- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
Week of 7 July 2025: Conditional Access optimization-agent guidance is the main substantive thread; TLS enforcement and Authenticator iOS backup are the key operational watch items
The Microsoft Learn feed is dominated by documentation maintenance: 223 updates, no new items, and one removed page. The most substantive cluster expands guidance for the Microsoft Entra Conditional Access optimization agent across Entra ID, Microsoft Security Copilot, and Agent ID. Other notable items are updated Microsoft Entra Domain Services TLS-enforcement guidance, a Global Secure Access and Netskope integration explicitly marked Preview, Azure AD Graph-format app-manifest deprecation guidance, and a September 2025 Microsoft Authenticator for iOS backup change from the Message Center. The supplied evidence does not establish a new GA launch or tenant-wide rollout for the documentation updates.
- Conditional Access optimization agent: expanded operational guidance, not a launch notice
Agent ID · Conditional Access
Updated Entra ID, Microsoft Security Copilot, and Agent ID pages describe an agent that analyzes sign-in patterns, identifies unprotected users and applications, recommends policy improvements, and helps consolidate redundant policies. The recommendations are aligned with Zero Trust guidance, but administrators decide what to apply and no changes are made without approval. The logging guidance adds a summary of discoveries from the last 30 days and security compute unit consumption; viewing Entra audit logs calls
- Microsoft Entra Domain Services: TLS 1.0 and 1.1 disabling is documented
Entra ID · Standards
Updated guidance says Microsoft is disabling TLS 1.0 and TLS 1.1 and points to TLS 1.2 or later for stronger cipher suites and perfect forward secrecy. The supplied record gives no enforcement date. Administrators should identify legacy clients or integrations that still negotiate the older protocols and test or update them for TLS 1.2 or later.
- Microsoft Authenticator for iOS: planned backup and restore behavior change from September 2025
External ID · Authentication
A 9 July Message Center major update says that starting in September 2025, Authenticator on iOS will use iCloud and iCloud Keychain for backup and restore, removing the need for a Microsoft personal account. Account names and third-party TOTP credentials will be backed up automatically. The notice explicitly says no admin action is required, making this a user-facing change rather than a tenant-configuration task.
- Global Secure Access and Netskope: ATP/DLP integration is explicitly Preview
Global Secure Access · Fundamentals
Updated Global Secure Access material covers Advanced Threat Protection and Data Loss Prevention policies powered by Netskope, as well as Security Service Edge coexistence with Microsoft and Netskope. The integration title explicitly labels the ATP/DLP capability as Preview. The evidence does not indicate general availability, a rollout date, or a required tenant change.
- Azure AD Graph-format app manifests: deprecation guidance, not a recorded retirement
Entra ID · General
An updated Entra ID article describes the deprecation of the app manifest's Azure AD Graph format and differences in attributes in the newer format. The supplied record includes no removal date or specific migration deadline, so it should be treated as deprecation guidance rather than evidence that the capability was retired during this week. Application owners whose scripts or runbooks use the old format should compare the affected attributes with the new format.
Check Microsoft Entra Domain Services clients and integrations for TLS 1.0 or 1.1 dependencies and move or test them on TLS 1.2 or later; no enforcement date is supplied. If the Conditional Access optimization agent is in use, administrators must review and approve its recommendations—no policy changes are made without approval. The updated guidance also documents a 30-day agent summary, security compute unit usage, and a Reports Reader requirement for viewing Entra audit logs. Treat the Netskope ATP/DLP material as preview guidance, and review automation that uses the deprecated Azure AD Graph-format app manifest without assuming a removal deadline. The Authenticator notice explicitly requires no admin action. The single removed Verified ID page has no explanation and is not, by itself,⋅e
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
177 updatescategory:
Updatedmanager: pmwongera
Template ID: d24aef57-1500-4070-84db-2666f29cf966
manager: pmwongera
A Microsoft Entra documentation page was updated: Microsoft 365 Migration Administrator.
Connect Microsoft Graph
UpdatedAfter enabling this feature, existing userPrincipalName values remain as-is. On next change of the userPrincipalName attribute on-premises, the normal delta sync on users updates the UPN. Once this feature is enabled, it's not possible to disable it.
Template ID: d24aef57-1500-4070-84db-2666f29cf966
Billing Administrator
UpdatedBilling Administrator
Cloud Device Administrator
UpdatedCloud Device Administrator
Compliance Administrator
UpdatedCompliance Administrator
Compliance Data Administrator
Customer LockBox Access Approver
Network Administrator
UpdatedNetwork Administrator
Office Apps Administrator
UpdatedOffice Apps Administrator
Organizational Messages Approver
Organizational Messages Writer
Ai Administrator
UpdatedA Microsoft Entra documentation page was updated: Ai Administrator.
Attack Payload Author
UpdatedA Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
A Microsoft Entra documentation page was updated: Attribute Assignment Administrator.
Attribute Assignment Reader
UpdatedA Microsoft Entra documentation page was updated: Attribute Assignment Reader.
A Microsoft Entra documentation page was updated: Attribute Definition Administrator.
Attribute Definition Reader
UpdatedA Microsoft Entra documentation page was updated: Attribute Definition Reader.
Azure Devops Administrator
UpdatedA Microsoft Entra documentation page was updated: Azure Devops Administrator.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
Directory Readers
UpdatedA Microsoft Entra documentation page was updated: Directory Readers.
Directory Writers
UpdatedA Microsoft Entra documentation page was updated: Directory Writers.
Domain Name Administrator
UpdatedA Microsoft Entra documentation page was updated: Domain Name Administrator.
Dynamics 365 Administrator
UpdatedDynamics 365 Administrator
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
Edge Administrator
UpdatedA Microsoft Entra documentation page was updated: Edge Administrator.
Exchange Administrator
UpdatedA Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
Fabric Administrator
UpdatedA Microsoft Entra documentation page was updated: Fabric Administrator.
Global Administrator
UpdatedA Microsoft Entra documentation page was updated: Global Administrator.
Global Reader
UpdatedA Microsoft Entra documentation page was updated: Global Reader.
Groups Administrator
UpdatedA Microsoft Entra documentation page was updated: Groups Administrator.
Guest Inviter
UpdatedA Microsoft Entra documentation page was updated: Guest Inviter.
Helpdesk Administrator
UpdatedA Microsoft Entra documentation page was updated: Helpdesk Administrator.
A Microsoft Entra documentation page was updated: Hybrid Identity Administrator.
Insights Administrator
UpdatedA Microsoft Entra documentation page was updated: Insights Administrator.
Insights Analyst
UpdatedA Microsoft Entra documentation page was updated: Insights Analyst.
Insights Business Leader
UpdatedA Microsoft Entra documentation page was updated: Insights Business Leader.
Intune Administrator
UpdatedA Microsoft Entra documentation page was updated: Intune Administrator.
Iot Device Administrator
UpdatedA Microsoft Entra documentation page was updated: Iot Device Administrator.
Kaizala Administrator
UpdatedA Microsoft Entra documentation page was updated: Kaizala Administrator.
Knowledge Administrator
UpdatedA Microsoft Entra documentation page was updated: Knowledge Administrator.
Knowledge Manager
UpdatedA Microsoft Entra documentation page was updated: Knowledge Manager.
License Administrator
UpdatedA Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
Message Center Reader
UpdatedA Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
A Microsoft Entra documentation page was updated: Microsoft Entra Joined Device Local Administrator.
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
Partner Tier1 Support
UpdatedA Microsoft Entra documentation page was updated: Partner Tier1 Support.
Partner Tier2 Support
UpdatedA Microsoft Entra documentation page was updated: Partner Tier2 Support.
People Administrator
UpdatedA Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
Permissions Reference
UpdatedA Microsoft Entra documentation page was updated: Permissions Reference.
Printer Administrator
UpdatedA Microsoft Entra documentation page was updated: Printer Administrator.
Printer Technician
UpdatedA Microsoft Entra documentation page was updated: Printer Technician.
A Microsoft Entra documentation page was updated: Privileged Role Administrator.
Search Administrator
UpdatedA Microsoft Entra documentation page was updated: Search Administrator.
Search Editor
UpdatedA Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
Sharepoint Administrator
UpdatedA Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
Teams Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
Teams Devices Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Devices Administrator.
Teams Reader
UpdatedA Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
Tenant Creator
UpdatedA Microsoft Entra documentation page was updated: Tenant Creator.
User Administrator
UpdatedA Microsoft Entra documentation page was updated: User Administrator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
Virtual Visits Administrator
UpdatedA Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
Viva Goals Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Goals Administrator.
Viva Pulse Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Pulse Administrator.
Windows 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
Yammer Administrator
UpdatedA Microsoft Entra documentation page was updated: Yammer Administrator.
Connect Version History
Updated> New Microsoft Entra Connect Sync Versions are only available via the Microsoft Entra admin center
Assign Local Admin
UpdatedYou can manage the [Microsoft Entra Joined Device Local Administrator](~/identity/role-based-access-control/permissions-reference.md#microsoft-entra-joined-device-local-administrator) role from **Device settings**.
Best Practices
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
Sharefile Tutorial
UpdatedTo configure the integration of Citrix ShareFile into Microsoft Entra ID, you need to add Citrix ShareFile from the gallery to your list of managed SaaS apps.
auth: {
Describes the deprecation of the app manifest (Azure AD Graph format) and attribute differences in the new format.
This article describes the federation metadata document that Microsoft Entra ID publishes for services that accept Microsoft Entra tokens.
Learn about the features and differences between single-tenant and multitenant apps in Microsoft Entra ID.
Learn how you can configure the terms of service and privacy statement for apps registered to use Microsoft Entra ID.
In this tutorial, you learn how to clean up the Azure resources allocated while creating the web app.
In this tutorial, you learn how to access data in Microsoft Graph from a web app for a signed-in user.
Connect Sso
Updated- It's supported on web browser-based clients and Office clients that support [modern authentication](/microsoft-365/enterprise/modern-auth-for-office-2013-and-2016) on platforms and browsers capable of Kerberos authentication:
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
manager: mwongerapk
Authentication Administrator
UpdatedA Microsoft Entra documentation page was updated: Authentication Administrator.
A Microsoft Entra documentation page was updated: Authentication Extensibility Administrator.
A Microsoft Entra documentation page was updated: Authentication Policy Administrator.
A Microsoft Entra documentation page was updated: Privileged Authentication Administrator.
This topic covers how to manage hardware oath tokens in Microsoft Entra ID, including Microsoft Graph APIs that you can use to upload, activate, and assign hardware OATH tokens.
Password Administrator
UpdatedA Microsoft Entra documentation page was updated: Password Administrator.
>[!Important]
By default, system-preferred MFA is Microsoft managed and enabled for all users.
If you don't plan on testing your app in the same tenant you registered it in, or you aren't an administrator in your tenant, you can't consent to the permissions from the [Microsoft Entra admin center](https://entra.microsoft.com). You can still consent to some permissions, however, by triggering a sign-in prompt in a web browser.
Howto Mfa Userstates
UpdatedThe per-user MFA administration experience in the Microsoft Entra admin center is recently improved. To view and manage user states, complete the following steps:
Tutorial Enable Sspr
UpdatedIn this tutorial, set up SSPR for a set of users in a test group. Use the *SSPR-Test-Group* and provide your own Microsoft Entra group as needed:
author: justinha
Learn about the AADSTS error codes that are returned from the Microsoft Entra security token service (STS).
Describes how to set up a pipeline in Azure Pipelines to build and deploy a web app to Azure and enable the Azure App Service built-in authentication. The article provides step-by-step instructions on how to configure Azure resources, build and deploy a web application, create a Microsoft Entra app registration, and configure App Service built-in authentication using Azure Pipelines.
Learn key terms used in Microsoft identity platform documentation, Microsoft Entra admin center, and authentication SDKs like the Microsoft Authentication Library (MSAL).
In this tutorial, you learn how to enable authentication for a web app running on Azure App Service. Limit access to the web app to users in your organization.
Learn about the sign-in flow of web, desktop, and mobile apps in Microsoft identity platform.
To create a PKI container object:
The Microsoft Entra Conditional Access optimization agent provides suggestions for your Conditional Access policies. The suggestions vary based on what the agent finds. As the administrator, you need to review the suggestions and decide what to do.
Conditional Access Administrator
Agent Optimization
UpdatedThe Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
The Microsoft Entra Conditional Access optimization agent provides suggestions for your Conditional Access policies. The suggestions vary based on what the agent finds. As the administrator, you need to review the suggestions and decide what to do. No changes are made without your approval.
For organizations that have no established use of device code flow, blocking can be done with the following Conditional Access policy:
Managed Policies
UpdatedAdministrators with at least the [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator) role assigned find these policies in the [Microsoft Entra admin center](https://entra.microsoft.com) under **Entra ID** > **Conditional Access** > **Policies**.
1. Sign into the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Reports Reader](../role-based-access-control/permissions-reference.md#reports-reader).
The **Agent summary** at the top of the Conditional Access optimization agent page provides a quick summary of what the agent has discovered in the last 30 days. The total number of [security compute units (SCU)](/copilot/security/manage-usage) consumed by the agent is also provided.
Developer guidance and scenarios for Microsoft Entra Conditional Access and Microsoft identity platform.
- To view the Microsoft Entra audit logs, you need at least the [Reports reader](../../identity/role-based-access-control/permissions-reference.md#reports-reader) role.
category: Monitoring
Updatedauthor: barclayn
Attribute Log Administrator
UpdatedA Microsoft Entra documentation page was updated: Attribute Log Administrator.
Attribute Log Reader
UpdatedA Microsoft Entra documentation page was updated: Attribute Log Reader.
Power Platform Administrator
UpdatedUsers in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Reports Reader.
Usage Summary Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).
Tenants are opted in to receive Microsoft Entra recommendation emails by default. To turn off these emails, follow these steps:
Cloud Application Administrator
Manage Consent Requests
UpdatedAfter disabling or restricting user consent, you have several important steps to take to help keep your organization secure as you continue to allow business-critical applications to be used. These steps are crucial to minimize impact on your organization's support team and IT administrators, and to help prevent the use of unmanaged accounts in non-Microsoft applications.
Application Administrator
UpdatedA Microsoft Entra documentation page was updated: Application Administrator.
Delete Application Portal
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Learn about the relationship between application and service principal objects in Microsoft Entra ID.
Learn how to implement role-based access control in your applications.
Describes the Microsoft Entra app manifest (Microsoft Graph format), which represents an application's identity configuration in a Microsoft Entra tenant.
Describes the Microsoft Entra app manifest, which represents an application's identity configuration in a Microsoft Entra tenant.
Application Developer
UpdatedA Microsoft Entra documentation page was updated: Application Developer.
Updates and breaking changes
UpdatedLearn about changes to the Microsoft identity platform that can impact your application.
Application model
UpdatedLearn about the process of registering your application so it can integrate with the Microsoft identity platform.
Learn about best practices, recommendations, and common oversights when integrating with the Microsoft identity platform.
Learn about what custom RBAC is and why it's important to implement in applications.
In this how-to, you configure an application registered with the Microsoft identity platform to change who, or what accounts, can access the application.
A description of authorization in the Microsoft identity platform, including scopes, permissions, and consent.
This article discusses the best practices for signing key rollover in Microsoft Entra ID.
Cloud App Security Administrator
Security Administrator
UpdatedA Microsoft Entra documentation page was updated: Security Administrator.
Security Operator
UpdatedA Microsoft Entra documentation page was updated: Security Operator.
Security Reader
UpdatedA Microsoft Entra documentation page was updated: Security Reader.
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
author: OwenRichards1
Learn how to use advanced certificate signing options in the SAML token for preintegrated apps in Microsoft Entra ID
Microsoft Entra ID has a gallery that contains thousands of preintegrated applications that use SSO. This article uses an enterprise application named **Microsoft Entra SAML Toolkit 1** as an example, but the concepts apply for most preconfigured enterprise applications in the Microsoft Entra application gallery.
Howto Use Recommendations
UpdatedMost recommendations follow the same pattern. You're provided information about how the recommendation works, its value, and some action steps to address the recommendation. This section provides an overview of the details provided in a recommendation, but aren't specific to one recommendation.
Use Copilot in Microsoft Entra to investigate identity risks and troubleshoot identity tasks quickly.
In this tutorial, you learn how to build a web app by using Azure App Service, sign in users to the web app, call Azure Storage, and call Microsoft Graph.
A Microsoft Entra documentation page was updated: Attribute Provisioning Administrator.
A Microsoft Entra documentation page was updated: Attribute Provisioning Reader.
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
Organizational Branding Administrator
Learn about application branding guidelines for Microsoft identity platform.
Recoverability Overview
Updated- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
Path Length Tip
Updatedauthor: OwenRichards1
Microsoft Entra Agent ID
1 updateThe Conditional Access optimization agent helps organizations improve their security posture by automatically analyzing sign-in patterns and suggesting policy optimizations. This Microsoft Security Copilot agent identifies unprotected users and applications, recommends policy improvements, and helps consolidate redundant policies.
Microsoft Entra ID Protection
1 updateUse Copilot in Microsoft Entra to quickly respond to identity threats by summarizing the risk level for a user and receiving insights relevant to the incident.
Microsoft Entra ID Governance
6 updatesA Microsoft Entra documentation page was updated: Lifecycle Workflows Administrator.
The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."
> [!IMPORTANT]
2. Select the directory you want to link: In the Microsoft Entra admin center toolbar, select the **Settings** icon in the portal toolbar. Then on the **Portal settings \| Directories + subscriptions** page, find your workforce tenant in the **Directory name** list, and then select **Switch**.
A conceptual article describing access package visibility in the My Access portal.
Use Microsoft Security Copilot in the Microsoft Entra admin center to create lifecycle workflows for Joiner, Mover, and Leaver scenarios. Execute workflows on-demand and use workflow insights to monitor execution and troubleshoot as needed.
Microsoft Entra External ID
21 updatesB2c Ief Keyset Administrator
UpdatedA Microsoft Entra documentation page was updated: B2c Ief Keyset Administrator.
B2c Ief Policy Administrator
UpdatedA Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
A Microsoft Entra documentation page was updated: External Identity Provider Administrator.
Service Limits
UpdatedLearn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.
Facebook Federation
UpdatedFederate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.
Cross Tenant Custom Roles
UpdatedA Microsoft Entra documentation page was updated: Cross Tenant Custom Roles.
| Microsoft 365 A3 student use benefits | M365EDU_A3_STUUSEBNFT | 18250162-5d87-4436-a834-d795c15c80f3 | AAD_BASIC_EDU (1d0f309f-fdf9-4b2a-9ae7-9c48b91f1426)<br/>RMS_S_ENTERPRISE (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>EducationAnalyticsP1 (a9b86446-fa4e-498f-a92a-41b447e03337)<br/>EXCHANGE_S_ENTERPRISE (efb87545-963c-4e0d-99df-69c6916d9eb0)<br/>INFORMATION_BARRIERS (c4801e8a-cb58-4c35-aca6-f2dcc106f287)<br/>MIP_S_CLP1 (5136a095-5cf0-4aff-bec3-e84448b38ea5)<br/>OFFICESUBSCRIPTION (43de0ff5-c92c-492b-9116-175376d08c38)<br/>MICROSOFTBOOKINGS (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>OFFICE_FORMS_PLAN_2 (9b5de886-f035-4ff2-b3d8-c9127bea3620)<br/>KAIZALA_O365_P3 (aebd3021-9f8f-4bf8-bbe3-0ed2f4f047a1)<br/>PROJECTWORKMANAGEMENT (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>MICROSOFT_SEARCH (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Deskless (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>STREAM_O365_E3 (9e700747-8b1d-45e5-ab8d-ef187ceec156)<br/>TEAMS1 (57ff2da0-773e-42df-b2af-ffb7a2317929)<br/>MINECRAFT_EDUCATION_EDITION (4c246bbc-f513-4311-beff-eba54c353256)<br/>INTUNE_O365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>ADALLOM_S_O365 (8c098270-9dd4-4350-9b30-ba4703f3b36b)<br/>SHAREPOINTWAC_EDU (e03c7e47-402c-463c-ab25-949079bedb21)<br/>PROJECT_O365_P2 (31b4e2fc-4cd6-4e7d-9c1b-41407303bd66)<br/>SCHOOL_DATA_SYNC_P2 (500b6a2a-7a50-4f40-b5f9-160e5b8c2f48)<br/>SHAREPOINTENTERPRISE_EDU (63038b2c-28d0-45f6-bc36-33062963b498)<br/>MCOSTANDARD (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>SWAY (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>BPOS_S_TODO_2 (c87f142c-d1e9-4363-8630-aaea9c4d9ae5)<br/>WHITEBOARD_PLAN2 (94a54592-cd8b-425e-87c6-97868b000b91)<br/>YAMMER_EDU (2078e8df-cff6-4290-98cb-5408261a760a)<br/>UNIVERSAL_PRINT_NO_SEEDING (b67adbaf-a096-42c9-967e-5a84edbe0086)<br/>Virtualization Rights for Windows 10 (E3/E5+VDA) (e7c91390-7625-45be-94e0-e16907e03118)<br/>AAD_PREMIUM (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>DYN365_CDS_O365_P2 (4ff01e01-1ba7-4d71-8cf8-ce96c3bbcf14)<br/>MFA_PREMIUM (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>ADALLOM_S_DISCOVERY (932ad362-64a8-4783-9106-97849a1a30b9)<br/>INTUNE_A (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>INTUNE_EDU (da24caf9-af8e-485c-b7c8-e73336da2693)<br/>POWERAPPS_O365_P2 (c68f8d98-5534-41c8-bf36-22fa496fa792)<br/>FLOW_O365_P2 (76846ad7-7776-4c40-a281-a386362dd1b9) | Microsoft Entra Basic for Education (1d0f309f-fdf9-4b2a-9ae7-9c48b91f1426)<br/>Azure Rights Management (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>Education Analytics (a9b86446-fa4e-498f-a92a-41b447e03337)<br/>Exchange Online (Plan 2) (efb87545-963c-4e0d-99df-69c6916d9eb0)<br/>Information Barriers (c4801e8a-cb58-4c35-aca6-f2dcc106f287)<br/>Information Protection for Office 365 - Standard (5136a095-5cf0-4aff-bec3-e84448b38ea5)<br/>Microsoft 365 Apps for enterprise (43de0ff5-c92c-492b-9116-175376d08c38)<br/>Microsoft Bookings (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>Microsoft Forms (Plan 2) (9b5de886-f035-4ff2-b3d8-c9127bea3620)<br/>Microsoft Kaizala Pro (aebd3021-9f8f-4bf8-bbe3-0ed2f4f047a1)<br/>Microsoft Planner (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>Microsoft Search (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Microsoft StaffHub (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>Microsoft Stream for Office 365 E3 (9e700747-8b1d-45e5-ab8d-ef187ceec156)<br/>Microsoft Teams (57ff2da0-773e-42df-b2af-ffb7a2317929)<br/>Minecraft Education Edition (4c246bbc-f513-4311-beff-eba54c353256)<br/>Mobile Device Management for Office 365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Office 365 Cloud App Security (8c098270-9dd4-4350-9b30-ba4703f3b36b)<br/>Office for the Web for Education (e03c7e47-402c-463c-ab25-949079bedb21)<br/>Project for Office (Plan E3) (31b4e2fc-4cd6-4e7d-9c1b-41407303bd66)<br/>School Data Sync (Plan 2) (500b6a2a-7a50-4f40-b5f9-160e5b8c2f48)<br/>SharePoint (Plan 2) for Education (63038b2c-28d0-45f6-bc36-33062963b498)<br/>Skype for Business Online (Plan 2) (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>Sway (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>To-Do (Plan 2) (c87f142c-d1e9-4363-8630-aaea9c4d9ae5)<br/>Whiteboard (Plan 2) (94a54592-cd8b-425e-87c6-97868b000b91)<br/>Yammer for Academic (2078e8df-cff6-4290-98cb-5408261a760a)<br/>Universal Print Without Seeding (b67adbaf-a096-42c9-967e-5a84edbe0086)<br/>Windows 10/11 Enterprise (e7c91390-7625-45be-94e0-e16907e03118)<br/>Microsoft Entra ID P1 (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>Common Data Service (4ff01e01-1ba7-4d71-8cf8-ce96c3bbcf14)<br/>Microsoft Azure Multi-Factor Authentication (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>Microsoft Defender for Cloud Apps Discovery (932ad362-64a8-4783-9106-97849a1a30b9)<br/>Microsoft Intune (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>Microsoft Intune for Education (da24caf9-af8e-485c-b7c8-e73336da2693)<br/>Power Apps for Office 365 (c68f8d98-5534-41c8-bf36-22fa496fa792)<br/>Power Automate for Office 365 (76846ad7-7776-4c40-a281-a386362dd1b9) |
Starting September 2025, Microsoft Authenticator on iOS will use iCloud and iCloud Keychain for backup and restore, eliminating the need for a Microsoft personal account. This update simplifies setup on new devices, with automatic backup of account names and third-party TOTP credentials. No admin action is required.
Create an enterprise application using the client ID for a multitenant application.
For B2B collaboration with other Microsoft Entra organizations, you should also review your [cross-tenant access settings](cross-tenant-access-settings-b2b-collaboration.yml) to ensure your inbound and outbound B2B collaboration and scope access to specific users, groups, and applications.
What Is B2b
Updated- **Example 2**: You allow B2B collaboration with Fabrikam in your cross-tenant access settings, but then you add `fabrikam.com` to your blocked domains in your external collaboration settings. Your users can't invite new Fabrikam business guests, but existing Fabrikam guests can continue using B2B collaboration.
B2b Direct Connect Overview
UpdatedMicrosoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.
Azure Monitor
UpdatedTo stop collecting logs to your Log Analytics workspace, delete the diagnostic settings you created. You'll continue to incur charges for retaining log data you've already collected into your workspace. If you no longer need the monitoring data you've collected, you can delete your Log Analytics workspace and the resource group you created for Azure Monitor. Deleting the Log Analytics workspace deletes all data in the workspace and prevents you from incurring other data retention charges.
Troubleshooting Known Issues
UpdatedCustomize Branding Customers
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Organizational Branding Administrator](~/identity/role-based-access-control/permissions-reference.md#organizational-branding-administrator).
Learn how to enforce multifactor authentication policies for Microsoft Entra B2B users.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) of the source tenant.
Microsoft Entra Verified ID
1 updateA Microsoft Entra documentation page was updated: Linkedin Employment Verification.
Microsoft Entra Workload ID
4 updatesDescribes how to use Azure PowerShell to create a Microsoft Entra application and service principal, and grant it access to resources through role-based access control. It shows how to authenticate application with a certificate.
The audience value must be set to one of the following values:<br/> • **Entra ID Global Service**: *api://AzureADTokenExchange* <br/>• **Entra ID for US Government**: *api://AzureADTokenExchangeUSGov* <br/>• **Entra ID China operated by 21Vianet**: *api://AzureADTokenExchangeChina* <br/>
In this tutorial, you learn how to access data in Microsoft Graph from a web app running in Azure App Service using managed identities.
Learn how to access Azure Storage from a web app in Azure App Service using managed identities. Simplify security and avoid managing secrets.
Microsoft Entra Global Secure Access
8 updatesConnector Groups
UpdatedYou must have multiple connectors to use connector groups. New connectors are automatically added to the **Default** connector group. For more information on installing connectors, see [configure connectors](how-to-configure-connectors.md).
manager: dougeby
Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
Partner Ecosystems Overview
Updatedauthor: kenwith
Compliant Network
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) with an account which has the [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator) and [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role activated.
A Microsoft Entra documentation page was updated: Global Secure Access Administrator.
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
author: kenwith
Security Copilot + Entra
6 updatesUse Microsoft Security Copilot and Microsoft Entra skills to quickly investigate potential risky applications.
Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate identity-based security incident.
Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
The Conditional Access optimization agent helps you ensure all users and applications are protected by Conditional Access policies. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
Agent Optimization
UpdatedLearn how the Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot can help secure your organization.
Learn how to review and apply suggestions provided by the Security Copilot for Microsoft Entra optimization agent.
