Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kisi Physical Security.
Secure-default changes and Workload ID authentication retirement headline the week
The week of 14 July 2025 was dominated by documentation maintenance: 308 of 315 records were updates, including large batches covering Microsoft Entra Connect, Cloud Sync, pass-through authentication, and hybrid identity. Those entries mainly refresh existing procedures and references; the supplied evidence does not show a new feature launch, general-availability release, or new runtime behavior in that material. The clear operational exceptions are Microsoft 365 security-default changes and the retirement of service-principal-less authentication. Workload ID also received new isolation-scope documentation, while Microsoft identity platform guidance now explicitly steers applications away from implicit grant.
- Microsoft 365 secure-by-default settings change
Entra ID · Authentication
Classification: Message Center major update and security-related behavior change. Microsoft 365 will update default settings to block legacy authentication protocols and require admin consent for third-party app access. The rollout starts in mid-July 2025 and completes by August 2025. The notice specifically calls for configuration assessment, stakeholder notification, documentation updates, and configuration of the Admin Consent workflow.
- Service-principal-less authentication is being retired
Workload ID · Authentication
Classification: Workload ID retirement and authentication behavior change. Microsoft Entra ID will block authentication for non-Microsoft multitenant applications that lack a service principal in the tenant where they authenticate. The scenario is also called service-principal-less authentication; it is already disabled for most non-Microsoft applications, with this change addressing the remaining exceptions as a preventive security measure.
- Isolation scope for user-assigned managed identities is newly documented
Workload ID · Security
Classification: new capability documentation, not a stated launch, preview, or general-availability announcement. New Workload ID pages explain isolation scope for user-assigned managed identities and how to configure it, describing security and resilience benefits. A related configuration page directs administrators to understand the benefits and implications first; the supplied evidence does not establish rollout status or require action.
- Authentication security guidance was clarified without evidence of enforcement
Entra ID · Authentication
Classification: documentation and security guidance. Updated Microsoft identity platform guidance says not to use the implicit grant and points developers to authorization code with PKCE instead. New Entra pages also focus on securing the My Security Info MFA-registration page and restricting high-risk sign-ins, but their supplied records contain no implementation details. These entries support review of application and security guidance, not an inference that new Conditional Access controls or runtime enforcement‑
Prioritize the Microsoft 365 Message Center change: assess legacy-authentication and third-party app-consent configurations, notify stakeholders, update internal documentation, and configure the Admin Consent workflow. For Workload ID, identify non-Microsoft multitenant applications authenticating in a tenant without a service principal; authentication for that scenario is being blocked, although the behavior has already been disabled for most non-Microsoft applications. Organizations using user-assigned managed identities can evaluate the new isolation-scope guidance, but no availability status or mandatory migration is supplied. Application owners should review use of implicit grant, while recognizing that the documentation update does not state that Microsoft Entra has disabled the flow
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
298 updatesLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Webroot Security Awareness Training.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to KnowBe4 Security Awareness Training.
This article lists all releases of Microsoft Entra provisioning agent and describes new features and fixed issues
This article describes how to install the Microsoft Entra Connect cloud provisioning agent.
This article describes the required accounts for each of the synchronization tools.
This article describes how the attribute mapping and how to configure attributes when provisioning from Microsoft Entra ID to Active Directory.
Lists the attributes that are synchronized to Microsoft Entra ID.
This article describes how you can configure accidental deletion prevention for the synchronization tools with Active Directory.
This article describes how you can configure the synchronization tools with Active Directory.
This document explains how various factors influence the Microsoft Entra Connect provisioning engine. These factors help organizations to plan their Microsoft Entra Connect deployment to make sure it meets their sync requirements.
This article describes how you can configure the synchronization tools to use single sign-on.
Learn how to install the Microsoft Entra Connect cloud provisioning agent by using PowerShell cmdlets.
This article describes the steps required to install either cloud sync or Microsoft Entra Connect.
This article describes the built-in automatic upgrade feature in the Microsoft Entra Connect cloud provisioning agent.
This article describes how to manage registry options in the Microsoft Entra Connect cloud provisioning agent.
Understand the Metaverse Designer tab in the Synchronization Service Manager for Microsoft Entra Connect.
Reference of declarative provisioning expressions in Microsoft Entra Connect Sync.
Understand Synchronization Service Manager for Microsoft Entra Connect.
Explains how Microsoft Entra Connect Sync works and how to customize.
This topic describes how to recover Microsoft Entra Connect Synchronization Service when it encounters LocalDB 10GB limit issue.
Learn how to use the Microsoft Entra provisioning agent gMSA PowerShell cmdlets.
This article describes how to use the cloud sync feature of Microsoft Entra Connect to test configuration changes.
This article describes how to use on-demand provisioning with Microsoft Entra Cloud Sync.
Understand the Metaverse Search tab in the Synchronization Service Manager for Microsoft Entra Connect.
This article introduces the various tools that can be used to synchronize the cloud with on-premises environments.
This article describes the steps to verify the version of the provisioning agent or connect sync.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Slack.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Acunetix 360.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Airbase.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Airtable.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Akamai Enterprise Application Access.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Albert.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlexisHR.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Alohi.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to ALVAO.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Amazon Business.
Configure Appaegis Isolation Access Cloud for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Appaegis Isolation Access Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Ardoq.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Asana.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Astro.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atmos.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Autodesk SSO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Axiad Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Better Stack.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BLDNG APP.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Blink.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Blinq.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Bonusly.
Configure Bustle B2B Transport Systems for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Bustle B2B Transport Systems.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Canva.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cerby.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Chaos.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Cisco Webex.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail Swiss.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ClearView Trade.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Colloquial.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Connecter.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ContractS CLM.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to CultureHQ.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cybozu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CybSafe.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Dagster Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Datadog.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Diffchecker.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Documo.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Egnyte.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Envoy.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Evercate.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Fortes Change Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Funnel Leasing.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Fuze.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Genesys Cloud for Azure.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Managed User (OIDC).
Configure GitHub Enterprise Managed User for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GitHub Enterprise Managed User.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoSkills.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GroupTalk.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Headspace.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hootsuite.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Hoxhunt.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Humbol.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Hypervault.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to IDEO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to InformaCast.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Insight4GRC.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insite LMS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to introDus Pre and Onboarding Platform.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Iris Intranet.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Island.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Jellyfish.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Juno Journey.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Keystone.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kintone.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Kno2fy.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to kpifire.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LawVu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Lucidchart.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Mixpanel.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to myPolicies.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to New Relic by Organization.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to NordPass.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to PrinterLogic SaaS.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to ProdPad.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Proware.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to RingCentral.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Rollbar.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Segment.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Shopify Plus.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Sigma Computing.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Smallstep SSH.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Snowflake.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SolarWinds Service Desk (previously Samanage).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Splashtop.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to SurveyMonkey Enterprise.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to TeamViewer.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to TerraTrue.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Thrive LXP.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Tic-Tac Mobile.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Uber.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Visibly.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Yellowbox.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zoom.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlertMedia.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atlassian Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AuditBoard.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AWS IAM Identity Center.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bentley - Automatic User Provisioning.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIC Cloud Design.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to BlogIn.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Boxcryptor.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bpanda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BrowserStack Single Sign-on.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BullseyeTDP.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CheckProof.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cisco User Management for Secure Access.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Clarizen One.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Clebex.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Coda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Code42.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Contentful.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to directprint.io.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Eletive.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to embed signage.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Exium.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Freshservice Provisioning.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to getAbstract.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub AE.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Global Relay Identity Sync.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GoLinks.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Gong.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Grammarly.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to H5mag.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Joyn FSM.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to KPN Grip.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to LanSchool Air.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to QA.
Describes how to use BypassDirSyncOverridesEnabled tenant feature to restore synchronization of Mobile and OtherMobile attributes from on-premises Active Directory.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to ThousandEyes.
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Box so that I can streamline the user management process and ensure that users have the appropriate access to Box..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cornerstone OnDemand so that I can streamline the user management process and ensure that users have the appropriate access to Cornerstone OnDemand..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to DocuSign so that I can streamline the user management process and ensure that users have the appropriate access to DocuSign..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to GoToMeeting so that I can streamline the user management process and ensure that users have the appropriate access to GoToMeeting..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Jive so that I can streamline the user management process and ensure that users have the appropriate access to Jive..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Merchlogix so that I can streamline the user management process and ensure that users have the appropriate access to Merchlogix..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Salesforce Sandbox so that I can streamline the user management process and ensure that users have the appropriate access to Salesforce Sandbox..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Velpic so that I can streamline the user management process and ensure that users have the appropriate access to Velpic..
author: nguhiu
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Netpresenter Next.
21869
UpdatedWhen enterprise applications lack both explicit assignment requirements AND scoped provisioning controls, threat actors can exploit this dual weakness to gain unauthorized access to sensitive applications and data. The highest risk occurs when applications are configured with the default setting: "Assignment required" is set to "No" *and* provisioning isn't required or scoped. This dangerous combination allows threat actors who compromise any user account within the tenant to immediately access applications with broad user bases, expanding their attack surface and potential for lateral movement within the organization.
Decommission Connect Sync V1
UpdatedThis article describes Azure AD Connect V1 decommissioning and how to migrate to V2.
This article describes the steps needed to successfully migrate groups from one forest to another for Microsoft Entra Connect.
Explains the different methods to upgrade to the latest release of Microsoft Entra Connect, including an in-place upgrade and a swing migration.
This article describes how to migrate groups that were initially set up for Group Writeback by using Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync.
Describes steps to migrate Microsoft Entra Connect to Microsoft Entra Cloud Sync.
This article describes what to do if you find that you're running a deprecated version.
This topic describes in more detail features which are in preview in Microsoft Entra Connect.
This article describes how to use the cloud sync feature of Microsoft Entra Connect to map attributes.
This article describes the common scenarios for using Microsoft Entra Cloud Sync and Microsoft Entra Connect.
Connect Fed Sha256 Guidance
UpdatedThis page provides guidelines for changing SHA algorithm for federation trust with Microsoft 365.
In this document, you'll learn how to federate multiple Microsoft Entra IDs with a single AD FS.
Connect Sync Recycle Bin
UpdatedThis topic recommends the use of AD Recycle Bin feature with Microsoft Entra Connect.
This article explains the custom installation options for Microsoft Entra Connect. Use these instructions to install Active Directory through Microsoft Entra Connect.
This article describes the steps required to integrate with Active Directory.
This article describes how to enable group writeback in Microsoft Entra Connect by using PowerShell and a wizard.
Learn how to fix modified default rules that come with Microsoft Entra Connect.
This article describes how to install and use single sign-on with cloud sync.
This page is a technical reference page for ports that are required to be open for Microsoft Entra Connect
Learn about the next version of Microsoft Entra Connect.
This article provides information on custom attribute mapping in cloud sync.
reference
This article describes how to use transformations to alter the default attribute mappings.
Microsoft Entra Connect - Manage AD FS trust with Microsoft Entra ID using Microsoft Entra Connect
UpdatedOperational details of Microsoft Entra ID trust handling by Microsoft Entra Connect.
This page is the central location for all documentation regarding AD FS operations that use Microsoft Entra Connect.
This document describes how to obtain GDPR compliancy with Microsoft Entra Connect.
Learn about user privacy and data collection with Microsoft Entra Connect Health.
Describes service side features for Microsoft Entra Connect Sync service.
Describes how shadow attributes work in Microsoft Entra Connect Sync service.
This topic describes the built-in scheduler feature in Microsoft Entra Connect Sync.
This document provides reference information for the ADConnectivityTools.psm1 PowerShell module.
This topic describes the built-in automatic upgrade feature in Microsoft Entra Connect Sync.
This document details device options available in Microsoft Entra Connect
Special considerations for deploying Microsoft Entra Connect with the Azure Government cloud.
This topic describes attribute behavior of the msExchUserHoldPolicies and cloudMsExchUserHoldPolicies attributes
This article describes how the Microsoft Entra seamless single sign-on feature works.
This topic walks you through how to select the installation type to use for Microsoft Entra Connect
This page documents special considerations for Microsoft Entra instances.
This page has non-Microsoft identity providers that can be used to implement single sign-on.
This topic describes Microsoft Entra seamless single sign-on and how it allows you to provide true single sign-on for corporate desktop users inside your corporate network.
This article describes the prerequisites required to integrate with Active Directory.
This article describes the prerequisites and hardware requirements you need for cloud sync.
Learn how to get started with Microsoft Entra seamless single sign-on by using Microsoft Entra Connect.
Explains how the installation wizard works the second time you run it.
This topic describes the pre-requisites and the hardware requirements cloud sync.
Learn how to add cloud sync to an existing hybrid identity environment.
This document describes how to uninstall Microsoft Entra Connect.
This article describes how to use the expression builder with cloud sync.
This article deals with Microsoft Entra seamless SSO and GDPR compliance.
This document describes the releases for Microsoft Entra Connect Health and what has been included in those releases.
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
Microsoft 365 will update default settings to enhance security by blocking legacy authentication protocols and requiring admin consent for third-party app access. Changes start mid-July 2025 and complete by August 2025. Organizations should assess configurations, notify stakeholders, update documentation, and configure the Admin Consent workflow.
1. Is the Connect server in [staging mode](how-to-connect-sync-staging-server.md)? A server in staging mode does not synchronize any passwords.
The Cloud Password Policy for Password-Synced Users feature ensures that Microsoft Entra ID enforces its native password policies (such as expiration and lockout), for users whose passwords are synchronized from on-premises Active Directory. This feature enables you to align the same on-premises Active Directory password policy with the Microsoft Entra password policy, for synchronized users.
This guide helps CEOs, CIOs, CISOs, Chief Identity Architects, Enterprise Architects, and Security and IT decision makers responsible for choosing an authentication method for their Microsoft Entra hybrid identity solution in medium to large organizations.
Learn how Microsoft Entra pass-through authentication protects your on-premises accounts.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forcepoint Cloud Security Gateway - User Authentication.
author: gargi-sinha
This article describes how to upgrade your Microsoft Entra pass-through authentication configuration.
Connect Pta
UpdatedThis article describes Microsoft Entra pass-through authentication and how it allows Microsoft Entra sign-ins by validating users' passwords against on-premises Active Directory.
This article describes the current limitations of Microsoft Entra pass-through authentication
Connect Pta User Privacy
UpdatedThis article deals with Microsoft Entra pass-through authentication and GDPR compliance.
This article describes how to disable pass-through authentication by using the Microsoft Entra Connect Do Not Configure feature or by using PowerShell.
This article describes how Microsoft Entra pass-through authentication works
This article describes how to troubleshoot Microsoft Entra pass-through authentication.
This article describes how to get started with Microsoft Entra pass-through authentication.
This article lists all releases of the Microsoft Entra pass-through authentication agent
Hybrid identity is having a common user identity for authentication and authorization both on-premises and in the cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks Cloud Identity Engine - Cloud Authentication Service.
This article describes how to allow the Microsoft Entra Connect application to authenticate with Microsoft Entra ID with modern, more secure credentials.
This topic document describes how to update Microsoft Entra Connect after the password of the AD DS account is changed.
This article discusses how to manage AD FS with Microsoft Entra Connect and customize the AD FS user sign-in experience with Microsoft Entra Connect and PowerShell.
This topic document describes the encryption key and how to abandon it after the password is changed.
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Agile Provisioning so that I can control who has access to Agile Provisioning, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location..
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Authorization Basics
UpdatedAuthorization logic is often implemented within the applications or solutions where access control is required. In many cases, application development platforms offer middleware or other API solutions that simplify the implementation of authorization. Examples include use of the [AuthorizeAttribute](/aspnet/core/security/authorization/simple?view=aspnetcore-5.0&preserve-view=true) in ASP.NET or [Route Guards](./scenario-spa-sign-in.md?tabs=angular2#sign-in-with-a-pop-up-window) in Angular.
Msal Authentication Flows
Updated| [Implicit grant](#implicit-grant) | User sign-in and access to web APIs on behalf of the user. *Do not use this flow - use authorization code with PKCE instead.* | * [Single-page app (SPA)](scenario-spa-app-registration.md) <br /> * [Web](scenario-web-api-call-api-app-registration.md) |
author: shlipsey3
Enable Passkey Fido2
Updated- Metadata for FIDO2 security keys needs to be published and verified with the FIDO Alliance Metadata Service, and also pass another set of validation testing by Microsoft. For more information, see [Become a Microsoft-compatible FIDO2 security key vendor](/entra/identity/authentication/concept-fido2-hardware-vendor).
This topic provides deep dive information on how cloud sync works.
This document provides an overview of the installation options and paths available for installing Microsoft Entra Connect and Connect Health.
Explains the technical concepts of Microsoft Entra Connect Sync.
Explains users, groups, and contacts in Microsoft Entra Connect Sync.
Explains the declarative provisioning expressions.
Explains the declarative provisioning configuration model in Microsoft Entra Connect.
This document introduces the new ADConnectivity PowerShell module and how it can be used to help troubleshoot.
Describes federation with Microsoft Entra ID.
Describes overview of identity provisioning.
Describes overview of identity inter-directory provisioning.
Describes Microsoft Entra Cloud Sync.
Learn about the tools used to synchronize and monitor your on-premises environment with Microsoft Entra ID.
Describes the tools that are used to synchronize and monitor your on-premises environment with Microsoft Entra ID.
This article describes the provisioning agent used by cloud sync and on-premsises app provisioning.
Configure Security
UpdatedA Microsoft Entra documentation page was updated: Configure Security.
Configure Security
Updatedauthor: MicrosoftGuyJFlo
reference article for cloud sync error codes
This article describes how to troubleshoot problems that might arise with the cloud provisioning agent.
This topic provides the remediation steps for LargeObject errors caused by userCertificate attribute.
This document describes the diagnosis process of duplicated attribute synchronization errors and a potential fix of the orphaned object scenarios directly from the [Microsoft Entra admin center](https://entra.microsoft.com).
Learn how to synchronize one object from Active Directory to Microsoft Entra ID for troubleshooting.
This article explains how to troubleshoot errors that occur during synchronization with Microsoft Entra Connect.
This topic provides steps for how to troubleshoot issues with attribute synchronization using the troubleshooting task.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to MX3 Diagnostics Connector.
Learn how to force your Microsoft Entra Connect server to use only Transport Layer Security (TLS) 1.2.
- [Manage Microsoft 365 for iOS and Android with Microsoft Intune](/intune/intune-service/apps/manage-microsoft-office#copilot-with-enterprise-data-protection)
author: shlipsey3
author: shlipsey3
author: barclayn
Network Considerations
UpdatedGet-AzNetworkSecurityGroup -Name "nsg-name" -ResourceGroupName "resource-group-name" | Add-AzNetworkSecurityRuleConfig -Name "new-rule-name" -Access "Allow" -Protocol "TCP" -Direction "Inbound" -Priority "priority-number" -SourceAddressPrefix "CorpNetSaw" -SourcePortRange "*" -DestinationPortRange "3389" -DestinationAddressPrefix "*" | Set-AzNetworkSecurityGroup
This article describes the Microsoft Entra Connect Health AD FS Risky IP report.
Learn about various on-premises and Microsoft Entra topologies that use Microsoft Entra Cloud Sync.
This document shows the catalog of all alerts in Microsoft Entra Connect Health.
This is the Microsoft Entra Connect Health page how to monitor your on-premises AD FS infrastructure.
This article explains how to monitor changes to your federation configuration with Microsoft Entra ID.
This document describes using a SAML 2.0 compliant Idp for single sign-on.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insightly SAML.
Configure Palo Alto Networks SCIM Connector for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks SCIM Connector.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon SAML.
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
Mobile Sso Support Overview
UpdatedIn addition, enabling single sign-on in your app unlocks new authentication mechanisms that come with modern authentication, like [passwordless logins](~/identity/authentication/concept-authentication-passwordless.md). Usernames and passwords are one of the most popular attack vectors against applications, and enabling SSO allows you to mitigate this risk by enforcing Conditional Access or passwordless logins that add extra security or rely on more secure authentication mechanisms. Finally, enabling single sign-on also enables [single sign-out](v2-protocols-oidc.md#single-sign-out). This is useful in situations like work applications that will be used on shared devices.
- **C2** – Require compliant devices
Microsoft Entra ID returns an HTTP response with some interesting data:
Get information on how to configure group claims for use with Microsoft Entra ID.
This document covers updates to the Microsoft Entra Connect Sync v2 endpoints API.
author: barclayn
This topic describes the architecture of Microsoft Entra Connect Sync and explains the terms used.
This topic describes how to enable inbound synchronization using just the Graph API
Microsoft Entra ID Governance
7 updatesCustomize Workflow Email
Updated1. On the pane that lists tasks, select the task for which you want to customize the email.
Lifecycle Workflow Tasks
Updated}
|Item|Description|
| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |
:::image type="content" source="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png" alt-text="Screenshot of the settings page under access reviews." lightbox="./media/pim-create-azure-ad-roles-and-resource-roles-review/current-v-series-setting.png":::
Whats New
Updated**Service category:** Lifecycle Workflows
Complete Access Review
Updated> - User not found / other errors can also result in an apply result not being supported.
Microsoft Entra External ID
1 updateMigrate Users
Updated- If you are migrating from Azure AD B2C, the [seamless user migration sample](https://github.com/azure-ad-b2c/samples/tree/master/policies/migrate-to-entra-external-id-for-customers) repository on GitHub contains a seamless migration custom policy example and REST API code sample.
Microsoft Entra Private Access
2 updatesmanager: dougeby
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Microsoft Entra Workload ID
5 updatesLearn about isolation scope for user-assigned managed identities and how it improves security and resilience.
Learn how to configure isolation scope for user-assigned managed identities to improve security and resilience.
Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.
- Read the [Isolation scope for user-assigned managed identities](managed-identities-isolation-scope.md) concept article to understand the benefits and implications.
A Microsoft Entra documentation page was updated: Enable Managed Identities Regional Isolation.
Transport Layer Security
Updated```
Security Copilot + Entra
1 updateAgent Optimization
UpdatedThe Security Administrator and Global Administrator roles have access to Security Copilot by default. You can assign Conditional Access Administrators with Security Copilot access. This authorization gives your Conditional Access Administrators the ability to use the agent as well. For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access).
