๐Ÿ“‹ Microsoft Entra Documentation Changes

Changes for June 4th 2025

Period: June 3rd 2025, 12:00 AM to June 4th 2025, 12:00 AM

๐Ÿ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 4th 2025.

๐Ÿ“Š Summary

43
Total Commits
4
New Files
82
Modified Files
5
Deleted Files
15
Contributors

๐Ÿ†• New Documentation Files

+0 lines added
Commit: changing manager field
+0 lines added
Commit: changing manager field
+0 lines added
Commit: changing manager field
+0 lines added
Commit: changing manager field

๐Ÿ“ Modified Documentation Files

+46 / -18 lines changed
Commit: Update acronis-cyber-protect-cloud-tutorial.md
Changes:
Before
After
---
title: Configure Acronis Cyber Protect Cloud for Single sign-on with Microsoft Entra ID
description: Learn how to configure single sign-on between Microsoft Entra ID and Acronis Cyber Protect Cloud.
services: active-directory
author: nguhiu
 
---
 
# Configure Acronis Cyber Protect Cloud for Single sign-on with Microsoft Entra ID
 
In this article, you learn how to integrate Acronis Cyber Protect Cloud with Microsoft Entra ID. When you integrate Acronis Cyber Protect Cloud with Microsoft Entra ID, you can:
 
* Control in Microsoft Entra ID who has access to Acronis Cyber Protect Cloud.
* Enable your users to be automatically signed-in to Acronis Cyber Protect Cloud with their Microsoft Entra accounts.
* Manage your accounts in one central location.
 
## Prerequisites
 
The scenario outlined in this article assumes that you already have the following prerequisites:
 
---
title: Configure Acronis Cyber Protect Cloud for Single Sign-On with Microsoft Entra ID
description: Learn how to configure single sign-on between Microsoft Entra ID and Acronis Cyber Protect Cloud.
services: active-directory
author: nguhiu
 
---
 
# Configure Acronis Cyber Protect Cloud for Single Sign-On with Microsoft Entra ID
 
In this article, you learn how to integrate Acronis Cyber Protect Cloud with Microsoft Entra ID. When you integrate Acronis Cyber Protect Cloud with Microsoft Entra ID, you can:
 
* Control in Microsoft Entra ID who has access to Acronis Cyber Protect Cloud.
* Enable your users to be automatically signed on to Acronis Cyber Protect Cloud with their Microsoft Entra accounts.
* Control SP-initiated and IDP-initiated SAML Single Logout (SLO) processes.
* Manage your accounts in one central location.
* By-pass Acronis 2FA challenge.
 
## Prerequisites
 
+24 / -4 lines changed
Commit: Update concept-mfa-regional-opt-in.md
Changes:
Before
After
---
title: Regional telecom restrictions
description: To protect customers, some regions require a support ticket to request to opt in to receive MFA telephony verification Microsoft Entra ID and Microsoft Azure B2C
 
ms.service: entra-id
ms.subservice: authentication
ms.reviewer: aloom3
ms.custom: references_regions
---
# Regions that need to opt in for MFA telephony verification
 
 
 
As a protection for our customers, Microsoft doesn't automatically support telephony verification for certain region codes. If you want to receive traffic from phone numbers with these region codes, a Microsoft Entra administrator must submit a support ticket and request to opt in.
 
B2C tenants can follow the guidelines in [B2C service limits](/azure/active-directory-b2c/service-limits).
Microsoft Entra External ID tenants can follow the guidelines in [How to region code opt-in](/entra/external-id/customers/how-to-region-code-opt-in).
 
## Why this protection is needed
 
---
title: Telephony Fraud Protections and Throttles
description: Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.
 
ms.service: entra-id
ms.subservice: authentication
ms.reviewer: aloom3
ms.custom: references_regions
---
## Overview
To protect customers from telephony-based abuse and fraud, Microsoft Entra ID applies intelligent detection and throttling mechanisms to all telecom based authentication requests.
 
These protections use a combination of heuristics, machine learning models, and risk-based signals to detect and block potentially abusive or fraudulent telephony activity in real time.
 
In addition, some region codes require opt-in. Admins can submit a support request to enable telephony verification for these regions if needed.
 
Together, these safeguards help organizations defend against fraud while preserving a smooth authentication experience for legitimate users.
 
B2C tenants can follow the guidelines in [B2C service limits](/azure/active-directory-b2c/service-limits).
Microsoft Entra External ID tenants can follow the guidelines in [How to region code opt-in](/entra/external-id/customers/how-to-region-code-opt-in).
Modified by omondiatieno on Jun 3, 2025 9:55 PM
๐Ÿ“– View on learn.microsoft.com
+8 / -16 lines changed
Commit: whatsnew updates for June
Changes:
Before
After
---
title: "What's new in Microsoft Entra application management"
description: "This article shows the new and updated documentation for the Microsoft Entra application management."
ms.date: 05/06/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## April 2025
 
### New articles
- [Review permissions granted to enterprise applications](manage-application-permissions.md)
 
- [Overview of user and admin consent](user-admin-consent-overview.md) - Revised the article to improve technical accuracy and clarity.
 
## February 2025
 
### New articles
---
title: What's new in Microsoft Entra application management
description: "This article shows the new and updated documentation for the Microsoft Entra application management."
ms.date: 06/03/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## May 2025
 
### Updated articles
 
No updates this month.
 
## April 2025
 
### New articles
- [Review permissions granted to enterprise applications](manage-application-permissions.md)
+12 / -12 lines changed
Commit: email-MDI
Changes:
Before
After
| Recommendation | Impacted resources | Availability | Identity Secure Score | Target roles for email notifications |
| --- | --- | --- | --- | --- |
| AAD Connect Deprecated | Tenant | Preview | No | Hybrid Identity Administrator |
| Configure VPN integration | Users | Preview | Yes | |
| [Convert per-user MFA to Conditional Access MFA](recommendation-turn-off-per-user-mfa.md) | Users | Generally available | No | Security Administrator |
| Designate more than one Global Administrator | Users | Generally available | Yes | Global Administrator |
| Do not allow users to grant consent to unreliable applications | Tenant | Generally available | Yes | Global Administrator |
| Do not expire passwords | Tenant | Generally available | Yes | Global Administrator |
| Edit misconfigured certificate templates access control lists | Applications | Preview | Yes | |
| Edit misconfigured enrollment agent certificate template | Applications | Preview | Yes | |
| Enable password hash sync if hybrid | Tenant | Generally available | Yes | Hybrid Identity Administrator |
| Enable policy to block legacy authentication | Users | Generally available | Yes | Conditional Access Administrator, Security Administrator |
| Enable self-service password reset | Users | Generally available | Yes | Authentication Policy Administrator |
| [Migrate service principals from the retiring Azure AD Graph APIs to Microsoft Graph](recommendation-migrate-to-microsoft-graph-api.md) | Applications | Preview | No | Application Administrator |
| [Migrate to Microsoft Authenticator](recommendation-migrate-to-authenticator.md) | Users | Preview | No | Global Administrator |
| [Minimize MFA prompts from known devices](recommendation-mfa-from-known-devices.md) | Users | Generally available | No | Global Administrator |
| Modify unsecure Kerberos delegations to prevent impersonation | Applications | Preview | Yes | |
| Protect all users with a sign-in risk policy | Users | Generally available | Yes | Conditional Access Administrator, Security Administrator |
| Protect all users with a user risk policy | Users | Generally available | Yes | Conditional Access Administrator, Security Administrator |
| Protect and manage local admin passwords with Microsoft LAPS | Users | Preview | Yes | |
| Recommendation | Impacted resources | Availability | Identity Secure Score | Target roles for email notifications |
| --- | --- | --- | --- | --- |
| AAD Connect Deprecated | Tenant | Preview | No | Hybrid Identity Administrator |
| Configure VPN integration | Users | Preview | Yes | N/A |
| [Convert per-user MFA to Conditional Access MFA](recommendation-turn-off-per-user-mfa.md) | Users | Generally available | No | Security Administrator |
| Designate more than one Global Administrator | Users | Generally available | Yes | Global Administrator |
| Do not allow users to grant consent to unreliable applications | Tenant | Generally available | Yes | Global Administrator |
| Do not expire passwords | Tenant | Generally available | Yes | Global Administrator |
| Edit misconfigured certificate templates access control lists | Applications | Preview | Yes | N/A |
| Edit misconfigured enrollment agent certificate template | Applications | Preview | Yes | N/A |
| Enable password hash sync if hybrid | Tenant | Generally available | Yes | Hybrid Identity Administrator |
| Enable policy to block legacy authentication | Users | Generally available | Yes | Conditional Access Administrator, Security Administrator |
| Enable self-service password reset | Users | Generally available | Yes | Authentication Policy Administrator |
| [Migrate service principals from the retiring Azure AD Graph APIs to Microsoft Graph](recommendation-migrate-to-microsoft-graph-api.md) | Applications | Preview | No | Application Administrator |
| [Migrate to Microsoft Authenticator](recommendation-migrate-to-authenticator.md) | Users | Preview | No | Global Administrator |
| [Minimize MFA prompts from known devices](recommendation-mfa-from-known-devices.md) | Users | Generally available | No | Global Administrator |
| Modify unsecure Kerberos delegations to prevent impersonation | Applications | Preview | Yes | N/A |
| Protect all users with a sign-in risk policy | Users | Generally available | Yes | Conditional Access Administrator, Security Administrator |
| Protect all users with a user risk policy | Users | Generally available | Yes | Conditional Access Administrator, Security Administrator |
| Protect and manage local admin passwords with Microsoft LAPS | Users | Preview | Yes | N/A |
Modified by Rohit Gulati on Jun 3, 2025 5:30 AM
๐Ÿ“– View on learn.microsoft.com
+9 / -11 lines changed
Commit: Updates to helpdesk page and partner gallery page for image
Changes:
Before
After
 
# Microsoft Entra Verified ID Identity Verification partners
 
Our Identity Verification (IDV) partner network extends Microsoft Entra Verified ID's capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable scenarios like remote onboarding with government ID checks using identity verification and proofing services.
The diagram shows a low-level workflow of how all parties interact with each other in a remote onboarding scenario. This integration pattern could be used as a reference.
 
:::image type="content" source="media/partner-gallery/identity-verification-integration.png" alt-text="Screenshot of the IDV integration pattern.":::
 
The following section covers a set of steps that IDVs can use for setting up issuance flows and by customers for verifying IDV Verified IDs.
 
## Issuer flow
Identity Verification (IDV) partners are ISVs who can use Verified ID Request Service REST API to issue Verified IDs. The steps required by an IDV to function as an issuer are as follows:
 
1. Set up Microsoft Entra Verified ID Service: using [Quick setup](verifiable-credentials-configure-tenant-quick.md) or [Advanced setup instructions](verifiable-credentials-configure-tenant.md).
 
>[!Note]
>For a multi-tenant model, IDV should explore setting up dedicated authorities if there is a 1:1 relationship required with the customer. Refer [Admin API](admin-api.md) section of the docs for creating authorities.
 
2. Set up a credential definition that defines what type of credentials you'll issue from the service โ€“ [Custom Credential](credential-design.md). Based on the scenario, select between id token (for Open ID connect attestations from providers) or id token hint (ISVs to use REST APIs to get the required attestations), self issued (user provided input), presentation or multiple attestations.
 
 
# Microsoft Entra Verified ID Identity Verification partners
 
Our Identity Verification (IDV) partner network extends Microsoft Entra Verified ID capabilities to help you build seamless end-user experiences. With Verified ID, you can integrate with IDV partners to enable scenarios like remote onboarding with government ID checks using identity verification and proofing services.
The diagram shows a low-level workflow of how all parties interact with each other in a remote onboarding scenario. This integration pattern could be used as a reference.
 
:::image type="content" source="media/partner-gallery/identity-verification-integration.png" alt-text="Screenshot of the IDV integration pattern." lightbox="true":::
 
The following section covers a set of steps that IDVs can use for setting up issuance flows and by customers for verifying IDV Verified IDs.
 
## Issuer flow
Identity Verification (IDV) partners are Independent Software vendors (ISVs) who can use Verified ID Request Service REST API to issue Verified IDs. The steps required by an IDV to function as an issuer are as follows:
 
1. Set up Microsoft Entra Verified ID Service: using [Quick setup](verifiable-credentials-configure-tenant-quick.md) or [Advanced setup instructions](verifiable-credentials-configure-tenant.md).
>[!Note]
>For a multi-tenant model, IDV should explore setting up dedicated authorities if there is a 1:1 relationship required with the customer. Refer [Admin API](admin-api.md) section of the docs for creating authorities.
 
2. Set up a credential definition that defines what type of credentials you'll issue from the service โ€“ [Custom Credential](credential-design.md). Based on the scenario, select between ID token (for Open ID connect attestations from providers) or ID token hint (ISVs to use REST APIs to get the required attestations), self issued (user provided input), presentation or multiple attestations.
 
3. Make sure to publish the credential in the Verified ID network if this credential is for general purpose consumption. If this credential was created for a specific customer, then skip this step. To publish the credential in the Verified ID network, select **Issue a credential** option under Manage and then select **Publish credential to Verified ID network** checkbox. You could also use [Admin APIs](admin-api.md) to set **โ€œavailableInVcDirectory"** to true for the credential.
+18 / -1 lines changed
Commit: Update concept-transport-layer-security.md
Changes:
Before
After
 
To get started with TLS inspection, see [Configure Transport Layer Security](how-to-transport-layer-security.md).
 
## Known limitations
TLS inspection has the following known limitations:
- When a TLS inspection rule is enabled, all categories except Education, Government, Finance, and Health and Medicine are decrypted by default. Additionally, Global Secure Access manages a system bypass list that includes common destinations known to be incompatible with TLS inspection. If a request matches the system bypass, the TLS action is logged as Bypassed. Work is underway to support custom TLS rules for intercepting or bypassing specific destinations or categories. In the meantime, use the custom bypass feature in the Internet Access forwarding profile to exclude destinations that TLS inspection affects.
- You can use only one active certificate at a time.
- TLS inspection doesn't support Application-Layer Protocol Negotiation (ALPN) version 2. If a destination site requires HTTP/2, the upstream TLS handshake fails, and the site isn't accessible when TLS inspection is enabled.
- TLS inspection doesn't follow Authority Information Access (AIA) and Online Certificate Status Protocol (OCSP) links when validating destination certificates.
 
## Related content
 
* [Configure Transport Layer Security](how-to-transport-layer-security.md)
* [Frequently asked questions for Transport Layer Security inspection](faq-transport-layer-security.yml)
* [Ciphers for Microsoft Entra Private Access](reference-ciphers.md)
 
 
 
 
 
 
To get started with TLS inspection, see [Configure Transport Layer Security](how-to-transport-layer-security.md).
 
## Supported Cyphers
|List of supported cyphers |
|-------------------|
|ECDHE-ECDSA-AES128-GCM-SHA256|
|ECDHE-ECDSA-CHACHA20-POLY1305|
|ECDHE-RSA-AES128-GCM-SHA256|
|ECDHE-RSA-CHACHA20-POLY1305|
|ECDHE-ECDSA-AES128-SHA|
|ECDHE-RSA-AES128-SHA|
|AES128-GCM-SHA256|
|AES128-SHA|
|ECDHE-ECDSA-AES256-GCM-SHA384|
|ECDHE-RSA-AES256-GCM-SHA384 |
|ECDHE-ECDSA-AES256-SHA |
|ECDHE-RSA-AES256-SHA |
|AES256-GCM-SHA384|
|AES256-SHA |
+9 / -8 lines changed
Commit: PM-review
Changes:
Before
After
ms.service: entra-id
ms.subservice: monitoring-health
ms.topic: conceptual
ms.date: 05/30/2025
 
ms.author: sarahlipsey
author: shlipsey3
manager: femila
ms.reviewer: jadedsouza
 
# Customer intent: As an IT admin, I want to know how to use the Identity Secure Score and related recommendations to improve the security posture of my Microsoft Entra tenant.
---
# What is Identity Secure Score?
 
The Identity Secure Score is shown as a percentage that functions as an indicator for how aligned you are with Microsoft's recommendations for security. Each improvement action in Identity Secure Score is tailored to your configuration. You can access the score and view individual recommendations related to your score in Microsoft Entra recommendations. You can also see how your score has changed over time.
 
![Screenshot of the Recommendations page with the Secure Score details highlighted.](./media/concept-identity-secure-score/secure-score-overview.png)
 
- Designate more than one Global Administrator
- Do not allow users to grant consent to unreliable applications
ms.service: entra-id
ms.subservice: monitoring-health
ms.topic: conceptual
ms.date: 06/02/2025
 
ms.author: sarahlipsey
author: shlipsey3
manager: pmwongera
ms.reviewer: jadedsouza
 
# Customer intent: As an IT admin, I want to know how to use the Identity Secure Score and related recommendations to improve the security posture of my Microsoft Entra tenant.
---
# What is Identity Secure Score?
 
The Identity Secure Score is shown as a percentage that functions as an indicator for how aligned you are with Microsoft's recommendations for security. Each improvement action in Identity Secure Score is tailored to your configuration. You can access the score and view individual recommendations related to your score in Microsoft Entra recommendations. You can also see how your score changes over time.
 
![Screenshot of the Recommendations page with the Secure Score details highlighted.](./media/concept-identity-secure-score/secure-score-overview.png)
 
- Designate more than one Global Administrator
- Do not allow users to grant consent to unreliable applications
+5 / -5 lines changed
Commit: Update how-to-transport-layer-security.md
Changes:
Before
After
1. Select **Create CSR**.
:::image type="content" source="media/how-to-transport-layer-security/create-certificate.png" alt-text="Screenshot of the Create certificate pane with fields filled and the Create CSR button highlighted.":::
 
1. Sign the CSR using your PKI service. Make sure Server Auth is in Extended Key Usage and certificate authority (CA)=true in Basic Extension.
1. Select **+Upload certificate**.
1. In the Upload certificate form, upload the certificate.pem and chain.pem files.
1. Select **Upload signed certificate**.
```
 
2. Create a new root certificate authority and private key using the following *openssl.cnf* config file:
```openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCA.key -sha256 -days 365 -out rootCA.crt -subj โ€œ/C=US/ST=US/O=Self Signed/CN=Self Signed Root CAโ€ -config openssl.cnf -extensions rootCA_ext```
1. Sign *csr.txt* with the following command:
```openssl x509 -req -in csr.txt -CA _rootCA.crt_ -CAkey rootCA.key -CAcreateserial -out signedcertificate.crt -days 365 -sha256 -extfile openssl.cnf -extensions signedCA_ext```
1. Rename *signedcertificate.crt* to *signedcertificate.pem* and *rootCA.crt* to *rootCA.pem*. Upload the signed certificates according to the steps in [Create a CSR and upload the signed certificate for TLS termination](#step-1-global-secure-access-admin-create-a-csr-and-upload-the-signed-certificate-for-tls-termination).
 
## Related content
 
1. Select **Create CSR**.
:::image type="content" source="media/how-to-transport-layer-security/create-certificate.png" alt-text="Screenshot of the Create certificate pane with fields filled and the Create CSR button highlighted.":::
 
1. Sign the CSR using your PKI service. Make sure Server Auth is in Extended Key Usage and certificate authority (CA)=true in Basic Extension. Save the signed certifcate in .pem format.
1. Select **+Upload certificate**.
1. In the Upload certificate form, upload the certificate.pem and chain.pem files.
1. Select **Upload signed certificate**.
```
 
2. Create a new root certificate authority and private key using the following *openssl.cnf* config file:
```openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCA.key -sha256 -days 365 -out rootCA.pem -subj "/C=US/ST=US/O=Self Signed/CN=Self Signed Root CA" -config openssl.cnf -extensions rootCA_ext```
1. Sign the CSR using the following command:
```openssl x509 -req -in <CSR file> -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -out signedcertificate.pem -days 365 -sha256 -extfile openssl.cnf -extensions signedCA_ext```
1. Upload the signed certificates according to the steps in [Create a CSR and upload the signed certificate for TLS termination](#step-1-global-secure-access-admin-create-a-csr-and-upload-the-signed-certificate-for-tls-termination).
 
## Related content
 
+6 / -4 lines changed
Commit: non-interactive
Changes:
Before
After
title: Non-interactive sign-in logs
description: Learn about the type of activity captured in the non-interactive sign-in logs in Microsoft Entra monitoring and health.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 03/17/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
ms.custom: sfi-image-nochange
- Status
- Resource ID
 
> [!NOTE]
> The IP address of non-interactive sign-ins performed by [confidential clients](../../identity-platform/msal-client-applications.md) doesn't match the actual source IP of where the refresh token request is coming from. Instead, it shows the original IP used for the original token issuance.
 
 
title: Non-interactive sign-in logs
description: Learn about the type of activity captured in the non-interactive sign-in logs in Microsoft Entra monitoring and health.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 06/02/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
ms.custom: sfi-image-nochange
- Status
- Resource ID
 
## Special considerations
 
- The IP address of non-interactive sign-ins performed by [confidential clients](../../identity-platform/msal-client-applications.md) doesn't match the actual source IP of where the refresh token request is coming from. Instead, it shows the original IP used for the original token issuance.
- As of April 11, 2025, all new sign-ins that obtain a refresh token with FIDO2 keys are now logged in the non-interactive sign-in logs.
Modified by Rohit Gulati on Jun 3, 2025 5:30 AM
๐Ÿ“– View on learn.microsoft.com
+5 / -5 lines changed
Commit: Updates to helpdesk page and partner gallery page for image
Changes:
Before
After
 
# Verified helpdesk with Microsoft Entra Verified ID
 
An ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Traditional methods such as personally identifiable information (PII) and knowledge-based authentication are no match for todayโ€™s sophisticated attackers, who leverage phishing, social engineering, and even AI-powered voice cloning to bypass defences. The consequences are serious: under pressure, helpdesk agents may unintentionally expose sensitive data or authorize fraudulent actions.
 
**The Way Forward: Stronger and Phish resistant Authentication**
To defend against these evolving threats without compromising user experience, organizations must adopt modern verification strategies built for todayโ€™s threat landscape. This includes:
* Phish resistant authentication (e.g. passkeys)
* AI-driven fraud detection to flag anomalous behaviour
* Zero Trust principles enforcing strict identity checks
* Enterprise-grade identity validationโ€”without relying on PII.
 
Microsoft offers solutions that enable Admins to enhance security without sacrificing user experience. Organizations can adopt the two key patterns:
 
1. Strong Authentication: Users authenticate with their existing corporate credentials before requesting helpdesk support. User is prompted to present strong phish resistant credentials before they are granted access to resources. Microsoft platform offers solutions like Azure Communication Services that supports multichannel communication APIs for adding voice, video, chat, text messaging/SMS, email, and more to all your applications. [Azure Communication Services (ACS)](https://azure.microsoft.com/products/communication-services/?msockid=27ae7d5196f463891a416cf192f46589#Features-3) supports a security pattern where users visit a URL to initiate a direct, encrypted voice/video/chat session with a helpdesk via an ACS-integrated app. Authentication is managed using Microsoft Entra ID, and secure ACS tokens ensure controlled access, preventing unauthorized connections.
2. Total Loss Recovery: In cases where a user has lost all authentication credentials, a secure, policy-driven recovery process is implemented to re-establish access without compromising security. Microsoft Entra Verified ID could help such enterprises add verification processes seamlessly into their existing helpdesk and service desk operations. Upon successful verification, service desk could offer tasks such as password resets, Temporary Access Pass (TAP) provision, MFA (multifactor authentication) onboarding, and account updates, potentially enabling self-service automation.
This document explains how to use Microsoft Entra Verified ID for the total loss recovery scenario.
 
 
An enterprise can add self-service automation services like generate a [Temporary Access Pass](~/identity/authentication/howto-authentication-temporary-access-pass.md) post successful verification of Verified ID taking claims from Verified ID. GitHub [sample](https://github.com/Azure-Samples/active-directory-verifiable-credentials-dotnet/tree/main/5-onboard-with-tap) explains this self-service automation process.
 
# Verified helpdesk with Microsoft Entra Verified ID
 
An ongoing challenge for helpdesk is verifying the identity of callers seeking help, especially in remote interactions via phone, chat, or email. Traditional methods such as personally identifiable information (PII) and knowledge-based authentication are no match for todayโ€™s sophisticated attackers, who use phishing, social engineering, and even AI-powered voice cloning to bypass defenses. The consequences are serious: under pressure, helpdesk agents may unintentionally expose sensitive data or authorize fraudulent actions.
 
**The Way Forward: Stronger and Phish resistant Authentication**
To defend against these evolving threats without compromising user experience, organizations must adopt modern verification strategies built for todayโ€™s threat landscape. This includes:
* Phish resistant authentication (for example, passkeys)
* AI-driven fraud detection to flag anomalous behavior
* Zero Trust principles enforcing strict identity checks
* Enterprise-grade identity validationโ€”without relying on PII.
 
Microsoft offers solutions that enable Admins to enhance security without sacrificing user experience. Organizations can adopt the two key patterns:
 
1. Strong Authentication: Users authenticate with their existing corporate credentials before requesting helpdesk support. User is prompted to present strong phish resistant credentials before they're granted access to resources. Microsoft platform offers solutions like Azure Communication Services that supports multichannel communication APIs for adding voice, video, chat, text messaging/SMS, email, and more to all your applications. [Azure Communication Services (ACS)](https://azure.microsoft.com/products/communication-services/?msockid=27ae7d5196f463891a416cf192f46589#Features-3) supports a security pattern where users visit a URL to initiate a direct, encrypted voice/video/chat session with a helpdesk via an ACS-integrated app. Authentication is managed using Microsoft Entra ID, and secure ACS tokens ensure controlled access, preventing unauthorized connections.
2. Total Loss Recovery: In cases where a user has lost all authentication credentials, a secure, policy-driven recovery process is implemented to re-establish access without compromising security. Microsoft Entra Verified ID could help such enterprises add verification processes seamlessly into their existing helpdesk and service desk operations. Upon successful verification, service desk could offer tasks such as password resets, Temporary Access Pass (TAP) provision, MFA (multifactor authentication) onboarding, and account updates, potentially enabling self-service automation.
This document explains how to use Microsoft Entra Verified ID for the total loss recovery scenario.
 
 
An enterprise can add self-service automation services like generate a [Temporary Access Pass](~/identity/authentication/howto-authentication-temporary-access-pass.md) post successful verification of Verified ID taking claims from Verified ID. GitHub [sample](https://github.com/Azure-Samples/active-directory-verifiable-credentials-dotnet/tree/main/5-onboard-with-tap) explains this self-service automation process.
Modified by Barclay Neira on Jun 3, 2025 8:50 AM
๐Ÿ“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: updating manager field
Changes:
Before
After
---
title: Quarantine unsanctioned tenants
description: Isolate unsanctioned tenants using Microsoft Entra features. Follow steps to quarantine unapproved tenants and strengthen security.
author: barclayn
manager: femila
ms.service: entra
ms.subservice: fundamentals
ms.topic: concept-article
ms.date: 04/14/2025
---
title: Quarantine unsanctioned tenants
description: Isolate unsanctioned tenants using Microsoft Entra features. Follow steps to quarantine unapproved tenants and strengthen security.
author: barclayn
manager: pmwongera
ms.service: entra
ms.subservice: fundamentals
ms.topic: concept-article
ms.date: 04/14/2025
+3 / -3 lines changed
Commit: logs-060225
Changes:
Before
After
title: Interactive user sign-in logs
description: Learn about the type of information captured in the interactive user sign-in logs in Microsoft Entra monitoring and health.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 03/17/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
ms.custom: sfi-image-nochange
 
### Non-interactive sign-ins on the interactive sign-in logs
 
Previously, some non-interactive sign-ins from Microsoft Exchange clients were included in the interactive user sign-in log for better visibility. This increased visibility was necessary before the non-interactive user sign-in logs were introduced in November 2020. However, it's important to note that some non-interactive sign-ins, such as those using FIDO2 keys, might still be marked as interactive due to the way the system was set up before the separate non-interactive logs were introduced. These sign-ins might display interactive details like client credential type and browser information, even though they're technically non-interactive sign-ins.
 
### Passthrough sign-ins
 
title: Interactive user sign-in logs
description: Learn about the type of information captured in the interactive user sign-in logs in Microsoft Entra monitoring and health.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 06/02/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
ms.custom: sfi-image-nochange
 
### Non-interactive sign-ins on the interactive sign-in logs
 
Previously, some non-interactive sign-ins were included in the interactive user sign-in log for better visibility. This increased visibility was necessary before the non-interactive user sign-in logs were introduced in November 2020. Non-interactive sign-ins involving FIDO2 keys were previously marked as interactive sign-ins, even though they were technically non-interactive. As of April 11, 2025, all new sign-ins that obtain a refresh token with FIDO2 keys are now logged in the non-interactive sign-in logs.
 
### Passthrough sign-ins
 
+1 / -1 lines changed
Commit: broken link fix for equinix federation app
Changes:
Before
After
 
## Configure Equinix Federation App SSO
 
To configure Single Sign-On on **Equinix Federation App** side, please follow the [link](https://docs.equinix.com/Content/home.htm).
 
### Create Equinix Federation App test user
 
 
## Configure Equinix Federation App SSO
 
To configure Single Sign-On on **Equinix Federation App** side, please follow the [link](https://docs.equinix.com).
 
### Create Equinix Federation App test user
 
Modified by Barclay Neira on Jun 3, 2025 8:38 PM
๐Ÿ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: changing manager field
Changes:
Before
After
description: You can convert users from external to internal without the need to recreate them.
author: barclayn
ms.author: barclayn
manager: femila
ms.date: 01/06/2025
ms.topic: how-to
ms.service: entra-id
description: You can convert users from external to internal without the need to recreate them.
author: barclayn
ms.author: barclayn
manager: pmwongera
ms.date: 01/06/2025
ms.topic: how-to
ms.service: entra-id
+1 / -1 lines changed
Commit: changing manager field
Changes:
Before
After
description: The relationship between older delegated admin permissions and new granular delegated admin permissions in Microsoft Entra ID
keywords:
author: barclayn
manager: femila
ms.author: barclayn
ms.reviewer: yuank
ms.date: 12/13/2024
description: The relationship between older delegated admin permissions and new granular delegated admin permissions in Microsoft Entra ID
keywords:
author: barclayn
manager: pmwongera
ms.author: barclayn
ms.reviewer: yuank
ms.date: 12/13/2024

๐Ÿ—‘๏ธ Deleted Documentation Files

DELETED docs/identity/devices/enterprise-state-roaming-windows-settings-reference.md
Deleted by Ortagus Winfrey on Jun 3, 2025 12:02 AM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity/devices/enterprise-state-roaming-windows-settings-reference
-51 lines removed
Commit: Article removed
DELETED docs/identity/users/licensing-groups-assign.md
Deleted by Barclay Neira on Jun 3, 2025 9:04 PM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity/users/licensing-groups-assign
-0 lines removed
Commit: removing redirected files per prmerger
DELETED docs/identity/users/licensing-groups-migrate-users.md
Deleted by Barclay Neira on Jun 3, 2025 9:04 PM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity/users/licensing-groups-migrate-users
-0 lines removed
Commit: removing redirected files per prmerger
DELETED docs/identity/users/licensing-groups-resolve-problems.md
Deleted by Barclay Neira on Jun 3, 2025 9:04 PM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity/users/licensing-groups-resolve-problems
-0 lines removed
Commit: removing redirected files per prmerger
DELETED docs/identity/users/licensing-ps-examples.md
Deleted by Barclay Neira on Jun 3, 2025 9:04 PM
๐Ÿ“– Was available at: https://learn.microsoft.com/en-us/entra/identity/users/licensing-ps-examples
-0 lines removed
Commit: removing redirected files per prmerger