📋 Microsoft Entra Documentation Changes

Changes for May 29th 2025

Period: May 28th 2025, 12:00 AM to May 29th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 29th 2025.

📊 Summary

78
Total Commits
2
New Files
34
Modified Files
1
Deleted Files
21
Contributors

🆕 New Documentation Files

+488 lines added
Commit: renamed and removed files for review
+56 lines added
Commit: Reference article added

📝 Modified Documentation Files

+62 / -62 lines changed
Commit: Beta references update
Changes:
Before
After
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: how-to
ms.date: 10/15/2024
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
 
# [PowerShell](#tab/ms-powershell)
 
1. In the owner tenant, use the [Update-MgBetaTenantRelationshipMultiTenantOrganization](/powershell/module/microsoft.graph.beta.identity.signins/update-mgbetatenantrelationshipmultitenantorganization) command to create your multitenant organization. This operation can take a few minutes.
 
```powershell
Update-MgBetaTenantRelationshipMultiTenantOrganization -DisplayName "Cairo"
```
 
1. Use the [Get-MgBetaTenantRelationshipMultiTenantOrganization](/powershell/module/microsoft.graph.beta.identity.signins/get-mgbetatenantrelationshipmultitenantorganization) command to check that the operation has completed before proceeding.
 
```powershell
Get-MgBetaTenantRelationshipMultiTenantOrganization | Format-List
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: how-to
ms.date: 05/27/2025
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
 
# [PowerShell](#tab/ms-powershell)
 
1. In the owner tenant, use the [Update-MgTenantRelationshipMultiTenantOrganization](/powershell/module/microsoft.graph.identity.signins/update-mgtenantrelationshipmultitenantorganization) command to create your multitenant organization. This operation can take a few minutes.
 
```powershell
Update-MgTenantRelationshipMultiTenantOrganization -DisplayName "Cairo"
```
 
1. Use the [Get-MgTenantRelationshipMultiTenantOrganization](/powershell/module/microsoft.graph.identity.signins/get-mgtenantrelationshipmultitenantorganization) command to check that the operation has completed before proceeding.
 
```powershell
Get-MgTenantRelationshipMultiTenantOrganization | Format-List
Modified by Ortagus Winfrey on May 28, 2025 10:09 AM
📖 View on learn.microsoft.com
+111 / -0 lines changed
Commit: November 2024 added to archive
Changes:
Before
After
 
---
 
## October 2024
 
### Public Preview - Passkey authentication in brokered Microsoft apps on Android
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
---
 
## November 2024
 
### Public Preview - Universal Continuous Access Evaluation
 
**Type:** New feature
**Service category:** Provisioning
**Product capability:** Network Access
 
Continuous Access Evaluation (CAE) revokes, and revalidates, network access in near real-time whenever Microsoft Entra ID detects changes to the identity. For more information, see: [Universal Continuous Access Evaluation (Preview)](../global-secure-access/concept-universal-continuous-access-evaluation.md).
 
---
 
### Public Preview - Microsoft Entra new store for certificate-based authentication
 
**Type:** New feature
**Service category:** Authentications (Logins)
**Product capability:** User Authentication
Modified by Ortagus Winfrey on May 28, 2025 10:09 AM
📖 View on learn.microsoft.com
+0 / -100 lines changed
Commit: November 2024 added to archive
Changes:
Before
After
 
---
 
 
## November 2024
 
### Public Preview - Universal Continuous Access Evaluation
 
**Type:** New feature
**Service category:** Provisioning
**Product capability:** Network Access
 
Continuous Access Evaluation (CAE) revokes, and revalidates, network access in near real-time whenever Microsoft Entra ID detects changes to the identity. For more information, see: [Universal Continuous Access Evaluation (Preview)](../global-secure-access/concept-universal-continuous-access-evaluation.md).
 
 
### Public Preview - Microsoft Entra new store for certificate-based authentication
 
**Type:** New feature
**Service category:** Authentications (Logins)
**Product capability:** User Authentication
 
---
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
+4 / -59 lines changed
Commit: Removed SPO references
Changes:
Before
After
 
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::
 
## Linkable identifiers in Microsoft SharePoint Online audit logs
 
Microsoft SharePoint Online audit logs provide a comprehensive audit trail of all requests processed by the SharePoint Online service for a tenant. These logs capture a wide range of user activities, including operations such as file and folder creation, updates, deletions, and list modifications. For a detailed overview of SharePoint Online audit logging, see [SharePoint Online Audit Logs](/purview/audit-log-sharing?tabs=microsoft-purview-portal).
 
**Investigation Scenarios Using Linkable Identifiers**
 
For scenarios involving SharePoint Online activity, you can:
 
- Start with linkable identifiers from Microsoft Entra sign-in logs, such as SID or UTI.
- Use these identifiers to search Microsoft Purview Audit (Standard) or Audit (Premium) logs.
- Track all user actions performed within SharePoint Online during a specific session or by a specific token.
 
This approach enables security analysts to correlate authentication events with SharePoint activity, supporting effective investigation and response to potential threats.
 
For guidance on searching SharePoint Online audit logs, see [Search the audit log | Microsoft Learn](/purview/audit-search).
 
The table below shows the mapping between linkable identifier claims and Microsoft SharePoint Online audit log attribute.
 
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::
 
## Linkable identifiers in Microsoft Teams audit logs
 
Microsoft Teams audit logs capture a detailed record of all requests processed by the Teams service for a tenant. Audited activities include team creation and deletion, channel additions and removals, and changes to channel settings.
| Admin | TeamsAdminAction, TeamsTenantSettingChanged |
| Team/User | TeamDeleted, TeamSettingChanged, MemberAdded, MemberRoleChanged, TeamsSessionStarted |
 
## Investigating Token Misuse in Microsoft Teams
 
In the event of a security incident where an access token is compromised—such as through phishing—and subsequently used by a malicious actor, tenant administrators should take immediate action to contain the threat and investigate its impact.
 
Using linkable identifiers such as the Session ID (SID) and Unique Token Identifier (UTI) from Microsoft Entra sign-in logs, administrators can correlate and trace activity across Microsoft Purview Audit (Standard) and Audit (Premium) logs. This enables visibility into:
 
Teams-related actions such as team or channel creation, deletion, or configuration changes.
 
1. Start with Microsoft Entra sign-in logs to find the session id of this access token by filtering around the time the token was phished and the user objectId.
 
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/linkable-signinlog-entries.png" alt-text="Screenshot of Microsoft Purview portal showing log item with linkable identifiers for Teams scenario.":::
+30 / -30 lines changed
Commit: May 27 updates per PM feedback
Changes:
Before
After
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/16/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
 
| Certification | Details | Inherited from | Status |
| --- | --- | --- | --- |
| [Canadian Privacy Laws](https://global.azure.com/auditmanager/certificates/views/cert/217) | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canada privacy laws](/azure/compliance/offerings/offering-canada-privacy-laws). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [CDSA](https://global.azure.com/auditmanager/certificates/views/cert/94) | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [CDSA](/azure/compliance/offerings/offering-cdsa). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | Certification available |
| [CSA STAR](https://global.azure.com/auditmanager/certificates/views/cert/132) | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [Cloud Security Alliance (CSA) STAR Certification](/azure/compliance/offerings/offering-csa-star-certification). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [DoD DISA SRG Level 2](https://global.azure.com/auditmanager/certificates/views/cert/122) | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [Department of Defense (DoD) Impact Level 2 (IL2)](/azure/compliance/offerings/offering-dod-il2). | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [EAR](https://global.azure.com/auditmanager/certificates/views/cert/191) | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [Export Administration Regulations (EAR)](/azure/compliance/offerings/offering-ear). | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [Federal Risk and Authorization Management Program (FedRAMP)](/azure/compliance/offerings/offering-fedramp). | NA | |
| [FIPS 140-2](https://global.azure.com/auditmanager/certificates/views/cert/147) | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [Federal Information Processing Standard (FIPS) 140](/azure/compliance/offerings/offering-fips-140-2). | [FedRAMP High](https://global.azure.com/auditmanager/certificates/views/cert/139) | |
| [GDPR](https://global.azure.com/auditmanager/certificates/views/cert/218) | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [General Data Protection Regulation summary](/compliance/regulatory/gdpr). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [GxP (FDA 21 CFR Part 11)](https://global.azure.com/auditmanager/certificates/views/cert/156) | Azure can help customers meet their requirements under Good Clinical, Laboratory, and Manufacturing Practices (GxP), as well as regulations enforced by the US Food and Drug Administration (FDA) under 21 CFR Part 11. For more information, see [GxP (FDA 21 CFR Part 11)](/azure/compliance/offerings/offering-gxp). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
| [HDS (France)](https://global.azure.com/auditmanager/certificates/views/cert/209) | Microsoft Azure has the Health Data Hosting (Hébergeurs de Données de Santé, HDS) certification, which is required for all entities that host personal health data governed by French law. Microsoft is the first major cloud service provider to meet the strict French standards for storing and processing health data. For more information, see [Health Data Hosting (HDS) France](/compliance/regulatory/offering-hds-france). | [ISO 27001:2013](https://global.azure.com/auditmanager/certificates/views/cert/95) | |
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/27/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
 
| Certification | Details | Inherited from | Status |
| --- | --- | --- | --- |
| Canadian Privacy Laws | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canada privacy laws](/azure/compliance/offerings/offering-canada-privacy-laws). | ISO 27001:2013 | |
| CDSA | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [CDSA](/azure/compliance/offerings/offering-cdsa). | ISO 27001:2013 | Certification available |
| CSA STAR | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [Cloud Security Alliance (CSA) STAR Certification](/azure/compliance/offerings/offering-csa-star-certification). | ISO 27001:2013 | |
| DoD DISA SRG Level 2 | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [Department of Defense (DoD) Impact Level 2 (IL2)](/azure/compliance/offerings/offering-dod-il2). | FedRAMP High | |
| EAR | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [Export Administration Regulations (EAR)](/azure/compliance/offerings/offering-ear). | FedRAMP High | |
| FedRAMP High | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [Federal Risk and Authorization Management Program (FedRAMP)](/azure/compliance/offerings/offering-fedramp). | NA | |
| FIPS 140-2 | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [Federal Information Processing Standard (FIPS) 140](/azure/compliance/offerings/offering-fips-140-2). | FedRAMP High | |
| GDPR | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [General Data Protection Regulation summary](/compliance/regulatory/gdpr). | ISO 27001:2013 | |
| GxP (FDA 21 CFR Part 11) | Azure can help customers meet their requirements under Good Clinical, Laboratory, and Manufacturing Practices (GxP), as well as regulations enforced by the US Food and Drug Administration (FDA) under 21 CFR Part 11. For more information, see [GxP (FDA 21 CFR Part 11)](/azure/compliance/offerings/offering-gxp). | ISO 27001:2013 | |
| HDS (France) | Microsoft Azure has the Health Data Hosting (Hébergeurs de Données de Santé, HDS) certification, which is required for all entities that host personal health data governed by French law. Microsoft is the first major cloud service provider to meet the strict French standards for storing and processing health data. For more information, see [Health Data Hosting (HDS) France](/compliance/regulatory/offering-hds-france). | ISO 27001:2013 | |
+31 / -3 lines changed
Commit: edge reset certificate choice
Changes:
Before
After
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/validation-error.png" alt-text="Screenshot of a certificate validation error." :::
 
If CBA fails on a browser, even if the failure is because you cancel the certificate picker, you need to close the browser session and open a new session to try CBA again. A new session is required because browsers cache the certificate. When CBA is retried, the browser sends the cached certificate during the TLS challenge, which causes sign-in failure and the validation error.
Select **More details** to get logging information that can be sent to an Authentication Policy Administrator, who in turn can get more information from the Sign-in logs.
 
 
Select **Other ways to sign in** to try other methods available to the user to sign in.
>[!NOTE]
>If you retry CBA in a browser, it'll keep failing due to the browser caching issue. Users need to open a new browser session and sign in again.
 
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/new-sign-in.png" alt-text="Screenshot of a new sign-in attempt." :::
 
## Certificate-based authentication in MostRecentlyUsed (MRU) methods
Once a user authenticates successfully using CBA, the user's MostRecentlyUsed (MRU) authentication method is set to CBA. Next time, when the user enters their UPN and selects **Next**, the user is taken to the CBA method directly, and need not select **Use the certificate or smart card**.
 
To reset the MRU method, the user needs to cancel the certificate picker, select **Other ways to sign in**, and select another method available to the user and authenticate successfully.
 
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/validation-error.png" alt-text="Screenshot of a certificate validation error." :::
 
If CBA fails on a browser, even if the failure is because you cancel the certificate picker, you need to close the browser session and open a new session to try CBA again. A new session is required because browsers cache the certificate. When CBA is retried, the browser sends the cached certificate during the TLS challenge, which causes sign-in failure and the validation error.
 
>[!NOTE]
>However, Edge browser has added a new feature to [reset the certificate selection without restarting the browser](concept-certificate-based-authentication-technical-deep-dive.md#reset-the-certificate-choice-on-edge-browser).
Select **More details** to get logging information that can be sent to an Authentication Policy Administrator, who in turn can get more information from the Sign-in logs.
 
 
Select **Other ways to sign in** to try other methods available to the user to sign in.
:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/new-sign-in.png" alt-text="Screenshot of a new sign-in attempt." :::
 
## Reset the certificate choice on edge browser
 
If CBA fails on a browser, even if the failure is because you cancel the certificate picker, you need to close the browser session and open a new session to try CBA again as the browsers cache the certificate. However, Edge browser had added a new enhancement to reset the certificate choice on the browser.
 
1. When CBA fails, the user will be sent to error page
 
Modified by shlipsey3 on May 28, 2025 3:37 AM
📖 View on learn.microsoft.com
+15 / -15 lines changed
Commit: freshness
Changes:
Before
After
description: Workload identity risk in Microsoft Entra ID Protection
ms.service: entra-workload-id
ms.topic: conceptual
ms.date: 01/16/2024
author: shlipsey3
ms.author: sarahlipsey
manager: femila
> Full risk details and risk-based access controls are available to Workload Identities Premium customers; however, customers without the [Workload Identities Premium](https://entra.microsoft.com/#view/Microsoft_Azure_ManagedServiceIdentity/WorkloadIdentitiesBlade) licenses still receive all detections with limited reporting details.
 
> [!NOTE]
> ID Protection detects risk on single tenant, third party SaaS, and multitenant apps. Managed Identities aren't currently in scope.
 
## Prerequisites
 
To make use of workload identity risk reports, including the **Risky workload identities** blade and the **Workload identity detections** tab in the **Risk detections** blade in the portal, you must have the following.
 
- One of the following administrator roles assigned
- Security Administrator
- Security Operator
- Security Reader
description: Workload identity risk in Microsoft Entra ID Protection
ms.service: entra-workload-id
ms.topic: conceptual
ms.date: 05/27/2025
author: shlipsey3
ms.author: sarahlipsey
manager: femila
> Full risk details and risk-based access controls are available to Workload Identities Premium customers; however, customers without the [Workload Identities Premium](https://entra.microsoft.com/#view/Microsoft_Azure_ManagedServiceIdentity/WorkloadIdentitiesBlade) licenses still receive all detections with limited reporting details.
 
> [!NOTE]
> ID Protection detects risk on single tenant, non-Microsoft SaaS, and multitenant apps. Managed Identities aren't currently in scope.
 
## Prerequisites
 
To make use of workload identity risk reports, including **Risky workload identities** and the **Workload identity detections** tab in the **Risk detections** in the admin center, you must have the following.
 
- One of the following administrator roles assigned
- [Security Administrator](../identity/role-based-access-control/permissions-reference.md#security-administrator)
- [Security Operator](../identity/role-based-access-control/permissions-reference.md#security-operator)
- [Security Reader](../identity/role-based-access-control/permissions-reference.md#security-reader)
+15 / -10 lines changed
Commit: freshness
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 01/16/2024
 
author: shlipsey3
ms.author: sarahlipsey
---
# Microsoft Entra ID Protection and the Microsoft Graph PowerShell
 
Microsoft Graph is the Microsoft unified API endpoint and the home of [Microsoft Entra ID Protection](./overview-identity-protection.md) APIs. This article shows you how to use the [Microsoft Graph PowerShell SDK](/powershell/microsoftgraph/get-started) to manage risky users using PowerShell. Organizations that want to query the Microsoft Graph APIs directly can use the article, [Tutorial: Identify and remediate risks using Microsoft Graph APIs](/graph/tutorial-riskdetection-api) to begin that journey.
 
To successfully complete this tutorial, make sure you have the required prerequisites:
 
- Microsoft Graph PowerShell SDK is installed. For more information, see the article [Install the Microsoft Graph PowerShell SDK](/powershell/microsoftgraph/installation?view=graph-powershell-1.0&preserve-view=true).
- Microsoft Graph PowerShell using a [Security Administrator](~/identity/role-based-access-control/permissions-reference.md#security-administrator) role. The IdentityRiskEvent.Read.All, IdentityRiskyUser.ReadWrite.All Or IdentityRiskyUser.ReadWrite.All delegated permissions are required. To set the permissions to IdentityRiskEvent.Read.All and IdentityRiskyUser.ReadWrite.All, run:
 
```powershell
Connect-MgGraph -Scopes "IdentityRiskEvent.Read.All","IdentityRiskyUser.ReadWrite.All"
```
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 05/27/2025
 
author: shlipsey3
ms.author: sarahlipsey
---
# Microsoft Entra ID Protection and the Microsoft Graph PowerShell
 
Microsoft Graph is the Microsoft unified API endpoint and the home of [Microsoft Entra ID Protection](./overview-identity-protection.md) APIs. This article shows you how to use the [Microsoft Graph PowerShell SDK](/powershell/microsoftgraph/get-started) to manage risky users with PowerShell. Organizations that want to query the Microsoft Graph APIs directly can use the article, [Tutorial: Identify and remediate risks using Microsoft Graph APIs](/graph/tutorial-riskdetection-api) to begin that journey.
 
## Prerequisites
 
To use the PowerShell commands in this article, you need the following prerequisites:
 
- Microsoft Graph PowerShell SDK is installed.
- For more information, see the article [Install the Microsoft Graph PowerShell SDK](/powershell/microsoftgraph/installation?view=graph-powershell-1.0&preserve-view=true).
- [Security Administrator](~/identity/role-based-access-control/permissions-reference.md#security-administrator) role.
- `IdentityRiskEvent.Read.All`, `IdentityRiskyUser.ReadWrite.All` Or `IdentityRiskyUser.ReadWrite.All` delegated permissions are required.
Modified by Derdus Kenga on May 28, 2025 3:15 AM
📖 View on learn.microsoft.com
+12 / -13 lines changed
Commit: Retract native auth update
Changes:
Before
After
---
title: Add a platform to your app registration
description: Learn how to add a platform to your app in Microsoft Entra to securely handle authentication tokens and enhance your application's security.
author: cilwerner
manager: CelesteDG
ms.author: cwerner
#Customer intent: As developer, I want to know how to register my application in Microsoft Entra tenant. I want to understand the additional configurations to help make my application secure.
---
 
# Add a platform to your app registration
 
The Microsoft identity platform supports authentication for modern application types such as web applications, single-page applications (SPA) and mobile and desktop apps. After you register your app in the Microsoft Entra admin center, specify the app type by setting up an app platform and other authentication settings for your platform.
 
When you add a platform to your app registration, specify a redirect URI. The redirect URI is the endpoint where the Microsoft identity platform sends security tokens after a user authenticates. This URI is a key security measure that makes sure security tokens go only to the intended recipient.
 
## Prerequisites
 
* [Quickstart: Register an app in Microsoft Entra ID](quickstart-register-app.md).
 
## Add a platform to your app
---
title: "How to add a redirect URI to your application"
description: Learn how to add a redirect URI to your application in Microsoft Entra to securely handle authentication tokens and enhance app security.
author: cilwerner
manager: CelesteDG
ms.author: cwerner
#Customer intent: As developer, I want to know how to register my application in Microsoft Entra tenant. I want to understand the additional configurations to help make my application secure.
---
 
# How to add a redirect URI to your application
 
To sign in a user, your application must send a login request to the Microsoft Entra authorization endpoint, with a redirect URI specified as a parameter. The redirect URI is a critical security feature that ensures the Microsoft Entra authentication server only sends authorization codes and access tokens to the intended recipient.
 
## Prerequisites
 
* [Quickstart: Register an app in Microsoft Entra ID](quickstart-register-app.md).
 
## Add a redirect URI
 
A *redirect URI* is where the Microsoft identity platform sends security tokens after authentication. Redirect URIs are configured in **Platform configurations** in the Microsoft Entra admin center. For **Web** and **Single-page applications**, you need to specify a redirect URI manually. For **Mobile and desktop** platforms, you select from generated redirect URIs.
+11 / -10 lines changed
Commit: freshness
Changes:
Before
After
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 05/06/2025
ms.author: sarahlipsey
ms.reviewer: madansr7
ms.custom: sfi-image-nochange
 
To access the data from Usage and insights you must have:
 
* A Microsoft Entra tenant
* A Microsoft Entra ID P1 or P2 license to view the sign-in data
* A user in the Reports Reader, Security Reader, or Security Administrator role.
 
## Access Usage and insights
 
 
Viewing the AD FS application activity using Microsoft Graph retrieves a list of the `relyingPartyDetailedSummary` objects, which identifies the relying party to a particular Federation Service.
 
Add the following query, then select the **Run query** button.
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 05/27/2025
ms.author: sarahlipsey
ms.reviewer: madansr7
ms.custom: sfi-image-nochange
 
To access the data from Usage and insights you must have:
 
- A Microsoft Entra tenant
- A Microsoft Entra ID P1 or P2 license to view the sign-in data
- The least privileged role is [Reports Reader](../role-based-access-control/permissions-reference.md#reports-reader).
- [Security Reader](../role-based-access-control/permissions-reference.md#security-reader) and [Security Administrator](../role-based-access-control/permissions-reference.md#security-reader) can also view the report.
 
## Access Usage and insights
 
 
Viewing the AD FS application activity using Microsoft Graph retrieves a list of the `relyingPartyDetailedSummary` objects, which identifies the relying party to a particular Federation Service.
 
+9 / -9 lines changed
Commit: Beta references update
Changes:
Before
After
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: how-to
ms.date: 10/15/2024
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
**Request**
 
```http
PATCH https://graph.microsoft.com/beta/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration
 
{
"inboundTrust": {
**Request**
 
```http
PATCH https://graph.microsoft.com/beta/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration
 
{
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: how-to
ms.date: 05/27/2025
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
**Request**
 
```http
PATCH https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration
 
{
"inboundTrust": {
**Request**
 
```http
PATCH https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/templates/multiTenantOrganizationPartnerConfiguration
 
{
+8 / -6 lines changed
Commit: freshness
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 07/16/2024
 
author: shlipsey3
ms.author: sarahlipsey
---
# How To: Give risk feedback in Microsoft Entra ID Protection
 
Microsoft Entra ID Protection allows you to give feedback on its risk assessment. The following document lists the scenarios where you would like to give feedback on Microsoft Entra ID Protection's risk assessment and how we incorporate it.
 
Your feedback helps us optimize detections in the future, improve their accuracy, and reduce false positives.
 
## What is a detection?
 
An ID Protection detection is an indicator of suspicious activity from an identity risk perspective. These suspicious activities are called risk detections. These identity-based detections can be based on heuristics, machine learning or can come from partner products. These detections are used to determine sign-in risk and user risk,
 
* User risk represents the probability an identity is compromised.
* Sign-in risk represents the probability a sign-in is compromised (for example, the identity owner didn't authorize the sign-in).
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 05/27/2025
 
author: shlipsey3
ms.author: sarahlipsey
---
# How To: Give risk feedback in Microsoft Entra ID Protection
 
Microsoft Entra ID Protection allows you to give feedback on its risk assessment.
 
Your feedback helps us optimize detections in the future, improve their accuracy, and reduce false positives.
 
## What is a detection?
 
An ID Protection detection is an indicator of suspicious activity related to identity risk. These suspicious activities are called risk detections. These identity-based detections can be based on heuristics, machine learning or can come from partner products. These detections are used to determine sign-in risk and user risk:
 
* User risk represents the probability an identity is compromised.
* Sign-in risk represents the probability a sign-in is compromised (for example, the identity owner didn't authorize the sign-in).
Modified by Janice Ricketts on May 28, 2025 4:30 AM
📖 View on learn.microsoft.com
+4 / -6 lines changed
Commit: Update gsa-poc-internet-access.md
Changes:
Before
After
 
### Implement universal tenant restrictions
 
[Universal tenant restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md) enable you to control access to external tenants by unmanaged identities on company-managed devices and networks. You can enforce this restriction at the authentication plane with tenant restrictions v1, by either blocking or allowing all traffic to an external tenant.
 
This scenario usually requires hair-pinning traffic to a corporate network proxy. With universal tenant restrictions, organizations can restrict access on a per-application level, extend protection to the data plane (in addition to the authentication plane), and eliminate the need to hair-pin traffic to reduce network latency.
 
After you enable the Microsoft traffic profile, follow these steps to implement universal tenant restrictions:
 
 
1. [Enable Global Secure Access signaling for tenant restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md#enable-global-secure-access-signaling-for-tenant-restrictions).
 
1. Sign in to your test device and try to access a different tenant's SharePoint Online or Exchange Online resource for which you have valid credentials.
 
1. [Validate authentication plane protection](../global-secure-access/how-to-universal-tenant-restrictions.md#validate-the-authentication-plane-protection).
 
1. [Validate data plane protection](../global-secure-access/how-to-universal-tenant-restrictions.md#validate-the-data-plane-protection).
 
## Troubleshoot
 
 
### Implement universal tenant restrictions
 
[Universal tenant restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md) enable you to control access to external tenants by unmanaged identities on company-managed devices and networks. You can enforce this restriction with Entra ID Tenant Restrictions, by either blocking or allowing all traffic to an external tenant.
 
This scenario usually requires that you send all of your traffic through a corporate network proxy. With Universal Tenant Restrictions, organizations can apply tenant restrictions policies to users on any device with the Global Secure Access client, without the need to implement VPN and send traffic through a specific proxy, reducing network latency.
 
After you enable the Microsoft traffic profile, follow these steps to implement universal tenant restrictions:
 
 
1. [Enable Global Secure Access signaling for tenant restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md#enable-global-secure-access-signaling-for-tenant-restrictions).
 
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
 
1. [Validate Univeral Tenant Restrictions](../global-secure-access/how-to-universal-tenant-restrictions.md#validate-the-authentication-plane-protection).
 
## Troubleshoot
 
 
 
+6 / -3 lines changed
Commit: image-refresh
Changes:
Before
After
ms.service: entra-id
ms.topic: how-to
ms.subservice: monitoring-health
ms.date: 05/07/2025
ms.author: sarahlipsey
ms.reviewer: deawari
 
 
## What do the recommendation emails contain?
 
The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, are not promotional or marketing emails, and do not contain any upsell content. They are purely informational and designed to help you act quickly when a new recommendation is available.
 
## How to update your email notification settings
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator).
1. Browse to **Identity** > **Overview** > **Recommendations**.
1. Select **Email settings**.
1. In the **Recommendation email settings** panel that opens, uncheck the **Send email notifications for new recommendations** box.
 
All email notifications for all Microsoft Entra recommendations are now blocked and are no longer sent to the tenant's administrative roles.
ms.service: entra-id
ms.topic: how-to
ms.subservice: monitoring-health
ms.date: 05/27/2025
ms.author: sarahlipsey
ms.reviewer: deawari
 
 
## What do the recommendation emails contain?
 
The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, aren't promotional or marketing emails, and don't contain any upselling content. These emails are purely informational and designed to help you act quickly when a new recommendation is available.
 
## How to update your email notification settings
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator).
1. Browse to **Identity** > **Overview** > **Recommendations**.
1. Select **Email settings**.
 
:::image type="content" source="media/howto-configure-recommendation-email-notification/recommendation-email-settings.png" alt-text="Screenshot of the recommendations page with the email settings button highlighted.":::
 
+0 / -9 lines changed
Commit: Remove diagnostic logs details section
Changes:
Before
After
- *Who are the owners of the Finance Department group?*
- *What roles does this group have?*
 
### Get diagnostic logs details
 
Finally, Natasha reviews the diagnostic logs to get more detailed information about the system’s operations during the times of the suspicious activities. She filters the logs by Karita’s user ID and the times of the unusual sign-ins.
 
She uses the following prompts to get the information she needs:
 
- *What are the diagnostics log configuration for the tenant that is [email protected] registered in?*
- *Which logs are being collected in this tenant?*
 
## Remediate
 
By using Security Copilot, Natasha is able to gather comprehensive information about the user, sign-in activities, audit logs, risky user detections, group memberships, and system diagnostics. After completing her investigation, Natasha needs to take action to remediate the risky user or unblock them.
- *Who are the owners of the Finance Department group?*
- *What roles does this group have?*
 
## Remediate
 
By using Security Copilot, Natasha is able to gather comprehensive information about the user, sign-in activities, audit logs, risky user detections, group memberships, and system diagnostics. After completing her investigation, Natasha needs to take action to remediate the risky user or unblock them.
 
 
 
 
 
 
 
 
 

🗑️ Deleted Documentation Files

DELETED docs/identity/hybrid/concept-source-of-authority-overview.md
Deleted by Justin Hall on May 28, 2025 6:34 AM
📖 Was available at: https://learn.microsoft.com/en-us/entra/identity/hybrid/concept-source-of-authority-overview
-485 lines removed
Commit: Delete docs/identity/hybrid/concept-source-of-authority-overview.md