📋 Microsoft Entra Documentation Changes

Changes for May 11th 2025

Period: May 10th 2025, 12:00 AM to May 11th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 11th 2025.

📊 Summary

36
Total Commits
2
New Files
13
Modified Files
0
Deleted Files
13
Contributors

🆕 New Documentation Files

+82 lines added
Commit: Secretless authentication
Added by Justin Ploegert on May 10, 2025 4:24 AM
📖 View on learn.microsoft.com
+16 lines added
Commit: Learn Editor: Update whats-new-linux.md

📝 Modified Documentation Files

+166 / -3 lines changed
Commit: Resource providers and types that support managed identities
Changes:
Before
After
 
author: rwike77
ms.author: ryanwi
ms.date: 02/27/2025
ms.topic: conceptual
ms.service: entra-id
ms.subservice: managed-identities
 
# Azure services that can use managed identities to access other services
 
Managed identities for Azure resources provide Azure services with an automatically managed identity in Microsoft Entra ID. Using a managed identity, you can authenticate to any service that supports Microsoft Entra authentication without managing credentials. We are integrating managed identities for Azure resources and Microsoft Entra authentication across Azure. This page provides links to services' content that can use managed identities to access other Azure resources. Each entry in the table includes a link to service documentation discussing managed identities.
 
>[!IMPORTANT]
> New technical content is added daily. This list does not include every article that talks about managed identities. Please refer to each service's content set for details on their managed identities support. Resource provider namespace information is available in the article titled [Resource providers for Azure services](/azure/azure-resource-manager/management/azure-services-resource-providers).
 
## Services supporting managed identities
 
| Azure Virtual Machines | [Secure and use policies on virtual machines in Azure](/azure/virtual-machines/windows/security-policy#managed-identities-for-azure-resources) |
| Azure Web PubSub Service | [Managed identities for Azure Web PubSub Service](/azure/azure-web-pubsub/howto-use-managed-identity) |
 
 
author: rwike77
ms.author: ryanwi
ms.date: 05/09/2025
ms.topic: conceptual
ms.service: entra-id
ms.subservice: managed-identities
 
# Azure services that can use managed identities to access other services
 
Managed identities for Azure resources provide Azure services with an automatically managed identity in Microsoft Entra ID. Using a managed identity, you can authenticate to any service that supports Microsoft Entra authentication without managing credentials. We are integrating managed identities for Azure resources and Microsoft Entra authentication across Azure.
 
This page provides links to services' content that can use managed identities to access other Azure resources as well as a list of Azure resource providers and resource types that support managed identities.
 
Additional resource provider namespace information is available in [Resource providers for Azure services](/azure/azure-resource-manager/management/azure-services-resource-providers).
 
>[!IMPORTANT]
> New technical content is added daily. This list does not include every article that talks about managed identities. Please refer to each service's content set for details on their managed identities support.
 
## Services supporting managed identities
Modified by Justin Ploegert on May 10, 2025 2:37 AM
📖 View on learn.microsoft.com
+158 / -8 lines changed
Commit: Learn Editor: Update sso-linux.md
Changes:
Before
After
- Support for Bash scripts for custom compliance policies
 
 
 
The Teams web application and a new PWA(Progressive Web App) for Linux will use the Conditional Access configuration, applied through Microsoft Intune Manager, to enable Linux users to access the Teams web application using Edge in a secure way. This helps organizations use an industry-leading, unified endpoint management solution for Teams from Linux endpoints with security and quality in mind.
 
There are several authentication methods that determine the end-user experience.
 
## Requirements
 
To deploy Platform SSO for macOS, you need the meet following minimum requirements.
 
* A recommended minimum version of macOS 14 Sonoma. While macOS 13 Ventura is supported, we strongly recommend using macOS 14 Sonoma for the best experience.
* [Microsoft Authenticator](https://support.microsoft.com/account-billing/how-to-use-the-microsoft-authenticator-app-9783c865-0308-42fb-a519-8cf666fe0acc)
 
* Microsoft Intune [Company Portal app](/mem/intune/apps/apps-company-portal-macos) version 5.2404.0 or later installed. This version is required before users are targeted for PSSO.
 
## Configuration
 
You can find more information and instructions on how to configure in these articles:
- Support for Bash scripts for custom compliance policies
 
 
The Teams web application and a new PWA(Progressive Web App) for Linux will use the Conditional Access configuration, applied through Microsoft Intune Manager, to enable Linux users to access the Teams web application using Edge in a secure way. This helps organizations use an industry-leading, unified endpoint management solution for Teams from Linux endpoints with security and quality in mind.
 
There are several authentication methods that determine the end-user experience.
 
## Requirements
 
The Microsoft Single Sign-On for Linux is supported with the following operating systems:
- Ubuntu Desktop 24.04, 22.04 or 20.04 LTS (physical or Hyper-V machine with x86/64 CPUs)
- RedHat Enterprise Linux 8
- RedHat Enterprise Linux 9
 
## Configuration
 
You can find more information and instructions on how to configure in these articles:
- [Configure Platform SSO for macOS devices in Microsoft Intune](/mem/intune/configuration/platform-sso-macos)
 
## Deployment
Modified by Justin Ploegert on May 10, 2025 4:32 AM
📖 View on learn.microsoft.com
+118 / -1 lines changed
Commit: Learn Editor: Update whats-new-linux.md
Changes:
Before
After
ms.date: 05/09/2025
---
 
What's new in Microsoft Single Sign-on for Linux
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
ms.date: 05/09/2025
---
 
 
# What's new in Microsoft Single Sign-on for Linux
This article provides information about the latest updates to Microsoft Single Sign-on for Linux.
 
### Package Repositories
Microsoft uses the following package repositories to distribute the Microsoft Identity Broker and Microsoft Identity Diagnostics for Linux. Packages are avilable in either .deb or .rpm format, however only Ubuntu LTS & Red Hat Enterprise Linux are supported today.
 
:::row:::
:::column span="2":::
#### Ubuntu 20.04
- [microsoft-identity-broker](https://packages.microsoft.com/ubuntu/20.04/prod/pool/main/m/msft-identity-broker/)
 
#### Ubuntu 22.04
- [microsoft-identity-broker](https://packages.microsoft.com/ubuntu/22.04/prod/pool/main/m/)
- [microsoft-identity-diagnostics](https://packages.microsoft.com/ubuntu/22.04/prod/pool/main/m/microsoft-identity-diagnostics/)
:::column-end:::
:::column span="":::
+28 / -28 lines changed
Commit: May 9 final polish
Changes:
Before
After
# Customer intent: I want to troubleshoot the Global Secure Access client using the Advanced diagnostics utility.
---
# Troubleshoot the Global Secure Access client for Windows: Advanced diagnostics
This document provides troubleshooting guidance for the Global Secure Access client for Windows. It explores each tab of the Advanced diagnostics utility.
 
## Introduction
The Global Secure Access client runs in the background and routes relevant network traffic to Global Secure Access. It doesn't require user interaction. The advanced diagnostics tool makes the client's behavior visible to the administrator and helps with troubleshooting.
 
## Launch the advanced diagnostics tool
To launch the advanced diagnostics tool:
1. Right-click the **Global Secure Access client** icon in the system tray.
1. Select **Advanced Diagnostics**. If enabled, User Account Control (UAC) prompts for elevation of privileges.
 
## Overview tab
The advanced diagnostics **Overview** tab shows general configuration details about the Global Secure Access client:
- **Username**: The Microsoft Entra user principal name of the user who authenticated to the client.
- **Device ID**: The ID of the device in Microsoft Entra. The device must be joined to the tenant.
- **Tenant ID**: The ID of the tenant that the client points to, which is the same tenant the device is joined to.
- **Forwarding Profile ID**: The ID of the forwarding profile currently in use by the client.
- **Forwarding Profile last checked**: The time when the client last checked for an updated forwarding profile.
# Customer intent: I want to troubleshoot the Global Secure Access client using the Advanced diagnostics utility.
---
# Troubleshoot the Global Secure Access client for Windows: Advanced diagnostics
This article provides troubleshooting guidance for the Global Secure Access client for Windows. It explores each tab of the Advanced diagnostics utility.
 
## Introduction
The Global Secure Access client runs in the background, routing relevant network traffic to Global Secure Access without requiring user interaction. Use the advanced diagnostics tool to gain visibility into the client's behavior and troubleshoot issues effectively.
 
## Launch the advanced diagnostics tool
To launch the advanced diagnostics tool:
1. Right-click the **Global Secure Access client** icon in the system tray.
1. Select **Advanced Diagnostics**. If enabled, User Account Control (UAC) prompts you to elevate privileges.
 
## Overview tab
The advanced diagnostics **Overview** tab shows general configuration details for the Global Secure Access client:
- **Username**: The Microsoft Entra user principal name of the user who authenticated to the client.
- **Device ID**: The ID of the device in Microsoft Entra. The device must be joined to the tenant.
- **Tenant ID**: The ID of the tenant that the client points to, which is the same tenant the device is joined to.
- **Forwarding Profile ID**: The ID of the forwarding profile currently in use by the client.
- **Forwarding Profile last checked**: The time the client last checked for an updated forwarding profile.
Modified by Ryan Wike on May 10, 2025 5:54 AM
📖 View on learn.microsoft.com
+13 / -13 lines changed
Commit: freshness updates
Changes:
Before
After
---
# Configurable token lifetimes in the Microsoft identity platform (preview)
 
You can configure the lifetime of access, ID, or SAML tokens issued by the Microsoft identity platform. Token lifetimes can be set for all apps in your organization, multitenant applications, or specific service principals. Note that configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) is not supported.
 
In Microsoft Entra ID, policies define rules applied to individual applications or all applications in an organization. Each policy type has unique properties that determine how it is enforced on the object to which it's assigned.
 
For practical guidance, see [examples of how to configure token lifetimes](configure-token-lifetimes.yml).
 
> [!NOTE]
> Configurable token lifetime policy only applies to mobile and desktop clients that access SharePoint Online and OneDrive for Business resources, and does not apply to web browser sessions.
> To manage the lifetime of web browser sessions for SharePoint Online and OneDrive for Business, use the [Conditional Access session lifetime](~/identity/conditional-access/howto-conditional-access-session-lifetime.md) feature. Refer to the [SharePoint Online blog](https://techcommunity.microsoft.com/t5/SharePoint-Blog/Introducing-Idle-Session-Timeout-in-SharePoint-and-OneDrive/ba-p/119208) to learn more about configuring idle session timeouts.
 
> [!NOTE]
> You might want to increase the token lifetime so that a script will run for more than an hour. Many Microsoft libraries, such as Microsoft Graph PowerShell SDK, extend the token lifetime as needed and you don't need to makes changes to the access token policy.
 
## License requirements
 
 
### Access tokens
---
# Configurable token lifetimes in the Microsoft identity platform (preview)
 
You can configure the lifetime of access, ID, or Security Assertion Markup Language (SAML) tokens issued by the Microsoft identity platform. Token lifetimes can be set for all apps in your organization, multitenant applications, or specific service principals. Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.
 
In Microsoft Entra ID, policies define rules applied to individual applications or all applications in an organization. Each policy type has unique properties that determine how it is enforced on the object to which it's assigned.
 
For practical guidance, see [examples of how to configure token lifetimes](configure-token-lifetimes.yml).
 
> [!NOTE]
> Configurable token lifetime policy only applies to mobile and desktop clients that access SharePoint Online and OneDrive for Business resources, and doesn't apply to web browser sessions.
> To manage the lifetime of web browser sessions for SharePoint Online and OneDrive for Business, use the [Conditional Access session lifetime](~/identity/conditional-access/howto-conditional-access-session-lifetime.md) feature. Refer to the [SharePoint Online blog](https://techcommunity.microsoft.com/t5/SharePoint-Blog/Introducing-Idle-Session-Timeout-in-SharePoint-and-OneDrive/ba-p/119208) to learn more about configuring idle session time-outs.
 
> [!NOTE]
> You might want to increase the token lifetime so that a script runs for more than an hour. Many Microsoft libraries, such as Microsoft Graph PowerShell SDK, extend the token lifetime as needed and you don't need to makes changes to the access token policy.
 
## License requirements
 
 
### Access tokens
Modified by Ryan Wike on May 10, 2025 5:54 AM
📖 View on learn.microsoft.com
+7 / -9 lines changed
Commit: freshness updates
Changes:
Before
After
---
title: Workload identity federation
description: Use workload identity federation to grant workloads running outside of Azure access to Microsoft Entra protected resources without using secrets or certificates. This eliminates the need for developers to store and maintain long-lived secrets or certificates outside of Azure.
 
author: rwike77
manager: CelesteDG
 
ms.service: entra-workload-id
 
ms.topic: concept-article
ms.date: 04/26/2024
ms.author: ryanwi
ms.reviewer: ludwicknick
ms.custom: aaddev
#Customer intent: As a developer, I want to learn about workload identity federation so that I can securely access Microsoft Entra protected resources from external apps and services without needing to manage secrets.
---
 
# Workload identity federation
This article provides an overview of workload identity federation for software workloads. Using workload identity federation allows you to access Microsoft Entra protected resources without needing to manage secrets (for supported scenarios).
 
---
title: Workload Identity Federation
description: Learn how workload identify federation enables secre access to Microsoft Entra protected resources from external software workloads without managing secrets.
 
author: rwike77
manager: CelesteDG
ms.service: entra-workload-id
ms.topic: concept-article
ms.date: 04/09/2025
ms.author: ryanwi
ms.reviewer: hosamsh
ms.custom: aaddev
#Customer intent: As a developer, I want to learn about workload identity federation so that I can securely access Microsoft Entra protected resources from external apps and services without needing to manage secrets.
---
 
# Workload identity federation concepts
Learn how workload identity federation enables secure access to Microsoft Entra protected resources without managing secrets. This article provides an overview of its benefits and supported scenarios.
 
You can use workload identity federation in scenarios such as GitHub Actions, workloads running on Kubernetes, or workloads running in compute platforms outside of Azure.
 
+6 / -6 lines changed
Commit: typo
Changes:
Before
After
---
title: secretles authentication in Azure
description:
 
author: rwike77
ms.author: ryanwi
 
 
#Customer intent: As a Azure developer or IT admin, I'd like learn about secretles authentication in Azure so I can securely access Azure resources without managing or storing passwords or secrets.
---
 
# Secretles authentication to Azure resources
secretles = This is a broader term that encompasses both passwordless and keyless. You often store a password or a key outside of the source-controlled directory as a secret. Key Vault Secrets and environment variables are 2 common approaches I see customers use to store those items. Once you move away from that secrets storage practice, you’ve transitioned to secretles authN.
 
Sub-scenarios/implementations of secretles:
• Passwordless = Use this term when the alternative authN mechanism is a username/password combination.
• Keyless = Use this term when the alternative authN mechanism is a key. Examples of keys are:
- The access key authN mechanism that Azure Communication Services supports.
 
[Managed identities](/entra/identity/managed-identities-azure-resources/overview) and the `DefaultAzureCredential` class in the Azure Identity client library are the recommended authentication option for secure, passwordless connections between Azure resources.
---
title: Secretless authentication in Azure
description:
 
author: rwike77
ms.author: ryanwi
 
 
#Customer intent: As a Azure developer or IT admin, I'd like learn about secretless authentication in Azure so I can securely access Azure resources without managing or storing passwords or secrets.
---
 
# Secretless authentication to Azure resources
secretless = This is a broader term that encompasses both passwordless and keyless. You often store a password or a key outside of the source-controlled directory as a secret. Key Vault Secrets and environment variables are 2 common approaches I see customers use to store those items. Once you move away from that secrets storage practice, you’ve transitioned to secretless authN.
 
Sub-scenarios/implementations of secretless:
• Passwordless = Use this term when the alternative authN mechanism is a username/password combination.
• Keyless = Use this term when the alternative authN mechanism is a key. Examples of keys are:
- The access key authN mechanism that Azure Communication Services supports.
 
[Managed identities](/entra/identity/managed-identities-azure-resources/overview) and the `DefaultAzureCredential` class in the Azure Identity client library are the recommended authentication option for secure, passwordless connections between Azure resources.
Modified by Dennis Rea on May 10, 2025 2:48 AM
📖 View on learn.microsoft.com
+3 / -3 lines changed
Commit: Acrolinx fix, bullet single step
Changes:
Before
After
1. **Create a Microsoft Entra test user** - to test Microsoft Entra single sign-on with Britta Simon.
1. **Assign the Microsoft Entra test user** - to enable Britta Simon to use Microsoft Entra single sign-on.
1. **[Configure Freshdesk SSO](#configure-freshdesk-sso)** - to configure the Single Sign-On settings on application side.
1. **[Create Freshdesk test user](#create-freshdesk-test-user)** - to have a counterpart of Britta Simon in Freshdesk that's linked to the Microsoft Entra representation of user.
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
 
<a name='configure-azure-ad-sso'></a>
 
## Configure Freshdesk SSO
 
1. In a different web browser window, log into your Freshdesk company site as an administrator.
 
1. Select the **Security icon** and in the **Security** section, perform the following steps:
 
 
## Create Freshdesk test user
 
In order to enable Microsoft Entra users to log into Freshdesk, they must be provisioned into Freshdesk.
In the case of Freshdesk, provisioning is a manual task.
 
1. **Create a Microsoft Entra test user** - to test Microsoft Entra single sign-on with Britta Simon.
1. **Assign the Microsoft Entra test user** - to enable Britta Simon to use Microsoft Entra single sign-on.
1. **[Configure Freshdesk SSO](#configure-freshdesk-sso)** - to configure the Single Sign-On settings on application side.
- **[Create Freshdesk test user](#create-freshdesk-test-user)** - to have a counterpart of Britta Simon in Freshdesk that's linked to the Microsoft Entra representation of user.
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
 
<a name='configure-azure-ad-sso'></a>
 
## Configure Freshdesk SSO
 
1. In a different web browser window, log in to your Freshdesk company site as an administrator.
 
1. Select the **Security icon** and in the **Security** section, perform the following steps:
 
 
## Create Freshdesk test user
 
In order to enable Microsoft Entra users to log in to Freshdesk, they must be provisioned into Freshdesk.
In the case of Freshdesk, provisioning is a manual task.
 
Modified by Michele Martin on May 10, 2025 1:56 AM
📖 View on learn.microsoft.com
+4 / -1 lines changed
Commit: free trials temporarily unavailable
Changes:
Before
After
ms.subservice: external
ms.topic: quickstart
ms.date: 05/07/2025
ms.author: cmulligan
ms.custom: it-pro
 
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
Get started with Microsoft External ID for consumer and business customer apps, which lets you create secure, customized sign-in experiences for your apps and services. With these built-in external configuration features, Microsoft Entra External ID can serve as the identity provider and access management service for your customers.
 
Microsoft Entra External ID is now generally available. To get started, you have two options:
 
 
 
ms.subservice: external
ms.topic: quickstart
ms.date: 05/09/2025
ms.author: cmulligan
ms.custom: it-pro
 
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
> [!IMPORTANT]
> Free trial registrations are currently unavailable.
 
Get started with Microsoft External ID for consumer and business customer apps, which lets you create secure, customized sign-in experiences for your apps and services. With these built-in external configuration features, Microsoft Entra External ID can serve as the identity provider and access management service for your customers.
 
Microsoft Entra External ID is now generally available. To get started, you have two options:
+2 / -2 lines changed
Commit: Update concept-remote-network-connectivity.md
Changes:
Before
After
ms.author: kenwith
manager: femila
ms.topic: conceptual
ms.date: 04/09/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
- Minimum number of licenses to use remote network connectivity feature is 50.
- The number of licenses is equal to the total number of licenses purchased (Entra ID P1 + Entra Internet Access /Entra Suite). After 10,000 licenses you get an additional 500 Mbps for every 500 licenses purchased (example 11,000 licenses = 36,000 Mbps).
- Organizations crossing the 10,000-license mark often operate at an enterprise scale requiring more robust infrastructure. The jump to 35,000 Mbps ensures ample capacity to meet the demands of such deployments, supporting higher traffic volumes and providing the flexibility to expand bandwidth allocations as needed.
- If more bandwidth is required, additional bandwidth will be available for purchase in increments of 500 Mbps via the Remote Network Bandwidth SKU.
 
 
#### Examples of Allocated Bandwidth per tenant:
ms.author: kenwith
manager: femila
ms.topic: conceptual
ms.date: 05/09/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
- Minimum number of licenses to use remote network connectivity feature is 50.
- The number of licenses is equal to the total number of licenses purchased (Entra ID P1 + Entra Internet Access /Entra Suite). After 10,000 licenses you get an additional 500 Mbps for every 500 licenses purchased (example 11,000 licenses = 36,000 Mbps).
- Organizations crossing the 10,000-license mark often operate at an enterprise scale requiring more robust infrastructure. The jump to 35,000 Mbps ensures ample capacity to meet the demands of such deployments, supporting higher traffic volumes and providing the flexibility to expand bandwidth allocations as needed.
- If more bandwidth is required, additional bandwidth is available for purchase in increments of 500 Mbps via the Remote Network Bandwidth SKU.
 
 
#### Examples of Allocated Bandwidth per tenant:
Modified by Ortagus Winfrey on May 10, 2025 7:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updates
Changes:
Before
After
ms.service: entra-id
ms.subservice: devices
ms.topic: overview
ms.date: 02/26/2024
 
ms.author: owinfrey
author: owinfreyATL
ms.service: entra-id
ms.subservice: devices
ms.topic: overview
ms.date: 05/09/2025
 
ms.author: owinfrey
author: owinfreyATL
Modified by Ortagus Winfrey on May 10, 2025 7:24 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Acrolinx fixes for AI readiness
Changes:
Before
After
ms.service: entra-id
ms.subservice: devices
ms.topic: conceptual
ms.date: 02/26/2024
 
ms.author: owinfrey
author: owinfreyATL
ms.service: entra-id
ms.subservice: devices
ms.topic: conceptual
ms.date: 05/09/2025
 
ms.author: owinfrey
author: owinfreyATL
+1 / -1 lines changed
Commit: Update concept-conditional-access-report-only.md
Changes:
Before
After
- Sign-in logs
- Policy impact (Preview)
 
### Policy impact (Preview)
 
The policy impact view of Conditional Access lets admins with at least the Security Reader role see a snapshot of information about the potential or existing impacts of policies on interactive sign-ins in your organization. This functionality lets you explore impact over a period of the past 24 hours, 7 days, or 1 month. Additionally, you can see and link to a sampling of sign-in events for further detail.
 
- Sign-in logs
- Policy impact (Preview)
 
### Policy impact
 
The policy impact view of Conditional Access lets admins with at least the Security Reader role see a snapshot of information about the potential or existing impacts of policies on interactive sign-ins in your organization. This functionality lets you explore impact over a period of the past 24 hours, 7 days, or 1 month. Additionally, you can see and link to a sampling of sign-in events for further detail.