πŸ“‹ Microsoft Entra Documentation Changes

Changes for June 20th 2025

Period: June 19th 2025, 12:00 AM to June 20th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 20th 2025.

πŸ“Š Summary

68
Total Commits
0
New Files
49
Modified Files
0
Deleted Files
20
Contributors

πŸ“ Modified Documentation Files

+76 / -85 lines changed
Commit: edit pass: authenticate-application-id
Changes:
Before
After
---
title: 'Group writeback for Microsoft 365 groups'
description: This article describes how to enable group writeback in Microsoft Entra Connect by using PowerShell and a wizard.
 
author: billmath
 
[!INCLUDE [deprecation](~/includes/gwb-v2-deprecation.md)]
 
Group writeback is a feature that allows you to write cloud groups back to your on-premises Active Directory instance by using Microsoft Entra Connect Sync. Group writeback V2 using Microsoft Entra Connect has been deprecated. Group writeback V1 using Microsoft Entra Connect still functions and should be used if you are synchronizing Microsoft 365 groups. This version of group writeback is being replaced with [Microsoft Entra Connect Cloud Sync group provisioning to Active Directory](../group-writeback-cloud-sync.md). However, the V1 functionality will continue to work until Microsoft Entra Connect cloud sync supports synchronizing Microsoft 365 groups.
 
This article provides information and walks you through enabling group writeback V1.
 
>[!IMPORTANT]
>This article describes how to enable group writeback V1 with Microsoft Entra Connect Sync. It should only be used by customers who provision Microsoft 365 groups to Active Directory.
 
## Prerequisites and information
The following prerequisites must be met in order to enable group writeback.
- Azure Active Directory Premium licenses for your tenant.
- A configured hybrid deployment between your Exchange on-premises organization and Microsoft 365 and verified it's functioning correctly.
---
title: Group Writeback for Microsoft 365 Groups
description: This article describes how to enable group writeback in Microsoft Entra Connect by using PowerShell and a wizard.
 
author: billmath
 
[!INCLUDE [deprecation](~/includes/gwb-v2-deprecation.md)]
 
Group writeback is a feature that you can use to write cloud groups back to your on-premises Active Directory instance by using Microsoft Entra Connect Sync. Group writeback V2 using Microsoft Entra Connect was deprecated. Group writeback V1 using Microsoft Entra Connect still functions, and you should use it if you're synchronizing Microsoft 365 groups. This version of group writeback is being replaced with [Microsoft Entra Cloud Sync group provisioning to Active Directory](../group-writeback-cloud-sync.md). The V1 functionality continues to work until Microsoft Entra Cloud Sync supports synchronizing Microsoft 365 groups.
 
This article provides information and walks you through how to enable group writeback V1.
 
> [!IMPORTANT]
> This article describes how to enable group writeback V1 with Microsoft Entra Connect Sync. Only customers who provision Microsoft 365 groups to Active Directory should use it.
 
## Prerequisites and information
 
To enable group writeback, you must have:
 
- Azure Active Directory Premium licenses for your tenant.
Modified by Ortagus Winfrey on Jun 19, 2025 4:10 AM
πŸ“– View on learn.microsoft.com
+148 / -0 lines changed
Commit: December 2024 added to archive
Changes:
Before
After
 
---
 
## November 2024
 
### Public Preview - Universal Continuous Access Evaluation
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
---
 
## December 2024
 
### General Availability - What's new in Microsoft Entra
 
**Type:** New feature
**Service category:** Reporting
**Product capability:** Monitoring & Reporting
 
What's new in Microsoft Entra offers a comprehensive view of Microsoft Entra product updates including product roadmap (like Public Previews and recent GAs), and change announcements (like deprecations, breaking changes, feature changes and Microsoft-managed policies). It's a one stop shop for Microsoft Entra admins to discover the product updates.
 
---
 
### Public Preview - Microsoft Entra ID Governance: Approvers can revoke access in MyAccess
 
**Type:** New feature
**Service category:** Entitlement Management
**Product capability:** Entitlement Management
Modified by Ortagus Winfrey on Jun 19, 2025 4:10 AM
πŸ“– View on learn.microsoft.com
+0 / -136 lines changed
Commit: December 2024 added to archive
Changes:
Before
After
For more information, see: [Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources](https://techcommunity.microsoft.com/blog/identity/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991).
 
---
 
## December 2024
 
### General Availability - What's new in Microsoft Entra
 
**Type:** New feature
**Service category:** Reporting
**Product capability:** Monitoring & Reporting
 
What's new in Microsoft Entra offers a comprehensive view of Microsoft Entra product updates including product roadmap (like Public Previews and recent GAs), and change announcements (like deprecations, breaking changes, feature changes and Microsoft-managed policies). It's a one stop shop for Microsoft Entra admins to discover the product updates.
 
 
### Public Preview - Microsoft Entra ID Governance: Approvers can revoke access in MyAccess
 
**Type:** New feature
**Service category:** Entitlement Management
**Product capability:** Entitlement Management
For more information, see: [Action required: MSOnline and AzureAD PowerShell retirement - 2025 info and resources](https://techcommunity.microsoft.com/blog/identity/action-required-msonline-and-azuread-powershell-retirement---2025-info-and-resou/4364991).
 
---
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Modified by shlipsey3 on Jun 19, 2025 5:44 AM
πŸ“– View on learn.microsoft.com
+76 / -0 lines changed
Commit: sec-recs-061825
Changes:
Before
After
 
[!INCLUDE [21787](../includes/secure-recommendations/21787.md)]
 
## Credential management
 
### Users have strong authentication methods configured
 
[!INCLUDE [21801](../includes/secure-recommendations/21801.md)]
 
## Access control
 
### Block legacy authentication
 
[!INCLUDE [21829](../includes/secure-recommendations/21829.md)]
 
## Application management
 
### Inactive applications don't have highly privileged Microsoft Graph API permissions
 
[!INCLUDE [21809](../includes/secure-recommendations/21809.md)]
 
[!INCLUDE [21787](../includes/secure-recommendations/21787.md)]
 
### Global Administrators don't have standing access to Azure subscriptions
 
[!INCLUDE [21788](../includes/secure-recommendations/21788.md)]
 
### Privileged role activations have monitoring and alerting configured
 
[!INCLUDE [21818](../includes/secure-recommendations/21818.md)]
 
### Global Administrator role activation triggers an approval workflow
 
[!INCLUDE [21817](../includes/secure-recommendations/21817.md)]
 
### Guests are not assigned high privileged directory roles
 
[!INCLUDE [22128](../includes/secure-recommendations/22128.md)]
 
### Conditional Access Policies for Privileged Access Workstations are configured
+35 / -30 lines changed
Commit: June 18 revisions for new client interface
Changes:
Before
After
description: Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
ms.service: global-secure-access
ms.topic: troubleshooting
ms.date: 05/09/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
The Global Secure Access client runs in the background, routing relevant network traffic to Global Secure Access without requiring user interaction. Use the advanced diagnostics tool to gain visibility into the client's behavior and troubleshoot issues effectively.
 
## Launch the advanced diagnostics tool
To launch the advanced diagnostics tool:
1. Right-click the **Global Secure Access client** icon in the system tray.
1. Select **Advanced Diagnostics**. If enabled, User Account Control (UAC) prompts you to elevate privileges.
 
## Overview tab
The advanced diagnostics **Overview** tab shows general configuration details for the Global Secure Access client:
- **Username**: The Microsoft Entra user principal name of the user who authenticated to the client.
 
The following files are collected:
 
description: Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
ms.service: global-secure-access
ms.topic: troubleshooting
ms.date: 06/18/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
The Global Secure Access client runs in the background, routing relevant network traffic to Global Secure Access without requiring user interaction. Use the advanced diagnostics tool to gain visibility into the client's behavior and troubleshoot issues effectively.
 
## Launch the advanced diagnostics tool
There are two ways to launch the advanced diagnostics tool:
1. Right-click the **Global Secure Access client** icon in the system tray.
1. Select **Advanced Diagnostics**. If enabled, User Account Control (UAC) prompts you to elevate privileges.
 
Or
1. Select the **Global Secure Access client** icon in the system tray.
1. Switch to the **Troubleshooting** view.
1. Under **Advanced diagnostics tool**, select **Run tool**.
 
## Overview tab
+19 / -6 lines changed
Commit: June 18 revisions for new client interface
Changes:
Before
After
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/13/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
ms.reviewer: lirazbarak
ms.custom: sfi-image-nochange
# Customer intent: Windows users, I want to download and install the Global Secure Access client.
---
# Global Secure Access client for Microsoft Windows
The Global Secure Access client is an essential part of Global Secure Access. It helps you manage and secure network traffic on end-user devices. The client routes traffic that needs to be secured by Global Secure Access to the cloud service. All other traffic goes directly to the network. The [Forwarding Profiles](concept-traffic-forwarding.md) you set up in the portal decide which traffic the Global Secure Access client routes to the cloud service.
 
>[!NOTE]
>The Global Secure Access Client is also available for macOS, Android, and iOS. To learn how to install the Global Secure Access client on these platforms, see [Global Secure Access client for macOS](how-to-install-macos-client.md), [Global Secure Access client for Android](how-to-install-android-client.md), and [Global Secure Access client for iOS](how-to-install-ios-client.md).
 
This article describes how to download and install the Global Secure Access client for Windows.
 
1. Hover over the connection icon to open the client status notification, which should show as **Connected**.
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/18/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
ms.reviewer: lirazbarak
ms.custom: sfi-image-nochange
 
# Customer intent: Windows users, I want to download and install the Global Secure Access client.
---
# Install the Global Secure Access client for Microsoft Windows
The Global Secure Access client is an essential part of Global Secure Access. It helps you manage and secure network traffic on end-user devices. The client routes traffic that needs to be secured by Global Secure Access to the cloud service. All other traffic goes directly to the network. The [Forwarding Profiles](concept-traffic-forwarding.md) you set up in the portal decide which traffic the Global Secure Access client routes to the cloud service.
 
> [!NOTE]
> The Global Secure Access Client is also available for macOS, Android, and iOS. To learn how to install the Global Secure Access client on these platforms, see [Global Secure Access client for macOS](how-to-install-macos-client.md), [Global Secure Access client for Android](how-to-install-android-client.md), and [Global Secure Access client for iOS](how-to-install-ios-client.md).
 
This article describes how to download and install the Global Secure Access client for Windows.
 
Modified by Ortagus Winfrey on Jun 19, 2025 5:22 AM
πŸ“– View on learn.microsoft.com
+12 / -12 lines changed
Commit: updates
Changes:
Before
After
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 12/13/2024
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-image-nochange
> Access reviews capture a snapshot of access at the beginning of each review instance. Any changes made during the review process will be reflected in the subsequent review cycle. Essentially, with the commencement of each new recurrence, pertinent data regarding the users, resources under review, and their respective reviewers is retrieved.
 
> [!NOTE]
> In a group review, nested groups will be automatically flattened, so users from nested groups will appear as individual users. If a user is flagged for removal due to their membership in a nested group, they will not be automatically removed from the nested group, but only from direct group membership.
 
## Create a single-stage access review
 
8. Or if you're conducting group membership review, you can create access reviews for only the inactive users in the group. In the *Users scope* section, check the box next to **Inactive users (on tenant level)**. If you check the box, the scope of the review focuses on inactive users only, those who haven't signed in either interactively or non-interactively to the tenant. Then, specify **Days inactive** with many days inactive up to 730 days (two years). Users in the group inactive for the specified number of days are the only users in the review.
 
> [!NOTE]
> Recently created users are not affected when configuring the inactivity time. The Access Review will check if a user has been created in the time frame configured and disregard users who haven’t existed for at least that amount of time. For example, if you set the inactivity time as 90 days and a guest user was created or invited less than 90 days ago, the guest user will not be in scope of the Access Review. This ensures that a user can sign in at least once before being removed.
 
9. Select **Next: Reviews**.
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 06/18/2025
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-image-nochange
> Access reviews capture a snapshot of access at the beginning of each review instance. Any changes made during the review process will be reflected in the subsequent review cycle. Essentially, with the commencement of each new recurrence, pertinent data regarding the users, resources under review, and their respective reviewers is retrieved.
 
> [!NOTE]
> In a group review, nested groups are automatically flattened, so users from nested groups appear as individual users. If a user is flagged for removal due to their membership in a nested group, they won't be automatically removed from the nested group, but only from direct group membership.
 
## Create a single-stage access review
 
8. Or if you're conducting group membership review, you can create access reviews for only the inactive users in the group. In the *Users scope* section, check the box next to **Inactive users (on tenant level)**. If you check the box, the scope of the review focuses on inactive users only, those who haven't signed in either interactively or non-interactively to the tenant. Then, specify **Days inactive** with many days inactive up to 730 days (two years). Users in the group inactive for the specified number of days are the only users in the review.
 
> [!NOTE]
> Recently created users aren't affected when configuring the inactivity time. The Access Review checks if a user has been created in the time frame configured and disregard users who haven’t existed for at least that amount of time. For example, if you set the inactivity time as 90 days and a guest user was created or invited less than 90 days ago, the guest user won't be in scope of the Access Review. This ensures that a user can sign in at least once before being removed.
 
9. Select **Next: Reviews**.
+19 / -3 lines changed
Commit: added 3 points from support
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: justinha
author: justinha
manager: dougeby
 
# Configure and enable users for SMS-based authentication using Microsoft Entra ID
 
To simplify and secure sign-in to applications and services, Microsoft Entra ID provides multiple authentication options. SMS-based authentication lets users sign-in without providing, or even knowing, their user name and password. After their account is created by an identity administrator, they can enter their phone number at the sign-in prompt. They receive an SMS authentication code that they can provide to complete the sign-in. This authentication method simplifies access to applications and services, especially for Frontline workers.
 
This article shows you how to enable SMS-based authentication for select users or groups in Microsoft Entra ID. For a list of apps that support using SMS-based sign-in, see [App support for SMS-based authentication](how-to-authentication-sms-supported-apps.md).
 
## Before you begin
 
To complete this article, you need the following resources and privileges:
 
* An active Azure subscription.
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/18/2025
ms.author: justinha
author: justinha
manager: dougeby
 
# Configure and enable users for SMS-based authentication using Microsoft Entra ID
 
To simplify and secure sign-in to applications and services, Microsoft Entra ID provides multiple authentication options. SMS-based authentication lets frontlone workers enter an SMS code as a first factor for sign in. Users don't need to provide, or even know, their user name and password.
 
After their account is created by an identity administrator, they can enter their phone number at the sign-in prompt. They receive an SMS authentication code that they can provide to complete the sign-in. This authentication method simplifies fronline worker access to applications and services.
 
The rest of this article shows you how to enable SMS-based authentication as a first factor for select users or groups in Microsoft Entra ID. For a list of apps that support using SMS-based sign-in, see [App support for SMS-based authentication](how-to-authentication-sms-supported-apps.md).
 
## Before you begin
 
Here are some important points before you start:
 
Modified by Ortagus Winfrey on Jun 19, 2025 5:45 AM
πŸ“– View on learn.microsoft.com
+6 / -6 lines changed
Commit: updates
Changes:
Before
After
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 04/09/2024
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-image-nochange
The first step to perform an access review is to find and open the access review.
 
>[!IMPORTANT]
> There could be delays in receiving email and it some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you are receiving all emails.
 
1. Look for an email from Microsoft that asks you to review access. Here's an example email to review your access to a group.
 
 
Your selection is submitted and you're returned to the My Apps portal.
 
If you want to change your response, reopen the access reviews page and update your response. You can change your response at any time until the access review has ended.
 
> [!NOTE]
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 06/18/2025
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-image-nochange
The first step to perform an access review is to find and open the access review.
 
>[!IMPORTANT]
> There could be delays in receiving email and it some cases it could take up to 24 hours. Add [email protected] to your safe recipients list to make sure that you're receiving all emails.
 
1. Look for an email from Microsoft that asks you to review access. Here's an example email to review your access to a group.
 
 
Your selection is submitted and you're returned to the My Apps portal.
 
If you want to change your response, reopen the access reviews page and update your response. You can change your response at any time until the access review ends.
 
> [!NOTE]
Modified by Ortagus Winfrey on Jun 19, 2025 5:41 AM
πŸ“– View on learn.microsoft.com
+5 / -5 lines changed
Commit: updates
Changes:
Before
After
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 07/15/2024
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-image-nochange
After it opens, you'll see the list of users in scope for the access review.
 
> [!NOTE]
> If the request is to review your own access, the page will look different. For more information, see [Review access for yourself to groups or applications](review-your-access.md).
 
There are two ways that you can approve or deny access:
 
 
1. Select **Submit**.
 
You can change your response at any time until the access review has ended. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
 
> [!IMPORTANT]
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 06/18/2025
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-image-nochange
After it opens, you'll see the list of users in scope for the access review.
 
> [!NOTE]
> If the request is to review your own access, the page looks different. For more information, see [Review access for yourself to groups or applications](review-your-access.md).
 
There are two ways that you can approve or deny access:
 
 
1. Select **Submit**.
 
You can change your response at any time until the access review ends. If you want to change your response, select the row and update the response. For example, you can approve a previously denied user or deny a previously approved user.
 
> [!IMPORTANT]
Modified by Ortagus Winfrey on Jun 19, 2025 5:32 AM
πŸ“– View on learn.microsoft.com
+5 / -5 lines changed
Commit: updates
Changes:
Before
After
ms.service: entra-id-governance
ms.subservice: entitlement-management
ms.topic: how-to
ms.date: 08/12/2024
ms.author: owinfrey
ms.reviewer: mamkumar
#Customer intent: As an approver, I want steps for how to approve requests for access packages so that I can unlock requestors who need to use the resources.
 
 
> [!NOTE]
> If you dont see an email to approve request, make sure that the access package does not have notifications disabled.
 
## View requestor's answers to questions
 
 
![My Access portal - Access request- Click request details](./media/entitlement-management-request-approve/requestor-information-request-details.png)
 
1. On the **Request details** page, basic information about the request are present such as who made the request, and whether it was for themselves or for someone else. See [Request access package on-behalf-of other users(Preview)](entitlement-management-request-behalf.md) for more details on requesting access for other users.
 
1. The information provided by the requestor is at the bottom of the panel.
ms.service: entra-id-governance
ms.subservice: entitlement-management
ms.topic: how-to
ms.date: 06/18/2025
ms.author: owinfrey
ms.reviewer: mamkumar
#Customer intent: As an approver, I want steps for how to approve requests for access packages so that I can unlock requestors who need to use the resources.
 
 
> [!NOTE]
> If you don't see an email to approve request, make sure that the access package doesn't have notifications disabled.
 
## View requestor's answers to questions
 
 
![My Access portal - Access request- Click request details](./media/entitlement-management-request-approve/requestor-information-request-details.png)
 
1. On the **Request details** page, basic information about the request is present such as who made the request, and whether it was for themselves or for someone else. See [Request access package on-behalf-of other users(Preview)](entitlement-management-request-behalf.md) for more details on requesting access for other users.
 
1. The information provided by the requestor is at the bottom of the panel.
Modified by Ortagus Winfrey on Jun 19, 2025 5:15 AM
πŸ“– View on learn.microsoft.com
+5 / -5 lines changed
Commit: updates
Changes:
Before
After
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 12/10/2024
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-ga-nochange, sfi-image-nochange
 
> [!NOTE]
> Some denied users are unable to have results applied to them. Scenarios where this could happen include:
> - Reviewing members of a synced on-premises Windows Server AD group: If the group is synced from on-premises Windows Server AD, the group cannot be managed in Microsoft Entra ID and therefore membership cannot be changed.
> - Reviewing a resource (role, group, application) with nested groups assigned: For users who have membership through a nested group, we will not remove their membership to the nested group and therefore they will retain access to the resource being reviewed.
> - User not found / other errors can also result in an apply result not being supported.
> - Reviewing the members of mail enabled group: The group cannot be managed in Microsoft Entra ID, so membership cannot be changed.
> - Reviewing an Application that uses group assignment will not remove the members of those groups, so they will retain the existing access from the group relationship for the application assignment
## Actions taken on denied guest users in an access review
ms.service: entra-id-governance
ms.subservice: access-reviews
ms.topic: how-to
ms.date: 06/18/2025
ms.author: owinfrey
ms.reviewer: mwahl
ms.custom: sfi-ga-nochange, sfi-image-nochange
 
> [!NOTE]
> Some denied users are unable to have results applied to them. Scenarios where this could happen include:
> - Reviewing members of a synced on-premises Windows Server AD group: If the group is synced from on-premises Windows Server AD, the group can't be managed in Microsoft Entra ID and therefore membership can't be changed.
> - Reviewing a resource (role, group, application) with nested groups assigned: For users who have membership through a nested group, we won't remove their membership to the nested group and therefore they'll retain access to the resource being reviewed.
> - User not found / other errors can also result in an apply result not being supported.
> - Reviewing the members of mail enabled group: The group can't be managed in Microsoft Entra ID, so membership can't be changed.
> - Reviewing an Application that uses group assignment won't remove the members of those groups, so they'll retain the existing access from the group relationship for the application assignment
## Actions taken on denied guest users in an access review
Modified by Barclay Neira on Jun 19, 2025 4:39 AM
πŸ“– View on learn.microsoft.com
+4 / -4 lines changed
Commit: minor edit
Changes:
Before
After
title: Include file
description: Include file
author: rolyon
ms.service: entra-id
ms.topic: include
ms.date: 04/03/2025
ms.author: rolyon
ms.custom: include file
---
Here are the usage constraints and other service limits for the Microsoft Entra service.
| Tenants | <li>A single user can belong to a maximum of 500 Microsoft Entra tenants as a member or a guest. <li>Create a maximum of 200 tenants.<li>Limit of 300 [license-based subscriptions](/microsoft-365/commerce/licenses/subscriptions-and-licenses) (such as Microsoft 365 subscriptions) per tenant |
| Domains | <li>You can add no more than 5,000 managed domain names. <li>If you set up all of your domains for federation with on-premises Active Directory, you can add no more than 2,500 domain names in each tenant. |
|Resources |<ul><li>By default, a maximum of 50,000 Microsoft Entra resources can be created in a single tenant by users of the Microsoft Entra ID Free edition. If you have at least one verified domain, the default Microsoft Entra service quota for your organization is extended to 300,000 Microsoft Entra resources. <br>The Microsoft Entra service quota for organizations created by self-service sign-up remains 50,000 Microsoft Entra resources, even after you perform an internal admin takeover and the organization is converted to a managed tenant with at least one verified domain. This service limit is unrelated to the pricing tier limit of 500,000 resources on the Microsoft Entra pricing page. <br>To go beyond the default quota, you must contact Microsoft Support.</li><li>A non-admin user can create no more than 250 Microsoft Entra resources. Both active resources and deleted resources that are available to restore count toward this quota. Only deleted Microsoft Entra resources that were deleted fewer than 30 days ago are available to restore. Deleted Microsoft Entra resources that are no longer available to restore count toward this quota at a value of one-quarter for 30 days. <br>If you have developers who are likely to repeatedly exceed this quota in the course of their regular duties, you can [create and assign a custom role](~/identity/role-based-access-control/quickstart-app-registration-limits.md) with permission to create a limitless number of app registrations.</li><li>Resource limitations apply to all directory objects in a given Microsoft Entra tenant, including users, groups, applications, and service principals.</li></ul> |
| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li></ul> |
| Applications | <ul><li>A maximum of 100 users and service principals can be owners of a single application.</li><li>A user, group, or service principal can have a maximum of 1,500 app role assignments. The limitation is on the assigned service principal, user, or group across all app roles and not on the number of assignments of a single app role. This limit includes app role assignments where the resource service principal has been soft-deleted.</li><li>A user can have credentials configured for a maximum of 48 apps using password-based single sign-on. This limit only applies for credentials configured when the user is directly assigned the app, not when the user is a member of a group that is assigned.</li><li>A group can have credentials configured for a maximum of 48 apps using password-based single sign-on.</li><li>See additional limits in [Validation differences by supported account types](~/identity-platform/supported-accounts-validation.md).</li></ul> |
|Application manifest |A maximum of 1,200 entries can be added to the application manifest.<br/>See additional limits in [Validation differences by supported account types](~/identity-platform/supported-accounts-validation.md). |
| Groups |<ul><li>A non-admin user can create a maximum of 250 groups in a Microsoft Entra organization. Any Microsoft Entra admin who can manage groups in the organization can also create an unlimited number of groups (up to the Microsoft Entra object limit). If you assign a role to a user to remove the limit for that user, assign a less privileged, built-in role such as User Administrator or Groups Administrator.</li><li>A Microsoft Entra organization can have a maximum of 15,000 dynamic groups (including those originating from Microsoft Entra entitlement management automatic assignment policies) and dynamic administrative units combined.</li><li>A maximum of 500 [role-assignable groups](~/identity/role-based-access-control/groups-concept.md) can be created in a single Microsoft Entra organization (tenant).</li><li>A maximum of 100 users can be owners of a single group.</li><li>There is a limit of 1010 groups per token allowed for [Entra Kerberos](/troubleshoot/windows-server/windows-security/logging-on-user-account-fails).</li><li>Any number of Microsoft Entra resources can be members of a single group.</li><li>A user can be a member of any number of groups. When security groups are being used in combination with SharePoint Online, a user can be a part of 2,047 security groups in total. This includes both direct and indirect group memberships. When this limit is exceeded, authentication and search results become unpredictable.</li><li>Starting with Microsoft Entra Connect v2.0, the V2 endpoint is the default API. The number of members in a group that you can synchronize from your on-premises Active Directory to Microsoft Entra ID by using Microsoft Entra Connect is limited to 250,000 members. For more information, see [Microsoft Entra Connect Sync V2](../identity/hybrid/connect/how-to-connect-sync-endpoint-api-v2.md).</li><li>When you select a list of groups, you can assign a group expiration policy to a maximum of 500 Microsoft 365 groups. There's no limit when the policy is applied to all Microsoft 365 groups.</li></ul><br/> At this time, the following scenarios are supported with nested groups:<ul><li> One group can be added as a member of another group, and you can achieve group nesting.</li><li> Group membership claims. When an app is configured to receive group membership claims in the token, nested groups in which the signed-in user is a member are included.</li><li>Conditional Access (when a Conditional Access policy has a group scope).</li><li>Restricting access to self-serve password reset.</li><li>Restricting which users can do Microsoft Entra join and device registration.</li></ul><br/>The following scenarios are *not* supported with nested groups:<ul><li> App role assignment, for both access and provisioning. Assigning groups to an app is supported, but any groups nested within the directly assigned group won't have access.</li><li>Group-based licensing (assigning a license automatically to all members of a group).</li><li>Microsoft 365 Groups.</li></ul> |
title: Include file
description: Include file
author: barclayn
ms.service: entra-id
ms.topic: include
ms.date: 06/18/2025
ms.author: barclayn
ms.custom: include file
---
Here are the usage constraints and other service limits for the Microsoft Entra service.
| Tenants | <li>A single user can belong to a maximum of 500 Microsoft Entra tenants as a member or a guest. <li>Create a maximum of 200 tenants.<li>Limit of 300 [license-based subscriptions](/microsoft-365/commerce/licenses/subscriptions-and-licenses) (such as Microsoft 365 subscriptions) per tenant |
| Domains | <li>You can add no more than 5,000 managed domain names. <li>If you set up all of your domains for federation with on-premises Active Directory, you can add no more than 2,500 domain names in each tenant. |
|Resources |<ul><li>By default, a maximum of 50,000 Microsoft Entra resources can be created in a single tenant by users of the Microsoft Entra ID Free edition. If you have at least one verified domain, the default Microsoft Entra service quota for your organization is extended to 300,000 Microsoft Entra resources. <br>The Microsoft Entra service quota for organizations created by self-service sign-up remains 50,000 Microsoft Entra resources, even after you perform an internal admin takeover and the organization is converted to a managed tenant with at least one verified domain. This service limit is unrelated to the pricing tier limit of 500,000 resources on the Microsoft Entra pricing page. <br>To go beyond the default quota, you must contact Microsoft Support.</li><li>A non-admin user can create no more than 250 Microsoft Entra resources. Both active resources and deleted resources that are available to restore count toward this quota. Only deleted Microsoft Entra resources that were deleted fewer than 30 days ago are available to restore. Deleted Microsoft Entra resources that are no longer available to restore count toward this quota at a value of one-quarter for 30 days. <br>If you have developers who are likely to repeatedly exceed this quota in the course of their regular duties, you can [create and assign a custom role](~/identity/role-based-access-control/quickstart-app-registration-limits.md) with permission to create a limitless number of app registrations.</li><li>Resource limitations apply to all directory objects in a given Microsoft Entra tenant, including users, groups, applications, and service principals.</li></ul> |
| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li><strong>Note:</strong> Only the "equals" operator is supported.</li></ul> |
| Applications | <ul><li>A maximum of 100 users and service principals can be owners of a single application.</li><li>A user, group, or service principal can have a maximum of 1,500 app role assignments. The limitation is on the assigned service principal, user, or group across all app roles and not on the number of assignments of a single app role. This limit includes app role assignments where the resource service principal has been soft-deleted.</li><li>A user can have credentials configured for a maximum of 48 apps using password-based single sign-on. This limit only applies for credentials configured when the user is directly assigned the app, not when the user is a member of a group that is assigned.</li><li>A group can have credentials configured for a maximum of 48 apps using password-based single sign-on.</li><li>See additional limits in [Validation differences by supported account types](~/identity-platform/supported-accounts-validation.md).</li></ul> |
|Application manifest |A maximum of 1,200 entries can be added to the application manifest.<br/>See additional limits in [Validation differences by supported account types](~/identity-platform/supported-accounts-validation.md). |
| Groups |<ul><li>A non-admin user can create a maximum of 250 groups in a Microsoft Entra organization. Any Microsoft Entra admin who can manage groups in the organization can also create an unlimited number of groups (up to the Microsoft Entra object limit). If you assign a role to a user to remove the limit for that user, assign a less privileged, built-in role such as User Administrator or Groups Administrator.</li><li>A Microsoft Entra organization can have a maximum of 15,000 dynamic groups (including those originating from Microsoft Entra entitlement management automatic assignment policies) and dynamic administrative units combined.</li><li>A maximum of 500 [role-assignable groups](~/identity/role-based-access-control/groups-concept.md) can be created in a single Microsoft Entra organization (tenant).</li><li>A maximum of 100 users can be owners of a single group.</li><li>There is a limit of 1010 groups per token allowed for [Entra Kerberos](/troubleshoot/windows-server/windows-security/logging-on-user-account-fails).</li><li>Any number of Microsoft Entra resources can be members of a single group.</li><li>A user can be a member of any number of groups. When security groups are being used in combination with SharePoint Online, a user can be a part of 2,047 security groups in total. This includes both direct and indirect group memberships. When this limit is exceeded, authentication and search results become unpredictable.</li><li>Starting with Microsoft Entra Connect v2.0, the V2 endpoint is the default API. The number of members in a group that you can synchronize from your on-premises Active Directory to Microsoft Entra ID by using Microsoft Entra Connect is limited to 250,000 members. For more information, see [Microsoft Entra Connect Sync V2](../identity/hybrid/connect/how-to-connect-sync-endpoint-api-v2.md).</li><li>When you select a list of groups, you can assign a group expiration policy to a maximum of 500 Microsoft 365 groups. There's no limit when the policy is applied to all Microsoft 365 groups.</li></ul><br/> At this time, the following scenarios are supported with nested groups:<ul><li> One group can be added as a member of another group, and you can achieve group nesting.</li><li> Group membership claims. When an app is configured to receive group membership claims in the token, nested groups in which the signed-in user is a member are included.</li><li>Conditional Access (when a Conditional Access policy has a group scope).</li><li>Restricting access to self-serve password reset.</li><li>Restricting which users can do Microsoft Entra join and device registration.</li></ul><br/>The following scenarios are *not* supported with nested groups:<ul><li> App role assignment, for both access and provisioning. Assigning groups to an app is supported, but any groups nested within the directly assigned group won't have access.</li><li>Group-based licensing (assigning a license automatically to all members of a group).</li><li>Microsoft 365 Groups.</li></ul> |
Modified by Anna Huff on Jun 19, 2025 5:54 AM
πŸ“– View on learn.microsoft.com
+4 / -4 lines changed
Commit: PR review: Update workday-inbound-tutorial.md
Changes:
Before
After
---
title: Configure Configure Workday for automatic user provisioning with Microsoft Entra ID
description: Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Workday.
author: cmmdesai
manager: femila
ms.custom: sfi-image-nochange
# Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Workday to Active Directory so that I can streamline the user management process and ensure that users have the appropriate access to Workday to Active Directory.
---
# Configure Configure Workday for for automatic user provisioning with Microsoft Entra ID
 
The objective of this article is to show the steps you need to perform to provision worker profiles from Workday into on-premises Active Directory (AD).
 
>[!NOTE]
>Use this article, if the users you want to provision from Workday need an on-premises AD account and a Microsoft Entra account.
>* If the users from Workday only need Microsoft Entra account (cloud-only users), then please refer to the article on [configure Workday to Microsoft Entra ID](workday-inbound-cloud-only-tutorial.md) user provisioning.
>* To configure writeback of attributes such as email address, username and phone number from Microsoft Entra ID to Workday, please refer to the article on [configure Workday writeback](workday-writeback-tutorial.md).
 
The following video provides a quick overview of the steps involved when planning your provisioning integration with Workday.
 
---
title: Configure Workday for automatic user provisioning with Microsoft Entra ID
description: Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Workday.
author: cmmdesai
manager: femila
ms.custom: sfi-image-nochange
# Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Workday to Active Directory so that I can streamline the user management process and ensure that users have the appropriate access to Workday to Active Directory.
---
# Configure Workday for automatic user provisioning with Microsoft Entra ID
 
The objective of this article is to show the steps you need to perform to provision worker profiles from Workday into on-premises Active Directory (AD).
 
>[!NOTE]
>Use this article, if the users you want to provision from Workday need an on-premises AD account and a Microsoft Entra account.
>* If the users from Workday only need Microsoft Entra account (cloud-only users), refer to the article on [configure Workday to Microsoft Entra ID](workday-inbound-cloud-only-tutorial.md) user provisioning.
>* To configure writeback of attributes such as email address, username and phone number from Microsoft Entra ID to Workday, refer to the article on [configure Workday writeback](workday-writeback-tutorial.md).
 
The following video provides a quick overview of the steps involved when planning your provisioning integration with Workday.
 
+3 / -3 lines changed
Commit: Fixing image naming
Changes:
Before
After
 
Go to the Entra portal, select **App Registrations**, and then select **New registration**. Create a single-tenant app as shown below.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-id-darwinbox-register.png" alt-text="Screenshot of Microsoft Entra ID Register an application page.":::
 
Add the following three Microsoft Graph application permissions to let Darwinbox create the provisioning job: `Application.ReadWrite.OwnedBy`, send user data `SyncrhonizationData-User.Upload.OwnedBy`, and review the provisioning logs `ProvisioningLog.Read.All`.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-id-darwinbox-sync.png" alt-text="Screenshot of Microsoft Entra ID registering with Darwinbox.":::
 
Create a client secret and provide the credentials to Darwinbox as specified in their guide.
 
 
To sync custom attributes from Darwinbox to Entra, update the attribute mapping for the provisioning job in the Entra portal.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-id-attribute-mapping.png" alt-text="Screenshot of Microsoft Entra ID mapping page.":::
 
Upload a CSV file with these mappings to Darwinbox.
 
 
Go to the Entra portal, select **App Registrations**, and then select **New registration**. Create a single-tenant app as shown below.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-darwinbox-register.png" alt-text="Screenshot of Microsoft Entra ID Register an application page.":::
 
Add the following three Microsoft Graph application permissions to let Darwinbox create the provisioning job: `Application.ReadWrite.OwnedBy`, send user data `SyncrhonizationData-User.Upload.OwnedBy`, and review the provisioning logs `ProvisioningLog.Read.All`.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-darwinbox-sync.png" alt-text="Screenshot of Microsoft Entra ID registering with Darwinbox.":::
 
Create a client secret and provide the credentials to Darwinbox as specified in their guide.
 
 
To sync custom attributes from Darwinbox to Entra, update the attribute mapping for the provisioning job in the Entra portal.
 
:::image type="content" border="true" source="./media/darwinbox-entra-integration-tutorial/entra-attribute-mapping.png" alt-text="Screenshot of Microsoft Entra ID mapping page.":::
 
Upload a CSV file with these mappings to Darwinbox.