πŸ“‹ Microsoft Entra Documentation Changes

Changes for June 18th 2025

Period: June 17th 2025, 12:00 AM to June 18th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 18th 2025.

πŸ“Š Summary

26
Total Commits
0
New Files
19
Modified Files
1
Deleted Files
15
Contributors

πŸ“ Modified Documentation Files

+275 / -273 lines changed
Commit: Update concept-mfa-regional-opt-in.md
Changes:
Before
After
---
title: Telephony Fraud Protections and Throttles
description: Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 05/20/2025
 
author: justinha
ms.author: justinha
manager: femila
ms.reviewer: aloom3
ms.custom: references_regions
---
# Overview
To protect customers from telephony-based abuse and fraud, Microsoft Entra ID applies intelligent detection and throttling mechanisms to all telecom based authentication requests.
 
These protections use a combination of heuristics, machine learning models, and risk-based signals to detect and block potentially abusive or fraudulent telephony activity in real time.
 
---
title: Telephony Fraud Protections and Throttles
description: Microsoft Entra ID uses heuristics and machine learning to detect and throttle suspicious telephony activity during MFA. Some regions require opt-in via support ticket due to elevated fraud risk.
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 05/20/2025
 
author: justinha
ms.author: justinha
manager: femila
ms.reviewer: aloom3
ms.custom: references_regions
---
 
# Overview
 
To protect customers from telephony-based abuse and fraud, Microsoft Entra ID applies intelligent detection and throttling mechanisms to all telecom-based authentication requests.
 
+254 / -203 lines changed
Commit: edit pass: authenticate-application-id
Changes:
Before
After
---
title: 'Authenticate to Microsoft Entra ID using Application Identity'
description: This article describes how to allow the Microsoft Entra Connect application to authenticate with Microsoft Entra ID with modern, more secure credentials.
 
author: billmath
ms.author: billmath
---
 
# Authenticate to Microsoft Entra ID using Application Identity
 
Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Entra ID. This account uses username and password to authenticate requests. To enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Entra or Administrator creates a single tenant third party application in Entra ID and use one of the relevant certificate management options below for the credentials.
 
Microsoft Entra Connect provides three options for application/certificate management:
 
1. [Managed by Microsoft Entra Connect (Recommended)](#managed-by-microsoft-entra-connect-recommended)
2. [Bring Your Own Application (BYOA)](#bring-your-own-application-byoa)
3. [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate-byoc)
 
## Managed by Microsoft Entra Connect (Recommended)
Microsoft Entra Connect manages the application and certificate including creation, rotation, and deletion of the certificate. The certificate is stored in the Current User store. For optimal protection of the certificate’s private key, it's recommended that the machine employs a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary. When a TPM is available, key service operations are performed within a dedicated hardware environment. In contrast, if a TPM can't be used, Entra Connect defaults to storing the certificate in the default Microsoft Software Key Storage Provider and marks the private key as nonexportable for additional protection. However, without the hardware isolation provided by a TPM, the private key is secured solely by software safeguards and doesn't achieve the same level of protection. For more information on TPM, see [Trusted Platform Module Technology Overview](/windows/security/hardware-security/tpm/trusted-platform-module-overview).
---
title: Authenticate to Microsoft Entra ID by Using Application Identity
description: This article describes how to allow the Microsoft Entra Connect application to authenticate with Microsoft Entra ID with modern, more secure credentials.
 
author: billmath
ms.author: billmath
---
 
# Authenticate to Microsoft Entra ID by using application identity
 
Microsoft Entra Connect uses the [Microsoft Entra Connector account](reference-connect-accounts-permissions.md#accounts-used-for-microsoft-entra-connect) to authenticate and sync identities from Active Directory to Microsoft Entra Connect. This account uses a username and password to authenticate requests.
 
To enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Microsoft Entra or Administrator creates a single tenant non-Microsoft application in Microsoft Entra ID and uses one of the following relevant certificate management options for the credentials.
 
Microsoft Entra Connect provides three options for application/certificate management:
 
- [Managed by Microsoft Entra Connect (recommended)](#managed-by-microsoft-entra-connect-recommended)
- [Bring Your Own Application (BYOA)](#bring-your-own-application-byoa)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate-byoc)
 
+10 / -4 lines changed
Commit: updates
Changes:
Before
After
 
When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and upcoming changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, outlines how it currently works, and highlights important changes effective September 30, 2025.
 
## Discovering Requestable Access Packages
 
When a user lands on the "*Available*" tab, searches for requestable packages, or selects "*View all*," Microsoft Entra evaluates which access packages they should be able to see and potentially request. This visibility is determined by a specific sequence of checks.
 
 
:::image type="content" source="media/entitlement-management-access-package-visibility/visibility-diagram.png" alt-text="Screenshot of visibility diagram for access package.":::
 
### Explaining the current visibility flow
 
Let's walk through the decision points in the diagram:
 
> Effective September 30, 2025: The visibility behavior previously described for policies scoped to "Specific users and groups" is
> changing. See the [Upcoming Changes to Visibility](entitlement-management-access-package-visibility.md) section for crucial details and required actions.
 
## Upcoming Changes to visibility
 
Effective September 30 2025, the visibility on the [My Access portal](https://myaccess.microsoft.com) will change for access packages configured with one or more policies where "Who can request access" is set to **"For users in your directory: Specific users and groups.** Access packages configured for "Specific users and groups" will be visible to all members (excluding guests) in the My Access portal. If you don't want the access packages visible to all members, you must hide the access package by this date.
 
When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and upcoming changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, outlines how it currently works, and highlights important changes effective September 30, 2025.
 
## Discovering requestable access packages
 
When a user lands on the "*Available*" tab, searches for requestable packages, or selects "*View all*," Microsoft Entra evaluates which access packages they should be able to see and potentially request. This visibility is determined by a specific sequence of checks.
 
 
:::image type="content" source="media/entitlement-management-access-package-visibility/visibility-diagram.png" alt-text="Screenshot of visibility diagram for access package.":::
 
**Explaining the current visibility flow**
 
Let's walk through the decision points in the diagram:
 
> Effective September 30, 2025: The visibility behavior previously described for policies scoped to "Specific users and groups" is
> changing. See the [Upcoming Changes to Visibility](entitlement-management-access-package-visibility.md) section for crucial details and required actions.
 
## Upcoming changes to visibility
 
Effective September 30 2025, the visibility on the [My Access portal](https://myaccess.microsoft.com) will change for access packages configured with one or more policies where "Who can request access" is set to **"For users in your directory: Specific users and groups.** Access packages configured for "Specific users and groups" will be visible to all members (excluding guests) in the My Access portal. If you don't want the access packages visible to all members, you must hide the access package by this date.
+4 / -4 lines changed
Commit: logs-061625
Changes:
Before
After
ms.service: entra-id
ms.topic: how-to
ms.subservice: monitoring-health
ms.date: 02/26/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg
 
 
The basic steps for configuring diagnostics settings are as follows:
 
1. To create a new diagnostic setting, select **Add diagnostic setting**.
1. Provide a name.
1. Select the logs you want to include.
1. Select the **Save** button.
 
![Screenshot of the create diagnostic settings page, with several logs selected to go to a Log Analytics workspace.](media/howto-configure-diagnostic-settings/diagnostic-settings-save.png)
 
> [!NOTE]
> It might take up to three days for the logs to start appearing in the destination.
ms.service: entra-id
ms.topic: how-to
ms.subservice: monitoring-health
ms.date: 06/16/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg
 
 
The basic steps for configuring diagnostics settings are as follows:
 
> [!NOTE]
> It might take up to three days for the logs to start appearing in the destination.
 
1. To create a new diagnostic setting, select **Add diagnostic setting**.
1. Provide a name.
1. Select the logs you want to include.
1. Select the **Save** button.
 
![Screenshot of the create diagnostic settings page, with several logs selected to go to a Log Analytics workspace.](media/howto-configure-diagnostic-settings/diagnostic-settings-save.png)
Modified by jayrusso on Jun 17, 2025 7:27 AM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: June 16 finalized includes per Sarah's feedback
Changes:
Before
After
author: HULKsmashGithub
ms.service: entra-id
ms.topic: include
ms.date: 06/13/2025
manager: dougeby
ms.custom: Identity-Secure-Recommendation
# category: Access control
# implementationcost: Low
 
---
If you don't enable ID Protection notifications, your organization loses critical real-time alerts when threat actors compromise user accounts or conduct reconnaissance activities. When Microsoft Entra ID Protection detects accounts at risk, it sends email alerts with "Users at risk detected" as the subject and links to the Users flagged for risk report. Without these notifications, security teams remain unaware of active threats, allowing threat actors to maintain persistence in compromised accounts without being detected. You can feed these risks into tools like Conditional Access to make access decisions or send them to a security information and event management (SIEM) tool for investigation and correlation. Threat actors can use this detection gap to conduct lateral movement activities, privilege escalation attempts, or data exfiltration operations while administrators remain unaware of the ongoing compromise. The delayed response enables threat actors to establish more persistence mechanisms, change user permissions, or access sensitive resources before you can fix the issue. Without proactive notification of risk detections, organizations must rely solely on manual monitoring of risk reports, which significantly increases the time it takes to detect and respond to identity-based attacks.
 
**Remediation action**
 
author: HULKsmashGithub
ms.service: entra-id
ms.topic: include
ms.date: 06/16/2025
manager: dougeby
ms.custom: Identity-Secure-Recommendation
# category: Access control
# implementationcost: Low
 
---
If you don't enable ID Protection notifications, your organization loses critical real-time alerts when threat actors compromise user accounts or conduct reconnaissance activities. When Microsoft Entra ID Protection detects accounts at risk, it sends email alerts with **Users at risk detected** as the subject and links to the **Users flagged for risk** report. Without these notifications, security teams remain unaware of active threats, allowing threat actors to maintain persistence in compromised accounts without being detected. You can feed these risks into tools like Conditional Access to make access decisions or send them to a security information and event management (SIEM) tool for investigation and correlation. Threat actors can use this detection gap to conduct lateral movement activities, privilege escalation attempts, or data exfiltration operations while administrators remain unaware of the ongoing compromise. The delayed response enables threat actors to establish more persistence mechanisms, change user permissions, or access sensitive resources before you can fix the issue. Without proactive notification of risk detections, organizations must rely solely on manual monitoring of risk reports, which significantly increases the time it takes to detect and respond to identity-based attacks.
 
**Remediation action**
 
Modified by jayrusso on Jun 17, 2025 7:27 AM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: June 16 finalized includes per Sarah's feedback
Changes:
Before
After
author: HULKsmashGithub
ms.service: entra-id
ms.topic: include
ms.date: 06/13/2025
manager: dougeby
ms.custom: Identity-Secure-Recommendation
# category: Access control
# implementationcost: Low
 
---
Configuring workload identity based on risk policy in Microsoft Entra ID is a critical security measure that ensures only trusted and verified workloads can access sensitive resources. Without these policies, threat actors can compromise workload identities with minimal detection to perform further attacks. The lack of conditional controls for risk detections, such as anomalous activity, allows malicious operations like token forgery, sensitive resource access, and disruption of workloads to proceed unchecked. The lack of automated containment mechanisms increases dwell time and impacts the confidentiality, integrity, and availability of critical services.
 
**Remediation action**
Create a risk-based Conditional Access policy for workload identities.
author: HULKsmashGithub
ms.service: entra-id
ms.topic: include
ms.date: 06/16/2025
manager: dougeby
ms.custom: Identity-Secure-Recommendation
# category: Access control
# implementationcost: Low
 
---
Set up risk-based Conditional Access policies for workload identities based on risk policy in Microsoft Entra ID to make sure only trusted and verified workloads use sensitive resources. Without these policies, threat actors can compromise workload identities with minimal detection and perform further attacks. Without conditional controls to detect anomalous activity and other risks, there's no check against malicious operations like token forgery, access to sensitive resources, and disruption of workloads. The lack of automated containment mechanisms increases dwell time and affects the confidentiality, integrity, and availability of critical services.
 
**Remediation action**
Create a risk-based Conditional Access policy for workload identities.
Modified by Sudhakaran-S-micro on Jun 17, 2025 8:55 PM
πŸ“– View on learn.microsoft.com
+3 / -0 lines changed
Commit: Vault_Provisioning_Attribute change
Changes:
Before
After
|name.givenName|String||✓|
|name.familyName|String||✓|
|emails[type eq "work"].value|String||✓|
 
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
 
 
 
 
|name.givenName|String||✓|
|name.familyName|String||✓|
|emails[type eq "work"].value|String||✓|
|userType|String|||
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String|||
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization|String|||
 
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
 
+1 / -2 lines changed
Commit: Update concept-conditional-access-cloud-apps.md
Changes:
Before
After
ms.custom: has-azure-ad-ps-ref
ms.topic: conceptual
 
ms.date: 10/28/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
- Azure CLI
- Azure Data Factory portal
- Azure DevOps
- Azure Event Hubs
- Azure PowerShell
- Azure Service Bus
ms.custom: has-azure-ad-ps-ref
ms.topic: conceptual
 
ms.date: 06/16/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
- Azure CLI
- Azure Data Factory portal
- Azure Event Hubs
- Azure PowerShell
- Azure Service Bus
 
Modified by csmulligan on Jun 17, 2025 11:12 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Minor update UUF 431875.
Changes:
Before
After
 
If you need to issue the UPN value as an application token claim, the actual claim mapping might behave differently for B2B users. If the B2B user authenticates with an external Microsoft Entra identity and you issue `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN attribute from the home tenant for this user.
 
For all [other external identity types](redemption-experience.md#invitation-redemption-flow), such as SAML/WS-Fed, Google, and Email one-time passcode (OTP) when you use `user.localuserprincipalname` as a claim, the system issues the user's UPN instead of their email address. If you want the actual UPN to be issued in the token claim for all B2B users, set `user.localuserprincipalname` as the source attribute instead.
 
>[!NOTE]
>The behavior mentioned in this section is the same for both cloud-only B2B users and synced users who were [invited/converted to B2B collaboration](invite-internal-users.md).
 
If you need to issue the UPN value as an application token claim, the actual claim mapping might behave differently for B2B users. If the B2B user authenticates with an external Microsoft Entra identity and you issue `user.userprincipalname` as the source attribute, Microsoft Entra ID issues the UPN attribute from the home tenant for this user.
 
For all [other external identity types](redemption-experience.md#invitation-redemption-flow), such as SAML/WS-Fed, Google, and Email one-time passcode (OTP) when you use `user.userprincipalname` as a claim, the system issues the user's UPN instead of their email address. If you want the actual UPN to be issued in the token claim for all B2B users, set `user.localuserprincipalname` as the source attribute instead.
 
>[!NOTE]
>The behavior mentioned in this section is the same for both cloud-only B2B users and synced users who were [invited/converted to B2B collaboration](invite-internal-users.md).
+1 / -1 lines changed
Commit: logs-manager-update
Changes:
Before
After
description: Learn how to interpret the details found in the Microsoft Entra audit and sign-in and logs schema.
 
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
description: Learn how to interpret the details found in the Microsoft Entra audit and sign-in and logs schema.
 
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
+1 / -1 lines changed
Commit: logs-manager-update
Changes:
Before
After
title: Logs available for streaming from Microsoft Entra ID
description: Learn about the Microsoft Entra logs available for streaming to an endpoint for storage, analysis, or monitoring.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
title: Logs available for streaming from Microsoft Entra ID
description: Learn about the Microsoft Entra logs available for streaming to an endpoint for storage, analysis, or monitoring.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
+1 / -1 lines changed
Commit: logs-manager-update
Changes:
Before
After
title: Microsoft Entra activity log integration options
description: Introduction to the options and considerations for integrating Microsoft Entra activity logs with storage and analysis tools.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
title: Microsoft Entra activity log integration options
description: Introduction to the options and considerations for integrating Microsoft Entra activity logs with storage and analysis tools.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
+1 / -1 lines changed
Commit: logs-manager-update
Changes:
Before
After
title: Learn about Microsoft Entra Health monitoring
description: Monitor the health of your tenant through several identity scenarios and authentication availability rates with Microsoft Entra Health
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
title: Learn about Microsoft Entra Health monitoring
description: Monitor the health of your tenant through several identity scenarios and authentication availability rates with Microsoft Entra Health
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
+1 / -1 lines changed
Commit: logs-manager-update
Changes:
Before
After
title: Service principal sign-in logs
description: Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
title: Service principal sign-in logs
description: Learn about the activity captured in the service principal sign-in logs in Microsoft Entra monitoring and health.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
Modified by shlipsey3 on Jun 17, 2025 9:32 AM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: logs-manager-update
Changes:
Before
After
title: Sign-in logs in Microsoft Entra ID
description: Learn about the different types of sign-in logs that are available in Microsoft Entra monitoring and health.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
title: Sign-in logs in Microsoft Entra ID
description: Learn about the different types of sign-in logs that are available in Microsoft Entra monitoring and health.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health

πŸ—‘οΈ Deleted Documentation Files

DELETED docs/identity/saas-apps/cloudknox-permissions-management-platform-tutorial.md
Deleted by jenniferf-skc on Jun 17, 2025 5:17 AM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/identity/saas-apps/cloudknox-permissions-management-platform-tutorial
-133 lines removed
Commit: Removing CloudKnox configuration article