📋 Microsoft Entra Documentation Changes

Changes for May 25th 2025

Period: May 24th 2025, 12:00 AM to May 25th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 25th 2025.

📊 Summary

21
Total Commits
0
New Files
6
Modified Files
0
Deleted Files
9
Contributors

📝 Modified Documentation Files

+9 / -11 lines changed
Commit: May 23 updates per PM feedback
Changes:
Before
After
---
title: Transport Layer Security Inspection (Preview) Overview
description: "This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties."
author: HULKsmashGithub
ms.author: jayrusso
manager: femila
ms.service: global-secure-access
ms.topic: concept-article
ms.date: 04/18/2025
 
#customer intent: As a Global Secure Access administrator, I want to learn about the Transport Layer Security (TLS) protocol to support the creation of TLS inspection policies.
 
---
# Transport Layer Security inspection (preview) overview
The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. This article provides an overview of the TLS inspection process and explains how it enhances security by enabling visibility into encrypted traffic. With TLS inspection, Global Secure Access admins can create and manage TLS inspection policies to detect and mitigate threats hidden within encrypted communications.
 
> [!IMPORTANT]
> The Transport Layer Security inspection feature is currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
---
title: What is Transport Layer Security Inspection? (Preview)
description: "This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties."
author: HULKsmashGithub
ms.author: jayrusso
manager: femila
ms.service: global-secure-access
ms.topic: concept-article
ms.date: 05/23/2025
 
#customer intent: As a Global Secure Access administrator, I want to learn about the Transport Layer Security (TLS) protocol to support the creation of TLS inspection policies.
 
---
# What is Transport Layer Security inspection? (Preview)
The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls.
 
> [!IMPORTANT]
> The Transport Layer Security inspection feature is currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
Modified by Celeste de Guzman on May 24, 2025 2:27 AM
📖 View on learn.microsoft.com
+10 / -10 lines changed
Commit: Updated Microsoft Entra ID to Microsoft Entra
Changes:
Before
After
---
title: Find help and get support for Microsoft Entra ID
description: Instructions about how to get help, find community support, and open a support request for Microsoft Entra ID.
author: shlipsey3
manager: femila
ms.service: entra
ms.topic: troubleshooting
ms.subservice: fundamentals
ms.date: 03/17/2025
ms.author: sarahlipsey
ms.reviewer: jeffsta
---
 
# Find help and get support for Microsoft Entra ID
 
Microsoft documentation and learning content provide quality support and troubleshooting information, but if you have a problem not covered in our content, there are several options to get help and support for Microsoft Entra ID.
 
This article provides the options to find support from the Microsoft community and how to submit a support request with Microsoft.
 
> [!NOTE]
---
title: Find help and get support for Microsoft Entra
description: Instructions about how to get help, find community support, and open a support request for Microsoft Entra.
author: shlipsey3
manager: femila
ms.service: entra
ms.topic: troubleshooting
ms.subservice: fundamentals
ms.date: 05/23/2025
ms.author: sarahlipsey
ms.reviewer: jeffsta
---
 
# Find help and get support for Microsoft Entra
 
Microsoft documentation and learning content provide quality support and troubleshooting information, but if you have a problem not covered in our content, there are several options to get help and support for Microsoft Entra.
 
This article provides the options to find support from the Microsoft community and how to submit a support request with Microsoft.
 
> [!NOTE]
+7 / -12 lines changed
Commit: Updates indentation.
Changes:
Before
After
- Configure the GlobalProtect tunnel settings and app settings to work with Microsoft Entra Private DNS and bypass Microsoft Entra service Fully Qualified Domain Name (FQDN) and Internet Protocol (IP) addresses.
 
> Tunnel Settings:
 
1. In the **Strata Cloud Manager portal**, go to **Workflows** \> **Prisma Access Setup** \> **GlobalProtect** \> **GlobalProtect App** \> **Tunnel Settings**.
2. In the **Split Tunneling** section, exclude traffic by adding the domain and routes: `*.globalsecureaccess.microsoft.com`, `150.171.19.0/24`, `150.171.20.0/24`, `13.107.232.0/24`, `13.107.233.0/24`, `150.171.15.0/24`, `150.171.18.0/24`, `151.206.0.0/16`, `6.6.0.0/16`.
 
> App Settings:
 
1. In the **Strata Cloud Manager portal**, go to **Workflows** \> **Prisma Access Setup** \> **GlobalProtect** \> **GlobalProtect App** \> **App Settings**
1. Scroll to **App Configuration** \> **Show Advanced Options** \> **DNS** and **uncheck** the box for **Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)**
 
> [!NOTE]
> The setting **"Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)"** should be **disabled** when using Microsoft Entra Private DNS (Configurations 1 and 2). During testing, this setting was **enabled** (checked) for Configurations 3 and 4.
 
1. Navigate to **Workflows** \> **Prisma Access Setup** \> **GlobalProtect** \> **GlobalProtect App**. Select **Push Config** and select **Push** on the top right side of your screen.
1. Verify that the configuration pushed to the GlobalProtect client. Navigate to **Manage** \> **Operations** \> **Push Status**.
 
- Install the Palo Alto Networks GlobalProtect client. For more information on installing the Palo Alto Networks GlobalProtect client, for Windows see [GlobalProtect App for Windows](https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-user-guide/globalprotect-app-for-windows). For macOS see, [GlobalProtect App for macOS](https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-user-guide/globalprotect-app-for-mac).
- To set up the GlobalProtect client there are a lot of options like tying in Microsoft Entra ID to create your accounts. To learn more about the options, see [Microsoft Entra single sign-on (SSO) integration with Palo Alto Networks - GlobalProtect](/entra/identity/saas-apps/palo-alto-networks-globalprotect-tutorial). For the most basic setup, add a local user to the GlobalProtect from Palo Alto Networks’ Strata Cloud Manager.
- Configure the GlobalProtect tunnel settings and app settings to work with Microsoft Entra Private DNS and bypass Microsoft Entra service Fully Qualified Domain Name (FQDN) and Internet Protocol (IP) addresses.
 
> Tunnel Settings:
1. In the **Strata Cloud Manager portal**, go to **Workflows** \> **Prisma Access Setup** \> **GlobalProtect** \> **GlobalProtect App** \> **Tunnel Settings**.
1. In the **Split Tunneling** section, exclude traffic by adding the domain and routes: `*.globalsecureaccess.microsoft.com`, `150.171.19.0/24`, `150.171.20.0/24`, `13.107.232.0/24`, `13.107.233.0/24`, `150.171.15.0/24`, `150.171.18.0/24`, `151.206.0.0/16`, `6.6.0.0/16`.
 
> App Settings:
1. In the **Strata Cloud Manager portal**, go to **Workflows** \> **Prisma Access Setup** \> **GlobalProtect** \> **GlobalProtect App** \> **App Settings**
1. Scroll to **App Configuration** \> **Show Advanced Options** \> **DNS** and **uncheck** the box for **Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)**
> [!NOTE]
> The setting **"Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)"** should be **disabled** when using Microsoft Entra Private DNS (Configurations 1 and 2). During testing, this setting was **enabled** (checked) for Configurations 3 and 4.
1. Navigate to **Workflows** \> **Prisma Access Setup** \> **GlobalProtect** \> **GlobalProtect App**. Select **Push Config** and select **Push** on the top right side of your screen.
1. Verify that the configuration pushed to the GlobalProtect client. Navigate to **Manage** \> **Operations** \> **Push Status**.
Install the Palo Alto Networks GlobalProtect client. For more information on installing the Palo Alto Networks GlobalProtect client, for Windows see [GlobalProtect App for Windows](https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-user-guide/globalprotect-app-for-windows). For macOS see, [GlobalProtect App for macOS](https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-user-guide/globalprotect-app-for-mac).
 
To set up the GlobalProtect client there are a lot of options like tying in Microsoft Entra ID to create your accounts. To learn more about the options, see [Microsoft Entra single sign-on (SSO) integration with Palo Alto Networks - GlobalProtect](/entra/identity/saas-apps/palo-alto-networks-globalprotect-tutorial). For the most basic setup, add a local user to the GlobalProtect from Palo Alto Networks’ Strata Cloud Manager.
1. Browse to **Manage** \> **Configuration** \> **NGFW and Prisma Access**.
1. Select **Configuration Scope** \> **GlobalProtect** and then select **Identity Services** \> **Local Users & Groups** \> **Local Users**. Add a user and password for testing.
1. After the client is installed, users enter the portal address and their credentials.
1. After users sign in, the connection icon turns blue, and clicking on shows it in a connected state.
+4 / -4 lines changed
Commit: May 23 updates per PM feedback
Changes:
Before
After
ms.service: global-secure-access
ms.topic: how-to
ms.reviewer: teresayao
ms.date: 05/22/2025
 
 
#customer intent: As a Global Secure Access administrator, I want to configure a context-aware Transport Layer Security inspection policy and assign the policy to users in my organization.
1. Switch to the **TLS inspection settings** tab.
1. Select **+ Create certificate**.
1. In the **Create certificate** pane, fill in the following fields:
- **Certificate name**: Up to 12 characters, no spaces. You can't reuse the name of an existing certificate.
- **Common name** (CN): Common name, for example, Contoso TLS ICA, that identifies the intermediate certificate.
- **Organizational Unit** (OU): Organization name, for example, Contoso IT.
1. Select **Create CSR**.
 
## Related content
 
* [Transport Layer Security Inspection Overview](concept-transport-layer-security.md)
* [Transport Layer Security Inspection Frequently Asked Questions](<resource-faq.yml>)
ms.service: global-secure-access
ms.topic: how-to
ms.reviewer: teresayao
ms.date: 05/23/2025
 
 
#customer intent: As a Global Secure Access administrator, I want to configure a context-aware Transport Layer Security inspection policy and assign the policy to users in my organization.
1. Switch to the **TLS inspection settings** tab.
1. Select **+ Create certificate**.
1. In the **Create certificate** pane, fill in the following fields:
- **Certificate name**: This name appears in the certificate hierarchy when viewed in a browser. It must be unique, contain no spaces, and be no more than 12 characters long. You can't reuse previous names.
- **Common name** (CN): Common name, for example, Contoso TLS ICA, that identifies the intermediate certificate.
- **Organizational Unit** (OU): Organization name, for example, Contoso IT.
1. Select **Create CSR**.
 
## Related content
 
* [What is Transport Layer Security inspection?](concept-transport-layer-security.md)
* [Frequently asked questions for Transport Layer Security inspection](<resource-faq.yml>)
Modified by Bogdan Gavril on May 24, 2025 7:50 AM
📖 View on learn.microsoft.com
+3 / -3 lines changed
Commit: Update certificate-credentials.md
Changes:
Before
After
| --- | --- |
| `alg` | Should be **PS256** |
| `typ` | Should be **JWT** |
| `x5t` | Base64url-encoded SHA-256 thumbprint of the X.509 certificate's DER encoding. |
 
### Claims (payload)
 
{
"alg": "PS256",
"typ": "JWT",
"x5t": "A1bC2dE3fH4iJ5kL6mN7oP8qR9sT0u"
}
.
{
* The last section is the *signature* computed with the certificates from the content of the first two sections
 
```
"eyJhbGciOiJSUzI1NiIsIng1dCI6Imd4OHRHeXN5amNScUtqRlBuZDdSRnd2d1pJMCJ9.eyJhdWQiOiJodHRwczpcL1wvbG9naW4ubWljcm9zb2Z0b25saW5lLmNvbVwvam1wcmlldXJob3RtYWlsLm9ubWljcm9zb2Z0LmNvbVwvb2F1dGgyXC90b2tlbiIsImV4cCI6MTQ4NDU5MzM0MSwiaXNzIjoiOTdlMGE1YjctZDc0NS00MGI2LTk0ZmUtNWY3N2QzNWM2ZTA1IiwianRpIjoiMjJiM2JiMjYtZTA0Ni00MmRmLTljOTYtNjVkYmQ3MmMxYzgxIiwibmJmIjoxNDg0NTkyNzQxLCJzdWIiOiI5N2UwYTViNy1kNzQ1LTQwYjYtOTRmZS01Zjc3ZDM1YzZlMDUifQ.
Gh95kHCOEGq5E_ArMBbDXhwKR577scxYaoJ1P{a lot of characters here}KKJDEg"
```
| --- | --- |
| `alg` | Should be **PS256** |
| `typ` | Should be **JWT** |
| `x5t#S256` | Base64url-encoded SHA-256 thumbprint of the X.509 certificate's DER encoding. |
 
### Claims (payload)
 
{
"alg": "PS256",
"typ": "JWT",
"x5t#S256": "A1bC2dE3fH4iJ5kL6mN7oP8qR9sT0u"
}
.
{
* The last section is the *signature* computed with the certificates from the content of the first two sections
 
```
"eyJhbGciOiJQUzI1NiIsIng1dCNTMjU2IjoiZ3g4dEd5c3lqY1JxS2pGUG5kN1JGd3Z3WkkwIn0.eyJhdWQiOiJodHRwczpcL1wvbG9naW4ubWljcm9zb2Z0b25saW5lLmNvbVwvam1wcmlldXJob3RtYWlsLm9ubWljcm9zb2Z0LmNvbVwvb2F1dGgyXC90b2tlbiIsImV4cCI6MTQ4NDU5MzM0MSwiaXNzIjoiOTdlMGE1YjctZDc0NS00MGI2LTk0ZmUtNWY3N2QzNWM2ZTA1IiwianRpIjoiMjJiM2JiMjYtZTA0Ni00MmRmLTljOTYtNjVkYmQ3MmMxYzgxIiwibmJmIjoxNDg0NTkyNzQxLCJzdWIiOiI5N2UwYTViNy1kNzQ1LTQwYjYtOTRmZS01Zjc3ZDM1YzZlMDUifQ.
Gh95kHCOEGq5E_ArMBbDXhwKR577scxYaoJ1P{a lot of characters here}KKJDEg"
```
+2 / -1 lines changed
Commit: Assign licenses and update the usage location
Changes:
Before
After
ms.service: entra-id
ms.topic: conceptual
ms.subservice: role-based-access-control
ms.date: 05/19/2025
ms.author: rolyon
ms.custom: oldportal, it-pro;, sfi-ga-nochange
---
| Modify email and mailbox settings in Exchange for the user in the restricted management administrative unit | | :white_check_mark: |
| Apply policies to a device in a restricted management administrative unit using Intune | | :white_check_mark: |
| Add or remove a group as a site owner in SharePoint | | :white_check_mark: |
 
## Who can modify objects?
 
 
ms.service: entra-id
ms.topic: conceptual
ms.subservice: role-based-access-control
ms.date: 05/24/2025
ms.author: rolyon
ms.custom: oldportal, it-pro;, sfi-ga-nochange
---
| Modify email and mailbox settings in Exchange for the user in the restricted management administrative unit | | :white_check_mark: |
| Apply policies to a device in a restricted management administrative unit using Intune | | :white_check_mark: |
| Add or remove a group as a site owner in SharePoint | | :white_check_mark: |
| Assign licenses and update the usage location of users in a restricted management administrative unit | | :white_check_mark: |
 
## Who can modify objects?