Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
External ID password-migration behavior is clarified in an otherwise documentation-heavy Entra week
The week of 2 February 2026 was overwhelmingly a Microsoft Learn documentation cycle: 858 recorded changes comprised 850 updates, 2 new pages, 6 removals, and no Message Center items. The meaningful exceptions are specific guidance and one documented External ID flow edge case, not a release wave. The supplied evidence does not establish a GA or preview launch, a retirement, or a product behavior change during the week. The two new records are a token guide and an app-registration deactivation article; one External ID B2B Guest Access page carries a prerelease disclaimer, but no preview scope or availability is given. The remaining MFA, B2B, custom URL, application proxy, and Conditional Access edits are best treated as how-to or reference maintenance unless a particular implementation depends on them.
The updated Migrate Passwords Just In Time page documents a specific flow: if a password is valid at the legacy identity provider but fails External ID password-complexity rules during Native Authentication, the user receives an error instead of being redirected to SSPR. This is an Updated documentation item, so it establishes the documented behavior but not that Microsoft changed it during this week. Teams using just-in-time migration should test this case and ensure their client-flow and support assumptions do不依赖
The new Deactivate an app registration article describes deactivating an app registration to prevent token issuance while preserving application configuration. The record does not say that the underlying operation launched this week or provide GA or preview status, so this should be read as new procedure documentation rather than a product launch. Administrators can compare the documented operation with existing app shutdown or incident-containment runbooks; no additional prerequisites or migration steps are stated
- Entra ID / External IDToken guidance was consolidated and External ID issuer distinctions clarified
A new comprehensive Microsoft identity platform guide covers access, ID, and refresh tokens, claims, validation, and configuration. The updated External ID Tokens Overview distinguishes workforce and customer tenant configurations: they use the same underlying identity service, but different sign-in domains and token-issuing authorities, allowing workflows to remain separated. This is reference and architecture guidance, not a stated token-format or availability change. Review issuer-validation assumptions in appsが
The updated Conditional Access for High-Risk Agent Identities article explains how to configure Conditional Access policies to block risky agent identities. Related Agent ID updates describe specialized agent identities for AI-agent authentication and authorization and show how an agent can call Microsoft Graph using an agent identity or agent user. This is security guidance, not a GA or preview announcement or an automatic policy change. Organizations using Agent ID should assess policy scope before altering their
- ID Governance / Global Secure Access / Internet AccessConditional Access exception and break-glass guidance was refreshed
The updated ID Governance page describes using access reviews to manage users excluded from Conditional Access policies. Related Internet Access and Global Secure Access PowerShell samples cover emergency operations: the Internet Access scenario disables traffic forwarding and Conditional Access policies using the compliant network condition, while the Global Secure Access recovery sample re-enables policies disabled during a break-glass scenario. These are operational security documentation updates, not a reported
Administrators using External ID just-in-time password migration should test the documented password-complexity mismatch path, because it returns an error rather than redirecting to SSPR. Teams that manage app registrations should review the deactivation procedure and its token-issuance implications; applications spanning workforce and customer configurations should verify issuer-validation assumptions. Agent ID and secure-access owners should review the updated Conditional Access and break-glass guidance. The B2B Guest Access material should be treated as prerelease information, not a GA commitment. These are targeted checks, not a basis for a tenant-wide configuration change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
326 updatesDeveloper
80Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Add an on-premises application for remote access through application proxy in Microsoft Entra ID.
UpdatedMicrosoft Entra ID has an application proxy service that enables users to access on-premises applications by signing in with their Microsoft Entra account. This tutorial shows you how to prepare your environment for use with application proxy. Then, it uses the Microsoft Entra admin center to add an on-premises application to your Microsoft Entra tenant.
Learn how to combine the application proxy service with a Traffic Manager solution.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
How to publish on-premises ASP.NET applications that accept Active Directory Federation Services claims for secure remote access by your users.
Understand complex applications in Microsoft Entra application proxy.
Configure and manage custom domains in Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Learn about debugging issues that occur when configuring Microsoft Entra application proxy.
Covers the basics about how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Covers the basics about how to integrate on-premises SharePoint Server with Microsoft Entra application proxy.
How traffic distribution works with your application proxy deployment. Includes tips for how to optimize connector performance and use load balancing for back-end servers.
Covers how to provide single sign-on using Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Publish native client apps
UpdatedCovers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.
Covers how to configure application proxy with Remote Desktop Services (RDS)
Remove personal data from connectors installed on devices for Microsoft Entra application proxy.
Learn how to identify and resolve cross-origin resource sharing (CORS) issues in Microsoft Entra application proxy.
Learn how to redirect hard coded links for applications published with Microsoft Entra application proxy.
Understand single sign-on with an on-premises app using application proxy.
Optimize performance for global connectivity scenarios using Azure Front Door for geo-acceleration with Microsoft Entra application proxy.
Learn how to use Wildcard applications in Microsoft Entra application proxy.
Covers how to work with existing on-premises proxy servers with Microsoft Entra ID.
Before deactivating the application, remove all owners from the application. This ensures only users with tenant-wide `microsoft.directory/applications/enable` scope can reactivate the application. This scope is restricted to administrative roles.
A Microsoft Entra documentation page was updated: Deactivate Application Portal.
author: shlipsey3
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Add an on-premises application for remote access through application proxy in Microsoft Entra ID.
UpdatedMicrosoft Entra ID has an application proxy service that enables users to access on-premises applications by signing in with their Microsoft Entra account. This tutorial shows you how to prepare your environment for use with application proxy. Then, it uses the Microsoft Entra admin center to add an on-premises application to your Microsoft Entra tenant.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
How to publish on-premises ASP.NET applications that accept Active Directory Federation Services claims for secure remote access by your users.
Understand complex applications in Microsoft Entra application proxy.
Configure Sso
UpdatedUnderstand single sign-on with an on-premises app using application proxy.
Configure and manage custom domains in Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Learn about debugging issues that occur when configuring Microsoft Entra application proxy.
Covers the basics about how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Covers the basics about how to integrate on-premises SharePoint Server with Microsoft Entra application proxy.
How traffic distribution works with your application proxy deployment. Includes tips for how to optimize connector performance and use load balancing for back-end servers.
Include file
UpdatedInclude file
Covers how to provide single sign-on using Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Publish native client apps
UpdatedCovers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.
Covers how to configure application proxy with Remote Desktop Services (RDS)
Remove personal data from connectors installed on devices for Microsoft Entra application proxy.
Learn how to identify and resolve cross-origin resource sharing (CORS) issues in Microsoft Entra application proxy.
Learn how to redirect hard coded links for applications published with Microsoft Entra application proxy.
Learn how to use Wildcard applications in Microsoft Entra application proxy.
Covers how to work with existing on-premises proxy servers with Microsoft Entra ID.
Provisioning
60Describes how to create and export a connector from MIM Sync to be used with the Microsoft Entra ECMA Connector Host.
Learn how to provision custom security attributes from HR sources.
This article lists all releases of Microsoft Entra Connect Provisioning Agent and describes new features and fixed issues.
Learn how to implement API-driven inbound provisioning with Azure Logic Apps.
Learn how to implement API-driven inbound provisioning with a PowerShell script.
Learn how to configure API-driven inbound provisioning app.
Enable Termination Lookahead query for your Workday-to-AD/Microsoft Entra ID provisioning job.
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID
Learn how to export your Application Provisioning configuration and roll back to a known good state for disaster recovery in Microsoft Entra ID.
Learn how to extend API-driven inbound provisioning to sync custom attributes.
Find out when a specific user is able to access an app in Microsoft Entra Application Provisioning
UpdatedHow to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
Learn more about the capabilities and integration scenarios supported by API-driven inbound provisioning.
Learn how to grant access to the inbound provisioning API.
Learn how to get index the employeeId attribute to automate user account creation and updates from Inbound Provisioning to Active Directory
Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.
Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
Technical deep dive into SAP SuccessFactors-HR driven provisioning for Microsoft Entra ID.
Technical deep dive into Workday-HR driven provisioning in Microsoft Entra ID
This document describes how to configure Microsoft Entra ID to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer REST and SOAP APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer Windows PowerShell based APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer web services based APIs.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory.
Use partner driven integrations to provision accounts into all your applications.
Guidance for planning and executing automatic user provisioning in Microsoft Entra ID
Preparing for Microsoft Entra provisioning to Active Directory Lightweight Directory Services
UpdatedThis document describes how to configure Microsoft Entra ID to provision users into Active Directory Lightweight Directory Services as an example of an LDAP directory.
Learn how to provision users on demand in Microsoft Entra ID.
Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.
Provisioning users into SQL based applications using the ECMA Connector host
Provisioning Workbook
UpdatedThis article describes the Azure Monitor workbook for provisioning.
When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
Learn how to get started quickly with API-driven inbound provisioning using Graph Explorer
This tutorial provides step-by-step instructions so you can get started with API-driven inbound provisioning using cURL.
Reference for writing expressions for attribute mappings in Microsoft Entra Application Provisioning
UpdatedLearn how to use expression mappings to transform attribute values into an acceptable format during automated provisioning of SaaS app objects in Microsoft Entra ID. Includes a reference list of functions.
Learn how to retrieve pronoun information from Workday
Learn which attributes from SuccessFactors are supported by SuccessFactors-HR driven provisioning in Microsoft Entra ID.
Learn how to use scoping filters to define attribute-based rules that determine which users or groups are provisioned in Microsoft Entra ID.
Learn how to override the default behavior of deprovisioning out of scope users in Microsoft Entra ID.
A comprehensive guide to commonly used expression mapping functions when configuring SuccessFactors to Microsoft Entra ID user provisioning. These functions help transform and map data from SuccessFactors to create appropriate user attributes in Microsoft Entra ID.
When configuring user provisioning with Microsoft Entra ID and SaaS apps, use the directory extension feature to add source attributes that aren't synchronized by default.
Learn about attribute mappings for Software as a Service (SaaS) apps in Microsoft Entra Application Provisioning. Learn what attributes are and how you can modify them to address your business needs.
Tutorial Ecma Sql Connector
UpdatedThis tutorial describes how to provision users from Microsoft Entra ID into a SQL database.
Understand how Application Provisioning works in Microsoft Entra ID.
Understand how expression builder works with Application Provisioning in Microsoft Entra ID.
Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
New and updated documentation for the Azure Active Directory application provisioning.
Learn which attributes that you can fetch from Workday using XPATH queries in Microsoft Entra ID.
A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.
Configure Adobe Identity Management (OIDC) for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (OIDC).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cofense Recipient Sync.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to myday.
This article describes the steps you need to perform in both Akamai Enterprise Application Access and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Akamai Enterprise Application Access](https://www.akamai.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
This article describes how to use the Microsoft Entra provisioning service to provision users into Azure Databricks with Private Link Workspace.
Integrating Oracle Fusion Cloud Human Capital Management (HCM) with Microsoft Entra ID and on-premises Active Directory using the Inbound Provisioning API.
Learn how to configure inbound provisioning from SuccessFactors
Learn how to configure inbound provisioning from SuccessFactors to Microsoft Entra ID
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Workday.
Include file
UpdatedInclude file
Licensing App Provisioning
Updatedauthor: barclayn
Learn how to configure inbound provisioning from Workday to Microsoft Entra ID
General
50Use tenant restrictions to control the types of external accounts that users can use on your networks and the devices that you manage.
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
Migrate Approved Client App
Updatedauthor: shlipsey3
Policy Migration Mfa
Updatedauthor: shlipsey3
include file
Updatedinclude file Microsoft Entra ID preview program information
Controls
Updatedauthor: shlipsey3
Managed Policies
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Policy Block Example
Updatedauthor: shlipsey3
Policy Guests Mfa Strength
Updatedauthor: shlipsey3
Policy Old Require Mfa Admin
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Policy Old Require Mfa Guest
Updatedauthor: shlipsey3
Resilience Defaults
Updatedauthor: shlipsey3
Service Dependencies
Updatedauthor: shlipsey3
Terms Of Use
Updatedauthor: shlipsey3
What If Tool
Updatedauthor: shlipsey3
Salesforce Sandbox Tutorial
Updated* Manage your accounts in one central location.
Salesforce Tutorial
Updated* Manage your accounts in one central location.
how to access workbooks
Updatedinclude file Microsoft Entra workbook instructions
include file
Updatedinclude file
include file
Updatedinclude file
include file
Updatedinclude file
include file
Updatedinclude file
include file
Updatedinclude file
Include file
UpdatedInclude file
Include file
UpdatedInclude file
Include file
UpdatedInclude file
Licensing Change
Updatedauthor: barclayn
author: barclayn
author: barclayn
author: barclayn
Licensing Roles
Updatedauthor: barclayn
keywords: Azure Active Directory licensing service plans
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
Users Close Account
UpdatedHow to close your work or school account in an unmanaged Microsoft Entra ID.
* Manage your accounts in one central location.
* Manage your accounts in one central location.
Connect Version History
Updated|[2.5.3.0](#2530)|31 July 2026 (12 months after release of 2.5.76.0)|
Fundamentals
42Tokens Overview
RemovedA Microsoft Entra documentation page was updated: Tokens Overview.
An overview of API-driven inbound provisioning.
Federation Overview
RemovedA Microsoft Entra documentation page was updated: Federation Overview.
An end-to-end guide for planning the deployment of application proxy within your organization
Sso Overview
RemovedA Microsoft Entra documentation page was updated: Sso Overview.
Sspr
RemovedA Microsoft Entra documentation page was updated: Sspr.
Learn how to use Microsoft Entra application proxy connectors.
An introduction to how you can use Microsoft Entra ID to automatically provision, deprovision, and continuously update user accounts across multiple third-party applications.
Describes overview of HR driven provisioning.
Whats New Archive
UpdatedWhats New
UpdatedRestricted management administrative units enable you to easily restrict access to users, groups, or devices to the specific users or applications you specify. Tenant-level administrators (including Global Administrators) can't modify members of restricted management administrative units unless they're explicitly assigned a role scoped to the administrative unit. This makes it easy to lock down a set of sensitive groups or user accounts in your tenant without having to remove tenant-level role assignments. For more information, see: [Restricted management administrative units in Microsoft Entra ID](../identity/role-based-access-control/admin-units-restricted-management.md).
Learn how to add new custom security attribute definitions or deactivate custom security attribute definitions in Microsoft Entra ID.
Learn how to manage access to custom security attributes in Microsoft Entra ID.
Learn how to troubleshoot custom security attributes in Microsoft Entra ID.
Learn about custom security attributes in Microsoft Entra ID.
Authentication Flows
Updatedauthor: shlipsey3
Authentication Transfer
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Conditional Access Grant
Updatedauthor: shlipsey3
Conditional Access Policies
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Conditional Access Session
Updatedauthor: shlipsey3
author: shlipsey3
Assignment Network
Updatedauthor: shlipsey3
author: shlipsey3
Continuous Access Evaluation
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Filter For Applications
Updatedauthor: shlipsey3
Overview
Updatedauthor: shlipsey3
Session Lifetime
Updatedauthor: shlipsey3
Token Protection
Updatedauthor: shlipsey3
author: custorod
Learn about Microsoft Entra groups, including how they work, what they can access, and how membership and access is assigned.
Sspr Howitworks
Updatedauthor: justinha
Tokens Microsoft Entra Id
Updatedauthor: jenniferf-skc
Learn how to use Microsoft Entra application proxy connectors.
Describes overview of identity provisioning and the ILM scenarios.
Recommendations
Updated| Group Policy Object (GPO) assigns unprivileged identities to local groups with elevated privileges | Users | Preview | Yes | N/A |
Whats New
UpdatedFor guidance, see:
Troubleshooting
24Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.
Learn how to check the status of automatic user account provisioning jobs, and how to troubleshoot the provisioning of individual users.
Learn how to resolve common access issues with Microsoft Entra application proxy applications.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot attribute retrieval issues with HR provisioning
Learn how to troubleshoot InsufficientAccessRights error when provisioning to on-premises Active Directory.
This article provides potential issues and resolutions that guide you in how to troubleshoot issues with the inbound provisioning API.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
This article provides potential issues and resolutions that show you how to troubleshoot manager update issues with HR provisioning
How to troubleshoot common issues faced when configuring user provisioning to an application already listed in the Microsoft Entra application gallery.
Learn how to troubleshoot user creation issues with HR provisioning
Learn how to troubleshoot user update issues with HR provisioning
This article provides potential issues and resolutions so you can troubleshoot writeback issues with HR provisioning.
Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
author: shlipsey3
author: shlipsey3
author: shlipsey3
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Learn how to troubleshoot sign-up errors using Microsoft Entra reports in the Microsoft Entra admin center
include file
Updatedinclude file
Learn how to resolve common access issues with Microsoft Entra application proxy applications.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
Authentication
15Whatis Phs
UpdatedTo use password hash synchronization in your environment, you need to:
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedLearn how to provide single sign-on for on-premises applications that are secured with header-based authentication.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory so that the users can then sign into a Linux or other POSIX system using pluggable authentication.
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
Turn on single sign-on for your published on-premises applications with Microsoft Entra application proxy in the Microsoft Entra admin center.
Policy Risk Based Sign In
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedLearn how to provide single sign-on for on-premises applications that are secured with header-based authentication.
author: mepples21
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
include file
Updatedinclude file
Turn on single sign-on for your published on-premises applications with Microsoft Entra application proxy in the Microsoft Entra admin center.
Security
13Covers security considerations for using Microsoft Entra application proxy
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
author: shlipsey3
author: shlipsey3
author: shlipsey3
Policy Risk Based User
Updatedauthor: shlipsey3
Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Covers security considerations for using Microsoft Entra application proxy
author: shlipsey3
include file
Updatedinclude file
author: jenniferf-skc
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
Standards
12Learn how to provide single sign-on (SSO) for on-premises applications that are secured with Security Assertion Markup Language (SAML) authentication. Provide remote access to on-premises apps with application proxy.
Learn how to integrate an on premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
This article describes how to use the Microsoft Entra provisioning service to provision users into an on-premises app that's SCIM enabled.
System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.
Tutorial - Test your SCIM endpoint for compatibility with the Microsoft Entra provisioning service.
UpdatedThis tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.
Use SCIM, Microsoft Graph, and Microsoft Entra ID to provision users and enrich apps with data
UpdatedUsing SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.
Configure Adobe Identity Management (SAML) for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML).
Learn how to provide single sign-on (SSO) for on-premises applications that are secured with Security Assertion Markup Language (SAML) authentication. Provide remote access to on-premises apps with application proxy.
Learn how to integrate an on premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
Single Sign On Saml Protocol
Updated| `ID` | Required | Microsoft Entra ID uses this attribute to populate the `InResponseTo` attribute of the returned response. ID must not begin with a number, so a common strategy is to prepend a string like "ID" to the string representation of a GUID. For example, `id6c1c178c166d486687be4aaf5e482730` is a valid ID. |
Governance
7This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can use entitlement management and other identity governance features to enforce the policies for access.
Describes how to check the users who fall into the execution scope of a Lifecycle Workflow.
Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID.
This article a tutorial on how to provision users and groups from on-premises to cloud using MIM.
Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.
Learn how to set up group writeback in entitlement management.
Architecture
6Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
Presents an overview of on-premises application provisioning architecture.
A Microsoft Entra documentation page was updated: Multi Tenant Common Considerations.
What Is App Proxy
UpdatedUnderstand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
Architecture overview
UpdatedLearn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.
Conceptual Deployment Plan
UpdatedAn end-to-end guide for planning the deployment of application proxy within your organization
Conditional Access
6Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Create a custom Conditional Access policy to block access to resources by IP location.
Create a custom Conditional Access policy require approved app or app protection policy
author: shlipsey3
author: shlipsey3
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Microsoft identity platform
6Complete guide to understanding, implementing, and securing tokens in Microsoft identity platform including access tokens, ID tokens, refresh tokens, claims, validation, and configuration.
Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.
Deactivate App Registration
Updated- [Delete an enterprise application](delete-application-portal.md) for permanent removal
Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.
A Microsoft Entra documentation page was updated: Recommendation Migrate From Adal To Msal.
Monitoring
5Covers network topology considerations when using Microsoft Entra application proxy.
Securely integrate Azure Logic Apps with on premises APIs using Microsoft Entra application proxy
UpdatedMicrosoft Entra application proxy lets cloud-native logic apps securely access on premises APIs to bridge your workload.
Learn how to configure the automatically generated Microsoft Entra recommendation email notification settings for your tenant.
Include file
UpdatedInclude file
Covers network topology considerations when using Microsoft Entra application proxy.
Microsoft Entra Agent ID
25 updatesGeneral
9Agent Id
Updatedauthor: shlipsey3
Agent Blueprint
Updatedauthor: SHERMANOUKO
Agent Lists
UpdatedAccess Microsoft Entra admin center to effortlessly view and filter agent identities. Streamline tenant oversight and take charge now.
Learn how to structure agent metadata for optimal discoverability in Microsoft Entra Agent Registry and understand how the collections model affects agent visibility.
author: SHERMANOUKO
Agent Registry Collections
Updatedauthor: shlipsey3
Learn how to navigate, create, and manage agent collections in Microsoft Entra Agent Registry.
Agent Users
Updatedauthor: SHERMANOUKO
Manage Agent Blueprint
UpdatedThis article explains how to manage agent blueprints and registry-only agents using the Microsoft Entra Admin Center.
Developer
4Call Api Azure Services
UpdatedLearn how to call Azure services using .NET Azure SDK from an agent using agent identities.
Learn how to enable secure agent communication through the Microsoft Entra Agent Registry API.
Learn how autonomous agents acquire tokens using the Microsoft Entra SDK for Agent ID to call downstream APIs independently.
Learn how to register agents to the Agent Registry in Microsoft Entra Agent ID through automatic registration or manual API calls for agent discovery and management.
Microsoft identity platform
3Call Api Microsoft Graph
UpdatedLearn how to call Microsoft Graph API from an agent using agent identities or agent users, including authentication configuration and implementation steps.
What Is Agent Id Platform
UpdatedLearn about the Microsoft Agent Identity Platform, a comprehensive identity, and authorization framework designed specifically for AI agents. Key concepts include agent registry, authentication protocols, tokens, claims, and agent discovery capabilities.
Learn about the Agent ID, Agent Blueprint, and Agent Identity error codes.
Standards
3Learn how agent identities operate autonomously without user context using app-only protocol with OAuth 2.0 client credentials flows.
Learn how agent applications operate on behalf of signed-in users using OAuth 2.0 On-Behalf-Of flows with agent identity blueprints and agent identities.
Agent User Oauth Flow
UpdatedLearn how agent identities operate with user context through agent users using the agent user impersonation protocol with OAuth 2.0 token exchange.
Fundamentals
2What Is Agent Id
UpdatedLearn about agent identities, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.
What Is Agent Registry
UpdatedLearn about the Agent Registry, a centralized metadata repository that enables agent discovery, and secure communication in enterprise environments.
Authentication
1Agent Identities
UpdatedLearn about agent identities in Microsoft Entra ID, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.
Conditional Access
1Learn how to configure Conditional Access policies to block risky agent identities. Follow best practices to enhance security in Microsoft Entra.
Security
1Call Api Custom
UpdatedLearn how to call custom protected APIs from an agent using different approaches including IDownstreamApi, MicrosoftIdentityMessageHandler, and IAuthorizationHeaderProvider.
Troubleshooting
1Preview Known Issues
UpdatedLearn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.
Microsoft Entra ID Protection
25 updatesSecurity
12author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Deploy Identity Protection
Updatedauthor: shlipsey3
author: shlipsey3
Id Protection Dashboard
Updatedauthor: shlipsey3
author: shlipsey3
Fundamentals
10Identity Protection Risks
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Risk Detection Types
Updatedauthor: shlipsey3
Risky Agents
Updatedauthor: shlipsey3
Workload Identity Risk
Updatedauthor: shlipsey3
Identity Protection B2b
Updatedauthor: shlipsey3
Identity Protection Policies
Updatedauthor: shlipsey3
author: shlipsey3
author: shlipsey3
Authentication
1author: shlipsey3
Monitoring
1Review agent findings
Updatedauthor: shlipsey3
Troubleshooting
1author: shlipsey3
Microsoft Entra ID Governance
168 updatesGovernance
143| Catalog owner | `ae79f266-94d4-4dab-b730-feca7e132178` | Edit and manage access packages and other resources in a catalog. Typically an IT administrator or resource owners, or an identity who the catalog owner chooses. |
Discovery and insights (formerly Security Wizard) help you convert permanent Microsoft Entra role assignments to just-in-time assignments with Privileged Identity Management.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can define policies for how users should obtain access to your business critical applications integrated with Microsoft Entra ID Governance.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.
Microsoft Entra ID Governance allows you to model organizational roles using access packages, so you can migrate your existing role definitions to entitlement management.
Integrate your applications for identity governance and establishing a baseline of reviewed access
UpdatedMicrosoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can integrate your existing business critical third party on-premises and cloud-based applications with Microsoft Entra ID for identity governance scenarios.
Learn the detailed steps for how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and provision those identities with access to SAP ECC, SAP S/4HANA, and other SAP and non-SAP applications, for organizations that were previously using SAP IDM.
Pim Powershell Migration
UpdatedThe following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.
Learn how to configure security alerts for Azure resource roles in Privileged
Configure security alerts for Microsoft Entra roles Privileged Identity Management.
Learn how to use custom security attribute to configure the scope of a workflow with lifecycle workflows.
Learn how to assign Microsoft Entra roles with access packages.
Learn how to create an access review of PIM for Groups in Microsoft Entra ID.
Access Reviews FAQs
UpdatedFrequently asked questions about Access Reviews.
Learn how to approve activation requests for group members and owners in Microsoft Entra Privileged Identity Management (PIM).
Learn how to use the My Access portal to approve or deny requests to an access package in Microsoft Entra entitlement management.
Learn how to approve or deny requests for Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to archive logs and create reports with Azure Monitor in entitlement management.
Learn how to assign eligibility for a group in Privileged Identity Management.
Learn how to assign Microsoft Entra roles in Privileged Identity Management (PIM).
View activity and audit activity history for group assignments in Privileged Identity Management (PIM).
Tutorial for moving users that change jobs using Lifecycle workflows with the Microsoft Entra admin center.
Tutorial for post off-boarding users from an organization using Lifecycle workflows with the Microsoft Entra admin center.
Tutorial for onboarding users to an organization using Lifecycle workflows with the Microsoft Entra admin center.
Automate Identity Lifecycle
Updatedauthor: owinfreyATL
Learn how to write PowerShell scripts in Azure Automation to interact with Microsoft Entra entitlement management and other features.
services: entra-id-governance
Learn how to bring groups into Privileged Identity Management.
Learn how to change approval and requestor information settings for an access package in entitlement management.
Learn how to change requestor information & lifecycle settings for an access package in entitlement management.
Learn how to change request settings for an access package in entitlement management.
Learn how to change the resource roles for an existing access package in entitlement management.
Check Status Workflow
UpdatedThis article guides a user on checking the status of a Lifecycle workflow
Check Workflow Insights
UpdatedLearn how to check workflow insights within your Microsoft Entra tenant.
Learn the high-level steps you should follow for common scenarios in Microsoft Entra entitlement management.
Learn how to complete an access review of Azure resource and Microsoft Entra roles Privileged Identity Management.
Learn how to complete an access review of group members or application access in Microsoft Entra access reviews.
Learn how to configure automatic assignments based on rules for an access package in entitlement management.
Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure Microsoft Entra role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Learn how to configure separation of duties enforcement for requests for an access package in entitlement management.
Learn how to configure verified ID settings for an access package in entitlement management.
Learn how to convert guest user access package assignments for an access package in entitlement management.
You can use Microsoft Entra entitlement management to enforce the policies for who can get assigned access to an application.
Learn how to create an access package of resources that you want to share in Microsoft Entra entitlement management.
Learn how to set up an access review in a policy for entitlement management access packages in Microsoft Entra ID part of Microsoft Entra.
Learn how to create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to create an access review of group members or application access in Microsoft Entra ID.
Learn how to create a new container of resources and access packages in entitlement management.
Using Microsoft Entra access reviews, you can download a review history for access reviews in your organization.
This tutorial describes how to create customized reports in Azure Data Explorer by using data from more sources in addition to Microsoft Entra
This tutorial describes how to create customized reports in Azure Data Explorer by using data from Microsoft Entra.
Create Lifecycle Workflow
UpdatedThis article guides you in creating a lifecycle workflow.
Learn how to customize the schedule of a lifecycle workflow.
Customize Workflow Email
UpdatedGet a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.
Learn how to delegate access governance from IT administrators to access package managers and project managers so that they can manage access themselves.
Learn how to delegate access governance from IT administrators to catalog creators and project managers so that they can manage access themselves.
Learn how to delegate access governance from IT administrators to department managers and project managers so that they can manage access themselves.
Delete a lifecycle workflow
UpdatedLearn how to delete a lifecycle workflow.
Deploy Sap Netweaver
Updatedauthor: owinfreyATL
Learn how to discover Azure resources to manage in Privileged Identity Management (PIM).
Describes email notifications in Microsoft Entra Privileged Identity Management (PIM).
This article serves as a reference for Microsoft Entra ID behavior when assignment periods of an access package and PIM policy don't align.
author: owinfreyATL
include file
Learn how to remove users from an organization in real time on their last day of work by using lifecycle workflows in the Microsoft Entra admin center.
Learn how to extend or renew PIM for groups assignments.
A how-to guide on dynamically determining the approval requirements for an access package externally using a custom extension.
Learn about the settings you can specify to govern access for external users in entitlement management.
Govern cloud users and groups with provisioning from on-premises and Entra Connect Cloud Sync
UpdatedThis article a tutorial on how to provision users and groups using cloud sync.
This article a tutorial on how to provision users and groups using connect sync.
This article a tutorial on how to provision users and groups from and managed in Workday.
This article a tutorial on how to provision users and groups from and managed in Microsoft Entra ID to Active Directory.
This article a tutorial on how to provision users and groups to AD with Workday.
Govern on-premises users that are provisioned to Active Directory with Microsoft Identity Manager
UpdatedThis article a tutorial on how to provision users and groups to Active Directory using MIM.
Governance Service Limits
UpdatedThis article details service limits for offerings within Microsoft Entra ID Governance
Groups Activate Roles
UpdatedLearn how to activate your group membership or ownership in Privileged
Learn how to hide or delete an access package in Microsoft Entra entitlement management.
This article shows how to create custom alerts with Microsoft Entra ID Governance
This article shows how to use the new identity governance dashboard
This article describes use cases Microsoft Entra ID Governance.
include file
Updatedinclude file
Include file
UpdatedInclude file
Least Privileged
Updatedauthor: owinfreyATL
Lifecycle Workflow Audits
UpdatedInformation about audit logs with Lifecycle Workflows
This article walks you through managing inactive users with Lifecycle Workflows.
Lifecycle Workflow Tasks
UpdatedThis article guides a user on Workflow task definitions and task parameters.
An article discussing Lifecycle workflow versioning and history
Lifecycle workflows FAQs
UpdatedFrequently asked questions about Lifecycle workflows.
Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.
Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.
Learn how to allow people outside your organization to request access packages so that you can collaborate on projects.
Manage guest users as members of a group or assigned to an application with Microsoft Entra access reviews.
Learn how to manage users' access as membership of a group or assignment to an application with Microsoft Entra access reviews
Manage Workflow On Premises
UpdatedA how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.
Manage Workflow Properties
UpdatedThis article guides a user to editing a workflow's properties using Lifecycle Workflows.
Manage Workflow Tasks
UpdatedThis article guides a user on managing workflow versions with Lifecycle Workflows.
Learn how Microsoft Entra ID is licensed for guest users.
On Demand Workflow
UpdatedThis article guides a user to running a workflow on demand using Lifecycle Workflows.
Learn how to simplify approving access to applications and resources for onboarding external users to your organization.
Pim Apis
UpdatedInformation for understanding the APIs in Microsoft Entra Privileged
Pim How To Use Audit Log
UpdatedLearn how to view the audit log history for Microsoft Entra roles in
Learn how to review access of Azure resource and Microsoft Entra roles
Learn how to approve or deny requests for Azure resource roles in Privileged
Learn how to assign Azure resource roles in Privileged Identity Management (PIM).
Pim Roles
UpdatedDescribes the roles you can't manage in Microsoft Entra Privileged Identity
Learn how to deploy Privileged Identity Management (PIM) in your Microsoft Entra organization.
Planning for a successful access reviews campaign for a particular application starts with understanding how to model access for that application in Microsoft Entra ID.
Provision Ldap
UpdatedThis document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.
Provision Sap
UpdatedThis document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
Provision Sql
UpdatedThis document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host
Learn how to extend or renew Azure resource role assignments in Privileged Identity Management (PIM).
Learn how to extend or renew Microsoft Entra role assignments in Microsoft Entra Privileged Identity Management (PIM)
Learn how to reprocess assignments for an access package in entitlement management.
Learn how to reprocess a request for an access package in entitlement management.
Reprocess Workflow
UpdatedThis article guides a user on reprocessing workflow runs using Lifecycle Workflows
Learn how to use the My Access portal to request access to an access package in Microsoft Entra entitlement management.
Learn about the request process for an access package and when email notifications are sent in entitlement management.
Learn how to complete an access review of entitlement management access packages in access reviews.
Learn how to review access of group members or application access in Microsoft Entra access reviews.
Learn how to review access of group members with review recommendations in Microsoft Entra access reviews.
Learn how to review your own access to groups or applications in access reviews.
Learn how to review your own access to resources in access reviews.
Sap Template
Updateddocumentationcenter: ''
Learn how to review user access of entitlement management access packages in access reviews.
Learn about partners who can help with deployment and integration of identity management (IAM) and identity governance scenarios.
Learn how to share link to request an access package in entitlement management.
Learn how to show suggested access packages to users in My Access so they can quickly find the most relevant access packages.
Start using PIM
UpdatedLearn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.
Trigger Custom Task
UpdatedTrigger Logic Apps based on custom task extensions
Learn how to configure and use custom logic app workflows in entitlement management.
Step-by-step tutorial for how to create your first access package using the Microsoft Entra admin center in entitlement management.
Tutorial for preparing user accounts for Lifecycle workflows.
Learn how to use Azure custom roles in Microsoft Entra Privileged Identity Management (PIM).
Use entitlement management and Global Secure Access to restrict employee access to cloud apps
UpdatedLearn how you can use entitlement management and Global Secure Access to restrict employee access to cloud apps.
Use Access Reviews to extend of remove access from members of partner organizations.
Learn how to use multi-stage reviews to design more efficient reviews with Microsoft Entra.
Learn how to view requests and remove for an access package in entitlement management.
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
Learn how to view the identity assignments report and audit logs in entitlement management.
View, add, and remove assignments for an access package in entitlement management - Microsoft Entra
UpdatedLearn how to view, add, and remove assignments for an access package in entitlement management.
Scenario: In this scenario you learn how to use custom extensibility, and a Logic App, to automatically generate ServiceNow tickets for manual provisioning of users who have received assignments and need access to apps.
Fundamentals
20Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.
Describes overview of identity lifecycle management and what is meant by governing the employee lifecycle.
Describes overview of Lifecycle workflow attributes.
Conceptual article about Lifecycle workflows execution conditions.
Conceptual article discussing workflow extensibility with Lifecycle Workflows
Lifecycle Workflow History
UpdatedConceptual article about Lifecycle Workflows reporting and history capabilities
Lifecycle Workflow Insights
UpdatedConceptual article about Lifecycle Workflows reporting and history capabilities.
Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.
Lifecycle Workflow Templates
UpdatedConceptual article discussing workflow templates and categories with Lifecycle Workflows.
This page provides an overview of the Microsoft Entra ID Governance integrations available to automate provisioning and governance controls.
This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
Describes how to use a resource dashboard to perform an access review
Plan new governance scenarios for business partners and external users with Microsoft ID Governance
UpdatedDescribes overview of getting started with new business partner and external user scenarios.
How to manage Microsoft Entra Privileged Identity Management (PIM) for Groups.
A conceptual article describing access package visibility in the My Access portal.
Describes an overview of Lifecycle workflows and the various parts.
Get an overview of the lifecycle workflow feature of Microsoft Entra ID.
Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external identities.
Provides an overview of Microsoft Entra Privileged Identity Management (PIM).
Architecture
2Planning guide for a successful Lifecycle Workflow deployment.
Planning guide for a successful access reviews deployment.
Troubleshooting
2Learn about some items you should check to help you troubleshoot Microsoft Entra entitlement management.
Learn how to troubleshoot system errors with roles in Microsoft Entra Privileged Identity Management (PIM).
Conditional Access
1Learn how to use access reviews to manage users that have been excluded from Conditional Access policies
Microsoft Entra External ID
185 updatesGeneral
87Migrate To External Id
Updatedauthor: MicrosoftGuyJFlo
Migrate Users
UpdatedLearn how to migrate users from another identity provider to Microsoft Entra External ID.
About Redirect Url
Updatedauthor: kengaderdus
Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.
Learn how to add and manage customer accounts in Microsoft Entra External ID.
Add App Client Secret
Updatedauthor: kengaderdus
Add App Role
Updatedauthor: kengaderdus
Add App User Flow
Updatedauthor: kengaderdus
B2B collaboration allows information workers and app owners to add guest users to Microsoft Entra ID for access.
Add Client App Certificate
Updatedauthor: kengaderdus
Add custom attributes
UpdatedLearn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.
Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.
Learn how to add Google as an identity provider for your external tenant.
Add Group Claim In Token
Updatedauthor: kengaderdus
Add Member To Group
Updatedauthor: kengaderdus
Add Optional Claims Access
Updatedauthor: kengaderdus
Add Optional Claims Id
Updatedauthor: kengaderdus
author: henrymbuguakiarie
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: henrymbuguakiarie
author: kengaderdus
author: kengaderdus
author: Dickson-Mwendia
author: SHERMANOUKO
author: SHERMANOUKO
author: kengaderdus
author: kengaderdus
author: SHERMANOUKO
Shows how an admin can add sponsors to guest users in Microsoft Entra B2B collaboration.
Allow or Block Invitations
UpdatedLearn how an administrator creates a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.
Applies To External Only
Updated**Applies to**:  External tenants ([learn more](/entra/external-id/tenant-configurations))
Applies To Ios Macos
Updated**Applies to**:  iOS (Swift)  macOS (Swift)
Applies To Workforce Only
Updated**Applies to**:  Workforce tenants ([learn more](/entra/external-id/tenant-configurations))
Assign Users Groups Roles
Updatedauthor: kengaderdus
Give partners access to both on-premises and cloud resources with Microsoft Entra B2B collaboration.
B2B Direct Connect Setup
UpdatedLearn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.
Bulk invite B2B users
UpdatedLearn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.
Learn how to configure external collaboration settings in Microsoft Entra External ID. Control guest user access, specify who can invite guests, and manage domain restrictions for B2B collaboration.
Cross Cloud Settings
UpdatedEnable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.
Declare App Roles
Updatedauthor: kengaderdus
Dynamic groups setup
UpdatedLearn how to create and manage dynamic membership groups in Microsoft Entra External ID. Set rules based on user attributes to automate group membership for B2B collaboration.
Enable Implicit Hybrid Flows
Updatedauthor: kengaderdus
Enable Public Client Flow
Updatedauthor: kengaderdus
External ID pricing
UpdatedLearn about the pricing structure for Microsoft Entra External ID. Understand the monthly active users (MAU) billing model, core offering, and premium add-ons. Link your tenant to an Azure subscription for proper billing and feature access.
Flask Web App
Updatedauthor: SHERMANOUKO
Frequently asked questions
UpdatedFind answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.
Google identity provider
UpdatedLearn how to add Google as an identity provider in Microsoft Entra External ID. Enable customers to sign in with their Google accounts and configure Google federation for seamless access.
Shows how to give cloud B2B users access to on premises apps with Microsoft Entra B2B collaboration.
Learn how to use Microsoft Entra ID as your default identity provider for sharing with external users.
Learn about customizing the language experience in your user flows in Microsoft Entra External ID.
Leave an Organization
UpdatedAs a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.
Current limitations for Microsoft Entra B2B collaboration
Use this quickstart to learn how Microsoft Entra admins can add B2B guest users in the Microsoft Entra admin center and walk through the B2B invitation workflow.
author: kengaderdus
Register Client App Common
Updatedauthor: kengaderdus
Register Daemon App
Updatedauthor: kengaderdus
Remove Client Secret
Updatedauthor: cilwerner
Learn how to customize the onboarding workflow for Microsoft Entra B2B users to fit your organization’s needs.
Learn about the service limits and restrictions in an external tenant.
Learn how to run a sample Angular SPA to sign in users
Learn how to run a sample React SPA to sign in users
Learn how to run a sample JavaScript SPA to sign in users
author: kengaderdus
Tenant configurations
UpdatedLearn about tenant configurations in Microsoft Entra External ID. Understand the differences between workforce and external tenants, and how to configure them for your organization's needs.
In this tutorial, you learn how to use PowerShell and a CSV file to send bulk invitations to external Microsoft Entra B2B collaboration guest users.
author: kengaderdus
Use Custom Domain Url
Updatedauthor: kengaderdus
author: kengaderdus
author: henrymbuguakiarie
author: henrymbuguakiarie
author: henrymbuguakiarie
author: henrymbuguakiarie
Use Custom Domain Url Ios
Updatedauthor: henrymbuguakiarie
Use Custom Domain Url Python
Updatedauthor: kengaderdus
Use Microsoft Accounts
UpdatedEnable your external business partners and guest users to use their Microsoft Account (MSA) to sign in to your apps for B2B collaboration.
Use Microsoft Entra Accounts
UpdatedEnable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.
Learn about the default permissions for users in an external tenant.
Learn how to run a sample ASP.NET web app to sign in users
Learn how to run a sample Node.js/Express web app to sign in users
Learn how to run a sample Python Django web app to sign in users
Learn how to run a sample Python Flask web app to sign in users
New and updated documentation for the Microsoft Entra External ID.
Redemption Experience
UpdatedWhen you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) that's initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.
If you don’t have an Azure subscription, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin.
Authentication
27To protect customers, some regions require you to enable the country codes to receive SMS telephony verification for Microsoft Entra External ID external tenants.
Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.
Learn how to enforce multifactor authentication policies for Microsoft Entra B2B users.
B2B guest user properties
UpdatedLearn about the properties of a B2B guest user in Microsoft Entra External ID. Understand user types, authentication methods, and how to manage guest user access and permissions.
author: henrymbugua
author: henrymbugua
Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.
Enable Native Authentication
Updatedauthor: kengaderdus
Learn how to set up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.
Training, demos, and videos
UpdatedExplore Microsoft Entra External ID training, live demos, and videos. Learn to create secure sign-up experiences and protect access with multifactor authentication.
In this tutorial, learn how to require multifactor authentication when you use Microsoft Entra B2B to collaborate with external users and partner organizations.
About B2B Invitations
UpdatedLearn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.
Learn how to add an application to a user flow to associate the application with a sign-up and sign-in user experience. Get guidance for updating the application configuration with application registration and tenant information.
Learn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.
Create a User Flow
UpdatedAdd sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.
author: kengaderdus
Learn how Microsoft Entra B2B invitation redemption works, including guest sign-in, consent process, and privacy terms. Ensure secure access for your organization’s resources.
Define custom attributes
UpdatedLearn how to create and define new custom attributes to be collected from users during sign-up and sign-in.
External Tenant Quickstart
UpdatedIn this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.
Grant Api Permission Sign In
Updatedauthor: kengaderdus
If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can change to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials or sign-in. Use either PowerShell or the Microsoft Graph invitation API.
In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.
Sign in with alias
UpdatedLearn how to Sign in with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.
Test a user flow
UpdatedLearn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.
Learn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.
Developer
24Learn about tenant-level restrictions and controls for users, groups, and applications, along with policy management in a cloud-based portal.
Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.
Configure a web API to be used in a user flow.
Add Api Mfa Scopes
Updatedauthor: kengaderdus
Add Api Scopes
Updatedauthor: kengaderdus
Learn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.
Add API connectors for custom approval workflows in External ID self-service sign-up
author: kengaderdus
Learn about how to analyze user activity and engagement for your registered application in the external tenant.
Code samples for API connectors in self-service sign-up flows for Microsoft Entra External ID.
Learn how to manage your external tenant by calling the Azure REST API.
Code and PowerShell samples for Microsoft Entra B2B collaboration
Learn how to configure Microsoft Entra External ID with Azure Web Application Firewall.
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
author: kengaderdus
Find out which core Microsoft Entra features related to the user and group management model and application assignment are available in external tenants.
Register Api App
Updatedauthor: kengaderdus
Register Mfa Api App
Updatedauthor: kengaderdus
Learn how to build and integrate apps with external tenants with scenarios such as sign-up, sign in, and getting an access token to call an API.
Secure APIs used as API connectors in Microsoft Entra External ID self-service sign-up user flows
UpdatedSecure your custom RESTful APIs used as API connectors in self-service sign-up user flows.
Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.
Fundamentals
19Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.
Tokens Overview
UpdatedMicrosoft Entra ID supports two tenant configurations: A workforce configuration that's intended for internal use and manages employees and business guests, and a [customer configuration](/entra/external-id/customers/concept-supported-features-customers) which is optimized for isolating consumers and partners in a restricted external-facing directory. While the underlying identity service is identical for both tenant configurations, the sign in domains and token issuing authority for external tenants is different. This allows applications to keep workforce and external ID workflows separated if needed.
Learn how to use custom authentication extensions in Microsoft Entra External ID. Integrate with external systems, add custom logic to authentication flows, and enhance user experiences.
Learn about setting up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.
Workforce Tenant Overview
UpdatedLearn about B2B collaboration for sharing apps with external identities, business partners, and guests, using External ID for authentication and identity access management.
B2b Guest Access
Updated> This information relates to a prerelease product that might be substantially modified before its release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
Use Microsoft Entra API connectors to customize and extend your self-service sign-up user flows by using web APIs.
Microsoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.
Cross-tenant access overview
UpdatedLearn how to manage cross-tenant access in Microsoft Entra External ID. Configure B2B collaboration and direct connect settings to control access and trust for external organizations.
External Tenant Features
UpdatedCompare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.
External Tenant Overview
UpdatedLearn how Microsoft Entra External ID provides to manage your external identities scenarios, including guest user access and customer identity and access management (CIAM) for apps.
Get started guide features
UpdatedLearn about the features you set up with the get started guide.
MFA in external tenants
UpdatedLearn about using MFA to secure apps in your external tenant and enabling email one-time passcodes (EOTP) or SMS as a second verification method for sign-up and sign-in.
Learn best practices and recommendations for business-to-business (B2B) guest user access in Microsoft Entra ID.
Microsoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.
Plan a CIAM Deployment
UpdatedDiscover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.
Self-service sign-up
UpdatedLearn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.
User Attributes
UpdatedUser profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.
B2b Guest Access
UpdatedLearn how Global Secure Access enables secure B2B guest access for external partners through the Global Secure Access client and Azure Virtual Desktop.
Standards
11**Password complexity mismatch in Native Auth**: During a Native Auth flow, if a user enters a password that is correct according to the legacy identity provider but is considered weak by External ID password complexity standards an error is returned instead of redirecting to SSPR.
Whats New
UpdatedWe are pleased to announce the general availability of client credentials in Entra External ID. The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. Permissions are granted directly to the application itself by an administrator.
Learn about federation with an external organization's SAML/WS-Fed identity provider (IdP) for external user self-service sign-up and invitation redemption.
Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Customize the user claims that are issued in the SAML token for Microsoft Entra B2B users.
Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.
Register a SAML app
UpdatedLearn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.
Set up direct federation with SAML 2.0 or WS-Fed identity providers (IdP) and enable self-service sign-up for external users, who can sign in with their own work accounts.
Set up AD FS federation
UpdatedLearn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Security
5Add Security Group
Updatedauthor: henrymbuguakiarie
Learn how to configure Akamai Web Application Firewall (WAF) to protect against attacks for Microsoft Entra External ID tenants.
Learn how to configure Cloudflare Web Application Firewall (WAF) to protect against attacks.
Fraud Protection Integration
UpdatedLearn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.
Give locally managed external partners access to both local and cloud resources using the same credentials with Microsoft Entra B2B collaboration.
Microsoft identity platform
4Learn how to Migrate to version 2 of the CrossTenantAccessPolicy Microsoft Graph API.
Disable Sign Up User Flow
UpdatedDisable sign-up in your user flow with Microsoft Graph API. Prevent new registrations and allow only sign-in for your external users.
Learn how to use Visual Studio Connected Services to integrate Microsoft Entra ID into your applications right from your development environment.
Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.
Provisioning
3Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
include file
Updatedinclude file
Include file
UpdatedInclude file
Monitoring
2Guest user properties are configurable in Microsoft Entra B2B collaboration
Learn how to set up Azure Monitor in external tenants to collect and analyze data in your tenant.
Troubleshooting
2Learn about known issues in external tenants.
Troubleshoot B2B issues
UpdatedLearn how to troubleshoot common issues with Microsoft Entra B2B collaboration. Resolve guest sign-in errors, direct connect access problems, policy update failures, and encrypted email access issues.
Branding
1Customize the sign-in experience for your application with branding themes in external tenants
UpdatedLearn about how to create branding themes and apply them to the sign-in experience for your application in Microsoft External ID for external tenants.
Microsoft Entra Internet Access
12 updatesGeneral
7Learn how to configure threat intelligence in Microsoft Entra Internet Access.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Data Storage And Privacy
UpdatedGlobal Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Points Of Presence
UpdatedGlobal Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
PowerShell sample - Add Intune device compliance bypasses to Global Secure Access Internet Access
UpdatedPowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Fundamentals
2Clients
UpdatedLearn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Internet Access
UpdatedLearn about how Microsoft Entra Internet Access secures access to the Internet.
Conditional Access
1PowerShell examples for use in a Microsoft Entra Internet Access break glass scenario.
Monitoring
1Event Enrichment Logs
UpdatedGlobal Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.
Security
1Configure Cloud Firewall
UpdatedLearn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Microsoft Entra Private Access
16 updatesGeneral
10Ciphers
UpdatedLearn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Configure Connectors
UpdatedLearn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Configure Domain Controllers
UpdatedLearn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.
Configure Quick Access
UpdatedLearn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Enable Multi Geo
UpdatedLearn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
author: kenwith
Covers how to provide single sign-on using Kerberos with Microsoft Entra Private Access.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
Fundamentals
3Connector Groups
UpdatedLearn how Microsoft Entra private network connector groups work, and how Microsoft Entra Private Access and application proxy use them.
Connectors
UpdatedLearn how Microsoft Entra private network connectors work and how Microsoft Entra Private Access and application proxy use them.
Private Access
UpdatedLearn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Developer
2Configure Per App Access
UpdatedLearn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.
Security
1Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Microsoft Entra Verified ID
5 updatesGeneral
2Dnsbind
UpdatedLearn how to link your domain to your decentralized identifier (DID).
Licensing Verified Id
Updatedauthor: barclayn
Security
2Use Quickstart
UpdatedIn this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.
In this tutorial, you learn how to configure your tenant to verify credentials.
Architecture
1Helpdesk With Verified Id
UpdatedA design pattern describing how to verify in helpdesk scenarios
Microsoft Entra Workload ID
2 updatesGeneral
2Workload Identity
Updatedauthor: shlipsey3
Licensing Managed Identities
Updatedauthor: barclayn
Microsoft Entra Global Secure Access
93 updatesGeneral
48Configure Connectors
Updatedauthor: kenwith
This article lists all releases of Microsoft Entra private network connector and describes new features and fixed issues.
author: kenwith
Ai Prompt Shield
Updatedauthor: HULKsmashGithub
Learn how to assign a remote network to a traffic forwarding profile for Global Secure Access.
China User Support
UpdatedLearn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.
Microsoft and Cisco’s Secure Access coexistence solution guide.
Cisco Vpn Coexistence
UpdatedMicrosoft and Cisco VPNs coexistence solution guide.
Compliant Network
Updatedauthor: kenwith
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Learn how to set up the bidirectional communication tunnel between Global Secure Access and your router.
Create Remote Networks
UpdatedLearn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.
Current Known Limitations
Updatedauthor: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: jenniferf-skc
Global Secure Access maintains a compliance portfolio. This article lists the current, supported certifications.
Install Android Client
Updatedauthor: HULKsmashGithub
Install Ios Client
Updatedauthor: HULKsmashGithub
Install Windows Client
Updatedauthor: HULKsmashGithub
List Remote Networks
UpdatedLearn how to list remote networks for Global Secure Access.
Macos Client Release History
Updatedauthor: HULKsmashGithub
Manage Microsoft Profile
UpdatedLearn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.
Learn how to add and delete customer premises equipment device links to remote networks for Global Secure Access.
Manage Remote Networks
UpdatedLearn how to update and delete remote networks for Global Secure Access.
Learn how to roll out traffic forwarding profiles to users and groups with Global Secure Access
Network Content Filtering
Updatedauthor: HULKsmashGithub
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
PowerShell example that gets the Auth Token for registering your Microsoft Entra private network connector through Azure, AWS, or GCP Marketplaces.
Use these PowerShell samples for Global Secure Access.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Quickstart Install Client
UpdatedLearn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
Quickstart Per App Access
UpdatedLearn how to configure per-app access to private resources in Global Secure Access.
Quickstart Quick Access
UpdatedLearn how to configure Quick Access to private resources in Global Secure Access.
Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.
Remote Network Resilience
Updatedai-usage: ai-assisted
Role Based Permissions
UpdatedLearn about the built-in administrator roles you can assign to manage Global Secure Access permissions.
Sentinel Integration
Updatedai-usage: ai-assisted
Covers how to perform an unattended installation of the Microsoft Entra private network connector.
Simulate Remote Network
Updatedauthor: kenwith
Source Ip Restoration
Updatedauthor: kenwith
author: kenwith
Global Secure Access Threat intelligence threat types
author: kenwith
Global Secure Access Web content filtering categories
author: HULKsmashGithub
Zscaler Coexistence
Updatedauthor: kenwith
Install Windows Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Fundamentals
17Transport Layer Security
UpdatedThis article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.
What Is Global Secure Access
UpdatedLearn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Continuous Access Evaluation
UpdatedLearn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
Universal Conditional Access
Updatedauthor: kenwith
Alerts
Updatedai-usage: ai-assisted
Application Usage Analytics
UpdatedA Microsoft Entra documentation page was updated: Application Usage Analytics.
Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.
Learn about the available Global Secure Access logs and monitoring options.
Microsoft Traffic Profile
UpdatedLearn about the capabilities and traffic handling in the Microsoft traffic profile
Netskope Integration
Updatedai-usage: ai-assisted
Partner Ecosystems Overview
UpdatedLearn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
Install the Global Secure Access Windows client as a proof of concept. This script automates installation and applies essential configurations.
Remote Network Connectivity
UpdatedLearn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.
Secure Web Ai Gateway Agents
Updatedai-usage: ai-assisted
Traffic Dashboard
UpdatedMonitor the health and status of your network traffic with the Global Secure Access dashboard.
Traffic Forwarding
UpdatedLearn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.
author: idmdev
Troubleshooting
10author: HULKsmashGithub
author: HULKsmashGithub
Understand critical IP address ranges to consider when configuring and troubleshooting internet over remote network connectivity.
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
Troubleshoot problems installing the Microsoft Entra private network connector.
Troubleshoot Connectors
Updated**To verify the client certificate:**
Monitoring
7Access Audit Logs
UpdatedLearn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
View Traffic Logs
UpdatedLearn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Export Connector Logs
Updatedauthor: jenniferf-skc
Remote Network Health Logs
UpdatedLearn how to check the health of your remote networks with the Global Secure Access remote network health logs.
Use Workbooks
UpdatedWorkbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
View Deployment Logs
Updatedauthor: kenwith
View Enriched Logs
UpdatedLearn how to use enriched Microsoft 365 logs for Global Secure Access.
Security
7Cisco Coexistence
UpdatedMicrosoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
ai-usage: ai-assisted
Palo Alto Coexistence
UpdatedMicrosoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Transport Layer Security
UpdatedLearn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Full Data Loss Protection
Updatedai-usage: ai-assisted
Conditional Access
2PowerShell examples that re-enable any Conditional Access policies that were disabled in a break glass scenario.
Quickstart Remote Network
UpdatedLearn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
Developer
2author: HULKsmashGithub
Secure private application access with Privileged Identity Management (PIM) and Global Secure Access
UpdatedLearn how to secure highly valued private application access with Privileged Identity Management (PIM) and Global Secure Access
Security Copilot + Entra
1 updateTroubleshooting
1author: shlipsey3
