๐Ÿ“‹ Microsoft Entra Documentation Changes

Changes for April 26th 2025

Period: April 25th 2025, 12:00 AM to April 26th 2025, 12:00 AM

๐Ÿ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on April 26th 2025.

๐Ÿ“Š Summary

67
Total Commits
1
New Files
96
Modified Files
0
Deleted Files
16
Contributors

๐Ÿ†• New Documentation Files

Added by Michele Martin on Apr 25, 2025 6:48 AM
๐Ÿ“– View on learn.microsoft.com
+590 lines added
Commit: add file for migration to v2 of policy API

๐Ÿ“ Modified Documentation Files

+214 / -213 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
The following table includes each FIDO2 security key model listed in MDS version 137 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
Description|AAGUID|Bio|USB|NFC|BLE
ACS FIDO Authenticator|50a45b0c-80e7-f944-bf29-f552bfa2e048|![n]|![y]|![n]|![n]
ACS FIDO Authenticator Card|973446ca-e21c-9a9b-99f5-9b985a67af0f|![n]|![n]|![y]|![n]
Allthenticator Android App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-fa57-1337-f1d0-a117371ca702|![y]|![y]|![n]|![n]
Allthenticator iOS App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-1337-fa57-f1d0-a117e71ca702|![y]|![y]|![n]|![n]
Android Authenticator with SafetyNet Attestation|b93fd961-f2e6-462f-b122-82002247de78|![y]|![n]|![n]|![n]
Arculus FIDO 2.1 Key Card \[P71\]|3f59672f-20aa-4afe-b6f4-7e5e916b6d98|![n]|![y]|![n]|![n]
Arculus FIDO2/U2F Key Card|9d3df6ba-282f-11ed-a261-0242ac120002|![n]|![y]|![n]|![n]
ATKey.Card CTAP2.0|d41f5a69-b817-4144-a13c-9ebd6d9254d6|![y]|![n]|![n]|![n]
ATKey.Card NFC|da1fa263-8b25-42b6-a820-c0036f21ba7f|![y]|![y]|![y]|![n]
ATKey.Pro CTAP2.0|e1a96183-5016-4f24-b55b-e3ae23614cc6|![y]|![n]|![n]|![n]
ATKey.Pro CTAP2.1|e416201b-afeb-41ca-a03d-2281c28322aa|![y]|![y]|![n]|![n]
ATKey.ProS|ba76a271-6eb6-4171-874d-b6428dbe3437|![y]|![y]|![n]|![n]
Atos CardOS FIDO2|1c086528-58d5-f211-823c-356786e36140|![n]|![y]|![y]|![n]
authenton1 - CTAP2.1|b267239b-954f-4041-a01b-ee4f33c145b6|![n]|![y]|![y]|![n]
CardOS FIDO2 Token|8da0e4dc-164b-454e-972e-88f362b23d59|![n]|![y]|![y]|![n]
Chunghwa Telecom FIDO2 Smart Card Authenticator|175cd298-83d2-4a26-b637-313c07a6434e|![n]|![n]|![y]|![n]
 
The following table includes each FIDO2 security key model listed in MDS version 137 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
|Description|AAGUID|Bio|USB|NFC|BLE|
|-----------|------|---|---|---|---|
|ACS FIDO Authenticator|50a45b0c-80e7-f944-bf29-f552bfa2e048|![n]|![y]|![n]|![n]|
|ACS FIDO Authenticator Card|973446ca-e21c-9a9b-99f5-9b985a67af0f|![n]|![n]|![y]|![n]|
|Allthenticator Android App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-fa57-1337-f1d0-a117371ca702|![y]|![y]|![n]|![n]|
|Allthenticator iOS App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-1337-fa57-f1d0-a117e71ca702|![y]|![y]|![n]|![n]|
|Android Authenticator with SafetyNet Attestation|b93fd961-f2e6-462f-b122-82002247de78|![y]|![n]|![n]|![n]|
|Arculus FIDO 2.1 Key Card \[P71\]|3f59672f-20aa-4afe-b6f4-7e5e916b6d98|![n]|![y]|![n]|![n]|
|Arculus FIDO2/U2F Key Card|9d3df6ba-282f-11ed-a261-0242ac120002|![n]|![y]|![n]|![n]|
|ATKey.Card CTAP2.0|d41f5a69-b817-4144-a13c-9ebd6d9254d6|![y]|![n]|![n]|![n]|
|ATKey.Card NFC|da1fa263-8b25-42b6-a820-c0036f21ba7f|![y]|![y]|![y]|![n]|
|ATKey.Pro CTAP2.0|e1a96183-5016-4f24-b55b-e3ae23614cc6|![y]|![n]|![n]|![n]|
|ATKey.Pro CTAP2.1|e416201b-afeb-41ca-a03d-2281c28322aa|![y]|![y]|![n]|![n]|
|ATKey.ProS|ba76a271-6eb6-4171-874d-b6428dbe3437|![y]|![y]|![n]|![n]|
|Atos CardOS FIDO2|1c086528-58d5-f211-823c-356786e36140|![n]|![y]|![y]|![n]|
|authenton1 - CTAP2.1|b267239b-954f-4041-a01b-ee4f33c145b6|![n]|![y]|![y]|![n]|
|CardOS FIDO2 Token|8da0e4dc-164b-454e-972e-88f362b23d59|![n]|![y]|![y]|![n]|
+91 / -84 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
The application registration process creates an application with several properties. These properties are required for our scenario.
 
Property | Description
Object ID | The provider can use the object ID with Microsoft Graph to query the application information. <br>The provider can use the object ID to programmatically retrieve and edit the application information.
Application ID | The provider can use the application ID as the ClientId of their application.
Home page URL | The provider home page URL isn't used for anything, but is required as part of application registration.
Reply URLs | Valid redirect URLs for the provider. One should match the provider host URL that was set for the providerโ€™s tenant. One of the reply URLs registered must match the prefix of the authorization_endpoint that Microsoft Entra ID retrieves through OIDC discovery for the host url.
 
An application for each tenant is also a valid model to support the integration. If you use a single-tenant registration, the tenant admin needs to create an application registration with the properties in the preceding table for a single-tenant application.
 
For the OIDC document with the values for Provider Metadata, see [Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata).
 
 
Metadata value | Value | Comments
Issuer | | This URL should match both the host URL used for discovery and the iss claim in the tokens issued by the providerโ€™s service.
authorization_endpoint | | The endpoint that Microsoft Entra ID communicates with for authorization. This endpoint must be present as one of the reply URLs for the allowed applications.
jwks_uri | | Where Microsoft Entra ID can find the public keys needed to verify the signatures issued by the provider. <br>[!NOTE]<br>The JSON Web Key (JWK) **x5c** parameter must be present to provide X.509 representations of keys provided.
scopes_supported | openid | Other values may also be included but aren't required.
response_types_supported | id_token | Other values may also be included but aren't required.
 
The application registration process creates an application with several properties. These properties are required for our scenario.
 
| Property | Description |
|----------|-------------|
| Object ID | The provider can use the object ID with Microsoft Graph to query the application information. <br>The provider can use the object ID to programmatically retrieve and edit the application information. |
| Application ID | The provider can use the application ID as the ClientId of their application. |
| Home page URL | The provider home page URL isn't used for anything, but is required as part of application registration. |
| Reply URLs | Valid redirect URLs for the provider. One should match the provider host URL that was set for the providerโ€™s tenant. One of the reply URLs registered must match the prefix of the authorization_endpoint that Microsoft Entra ID retrieves through OIDC discovery for the host url. |
 
An application for each tenant is also a valid model to support the integration. If you use a single-tenant registration, the tenant admin needs to create an application registration with the properties in the preceding table for a single-tenant application.
 
For the OIDC document with the values for Provider Metadata, see [Provider Metadata](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata).
 
 
| Metadata value | Value | Comments |
|-----------------------|--------|----------|
| Issuer | | This URL should match both the host URL used for discovery and the iss claim in the tokens issued by the providerโ€™s service. |
| authorization_endpoint | | The endpoint that Microsoft Entra ID communicates with for authorization. This endpoint must be present as one of the reply URLs for the allowed applications. |
| jwks_uri | | Where Microsoft Entra ID can find the public keys needed to verify the signatures issued by the provider. <br>[!NOTE]<br>The JSON Web Key (JWK) **x5c** parameter must be present to provide X.509 representations of keys provided. |
+54 / -55 lines changed
Commit: Update authenticate-application-id.md
Changes:
Before
After
---
 
# Authenticate to Microsoft Entra ID using Application Identity
Entra Connect uses the [Microsoft Entra Connector account](entra/identity/hybrid/connect/reference-connect-accounts-permissions#accounts-used-for-microsoft-entra-connect.md) to authenticate and sync identities from Active Directorty to Entra ID. This account uses username and password to authenticate requests. To enhance the security of the service, we are rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Entra will create a single tenant 3rd party application in Entra ID and use one of the two certificate management options below for the credentials.
 
Microsoft Entra Connect provides 2 options for certificate management:
 
1. [Managed by Microsoft Entra Connect (Recommended)](#managed-by-microsoft-entra-connect-recommended)
2. [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate-byoc)
 
## Managed by Microsoft Entra Connect (Recommended)
Microsoft Entra Connect manages the application and certificate including creation, rotation and deletion of the certificate. The certificate is stored in the Current User store. For optimal protection of the certificateโ€™s private key, it is recommended that the machine employs a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary. When a TPM is available, key service operations are performed within a dedicated hardware environment. In contrast, if a TPM cannot be used, Entra Connect defaults to storing the certificate in the Current User store and marks the private key as non-exportable for additional protection. However, without the hardware isolation provided by a TPM, the private key is secured solely by software safeguards and does not achieve the same level of protection. For more information on TPM, see [Trusted Platform Module Technology Overview](/windows/security/hardware-security/tpm/trusted-platform-module-overview).
 
:::image type="content" source="media/authenticate-application-id/auth-1.png" alt-text="Diagram of authentication with application id." lightbox="media/authenticate-application-id/auth-1.png":::
 
Microsoft recommendeds the Microsoft Entra Connect certificate management option as we manage the keys and automatically rotate the certificate on expiry.
 
## Bring Your Own Certificate (BYOC)
 
Microsoft Entra Connect Sync manages the application identity that will be used by Entra Connect Sync to authenticate to Microsoft Entra ID, and you manage the certificate credential used by the application. Your administrator is responsible for creating the certificate, rotation and deletion of unused/expired certificates. The certificate should be stored in the Current User store. You are responsible for securing the private key of the certificate and ensuring only Microsoft Azure AD Sync service can access the private key for signing.
---
 
# Authenticate to Microsoft Entra ID using Application Identity
Entra Connect creates and uses a [Microsoft Entra Connector account](reference-connect-accounts-permissions#accounts-used-for-microsoft-entra-connect.md) to authenticate and sync identities from Active Directory to Entra ID. This account uses a locally stored password to authenticate with Entra ID. To enhance the security of the Entra Connect and the sync process, the application will now support "Application based Authentication", which uses an Entra ID application based identity and [Oauth 2.0 client credential flow](identity-platform/v2-oauth2-client-creds-grant-flow.md) to authenticate with Entra ID. To enable this, Entra Connect will create a single tenant 3rd party application in customer's Entra ID tenant, register a certificate as the credential for the application, and authorize the application to perform on-premises directory synchronization. Entra Connect will support two ways to manage the certificate used in Application based authentication.
1. [Managed by Microsoft Entra Connect (Recommended)](#managed-by-microsoft-entra-connect-recommended)
2. [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate-byoc)
 
## Managed by Microsoft Entra Connect (Recommended)
Microsoft Entra Connect manages the application and certificate including creation, rotation and deletion of the certificate. The certificate is stored in the Current User store. For optimal protection of the certificateโ€™s private key, it is recommended that the machine employs a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary. When a TPM is available, key service operations are performed within a dedicated hardware environment. In contrast, if a TPM cannot be used, Entra Connect defaults to storing the certificate in the default Microsoft Software Key Storage Provider and marks the private key as non-exportable for additional protection. However, without the hardware isolation provided by a TPM, the private key is secured solely by software safeguards and does not achieve the same level of protection. For more information on TPM, see [Trusted Platform Module Technology Overview](/windows/security/hardware-security/tpm/trusted-platform-module-overview).
 
:::image type="content" source="media/authenticate-application-id/auth-1.png" alt-text="Diagram of authentication with application id." lightbox="media/authenticate-application-id/auth-1.png":::
 
Microsoft recommendeds the Entra Connect certificate management option as we manage the keys and automatically rotate the certificate on expiry. This is the default option in Entra Connect Sync versions equal to or higher than 2.4.252.0. Note that we use the maintenance task to check if the certificate is due for rotation and automatically rotate the certificate, so if the scheduler is suspended or maintenance task is disabled, auto rotation will not happen even though the certificate is managed by Entra Connect sync
 
## Bring Your Own Certificate (BYOC)
 
Microsoft Entra Connect Sync manages the application identity that will be used by Entra Connect Sync to authenticate to Microsoft Entra ID, and you manage the certificate credential used by the application. Your administrator is responsible for creating the certificate, rotation and deletion of unused/expired certificates and keys. The certificate should be stored in the Local Machine store. You are responsible for securing the private key of the certificate and ensuring only Microsoft Azure AD Sync service can access the private key for signing.
> [!NOTE]
> - It is recommended to use a TPM or an HSM to provide a hardware-based security boundary, as opposed to the default. To check the status of your TPM use the [Get-TPM](/powershell/module/trustedplatformmodule/get-tpm?view=windowsserver2025-ps) PowerShell cmdlet. If using Hyper-V VMs, the TPM can be enabled by checking Security &gt; Enable Trusted Platform Module. This can only be done on a generation 2 virtual machines. Generation 1 virtual machines can't be converted to a generation 2 virtual machines. For more information see [Generation 2 virtual machine security settings for Hyper-V](/windows-server/virtualization/hyper-v/learn-more/generation-2-virtual-machine-security-settings-for-hyper-v) and [Enable Trusted launch on existing Azure Gen2 VMs](/azure/virtual-machines/trusted-launch-existing-vm)
 
+41 / -37 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
Users with this role have permissions to manage compliance-related features in the Microsoft Purview compliance portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
 
In | Can do
[Microsoft Purview compliance portal](/microsoft-365/compliance/microsoft-365-compliance-center) | Protect and manage your organization's data across Microsoft 365 services<br>Manage compliance alerts
[Microsoft Purview Compliance Manager](/microsoft-365/compliance/compliance-manager) | Track, assign, and verify your organization's regulatory compliance activities
[Microsoft 365 Defender portal](/microsoft-365/security/defender/microsoft-365-defender-portal) | Manage data governance<br>Perform legal and data investigation<br>Manage Data Subject Request<br><br>This role has the same permissions as the [Compliance Administrator role group](/microsoft-365/security/office-365-security/scc-permissions) in Microsoft 365 Defender portal role-based access control.
[Intune](/mem/intune/fundamentals/role-based-access-control) | View all Intune audit data
[Microsoft Defender for Cloud Apps](/defender-cloud-apps/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br>Can view all the built-in reports under Data Management
 
> [!div class="mx-tableFixed"]
> | Actions | Description |
 
Users with this role have permissions to track data in the Microsoft Purview compliance portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
 
In | Can do
[Microsoft Purview compliance portal](/microsoft-365/compliance/microsoft-365-compliance-center) | Monitor compliance-related policies across Microsoft 365 services<br>Manage compliance alerts
[Microsoft Purview Compliance Manager](/microsoft-365/compliance/compliance-manager) | Track, assign, and verify your organization's regulatory compliance activities
[Microsoft 365 Defender portal](/microsoft-365/security/defender/microsoft-365-defender-portal) | Manage data governance<br>Perform legal and data investigation<br>Manage Data Subject Request<br><br>This role has the same permissions as the [Compliance Data Administrator role group](/microsoft-365/security/office-365-security/scc-permissions) in Microsoft 365 Defender portal role-based access control.
[Intune](/mem/intune/fundamentals/role-based-access-control) | View all Intune audit data
 
Users with this role have permissions to manage compliance-related features in the Microsoft Purview compliance portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
 
| In | Can do |
| ----- | ---------- |
| [Microsoft Purview compliance portal](/microsoft-365/compliance/microsoft-365-compliance-center) | Protect and manage your organization's data across Microsoft 365 services<br>Manage compliance alerts |
| [Microsoft Purview Compliance Manager](/microsoft-365/compliance/compliance-manager) | Track, assign, and verify your organization's regulatory compliance activities |
| [Microsoft 365 Defender portal](/microsoft-365/security/defender/microsoft-365-defender-portal) | Manage data governance<br>Perform legal and data investigation<br>Manage Data Subject Request<br><br>This role has the same permissions as the [Compliance Administrator role group](/microsoft-365/security/office-365-security/scc-permissions) in Microsoft 365 Defender portal role-based access control. |
| [Intune](/mem/intune/fundamentals/role-based-access-control) | View all Intune audit data |
| [Microsoft Defender for Cloud Apps](/defender-cloud-apps/manage-admins) | Has read-only permissions and can manage alerts<br>Can create and modify file policies and allow file governance actions<br>Can view all the built-in reports under Data Management |
 
> [!div class="mx-tableFixed"]
> | Actions | Description |
 
Users with this role have permissions to track data in the Microsoft Purview compliance portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
 
| In | Can do |
| ----- | ---------- |
| [Microsoft Purview compliance portal](/microsoft-365/compliance/microsoft-365-compliance-center) | Monitor compliance-related policies across Microsoft 365 services<br>Manage compliance alerts |
| [Microsoft Purview Compliance Manager](/microsoft-365/compliance/compliance-manager) | Track, assign, and verify your organization's regulatory compliance activities |
Modified by Michele Martin on Apr 25, 2025 8:09 AM
๐Ÿ“– View on learn.microsoft.com
+32 / -28 lines changed
Commit: add file for migration to v2 of policy API
Changes:
Before
After
 
Two options are available for migrating your existing policies to the new schema supported by the Microsoft Graph API:
 
- Method 1: [Migrate in place](#method-1-migrate-in-place). Follow this method if your policy is in a production environment and data needs to be migrated.
- Method 2: [Replace policy with blank new policy](#method-2-replace-the-policy-with-a-new-blank-policy). The simplest method is to replace the old policy by creating a new one using the new API.
 
You need to perform migration only once. After migration, you don't need to modify the JSON directly. The Microsoft Graph API will manage the underlying JSON for you.
 
### Pre-check: Determine if migration is necessary
 
> [!NOTE]
> If youโ€™ve already received a communication instructing you to upgrade manually, this pre-check is most likely failing.
 
Before starting, ensure that migration is necessary by trying to access the new CrossTenantAccessPolicy Microsoft Graph API. If you encounter an error indicating an outdated schema, it means an unsupported policy JSON is in use. To perform this check, you must have an account with one of the following roles: Global Administrator, Security Administrator, or Conditional Access Administrator.
 
1. Using Graph Explorer, sign in to your tenant and ensure youโ€™ve consented to `directory.AccessAsUser.All`.
 
1. Run the following requests:
 
```http
 
Two options are available for migrating your existing policies to the new schema supported by the Microsoft Graph API:
 
- [Method 1: Migrate in place](#method-1-migrate-in-place). Follow this method if your policy is in a production environment and data needs to be migrated.
- [Method 2: Replace the policy with a new blank policy](#method-2-replace-the-policy-with-a-new-blank-policy). The simplest method is to replace the old policy by creating a new one using the new API.
 
You need to perform migration only once. After migration, you don't need to modify the JSON directly because the Microsoft Graph API manages the underlying JSON for you.
 
### Pre-check: Determine if migration is necessary
 
> [!NOTE]
> If youโ€™ve already received a communication instructing you to upgrade manually, this pre-check is most likely failing.
 
First, determine if migration is necessary by trying to access the new CrossTenantAccessPolicy Microsoft Graph API. If you encounter an error indicating an outdated schema, it means an unsupported policy JSON is in use. To perform this check, you must have an account with one of the following roles: Global Administrator, Security Administrator, or Conditional Access Administrator.
 
1. Using Graph Explorer, sign in to your tenant and ensure youโ€™ve consented to `directory.AccessAsUser.All`.
 
1. Run the following requests:
```http
+14 / -14 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
1. Enter the following PowerShell command. Replace the **UserPrincipalName** and **SamAccountName** values with your environment values. For better security, use a dedicated service principal name (SPN) that matches the host header of the application.
```New-ADUser -Name "F5 BIG-IP Delegation Account" UserPrincipalName $HOST_SPN SamAccountName "f5-big-ip" -PasswordNeverExpires $true Enabled $true -AccountPassword (Read-Host -AsSecureString "Account Password") ```
HOST_SPN = host/[email protected]
2. Create a **Service Principal Name (SPN)** for the APM service account to use during delegation to the web application service account:
```Set-AdUser -Identity f5-big-ip -ServicePrincipalNames @Add="host/f5-big-ip.contoso.com"} ```
>[!NOTE]
>It is mandatory to include the host/ part in the format of UserPrincipleName (host/name.domain@domain) or ServicePrincipleName (host/name.domain).
* Confirm your web application is running in the computer context or a dedicated service account.
* For the Computer context, use the following command to query the account object in the Active Directory to see its defined SPNs. Replace <name_of_account> with the account for your environment.
```Get-ADComputer -identity <name_of_account> -properties ServicePrincipalNames | Select-Object -ExpandProperty ServicePrincipalNames ```
For example:
1. Enter the following PowerShell command. Replace the **UserPrincipalName** and **SamAccountName** values with your environment values. For better security, use a dedicated service principal name (SPN) that matches the host header of the application.
```New-ADUser -Name "F5 BIG-IP Delegation Account" UserPrincipalName $HOST_SPN SamAccountName "f5-big-ip" -PasswordNeverExpires $true Enabled $true -AccountPassword (Read-Host -AsSecureString "Account Password")```
HOST_SPN = host/[email protected]
2. Create a **Service Principal Name (SPN)** for the APM service account to use during delegation to the web application service account:
```Set-AdUser -Identity f5-big-ip -ServicePrincipalNames @Add="host/f5-big-ip.contoso.com"}```
>[!NOTE]
>It is mandatory to include the host/ part in the format of UserPrincipleName (host/name.domain@domain) or ServicePrincipleName (host/name.domain).
* Confirm your web application is running in the computer context or a dedicated service account.
* For the Computer context, use the following command to query the account object in the Active Directory to see its defined SPNs. Replace <name_of_account> with the account for your environment.
```Get-ADComputer -identity <name_of_account> -properties ServicePrincipalNames | Select-Object -ExpandProperty ServicePrincipalNames```
For example:
Modified by Arie Heinrich on Apr 25, 2025 8:23 AM
๐Ÿ“– View on learn.microsoft.com
+15 / -13 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
## Compare member and guest default permissions
 
**Area** | **Member user permissions** | **Default guest user permissions** | **Restricted guest user permissions**
Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul>
Groups | <ul><li>Create security groups<li>Create Microsoft 365 groups<li>Enumerate the list of all groups<li>Read all properties of groups<li>Read nonhidden group membership<li>Read hidden Microsoft 365 group membership for joined groups<li>Manage properties, ownership, and membership of groups that the user owns<li>Add guests to owned groups<li>Manage group membership settings<li>Delete owned groups<li>Restore owned Microsoft 365 groups</li></ul> | <ul><li>Read properties of nonhidden groups, including membership and ownership (even nonjoined groups)<li>Read hidden Microsoft 365 group membership for joined groups<li>Search for groups by display name or object ID (if allowed)</li></ul> | <ul><li>Read object ID for joined groups<li>Read membership and ownership of joined groups in some Microsoft 365 apps (if allowed)</li></ul>
Applications | <ul><li>Register (create) new applications<li>Enumerate the list of all applications<li>Read properties of registered and enterprise applications<li>Manage application properties, assignments, and credentials for owned applications<li>Create or delete application passwords for users<li>Delete owned applications<li>Restore owned applications<li>List permissions granted to applications</ul> | <ul><li>Read properties of registered and enterprise applications<li>List permissions granted to applications</ul> | <ul><li>Read properties of registered and enterprise applications</li><li>List permissions granted to applications</li></ul>
Devices</li></ul> | <ul><li>Enumerate the list of all devices<li>Read all properties of devices<li>Manage all properties of owned devices</li></ul> | No permissions | No permissions
Organization | <ul><li>Read all company information<li>Read all domains<li>Read configuration of certificate-based authentication<li>Read all partner contracts</li><li>Read multitenant organization basic details and active tenants</li></ul> | <ul><li>Read company display name<li>Read all domains<li>Read configuration of certificate-based authentication</li></ul> | <ul><li>Read company display name<li>Read all domains</li></ul>
Roles and scopes | <ul><li>Read all administrative roles and memberships<li>Read all properties and membership of administrative units</li></ul> | No permissions | No permissions
Subscriptions | <ul><li>Read all licensing subscriptions<li>Enable service plan memberships</li></ul> | No permissions | No permissions
Policies | <ul><li>Read all properties of policies<li>Manage all properties of owned policies</li></ul> | No permissions | No permissions
Terms of use | Read terms of use a user has accepted. | Read terms of use a user has accepted. | Read terms of use a user has accepted.
 
## Restrict member users' default permissions
 
>[!NOTE]
>The **Guest user access restrictions** setting replaced the **Guest users permissions are limited** setting. For guidance on using this feature, see [Restrict guest access permissions in Microsoft Entra ID](~/identity/users/users-restrict-guest-permissions.md).
 
Permission | Setting explanation
 
## Compare member and guest default permissions
 
| **Area** | **Member user permissions** | **Default guest user permissions** | **Restricted guest user permissions** |
| ------------ | --------- | ---------- | ---------- |
| Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul> |
| Groups | <ul><li>Create security groups<li>Create Microsoft 365 groups<li>Enumerate the list of all groups<li>Read all properties of groups<li>Read nonhidden group membership<li>Read hidden Microsoft 365 group membership for joined groups<li>Manage properties, ownership, and membership of groups that the user owns<li>Add guests to owned groups<li>Manage group membership settings<li>Delete owned groups<li>Restore owned Microsoft 365 groups</li></ul> | <ul><li>Read properties of nonhidden groups, including membership and ownership (even nonjoined groups)<li>Read hidden Microsoft 365 group membership for joined groups<li>Search for groups by display name or object ID (if allowed)</li></ul> | <ul><li>Read object ID for joined groups<li>Read membership and ownership of joined groups in some Microsoft 365 apps (if allowed)</li></ul> |
| Applications | <ul><li>Register (create) new applications<li>Enumerate the list of all applications<li>Read properties of registered and enterprise applications<li>Manage application properties, assignments, and credentials for owned applications<li>Create or delete application passwords for users<li>Delete owned applications<li>Restore owned applications<li>List permissions granted to applications</ul> | <ul><li>Read properties of registered and enterprise applications<li>List permissions granted to applications</ul> | <ul><li>Read properties of registered and enterprise applications</li><li>List permissions granted to applications</li></ul> |
| Devices</li></ul> | <ul><li>Enumerate the list of all devices<li>Read all properties of devices<li>Manage all properties of owned devices</li></ul> | No permissions | No permissions |
| Organization | <ul><li>Read all company information<li>Read all domains<li>Read configuration of certificate-based authentication<li>Read all partner contracts</li><li>Read multitenant organization basic details and active tenants</li></ul> | <ul><li>Read company display name<li>Read all domains<li>Read configuration of certificate-based authentication</li></ul> | <ul><li>Read company display name<li>Read all domains</li></ul> |
| Roles and scopes | <ul><li>Read all administrative roles and memberships<li>Read all properties and membership of administrative units</li></ul> | No permissions | No permissions |
| Subscriptions | <ul><li>Read all licensing subscriptions<li>Enable service plan memberships</li></ul> | No permissions | No permissions |
| Policies | <ul><li>Read all properties of policies<li>Manage all properties of owned policies</li></ul> | No permissions | No permissions |
| Terms of use | Read terms of use a user has accepted. | Read terms of use a user has accepted. | Read terms of use a user has accepted. |
 
## Restrict member users' default permissions
 
>[!NOTE]
>The **Guest user access restrictions** setting replaced the **Guest users permissions are limited** setting. For guidance on using this feature, see [Restrict guest access permissions in Microsoft Entra ID](~/identity/users/users-restrict-guest-permissions.md).
 
+11 / -11 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators and new lines MD 055 - 056
Changes:
Before
After
 
| Parameter | Description | Processing remarks |
|----------|----------------|--------------------|
| Path | The full or relative path to the CSV file. For example: `.\Samples\csv-with-1000-records.csv` | Mandatory: Yes |
|ScimSchemaNamespace | The custom SCIM Schema namespace to use to send all columns in the CSV file as custom SCIM attributes belonging to specific namespace. For example, `urn:ietf:params:scim:schemas:extension:csv:1.0:User` | Mandatory: Only when you want to:</br>- Update the provisioning app schema or </br>When you want to include custom SCIM attributes in the payload. |
| AttributeMapping | Points to a PowerShell Data (.psd1 extension) file that maps columns in the CSV file to SCIM Core User and Enterprise User attributes. </br>See example: [AttributeMapping.psd file for CSV2SCIM script]().</br> For example: ```powershell $AttributeMapping = Import-PowerShellDataFile '.\Samples\AttributeMapping.psd1'`-AttributeMapping $AttributeMapping``` | Mandatory: Yes </br> The only scenario when you don't need to specify this is when using the `UpdateSchema` switch.|
| ValidateAttributeMapping |Use this Switch flag to validate that the AttributeMapping file contains attributes that comply with the SCIM Core and Enterprise user schema. | Mandatory: No</br> Recommend using it to ensure compliance. |
| ServicePrincipalId |The GUID value of your provisioning app's service principal ID that you can retrieve from the **Provisioning App** > **Properties** > **Object ID**| Mandatory: Only when you want to: </br>- Update the provisioning app schema, or</br>- Send the generated bulk request to the API endpoint. |
| UpdateSchema |Use this switch to instruct the script to read the CSV columns and add them as custom SCIM attributes in your provisioning app schema.|
| ClientId |The Client ID of a Microsoft Entra registered app to use for OAuth authentication flow. This app must have valid certificate credentials. | Mandatory: Only when performing certificate-based authentication. |
| ClientCertificate |The Client Authentication Certificate to use during OAuth flow. | Mandatory: Only when performing certificate-based authentication.|
| GetPreviousCycleLogs |To get the provisioning logs of the latest sync cycles. |
| NumberOfCycles | To specify how many sync cycles should be retrieved. This value is 1 by default.|
| RestartService | With this option, the script temporarily pauses the provisioning job before uploading the data, it uploads the data and then starts the job again to ensure immediate processing of the payload. | Use this option only during testing. |
 
### AttributeMapping.psd file
 
 
| Parameter | Description | Processing remarks |
|----------|----------------|--------------------|
| Path | The full or relative path to the CSV file. For example: `.\Samples\csv-with-1000-records.csv` | Mandatory: Yes |
| ScimSchemaNamespace | The custom SCIM Schema namespace to use to send all columns in the CSV file as custom SCIM attributes belonging to specific namespace. For example, `urn:ietf:params:scim:schemas:extension:csv:1.0:User` | Mandatory: Only when you want to:</br>- Update the provisioning app schema or </br>When you want to include custom SCIM attributes in the payload. |
| AttributeMapping | Points to a PowerShell Data (.psd1 extension) file that maps columns in the CSV file to SCIM Core User and Enterprise User attributes. </br>See example: [AttributeMapping.psd file for CSV2SCIM script]().</br> For example: ```powershell $AttributeMapping = Import-PowerShellDataFile '.\Samples\AttributeMapping.psd1'`-AttributeMapping $AttributeMapping``` | Mandatory: Yes </br> The only scenario when you don't need to specify this is when using the `UpdateSchema` switch. |
| ValidateAttributeMapping | Use this Switch flag to validate that the AttributeMapping file contains attributes that comply with the SCIM Core and Enterprise user schema. | Mandatory: No</br> Recommend using it to ensure compliance. |
| ServicePrincipalId | The GUID value of your provisioning app's service principal ID that you can retrieve from the **Provisioning App** > **Properties** > **Object ID** | Mandatory: Only when you want to: </br>- Update the provisioning app schema, or</br>- Send the generated bulk request to the API endpoint. |
| UpdateSchema | Use this switch to instruct the script to read the CSV columns and add them as custom SCIM attributes in your provisioning app schema. | |
| ClientId | The Client ID of a Microsoft Entra registered app to use for OAuth authentication flow. This app must have valid certificate credentials. | Mandatory: Only when performing certificate-based authentication. |
| ClientCertificate | The Client Authentication Certificate to use during OAuth flow. | Mandatory: Only when performing certificate-based authentication. |
| GetPreviousCycleLogs | To get the provisioning logs of the latest sync cycles. | |
| NumberOfCycles | To specify how many sync cycles should be retrieved. This value is 1 by default. | |
| RestartService | With this option, the script temporarily pauses the provisioning job before uploading the data, it uploads the data and then starts the job again to ensure immediate processing of the payload. | Use this option only during testing. |
 
### AttributeMapping.psd file
 
+9 / -11 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators and new lines MD 055 - 056
Changes:
Before
After
|Autosync timer (minutes)|120|
|Secret Token|Enter your secret token here. It should be 12 characters minimum.|
|Extension DLL|For the generic LDAP connector, select **Microsoft.IAM.Connector.GenericLdap.dll**.|
4. On the **Connectivity** page, you'll configure how the ECMA Connector Host communicates with the directory server, and set some of the configuration options. Fill in the boxes with the values specified in the table that follows the image and select **Next**. When you select **Next**, the connector queries the directory server for its configuration.
[![Screenshot that shows the Connectivity page.](~/includes/media/app-provisioning-ldap/create-2.png)](~/includes/media/app-provisioning-ldap/create-2.png#lightbox)</br>
|Property|Description|
|-----|-----|
|Host|The host name where the LDAP server is located. This sample uses `APP3` as the example hostname.|
|Delta Import|The change log DN is the naming context used by the delta change log, for example **cn=changelog**. This value must be specified to be able to do delta import. If you don't need to implement delta import, then this field can be blank.|
|Password Attribute|If the directory server supports a different password attribute or password hashing, you can specify the destination for password changes.|
|Partition Names|In the additional partitions list, it's possible to add additional namespaces not automatically detected. For example, this setting can be used if several servers make up a logical cluster, which should all be imported at the same time. Just as Active Directory can have multiple domains in one forest but all domains share one schema, the same can be simulated by entering the additional namespaces in this box. Each namespace can import from different servers and is further configured on the **Configure Partitions and Hierarchies** page.|
1. On the **Partitions** page, keep the default and select **Next**.
1. On the **Run Profiles** page, ensure the **Export** checkbox and the **Full import** checkbox are both selected. Then select **Next**.
[![Screenshot that shows the Run Profiles page.](~/includes/media/app-provisioning-ldap/create-3.png)](~/includes/media/app-provisioning-ldap/create-3.png#lightbox)</br>
|Property|Description|
|-----|-----|
|Export|Run profile that exports data to the LDAP directory server. This run profile is required.|
|Autosync timer (minutes)|120|
|Secret Token|Enter your secret token here. It should be 12 characters minimum.|
|Extension DLL|For the generic LDAP connector, select **Microsoft.IAM.Connector.GenericLdap.dll**.|
 
4. On the **Connectivity** page, you'll configure how the ECMA Connector Host communicates with the directory server, and set some of the configuration options. Fill in the boxes with the values specified in the table that follows the image and select **Next**. When you select **Next**, the connector queries the directory server for its configuration.
[![Screenshot that shows the Connectivity page.](~/includes/media/app-provisioning-ldap/create-2.png)](~/includes/media/app-provisioning-ldap/create-2.png#lightbox)</br>
 
|Property|Description|
|-----|-----|
|Host|The host name where the LDAP server is located. This sample uses `APP3` as the example hostname.|
|Delta Import|The change log DN is the naming context used by the delta change log, for example **cn=changelog**. This value must be specified to be able to do delta import. If you don't need to implement delta import, then this field can be blank.|
|Password Attribute|If the directory server supports a different password attribute or password hashing, you can specify the destination for password changes.|
|Partition Names|In the additional partitions list, it's possible to add additional namespaces not automatically detected. For example, this setting can be used if several servers make up a logical cluster, which should all be imported at the same time. Just as Active Directory can have multiple domains in one forest but all domains share one schema, the same can be simulated by entering the additional namespaces in this box. Each namespace can import from different servers and is further configured on the **Configure Partitions and Hierarchies** page.|
 
1. On the **Partitions** page, keep the default and select **Next**.
1. On the **Run Profiles** page, ensure the **Export** checkbox and the **Full import** checkbox are both selected. Then select **Next**.
[![Screenshot that shows the Run Profiles page.](~/includes/media/app-provisioning-ldap/create-3.png)](~/includes/media/app-provisioning-ldap/create-3.png#lightbox)</br>
 
|Property|Description|
|-----|-----|
Modified by Ortagus Winfrey on Apr 25, 2025 2:26 AM
๐Ÿ“– View on learn.microsoft.com
+9 / -9 lines changed
Commit: updates
Changes:
Before
After
 
## April 2025
 
### Public Preview - As an end user, I can see suggestions about which access packages to request
 
**Type:** New feature
**Service category:** Entitlement Management
**Product capability:** Entitlement Management
 
Microsoft Entra ID Governance: access package request suggestions โ€“ As communicated earlier, we're excited to introduce a new feature in My Access: a curated list of _suggested_ access packages. This capability will allow users to quickly view the most relevant access packages (based off their peers' access packages and previous requests) without scrolling through a long list. In December you can enable the preview in the Opt-in Preview Features for Identity Governance. From January, this setting will be enabled by default.
 
---
 
### Public Preview - Conditional Access What If API
 
**Type:** New feature
**Service category:** Conditional Access
**Product capability:** Access Control
 
Conditional Access What If evaluation API โ€“ Leverage the What If tool using the Microsoft Graph API to programmatically evaluate the applicability of conditional access policies in your tenant on user and service principal sign-ins.
 
## April 2025
 
### Public Preview - [Opt-out] Microsoft Entra ID Governance: access package request suggestions
 
**Type:** New feature
**Service category:** Entitlement Management
**Product capability:** Entitlement Management
 
As communicated [earlier](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/whats-new-in-microsoft-entra---september-2024/4253153), we're excited to introduce a new feature in My Access: a curated list of *suggested* access packages. This capability will allow users to quickly view the most relevant access packages (based off their peers' access packages and previous requests) without scrolling through a long list. In December you can [enable the preview in the Opt-in Preview Features for Identity Governance](https://entra.microsoft.com/?feature.msaljs=true#view/Microsoft_AAD_ERM/DashboardBlade/~/elmSetting). From January, this setting will be enabled by default.
 
---
 
### Public Preview - CConditional Access What If evaluation API
 
**Type:** New feature
**Service category:** Conditional Access
**Product capability:** Access Control
 
Conditional Access What If evaluation API โ€“ Leverage the What If tool using the Microsoft Graph API to programmatically evaluate the applicability of conditional access policies in your tenant on user, and service principal, sign-ins. For more information, see: [conditionalAccessRoot: evaluate](/graph/api/conditionalaccessroot-evaluate).
+9 / -8 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
- Use PowerShell to format the JSON. This script produces a JSON output in a format that includes tabs and spaces:
 
` $JSONContent = Get-Content -Path "<PATH TO THE PROVISIONING LOGS FILE>" | ConvertFrom-JSON`
 
`$JSONContent | ConvertTo-Json > <PATH TO OUTPUT THE JSON FILE>`
 
 
- [Read the JSON file](/powershell/module/microsoft.powershell.utility/convertfrom-json):
 
` $JSONContent = Get-Content -Path "<PATH TO THE PROVISIONING LOGS FILE>" | ConvertFrom-JSON`
 
Now you can parse the data according to your scenario. Here are a couple of examples:
 
 
- Output all change IDs for events where the action was "create":
 
`foreach ($provitem in $JSONContent) { `
` if ($provItem.action -eq 'Create') {`
` $provitem.changeId `
 
- Use PowerShell to format the JSON. This script produces a JSON output in a format that includes tabs and spaces:
 
`$JSONContent = Get-Content -Path "<PATH TO THE PROVISIONING LOGS FILE>" | ConvertFrom-JSON`
 
`$JSONContent | ConvertTo-Json > <PATH TO OUTPUT THE JSON FILE>`
 
 
- [Read the JSON file](/powershell/module/microsoft.powershell.utility/convertfrom-json):
 
`$JSONContent = Get-Content -Path "<PATH TO THE PROVISIONING LOGS FILE>" | ConvertFrom-JSON`
 
Now you can parse the data according to your scenario. Here are a couple of examples:
 
 
- Output all change IDs for events where the action was "create":
 
```powershell
foreach ($provitem in $JSONContent) {
if ($provItem.action -eq 'Create') {
+7 / -7 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
If you require that each resource has its own identity, or have resources that require a unique set of permissions and want the identity to be deleted as the resource is deleted, then you should use a system-assigned identity.
 
| Scenario| Recommendation|Notes|
|---|---|---|
| Rapid creation of resources (for example, ephemeral computing) with managed identities | User-assigned identity | If you attempt to create multiple managed identities in a short space of time โ€“ for example, deploying multiple virtual machines each with their own system-assigned identity - you may exceed the rate limit for Microsoft Entra object creations, and the request fails with an HTTP 429 error. <br/><br/>If resources are being created or deleted rapidly, you may also exceed the limit on the number of resources in Microsoft Entra ID if using system-assigned identities. While a deleted system-assigned identity is no longer accessible by any resource, it counts towards your limit until fully purged after 30 days.<br/><br/>Deploying the resources associated with a single user-assigned identity require the creation of only one Service Principal in Microsoft Entra ID, avoiding the rate limit. Using a single identity that is created in advance reduces the risk of replication delays that could occur if multiple resources are created each with their own identity.<br/><br/>Read more about the [Azure subscription service limits](/azure/azure-resource-manager/management/azure-subscription-service-limits#managed-identity-limits). |
| Replicated resources/applications | User-assigned identity | Resources that carry out the same task โ€“ for example, duplicated web servers or identical functionality running in an app service and in an application on a virtual machine โ€“ typically require the same permissions. <br/><br/>By using the same user-assigned identity, fewer role assignments are required which reduces the management overhead. The resources don't have to be of the same type.
|Compliance| User-assigned identity | If your organization requires that all identity creation must go through an approval process, using a single user-assigned identity across multiple resources requires fewer approvals than system-assigned Identities, which are created as new resources are created. |
Access required before a resource is deployed |User-assigned identity| Some resources may require access to certain Azure resources as part of their deployment.<br/><br/>In this case, a system-assigned identity may not be created in time so a preexisting user-assigned identity should be used.|
Audit Logging|System-assigned identity|If you need to log which specific resource carried out an action, rather than which identity, use a system-assigned identity.|
Permissions Lifecycle Management|System-assigned identity|If you require that the permissions for a resource be removed along with the resource, use a system-assigned identity.
 
### Using user-assigned identities to reduce administration
 
 
If you require that each resource has its own identity, or have resources that require a unique set of permissions and want the identity to be deleted as the resource is deleted, then you should use a system-assigned identity.
 
| Scenario | Recommendation | Notes |
|---|---|---|
| Rapid creation of resources (for example, ephemeral computing) with managed identities | User-assigned identity | If you attempt to create multiple managed identities in a short space of time โ€“ for example, deploying multiple virtual machines each with their own system-assigned identity - you may exceed the rate limit for Microsoft Entra object creations, and the request fails with an HTTP 429 error. <br/><br/>If resources are being created or deleted rapidly, you may also exceed the limit on the number of resources in Microsoft Entra ID if using system-assigned identities. While a deleted system-assigned identity is no longer accessible by any resource, it counts towards your limit until fully purged after 30 days.<br/><br/>Deploying the resources associated with a single user-assigned identity require the creation of only one Service Principal in Microsoft Entra ID, avoiding the rate limit. Using a single identity that is created in advance reduces the risk of replication delays that could occur if multiple resources are created each with their own identity.<br/><br/>Read more about the [Azure subscription service limits](/azure/azure-resource-manager/management/azure-subscription-service-limits#managed-identity-limits). |
| Replicated resources/applications | User-assigned identity | Resources that carry out the same task โ€“ for example, duplicated web servers or identical functionality running in an app service and in an application on a virtual machine โ€“ typically require the same permissions. <br/><br/>By using the same user-assigned identity, fewer role assignments are required which reduces the management overhead. The resources don't have to be of the same type. |
| Compliance | User-assigned identity | If your organization requires that all identity creation must go through an approval process, using a single user-assigned identity across multiple resources requires fewer approvals than system-assigned Identities, which are created as new resources are created. |
| Access required before a resource is deployed |User-assigned identity | Some resources may require access to certain Azure resources as part of their deployment.<br/><br/>In this case, a system-assigned identity may not be created in time so a preexisting user-assigned identity should be used. |
| Audit Logging|System-assigned identity | If you need to log which specific resource carried out an action, rather than which identity, use a system-assigned identity. |
| Permissions Lifecycle Management | System-assigned identity|If you require that the permissions for a resource be removed along with the resource, use a system-assigned identity. |
 
### Using user-assigned identities to reduce administration
 
Modified by Arie Heinrich on Apr 25, 2025 8:23 AM
๐Ÿ“– View on learn.microsoft.com
+7 / -7 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
The following diagram illustrates the authentication flow when a Microsoft Entra organization shares resources with users from other Microsoft Entra organizations. This diagram shows how cross-tenant access settings work with Conditional Access policies, such as multifactor authentication, to determine if the user can access resources. This flow applies to both B2B collaboration and B2B direct connect, except as noted in step 6.
 
[ ![Diagram showing the cross-tenant authentication process.](media/authentication-conditional-access/cross-tenant-auth.png) ](media/authentication-conditional-access/cross-tenant-auth.png#lightbox)
 
|Step |Description |
|---------|---------|
 
The following diagram illustrates the authentication flow when an external user signs in with an account from a non-Microsoft Entra ID identity provider, such as Google, Facebook, or a federated SAML/WS-Fed identity provider.
 
[ ![Diagram showing the Authentication flow for B2B guest users from an external directory.](media/authentication-conditional-access/authentication-flow-b2b-guests.png) ](media/authentication-conditional-access/authentication-flow-b2b-guests.png#lightbox)
 
| Step | Description |
|--------------|-----------------------|
| **1** | The B2B guest user requests access to a resource. The resource redirects the user to its resource tenant, a trusted IdP.|
| **2** | The resource tenant identifies the user as external and redirects the user to the B2B guest userโ€™s IdP. The user performs primary authentication in the IdP.
| **3** | Authorization policies are evaluated in the B2B guest user's IdP. If the user satisfies these policies, the B2B guest user's IdP issues a token to the user. The user is redirected back to the resource tenant with the token. The resource tenant validates the token and then evaluates the user against its Conditional Access policies. For example, the resource tenant could require the user to perform Microsoft Entra multifactor authentication.
| **4** | Inbound cross-tenant access settings and Conditional Access policies are evaluated. If all policies are satisfied, the resource tenant issues its own token and redirects the user to its resource.
 
### Example 2: Authentication flow and token for one-time passcode user
 
The following diagram illustrates the authentication flow when a Microsoft Entra organization shares resources with users from other Microsoft Entra organizations. This diagram shows how cross-tenant access settings work with Conditional Access policies, such as multifactor authentication, to determine if the user can access resources. This flow applies to both B2B collaboration and B2B direct connect, except as noted in step 6.
 
[![Diagram showing the cross-tenant authentication process.](media/authentication-conditional-access/cross-tenant-auth.png)](media/authentication-conditional-access/cross-tenant-auth.png#lightbox)
 
|Step |Description |
|---------|---------|
 
The following diagram illustrates the authentication flow when an external user signs in with an account from a non-Microsoft Entra ID identity provider, such as Google, Facebook, or a federated SAML/WS-Fed identity provider.
 
[![Diagram showing the Authentication flow for B2B guest users from an external directory.](media/authentication-conditional-access/authentication-flow-b2b-guests.png)](media/authentication-conditional-access/authentication-flow-b2b-guests.png#lightbox)
 
| Step | Description |
|--------------|-----------------------|
| **1** | The B2B guest user requests access to a resource. The resource redirects the user to its resource tenant, a trusted IdP.|
| **2** | The resource tenant identifies the user as external and redirects the user to the B2B guest userโ€™s IdP. The user performs primary authentication in the IdP. |
| **3** | Authorization policies are evaluated in the B2B guest user's IdP. If the user satisfies these policies, the B2B guest user's IdP issues a token to the user. The user is redirected back to the resource tenant with the token. The resource tenant validates the token and then evaluates the user against its Conditional Access policies. For example, the resource tenant could require the user to perform Microsoft Entra multifactor authentication. |
| **4** | Inbound cross-tenant access settings and Conditional Access policies are evaluated. If all policies are satisfied, the resource tenant issues its own token and redirects the user to its resource. |
 
### Example 2: Authentication flow and token for one-time passcode user
Modified by Arie Heinrich on Apr 25, 2025 8:23 AM
๐Ÿ“– View on learn.microsoft.com
+6 / -6 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
1. In **Cross-tenant access settings**, [add each domain/tenant as an organization under Organizational settings](cross-tenant-access-settings-b2b-collaboration.yml#add-an-organization).
2. To allow all users and groups and allow all applications, for each added organization, [configure outbound access for B2B collaboration](cross-tenant-access-settings-b2b-collaboration.yml#modify-outbound-access-settings).
[ ![Screenshot of the Organizational settings tab under cross-tenant access settings.](media/tenant-restrictions-migration/organizational-settings.png)](media/tenant-restrictions-migration/organizational-settings.png#lightbox)
3. To block all users and groups and all applications for B2B collaboration, [configure the default cross-tenant access outbound settings](cross-tenant-access-settings-b2b-collaboration.yml#configure-default-settings). This action applies only to tenants not added in [step 1](#allow-only-internal-identities-access-to-specific-external-tenants).
[ ![Screenshot of the Default settings tab under cross-tenant access settings.](media/tenant-restrictions-migration/default-settings.png)](media/tenant-restrictions-migration/default-settings.png#lightbox)
4. In **Tenant restrictions** defaults, create the policy ID (if not created) and [configure the policy to block all users, groups, and external applications](tenant-restrictions-v2.md#configure-server-side-tenant-restrictions-v2-cloud-policy). This action applies only to tenants not added in [step 1](#allow-only-internal-identities-access-to-specific-external-tenants).
[ ![Screenshot of the Tenant restrictions defaults.](media/tenant-restrictions-migration/tenant-restrictions-default.png)](media/tenant-restrictions-migration/tenant-restrictions-default.png#lightbox)
### Allow internal and external identities to access specific external tenants
2. For each added organization to enable internal identities, [configure Outbound access for B2B collaboration](cross-tenant-access-settings-b2b-collaboration.yml#modify-outbound-access-settings) to allow all users, groups, and applications.
3. For each added organization to enable external identities, [configure the organization tenant restrictions](tenant-restrictions-v2.md#step-2-configure-tenant-restrictions-v2-for-specific-partners) to allow all users, groups, and applications.
[ ![Screenshot of Outbound access and Tenant restrictions details under Organizational settings.](media/tenant-restrictions-migration/organizational-settings-outbound.png)](media/tenant-restrictions-migration/organizational-settings-outbound.png#lightbox)
1. In **Cross-tenant access settings**, [add each domain/tenant as an organization under Organizational settings](cross-tenant-access-settings-b2b-collaboration.yml#add-an-organization).
2. To allow all users and groups and allow all applications, for each added organization, [configure outbound access for B2B collaboration](cross-tenant-access-settings-b2b-collaboration.yml#modify-outbound-access-settings).
[![Screenshot of the Organizational settings tab under cross-tenant access settings.](media/tenant-restrictions-migration/organizational-settings.png)](media/tenant-restrictions-migration/organizational-settings.png#lightbox)
3. To block all users and groups and all applications for B2B collaboration, [configure the default cross-tenant access outbound settings](cross-tenant-access-settings-b2b-collaboration.yml#configure-default-settings). This action applies only to tenants not added in [step 1](#allow-only-internal-identities-access-to-specific-external-tenants).
[![Screenshot of the Default settings tab under cross-tenant access settings.](media/tenant-restrictions-migration/default-settings.png)](media/tenant-restrictions-migration/default-settings.png#lightbox)
4. In **Tenant restrictions** defaults, create the policy ID (if not created) and [configure the policy to block all users, groups, and external applications](tenant-restrictions-v2.md#configure-server-side-tenant-restrictions-v2-cloud-policy). This action applies only to tenants not added in [step 1](#allow-only-internal-identities-access-to-specific-external-tenants).
[![Screenshot of the Tenant restrictions defaults.](media/tenant-restrictions-migration/tenant-restrictions-default.png)](media/tenant-restrictions-migration/tenant-restrictions-default.png#lightbox)
### Allow internal and external identities to access specific external tenants
2. For each added organization to enable internal identities, [configure Outbound access for B2B collaboration](cross-tenant-access-settings-b2b-collaboration.yml#modify-outbound-access-settings) to allow all users, groups, and applications.
3. For each added organization to enable external identities, [configure the organization tenant restrictions](tenant-restrictions-v2.md#step-2-configure-tenant-restrictions-v2-for-specific-partners) to allow all users, groups, and applications.
[![Screenshot of Outbound access and Tenant restrictions details under Organizational settings.](media/tenant-restrictions-migration/organizational-settings-outbound.png)](media/tenant-restrictions-migration/organizational-settings-outbound.png#lightbox)
Modified by Arie Heinrich on Apr 25, 2025 8:37 AM
๐Ÿ“– View on learn.microsoft.com
+5 / -4 lines changed
Commit: Spelling - Remove spaces MD038 - Add table separators MD 055 - 056
Changes:
Before
After
 
In Domain Services, you can also create a forest *trust* with another domain to allow users to access resources. Depending on your access requirements, you can create the forest trust in different directions.
 
Trust direction | User access
Two-way | Allows users in both the managed domain and the on-premises domain to access resources in either domain.
One-way outgoing | Allows users in the on-premises domain to access resources in the managed domain, but not vice versa.
One-way incoming | Allows users in the managed domain to access resources in the on-premises domain.
 
<a name='azure-ad-ds-skus'></a>
 
 
 
In Domain Services, you can also create a forest *trust* with another domain to allow users to access resources. Depending on your access requirements, you can create the forest trust in different directions.
 
| Trust direction | User access |
|-----------------|-------------|
| Two-way | Allows users in both the managed domain and the on-premises domain to access resources in either domain. |
| One-way outgoing | Allows users in the on-premises domain to access resources in the managed domain, but not vice versa. |
| One-way incoming | Allows users in the managed domain to access resources in the on-premises domain. |
 
<a name='azure-ad-ds-skus'></a>