📋 Microsoft Entra Documentation Changes

Changes for May 3rd 2025

Period: May 2nd 2025, 12:00 AM to May 3rd 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 3rd 2025.

📊 Summary

83
Total Commits
2
New Files
46
Modified Files
1
Deleted Files
21
Contributors

🆕 New Documentation Files

+69 lines added
Commit: Add files via upload
+16 lines added
Commit: Cloud pairs and settings text

📝 Modified Documentation Files

Modified by Gideon Kiratu on May 2, 2025 12:39 AM
📖 View on learn.microsoft.com
+30 / -28 lines changed
Commit: update pexip tutorial
Changes:
Before
After
---
title: Microsoft Entra integration with Pexip Service (MMV legacy app)
description: Learn how to configure single sign-on between Microsoft Entra ID and Pexip Service (MMV legacy app).
 
author: nguhiu
manager: CelesteDG
ms.date: 03/25/2024
ms.author: gideonkiratu
---
# Microsoft Entra integration with Pexip Service (MMV legacy app)
 
In this article, you learn how to integrate Pexip Service (MMV legacy app) with Microsoft Entra ID. When you integrate Pexip Service (MMV legacy app) with Microsoft Entra ID, you can:
 
* Control in Microsoft Entra ID who has access to Pexip Service (MMV legacy app).
* Enable your users to be automatically signed-in to Pexip Service (MMV legacy app) with their Microsoft Entra accounts.
* Manage your accounts in one central location.
 
## Prerequisites
The scenario outlined in this article assumes that you already have the following prerequisites:
[!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)]
---
title: Microsoft Entra integration with Pexip Service
description: Learn how to configure single sign-on between Microsoft Entra ID and Pexip Service.
 
author: nguhiu
manager: CelesteDG
ms.date: 03/25/2024
ms.author: gideonkiratu
---
# Microsoft Entra integration with Pexip Service
 
In this article, you learn how to integrate Pexip Service with Microsoft Entra ID. When you integrate Pexip Service with Microsoft Entra ID, you can:
 
* Control in Microsoft Entra ID who has access to Pexip Service.
* Enable your users to be automatically signed-in to Pexip Service with their Microsoft Entra accounts.
* Manage your accounts in one central location.
 
## Prerequisites
The scenario outlined in this article assumes that you already have the following prerequisites:
[!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)]
Modified by Ed McKillop on May 2, 2025 4:00 AM
📖 View on learn.microsoft.com
+21 / -21 lines changed
Commit: Update locate-integration-partners.md
Changes:
Before
After
|Partner|Description|
|---|---|
|Accenture|Accenture's Microsoft Entra Suite offering is distinguished by its exceptional global delivery capabilities, advanced technical expertise, and proven proficiency. As Microsoft's 19-time Global Systems Integrator Partner of the Year award recipient, Accenture provides state-of-the-art solutions and seamless integration, positioning itself as the foremost partner for all enterprise requirements. |
|[Armis](https://www.armisgroup.com/services/it-services/security-and-identity/identity/)|Armis, leveraging over 20 years of digital transformation expertise, provides global tech solutions as a trusted Microsoft partner. We specialize in security, data and AI, also business applications, delivering innovative solutions that boost efficiency and sustainable growth. By using the comprehensive capabilities of the Microsoft Entra Suite, Armis supports businesses in adopting Zero Trust principles, thereby fortifying their security posture and enabling a resilient, future-ready infrastructure. |
|[Ascent Solutions](https://www.meetascent.com/services/cybersecurity/identity-management)|Ascent Solutions accelerates secure Microsoft Entra adoption by combining deep identity expertise with tailored deployment, governance, and protection services. We optimize Microsoft Entra to enable secure single sign-on (SSO), Microsoft Entra multifactor authentication (MFA), and Microsoft Entra Conditional Access, while aligning identity governance with compliance goals. Ascent empowers organizations to reduce risk, simplify access, and fully enable their Microsoft investment. |
|[Atea](https://www.atea.se/eshop/campaigns/microsoft-entra-suite)|Atea is the largest Microsoft partner in the Nordics and Baltics. We are specialized in providing our customers with professional services around Microsoft Entra. With our license specialists and certified experts, we make sure that our customers will get the full value out of the components in the Microsoft Entra Suite. |
|[Avande](https://www.avanade.com/en/services/microsoft-tech/microsoft-security/advanced-identity)|Avanade's asset-driven approach to the Microsoft Entra Suite harnesses a robust Microsoft Entra ID Governance content library, complete with repeatable lifecycle workflows, and advanced assets for Microsoft Entra Verified ID. It also features accelerated methodologies for Security Service Edge (SSE), streamlining adoption and migration from legacy solutions. This distinctive strategy boosts security, improves operational efficiency, and speeds up transformation. |
|[baseVISION AG](https://www.basevision.ch/our-solutions/identity-management-solutions/)|baseVISION is a leading Microsoft Security Partner focused on secure and modern endpoint management. Our Microsoft Entra ID Governance services enable companies to transform their identity and access management (IAM) processes around the globe, in a more efficient and modern way, and at an enterprise scale. We combine exceptional knowledge with practical experience, thanks to our focused company strategy and partnership with Microsoft. |
|[BDO](https://www.bdo.com/services/bdo-digital/cybersecurity)|As a global cybersecurity advisor and integrator, BDO helps clients manage risk and transform their organization with the Microsoft Entra Suite. Leveraging our industry experience, we help clients grow confidently with transformative security and cloud solutions that implement the right identity strategy and governance, powered by Microsoft. |
|[Campana & Schott](https://www.campana-schott.com/de/en/expertise/strategie/cyber-security-services/identity-access-management)|Campana & Schott is an international management and technology consultancy with more than 600 employees in Europe and the U.S. With our longstanding transformation experience, and our in-depth knowledge of Microsoft technologies, IT strategy and IT organization, we are an ideal partner to support you in your identity and access management (IAM) transformation with the Microsoft Entra Suite. |
|[Condatis](https://condatis.com/technology/microsoft-entra-suite/entra-id-governance/)|Condatis delivers practical identity solutions using the Microsoft Entra Suite for complex global clients. Working closely with Microsoft, Condatis has proven IAM expertise, focused on reducing cyber risk, and optimizing costs. The Microsoft Entra Suite ensures seamless and secure access to empower your workforce, safeguard your digital ecosystem, and deliver measurable business outcomes. |
|[Cyclotron](https://www.cyclotron.com/post/streamline-identity-access-management-with-microsofts-entra-suite)|Cyclotron provides expert migration for SailPoint to the Microsoft Entra Suite, Okta to the Microsoft Entra Suite, and specialized knowledge of other toolset migration. Our proprietary migration tools significantly help accelerate deployment timelines, while our Change Leadership experts ease the burden of change on users and seamlessly engage stakeholders throughout the success strategy. |
|[DXC Technologies](https://dxc.com/content/dam/dxc/projects/dxc-com/us/pdfs/practices/DXC%20Service%20for%20MS%20Entra%20FS.pdf)|DXC Technology, a trusted global partner, is excited to enable the spectrum of controls in the Microsoft Entra Suite to help organizations improve efficiencies and adopt a Zero Trust model, through strategy, planning, preparation, transformation, and operational management of key security domains including identity, network, devices, applications, workloads, and data. |
|[Ernst & Young, LLP](https://www.ey.com/en_us/alliances/simplify-your-cybersecurity-with-the-ey-microsoft-alliance)|EY is a trusted global leader in professional services that creates a better working world with people at the center, using technology at scale and driving innovation at speed. The EY-Microsoft Alliance collaborates on innovative identity management solutions with Microsoft Entra, transforming the way businesses protect and manage identities, creating a future where trust and safety are paramount. |
|[glueckkanja AG](https://www.glueckkanja.com/en/workplace/microsoft-entra-suite/)|glueckkanja is a leading Microsoft partner renowned for its expertise in 100% cloud solutions and identity-centric security. The company has established itself as a pioneer in implementing a fully cloud-managed workplace with consistent and practical applications of Zero Trust strategies. Their services range from proof-of-concepts for the latest Microsoft products, including Microsoft Global Secure Access, and innovative solutions for identity security, for example MyWorkID, to managed services, such as Managed Red Tenant. glueckkanja drives its blueprint approach at the cutting edge of Microsoft technology through close connections with Microsoft product teams as well as the TechCommunity. Several Microsoft MVPs specialize in identity and access work as subject matter experts in the Security organization. |
|[IBM Consulting](https://www.ibm.com/services/security)|IBM's strategic partnership with Microsoft is underpinned by deep technical expertise and a strong, shared commitment to continuous innovation. IBM's powerful AskIAM for Microsoft Entra uses cutting-edge Agentic AI to revolutionize identity governance, seamlessly automating complex workflows, significantly enhancing enterprise-grade security, ensuring robust regulatory compliance, and dramatically improving operational productivity. |
|[Increment](https://appsource.microsoft.com/en-us/marketplace/consulting-services/incrementptyltd1637494276783.inc_offer-microsoft_entra_suite_engagement-01)|Increment's Microsoft Entra Suite engagement showcases the breadth of Microsoft Entra in your environment. We demonstrate how to automate employee lifecycle with Microsoft Entra ID Governance, provide secure internet access with Microsoft Entra Internet Access, unlock true zero-trust with Microsoft Entra Private Access, and create next-generation identity verification experiences with Microsoft Entra Verified ID. |
|[InSpark](https://www.inspark.nl/en/solution/security/entra)|InSpark transforms identity and network access with Microsoft Entra. Specializing in Microsoft Entra ID, Microsoft Entra ID Governance, Microsoft Entra ID Protection, Security Service Edge (SSE), Microsoft Entra Verified ID, and Microsoft Entra External ID, we offer unique project accelerators for rapid deployment. From consultancy to managed services, we ensure seamless and secure innovation. Partner with InSpark and experience the difference.|
|[Invoke](https://www.invokellc.com/identity-access-management)|Invoke excels exclusively at the Microsoft unified security operations platform, following Zero Trust principles. As a Partner of the Year Finalist for Identity and earning all Microsoft Security partner credentials, Invoke integrates identity solutions leveraging best-of-suite workloads. Their expertise in Microsoft Entra ID migrations, Microsoft Entra ID Protection, Microsoft Global Secure Access, and Microsoft Entra ID Governance safeguards comprehensive identity transformation. |
|[Japan Business System, Inc.](https://blog.jbs.co.jp/archive/category/Microsoft%20Entra%20ID)|JBS has extensive integration experience and expertise in Microsoft Entra and Microsoft 365, and provides one-stop services across all phases, from initial planning and validation to implementation, deployment, and operational support. Their strong partnership with Microsoft further strengthens their ability to deliver comprehensive solutions. |
|Partner|Description|
|---|---|
|Accenture|Accenture's Microsoft Entra Suite offering is distinguished by its exceptional global delivery capabilities, advanced technical expertise, and proven proficiency. As Microsoft's 19-time Global Systems Integrator Partner of the Year award recipient, Accenture provides state-of-the-art solutions and seamless integration, positioning itself as the foremost partner for all enterprise requirements. |
|[Armis](https://www.armisgroup.com/services/it-services/security-and-identity/identity/)|Armis, leveraging over 20 years of digital transformation expertise, provides global tech solutions as a trusted Microsoft partner. We specialize in security, data and AI, also business applications, delivering innovative solutions that boost efficiency and sustainable growth. By using the comprehensive capabilities of the Microsoft Entra Suite, Armis supports businesses in adopting Zero Trust principles. This effort fortifies their security posture and enabling a resilient, future-ready infrastructure. |
|[Ascent Solutions](https://www.meetascent.com/services/cybersecurity/identity-management)|Ascent Solutions accelerates secure Microsoft Entra adoption by combining deep identity expertise with tailored deployment, governance, and protection services. We optimize Microsoft Entra to enable secure single sign-on (SSO), Microsoft Entra multifactor authentication (MFA), and Microsoft Entra Conditional Access, while aligning identity governance with compliance goals. Ascent empowers organizations to reduce risk, simplify access, and fully enable their Microsoft investment. |
|[Atea](https://www.atea.se/eshop/campaigns/microsoft-entra-suite)|Atea is the largest Microsoft partner in the Nordic and Baltic regions. We are specialized in providing our customers with professional services around Microsoft Entra. With our license specialists and certified experts, we make sure that our customers get the full value out of the components in the Microsoft Entra Suite. |
|[Avande](https://www.avanade.com/en/services/microsoft-tech/microsoft-security/advanced-identity)|Avanade's asset-driven approach to the Microsoft Entra Suite harnesses a robust Microsoft Entra ID Governance content library, complete with repeatable lifecycle workflows, and advanced assets for Microsoft Entra Verified ID. It also features accelerated methodologies for Security Service Edge (SSE), streamlining adoption and migration from legacy solutions. This distinctive strategy boosts security, improves operational efficiency, and speeds up transformation. |
|[baseVISION AG](https://www.basevision.ch/our-solutions/identity-management-solutions/)|baseVISION is a leading Microsoft Security Partner focused on secure and modern endpoint management. Our Microsoft Entra ID Governance services enable companies to transform their identity and access management (IAM) processes around the globe, in a more efficient and modern way, and at an enterprise scale. We combine exceptional knowledge with practical experience, thanks to our focused company strategy and partnership with Microsoft. |
|[BDO](https://www.bdo.com/services/bdo-digital/cybersecurity)|As a global cybersecurity advisor and integrator, BDO helps clients manage risk and transform their organization with the Microsoft Entra Suite. Using our industry experience, we help clients grow confidently with transformative security and cloud solutions that implement the right identity strategy and governance, powered by Microsoft. |
|[Campana & Schott](https://www.campana-schott.com/de/en/expertise/strategie/cyber-security-services/identity-access-management)|Campana & Schott is an international management and technology consultancy with more than 600 employees in Europe and the U.S. We have longstanding transformation experience, and in-depth knowledge of Microsoft technologies, IT strategy, and IT organization. We're an ideal partner to support you in your identity and access management (IAM) transformation with the Microsoft Entra Suite. |
|[Condatis](https://condatis.com/technology/microsoft-entra-suite/entra-id-governance/)|Condatis delivers practical identity solutions using the Microsoft Entra Suite for complex global clients. Working closely with Microsoft, Condatis has strong IAM expertise, focused on reducing cyber risk, and optimizing costs. The Microsoft Entra Suite ensures seamless and secure access to empower your workforce, safeguard your digital ecosystem, and deliver measurable business outcomes. |
|[Cyclotron](https://www.cyclotron.com/post/streamline-identity-access-management-with-microsofts-entra-suite)|Cyclotron provides expert migration for SailPoint to the Microsoft Entra Suite, Okta to the Microsoft Entra Suite, and specialized knowledge of other toolset migration. Our proprietary migration tools significantly help accelerate deployment timelines, while our Change Leadership experts ease the burden of change on users and seamlessly engage stakeholders throughout the success strategy. |
|[DXC Technologies](https://dxc.com/content/dam/dxc/projects/dxc-com/us/pdfs/practices/DXC%20Service%20for%20MS%20Entra%20FS.pdf)|DXC Technology, a trusted global partner, is excited to enable the spectrum of controls in the Microsoft Entra Suite. We help organizations improve efficiencies and adopt a Zero Trust model through strategy, planning, preparation, transformation, and operational management of key security domains including identity, network, devices, applications, workloads, and data. |
|[Ernst & Young, LLP](https://www.ey.com/en_us/alliances/simplify-your-cybersecurity-with-the-ey-microsoft-alliance)|EY is a trusted global leader in professional services that creates a better working world with people at the center, using technology at scale and driving innovation at speed. The EY-Microsoft Alliance collaborates on innovative identity management solutions with Microsoft Entra, transforming the way businesses protect and manage identities, creating a future where trust and safety are paramount. |
|[glueckkanja AG](https://www.glueckkanja.com/en/workplace/microsoft-entra-suite/)|glueckkanja is a leading Microsoft partner renowned for its expertise in 100% cloud solutions and identity-centric security. The company is an established pioneer in implementing a fully cloud-managed workplace with consistent and practical applications of Zero Trust strategies. Their services range from proof-of-concepts for the latest Microsoft products, including Microsoft Global Secure Access. There are solutions for identity security, for example MyWorkID, to managed services, such as Managed Red Tenant. glueckkanja drives its blueprint approach at the cutting edge of Microsoft technology through close connections with Microsoft product teams and the TechCommunity. Several Microsoft MVPs specialize in identity and access work as subject matter experts in the Security organization. |
|[IBM Consulting](https://www.ibm.com/services/security)|IBM's strategic partnership with Microsoft has a foundation of deep technical expertise and a strong, shared commitment to continuous innovation. IBM's powerful AskIAM for Microsoft Entra uses cutting-edge Agentic AI to revolutionize identity governance. This technology seamlessly automates complex workflows, significantly enhances enterprise-grade security, ensures robust regulatory compliance, and dramatically improves operational productivity. |
|[Increment](https://appsource.microsoft.com/en-us/marketplace/consulting-services/incrementptyltd1637494276783.inc_offer-microsoft_entra_suite_engagement-01)|Increment's Microsoft Entra Suite engagement showcases the breadth of Microsoft Entra in your environment. We demonstrate how to automate employee lifecycles with Microsoft Entra ID Governance and provide secure internet access with Microsoft Entra Internet Access. We unlock true Zero Trust with Microsoft Entra Private Access, and create next-generation identity verification experiences with Microsoft Entra Verified ID. |
|[InSpark](https://www.inspark.nl/en/solution/security/entra)|InSpark transforms identity and network access with Microsoft Entra. We specialize in Microsoft Entra ID, Microsoft Entra ID Governance, Microsoft Entra ID Protection, Security Service Edge (SSE), Microsoft Entra Verified ID, and Microsoft Entra External ID. We offer unique project accelerators for rapid deployment. From consultancy to managed services, we ensure seamless and secure innovation. Partner with InSpark and experience the difference.|
|[Invoke](https://www.invokellc.com/identity-access-management)|Invoke excels exclusively at the Microsoft unified security operations platform, following Zero Trust principles. As a Partner of the Year Finalist for Identity and earning all Microsoft Security partner credentials, Invoke integrates identity solutions with best-of-suite workloads. Their expertise in Microsoft Entra ID migrations, Microsoft Entra ID Protection, Microsoft Global Secure Access, and Microsoft Entra ID Governance safeguards comprehensive identity transformation. |
|[Japan Business System, Inc.](https://blog.jbs.co.jp/archive/category/Microsoft%20Entra%20ID)|JBS has extensive integration experience and expertise in Microsoft Entra and Microsoft 365, and provides one-stop services across all phases, from initial planning and validation to implementation, deployment, and operational support. Their strong partnership with Microsoft further strengthens their ability to deliver comprehensive solutions. |
Modified by Ken Withee on May 2, 2025 6:27 AM
📖 View on learn.microsoft.com
+17 / -17 lines changed
Commit: Updates for clarity.
Changes:
Before
After
 
# Debug application proxy issues
 
This article describes steps you can take to troubleshoot issues with Microsoft Entra application proxy. Use the flowchart to troubleshoot remote access to an on-premises web application.
 
## Before you begin
 
The first thing to check is the connector. To learn how, see [Debug private network connector issues](application-proxy-debug-connectors.md).
 
If you still have application proxy issues, return to this article to troubleshoot the application.
 
## Flowchart for application issues
 
The flowchart contains the steps to debug common issues.
 
The table that appears after the flowchart contains details about each step.
 
![Diagram of a flowchart that shows steps to debug an application for application proxy issues.](media/application-proxy-debug-apps/application-proxy-apps-debugging-flowchart.png)
 
| Step | Action | Description |
 
# Debug application proxy issues
 
This article explains how to troubleshoot issues with Microsoft Entra application proxy. Use the flowchart to fix remote access issues for an on-premises web application.
 
## Before you begin
 
First, check the connector. Learn how in [Debug private network connector issues](application-proxy-debug-connectors.md).
 
If application proxy issues persist, return to this article to troubleshoot the issue.
 
## Flowchart for application issues
 
This flowchart helps you debug and fix common issues with the Microsoft Entra application proxy.
 
The table after the flowchart contains details about each step.
 
![Diagram of a flowchart that helps debug an application for Microsoft Entra application proxy issues.](media/application-proxy-debug-apps/application-proxy-apps-debugging-flowchart.png)
 
| Step | Goal | Action |
Modified by Henry Mbugua on May 2, 2025 6:34 PM
📖 View on learn.microsoft.com
+21 / -8 lines changed
Commit: [Content-Freshness] Keeping Your Content Up-to-Date and Accurate
Changes:
Before
After
manager: CelesteDG
ms.author: henrymbugua
ms.custom: has-adal-ref
ms.date: 04/01/2025
ms.service: identity-platform
 
ms.topic: whats-new
 
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
 
## March 2025
 
### Updated articles
### Updated articles
 
- [Microsoft identity platform and OAuth 2.0 Resource Owner Password Credentials](v2-oauth-ropc.md) - Added clarity to the content
 
## January 2025
 
### Updated articles
manager: CelesteDG
ms.author: henrymbugua
ms.custom: has-adal-ref
ms.date: 05/02/2025
ms.service: identity-platform
 
ms.topic: whats-new
 
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
 
## April 2025
 
### New articles
 
* [Add and manage application credentials in Microsoft Entra ID](how-to-add-credentials.md) - Register app refactor
* [How to add a redirect URI to your application](how-to-add-redirect-uri.md) - Register app refactor
 
### Updated articles
 
* [Quickstart: Call a web API that is protected by the Microsoft identity platform](quickstart-web-api-dotnet-protect-app.md) - Update ASP.NET Core web API tutorial (from minimal weather forecast API to controller-based Todo list API)
+13 / -1 lines changed
Commit: add fields beyond ID and displayname to groups
Changes:
Before
After
 
```powershell
# Get all groups and select Id and DisplayName
$groups = Get-MgGroup -All | Select-Object Id,DisplayName
# Export the groups to a JSON file
$groups | ConvertTo-Json | Set-Content ".\EntraGroups.json"
```
 
 
 
 
 
 
 
 
 
 
 
 
 
```powershell
# Get all groups and select Id and DisplayName
$groups = Get-MgGroup -All | Foreach-Object {
$groupObject = @{}
$groupObject["Id"] = $_.Id
$groupObject["DisplayName"] = $_.DisplayName
$groupObject["SecurityEnabled"] = $_.SecurityEnabled
$groupObject["MailEnabled"] = $_.MailEnabled
$groupObject["MailNickname"] = $_.MailNickname
$groupObject["SecurityIdentifier"] = $_.SecurityIdentifier
$date = [datetime]::Parse($_.CreatedDateTime)
$groupObject["CreatedDateTime"] = $date.ToString("yyyy-MM-dd")
$groupObject["SnapshotDate"] = $SnapshotDate
[pscustomobject]$groupObject
}
# Export the groups to a JSON file
$groups | ConvertTo-Json | Set-Content ".\EntraGroups.json"
```
+7 / -7 lines changed
Commit: Updates for clarity and consistency.
Changes:
Before
After
 
- Cross-domain scenarios rely on referrals that direct a connector host to DCs that might be outside of the local network perimeter. In these cases, it's equally important to send traffic onward to DCs that represent other respective domains. If you don't, delegation fails.
 
- Avoid active Intrusion Prevention System (IPS) or Intrusion Detection System (IDS) devices between connector hosts and DCs. These devices are too intrusive and interfere with core Remote Procedure Call (RPC) traffic.
 
- Test delegation in a simple scenario. The more variables you introduce in a scenario, the more complex configuration and troubleshooting is. To save time, limit your testing to a single connector. Add more connectors after the issue is resolved.
 
- Environmental factors might contribute to the cause of an issue. To avoid these factors, minimize architecture as much as possible during testing. For example, misconfigured internal firewall access control lists (ACLs) are common. If possible, send all traffic from a connector directly to the DCs and back-end application.
 
- The best place to position connectors is as close as possible to their targets. A firewall that sits inline when you test adds unnecessary complexity and can prolong your investigations.
 
- What indicates a KCD problem? Several common errors indicate that KCD SSO is failing. The first signs of an issue appear in the browser.
 
 
### The application
 
The target application consumes the Kerberos ticket that the connector provides. At this stage, it's expected that the connector sent a Kerberos service ticket to the back end. The ticket is a header in the first application request.
 
To troubleshoot an application issue:
 
 
- Cross-domain scenarios rely on referrals that direct a connector host to DCs that might be outside of the local network perimeter. In these cases, it's equally important to send traffic onward to DCs that represent other respective domains. If you don't, delegation fails.
 
- Avoidance of active Intrusion Prevention System (IPS) or Intrusion Detection System (IDS) devices between connector hosts and domain controllers (DCs) due to interference with core Remote Procedure Call (RPC) traffic.
 
- Test delegation in a simple scenario. The more variables you introduce in a scenario, the more complex configuration and troubleshooting is. To save time, limit your testing to a single connector. Add more connectors after the issue is resolved.
 
- Environmental factors might contribute to the cause of an issue. To avoid these factors, minimize architecture as much as possible during testing. For example, misconfigured internal firewall access control lists (ACLs) are common. If possible, send all traffic from a connector directly to the DCs and back-end application.
 
- The best place to position connectors is as close as possible to their targets. A firewall that sits inline when you test the connector adds unnecessary complexity and can prolong your investigations.
 
- What indicates a KCD problem? Several common errors indicate that KCD SSO is failing. The first signs of an issue appear in the browser.
 
 
### The application
 
The target application processes the Kerberos ticket provided by the connector. At this stage, the connector includes a Kerberos service ticket as a header in the first application request to the back end.
 
To troubleshoot an application issue:
 
+8 / -2 lines changed
Commit: Cross-cloud synchronization updates
Changes:
Before
After
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: how-to
ms.date: 10/09/2024
ms.author: rolyon
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
 
1. At the top of the page, select **New configuration**.
 
1. Provide a name for the configuration and select **Create**.
 
It can take up to 15 seconds for the configuration that you just created to appear in the list.
 
 
 
 
 
 
 
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: how-to
ms.date: 05/02/2025
ms.author: rolyon
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
 
1. At the top of the page, select **New configuration**.
 
1. Provide a name for the configuration.
 
:::image type="content" source="./media/cross-tenant-synchronization-configure/configuration-name-cross-tenant-sync.png" alt-text="Screenshot of a new configuration that shows the name and cross-tenant synchronization check box." lightbox="./media/cross-tenant-synchronization-configure/configuration-name-cross-tenant-sync.png":::
 
You might see a **Setup cross-tenant synchronization across Microsoft clouds** check box. This capability is currently being deployed in stages and is not yet functional.
 
1. Select **Create**.
 
It can take up to 15 seconds for the configuration that you just created to appear in the list.
 
Modified by Ken Withee on May 2, 2025 8:04 AM
📖 View on learn.microsoft.com
+5 / -5 lines changed
Commit: Minor fixes for acrolinx clarity and tone.
Changes:
Before
After
 
![Authentication settings](./media/jitbit-helpdesk-tutorial/authentication.png "Authentication settings")
 
a. Select **Enable SAML 2.0 single sign on**, to sign in using Single Sign-On (SSO), with **OneLogin**.
 
b. In the **EndPoint URL** textbox, paste the value of **Login URL**..
 
c. Open your **base-64** encoded certificate in notepad, copy the content of it into your clipboard, and then paste it to the **X.509 Certificate** textbox
 
 
c. In the **First Name** textbox, type first name of the user like **Britta**.
 
d. In the **Last Name** textbox, type last name of the user like **Simon**.
 
e. Select **Create**.
 
 
In this section, you test your Microsoft Entra single sign-on configuration with following options.
 
* Select **Test this application**, this option redirects to Jitbit Helpdesk Sign-on URL where you can initiate the login flow.
 
![Authentication settings](./media/jitbit-helpdesk-tutorial/authentication.png "Authentication settings")
 
a. Select **Enable SAML 2.0 single sign on**, to sign in using single sign-on (SSO), with **OneLogin**.
 
b. In the **EndPoint URL** textbox, paste the value of **Login URL**.
 
c. Open your **base-64** encoded certificate in notepad, copy the content of it into your clipboard, and then paste it to the **X.509 Certificate** textbox
 
 
c. In the **First Name** textbox, type first name of the user like **Britta**.
 
d. In the **Last Name** textbox, type the family name of the user like **Simon**.
 
e. Select **Create**.
 
 
In this section, you test your Microsoft Entra single sign-on configuration with following options.
 
* Select **Test this application**, this option redirects to Jitbit Helpdesk Sign-on URL where you can initiate the sign-in flow.
+5 / -5 lines changed
Commit: Updates for clarity, consistency, and tone.
Changes:
Before
After
- A Microsoft Entra tenant with a plan that includes application proxy. Learn more about [Microsoft Entra ID plans and pricing](https://www.microsoft.com/security/business/identity-access-management/azure-ad-pricing).
- A Microsoft Office Web Apps Server farm to properly launch Office files from the on-premises SharePoint farm.
- A [custom, verified domain](~/fundamentals/add-custom-domain.yml) in the Microsoft Entra tenant.
- On-premises Active Directory synchronized with Microsoft Entra Connect, through which users can [sign in to Azure](~/identity/hybrid/connect/plan-connect-user-signin.md).
- a private network connector installed and running on a machine within the corporate domain.
 
Configuring SharePoint with application proxy requires two URLs:
> To make sure the links are mapped correctly, follow these recommendations for the internal URL:
> - Use HTTPS.
> - Don't use custom ports.
> - In the corporate Domain Name System (DNS), create a host (A) to point to the SharePoint WFE (or load balancer), and not an alias (CName).
 
This article uses the following values:
- Internal URL: `https://sharepoint`.
The SharePoint web application must be configured with Kerberos and the appropriate alternate access mappings to work correctly with Microsoft Entra application proxy. There are two possible options:
 
- Create a new web application and use only the **default** zone. Using the default zone is the preferred option, it offers the best experience with SharePoint. For example, the links in email alerts that SharePoint generates point to the **default** zone.
- Extend an existing web application to configure Kerberos in a non default zone.
 
> [!IMPORTANT]
- A Microsoft Entra tenant with a plan that includes application proxy. Learn more about [Microsoft Entra ID plans and pricing](https://www.microsoft.com/security/business/identity-access-management/azure-ad-pricing).
- A Microsoft Office Web Apps Server farm to properly launch Office files from the on-premises SharePoint farm.
- A [custom, verified domain](~/fundamentals/add-custom-domain.yml) in the Microsoft Entra tenant.
- On-premises Active Directory deployments synchronized with Microsoft Entra Connect, through which users can [sign in to Azure](~/identity/hybrid/connect/plan-connect-user-signin.md).
- a private network connector installed and running on a machine within the corporate domain.
 
Configuring SharePoint with application proxy requires two URLs:
> To make sure the links are mapped correctly, follow these recommendations for the internal URL:
> - Use HTTPS.
> - Don't use custom ports.
> - Create a host (`A` record) in the corporate Domain Name System (DNS) that point to the SharePoint Web Front End (WFE) (or load balancer), and not an alias (`CName` record).
 
This article uses the following values:
- Internal URL: `https://sharepoint`.
The SharePoint web application must be configured with Kerberos and the appropriate alternate access mappings to work correctly with Microsoft Entra application proxy. There are two possible options:
 
- Create a new web application and use only the **default** zone. Using the default zone is the preferred option, it offers the best experience with SharePoint. For example, the links in email alerts that SharePoint generates point to the **default** zone.
- Extend an existing web application to configure Kerberos in a nondefault zone.
 
> [!IMPORTANT]
Modified by Ortagus Winfrey on May 2, 2025 12:08 AM
📖 View on learn.microsoft.com
+10 / -0 lines changed
Commit: Conditional access optimization agent added to whats new
Changes:
Before
After
 
## April 2025
 
### Public Preview - Microsoft Entra ID Governance: Suggested access packages in My Access
 
**Type:** New feature
 
 
 
 
 
 
 
 
 
 
 
## April 2025
 
### Public Preview - Conditional Access Optimization Agent in Microsoft Entra
 
**Type:** New feature
**Service category:** Conditional Access
**Product capability:** Identity Security & Protection
 
[Conditional Access Optimization Agent in Microsoft Entra](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-innovations-in-microsoft-entra-to-strengthen-ai-security-and-identity-protec/3827393) monitors for new users or apps not covered by existing policies, identifies necessary updates to close security gaps, and recommends quick fixes for identity teams to apply with a single selection. For more information, see: [Microsoft Entra Conditional Access optimization agent](../identity/conditional-access/agent-optimization.md).
 
---
 
### Public Preview - Microsoft Entra ID Governance: Suggested access packages in My Access
 
**Type:** New feature
+7 / -1 lines changed
Commit: Cloud pairs and settings text
Changes:
Before
After
- Cross-tenant synchronization is supported within the commercial cloud and Azure Government.
- Cross-tenant synchronization isn't supported within the Microsoft Azure operated by 21Vianet cloud.
- Synchronization is only supported between two tenants in the same Azure cloud. For information about the relationship between the Azure Cloud environments and Microsoft 365 (GCC, GCCH), see [Microsoft 365 integration](/azure/security/fundamentals/feature-availability#microsoft-365-integration). Synchronization between commercial and GCC is supported.
- Cross-cloud synchronization (such as public cloud to Azure Government) isn't supported. This capability is currently being deployed in stages. You might see cross-cloud synchroniztion settings in the Microsoft Entra admin center or Azure portal, but these settings are not yet functional.
 
#### Existing B2B users
 
 
 
 
 
 
 
- Cross-tenant synchronization is supported within the commercial cloud and Azure Government.
- Cross-tenant synchronization isn't supported within the Microsoft Azure operated by 21Vianet cloud.
- Synchronization is only supported between two tenants in the same Azure cloud. For information about the relationship between the Azure Cloud environments and Microsoft 365 (GCC, GCCH), see [Microsoft 365 integration](/azure/security/fundamentals/feature-availability#microsoft-365-integration). Synchronization between commercial and GCC is supported.
- Cross-cloud synchronization (such as public cloud to Azure Government) isn't supported. This capability is currently being deployed in stages. You might see cross-cloud synchroniztion settings in the Microsoft Entra admin center or Azure portal. These settings are not yet functional and you shouldn't try to select these settings.
 
What cloud pairs are supported for cross-tenant synchronization?
 
- Cross-tenant synchronization supports these cloud pairs:
 
[!INCLUDE [cross-tenant-synchronization-cloud-pairs-include](../../includes/cross-tenant-synchronization-cloud-pairs-include.md)]
 
#### Existing B2B users
 
+4 / -4 lines changed
Commit: Updates for clarity and tone.
Changes:
Before
After
 
![Diagram that shows Logic App to API connection via Azure application proxy.](./media/application-proxy-integrate-with-logic-apps/azure-logic-app-to-api-connection-app-proxy.png)
 
The Microsoft Entra application proxy and associated connector facilitate secure authorization and integration to your on premises services without more configuration to your network security infrastructure.
 
## Prerequisites
 
- Azure private network connector deployed and an application configured as detailed in [Add an on premises app - application proxy in Microsoft Entra ID](./application-proxy-add-on-premises-application.md)
 
> [!NOTE]
> While granting a user entitlement and testing the sign on is recommended, it's not required for this guide.
 
## Configure the Application Access
 
1. Navigate to the application with a matching name to your deployed application proxy application. For example, if you deployed *Sample App 1* as an Enterprise Application, select the **Sample App 1** registration item.
 
> [!NOTE]
> If an associated application can't be found, it may have not been automatically created or may have been deleted. A registration can be created using the **New Registration** button.
 
1. From the *Sample App 1* detail page, record the *Application (client) ID* and *Directory (tenant) ID* fields.
 
![Diagram that shows Logic App to API connection via Azure application proxy.](./media/application-proxy-integrate-with-logic-apps/azure-logic-app-to-api-connection-app-proxy.png)
 
The Microsoft Entra application proxy and associated connector facilitate secure authorization and integration to your on premises services without more configurations to your network security infrastructure.
 
## Prerequisites
 
- Azure private network connector deployed and an application configured as detailed in [Add an on premises app - application proxy in Microsoft Entra ID](./application-proxy-add-on-premises-application.md)
 
> [!NOTE]
> Granting a user entitlement and testing the sign-on is recommended but not required for this guide.
 
## Configure the Application Access
 
1. Navigate to the application with a matching name to your deployed application proxy application. For example, if you deployed *Sample App 1* as an Enterprise Application, select the **Sample App 1** registration item.
 
> [!NOTE]
> An associated application might be deleted or not automatically created if it can't be found. A registration can be created using the **New Registration** button.
 
1. From the *Sample App 1* detail page, record the *Application (client) ID* and *Directory (tenant) ID* fields.
+4 / -4 lines changed
Commit: Updates to improve readability and quality.
Changes:
Before
After
If you can't use custom domains in your tenant, there are several other options for providing this functionality. All of the other options are also compatible with custom domains and each other, so you can configure custom domains and other solutions.
 
> [!NOTE]
> Link translation is not supported for hard-coded internal URLs generated through JavaScript.
 
**Option 1: Use Microsoft Edge** – This solution is only applicable if you plan to recommend or require that users access the application through the Microsoft Edge browser. It handles all published URLs.
 
 
You can use Microsoft Edge to further protect your application and content. To use this solution, you need to require/recommend users access the application through Microsoft Edge. Microsoft Edge recognizes all internal URLs published with application proxy and redirects them to the corresponding external URL. The redirection ensures that hard coded internal URLs work. If a user goes to the browser and directly types the internal URL, it works even if the user is remote.
 
To learn more, including how to configure this option, see the [Manage web access by using Microsoft Edge for iOS and Android with Microsoft Intune](/mem/intune/apps/manage-microsoft-edge) documentation.
 
### Option 2: MyApps Browser Extension
 
To learn more, including how to configure this option, see the [MyApps Browser Extension](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510#download-and-install-the-my-apps-secure-sign-in-extension) documentation.
 
> [!NOTE]
> The MyApps Browser Extension does not support link translation for wildcard URLs.
 
### Option 3: Link Translation Setting
If you can't use custom domains in your tenant, there are several other options for providing this functionality. All of the other options are also compatible with custom domains and each other, so you can configure custom domains and other solutions.
 
> [!NOTE]
> Link translation isn't supported for hard-coded internal URLs generated through JavaScript.
 
**Option 1: Use Microsoft Edge** – This solution is only applicable if you plan to recommend or require that users access the application through the Microsoft Edge browser. It handles all published URLs.
 
 
You can use Microsoft Edge to further protect your application and content. To use this solution, you need to require/recommend users access the application through Microsoft Edge. Microsoft Edge recognizes all internal URLs published with application proxy and redirects them to the corresponding external URL. The redirection ensures that hard coded internal URLs work. If a user goes to the browser and directly types the internal URL, it works even if the user is remote.
 
To learn more, including how to configure this option, see [Manage web access by using Microsoft Edge for iOS and Android with Microsoft Intune](/mem/intune/apps/manage-microsoft-edge) documentation.
 
### Option 2: MyApps Browser Extension
 
To learn more, including how to configure this option, see the [MyApps Browser Extension](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510#download-and-install-the-my-apps-secure-sign-in-extension) documentation.
 
> [!NOTE]
> The MyApps Browser Extension doesn't support link translation for wildcard URLs.
 
### Option 3: Link Translation Setting
+3 / -3 lines changed
Commit: Updates for clarity and consistency.
Changes:
Before
After
 
## General remarks
 
Public DNS records for Microsoft Entra application proxy endpoints are chained CNAME records pointing to an A record. Setting up the records this way ensures fault tolerance and flexibility. The Microsoft Entra private network connector always accesses host names with the domain suffixes `*.msappproxy.net` or `*.servicebus.windows.net`. However, during the name resolution the CNAME records might contain DNS records with different host names and suffixes. Due to the difference, you must ensure that the device (depending on your setup - connector server, firewall, outbound proxy) can resolve all the records in the chain and allows connection to the resolved IP addresses. Since the DNS records in the chain might be changed from time to time, we can't provide you with any list DNS records.
 
If you install connectors in different regions, you should optimize traffic by selecting the closest application proxy cloud service region with each connector group. To learn more, see [Optimize traffic flow with Microsoft Entra application proxy](application-proxy-network-topology.md).
 
 
| Field | Description |
| :------------------------------ | :----------------------------------------------------------- |
| **Backend Application Timeout** | Set this value to **Long** only if your application is slow to authenticate and connect. At default, the backend application timeout has a length of 85 seconds. When set too long, the backend timeout is increased to 180 seconds. |
| **Use HTTP-Only Cookie** | Select to have application proxy cookies include the HTTPOnly flag in the HTTP response header. If using Remote Desktop Services, keep the option unselected. |
| **Use Persistent Cookie**| Keep the option unselected. Only use this setting for applications that can't share cookies between processes. For more information about cookie settings, see [Cookie settings for accessing on-premises applications in Microsoft Entra ID](./application-proxy-configure-cookie-settings.md). |
| **Translate URLs in Headers** | Keep the option selected unless your application required the original host header in the authentication request. |
| **Translate URLs in Application Body** | Keep the option unselected unless HTML links are hardcoded to other on-premises applications and don't use custom domains. For more information, see [Link translation with application proxy](./application-proxy-configure-hard-coded-link-translation.md).<br><br>Select if you plan to monitor this application with Microsoft Defender for Cloud Apps. For more information, see [Configure real-time application access monitoring with Microsoft Defender for Cloud Apps and Microsoft Entra ID](./application-proxy-integrate-with-microsoft-cloud-application-security.md). |
| **Validate Backend TLS/SSL Certificate** | Select to enable backend TLS/SSL certificate validation for the application. |
 
1. Select **Add**.
 
 
## General remarks
 
Public Domain Name System (DNS) records for Microsoft Entra application proxy endpoints are chained CNAME records pointing to an A record. Setting up the records this way ensures fault tolerance and flexibility. The Microsoft Entra private network connector always accesses host names with the domain suffixes `*.msappproxy.net` or `*.servicebus.windows.net`. However, during the name resolution the CNAME records might contain DNS records with different host names and suffixes. Due to the difference, you must ensure that the device (depending on your setup - connector server, firewall, outbound proxy) can resolve all the records in the chain and allows connection to the resolved IP addresses. Since the DNS records in the chain might be changed from time to time, we can't provide you with any list DNS records.
 
If you install connectors in different regions, you should optimize traffic by selecting the closest application proxy cloud service region with each connector group. To learn more, see [Optimize traffic flow with Microsoft Entra application proxy](application-proxy-network-topology.md).
 
 
| Field | Description |
| :------------------------------ | :----------------------------------------------------------- |
| **Backend Application Timeout** | Set this value to **Long** only if your application is slow to authenticate and connect. At default, the backend application time-out has a length of 85 seconds. When set too long, the backend time out is increased to 180 seconds. |
| **Use HTTP-Only Cookie** | Select to have application proxy cookies include the HTTPOnly flag in the HTTP response header. If using Remote Desktop Services, keep the option unselected. |
| **Use Persistent Cookie**| Keep the option unselected. Only use this setting for applications that can't share cookies between processes. For more information about cookie settings, see [Cookie settings for accessing on-premises applications in Microsoft Entra ID](./application-proxy-configure-cookie-settings.md). |
| **Translate URLs in Headers** | Keep the option selected unless your application required the original host header in the authentication request. |
| **Translate URLs in Application Body** | Keep the option unselected unless HTML links are hardcoded to other on-premises applications and don't use custom domains. For more information, see [Link translation with application proxy](./application-proxy-configure-hard-coded-link-translation.md).<br><br>Select if you plan to monitor this application with Microsoft Defender for Cloud Apps. For more information, see [Configure real-time application access monitoring with Microsoft Defender for Cloud Apps and Microsoft Entra ID](./application-proxy-integrate-with-microsoft-cloud-application-security.md). |
| **Validate Backend TLS Certificate** | Select to enable backend Transport Layer Security (TLS) certificate validation for the application. |
 
1. Select **Add**.
 
+3 / -3 lines changed
Commit: Updates for clarity and consistency.
Changes:
Before
After
- CORS Rules (optional) can be configured per application segment.
- Access is only granted to defined application segments for a complex application.
> [!NOTE]
> If all application segments are deleted, a complex application will behave as a wildcard application opening access to all valid URLs by specified domain.
- You can have an internal URL defined both as an application segment and a regular application.
> [!NOTE]
> Regular applications always take precedence over a complex app (wildcard application).
## Configure application segments for complex application.
 
> [!NOTE]
> Two application segment per complex distributed application are supported for [Microsoft Entra ID P1 or P2 subscription](https://azure.microsoft.com/pricing/details/active-directory).
 
To publish a complex distributed app through application proxy with application segments:
 
## Configuring single sign-on (SSO)
 
> [!NOTE]
> Integrated Windows Authentication (IWA) single sign-on doesn't support using wildcard SPNs. For example, a wildcard such as `http/*.contoso.com` uses the single configured SPN such as `http/app.contoso.com` for all the segments.
 
## DNS updates
- CORS Rules (optional) can be configured per application segment.
- Access is only granted to defined application segments for a complex application.
> [!NOTE]
> If you delete all application segments, the complex application acts like a wildcard application, allowing access to any valid URL under the specified domain.
- You can have an internal URL defined both as an application segment and a regular application.
> [!NOTE]
> Regular applications always take precedence over a complex app (wildcard application).
## Configure application segments for complex application.
 
> [!NOTE]
> Two application segments per complex distributed application are supported for [Microsoft Entra ID P1 or P2 subscription](https://azure.microsoft.com/pricing/details/active-directory).
 
To publish a complex distributed app through application proxy with application segments:
 
## Configuring single sign-on (SSO)
 
> [!NOTE]
> Single sign-on with Integrated Windows Authentication (IWA) doesn't support wildcard Service Principal Names (SPNs). For example, a wildcard such as `http/*.contoso.com` uses the single configured SPN such as `http/app.contoso.com` for all the segments.
 
## DNS updates

🗑️ Deleted Documentation Files

DELETED docs/fundamentals/how-to-navigate.md
Deleted by John Flores on May 2, 2025 4:28 AM
📖 Was available at: https://learn.microsoft.com/en-us/entra/fundamentals/how-to-navigate
-66 lines removed
Commit: [Fundamentals] Delete and redirect navigation topic