πŸ“‹ Microsoft Entra Documentation Changes

Changes for April 19th 2025

Period: April 18th 2025, 12:00 AM to April 19th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on April 19th 2025.

πŸ“Š Summary

50
Total Commits
0
New Files
24
Modified Files
0
Deleted Files
18
Contributors

πŸ“ Modified Documentation Files

Modified by Shravan Jewargikar on Apr 18, 2025 2:26 AM
πŸ“– View on learn.microsoft.com
+217 / -75 lines changed
Commit: Updated with Tier 4 countries
Changes:
Before
After
 
For SMS verification, the following region codes require an opt-in. This means that if you'd like to use telecom in these regions, you'll have to reach out to support.
 
 
| Region Code | Region Name |
|:----------- |:---------------------------------------------- |
| 222 | Mauritania |
| 998 | Uzbek |
| 63 | Philippines |
| 20 | Egypt |
| 967 | Yemen |
| 84 | Vietnam |
| 62 | Indonesia |
| 234 | Nigeria |
| 972 | Israel |
| 233 | Ghana |
| 92 | Pakistan |
| 966 | Saudi Arabia |
| 971 | United Arab Emriates |
| 94 | Sri Lanka |
 
For SMS verification, the following region codes require an opt-in. This means that if you'd like to use telecom in these regions, you'll have to reach out to support.
 
| Region Code | Region Name |
|------------|------------|
| 7 | Russia |
| 20 | Egypt |
| 53 | Cuba |
| 58 | Venezuela |
| 62 | Indonesia |
| 63 | Philippines |
| 84 | Vietnam |
| 92 | Pakistan |
| 93 | Afghanistan |
| 94 | Sri Lanka |
| 95 | Myanmar |
| 98 | Iran |
| 211 | South Sudan |
| 212 | Morocco |
| 213 | Algeria |
+93 / -94 lines changed
Commit: edit pass: sspr-articles
Changes:
Before
After
---
title: Self-service password reset for Windows devices
description: Learn how to enable Microsoft Entra self-service password reset at the Windows sign-in screen.
 
ms.service: entra-id
ms.subservice: authentication
manager: femila
ms.reviewer: tilarso
---
# Enable Microsoft Entra self-service password reset at the Windows sign-in screen
 
Self-service password reset (SSPR) gives users in Microsoft Entra ID the ability to change or reset their password, with no administrator or help desk involvement. Typically, users open a web browser on another device to access the [SSPR portal](https://aka.ms/sspr). To improve the experience on computers that run Windows 7, 8, 8.1, 10, and 11 you can enable users to reset their password at the Windows sign-in screen.
 
![Example Windows login screens with SSPR link shown](./media/howto-sspr-windows/windows-reset-password.png)
 
> [!IMPORTANT]
> This tutorial shows an administrator how to enable SSPR for Windows devices in an enterprise.
>
> If your IT team hasn't enabled the ability to use SSPR from your Windows device or you have problems during sign-in, reach out to your helpdesk for additional assistance.
 
---
title: Self-Service Password Reset for Windows Devices
description: Learn how to enable Microsoft Entra self-service password reset on the Windows sign-in screen.
 
ms.service: entra-id
ms.subservice: authentication
manager: femila
ms.reviewer: tilarso
---
# Enable Microsoft Entra self-service password reset on the Windows sign-in screen
 
By using self-service password reset (SSPR) in Microsoft Entra ID, users can change or reset their password with no administrator or help desk involvement. Typically, users open a web browser on another device to access the [SSPR portal](https://aka.ms/sspr). To improve the experience on computers that run Windows 7, 8, 8.1, 10, and 11, you can enable users to reset their password on the Windows sign-in screen.
 
![Screenshot that shows examples of Windows sign-in screens with the SSPR link.](./media/howto-sspr-windows/windows-reset-password.png)
 
> [!IMPORTANT]
> This article shows an administrator how to enable SSPR for Windows devices in an enterprise.
>
> If your IT team hasn't enabled the ability to use SSPR from your Windows device or you have problems during sign-in, reach out to your help desk for more assistance.
 
+90 / -18 lines changed
Commit: Cross-cloud synchronization initial draft
Changes:
Before
After
ms.date: 10/09/2024
ms.author: rolyon
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
---
 
# Configure cross-tenant synchronization
 
This article describes the steps to configure cross-tenant synchronization using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](../app-provisioning/user-provisioning.md).
 
:::image type="content" source="./media/common/configure-diagram.png" alt-text="Diagram that shows cross-tenant synchronization between source tenant and target tenant." lightbox="./media/common/configure-diagram.png":::
 
## Learning objectives
 
By the end of this article, you'll be able to:
- Microsoft Entra ID P1 or P2 license. For more information, see [License requirements](cross-tenant-synchronization-overview.md#license-requirements).
- [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) role to configure cross-tenant access settings.
 
## Step 1: Plan your provisioning deployment
 
ms.date: 10/09/2024
ms.author: rolyon
ms.custom: it-pro
zone_pivot_groups: same-cloud-cross-cloud-synchronization
 
#Customer intent: As a dev, devops, or it admin, I want to
---
 
# Configure cross-tenant synchronization
 
::: zone pivot="same-cloud-synchronization"
 
This article describes the steps to configure cross-tenant synchronization using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](../app-provisioning/user-provisioning.md).
 
:::image type="content" source="./media/common/configure-diagram.png" alt-text="Diagram that shows cross-tenant synchronization between source tenant and target tenant." lightbox="./media/common/configure-diagram.png":::
 
::: zone-end
 
::: zone pivot="cross-cloud-synchronization"
 
Modified by ShawnJackson on Apr 18, 2025 9:58 AM
πŸ“– View on learn.microsoft.com
+31 / -36 lines changed
Commit: edit pass: microsoft-entra-dynamic-groups
Changes:
Before
After
---
title: Understanding and Managing Dynamic Group Processing in Microsoft Entra ID
description: Learn how dynamic group management works.
author: barclayn
manager: femila
ms.reviewer: mbhargava
---
 
# Understanding and Managing Dynamic Group Processing in Microsoft Entra ID
 
Dynamic membership groups in Microsoft Entra are a powerful feature that allows administrators to automate group membership management. Changes to membership typically process within a few hours. However, under certain conditions, customers can experience delays in membership updates. Processing can take more than 24 hours. Understanding the underlying causes can help admins optimize their configurations and avoid unnecessary processing bottlenecks.
 
## How Dynamic Group Processing Works
 
Dynamic group processing operates in a sequential manner, meaning changes for a single tenant are evaluated and applied in order rather than all at once. Large volumes of changes, especially those affecting many users or devices, can lead to long processing queues, extending the time required for updates to be complete processing.
 
### Key Factors Affecting Processing Time
 
The three biggest factors influencing processing that can cause membership updates to take longer are:
 
---
title: Understand and Manage Dynamic Group Processing in Microsoft Entra ID
description: Learn how dynamic group management works.
author: barclayn
manager: femila
ms.reviewer: mbhargava
---
 
# Understand and manage dynamic group processing in Microsoft Entra ID
 
Dynamic membership groups in Microsoft Entra ID are a powerful feature that enables administrators to automate the management of group memberships. Changes to memberships are typically processed within a few hours.
 
However, under certain conditions, customers can experience delays in membership updates. Processing can take more than 24 hours. Understanding the underlying causes can help admins optimize their configurations and avoid unnecessary processing bottlenecks.
 
## How dynamic group processing works
 
Dynamic group processing operates in a sequential manner. Changes for a single tenant are evaluated and applied in order, rather than all at once. Large volumes of changes, especially when they affect many users or devices, can lead to long processing queues. The long queues can extend the time required for updates to finish processing.
 
### Key factors that affect processing time
 
+31 / -32 lines changed
Commit: edit pass: sspr-articles
Changes:
Before
After
---
title: Customize self-service password reset
description: Learn how to customize user display and experience options for Microsoft Entra self-service password reset
 
ms.service: entra-id
ms.subservice: authentication
---
# Customize the user experience for Microsoft Entra self-service password reset
 
Self-service password reset (SSPR) gives users in Microsoft Entra ID the ability to change or reset their password, with no administrator or help desk involvement. If a user's account is locked or they forget their password, they can follow prompts to unblock themselves and get back to work. This ability reduces help desk calls and loss of productivity when a user can't sign in to their device or an application.
 
To improve the SSPR experience for users, you can customize the look and feel of the password reset page, email notifications, or sign-in pages. These customization options let you make it clear to the user they're in the right place, and give them confidence they're accessing company resources.
This article shows you how to customize the SSPR e-mail link for users, company branding, and AD FS sign-in page link. Most of these options can be customized by anyone assigned the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role.
 
## Customize the "Contact your administrator" link
 
To help users reach out for assistance with self-service password reset, a "Contact your administrator" link is shown in the password reset portal. If a user selects this link, it does one of two things:
 
* If this contact link is left in the default state, an email is sent to your administrators and asks them to provide assistance in changing the user's password. The following sample e-mail shows this default e-mail message:
---
title: Customize Self-Service Password Reset
description: Learn how to customize user display and experience options for Microsoft Entra self-service password reset.
 
ms.service: entra-id
ms.subservice: authentication
---
# Customize the user experience for Microsoft Entra self-service password reset
 
Self-service password reset (SSPR) gives users in Microsoft Entra ID the ability to change or reset their password, with no administrator or help desk involvement. If a user's account is locked or they forget their password, they can follow prompts to unblock themselves and get back to work. This ability reduces help-desk calls and loss of productivity when a user can't sign in to their device or an application.
 
To improve the SSPR experience for users, you can customize the look and feel of the password reset page, email notifications, or sign-in pages. Customization options help to make it clear to users that they're in the right place and give them confidence that they're accessing company resources.
 
This article shows you how to customize the SSPR e-mail link for users, company branding, and the Active Directory Federation Services (AD FS) sign-in page link. Anyone who is assigned the [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator) role can customize most of these options.
 
## Customize the Contact your administrator link
 
To help users reach out for assistance with SSPR, a **Contact your administrator** link is shown in the password reset portal. If a user selects this link, it does one of two things:
 
* If this contact link is left in the default state, an email is sent to your administrators and asks them to help in changing the user's password. The following sample e-mail shows this default e-mail message:
+25 / -25 lines changed
Commit: edit pass: sspr-articles
Changes:
Before
After
---
title: Prepopulate contact information for self-service password reset
description: Learn how to prepopulate contact information for users of Microsoft Entra self-service password reset (SSPR) so they can use the feature without completing a registration process.
 
ms.service: entra-id
ms.subservice: authentication
---
# Prepopulate user authentication contact information for Microsoft Entra self-service password reset (SSPR)
 
To use Microsoft Entra self-service password reset (SSPR), authentication information for a user must be present. Most organizations have users register their authentication data themselves while collecting information for MFA. Some organizations prefer to bootstrap this process through synchronization of authentication data that already exists in Active Directory Domain Services (AD DS). This synchronized data is made available to Microsoft Entra ID and SSPR without requiring user interaction. When users need to change or reset their password, they can do so even if they haven't previously registered their contact information.
 
You can prepopulate authentication contact information if you meet the following requirements:
 
* You have properly formatted the data in your on-premises directory.
* You have configured [Microsoft Entra Connect](~/identity/hybrid/connect/how-to-connect-install-express.md) for your Microsoft Entra tenant.
 
Phone numbers must be in the format *+CountryCode PhoneNumber*, such as *+1 4251234567*.
 
 
| On-premises Active Directory | Microsoft Entra ID |
---
title: Prepopulate Contact Information for Self-Service Password Reset
description: Learn how to prepopulate contact information for users of Microsoft Entra self-service password reset (SSPR) so that they can use the feature without completing a registration process.
 
ms.service: entra-id
ms.subservice: authentication
---
# Prepopulate user authentication contact information for Microsoft Entra self-service password reset (SSPR)
 
To use Microsoft Entra self-service password reset (SSPR), authentication information for a user must be present. Most organizations have users register their authentication data themselves while collecting information for multifactor authentication. Some organizations prefer to bootstrap this process through synchronization of authentication data that already exists in Active Directory Domain Services. This synchronized data is made available to Microsoft Entra ID and SSPR without requiring user interaction. When users need to change or reset their password, they can do so even if they haven't previously registered their contact information.
 
You can prepopulate authentication contact information if you meet the following requirements:
 
* You formatted the data in your on-premises directory properly.
* You configured [Microsoft Entra Connect](~/identity/hybrid/connect/how-to-connect-install-express.md) for your Microsoft Entra tenant.
 
Phone numbers must be in the format *+CountryCode PhoneNumber*, such as *+1 4251234567*.
 
 
| On-premises Active Directory | Microsoft Entra ID |
Modified by ShawnJackson on Apr 18, 2025 9:58 AM
πŸ“– View on learn.microsoft.com
+23 / -24 lines changed
Commit: edit pass: microsoft-entra-dynamic-groups
Changes:
Before
After
---
title: Create or edit a dynamic membership group and get its processing status
description: How to create or update rules for dynamic membership groups in the Azure portal, and check its processing status.
 
author: barclayn
manager: femila
 
# Create or update a dynamic membership group in Microsoft Entra ID
 
You can use rules to determine dynamic membership groups based on user or device properties In Microsoft Entra ID, part of Microsoft Entra. This article tells how to set up a rule for a dynamic membership groups in the Azure portal.
 
Group membership based on user or device properties is supported for security groups and Microsoft 365 groups. When you apply a rule for a dynamic membership group, user and device attributes are evaluated for matches with the membership rule. When an attribute changes for a user or device, all rules for dynamic membership groups in the organization are processed for changes. Users and devices are added or removed if they meet the conditions for a dynamic membership group. In Microsoft Entra, a single tenant can have a maximum of 15,000 dynamic membership groups.
 
> [!NOTE]
> Security groups can be used for either devices or users, but Microsoft 365 groups can include only users.
 
Using dynamic membership groups requires Microsoft Entra ID P1 license or Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md) for more details.
 
## Rule builder in the Azure portal
 
---
title: Create or Edit a Dynamic Membership Group and Get Its Processing Status
description: Learn how to create or update rules for dynamic membership groups in the Azure portal and check their processing status.
 
author: barclayn
manager: femila
 
# Create or update a dynamic membership group in Microsoft Entra ID
 
You can use rules to determine dynamic membership groups based on user or device properties in Microsoft Entra ID. This article describes how to set up a rule for a dynamic membership groups in the Azure portal.
 
Group membership based on user or device properties is supported for security groups and Microsoft 365 groups. When you apply a rule for a dynamic membership group, user and device attributes are evaluated for matches with the membership rule. When an attribute changes for a user or device, all rules for dynamic membership groups in the organization are processed for changes. Users and devices are added or removed if they meet the conditions for a dynamic membership group. In Microsoft Entra ID, a single tenant can have a maximum of 15,000 dynamic membership groups.
 
> [!NOTE]
> Security groups can be used for either devices or users, but Microsoft 365 groups can include only users.
 
Using dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).
 
## Rule builder in the Azure portal
 
+23 / -10 lines changed
Commit: Incorporating feedback
Changes:
Before
After
 
# Tutorial: Enforce secret and certificate standards using application management policies
 
In this tutorial, you learn how to enforce secret and certificate standards using application management policies in Microsoft Entra ID.
 
Ensuring that applications in your organization are using secure authentication is crucial for protecting sensitive data and maintaining the integrity of your systems. Microsoft Entra ID provides a way to enforce secret and certificate restrictions through application management policies. This feature can help you manage what kinds of secrets and keys can be used and ensure that they're rotated regularly. To learn more about application management policies, see [Microsoft Entra application management policies API overview](/graph/api/resources/applicationauthenticationmethodpolicy).
 
Policies can be applied to all applications in your organization or to specific applications. In this tutorial, you learn:
 
> * Update that policy to enforce restrictions.
> * Confirm that the policy has been applied.
 
## Prerequisites
 
* A user account. If you don't already have one, you can [create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
 
Before you create a new application management policy, you can read your existing policy to see if it meets your needs. The following example shows how to read the default application management policy for your tenant. You can also reuse this API request to confirm the policy has been applied later in this tutorial.
 
### Example
 
 
# Tutorial: Enforce secret and certificate standards using application management policies
 
In this tutorial, you learn how to enforce secret and certificate standards using application management policies in Microsoft Entra ID.
 
Ensuring that applications in your organization are using secure authentication is crucial for protecting sensitive data and maintaining the integrity of your systems. Microsoft Entra ID provides a way to enforce secret and certificate restrictions through application management policies. This feature can help you manage what kinds of secrets and keys can be used and ensure that they're rotated regularly. Application management policies can only be updated using Microsoft Graph PowerShell or Microsoft Graph API. To learn more about this feature, see [Microsoft Entra application management policies API overview](/graph/api/resources/applicationauthenticationmethodpolicy).
 
Policies can be applied to all applications in your organization or to specific applications. In this tutorial, you learn:
 
> * Update that policy to enforce restrictions.
> * Confirm that the policy has been applied.
 
> [!Important]
> Making changes to your application management policy can have a significant impact on your applications and their ability to authenticate. Before making any changes, it's important to understand the implications of those changes and how they might affect your applications. You should test any changes in a non-production environment before applying them to your production environment and make a copy of the current policy settings before you update them.
 
## Prerequisites
 
* A user account. If you don't already have one, you can [create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
 
Before you create a new application management policy, you can read your existing policy to see if it meets your needs. The following example shows how to read the default application management policy for your tenant. You can also reuse this API request to confirm the policy has been applied later in this tutorial.
+8 / -9 lines changed
Commit: Update CertificateUserIds documentation with PowerShell details
Changes:
Before
After
>[!NOTE]
>Active Directory administrators can make changes that impact the certificateUserIds value in Microsoft Entra ID for any synchronized account. Administrators can include accounts with delegated administrative privilege over synchronized user accounts, or administrative rights over the Microsoft Entra Connect servers.
 
## How to get CertificateUserIds values from end user certificate
 
More information at [Microsoft Entra PowerShell Installation](/powershell/entra-powershell/installation?view=entra-powershell&tabs=powershell%2Cv1&pivots=windows#installation) and [Microsoft Graph PowerShell](/powershell/microsoftgraph/installation).
 
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
```
 
1. Connect to the tenant and accept all.
 
```powershell
Connect-MGGraph -Scopes "Directory.Read.All", "User.Read.All" -TenantId <tenantId>
```
 
1. Install Microsoft Entra powershell module (Minimum required version is 1.0.6)
```powershell
Install-Module -Name Microsoft.Entra
}
>[!NOTE]
>Active Directory administrators can make changes that impact the certificateUserIds value in Microsoft Entra ID for any synchronized account. Administrators can include accounts with delegated administrative privilege over synchronized user accounts, or administrative rights over the Microsoft Entra Connect servers.
 
## How to find the correct CertificateUserIds values for a user from the end user certificate using power shell module
 
Certificate UserIds follow a certain pattern for its values as per the UserName binding configurations on the tenant.
The following powershell command helps an admin to retrieve the exact values for Certificate UserIds attribute for a user from a end user certificate.
Admin can also get the current values in Certificate UserIds attribute for an user for a given username binding and
set the value of the Certificate UserIds attribute.
 
More information at [Microsoft Entra PowerShell Installation](/powershell/entra-powershell/installation?view=entra-powershell&tabs=powershell%2Cv1&pivots=windows#installation) and [Microsoft Graph PowerShell](/powershell/microsoftgraph/installation).
 
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
```
 
1. Install Microsoft Entra powershell module (Minimum required version is 1.0.6)
```powershell
Install-Module -Name Microsoft.Entra
}
}
+6 / -2 lines changed
Commit: Update governance-deployment-employee-access.md
Changes:
Before
After
manager: martinco
ms.service: entra-id-governance
ms.topic: concept-article
ms.date: 03/25/2025
ms.author: gasinh
#customer intent: My goal is to understand deployment of Microsoft Entra ID Governance in my test and production environments.
1. Go to [Trigger Azure Logic Apps with custom extensions in entitlement management](/azure/active-directory/governance/entitlement-management-logic-apps-integration).
2. Use the instructions to create and add a custom extension to a catalog.
3. Edit the custom extension.
3. Add custom extensions to an access package.
## Access recertification: Access reviews
 
 
 
 
manager: martinco
ms.service: entra-id-governance
ms.topic: concept-article
ms.date: 04/17/2025
ms.author: gasinh
#customer intent: My goal is to understand deployment of Microsoft Entra ID Governance in my test and production environments.
1. Go to [Trigger Azure Logic Apps with custom extensions in entitlement management](/azure/active-directory/governance/entitlement-management-logic-apps-integration).
2. Use the instructions to create and add a custom extension to a catalog.
3. Edit the custom extension.
3. Add custom extensions to an access package.
See the following video to learn about custom extenstions and access packages in Microsoft Entra ID Governance.
> [!VIDEO 4fdc4503-b3c9-42b7-b36b-375aea3024a9]
## Access recertification: Access reviews
Modified by Michele Martin on Apr 18, 2025 7:55 AM
πŸ“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: freshness pass, fix date
Changes:
Before
After
ms.service: entra-external-id
ms.topic: concept-article
ms.date: 05/15/2024
 
ms.author: mimart
author: msmimart
- **Google**: Google federation allows external users to redeem invitations from you by signing in to your apps with their own Gmail accounts. Google federation can also be used in your self-service sign-up user flows. See how to [add Google as an identity provider](google-federation.md).
> [!IMPORTANT]
>
> - **Starting July 12, 2021**, if Microsoft Entra B2B customers set up new Google integrations for use with self-service sign-up for their custom or line-of-business applications, authentication with Google identities won’t work until authentications are moved to system web-views. [Learn more](google-federation.md#deprecation-of-web-view-sign-in-support).
> - **Starting September 30, 2021**, Google is [deprecating embedded web-view sign-in support](https://developers.googleblog.com/2016/08/modernizing-oauth-interactions-in-native-apps.html). If your apps authenticate users with an embedded web-view and you're using Google federation with [Azure AD B2C](/azure/active-directory-b2c/identity-provider-google) or Microsoft Entra B2B for [external user invitations](google-federation.md) or self-service sign-up, Google Gmail users won't be able to authenticate. [Learn more](google-federation.md#deprecation-of-web-view-sign-in-support).
 
 
- **Facebook**: When building an app, you can configure self-service sign-up and enable Facebook federation so that users can sign up for your app using their own Facebook accounts. Facebook can only be used for self-service sign-up user flows and isn't available as a sign-in option when users are redeeming invitations from you. See how to [add Facebook as an identity provider](facebook-federation.md).
ms.service: entra-external-id
ms.topic: concept-article
ms.date: 04/16/2025
 
ms.author: mimart
author: msmimart
- **Google**: Google federation allows external users to redeem invitations from you by signing in to your apps with their own Gmail accounts. Google federation can also be used in your self-service sign-up user flows. See how to [add Google as an identity provider](google-federation.md).
> [!IMPORTANT]
>
> - **As of July 12, 2021**, if Microsoft Entra B2B customers set up new Google integrations for use with self-service sign-up for their custom or line-of-business applications, authentication with Google identities won’t work until authentications are moved to system web-views. [Learn more](google-federation.md#deprecation-of-web-view-sign-in-support).
> - **On September 30, 2021**, Google [deprecated embedded web-view sign-in support](https://developers.googleblog.com/2016/08/modernizing-oauth-interactions-in-native-apps.html). If your apps authenticate users with an embedded web-view and you're using Google federation with [Azure AD B2C](/azure/active-directory-b2c/identity-provider-google) or Microsoft Entra B2B for [external user invitations](google-federation.md) or self-service sign-up, Google Gmail users won't be able to authenticate. [Learn more](google-federation.md#deprecation-of-web-view-sign-in-support).
 
 
- **Facebook**: When building an app, you can configure self-service sign-up and enable Facebook federation so that users can sign up for your app using their own Facebook accounts. Facebook can only be used for self-service sign-up user flows and isn't available as a sign-in option when users are redeeming invitations from you. See how to [add Facebook as an identity provider](facebook-federation.md).
Modified by Janice Ricketts on Apr 18, 2025 3:02 AM
πŸ“– View on learn.microsoft.com
+5 / -1 lines changed
Commit: Update gsa-deployment-guide-intro.md
Changes:
Before
After
- Secure and monitor Microsoft Traffic for on-site and remote employees.
- Secure and monitor internet traffic for on-site and remote employees.
 
This Deployment Guide helps you to plan and deploy Microsoft Global Secure Access. See [Global Secure Access licensing overview](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview) for licensing information. While most of the services are generally available (GA), some parts of the service are in public preview. ​
 
## Perform a Proof of Concept
 
- Deploy and test Microsoft Entra Private Access: One hour
- Close PoC: 30 minutes
 
## Initiate your Global Secure Access project
 
Project initiation is the first step in any successful project. At the start of project initiation, you decided to implement Microsoft Global Secure Access. Project success depends on you to understand requirements, define success criteria, and ensure appropriate communications. Be sure to manage expectations, outcomes, and responsibilities.
 
## Next steps
 
- Learn how to accelerate your transition to a Zero Trust security model with [Microsoft Entra Suite and Microsoft's unified security operations platform](https://www.microsoft.com/security/blog/2024/07/11/simplified-zero-trust-security-with-the-microsoft-entra-suite-and-unified-security-operations-platform-now-generally-available/)
- [Microsoft Global Secure Access deployment guide for Microsoft Traffic](gsa-deployment-guide-microsoft-traffic.md)
- [Microsoft Global Secure Access Deployment Guide for Microsoft Entra Internet Access](gsa-deployment-guide-internet-access.md)
- [Simulate remote network connectivity using Azure Virtual Network Gateway - Global Secure Access](../global-secure-access/how-to-simulate-remote-network.md)
- Secure and monitor Microsoft Traffic for on-site and remote employees.
- Secure and monitor internet traffic for on-site and remote employees.
 
This Deployment Guide helps you to plan and deploy Microsoft Global Secure Access. See [Global Secure Access licensing overview](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview) for licensing information. While most of the services are generally available (GA), some parts of the service are in public preview. ​See [425 Show: Plan and Implement your Global Secure Access deployment](https://youtu.be/px6dd9ZJ7R0) for a video walk through detailing deployment planning and implementation recommendations.
 
## Perform a Proof of Concept
 
- Deploy and test Microsoft Entra Private Access: One hour
- Close PoC: 30 minutes
 
See [425 Show: Global Secure Access Proof of Concept Deep Dive](https://youtu.be/BKLvA0p_v1g) for a video walk-through detailing proof of concept procedures.
 
## Initiate your Global Secure Access project
 
Project initiation is the first step in any successful project. At the start of project initiation, you decided to implement Microsoft Global Secure Access. Project success depends on you to understand requirements, define success criteria, and ensure appropriate communications. Be sure to manage expectations, outcomes, and responsibilities.
 
## Next steps
 
- [425 Show: Plan and Implement your Global Secure Access deployment](https://youtu.be/px6dd9ZJ7R0).
- Learn how to accelerate your transition to a Zero Trust security model with [Microsoft Entra Suite and Microsoft's unified security operations platform](https://www.microsoft.com/security/blog/2024/07/11/simplified-zero-trust-security-with-the-microsoft-entra-suite-and-unified-security-operations-platform-now-generally-available/)
+3 / -3 lines changed
Commit: fixed metadata
Changes:
Before
After
ms.subservice: authentication
ms.custom: no-azure-ad-ps-ref
ms.topic: how-to
ms.date: 03/12/2025
 
ms.author: justinha
author: calui
manager: femila
ms.reviewer: calui
---
# Sign-in to Microsoft Entra ID with email as an alternate login ID (Preview)
 
ms.subservice: authentication
ms.custom: no-azure-ad-ps-ref
ms.topic: how-to
ms.date: 04/17/2025
 
ms.author: justinha
author: justinha
manager: femila
ms.reviewer: rahulnagraj
---
# Sign-in to Microsoft Entra ID with email as an alternate login ID (Preview)
 
+4 / -2 lines changed
Commit: Update governance-deployment-employee-lifecycle.md
Changes:
Before
After
manager: martinco
ms.service: entra-id-governance
ms.topic: concept-article
ms.date: 03/25/2025
ms.author: gasinh
#customer intent: My goal is to deploy Microsoft Entra ID Governance in my test and production environments.
## Cloud HR to Active Directory
Learn how to [configure API-driven inbound provisioning to on-premises Active Directory (AD)](../identity/app-provisioning/inbound-provisioning-api-configure-app.md).
## Deploy Workday to Active Directory
 
 
manager: martinco
ms.service: entra-id-governance
ms.topic: concept-article
ms.date: 04/17/2025
ms.author: gasinh
#customer intent: My goal is to deploy Microsoft Entra ID Governance in my test and production environments.
## Cloud HR to Active Directory
Use the following video to learn about inbound provisioning for on-premises Active Directory.
> [!VIDEO fa17234c-ecc7-4c87-82e9-6609270e1744]
## Deploy Workday to Active Directory
+2 / -2 lines changed
Commit: Update workload-identity-federation-config-app-trust-managed-identity.md
Changes:
Before
After
---
title: Configure an application to trust a managed identity (preview)
description: Learn how to configure an application to trust a managed identity in Microsoft Entra ID.
author: cilwerner
manager: CelesteDG
#Customer intent: As an application developer, I want to configure my application to trust a managed identity so that I can access Microsoft Entra protected resources without needing to use or manage application secrets or certificates.
---
 
# Configure an application to trust a managed identity (preview)
 
This article describes how to configure a Microsoft Entra application to trust a managed identity. You can then exchange the managed identity token for an access token that can access Microsoft Entra protected resources without needing to use or manage App secrets.
 
---
title: Configure an application to trust a managed identity
description: Learn how to configure an application to trust a managed identity in Microsoft Entra ID.
author: cilwerner
manager: CelesteDG
#Customer intent: As an application developer, I want to configure my application to trust a managed identity so that I can access Microsoft Entra protected resources without needing to use or manage application secrets or certificates.
---
 
# Configure an application to trust a managed identity
 
This article describes how to configure a Microsoft Entra application to trust a managed identity. You can then exchange the managed identity token for an access token that can access Microsoft Entra protected resources without needing to use or manage App secrets.