πŸ“‹ Microsoft Entra Documentation Changes

Changes for June 22nd 2025

Period: June 21st 2025, 12:00 AM to June 22nd 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 22nd 2025.

πŸ“Š Summary

40
Total Commits
0
New Files
19
Modified Files
5
Deleted Files
14
Contributors

πŸ“ Modified Documentation Files

+67 / -43 lines changed
Commit: Updated the doc with SPO
Changes:
Before
After
 
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::
 
## Linkable identifiers in Microsoft Teams audit logs
 
Microsoft Teams audit logs capture a detailed record of all requests processed by the Teams service for a tenant. Audited activities include team creation and deletion, channel additions and removals, and changes to channel settings.
 
For a full list of audited Teams activities, see [Teams activities in the audit log](/purview/audit-log-activities).
For more information about Teams audit logs, see [Teams Audit Logs](/purview/audit-teams-audit-log-events). For more information about how to search the Teams audit logs, see [Search the audit log](/purview/audit-search).
 
### Investigation scenarios using linkable identifiers
 
To investigate Teams activity:
 
- Start with linkable identifiers from Microsoft Entra sign-in logs, such as SID or UTI.
- Use these identifiers to search Microsoft Purview Audit (Standard) or Audit (Premium) logs.
- Track user actions across Teams sessions, including team and channel operations.
 
The table below shows the mapping between linkable identifier claims and Teams audit log attribute.
 
 
:::image type="content" border="true" source="media/how-to-authentication-track-linkable-identifiers/search-token-id.png" alt-text="Screenshot of log line with linkable identifiers.":::
 
## Linkable identifiers in Microsoft SharePoint Online audit logs
 
Microsoft SharePoint Online audit logs provide a comprehensive audit trail of all requests processed by the SharePoint Online service for a tenant. These logs capture a wide range of user activities, including operations such as file and folder creation, updates, deletions, and list modifications. For a detailed overview of SharePoint Online audit logging, see [SharePoint Online Audit Logs](/purview/audit-log-sharing?tabs=microsoft-purview-portal).
 
**Investigation Scenarios Using Linkable Identifiers**
 
For scenarios involving SharePoint Online activity, you can:
 
- Start with linkable identifiers from Microsoft Entra sign-in logs, such as SID or UTI.
- Use these identifiers to search Microsoft Purview Audit (Standard) or Audit (Premium) logs.
- Track all user actions performed within SharePoint Online during a specific session or by a specific token.
 
This approach enables security analysts to correlate authentication events with SharePoint activity, supporting effective investigation and response to potential threats.
 
For guidance on searching SharePoint Online audit logs, see [Search the audit log | Microsoft Learn](/purview/audit-search).
 
The table below shows the mapping between linkable identifier claims and Microsoft SharePoint Online audit log attribute.
+53 / -19 lines changed
Commit: June 20 updates for client version 1.1.25060400
Changes:
Before
After
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 02/25/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
ms.reviewer: lirazbarak
ms.custom: sfi-image-nochange
# Customer intent: macOS users, I want to download and install the Global Secure Access client.
---
# Global Secure Access client for macOS (Preview)
> [!IMPORTANT]
> The Global Secure Access client for macOS is currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
The Global Secure Access client, an essential component of Global Secure Access, helps organizations manage and secure network traffic on end-user devices. The client's main role is to route traffic that needs to be secured by Global Secure Access to the cloud service. All other traffic goes directly to the network. The [Forwarding Profiles](concept-traffic-forwarding.md), configured in the portal, determine which traffic the Global Secure Access client routes to the cloud service.
 
This article describes how to download and install the Global Secure Access client for macOS.
 
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/20/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
ms.reviewer: lirazbarak
ms.custom: sfi-image-nochange
# Customer intent: macOS users, I want to download and install the Global Secure Access client.
 
---
# Install the Global Secure Access client for macOS (Preview)
The Global Secure Access client, an essential component of Global Secure Access, helps organizations manage and secure network traffic on end-user devices. The client's main role is to route traffic that needs to be secured by Global Secure Access to the cloud service. All other traffic goes directly to the network. The [Forwarding Profiles](concept-traffic-forwarding.md), configured in the portal, determine which traffic the Global Secure Access client routes to the cloud service.
 
> [!IMPORTANT]
> The Global Secure Access client for macOS is currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
This article describes how to download and install the Global Secure Access client for macOS.
+35 / -23 lines changed
Commit: conditional-access-audience-preview-addition
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: troubleshooting
ms.date: 06/06/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
ms.reviewer: kvenkit
ms.custom: sfi-image-nochange
---
# Troubleshooting sign-in problems with Conditional Access
 
Use this article to troubleshoot unexpected sign-in outcomes related to Conditional Access using error messages and Microsoft Entra sign-in logs.
 
## Select "all" consequences
 
The Conditional Access framework provides great configuration flexibility. However, great flexibility also means that you should carefully review each configuration policy before releasing it to avoid undesirable results. In this context, pay special attention to assignments affecting complete sets such as **all users / groups / cloud apps**.
 
Organizations should avoid the following configurations:
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: troubleshooting
ms.date: 06/20/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
ms.reviewer: kvenkit
ms.custom: sfi-image-nochange
---
# Troubleshoot sign-in problems with Conditional Access
 
Use this article to fix unexpected sign-in outcomes related to Conditional Access by checking error messages and Microsoft Entra sign-in logs.
 
## Select "all" consequences
 
The Conditional Access framework gives you a lot of configuration flexibility. But this flexibility means you need to carefully review each configuration policy before releasing it to avoid unwanted results. In this context, pay special attention to assignments that affect complete sets like **all users / groups / resources**.
 
Don't use the following configurations:
 
+41 / -6 lines changed
Commit: June 20 updates for client version 1.1.25060400
Changes:
Before
After
description: This article tracks the changes in each released version of the Global Secure Access client for macOS.
ms.service: global-secure-access
ms.topic: reference
ms.date: 02/28/2025
ms.author: jfields
author: jenniferf-skc
manager: femila
ms.reviewer: lirazbarak
 
 
---
# Global Secure Access client for macOS release notes
This article lists the released versions of the Global Secure Access client for macOS along with the changes in each version.
 
## Download the latest version
The current version of the Global Secure Access client is available to download from the Microsoft Entra admin center.
1. Select **Download Client**.
:::image type="content" source="media/reference-macos-client-release-history/macos-client-download-screen.png" alt-text="Screenshot of the Client download screen with the Download Client button highlighted.":::
 
## Version 1.1.584
description: This article tracks the changes in each released version of the Global Secure Access client for macOS.
ms.service: global-secure-access
ms.topic: reference
ms.date: 06/20/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
ms.reviewer: lirazbarak
 
 
---
# Global Secure Access client for macOS release notes
This article lists the released versions of the Global Secure Access client for macOS and describes the changes in each version.
 
## Download the latest version
The current version of the Global Secure Access client is available to download from the Microsoft Entra admin center.
1. Select **Download Client**.
:::image type="content" source="media/reference-macos-client-release-history/macos-client-download-screen.png" alt-text="Screenshot of the Client download screen with the Download Client button highlighted.":::
 
## Version 1.1.25060400
+33 / -7 lines changed
Commit: Applying feedback
Changes:
Before
After
 
Because secure applications are essential to the organization, any downtime to them because of security issues can affect the business or some critical service that the business depends upon. So, it's important to allocate time and resources to ensure applications always stay in a healthy and secure state. Conduct a periodic security and health assessment of applications, much like a Security Threat Model assessment for code. For a broader perspective on security for organizations, see the [security development lifecycle (SDL)](https://www.microsoft.com/securityengineering/sdl).
 
This article describes security best practices for the following application properties:
 
- Credentials
- Redirect URIs
- Implicit flow configuration
- Application instance lock
- Application ownership
 
## Credentials (including certificates and secrets)
 
Credentials are a vital part of an application when it's used as a confidential client. Under the **Certificates and secrets** page for the application in the Azure portal, credentials can be added or removed.
- If the service the app is used in doesn't run on Azure, but does run on another platform that offers automated credential management, consider [using an identity from that platform as a credential](../workload-id/workload-identity-federation-create-trust). For example, a [Github actions workflow can be configured as a credential](../workload-id/workload-identity-federation-create-trust#github-actions), eliminating the need to manage and secure credentials for the Github actions pipeline. Use caution with this approach and only configure federated credentials from platforms you trust. An app is only as secure as the identity platform it has configured as a credential.
- If using a managed identity or other secure external identity provider isn't possible, use [certificate credentials](./certificate-credentials.md). **Don't use password credentials, also known as *secrets***. While it's convenient to use password secrets as a credential, password credentials are often mismanaged and can be easily compromised.
- If a certificate must be used instead of a managed identity, store that certificate in a secure key vault, like [Azure Key Vault](https://azure.microsoft.com/products/key-vault).
- Configure [application management policies](/graph/api/resources/applicationauthenticationmethodpolicy) to govern the use of secrets by limiting their lifetimes or blocking their use altogether.
- If an application is used only as a public or installed client (for example, mobile or desktop apps that are installed on the end user machine), make sure that there are no credentials specified on the application object.
- Review the credentials used in applications for freshness of use and their expiration. An unused credential on an application can result in a security breach. Rollover credentials frequently and don't share credentials across applications. Don't have many credentials on one application.
 
Because secure applications are essential to the organization, any downtime to them because of security issues can affect the business or some critical service that the business depends upon. So, it's important to allocate time and resources to ensure applications always stay in a healthy and secure state. Conduct a periodic security and health assessment of applications, much like a Security Threat Model assessment for code. For a broader perspective on security for organizations, see the [security development lifecycle (SDL)](https://www.microsoft.com/securityengineering/sdl).
 
This article describes security best practices for the following application properties and scenarios:
 
- Identity type
- Credentials
- Redirect URIs
- Implicit flow configuration
- Application instance lock
- Application ownership
 
## Identity type
 
You are likely here to learn about security best practices for [Entra applications](../identity-platform/how-applications-are-added) - also referred to as app registrations or app objects. However, there is another identity type that can be used to access Entra-protected resources, called [managed identities for Azure resources](https://learn.microsoft.com/entra/identity/managed-identities-azure-resources/overview).
 
Azure managed identities are secure by default and require little to no ongoing maintenance or overhead. Consider using a managed identity instead of an Entra application for your app identity if all of the following are true:
 
- The service runs in the Azure cloud
- The app doesn't need to sign in users
+26 / -4 lines changed
Commit: GA CA store
Changes:
Before
After
 
:::image type="content" border="false" source="./media/how-to-certificate-based-authentication/steps.png" alt-text="Diagram of the steps required to enable Microsoft Entra certificate-based authentication.":::
 
## Step 1: Configure the certificate authorities with PKI-based trust store (Preview)
 
Entra has a new public key infrastructure (PKI) based certificate authorities (CA) trust store. The PKI-based CA trust store keeps CAs within a container object for each different PKI. Admins can manage CAs in a container based on PKI easier than one flat list of CAs.
 
1. Select **Columns** to add or delete columns.
1. Select **Refresh** to refresh the list of CAs.
 
#### Upload all CAs with upload PKI into PKI container object
1. To upload all CAs at once into the PKI container:
1. Select the upload.
1. Upload PKI is an asynchronous process. As each CA is uploaded, it's available in the PKI. Completion of PKI upload can take up to 30 minutes.
1. Select **Refresh** to refresh the CAs.
 
To generate the SHA256 checksum of the PKI .p7b file, run this command:
 
1. To edit PKI, select **...** on the PKI row and select **Edit**.
 
:::image type="content" border="false" source="./media/how-to-certificate-based-authentication/steps.png" alt-text="Diagram of the steps required to enable Microsoft Entra certificate-based authentication.":::
 
## Step 1: Configure the certificate authorities with PKI-based trust store
 
Entra has a new public key infrastructure (PKI) based certificate authorities (CA) trust store. The PKI-based CA trust store keeps CAs within a container object for each different PKI. Admins can manage CAs in a container based on PKI easier than one flat list of CAs.
 
1. Select **Columns** to add or delete columns.
1. Select **Refresh** to refresh the list of CAs.
1. Initially 100 CA certificates will be displayed and display more as the page is scrolled down.
 
#### Upload all CAs with upload PKI into PKI container object
1. To upload all CAs at once into the PKI container:
1. Select the upload.
1. Upload PKI is an asynchronous process. As each CA is uploaded, it's available in the PKI. Completion of PKI upload can take up to 30 minutes.
1. Select **Refresh** to refresh the CAs.
1. Each uploaded CA **CRL endpoint** attribute will be updated with the CA certificate's first available http URL on **CRL distribution points** attribute. The leaf CA certificate CA needs to be updated manually by the admin.
 
To generate the SHA256 checksum of the PKI .p7b file, run this command:
+14 / -14 lines changed
Commit: conditional-access-audience-preview-addition
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 06/14/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: calebb
---
# What are service dependencies in Microsoft Entra Conditional Access?
 
With Conditional Access policies, you can specify access requirements to websites and services. For example, your access requirements can include requiring multifactor authentication (MFA) or [managed devices](./concept-conditional-access-grant.md).
 
When you access a site or service directly, the impact of a related policy is typically easy to assess. For example, if you have a policy that requires multifactor authentication (MFA) for SharePoint Online configured, MFA is enforced for each sign-in to the SharePoint web portal. However, it isn't always straight-forward to assess the impact of a policy because there are cloud apps with dependencies to other cloud apps. For example, Microsoft Teams can provide access to resources in SharePoint Online. So, when you access Microsoft Teams in our current scenario, you're also subject to the SharePoint MFA policy.
 
> [!TIP]
> Using the [Office 365](concept-conditional-access-cloud-apps.md#office-365) app will target all Office apps to avoid issues with service dependencies in the Office stack.
 
<!-- docutune:ignore "Windows Azure Active Directory" -->
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 06/20/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: kvenkit
---
# Service dependencies in Microsoft Entra Conditional Access
 
With Conditional Access policies, you specify requirements to use websites and services. For example, your requirements can include requiring multifactor authentication (MFA) or [managed devices](./concept-conditional-access-grant.md).
 
When you use a site or service directly, it's usually easy to see how a related policy affects you. For example, if you set a policy that requires multifactor authentication (MFA) for SharePoint Online, MFA is required for each sign-in to the SharePoint web portal. But sometimes it's hard to know how a policy affects you because some cloud apps depend on other cloud apps. For example, Microsoft Teams lets you use resources in SharePoint Online. So, when you use Microsoft Teams in this scenario, you're also subject to the SharePoint MFA policy.
 
> [!TIP]
> Use the [Office 365](concept-conditional-access-cloud-apps.md#office-365) app to target all Office apps and avoid issues with service dependencies in the Office stack.
 
<!-- docutune:ignore "Windows Azure Active Directory" -->
+1 / -13 lines changed
Commit: Remediating in Identity
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: reference
ms.date: 06/12/2025
ms.author: barclayn
ms.custom: it-pro, sfi-ga-nochange
#Customer intent: As a Microsoft Entra administrator, I want to know which role has the least privilege for a given task to make my Microsoft Entra organization more secure.
> | Configure registration | [Authentication Policy Administrator](permissions-reference.md#authentication-policy-administrator) | |
> | Read all configuration | [Security Administrator](permissions-reference.md#security-administrator) | [User Administrator](permissions-reference.md#user-administrator) |
 
## Permissions management least privileged roles
 
Here are the least privileged roles you should use when performing tasks in [Microsoft Entra Permissions Management](../../permissions-management/overview.md).
 
> [!div class="mx-tableFixed"]
> | Task | Least privileged role | Additional roles |
> | ---- | --------------------- | ---------------- |
> | Tenant onboarding | [Permissions Management Administrator](permissions-reference.md#permissions-management-administrator) | |
> | Onboard cloud environments | [Permissions Management Administrator](permissions-reference.md#permissions-management-administrator) | |
> | Assign permissions in Microsoft Entra Permissions Management | [Permissions Management Administrator](permissions-reference.md#permissions-management-administrator) | |
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: reference
ms.date: 06/20/2025
ms.author: barclayn
ms.custom: it-pro, sfi-ga-nochange
#Customer intent: As a Microsoft Entra administrator, I want to know which role has the least privilege for a given task to make my Microsoft Entra organization more secure.
> | Configure registration | [Authentication Policy Administrator](permissions-reference.md#authentication-policy-administrator) | |
> | Read all configuration | [Security Administrator](permissions-reference.md#security-administrator) | [User Administrator](permissions-reference.md#user-administrator) |
 
## Privileged Identity Management least privileged roles
 
Here are the least privileged roles you should use when performing tasks for [Microsoft Entra Privileged Identity Management](../../id-governance/privileged-identity-management/pim-configure.md) in Microsoft Entra ID Governance.
 
 
 
 
 
 
 
+2 / -7 lines changed
Commit: Learn Editor: Update reference-connect-version-history.md
Changes:
Before
After
 
### Breaking Change on Entra Connect Sync
 
>[!IMPORTANT]
> New Microsoft Entra Connect Sync Versions are only available via the Microsoft Entra admin center
>
> Following up on our earlier [What’s New](../../../fundamentals/whats-new.md#general-availability---download-microsoft-entra-connect-sync-on-the-microsoft-entra-admin-center) communication, new versions of Microsoft Entra Connect Sync are only available on theβ€―[Microsoft Entra Connect blade](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/%7E/GetStarted) within Microsoft Entra admin center and are no longer be released to the [Microsoft Download Center](https://www.microsoft.com/en-us/download/details.aspx?id=47594).
 
 
 
> [!WARNING]
> The MSOnline PowerShell [retirement](https://aka.ms/msonlineretirement) will impact the Microsoft Entra Connect Sync wizard in April 2025. You must upgrade your Connect Sync version **by 30 April 2025** to maintain Connect Sync wizard capabilities such as schema refresh, configuration of staging mode, and user-sign in changes. The minimum supported versions are [2.4.18.0](reference-connect-version-history.md#24180) for commercial cloud and [2.4.21.0](reference-connect-version-history.md#24210) for non-commercial clouds, or any newer version. No action is required if your Microsoft Entra Connect Sync server is within the recommended version range. [Learn More](harden-update-ad-fs-pingfederate.md)
 
This release addresses a vulnerability as documented in [this CVE](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36949). For more information about this vulnerability, see the CVE.
 
To download the latest version of Microsoft Entra Connect 2.0, see the [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=47594).
 
### Release status
 
8/10/2021: Released for download only, not available for autoupgrade
 
### Breaking Change on Entra Connect Sync
 
> [!IMPORTANT]
> New Microsoft Entra Connect Sync Versions are only available via the Microsoft Entra admin center
> > Following up on our earlier [What’s New](../../../fundamentals/whats-new.md#general-availability---download-microsoft-entra-connect-sync-on-the-microsoft-entra-admin-center) communication, new versions of Microsoft Entra Connect Sync are only available on theβ€―[Microsoft Entra Connect blade](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/%7E/GetStarted) within Microsoft Entra admin center and are no longer be released to the Microsoft Download Center.
 
> [!WARNING]
> The MSOnline PowerShell [retirement](https://aka.ms/msonlineretirement) will impact the Microsoft Entra Connect Sync wizard in April 2025. You must upgrade your Connect Sync version **by 30 April 2025** to maintain Connect Sync wizard capabilities such as schema refresh, configuration of staging mode, and user-sign in changes. The minimum supported versions are [2.4.18.0](reference-connect-version-history.md#24180) for commercial cloud and [2.4.21.0](reference-connect-version-history.md#24210) for non-commercial clouds, or any newer version. No action is required if your Microsoft Entra Connect Sync server is within the recommended version range. [Learn More](harden-update-ad-fs-pingfederate.md)
 
This release addresses a vulnerability as documented in [this CVE](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36949). For more information about this vulnerability, see the CVE.
 
### Release status
 
8/10/2021: Released for download only, not available for autoupgrade
 
 
 
 
 
+6 / -2 lines changed
Commit: added image for first sign in
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/19/2025
ms.author: justinha
author: justinha
manager: dougeby
>
>By postponing the start date of enforcement, you take extra risk because accounts that access Microsoft services like the Azure portal are highly valuable targets for threat actors. We recommend all tenants set up MFA now to secure cloud resources.
 
If you never previously signed in to the Azure portal with MFA, this screen appears when you sign in. You can either confirm enforcement, or complete the steps to postpone the start date of enforcement for the tenant.
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
 
 
 
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/20/2025
ms.author: justinha
author: justinha
manager: dougeby
>
>By postponing the start date of enforcement, you take extra risk because accounts that access Microsoft services like the Azure portal are highly valuable targets for threat actors. We recommend all tenants set up MFA now to secure cloud resources.
 
If you never previously signed in to the Azure portal with MFA, this screen appears when you sign in. You can either complete MFA to sign in, or postpone MFA enforcement.
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/mandatory.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
If you select **Confirm enforcement**, you'll be guided through the steps to elevate access and set the start date of enforcement for the tenant. If you select **Continue without postponement**, you return to the portal sign-in page.
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
Modified by jenniferf-skc on Jun 21, 2025 6:45 AM
πŸ“– View on learn.microsoft.com
+2 / -6 lines changed
Commit: Remediating in Fundamentals
Changes:
Before
After
manager: pmwongera
ms.service: entra
ms.topic: conceptual
ms.date: 03/05/2025
ms.subservice: fundamentals
ms.author: barclayn
---
## App provisioning
 
[!INCLUDE [App provisioning](../includes/licensing-app-provisioning.md)]
 
## Authentication
 
[!INCLUDE [Authentication](../includes/licensing-authentication.md)]
 
[!INCLUDE [Microsoft Entra monitoring and health](../includes/licensing-monitoring-health.md)]
 
## Microsoft Entra Permissions management
 
Permissions Management supports all resources across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform but only requires licenses for [billable resources](../permissions-management/product-data-billable-resources.md).
manager: pmwongera
ms.service: entra
ms.topic: conceptual
ms.date: 06/20/2025
ms.subservice: fundamentals
ms.author: barclayn
---
## App provisioning
 
[!INCLUDE [App provisioning](../includes/licensing-app-provisioning.md)]
https://dev.azure.com/msft-skilling/Content/_workitems/edit/438678
## Authentication
 
[!INCLUDE [Authentication](../includes/licensing-authentication.md)]
 
[!INCLUDE [Microsoft Entra monitoring and health](../includes/licensing-monitoring-health.md)]
 
## Microsoft Entra Private Access
 
[Microsoft Entra Private access](../global-secure-access/overview-what-is-global-secure-access.md) is available on its own or as part of the Microsoft Entra Suite.
Modified by jenniferf-skc on Jun 21, 2025 6:45 AM
πŸ“– View on learn.microsoft.com
+1 / -7 lines changed
Commit: Remediating in Fundamentals
Changes:
Before
After
ms.service: entra
ms.subservice: fundamentals
ms.topic: overview
ms.date: 07/10/2024
ms.author: barclayn
 
# Customer intent: As a new customer, I want an overview of all Microsoft Entra products including links to get started.
 
### Secure access in any cloud
 
#### Microsoft Entra Permissions Management
 
[Microsoft Entra Permissions Management](~/permissions-management/overview.md) provides comprehensive visibility into permissions assigned to all identities managed by Microsoft Entra ID and other identity providers. It enables organizations to detect, automatically right-size, and continuously monitor unused and excessive permissions across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
 
**For example**, administrators can see the users that have high-risk permissions but aren't using them, and automatically remove those unused permissions across authorization systems.
 
#### Microsoft Entra Workload ID
 
In addition to human and device identities, workload identities such as applications, services, and containers require authentication and authorization policies.
ms.service: entra
ms.subservice: fundamentals
ms.topic: overview
ms.date: 06/20/2025
ms.author: barclayn
 
# Customer intent: As a new customer, I want an overview of all Microsoft Entra products including links to get started.
 
### Secure access in any cloud
 
#### Microsoft Entra Workload ID
 
In addition to human and device identities, workload identities such as applications, services, and containers require authentication and authorization policies.
 
 
 
 
 
 
Modified by jenniferf-skc on Jun 21, 2025 6:26 AM
πŸ“– View on learn.microsoft.com
+2 / -6 lines changed
Commit: Remediating cross-reference mention of Permissions Management due to product deprecation.
Changes:
Before
After
ms.service: entra
ms.subservice: architecture
ms.topic: conceptual
ms.date: 11/12/2024
ms.reviewer: joflore
ms.custom: sfi-ga-nochange
#CustomerIntent: As an identity and security administrator, I want to mitigate security challenges that Generative AI (Gen AI) poses, so that I can ensure organizational security with Microsoft Entra.
 
Microsoft Entra offers a comprehensive suite of capabilities to securely manage AI applications, appropriately control access, and protect sensitive data:
 
- [Microsoft Entra Permissions Management](../permissions-management/overview.md) (MEPM)
- [Microsoft Entra ID Governance](/graph/api/resources/identitygovernance-overview)
- [Microsoft Entra Conditional Access](../identity/conditional-access/overview.md)
- [Microsoft Entra Privileged Identity Management](../id-governance/privileged-identity-management/pim-configure.md) (PIM)
 
### Identify nonhuman accounts
 
Nonhuman accounts have repeatable patterns and are less likely to change over time. When you identify these accounts, consider using [workload or managed identities](../workload-id/workload-identities-overview.md) and Microsoft Entra Permissions Management. Permissions Management is a Cloud Infrastructure Entitlement Management (CIEM) tool. It provides comprehensive visibility into permissions that you assign to all identities across Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
 
Trim roles down to the [Zero Trust](/security/zero-trust/zero-trust-overview) least privilege access security principle. Pay close attention to [super identities](https://techcommunity.microsoft.com/blog/identity/securing-access-to-any-resource-anywhere/4120308) (such as [serverless functions and apps](https://azure.microsoft.com/resources/cloud-computing-dictionary/what-is-serverless-computing)). Factor in use cases for Gen AI applications.
ms.service: entra
ms.subservice: architecture
ms.topic: conceptual
ms.date: 06/20/2025
ms.reviewer: joflore
ms.custom: sfi-ga-nochange
#CustomerIntent: As an identity and security administrator, I want to mitigate security challenges that Generative AI (Gen AI) poses, so that I can ensure organizational security with Microsoft Entra.
 
Microsoft Entra offers a comprehensive suite of capabilities to securely manage AI applications, appropriately control access, and protect sensitive data:
 
- [Microsoft Entra ID Governance](/graph/api/resources/identitygovernance-overview)
- [Microsoft Entra Conditional Access](../identity/conditional-access/overview.md)
- [Microsoft Entra Privileged Identity Management](../id-governance/privileged-identity-management/pim-configure.md) (PIM)
 
### Identify nonhuman accounts
 
Nonhuman accounts have repeatable patterns and are less likely to change over time. When you identify these accounts, consider using [workload or managed identities](../workload-id/workload-identities-overview.md).
 
Trim roles down to the [Zero Trust](/security/zero-trust/zero-trust-overview) least privilege access security principle. Pay close attention to [super identities](https://techcommunity.microsoft.com/blog/identity/securing-access-to-any-resource-anywhere/4120308) (such as [serverless functions and apps](https://azure.microsoft.com/resources/cloud-computing-dictionary/what-is-serverless-computing)). Factor in use cases for Gen AI applications.
 
+2 / -2 lines changed
Commit: Update cross-tenant-synchronization-configure.md
Changes:
Before
After
 
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
 
For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](../app-provisioning/user-provisioning.md). For differences between cross-tenant sychronization and cross-cloud synchronization, see [Cross-cloud synchronization in Frequently asked questions](./cross-tenant-synchronization-overview.md#cross-cloud-synchronization).
 
:::image type="content" source="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png" alt-text="Diagram that shows cross-cloud synchronization between source tenant and target tenant." lightbox="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png":::
::: zone-end
| **Guest** | Users will be created as external guests (B2B collaboration users) in the target tenant. |
 
> [!NOTE]
> If the B2B user already exists in the target tenant, then **Member (userType)** won't changed to **Member**, unless the **Apply this mapping** setting is set to **Always**.
 
The user type you choose has the following limitations for apps or services (but aren't limited to):
 
 
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
 
For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](../app-provisioning/user-provisioning.md). For differences between cross-tenant synchronization and cross-cloud synchronization, see [Cross-cloud synchronization in Frequently asked questions](./cross-tenant-synchronization-overview.md#cross-cloud-synchronization).
 
:::image type="content" source="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png" alt-text="Diagram that shows cross-cloud synchronization between source tenant and target tenant." lightbox="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png":::
::: zone-end
| **Guest** | Users will be created as external guests (B2B collaboration users) in the target tenant. |
 
> [!NOTE]
> If the B2B user already exists in the target tenant, then **Member (userType)** won't be changed to **Member**, unless the **Apply this mapping** setting is set to **Always**.
 
The user type you choose has the following limitations for apps or services (but aren't limited to):
 
Modified by jenniferf-skc on Jun 21, 2025 6:45 AM
πŸ“– View on learn.microsoft.com
+1 / -3 lines changed
Commit: Remediating in Fundamentals
Changes:
Before
After
ms.service: entra
ms.subservice: fundamentals
ms.topic: overview
ms.date: 03/05/2025
ms.author: barclayn
ms.custom: it-pro, sfi-ga-nochange
ms.collection: M365-identity-device-management
 
- **Microsoft Entra ID Governance.** [Microsoft Entra ID Governance](~/id-governance/identity-governance-overview.md) is an advanced set of [identity governance capabilities](~/id-governance/licensing-fundamentals.md) for Microsoft Entra ID P1 and P2 customers.
 
- **Microsoft Entra Permissions Management.** [Microsoft Entra Permissions Management](/entra/permissions-management/) is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities (users and workloads), actions, and resources across cloud infrastructures Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
 
- **"Pay as you go" feature licenses.** You can also get licenses for features such as Microsoft Entra Domain Services, and Microsoft Entra customer identity and access management solution (CIAM). CIAM can help you provide identity and access management solutions for your customer-facing apps. For more information, see our next-generation solution for external identities, [Microsoft Entra External ID](/entra/external-id/).
 
[!INCLUDE [active-directory-b2c-end-of-sale-notice.md](~/includes/active-directory-b2c-end-of-sale-notice.md)]
ms.service: entra
ms.subservice: fundamentals
ms.topic: overview
ms.date: 06/20/2025
ms.author: barclayn
ms.custom: it-pro, sfi-ga-nochange
ms.collection: M365-identity-device-management
 
- **Microsoft Entra ID Governance.** [Microsoft Entra ID Governance](~/id-governance/identity-governance-overview.md) is an advanced set of [identity governance capabilities](~/id-governance/licensing-fundamentals.md) for Microsoft Entra ID P1 and P2 customers.
 
- **"Pay as you go" feature licenses.** You can also get licenses for features such as Microsoft Entra Domain Services, and Microsoft Entra customer identity and access management solution (CIAM). CIAM can help you provide identity and access management solutions for your customer-facing apps. For more information, see our next-generation solution for external identities, [Microsoft Entra External ID](/entra/external-id/).
 
[!INCLUDE [active-directory-b2c-end-of-sale-notice.md](~/includes/active-directory-b2c-end-of-sale-notice.md)]
 
 

πŸ—‘οΈ Deleted Documentation Files

DELETED docs/architecture/permissions-manage-ops-guide-alerts.md
Deleted by jenniferf-skc on Jun 21, 2025 6:27 AM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-alerts
-237 lines removed
Commit: Removing permissions-management articles, adding redirection links
DELETED docs/architecture/permissions-manage-ops-guide-two.md
Deleted by jenniferf-skc on Jun 21, 2025 6:27 AM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-two
-184 lines removed
Commit: Removing permissions-management articles, adding redirection links
DELETED docs/architecture/permissions-manage-ops-guide-three.md
Deleted by jenniferf-skc on Jun 21, 2025 6:27 AM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-three
-118 lines removed
Commit: Removing permissions-management articles, adding redirection links
DELETED docs/architecture/permissions-manage-ops-guide-one.md
Deleted by jenniferf-skc on Jun 21, 2025 6:27 AM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-one
-115 lines removed
Commit: Removing permissions-management articles, adding redirection links
DELETED docs/architecture/permissions-manage-ops-guide-intro.md
Deleted by jenniferf-skc on Jun 21, 2025 6:27 AM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-intro
-63 lines removed
Commit: Removing permissions-management articles, adding redirection links