📋 Microsoft Entra Documentation Changes

Changes for May 10th 2025

Period: May 9th 2025, 12:00 AM to May 10th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 10th 2025.

📊 Summary

27
Total Commits
0
New Files
12
Modified Files
3
Deleted Files
15
Contributors

📝 Modified Documentation Files

Modified by omondiatieno on May 9, 2025 7:25 PM
📖 View on learn.microsoft.com
+33 / -33 lines changed
Commit: Resolve UUF issues for SaaS-apps
Changes:
Before
After
---
title: Microsoft Entra integration with FreshDesk
description: Learn how to configure single sign-on between Microsoft Entra ID and FreshDesk.
 
author: nguhiu
manager: CelesteDG
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 03/25/2025
ms.author: gideonkiratu
 
# Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and FreshDesk so that I can control who has access to FreshDesk, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.
---
# Microsoft Entra integration with FreshDesk
 
In this article, you learn how to integrate FreshDesk with Microsoft Entra ID. When you integrate FreshDesk with Microsoft Entra ID, you can:
 
* Control in Microsoft Entra ID who has access to FreshDesk.
* Enable your users to be automatically signed-in to FreshDesk with their Microsoft Entra accounts.
---
title: Microsoft Entra integration with Freshdesk
description: Learn how to configure single sign-on between Microsoft Entra ID and Freshdesk.
 
author: nguhiu
manager: CelesteDG
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 05/09/2025
ms.author: gideonkiratu
 
# Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Freshdesk so that I can control who has access to Freshdesk, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.
---
# Microsoft Entra integration with Freshdesk
 
In this article, you learn how to integrate Freshdesk with Microsoft Entra ID. When you integrate Freshdesk with Microsoft Entra ID, you can:
 
* Control in Microsoft Entra ID who has access to Freshdesk.
* Enable your users to be automatically signed-in to Freshdesk with their Microsoft Entra accounts.
Modified by omondiatieno on May 9, 2025 7:25 PM
📖 View on learn.microsoft.com
+5 / -18 lines changed
Commit: Resolve UUF issues for SaaS-apps
Changes:
Before
After
---
title: Microsoft Entra integration with Adaptive Insights
description: Learn how to configure single sign-on between Microsoft Entra ID and Adaptive Insights.
 
author: nguhiu
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 03/25/2025
ms.author: gideonkiratu
 
# Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Adaptive Insights so that I can control who has access to Adaptive Insights, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.
 
1. Sign in to your **Adaptive Insights** company site as an administrator.
 
2. Go to **Administration**.
 
![Admin](./media/adaptivesuite-tutorial/administration.png "Admin")
 
3. In the **Users and Roles** section, select **Users**.
---
title: Integrate Adaptive Insights with Microsoft Entra ID
description: Learn how to configure single sign-on between Microsoft Entra ID and Adaptive Insights.
 
author: nguhiu
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 05/09/2025
ms.author: gideonkiratu
 
# Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Adaptive Insights so that I can control who has access to Adaptive Insights, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.
 
1. Sign in to your **Adaptive Insights** company site as an administrator.
 
2. Go to **Administration** > **Users and Roles** > **Users**.
 
4. In the **New User** section, enter the details of the user you want to create. Ensure that the user names in Microsoft Entra ID match the corresponding user names in Adaptive Insights.
5. Select **Submit**.
 
+0 / -14 lines changed
Commit: Update how-to-certificate-based-authentication.md
Changes:
Before
After
 
1. Authenticate with a certificate that has policy OID of 3.4.5.6 and Issued by CN=CBATestRootProd. Authentication should pass and get a multifactor claim.
 
>[!IMPORTANT]
>There's a known issue where a Microsoft Entra tenant Authentication Policy Administrator configures a CBA authentication policy rule by using both Issuer and Policy OID. The issue impacts some device registration scenarios, including:
>- Windows Hello For Business enrollment
>- FIDO2 security key registration
>- Windows passwordless phone sign-in
>
>Device registration with Workplace Join, Microsoft Entra ID and Hybrid Microsoft Entra device join scenarios aren't impacted. CBA authentication policy rules using either Issuer OR Policy OID aren't impacted.
>To mitigate, admins should:
>- Edit the certificate-based authentication policy rules that use both Issuer and Policy OID options. Remove either the Issuer or Policy OID requirement and **Save**.
> -Or-
>- Remove the authentication policy rule that uses both Issuer and Policy OID. Create rules that use only Issuer or Policy OID.
>
>We're working to fix the issue.
 
To create a rule by Issuer and Serial Number:
 
1. Add an authentication binding policy. The policy requires that any certificate issued by CN=CBATestRootProd with policyOID 1.2.3.4.6 needs only high affinity binding. Issuer and serial number are used.
 
1. Authenticate with a certificate that has policy OID of 3.4.5.6 and Issued by CN=CBATestRootProd. Authentication should pass and get a multifactor claim.
 
To create a rule by Issuer and Serial Number:
 
1. Add an authentication binding policy. The policy requires that any certificate issued by CN=CBATestRootProd with policyOID 1.2.3.4.6 needs only high affinity binding. Issuer and serial number are used.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
+6 / -5 lines changed
Commit: Resolve UUF issues for SaaS-apps
Changes:
Before
After
---
title: Microsoft Entra integration with Palo Alto Networks Captive Portal
description: Learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks Captive Portal.
 
author: nguhiu
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 03/25/2025
ms.author: gideonkiratu
 
# Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks - Captive Portal so that I can control who has access to Palo Alto Networks - Captive Portal, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.
---
# Microsoft Entra integration with Palo Alto Networks Captive Portal
 
In this article, you learn how to integrate Palo Alto Networks Captive Portal with Microsoft Entra ID.
Integrating Palo Alto Networks Captive Portal with Microsoft Entra ID provides you with the following benefits:
4. In the **Basic SAML Configuration** pane, perform the following steps:
 
1. For **Identifier**, enter a URL that has the pattern
---
title: Integrate Palo Alto Networks Captive Portal with Microsoft Entra ID
description: Learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks Captive Portal.
 
author: nguhiu
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 05/09/2025
ms.author: gideonkiratu
 
# Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Palo Alto Networks - Captive Portal so that I can control who has access to Palo Alto Networks - Captive Portal, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.
---
 
# Integrate Palo Alto Networks Captive Portal with Microsoft Entra ID
 
In this article, you learn how to integrate Palo Alto Networks Captive Portal with Microsoft Entra ID.
Integrating Palo Alto Networks Captive Portal with Microsoft Entra ID provides you with the following benefits:
4. In the **Basic SAML Configuration** pane, perform the following steps:
 
Modified by omondiatieno on May 9, 2025 7:25 PM
📖 View on learn.microsoft.com
+2 / -8 lines changed
Commit: Resolve UUF issues for SaaS-apps
Changes:
Before
After
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 03/25/2025
ms.author: gideonkiratu
 
 
> [!NOTE]
> These values aren't real. Update these values with the actual Sign on URL and Reply URL. The Sign on URL and Reply URL can have the same value (`http://127.0.0.1:35001`). Refer to [AWS Client VPN Documentation](https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/client-authentication.html#ad) for details. You can also refer to the patterns shown in the **Basic SAML Configuration** section. Contact [AWS ClientVPN support team](https://aws.amazon.com/contact-us/) for any configuration issues.
 
1. In the Microsoft Entra service, navigate to **App registrations** and then select **All Applications**.
 
1. Type **AWS ClientVPN** in the search box and select **AWS ClientVPN** from the search panel.
 
1. Select **Manifest**. Under **replyUrlWithType**, keep the Reply URL as **http** instead of **https** to get the integration working. Select **Save**.
 
1. AWS ClientVPN application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
 
![image](common/default-attributes.png)
 
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 05/09/2025
ms.author: gideonkiratu
 
 
> [!NOTE]
> These values aren't real. Update these values with the actual Sign on URL and Reply URL. The Sign on URL and Reply URL can have the same value (`http://127.0.0.1:35001`). Refer to [AWS Client VPN Documentation](https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/client-authentication.html#ad) for details. You can also refer to the patterns shown in the **Basic SAML Configuration** section. Contact [AWS ClientVPN support team](https://aws.amazon.com/contact-us/) for any configuration issues.
 
1. AWS ClientVPN application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows the list of default attributes.
 
![image](common/default-attributes.png)
 
1. In addition to above, AWS ClientVPN application expects few more attributes to be passed back in the SAML response which are shown below. These attributes are also pre populated but you can review them as per your requirements.
| Name | Source Attribute|
| -------------- | --------- |
 
 
+3 / -4 lines changed
Commit: Make heading imperative, adjust indentation, bullet nonsequential list items
Changes:
Before
After
9. Click the folder icon to upload your **Configuration profile file**. Choose the *kerberos.mobileconfig* file you [saved previously](#Kerberos SSO MDM profile configuration for on-premises Active Directory) after customizing the template.
10. Select **Next**.
11. In **Scope tags** (optional), assign a tag to filter the profile to specific IT groups, such as `US-NC IT Team` or `JohnGlenn_ITDepartment`. Select **Next**.
- For more information about scope tags, see [Use RBAC roles and scope tags for distributed IT](/mem/intune/fundamentals/scope-tags).
12. In **Assignments**, select the users or user groups that will receive your profile. Platform SSO policies are user-based policies. Don't assign the platform SSO policy to devices.
- For more information on assigning profiles, see [Assign user and device profiles](/mem/intune/configuration/device-profile-assign).
13. Select **Next**.
 
The next time the device checks for configuration updates, the settings you configured are applied.
 
## Testing Kerberos SSO
 
Once the user has completed Platform SSO registration, you can check that the device has Kerberos tickets by running the `app-sso platform -s` command in the Terminal app:
 
 
Validate your configuration is working by testing with appropriate Kerberos-capable resources:
 
1. Test on-premises Active Directory functionality by accessing an on-premises AD-integrated file server using Finder or a web application using Safari. The user should be able to access the file share without being challenged for interactive credentials.
2. Test Microsoft Entra ID Kerberos functionality by accessing an Azure Files share enabled for Microsoft Entra ID cloud kerberos. The user should be able to access the file share without being challenged for interactive credentials. Refer to [this guide](/azure/storage/files/storage-files-identity-auth-hybrid-identities-enable) if you need to configure a cloud file share in Azure Files.
 
9. Click the folder icon to upload your **Configuration profile file**. Choose the *kerberos.mobileconfig* file you [saved previously](#Kerberos SSO MDM profile configuration for on-premises Active Directory) after customizing the template.
10. Select **Next**.
11. In **Scope tags** (optional), assign a tag to filter the profile to specific IT groups, such as `US-NC IT Team` or `JohnGlenn_ITDepartment`. Select **Next**.
- For more information about scope tags, see [Use RBAC roles and scope tags for distributed IT](/mem/intune/fundamentals/scope-tags).
12. In **Assignments**, select the users or user groups that will receive your profile. Platform SSO policies are user-based policies. Don't assign the platform SSO policy to devices.
- For more information on assigning profiles, see [Assign user and device profiles](/mem/intune/configuration/device-profile-assign).
13. Select **Next**.
 
The next time the device checks for configuration updates, the settings you configured are applied.
 
## Test Kerberos SSO
 
Once the user has completed Platform SSO registration, you can check that the device has Kerberos tickets by running the `app-sso platform -s` command in the Terminal app:
 
 
Validate your configuration is working by testing with appropriate Kerberos-capable resources:
 
- Test on-premises Active Directory functionality by accessing an on-premises AD-integrated file server using Finder or a web application using Safari. The user should be able to access the file share without being challenged for interactive credentials.- Test Microsoft Entra ID Kerberos functionality by accessing an Azure Files share enabled for Microsoft Entra ID cloud kerberos. The user should be able to access the file share without being challenged for interactive credentials. Refer to [this guide](/azure/storage/files/storage-files-identity-auth-hybrid-identities-enable) if you need to configure a cloud file share in Azure Files.
 
> [!NOTE]
Modified by Ari Crowe on May 9, 2025 3:06 AM
📖 View on learn.microsoft.com
+1 / -5 lines changed
Commit: Minor updates
Changes:
Before
After
 
### Policy behavior
 
When this setting is enabled, the secure patterns are strictly enforced. Todo - insert error message
 
Doesn't apply to v2 or SAML apps
 
Existing identifier URIs already configured on the Entra app won't be affected, and all apps will continue to function as normal. This will only affect new updates to Entra app configurations.
 
 
If you're a developer and you've received this error, check [this guidance](#guidance-for-developers).
 
### Security benefit
 
This more restrictive policy can help protect your organization from common token validation errors in the `audience` claim. We recommend enabling it if possible.
 
### Enabling and managing the policy
 
### Policy behavior
 
When this setting is enabled, the secure patterns are strictly enforced.
 
Existing identifier URIs already configured on the Entra app won't be affected, and all apps will continue to function as normal. This will only affect new updates to Entra app configurations.
 
 
If you're a developer and you've received this error, check [this guidance](#guidance-for-developers).
 
This more restrictive policy can help protect your organization from common token validation errors in the `audience` claim. We recommend enabling it if possible.
 
### Enabling and managing the policy
 
 
 
 
+4 / -1 lines changed
Commit: Update concept-certificate-based-authentication-technical-deep-dive.md
Changes:
Before
After
|IssuerAndSubject | `X509:<I>DC=com,DC=contoso,CN=CONTOSO-DC-CA<S>DC=com,DC=contoso,OU=UserAccounts,CN=mfatest` | certificateUserIds | low-affinity |
|Subject | `X509:<S>DC=com,DC=contoso,OU=UserAccounts,CN=mfatest` | certificateUserIds | low-affinity |
|SKI | `X509:<SKI>aB1cD2eF3gH4iJ5kL6-mN7oP8qR=` | certificateUserIds | high-affinity |
|SHA1PublicKey | `X509:<SHA1-PUKEY>aB1cD2eF3gH4iJ5kL6-mN7oP8qR` | certificateUserIds | high-affinity |
|IssuerAndSerialNumber | `X509:<I>DC=com,DC=contoso,CN=CONTOSO-DC-CA<SR>cD2eF3gH4iJ5kL6mN7-oP8qR9sT` <br> To get the correct value for serial number, run this command and store the value shown in CertificateUserIds:<br> **Syntax**:<br> `Certutil –dump –v [~certificate path~] >> [~dumpFile path~]` <br> **Example**: <br> `certutil -dump -v firstusercert.cer >> firstCertDump.txt` | certificateUserIds | high-affinity |
 
### Define Affinity binding at the tenant level and override with custom rules
 
With this feature an Authentication Policy Administrator can configure whether a user can be authenticated by using low-affinity or high-affinity username binding mapping. You can set **Required affinity binding** for the tenant, which applies to all users. You can also override the tenant-wide default value by creating custom rules based on Issuer and Policy OID, or Policy OID, or Issuer.
 
 
 
|IssuerAndSubject | `X509:<I>DC=com,DC=contoso,CN=CONTOSO-DC-CA<S>DC=com,DC=contoso,OU=UserAccounts,CN=mfatest` | certificateUserIds | low-affinity |
|Subject | `X509:<S>DC=com,DC=contoso,OU=UserAccounts,CN=mfatest` | certificateUserIds | low-affinity |
|SKI | `X509:<SKI>aB1cD2eF3gH4iJ5kL6-mN7oP8qR=` | certificateUserIds | high-affinity |
|SHA1PublicKey | `X509:<SHA1-PUKEY>aB1cD2eF3gH4iJ5kL6-mN7oP8qR` <br> The SHA1PublicKey value (SHA1 hash of the entire certificate content including the public key) is found in the Thumbprint property of certificate.| certificateUserIds | high-affinity |
|IssuerAndSerialNumber | `X509:<I>DC=com,DC=contoso,CN=CONTOSO-DC-CA<SR>cD2eF3gH4iJ5kL6mN7-oP8qR9sT` <br> To get the correct value for serial number, run this command and store the value shown in CertificateUserIds:<br> **Syntax**:<br> `Certutil –dump –v [~certificate path~] >> [~dumpFile path~]` <br> **Example**: <br> `certutil -dump -v firstusercert.cer >> firstCertDump.txt` | certificateUserIds | high-affinity |
 
>[!IMPORTANT]
> You can use the [CertificateBasedAuthentication PowerShell module](concept-certificate-based-authentication-certificateuserids.md#how-to-find-the-correct-certificateuserids-values-for-a-user-from-the-end-user-certificate-using-powershell-module) to find the correct CertificateUserIds values for a user from the end user certificate.
 
### Define Affinity binding at the tenant level and override with custom rules
 
With this feature an Authentication Policy Administrator can configure whether a user can be authenticated by using low-affinity or high-affinity username binding mapping. You can set **Required affinity binding** for the tenant, which applies to all users. You can also override the tenant-wide default value by creating custom rules based on Issuer and Policy OID, or Policy OID, or Issuer.
Modified by Henry Mbugua on May 9, 2025 7:51 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Confirming accuracy of msal-shared-devices.md
Changes:
Before
After
author: henrymbuguakiarie
manager: CelesteDG
ms.author: henrymbugua
ms.date: 08/27/2024
ms.reviewer: brianmel, akgoel, dmwendia
ms.service: identity-platform
 
 
To take advantage of the shared device mode feature, cloud device admins and application developers work together:
 
**Device administrators** prepare the devices to be shared by setting up the devices in shared device mode manually or via a mobile device management (MDM) provider like Microsoft Intune. The preferred option is using an MDM as it allows the device setup in shared device mode at scale via zero-touch provisioning. The MDM is configured to push the Microsoft Authenticator app to the device with shared device mode turned on. On iOS devices, MDM also enables the Microsoft Enterprise SSO plug-in that is required for shared device mode.
 
The following guides provide more details on how to set up devices in shared device mode via Intune:
 
author: henrymbuguakiarie
manager: CelesteDG
ms.author: henrymbugua
ms.date: 05/09/2025
ms.reviewer: brianmel, akgoel, dmwendia
ms.service: identity-platform
 
 
To take advantage of the shared device mode feature, cloud device admins and application developers work together:
 
**Device administrators** prepare the devices to be shared by setting up the devices in shared device mode manually or via a mobile device management (MDM) provider like Microsoft Intune. The preferred option is using an MDM as it allows the device setup in shared device mode at scale via zero-touch provisioning. The MDM is configured to push the Microsoft Authenticator app to the device with shared device mode turned on. On iOS devices, MDM also enables the Microsoft Enterprise single sign-on (SSO) plug-in that is required for shared device mode.
 
The following guides provide more details on how to set up devices in shared device mode via Intune:
 
Modified by Pratik Jadhav on May 9, 2025 11:05 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs#419721
Changes:
Before
After
## Delete an enterprise application using Microsoft Entra admin center
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Browse to **Entra ID** > **Enterprise apps** > **All applications**.
1. Enter the name of the existing application in the search box, and then select the application from the search results. In this article, we use the **Microsoft Entra SAML Toolkit 1** as an example.
1. In the **Manage** section of the left menu, select **Properties**.
1. At the top of the **Properties** pane, select **Delete**, and then select **Yes** to confirm you want to delete the application from your Microsoft Entra tenant.
## Delete an enterprise application using Microsoft Entra admin center
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Browse to **Identity** > **Applications** > **Enterprise applications** > **All applications**.
1. Enter the name of the existing application in the search box, and then select the application from the search results. In this article, we use the **Microsoft Entra SAML Toolkit 1** as an example.
1. In the **Manage** section of the left menu, select **Properties**.
1. At the top of the **Properties** pane, select **Delete**, and then select **Yes** to confirm you want to delete the application from your Microsoft Entra tenant.
+1 / -1 lines changed
Commit: added lightbox to image
Changes:
Before
After
1. Select **My Access settings for end users**.
 
1. Select **Show peer-based insights to suggested access packages in My Access**. When this setting is unchecked, users will only see suggestions based on past assignments.
:::image type="content" source="media/entitlement-management-suggested-access-packages/my-access-control-configurations.png" alt-text="Screenshot of My Access control configuration settings." lightbox="media/entitlement-management-suggested-access-packages/myaccess-control-configurations.png":::
1. Select **Save**.
 
1. Sign in to the My Access portal at https://myaccess.microsoft.com. Select **Access packages** to see your suggested access packages with peer-based insights.
1. Select **My Access settings for end users**.
 
1. Select **Show peer-based insights to suggested access packages in My Access**. When this setting is unchecked, users will only see suggestions based on past assignments.
:::image type="content" source="media/entitlement-management-suggested-access-packages/my-access-control-configurations.png" alt-text="screenshot of My Access control configurations." lightbox="media/entitlement-management-suggested-access-packages/my-access-control-configurations.png":::
1. Select **Save**.
 
1. Sign in to the My Access portal at https://myaccess.microsoft.com. Select **Access packages** to see your suggested access packages with peer-based insights.
Modified by John Flores on May 9, 2025 5:04 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update agent-optimization.md
Changes:
Before
After
 
## Prerequisites
 
- You must be assigned the [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview. These roles also have [access to Security Copilot by default](/copilot/security/authentication).
- You must have at least [Microsoft Entra ID P1](overview.md#license-requirements).
- You must have available [security compute units (SCU)](/copilot/security/manage-usage). On average, each agent run consumes less than one SCU.
- Device-based controls require [Microsoft Intune licenses](/intune/intune-service/fundamentals/licenses).
 
## Prerequisites
 
- For the initial agent enablement/setup, you will need to be either a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview. These roles also have [access to Security Copilot by default](/copilot/security/authentication). After setup, you can assign Conditional Access Administrators with Security Copilot access. This will give your Conditional Access Administrators the ability to use the agent as well.
- You must have at least [Microsoft Entra ID P1](overview.md#license-requirements).
- You must have available [security compute units (SCU)](/copilot/security/manage-usage). On average, each agent run consumes less than one SCU.
- Device-based controls require [Microsoft Intune licenses](/intune/intune-service/fundamentals/licenses).

🗑️ Deleted Documentation Files

DELETED docs/identity-platform/tutorial-v2-android.md
Deleted by Henry Mbugua on May 9, 2025 7:38 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/identity-platform/tutorial-v2-android
-1324 lines removed
Commit: Removing duplicated content
DELETED docs/identity/saas-apps/adobe-creative-cloud-tutorial.md
Deleted by omondiatieno on May 9, 2025 7:25 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/identity/saas-apps/adobe-creative-cloud-tutorial
-161 lines removed
Commit: Resolve UUF issues for SaaS-apps
DELETED docs/identity/saas-apps/kao-navi-tutorial.md
Deleted by omondiatieno on May 9, 2025 7:25 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/identity/saas-apps/kao-navi-tutorial
-123 lines removed
Commit: Resolve UUF issues for SaaS-apps