> [!NOTE]
Entra week: cross-cloud synchronization preview leads, while retirement guidance surfaces for Permissions Management and workload authentication
The most consequential product-level item for the week of 29 September is the 3 October Microsoft 365 Message Center notice for Microsoft Entra cross-cloud synchronization. The notice calls it public preview and opt-in, while listing general availability for late September–early October 2025; that is not an unqualified GA confirmation. The other meaningful signals are new offboarding guidance for an anticipated Microsoft Entra Permissions Management deprecation and updated Workload ID mitigation guidance for retiring service principal-less authentication. Much of the remaining supplied Learn activity is ordinary maintenance—especially a large Native Authentication API, CORS, Android, iOS/macOS, and SPA tutorial set with author- and manager-style summaries—so it should not be read as evidence of launches or changed tenant behavior.
- Cross-cloud synchronization is announced as an opt-in public preview
ID Governance · Microsoft identity platform
The Message Center notice says the capability automates user lifecycle management across Microsoft commercial, US Government, and China clouds. It requires specific licenses and administrator enablement and supports configuration through the portal, PowerShell, and API. The notice separately lists late September–early October 2025 as the general-availability window, so the supplied evidence supports preview planning rather than a claim that GA is complete.
- Permissions Management receives offboarding guidance for an anticipated deprecation
Entra ID · General
New Microsoft Entra Permissions Management content includes an explicit offboarding guide for an anticipated product deprecation. The same documentation set covers onboarding Azure, AWS, and GCP accounts or projects, alerts, analytics, remediation, controller and data-collection settings, user access management, and API settings. These are new documentation pages, not proof that the capabilities launched this week; no deprecation date or replacement is provided.
- Workload ID retirement guidance addresses service principal-less authentication
Workload ID · Authentication
An updated Workload ID article specifically covers retiring service principal-less authentication and says tenant administrators should perform mitigation steps. The record does not state a retirement date, identify affected configurations, or announce an enforcement change, so the evidenced change is the availability of mitigation guidance rather than a dated service cutoff.
- Conditional Access and ID Protection updates reinforce a staged security rollout
Entra ID · Conditional Access
Related Learn updates state that policies created from Conditional Access templates are in report-only mode by default and should be tested and monitored before enablement. They also document enforcing Intune device compliance for Conditional Access-protected services, password changes for elevated user risk, and sign-in risk-based multifactor authentication. These are security and rollout guidance updates; the supplied records do not announce changed Conditional Access defaults or ID Protection behavior.
- Pass-through Authentication setup prerequisites are clarified
Entra ID · Governance
The updated Connect Pass-through Authentication quick start calls out Windows Server 2022, 2019, or 2016, TLS 1.2, placement in the same Active Directory forest as the users whose passwords are validated, and lack of support for the PTA agent on Windows Server Core. This is a documentation clarification for setup planning, not an announced installer rule or stated change to existing deployments.
For cross-cloud synchronization, assess whether the tenant needs user lifecycle management across Microsoft commercial, US Government, and China clouds, then check the notice’s specific licensing and administrator-enablement prerequisites; the supplied status is opt-in preview. Organizations using Permissions Management should review the offboarding guidance and plan for the anticipated deprecation, but no retirement date or replacement is supplied. Workload ID administrators should follow the documented mitigation steps if service principal-less authentication is relevant. For Conditional Access and Pass-through Authentication, use the updated report-only, test-and-monitor, and setup-prerequisite guidance without assuming that the underlying service behavior changed this week.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
308 updates> [!NOTE]
Develop Preview
Updatedmanager: pmwongera
A Microsoft Entra documentation page was updated: Multi Service Web App Access Storage.
author: cilwerner
Access Tokens
Updatedauthor: cilwerner
> [!NOTE]
Add and remove roles and tasks for Microsoft Azure and Google Cloud Platform (GCP) identities
Updated> [!NOTE]
> [!NOTE]
author: kengaderdus
> [!NOTE]
Claims Customization
Updatedauthor: cilwerner
Claims Validation
Updatedauthor: cilwerner
author: cilwerner
Create a custom query
Updated> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
Id Token Claims Reference
Updatedauthor: cilwerner
Id Tokens
Updatedauthor: cilwerner
Jwt Claims Customization
UpdatedA Microsoft Entra documentation page was updated: Jwt Claims Customization.
Libraries Daemon
Updatedmanager: pmwongera
Libraries Desktop
Updatedmanager: pmwongera
Libraries Mobile
Updatedmanager: pmwongera
Libraries Spa
Updatedmanager: pmwongera
Libraries Webapp
Updatedmanager: pmwongera
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
A Microsoft Entra documentation page was updated: Multi Service Web App Access Microsoft Graph As App.
A Microsoft Entra documentation page was updated: Multi Service Web App Access Microsoft Graph As User.
A Microsoft Entra documentation page was updated: Multi Service Web App Clean Up Resources.
> [!NOTE]
> [!NOTE]
> [!NOTE]
Optional Claims
Updatedauthor: cilwerner
Optional Claims Reference
Updatedauthor: cilwerner
> [!NOTE]
Refresh Tokens
Updatedauthor: cilwerner
Schema Extensions
Updatedauthor: cilwerner
> [!NOTE]
> [!NOTE]
A Microsoft Entra documentation page was updated: Tutorial V2 Shared Device Mode.
Use Custom Domain Url
Updatedmanager: dougeby
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
How to transition off of Microsoft Entra Permissions Management for the anticipated product deprecation.
View the latest public preview and general availability of features in Permissions Management.
How to add an account/subscription/project to Permissions Management after onboarding is complete.
How to configure Okta as an identity provider in Microsoft Entra Permissions Management.
How to create and view activity alerts and alert triggers in Microsoft Entra Permissions Management.
How to create and view permission analytics triggers in the Permission analytics tab in Permissions Management.
How to create and view rule-based anomaly alerts and alert triggers in Permissions Management.
How to create and view statistical anomaly alerts and alert triggers in the Statistical Anomaly tab in Permissions Management.
How to define and manage users, roles, and access levels in the Permissions Management User management dashboard.
How to enable or disable the controller in Permissions Management after onboarding is complete.
Frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
Quickstart guide - How to quickly onboard your Microsoft Entra Permissions Management product
How to onboard a Google Cloud Platform (GCP) project on Permissions Management.
How to a Microsoft Azure subscription on Permissions Management.
How to onboard an Amazon Web Services (AWS) account to Permissions Management.
How to view analytic information about access keys in Permissions Management.
How to view usage analytics about active resources in Permissions Management.
How to view analytic information about active tasks in Permissions Management.
How to view analytic information about groups in Permissions Management.
How to view analytic information about serverless functions in Permissions Management.
How to view analytic information about users in Permissions Management.
How to view and configure settings for collecting data from your authorization system.
How to view statistics and data about your authorization system in the Permissions Management.
Microsoft Entra Permissions Management glossary
How to generate, view, and apply rule recommendations in the Microsoft Entra Permissions Management Autopilot dashboard.
How to manage users and groups in the User management dashboard in Permissions Management.
How to view information about alerts and alert triggers in the Alerts dashboard in Permissions Management.
How to view data about the activity in your authorization system in the Microsoft Entra Permissions Management Dashboard.
How to view information about rules in the Autopilot dashboard in Permissions Management.
How to view information about identities that can access accounts from an external account in Permissions Management.
How to enable Microsoft Entra Permissions Management in your organization.
Review roles and the level of permissions assigned in Microsoft Entra Permissions Management.
How to create a rule in the Autopilot dashboard in Microsoft Entra Permissions Management.
How to configure AWS IAM Identity Center as an identity provider.
View current Microsoft Entra Permissions Management partners and their websites.
How to select group-based permissions settings with the User management dashboard.
How to add or remove a user in Microsoft Entra Permissions Management through the Microsoft Enter admin center.
How to use the Analytics dashboard in Permissions Management to view details about users, groups, active resources, active tasks, access keys, and serverless functions.
How to view current billable resources in your authorization system in Microsoft Entra Permissions Management.
How to view personal and organization information in the Account settings dashboard in Microsoft Entra Permissions Management.
How to view current privileged role assignments in the Microsoft Entra Insights tab.
How to view information about active and completed tasks in the Activities pane in Permissions Management.
How to create folders to organize Authorization Systems - accounts, subscriptions, and projects - in Microsoft Entra Permissions Management.
Teams Reader
UpdatedAssign the Teams Reader role to users who need to do the following tasks:
Dragon Administrator
UpdatedAssign the Dragon Administrator role to users who need to do the following tasks:
Agent Optimization
Updatedmanager: dougeby
Whats New
Updated| Date | Area | Description |
Tutorial Create Instance
Updated>
Add Remove Role Task
RemovedA Microsoft Entra documentation page was updated: Add Remove Role Task.
Add Remove User To Group
RemovedA Microsoft Entra documentation page was updated: Add Remove User To Group.
Attach Detach Permissions
RemovedA Microsoft Entra documentation page was updated: Attach Detach Permissions.
Clone Role Policy
RemovedA Microsoft Entra documentation page was updated: Clone Role Policy.
Configure Aws Iam
RemovedA Microsoft Entra documentation page was updated: Configure Aws Iam.
A Microsoft Entra documentation page was updated: Configure Okta As An Identity Provider.
Create Alert Trigger
RemovedA Microsoft Entra documentation page was updated: Create Alert Trigger.
A Microsoft Entra documentation page was updated: Create Approve Privilege Request.
Create Custom Queries
RemovedA Microsoft Entra documentation page was updated: Create Custom Queries.
Create Folders
RemovedA Microsoft Entra documentation page was updated: Create Folders.
A Microsoft Entra documentation page was updated: Create Group Based Permissions.
Create Role Policy
RemovedA Microsoft Entra documentation page was updated: Create Role Policy.
Create Rule
RemovedA Microsoft Entra documentation page was updated: Create Rule.
Delete Role Policy
RemovedA Microsoft Entra documentation page was updated: Delete Role Policy.
Faqs
RemovedA Microsoft Entra documentation page was updated: Faqs.
Modify Role Policy
RemovedA Microsoft Entra documentation page was updated: Modify Role Policy.
Multi Cloud Glossary
RemovedA Microsoft Entra documentation page was updated: Multi Cloud Glossary.
A Microsoft Entra documentation page was updated: Offboard Permissions Management.
A Microsoft Entra documentation page was updated: Onboard Add Account After Onboarding.
Onboard Aws
RemovedA Microsoft Entra documentation page was updated: Onboard Aws.
Onboard Azure
RemovedA Microsoft Entra documentation page was updated: Onboard Azure.
A Microsoft Entra documentation page was updated: Onboard Enable Controller After Onboarding.
Onboard Enable Tenant
RemovedA Microsoft Entra documentation page was updated: Onboard Enable Tenant.
Onboard Gcp
RemovedA Microsoft Entra documentation page was updated: Onboard Gcp.
Partner List
RemovedA Microsoft Entra documentation page was updated: Partner List.
A Microsoft Entra documentation page was updated: Permissions Management For Defender For Cloud.
A Microsoft Entra documentation page was updated: Permissions Management Quickstart Guide.
Permissions Reference
UpdatedA Microsoft Entra documentation page was updated: Permissions Reference.
Product Account Explorer
RemovedA Microsoft Entra documentation page was updated: Product Account Explorer.
Product Account Settings
RemovedA Microsoft Entra documentation page was updated: Product Account Settings.
Product Dashboard
RemovedA Microsoft Entra documentation page was updated: Product Dashboard.
A Microsoft Entra documentation page was updated: Product Data Billable Resources.
Product Data Sources
RemovedA Microsoft Entra documentation page was updated: Product Data Sources.
A Microsoft Entra documentation page was updated: Product Define Permission Levels.
Product Permission Analytics
RemovedA Microsoft Entra documentation page was updated: Product Permission Analytics.
A Microsoft Entra documentation page was updated: Product Privileged Role Insights.
Product Roles Permissions
RemovedA Microsoft Entra documentation page was updated: Product Roles Permissions.
Product Rule Based Anomalies
RemovedA Microsoft Entra documentation page was updated: Product Rule Based Anomalies.
A Microsoft Entra documentation page was updated: Product Statistical Anomalies.
Recommendations Rule
RemovedA Microsoft Entra documentation page was updated: Recommendations Rule.
Revoke Task Readonly Status
RemovedA Microsoft Entra documentation page was updated: Revoke Task Readonly Status.
Ui Autopilot
RemovedA Microsoft Entra documentation page was updated: Ui Autopilot.
Ui Dashboard
RemovedA Microsoft Entra documentation page was updated: Ui Dashboard.
Ui Tasks
RemovedA Microsoft Entra documentation page was updated: Ui Tasks.
Ui Triggers
RemovedA Microsoft Entra documentation page was updated: Ui Triggers.
Ui User Management
RemovedA Microsoft Entra documentation page was updated: Ui User Management.
Usage Analytics Access Keys
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Access Keys.
A Microsoft Entra documentation page was updated: Usage Analytics Active Resources.
Usage Analytics Active Tasks
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Active Tasks.
Usage Analytics Groups
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Groups.
Usage Analytics Home
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Home.
A Microsoft Entra documentation page was updated: Usage Analytics Serverless Functions.
Usage Analytics Users
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Users.
View Role Policy
RemovedA Microsoft Entra documentation page was updated: View Role Policy.
A Microsoft Entra documentation page was updated: Whats New In Permissions Management.
Agent Optimization
Updatedmanager: dougeby
Migrate Group Writeback
Updatedmanager: mwongerapk
Prerequisites
Updated- The Active Directory schema in the gMSA domain's forest needs to be updated to Windows Server 2012 or later.
Prerequisites
Updated|Requirement|Description and more requirements|
Tutorial Federation
UpdatedTo complete the tutorial, you need these items:
Gmsa Cloud Sync
Updatedmanager: mwongerapk
Gpad Prereqs
Updatedauthor: omondiatieno
Tutorial Basic Ad Azure
UpdatedThe following are prerequisites required for completing this tutorial
Tutorial Pilot Aadc Aadccp
Updatedmanager: mwongerapk
A Microsoft Entra documentation page was updated: Multi Service Web App Authentication App Service.
Native Authentication Api
Updatedauthor: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
manager: pmwongera
author: kengaderdus
author: kengaderdus
manager: pmwongera
manager: pmwongera
author: kengaderdus
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
manager: pmwongera
author: henrymbuguakiarie
manager: pmwongera
manager: pmwongera
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
Learn how to add authentication to a React single-page app (SPA) using the Microsoft identity platform.
Learn how to test sign-in and sign-out in a React single-page app (SPA) using the Microsoft identity platform.
Connect Pta Quick Start
Updated1. Identify a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016 to run Microsoft Entra Connect. If not enabled already, [enable TLS 1.2 on the server](./how-to-connect-install-prerequisites.md#enable-tls-12-for-azure-ad-connect). Add the server to the same Active Directory forest as the users whose passwords you need to validate. It should be noted that installation of Pass-Through Authentication agent on Windows Server Core versions isn't supported.
manager: mwongerapk
Sign in with the user account in a web browser. For instance, sign in to the [Azure portal](https://portal.azure.com) in a private browsing window. If you're prompted to change the password, set a new password. Then try connecting again.
Sla Performance
Updated| June | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
How to create a custom query in the Audit dashboard in Microsoft Entra Permissions Management.
How to create, view, and share a custom report in the Permissions Management.
How to filter and query user activity in Microsoft Entra Permissions Management.
How to view and download the Permissions Analytics Report in Permissions Management.
How to view system reports in the Reports dashboard in Permissions Management.
Use queries to see how users access information in an authorization system in Permissions Management
NewHow to use queries to see how users access information in an authorization system in Permissions Management.
How to generate and view a system report in the Permissions Management.
View a list and description of all system reports available in Permissions Management.
How to generate an on-demand report from a query in the **Audit** dashboard in Permissions Management.
All Reports
RemovedA Microsoft Entra documentation page was updated: All Reports.
Audit Trail Results
RemovedA Microsoft Entra documentation page was updated: Audit Trail Results.
Product Audit Trail
RemovedA Microsoft Entra documentation page was updated: Product Audit Trail.
A Microsoft Entra documentation page was updated: Product Permissions Analytics Reports.
Product Reports
RemovedA Microsoft Entra documentation page was updated: Product Reports.
Report Create Custom Report
RemovedA Microsoft Entra documentation page was updated: Report Create Custom Report.
Report View System Report
RemovedA Microsoft Entra documentation page was updated: Report View System Report.
Ui Audit Trail
RemovedA Microsoft Entra documentation page was updated: Ui Audit Trail.
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
> [!NOTE]
Purpose:
Updatedmanager: pmwongera
> [!NOTE]
> [!NOTE]
> [!NOTE]
How to revoke access to high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard.
How to attach and detach permissions for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management.
How to create a role/policy in the Remediation dashboard.
How to create or approve a request for permissions in the Remediation dashboard.
Understand potential error codes that may appear during onboarding of Microsoft Entra Permissions Management
How to view existing roles/policies and requests for permission in the Remediation dashboard in Permissions Management.
How to view and filter information about roles/policies in the Microsoft Entra Permissions Management Remediation dashboard.
How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
How to clone a role/policy in Microsoft Entra Permissions Management.
How to delete a role/policy in the Microsoft Entra Permissions Management Remediation dashboard.
How to modify a role/policy in the Remediation dashboard in Microsoft Entra Permissions Management.
Troubleshoot issues with Permissions Management
Error Codes Onboarding
RemovedA Microsoft Entra documentation page was updated: Error Codes Onboarding.
Troubleshoot
RemovedA Microsoft Entra documentation page was updated: Troubleshoot.
Ui Remediation
RemovedA Microsoft Entra documentation page was updated: Ui Remediation.
Error Codes
Updated| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |
> [!NOTE]
Continuation Token
Updatedauthor: kengaderdus
Custom Attributes Note
Updatedauthor: kengaderdus
author: kengaderdus
Native Auth Api Cors Note
Updatedauthor: kengaderdus
Native Auth Challenge Type
Updatedauthor: kengaderdus
> [!NOTE]
author: kengaderdus
User Attribute Format
Updatedauthor: kengaderdus
How to view the Permissions Management API integration settings and create service accounts and roles.
How to configure ServiceNow with Microsoft Entra Permissions Management.
4. Select the app, then click **Install**.
A Microsoft Entra documentation page was updated: Configure Servicenow Application.
Integration Api
RemovedA Microsoft Entra documentation page was updated: Integration Api.
author: cilwerner
> [!NOTE]
An introduction to Microsoft Entra Permissions Management.
Overview
RemovedA Microsoft Entra documentation page was updated: Overview.
- [Microsoft Entra Domain Services](/entra/identity/domain-services/overview)
What Is Cloud Sync
Updatedmanager: mwongerapk
Plan Conditional Access
UpdatedStart with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.
- Azure CLI
> [!NOTE]
Certificate Credentials
UpdatedA Microsoft Entra documentation page was updated: Certificate Credentials.
Learn how Microsoft Entra Permissions Management helps strengthen security in cloud environments as an enhancement for Defender for Cloud
Adal Msal Migration
Updatedmanager: pmwongera
Whats New Docs
UpdatedWelcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
manager: martinco
Howto Add Branding In Apps
Updatedauthor: cilwerner
- Microsoft Entra Connect must be installed on a domain-joined server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016. We recommend Windows Server 2022. You can deploy Microsoft Entra Connect on Windows Server 2016. However, since Windows Server 2016 is in extended support, you might need [a paid support program](/lifecycle/policies/fixed#extended-support) if you require support for this configuration. Installing on unsupported versions of Windows Server may cause service failures or unexpected behavior.
How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain
UpdatedObjects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.
Saml Claims Customization
Updatedauthor: cilwerner
Microsoft Entra ID Protection
4 updatesLearn how to create Conditional Access policies using Microsoft Entra ID Protection to enforce secure password changes for users with elevated risk.
Protect your organization by implementing Conditional Access policies that address sign-in risks using Microsoft Entra ID Protection.
Source Ip Restoration
Updated- [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks) get a consistent view of original user Source IP address for assessing various risk scores.
Howto Export Risk Data
UpdatedAccess more queries and visual insights based on AADUserRiskEvents and AADRisky Users logs in the [Impact analysis of risk-based access policies workbook](workbook-risk-based-policy-impact.md).
Microsoft Entra ID Governance
1 updateMicrosoft Entra's cross-cloud synchronization, in public preview and opt-in, automates user lifecycle management across Microsoft commercial, US Government, and China clouds. General availability is late September to early October 2025. It requires specific licenses, admin enablement, and supports configuration via portal, PowerShell, and API.
Microsoft Entra External ID
7 updatesSecurity Customers
UpdatedPlanning Your Solution
Updated- [Start a free trial](https://aka.ms/ciam-free-trial?wt.mc_id=ciamcustomertenantfreetrial_linkclick_content_cnl) or [create your external tenant](how-to-create-external-tenant-portal.md).
B2b Guest Access
UpdatedTo enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
Azure Monitor
UpdatedTThe external tenant uses [Microsoft Entra monitoring](/entra/identity/monitoring-health/overview-monitoring-health). Unlike Microsoft Entra tenants, an external tenant can't have a subscription associated with it. So, we need to take extra steps to enable the integration between external tenant and Log Analytics, which is where we send the logs.
B2b Guest Access
Updatedmanager: dougeby
Azure Monitor
UpdatedDuring this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.
- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available
Microsoft Entra Workload ID
2 updatesLearn about the mitigation steps tenant administrators should perform for the retirement of service principal-less authentication.
A Microsoft Entra documentation page was updated: Howto Create Service Principal Portal.
Microsoft Entra Global Secure Access
2 updatesUse the web category checker to find which web content category a URL belongs to via Microsoft Graph.
Export Connector Logs
Updated1. Download the Azure Arc agent setup script from the Azure portal.
