Week in brief

External ID password-migration behavior is clarified in an otherwise documentation-heavy Entra week

The week of 2 February 2026 was overwhelmingly a Microsoft Learn documentation cycle: 858 recorded changes comprised 850 updates, 2 new pages, 6 removals, and no Message Center items. The meaningful exceptions are specific guidance and one documented External ID flow edge case, not a release wave. The supplied evidence does not establish a GA or preview launch, a retirement, or a product behavior change during the week. The two new records are a token guide and an app-registration deactivation article; one External ID B2B Guest Access page carries a prerelease disclaimer, but no preview scope or availability is given. The remaining MFA, B2B, custom URL, application proxy, and Conditional Access edits are best treated as how-to or reference maintenance unless a particular implementation depends on them.

  • The updated Migrate Passwords Just In Time page documents a specific flow: if a password is valid at the legacy identity provider but fails External ID password-complexity rules during Native Authentication, the user receives an error instead of being redirected to SSPR. This is an Updated documentation item, so it establishes the documented behavior but not that Microsoft changed it during this week. Teams using just-in-time migration should test this case and ensure their client-flow and support assumptions do不依赖

  • The new Deactivate an app registration article describes deactivating an app registration to prevent token issuance while preserving application configuration. The record does not say that the underlying operation launched this week or provide GA or preview status, so this should be read as new procedure documentation rather than a product launch. Administrators can compare the documented operation with existing app shutdown or incident-containment runbooks; no additional prerequisites or migration steps are stated

  • A new comprehensive Microsoft identity platform guide covers access, ID, and refresh tokens, claims, validation, and configuration. The updated External ID Tokens Overview distinguishes workforce and customer tenant configurations: they use the same underlying identity service, but different sign-in domains and token-issuing authorities, allowing workflows to remain separated. This is reference and architecture guidance, not a stated token-format or availability change. Review issuer-validation assumptions in appsが

  • The updated Conditional Access for High-Risk Agent Identities article explains how to configure Conditional Access policies to block risky agent identities. Related Agent ID updates describe specialized agent identities for AI-agent authentication and authorization and show how an agent can call Microsoft Graph using an agent identity or agent user. This is security guidance, not a GA or preview announcement or an automatic policy change. Organizations using Agent ID should assess policy scope before altering their

  • ID Governance / Global Secure Access / Internet AccessConditional Access exception and break-glass guidance was refreshed

    The updated ID Governance page describes using access reviews to manage users excluded from Conditional Access policies. Related Internet Access and Global Secure Access PowerShell samples cover emergency operations: the Internet Access scenario disables traffic forwarding and Conditional Access policies using the compliant network condition, while the Global Secure Access recovery sample re-enables policies disabled during a break-glass scenario. These are operational security documentation updates, not a reported

For Entra administrators

Administrators using External ID just-in-time password migration should test the documented password-complexity mismatch path, because it returns an error rather than redirecting to SSPR. Teams that manage app registrations should review the deactivation procedure and its token-issuance implications; applications spanning workforce and customer configurations should verify issuer-validation assumptions. Agent ID and secure-access owners should review the updated Conditional Access and break-glass guidance. The B2B Guest Access material should be treated as prerelease information, not a GA commitment. These are targeted checks, not a basis for a tenant-wide configuration change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Developer

80

Application Proxy Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

6 February 2026

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

6 February 2026

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

6 February 2026

Deactivate Application Portal

Updated

Before deactivating the application, remove all owners from the application. This ensures only users with tenant-wide `microsoft.directory/applications/enable` scope can reactivate the application. This scope is restricted to administrative roles.

5 February 2026

Application Proxy Configure Cookie Settings

Updated

Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.

4 February 2026

Configure Sso

Updated

Understand single sign-on with an on-premises app using application proxy.

4 February 2026

PowerShell samples for Microsoft Entra application proxy

Updated

Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.

4 February 2026

Publish native client apps

Updated

Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.

4 February 2026

Provisioning

60

Provision a User with Expression Builder

Updated

Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.

6 February 2026

Provisioning Workbook

Updated

This article describes the Azure Monitor workbook for provisioning.

6 February 2026

Tutorial Ecma Sql Connector

Updated

This tutorial describes how to provision users from Microsoft Entra ID into a SQL database.

6 February 2026

Workday Expression Mapping Functions for Microsoft Entra ID Provisioning

Updated

A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.

6 February 2026

Configure Akamai Enterprise Application Access for automatic user provisioning with Microsoft Entra ID

Updated

This article describes the steps you need to perform in both Akamai Enterprise Application Access and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Akamai Enterprise Application Access](https://www.akamai.com) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

5 February 2026

General

50

include file

Updated

include file Microsoft Entra ID preview program information

4 February 2026

Controls

Updated

author: shlipsey3

4 February 2026

Users Close Account

Updated

How to close your work or school account in an unmanaged Microsoft Entra ID.

4 February 2026

Fundamentals

42

Tokens Overview

Removed

A Microsoft Entra documentation page was updated: Tokens Overview.

7 February 2026

Federation Overview

Removed

A Microsoft Entra documentation page was updated: Federation Overview.

6 February 2026

Sso Overview

Removed

A Microsoft Entra documentation page was updated: Sso Overview.

6 February 2026

Sspr

Removed

A Microsoft Entra documentation page was updated: Sspr.

6 February 2026

Whats New

Updated

Restricted management administrative units enable you to easily restrict access to users, groups, or devices to the specific users or applications you specify. Tenant-level administrators (including Global Administrators) can't modify members of restricted management administrative units unless they're explicitly assigned a role scoped to the administrative unit. This makes it easy to lock down a set of sensitive groups or user accounts in your tenant without having to remove tenant-level role assignments. For more information, see: [Restricted management administrative units in Microsoft Entra ID](../identity/role-based-access-control/admin-units-restricted-management.md).

5 February 2026

Overview

Updated

author: shlipsey3

4 February 2026

Recommendations

Updated

| Group Policy Object (GPO) assigns unprivileged identities to local groups with elevated privileges | Users | Preview | Yes | N/A |

3 February 2026

Whats New

Updated

For guidance, see:

3 February 2026

Troubleshooting

24

Broken Links in an Application

Updated

Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.

6 February 2026

On Premises Ecma Troubleshoot

Updated

Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.

6 February 2026

Broken Links in an Application

Updated

Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.

4 February 2026

Authentication

15

Whatis Phs

Updated

To use password hash synchronization in your environment, you need to:

7 February 2026

Security

13

Standards

12

Single Sign On Saml Protocol

Updated

| `ID` | Required | Microsoft Entra ID uses this attribute to populate the `InResponseTo` attribute of the returned response. ID must not begin with a number, so a common strategy is to prepend a string like "ID" to the string representation of a GUID. For example, `id6c1c178c166d486687be4aaf5e482730` is a valid ID. |

3 February 2026

Governance

7

Plan cloud HR application to Microsoft Entra user provisioning

Updated

This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.

6 February 2026

Govern the existing users of an application that does not support provisioning in Microsoft Entra ID with Microsoft PowerShell

Updated

Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.

4 February 2026

Architecture

6

What Is App Proxy

Updated

Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.

4 February 2026

Architecture overview

Updated

Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.

4 February 2026

Conceptual Deployment Plan

Updated

An end-to-end guide for planning the deployment of application proxy within your organization

4 February 2026

Conditional Access

6

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

6 February 2026

Use application proxy to integrate on-premises apps with Defender for Cloud Apps

Updated

Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.

4 February 2026

Microsoft identity platform

6

Deactivate an app registration

New

Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.

5 February 2026

Deactivate App Registration

Updated

- [Delete an enterprise application](delete-application-portal.md) for permanent removal

5 February 2026

Sap Cloud Platform Identity Authentication Provisioning Tutorial

Updated

Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.

4 February 2026

Monitoring

5

General

9

Agent Id

Updated

author: shlipsey3

4 February 2026

Agent Lists

Updated

Access Microsoft Entra admin center to effortlessly view and filter agent identities. Streamline tenant oversight and take charge now.

4 February 2026

Agent metadata and discoverability patterns

Updated

Learn how to structure agent metadata for optimal discoverability in Microsoft Entra Agent Registry and understand how the collections model affects agent visibility.

4 February 2026

Manage Agent Blueprint

Updated

This article explains how to manage agent blueprints and registry-only agents using the Microsoft Entra Admin Center.

4 February 2026

Developer

4

Call Api Azure Services

Updated

Learn how to call Azure services using .NET Azure SDK from an agent using agent identities.

4 February 2026

Register Agents to the Agent Registry

Updated

Learn how to register agents to the Agent Registry in Microsoft Entra Agent ID through automatic registration or manual API calls for agent discovery and management.

4 February 2026

Microsoft identity platform

3

Call Api Microsoft Graph

Updated

Learn how to call Microsoft Graph API from an agent using agent identities or agent users, including authentication configuration and implementation steps.

4 February 2026

What Is Agent Id Platform

Updated

Learn about the Microsoft Agent Identity Platform, a comprehensive identity, and authorization framework designed specifically for AI agents. Key concepts include agent registry, authentication protocols, tokens, claims, and agent discovery capabilities.

4 February 2026

Standards

3

Agent Autonomous App Oauth Flow

Updated

Learn how agent identities operate autonomously without user context using app-only protocol with OAuth 2.0 client credentials flows.

4 February 2026

Agent On Behalf Of Oauth Flow

Updated

Learn how agent applications operate on behalf of signed-in users using OAuth 2.0 On-Behalf-Of flows with agent identity blueprints and agent identities.

4 February 2026

Agent User Oauth Flow

Updated

Learn how agent identities operate with user context through agent users using the agent user impersonation protocol with OAuth 2.0 token exchange.

4 February 2026

Fundamentals

2

What Is Agent Id

Updated

Learn about agent identities, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.

4 February 2026

What Is Agent Registry

Updated

Learn about the Agent Registry, a centralized metadata repository that enables agent discovery, and secure communication in enterprise environments.

4 February 2026

Authentication

1

Agent Identities

Updated

Learn about agent identities in Microsoft Entra ID, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.

4 February 2026

Conditional Access

1

Security

1

Call Api Custom

Updated

Learn how to call custom protected APIs from an agent using different approaches including IDownstreamApi, MicrosoftIdentityMessageHandler, and IAuthorizationHeaderProvider.

4 February 2026

Troubleshooting

1

Preview Known Issues

Updated

Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.

4 February 2026

Security

12

Fundamentals

10

Authentication

1

Monitoring

1

Troubleshooting

1

Governance

143

Entitlement Management Delegate

Updated

| Catalog owner | `ae79f266-94d4-4dab-b730-feca7e132178` | Edit and manage access packages and other resources in a catalog. Typically an IT administrator or resource owners, or an identity who the catalog owner chooses. |

6 February 2026

Govern access for applications in your environment

Updated

Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.

4 February 2026

Govern access with an organizational role model

Updated

Microsoft Entra ID Governance allows you to model organizational roles using access packages, so you can migrate your existing role definitions to entitlement management.

4 February 2026

Migrate identity management scenarios from SAP IDM to Microsoft Entra

Updated

Learn the detailed steps for how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and provision those identities with access to SAP ECC, SAP S/4HANA, and other SAP and non-SAP applications, for organizations that were previously using SAP IDM.

4 February 2026

Pim Powershell Migration

Updated

The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.

4 February 2026

Check Status Workflow

Updated

This article guides a user on checking the status of a Lifecycle workflow

4 February 2026

Check Workflow Insights

Updated

Learn how to check workflow insights within your Microsoft Entra tenant.

4 February 2026

Customize Workflow Email

Updated

Get a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.

4 February 2026

Governance Service Limits

Updated

This article details service limits for offerings within Microsoft Entra ID Governance

4 February 2026

Groups Activate Roles

Updated

Learn how to activate your group membership or ownership in Privileged

4 February 2026

Lifecycle Workflow Tasks

Updated

This article guides a user on Workflow task definitions and task parameters.

4 February 2026

Manage access to your SAP applications

Updated

Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.

4 February 2026

Manage access with access reviews

Updated

Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.

4 February 2026

Manage Workflow On Premises

Updated

A how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.

4 February 2026

Manage Workflow Properties

Updated

This article guides a user to editing a workflow's properties using Lifecycle Workflows.

4 February 2026

Manage Workflow Tasks

Updated

This article guides a user on managing workflow versions with Lifecycle Workflows.

4 February 2026

On Demand Workflow

Updated

This article guides a user to running a workflow on demand using Lifecycle Workflows.

4 February 2026

Pim Apis

Updated

Information for understanding the APIs in Microsoft Entra Privileged

4 February 2026

Pim Roles

Updated

Describes the roles you can't manage in Microsoft Entra Privileged Identity

4 February 2026

Provision Ldap

Updated

This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.

4 February 2026

Provision Sap

Updated

This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.

4 February 2026

Provision Sql

Updated

This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host

4 February 2026

Reprocess Workflow

Updated

This article guides a user on reprocessing workflow runs using Lifecycle Workflows

4 February 2026

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

4 February 2026

Entitlement Management Ticketed Provisioning

Updated

Scenario: In this scenario you learn how to use custom extensibility, and a Logic App, to automatically generate ServiceNow tickets for manual provisioning of users who have received assignments and need access to apps.

3 February 2026

Fundamentals

20

Microsoft Entra ID Governance

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

4 February 2026

What are access reviews? - Microsoft Entra

Updated

Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.

4 February 2026

Lifecycle Workflow On Premises

Updated

Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.

4 February 2026

What is entitlement management?

Updated

Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external identities.

4 February 2026

Architecture

2

Troubleshooting

2

Conditional Access

1

General

87

Migrate Users

Updated

Learn how to migrate users from another identity provider to Microsoft Entra External ID.

7 February 2026

Add and manage admin accounts

Updated

Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.

7 February 2026

Add custom attributes

Updated

Learn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.

7 February 2026

Add Facebook as an identity provider

Updated

Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.

7 February 2026

Allow or Block Invitations

Updated

Learn how an administrator creates a list to allow or block B2B collaboration with specific domains by using the Microsoft Entra admin center.

7 February 2026

Applies To External Only

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to external tenants.](../media/common/applies-to-yes.png) External tenants ([learn more](/entra/external-id/tenant-configurations))

7 February 2026

Applies To Ios Macos

Updated

**Applies to**: ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) iOS (Swift) ![Green circle with a white check mark symbol.](../media/common/applies-to-yes.png) macOS (Swift)

7 February 2026

Applies To Workforce Only

Updated

**Applies to**: ![Green circle with a white check mark symbol that indicates the following content applies to workforce tenants.](../media/common/applies-to-yes.png) Workforce tenants ([learn more](/entra/external-id/tenant-configurations))

7 February 2026

B2B Direct Connect Setup

Updated

Learn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.

7 February 2026

Bulk invite B2B users

Updated

Learn how to bulk invite B2B collaboration users in Microsoft Entra External ID. Follow the steps to prepare a CSV file, upload it, and verify guest users in the directory.

7 February 2026

Configure external collaboration

Updated

Learn how to configure external collaboration settings in Microsoft Entra External ID. Control guest user access, specify who can invite guests, and manage domain restrictions for B2B collaboration.

7 February 2026

Cross Cloud Settings

Updated

Enable secure cross-cloud B2B collaboration between organizations in different sovereign (national) Microsoft Azure clouds by configuring Microsoft cloud settings.

7 February 2026

Dynamic groups setup

Updated

Learn how to create and manage dynamic membership groups in Microsoft Entra External ID. Set rules based on user attributes to automate group membership for B2B collaboration.

7 February 2026

External ID pricing

Updated

Learn about the pricing structure for Microsoft Entra External ID. Understand the monthly active users (MAU) billing model, core offering, and premium add-ons. Link your tenant to an Azure subscription for proper billing and feature access.

7 February 2026

Frequently asked questions

Updated

Find answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.

7 February 2026

Google identity provider

Updated

Learn how to add Google as an identity provider in Microsoft Entra External ID. Enable customers to sign in with their Google accounts and configure Google federation for seamless access.

7 February 2026

Leave an Organization

Updated

As a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.

7 February 2026

Tenant configurations

Updated

Learn about tenant configurations in Microsoft Entra External ID. Understand the differences between workforce and external tenants, and how to configure them for your organization's needs.

7 February 2026

Use Microsoft Accounts

Updated

Enable your external business partners and guest users to use their Microsoft Account (MSA) to sign in to your apps for B2B collaboration.

7 February 2026

Use Microsoft Entra Accounts

Updated

Enable your external business partners and guest users to use their Microsoft Entra work or school accounts to sign in to your apps for B2B collaboration.

7 February 2026

Redemption Experience

Updated

When you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) that's initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.

6 February 2026

B2b Quickstart Add Guest Users Portal

Updated

If you don’t have an Azure subscription, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin.

6 February 2026

Authentication

27

Add multifactor authentication (MFA) to a customer app

Updated

Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.

7 February 2026

B2B guest user properties

Updated

Learn about the properties of a B2B guest user in Microsoft Entra External ID. Understand user types, authentication methods, and how to manage guest user access and permissions.

7 February 2026

Customize the browser language

Updated

Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.

7 February 2026

Email one-time passcode authentication

Updated

Learn how to enable and use email one-time passcode authentication for B2B guest users in Microsoft Entra External ID. This feature provides a seamless fallback authentication method for sign-in.

7 February 2026

Training, demos, and videos

Updated

Explore Microsoft Entra External ID training, live demos, and videos. Learn to create secure sign-up experiences and protect access with multifactor authentication.

7 February 2026

Tutorial - multifactor authentication for B2B

Updated

In this tutorial, learn how to require multifactor authentication when you use Microsoft Entra B2B to collaborate with external users and partner organizations.

7 February 2026

About B2B Invitations

Updated

Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.

7 February 2026

Add an application to a user flow

Updated

Learn how to add an application to a user flow to associate the application with a sign-up and sign-in user experience. Get guidance for updating the application configuration with application registration and tenant information.

7 February 2026

Add Azure AD B2C for customer sign-in

Updated

Learn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

7 February 2026

Add Facebook for customer sign-in

Updated

Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.

7 February 2026

Create a User Flow

Updated

Add sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.

7 February 2026

Define custom attributes

Updated

Learn how to create and define new custom attributes to be collected from users during sign-up and sign-in.

7 February 2026

External Tenant Quickstart

Updated

In this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.

7 February 2026

Invite internal users to B2B collaboration

Updated

If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can change to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials or sign-in. Use either PowerShell or the Microsoft Graph invitation API.

7 February 2026

Quickstart: Add a guest user with PowerShell

Updated

In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.

7 February 2026

Sign in with alias

Updated

Learn how to Sign in with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

7 February 2026

Test a user flow

Updated

Learn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.

7 February 2026

Visual Studio Code extension for External ID

Updated

Learn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.

7 February 2026

Developer

24

Add an enterprise application

Updated

Learn how to add enterprise applications to your Microsoft Entra external tenant using the admin center. Discover gallery apps, configuration steps, and deployment tips.

7 February 2026

Add attributes to token claims

Updated

Learn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.

7 February 2026

Using role-based access control for apps

Updated

Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.

7 February 2026

Fundamentals

19

Security Features in External Tenants

Updated

Learn about security features and fundamentals for Microsoft Entra External ID customer identity and access management (CIAM) in external tenant configurations.

7 February 2026

Tokens Overview

Updated

Microsoft Entra ID supports two tenant configurations: A workforce configuration that's intended for internal use and manages employees and business guests, and a [customer configuration](/entra/external-id/customers/concept-supported-features-customers) which is optimized for isolating consumers and partners in a restricted external-facing directory. While the underlying identity service is identical for both tenant configurations, the sign in domains and token issuing authority for external tenants is different. This allows applications to keep workforce and external ID workflows separated if needed.

7 February 2026

Custom authentication extensions

Updated

Learn how to use custom authentication extensions in Microsoft Entra External ID. Integrate with external systems, add custom logic to authentication flows, and enhance user experiences.

7 February 2026

Workforce Tenant Overview

Updated

Learn about B2B collaboration for sharing apps with external identities, business partners, and guests, using External ID for authentication and identity access management.

7 February 2026

B2b Guest Access

Updated

> This information relates to a prerelease product that might be substantially modified before its release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

7 February 2026

B2B direct connect Microsoft Entra overview

Updated

Microsoft Entra B2B direct connect lets users from other Microsoft Entra tenants seamlessly sign in to your shared resources via Teams shared channels. There's no need for a guest user object in your Microsoft Entra directory.

7 February 2026

Cross-tenant access overview

Updated

Learn how to manage cross-tenant access in Microsoft Entra External ID. Configure B2B collaboration and direct connect settings to control access and trust for external organizations.

7 February 2026

External Tenant Features

Updated

Compare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.

7 February 2026

External Tenant Overview

Updated

Learn how Microsoft Entra External ID provides to manage your external identities scenarios, including guest user access and customer identity and access management (CIAM) for apps.

7 February 2026

MFA in external tenants

Updated

Learn about using MFA to secure apps in your external tenant and enabling email one-time passcodes (EOTP) or SMS as a second verification method for sign-up and sign-in.

7 February 2026

Microsoft Entra External ID overview

Updated

Microsoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.

7 February 2026

Plan a CIAM Deployment

Updated

Discover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.

7 February 2026

Self-service sign-up

Updated

Learn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.

7 February 2026

User Attributes

Updated

User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.

7 February 2026

B2b Guest Access

Updated

Learn how Global Secure Access enables secure B2B guest access for external partners through the Global Secure Access client and Azure Virtual Desktop.

4 February 2026

Standards

11

Migrate Passwords Just In Time

Updated

**Password complexity mismatch in Native Auth**: During a Native Auth flow, if a user enters a password that is correct according to the legacy identity provider but is considered weak by External ID password complexity standards an error is returned instead of redirecting to SSPR.

7 February 2026

Whats New

Updated

We are pleased to announce the general availability of client credentials in Entra External ID. The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. Permissions are granted directly to the application itself by an administrator.

7 February 2026

Add a SAML/WS-Fed identity provider

Updated

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

7 February 2026

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

7 February 2026

Identity providers for external tenants

Updated

Learn sign-in and MFA options for customer identity and access management (CIAM), including email, one-time passcodes, social providers, SAML/WS-Fed, and OIDC.

7 February 2026

Register a SAML app

Updated

Learn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.

7 February 2026

SAML/WS-Fed federation for self-service sign-up

Updated

Set up direct federation with SAML 2.0 or WS-Fed identity providers (IdP) and enable self-service sign-up for external users, who can sign in with their own work accounts.

7 February 2026

Set up AD FS federation

Updated

Learn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.

7 February 2026

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

7 February 2026

Security

5

Fraud Protection Integration

Updated

Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.

7 February 2026

Microsoft identity platform

4

Disable Sign Up User Flow

Updated

Disable sign-up in your user flow with Microsoft Graph API. Prevent new registrations and allow only sign-in for your external users.

7 February 2026

Reset guest redemption status

Updated

Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.

7 February 2026

Provisioning

3

Monitoring

2

Troubleshooting

2

Troubleshoot B2B issues

Updated

Learn how to troubleshoot common issues with Microsoft Entra B2B collaboration. Resolve guest sign-in errors, direct connect access problems, policy update failures, and encrypted email access issues.

7 February 2026

Branding

1

General

7

Data Storage And Privacy

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.

4 February 2026

Manage Internet Access Profile

Updated

Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.

4 February 2026

Points Of Presence

Updated

Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.

4 February 2026

Fundamentals

2

Clients

Updated

Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.

4 February 2026

Internet Access

Updated

Learn about how Microsoft Entra Internet Access secures access to the Internet.

4 February 2026

Conditional Access

1

Monitoring

1

Event Enrichment Logs

Updated

Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.

4 February 2026

Security

1

Configure Cloud Firewall

Updated

Learn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.

4 February 2026

General

10

Ciphers

Updated

Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.

4 February 2026

Configure Connectors

Updated

Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.

4 February 2026

Configure Domain Controllers

Updated

Learn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.

4 February 2026

Configure Quick Access

Updated

Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.

4 February 2026

Enable Multi Geo

Updated

Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.

4 February 2026

Manage Private Access Profile

Updated

Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.

4 February 2026

Fundamentals

3

Connector Groups

Updated

Learn how Microsoft Entra private network connector groups work, and how Microsoft Entra Private Access and application proxy use them.

4 February 2026

Connectors

Updated

Learn how Microsoft Entra private network connectors work and how Microsoft Entra Private Access and application proxy use them.

4 February 2026

Private Access

Updated

Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.

4 February 2026

Developer

2

Configure Per App Access

Updated

Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.

4 February 2026

Source IP anchoring with Global Secure Access

Updated

Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.

4 February 2026

Security

1

General

2

Dnsbind

Updated

Learn how to link your domain to your decentralized identifier (DID).

4 February 2026

Security

2

Use Quickstart

Updated

In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.

4 February 2026

Architecture

1

General

2

General

48

China User Support

Updated

Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.

4 February 2026

Create Remote Networks

Updated

Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.

4 February 2026

List Remote Networks

Updated

Learn how to list remote networks for Global Secure Access.

4 February 2026

Manage Microsoft Profile

Updated

Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.

4 February 2026

Manage Remote Networks

Updated

Learn how to update and delete remote networks for Global Secure Access.

4 February 2026

Quickstart Install Client

Updated

Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.

4 February 2026

Quickstart Per App Access

Updated

Learn how to configure per-app access to private resources in Global Secure Access.

4 February 2026

Quickstart Quick Access

Updated

Learn how to configure Quick Access to private resources in Global Secure Access.

4 February 2026

Remote Network Configurations

Updated

Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.

4 February 2026

Role Based Permissions

Updated

Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.

4 February 2026

Install Windows Client

Updated

The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.

3 February 2026

Fundamentals

17

Transport Layer Security

Updated

This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.

4 February 2026

What Is Global Secure Access

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

4 February 2026

Alerts

Updated

ai-usage: ai-assisted

4 February 2026

Microsoft Traffic Profile

Updated

Learn about the capabilities and traffic handling in the Microsoft traffic profile

4 February 2026

Partner Ecosystems Overview

Updated

Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.

4 February 2026

Remote Network Connectivity

Updated

Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.

4 February 2026

Traffic Dashboard

Updated

Monitor the health and status of your network traffic with the Global Secure Access dashboard.

4 February 2026

Traffic Forwarding

Updated

Learn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.

4 February 2026

Troubleshooting

10

Troubleshoot Distributed File System

Updated

A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.

4 February 2026

Monitoring

7

Access Audit Logs

Updated

Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.

4 February 2026

View Traffic Logs

Updated

Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.

4 February 2026

Remote Network Health Logs

Updated

Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.

4 February 2026

Use Workbooks

Updated

Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.

4 February 2026

View Enriched Logs

Updated

Learn how to use enriched Microsoft 365 logs for Global Secure Access.

4 February 2026

Security

7

Cisco Coexistence

Updated

Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.

4 February 2026

Palo Alto Coexistence

Updated

Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.

4 February 2026

Powershell Open Secure Sockets Layer

Updated

Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.

4 February 2026

Transport Layer Security

Updated

Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.

4 February 2026

Conditional Access

2

Quickstart Remote Network

Updated

Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.

4 February 2026

Developer

2

Troubleshooting

1