📋 Microsoft Entra Documentation Changes

Changes for June 25th 2025

Period: June 24th 2025, 12:00 AM to June 25th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on June 25th 2025.

📊 Summary

45
Total Commits
0
New Files
19
Modified Files
0
Deleted Files
16
Contributors

📝 Modified Documentation Files

Modified by paulth1 on Jun 24, 2025 6:39 AM
📖 View on learn.microsoft.com
+22 / -22 lines changed
Commit: edit pass: authenticate-application-id
Changes:
Before
After
 
|Event ID|Event name|Description|
|-----|-----|-----|
|2503|Add/Update/Delete directories|Provides the name of the affected directory.|
|2504|Enable Express settings mode| This event is logged after the administrator selects **Express Setup**.|
|2505|Enable/Disable domains and organizational units (OUs) for sync| Shows a list of all domains connected to Microsoft Entra Connect Sync.|
|2506|Enable/Disable password hash synchronization (PHS) sync| Shows that PHS is enabled or disabled.|
|2507|Enable/Disable sync start after installation| Event is logged when sync is enabled or disabled after the installation is finished.|
|2508|Create Active Directory Domain Services (AD DS) account| Shows the created account needed to connect to the new directory added.|
|2509|Use existing ADDS account| Shows the name of the account used to connect to the directory.|
|2510|Create/Update/Delete custom sync rule| Shows the name of the sync rule that changed along with information on what changed.|
|2511|Enable/Disable domain-based filtering|Shows that domain filtering is selected and lists selected domains.|
|2512|Enable/Disable OU-based filtering| Shows that OU-based filtering is selected and lists selected OUs. |
|2513|User sign-in method changed|Shows the old sign-in method and the new one. |
|2514|Configure new Active Directory Federation Services (AD FS) farm| Shows the federation services name.|
|2515|Enable/Disable single sign-on| Shows single sign-on change. |
|2516|Install web application proxy server|Shows selected ADFS servers and the domain admin username.|
|2517|Set permissions| Shows the specific AD Sync permission that changed.|
|2518|Change ADDS Connector credential| Shows the ADDS Connector credential that changed.|
|2519|Reinitialize Entra ID Connector account password| Shows that the AD Sync account password was reset.|
 
|Event ID|Event name|Description|
|-----|-----|-----|
|2503|Add/Update/Delete directories.|Provides the name of the affected directory.|
|2504|Enable Express settings mode.| This event is logged after the administrator selects **Express Setup**.|
|2505|Enable/Disable domains and organizational units (OUs) for sync.| Shows a list of all domains connected to Microsoft Entra Connect Sync.|
|2506|Enable/Disable password hash synchronization (PHS) sync.| Shows that PHS is enabled or disabled.|
|2507|Enable/Disable sync start after installation.| Event is logged when sync is enabled or disabled after the installation is finished.|
|2508|Create Active Directory Domain Services (AD DS) account.| Shows the created account needed to connect to the new directory added.|
|2509|Use existing AD DS account.| Shows the name of the account used to connect to the directory.|
|2510|Create/Update/Delete custom sync rule.| Shows the name of the sync rule that changed along with information on what changed.|
|2511|Enable/Disable domain-based filtering.|Shows that domain filtering is selected and lists selected domains.|
|2512|Enable/Disable OU-based filtering.| Shows that OU-based filtering is selected and lists selected OUs. |
|2513|User sign-in method changed.|Shows the old sign-in method and the new one. |
|2514|Configure new Active Directory Federation Services (AD FS) farm.| Shows the federation services name.|
|2515|Enable/Disable single sign-on.| Shows single sign-on change. |
|2516|Install web application proxy server.|Shows selected AD FS servers and the domain admin username.|
|2517|Set permissions.| Shows the specific ADSync permission that changed.|
|2518|Change AD DS Connector credential.| Shows the AD DS Connector credential that changed.|
|2519|Reinitialize Entra ID Connector account password.| Shows that the ADSync account password was reset.|
+12 / -6 lines changed
Commit: Update cross-tenant-synchronization-configure.md
Changes:
Before
After
 
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
 
For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](../app-provisioning/user-provisioning.md). For differences between cross-tenant synchronization and cross-cloud synchronization, see [Cross-cloud synchronization in Frequently asked questions](./cross-tenant-synchronization-overview.md#cross-cloud-synchronization).
 
:::image type="content" source="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png" alt-text="Diagram that shows cross-cloud synchronization between source tenant and target tenant." lightbox="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png":::
::: zone-end
 
## Common scenarios and solutions
 
#### Symptom - Test connection fails with AzureDirectoryB2BManagementPolicyCheckFailure
 
When configuring cross-tenant synchronization in the source tenant and you test the connection, it fails with the following error message:
 
```
You appear to have entered invalid credentials. Please confirm you are using the correct information for an administrative account.
Error code: AzureDirectoryB2BManagementPolicyCheckFailure
Details: Policy permitting auto-redemption of invitations not configured.
```
 
 
This article describes the steps to configure cross-tenant synchronization between Microsoft clouds, such as Microsoft Azure commercial and Microsoft Azure Government, using the Microsoft Entra admin center. When configured, Microsoft Entra ID automatically provisions and de-provisions B2B users in your target tenant.
 
For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](../app-provisioning/user-provisioning.md). For differences between cross-tenant synchronization and cross-cloud synchronization, see [Cross-cloud synchronization in Frequently asked questions](./cross-tenant-synchronization-overview.md#clouds).
 
:::image type="content" source="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png" alt-text="Diagram that shows cross-cloud synchronization between source tenant and target tenant." lightbox="./media/cross-tenant-synchronization-configure/configure-cross-cloud-diagram.png":::
::: zone-end
 
## Common scenarios and solutions
 
#### Symptom - Test connection fails with AzureActiveDirectoryCrossTenantSyncPolicyCheckFailure
 
When configuring cross-tenant synchronization in the source tenant and you test the connection, it fails with one of the following error messages:
 
```
You appear to have entered invalid credentials. Please confirm you are using the correct information for an administrative account.
Error code: AzureActiveDirectoryCrossTenantSyncPolicyCheckFailure
Details: The source tenant has not enabled automatic user consent with the target tenant. Please enable the outbound cross-tenant access policy for automatic user consent in the source tenant. aka.ms/TroubleshootingCrossTenantSyncPolicyCheck
```
 
+6 / -10 lines changed
Commit: edit pass: authenticate-application-id
Changes:
Before
After
 
When you configure group writeback, a checkbox appears at the bottom of the configuration window. Select it to enable this feature.
 
> [!NOTE]
> Groups that are written back from Microsoft Entra ID to Active Directory have a source of authority in the cloud. Any changes made on-premises to groups that are written back from Microsoft Entra ID are overwritten in the next sync cycle.
 
:::image type="content" source="media/how-to-connect-group-writeback/optional-group-writeback-1.png" alt-text="Screenshot that shows selecting the Writeback group Distinguished Name with cloud Display Name option." lightbox="media/how-to-connect-group-writeback/optional-group-writeback-1.png":::
 
1. On the **Ready to configure** page, select **Configure**.
1. When the wizard is complete, on the **Configuration complete** page, select **Exit**.
1. Open the Azure Active Directory Connect wizard and go to the **Additional tasks** page. Select the **Customize synchronization options** task and select **Next**.
1. On the **Optional features** page, clear the **Group writeback** checkbox. A warning states that you are about to delete groups. Select **Yes**.
 
> [!IMPORTANT]
> Disabling group writeback causes any groups that this feature created previously to be deleted from your local Active Directory on the next sync cycle.
 
![Screenshot that shows the Group writeback checkbox to clear.](media/how-to-connect-group-writeback/group-1.png)
 
1. Select **Next**.
1. Select **Configure**.
 
When you configure group writeback, a checkbox appears at the bottom of the configuration window. Select it to enable this feature.
 
Groups that are written back from Microsoft Entra ID to Active Directory have a source of authority in the cloud. Any changes made on-premises to groups that are written back from Microsoft Entra ID are overwritten in the next sync cycle.
 
:::image type="content" source="media/how-to-connect-group-writeback/optional-group-writeback-1.png" alt-text="Screenshot that shows selecting the Writeback group Distinguished Name with cloud Display Name option." lightbox="media/how-to-connect-group-writeback/optional-group-writeback-1.png":::
 
1. On the **Ready to configure** page, select **Configure**.
1. When the wizard is complete, on the **Configuration complete** page, select **Exit**.
1. Open the Azure Active Directory Connect wizard and go to the **Additional tasks** page. Select the **Customize synchronization options** task and select **Next**.
1. On the **Optional features** page, clear the **Group writeback** checkbox. A warning states that you are about to delete groups. Select **Yes**.
 
Disabling group writeback causes any groups that this feature created previously to be deleted from your local Active Directory on the next sync cycle.
 
![Screenshot that shows the Group writeback checkbox to clear.](media/how-to-connect-group-writeback/group-1.png)
 
1. Select **Next**.
1. Select **Configure**.
 
Disabling group writeback sets the `Full Import` and `Full Synchronization` flags to `true` on the Azure Active Directory Connector. The rule changes propagate through on the next sync cycle and delete the groups that were previously written back to your Active Directory.
+3 / -12 lines changed
Commit: Update cross-tenant-synchronization-overview.md
Changes:
Before
After
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: overview
ms.date: 06/20/2025
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
 
- Cross-tenant synchronization is supported within the commercial cloud and Azure Government.
- Cross-tenant synchronization isn't supported within the Microsoft Azure operated by 21Vianet cloud.
 
What cloud pairs are supported for cross-tenant synchronization?
 
- Cross-tenant synchronization supports these cloud pairs:
 
[!INCLUDE [cross-tenant-synchronization-cloud-pairs-include](../../includes/cross-tenant-synchronization-cloud-pairs-include.md)]
 
#### Cross-cloud synchronization
 
Is [cross-cloud synchronization](cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization) supported?
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: overview
ms.date: 06/23/2025
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, devops, or it admin, I want to
 
- Cross-tenant synchronization is supported within the commercial cloud and Azure Government.
- Cross-tenant synchronization isn't supported within the Microsoft Azure operated by 21Vianet cloud.
- For information about the relationship between the Azure Cloud environments and Microsoft 365 (GCC, GCCH), see [Microsoft 365 integration](/azure/security/fundamentals/feature-availability#microsoft-365-integration). Synchronization between commercial and GCC is supported.
 
Is [cross-cloud synchronization](cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization) supported?
 
- Cross-cloud synchronization (such as public cloud to Azure Government) is currently in public preview.
 
What cloud pairs are supported for cross-cloud synchronization?
 
 
 
+7 / -8 lines changed
Commit: edit pass: authenticate-application-id
Changes:
Before
After
Entra Connect provides three options for application and certificate management:
 
- [Managed by Microsoft Entra Connect (recommended)](#managed-by-microsoft-entra-connect-recommended)
- [Bring Your Own Application (BYOA)](#bring-your-own-application-byoa)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate-byoc)
 
## Managed by Microsoft Entra Connect (recommended)
 
The following extra requirements are needed for the BYOC certificate management option:
 
- A certificate is created in an HSM or TPM by using a Cryptography API: Next Generation provider. The private key is marked as nonexportable. A warning event 1014 is emitted if TPM isn't used. The following certificate configurations are supported:
 
- `KeyLength`: 2048
- `KeyAlgorithm`: RSA
- `KeyHashAlgorithm`: SHA256
Set-ADSyncScheduler -SyncCycleEnabled $true
```
 
1. [Remove the Directory Synchronization Account (DSA) from Entra ID (recommended)](#remove-legacy-service-account-using-powershell).
 
Entra Connect provides three options for application and certificate management:
 
- [Managed by Microsoft Entra Connect (recommended)](#managed-by-microsoft-entra-connect-recommended)
- [Bring Your Own Application (BYOA)](#bring-your-own-application)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate)
 
## Managed by Microsoft Entra Connect (recommended)
 
The following extra requirements are needed for the BYOC certificate management option:
 
- A certificate is created in an HSM or TPM by using a Cryptography API: Next Generation provider. The private key is marked as nonexportable. A warning event 1014 is emitted if TPM isn't used. The following certificate configurations are supported:
- `KeyLength`: 2048
- `KeyAlgorithm`: RSA
- `KeyHashAlgorithm`: SHA256
Set-ADSyncScheduler -SyncCycleEnabled $true
```
 
1. [Remove the Directory Synchronization Account (DSA) from Entra ID (recommended)](#remove-a-legacy-service-account-by-using-powershell).
 
## View the certificate
Modified by shlipsey3 on Jun 24, 2025 7:54 AM
📖 View on learn.microsoft.com
+9 / -3 lines changed
Commit: branding-update-062325
Changes:
Before
After
title: Add company branding to your organization's sign-in page
description: Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
author: shlipsey3
manager: femila
ms.service: entra
ms.subservice: fundamentals
ms.topic: how-to
ms.date: 05/27/2025
ms.author: sarahlipsey
ms.reviewer: almars
ms.custom: sfi-image-nochange
# Customer intent: As a Microsoft Entra administrator, I want to customize the sign-in experience for my organization's users so that I can provide a consistent look and feel across all sign-ins.
---
 
There are some scenarios for you to consider when you customize the sign-in pages for your organization's tenant-specific applications.
 
### Software as a Service (SaaS) and multitenant applications
 
For Microsoft, Software as a Service (SaaS), and multitenant applications such as <https://myapps.microsoft.com>, or <https://outlook.com>, the customized sign-in page appears only after the user types their **Email** or **Phone number** and selects the **Next** button.
 
title: Add company branding to your organization's sign-in page
description: Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
author: shlipsey3
manager: pmwongera
ms.service: entra
ms.subservice: fundamentals
ms.topic: how-to
ms.date: 06/23/2025
ms.author: sarahlipsey
ms.reviewer: mkokkalera
ms.custom: sfi-image-nochange
# Customer intent: As a Microsoft Entra administrator, I want to customize the sign-in experience for my organization's users so that I can provide a consistent look and feel across all sign-ins.
---
 
There are some scenarios for you to consider when you customize the sign-in pages for your organization's tenant-specific applications.
 
### Default background image
 
The default background image behind the sign-in box is changing later this year. The change is only to the image and requires no action and doesn't change any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).
 
Modified by Jackline Omondi on Jun 24, 2025 6:48 PM
📖 View on learn.microsoft.com
+4 / -4 lines changed
Commit: Add customer feedback
Changes:
Before
After
 
:::zone pivot="ms-powershell"
 
## Understand authorization and permission grant policies in Microsoft Graph PowerShell
 
To configure user consent settings programmatically using Microsoft Graph PowerShell, it's important to understand the distinction between the tenant-wide **authorization policy** and individual **permission grant policies**. The `authorizationPolicy`, retrieved using [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy) governs global settings such as whether users can consent to apps and which permission grant policies are assigned to the default user role. For example, you can disable user consent while still allowing developers to manage permissions for the apps they own by assigning only `ManagePermissionGrantsForOwnedResource.DeveloperConsent` in the `permissionGrantPoliciesAssigned` collection.
 
On the other hand, the [permissionGrantPolicies](/powershell/module/microsoft.graph.identity.signins/get-mgpolicypermissiongrantpolicy) endpoint, lists all defined consent policies in the tenant. These policies determine the specific types of app permissions that users are allowed to grant—such as low-risk delegated permissions. For instance, a policy like `UserConsentLowRisk` might allow users to consent only to apps that request basic profile information, while a custom policy could restrict consent even further or broaden it for specific user groups.
 
> [!NOTE]
> Before updating consent settings with a `Update-MgPolicyPermissionGrantPolicy` command, always retrieve the current `authorizationPolicy` to identify which permission grant policies are already assigned. This ensures you preserve necessary permissions—such as those enabling developers to manage consent for apps they own—and avoid unintentionally removing existing functionality.
 
:::zone pivot="ms-graph"
 
## Understand authorization and permission grant policies in Microsoft Graph
 
To configure user consent settings programmatically using Microsoft Graph, it's important to understand the distinction between the tenant-wide **authorization policy** and individual **permission grant policies**. The `authorizationPolicy` (retrieved using `GET https://graph.microsoft.com/v1.0/policies/authorizationPolicy/authorizationPolicy`) governs global settings such as whether users can consent to apps and which permission grant policies are assigned to the default user role. For example, you can disable user consent while still allowing developers to manage permissions for the apps they own by assigning only `ManagePermissionGrantsForOwnedResource.DeveloperConsent` in the `permissionGrantPoliciesAssigned` collection.
 
On the other hand, the `permissionGrantPolicies` endpoint (`GET https://graph.microsoft.com/v1.0/policies/permissionGrantPolicies`) lists all defined consent policies in the tenant. These policies determine the specific types of app permissions that users are allowed to grant—such as low-risk delegated permissions. For instance, a policy like `UserConsentLowRisk` might allow users to consent only to apps that request basic profile information, while a custom policy could restrict consent even further or broaden it for specific user groups.
 
 
:::zone pivot="ms-powershell"
 
### Understand authorization and permission grant policies in Microsoft Graph PowerShell
 
To configure user consent settings programmatically using Microsoft Graph PowerShell, it's important to understand the distinction between the tenant-wide **authorization policy** and individual **permission grant policies**. The `authorizationPolicy`, retrieved using [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy) governs global settings such as whether users can consent to apps and which permission grant policies are assigned to the default user role. For example, you can disable user consent while still allowing developers to manage permissions for the apps they own by assigning only `ManagePermissionGrantsForOwnedResource.DeveloperConsent` in the `permissionGrantPoliciesAssigned` collection.
 
On the other hand, the [permissionGrantPolicies](/powershell/module/microsoft.graph.identity.signins/get-mgpolicypermissiongrantpolicy) endpoint lists your current permission grant policies. These policies determine what permissions can be granted to applications and under what circumstances. Each policy 'includes' certain conditions, but 'excludes' others. When a user tries to consent to an application, the system checks the permission grant policies to see if any of them apply to the user's request. For example, the low-risk policy would allow users to consent to those permissions configured as 'low risk'. It includes these low-risk policies (as a GUID). In another scenario, if a user tries to consent in a context that matches the 'AdminOnly' policy, they're unable to consent.
 
> [!NOTE]
> Before updating consent settings with a `Update-MgPolicyPermissionGrantPolicy` command, always retrieve the current `authorizationPolicy` to identify which permission grant policies are already assigned. This ensures you preserve necessary permissions—such as those enabling developers to manage consent for apps they own—and avoid unintentionally removing existing functionality.
 
:::zone pivot="ms-graph"
 
### Understand authorization and permission grant policies in Microsoft Graph
 
To configure user consent settings programmatically using Microsoft Graph, it's important to understand the distinction between the tenant-wide **authorization policy** and individual **permission grant policies**. The `authorizationPolicy` (retrieved using `GET https://graph.microsoft.com/v1.0/policies/authorizationPolicy/authorizationPolicy`) governs global settings such as whether users can consent to apps and which permission grant policies are assigned to the default user role. For example, you can disable user consent while still allowing developers to manage permissions for the apps they own by assigning only `ManagePermissionGrantsForOwnedResource.DeveloperConsent` in the `permissionGrantPoliciesAssigned` collection.
 
On the other hand, the `permissionGrantPolicies` endpoint (`GET https://graph.microsoft.com/v1.0/policies/permissionGrantPolicies`) lists your current permission grant policies. These policies determine what permissions can be granted to applications and under what circumstances. Each policy 'includes' certain conditions, but 'excludes' others. When a user tries to consent to an application, the system checks the permission grant policies to see if any of them apply to the user's request. For example, the low-risk policy would allow users to consent to those permissions configured as 'low risk'. It includes these low-risk policies (as a GUID). In another scenario, if a user tries to consent in a context that matches the 'AdminOnly' policy, they're unable to consent.
 
Modified by shlipsey3 on Jun 24, 2025 9:31 AM
📖 View on learn.microsoft.com
+4 / -4 lines changed
Commit: security-recs-062325
Changes:
Before
After
manager: pmwongera
ms.service: entra-id
ms.topic: include
ms.date: 02/03/2025
ms.custom: Identity-Secure-Recommendation
# category:
# risklevel:
# userimpact:
# implementationcost:
---
External user accounts are often used to provide access to business partners who belong to organizations that have a business relationship with your organization. If these accounts are compromised in their organization, attackers can use the valid credentials to gain initial access to your environment, often bypassing traditional defenses due to their legitimacy.
 
manager: pmwongera
ms.service: entra-id
ms.topic: include
ms.date: 06/23/2025
ms.custom: Identity-Secure-Recommendation
# category:
# risklevel: medium
# userimpact: medium
# implementationcost: medium
---
External user accounts are often used to provide access to business partners who belong to organizations that have a business relationship with your organization. If these accounts are compromised in their organization, attackers can use the valid credentials to gain initial access to your environment, often bypassing traditional defenses due to their legitimacy.
 
Modified by Ortagus Winfrey on Jun 24, 2025 12:58 AM
📖 View on learn.microsoft.com
+4 / -4 lines changed
Commit: Licensing for guest update
Changes:
Before
After
 
### How can I license usage of Microsoft Entra ID Governance features for business guests?
 
All users who are in scope of Microsoft Entra ID Governance features, including business guests such as contractors, partners, and external collaborators, need a license. We're creating a new Microsoft Entra ID Governance license for business guests. This license operates on a monthly active usage (MAU) model. Customers are able to acquire licenses matching their anticipated business guest MAU.
 
We anticipate making these licenses available in the second quarter (Q2) of 2025. In the interim, organizations that govern the identities of their employees with Microsoft Entra ID Governance can govern the identities of their business guests for no additional cost. At this time, existing customers of Microsoft Entra ID P1 or P2 with Microsoft Entra External ID can continue using the subset of features that are included in P1 or P2 with their business guests through their Microsoft Entra External ID license.
 
For more information, see: [Microsoft Entra ID Governance licensing for business guests](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/microsoft-entra-id-governance-licensing-for-business-guests/ba-p/3575579).
 
### What happens to PIM when a license expires?
 
 
### How can I license usage of Microsoft Entra ID Governance features for business guests?
 
Microsoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees and requires an Azure subscription.
Under the guest billing model, guests are identified by a *userType* of Guest regardless of where the user authenticates. A *userType* of Guest is the default userType for all B2B invitation methods and can also be set by an Identity administrator. The bill for each month includes a record for each guest user with one or more governance actions in that month. See the Azure pricing page for pricing details.
 
For more information, see: [Microsoft Entra ID Governance licensing for guest users](microsoft-entra-id-governance-licensing-for-guest-users.md).
 
### What happens to PIM when a license expires?
 
+4 / -3 lines changed
Commit: revised description of how to change start date
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/20/2025
ms.author: justinha
author: justinha
manager: dougeby
>
>By postponing the start date of enforcement, you take extra risk because accounts that access Microsoft services like the Azure portal are highly valuable targets for threat actors. We recommend all tenants set up MFA now to secure cloud resources.
 
If you never previously signed in to the Azure portal with MFA, you're prompted to complete MFA to sign in, or postpone MFA enforcement. For more information about how to set up MFA, see [How to verify that users are set up for mandatory MFA](how-to-mandatory-multifactor-authentication.md).
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/mandatory.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
If you select **Postpone MFA**, you're guided through the steps to elevate access and set the start date of enforcement for the tenant. To confirm that you want to proceed with the postponement request, click **Confirm postponement**.
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
## FAQs
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/23/2025
ms.author: justinha
author: justinha
manager: dougeby
>
>By postponing the start date of enforcement, you take extra risk because accounts that access Microsoft services like the Azure portal are highly valuable targets for threat actors. We recommend all tenants set up MFA now to secure cloud resources.
 
If you never previously signed in to the Azure portal with MFA, you're prompted to complete MFA to sign in, or postpone MFA enforcement. This screen is displayed only once. For more information about how to set up MFA, see [How to verify that users are set up for mandatory MFA](how-to-mandatory-multifactor-authentication.md).
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/mandatory.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
If you select **Postpone MFA**, the date of NFA enforcement will be one month in the future, or Sept 30, 2025, whichever is earlier. After you sign in, you can change the date at [https://aka.ms/managemfaforazure](https://aka.ms/managemfaforazure). To confirm that you want to proceed with the postponement request, click **Confirm postponement**.
 
:::image type="content" border="true" source="media/concept-mandatory-multifactor-authentication/postpone.png" alt-text="Screenshot of how to postpone mandatory MFA."
 
 
## FAQs
+2 / -2 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs#441018
Changes:
Before
After
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).
 
1. Browse to **Entra ID** > **Overview**.
 
1. Select the **Recommendations** tab and select the **Renew expiring application credentials** recommendation.
 
- [Review the Microsoft Entra recommendations overview](overview-recommendations.md)
- [Learn how to use Microsoft Entra recommendations](howto-use-recommendations.md)
- [Explore the Microsoft Graph API properties for recommendations](/graph/api/resources/recommendation)
- [Learn about app and service principal objects in Microsoft Entra ID](../../identity-platform/app-objects-and-service-principals.md)
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#search-administrator).
 
1. Browse to **Identity** > **Overview**.
 
1. Select the **Recommendations** tab and select the **Renew expiring application credentials** recommendation.
 
- [Review the Microsoft Entra recommendations overview](overview-recommendations.md)
- [Learn how to use Microsoft Entra recommendations](howto-use-recommendations.md)
- [Explore the Microsoft Graph API properties for recommendations](/graph/api/resources/recommendation)
- [Learn about app and service principal objects in Microsoft Entra ID](../../identity-platform/app-objects-and-service-principals.md)
Modified by v-sashankar on Jun 24, 2025 3:47 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Update confluencemicrosoft-tutorial.md
Changes:
Before
After
- Confluence: 6.0.1 to 6.15.9
- Confluence: 7.0.1 to 7.20.3
- Confluence: 8.0.0 to 8.9.8
- Confluence: 9.0.1 to 9.4.1
 
> [!NOTE]
> Please note that our Confluence Plugin also works on Ubuntu Version 16.04
 
## Scenario description
 
- Confluence: 6.0.1 to 6.15.9
- Confluence: 7.0.1 to 7.20.3
- Confluence: 8.0.0 to 8.9.8
- Confluence: 9.0.1 to 9.5.1
 
> [!NOTE]
> Please note that our Confluence Plugin was last supported on **Ubuntu 16.04**, which is no longer supported. The plugin now supports **only Windows**.
 
## Scenario description
 
+2 / -2 lines changed
Commit: June 23 revised the Intune URL
Changes:
Before
After
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/20/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
|HideQuitButton |Boolean |false = shown true = hidden |hidden |Set this value to show or hide the **Quit** action. When visible, the user can quit the Global Secure Access client, which closes the client application. To open it again, run the Global Secure Access application from Finder. |
 
You can also configure the client system tray icon menu with Microsoft Intune:
1. Follow the instructions to [Create the profile](../intune/intune-service/configuration/preference-file-settings-macos#create-the-profile).
1. For **Preference domain name**, enter `com.microsoft.globalsecureaccess`.
1. For **Property list file**, upload an XML file similar to the following sample. Revise the XML to match your preferences.
 
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 06/23/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
|HideQuitButton |Boolean |false = shown true = hidden |hidden |Set this value to show or hide the **Quit** action. When visible, the user can quit the Global Secure Access client, which closes the client application. To open it again, run the Global Secure Access application from Finder. |
 
You can also configure the client system tray icon menu with Microsoft Intune:
1. Follow the instructions to [Create the profile](../mem/intune-service/configuration/preference-file-settings-macos#create-the-profile).
1. For **Preference domain name**, enter `com.microsoft.globalsecureaccess`.
1. For **Property list file**, upload an XML file similar to the following sample. Revise the XML to match your preferences.
 
Modified by Sudhakaran-S-micro on Jun 24, 2025 6:07 PM
📖 View on learn.microsoft.com
+0 / -3 lines changed
Commit: Attribute changes are done
Changes:
Before
After
|name.givenName|String||&check;|
|name.familyName|String||&check;|
|emails[type eq "work"].value|String||&check;|
|userType|String|||
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String|||
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization|String|||
 
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
 
|name.givenName|String||&check;|
|name.familyName|String||&check;|
|emails[type eq "work"].value|String||&check;|
 
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
 
 
 
 
Modified by Sudhakaran-S-micro on Jun 24, 2025 6:07 PM
📖 View on learn.microsoft.com
+3 / -0 lines changed
Commit: Attribute changes are done
Changes:
Before
After
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber|String||&check;
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department|String||&check;
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager|String||
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).
 
 
 
 
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber|String||&check;
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department|String||&check;
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager|String||
|userType|String||
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division|String||
|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization|String||
1. To configure scoping filters, refer to the following instructions provided in the [Scoping filter article](~/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md).