๐Ÿ“‹ Microsoft Entra Documentation Changes

Changes for May 8th 2025

Period: May 7th 2025, 12:00 AM to May 8th 2025, 12:00 AM

๐Ÿ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 8th 2025.

๐Ÿ“Š Summary

24
Total Commits
0
New Files
9
Modified Files
0
Deleted Files
11
Contributors

๐Ÿ“ Modified Documentation Files

+88 / -26 lines changed
Commit: macOS Kerb Profile Fixes
Changes:
Before
After
 
Refer to the [Microsoft Entra ID macOS Platform SSO documentation](./macos-psso.md) to learn how to configure and deploy Platform SSO. Platform SSO should be deployed on Enterprise-managed Macs regardless of whether you choose to deploy Kerberos SSO using this guide.
 
## Kerberos SSO MDM profile configuration
 
You must configure a Kerberos SSO MDM profile. Use the following settings, ensuring that you replace all references to **contoso.com** and **Contoso** with the proper values for your environment:
 
| Configuration Key | Recommended Value | Note |
|-|-|-|
| `preferredKDCs` | `<string>kkdcp://login.microsoftonline.com/contoso.com/kerberos</string>` | Replace the **contoso.com** value with the value of one of your tenant domains or your tenant's GUID |
| `Hosts` | `<string>contoso.com</string>` | Replace **contoso.com** with your on-premises domain/forest name |
| `Hosts` | `<string>*.contoso.com</string>` | Replace **contoso.com** with your on-premises domain/forest name. Keep the preceding `*.` characters before your domain/forest name |
| `PayloadOrganization` | `<string>Contoso</string>` | Replace **Contoso** with the name of your organization |
 
```xml
<false/>
<key>usePlatformSSOTGT</key>
<true/>
<key>preferredKDCs</key>
<array>
 
Refer to the [Microsoft Entra ID macOS Platform SSO documentation](./macos-psso.md) to learn how to configure and deploy Platform SSO. Platform SSO should be deployed on Enterprise-managed Macs regardless of whether you choose to deploy Kerberos SSO using this guide.
 
## Kerberos SSO MDM profile configuration for on-premises Active Directory
 
You must configure at least one Kerberos SSO MDM profile. Use the following settings, ensuring that you replace all references to **contoso.com** and **Contoso** with the proper values for your environment:
 
| Configuration Key | Recommended Value | Note |
|-|-|-|
| `Hosts` | `<string>.contoso.com</string>` | Replace **contoso.com** with your on-premises domain/forest name |
| `Hosts` | `<string>contoso.com</string>` | Replace **contoso.com** with your on-premises domain/forest name. Keep the preceding `.` characters before your domain/forest name |
| `Realm` | `<string>CONTOSO.COM</string>` | Replace **CONTOSO.COM** with your on-premises realm name. The value should be all capitalized. |
| `PayloadOrganization` | `<string>Contoso</string>` | Replace **Contoso** with the name of your organization |
 
```xml
<false/>
<key>usePlatformSSOTGT</key>
<true/>
</dict>
<key>ExtensionIdentifier</key>
+13 / -8 lines changed
Commit: updates for v163
Changes:
Before
After
---
title: Microsoft Entra ID attestation for FIDO2 security key vendors
description: Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
ms.date: 05/02/2025
ms.service: entra-id
ms.subservice: authentication
author: justinha
 
## FIDO2 security keys eligible for attestation with Microsoft Entra ID
 
The following table includes each FIDO2 security key model listed in MDS version 156 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
Description|AAGUID|Bio|USB|NFC|BLE
-----------|------|---|---|---|---
Cryptnox FIDO2|9c835346-796b-4c27-8898-d6032f515cc5|&#10060;|&#10060;|&#x2705;|&#10060;
Cryptnox FIDO2.1|1d1b4e33-76a1-47fb-97a0-14b10d0933f1|&#10060;|&#10060;|&#x2705;|&#10060;
Dapple Authenticator from Dapple Security Inc.|6dae43be-af9c-417b-8b9f-1b611168ec60|&#10060;|&#10060;|&#10060;|&#10060;
Deepnet SafeKey/Classic (USB)|b9f6b7b6-f929-4189-bca9-dd951240c132|&#10060;|&#10060;|&#10060;|&#10060;
Egomet FIDO2 Authenticator for Android|1105e4ed-af1d-02ff-ffff-ffffffffffff|&#x2705;|&#10060;|&#10060;|&#10060;
ellipticSecure MIRkey USB Authenticator|eb3b131e-59dc-536a-d176-cb7306da10f5|&#10060;|&#x2705;|&#10060;|&#10060;
---
title: Microsoft Entra ID attestation for FIDO2 security key vendors
description: Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
ms.date: 05/06/2025
ms.service: entra-id
ms.subservice: authentication
author: justinha
 
## FIDO2 security keys eligible for attestation with Microsoft Entra ID
 
The following table includes each FIDO2 security key model listed in MDS version 163 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
Description|AAGUID|Bio|USB|NFC|BLE
-----------|------|---|---|---|---
Cryptnox FIDO2|9c835346-796b-4c27-8898-d6032f515cc5|&#10060;|&#10060;|&#x2705;|&#10060;
Cryptnox FIDO2.1|1d1b4e33-76a1-47fb-97a0-14b10d0933f1|&#10060;|&#10060;|&#x2705;|&#10060;
Dapple Authenticator from Dapple Security Inc.|6dae43be-af9c-417b-8b9f-1b611168ec60|&#10060;|&#10060;|&#10060;|&#10060;
Deepnet SafeKey/Classic (NFC)|b12eac35-586c-4809-a4b1-d81af6c305cf|&#10060;|&#10060;|&#10060;|&#10060;
Deepnet SafeKey/Classic (USB)|b9f6b7b6-f929-4189-bca9-dd951240c132|&#10060;|&#10060;|&#10060;|&#10060;
Egomet FIDO2 Authenticator for Android|1105e4ed-af1d-02ff-ffff-ffffffffffff|&#x2705;|&#10060;|&#10060;|&#10060;
+7 / -7 lines changed
Commit: updates
Changes:
Before
After
 
## Prerequisites
 
- At least the [Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) role of the catalog where the custom extension will be created.
- At least the [Azure built-in role](/azure/role-based-access-control/built-in-roles) of [Logic App Contributor](/azure/role-based-access-control/built-in-roles/integration#logic-app-contributor) on the Logic App itself, the resource group, subscription, or management group that the logic app is in.
 
## Create the custom extension and Azure Logic App
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) of the catalog where the custom extension will be located.
 
1. Browse to **Identity governance** > **Entitlement management** > **Catalogs**.
 
1. On the Catalogs overview page, select an existing catalog where your custom extension will be located, or create a new catalog.
 
1. On the specific catalog page where you want to create your custom extension, select **Custom extensions**.
:::image type="content" source="media/entitlement-management-dynamic-approval/extensibility-catalog-screen.png" alt-text="Screenshot of catalog page where custom extension is being added.":::
1. Select **Add a custom extension** and add a name and description for the custom extension. When finished, select **Next**.
:::image type="content" source="media/entitlement-management-dynamic-approval/custom-extension-basics.png" alt-text="Screenshot of custom extension basics.":::
1. On the **Extension Type** page, select **Request workflow (triggered when an access package is request, approved, granted, or removed)** and select **Next**.
:::image type="content" source="media/entitlement-management-dynamic-approval/extension-type.png" alt-text="Screenshot of selecting the extension type for a custom extension.":::
 
## Prerequisites
 
- At least the [Entitlement Management Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) role of the catalog where the custom extension will be created.
- At least the [Azure built-in role](/azure/role-based-access-control/built-in-roles) of [Logic App Contributor](/azure/role-based-access-control/built-in-roles/integration#logic-app-contributor) on the Logic App itself, the resource group, subscription, or management group that the logic app is in.
 
## Create the custom extension and Azure Logic App
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) of the catalog where the custom extension will be located.
 
1. Browse to **ID Governance** > **Entitlement management** > **Catalogs**.
 
1. On the Catalogs overview page, select an existing catalog where your custom extension will be located, or create a new catalog.
 
1. On the specific catalog page where you want to create your custom extension, select **Custom extensions**.
:::image type="content" source="media/entitlement-management-dynamic-approval/extensibility-catalog-screen.png" alt-text="Screenshot of catalog page where custom extension is being added.":::
1. Select **Add a custom extension** to add a name and description for the custom extension. When finished, select **Next**.
:::image type="content" source="media/entitlement-management-dynamic-approval/custom-extension-basics.png" alt-text="Screenshot of custom extension basics.":::
1. On the **Extension Type** page, select **Request workflow (triggered when an access package is request, approved, granted, or removed)** and select **Next**.
:::image type="content" source="media/entitlement-management-dynamic-approval/extension-type.png" alt-text="Screenshot of selecting the extension type for a custom extension.":::
+2 / -2 lines changed
Commit: PM-update
Changes:
Before
After
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 04/29/2025
ms.author: sarahlipsey
ms.reviewer: madansr7
 
 
![Screenshot of the sign-in activity details for a selected application.](./media/concept-usage-insights-report/application-activity-sign-in-detail.png)
 
This report now includes applications that authenticate *to* or are authenticated *by* other Microsoft Cloud Services applications in your tenant. These applications might appear in this report but when you select the link for an application, the results say "Not found." This message indicates that the application was only instantiated in your tenant, meaning only an instance of it appears in this report to indicate a service-to-service authentication. The application itself doesn't have a service principal in your tenant. We realize that this message might cause confusion and are working to improve the experience.
 
### Application activity using Microsoft Graph
 
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 05/06/2025
ms.author: sarahlipsey
ms.reviewer: madansr7
 
 
![Screenshot of the sign-in activity details for a selected application.](./media/concept-usage-insights-report/application-activity-sign-in-detail.png)
 
This report now includes applications owned by Microsoft Services that are instantiated in customer tenants. These applications can be involved in service-to-service authentications. When you select the applications from the **Usage and insights** report, the results say "Not found" because the application is not owned by your tenant, but is only instantiated in your tenant. To see the sign-in activity for these applications, select the **View sign-in activity** link.
 
### Application activity using Microsoft Graph
 
+2 / -2 lines changed
Commit: cleanup
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: conceptual
ms.date: 05/05/2025
 
author: shlipsey3
ms.author: sarahlipsey
 
#### Leaked credentials
 
Calculated offline. This risk detection type indicates that the user's valid credentials leaked. When cybercriminals compromise valid passwords of legitimate users, they often share these gathered credentials. This sharing is typically done by posting publicly on the dark web, paste sites, or by trading and selling the credentials on the black market. When the Microsoft leaked credentials service acquires user credentials from the dark web, paste sites, or other sources, they're checked against Microsoft Entra users' current valid credentials to find valid matches. For more information about leaked credentials, seeโ€ฏthe [FAQs](id-protection.yml.#leaked-credentials).
 
[Tips for investigating leaked credentials detections.](howto-identity-protection-investigate-risk.md#investigating-leaked-credentials-detections)
 
ms.service: entra-id-protection
 
ms.topic: conceptual
ms.date: 05/06/2025
 
author: shlipsey3
ms.author: sarahlipsey
 
#### Leaked credentials
 
Calculated offline. This risk detection type indicates that the user's valid credentials leaked. When cybercriminals compromise valid passwords of legitimate users, they often share these gathered credentials. This sharing is typically done by posting publicly on the dark web, paste sites, or by trading and selling the credentials on the black market. When the Microsoft leaked credentials service acquires user credentials from the dark web, paste sites, or other sources, they're checked against Microsoft Entra users' current valid credentials to find valid matches. For more information about leaked credentials, seeโ€ฏthe [FAQs](id-protection.faq.yml#leaked-credentials).
 
[Tips for investigating leaked credentials detections.](howto-identity-protection-investigate-risk.md#investigating-leaked-credentials-detections)
 
+1 / -1 lines changed
Commit: PM-update
Changes:
Before
After
ms.service: entra-id
ms.topic: reference
ms.subservice: monitoring-health
ms.date: 04/28/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg
---
ms.service: entra-id
ms.topic: reference
ms.subservice: monitoring-health
ms.date: 05/06/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg
---
Modified by dimeji-omikunle-hs on May 7, 2025 4:42 AM
๐Ÿ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/identity/saas-apps/hootsuite-tutorial.md
Changes:
Before
After
1. Perform the following step, if you wish to configure the application in **SP** initiated mode:
 
In the **Sign-on URL** text box, type the URL:
`[https://hootsuite.com/login](https://hootsuite.com/login?method=sso)`
 
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
 
1. Perform the following step, if you wish to configure the application in **SP** initiated mode:
 
In the **Sign-on URL** text box, type the URL:
`https://hootsuite.com/login?method=sso`
 
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
 
+1 / -1 lines changed
Commit: Acrolinx fix
Changes:
Before
After
Assigning Microsoft Entra roles through access packages helps to efficiently manage role assignments at scale and improves the role assignment lifecycle.
 
> [!NOTE]
> We recommend that you use Privileged Identity Management to provide just-in-time access to a user to perform a task that requires elevated permissions. These permissions are provided through the Microsoft Entra Roles, that are tagged as โ€œprivilegedโ€, in our documentation here: Microsoft Entra built-in roles. Entitlement Management is better suited for assigning users a bundle of resources, which can include a Microsoft Entra role, necessary to do oneโ€™s job. Users assigned to access packages tend to have more longstanding access to resources. While we recommend that you manage high-privileged roles through Privileged Identity Management, you can set up eligibility for those roles through access packages in Entitlement Management.
 
Follow these steps to include a Microsoft Entra role as a resource in an access package:
 
Assigning Microsoft Entra roles through access packages helps to efficiently manage role assignments at scale and improves the role assignment lifecycle.
 
> [!NOTE]
> We recommend that you use Privileged Identity Management to provide just-in-time access to a user to perform a task that requires elevated permissions. These permissions are provided through the Microsoft Entra Roles that are tagged as โ€œprivilegedโ€ in our documentation here: Microsoft Entra built-in roles. Entitlement Management is better suited for assigning users a bundle of resources, which can include a Microsoft Entra role, necessary to do oneโ€™s job. Users assigned to access packages tend to have more longstanding access to resources. While we recommend that you manage high-privileged roles through Privileged Identity Management, you can set up eligibility for those roles through access packages in Entitlement Management.
 
Follow these steps to include a Microsoft Entra role as a resource in an access package:
 
Modified by nucarampanta on May 7, 2025 5:44 PM
๐Ÿ“– View on learn.microsoft.com
+1 / -0 lines changed
Commit: Update hybrid-join-plan.md
Changes:
Before
After
- Windows Server 2016
- **Note:** Azure National cloud customers require version 1803
- Windows Server 2019
 
As a best practice, Microsoft recommends you upgrade to the latest version of Windows.
 
 
- Windows Server 2016
- **Note:** Azure National cloud customers require version 1803
- Windows Server 2019
- Windows Server 2022
 
As a best practice, Microsoft recommends you upgrade to the latest version of Windows.