inviter.
Insights Administrator
UpdatedA Microsoft Entra documentation page was updated: Insights Administrator.
Insights Analyst
UpdatedA Microsoft Entra documentation page was updated: Insights Analyst.
Insights Business Leader
UpdatedA Microsoft Entra documentation page was updated: Insights Business Leader.
Iot Device Administrator
UpdatedA Microsoft Entra documentation page was updated: Iot Device Administrator.
Kaizala Administrator
UpdatedA Microsoft Entra documentation page was updated: Kaizala Administrator.
Knowledge Administrator
UpdatedA Microsoft Entra documentation page was updated: Knowledge Administrator.
Knowledge Manager
UpdatedA Microsoft Entra documentation page was updated: Knowledge Manager.
License Administrator
UpdatedA Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
Message Center Reader
UpdatedA Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
Microsoft Entra Joined Device Local Administrator
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
Network Administrator
UpdatedA Microsoft Entra documentation page was updated: Network Administrator.
Office Apps Administrator
UpdatedA Microsoft Entra documentation page was updated: Office Apps Administrator.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
A Microsoft Entra documentation page was updated: Organizational Messages Approver.
A Microsoft Entra documentation page was updated: Organizational Messages Writer.
People Administrator
UpdatedA Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
Printer Administrator
UpdatedA Microsoft Entra documentation page was updated: Printer Administrator.
Printer Technician
UpdatedA Microsoft Entra documentation page was updated: Printer Technician.
Search Administrator
UpdatedA Microsoft Entra documentation page was updated: Search Administrator.
Search Editor
UpdatedA Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
Sharepoint Administrator
UpdatedA Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
Teams Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
Teams Devices Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Devices Administrator.
Teams Reader
UpdatedA Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
Tenant Creator
UpdatedA Microsoft Entra documentation page was updated: Tenant Creator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
Virtual Visits Administrator
UpdatedA Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
Viva Goals Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Goals Administrator.
Viva Pulse Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Pulse Administrator.
Windows 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
Yammer Administrator
UpdatedA Microsoft Entra documentation page was updated: Yammer Administrator.
author: msmimart
author: msmimart
User Administrator
Updated> | microsoft.directory/groups/restore | Restore groups from soft-deleted container |
Directory Writers
Updated> | microsoft.directory/groupSettings/basic/update | Update basic properties on group settings |
Cloud Device Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Domain Name Administrator
Updated> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
Iot Device Administrator
UpdatedAssign the IoT Device Administrator role to users who need to do the following tasks:
> [!div class="mx-tableFixed"]
Teams Reader
Updated> [!div class="mx-tableFixed"]
Microsoft 365 Migration Administrator
Partner Tier2 Support
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
Partner Tier1 Support
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
A Microsoft Entra documentation page was updated: Microsoft 365 Migration Administrator.
Global Administrator
Global Reader
Permissions Reference
UpdatedThis article lists the Microsoft Entra built-in roles you can assign to allow management of Microsoft Entra resources. For information about how to assign roles, see [Assign Microsoft Entra roles](manage-roles-portal.md). If you are looking for roles to manage Azure resources, see [Azure built-in roles](/azure/role-based-access-control/built-in-roles).
User Administrator
Hybrid Identity Administrator
Directory Readers
Partner Tier2 Support
Intune Administrator
Directory Writers
Partner Tier1 Support
Windows 365 Administrator
Privileged Role Administrator
SharePoint Administrator
Teams Administrator
Exchange Administrator
Helpdesk Administrator
Groups Administrator
Yammer Administrator
role
Newrole
IoT Device Administrator
AI Administrator
Dynamics 365 Business Central Administrator
Microsoft Graph Data Connect Administrator
role
Newrole
Guest Inviter
Microsoft Hardware Warranty Administrator
SharePoint Embedded Administrator
Teams Telephony Administrator
Attribute Assignment Administrator
Knowledge Administrator
Microsoft Hardware Warranty Specialist
role
Newrole
role
Newrole
Viva Glint Tenant Administrator
Viva Pulse Administrator
Virtual Visits Administrator
Microsoft 365 Backup Administrator
User Experience Success Manager
Attribute Assignment Reader
Insights Analyst
Knowledge Manager
Teams Communications Administrator
Viva Goals Administrator
Skype for Business Administrator
Attack Payload Author
Attack Simulation Administrator
Insights Administrator
License Administrator
Service Support Administrator
People Administrator
role
Newrole
Attribute Definition Administrator
Attribute Definition Reader
Assign the Dynamics 365 Administrator role to users who need to manage all aspects of Dynamics 365 services, including configuration, user management, and support tickets.
Extended Directory User Administrator
Fabric Administrator
Modern Commerce Administrator
Organizational Data Source Administrator
Power Platform Administrator
role
Newrole
role
Newrole
Teams Communications Support Specialist
Domain Name Administrator
Edge Administrator
role
Newrole
Teams Communications Support Engineer
Desktop Analytics Administrator
Insights Business Leader
Permissions Management Administrator
Kaizala Administrator
Printer Technician
Search Administrator
Search Editor
Tenant Creator
Exchange Recipient Administrator
Message Center Privacy Reader
Message Center Reader
Microsoft Entra Joined Device Local Administrator
Teams Devices Administrator
author: shlipsey3
Azure DevOps Administrator
Microsoft Entra Domain Services supports TLS versions 1.0 and 1.1, but they're disabled by default.
role
Newrole
role
Newrole
Teams Reader
NewTeams Reader
Printer Administrator
Windows Update Deployment Administrator
User Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the User Administrator role to users who need to do the following:
To enable group writeback, you must have:
Cloud Device Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can enable, disable, and delete devices in Microsoft Entra ID and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.
manager: CelesteDG
author: MicrosoftGuyJFlo
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage role assignments in Microsoft Entra ID, as well as within Microsoft Entra Privileged Identity Management. They can create and manage groups that can be assigned to Microsoft Entra roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units.
Connect Version History
Updated> [!IMPORTANT]
Ai Administrator
UpdatedA Microsoft Entra documentation page was updated: Ai Administrator.
Attack Payload Author
UpdatedA Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
Azure Devops Administrator
UpdatedA Microsoft Entra documentation page was updated: Azure Devops Administrator.
Billing Administrator
UpdatedA Microsoft Entra documentation page was updated: Billing Administrator.
Compliance Administrator
UpdatedA Microsoft Entra documentation page was updated: Compliance Administrator.
A Microsoft Entra documentation page was updated: Compliance Data Administrator.
A Microsoft Entra documentation page was updated: Customer Lockbox Access Approver.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
Directory Readers
UpdatedA Microsoft Entra documentation page was updated: Directory Readers.
Dynamics 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Dynamics 365 Administrator.
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
Edge Administrator
UpdatedA Microsoft Entra documentation page was updated: Edge Administrator.
Exchange Administrator
UpdatedA Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
Fabric Administrator
UpdatedA Microsoft Entra documentation page was updated: Fabric Administrator.
Groups Administrator
UpdatedA Microsoft Entra documentation page was updated: Groups Administrator.
Guest Inviter
UpdatedA Microsoft Entra documentation page was updated: Guest Inviter.
Insights Administrator
UpdatedA Microsoft Entra documentation page was updated: Insights Administrator.
Insights Analyst
UpdatedA Microsoft Entra documentation page was updated: Insights Analyst.
Insights Business Leader
UpdatedA Microsoft Entra documentation page was updated: Insights Business Leader.
Iot Device Administrator
UpdatedA Microsoft Entra documentation page was updated: Iot Device Administrator.
Kaizala Administrator
UpdatedA Microsoft Entra documentation page was updated: Kaizala Administrator.
Knowledge Administrator
UpdatedA Microsoft Entra documentation page was updated: Knowledge Administrator.
Knowledge Manager
UpdatedA Microsoft Entra documentation page was updated: Knowledge Manager.
License Administrator
UpdatedA Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
Message Center Reader
UpdatedA Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
A Microsoft Entra documentation page was updated: Microsoft Entra Joined Device Local Administrator.
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
Network Administrator
UpdatedA Microsoft Entra documentation page was updated: Network Administrator.
Office Apps Administrator
UpdatedA Microsoft Entra documentation page was updated: Office Apps Administrator.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
A Microsoft Entra documentation page was updated: Organizational Messages Approver.
A Microsoft Entra documentation page was updated: Organizational Messages Writer.
People Administrator
UpdatedA Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
Printer Administrator
UpdatedA Microsoft Entra documentation page was updated: Printer Administrator.
Printer Technician
UpdatedA Microsoft Entra documentation page was updated: Printer Technician.
Search Administrator
UpdatedA Microsoft Entra documentation page was updated: Search Administrator.
Search Editor
UpdatedA Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
Sharepoint Administrator
UpdatedA Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
Teams Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
Teams Devices Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Devices Administrator.
Teams Reader
UpdatedA Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
Tenant Creator
UpdatedA Microsoft Entra documentation page was updated: Tenant Creator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
Virtual Visits Administrator
UpdatedA Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
Viva Goals Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Goals Administrator.
Viva Pulse Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Pulse Administrator.
Windows 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
Yammer Administrator
UpdatedA Microsoft Entra documentation page was updated: Yammer Administrator.
When you configure group writeback, a checkbox appears at the bottom of the configuration window. Select it to enable this feature.
category:
Updatedmanager: pmwongera
Configure User Consent
Updated:::zone pivot="ms-powershell"
Confluencemicrosoft Tutorial
Updated- Confluence: 6.0.1 to 6.15.9
Digicert Tutorial
UpdatedTo configure the integration of DigiCert into Microsoft Entra ID, you need to add DigiCert from the gallery to your list of managed SaaS apps.
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Authentication Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Application Administrator
Updated> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> [!div class="mx-tableFixed"]
Learn how to use the authentication prompts analysis workbook in Microsoft Entra ID to investigate users getting too many MFA prompts.
Learn about the service level agreement performance and attainment for authentication services in Microsoft Entra ID
Learn how to use the sign-ins using legacy authentication workbook in Microsoft Entra ID to identify apps using legacy methods.
Sspr Policy
Updated| Password expiry (Let passwords never expire) |Default value: **false** (indicates that passwords have an expiration date).<br>The value can be configured for individual user accounts by using the [Update-MgUser](/powershell/module/microsoft.graph.users/update-mguser) cmdlet. |
author: owinfreyATL
author: owinfreyATL
Reference information for the factors that drive sign-in and audit log latency in Microsoft Entra ID
Learn about the data retention policies for the Microsoft Entra audit, sign-in, and provisioning logs.
Password Administrator
Updated> [!div class="mx-tableFixed"]
Learn about the recommendation to migrate application authentication from AD FS to Microsoft Entra ID
Learn why you should migrate from the Azure Active Directory Authentication Library to the Microsoft Authentication Libraries.
Learn about the Microsoft Entra recommendation to migrate to Microsoft Entra multifactor authentication from MFA server
Learn the importance of migrating your users to the Microsoft authenticator app in Microsoft Entra ID.
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Authentication Administrator
Updated> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
Application Administrator
Updated> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
Permissions Reference
Updated> | [Authentication Administrator](#authentication-administrator) | Can access to view, set and reset authentication method information for any non-admin user.<br/>[](privileged-roles-permissions.md) | c4e39bd9-1100-46d3-8c65-fb160da0071f |
For hybrid-joined devices, users must first authenticate with another method such as a password, smartcard or FIDO2 key, before using TAP to set up Windows Hello for Business.
> [!div class="mx-tableFixed"]
A Microsoft Entra documentation page was updated: Authentication Policy Administrator.
Learn about the recommendation to minimize multifactor authentication prompts from known devices in Microsoft Entra ID.
Customize Branding
UpdatedThe default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).
Password Administrator
Updated> [!div class="mx-tableFixed"]
How to download the audit, sign-in, and provisioning log data for manual storage in Microsoft Entra ID.
Learn how to troubleshoot sign-in errors using Microsoft Entra reports in the Microsoft Entra admin center
How to use the Sign-in diagnostic in tool Microsoft Entra ID to troubleshoot sign-in related scenarios.
Quickstart Analyze Sign In
Updatedauthor: shlipsey3
If you're using a federated Identity Provider (IdP), such as Active Directory Federation Services, and your MFA provider is integrated directly with this federated IdP, the federated IdP must be configured to send an MFA claim. For more information, see [Expected inbound assertions for Microsoft Entra MFA](how-to-mfa-expected-inbound-assertions.md).
Authentication Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:
> | microsoft.azure.serviceHealth/allEntities/allTasks | Read and configure Azure Service Health |
This is configured by the Authentication Policy Administrator through an [app configuration policy for managed Android Enterprise devices](/mem/intune/apps/app-configuration-policies-use-android) on the Microsoft Authenticator App, setting `sdm_suppress_camera_consent` equal to `true`, similar to how the `preferred_auth_method` is configured.
> | microsoft.directory/applications/authentication/update | Update authentication on all types of applications |
- Create and manage all aspects of custom authentication extensions.
Global Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Helpdesk Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).
Refresh Tokens
Updated| Password expires | Stays alive | Stays alive | Stays alive | Stays alive | Stays alive |
Password Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](../privileged-roles-permissions.md#who-can-reset-passwords).
Learn how to access and analyze Microsoft Entra sign-in and audit logs with the Microsoft Graph reporting APIs.
How to download the audit, sign-in, and provisioning log data for manual storage in Microsoft Entra ID.
Learn how to troubleshoot sign-in errors using Microsoft Entra reports in the Microsoft Entra admin center
How to use the Sign-in diagnostic in tool Microsoft Entra ID to troubleshoot sign-in related scenarios.
Learn about how flagged the sign-ins feature can be used for troubleshooting sign-in issues in Microsoft Entra ID.
Learn about the information available on each of the tabs on the Microsoft Entra sign-in log activity details.
Microsoft Entra seamless single sign-on (Seamless SSO) is a legacy authentication feature designed to provide passwordless access for domain-joined devices that are not hybrid Microsoft Entra ID joined. Seamless SSO relies on Kerberos authentication and is primarily beneficial for older operating systems like Windows 7 and Windows 8.1, which do not support Primary Refresh Tokens (PRT). If these legacy systems are no longer present in the environment, continuing to use Seamless SSO introduces unnecessary complexity and potential security exposure. Threat actors could exploit misconfigured or stale Kerberos tickets, or compromise the `AZUREADSSOACC` computer account in Active Directory, which holds the Kerberos decryption key used by Microsoft Entra ID. Once compromised, attackers could impersonate users, bypass modern authentication controls, and gain unauthorized access to cloud resources. Disabling Seamless SSO in environments where it is no longer needed reduces the attack surface and enforces the use of modern, token-based authentication mechanisms that offer stronger protections.
Authenticate Application Id
UpdatedTo enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Microsoft Entra or an administrator creates a single tenant non-Microsoft application in Microsoft Entra ID and uses one of the following relevant certificate management options for the credentials.
Microsoft Entra ID will update the guest authentication experience for B2B collaboration starting July 2025, completing by December 2025. Guest users will sign in via their home organization’s sign-in page, enhancing usability and reducing confusion. No administrative action is required, but review your B2B configuration.
Authentication Administrator
Privileged Authentication Administrator
Authentication Policy Administrator
Authentication Extensibility Administrator
The `getPreferredAuthConfiguration` method requires the Microsoft Authenticator app to be installed on the device. If the Microsoft Authenticator app isn't installed, the method returns `None`.
This is a [privileged role](../privileged-roles-permissions.md). Assign the Privileged Authentication Administrator role to users who need to do the following:
Authentication Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:
Enable Authenticator Passkey
Updatedauthor: justinha
Users with this role **cannot** do the following:
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create, manage and deploy provisioning configuration setup from Active Directory to Microsoft Entra ID using Cloud Provisioning as well as manage Microsoft Entra Connect, pass-through authentication (PTA), password hash synchronization (PHS), seamless single sign-on (seamless SSO), and federation settings. Does not have access to manage Microsoft Entra Connect Health. Users can also troubleshoot and monitor logs using this role.
This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Extensibility Administrator role to users who need to do the following tasks:
Authentication Qr Code
Updatedauthor: aanjusingh
Authentication Table Include
UpdatedA Microsoft Entra documentation page was updated: Authentication Table Include.
Password Administrator
Global Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Microsoft Entra Connect deployments vary from a single forest Express mode installation to complex deployments that are synced across multiple forests by using custom synchronization rules. Because of the large number of configuration options and mechanisms, it's essential to understand what settings are in effect and be able to quickly deploy a server with an identical configuration. This feature introduces the ability to catalog the configuration of a specific synchronization server and import the settings into a new deployment. You can compare different synchronization settings snapshots to easily visualize the differences between two servers or the same server over time.
Howto Mfa Reporting
Updatedauthor: justinha
Helpdesk Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).
Domain Name Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage (read, add, verify, update, and delete) domain names. They can also read directory information about users, groups, and applications, as these objects possess domain dependencies. For on-premises environments, users with this role can configure domain names for federation so that associated users are always authenticated on-premises. These users can then sign into Microsoft Entra based services with their on-premises passwords via single sign-on. Federation settings need to be synced via Microsoft Entra Connect, so users also have permissions to manage Microsoft Entra Connect.
Password Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).
Customize Branding
UpdatedThe default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).
author: justinha
How to configure certificate authorities for Microsoft Entra certificate-based authentication
UpdatedThe best way to configure the certificate authorities (CAs) is with the PKI-based trust store (Preview). You can delegate configuration with a PKI-based trust store to least privileged roles. For more information see, [Step 1: Configure the certificate authorities with PKI-based trust store (Preview)](how-to-certificate-based-authentication.md#step-1-configure-the-certificate-authorities-with-pki-based-trust-store).
Whats New Archive
Updated**Service category:** Authentications (Logins)
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Authenticate Application Id
UpdatedEntra Connect provides three options for application and certificate management:
Workbook Risk Analysis
UpdatedLearn how to use the identity protection risk analysis workbook in Microsoft Entra ID to explore trends and gaps in your risk policies.
author: shlipsey3
author: shlipsey3
Reference information for Microsoft Graph PowerShell cmdlets for Microsoft Entra monitoring and health.
Learn how the Microsoft Entra recommendation to remove unused apps works and why you should follow the guidance.
Learn how the Microsoft Entra recommendation to remove unused credentials from apps works and why it's important.
Learn how the Microsoft Entra recommendation to renew expiring application credentials works and why it's important.
Learn why you should turn off per user MFA in Microsoft Entra ID with Microsoft Entra recommendations
Workbook Mfa Gaps
UpdatedLearn how to use the MFA Gaps workbook in Microsoft Entra ID to identify apps and users who aren't protected by MFA.
Attribute Log Administrator
UpdatedA Microsoft Entra documentation page was updated: Attribute Log Administrator.
Attribute Log Reader
UpdatedA Microsoft Entra documentation page was updated: Attribute Log Reader.
Learn how to customize the columns and filter of the Microsoft Entra activity logs so you can analyze the results.
Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.
Learn how to use the Microsoft Entra recommendations to monitor and improve the health of your tenant.
Howto Use Workbooks
UpdatedLearn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.
Power Platform Administrator
UpdatedUsers in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Reports Reader.
Learn how to stream Microsoft Entra activity logs to an event hub for SIEM tool integration and analysis.
Usage Summary Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
Attack Payload Author
UpdatedUsers in this role can create attack payloads but not actually launch or schedule them. Attack payloads are then available to all administrators in the tenant who can use them to create a simulation. Access to reports is limited to simulations executed by the user, and this role doesn't grant access to aggregate reports such as Training efficacy, Repeat offenders, Training completion, or User coverage.
Learn how to configure the Microsoft Entra health monitoring email notifications to monitor and improve the health of your tenant.
Attribute Log Administrator
UpdatedUsers with this role **cannot** read audit logs for other events.
How to choose the right method for accessing and integrating the activity logs in Microsoft Entra ID.
Learn how to customize the columns and filter of the Microsoft Entra activity logs so you can analyze the results.
Learn how to detect and resolve Microsoft Entra user accounts that are inactive or obsolete using the Microsoft Entra admin center and Microsoft Graph.
Learn how to use the Microsoft Entra recommendations to monitor and improve the health of your tenant.
Howto Use Workbooks
UpdatedLearn how to use Azure Monitor workbooks for Microsoft Entra ID, for analyzing identity related activity, trends, and gaps.
Learn how to stream Microsoft Entra activity logs to an event hub for SIEM tool integration and analysis.
Attribute Log Reader
Attribute Log Administrator
Usage Summary Reports Reader
Reports Reader
Admin Audit Logging
UpdatedThe following table is a list of events that are logged with the new auditing feature. To view the events, use the Event Viewer and view the Application log.
Global Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview compliance portal, Azure portal, and Device Management admin center.
Power Platform Administrator
UpdatedUsers in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Reports Reader.
Usage Summary Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).
Admin Audit Logging
Updated|Event ID|Event name|Description|
Whats New
UpdatedAudit Activities
UpdatedGet an overview of the audit activities that can be logged in your audit logs in Microsoft Entra ID.
Device Registration
Updatedauthor: owinfreyATL
Directory Join
Updatedauthor: owinfreyATL
Hybrid Join
Updatedauthor: owinfreyATL
Overview
Updatedauthor: owinfreyATL
Primary Refresh Token
Updatedauthor: owinfreyATL
Whats New
Updated>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your  feed reader.
Monitoring Health
UpdatedLearn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.
Workbooks
UpdatedLearn how to create and work with Microsoft Entra workbooks, for identity monitoring, alerts, and data visualization.
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
Custom Extension Overview
Updatedmanager: CelesteDG
Intune Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).
Learn about the types of activities and events that are captured in Microsoft Entra audit logs and how you can use the logs for troubleshooting.
Monitoring Health
UpdatedLearn about the features and capabilities of the logs and reports in Microsoft Entra monitoring and health.
Usage and insights report
UpdatedLearn about the information you can explore using the Usage and insights report in Microsoft Entra ID.
Learn about the details included in the user provisioning logs in Microsoft Entra ID when a non-Microsoft service provisions users.
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
author: MicrosoftGuyJFlo
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
Attribute Assignment Reader
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
Attribute Definition Reader
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
Attribute Log Administrator
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).
Attribute Log Reader
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).
Intune Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).
Security Administrator
Updated> | microsoft.directory/applications/policies/update | Update policies of applications |
author: shlipsey3
Security Administrator
Updated> | microsoft.directory/applications/policies/update | Update policies of applications |
A Microsoft Entra documentation page was updated: Cloud App Security Administrator.
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
Security Administrator
Updated> | microsoft.directory/applications/policies/update | Update policies of applications |
Attribute Assignment Reader
UpdatedUsers with this role can read custom security attribute keys and values for supported Microsoft Entra objects.
Users with this role can define a valid set of custom security attributes that can be assigned to supported Microsoft Entra objects. This role can also activate and deactivate custom security attributes.
Attribute Definition Reader
UpdatedUsers with this role can read the definition of custom security attributes.
Security Administrator
Security Reader
Security Operator
A Microsoft Entra documentation page was updated: Cloud App Security Administrator.
Azure Information Protection Administrator
role
Newrole
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
> [!IMPORTANT]
Users with this role cannot read audit logs for other events. This role must be used in conjunction with the Cloud Application Administrator or Application Administrator roles (from least to most privileged) to read provisioning configurations.
This example includes custom security attributes that you could add to your tenant. Use the attribute set `HRConfidentialData` and then add the following attributes to:
Attribute Provisioning Administrator
Attribute Provisioning Reader
Directory Synchronization Accounts
This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Administrator role to users who need to do the following tasks:
This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Reader role to users who need to do the following tasks:
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
|name.givenName|String||✓|
Partner Tier2 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Partner Tier1 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
Partner Tier2 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Partner Tier1 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
Partner Tier2 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Partner Tier1 Support
Updated> | microsoft.directory/applications/audience/update | Update the audience property for applications |
Application Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
> | microsoft.directory/deletedItems.applications/delete | Permanently delete applications, which can no longer be restored |
Application Administrator
role
Newrole
Application Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role have the same permissions as the Application Administrator role, excluding the ability to manage application proxy. This role grants the ability to create and manage all aspects of enterprise applications and application registrations. Users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
Security Operator
Updated> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
Global Reader
Updated> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
Security Operator
Updated> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
Global Reader
Updated> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String||
Security Operator
Updated> | microsoft.directory/authorizationPolicy/standard/read | Read standard properties of authorization policy |
Learn how to configure SAML single sign-on between Microsoft Entra ID and a GitHub enterprise with Enterprise Managed Users.
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String||
Global Reader
Updated> | microsoft.directory/applications/synchronization/standard/read | Read provisioning settings associated with the application object |
Getthere Tutorial
UpdatedTo configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:[email protected]). They set this setting to have the SAML SSO connection set properly on both sides.
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber|String||✓
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
Learn how to use the Conditional Access gap analyzer workbook in Microsoft Entra ID to ensure resources are properly protected.
Learn how you can protect your tenant by enabling the Insider Risk condition in Conditional Access integrated with Microsoft Purview Adaptive Protection.
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
author: MicrosoftGuyJFlo
> | microsoft.directory/namedLocations/create | Create custom rules that define network locations |
> [!NOTE]
Conditional Access Grant
Updatedauthor: MicrosoftGuyJFlo
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have the ability to manage Microsoft Entra Conditional Access settings.
- Results are logged in the **Conditional Access** and **Report-only** tabs of the Sign-in log details.
Application Developer
Updated> | Actions | Description |
Learn about the Microsoft Entra recommendation to migrate from Azure Active Directory Graph APIs to Microsoft Graph APIs.
Application Developer
Updated> | Actions | Description |
author: shlipsey3
Application Developer
Updated> | Actions | Description |
Application Developer
Application Developer
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can create application registrations when the "Users can register applications" setting is set to No. This role also grants permission to consent on one's own behalf when the "Users can consent to apps accessing company data on their behalf" setting is set to No. Users assigned to this role are added as owners when creating new application registrations.
Microsoft Entra ID is updating its data retention policy for access reviews. Starting August 15, 2025, only the last 12 months of access review data will be available via the user interface and APIs. Organizations should export historical data before this date and establish a routine for annual data storage.
author: owinfreyATL
Learn how Microsoft Entra audit logs display UserManagement updates from Core Directory during verified domain changes.
Troubleshoot Device Dsregcmd
Updatedauthor: owinfreyATL
author: owinfreyATL
author: owinfreyATL
author: owinfreyATL
Attribute Log Reader
Updated- Configure diagnostic settings for custom security attributes
Learn how to archive Microsoft Entra activity logs to a storage account through Diagnostic settings.
A Microsoft Entra documentation page was updated: Organizational Branding Administrator.
role
Newrole
A Microsoft Entra documentation page was updated: Organizational Branding Administrator.
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
Identity Governance Administrator
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
manager: dougeby
Microsoft Entra ID Protection
4 updatesSecurity Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, as well as the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Users with this role have all permissions in the Azure Information Protection service. This role allows configuring labels for the Azure Information Protection policy, managing protection templates, and activating protection. This role doesn't grant any permissions in Microsoft Entra ID Protection, Privileged Identity Management, Monitor Microsoft 365 Service Health, Microsoft Defender XDR portal, or Microsoft Purview portal.
Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Microsoft Entra ID Governance
47 updatesSecurity Reader
Updated> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
Entitlement Management Roles
Updated> [!NOTE]
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
> | --- | --- |
Security Reader
Updated> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
When they lose an access package assignment, then they're removed from all the resource roles in the access package.
When you create an access package, you can specify the request, approval and lifecycle settings, which are stored on the first policy of the access package. Most access packages have a single policy for users to request access, but a single access package can have multiple policies. You would create multiple policies for an access package if you want to allow different sets of users to be granted assignments with different request and approval settings.
>[!VIDEO https://learn-video.azurefd.net/vod/player?id=25c39e83-da3e-4f41-8d91-8b865b25b702]
:::image type="content" source="./media/entitlement-management-access-package-first/resource-roles.png" alt-text="Screenshot the shows how to select the member role." lightbox="./media/entitlement-management-access-package-first/resource-roles.png":::
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
1. Provide a rule for dynamic membership groups using the [membership rule builder](../identity/users/groups-dynamic-membership.md) or by clicking **Edit** on the rule syntax text box.
1. Select **Update**.
> | --- | --- |
A Microsoft Entra documentation page was updated: Entitlement Management Access Package Assignments.
> Other least privilege roles that can complete this task include the Catalog owner and the Access package manager.
A Microsoft Entra documentation page was updated: Entitlement Management Access Package Lifecycle Policy.
A Microsoft Entra documentation page was updated: Entitlement Management Access Package Manage Lifecycle.
manager: dougeby
A Microsoft Entra documentation page was updated: Entitlement Management Access Package Requests.
A Microsoft Entra documentation page was updated: Entitlement Management Access Package Settings.
Lifecycle Workflow Audits
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Audits.
Security Reader
Updated> | microsoft.directory/accessReviews/definitions/allProperties/read | Read all properties of access reviews of all reviewable resources in Microsoft Entra ID |
The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.
> | microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create | Create access reviews for membership in groups that are assignable to Microsoft Entra roles |
A Microsoft Entra documentation page was updated: Check Workflow Execution Scope.
Create Lifecycle Workflow
UpdatedA Microsoft Entra documentation page was updated: Create Lifecycle Workflow.
Customize Workflow Email
UpdatedA Microsoft Entra documentation page was updated: Customize Workflow Email.
Customize Workflow Schedule
UpdatedA Microsoft Entra documentation page was updated: Customize Workflow Schedule.
Delete Lifecycle Workflow
UpdatedA Microsoft Entra documentation page was updated: Delete Lifecycle Workflow.
Download Workflow History
UpdatedA Microsoft Entra documentation page was updated: Download Workflow History.
Lifecycle Workflow Audits
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Audits.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Execution Conditions.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Extensibility.
Lifecycle Workflow History
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow History.
Lifecycle Workflow Insights
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Insights.
A Microsoft Entra documentation page was updated: Lifecycle Workflow On Premises.
Lifecycle Workflow Tasks
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Tasks.
Lifecycle Workflow Templates
UpdatedA Microsoft Entra documentation page was updated: Lifecycle Workflow Templates.
A Microsoft Entra documentation page was updated: Lifecycle Workflow Versioning.
> | --- | --- |
On Demand Workflow
UpdatedA Microsoft Entra documentation page was updated: On Demand Workflow.
What Are Lifecycle Workflows
UpdatedA Microsoft Entra documentation page was updated: What Are Lifecycle Workflows.
Workflows Faqs
UpdatedA Microsoft Entra documentation page was updated: Workflows Faqs.
Lifecycle Workflows Administrator
This is a [privileged role](../privileged-roles-permissions.md). Assign the Lifecycle Workflows Administrator role to users who need to do the following tasks:
Licensing Fundamentals
Updatedmanager: dougeby
Licensing Fundamentals
UpdatedMicrosoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees and requires an Azure subscription.
Microsoft Entra External ID
33 updates> [!div class="mx-tableFixed"]
B2c Ief Keyset Administrator
Updated> [!div class="mx-tableFixed"]
> [!div class="mx-tableFixed"]
B2c Ief Keyset Administrator
Updated> [!div class="mx-tableFixed"]
B2c Ief Policy Administrator
UpdatedA Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
External Identity Provider Administrator
B2C IEF Keyset Administrator
B2C IEF Policy Administrator
External ID User Flow Administrator
External ID User Flow Attribute Administrator
Training Videos
Updated> [!VIDEO https://www.youtube.com/embed/_CD3shvqpx4?si=cYvAO8CyXuI9YPiS]
B2c Ief Policy Administrator
UpdatedA Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
B2c Ief Policy Administrator
UpdatedUsers in this role have the ability to create, read, update, and delete all custom policies in Azure AD B2C and therefore have full control over the Identity Experience Framework in the relevant Azure AD B2C organization. By editing policies, this user can establish direct federation with external identity providers, change the directory schema, change all user-facing content (HTML, CSS, JavaScript), change the requirements to complete an authentication, create new users, send user data to external systems including full migrations, and edit all user information including sensitive fields like passwords and phone numbers. Conversely, this role cannot change the encryption keys or edit the secrets used for federation in the organization.
Training Videos
UpdatedThe video explains step-up authentication and tenant configuration. In step-up authentication, users sign in with minimal authentication steps, like a username and password, or a social identity. However, upon risky actions, like high-value transactions or accessing sensitive data, the application requires more verifications.
This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:
This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:
For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.
B2c Ief Keyset Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users assigned to this role can create and manage policy keys and secrets used for token encryption, token signing, and claim encryption/decryption. They can add new keys to existing key containers, enabling secret rollover without affecting existing applications. Additionally, users in this role can view the complete details of these secrets, including their expiration dates, even after creation.
Users with this role add or delete custom attributes available to all user flows in the Microsoft Entra organization. As such, users with this role can change or add new elements to the end-user schema and impact the behavior of all user flows, and indirectly result in changes to what data may be asked of end users and ultimately sent as claims to applications. This role can't edit user flows.
B2c Ief Keyset Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). User can create and manage policy keys and secrets for token encryption, token signatures, and claim encryption/decryption. By adding new keys to existing key containers, this limited administrator can roll over secrets as needed without impacting existing applications. This user can see the full content of these secrets and their expiration dates even after their creation.
B2b Fundamentals
Updated| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
What Is B2b
Updated- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.
- Organizations that own multiple Microsoft Entra tenants and want to streamline intra-organization cross-tenant application access.
- Cross-tenant synchronization is supported within the commercial cloud and Azure Government.
> Cross-cloud synchronization is currently in PREVIEW.
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
Service Limits
Updated|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |
Learn how to use the cross-tenant access activity workbook in Microsoft Entra ID to monitor the resources your external users are accessing.
Effective July 1, 2025, external users will lose access to content shared via SharePoint One Time Passcode (OTP) before enabling Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B. Resharing is required to restore access. Notify users and update internal documentation accordingly.
Microsoft Entra Verified ID
2 updatesmanager: femila
Issuer Revoke
Updatedmanager: femila
Microsoft Entra Workload ID
8 updatesService Principal Table
UpdatedReference table that maps application IDs to applications and their service principal usage from the sign-in logs.
Learn about the type of information captured in the managed identity sign-in logs in Microsoft Entra monitoring and health.
Learn how the Microsoft Entra recommendation to renew expiring service principal credentials work and why it's important.
Learn how to use the sensitive operations report workbook in Microsoft Entra ID to explore suspicious app and service principal activity.
author: barclayn
Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.
Directory Writers
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.
Users with this role can assign and remove custom security attribute keys and values for supported Microsoft Entra objects such as users, service principals, and devices.
Microsoft Entra Global Secure Access
16 updatesA Microsoft Entra documentation page was updated: Global Secure Access Administrator.
Global Secure Access Administrator
Customer intent: Windows users, I want to download and install the Global Secure Access client.
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Install Macos Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
A Microsoft Entra documentation page was updated: Global Secure Access Administrator.
1. Choose the right connector group with the connector deployed in the service endpoint subnet.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Install Macos Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
Macos Client Release History
UpdatedThis article tracks the changes in each released version of the Global Secure Access client for macOS.
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
Assign the Global Secure Access Log Reader role to users who need to do the following:
Global Secure Access Log Reader
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
- Cannot manage enterprise applications, application registrations, Conditional Access, or application proxy settings
Version History
Updated| Understand Microsoft Entra private network connectors | Find out more about [connector management](../identity/app-proxy/application-proxy-connectors.md) and how connectors [autoupgrade](../identity/app-proxy/application-proxy-connectors.md#automatic-updates). |
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
