📋 Microsoft Entra Documentation Changes

Changes for June 10th 2025

Period: June 9th 2025, 12:00 AM to June 10th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 10th 2025.

📊 Summary

14
Total Commits
0
New Files
31
Modified Files
0
Deleted Files
7
Contributors

📝 Modified Documentation Files

+10 / -15 lines changed
Commit: updates
Changes:
Before
After
| Entitlement Management | [Guest uses verified ID for request](entitlement-management-verified-id-settings.md) | Bill on successful request creation when verified ID is required in the policy.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when the access package policy requires a Verified ID. | User requests access package assignment, Create access package assignment user update request. |
| Entitlement Management | [Guest policy assigned with custom extension](entitlement-management-logic-apps-integration.md) | Bill on successful request creation when a custom extension is included in the assignment policy.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when a custom extension is included in the assignment policy. | User requests access package assignment, Create access package assignment user update request. |
| Entitlement Management| [Guest is granted an auto-assignment policy](entitlement-management-access-package-auto-assignment-policy.md) | Bill on successful request creation with an auto-assignment policy. | Entitlement Management creates access package assignment request for user. |
| Entitlement Management | [Directly assign any user](entitlement-management-access-package-assignments.md#directly-assign-any-user-preview) | Bill on successful request creation when using directly assigning an access package to a user not yet in the directory.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when using requestType “*AdminAdd*” for a user who doesn’t exist in the directory. | Administrator directly assigns user to access package. |
| Entitlement Management |[Mark guest as governed](entitlement-management-access-package-manage-lifecycle.md) | Bill on conversion to governed user.<br>**API**<br> https://graph.microsoft.com/beta/identityGovernance/entitlementManagement/subjects where subjectLifecycle is set to “*governed*”. | Update access package user lifecycle. |
| Lifecycle Workflows  | [Workflow is run for guest](what-are-lifecycle-workflows.md) | Bill on workflow execution.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/lifecycleWorkflows/workflows/{workflowId}/activate | Workflow execution started for user. |
| Access Reviews  | [Access Review – machine learning assisted access reviews](review-recommendations-access-reviews.md#user-to-group-affiliation) | Bill on access review start date. | Available after 8/1/2025 |
| Access Reviews  | [Access Review – inactive users](review-recommendations-access-reviews.md#inactive-user-recommendations) | Bill on access review start date. | Available after 8/1/2025 |
 
## Guest billing in multitenant organizations
 
Governance guest billing only applies for users with a userType of
**guest**, so if Microsoft Entra ID Governance licensed member users are brought
into additional organization tenants with a userType of **member**, they
won't accrue to the billing meter.
 
If these users are brought in with a userType of **guest** they accrue to the meter, however you can avoid being charged by setting up
or joining a multitenant organization. If the guest user is from a
participating organizational tenant, the guest won't accrue to the
billing meter. See [Set up a multitenant org in Microsoft
| Entitlement Management | [Guest uses verified ID for request](entitlement-management-verified-id-settings.md) | Bill on successful request creation when verified ID is required in the policy.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when the access package policy requires a Verified ID. | User requests access package assignment, Create access package assignment user update request. |
| Entitlement Management | [Guest policy assigned with custom extension](entitlement-management-logic-apps-integration.md) | Bill on successful request creation when a custom extension is included in the assignment policy.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when a custom extension is included in the assignment policy. | User requests access package assignment, Create access package assignment user update request. |
| Entitlement Management| [Guest is granted an auto-assignment policy](entitlement-management-access-package-auto-assignment-policy.md) | Bill on successful request creation with an auto-assignment policy. | Entitlement Management creates access package assignment request for user. |
| Entitlement Management | [Directly assign any user](entitlement-management-access-package-assignments.md#directly-assign-any-user-preview) | Bill on successful request creation when using directly assigning an access package to a user not yet in the directory.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/entitlementManagement/assignmentRequests when using requestType "*AdminAdd*" for a user who doesn’t exist in the directory. | Administrator directly assigns user to access package. |
| Entitlement Management |[Mark guest as governed](entitlement-management-access-package-manage-lifecycle.md) | Bill on conversion to governed user.<br>**API**<br> https://graph.microsoft.com/beta/identityGovernance/entitlementManagement/subjects where subjectLifecycle is set to "governed". | Update access package user lifecycle. |
| Lifecycle Workflows  | [Workflow is run for guest](what-are-lifecycle-workflows.md) | Bill on workflow execution.<br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/lifecycleWorkflows/workflows/{workflowId}/activate | Workflow execution started for user. |
| Access Reviews  | [Access Review – machine learning assisted access reviews](review-recommendations-access-reviews.md#user-to-group-affiliation) | Bill on access review start date. | Available after 8/1/2025 |
| Access Reviews  | [Access Review – inactive users](review-recommendations-access-reviews.md#inactive-user-recommendations) | Bill on access review start date. | Available after 8/1/2025 |
 
## Guest billing in multitenant organizations
 
Governance guest billing only applies for users with a userType of **guest**, so if Microsoft Entra ID Governance licensed member users are brought into additional organization tenants with a userType of **member**, they won't accrue to the billing meter.
 
If these users are brought in with a userType of **guest** they accrue to the meter, however you can avoid being charged by setting up
or joining a multitenant organization. If the guest user is from a participating organizational tenant, the guest won't accrue to the
billing meter. See [Set up a multitenant org in Microsoft 365](/microsoft-365/enterprise/set-up-multi-tenant-org?view=o365-worldwide).
 
## Billing examples
 
 
Modified by Chris Werner on Jun 9, 2025 8:49 PM
📖 View on learn.microsoft.com
+2 / -5 lines changed
Commit: removing bad prompts
Changes:
Before
After
- *What is my SLA for Microsoft Entra authentication?*
- *What is my Microsoft Entra SLA?*
- *SLA of Microsoft Entra authentication*
- *Microsoft Entra SLA*
- *Show me my tenant's authentication availability*
- *What is my authentication availability?*
- *Authentication availability*
- *Has my tenant had an SLA breach in the last X months?*
 
### Microsoft Entra domains
 
- *What is my SLA for Microsoft Entra authentication?*
- *What is my Microsoft Entra SLA?*
- *SLA of Microsoft Entra authentication*
- *Show me my tenant's authentication availability.*
- *Has my tenant had an SLA breach in the last "X" months?*
 
### Microsoft Entra domains
 
 
 
 
Modified by Alexander Filipin on Jun 9, 2025 11:43 PM
📖 View on learn.microsoft.com
+3 / -0 lines changed
Commit: Update understanding-lifecycle-workflows.md
Changes:
Before
After
 
[![Workflow template schedule.](media/understanding-lifecycle-workflows/workflow-10.png)](media/understanding-lifecycle-workflows/workflow-10.png#lightbox)
 
To view a detailed guide on customizing the schedule of a workflow, see: [Customize the schedule of workflows](customize-workflow-schedule.md).
 
### On-demand scheduling
 
 
 
 
[![Workflow template schedule.](media/understanding-lifecycle-workflows/workflow-10.png)](media/understanding-lifecycle-workflows/workflow-10.png#lightbox)
 
>[!NOTE]
> The time based attribute trigger processes a user at a specific point in time based on the workflow configuration (e.g., seven days before the user’s hire date) and user account configuration. For reliable workflow execution, the user account must be configured with all relevant details (e.g., trigger and scoping attributes) in advance of the scheduled workflow execution. Once the designated time arrives, the next scheduled workflow run will process the user if it meets the execution conditions. If the workflow or user account is configured after the intended processing time (e.g., due to a delay in the HR system), Lifecycle Workflows will still attempt to process the user—provided the necessary setup is completed within three days of the original processing time.
 
To view a detailed guide on customizing the schedule of a workflow, see: [Customize the schedule of workflows](customize-workflow-schedule.md).
 
### On-demand scheduling
Modified by Regan Downer on Jun 9, 2025 11:40 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/identity-platform/v2-oauth2-on-behalf-of-flow.md
Changes:
Before
After
> [!IMPORTANT]
> While it's valid to use `scope=openid https://resource/.default` in combined consent flows involving [known client applications](reference-app-manifest.md#knownclientapplications-attribute), you must **not** combine `.default` with other delegated scopes like `User.Read`, `Mail.Read`, `profile`, or `User.ReadWrite.All` in the same request. This will result in `AADSTS70011` errors because `.default` represents pre-consented static permissions, while the others require dynamic user consent at runtime.
>
> ✅ `offline_access` is sometimes accepted with `.default` to enable refresh tokens, but should not be combined with any additional delegated scopes. When in doubt, split the token requests to avoid scope-type conflicts.
 
 
### Preauthorized applications
> [!IMPORTANT]
> While it's valid to use `scope=openid https://resource/.default` in combined consent flows involving [known client applications](reference-app-manifest.md#knownclientapplications-attribute), you must **not** combine `.default` with other delegated scopes like `User.Read`, `Mail.Read`, `profile`, or `User.ReadWrite.All` in the same request. This will result in `AADSTS70011` errors because `.default` represents pre-consented static permissions, while the others require dynamic user consent at runtime.
>
> `offline_access` is sometimes accepted with `.default` to enable refresh tokens, but should not be combined with any additional delegated scopes. When in doubt, split the token requests to avoid scope-type conflicts.
 
 
### Preauthorized applications
+1 / -1 lines changed
Commit: relative link
Changes:
Before
After
| Microsoft Entra registered | Federated/Managed | Windows current | Persistent/Non-persistent | Not Applicable |
 
> [!IMPORTANT]
> When deploying a VDI farm (persistent or non-persistent), customers should take into consideration [Entra device operation throttling limits](https://learn.microsoft.com/graph/throttling-limits#identity-and-access-device-operation-service-limits). Microsoft recommends device registration requests to be staged at the rate of 500 requests per every 2 minutes and 30 seconds interval. Failure to stage such requests can lead to throttling errors resulting in device registration failures and longer delays for device registration to succeed.
 
<sup>3</sup> A **Federated** identity infrastructure environment represents an environment with an identity provider (IdP) such as AD FS or other non-Microsoft IdP. In a federated identity infrastructure environment, computers follow the [federated device registration flow](device-registration-how-it-works.md#microsoft-entra-joined-in-federated-environments) based on the [Microsoft Windows Server Active Directory Service Connection Point (SCP) settings](hybrid-join-manual.md#configure-a-service-connection-point).
 
| Microsoft Entra registered | Federated/Managed | Windows current | Persistent/Non-persistent | Not Applicable |
 
> [!IMPORTANT]
> When deploying a VDI farm (persistent or non-persistent), customers should take into consideration [Entra device operation throttling limits](/graph/throttling-limits#identity-and-access-device-operation-service-limits). Microsoft recommends device registration requests to be staged at the rate of 500 requests per every 2 minutes and 30 seconds interval. Failure to stage such requests can lead to throttling errors resulting in device registration failures and longer delays for device registration to succeed.
 
<sup>3</sup> A **Federated** identity infrastructure environment represents an environment with an identity provider (IdP) such as AD FS or other non-Microsoft IdP. In a federated identity infrastructure environment, computers follow the [federated device registration flow](device-registration-how-it-works.md#microsoft-entra-joined-in-federated-environments) based on the [Microsoft Windows Server Active Directory Service Connection Point (SCP) settings](hybrid-join-manual.md#configure-a-service-connection-point).
 
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
ms.date: 06/27/2024
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer:
ms.custom: sfi-ga-nochange
#Customer intent: As an IT admin, I want to manage the local administrators group assignment during a Microsoft Entra join, so that I can control who can manage Microsoft Entra joined devices
ms.date: 06/27/2024
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer:
ms.custom: sfi-ga-nochange
#Customer intent: As an IT admin, I want to manage the local administrators group assignment during a Microsoft Entra join, so that I can control who can manage Microsoft Entra joined devices
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer: sandeo
---
 
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer: sandeo
---
 
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer: sandeo
---
 
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer: sandeo
---
 
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer: sandeo
---
 
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer: sandeo
---
 
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
ms.date: 03/03/2025
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer:
ms.custom: sfi-image-nochange
---
ms.date: 03/03/2025
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer:
ms.custom: sfi-image-nochange
---
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer: sgrandhi
---
# Security update to remove KDFv1 algorithm support in Microsoft Entra authentication
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer: sgrandhi
---
# Security update to remove KDFv1 algorithm support in Microsoft Entra authentication
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer:
---
# Microsoft Entra join a new Windows device during the out of box experience
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer:
---
# Microsoft Entra join a new Windows device during the out of box experience
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer: sandeo
---
# How to: Plan your Microsoft Entra join implementation
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer: sandeo
---
# How to: Plan your Microsoft Entra join implementation
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
ms.date: 05/29/2024
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer:
ms.custom: sfi-image-nochange
---
ms.date: 05/29/2024
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer:
ms.custom: sfi-image-nochange
---
Modified by Ortagus Winfrey on Jun 9, 2025 8:38 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Device Manager Updates
Changes:
Before
After
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer:
---
# How SSO to on-premises resources works on Microsoft Entra joined devices
 
ms.author: owinfrey
author: owinfreyATL
manager: dougeby
ms.reviewer:
---
# How SSO to on-premises resources works on Microsoft Entra joined devices