πŸ“‹ Microsoft Entra Documentation Changes

Changes for May 31st 2025

Period: May 30th 2025, 12:00 AM to May 31st 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on May 31st 2025.

πŸ“Š Summary

54
Total Commits
8
New Files
18
Modified Files
0
Deleted Files
13
Contributors

πŸ†• New Documentation Files

+79 lines added
Commit: entitlement management draft
+55 lines added
Commit: entitlement management draft
+53 lines added
Commit: access reviews draft
Added by Barclay Neira on May 30, 2025 6:37 AM
πŸ“– View on learn.microsoft.com
+23 lines added
Commit: adding the next two includes
Added by Barclay Neira on May 30, 2025 6:37 AM
πŸ“– View on learn.microsoft.com
+23 lines added
Commit: adding the next two includes
Added by Barclay Neira on May 30, 2025 5:45 AM
πŸ“– View on learn.microsoft.com
+23 lines added
Commit: adding a second include to test
Added by Barclay Neira on May 30, 2025 5:21 AM
πŸ“– View on learn.microsoft.com
+23 lines added
Commit: testing one recommendation process
Added by Ortagus Winfrey on May 30, 2025 2:47 AM
πŸ“– View on learn.microsoft.com
+0 lines added
Commit: Updates

πŸ“ Modified Documentation Files

Modified by omondiatieno on May 30, 2025 9:26 PM
πŸ“– View on learn.microsoft.com
+24 / -157 lines changed
Commit: Retire Azure AD PowerShell references
Changes:
Before
After
ms.service: entra
ms.subservice: fundamentals
ms.topic: how-to
ms.date: 11/27/2024
ms.collection: M365-identity-device-management
---
 
# Add or deactivate custom security attribute definitions in Microsoft Entra ID
 
- [Attribute Definition Administrator](~/identity/role-based-access-control/permissions-reference.md#attribute-definition-administrator)
- Microsoft.Graph module when using [Microsoft Graph PowerShell](/powershell/microsoftgraph/installation)
- [AzureADPreview](https://www.powershellgallery.com/packages/AzureADPreview) version 2.0.2.138 or later when using Azure AD PowerShell
 
[!INCLUDE [security-attributes-roles](../includes/security-attributes-roles.md)]
 
 
The following example gets all attribute sets.
 
# [PowerShell](#tab/ms-powershell)
 
ms.service: entra
ms.subservice: fundamentals
ms.topic: how-to
ms.date: 05/30/2025
ms.collection: M365-identity-device-management
 
#customer-intent: As an admin, I want to define and manage custom security attributes in Microsoft Entra ID, so that I can implement fine-grained access control, organize identity data effectively, and support attribute-based access policies across users and applications.
---
 
# Add or deactivate custom security attribute definitions in Microsoft Entra ID
 
- [Attribute Definition Administrator](~/identity/role-based-access-control/permissions-reference.md#attribute-definition-administrator)
- Microsoft.Graph module when using [Microsoft Graph PowerShell](/powershell/microsoftgraph/installation)
 
[!INCLUDE [security-attributes-roles](../includes/security-attributes-roles.md)]
 
 
The following example gets all attribute sets.
 
# [Microsoft Graph PowerShell](#tab/ms-powershell)
Modified by Chris Werner on May 30, 2025 8:22 PM
πŸ“– View on learn.microsoft.com
+39 / -57 lines changed
Commit: add recommendations article draft
Changes:
Before
After
ms.topic: conceptual
ms.service: entra
ms.custom: microsoft-copilot
# Customer intent:
---
 
# Microsoft Entra Recommendations with Microsoft Security Copilot
 
> [!NOTE]
>
> This article is a work in progress. It will be updated with more information, methods, and examples before GA.
 
Keeping track of all the settings and resources in your tenant can be overwhelming. The Microsoft Entra recommendations feature helps monitor the status of your tenant, so you don't have to. Entra Recommendations applies the capabilities of Microsoft Security Copilotβ€― to help your security team investigate how to evolve your tenants to secure and healthy state while also helping you maximize the value of the features available in Microsoft Entra ID.
 
By combining Recommendations signals with the power of generative AI, Security Copilot enables analysts to ask natural language questionsβ€”such as how to improve your secure score, recommendations details, or retrieving details of impacted resources β€”and receive clear insights in seconds.
 
Required
 
Roles: Global Administrator, Application Administrator, IT Governance Administrator, Privileged Role Administrator, Identity Governance Administrator, Conditional Access Administrator, Security Administrator, Hybrid Identity Administrator, Authentication Policy Administrator, Authentication Administrator
 
ms.topic: conceptual
ms.service: entra
ms.custom: microsoft-copilot
# Customer intent: As a security administrator, I want to learn how to use Microsoft Security Copilot to investigate recommendations in Microsoft Entra so that I can evolve my tenant to a secure and healthy state.
---
 
# Microsoft Entra Recommendations with Microsoft Security Copilot
 
> [!NOTE]
> This article is a work in progress. It will be updated with more information, methods, and examples before GA.
>
> The following roles can use this feature: Global Administrator, Application Administrator, IT Governance Administrator, Privileged Role Administrator, Identity Governance Administrator, Conditional Access Administrator, Security Administrator, Hybrid Identity Administrator, Authentication Policy Administrator, Authentication Administrator.
 
Recommendations in Microsoft Entra help you improve the status and security of your tenant by providing actionable insights and guidance. These recommendations cover various areas, including secure score, best practices, conditional access policies, and more. Using the capabilities of Microsoft Security Copilot, you can now interact with these recommendations using natural language, enabling your security team to quickly investigate how to evolve your tenant to a secure and healthy state.
 
This article describes how to use Microsoft Security Copilot to investigate recommendations in Microsoft Entra. This feature is available using a free Microsoft Entra ID license, or a Microsoft Entra ID P1 or P2 license. It is also available in Microsoft Entra Workload ID. You also need to have a cloud tenant with recommendations for maximizing your license on it.
 
## Investigate recommendations in Microsoft Entra
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/) as at least a [Security Administrator](/entra/identity/role-based-access-control/permissions-reference#security-administrator).
Modified by Rohit Gulati on May 30, 2025 4:10 AM
πŸ“– View on learn.microsoft.com
+89 / -3 lines changed
Commit: Updates to helpdesk and IDV partner gallery pages
Changes:
Before
After
ms.author: barclayn
---
 
# Microsoft Entra Verified ID IDV partners
 
Our IDV partner network extends Microsoft Entra Verified ID's capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable remote onboarding using their identity verification and proofing services.
 
## Partner list
 
| IDV partner | Description | Integration walkthroughs |
|:-------------------------|:--------------|:--------------|
|:::image type="content" source="media/partner-gallery/au10tix.png" alt-text="Screenshot of au10tix logo."::: | [AU10TIX](https://www.au10tix.com/solutions/verifiable-credentials/) improves Verifiability While Protecting Privacy For Businesses, Employees, Contractors, Vendors, And Customers. | [Configure Verified ID by AU10TIX as your Identity Verification Partner](https://aka.ms/au10tixvc). |
 
## Next steps
 
Select a partner in the tables mentioned to learn how to integrate their solution with your application.
 
 
 
 
ms.author: barclayn
---
 
# Microsoft Entra Verified ID Identity Verification partners
 
Our Identity Verification (IDV) partner network extends Microsoft Entra Verified ID's capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable scenarios like remote onboarding with government ID checks using identity verification and proofing services.
The diagram below shows a low-level workflow of how all parties interact with each other in an remote onboarding scenario. This integration pattern could be used as a reference.
 
:::image type="content" source="media/partner-gallery/identity-verification-integration.png" alt-text="Screenshot of the IDV integration pattern.":::
 
The following section covers a set of steps that could be used by IDV's for setting up issuance flows and by customers for verifying Verified ID's issued by IDVs.
 
## Issuer ISV (IDV) flow
These are Identity Verification (IDV) ISVs who can use Verified ID Request Service REST API to issue Verified IDs. The steps required by an IDV to function as an issuer are as follows:
 
1. Set up Microsoft Entra Verified ID Service: using [Quick setup](verifiable-credentials-configure-tenant-quick.md) or [Advanced setup instructions](verifiable-credentials-configure-tenant.md).
 
>[!Note]
>For a multi-tenant model, IDV should explore setting up dedicated authorities if there is a 1:1 relationship required with the customer. Refer [Admin API](admin-api.md) section of the docs for creating authorities.
 
+53 / -36 lines changed
Commit: Updates
Changes:
Before
After
---
title: Using groups managed Privileged Identity Management with access packages reference
description: This article serves as a reference for Microsoft Entra ID behavior when assignment periods of an access package and PIM policy dont allign.
author: owinfreyATL
ms.author: owinfrey
manager: femila
 
# Using groups managed by Privileged Identity Management with access packages reference
 
This article contains Microsoft Entra ID behavior in different scenarios if the group managed by PIM and the access package expiration periods differ. By assigning a group managed by PIM to an access package, you're able to assign eligible roles to a group when an access package is requested. If you’re looking for a guide on setting up a group to assign eligible roles via access packages, see: [Assign eligible group membership and ownership in access packages via Privileged Identity Management for Groups (Preview)](entitlement-management-access-package-eligible.md).
 
 
## Entitlement Management
 
> [!Tip]
> We recommend that access packages contain more than one resource role and are modeled on the basis of departments, job functions, locations, projects or a combination of these.
 
|Feature |Limit |
|---------|---------|
|Access Packages | 20,000 per tenant |
---
title: Using groups managed Privileged Identity Management with access packages reference
description: This article serves as a reference for Microsoft Entra ID behavior when assignment periods of an access package and PIM policy dont align.
author: owinfreyATL
ms.author: owinfrey
manager: femila
 
# Using groups managed by Privileged Identity Management with access packages reference
 
This article contains Microsoft Entra ID behavior in scenarios where the group managed by PIM, and the access package expiration periods, differ. By assigning a group managed by PIM to an access package, you're able to assign eligible roles when an access package is requested. If you’re looking for a guide on setting up a group to assign eligible roles via access packages, see: [Assign eligible group membership and ownership in access packages via Privileged Identity Management for Groups (Preview)](entitlement-management-access-package-eligible.md).
 
 
## Shorter access package expiration
 
When an access package's expiration date is shorter than PIM's "*Expire eligible assignments after*" date, then the PIM assignment expires when the access package expires.
 
### Example
 
| Access package policy assignment expiration | PIM policy max assignment duration | Microsoft Entra ID behavior |
|-------------------------------------|-----------------------------------|-----------------------------|
+32 / -32 lines changed
Commit: May 29 final revision per PM feedback; ready to publish
Changes:
Before
After
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/27/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
 
## Supported certifications
Global Secure Access is included in several Azure compliance audits. The supported certifications are:
| Certification | Details | Inherited from | Status |
| --- | --- | --- | --- |
| Canadian Privacy Laws | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canada privacy laws](/azure/compliance/offerings/offering-canada-privacy-laws). | ISO 27001:2013 | |
| CDSA | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [CDSA](/azure/compliance/offerings/offering-cdsa). | ISO 27001:2013 | Certification available |
| CSA STAR | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [Cloud Security Alliance (CSA) STAR Certification](/azure/compliance/offerings/offering-csa-star-certification). | ISO 27001:2013 | |
| DoD DISA SRG Level 2 | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [Department of Defense (DoD) Impact Level 2 (IL2)](/azure/compliance/offerings/offering-dod-il2). | FedRAMP High | |
| EAR | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [Export Administration Regulations (EAR)](/azure/compliance/offerings/offering-ear). | FedRAMP High | |
| FedRAMP High | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [Federal Risk and Authorization Management Program (FedRAMP)](/azure/compliance/offerings/offering-fedramp). | NA | |
| FIPS 140-2 | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [Federal Information Processing Standard (FIPS) 140](/azure/compliance/offerings/offering-fips-140-2). | FedRAMP High | |
| GDPR | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [General Data Protection Regulation summary](/compliance/regulatory/gdpr). | ISO 27001:2013 | |
author: HULKsmashGithub
manager: femila
ms.topic: reference
ms.date: 05/29/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
 
## Supported certifications
Global Secure Access is included in several Azure compliance audits. The supported certifications are:
| Certification | Details | Inherited from |
| --- | --- | --- |
| Canadian Privacy Laws | Canadian privacy laws aim to protect the privacy of individuals and give them the right to access information gathered about them. These privacy laws include the Privacy Act, Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta Personal Information Protection Act (PIPA), and British Columbia Freedom of Information and Protection of Privacy Act (BC FIPPA). For more information, see [Canada privacy laws](/azure/compliance/offerings/offering-canada-privacy-laws). | ISO 27001:2013 |
| CDSA | The Content Delivery & Security Association (CDSA) Content Protection & Security (CPS) standard provides guidance and requirements for securing media assets within a Content Security Management System (CSMS). The standard includes controls to protect intellectual property and keep media assets secure and confidential throughout the digital media supply chain. For more information, see [CDSA](/azure/compliance/offerings/offering-cdsa). | ISO 27001:2013 |
| CSA STAR | Cloud Security Alliance (CSA) STAR certification is based on achieving ISO 27001 certification and meeting criteria in the Cloud Controls Matrix (CCM). It shows that a cloud service provider meets ISO 27001 requirements, addresses key cloud security issues in the CCM, and is assessed against the STAR Capability Maturity Model for managing activities in CCM control areas. For more information, see [Cloud Security Alliance (CSA) STAR Certification](/azure/compliance/offerings/offering-csa-star-certification). | ISO 27001:2013 |
| DoD DISA SRG Level 2 | The Defense Information Systems Agency (DISA) is an agency of the US Department of Defense (DoD) that is responsible for developing and maintaining the DoD Cloud Computing Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by DoD to assess the security posture of a cloud service provider (CSP), supporting the decision to grant a DoD Provisional Authorization (PA) that allows a CSP to host DoD missions. It incorporates, supersedes, and rescinds the previously published DoD Cloud Security Model (CSM). For more information, see [Department of Defense (DoD) Impact Level 2 (IL2)](/azure/compliance/offerings/offering-dod-il2). | FedRAMP High |
| EAR | The US Department of Commerce is responsible for enforcing the Export Administration Regulations (EAR) through the Bureau of Industry and Security (BIS). According to BIS definitions, Export is the transfer of protected technology or information to a foreign destination or release of protected technology or information to a foreign person in the United States (also known as Deemed Export). For more information, see [Export Administration Regulations (EAR)](/azure/compliance/offerings/offering-ear). | FedRAMP High |
| FedRAMP High | The US Federal Risk and Authorization Management Program (FedRAMP) was established in December 2011 to provide a standardized approach for assessing, monitoring, and authorizing cloud service providers (CSPs). For more information, see [Federal Risk and Authorization Management Program (FedRAMP)](/azure/compliance/offerings/offering-fedramp). | NA |
| FIPS 140-2 | The Federal Information Processing Standard (FIPS) Publication 140-2 is a US government standard that defines minimum security requirements for cryptographic modules in products and systems. Validation against the FIPS 140-2 standard is required for all US federal government agencies that use cryptography-based security systems to protect sensitive but unclassified information stored digitally. For more information, see [Federal Information Processing Standard (FIPS) 140](/azure/compliance/offerings/offering-fips-140-2). | FedRAMP High |
| GDPR | The General Data Protection Regulation (GDPR) is a European privacy law that became effective in May 2018. It imposes new rules on organizations that offer goods and services to people in the European Union (EU) or that collect and analyze data belonging to EU individuals. The GDPR requires that data controllers, such as organizations using Azure, only use data processors, such as Microsoft, that provide sufficient guarantees to meet key requirements of the GDPR. For more information, see [General Data Protection Regulation summary](/compliance/regulatory/gdpr). | ISO 27001:2013 |
Modified by Ortagus Winfrey on May 30, 2025 3:55 AM
πŸ“– View on learn.microsoft.com
+36 / -0 lines changed
Commit: May 2024 release notes
Changes:
Before
After
 
>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your ![RSS feed reader icon](./media/whats-new/feed-icon-16x16.png) feed reader.
 
## April 2025
 
### Public Preview - Conditional Access Optimization Agent in Microsoft Entra
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
>Get notified about when to revisit this page for updates by copying and pasting this URL: `https://learn.microsoft.com/api/search/rss?search=%22Release+notes+-+Azure+Active+Directory%22&locale=en-us` into your ![RSS feed reader icon](./media/whats-new/feed-icon-16x16.png) feed reader.
 
## May 2025
 
### Public Preview - Roll out of Application Based Authentication on Microsoft Entra Connect Sync
 
**Type:** New feature
**Service category:** Microsoft Entra Connect
**Product capability:** Microsoft Entra Connect
 
Microsoft Entra Connect creates and uses a [Microsoft Entra Connector account](../identity/hybrid/connect/reference-connect-accounts-permissions.md) to authenticate and sync identities from Active Directory to Microsoft Entra ID. The account uses a locally stored password to authenticate with Microsoft Entra ID. To enhance the security of the Microsoft Entra Connect sync process with the application, we've rolled out support for "*Application based Authentication" (ABA)*, which uses a Microsoft Entra ID application identity and Oauth 2.0 client credential flow to authenticate with Microsoft Entra ID. To enable this, Microsoft Entra Connect will create a single tenant 3rd party application in customer's Microsoft Entra ID tenant, register a certificate as the credential for the application, and authorize the application to perform on-premises directory synchronization.
The Microsoft Entra Connect Sync .msi installation file for this change is exclusively available on Microsoft Entra Admin Center within the [Microsoft Entra Connect pane](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted).
 
Check our [version history page](../identity/hybrid/connect/reference-connect-version-history.md) for more details of the change.
 
---
 
### General Availability – Conditional Access Per-Policy Reporting
 
Modified by Sumeet Mittal on May 30, 2025 8:55 AM
πŸ“– View on learn.microsoft.com
+20 / -0 lines changed
Commit: Update troubleshoot-connectors.md
Changes:
Before
After
> [!NOTE]
> The connector installation logs can be found in the `%TEMP%` folder and can help provide additional information on what is causing an installation failure.
 
## Verify connectivity to the cloud application proxy service and Microsoft sign in page
 
**Objective:** Verify that the connector machine can connect to the application proxy registration endpoint and the Microsoft sign-in page.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
> [!NOTE]
> The connector installation logs can be found in the `%TEMP%` folder and can help provide additional information on what is causing an installation failure.
 
## Use Connector Diagnostics tool to identity connector installation and network problems
The connector diagnostics tool is an exe command-line application that is included in connector package. This tool is designed to diagnose common connector setup and runtime errors to identify installation or network problems. Currently, the tool supports the following checks:
1. Certificate validity
2. Ports 80/443 accessibility
3. Outbound proxy configuration
4. CRL accessibility
5. Connector service running
6. Backend service endpoint accessibility
 
The tool also provides additional information, such as certificate details (if the cert is valid), tenant and connector ID, and TLS versions. To ensure that no checks are missed due to network / intermittent issues, the tool contains retries and prints out exception messages for any connectivity failures.
 
**How to Get the tool:** Connector diagnostics tool is available in connector installation package starting version 1.5.4287.0. Previous versions don't contain the tool. A new connector installation is needed to get the tool if you are using previous version.
 
**How to Use the tool:** After verifying successful installation, the tool can be found in the connector installation folder, located by default in C:/Program Files/Microsoft Entra Private Network Connector. Double click the application "ConnectorDiagnosticsTool" to launch the tool.
 
![image](https://github.com/user-attachments/assets/76feaf98-9f2c-492c-bb66-7d65fa4dc576)
 
Modified by Rohit Gulati on May 30, 2025 4:10 AM
πŸ“– View on learn.microsoft.com
+14 / -1 lines changed
Commit: Updates to helpdesk and IDV partner gallery pages
Changes:
Before
After
 
# Verified helpdesk with Microsoft Entra Verified ID
 
An ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Microsoft Entra Verified ID could help such enterprises add verification processes seamlessly into their existing helpdesk and service desk operations. Upon successful verification, service desk could offer tasks such as password resets, Temporary Access Pass (TAP) provision, MFA (multifactor authentication) onboarding, and account updates, potentially enabling self-service automation.
 
## When to use this pattern
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
# Verified helpdesk with Microsoft Entra Verified ID
 
An ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Traditional methods such as personally identifiable information (PII) and knowledge-based authentication are no match for today’s sophisticated attackers, who leverage phishing, social engineering, and even AI-powered voice cloning to bypass defences. The consequences are serious: under pressure, helpdesk agents may unintentionally expose sensitive data or authorize fraudulent actions.
 
**The Way Forward: Stronger and Phish resistant Authentication**
To defend against these evolving threats without compromising user experience, organizations must adopt modern verification strategies built for today’s threat landscape. This includes:
* Phish resistant authentication (e.g., passkeys)
* AI-driven fraud detection to flag anomalous behaviour
* Zero Trust principles enforcing strict identity checks
* Enterprise-grade identity validationβ€”without relying on PII.
 
Microsoft offers solutions that enable Admins to enhance security without sacrificing user experience. Organizations can adopt two key patterns:
 
1. Strong Authentication: Users authenticate with their existing corporate credentials before requesting helpdesk support. User is prompted to present strong phish resistant credentials before they are granted access to resources. Microsoft platform offers solutions like Azure Communication Services that supports multichannel communication APIs for adding voice, video, chat, text messaging/SMS, email, and more to all your applications. [Azure Communication Services (ACS)](https://azure.microsoft.com/products/communication-services/?msockid=27ae7d5196f463891a416cf192f46589#Features-3) supports a security pattern where users visit a URL to initiate a direct, encrypted voice/video/chat session with a helpdesk via an ACS-integrated app. Authentication is managed using Microsoft Entra ID, and secure ACS tokens ensure controlled access, preventing unauthorized connections.
2. Total Loss Recovery: In cases where a user has lost all authentication credentials, a secure, policy-driven recovery process is implemented to re-establish access without compromising security. Microsoft Entra Verified ID could help such enterprises add verification processes seamlessly into their existing helpdesk and service desk operations. Upon successful verification, service desk could offer tasks such as password resets, Temporary Access Pass (TAP) provision, MFA (multifactor authentication) onboarding, and account updates, potentially enabling self-service automation.
This document explains how to use Microsoft Entra Verified ID for the total loss recovery scenario.
 
## When to use this pattern
 
Modified by Chris Werner on May 30, 2025 9:23 PM
πŸ“– View on learn.microsoft.com
+12 / -0 lines changed
Commit: add H3s to overview, and items to TOC
Changes:
Before
After
 
:::image type="content" source="./media/copilot-entra-risky-user-summarization/risky-user-details.png" alt-text="Screenshot that shows the ID Protection risky user summarization details.":::
 
## Enable the Security Copilot integration in Microsoft Entra
 
You can learn more about plugins implemented in the Security Copilot portal in [Manage plugins in Security Copilot](/security-copilot/manage-plugins). Additionally, you can learn more about the embedded experiences in other Microsoft security products in [Security Copilot experiences](/security-copilot/experiences-security-copilot).
 
 
 
 
 
 
 
 
 
 
 
 
 
:::image type="content" source="./media/copilot-entra-risky-user-summarization/risky-user-details.png" alt-text="Screenshot that shows the ID Protection risky user summarization details.":::
 
### Investigate access reviews
 
Administrators can use Microsoft Security Copilot with Microsoft Entra ID Governance Access Reviews to extract and analyze access review data. This integration allows admins to explore, track, and analyze access reviews at scale. For more information, see [Investigate access reviews in Microsoft Entra Copilot](copilot-entra-access-reviews.md).
 
### Investigate recommendations
 
The Microsoft Entra recommendations feature helps monitor the status of your tenant, so you don't have to. Entra Recommendations applies the capabilities of Microsoft Security Copilotβ€― to help your security team investigate how to evolve your tenants to secure and healthy state while also helping you maximize the value of the features available in Microsoft Entra ID. For more information, see [Microsoft Entra Recommendations with Microsoft Security Copilot](copilot-entra-recommendations.md).
 
### Investigate insights within entitlements management
 
Use Microsoft Security Copilot with Microsoft Entra ID Governance Entitlement Management to get quick access to information about access packages, policies, connected organizations, and catalog resources. For more information, see [Investigate insights within entitlements management in Microsoft Entra Copilot](copilot-entra-entitlement-management.md).
 
## Enable the Security Copilot integration in Microsoft Entra
 
You can learn more about plugins implemented in the Security Copilot portal in [Manage plugins in Security Copilot](/security-copilot/manage-plugins). Additionally, you can learn more about the embedded experiences in other Microsoft security products in [Security Copilot experiences](/security-copilot/experiences-security-copilot).
+7 / -3 lines changed
Commit: Update licensing-service-plan-reference.md
Changes:
Before
After
ms.service: entra-id
ms.subservice: users
ms.topic: reference
ms.date: 05/28/2025
ms.author: nicholak
ms.reviewer: Nicholak-MS
ms.custom: it-pro
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
 
>[!NOTE]
>This information was last updated on May 28, 2025.<br/>You can also download a CSV version of this table [here](https://download.microsoft.com/download/e/3/e/e3e9faf2-f28b-490a-9ada-c6089a1fc5b0/Product%20names%20and%20service%20plan%20identifiers%20for%20licensing.csv).
><br/>
 
| Product name | String ID | GUID | Service plans included | Service plans included (friendly names) |
| Microsoft 365 Business Premium EEA (no Teams) | Office_365_w/o_Teams_Bundle_Business_Premium | a3f586b6-8cce-4d9b-99d6-55238397f77a | EXCHANGE_S_FOUNDATION (113feb6c-3fe4-4440-bddc-54d774bf0318)<br/>DYN365BC_MS_INVOICING (39b5c996-467e-4e60-bd62-46066f572726)<br/>Bing_Chat_Enterprise (0d0c0d31-fae7-41f2-b909-eaf4d7f26dba)<br/>CDS_O365_P3 (afa73018-811e-46e9-988f-f75d2b1b8430)<br/>BPOS_S_DlpAddOn (9bec7e34-c9fa-40b7-a9d1-bd6d1165c7ed)<br/>EXCHANGE_S_STANDARD (9aaf7827-d63c-4b61-89c3-182f06f82e5c)<br/>EXCHANGE_S_ARCHIVE_ADDON (176a09a6-7ec5-4039-ac02-b2791c6ba793)<br/>MYANALYTICS_P2 (33c4f319-9bdd-48d6-9c4d-410b750a4a5a)<br/>OFFICE_BUSINESS (094e7854-93fc-4d55-b2c0-3ab5369ebdc1)<br/>M365_LIGHTHOUSE_CUSTOMER_PLAN1 (6f23d6a9-adbf-481c-8538-b4c095654487)<br/>M365_LIGHTHOUSE_PARTNER_PLAN1 (d55411c9-cfff-40a9-87c7-240f14df7da5)<br/>MICROSOFTBOOKINGS (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>CLIPCHAMP (a1ace008-72f3-4ea0-8dac-33b3a23a2472)<br/>MDE_SMB (bfc1bbd9-981b-4f71-9b82-17c35fd0e2a4)<br/>ATP_ENTERPRISE (f20fedf3-f3c3-43c3-8267-2bfdd51c0939)<br/>FORMS_PLAN_E1 (159f4cd6-e380-449f-a816-af1a9ef76344)<br/>KAIZALA_O365_P2 (54fc630f-5a40-48ee-8965-af0503c1386e)<br/>PROJECTWORKMANAGEMENT (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>MICROSOFT_SEARCH (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Deskless (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>INTUNE_O365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Nucleus (db4d623d-b514-490b-b7ef-8885eee514de)<br/>SHAREPOINTWAC (e95bec33-7c88-4a70-8e19-b10bd9d0c014)<br/>OFFICE_SHARED_COMPUTER_ACTIVATION (276d6e8a-f056-4f70-b7e8-4fc27f79f809)<br/>PROJECT_O365_P3 (b21a6b06-1988-436e-a07b-51ec6d9f52ad)<br/>O365_SB_Relationship_Management (5bfe124c-bbdc-4494-8835-f1297d457d79)<br/>SHAREPOINTSTANDARD (c7699d2e-19aa-44de-8edf-1736da088ca1)<br/>MCOSTANDARD (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>SWAY (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>BPOS_S_TODO_1 (5e62787c-c316-451f-b873-1d05acd4d12c)<br/>VIVAENGAGE_CORE (a82fbf69-b4d7-49f4-83a6-915b2cf354f4)<br/>VIVA_LEARNING_SEEDED (b76fb638-6ba6-402a-b9f9-83d28acb3d86)<br/>WHITEBOARD_PLAN1 (b8afc642-032e-4de5-8c0a-507a7bba7e5d)<br/>YAMMER_ENTERPRISE (7547a3fe-08ee-4ccb-b430-5077c5041653)<br/>UNIVERSAL_PRINT_01 (795f6fe0-cc4d-4773-b050-5dde4dc704c9)<br/>WINBIZ (8e229017-d77b-43d5-9305-903395523b99)<br/>WINDOWSUPDATEFORBUSINESS_DEPLOYMENTSERVICE (7bf960f6-2cd9-443a-8046-5dbff9558365)<br/>AAD_SMB (de377cbc-0019-4ec2-b77c-3f223947e102)<br/>RMS_S_PREMIUM (6c57d4b6-3b23-47a5-9bc9-69f17b4947b3)<br/>RMS_S_ENTERPRISE (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>DYN365_CDS_O365_P3 (28b0fa46-c39a-4188-89e2-58e979a6b014)<br/>MFA_PREMIUM (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>ADALLOM_S_DISCOVERY (932ad362-64a8-4783-9106-97849a1a30b9)<br/>AAD_PREMIUM (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>INTUNE_SMBIZ (8e9ff0ff-aa7a-4b20-83c1-2f636b600ac2)<br/>INTUNE_A (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>STREAM_O365_E1 (743dd19e-1ce3-4c62-a3ad-49ba8f63a2f6)<br/>POWERAPPS_O365_P1 (92f7a6f3-b89b-4bbd-8c30-809e6da5ad1c)<br/>FLOW_O365_P1 (0f9b09cb-62d1-4ff4-9129-43f4996f83f4)<br/>POWER_VIRTUAL_AGENTS_O365_P3 (ded3d325-1bdc-453e-8432-5bac26d7a014) | Exchange Foundation (113feb6c-3fe4-4440-bddc-54d774bf0318)<br/>Microsoft Invoicing (39b5c996-467e-4e60-bd62-46066f572726)<br/>Commercial data protection for Microsoft Copilot (0d0c0d31-fae7-41f2-b909-eaf4d7f26dba)<br/>Common Data Service for Teams (afa73018-811e-46e9-988f-f75d2b1b8430)<br/>Data Loss Prevention (9bec7e34-c9fa-40b7-a9d1-bd6d1165c7ed)<br/>Exchange Online (Plan 1) (9aaf7827-d63c-4b61-89c3-182f06f82e5c)<br/>Exchange Online Archiving (176a09a6-7ec5-4039-ac02-b2791c6ba793)<br/>Insights by MyAnalytics (33c4f319-9bdd-48d6-9c4d-410b750a4a5a)<br/>Microsoft 365 Apps for business (094e7854-93fc-4d55-b2c0-3ab5369ebdc1)<br/>Microsoft 365 Lighthouse (Plan 1) (6f23d6a9-adbf-481c-8538-b4c095654487)<br/>Microsoft 365 Lighthouse (Plan 2) (d55411c9-cfff-40a9-87c7-240f14df7da5)<br/>Microsoft Bookings (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>Microsoft Clipchamp (a1ace008-72f3-4ea0-8dac-33b3a23a2472)<br/>Microsoft Defender for Business (bfc1bbd9-981b-4f71-9b82-17c35fd0e2a4)<br/>Microsoft Defender for Office 365 (Plan 1) (f20fedf3-f3c3-43c3-8267-2bfdd51c0939)<br/>Microsoft Forms (Plan E1) (159f4cd6-e380-449f-a816-af1a9ef76344)<br/>Microsoft Kaizala Pro (54fc630f-5a40-48ee-8965-af0503c1386e)<br/>Microsoft Planner (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>Microsoft Search (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Microsoft StaffHub (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>Mobile Device Management for Office 365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Nucleus (db4d623d-b514-490b-b7ef-8885eee514de)<br/>Office for the Web (e95bec33-7c88-4a70-8e19-b10bd9d0c014)<br/>Office Shared Computer Activation (276d6e8a-f056-4f70-b7e8-4fc27f79f809)<br/>Project for Office (Plan E5) (b21a6b06-1988-436e-a07b-51ec6d9f52ad)<br/>RETIRED - Outlook Customer Manager (5bfe124c-bbdc-4494-8835-f1297d457d79)<br/>SharePoint (Plan 1) (c7699d2e-19aa-44de-8edf-1736da088ca1)<br/>Skype for Business Online (Plan 2) (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>Sway (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>To-Do (Plan 1) (5e62787c-c316-451f-b873-1d05acd4d12c)<br/>Viva Engage Core (a82fbf69-b4d7-49f4-83a6-915b2cf354f4)<br/>Viva Learning Seeded (b76fb638-6ba6-402a-b9f9-83d28acb3d86)<br/>Whiteboard (Plan 1) (b8afc642-032e-4de5-8c0a-507a7bba7e5d)<br/>Yammer Enterprise (7547a3fe-08ee-4ccb-b430-5077c5041653)<br/>Universal Print (795f6fe0-cc4d-4773-b050-5dde4dc704c9)<br/>Windows 10/11 Business (8e229017-d77b-43d5-9305-903395523b99)<br/>Windows Update for Business Deployment Service (7bf960f6-2cd9-443a-8046-5dbff9558365)<br/>Microsoft Entra ID (de377cbc-0019-4ec2-b77c-3f223947e102)<br/>Azure Information Protection Premium P1 (6c57d4b6-3b23-47a5-9bc9-69f17b4947b3)<br/>Azure Rights Management (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>Common Data Service (28b0fa46-c39a-4188-89e2-58e979a6b014)<br/>Microsoft Azure Multi-Factor Authentication (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>Microsoft Defender for Cloud Apps Discovery (932ad362-64a8-4783-9106-97849a1a30b9)<br/>Microsoft Entra ID P1 (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>Microsoft Intune (8e9ff0ff-aa7a-4b20-83c1-2f636b600ac2)<br/>Microsoft Intune Plan 1 (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>Microsoft Stream for Office 365 E1 (743dd19e-1ce3-4c62-a3ad-49ba8f63a2f6)<br/>Power Apps for Office 365 (92f7a6f3-b89b-4bbd-8c30-809e6da5ad1c)<br/>Power Automate for Office 365 (0f9b09cb-62d1-4ff4-9129-43f4996f83f4)<br/>Power Virtual Agents for Office 365 (ded3d325-1bdc-453e-8432-5bac26d7a014) |
| Microsoft 365 Business Voice (US) | BUSINESS_VOICE_MED2_TELCO | 08d7bce8-6e16-490e-89db-1d508e5e9609 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOPSTN1 (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Domestic Calling Plan (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice (without Calling Plan) | BUSINESS_VOICE_DIRECTROUTING | d52db95a-5ecb-46b6-beb0-190ab5cda4a8 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice | BUSINESS_VOICE_MED2 | a6051f20-9cbc-47d2-930d-419183bf6cf1 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOPSTN1 (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Domestic Calling Plan (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice (UK) | BUSINESS_VOICE | e5a17adf-8f0d-4b57-bc14-d331235f9307 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOPSTN1 (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Domestic Calling Plan (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Copilot (Education Faculty) | Microsoft_365_Copilot_EDU | ad9c22b3-52d7-4e7e-973c-88121ea96436 | COPILOT_STUDIO_IN_COPILOT_FOR_M365 (fe6c28b3-d468-44ea-bbd0-a10a5167435c)<br/>GRAPH_CONNECTORS_COPILOT (82d30987-df9b-4486-b146-198b21d164c7)<br/>M365_COPILOT_INTELLIGENT_SEARCH (931e4a88-a67f-48b5-814f-16a5f1e6028d)<br/>M365_COPILOT_SHAREPOINT (0aedf20c-091d-420b-aadf-30c042609612)<br/>M365_COPILOT_TEAMS (b95945de-b3bd-46db-8437-f2beb6ea2347)<br/>M365_COPILOT_APPS (a62f8878-de10-42f3-b68f-6149a25ceb97)<br/>M365_COPILOT_BUSINESS_CHAT (3f30311c-6b1e-48a4-ab79-725b469da960)<br/>M365_COPILOT_CONNECTORS (89f1c4c8-0878-40f7-804d-869c9128ab5d) | COPILOT_STUDIO_IN_COPILOT_FOR_M365 (fe6c28b3-d468-44ea-bbd0-a10a5167435c)<br/>GRAPH_CONNECTORS_COPILOT (82d30987-df9b-4486-b146-198b21d164c7)<br/>M365_COPILOT_INTELLIGENT_SEARCH (931e4a88-a67f-48b5-814f-16a5f1e6028d)<br/>M365_COPILOT_SHAREPOINT (0aedf20c-091d-420b-aadf-30c042609612)<br/>M365_COPILOT_TEAMS (b95945de-b3bd-46db-8437-f2beb6ea2347)<br/>M365_COPILOT_APPS (a62f8878-de10-42f3-b68f-6149a25ceb97)<br/>M365_COPILOT_BUSINESS_CHAT (3f30311c-6b1e-48a4-ab79-725b469da960)<br/>M365_COPILOT_CONNECTORS (89f1c4c8-0878-40f7-804d-869c9128ab5d) |
ms.service: entra-id
ms.subservice: users
ms.topic: reference
ms.date: 05/29/2025
ms.author: nicholak
ms.reviewer: Nicholak-MS
ms.custom: it-pro
- **Service plans included (friendly names)**: A list of service plans (friendly names) in the product that correspond to the string ID and GUID
 
>[!NOTE]
>This information was last updated on May 29, 2025.<br/>You can also download a CSV version of this table [here](https://download.microsoft.com/download/e/3/e/e3e9faf2-f28b-490a-9ada-c6089a1fc5b0/Product%20names%20and%20service%20plan%20identifiers%20for%20licensing.csv).
><br/>
 
| Product name | String ID | GUID | Service plans included | Service plans included (friendly names) |
| Microsoft 365 Business Premium EEA (no Teams) | Office_365_w/o_Teams_Bundle_Business_Premium | a3f586b6-8cce-4d9b-99d6-55238397f77a | EXCHANGE_S_FOUNDATION (113feb6c-3fe4-4440-bddc-54d774bf0318)<br/>DYN365BC_MS_INVOICING (39b5c996-467e-4e60-bd62-46066f572726)<br/>Bing_Chat_Enterprise (0d0c0d31-fae7-41f2-b909-eaf4d7f26dba)<br/>CDS_O365_P3 (afa73018-811e-46e9-988f-f75d2b1b8430)<br/>BPOS_S_DlpAddOn (9bec7e34-c9fa-40b7-a9d1-bd6d1165c7ed)<br/>EXCHANGE_S_STANDARD (9aaf7827-d63c-4b61-89c3-182f06f82e5c)<br/>EXCHANGE_S_ARCHIVE_ADDON (176a09a6-7ec5-4039-ac02-b2791c6ba793)<br/>MYANALYTICS_P2 (33c4f319-9bdd-48d6-9c4d-410b750a4a5a)<br/>OFFICE_BUSINESS (094e7854-93fc-4d55-b2c0-3ab5369ebdc1)<br/>M365_LIGHTHOUSE_CUSTOMER_PLAN1 (6f23d6a9-adbf-481c-8538-b4c095654487)<br/>M365_LIGHTHOUSE_PARTNER_PLAN1 (d55411c9-cfff-40a9-87c7-240f14df7da5)<br/>MICROSOFTBOOKINGS (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>CLIPCHAMP (a1ace008-72f3-4ea0-8dac-33b3a23a2472)<br/>MDE_SMB (bfc1bbd9-981b-4f71-9b82-17c35fd0e2a4)<br/>ATP_ENTERPRISE (f20fedf3-f3c3-43c3-8267-2bfdd51c0939)<br/>FORMS_PLAN_E1 (159f4cd6-e380-449f-a816-af1a9ef76344)<br/>KAIZALA_O365_P2 (54fc630f-5a40-48ee-8965-af0503c1386e)<br/>PROJECTWORKMANAGEMENT (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>MICROSOFT_SEARCH (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Deskless (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>INTUNE_O365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Nucleus (db4d623d-b514-490b-b7ef-8885eee514de)<br/>SHAREPOINTWAC (e95bec33-7c88-4a70-8e19-b10bd9d0c014)<br/>OFFICE_SHARED_COMPUTER_ACTIVATION (276d6e8a-f056-4f70-b7e8-4fc27f79f809)<br/>PROJECT_O365_P3 (b21a6b06-1988-436e-a07b-51ec6d9f52ad)<br/>O365_SB_Relationship_Management (5bfe124c-bbdc-4494-8835-f1297d457d79)<br/>SHAREPOINTSTANDARD (c7699d2e-19aa-44de-8edf-1736da088ca1)<br/>MCOSTANDARD (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>SWAY (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>BPOS_S_TODO_1 (5e62787c-c316-451f-b873-1d05acd4d12c)<br/>VIVAENGAGE_CORE (a82fbf69-b4d7-49f4-83a6-915b2cf354f4)<br/>VIVA_LEARNING_SEEDED (b76fb638-6ba6-402a-b9f9-83d28acb3d86)<br/>WHITEBOARD_PLAN1 (b8afc642-032e-4de5-8c0a-507a7bba7e5d)<br/>YAMMER_ENTERPRISE (7547a3fe-08ee-4ccb-b430-5077c5041653)<br/>UNIVERSAL_PRINT_01 (795f6fe0-cc4d-4773-b050-5dde4dc704c9)<br/>WINBIZ (8e229017-d77b-43d5-9305-903395523b99)<br/>WINDOWSUPDATEFORBUSINESS_DEPLOYMENTSERVICE (7bf960f6-2cd9-443a-8046-5dbff9558365)<br/>AAD_SMB (de377cbc-0019-4ec2-b77c-3f223947e102)<br/>RMS_S_PREMIUM (6c57d4b6-3b23-47a5-9bc9-69f17b4947b3)<br/>RMS_S_ENTERPRISE (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>DYN365_CDS_O365_P3 (28b0fa46-c39a-4188-89e2-58e979a6b014)<br/>MFA_PREMIUM (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>ADALLOM_S_DISCOVERY (932ad362-64a8-4783-9106-97849a1a30b9)<br/>AAD_PREMIUM (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>INTUNE_SMBIZ (8e9ff0ff-aa7a-4b20-83c1-2f636b600ac2)<br/>INTUNE_A (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>STREAM_O365_E1 (743dd19e-1ce3-4c62-a3ad-49ba8f63a2f6)<br/>POWERAPPS_O365_P1 (92f7a6f3-b89b-4bbd-8c30-809e6da5ad1c)<br/>FLOW_O365_P1 (0f9b09cb-62d1-4ff4-9129-43f4996f83f4)<br/>POWER_VIRTUAL_AGENTS_O365_P3 (ded3d325-1bdc-453e-8432-5bac26d7a014) | Exchange Foundation (113feb6c-3fe4-4440-bddc-54d774bf0318)<br/>Microsoft Invoicing (39b5c996-467e-4e60-bd62-46066f572726)<br/>Commercial data protection for Microsoft Copilot (0d0c0d31-fae7-41f2-b909-eaf4d7f26dba)<br/>Common Data Service for Teams (afa73018-811e-46e9-988f-f75d2b1b8430)<br/>Data Loss Prevention (9bec7e34-c9fa-40b7-a9d1-bd6d1165c7ed)<br/>Exchange Online (Plan 1) (9aaf7827-d63c-4b61-89c3-182f06f82e5c)<br/>Exchange Online Archiving (176a09a6-7ec5-4039-ac02-b2791c6ba793)<br/>Insights by MyAnalytics (33c4f319-9bdd-48d6-9c4d-410b750a4a5a)<br/>Microsoft 365 Apps for business (094e7854-93fc-4d55-b2c0-3ab5369ebdc1)<br/>Microsoft 365 Lighthouse (Plan 1) (6f23d6a9-adbf-481c-8538-b4c095654487)<br/>Microsoft 365 Lighthouse (Plan 2) (d55411c9-cfff-40a9-87c7-240f14df7da5)<br/>Microsoft Bookings (199a5c09-e0ca-4e37-8f7c-b05d533e1ea2)<br/>Microsoft Clipchamp (a1ace008-72f3-4ea0-8dac-33b3a23a2472)<br/>Microsoft Defender for Business (bfc1bbd9-981b-4f71-9b82-17c35fd0e2a4)<br/>Microsoft Defender for Office 365 (Plan 1) (f20fedf3-f3c3-43c3-8267-2bfdd51c0939)<br/>Microsoft Forms (Plan E1) (159f4cd6-e380-449f-a816-af1a9ef76344)<br/>Microsoft Kaizala Pro (54fc630f-5a40-48ee-8965-af0503c1386e)<br/>Microsoft Planner (b737dad2-2f6c-4c65-90e3-ca563267e8b9)<br/>Microsoft Search (94065c59-bc8e-4e8b-89e5-5138d471eaff)<br/>Microsoft StaffHub (8c7d2df8-86f0-4902-b2ed-a0458298f3b3)<br/>Mobile Device Management for Office 365 (882e1d05-acd1-4ccb-8708-6ee03664b117)<br/>Nucleus (db4d623d-b514-490b-b7ef-8885eee514de)<br/>Office for the Web (e95bec33-7c88-4a70-8e19-b10bd9d0c014)<br/>Office Shared Computer Activation (276d6e8a-f056-4f70-b7e8-4fc27f79f809)<br/>Project for Office (Plan E5) (b21a6b06-1988-436e-a07b-51ec6d9f52ad)<br/>RETIRED - Outlook Customer Manager (5bfe124c-bbdc-4494-8835-f1297d457d79)<br/>SharePoint (Plan 1) (c7699d2e-19aa-44de-8edf-1736da088ca1)<br/>Skype for Business Online (Plan 2) (0feaeb32-d00e-4d66-bd5a-43b5b83db82c)<br/>Sway (a23b959c-7ce8-4e57-9140-b90eb88a9e97)<br/>To-Do (Plan 1) (5e62787c-c316-451f-b873-1d05acd4d12c)<br/>Viva Engage Core (a82fbf69-b4d7-49f4-83a6-915b2cf354f4)<br/>Viva Learning Seeded (b76fb638-6ba6-402a-b9f9-83d28acb3d86)<br/>Whiteboard (Plan 1) (b8afc642-032e-4de5-8c0a-507a7bba7e5d)<br/>Yammer Enterprise (7547a3fe-08ee-4ccb-b430-5077c5041653)<br/>Universal Print (795f6fe0-cc4d-4773-b050-5dde4dc704c9)<br/>Windows 10/11 Business (8e229017-d77b-43d5-9305-903395523b99)<br/>Windows Update for Business Deployment Service (7bf960f6-2cd9-443a-8046-5dbff9558365)<br/>Microsoft Entra ID (de377cbc-0019-4ec2-b77c-3f223947e102)<br/>Azure Information Protection Premium P1 (6c57d4b6-3b23-47a5-9bc9-69f17b4947b3)<br/>Azure Rights Management (bea4c11e-220a-4e6d-8eb8-8ea15d019f90)<br/>Common Data Service (28b0fa46-c39a-4188-89e2-58e979a6b014)<br/>Microsoft Azure Multi-Factor Authentication (8a256a2b-b617-496d-b51b-e76466e88db0)<br/>Microsoft Defender for Cloud Apps Discovery (932ad362-64a8-4783-9106-97849a1a30b9)<br/>Microsoft Entra ID P1 (41781fb2-bc02-4b7c-bd55-b576c07bb09d)<br/>Microsoft Intune (8e9ff0ff-aa7a-4b20-83c1-2f636b600ac2)<br/>Microsoft Intune Plan 1 (c1ec4a95-1f05-45b3-a911-aa3fa01094f5)<br/>Microsoft Stream for Office 365 E1 (743dd19e-1ce3-4c62-a3ad-49ba8f63a2f6)<br/>Power Apps for Office 365 (92f7a6f3-b89b-4bbd-8c30-809e6da5ad1c)<br/>Power Automate for Office 365 (0f9b09cb-62d1-4ff4-9129-43f4996f83f4)<br/>Power Virtual Agents for Office 365 (ded3d325-1bdc-453e-8432-5bac26d7a014) |
| Microsoft 365 Business Voice (US) | BUSINESS_VOICE_MED2_TELCO | 08d7bce8-6e16-490e-89db-1d508e5e9609 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOPSTN1 (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Domestic Calling Plan (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice (without Calling Plan) | BUSINESS_VOICE_DIRECTROUTING | d52db95a-5ecb-46b6-beb0-190ab5cda4a8 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice (without Calling Plan) for US | BUSINESS_VOICE_DIRECTROUTING_MED | 8330dae3-d349-44f7-9cad-1b23c64baabe | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice | BUSINESS_VOICE_MED2 | a6051f20-9cbc-47d2-930d-419183bf6cf1 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOPSTN1 (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Domestic Calling Plan (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
| Microsoft 365 Business Voice (UK) | BUSINESS_VOICE | e5a17adf-8f0d-4b57-bc14-d331235f9307 | MCOMEETADV (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>MCOPSTN1 (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>MCOEV (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) | Microsoft 365 Audio Conferencing (3e26ee1f-8a5f-4d52-aee2-b81ce45c8f40)<br/>Microsoft 365 Domestic Calling Plan (4ed3ff63-69d7-4fb7-b984-5aec7f605ca8)<br/>Microsoft 365 Phone System (4828c8ec-dc2e-4779-b502-87ac9ce28ab7) |
+4 / -4 lines changed
Commit: Review fixes
Changes:
Before
After
 
# Assign eligible group membership and ownership in access packages via Privileged Identity Management for Groups (Preview)
 
As an access package manager, you can assign which role you want to provide a user for a group within an access package. By [managing groups with Privileged Identity Management(PIM)](../id-governance/privileged-identity-management/groups-discover-groups.md), you're able to enhance security by designating that group access happens just-in-time. This article describes how to enable pim for a group, adding the group to an access package, and verifying eligible assignments are available.
 
<!---Avoid notes, tips, and important boxes. Readers tend to skip over them. Better to put that info directly into the article text.
 
1. Give the group a name and description and then complete the other required options:
- **Group Type:** Security
- **Membership type:** Select *Assigned*.
:::image type="content" source="media/entitlement-management-access-package-eligible/create-group-eligible.png" alt-text="Picture of creating the group for the access package.":::
1. Select **Create**.
 
 
1. Select **Manage groups** and **OK**.
 
1. Select **Groups** to return to the list of groups enabled in PIM for Groups, and notice the group you added is now on the list.
:::image type="content" source="media/entitlement-management-access-package-eligible/groups-managed-pim-list.png" alt-text="Screenshot of groups managed by PIM list.":::
 
> [!IMPORTANT]
 
# Assign eligible group membership and ownership in access packages via Privileged Identity Management for Groups (Preview)
 
As an access package manager, you can assign which role you want to provide a user for a group within an access package. By [managing groups with Privileged Identity Management(PIM)](../id-governance/privileged-identity-management/groups-discover-groups.md), you're able to enhance security by designating that group access happens just-in-time. This article describes how to enable PIM for a group, adding the group to an access package, and verifying eligible assignments are available.
 
<!---Avoid notes, tips, and important boxes. Readers tend to skip over them. Better to put that info directly into the article text.
 
1. Give the group a name and description and then complete the other required options:
- **Group Type:** Security
- **Membership type:** Select *Assigned*.
:::image type="content" source="media/entitlement-management-access-package-eligible/create-group-eligible.png" alt-text="Picture of creating the group for the access package." lightbox="media/entitlement-management-access-package-eligible/create-group-eligible.png":::
1. Select **Create**.
 
 
1. Select **Manage groups** and **OK**.
 
1. Select **Groups** to return to the list of groups enabled in PIM for Groups, and notice the group you added is now on the list.
:::image type="content" source="media/entitlement-management-access-package-eligible/groups-managed-pim-list.png" alt-text="Screenshot of groups managed by PIM list." lightbox="media/entitlement-management-access-package-eligible/groups-managed-pim-list.png":::
 
> [!IMPORTANT]
Modified by Chris Werner on May 30, 2025 11:50 PM
πŸ“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: Addressing UUF 436284
Changes:
Before
After
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.date: 05/30/2024
ms.reviewer: alamaral
ms.service: identity-platform
ms.topic: how-to
$base64cer = [System.Convert]::ToBase64String($cer_cert)
# getting id for the keyCredential object
$guid1 = New-Guid
$guid2 = New-Guid
# get the custom key identifier from the certificate thumbprint:
$hasher = [System.Security.Cryptography.HashAlgorithm]::Create('sha256')
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.date: 05/30/2025
ms.reviewer: alamaral
ms.service: identity-platform
ms.topic: how-to
$base64cer = [System.Convert]::ToBase64String($cer_cert)
# getting id for the keyCredential object
[string]$guid1 = New-Guid
[string]$guid2 = New-Guid
# get the custom key identifier from the certificate thumbprint:
$hasher = [System.Security.Cryptography.HashAlgorithm]::Create('sha256')
Modified by Chris Werner on May 30, 2025 7:11 PM
πŸ“– View on learn.microsoft.com
+3 / -1 lines changed
Commit: entitlement management draft
Changes:
Before
After
1. Navigate to **Identity Governance** > **Access reviews**.
1. {ADDME}
 
 
Use the following example prompts to extract access reviews data in Microsoft Entra:
 
| Use Case | Example Prompts |
|--- -----|-----------------|
| Explore current configured access reviews in the tenant | *Show me top 10 access reviews with schedule, status, and metadata* |
| Get detailed info on a specific access review | *Get access review details for Finance M365 Groups Q2* |
| View access review decisions for a specific instance | *Who approved or denied access in the Q2 finance review?* |
 
 
1. Navigate to **Identity Governance** > **Access reviews**.
1. {ADDME}
 
> [!NOTE]
> This space is being reserved for an image showing the Copilot experience in the Microsoft Entra admin center.
 
Use the following example prompts to extract access reviews data in Microsoft Entra:
 
| Use Case | Example Prompts |
|----------|-----------------|
| Explore current configured access reviews in the tenant | *Show me top 10 access reviews with schedule, status, and metadata* |
| Get detailed info on a specific access review | *Get access review details for Finance M365 Groups Q2* |
| View access review decisions for a specific instance | *Who approved or denied access in the Q2 finance review?* |
+2 / -2 lines changed
Commit: Update troubleshoot-publisher-verification.md
Changes:
Before
After
1. Navigate to the [Cloud Partner Program enrollment page](https://partner.microsoft.com/dashboard/account/v3/enrollment/joinnow/basicpartnernetwork/new).
1. Sign in with a user account in the org's primary Microsoft Entra tenant.
1. If a Cloud Partner Program account already exists, this account is recognized and you are added to the account.
1. Navigate to the [partner profile page](https://partner.microsoft.com/en-us/dashboard/account/v3/overview) where the Partner One ID and primary account contact are listed.
 
- **I don't know who my Microsoft Entra Global Administrator (also known as company admin or tenant admin) is, how do I find them? What about the Application Administrator or Cloud Application Administrator?**
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. The list of users assigned that role are displayed.
 
- **I don't know who the admin(s) for my CPP account are**
Go to the [CPP User Management page](https://partner.microsoft.com/en-us/dashboard/account/v3/usermanagement) and filter the user list to see what users are in various admin roles.
 
- **I am getting an error saying that my Partner One ID is invalid or that I do not have access to it.**
Follow the [remediation guidance](#mpnaccountnotfoundornoaccess).
1. Navigate to the [Cloud Partner Program enrollment page](https://partner.microsoft.com/dashboard/account/v3/enrollment/joinnow/basicpartnernetwork/new).
1. Sign in with a user account in the org's primary Microsoft Entra tenant.
1. If a Cloud Partner Program account already exists, this account is recognized and you are added to the account.
1. Navigate to the [partner profile page](https://partner.microsoft.com/dashboard/account/v3/overview) where the Partner One ID and primary account contact are listed.
 
- **I don't know who my Microsoft Entra Global Administrator (also known as company admin or tenant admin) is, how do I find them? What about the Application Administrator or Cloud Application Administrator?**
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. The list of users assigned that role are displayed.
 
- **I don't know who the admin(s) for my CPP account are**
Go to the [CPP User Management page](https://partner.microsoft.com/dashboard/account/v3/usermanagement) and filter the user list to see what users are in various admin roles.
 
- **I am getting an error saying that my Partner One ID is invalid or that I do not have access to it.**
Follow the [remediation guidance](#mpnaccountnotfoundornoaccess).
+3 / -0 lines changed
Commit: Updates
Changes:
Before
After
 
Any users with existing assignments to the access package will automatically become members (or owners) of this group or team after it's added. For more information, see [when changes are applied](#when-changes-are-applied).
 
## Add an application resource role
 
You can have Microsoft Entra ID automatically assign users access to a Microsoft Entra enterprise application, including SaaS applications, on-premises applications, and your organization's applications integrated with Microsoft Entra ID, when a user is assigned an access package. For applications that integrate with Microsoft Entra ID through federated single sign-on, Microsoft Entra ID issues federation tokens for users assigned to the application.
 
 
 
 
Any users with existing assignments to the access package will automatically become members (or owners) of this group or team after it's added. For more information, see [when changes are applied](#when-changes-are-applied).
 
> [!NOTE]
> If an Access Package expiration period exceeds the "*Expire eligible assignments after*" policy setting in the PIM managed group, it can cause discrepancies between Entitlement Management and Privileged Identity Management, leading to users losing access while EM shows they're still assigned. For more information, see: [Using groups managed by Privileged Identity Management with access packages reference](entitlement-management-access-package-pim-reference.md).
 
## Add an application resource role
 
You can have Microsoft Entra ID automatically assign users access to a Microsoft Entra enterprise application, including SaaS applications, on-premises applications, and your organization's applications integrated with Microsoft Entra ID, when a user is assigned an access package. For applications that integrate with Microsoft Entra ID through federated single sign-on, Microsoft Entra ID issues federation tokens for users assigned to the application.