πŸ“‹ Microsoft Entra Documentation Changes

Changes for May 16th 2025

Period: May 15th 2025, 12:00 AM to May 16th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 16th 2025.

πŸ“Š Summary

45
Total Commits
1
New Files
20
Modified Files
0
Deleted Files
17
Contributors

πŸ†• New Documentation Files

+0 lines added
Commit: Add include file for sso wizard content

πŸ“ Modified Documentation Files

Modified by ShawnJackson on May 15, 2025 10:12 AM
πŸ“– View on learn.microsoft.com
+187 / -179 lines changed
Commit: edit pass: articles-about-tenant-restrictions
Changes:
Before
After
---
title: Configure tenant restrictions - Microsoft Entra ID
description: Use tenant restrictions to control the types of external accounts your users can use on your networks and the devices you manage. You can scope settings to apps, groups, and users for specified tenants.
ms.service: entra-external-id
ms.topic: how-to
manager: celestedg
ms.custom: it-pro
ms.collection: M365-identity-device-management
#customer intent: As an IT admin, I want to configure tenant restrictions v2, so that I can control access to external apps and enhance security for users signing in from our networks or devices.
---
 
# Set up tenant restrictions v2
 
To enhance security, you can limit what your users can access when they use an external account to sign in from your networks or devices. The **Tenant restrictions** settings, included with [cross-tenant access settings](cross-tenant-access-overview.md), let you create a policy to control access to external apps.
 
For example, suppose a user in your organization has created a separate account in an unknown tenant, or an external organization has given your user an account that lets them sign in to their organization. You can use tenant restrictions to prevent the user from using some or all external apps while they're signed in with the external account on your network or devices.
 
:::image type="content" source="media/tenant-restrictions-v2/authentication-flow.png" alt-text="Diagram illustrating tenant restrictions v2.":::
 
---
title: Configure Tenant Restrictions - Microsoft Entra ID
description: Use tenant restrictions to control the types of external accounts that users can use on your networks and the devices that you manage.
ms.service: entra-external-id
ms.topic: how-to
manager: celestedg
ms.custom: it-pro
ms.collection: M365-identity-device-management
#customer intent: As an IT admin, I want to configure tenant restrictions v2 so that I can control access to external apps and enhance security for users signing in from my organization's networks or devices.
---
 
# Set up tenant restrictions v2
 
To enhance security, you can limit what your users can access when they use an external account to sign in from your networks or devices. The **Tenant restrictions** settings, included with [cross-tenant access settings](cross-tenant-access-overview.md), let you create a policy to control access to external apps.
 
For example, suppose a user in your organization created a separate account in an unknown tenant, or an external organization gave your user an account that lets them sign in to their organization. You can use tenant restrictions to prevent the user from using some or all external apps while they're signed in with the external account on your network or devices.
 
The following diagram shows the steps that an example organization takes to prevent user access by using tenant restrictions v2.
 
+52 / -51 lines changed
Commit: edit pass: articles-about-tenant-restrictions
Changes:
Before
After
ms.reviewer: alexpav
ai-usage: ai-assisted
---
# Universal tenant restrictions
 
Universal tenant restrictions enhance the functionality of [tenant restrictions v2](https://aka.ms/tenant-restrictions-enforcement). They use Global Secure Access to tag all traffic no matter the operating system, browser, or device form factor. They allow support for both client and remote network connectivity.
 
Administrators no longer have to manage proxy server configurations or complex network configurations. They can apply tenant restrictions v2 on any platform by using the Global Secure Access client or remote networks.
 
When you enable Universal tenant restrictions, Global Secure Access adds policy information for tenant restrictions v2 to the authentication plane's network traffic. This traffic is from Microsoft Entra ID traffic and Microsoft Graph. As a result, users who use devices and networks in your organization must use only authorized external tenants. This restriction helps prevent data exfiltration for any application integrated with single sign-on (SSO) with your Microsoft Entra ID tenant.
 
:::image type="content" source="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png" alt-text="Diagram that shows how tenant restrictions v2 protects against malicious users." lightbox="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png":::
 
The following table explains the steps taken at each point in the previous diagram.
 
| Step | Description |
| --- | --- |
| **1** | Contoso configures a **tenant restrictions v2** policy in their cross-tenant access settings to block all external accounts and external apps. Contoso enforces the policy using Global Secure Access universal tenant restrictions. |
| **2** | A user with a Contoso-managed device tries to access a Microsoft Entra integrated app with an unsanctioned external identity. |
| **3** | *Authentication plane protection:* Using Microsoft Entra ID, Contoso's policy blocks unsanctioned external accounts from accessing external tenants. Additionally, if a Microsoft Graph token is obtained using another device and is brought into your environment within its lifetime, this token cannot be replayed from your devices with the Global Secure Access client or via your remote networks. |
ms.reviewer: alexpav
ai-usage: ai-assisted
---
 
# Universal tenant restrictions
 
Universal tenant restrictions enhance the functionality of [tenant restrictions v2](https://aka.ms/tenant-restrictions-enforcement). They use Global Secure Access to tag all traffic no matter the operating system, browser, or device form factor. They allow support for both client and remote network connectivity.
 
Administrators no longer have to manage proxy server configurations or complex network configurations. They can apply tenant restrictions v2 on any platform by using the Global Secure Access client or remote networks.
 
When you enable universal tenant restrictions, Global Secure Access adds policy information for tenant restrictions v2 to the authentication plane's network traffic. This traffic is from Microsoft Entra ID and Microsoft Graph. As a result, users who use devices and networks in your organization must use only authorized external tenants. This restriction helps prevent data exfiltration for any application integrated with your Microsoft Entra ID tenant through single sign-on (SSO).
 
The following diagram shows the steps that an example organization takes to help protect against malicious users by using tenant restrictions v2.
 
:::image type="content" source="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png" alt-text="Diagram that shows how tenant restrictions v2 helps protect against malicious users." lightbox="media/how-to-universal-tenant-restrictions/tenant-restrictions-v-2-universal-tenant-restrictions-flow.png":::
 
| Step | Description |
| --- | --- |
| **1** | Contoso configures a tenant restrictions v2 policy in its cross-tenant access settings to block all external accounts and external apps. Contoso enforces the policy by using Global Secure Access universal tenant restrictions. |
| **2** | A user with a Contoso-managed device tries to access a Microsoft Entra integrated app with an unsanctioned external identity. |
Modified by ShawnJackson on May 15, 2025 10:12 AM
πŸ“– View on learn.microsoft.com
+41 / -39 lines changed
Commit: edit pass: articles-about-tenant-restrictions
Changes:
Before
After
Administrators use [tenant restrictions v1](~/identity/enterprise-apps/tenant-restrictions.md) to control user access to external tenants on their network. However, [tenant restrictions v2](tenant-restrictions-v2.md) with cross tenant access settings adds tenant-level restrictions and more granularity such as individual user, group, and application controls. Tenant restrictions v2 moves policy management from network proxies to a cloud-based portal. Organizations no longer hit a maximum number of targeted tenants due to proxy header size limitations.
Migration from tenant restrictions v1 to tenant restrictions v2 is a one-time process with no other licensing requirements. As you plan the migration, include stakeholders from networking and identity teams.
## Prerequisites
Ensure the following prerequisites are met.
* Administrator access to proxies injecting the tenant restrictions v1 headers
* Proxies can use on-premises or a cloud-based service
## Required roles
This section has the least-privileged roles required for the deployment. Use the Security Administrator role, or a custom role with at least the following permissions.
### Microsoft.directory/crossTenantAccessPolicy/
* Standard/read
Administrators use [tenant restrictions v1](~/identity/enterprise-apps/tenant-restrictions.md) to control user access to external tenants on their network. However, [tenant restrictions v2](tenant-restrictions-v2.md) with cross tenant access settings adds tenant-level restrictions and more granularity such as individual user, group, and application controls. Tenant restrictions v2 moves policy management from network proxies to a cloud-based portal. Organizations no longer hit a maximum number of targeted tenants due to proxy header size limitations.
Migration from tenant restrictions v1 to tenant restrictions v2 is a one-time process with no other licensing requirements. As you plan the migration, include stakeholders from networking and identity teams.
## Prerequisites
Ensure the following prerequisites are met.
* Administrator access to proxies injecting the tenant restrictions v1 headers
* Proxies can use on-premises or a cloud-based service
## Required roles
This section has the least-privileged roles required for the deployment. Use the Security Administrator role, or a custom role with at least the following permissions.
### Microsoft.directory/crossTenantAccessPolicy/
* Standard/read
* Partners/standard/read
+21 / -21 lines changed
Commit: Update concept-condition-filters-for-devices.md
Changes:
Before
After
ms.subservice: conditional-access
 
ms.topic: conceptual
ms.date: 04/08/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
The following device attributes can be used with the filter for devices condition in Conditional Access.
 
> [!NOTE]
> Microsoft Entra ID uses device authentication to evaluate device filter rules. For a device that is unregistered with Microsoft Entra ID, all device properties are considered as null values and the device attributes cannot be determined since the device does not exist in the directory. The best way to target policies for unregistered devices is by using the negative operator since the configured filter rule would apply. If you were to use a positive operator, the filter rule would only apply when a device exists in the directory and the configured rule matches the attribute on the device.
 
| Supported device attributes | Supported operators | Supported values | Example |
| --- | --- | --- | --- |
| deviceId | Equals, NotEquals, In, NotIn | A valid deviceId that is a GUID | (device.deviceid -eq "aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb") |
| displayName | Equals, NotEquals, StartsWith, NotStartsWith, EndsWith, NotEndsWith, Contains, NotContains, In, NotIn | Any string | (device.displayName -contains "ABC") |
| deviceOwnership | Equals, NotEquals | Supported values are "Personal" for bring your own devices and "Company" for corporate owned devices | (device.deviceOwnership -eq "Company") |
| enrollmentProfileName | Equals, NotEquals, StartsWith, NotStartsWith, EndsWith, NotEndsWith, Contains, NotContains, In, NotIn | This is set by Microsoft Intune based on the profile the device was enrolled under at the time of enrollment. It's a string value created by Microsoft Intune admin, and matches the Windows Autopilot, Apple Automated Device Enrollment (ADE), or Google enrollment profile applied to the device. | (device.enrollmentProfileName -startsWith "AutoPilot Profile") |
| isCompliant | Equals, NotEquals | Supported values are "True" for compliant devices and "False" for non compliant devices | (device.isCompliant -eq "True") |
ms.subservice: conditional-access
 
ms.topic: conceptual
ms.date: 05/14/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
The following device attributes can be used with the filter for devices condition in Conditional Access.
 
> [!IMPORTANT]
> Microsoft recommends using one or more system defined or admin configurable device properties when using Filter for devices condition in Conditional Access.
 
> [!NOTE]
> Microsoft Entra ID uses device authentication to evaluate device filter rules. For a device that is unregistered with Microsoft Entra ID, all device properties are considered as null values and the device attributes cannot be determined since the device does not exist in the directory. The best way to target policies for unregistered devices is by using the negative operator since the configured filter rule would apply. If you were to use a positive operator, the filter rule would only apply when a device exists in the directory and the configured rule matches the attribute on the device.
 
| Supported device attributes | System defined or admin configured | Supported operators | Supported values | Example |
| --- | --- | --- | --- | --- |
| deviceId | Yes | Equals, NotEquals, In, NotIn | A valid deviceId that is a GUID | (device.deviceid -eq "aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb") |
| displayName | No | Equals, NotEquals, StartsWith, NotStartsWith, EndsWith, NotEndsWith, Contains, NotContains, In, NotIn | Any string | (device.displayName -contains "ABC") |
+16 / -10 lines changed
Commit: May 15 added preview language and tags
Changes:
Before
After
---
title: Global Secure Access Support for Microsoft Azure in China
description: Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities for Microsoft Azure in China.
ms.author: jayrusso
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 03/05/2025
ms.service: global-secure-access
ms.reviewer: sumeetmittal
 
 
---
 
# Global Secure Access Support for Microsoft Azure in China
Microsoft is dedicated to supporting Global Secure Access capabilities in China, providing secure and compliant connectivity solutions that meet the unique needs of organizations operating in China. There are two scenarios that are applicable to Global Secure Access in China.
1. Global Secure Access availability for customer tenants deployed on Microsoft Azure in China. **Microsoft currently doesn’t support this scenario**.
1. Global Secure Access availability for tenants outside China. This scenario includes use cases where Global Secure Access customers with a presence in multiple geographies make a temporary visit to China. For example, when an employee of USA-based company Contoso, using Global Secure Access, travels to China. **Microsoft supports this scenario**.
 
However, it’s important to recognize the specific connectivity disclaimers that apply to Secure Access Service Edge (SASE) providers operating in China. Due to regulatory restrictions and local infrastructure requirements, SASE providers might encounter:
---
title: Global Secure Access Support for Microsoft Azure in China (Preview)
description: Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities for Microsoft Azure in China.
ms.author: jayrusso
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/14/2025
ms.service: global-secure-access
ms.reviewer: sumeetmittal
 
# Customer intent: As an IT admin, I want to evaluate the regulatory constraints of using Global Secure Access in China so that I can ensure compliance and plan connectivity strategies effectively.
---
 
# Global Secure Access Support for Microsoft Azure in China (Preview)
Microsoft supports Global Secure Access capabilities in China, offering secure and compliant connectivity solutions tailored to the needs of organizations operating in China.
 
> [!IMPORTANT]
> Global Secure Access support for Microsoft Azure in China is currently in PREVIEW.
> This information relates to a prerelease functionality that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided in this article.
Modified by shlipsey3 on May 15, 2025 7:39 AM
πŸ“– View on learn.microsoft.com
+14 / -11 lines changed
Commit: simplify
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: overview
ms.date: 04/29/2025
 
author: shlipsey3
ms.author: sarahlipsey
 
### Microsoft Defender
 
Microsoft Entra ID Protection receives signals from the Microsoft Defender products for several risk detections, so you also need the appropriate license for the Microsoft Defender product that owns the signal you're interested in.
 
| Risk detection | Microsoft Defender product | Required License |
| --- | --- | --- |
| Activity from anonymous IP address | Microsoft Defender for Cloud Apps | Microsoft 365 E5, EMS E5, or standalone license |
| Impossible travel | Microsoft Defender for Cloud Apps | Microsoft 365 E5, EMS E5, or standalone license |
| Mass access to sensitive files | Microsoft Defender for Cloud Apps | Microsoft 365 E5, EMS E5, or standalone license |
| New country | Microsoft Defender for Cloud Apps | Microsoft 365 E5, EMS E5, or standalone license |
| Suspicious inbox rules | Microsoft Defender for Office 365 | Microsoft 365 E5 or Office 365 E5 |
| Attacker in the Middle | Microsoft 365 Defender Apps | Microsoft 365 E5 |
ms.service: entra-id-protection
 
ms.topic: overview
ms.date: 05/14/2025
 
author: shlipsey3
ms.author: sarahlipsey
 
### Microsoft Defender
 
Microsoft Entra ID Protection receives signals from Microsoft Defender products for several risk detections, so you also need the appropriate license for the Microsoft Defender product that owns the signal you're interested in.
 
**Microsoft 365 E5** covers all of the following signals:
 
- **Microsoft Defender for Cloud Apps**
- Activity from anonymous IP address
- Impossible travel
- Mass access to sensitive files
- New country
 
+20 / -4 lines changed
Commit: Incorporate feedback
Changes:
Before
After
 
When you select this check box, it grants an underlying service principal the following permissions:
 
- TBD
- TBD
 
6. Select **Create**.
 
 
::: zone pivot="cross-cloud-synchronization"
 
#### Symptom - Cross-cloud synchronization error
 
TBD
 
::: zone-end
 
 
 
 
 
When you select this check box, it grants an underlying service principal the following permissions:
 
- User.ReadWrite.CrossCloud
- User.Invite.All
- Organization.Read.All
- Policy.Read.All
 
6. Select **Create**.
 
 
::: zone pivot="cross-cloud-synchronization"
 
#### Symptom - Test connection fails with AzureActiveDirectoryTokenExpired
 
When configuring cross-cloud synchronization in the source tenant and you test the connection, it fails with the following error message:
 
```
You appear to have entered invalid credentials. Please confirm you are using the correct information for an administrative account.
Error code: AzureActiveDirectoryTokenExpired
+14 / -1 lines changed
Commit: add info on hidden and editable flags
Changes:
Before
After
ms.subservice: external
ms.topic: how-to
ms.date: 04/28/2025
ms.author: mimart
ms.custom: it-pro
 
 
1. When all your changes are complete, select **Save**.
 
### Configure a single-select checkbox (CheckboxSingleSelect)
 
An attribute with a Boolean data type has a user input type of CheckboxSingleSelect. You can modify the text that displays next to the checkbox and include hyperlinks.
 
 
 
 
 
 
 
ms.subservice: external
ms.topic: how-to
ms.date: 05/14/2025
ms.author: mimart
ms.custom: it-pro
 
 
1. When all your changes are complete, select **Save**.
 
### Configure attribute visibility and editability during sign-up
 
You can control which attributes are shown or collected from users during sign-up by configuring the hidden and editable flags for each attribute. These settings are not currently available in the admin center UI, but you can configure them using Microsoft Graph.
 
Each attribute supports the following flags:
 
- `hidden`: Set to `true` to hide the attribute from the sign-up page, or `false` to display it.
- `editable`: Set to `true` to allow users to edit the attribute, or `false` to make it read-only.
 
For example, you could set hidden to false and editable to false to shows the attribute on the page, but prevent users from editing it.
+12 / -0 lines changed
Commit: Incorporate feedback
Changes:
Before
After
 
[Cross-cloud synchronization](cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization) requires Microsoft Entra ID Governance or Microsoft Entra Suite licenses. For more information, see [Microsoft Entra ID Governance licensing fundamentals](../../id-governance/licensing-fundamentals.md).
 
## Frequently asked questions
 
#### Clouds
- Cross-tenant synchronization and cross-cloud synchronization are built using the same technologies and are fundamentally the same. The primary difference is that synchronization occurs across clouds instead of within the same cloud.
- Synchronization of the manager attributue isn't yet supported in cross-cloud synchronization.
 
#### Existing B2B users
 
Will cross-tenant synchronization manage existing B2B users?
 
 
 
 
 
 
 
 
 
[Cross-cloud synchronization](cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization) requires Microsoft Entra ID Governance or Microsoft Entra Suite licenses. For more information, see [Microsoft Entra ID Governance licensing fundamentals](../../id-governance/licensing-fundamentals.md).
 
The following table lists the required licenses depending on your scenario.
 
| Scenario | Source tenant | Target tenant |
| --- | --- | --- |
| Cross-tenant synchronization (same cloud) | Microsoft Entra ID P1 licenses | N/A |
| [Cross-cloud synchronization](cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization) | Microsoft Entra ID Governance or Microsoft Entra Suite licenses | N/A |
 
## Frequently asked questions
 
#### Clouds
- Cross-tenant synchronization and cross-cloud synchronization are built using the same technologies and are fundamentally the same. The primary difference is that synchronization occurs across clouds instead of within the same cloud.
- Synchronization of the manager attributue isn't yet supported in cross-cloud synchronization.
 
Are there limitations for cross-cloud synchronization?
 
- For multitenant organization limitations, see [Multitenant org FAQ](/microsoft-365/enterprise/multitenant-org-faq#can-an-mto-be-created-across-worldwide-geographies).
- External members aren't supported. For more information, see [Collaborate with guests from other Microsoft 365 cloud environments](/microsoft-365/solutions/collaborate-guests-cross-cloud).
Modified by omondiatieno on May 15, 2025 9:44 PM
πŸ“– View on learn.microsoft.com
+11 / -0 lines changed
Commit: add include file details
Changes:
Before
After
 
 
 
 
 
 
 
 
 
 
 
---
author: omondiatieno
ms.author: jomondi
ms.date: 05/12/2025
ms.service: entra-id
ms.subservice: saas-apps
ms.topic: include
# Purpose:
# This is used to include the content for app intergration wizard in SaaS apps articles
---
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, assign roles, and walk through the SSO configuration as well. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides).
Modified by Yoel Horvitz on May 15, 2025 1:58 AM
πŸ“– View on learn.microsoft.com
+8 / -1 lines changed
Commit: Update reference-training-videos.md
Changes:
Before
After
 
ms.subservice: external
ms.topic: concept-article
ms.date: 05/02/2025
ms.author: mimart
ms.custom: it-pro
 
The video covers how to integrate social identity providers like Facebook, Google and Apple into application sign-up and sign-in flows. It focuses on how you can enhance and personalize the registration experience. It also describes ways to ensure robust security and manage users efficiently using Microsoft Entra External ID.
 
> [!VIDEO https://www.youtube.com/embed/lIdGt9rDM-E?si=8n1_G_AqFbYDP22y]
### Authorize access to your application
 
This video explores the intricacies of role-based control and claims-based authorization for applications using Microsoft Entra ID and Microsoft Entra External ID.
 
 
 
 
 
 
 
 
ms.subservice: external
ms.topic: concept-article
ms.date: 05/14/2025
ms.author: mimart
ms.custom: it-pro
 
The video covers how to integrate social identity providers like Facebook, Google and Apple into application sign-up and sign-in flows. It focuses on how you can enhance and personalize the registration experience. It also describes ways to ensure robust security and manage users efficiently using Microsoft Entra External ID.
 
> [!VIDEO https://www.youtube.com/embed/lIdGt9rDM-E?si=8n1_G_AqFbYDP22y]
 
## Protect access to applications
 
The following video provides instructions on how to protect access to applications using Microsoft Entra external ID. It outlines the steps for securing application access and implementing enhanced protection with Microsoft Entra external ID to ensure only authorized users and software components can access your application.
 
> [!VIDEO https://www.youtube.com/embed/H76KFHocM0M?si=1CrSLVOgks79B-XL]
 
### Authorize access to your application
 
This video explores the intricacies of role-based control and claims-based authorization for applications using Microsoft Entra ID and Microsoft Entra External ID.
+4 / -4 lines changed
Commit: ID Protection unsupported fix
Changes:
Before
After
ms.subservice: external
ms.topic: concept-article
ms.date: 05/14/2025
ms.author: mimart
ms.custom: it-pro, seo-july-2024
 
 
|Feature |Workforce tenant | External tenant |
|---------|---------|---------|
| **Identity providers for external users (primary authentication)** | **For self-service sign-up guests**</br>- Microsoft Entra accounts</br>- Microsoft accounts</br>- Email one-time passcode</br>- Google federation</br>- Facebook federation<br></br>**For invited guests**</br>- Microsoft Entra accounts</br>- Microsoft accounts</br>- Email one-time passcode</br>- Google federation</br>- SAML/WS-Fed federation | **For self-service sign-up users (consumers, business customers)**</br>- [Email with password](concept-authentication-methods-customers.md#email-and-password-sign-in)</br>- [Email one-time passcode](./concept-authentication-methods-customers.md#email-with-one-time-passcode-sign-in)</br>- [Google federation (preview)](./how-to-google-federation-customers.md)</br>- [Facebook federation (preview)](./how-to-facebook-federation-customers.md)</br>- [Apple federation (preview)](./how-to-apple-federation-customers.md)</br>- [OIDC federation](./how-to-custom-oidc-federation-customers.md)<br></br>**For invited guests (preview)**</br>Guests invited with a directory role (for example, admins):</br>- Microsoft Entra accounts </br>- Microsoft accounts </br>- [Email one-time passcode](./concept-authentication-methods-customers.md#email-with-one-time-passcode-sign-in)<br>- [SAML/WS-Fed federation](../direct-federation.md) |
| **Authentication methods for MFA** | **For internal users (employees and admins)** </br>- [Authentication and verification methods](~/identity/authentication/concept-authentication-methods.md) </br>**For guests (invited or self-service sign-up)** </br>- [Authentication methods for guest MFA](../authentication-conditional-access.md#table-1-authentication-strength-mfa-methods-for-external-users) | **For self-service sign-up users (consumers, business customers) or invited users (preview)**</br>- [Email one-time passcode](concept-multifactor-authentication-customers.md#email-one-time-passcode)</br>- [SMS-based authentication](concept-multifactor-authentication-customers.md#sms-based-authentication) |
 
## Application registration
|---------|---------|---------|
| **Assignments**| [Users, groups](~/identity/conditional-access/concept-conditional-access-users-groups.md), and [workload identities](~/identity/conditional-access/concept-conditional-access-users-groups.md#workload-identities) | Include **all users**, and exclude users and groups. For more information, see [Add multifactor authentication (MFA) to an app](./how-to-multifactor-authentication-customers.md).|
|**Target resources**|<ul><li>[Cloud apps](~/identity/conditional-access/concept-conditional-access-cloud-apps.md)</li><li>[User actions](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#user-actions)</li><li>[Global Secure Access](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#traffic-forwarding-profiles)</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|<ul><li>[All resources, selected apps](./how-to-multifactor-authentication-customers.md), or [filter applications](~/identity/conditional-access/concept-filter-for-applications.md).</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|
| **Conditions**|<ul><li>[Sign-in risk](~/identity/conditional-access/concept-conditional-access-conditions.md#sign-in-risk)</li><li>[User risk](~/identity/conditional-access/concept-conditional-access-conditions.md#user-risk)</li><li>[Device platforms](~/identity/conditional-access/concept-conditional-access-conditions.md#device-platforms)</li><li>[Locations](~/identity/conditional-access/concept-conditional-access-conditions.md#locations)</li><li>[Client apps](~/identity/conditional-access/concept-conditional-access-conditions.md#client-apps)</li><li>[Filter for devices](~/identity/conditional-access/concept-conditional-access-conditions.md#filter-for-devices)</li></ul>|<ul><li>[Sign-in risk](~/identity/conditional-access/concept-conditional-access-conditions.md#sign-in-risk)</li><li>[User risk](~/identity/conditional-access/concept-conditional-access-conditions.md#user-risk)</li><li>[Device platforms](~/identity/conditional-access/concept-conditional-access-conditions.md#device-platforms)</li><li>[Locations](~/identity/conditional-access/concept-conditional-access-conditions.md#locations)</li></ul>|
|**Grant**|[Grant or block access to resources](~/identity/conditional-access/concept-conditional-access-grant.md)|<ul><li>[Block access](~/identity/conditional-access/concept-conditional-access-grant.md#block-access)</li><li>[Require multifactor authentication](./how-to-multifactor-authentication-customers.md)</li><li>[Require password reset](./how-to-enable-password-reset-customers.md)</li></ul>|
|**Session**|[Session controls](~/identity/conditional-access/concept-conditional-access-session.md)|Not available|
ms.subservice: external
ms.topic: concept-article
ms.date: 05/15/2025
ms.author: mimart
ms.custom: it-pro, seo-july-2024
 
 
|Feature |Workforce tenant | External tenant |
|---------|---------|---------|
| **Identity providers for external users (primary authentication)** | **For self-service sign-up guests**</br>- Microsoft Entra accounts</br>- Microsoft accounts</br>- Email one-time passcode</br>- Google federation</br>- Facebook federation<br></br>**For invited guests**</br>- Microsoft Entra accounts</br>- Microsoft accounts</br>- Email one-time passcode</br>- Google federation</br>- SAML/WS-Fed federation | **For self-service sign-up users (consumers, business customers)**</br>- [Email with password](concept-authentication-methods-customers.md#email-and-password-sign-in)</br>- [Email one-time passcode](./concept-authentication-methods-customers.md#email-with-one-time-passcode-sign-in)</br>- [Google federation (preview)](./how-to-google-federation-customers.md)</br>- [Facebook federation (preview)](./how-to-facebook-federation-customers.md)</br>- [Apple federation (preview)](./how-to-apple-federation-customers.md)</br>- [OpenID Connect federation](./how-to-custom-oidc-federation-customers.md)<br></br>**For invited guests (preview)**</br>Guests invited with a directory role (for example, admins):</br>- Microsoft Entra accounts </br>- Microsoft accounts </br>- [Email one-time passcode](./concept-authentication-methods-customers.md#email-with-one-time-passcode-sign-in)<br>- [SAML/WS-Fed federation](../direct-federation.md) |
| **Authentication methods for MFA** | **For internal users (employees and admins)** </br>- [Authentication and verification methods](~/identity/authentication/concept-authentication-methods.md) </br>**For guests (invited or self-service sign-up)** </br>- [Authentication methods for guest MFA](../authentication-conditional-access.md#table-1-authentication-strength-mfa-methods-for-external-users) | **For self-service sign-up users (consumers, business customers) or invited users (preview)**</br>- [Email one-time passcode](concept-multifactor-authentication-customers.md#email-one-time-passcode)</br>- [SMS-based authentication](concept-multifactor-authentication-customers.md#sms-based-authentication) |
 
## Application registration
|---------|---------|---------|
| **Assignments**| [Users, groups](~/identity/conditional-access/concept-conditional-access-users-groups.md), and [workload identities](~/identity/conditional-access/concept-conditional-access-users-groups.md#workload-identities) | Include **all users**, and exclude users and groups. For more information, see [Add multifactor authentication (MFA) to an app](./how-to-multifactor-authentication-customers.md).|
|**Target resources**|<ul><li>[Cloud apps](~/identity/conditional-access/concept-conditional-access-cloud-apps.md)</li><li>[User actions](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#user-actions)</li><li>[Global Secure Access](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#traffic-forwarding-profiles)</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|<ul><li>[All resources, selected apps](./how-to-multifactor-authentication-customers.md), or [filter applications](~/identity/conditional-access/concept-filter-for-applications.md).</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|
| **Conditions**|<ul><li>[Sign-in risk](~/identity/conditional-access/concept-conditional-access-conditions.md#sign-in-risk)</li><li>[User risk](~/identity/conditional-access/concept-conditional-access-conditions.md#user-risk)</li><li>[Device platforms](~/identity/conditional-access/concept-conditional-access-conditions.md#device-platforms)</li><li>[Locations](~/identity/conditional-access/concept-conditional-access-conditions.md#locations)</li><li>[Client apps](~/identity/conditional-access/concept-conditional-access-conditions.md#client-apps)</li><li>[Filter for devices](~/identity/conditional-access/concept-conditional-access-conditions.md#filter-for-devices)</li></ul>|<ul><li>[Device platforms](~/identity/conditional-access/concept-conditional-access-conditions.md#device-platforms)</li><li>[Locations](~/identity/conditional-access/concept-conditional-access-conditions.md#locations)</li></ul>|
|**Grant**|[Grant or block access to resources](~/identity/conditional-access/concept-conditional-access-grant.md)|<ul><li>[Block access](~/identity/conditional-access/concept-conditional-access-grant.md#block-access)</li><li>[Require multifactor authentication](./how-to-multifactor-authentication-customers.md)</li><li>[Require password reset](./how-to-enable-password-reset-customers.md)</li></ul>|
|**Session**|[Session controls](~/identity/conditional-access/concept-conditional-access-session.md)|Not available|
Modified by omondiatieno on May 15, 2025 9:21 PM
πŸ“– View on learn.microsoft.com
+4 / -1 lines changed
Commit: Add include file for sso wizard content
Changes:
Before
After
* Manage your accounts in one central location.
 
## Prerequisites
The scenario outlined in this article assumes that you already have the following prerequisites:
[!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)]
 
## Scenario description
 
1. In the **Add from the gallery** section, type **Salesforce** in the search box.
1. Select **Salesforce** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
 
Alternatively, you can also use the [Enterprise App Configuration Wizard](https://portal.office.com/AdminPortal/home?Q=Docs#/azureadappintegration). In this wizard, you can add an application to your tenant, add users/groups to the app, assign roles, and walk through the SSO configuration as well. [Learn more about Microsoft 365 wizards.](/microsoft-365/admin/misc/azure-ad-setup-guides)
 
<a name='configure-and-test-azure-ad-sso-for-salesforce'></a>
 
 
 
 
* Manage your accounts in one central location.
 
## Prerequisites
 
The scenario outlined in this article assumes that you already have the following prerequisites:
 
[!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)]
- Salesforce single sign-on (SSO) enabled subscription.
 
## Scenario description
 
1. In the **Add from the gallery** section, type **Salesforce** in the search box.
1. Select **Salesforce** from results panel and then add the app. Wait a few seconds while the app is added to your tenant.
 
[!INCLUDE [sso-wizard.md](~/identity/saas-apps/includes/sso-wizard.md)]
 
<a name='configure-and-test-azure-ad-sso-for-salesforce'></a>
 
+2 / -3 lines changed
Commit: Incorporate feedback
Changes:
Before
After
| App or service | Limitations |
| --- | --- |
| Power BI | - Support for UserType Member in Power BI is currently in preview. For more information, see [Distribute Power BI content to external guest users with Microsoft Entra B2B](/power-bi/enterprise/service-admin-azure-ad-b2b#who-can-you-invite). |
| Azure Virtual Desktop | - External member and external guest aren't supported in Azure Virtual Desktop. |
| Azure Virtual Desktop | - For limitations related to Azure Virtual Desktop, see TBD. |
| Microsoft Teams | - For limitations related to Azure Government, see TBD. |
| App or service | Limitations |
| --- | --- |
| Power BI | - Support for UserType Member in Power BI is currently in preview. For more information, see [Distribute Power BI content to external guest users with Microsoft Entra B2B](/power-bi/enterprise/service-admin-azure-ad-b2b#who-can-you-invite). |
| Azure Virtual Desktop | - For limitations, see [Prerequisites for Azure Virtual Desktop](/azure/virtual-desktop/prerequisites#users). |
| Microsoft Teams | - For limitations, see [Collaborate with guests from other Microsoft 365 cloud environments](/microsoft-365/solutions/collaborate-guests-cross-cloud). |
 
+2 / -2 lines changed
Commit: added two more default numbers
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: how-to
ms.date: 03/24/2025
 
ms.author: justinha
author: justinha
 
In the United States, if you haven't configured MFA caller ID, voice calls from Microsoft come from the following numbers. Users with spam filters should exclude these numbers.
 
Default number: *+1 (855) 330-8653*
 
The following table lists more numbers for different countries/regions.
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: how-to
ms.date: 05/14/2025
 
ms.author: justinha
author: justinha
 
In the United States, if you haven't configured MFA caller ID, voice calls from Microsoft come from the following numbers. Users with spam filters should exclude these numbers.
 
Default numbers: *+1 (855) 330-8653*, *+1 (855) 336-2194*, *+1 (855) 341-5605*
 
The following table lists more numbers for different countries/regions.