πŸ“‹ Microsoft Entra Documentation Changes

Changes for April 30th 2025

Period: April 29th 2025, 12:00 AM to April 30th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on April 30th 2025.

πŸ“Š Summary

89
Total Commits
0
New Files
36
Modified Files
0
Deleted Files
29
Contributors

πŸ“ Modified Documentation Files

+51 / -42 lines changed
Commit: updating
Changes:
Before
After
> [!NOTE]
> We use the maintenance task to check if the certificate is due for rotation and automatically rotate the certificate, so if the scheduler is suspended or maintenance task is disabled, auto rotation will not happen even though the certificate is managed by Entra Connect Sync.
 
The Microsoft Entra Connect Sync managed application and credential is automatically set up during initial installation for new installs. You will can confirm that Microsoft Entra Connect is using the application identity by using the PowerShell cmdlet `Get-ADSyncEntraConnectorCredential`
 
:::image type="content" source="media/authenticate-application-id/auth-2.png" alt-text="Screenshot of Get-ADSyncEntraConnectorCredential." lightbox="media/authenticate-application-id/auth-2.png":::
 
For upgrades, you can select the **Configure application based authentication to Microsoft Entra ID (Preview)** box, to upgrade to using the certificate credentials.
 
:::image type="content" source="media/authenticate-application-id/auth-3.png" alt-text="Screenshot of configuring application based authentication." lightbox="media/authenticate-application-id/auth-3.png":::
 
If you did not select the box during upgrade, you will be shown the following recommendaton once installation completes.
 
:::image type="content" source="media/authenticate-application-id/auth-5.png" alt-text="Screenshot of recommendation." lightbox="media/authenticate-application-id/auth-5.png":::
 
If you did not select the box during upgrade, or want to switch to application based authentication you can do this through tasks.
 
In tasks, select **Configure application based authentication to Microsoft Entra ID (Preview)** and then follow the prompts.
 
:::image type="content" source="media/authenticate-application-id/auth-4.png" alt-text="Screenshot of configuring application based authentication under tasks." lightbox="media/authenticate-application-id/auth-4.png":::
> [!NOTE]
> We use the maintenance task to check if the certificate is due for rotation and automatically rotate the certificate, so if the scheduler is suspended or maintenance task is disabled, auto rotation will not happen even though the certificate is managed by Entra Connect Sync.
 
## Bring Your Own Application (BYOA)
 
In this set up, the customer administrator manages the application that will be used by Entra Connect Sync to authenticate to Entra, the application permissions and certificate credential used by the application. The administrator [registers a Microsoft Entra app and creates a service principal.](identity-platform/howto-create-service-principal-portal.md)
## Prerequisites
The following prerequisites are required to implement authentication using application identity.
 
>[!IMPORTANT]
> New Micrsoft Entra Connect Sync Versions will only be available via the Microsoft Entra admin center
>
> Following up on our earlier [What’s New](../../../fundamentals/whats-new#general-availability---download-microsoft-entra-connect-sync-on-the-microsoft-entra-admin-center) communication, new versions of Microsoft Entra Connect Sync are only available on theβ€―[Microsoft Entra Connect blade](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/%7E/GetStarted) within Microsoft Entra Admin Center and will no longer be released to the [Microsoft Download Center](https://www.microsoft.com/en-us/download/details.aspx?id=47594).
 
- [Microsoft Entra Connect](https://www.microsoft.com/download/details.aspx?id=47594) version [2.4.252.0](reference-connect-version-history.md) or greater.
- Microsoft Entra account with at least a [Hybrid Identity Administrator](../../role-based-access-control/permissions-reference.md#hybrid-identity-administrator) role.
- On-premises Active Directory Domain Services environment with Windows Server 2016 operating system or later.
- Customer registers an application with Entra and creates service principal.
- Customer registers the certificate with the application
 
+39 / -27 lines changed
Commit: Apr 28 completed draft
Changes:
Before
After
description: This article tracks the changes in each released version of the Global Secure Access client for Windows.
ms.service: global-secure-access
ms.topic: reference
ms.date: 02/27/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: femila
 
---
# Global Secure Access client for Windows release notes
This article lists the released versions of the Global Secure Access client for Windows along with the changes in each version.
 
## Download the latest version
The current version of the Global Secure Access client is available to download from the Microsoft Entra admin center.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](/azure/active-directory/roles/permissions-reference#global-secure-access-administrator).
1. Browse to **Global Secure Access** > **Connect** > **Client download**.
1. Select **Download Client**.
:::image type="content" source="media/reference-windows-client-release-history/client-download-screen.png" alt-text="Screenshot of the Client download screen with the Download Client button highlighted.":::
 
## Version 2.14.80
description: This article tracks the changes in each released version of the Global Secure Access client for Windows.
ms.service: global-secure-access
ms.topic: reference
ms.date: 04/28/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: femila
 
---
# Global Secure Access client for Windows release notes
This article lists the released versions of the Global Secure Access client for Windows and the changes in each version.
 
## Download the latest version
The current version of the Global Secure Access client is available to download from the Microsoft Entra admin center.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](/azure/active-directory/roles/permissions-reference#global-secure-access-administrator).
1. Browse to **Global Secure Access** > **Connect** > **Client download**.
1. Select **Download Client**.
:::image type="content" source="media/reference-windows-client-release-history/client-download-screen.png" alt-text="Screenshot of the client download screen with the Download Client button highlighted.":::
 
## Version 2.18.62
+24 / -40 lines changed
Commit: [Conditional Access] Location condition platform API clarification
Changes:
Before
After
 
Administrators can create policies that target specific network locations as a signal along with other conditions in their decision making process. They can include or exclude these network locations as part of their policy configuration. These network locations might include public IPv4 or IPv6 network information, countries/regions, unknown areas that don't map to specific countries/regions, or [Global Secure Access' compliant network](../../global-secure-access/how-to-compliant-network.md).
 
:::image type="content" source="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png" alt-text="Diagram showing concept of Conditional Access signals plus decision to enforce organizational policy." lightbox="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png":::
 
> [!NOTE]
> Conditional Access policies are enforced after first-factor authentication is completed. Conditional Access isn't intended to be an organization's frontline of defense for scenarios like denial-of-service (DoS) attacks, but it can use signals from these events to determine access.
 
Organizations might use these locations for common tasks like:
 
- Requiring multifactor authentication for users accessing a service when they're off the corporate network.
- Blocking access from specific countries your organization never operates from.
A user's location is found using their public IP address or the GPS coordinates provided by the Microsoft Authenticator app. Conditional Access policies apply to all locations by default.
 
> [!TIP]
> The **Location** condition moved and was renamed **Network**. At first this condition appears at both the **Assignment** level, and under **Conditions**.
>
> Updates or changes appear in both locations. The functionality remains the same and existing policies using **Location** continue to work without changes.
 
:::image type="content" source="media/concept-assignment-network/network-assignment.png" alt-text="Screenshot showing the network assignment condition in Conditional Access policy." lightbox="media/concept-assignment-network/network-assignment.png":::
 
Administrators can create policies that target specific network locations as a signal along with other conditions in their decision making process. They can include or exclude these network locations as part of their policy configuration. These network locations might include public IPv4 or IPv6 network information, countries/regions, unknown areas that don't map to specific countries/regions, or [Global Secure Access' compliant network](../../global-secure-access/how-to-compliant-network.md).
 
:::image type="content" source="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png" alt-text="Diagram that shows the concept of Conditional Access signals and the decision to enforce organizational policy." lightbox="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png":::
 
> [!NOTE]
> Conditional Access policies are enforced after first-factor authentication completes. Conditional Access isn't intended to be an organization's frontline of defense for scenarios like denial-of-service (DoS) attacks, but it can use signals from these events to determine access.
 
Organizations might use these locations for common tasks such as:
 
- Requiring multifactor authentication for users accessing a service when they're off the corporate network.
- Blocking access from specific countries your organization never operates from.
A user's location is found using their public IP address or the GPS coordinates provided by the Microsoft Authenticator app. Conditional Access policies apply to all locations by default.
 
> [!TIP]
> The **Location** condition moved and was renamed **Network**. Initially, this condition appears at both the **Assignment** level and under **Conditions**.
>
> Updates or changes appear in both locations. The functionality remains the same, and existing policies using **Location** continue to work without changes.
 
:::image type="content" source="media/concept-assignment-network/network-assignment.png" alt-text="Screenshot that shows the network assignment condition in a Conditional Access policy." lightbox="media/concept-assignment-network/network-assignment.png":::
Modified by Mathieu Simon on Apr 29, 2025 5:15 PM
πŸ“– View on learn.microsoft.com
+39 / -8 lines changed
Commit: Add and partially update error code
Changes:
Before
After
| AADSTS50088 | Limit on telecom MFA calls reached. Please try again in a few minutes. |
| AADSTS50089 | Authentication failed due to flow token expired. Expected - auth codes, refresh tokens, and sessions expire over time or are revoked by the user or an admin. The app will request a new login from the user. |
| AADSTS50097 | DeviceAuthenticationRequired - Device authentication is required. |
| AADSTS50099 | PKeyAuthInvalidJwtUnauthorized - The JWT signature is invalid. |
| AADSTS50105 | EntitlementGrantsNotFound - The signed in user isn't assigned to a role for the signed in app. Assign the user to the app. To learn more, see the troubleshooting article for error [AADSTS50105](/troubleshoot/azure/active-directory/error-code-aadsts50105-user-not-assigned-role). |
| AADSTS50107 | InvalidRealmUri - The requested federation realm object doesn't exist. Contact the tenant admin. |
| AADSTS50120 | ThresholdJwtInvalidJwtFormat - Issue with JWT header. Contact the tenant admin. |
| AADSTS50124 | ClaimsTransformationInvalidInputParameter - Claims Transformation contains invalid input parameter. Contact the tenant admin to update the policy. |
| AADSTS501241 | Mandatory Input '{paramName}' missing from transformation ID '{transformId}'. This error is returned while Microsoft Entra ID is trying to build a SAML response to the application. NameID claim or NameIdentifier is mandatory in SAML response and if Microsoft Entra ID failed to get source attribute for NameID claim, it returns this error. As a resolution, ensure that you add claim rules. To add claim rules, sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator), and then browse to **Entra ID** > **Enterprise apps**. Select your application, select **Single Sign-On** and then in **User Attributes & Claims** enter the Unique User Identifier (Name ID). |
| AADSTS50125 | PasswordResetRegistrationRequiredInterrupt - Sign-in was interrupted because of a password reset or password registration entry. |
| AADSTS50126 | InvalidUserNameOrPassword - Error validating credentials due to invalid username or password. The user didn't enter the right credentials. Expect to see some number of these errors in your logs due to users making mistakes. |
| AADSTS50127 | BrokerAppNotInstalled - User needs to install a broker app to gain access to this content. |
| AADSTS50128 | Invalid domain name - No tenant-identifying information found in either the request or implied by any provided credentials. |
| AADSTS50129 | DeviceIsNotWorkplaceJoined - Workplace join is required to register the device. |
| AADSTS50131 | ConditionalAccessFailed - Indicates various Conditional Access errors such as bad Windows device state, request blocked due to suspicious activity, access policy, or security policy decisions. |
| AADSTS50132 | SsoArtifactInvalidOrExpired - The session isn't valid due to password expiration or recent password change. |
| AADSTS50133 | SsoArtifactRevoked - The session isn't valid due to password expiration or recent password change. |
| AADSTS50134 | DeviceFlowAuthorizeWrongDatacenter - Wrong data center. To authorize a request that was initiated by an app in the OAuth 2.0 device flow, the authorizing party must be in the same data center where the original request resides. |
| AADSTS50135 | PasswordChangeCompromisedPassword - Password change is required due to account risk. |
| AADSTS50136 | RedirectMsaSessionToApp - Single MSA session detected. |
| AADSTS50088 | Limit on telecom MFA calls reached. Please try again in a few minutes. |
| AADSTS50089 | Authentication failed due to flow token expired. Expected - auth codes, refresh tokens, and sessions expire over time or are revoked by the user or an admin. The app will request a new login from the user. |
| AADSTS50097 | DeviceAuthenticationRequired - Device authentication is required. |
| AADSTS50098 | JWT body must contain '{field}'. |
| AADSTS50099 | PKeyAuthInvalidJwtUnauthorized - The JWT signature is invalid. |
| AADSTS50100 | There was an error transforming the claims for the token. |
| AADSTS50101 | Unknown claims transformer '{name}' was specified for principal '{principalId}'. |
| AADSTS50102 | Unable to load CustomClaimsTransformer '{type}' was specified for principal '{principalId}'. |
| AADSTS50103 | There was an error transforming the claims for the token: {errorMessage} |
| AADSTS50105 | EntitlementGrantsNotFound - The signed in user isn't assigned to a role for the signed in app. Assign the user to the app. To learn more, see the troubleshooting article for error [AADSTS50105](/troubleshoot/azure/active-directory/error-code-aadsts50105-user-not-assigned-role). |
| AADSTS50107 |The requested federation realm object '{name}' does not exist. Application error - the login request was malformed and could not be matched with an existing authentication endpoint or instance. |
| AADSTS50108 | Claims transformation configuration could not be retrieved. |
| AADSTS50109 | Claim transformation is unknown from configuration. |
| AADSTS50111 | Unknown claim transformation was asked to be applied. |
| AADSTS50117 | Failed to deserialize policy specified in the request's claim parameter. |
| AADSTS50120 | Unknown credential type, issue with the JWT header. Contact the tenant admin. |
| AADSTS50123 | Unknown claims transformation method '{method}' was specified for principal '{principalId}'. |
| AADSTS50124 | Invalid regular expression configured for claims transformation for this application. Contact your tenant admin to fix the claims mapping configuration. See [Customize SAML token claims](~/identity/saml-claims-customization) |
| AADSTS501241 | Mandatory Input '{paramName}' missing from transformation ID '{transformId}'. This error is returned while Microsoft Entra ID is trying to build a SAML response to the application. NameID claim or NameIdentifier is mandatory in SAML response and if Microsoft Entra ID failed to get source attribute for NameID claim, it returns this error. As a resolution, ensure that you add claim rules. To add claim rules, sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator), and then browse to **Entra ID** > **Enterprise apps**. Select your application, select **Single Sign-On** and then in **User Attributes & Claims** enter the Unique User Identifier (Name ID). |
| AADSTS50125 | PasswordResetRegistrationRequiredInterrupt - Sign-in was interrupted because of a password reset or password registration entry. |
+30 / -2 lines changed
Commit: Updates
Changes:
Before
After
Once updated, you can go to the edited policy, and confirm the change by selecting **Approval stage details**:
:::image type="content" source="media/entitlement-management-dynamic-approval/access-package-approval-stage-details.png" alt-text="Screenshot of edited approval stage details.":::
 
## Configure the Azure Logic App and corresponding business logic.
 
With the Azure logic app created, you must edit the logic app so that it can communicate with Microsoft Entra. To edit the logic app, you'd do the following steps:
 
 
1. Sign in to the Azure portal and go to the subscription, resource group, or logic app itself with the [Azure built-in role](/azure/role-based-access-control/built-in-roles) of at least [Logic App Contributor](/azure/role-based-access-control/built-in-roles/integration#logic-app-contributor).
 
1. On the logic app created, go to **Development Tools** > **Logic app designer**.
 
1. On the designer screen, remove everything under the **manual** trigger, and select the **Add an action** button.
:::image type="content" source="media/entitlement-management-dynamic-approval/logic-app-add-action.png" alt-text="Screenshot of adding action in logic app designer.":::
1.
 
## Related content
 
 
 
Once updated, you can go to the edited policy, and confirm the change by selecting **Approval stage details**:
:::image type="content" source="media/entitlement-management-dynamic-approval/access-package-approval-stage-details.png" alt-text="Screenshot of edited approval stage details.":::
 
## Set up identity and role for the logic app
 
With the Azure logic app created, you must edit the logic app so that it can communicate with Microsoft Entra. To edit the logic app, you'd do the following steps:
 
 
1. Sign in to the Azure portal and go to the subscription, resource group, or logic app itself with the [Azure built-in role](/azure/role-based-access-control/built-in-roles) of at least [Logic App Contributor](/azure/role-based-access-control/built-in-roles/integration#logic-app-contributor).
 
1. On the logic app created, go to **Settings** > **Identity**.
 
1. On the Identity page, enable the system assigned managed identity
:::image type="content" source="media/entitlement-management-dynamic-approval/enable-logic-app-identity.png" alt-text="Screenshot of enabling logic app system assigned managed identity.":::
1. Select **Save**.
 
1. Back in the Microsoft Entra admin center go to the catalog in which you created the custom extension and select **Roles and administrators**.
 
1. On the roles and administrators page, select **Add access package assignment manager**, and select the logic app you just created.
:::image type="content" source="media/entitlement-management-dynamic-approval/add-logic-app-role.png" alt-text="Screenshot of adding logic app as access package assignment manager for a catalog.":::
Modified by shlipsey3 on Apr 29, 2025 8:30 AM
πŸ“– View on learn.microsoft.com
+11 / -11 lines changed
Commit: idp-042825-licensing
Changes:
Before
After
manager: femila
ms.service: entra-id
ms.topic: include
ms.date: 01/31/2025
ms.author: barclayn
ms.custom: include file,licensing
---
 
[!INCLUDE [Microsoft Entra ID P2 license](~/includes/entra-p2-license.md)]
 
| Capability | Details | Microsoft Entra ID Free / Microsoft 365 Apps | Microsoft Entra ID P1 | Microsoft Entra ID P2 | Microsoft Entra Suite |
| --- | --- | --- | --- | --- | --- |
| Risk policies | Sign-in and user risk policies (via Conditional Access) | No | No | Yes | Yes |
| Security reports | Overview | No | No | Yes | Yes |
| Security reports | Risky users | Limited Information. Only users with medium and high risk are shown. No details drawer or risk history. | Limited Information. Only users with medium and high risk are shown. No details drawer or risk history. | Full access| Yes |
| Security reports | Risky sign-ins | Limited Information. No risk detail or risk level is shown. | Limited Information. No risk detail or risk level is shown. | Full access | Yes |
| Security reports | Risk detections | No | Limited Information. No details drawer.| Full access | Yes |
| Notifications | Users at risk detected alerts | No | No | Yes | Yes |
| Notifications | Weekly digest | No | No | Yes | Yes |
| MFA registration policy | | No | No | Yes | Yes |
manager: femila
ms.service: entra-id
ms.topic: include
ms.date: 04/28/2025
ms.author: barclayn
ms.custom: include file,licensing
---
 
[!INCLUDE [Microsoft Entra ID P2 license](~/includes/entra-p2-license.md)]
 
| Capability | Details | Microsoft Entra ID Free / Microsoft 365 Apps | Microsoft Entra ID P1 | Microsoft Entra ID P2 / Microsoft Entra Suite |
| --- | --- | --- | --- | --- |
| Risk policies | Sign-in and user risk policies (via Conditional Access) | No | No | Yes |
| Security reports | Overview | No | No | Yes |
| Security reports | Risky users | Limited Information. Only users with medium and high risk are shown. No details drawer or risk history. | Limited Information. Only users with medium and high risk are shown. No details drawer or risk history. | Full access |
| Security reports | Risky sign-ins | Limited Information. No risk detail or risk level is shown. | Limited Information. No risk detail or risk level is shown. | Full access |
| Security reports | Risk detections | No | Limited Information. No details drawer.| Full access |
| Notifications | Users at risk detected alerts | No | No | Yes |
| Notifications | Weekly digest | No | No | Yes |
| MFA registration policy | Require MFA (via Conditional Access) | No | No | Yes |
Modified by csmulligan on Apr 29, 2025 12:15 AM
πŸ“– View on learn.microsoft.com
+9 / -11 lines changed
Commit: Minor updates based on UUF.
Changes:
Before
After
---
title: 'Tutorial - multifactor authentication for B2B'
description: In this tutorial, learn how to require multifactor authentication when you use Microsoft Entra B2B to collaborate with external users and partner organizations.
 
ms.service: entra-external-id
ms.topic: tutorial
ms.date: 04/09/2025
 
ms.author: cmulligan
author: csmulligan
 
1. You can optionally add further details to the user under the **Properties** and **Assignments** tabs.
1. Select **Review + invite** to automatically send the invitation to the guest user. A **Successfully invited user** message appears.
1. After you send the invitation, the user account is automatically added to the directory as a guest.
 
## Test the sign-in experience before MFA setup
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using your test user name and password.
1. You should be able to access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.
---
title: 'Tutorial - multifactor authentication for B2B'
description: In this tutorial, learn how to require multifactor authentication when you use Microsoft Entra B2B to collaborate with external users and partner organizations.
ms.service: entra-external-id
ms.topic: tutorial
ms.date: 04/28/2025
 
ms.author: cmulligan
author: csmulligan
 
1. You can optionally add further details to the user under the **Properties** and **Assignments** tabs.
1. Select **Review + invite** to automatically send the invitation to the guest user. A **Successfully invited user** message appears.
1. After you send the invitation, the user account is added to the directory as a guest.
 
## Test the sign-in experience before MFA setup
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using your test user name and password.
1. Access the Microsoft Entra admin center using only your sign-in credentials. No other authentication is required.
1. Sign out of the Microsoft Entra admin center.
 
+9 / -9 lines changed
Commit: Review stale articles for April
Changes:
Before
After
---
title: Error message appears on app page after you sign in
description: How to resolve issues with Microsoft Entra sign-in when the app returns an error message.
 
author: omondiatieno
ms.subservice: enterprise-apps
 
ms.topic: troubleshooting
ms.date: 09/06/2022
ms.author: jomondi
ms.reviewer: ergreenl
ms.collection: M365-identity-device-management
- [Microsoft Entra authentication and authorization error codes](~/identity-platform/reference-error-codes.md)
- [Troubleshooting consent prompt errors](application-sign-in-unexpected-user-consent-error.md)
 
If the error message doesn't clearly identify what's missing from the response, try the following:
 
- If the app is in the Microsoft Entra gallery, verify that you followed the steps in [How to debug SAML-based single sign-on to applications in Microsoft Entra ID](./debug-saml-sso-issues.md).
- Use a tool like [Fiddler](https://www.telerik.com/fiddler) to capture the SAML request, response, and token.
 
---
title: An app page shows an error message after the user signs in
description: How to resolve issues with Microsoft Entra sign-in when the app returns an error message.
 
author: omondiatieno
ms.subservice: enterprise-apps
 
ms.topic: troubleshooting
ms.date: 04/29/2025
ms.author: jomondi
ms.reviewer: ergreenl
ms.collection: M365-identity-device-management
- [Microsoft Entra authentication and authorization error codes](~/identity-platform/reference-error-codes.md)
- [Troubleshooting consent prompt errors](application-sign-in-unexpected-user-consent-error.md)
 
If the error message doesn't clearly identify what's missing from the response, try the following steps:
 
- If the app is in the Microsoft Entra gallery, verify that you followed the steps in [How to debug SAML-based single sign-on to applications in Microsoft Entra ID](./debug-saml-sso-issues.md).
- Use a tool like [Fiddler](https://www.telerik.com/fiddler) to capture the SAML request, response, and token.
 
Modified by omondiatieno on Apr 29, 2025 6:02 PM
πŸ“– View on learn.microsoft.com
+9 / -9 lines changed
Commit: Review stale articles for April
Changes:
Before
After
---
title: End-user experiences for applications
description: Learn about the customizable ways to deploy applications to end users in your organization with Microsoft Entra ID
 
author: omondiatieno
manager: CelesteDG
ms.subservice: enterprise-apps
 
ms.topic: concept-article
ms.date: 12/08/2022
ms.author: jomondi
ms.reviewer: lenalepa
ms.custom: enterprise-apps
- Direct sign-on to federated apps
- Deep links to federated, password-based, or existing apps
 
Which method(s) you choose to deploy in your organization is your discretion.
 
<a name='azure-ad-my-apps'></a>
 
---
title: End-user experiences for applications
description: Learn about the customizable ways to deploy applications to end users in your organization with Microsoft Entra ID.
 
author: omondiatieno
manager: CelesteDG
ms.subservice: enterprise-apps
 
ms.topic: concept-article
ms.date: 04/29/2025
ms.author: jomondi
ms.reviewer: lenalepa
ms.custom: enterprise-apps
- Direct sign-on to federated apps
- Deep links to federated, password-based, or existing apps
 
Which method you choose to deploy in your organization is your discretion.
 
<a name='azure-ad-my-apps'></a>
 
+15 / -1 lines changed
Commit: updating
Changes:
Before
After
This article helps you keep track of the versions that have released and the changes in those versions.
 
### Breaking Change on Entra Connect Sync
>[!IMPORTANT]
> New Micrsoft Entra Connect Sync Versions will only be available via the Microsoft Entra admin center
>
|[2.4.21.0](#24210)|15 Nov 2025 (12 months after release of 2.4.27.0)|
|[2.4.27.0](#24270)|15 Jan 2026 (12 months after release of 2.4.129.0)|
|[2.4.129.0](#241290)|27 Mar 2026 (12 months after release of 2.4.131.0)|
|[2.4.131.0](#241310)||
 
**All other versions are not supported**
 
To read more about autoupgrade, see [Microsoft Entra Connect: Automatic upgrade](how-to-connect-install-automatic-upgrade.md).
 
 
## 2.4.131.0
 
### Release status
 
This article helps you keep track of the versions that have released and the changes in those versions.
 
### Breaking Change on Entra Connect Sync
 
>[!IMPORTANT]
> New Micrsoft Entra Connect Sync Versions will only be available via the Microsoft Entra admin center
>
|[2.4.21.0](#24210)|15 Nov 2025 (12 months after release of 2.4.27.0)|
|[2.4.27.0](#24270)|15 Jan 2026 (12 months after release of 2.4.129.0)|
|[2.4.129.0](#241290)|27 Mar 2026 (12 months after release of 2.4.131.0)|
|[2.4.131.0](#241310)|30 April 2026|(12 months after release of x.x.xxx.x)
 
**All other versions are not supported**
 
To read more about autoupgrade, see [Microsoft Entra Connect: Automatic upgrade](how-to-connect-install-automatic-upgrade.md).
 
 
## x.x.xxx.x
 
### Release status
+6 / -8 lines changed
Commit: Review stale articles for April
Changes:
Before
After
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: how-to
ms.date: 01/04/2024
ms.author: jomondi
ms.collection: M365-identity-device-management
ms.reviewer: ergreenl
 
In this article, you learn how to enable self-service application access using the Microsoft Entra admin center.
 
Before your users can self-discover applications from the [My Apps portal](./myapps-overview.md), you need to enable **Self-service application access** for the applications. This functionality is available for applications that were added from the Microsoft Entra Gallery, [Microsoft Entra application proxy](/entra/identity/app-proxy), or were added using [user or admin consent](~/identity-platform/application-consent-experience.md).
 
Using this feature, you can:
 
 
- Optionally allow a business approver to set the passwords those users can use to sign in to the application, right from the business approver’s My Apps portal
 
- Optionally automatically assign self-service assigned users to an application role directly.
 
## Prerequisites
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: how-to
ms.date: 04/28/2025
ms.author: jomondi
ms.collection: M365-identity-device-management
ms.reviewer: ergreenl
 
In this article, you learn how to enable self-service application access using the Microsoft Entra admin center.
 
Before your users can self-discover applications from the [My Apps portal](./myapps-overview.md), you need to enable **Self-service application access** for the applications. This functionality is available for applications that were added from the Microsoft Entra Gallery. It's also available for [Microsoft Entra application proxy](/entra/identity/app-proxy), or applications added using [user or admin consent](~/identity-platform/application-consent-experience.md).
 
Using this feature, you can:
 
 
- Optionally allow a business approver to set the passwords those users can use to sign in to the application, right from the business approver’s My Apps portal
 
- Optionally automate the assignment of self-service assigned users to an application role directly.
 
## Prerequisites
Modified by shlipsey3 on Apr 29, 2025 8:30 AM
πŸ“– View on learn.microsoft.com
+6 / -8 lines changed
Commit: idp-042825-licensing
Changes:
Before
After
 
| Role | Can do | Can't do |
| --- | --- | --- |
| [Security Administrator](~/identity/role-based-access-control/permissions-reference.md#security-administrator) | Full access to ID Protection | Reset password for a user |
| [Security Operator](~/identity/role-based-access-control/permissions-reference.md#security-operator) | View all ID Protection reports and Overview <br><br> Dismiss user risk, confirm safe sign-in, confirm compromise | Configure or change policies <br><br> Reset password for a user <br><br> Configure alerts |
| [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader) | View all ID Protection reports and Overview | Configure or change policies <br><br> Reset password for a user <br><br> Configure alerts <br><br> Give feedback on detections |
| [Global Reader](~/identity/role-based-access-control/permissions-reference.md#global-reader) | Read-only access to ID Protection | |
| [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator) | Reset user passwords | |
 
Currently, the Security Operator role can't access the Risky sign-ins report.
 
Conditional Access Administrators can create policies that factor in user or sign-in risk as a condition. Find more information in the article [Conditional Access: Conditions](~/identity/conditional-access/concept-conditional-access-conditions.md#sign-in-risk).
 
## License requirements
 
[!INCLUDE [Active Directory P2 license](~/includes/entra-p2-license.md)]
 
| Capability | Details | Microsoft Entra ID Free / Microsoft 365 Apps | Microsoft Entra ID P1 | Microsoft Entra ID P2 |
| --- | --- | --- | --- | --- |
| Risk policies | Sign-in and user risk policies (via ID Protection or Conditional Access) | No | No | Yes |
 
| Role | Can do | Can't do |
| --- | --- | --- |
| [Global Reader](~/identity/role-based-access-control/permissions-reference.md#global-reader) | Read-only access to ID Protection | |
| [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator) | Reset user passwords | |
| [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader) | View all ID Protection reports and Overview | Configure or change policies <br><br> Reset password for a user <br><br> Configure alerts <br><br> Give feedback on detections |
| [Security Operator](~/identity/role-based-access-control/permissions-reference.md#security-operator) | View all ID Protection reports and Overview <br><br> Dismiss user risk, confirm safe sign-in, confirm compromise | Configure or change policies <br><br> Reset password for a user <br><br> Configure alerts |
| [Security Administrator](~/identity/role-based-access-control/permissions-reference.md#security-administrator) | Full access to ID Protection | Reset password for a user |
 
The [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role can create policies that factor in user or sign-in risk as a condition. Find more information in the article [Conditional Access: Conditions](~/identity/conditional-access/concept-conditional-access-conditions.md#sign-in-risk).
 
## License requirements
 
[!INCLUDE [Active Directory P2 license](~/includes/entra-p2-license.md)]
 
| Capability | Details | Microsoft Entra ID Free / Microsoft 365 Apps | Microsoft Entra ID P1 | Microsoft Entra ID P2 / Microsoft Entra Suite |
| --- | --- | --- | --- | --- |
| Risk policies | Sign-in and user risk policies (via ID Protection or Conditional Access) | No | No | Yes |
| Security reports | Overview | No | No | Yes |
| Security reports | Risk detections | No | Limited Information. No details drawer.| Full access |
Modified by omondiatieno on Apr 29, 2025 6:02 PM
πŸ“– View on learn.microsoft.com
+6 / -6 lines changed
Commit: Review stale articles for April
Changes:
Before
After
ms.subservice: enterprise-apps
 
ms.topic: how-to
ms.date: 04/08/2024
ms.author: jomondi
ms.reviewer: ergreenl
ms.custom: enterprise-apps
#customer intent: As an admin, I want to understand how to view the activity logs of what permissions are being granted and revoked for applications in my directory so that I can review permissions granted to apps and remediate risks due to overprivileged apps.
---
 
# View activity logs for application permissions
 
Microsoft Entra is a platform that allows you to create and manage applications for your organization. You can grant different permissions to your applications, such as accessing data, or performing actions. However, you might want to review the permissions that are granted to your applications from time to time, to ensure that they're appropriate and secure.
 
One way to review permissions granted to your apps is by using activity logs, which record the activities and events that occur in your Microsoft Entra applications. Activity logs help you to monitor the usage and performance of your applications, and to identify any potential issues or risks. By reviewing the activity logs, you can see what permissions your applications have and whether they're complying with your policies and expectations.
 
 
| Scenario | Audit Service | Audit Category | Audit Activity | Audit Actor | Audit log limitations |
| ------------------------------------- | -------------- | --------------------- | ------------------------------------------------- | ------------ | --------------------- |
| Granting app-only access to an app | Core Directory | ApplicationManagement | Add app role assignment to service principal | User context | |
ms.subservice: enterprise-apps
 
ms.topic: how-to
ms.date: 04/28/2025
ms.author: jomondi
ms.reviewer: ergreenl
ms.custom: enterprise-apps
#customer intent: As an admin, I want to understand how to view the activity logs of what permissions are being granted and revoked for applications in my directory so that I can review permissions granted to apps and remediate risks due to overprivileged apps.
---
 
# View activity logs of application permissions
 
Microsoft Entra is a platform that allows you to create and manage applications for your organization. You can grant different permissions to your applications, such as accessing data, or performing actions. It's important to review these permissions periodically to ensure they remain appropriate and secure.
 
One way to review permissions granted to your apps is by using activity logs, which record the activities and events that occur in your Microsoft Entra applications. Activity logs help you to monitor the usage and performance of your applications, and to identify any potential issues or risks. By reviewing the activity logs, you can see what permissions your applications have and whether they're complying with your policies and expectations.
 
 
| Scenario | Audit Service | Audit Category | Audit Activity | Audit Actor | Audit log limitations |
| ------------------------------------- | -------------- | --------------------- | ------------------------------------------------- | ------------ | --------------------- |
| Granting app-only access to an app | Core Directory | ApplicationManagement | Add app role assignment to the service principal | User context | |
+6 / -6 lines changed
Commit: Review stale articles for April
Changes:
Before
After
---
title: 'Understand the stages of migrating application authentication from AD FS to Microsoft Entra ID'
description: This article provides the stages of the migration process and what types of applications to migrate.
 
author: omondiatieno
manager: CelesteDG
ms.subservice: enterprise-apps
ms.topic: concept-article
 
ms.date: 12/19/2023
ms.author: jomondi
ms.reviewer: alamaral
ms.custom: not-enterprise-apps
 
Your applications might use modern or legacy protocols for authentication. When you plan your migration to Microsoft Entra ID, consider migrating the apps that use modern authentication protocols (such as SAML and OpenID Connect) first.
 
These apps can be reconfigured to authenticate with Microsoft Entra ID either via a built-in connector from the Azure App Gallery, or by registering the custom application in Microsoft Entra ID.
 
Apps that use older protocols can be integrated using [Application Proxy](~/identity/app-proxy/overview-what-is-app-proxy.md) or any of our [Secure Hybrid Access (SHA) partners](secure-hybrid-access-integrations.md).
 
---
title: Understand the stages of migrating application authentication from AD FS to Microsoft Entra ID
description: Migrating application authentication from AD FS to Microsoft Entra ID in four stages. Plan your move, test configurations, and secure apps.
 
author: omondiatieno
manager: CelesteDG
ms.subservice: enterprise-apps
ms.topic: concept-article
 
ms.date: 04/29/2025
ms.author: jomondi
ms.reviewer: alamaral
ms.custom: not-enterprise-apps
 
Your applications might use modern or legacy protocols for authentication. When you plan your migration to Microsoft Entra ID, consider migrating the apps that use modern authentication protocols (such as SAML and OpenID Connect) first.
 
These apps can be reconfigured to authenticate with Microsoft Entra ID either via a built-in connector from the Azure App Gallery. They can also be reconfigured by registering the custom application in Microsoft Entra ID.
 
Apps that use older protocols can be integrated using [Application Proxy](~/identity/app-proxy/overview-what-is-app-proxy.md) or any of our [Secure Hybrid Access (SHA) partners](secure-hybrid-access-integrations.md).
 
+7 / -2 lines changed
Commit: updating
Changes:
Before
After
|5. Enable [your configuration](#enable-your-configuration)|Once ready, enable the configuration and users/groups will begin synchronizing|
 
## Scope provisioning to specific groups
You can scope the agent to synchronize all or specific security groups. You can configure groups and organizational units within a configuration.
1. On the **Getting started** configuration screen. Click either **Add scoping filters** next to the **Add scoping filters** icon or on the click **Scoping filters** on the left under **Manage**.
 
:::image type="content" source="media/how-to-configure-entra-to-active-directory/config-2.png" alt-text="Screenshot of the scoping filters sections." lightbox="media/how-to-configure-entra-to-active-directory/config-2.png":::
 
 
 
 
 
|5. Enable [your configuration](#enable-your-configuration)|Once ready, enable the configuration and users/groups will begin synchronizing|
 
## Scope provisioning to specific groups
You can scope the agent to synchronize all or specific security groups.
 
For more information see [Attribute based scope filtering](how-to-attribute-mapping-entra-to-active-directory.md#attribute-scope-filtering) and [Reference for writing expressions for attribute mappings in Microsoft Entra ID](../../app-provisioning/functions-for-customizing-application-data.md) and [Scenario - Using directory extensions with group provisioning to Active Directory](tutorial-directory-extension-group-provisioning.md).
 
 
You can configure groups and organizational units within a configuration.
 
1. On the **Getting started** configuration screen. Click either **Add scoping filters** next to the **Add scoping filters** icon or on the click **Scoping filters** on the left under **Manage**.
 
:::image type="content" source="media/how-to-configure-entra-to-active-directory/config-2.png" alt-text="Screenshot of the scoping filters sections." lightbox="media/how-to-configure-entra-to-active-directory/config-2.png":::