📋 Microsoft Entra Documentation Changes

Changes for June 16th 2025

Period: June 15th 2025, 12:00 AM to June 16th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 16th 2025.

📊 Summary

2
Total Commits
0
New Files
5
Modified Files
0
Deleted Files
2
Contributors

📝 Modified Documentation Files

+6 / -6 lines changed
Commit: Update how-to-mfa-manage-oath-tokens.md
Changes:
Before
After
>[!NOTE]
>There might be up to a 20-minute delay for the policy propagation. Allow an hour for the policy to update before users can sign in with their hardware OATH token and see it in their [Security info](https://mysignins.microsoft.com/security-info).
 
Let's look at an example where an Authentication Policy Administrator creates a token and assigns it to a user. You can allow assignment without activation.
 
For the body of the POST in this example, you can find the **serialNumber** from your device and the **secretKey** is delivered to you.
 
 
 
 
This example creates a single token:
 
```https
POST https://graph.microsoft.com/beta/directory/authenticationMethodDevices/hardwareOathDevices
 
## Scenario: Admin creates and assigns a hardware OATH token that a user activates
 
In this scenario, an Authentication Policy Administrator creates and assigns a token, and then a user can activate it on their Security info page, or by using Microsoft Graph Explorer. When you assign a token, you can share steps for the user to sign in to [Security info](https://aka.ms/mysecurityinfo) to activate their token. They can choose **Add sign-in method** > **Hardware token**. They need to provide the hardware token serial number, which is typically on the back of the device.
 
 
>[!NOTE]
>There might be up to a 20-minute delay for the policy propagation. Allow an hour for the policy to update before users can sign in with their hardware OATH token and see it in their [Security info](https://mysignins.microsoft.com/security-info).
 
Let's look at an example where an Global Administrator creates a token and assigns it to a user. You can allow assignment without activation.
 
For the body of the POST in this example, you can find the **serialNumber** from your device and the **secretKey** is delivered to you.
 
 
 
 
This example Authentication Policy Administrator creates a single token:
 
```https
POST https://graph.microsoft.com/beta/directory/authenticationMethodDevices/hardwareOathDevices
 
## Scenario: Admin creates and assigns a hardware OATH token that a user activates
 
In this scenario, a Global Administrator creates and assigns a token, and then a user can activate it on their Security info page, or by using Microsoft Graph Explorer. When you assign a token, you can share steps for the user to sign in to [Security info](https://aka.ms/mysecurityinfo) to activate their token. They can choose **Add sign-in method** > **Hardware token**. They need to provide the hardware token serial number, which is typically on the back of the device.
 
 
Modified by OpenPublishing.Build on Jun 15, 2025 4:12 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: update
Changes:
Before
After
[Migration and testing tools](/azure/active-directory/manage-apps/migrate-adfs-plan-migration-test) include the [Microsoft Entra apps migration toolkit](/azure/active-directory/manage-apps/migration-resources) to discover, classify, and migrate apps. Reference the list of [SaaS app tutorials](/azure/active-directory/saas-apps/tutorial-list) and the [Microsoft Entra Single Sign-on (SSO) deployment plan](/azure/active-directory/manage-apps/plan-sso-deployment) that walk through the end-to-end process.
Learn about [Microsoft Entra application proxy](/azure/active-directory/app-proxy/application-proxy) and use the complete [Microsoft Entra application proxy deployment plan](https://aka.ms/AppProxyDPDownload). Consider [secure hybrid access (SHA)](/azure/active-directory/manage-apps/secure-hybrid-access) to protect your on-premises and cloud legacy authentication applications by connecting them to Microsoft Entra ID. Use [Microsoft Entra Connect](/azure/active-directory/hybrid/connect/whatis-azure-ad-connect-v2) to synchronize AD FS users and groups with Microsoft Entra ID.
### Phase 4: Plan management and insights
[Migration and testing tools](/azure/active-directory/manage-apps/migrate-adfs-plan-migration-test) include the [Microsoft Entra apps migration toolkit](/azure/active-directory/manage-apps/migration-resources) to discover, classify, and migrate apps. Reference the list of [SaaS app tutorials](/azure/active-directory/saas-apps/tutorial-list) and the [Microsoft Entra Single Sign-on (SSO) deployment plan](/azure/active-directory/manage-apps/plan-sso-deployment) that walk through the end-to-end process.
Learn about [Microsoft Entra application proxy](/entra/identity/app-proxy/) and use the complete [Microsoft Entra application proxy deployment plan](https://aka.ms/AppProxyDPDownload). Consider [secure hybrid access (SHA)](/azure/active-directory/manage-apps/secure-hybrid-access) to protect your on-premises and cloud legacy authentication applications by connecting them to Microsoft Entra ID. Use [Microsoft Entra Connect](/azure/active-directory/hybrid/connect/whatis-azure-ad-connect-v2) to synchronize AD FS users and groups with Microsoft Entra ID.
### Phase 4: Plan management and insights
Modified by OpenPublishing.Build on Jun 15, 2025 4:12 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: update
Changes:
Before
After
 
Per-App Access is configured by creating a new Global Secure Access app. You create the app, select a connector group, and add network access segments. These settings make up the individual app that you can assign users and groups to.
 
To configure Per-App Access, you need to have a connector group with at least one active [Microsoft Entra application proxy](/azure/active-directory/app-proxy/application-proxy) connector. This connector group handles the traffic to this new application. With Connectors, you can isolate apps per network and connector.
 
To summarize, the overall process is as follows:
 
 
Per-App Access is configured by creating a new Global Secure Access app. You create the app, select a connector group, and add network access segments. These settings make up the individual app that you can assign users and groups to.
 
To configure Per-App Access, you need to have a connector group with at least one active [Microsoft Entra application proxy](/entra/identity/app-proxy/) connector. This connector group handles the traffic to this new application. With Connectors, you can isolate apps per network and connector.
 
To summarize, the overall process is as follows:
 
Modified by OpenPublishing.Build on Jun 15, 2025 4:12 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: update
Changes:
Before
After
 
Configuring your Quick Access settings is a major component to utilizing Microsoft Entra Private Access. When you configure Quick Access for the first time, Private Access creates a new enterprise application. The properties of this new app are automatically configured to work with Private Access.
 
To configure Quick Access, you need to have a connector group with at least one active [Microsoft Entra application proxy](/azure/active-directory/app-proxy/application-proxy) connector. The connector group handles the traffic to this new application. Once you have Quick Access and a private network connector group configured, you need to grant access to the app.
 
To summarize, the overall process is as follows:
 
 
Configuring your Quick Access settings is a major component to utilizing Microsoft Entra Private Access. When you configure Quick Access for the first time, Private Access creates a new enterprise application. The properties of this new app are automatically configured to work with Private Access.
 
To configure Quick Access, you need to have a connector group with at least one active [Microsoft Entra application proxy](/entra/identity/app-proxy/) connector. The connector group handles the traffic to this new application. Once you have Quick Access and a private network connector group configured, you need to grant access to the app.
 
To summarize, the overall process is as follows:
 
Modified by OpenPublishing.Build on Jun 15, 2025 4:12 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: update
Changes:
Before
After
1. On the Add an Action pane, select **HTTP**.
 
1. On the **HTTP** pane under Parameters, enter the following parameters:
- URI: https://graph.microsoft.com/v1.0@{triggerBody()?['CallbackUriPath']}
- Method: POST
- Authentication Type: Managed identity
- Managed Identity: System-assigned managed identity
1. On the Add an Action pane, select **HTTP**.
 
1. On the **HTTP** pane under Parameters, enter the following parameters:
- URI: `https://graph.microsoft.com/v1.0@{triggerBody()?['CallbackUriPath']}`
- Method: POST
- Authentication Type: Managed identity
- Managed Identity: System-assigned managed identity