📋 Microsoft Entra Documentation Changes

Changes for June 13th 2025

Period: June 12th 2025, 12:00 AM to June 13th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 13th 2025.

📊 Summary

32
Total Commits
0
New Files
12
Modified Files
0
Deleted Files
12
Contributors

📝 Modified Documentation Files

+36 / -24 lines changed
Commit: [Conditional Access] Audience Preview addition
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: troubleshooting
ms.date: 06/06/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
ms.reviewer: kvenkit
ms.custom: sfi-image-nochange
---
# Troubleshooting sign-in problems with Conditional Access
 
Use this article to troubleshoot unexpected sign-in outcomes related to Conditional Access using error messages and Microsoft Entra sign-in logs.
 
## Select "all" consequences
 
The Conditional Access framework provides great configuration flexibility. However, great flexibility also means that you should carefully review each configuration policy before releasing it to avoid undesirable results. In this context, pay special attention to assignments affecting complete sets such as **all users / groups / cloud apps**.
 
Organizations should avoid the following configurations:
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: troubleshooting
ms.date: 06/11/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
ms.reviewer: kvenkit
ms.custom: sfi-image-nochange
---
# Troubleshoot sign-in problems with Conditional Access
 
Use this article to fix unexpected sign-in outcomes related to Conditional Access by checking error messages and Microsoft Entra sign-in logs.
 
## Select "all" consequences
 
The Conditional Access framework gives you a lot of configuration flexibility. But this flexibility means you need to carefully review each configuration policy before releasing it to avoid unwanted results. In this context, pay special attention to assignments that affect complete sets like **all users / groups / cloud apps**.
 
Don't use the following configurations:
 
Modified by John Flores on Jun 12, 2025 6:40 AM
📖 View on learn.microsoft.com
+13 / -13 lines changed
Commit: [Conditional Access] Audience Preview addition
Changes:
Before
After
---
title: Conditional Access service dependencies
description: Learn how conditions are used in Microsoft Entra Conditional Access to trigger a policy.
 
ms.service: entra-id
manager: femila
ms.reviewer: calebb
---
# What are service dependencies in Microsoft Entra Conditional Access?
 
With Conditional Access policies, you can specify access requirements to websites and services. For example, your access requirements can include requiring multifactor authentication (MFA) or [managed devices](./concept-conditional-access-grant.md).
 
When you access a site or service directly, the impact of a related policy is typically easy to assess. For example, if you have a policy that requires multifactor authentication (MFA) for SharePoint Online configured, MFA is enforced for each sign-in to the SharePoint web portal. However, it isn't always straight-forward to assess the impact of a policy because there are cloud apps with dependencies to other cloud apps. For example, Microsoft Teams can provide access to resources in SharePoint Online. So, when you access Microsoft Teams in our current scenario, you're also subject to the SharePoint MFA policy.
 
> [!TIP]
> Using the [Office 365](concept-conditional-access-cloud-apps.md#office-365) app will target all Office apps to avoid issues with service dependencies in the Office stack.
 
<!-- docutune:ignore "Windows Azure Active Directory" -->
 
 
---
title: Conditional Access service dependencies
description: Learn how conditions are used in Microsoft Entra Conditional Access to trigger a policy.
 
ms.service: entra-id
manager: femila
ms.reviewer: calebb
---
# Service dependencies in Microsoft Entra Conditional Access
 
With Conditional Access policies, you specify requirements to use websites and services. For example, your requirements can include requiring multifactor authentication (MFA) or [managed devices](./concept-conditional-access-grant.md).
 
When you use a site or service directly, it's usually easy to see how a related policy affects you. For example, if you set a policy that requires multifactor authentication (MFA) for SharePoint Online, MFA is required for each sign-in to the SharePoint web portal. But sometimes it's hard to know how a policy affects you because some cloud apps depend on other cloud apps. For example, Microsoft Teams lets you use resources in SharePoint Online. So, when you use Microsoft Teams in this scenario, you're also subject to the SharePoint MFA policy.
 
> [!TIP]
> Use the [Office 365](concept-conditional-access-cloud-apps.md#office-365) app to target all Office apps and avoid issues with service dependencies in the Office stack.
 
<!-- docutune:ignore "Windows Azure Active Directory" -->
 
 
Modified by Michele Martin on Jun 12, 2025 7:21 AM
📖 View on learn.microsoft.com
+7 / -16 lines changed
Commit: update content
Changes:
Before
After
ms.subservice: external
ms.topic: concept-article
ms.date: 06/09/2025
ms.custom: it-pro
---
 
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
Microsoft Entra External ID external tenants include several baseline security features to help immediately secure customer data. Default settings provide initial protection against threats like brute force attacks and network layer attacks. These protections serve as a starting point as you develop your own identity security plan and add Microsoft Entra premium security features.
 
## Built-in security controls
 
 
|Feature Name |Description |
|--------------|-------------|
|Brute force protection | Mitigates brute force attacks by limiting the number of login attempts to prevent unauthorized access through repeated password guessing. |
|Common networking HTTP Protection | Provides protection against common network-layer attacks and timing-based attacks, protecting against attempts to overwhelm your service with excessive requests.|
|Account Protection | Ensures accounts are protected from unauthorized access to safeguard user data and prevent account compromise. |
ms.subservice: external
ms.topic: concept-article
ms.date: 06/11/2025
ms.custom: it-pro
---
 
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
Microsoft Entra External ID provides baseline security features for external tenants, offering immediate protection against threats like brute force and network layer attacks. These default settings serve as a foundation for developing your own identity security plan. From this starting point, you can implement real-time and offline protection through Microsoft Entra premium security features.
 
## Built-in security controls
 
 
|Feature Name |Description |
|--------------|-------------|
|Brute force protection | Mitigates brute force attacks by limiting the number of sign-in attempts to prevent unauthorized access through repeated password guessing. |
|Common networking HTTP Protection | Provides protection against common network-layer attacks and timing-based attacks, protecting against attempts to overwhelm your service with excessive requests.|
|Account Protection | Guards against unauthorized account access to protect user data and prevent account breaches. |
Modified by Ortagus Winfrey on Jun 12, 2025 10:15 AM
📖 View on learn.microsoft.com
+10 / -10 lines changed
Commit: Licensing Acrolinx and Metadata update
Changes:
Before
After
---
title: 'Microsoft Entra ID Governance licensing fundamentals'
description: This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
author: billmath
manager: dougeby
ms.service: entra-id-governance
ms.topic: conceptual
ms.date: 04/09/2025
ms.author: billmath
---
 
# Microsoft Entra ID Governance licensing fundamentals
- **Microsoft Entra Suite** - Microsoft Entra Suite is a complete cloud-based solution for workforce access, available for Microsoft Entra ID P1 and P2 customers. Microsoft Entra Suite brings together **Microsoft Entra Private Access**, **Microsoft Entra Internet Access**, **Microsoft Entra ID Governance**, **Microsoft Entra ID Protection**, and **Microsoft Entra Verified ID**. The Microsoft Entra ID Governance portion provides the same identity governance capabilities as the **Microsoft Entra ID Governance** product. The difference is that they have different prerequisites.
 
>[!NOTE]
>Some Microsoft Entra ID Governance scenarios can be configured to depend upon other features that aren't covered by Microsoft Entra ID Governance. These features might have additional licensing requirements. See the [Identity Governance overview](identity-governance-overview.md) for more information on governance scenarios that rely on additional features.
 
The Microsoft Entra ID Governance for Government and Microsoft Entra ID Governance Add-on for Microsoft Entra ID P2 for Government products are available in the US Government community cloud (GCC), GCC-High, and Department of Defense cloud environments.
 
The [product names and service plan identifiers for licensing](../identity/users/licensing-service-plan-reference.md) lists additional products that include the prerequisite service plans.
---
title: 'Microsoft Entra ID Governance licensing fundamentals'
description: This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
author: owinfreyATL
manager: dougeby
ms.service: entra-id-governance
ms.topic: conceptual
ms.date: 06/11/2025
ms.author: owinfrey
---
 
# Microsoft Entra ID Governance licensing fundamentals
- **Microsoft Entra Suite** - Microsoft Entra Suite is a complete cloud-based solution for workforce access, available for Microsoft Entra ID P1 and P2 customers. Microsoft Entra Suite brings together **Microsoft Entra Private Access**, **Microsoft Entra Internet Access**, **Microsoft Entra ID Governance**, **Microsoft Entra ID Protection**, and **Microsoft Entra Verified ID**. The Microsoft Entra ID Governance portion provides the same identity governance capabilities as the **Microsoft Entra ID Governance** product. The difference is that they have different prerequisites.
 
>[!NOTE]
>Some Microsoft Entra ID Governance scenarios can be configured to depend upon other features that aren't covered by Microsoft Entra ID Governance. These features might have additional licensing requirements. For more information on governance scenarios using other features, see the [Identity Governance overview](identity-governance-overview.md) page.
 
The Microsoft Entra ID Governance for Government and Microsoft Entra ID Governance Add-on for Microsoft Entra ID P2 for Government products are available in the US Government community cloud (GCC), GCC-High, and Department of Defense cloud environments.
 
The [product names and service plan identifiers for licensing](../identity/users/licensing-service-plan-reference.md) lists additional products that include the prerequisite service plans.
Modified by Michele Martin on Jun 12, 2025 2:23 AM
📖 View on learn.microsoft.com
+3 / -16 lines changed
Commit: B2C section edits
Changes:
Before
After
ms.subservice: external
ms.topic: overview
ms.date: 03/12/2025
ms.custom: it-pro, seo-july-2024
 
#Customer intent: As a dev, devops, or it admin, I want to learn about identity solutions for apps for consumers and business customers.
> [![Try it now](./media/common/try-it-now.png)](https://woodgrovedemo.com/#usecase=CA)
>
> To try out this feature, go to the Woodgrove Groceries demo and start the “Conditional Access and multifactor authentication” use case.
 
### Multifactor authentication (MFA)
 
Microsoft Entra MFA helps safeguard access to data and applications while maintaining simplicity for your users. Microsoft Entra External ID integrates directly with Microsoft Entra MFA so you can add security to your sign-up and sign-in experiences by requiring a second form of authentication. You can fine-tune MFA depending on the extent of security you want to apply to your apps. Consider the following scenarios:
 
Learn more about [MFA in external tenants](concept-multifactor-authentication-customers.md) or see [how to enable multifactor authentication](how-to-multifactor-authentication-customers.md).
 
### Identity protection
 
Microsoft Entra [Identity Protection](~/id-protection/overview-identity-protection.md) provides ongoing risk detection for your external tenant. It allows you to discover, investigate, and remediate identity-based risks. Identity Protection allows organizations to accomplish three key tasks:
ms.subservice: external
ms.topic: overview
ms.date: 06/11/2025
ms.custom: it-pro, seo-july-2024
 
#Customer intent: As a dev, devops, or it admin, I want to learn about identity solutions for apps for consumers and business customers.
> [![Try it now](./media/common/try-it-now.png)](https://woodgrovedemo.com/#usecase=CA)
>
> To try out this feature, go to the Woodgrove Groceries demo and start the “Conditional Access and multifactor authentication” use case.
### Multifactor authentication (MFA)
 
Microsoft Entra MFA helps safeguard access to data and applications while maintaining simplicity for your users. Microsoft Entra External ID integrates directly with Microsoft Entra MFA so you can add security to your sign-up and sign-in experiences by requiring a second form of authentication. You can fine-tune MFA depending on the extent of security you want to apply to your apps. Consider the following scenarios:
 
Learn more about [MFA in external tenants](concept-multifactor-authentication-customers.md) or see [how to enable multifactor authentication](how-to-multifactor-authentication-customers.md).
 
### Microsoft Entra reliability and scalability
 
Create highly customized sign-in experiences and manage customer accounts at a large scale. Ensure a good customer experience by taking advantage of Microsoft Entra performance, resiliency, business continuity, low-latency, and high throughput.
 
+6 / -6 lines changed
Commit: Fixes
Changes:
Before
After
---
title: Microsoft Entra ID Governance Licensing for Guest Users
description: Learn how Microsoft Entra ID is licensed for guest users.
author: owinfreyatl
manager: dougeby
ms.reviewer: jercon
---
 
# Microsoft Entra ID Governance Licensing for Guest Users
 
This article outlines the pricing structure for Microsoft Entra Governance ID for guests add-on and describes how to link your tenant to an Azure subscription to ensure correct billing and feature access.
 
## Monthly active users (MAU) billing model
 
 
You can identify actions that will be billed to the Microsoft Entra ID Governance for guests add-on by looking at your audit logs. Specifically, each billable action has these properties included:
 
1. TargetId: object ID of the target user
 
1. TargetUserType: Guest
---
title: Microsoft Entra ID Governance licensing for guest users
description: Learn how Microsoft Entra ID is licensed for guest users.
author: owinfreyatl
manager: dougeby
ms.reviewer: jercon
---
 
# Microsoft Entra ID Governance licensing for guest users
 
This article outlines the pricing structure for Microsoft Entra ID Governance for guests add-on and describes how to link your tenant to an Azure subscription to ensure correct billing and feature access.
 
## Monthly active users (MAU) billing model
 
 
You can identify actions that will be billed to the Microsoft Entra ID Governance for guests add-on by looking at your audit logs. Specifically, each billable action has these properties included:
 
- TargetId: object ID of the target user
 
- TargetUserType: Guest
Modified by Ortagus Winfrey on Jun 12, 2025 1:55 AM
📖 View on learn.microsoft.com
+4 / -2 lines changed
Commit: new location for note
Changes:
Before
After
- To review Azure resource or Microsoft Entra roles, see [Create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management](privileged-identity-management/pim-create-roles-and-resource-roles-review.md).
- For reviews of PIM for Groups, see [create an access review of PIM for Groups](create-access-review-pim-for-groups.md).
 
> [!NOTE]
> Groups and users in a restricted management administrative unit can't be managed with Microsoft Entra ID Governance features such as [Access reviews](access-reviews-overview.md).
 
## Prerequisites
 
> [!NOTE]
> Once the access review is initiated, you can use the [contactedReviewers](/graph/api/accessreviewinstance-list-contactedreviewers) API call to see the list of all reviewers notified, or who would be if notifications are turned off, via email for an access review. Time stamps for when these users were notified are also provided.
 
## Next steps
 
- [Complete an access review of groups or applications](complete-access-review.md)
 
 
- To review Azure resource or Microsoft Entra roles, see [Create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management](privileged-identity-management/pim-create-roles-and-resource-roles-review.md).
- For reviews of PIM for Groups, see [create an access review of PIM for Groups](create-access-review-pim-for-groups.md).
 
 
 
## Prerequisites
 
> [!NOTE]
> Once the access review is initiated, you can use the [contactedReviewers](/graph/api/accessreviewinstance-list-contactedreviewers) API call to see the list of all reviewers notified, or who would be if notifications are turned off, via email for an access review. Time stamps for when these users were notified are also provided.
 
> [!NOTE]
> Groups and users in a restricted management administrative unit can't be managed with Microsoft Entra ID Governance features such as [Access reviews](access-reviews-overview.md).
 
## Next steps
 
- [Complete an access review of groups or applications](complete-access-review.md)
+1 / -4 lines changed
Commit: [Conditional Access] First party apps in picker
Changes:
Before
After
 
Administrators can assign a Conditional Access policy to cloud apps from Microsoft as long as the service principal appears in their tenant. Some apps like [Office 365](#office-365) and [Windows Azure Service Management API](#windows-azure-service-management-api) include multiple related child apps or services. When new supported Microsoft cloud applications are created, they appear in the app picker list.
 
> [!IMPORTANT]
> Applications that are available to Conditional Access have gone through an onboarding and validation process. This list doesn't include some backend services not meant to have policy directly applied to them. If you're looking for an application that is missing, you can contact the specific application team or make a request on [UserVoice](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789).
 
### Office 365
 
Microsoft 365 provides cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration can cause confusion when creating policies as some apps such as Microsoft Teams have dependencies on others such as SharePoint or Exchange.
> [!NOTE]
> Since Conditional Access policy sets the requirements for accessing a service, you aren't able to apply it to a client (public/native) application. In other words, the policy isn't set directly on a client (public/native) application, but is applied when a client calls a service. For example, a policy set on SharePoint service applies to all clients calling SharePoint. A policy set on Exchange applies to the attempt to access the email using Outlook client. That is why client (public/native) applications aren't available for selection in the app picker and Conditional Access option isn't available in the application settings for the client (public/native) application registered in your tenant.
 
Some applications don't appear in the picker at all. The only way to include these applications in a Conditional Access policy is to include **All resources (formerly 'All cloud apps')**.
 
#### Understanding Conditional Access for different client types
 
 
Administrators can assign a Conditional Access policy to cloud apps from Microsoft as long as the service principal appears in their tenant. Some apps like [Office 365](#office-365) and [Windows Azure Service Management API](#windows-azure-service-management-api) include multiple related child apps or services. When new supported Microsoft cloud applications are created, they appear in the app picker list.
 
### Office 365
 
Microsoft 365 provides cloud-based productivity and collaboration services like Exchange, SharePoint, and Microsoft Teams. Microsoft 365 cloud services are deeply integrated to ensure smooth and collaborative experiences. This integration can cause confusion when creating policies as some apps such as Microsoft Teams have dependencies on others such as SharePoint or Exchange.
> [!NOTE]
> Since Conditional Access policy sets the requirements for accessing a service, you aren't able to apply it to a client (public/native) application. In other words, the policy isn't set directly on a client (public/native) application, but is applied when a client calls a service. For example, a policy set on SharePoint service applies to all clients calling SharePoint. A policy set on Exchange applies to the attempt to access the email using Outlook client. That is why client (public/native) applications aren't available for selection in the app picker and Conditional Access option isn't available in the application settings for the client (public/native) application registered in your tenant.
 
Some applications don't appear in the picker at all. The only way to include these applications in a Conditional Access policy is to include **All resources (formerly 'All cloud apps')** or add the missing service principal using the [New-MgServicePrincipal](/powershell/module/microsoft.graph.applications/new-mgserviceprincipal) PowerShell cmdlet.
 
#### Understanding Conditional Access for different client types
 
 
 
 
+3 / -1 lines changed
Commit: ca-061126
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 04/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
This article shows an example of how to migrate a classic policy that requires **Multifactor authentication** for a cloud app.
 
> [!TIP]
> As of the August 2023 Intune service release (2308), classic Conditional Access policies are no longer created for the [Microsoft Defender for Endpoint connector](/mem/intune/protect/advanced-threat-protection-configure#connect-microsoft-defender-for-endpoint-to-intune). If your tenant has a classic Conditional Access policy that was previously created for integration with Microsoft Defender for Endpoint, it can be deleted.
 
![Classic policy details requiring MFA for Salesforce app](./media/policy-migration/33.png)
 
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 06/11/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
This article shows an example of how to migrate a classic policy that requires **Multifactor authentication** for a cloud app.
 
> [!TIP]
> The Outlook Web App doesn't enforce Classic Conditional Access policies. Microsoft recommends migrating to [Modern Conditional Access](concept-conditional-access-policy-common.md).
>
> As of the August 2023 Intune service release (2308), classic Conditional Access policies are no longer created for the [Microsoft Defender for Endpoint connector](/mem/intune/protect/advanced-threat-protection-configure#connect-microsoft-defender-for-endpoint-to-intune). If your tenant has a classic Conditional Access policy that was previously created for integration with Microsoft Defender for Endpoint, it can be deleted.
 
![Classic policy details requiring MFA for Salesforce app](./media/policy-migration/33.png)
Modified by Ortagus Winfrey on Jun 12, 2025 6:19 AM
📖 View on learn.microsoft.com
+3 / -0 lines changed
Commit: CIS hardened images in Microsoft Entra ID
Changes:
Before
After
- Azure Government
- Microsoft Azure operated by 21Vianet
 
### Network requirements
 
To enable Microsoft Entra authentication for your Windows VMs in Azure, you need to ensure that your VM's network configuration permits outbound access to the following endpoints over TCP port 443.
 
 
 
- Azure Government
- Microsoft Azure operated by 21Vianet
 
> [!NOTE]
> CIS hardened images support Microsoft Entra ID authentication for Microsoft Windows Enterprise and Microsoft Windows Server offerings. For more information, see: [CIS Hardened Images on Microsoft Windows Enterprise](https://azuremarketplace.microsoft.com/marketplace/apps/center-for-internet-security-inc.cis-windows-server).
 
### Network requirements
 
To enable Microsoft Entra authentication for your Windows VMs in Azure, you need to ensure that your VM's network configuration permits outbound access to the following endpoints over TCP port 443.
Modified by Barclay Neira on Jun 12, 2025 6:06 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/includes/secure-recommendations/21788.md
Changes:
Before
After
# userimpact: Low
# implementationcost: Medium
---
Global Administrators with standing access to Azure subscriptions create an expanded attack surface for threat actors. If a Global Administrator account is compromised, attackers can immediately enumerate resources, modify configurations, assign roles, and exfiltrate sensitive data across all subscriptions. Requiring explicit elevation for subscription access introduces detectable signals, reduces attacker velocity, and forces high-impact operations through observable control points.
 
**Remediation action**
 
# userimpact: Low
# implementationcost: Medium
---
Global Administrators with persistent access to Azure subscriptions expand the attack surface for threat actors. If a Global Administrator account is compromised, attackers can immediately enumerate resources, modify configurations, assign roles, and exfiltrate sensitive data across all subscriptions. Requiring just-in-time elevation for subscription access introduces detectable signals, slows attacker velocity, and routes high-impact operations through observable control points.
 
**Remediation action**
 
Modified by Barclay Neira on Jun 12, 2025 6:06 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/includes/secure-recommendations/21888.md
Changes:
Before
After
# userimpact: Low
# implementationcost: Low
---
Unmaintained or orphaned redirect URIs in app registrations create significant security vulnerabilities when they reference domains that no longer point to active resources. Threat actors can exploit these "dangling" DNS entries by provisioning resources at abandoned domains, effectively taking control of redirect endpoints. This enables attackers to intercept authentication tokens and credentials during OAuth 2.0 flows, leading to unauthorized access, session hijacking, and potential broader organizational compromise.
 
**Remediation action**
 
# userimpact: Low
# implementationcost: Low
---
Unmaintained or orphaned redirect URIs in app registrations create significant security vulnerabilities when they reference domains that no longer point to active resources. Threat actors can exploit these "dangling" DNS entries by provisioning resources at abandoned domains, effectively taking control of redirect endpoints. This vulnerability enables attackers to intercept authentication tokens and credentials during OAuth 2.0 flows, which can lead to unauthorized access, session hijacking, and potential broader organizational compromise.
 
**Remediation action**