📋 Microsoft Entra Documentation Changes

Changes for April 18th 2025

Period: April 17th 2025, 12:00 AM to April 18th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on April 18th 2025.

📊 Summary

74
Total Commits
2
New Files
20
Modified Files
0
Deleted Files
21
Contributors

🆕 New Documentation Files

+49 lines added
Commit: new doc file
Added by John Flores on Apr 17, 2025 3:23 AM
📖 View on learn.microsoft.com
+21 lines added
Commit: [Securing Entra] 23183 Addition

📝 Modified Documentation Files

+110 / -103 lines changed
Commit: Update reference-office-365-application-contents.md
Changes:
Before
After
 
The following list is provided as a reference and includes a detailed list of services and applications that are included in the Conditional Access [Office 365](concept-conditional-access-cloud-apps.md#office-365) app.
 
- App Studio for Microsoft Teams
- Augmentation Loop
- Call Recorder
- Connectors
- DataSecurityInvestigation
- Device Management Service
- EDU Assignments
- EnrichmentSvc
- Enterprise Copilot Platform
- Groups Service
- IC3 Gateway
- IC3 Gateway Non Cae
- Insights Services
- INT Augmentation Loop 1P
- Legacy Smart Compose
- Loop
- Loop Web Service
 
The following list is provided as a reference and includes a detailed list of services and applications that are included in the Conditional Access [Office 365](concept-conditional-access-cloud-apps.md#office-365) app.
 
- App Studio for Microsoft Teams
- Augmentation Loop
- Call Recorder
- Connectors
- DataSecurityInvestigation
- Device Management Service
- EDU Assignments
- EnrichmentSvc
- Enterprise Copilot Platform
- Groups Service
- IC3 Gateway
- IC3 Gateway Non Cae
- Insights Services
- INT Augmentation Loop 1P
- Legacy Smart Compose
- Loop
- Loop Web Application
+175 / -1 lines changed
Commit: Update concept-certificate-based-authentication-certificateuserids.md
Changes:
Before
After
>[!NOTE]
>Active Directory administrators can make changes that impact the certificateUserIds value in Microsoft Entra ID for any synchronized account. Administrators can include accounts with delegated administrative privilege over synchronized user accounts, or administrative rights over the Microsoft Entra Connect servers.
 
## Update certificateUserIds
Use the following steps to update certificateUserIds for users:
 
 
 
 
 
 
 
 
 
 
 
 
 
 
>[!NOTE]
>Active Directory administrators can make changes that impact the certificateUserIds value in Microsoft Entra ID for any synchronized account. Administrators can include accounts with delegated administrative privilege over synchronized user accounts, or administrative rights over the Microsoft Entra Connect servers.
 
## How to get CertificateUserIds values from end user certificate
 
For this configuration, you can use [Microsoft Graph PowerShell] (/powershell/microsoftgraph/installation).
 
1. Start PowerShell with administrator privileges.
1. Install and import the Microsoft Graph PowerShell SDK.
 
```powershell
Install-Module Microsoft.Graph -Scope AllUsers
Import-Module Microsoft.Graph.Authentication
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
```
 
1. Connect to the tenant and accept all.
 
```powershell
Connect-MGGraph -Scopes "Directory.ReadWrite.All", "User.ReadWrite.All" -TenantId <tenantId>
Modified by Ken Withee on Apr 17, 2025 1:30 AM
📖 View on learn.microsoft.com
+27 / -71 lines changed
Commit: Updates to intro.
Changes:
Before
After
author: kenwith
ms.author: kenwith
manager: femila
ms.topic: concept-article
ms.date: 04/16/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
---
 
# Learn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
 
Microsoft and Zscaler’s Secure Access Service Edge (SASE) solution can be used together in a unified environment. When used together, you harness a robust set of capabilities from both platforms to elevate your SASE journey. The synergy between these platforms enhances security and provides seamless connectivity.
 
This document contains steps to deploy these solutions side by side across several different access scenarios.
 
1. **Microsoft Entra Private Access with Zscaler Internet Access**
 
### Microsoft Global Secure Access
 
To set up Entra Global Secure Access and test all scenarios in this documentation you will need to perform the following:
author: kenwith
ms.author: kenwith
manager: femila
ms.topic: how-to
ms.date: 04/16/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
---
 
# Learn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
In today's rapidly evolving digital landscape, organizations require robust and unified solutions to ensure secure and seamless connectivity. Microsoft and Zscaler offer complementary Secure Access Service Edge (SASE) capabilities that, when integrated, provide enhanced security and connectivity for diverse access scenarios.
 
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Zscaler's Security Service Edge (SSE) offerings. By leveraging the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
 
1. **Microsoft Entra Private Access with Zscaler Internet Access**
 
### Microsoft Global Secure Access
 
To set up Entra Global Secure Access and test all scenarios in this documentation you will need to perform the following:
- Enable and disable different Microsoft Global Secure Access traffic forwarding profiles for your Microsoft Entra tenant. For more information about enabling and disabling profiles, see [Global Secure Access traffic forwarding profiles](concept-traffic-forwarding.md).
Modified by Ken Withee on Apr 17, 2025 2:11 AM
📖 View on learn.microsoft.com
+50 / -47 lines changed
Commit: Updates with Acrolinx to change to active voice, present tense, add clarity, simplify.
Changes:
Before
After
---
 
# Learn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
In today's rapidly evolving digital landscape, organizations require robust and unified solutions to ensure secure and seamless connectivity. Microsoft and Zscaler offer complementary Secure Access Service Edge (SASE) capabilities that, when integrated, provide enhanced security and connectivity for diverse access scenarios.
 
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Zscaler's Security Service Edge (SSE) offerings. By leveraging the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
 
1. **Microsoft Entra Private Access with Zscaler Internet Access**
 
In this scenario Global Secure Access will handle private application traffic. Zscaler will only capture Internet traffic. Therefore, the Zscaler Private Access module will be disabled from the Zscaler portal.
 
2. **Microsoft Entra Private Access with Zscaler Private Access and Zscaler Internet Access**
 
In this scenario both clients will handle traffic for separate private applications. Private applications in Microsoft Entra Private Access will be handled by Global Secure Access while private applications in Zscaler Private Access will be accessed through Zscaler Private Access module. Internet traffic will be handled by Zscaler Internet Access.
 
3. **Microsoft Entra Microsoft Access with Zscaler Private Access and Zscaler Internet Access**
 
In this scenario Global Secure Access will handle all Microsoft 365 traffic. Zscaler Private Access will handle Private application traffic and Zscaler Internet Access will handle Internet traffic.
 
4. **Microsoft Entra Internet Access and Microsoft Entra Microsoft Access and Zscaler Private Access**
---
 
# Learn about Security Service Edge (SSE) coexistence with Microsoft and Zscaler
In today's rapidly evolving digital landscape, organizations require robust, and unified solutions to ensure secure and seamless connectivity. Microsoft and Zscaler offer complementary Secure Access Service Edge (SASE) capabilities that, when integrated, provide enhanced security and connectivity for diverse access scenarios.
 
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Zscaler's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
 
1. **Microsoft Entra Private Access with Zscaler Internet Access**
 
In this scenario, Global Secure Access handles private application traffic. Zscaler only captures Internet traffic. Therefore, the Zscaler Private Access module is disabled from the Zscaler portal.
 
2. **Microsoft Entra Private Access with Zscaler Private Access and Zscaler Internet Access**
 
In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
 
 
3. **Microsoft Entra Microsoft Access with Zscaler Private Access and Zscaler Internet Access**
 
In this scenario, Global Secure Access handles all Microsoft 365 traffic. Zscaler Private Access handles Private application traffic and Zscaler Internet Access handles Internet traffic.
 
Modified by Shravan Jewargikar on Apr 17, 2025 12:48 AM
📖 View on learn.microsoft.com
+46 / -22 lines changed
Commit: Update concept-mfa-regional-opt-in.md
Changes:
Before
After
|:----------- |:---------------------------------------------- |
| 222 | Mauritania |
| 998 | Uzbek |
| 63 | Philippines |
| 20 | Egypt |
| 967 | Yemen |
| 84 | Vietnam |
| 62 | Indonesia |
| 234 | Nigeria |
| 972 | Israel |
| 233 | Ghana |
| 92 | Pakistan |
| 966 | Saudi Arabia |
| 971 | United Arab Emriates |
| 94 | Sri Lanka |
| 258 | Mozambique |
| 502 | Guatemala |
| 974 | Qatar |
| 591 | Bolivia |
| 254 | Kenya |
|:----------- |:---------------------------------------------- |
| 222 | Mauritania |
| 998 | Uzbek |
| 63 | Philippines |
| 20 | Egypt |
| 967 | Yemen |
| 84 | Vietnam |
| 62 | Indonesia |
| 234 | Nigeria |
| 972 | Israel |
| 233 | Ghana |
| 92 | Pakistan |
| 966 | Saudi Arabia |
| 971 | United Arab Emriates |
| 94 | Sri Lanka |
| 258 | Mozambique |
| 502 | Guatemala |
| 974 | Qatar |
| 591 | Bolivia |
| 254 | Kenya |
Modified by John Flores on Apr 17, 2025 2:02 AM
📖 View on learn.microsoft.com
+24 / -19 lines changed
Commit: [Conditional Access] Microsoft managed policy MFA for all
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 03/20/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Microsoft-managed policies
 
As mentioned in the [Microsoft Digital Defense Report in October 2023](https://www.microsoft.com/security/security-insider/microsoft-digital-defense-report-2023)
 
> ...threats to digital peace have reduced trust in technology and highlighted the urgent need for improved cyber defenses at all levels...
>
> ...at Microsoft, our more than 10,000 security experts analyze over 65 trillion signals each day... driving some of the most influential insights in
cybersecurity. Together, we can build cyber resilience through innovative action and collective defense.
 
As part this work we're making Microsoft-managed policies available in Microsoft Entra tenants around the world. These [simplified Conditional Access policies](#what-is-conditional-access) take action to require multifactor authentication, which a [recent study](https://arxiv.org/abs/2305.00945) finds can reduce the risk of compromise by greater than 99%.
 
:::image type="content" source="media/managed-policies/microsoft-managed-policy.png" alt-text="Screenshot showing an example of a Microsoft-managed policy in the Microsoft Entra admin center." lightbox="media/managed-policies/microsoft-managed-policy-expanded-full.png":::
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 04/16/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Microsoft-managed policies
 
As mentioned in the [Microsoft Digital Defense Report](https://www.microsoft.com/security/security-insider/microsoft-digital-defense-report-2023) from October 2023,
 
> ...threats to digital peace have reduced trust in technology and highlighted the urgent need for improved cyber defenses at all levels...
>
> ...at Microsoft, our more than 10,000 security experts analyze over 65 trillion signals each day... driving some of the most influential insights in
cybersecurity. Together, we can build cyber resilience through innovative action and collective defense.
 
As part of this work, we're making Microsoft-managed policies available in Microsoft Entra tenants around the world. These [simplified Conditional Access policies](#what-is-conditional-access) require multifactor authentication, which a [recent study](https://arxiv.org/abs/2305.00945) finds reduces the risk of compromise by more than 99%.
 
:::image type="content" source="media/managed-policies/microsoft-managed-policy.png" alt-text="Screenshot of a Microsoft-managed policy in the Microsoft Entra admin center." lightbox="media/managed-policies/microsoft-managed-policy-expanded-full.png":::
Modified by Sreyanth on Apr 17, 2025 7:25 AM
📖 View on learn.microsoft.com
+1 / -11 lines changed
Commit: remove token timeouts for RTs
Changes:
Before
After
 
## Token expiration
 
Refresh tokens can be revoked at any time, because of timeouts and revocations. Your app must handle revocations by the sign-in service gracefully by sending the user to an interactive sign-in prompt to sign in again.
 
### Token timeouts
 
You can't configure the lifetime of a refresh token. You can't reduce or lengthen their lifetime. Therefore, it's important to ensure that you secure refresh tokens, as they can be extracted from public locations by bad actors, or indeed from the device itself if the device is compromised. There are a few things you can do:
 
- Configure sign-in frequency in Conditional Access to define the time periods before a user is required to sign in again. For more information, see [Configuring authentication session management with Conditional Access](~/identity/conditional-access/howto-conditional-access-session-lifetime.md).
- Use [Microsoft Intune app management](/mem/intune/apps/app-management) services such as mobile application management (MAM) and mobile device management (MDM) to protect your organization's data
- Implement [Conditional Access token protection policy](~/identity/conditional-access/concept-token-protection.md)
 
Not all refresh tokens follow the rules set in the token lifetime policy. Specifically, refresh tokens used in single page apps are always fixed to 24 hours of activity, as if they have a `MaxAgeSessionSingleFactor` policy of 24 hours applied to them.
 
### Token revocation
 
 
## Token expiration
 
Refresh tokens will automatically expire once the lifetime period elapses. Additionally, they can be revoked by the sign-in service at any time before their expiration. Your app should handle such revocations gracefully by redirecting the user to an interactive sign-in prompt to reauthenticate and obtain a new token.
 
### Token revocation
 
 
 
 
 
 
 
 
 
 
 
Modified by Mark Wahl on Apr 17, 2025 7:02 AM
📖 View on learn.microsoft.com
+7 / -4 lines changed
Commit: add entra suite to gov licensing
Changes:
Before
After
 
### Governance products and prerequisites
 
The Microsoft Entra ID Governance capabilities are currently available in five products. These five products provide the same identity governance capabilities. The difference between the five products is that they have different prerequisites.
 
- A subscription to **Microsoft Entra ID Governance** or **MIcrosoft Entra ID Governance for Government**, listed in the product terms as the **Microsoft Entra ID Governance (User SL)** license, requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM` or `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID P1**, **Microsoft 365 E3/E5/A3/A5/G3/G5**, **Enterprise Mobility + Security E3/E5** or **Microsoft 365 F1/F3**.
- A subscription to **Microsoft Entra ID Governance Step Up for Microsoft Entra ID P2** or **Microsoft Entra ID Governance Add-on for Microsoft Entra ID P2 for Government**, listed in the product terms as the **Microsoft Entra ID Governance P2** license, requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID P2**, **Microsoft 365 E5/A5/G5**, **Enterprise Mobility + Security E5**, **Microsoft 365 E5/F5 Security** or **Microsoft 365 F5 Security + Compliance**.
- A subscription to **Microsoft Entra ID Governance Step up for Microsoft Entra ID F2**, listed in the product terms as the **Microsoft Entra ID Governance F2** license, requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID F2**.
 
The [product names and service plan identifiers for licensing](../identity/users/licensing-service-plan-reference.md) lists additional products that include the prerequisite service plans.
 
 
 
 
 
### Governance products and prerequisites
 
The Microsoft Entra ID Governance capabilities are currently available in six standalone products. These six products provide the same identity governance capabilities. The difference between the six products is that they have different prerequisites.
 
- A subscription to **Microsoft Entra ID Governance** or **MIcrosoft Entra ID Governance for Government**, listed in the product terms as the **Microsoft Entra ID Governance (User SL)** product, requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM` or `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID P1**, **Microsoft 365 E3/E5/A3/A5/G3/G5** or **Enterprise Mobility + Security E3/E5**.
- A subscription to **Microsoft Entra ID Governance Step Up for Microsoft Entra ID P2** or **Microsoft Entra ID Governance Add-on for Microsoft Entra ID P2 for Government**, listed in the product terms as the **Microsoft Entra ID Governance P2** product, requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID P2**, **Microsoft 365 E5/A5/G5**, **Enterprise Mobility + Security E5**, **Microsoft 365 E5/F5 Security** or **Microsoft 365 F5 Security + Compliance**.
- A subscription to the **Entra ID Governance Frontline Worker (User SL)** product requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM` or `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID P1**, **Microsoft 365 E3/E5/A3/A5/G3/G5**, **Enterprise Mobility + Security E3/E5** or **Microsoft 365 F1/F3**.
- A subscription to **Microsoft Entra ID Governance Step up for Microsoft Entra ID F2**, listed in the product terms as the **Microsoft Entra ID Governance F2** or **Microsoft Entra ID Governance Step-Up for Microsoft Entra ID F2 for Frontline Worker (User SL)** product, requires that the tenant also have an active subscription to another product, one that contains the `AAD_PREMIUM_P2` service plan. Examples of products meeting this prerequisite include **Microsoft Entra ID F2**.
 
Microsoft Entra ID Governance capabilities are also included in the Microsoft Entra Suite. The available Microsoft Entra Suite products include **Microsoft Entra Suite (User SL)**, **Microsoft Entra Suite Add-on for Microsoft Entra ID F2 for FLW (User SL)**, **Microsoft Entra Suite Add-on for Microsoft Entra ID P2 (User SL)**, **Microsoft Entra Suite Add-on for Microsoft Entra ID P2 EDU (User SL)**, **Microsoft Entra Suite FLW (User SL)**, and **Microsoft Entra Suite for EDU (User SL)**.
 
The [product names and service plan identifiers for licensing](../identity/users/licensing-service-plan-reference.md) lists additional products that include the prerequisite service plans.
 
+6 / -4 lines changed
Commit: moved image
Changes:
Before
After
 
:::image type="content" source="media/concept-private-name-resolution/image1.png" alt-text="Screenshot of a network diagram showing the high-level Private DNS flow for Windows clients.":::
 
When a DNS suffix is configured in Quick Access, all DNS queries for fully qualified domain names (FQDN) ending with the matching suffixes are resolved via Private DNS, including those used to define Enterprise Apps.
 
:::image type="content" source="media/concept-private-name-resolution/image2.png" alt-text="Screenshot of a diagram showing DNS queries resolved via Private DNS when a DNS suffix is configured in Quick Access.":::
 
## Single Label Domain (SLD) resolution
 
> [!NOTE]
> For some applications such as Kerberos authentication, it is important to have the correct SPN. GSA synthetic suffix may break Kerberos flow, so it is recommended to use FQDN for applications that require Kerberos authentication.
 
To learn how to enable Private DNS with Quick Access, see [How to configure Quick Access](/entra/global-secure-access/how-to-configure-quick-access).
 
To learn how Private DNS works with SSO, see [Use Kerberos for single sign-on (SSO) to your resources with Microsoft Entra Private Access](/entra/global-secure-access/use-kerberos-for-single-sign-on-sso-with-microsoft-entra-private-access).
 
To learn tips on DNS troubleshooting, [Troubleshoot application access - Global Secure Access](/entra/global-secure-access/troubleshoot-app-access#how-does-dns-work-with-global-secure-access).
 
To learn hostname acquisition advanced diagnostics, [Troubleshoot the Global Secure Access client: diagnostics - Global Secure Access](/entra/global-secure-access/troubleshoot-global-secure-access-client-advanced-diagnostics#hostname-acquisition-tab).
 
 
:::image type="content" source="media/concept-private-name-resolution/image1.png" alt-text="Screenshot of a network diagram showing the high-level Private DNS flow for Windows clients.":::
 
:::image type="content" source="media/concept-private-name-resolution/image2.png" alt-text="Screenshot of a diagram showing DNS queries resolved via Private DNS when a DNS suffix is configured in Quick Access.":::
 
When a DNS suffix is configured in Quick Access, all DNS queries for fully qualified domain names (FQDN) ending with the matching suffixes are resolved via Private DNS, including those used to define Enterprise Apps.
 
 
## Single Label Domain (SLD) resolution
 
> [!NOTE]
> For some applications such as Kerberos authentication, it is important to have the correct SPN. GSA synthetic suffix may break Kerberos flow, so it is recommended to use FQDN for applications that require Kerberos authentication.
 
 
To learn how to enable Private DNS with Quick Access, see [How to configure Quick Access](/entra/global-secure-access/how-to-configure-quick-access).
 
To learn how Private DNS works with SSO, see [Use Kerberos for single sign-on (SSO) to your resources with Microsoft Entra Private Access](/entra/global-secure-access/how-to-configure-kerberos-sso).
 
To learn tips on DNS troubleshooting, see [Troubleshoot application access - Global Secure Access](/entra/global-secure-access/troubleshoot-app-access#how-does-dns-work-with-global-secure-access).
 
+5 / -1 lines changed
Commit: blurb-faqs
Changes:
Before
After
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 09/01/2024
ms.author: sarahlipsey
ms.reviewer: egreenberg14
 
 
The `RemoteNetworkHealthLogs` provide insights into the health of your remote network configured through Global Secure Access. Selecting this option doesn't add new logs to your workspace unless your organization is using Microsoft Entra Internet Access and Microsoft Entra Private Access to secure access to your corporate resources. For more information, see [Remote network health logs](../../global-secure-access/how-to-remote-network-health-logs.md).
 
### Custom security attribute audit logs
 
The `CustomSecurityAttributeAuditLogs` are configured in the **Custom security attributes** section of diagnostic settings. These logs capture changes to custom security attributes in your Microsoft Entra tenant. To view these logs in the Microsoft Entra audit logs, you need the [Attribute Log Reader](../../identity/role-based-access-control/permissions-reference.md#attribute-log-reader) role. To route these logs to an endpoint, you need the [Attribute Log Administrator](../../identity/role-based-access-control/permissions-reference.md#attribute-log-administrator) role and the [Security Administrator](../../identity/role-based-access-control/permissions-reference.md#security-administrator).
 
 
 
 
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 04/16/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
 
 
The `RemoteNetworkHealthLogs` provide insights into the health of your remote network configured through Global Secure Access. Selecting this option doesn't add new logs to your workspace unless your organization is using Microsoft Entra Internet Access and Microsoft Entra Private Access to secure access to your corporate resources. For more information, see [Remote network health logs](../../global-secure-access/how-to-remote-network-health-logs.md).
 
### Microsoft service principal sign-in logs (preview)
 
The `MicrosoftServicePrincipalSignInLogs` provides visibility into scenarios where Microsoft-owned (first-party) services authenticate to other Microsoft services within a tenant, such as when a user opens a Word document inside Microsoft Teams. These logs were released to provide greater transparency around service-to-service authentication but are not necessary for most customers as they are complex and generate a high volume of data. These applications are monitored by Microsoft security to ensure the security of the applications and follows principles of least privilege. We want to emphasize that this data is not essential for security investigations and we strongly advise against taking actions such as disabling applications based on this data, as doing so could cause misconfigurations and potential adverse effects such as tenant lock-out. This data is offered as an opt-in through diagnostic settings only and is currently in preview. For more information and commonly asked questions, please visit our [FAQ page](reports-faq.yml).
 
### Custom security attribute audit logs
 
The `CustomSecurityAttributeAuditLogs` are configured in the **Custom security attributes** section of diagnostic settings. These logs capture changes to custom security attributes in your Microsoft Entra tenant. To view these logs in the Microsoft Entra audit logs, you need the [Attribute Log Reader](../../identity/role-based-access-control/permissions-reference.md#attribute-log-reader) role. To route these logs to an endpoint, you need the [Attribute Log Administrator](../../identity/role-based-access-control/permissions-reference.md#attribute-log-administrator) role and the [Security Administrator](../../identity/role-based-access-control/permissions-reference.md#security-administrator).
+2 / -2 lines changed
Commit: added Connect tool to description
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: how-to
ms.date: 03/21/2025
 
ms.author: justinha
author: justinha
 
Microsoft Entra ID can issue Kerberos ticket-granting tickets (TGTs) for one or more of your Active Directory domains. With this functionality, users can sign in to Windows with modern credentials, such as FIDO2 security keys, and then access traditional Active Directory-based resources. Kerberos Service Tickets and authorization continue to be controlled by your on-premises Active Directory domain controllers (DCs).
 
A Microsoft Entra Kerberos server object is created in your on-premises Active Directory instance and then securely published to Microsoft Entra ID. The object isn't associated with any physical servers. It's simply a resource that can be used by Microsoft Entra ID to generate Kerberos TGTs for your Active Directory domain.
 
:::image type="Image" source="./media/howto-authentication-passwordless-on-premises/fido2-ticket-granting-ticket-exchange-process.png" alt-text="Diagram showing how to get a TGT from Microsoft Entra ID and Active Directory Domain Services." lightbox="./media/howto-authentication-passwordless-on-premises/fido2-ticket-granting-ticket-exchange-process.png":::
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: how-to
ms.date: 04/16/2025
 
ms.author: justinha
author: justinha
 
Microsoft Entra ID can issue Kerberos ticket-granting tickets (TGTs) for one or more of your Active Directory domains. With this functionality, users can sign in to Windows with modern credentials, such as FIDO2 security keys, and then access traditional Active Directory-based resources. Kerberos Service Tickets and authorization continue to be controlled by your on-premises Active Directory domain controllers (DCs).
 
A Microsoft Entra Kerberos server object is created in your on-premises Active Directory instance and then securely published to Microsoft Entra ID by using Microsoft Entra Connect. The object isn't associated with any physical servers. It's simply a resource that can be used by Microsoft Entra ID to generate Kerberos TGTs for your Active Directory domain.
 
:::image type="Image" source="./media/howto-authentication-passwordless-on-premises/fido2-ticket-granting-ticket-exchange-process.png" alt-text="Diagram showing how to get a TGT from Microsoft Entra ID and Active Directory Domain Services." lightbox="./media/howto-authentication-passwordless-on-premises/fido2-ticket-granting-ticket-exchange-process.png":::
 
Modified by Mohammad Zmaili on Apr 17, 2025 6:15 AM
📖 View on learn.microsoft.com
+1 / -2 lines changed
Commit: Update reference-current-known-limitations.md
Changes:
Before
After
 
## Private Access limitations
Known limitations for Private Access include:
- Avoid overlapping app segments between Quick Access and Global Secure Access apps.
- Avoid overlapping app segments between Quick Access and per-app access.
- Tunneling traffic to Private Access destinations by IP address is supported only for IP ranges outside of the end-user device local subnet.
- At this time, Private Access traffic can only be acquired with the Global Secure Access client. Remote networks can't be assigned to the Private access traffic forwarding profile.
 
 
## Private Access limitations
Known limitations for Private Access include:
- Avoid overlapping app segments between Global Secure Access apps.
- Tunneling traffic to Private Access destinations by IP address is supported only for IP ranges outside of the end-user device local subnet.
- At this time, Private Access traffic can only be acquired with the Global Secure Access client. Remote networks can't be assigned to the Private access traffic forwarding profile.
 
 
Modified by ManoharLakkoju-MSFT on Apr 17, 2025 7:42 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/Entra-docs#418583
Changes:
Before
After
 
![In-place upgrade](./media/how-to-upgrade-previous-version/inplaceupgrade.png)
 
If made changes to the out-of-box synchronization rules, then these rules are set back to the default configuration on upgrade. To make sure that your configuration is kept between upgrades, make sure that you make changes as they're described in [Best practices for changing the default configuration](how-to-connect-sync-best-practices-changing-default-configuration.md). If you already changed the default sync rules, please see how to [Fix modified default rules in Microsoft Entra Connect](./how-to-connect-sync-best-practices-changing-default-configuration.md), before starting the upgrade process.
 
During in-place upgrade, there may be changes introduced that require specific synchronization activities (including Full Import step and Full Synchronization step) to be executed after upgrade completes. To defer such activities, refer to section [How to defer full synchronization after upgrade](#how-to-defer-full-synchronization-after-upgrade).
 
 
![In-place upgrade](./media/how-to-upgrade-previous-version/inplaceupgrade.png)
 
If you made changes to the out-of-box synchronization rules, then these rules are set back to the default configuration on upgrade. To make sure that your configuration is kept between upgrades, make sure that you make changes as they're described in [Best practices for changing the default configuration](how-to-connect-sync-best-practices-changing-default-configuration.md). If you already changed the default sync rules, please see how to [Fix modified default rules in Microsoft Entra Connect](./how-to-connect-sync-best-practices-changing-default-configuration.md), before starting the upgrade process.
 
During in-place upgrade, there may be changes introduced that require specific synchronization activities (including Full Import step and Full Synchronization step) to be executed after upgrade completes. To defer such activities, refer to section [How to defer full synchronization after upgrade](#how-to-defer-full-synchronization-after-upgrade).
 
Modified by Mark Wahl on Apr 17, 2025 7:02 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: add entra suite to gov licensing
Changes:
Before
After
 
### Features by license
 
The following table shows what features are available with each license. Not all features are available in all clouds; see [Microsoft Entra feature availability](~/identity/authentication/feature-availability.md) for Azure Government.
 
|Feature|Free|Microsoft Entra ID P1|Microsoft Entra ID P2|Microsoft Entra ID Governance| Microsoft Entra Suite |
|-----|:-----:|:-----:|:-----:|:-----:|:-----:|
 
### Features by license
 
The following table shows what features associated with identity governance are available with each license. For more information on other features, see [Microsoft Entra plans and pricing](https://www.microsoft.com/security/business/microsoft-entra-pricing). Not all features are available in all clouds; see [Microsoft Entra feature availability](~/identity/authentication/feature-availability.md) for Azure Government.
 
|Feature|Free|Microsoft Entra ID P1|Microsoft Entra ID P2|Microsoft Entra ID Governance| Microsoft Entra Suite |
|-----|:-----:|:-----:|:-----:|:-----:|:-----:|
Modified by Mohammad Zmaili on Apr 17, 2025 5:01 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update gsa-deployment-guide-intro.md
Changes:
Before
After
- [Microsoft Global Secure Access Deployment Guide for Microsoft Entra Private Access](gsa-deployment-guide-private-access.md)
- [Simulate remote network connectivity using Azure Virtual Network Gateway - Global Secure Access](../global-secure-access/how-to-simulate-remote-network.md)
- [Simulate remote network connectivity using Azure vWAN - Global Secure Access](../global-secure-access/how-to-create-remote-network-vwan.md)
- [Introduction to Global Secure Access Proof of Concept Guidance](gsa-poc-guidance-intro.md)](gsa-poc-guidance-intro.md)
- [Global Secure Access Proof of Concept Guidance - Configure Microsoft Entra Private Access](gsa-poc-private-access.md)
- [Global Secure Access Proof of Concept Guidance - Configure Microsoft Entra Internet Access](gsa-poc-internet-access.md)
- [Microsoft Global Secure Access Deployment Guide for Microsoft Entra Private Access](gsa-deployment-guide-private-access.md)
- [Simulate remote network connectivity using Azure Virtual Network Gateway - Global Secure Access](../global-secure-access/how-to-simulate-remote-network.md)
- [Simulate remote network connectivity using Azure vWAN - Global Secure Access](../global-secure-access/how-to-create-remote-network-vwan.md)
- [Introduction to Global Secure Access Proof of Concept Guidance](gsa-poc-guidance-intro.md)
- [Global Secure Access Proof of Concept Guidance - Configure Microsoft Entra Private Access](gsa-poc-private-access.md)
- [Global Secure Access Proof of Concept Guidance - Configure Microsoft Entra Internet Access](gsa-poc-internet-access.md)