๐Ÿ“‹ Microsoft Entra Documentation Changes

Changes for May 15th 2025

Period: May 14th 2025, 12:00 AM to May 15th 2025, 12:00 AM

๐Ÿ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 15th 2025.

๐Ÿ“Š Summary

41
Total Commits
1
New Files
34
Modified Files
2
Deleted Files
16
Contributors

๐Ÿ†• New Documentation Files

Added by Ortagus Winfrey on May 14, 2025 9:47 AM
๐Ÿ“– View on learn.microsoft.com
+111 lines added
Commit: Using Entitlement Management and Global Secure Access to restrict employee access to cloud apps

๐Ÿ“ Modified Documentation Files

+83 / -50 lines changed
Commit: edit pass: articles-about-tenant-restrictions
Changes:
Before
After
---
title: Global Secure Access and Universal Tenant Restrictions
description: Learn about how Global Secure Access secures access to your corporate network by restricting access to external tenants.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 02/21/2025
---
# Universal tenant restrictions
 
Universal tenant restrictions enhance the functionality of [tenant restriction v2](https://aka.ms/tenant-restrictions-enforcement) using Global Secure Access to tag all traffic no matter the operating system, browser, or device form factor. It allows support for both client and remote network connectivity. Administrators no longer have to manage proxy server configurations or complex network configurations and can apply TRv2 on any platform with the Global Secure Access client or via the Remote Networks feature.
 
When enabled, Global Secure Access adds Tenant Restrictions v2 policy information to the authentication plane network traffic, which includes Microsoft Entra ID traffic and Microsoft Graph. As the result, users using devices and networks in your organization must only use authorized external tenants, which helps prevent data exfiltration for any application integrated with SSO with your Microsoft Entra ID tenant.
 
:::image type="content" source="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png" alt-text="Diagram showing how tenant restrictions v2 protects against malicious users." lightbox="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png":::
 
The following table explains the steps taken at each point in the previous diagram.
 
| Step | Description |
| --- | --- |
| **1** | Contoso configures a **tenant restrictions v2 ** policy in their cross-tenant access settings to block all external accounts and external apps. Contoso enforces the policy using Global Secure Access universal tenant restrictions. |
---
title: Global Secure Access and Universal Tenant Restrictions
description: Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 02/21/2025
---
# Universal tenant restrictions
 
Universal tenant restrictions enhance the functionality of [tenant restrictions v2](https://aka.ms/tenant-restrictions-enforcement). They use Global Secure Access to tag all traffic no matter the operating system, browser, or device form factor. They allow support for both client and remote network connectivity.
 
Administrators no longer have to manage proxy server configurations or complex network configurations. They can apply tenant restrictions v2 on any platform by using the Global Secure Access client or remote networks.
 
When you enable Universal tenant restrictions, Global Secure Access adds policy information for tenant restrictions v2 to the authentication plane's network traffic. This traffic is from Microsoft Entra ID traffic and Microsoft Graph. As a result, users who use devices and networks in your organization must use only authorized external tenants. This restriction helps prevent data exfiltration for any application integrated with single sign-on (SSO) with your Microsoft Entra ID tenant.
 
:::image type="content" source="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png" alt-text="Diagram that shows how tenant restrictions v2 protects against malicious users." lightbox="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png":::
 
The following table explains the steps taken at each point in the previous diagram.
 
| Step | Description |
+8 / -14 lines changed
Commit: reverted to 156
Changes:
Before
After
 
| Enforce attestation set to Yes | Enforce attestation set to No |
|--------------------------------|-------------------------------|
|It must provide a valid *packed* attestation statement and a complete certificate that chains back to the attestation roots extracted from the FIDO Alliance MDS, so that Microsoft can validate the key's metadata.|It must provide a valid *packed* attestation statement (but Microsoft will ignore attestation verification results) and a complete certificate (which doesnโ€™t need to be associated with a particular certificate chain). |
 
>[!NOTE]
>Vendors are responsible to publish all root attestation certificates to the FIDO Alliance MDS; otherwise, attestation verification can fail.
 
## FIDO2 security keys eligible for attestation with Microsoft Entra ID
 
The following table includes each FIDO2 security key model listed in MDS version 163 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
 
Description|AAGUID|Bio|USB|NFC|BLE
-----------|------|---|---|---|---
Cryptnox FIDO2|9c835346-796b-4c27-8898-d6032f515cc5|❌|❌|✅|❌
Cryptnox FIDO2.1|1d1b4e33-76a1-47fb-97a0-14b10d0933f1|❌|❌|✅|❌
Dapple Authenticator from Dapple Security Inc.|6dae43be-af9c-417b-8b9f-1b611168ec60|❌|❌|❌|❌
Deepnet SafeKey/Classic (NFC)|b12eac35-586c-4809-a4b1-d81af6c305cf|❌|❌|❌|❌
Deepnet SafeKey/Classic (USB)|b9f6b7b6-f929-4189-bca9-dd951240c132|❌|❌|❌|❌
 
| Enforce attestation set to Yes | Enforce attestation set to No |
|--------------------------------|-------------------------------|
|It must provide a valid *packed* attestation statement and a complete certificate that chains back to the attestation roots extracted from the FIDO Alliance MDS, so that Microsoft can validate the key's metadata.|It must provide a valid *packed* attestation statement (but Microsoft will ignore attestation verification results) and a complete certificate (which doesn't need to be associated with a particular certificate chain). |
 
>[!NOTE]
>Vendors are responsible to publish all root attestation certificates to the FIDO Alliance MDS; otherwise, attestation verification can fail.
 
## FIDO2 security keys eligible for attestation with Microsoft Entra ID
 
The following table includes each FIDO2 security key model listed in MDS version 156 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
Description|AAGUID|Bio|USB|NFC|BLE
-----------|------|---|---|---|---
Cryptnox FIDO2|9c835346-796b-4c27-8898-d6032f515cc5|❌|❌|✅|❌
Cryptnox FIDO2.1|1d1b4e33-76a1-47fb-97a0-14b10d0933f1|❌|❌|✅|❌
Dapple Authenticator from Dapple Security Inc.|6dae43be-af9c-417b-8b9f-1b611168ec60|❌|❌|❌|❌
Deepnet SafeKey/Classic (USB)|b9f6b7b6-f929-4189-bca9-dd951240c132|❌|❌|❌|❌
Egomet FIDO2 Authenticator for Android|1105e4ed-af1d-02ff-ffff-ffffffffffff|✅|❌|❌|❌
ellipticSecure MIRkey USB Authenticator|eb3b131e-59dc-536a-d176-cb7306da10f5|❌|✅|❌|❌
+15 / -1 lines changed
Commit: MEEID single-sign-on update
Changes:
Before
After
ms.subservice: external
ms.topic: concept-article
ms.date: 04/03/2025
ms.author: mimart
ms.custom: it-pro, seo-july-2024
 
|**Custom claims provider**| [Custom authentication extension](~/identity-platform/custom-extension-overview.md) that calls an external REST API, to fetch claims from external systems. | Same as workforce. [Learn more](../../identity-platform/custom-claims-provider-overview.md)|
|**Security groups**| [Configure groups optional claims](../../identity-platform/optional-claims.md#configure-groups-optional-claims). |[Configure groups optional claims](../../identity-platform/optional-claims.md#configure-groups-optional-claims) are limited to the group object ID.|
| **Token lifetimes**| You can [specify the lifetime](../../identity-platform/configurable-token-lifetimes.md) of security tokens issued by the Microsoft Entra ID.| Same as workforce.|
 
## Microsoft Graph APIs
 
 
 
 
 
 
 
 
ms.subservice: external
ms.topic: concept-article
ms.date: 05/14/2025
ms.author: mimart
ms.custom: it-pro, seo-july-2024
 
|**Custom claims provider**| [Custom authentication extension](~/identity-platform/custom-extension-overview.md) that calls an external REST API, to fetch claims from external systems. | Same as workforce. [Learn more](../../identity-platform/custom-claims-provider-overview.md)|
|**Security groups**| [Configure groups optional claims](../../identity-platform/optional-claims.md#configure-groups-optional-claims). |[Configure groups optional claims](../../identity-platform/optional-claims.md#configure-groups-optional-claims) are limited to the group object ID.|
| **Token lifetimes**| You can [specify the lifetime](../../identity-platform/configurable-token-lifetimes.md) of security tokens issued by the Microsoft Entra ID.| Same as workforce.|
| **Session and token revocation** | Yes, administrator can [invalidate all the refresh tokens and session](/graph/api/user-revokesigninsessions) for a user. | Same as workforce.|
 
## Single sign-on
 
[Single sign-on (SSO)](../../identity-platform/msal-js-sso.md) provides a more seamless experience by reducing the number of times a user is asked for credentials. Users enter their credentials once, and the established session can be reused by other applications on the same device and web browser without further prompting. The following table compares the features available for SSO in each type of tenant.
 
|Feature |Workforce tenant | External tenant |
|---------|---------|---------|
| **Types of application registration** | <ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li><li>Enterprise applications offer [more options](../../identity/enterprise-apps/plan-sso-deployment.md), like password-based, linked, and header-based.</li></ul> |<ul><li>OpenID Connect</li> <li>OAuth 2.0</li> <li>SAML (enterprise application)</li></ul>|
| **Domain name** | When a user authenticates, a session cookie is set on the Microsoft Entra domain `login.microsoftonline.com` in the web browser.| When a user authenticates, a session cookie is set on the Microsoft Entra external ID domain `<tenant-name>.ciamlogin.com` or a [custom URL domain](concept-custom-url-domain.md) in the web browser. To ensure SSO functions correctly, use a single URL domain.|
Modified by Ed McKillop on May 14, 2025 1:15 AM
๐Ÿ“– View on learn.microsoft.com
+6 / -6 lines changed
Commit: Update locate-integration-partners.md
Changes:
Before
After
# Microsoft Entra Suite services and integration partners
Partners can help your organization with the planning and deployment of [Microsoft Entra](../fundamentals/what-is-entra.md) scenarios in the Microsoft Entra Suite. This includes:
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
* [Microsoft Global Secure Access](../global-secure-access/overview-what-is-global-secure-access.md)
|---|---|
|Accenture|Accenture's Microsoft Entra Suite offering is distinguished by its exceptional global delivery capabilities, advanced technical expertise, and proven proficiency. As Microsoft's 19-time Global Systems Integrator Partner of the Year award recipient, Accenture provides state-of-the-art solutions and seamless integration, positioning itself as the foremost partner for all enterprise requirements. |
|[Armis](https://www.armisgroup.com/services/it-services/security-and-identity/identity/)|Armis, applying over 20 years of digital transformation expertise, provides global tech solutions as a trusted Microsoft partner.โ€ฏWe specialize in security, data and AI, also business applications, delivering innovative solutions that boost efficiency and sustainable growth. By using the comprehensive capabilities of the Microsoft Entra Suite, Armis supports businesses in adopting Zero Trust principles. This effort fortifies their security posture and enabling a resilient, future-ready infrastructure. |
|[Ascent Solutions](https://www.meetascent.com/services/cybersecurity/identity-management)|Ascent Solutions accelerates secure Microsoft Entra adoption by combining deep identity expertise with tailored deployment, governance, and protection services. We optimize Microsoft Entra to enable secure single sign-on (SSO), Microsoft Entra multifactor authentication (MFA), and Microsoft Entra Conditional Access, while aligning identity governance with compliance goals. Ascent empowers organizations to reduce risk, simplify access, and fully enable their Microsoft investment. |
|[Atea](https://www.atea.se/eshop/campaigns/microsoft-entra-suite)|Atea is the largest Microsoft partner in the Nordic and Baltic regions. We are specialized in providing our customers with professional services around Microsoft Entra. With our license specialists and certified experts, we make sure that our customers get the full value out of the components in the Microsoft Entra Suite. |
|[Avande](https://www.avanade.com/en/services/microsoft-tech/microsoft-security/advanced-identity)|Avanade's asset-driven approach to the Microsoft Entra Suite harnesses a robust Microsoft Entra ID Governance content library, complete with repeatable lifecycle workflows, and advanced assets for Microsoft Entra Verified ID. It also features accelerated methodologies for Security Service Edge (SSE), streamlining adoption and migration from legacy solutions. This distinctive strategy boosts security, improves operational efficiency, and speeds up transformation. |
|[baseVISION AG](https://www.basevision.ch/our-solutions/identity-management-solutions/)|baseVISION is a leading Microsoft Security Partner focused on secure and modern endpoint management. Our Microsoft Entra ID Governance services enable companies to transform their identity and access management (IAM) processes around the globe, in a more efficient and modern way, and at an enterprise scale. We combine exceptional knowledge with practical experience, thanks to our focused company strategy and partnership with Microsoft. |
|[Paramount](https://paramountassure.com/microsoft-entra/)|Paramount Computer Systems is a cybersecurity leader in the Middle East geography, backed by over 20 years of expertise in identity and access management (IAM). Paramount partners strategically with Microsoft for advanced identity solutions such as Paramount Identity 360, powered by the Microsoft Entra Suite. Our IAM subject-matter experts implemented successful identity governance, access management, access recertification, verified identity, and global secure access. This work was for enterprises, small, medium, corporate (SMC), and small-to-medium business (SMB) customers. Our team excels at custom development, and integrating complex legacy environments, ensuring a seamless identity modernization journey. |
|[Protiviti](https://www.protiviti.com/us-en/microsoft-consulting-solutions)|Protiviti offers innovative solutions to modernize digital identity management through the powerful capabilities of the Microsoft Entra Suite. Our tailored solutions empower your identity modernization journey transitioning on-premises identities, applications, authentication, and devices to Microsoft Entra. We apply robust access security and governance through cutting-edge technologies such as risk-based Microsoft Entra Conditional Access and Microsoft Global Secure Access. |
|[PwC](https://www.pwc.com/us/en/technology/alliances/microsoft/cybersecurity.html)|PwC's differentiated approach tailors delivery by using custom accelerators for strategic planning, deployment, and managed services to enhance identity security and support Zero Trust frameworks. We offer end-to-end strategic and technical services to implement the Microsoft Entra Suite. The offering encompasses Microsoft Entra ID Protection, Microsoft Entra ID Governance, Microsoft Entra Verified ID, workloads, and Security Service Edge (SSE).|
|[Quorum](https://quorumsystems.com.au/our-capabilities/modern-work/microsoft-entra/)|Quorum is a highly specialized Microsoft partner working across the Australia and New Zealand regions. Quorum has deep Microsoft expertise across the Microsoft Entra Suite, including Microsoft Entra ID Protection, Microsoft Entra ID Governance, Microsoft Global Secure Access, and Microsoft Entra Verified ID. We enable organizations to thrive through technology with exceptional people making the complicated simple. |
|[Ravenswood Technology Group](https://www.ravenswoodtechnology.com/microsoft-technologies/identity-and-access-solutions/microsoft-entra-suite-overview/)|Ravenswood brings decades of identity expertise to your initiative. Our team excels at integrating complex enterprise systems, both on premises, and in the cloud. Ravenswood helps organizations around the world, including some of the most recognized brand names, tackle challenging identity, security, and compliance challenges. |
|[SB Technology Corp.](https://www.softbanktech.co.jp/service/list/microsoft365/e5-security)|Integrating Entra Suite via SB Technology's service provides a robust security framework, protecting against sophisticated cyber threats. Key features include multi-factor authentication (MFA), identity protection, and risk-based conditional access, ensuring comprehensive security management tailored to your organization's needs. |
# Microsoft Entra Suite services and integration partners
Partners can help your organization with planning and deployment of [Microsoft Entra](../fundamentals/what-is-entra.md) scenarios in the Microsoft Entra Suite, including:
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
* [Microsoft Global Secure Access](../global-secure-access/overview-what-is-global-secure-access.md)
|---|---|
|Accenture|Accenture's Microsoft Entra Suite offering is distinguished by its exceptional global delivery capabilities, advanced technical expertise, and proven proficiency. As Microsoft's 19-time Global Systems Integrator Partner of the Year award recipient, Accenture provides state-of-the-art solutions and seamless integration, positioning itself as the foremost partner for all enterprise requirements. |
|[Armis](https://www.armisgroup.com/services/it-services/security-and-identity/identity/)|Armis, applying over 20 years of digital transformation expertise, provides global tech solutions as a trusted Microsoft partner.โ€ฏWe specialize in security, data and AI, also business applications, delivering innovative solutions that boost efficiency and sustainable growth. By using the comprehensive capabilities of the Microsoft Entra Suite, Armis supports businesses in adopting Zero Trust principles. This effort fortifies their security posture and enabling a resilient, future-ready infrastructure. |
|[Ascent Solutions](https://www.meetascent.com/services/cybersecurity/identity-management)|Ascent Solutions accelerates secure Microsoft Entra adoption by combining deep identity expertise with tailored deployment, governance, and protection services. We optimize Microsoft Entra to enable secure single sign-on (SSO), Microsoft Entra multi-factor authentication (MFA), and Microsoft Entra Conditional Access, while aligning identity governance with compliance goals. Ascent empowers organizations to reduce risk, simplify access, and fully enable their Microsoft investment. |
|[Atea](https://www.atea.se/eshop/campaigns/microsoft-entra-suite)|Atea is the largest Microsoft partner in the Nordic and Baltic regions. We are specialized in providing our customers with professional services around Microsoft Entra. With our license specialists and certified experts, we make sure that our customers get the full value out of the components in the Microsoft Entra Suite. |
|[Avande](https://www.avanade.com/en/services/microsoft-tech/microsoft-security/advanced-identity)|Avanade's asset-driven approach to the Microsoft Entra Suite harnesses a robust Microsoft Entra ID Governance content library, complete with repeatable lifecycle workflows, and advanced assets for Microsoft Entra Verified ID. It also features accelerated methodologies for Security Service Edge (SSE), streamlining adoption and migration from legacy solutions. This distinctive strategy boosts security, improves operational efficiency, and speeds up transformation. |
|[baseVISION AG](https://www.basevision.ch/our-solutions/identity-management-solutions/)|baseVISION is a leading Microsoft Security Partner focused on secure and modern endpoint management. Our Microsoft Entra ID Governance services enable companies to transform their identity and access management (IAM) processes around the globe, in a more efficient and modern way, and at an enterprise scale. We combine exceptional knowledge with practical experience, thanks to our focused company strategy and partnership with Microsoft. |
|[Paramount](https://paramountassure.com/microsoft-entra/)|Paramount Computer Systems is a cybersecurity leader in the Middle East geography, backed by over 20 years of expertise in identity and access management (IAM). Paramount partners strategically with Microsoft for advanced identity solutions such as Paramount Identity 360, powered by the Microsoft Entra Suite. Our IAM subject-matter experts implemented successful identity governance, access management, access recertification, verified identity, and global secure access. This work was for enterprises, small, medium, corporate (SMC), and small-to-medium business (SMB) customers. Our team excels at custom development, and integrating complex legacy environments, ensuring a seamless identity modernization journey. |
|[Protiviti](https://www.protiviti.com/us-en/microsoft-consulting-solutions)|Protiviti offers innovative solutions to modernize digital identity management through the powerful capabilities of the Microsoft Entra Suite. Our tailored solutions empower your identity modernization journey transitioning on-premises identities, applications, authentication, and devices to Microsoft Entra. We apply robust access security and governance through cutting-edge technologies such as risk-based Microsoft Entra Conditional Access and Microsoft Global Secure Access. |
|[PwC](https://www.pwc.com/us/en/technology/alliances/microsoft/cybersecurity.html)|PwC's differentiated approach tailors delivery by using custom accelerators for strategic planning, deployment, and managed services to enhance identity security and support Zero Trust frameworks. We offer end-to-end strategic and technical services to implement the Microsoft Entra Suite. The offering encompasses Microsoft Entra ID Protection, Microsoft Entra ID Governance, Microsoft Entra Verified ID, workloads, and Security Service Edge (SSE).|
|[Quorum](https://quorumsystems.com.au/our-capabilities/modern-work/microsoft-entra/)|Quorum is a highly specialized Microsoft partner working across the Australia and New Zealand regions. Quorum has deep Microsoft expertise across the Microsoft Entra Suite. Our scope includes Microsoft Entra ID Protection, Microsoft Entra ID Governance, Microsoft Global Secure Access, and Microsoft Entra Verified ID. We enable organizations to thrive through technology with exceptional people making the complicated simple. |
|[Ravenswood Technology Group](https://www.ravenswoodtechnology.com/microsoft-technologies/identity-and-access-solutions/microsoft-entra-suite-overview/)|Ravenswood brings decades of identity expertise to your initiative. Our team excels at integrating complex enterprise systems, both on premises, and in the cloud. Ravenswood helps organizations around the world, including some of the most recognized brand names, tackle challenging identity, security, and compliance challenges. |
|[SB Technology Corp.](https://www.softbanktech.co.jp/service/list/microsoft365/e5-security)|Integrating Entra Suite via SB Technology's service provides a robust security framework, protecting against sophisticated cyber threats. Key features include multi-factor authentication (MFA), identity protection, and risk-based conditional access, ensuring comprehensive security management tailored to your organization's needs. |
Modified by csmulligan on May 14, 2025 11:52 PM
๐Ÿ“– View on learn.microsoft.com
+5 / -6 lines changed
Commit: Minor SEO updates.
Changes:
Before
After
---
 
title: B2B Invitation Redemption
description: Learn about Microsoft Entra B2B collaboration invitation redemption and sign-in experiences for guest users, including the consent process and privacy terms agreement.
ms.service: entra-external-id
ms.topic: concept-article
ms.date: 03/10/2025
ms.author: cmulligan
author: csmulligan
manager: celestedg
 
[!INCLUDE [applies-to-workforce-only](./includes/applies-to-workforce-only.md)]
 
This article describes how guest users can access your resources and the consent process they encounter. If you send an invitation email to the guest, the invitation includes a link that the guest can redeem to access your app or portal. The invitation email is just one way guests can access your resources. Alternatively, you can add guests to your directory and give them a direct link to the portal or app you want to share. Regardless of the method they use, guests are guided through a first-time consent process. This process ensures that your guests agree to privacy terms and accept any [terms of use](~/identity/conditional-access/terms-of-use.md) you've set up.
 
When you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) thatโ€™s initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.
 
 
Guest users can now sign in to your multitenant or Microsoft first-party apps through a common endpoint (URL), for example `https://myapps.microsoft.com`. Previously, a common URL would redirect a guest user to their home tenant instead of your resource tenant for authentication, so a tenant-specific link was required (for example `https://myapps.microsoft.com/?tenantid=<tenant id>`). Now the guest user can go to the application's common URL, choose **Sign-in options**, and then select **Sign in to an organization**. The user then types the domain name of your organization.
 
---
title: B2B Invitation Redemption
description: Learn how Microsoft Entra B2B invitation redemption works, including guest sign-in, consent process, and privacy terms. Ensure secure access for your organizationโ€™s resources.
 
ms.topic: concept-article
ms.date: 05/14/2025
ms.author: cmulligan
author: csmulligan
manager: celestedg
 
[!INCLUDE [applies-to-workforce-only](./includes/applies-to-workforce-only.md)]
 
This article explains the Microsoft Entra B2B invitation redemption process for guest users, including how they access your resources and complete the required consent steps. Whether you send an invitation email or provide a direct link, guests are guided through a secure sign-in and consent process to ensure compliance with your organizationโ€™s privacy terms and [terms of use](~/identity/conditional-access/terms-of-use.md).
 
When you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) thatโ€™s initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.
 
 
Guest users can now sign in to your multitenant or Microsoft first-party apps through a common endpoint (URL), for example `https://myapps.microsoft.com`. Previously, a common URL would redirect a guest user to their home tenant instead of your resource tenant for authentication, so a tenant-specific link was required (for example `https://myapps.microsoft.com/?tenantid=<tenant id>`). Now the guest user can go to the application's common URL, choose **Sign-in options**, and then select **Sign in to an organization**. The user then types the domain name of your organization.
 
![Screenshot of the Microsoft Entra B2B invitation redemption flow diagram.](media/redemption-experience/common-endpoint-flow-small.png)
+5 / -6 lines changed
Commit: Minor SEO updates.
Changes:
Before
After
---
title: Customize the browser language for authentication
description: Learn about how to customize the browser language of your app's authentication experience.
author: csmulligan
ms.author: cmulligan
manager: celestedg
ms.subservice: external
ms.topic: how-to
ms.date: 03/13/2025
ms.custom: it-pro
 
#Customer intent: As a dev, devops, or it admin, I want to learn about how to add customized browser languages to my app's authentication experience.
---
# Customize the language of the authentication experience
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
> [!TIP]
---
title: Customize the browser language
description: Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
author: csmulligan
ms.author: cmulligan
manager: celestedg
ms.subservice: external
ms.topic: how-to
ms.date: 05/14/2025
ms.custom: it-pro
 
#Customer intent: As a dev, devops, or it admin, I want to learn about how to add customized browser languages to my app's authentication experience.
---
# Customize browser language for authentication experience
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
> [!TIP]
> This article applies to user flows in external tenants. For information about workforce tenants, see [Language customization in Microsoft Entra External ID](../user-flow-customize-language.md).
Modified by Pratik Jadhav on May 14, 2025 5:28 PM
๐Ÿ“– View on learn.microsoft.com
+4 / -4 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs#426092
Changes:
Before
After
### Create a memberOf dynamic group
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
1. Browse to **Entra ID** > **Groups** > **All groups**.
1. Select **New group**.
1. Fill in group details. The group type can be **Security** or **Microsoft 365**, and the membership type can be set to **Dynamic User** or **Dynamic Device**.
1. Select **Add dynamic query**.
1. MemberOf isn't yet supported in the rule builder. Select **Edit** to write the rule in the **Rule syntax** box.
1. Example user rule: `user.memberof -any (group.objectId -in ['groupId', 'groupId'])`
1. Example device rule: `device.memberof -any (group.objectId -in ['groupId', 'groupId'])`
1. Select **OK**.
1. Select **Create group**.
### Create a memberOf dynamic group
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).
1. Browse to **Identity** > **Groups** > **All groups**.
1. Select **New group**.
1. Fill in group details. The group type can be **Security** or **Microsoft 365**, and the membership type can be set to **Dynamic User** or **Dynamic Device**.
1. Select **Add dynamic query**.
1. MemberOf isn't yet supported in the rule builder UI. Select **Edit** to write the rule in the **Rule syntax** box.
1. Example user rule: `user.memberof -any (group.objectId -in ['groupId'])`
1. Example device rule: `device.memberof -any (group.objectId -in ['groupId'])`
1. Select **OK**.
1. Select **Create group**.
Modified by Ortagus Winfrey on May 14, 2025 10:15 AM
๐Ÿ“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: updates
Changes:
Before
After
---
title: Microsoft Entra Suite Scenario - Using Entitlement Management and Global Secure Access to restrict employee access to cloud apps
description: Learn how to configure verified ID settings for an access package in entitlement management.
author: owinfreyatl
manager: femila
editor: HANKI
---
 
 
# Microsoft Entra Suite Scenario: Using Entitlement Management and Global Secure Access to restrict employee access to cloud apps
 
The Microsoft Entra Suite provides capabilities to govern who can access restricted websites. Microsoft Entra Internet Access protects access to SaaS apps and Entitlement management enables organizations to manage identity and access lifecycle at scale, by automating access request workflows, access assignments, reviews, and expiration.
 
---
title: Microsoft Entra Suite Scenario - Use Entitlement Management and Global Secure Access to restrict employee access to cloud apps
description: Learn how you can use Entitlement Management and Global Secure Access to restrict employee access to cloud apps.
author: owinfreyatl
manager: femila
editor: HANKI
---
 
 
# Microsoft Entra Suite Scenario: Use Entitlement Management and Global Secure Access to restrict employee access to cloud apps
 
The Microsoft Entra Suite provides capabilities to govern who can access restricted websites. Microsoft Entra Internet Access protects access to SaaS apps and Entitlement management enables organizations to manage identity and access lifecycle at scale, by automating access request workflows, access assignments, reviews, and expiration.
 
Modified by Henry Mbugua on May 14, 2025 7:40 PM
๐Ÿ“– View on learn.microsoft.com
+2 / -3 lines changed
Commit: Remove xamarin article
Changes:
Before
After
author: henrymbuguakiarie
manager: CelesteDG
ms.author: henrymbugua
ms.date: 03/19/2025
ms.reviewer: jmprieur
ms.service: identity-platform
 
| An app that runs natively on a mobile device or desktop machine | Node.js electron, Windows desktop, UWP, React Native, Android, iOS/macOS | Mobile and desktop applications |
 
If you're building an iOS app using one of the following methods, use the **Mobile and desktop applications** platform to add a redirect URI:
 
- iOS apps using legacy SDKs (ADAL)
- iOS apps using open source SDKs (AppAuth)
- iOS apps using cross-plat tech we don't support (Flutter)
- iOS apps implementing our OAuth protocols directly
author: henrymbuguakiarie
manager: CelesteDG
ms.author: henrymbugua
ms.date: 05/14/2025
ms.reviewer: jmprieur
ms.service: identity-platform
 
| An app that runs natively on a mobile device or desktop machine | Node.js electron, Windows desktop, UWP, React Native, Android, iOS/macOS | Mobile and desktop applications |
 
If you're building an iOS app using one of the following methods, use the **Mobile and desktop applications** platform to add a redirect URI:
- iOS apps using open source SDKs (AppAuth)
- iOS apps using cross-plat tech we don't support (Flutter)
- iOS apps implementing our OAuth protocols directly
 
Modified by Henry Mbugua on May 14, 2025 7:16 PM
๐Ÿ“– View on learn.microsoft.com
+2 / -3 lines changed
Commit: Remove xamarin article
Changes:
Before
After
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.custom: has-adal-ref
ms.date: 09/14/2019
ms.devlang: java
ms.reviewer: shoatman
ms.service: identity-platform
 
The MSAL account ID isn't an account object ID. It isn't meant to be parsed and/or relied upon to convey anything other than uniqueness within the Microsoft identity platform.
 
For compatibility with the Azure AD Authentication Library (ADAL), and to ease Migration from ADAL to MSAL, MSAL can look up accounts using any valid identifier for the account available in the MSAL cache. For example, the following will always retrieve the same account object for [email protected] because each of the identifiers is valid:
 
```java
// The following would always retrieve the same account object for [email protected] because each identifier is valid
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.date: 05/14/2025
ms.devlang: java
ms.reviewer: shoatman
ms.service: identity-platform
 
The MSAL account ID isn't an account object ID. It isn't meant to be parsed and/or relied upon to convey anything other than uniqueness within the Microsoft identity platform.
 
MSAL can look up accounts using any valid identifier for the account available in the MSAL cache. For example, the following will always retrieve the same account object for [email protected] because each of the identifiers is valid:
 
```java
// The following would always retrieve the same account object for [email protected] because each identifier is valid
 
+4 / -1 lines changed
Commit: Update pim-apis.md
Changes:
Before
After
- PIM alerts for Microsoft Entra roles in Microsoft Graph API - Preview.
- PIM alerts for Azure Resources in ARM API - Preview.
 
Having PIM for Microsoft Entra roles in Microsoft Graph API and PIM for Azure Resources in ARM API provide a few benefits including:
- Alignment of the PIM APIs for regular role assignment for both Microsoft Entra roles and Azure Resource roles.
- Reducing the need to call other PIM APIs to onboard a resource, get a resource, or get role definition.
 
## Next steps
 
- [Microsoft Entra Privileged Identity Management API reference](/graph/api/resources/privilegedidentitymanagementv3-overview)
 
 
 
- PIM alerts for Microsoft Entra roles in Microsoft Graph API - Preview.
- PIM alerts for Azure Resources in ARM API - Preview.
 
> [!NOTE]
> The roleAssignmentApprovals APIs are only available in /beta
 
Having PIM for Microsoft Entra roles in Microsoft Graph API and PIM for Azure Resources in ARM API provide a few benefits including:
- Alignment of the PIM APIs for regular role assignment for both Microsoft Entra roles and Azure Resource roles.
- Reducing the need to call other PIM APIs to onboard a resource, get a resource, or get role definition.
 
## Next steps
 
- [Microsoft Entra Privileged Identity Management API reference](/graph/api/resources/privilegedidentitymanagementv3-overview)
+2 / -2 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs#421992
Changes:
Before
After
For organizations that have no established use of device code flow, blocking can be done with the following Conditional Access policy:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Browse to **Entra ID** > **Conditional Access** > **Policies**.
1. Select **New policy**.
1. Under **Assignments**, select **Users or workload identities**.
1. Under **Include**, select the users you want to be in-scope for the policy (**all users** recommended).
Use the **Authentication flows** condition in Conditional Access to manage the feature. You might want to block [authentication transfer](concept-authentication-transfer.md) if you donโ€™t want users to transfer authentication from their PC to a mobile device. For example, if you donโ€™t allow Outlook to be used on personal devices by certain groups. Blocking authentication transfer can be done with the following Conditional Access policy:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Browse to **Entra ID** > **Conditional Access**.
1. Select **Create new policy**.
1. Under **Assignments**, select **Users or workload identities**.
1. Under **Include**, select **All users** or user groups you would like to block for authentication transfer.
For organizations that have no established use of device code flow, blocking can be done with the following Conditional Access policy:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Browse to **Protection** > **Conditional Access** > **Policies**.
1. Select **New policy**.
1. Under **Assignments**, select **Users or workload identities**.
1. Under **Include**, select the users you want to be in-scope for the policy (**all users** recommended).
Use the **Authentication flows** condition in Conditional Access to manage the feature. You might want to block [authentication transfer](concept-authentication-transfer.md) if you donโ€™t want users to transfer authentication from their PC to a mobile device. For example, if you donโ€™t allow Outlook to be used on personal devices by certain groups. Blocking authentication transfer can be done with the following Conditional Access policy:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](../role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Browse to **Protection** > **Conditional Access**.
1. Select **Create new policy**.
1. Under **Assignments**, select **Users or workload identities**.
1. Under **Include**, select **All users** or user groups you would like to block for authentication transfer.
Modified by Pratik Jadhav on May 14, 2025 4:02 PM
๐Ÿ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs#420673
Changes:
Before
After
In this tutorial, set up SSPR for a set of users in a test group. Use the *SSPR-Test-Group* and provide your own Microsoft Entra group as needed:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
1. Browse to **Entra ID** > **Password reset** from the menu on the left side.
1. From the **Properties** page, under the option *Self service password reset enabled*, choose **Selected**.
1. If your group isn't visible, choose **No groups selected**, browse for and select your Microsoft Entra group, like *SSPR-Test-Group*, and then choose *Select*.
 
 
1. To apply the notification preferences, select **Save**.
 
If users need more help with the SSPR process, you can customize the "Contact your administrator" link. The user can select this link in the SSPR registration process and when they unlock their account or resets their password. To make sure your users get the support needed, we recommend you provide a custom helpdesk email or URL.
 
1. From the menu on the left side of the **Customization** page, set **Customize helpdesk link** to *Yes*.
1. In the **Custom helpdesk email or URL** field, provide an email address or web page URL where your users can get more help from your organization, like *https:\//support.contoso.com/*
In this tutorial, set up SSPR for a set of users in a test group. Use the *SSPR-Test-Group* and provide your own Microsoft Entra group as needed:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
1. Browse to **Protection** > **Password reset** from the menu on the left side.
1. From the **Properties** page, under the option *Self service password reset enabled*, choose **Selected**.
1. If your group isn't visible, choose **No groups selected**, browse for and select your Microsoft Entra group, like *SSPR-Test-Group*, and then choose *Select*.
 
 
1. To apply the notification preferences, select **Save**.
 
If users need more help with the SSPR process, you can customize the **"Contact your administrator"** link. The user can select this link in the SSPR registration process and when they unlock their account or resets their password. To make sure your users get the support needed, we recommend you provide a custom helpdesk email or URL.
 
1. From the menu on the left side of the **Customization** page, set **Customize helpdesk link** to *Yes*.
1. In the **Custom helpdesk email or URL** field, provide an email address or web page URL where your users can get more help from your organization, like *https:\//support.contoso.com/*
Modified by ManoharLakkoju-MSFT on May 14, 2025 3:59 PM
๐Ÿ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/Entra-docs#424894
Changes:
Before
After
$messageInfo.customizedMessageBody = "Hello. You are invited to the Contoso organization."
 
foreach ($email in $invitations) {
New-MgInvitation
-InvitedUserEmailAddress $email.InvitedUserEmailAddress `
-InvitedUserDisplayName $email.Name `
-InviteRedirectUrl https://myapplications.microsoft.com/?tenantid=aaaabbbb-0000-cccc-1111-dddd2222eeee `
 
In this tutorial, you sent bulk invitations to guest users outside of your organization. Next, learn how to bulk invite guest users on the portal and how to enforce MFA for them.
 
- [Bulk invite guest users via the portal](tutorial-bulk-invite.md)
$messageInfo.customizedMessageBody = "Hello. You are invited to the Contoso organization."
 
foreach ($email in $invitations) {
New-MgInvitation `
-InvitedUserEmailAddress $email.InvitedUserEmailAddress `
-InvitedUserDisplayName $email.Name `
-InviteRedirectUrl https://myapplications.microsoft.com/?tenantid=aaaabbbb-0000-cccc-1111-dddd2222eeee `
 
In this tutorial, you sent bulk invitations to guest users outside of your organization. Next, learn how to bulk invite guest users on the portal and how to enforce MFA for them.
 
- [Bulk invite guest users via the portal](tutorial-bulk-invite.md)
Modified by Henry Mbugua on May 14, 2025 7:40 PM
๐Ÿ“– View on learn.microsoft.com
+1 / -2 lines changed
Commit: Remove xamarin article
Changes:
Before
After
author: rwike77
manager: CelesteDG
ms.author: ryanwi
ms.custom: has-adal-ref
ms.date: 04/10/2024
ms.reviewer: ludwignick
ms.service: identity-platform
 
If your app reuses authorization codes to get tokens for multiple resources, we recommend that you use the code to get a refresh token, and then use that refresh token to acquire additional tokens for other resources. Authorization codes can only be used once, but refresh tokens can be used multiple times across multiple resources. Any new app that attempts to reuse an authentication code during the OAuth code flow will get an invalid_grant error.
 
For more information about refresh tokens, see [Refreshing the access tokens](v2-oauth2-auth-code-flow.md#refresh-the-access-token). If using ADAL or MSAL, this is handled for you by the library - replace the second instance of `AcquireTokenByAuthorizationCodeAsync` with `AcquireTokenSilentAsync`.
 
## May 2018
 
author: rwike77
manager: CelesteDG
ms.author: ryanwi
ms.date: 04/10/2024
ms.reviewer: ludwignick
ms.service: identity-platform
 
If your app reuses authorization codes to get tokens for multiple resources, we recommend that you use the code to get a refresh token, and then use that refresh token to acquire additional tokens for other resources. Authorization codes can only be used once, but refresh tokens can be used multiple times across multiple resources. Any new app that attempts to reuse an authentication code during the OAuth code flow will get an invalid_grant error.
 
For more information about refresh tokens, see [Refreshing the access tokens](v2-oauth2-auth-code-flow.md#refresh-the-access-token). If using MSAL, this is handled for you by the library - replace the second instance of `AcquireTokenByAuthorizationCodeAsync` with `AcquireTokenSilentAsync`.
 
## May 2018
 
 

๐Ÿ—‘๏ธ Deleted Documentation Files

DELETED docs/identity-platform/msal-net-use-brokers-with-xamarin-apps.md
Deleted by Henry Mbugua on May 14, 2025 6:32 PM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity-platform/msal-net-use-brokers-with-xamarin-apps
-383 lines removed
Commit: Removing Xamarin article
DELETED docs/identity-platform/msal-net-xamarin-ios-considerations.md
Deleted by Henry Mbugua on May 14, 2025 7:02 PM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity-platform/msal-net-xamarin-ios-considerations
-173 lines removed
Commit: Remove xamarin article