📋 Microsoft Entra Documentation Changes

Changes for July 3rd 2025

Period: July 2nd 2025, 12:00 AM to July 3rd 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on July 3rd 2025.

📊 Summary

32
Total Commits
0
New Files
125
Modified Files
0
Deleted Files
15
Contributors

📝 Modified Documentation Files

+50 / -23 lines changed
Commit: PM-updates
Changes:
Before
After
- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.
- **Require device-based controls**: The agent can enforce device-based controls, such as device compliance, app protection policies, and domain-joined devices.
- **Block legacy authentication**: User accounts with legacy authentication are blocked from signing in.
- **Policy consolidation**: The agent scans your policy and identifies overlapping settings. For example, if you have more than one policy that has the same grant controls, the agent suggests consolidating those policies into one.
- **Block device code flow**: The agent looks for a policy blocking device code flow authentication.
 
> [!IMPORTANT]
> The agent only provides the suggestion. It doesn't create or modify policies unless an administrator explicitly approves the suggestion. All new policies created by the agent are created in report-only mode.
 
## Getting started
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator).
1. From the new home page, select **Go to agents** from the agent notification card then select **View details** under the Conditional Access Optimization Agent.
 
:::image type="content" source="media/agent-optimization/conditional-access-optimization-agent-try-now.png" alt-text="Screenshot of the Microsoft Entra admin center showcasing the new Security Copilot agents experience." lightbox="media/agent-optimization/conditional-access-optimization-agent-try-now.png":::
 
1. Select **Run agent** to begin your first run.
 
:::image type="content" source="media/agent-optimization/agent-optimization-start-agent.png" alt-text="Screenshot showing the Conditional Access Optimization Agent configuration page." lightbox="media/agent-optimization/agent-optimization-start-agent.png":::
 
- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.
- **Require device-based controls**: The agent can enforce device-based controls, such as device compliance, app protection policies, and domain-joined devices.
- **Block legacy authentication**: User accounts with legacy authentication are blocked from signing in.
- **Block device code flow**: The agent looks for a policy blocking device code flow authentication.
- **Policy consolidation**: The agent scans your policy and identifies overlapping settings. For example, if you have more than one policy that has the same grant controls, the agent suggests consolidating those policies into one.
 
> [!IMPORTANT]
> The agent only provides the suggestion. It doesn't create or modify policies unless an administrator explicitly approves the suggestion.
>
> All new policies suggested by the agent are created in report-only mode.
 
## Getting started
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator).
1. From the new home page, select **Go to agents** from the agent notification card.
- You can also select **Agents** from the left navigation menu.
 
:::image type="content" source="media/agent-optimization/go-to-agents.png" alt-text="Screenshot of the Microsoft Entra admin center showcasing the new Security Copilot agents experience." lightbox="media/agent-optimization/go-to-agents.png":::
 
1. Select **View details** on the Conditional Access Optimization Agent tile.
+15 / -1 lines changed
Commit: Features available for Activity logs and reports
Changes:
Before
After
ms.service: entra-external-id
ms.subservice: external
ms.topic: concept-article
ms.date: 06/04/2025
ms.custom: it-pro, seo-july-2024, sfi-ropc-nochange
#Customer intent: As a dev, devops, or it admin, I want to learn about features supported in a CIAM tenant.
---
| **Sign-out** | When a [SAML](../../identity-platform/single-sign-out-saml-protocol.md) or [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#send-a-sign-out-request) application directs the user to the logout endpoint, Microsoft Entra ID removes and invalidates the user's session from the browser. | Same as workforce.|
| **Single sign-out**| Upon successful sign-out, Microsoft Entra ID sends a logout notification to all other [SAML](../../identity-platform/single-sign-out-saml-protocol.md) and [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#single-sign-out) applications that the user is signed into. | Same as workforce.|
 
## Microsoft Graph APIs
 
All features that are supported in external tenants are also supported for automation through Microsoft Graph APIs. Some features that are in preview in external tenants might be generally available through Microsoft Graph. For more information, see [Manage Microsoft Entra identity and network access by using Microsoft Graph](/graph/api/resources/identity-network-access-overview).
 
 
 
 
 
 
 
ms.service: entra-external-id
ms.subservice: external
ms.topic: concept-article
ms.date: 07/02/2025
ms.custom: it-pro, seo-july-2024, sfi-ropc-nochange
#Customer intent: As a dev, devops, or it admin, I want to learn about features supported in a CIAM tenant.
---
| **Sign-out** | When a [SAML](../../identity-platform/single-sign-out-saml-protocol.md) or [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#send-a-sign-out-request) application directs the user to the logout endpoint, Microsoft Entra ID removes and invalidates the user's session from the browser. | Same as workforce.|
| **Single sign-out**| Upon successful sign-out, Microsoft Entra ID sends a logout notification to all other [SAML](../../identity-platform/single-sign-out-saml-protocol.md) and [OpenID Connect](../../identity-platform/v2-protocols-oidc.md#single-sign-out) applications that the user is signed into. | Same as workforce.|
 
## Activity logs and reports
 
The table below compares the features available for activity logs and reports across different types of tenants.
 
|Feature |Workforce tenant | External tenant |
|---------|---------|---------|
|[Audit logs](~/identity/monitoring-health/concept-audit-logs.md)|Detailed report of all events logged in Microsoft Entra ID, including modifications to applications, groups, and users.|Same as workforce.|
|[Sign-in logs](~/identity/monitoring-health/concept-sign-ins.md) |The sign-in logs track all sign-in activities within a Microsoft Entra tenant, including access to your applications and resources.|Same as workforce.|
|[Sign-up logs](~/identity/monitoring-health/concept-sign-ups.md) (preview)| Not available|Microsoft Entra External ID logs all self-service sign-up events, including both successful sign-ups and failed attempts. |
| [Provisioning logs](~/identity/monitoring-health/concept-provisioning-logs.md)| The provisioning logs provide detailed records of provisioning events within a tenant, such as user account creations, updates, and deletions.|Not available|
+5 / -4 lines changed
Commit: revision
Changes:
Before
After
title: Learn about the sign-in log activity details
description: Learn about the information available on each of the tabs on the Microsoft Entra sign-in log activity details.
author: shlipsey3
manager: femila
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 05/12/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
 
 
- **Multifactor authentication:** When a user signs in with MFA, several separate MFA events are actually taking place. For example, if a user enters the wrong validation code or doesn't respond in time, more MFA events are sent to reflect the latest status of the sign-in attempt. These sign-in events appear as one line item in the Microsoft Entra sign-in logs. That same sign-in event in Azure Monitor, however, appears as multiple line items. These events all have the same `correlationId`.
 
- **Authentication requirement:** Shows the highest level of authentication reached during the sign-in attempt, but not the highest level of authentication required.
- For sign-in attempts where MFA is required but primary authentication failed, value is `singleFactorAuthentication` because the attempt wasn't evaluated by Conditional Access to require MFA.
- A subsequent sign-in attempt after the failure where primary authentication is successful and MFA is required, the value is `multiFactorAuthentication`.
- Graph API supports `$filter` (`eq` and `startsWith` operators only).
 
- **Sign-in event types:** Indicates the category of the sign-in the event represents.
title: Learn about the sign-in log activity details
description: Learn about the information available on each of the tabs on the Microsoft Entra sign-in log activity details.
author: shlipsey3
manager: pmwongera
ms.service: entra-id
ms.topic: conceptual
ms.subservice: monitoring-health
ms.date: 07/01/2025
ms.author: sarahlipsey
ms.reviewer: egreenberg14
 
 
- **Multifactor authentication:** When a user signs in with MFA, several separate MFA events are actually taking place. For example, if a user enters the wrong validation code or doesn't respond in time, more MFA events are sent to reflect the latest status of the sign-in attempt. These sign-in events appear as one line item in the Microsoft Entra sign-in logs. That same sign-in event in Azure Monitor, however, appears as multiple line items. These events all have the same `correlationId`.
 
- **Authentication requirement:** Shows the authentication requirement requested by the resource provider for the sign-in to succeed. This value commonly reflects the authentication stage reached during the sign-in.
- A subsequent sign-in attempt after the failure where primary authentication is successful and MFA is required, the value is `multiFactorAuthentication`.
- There are some edge cases where this field doesn't reflect the authentication reached during the sign-in. For example, if the requirement is already fulfilled from a previous MFA claim the resource provider doesn't ask to enforce it.
- For sign-in attempts where MFA is required but primary authentication failed, value is `singleFactorAuthentication` because the attempt wasn't evaluated by Conditional Access to require MFA.
- Graph API supports `$filter` (`eq` and `startsWith` operators only).
 
Modified by shlipsey3 on Jul 2, 2025 4:19 AM
📖 View on learn.microsoft.com
+5 / -1 lines changed
Commit: ca-agent-070125
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: overview
ms.date: 03/04/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
Conditional Access policies on the **Policies** page can be filtered by administrators based on items like the actor, target resource, condition, control applied, state, or date. This filtering ability lets administrators find specific policies based on their configuration quickly.
 
## License requirements
 
[!INCLUDE [Active Directory P1 license](~/includes/entra-p1-license.md)]
 
 
 
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: overview
ms.date: 07/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
Conditional Access policies on the **Policies** page can be filtered by administrators based on items like the actor, target resource, condition, control applied, state, or date. This filtering ability lets administrators find specific policies based on their configuration quickly.
 
### Conditional Access optimization agent
 
The [Conditional Access optimization agent](agent-optimization.md) (preview) with Microsoft Security Copilot recommends new policies and changes to existing policies based on Zero Trust principles and Microsoft best practices. With one click, you can apply the suggestion to automatically update or create a Conditional Access policy. The agent requires at least the Microsoft Entra ID P1 license and [security compute units (SCU)](/copilot/security/manage-usage).
 
## License requirements
 
[!INCLUDE [Active Directory P1 license](~/includes/entra-p1-license.md)]
+5 / -0 lines changed
Commit: Verified ID updates
Changes:
Before
After
> If you select multiple credential types from one issuer, users will be required to present credentials of all selected types. Similarly, if you include multiple issuers, users will be required to present credentials from each of the issuers you include in the policy. To give users the option of presenting different credentials from various issuers, configure separate policies for each issuer/credential type you’ll accept.
1. Select **Add** to add the verified ID requirement to the access package policy.
 
1. Once you finish configuring the rest of the settings, you can review your selections on the **Review + create** tab. You can see all verified ID requirements for this access package policy in the **Verified IDs** section.
:::image type="content" source="media/entitlement-management-verified-id-settings/verified-ids-list.png" alt-text="Screenshot of a list of verified IDs.":::
 
:::image type="content" source="media/entitlement-management-verified-id-settings/present-verified-id-access-package.png" alt-text="Screenshot of the present verified ID for access package option.":::
1. Select **Request Access**. You should now see a QR code. Use your phone to scan the QR code. This launches Microsoft Authenticator, where you're prompted to share your credentials.
:::image type="content" source="media/entitlement-management-verified-id-settings/verified-id-qr-code.png" alt-text="Screenshot of use QR code for verified IDs.":::
1. After you share your credentials, My Access will automatically take you to the next step of the request process.
 
 
 
 
 
 
 
> If you select multiple credential types from one issuer, users will be required to present credentials of all selected types. Similarly, if you include multiple issuers, users will be required to present credentials from each of the issuers you include in the policy. To give users the option of presenting different credentials from various issuers, configure separate policies for each issuer/credential type you’ll accept.
1. Select **Add** to add the verified ID requirement to the access package policy.
 
1. If you want users to complete a Face Check, select **Require Face Check**. This will ask users requesting the access package to perform a real-time, privacy compliant selfie check against the photo that is stored on their Verified ID. Once you select the checkbox, it will ask you to select the claim name that maps to the photo on the ID. For more information on Face Check, see [Use Face Check with Microsoft Entra Verified ID](~/verified-id/using-facecheck.md).
 
1. Once you finish configuring the rest of the settings, you can review your selections on the **Review + create** tab. You can see all verified ID requirements for this access package policy in the **Verified IDs** section.
:::image type="content" source="media/entitlement-management-verified-id-settings/verified-ids-list.png" alt-text="Screenshot of a list of verified IDs.":::
 
:::image type="content" source="media/entitlement-management-verified-id-settings/present-verified-id-access-package.png" alt-text="Screenshot of the present verified ID for access package option.":::
1. Select **Request Access**. You should now see a QR code. Use your phone to scan the QR code. This launches Microsoft Authenticator, where you're prompted to share your credentials.
:::image type="content" source="media/entitlement-management-verified-id-settings/verified-id-qr-code.png" alt-text="Screenshot of use QR code for verified IDs.":::
 
1. If Face Check is required for the access package, the requesting user will need to perform a real-time selfie check against the photo stored on their Verified ID. Face Check protects user privacy by sharing only the match results and not any sensitive identity data.
 
1. After you share your credentials, My Access will automatically take you to the next step of the request process.
 
 
+2 / -2 lines changed
Commit: deprecate ropc in dotnet
Changes:
Before
After
 
### [.NET](#tab/dotnet)
 
Changes are required if you use the [Microsoft.Identity.Client](https://www.nuget.org/packages/Microsoft.Identity.Client) package and one of the following APIs in your application:
 
- [IByUsernameAndPassword.AcquireTokenByUsernamePassword](/dotnet/api/microsoft.identity.client.ibyusernameandpassword.acquiretokenbyusernamepassword) (confidential client API)
- [PublicClientApplication.AcquireTokenByUsernamePassword](/dotnet/api/microsoft.identity.client.publicclientapplication.acquiretokenbyusernamepassword) (public client API)
 
### [Go](#tab/go)
 
 
### [.NET](#tab/dotnet)
 
Changes are required if you use the [Microsoft.Identity.Client](https://www.nuget.org/packages/Microsoft.Identity.Client) package and one of the following APIs in your application. The public client API is **deprecated** [as of the 4.73.1 release](https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/blob/main/CHANGELOG.md):
 
- [IByUsernameAndPassword.AcquireTokenByUsernamePassword](/dotnet/api/microsoft.identity.client.ibyusernameandpassword.acquiretokenbyusernamepassword) (confidential client API)
- [PublicClientApplication.AcquireTokenByUsernamePassword](/dotnet/api/microsoft.identity.client.publicclientapplication.acquiretokenbyusernamepassword) (public client API) [deprecated]
 
### [Go](#tab/go)
 
Modified by Ugonna Akali on Jul 2, 2025 7:10 AM
📖 View on learn.microsoft.com
+2 / -1 lines changed
Commit: deprecate ropc in dotnet
Changes:
Before
After
The [OAuth 2.0 resource owner password credentials](v2-oauth-ropc.md) (ROPC) grant allows an application to sign in the user by directly handling their password. In your desktop application, you can use the username/password flow to acquire a token silently. No UI is required when using the application.
 
> [!WARNING]
> The resource owner password credentials (ROPC) flow is NOT recommended. ROPC requires a high degree of trust and credential exposure. *Resort to using ROPC only if a more secure flow can't be used.* For more information, see [What's the solution to the growing problem of passwords?](https://news.microsoft.com/features/whats-solution-growing-problem-passwords-says-microsoft/).
 
In the following diagram, the application:
 
 
The [OAuth 2.0 resource owner password credentials](v2-oauth-ropc.md) (ROPC) grant allows an application to sign in the user by directly handling their password. In your desktop application, you can use the username/password flow to acquire a token silently. No UI is required when using the application.
 
> [!WARNING]
> The ROPC flow has been deprecated, use a more secure flow. Follow [this guide](https://aka.ms/msal-ropc-migration) for migration guidance.
> ROPC requires a high degree of trust and credential exposure.For more information, see [What's the solution to the growing problem of passwords?](https://news.microsoft.com/features/whats-solution-growing-problem-passwords-says-microsoft/).
 
In the following diagram, the application:
 
+1 / -1 lines changed
Commit: Update date
Changes:
Before
After
ms.service: entra-external-id
ms.subservice: external
ms.topic: how-to
ms.date: 06/30/2025
ms.author: gasinh
ms.custom: it-pro
ms.service: entra-external-id
ms.subservice: external
ms.topic: how-to
ms.date: 07/02/2025
ms.author: gasinh
ms.custom: it-pro
Modified by Namsoo Choi on Jul 2, 2025 11:18 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/identity-platform/v2-oauth2-auth-code-flow.md
Changes:
Before
After
 
Redirect URIs for SPAs that use the auth code flow require special configuration.
 
- **Add a redirect URI** that supports auth code flow with PKCE and cross-origin resource sharing (CORS): Follow the steps in [Redirect URI: MSAL.js 2.0 with auth code flow](scenario-spa-app-registration.md#redirect-uri-msaljs-20-with-auth-code-flow).
- **Update a redirect URI**: Set the redirect URI's `type` to `spa` by using the [application manifest editor](reference-microsoft-graph-app-manifest.md) in the Microsoft Entra admin center.
 
 
 
Redirect URIs for SPAs that use the auth code flow require special configuration.
 
- **Add a redirect URI** that supports auth code flow with PKCE and cross-origin resource sharing (CORS): Follow the steps in [How to add a redirect URI to your application](how-to-add-redirect-uri.md).
- **Update a redirect URI**: Set the redirect URI's `type` to `spa` by using the [application manifest editor](reference-microsoft-graph-app-manifest.md) in the Microsoft Entra admin center.
 
 
+0 / -2 lines changed
Commit: Update cross-tenant-synchronization-configure.md
Changes:
Before
After
![Icon for the target tenant.](../../media/common/icons/entra-id.png)<br/>**Target tenant**
 
::: zone pivot="same-cloud-synchronization"
- Microsoft Entra ID P1 or P2 license. For more information, see [License requirements](cross-tenant-synchronization-overview.md#license-requirements).
- [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) role to configure cross-tenant access settings.
::: zone-end
 
::: zone pivot="cross-cloud-synchronization"
- Microsoft Entra ID Governance or Microsoft Entra Suite license. For more information, see [License requirements](cross-tenant-synchronization-overview.md#license-requirements).
- [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) role to configure cross-tenant access settings.
::: zone-end
 
![Icon for the target tenant.](../../media/common/icons/entra-id.png)<br/>**Target tenant**
 
::: zone pivot="same-cloud-synchronization"
- [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) role to configure cross-tenant access settings.
::: zone-end
 
::: zone pivot="cross-cloud-synchronization"
- [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) role to configure cross-tenant access settings.
::: zone-end
 
 
 
Modified by Faith Moraa Ombongi on Jul 2, 2025 1:04 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: July 1 run
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 06/27/2025
ms.custom: include file
---
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/01/2025
ms.custom: include file
---
 
+1 / -1 lines changed
Commit: July 1 run
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 06/27/2025
ms.custom: include file
---
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/01/2025
ms.custom: include file
---
 
+1 / -1 lines changed
Commit: July 1 run
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 06/27/2025
ms.custom: include file
---
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/01/2025
ms.custom: include file
---
 
+1 / -1 lines changed
Commit: July 1 run
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 06/27/2025
ms.custom: include file
---
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/01/2025
ms.custom: include file
---
 
+1 / -1 lines changed
Commit: July 1 run
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 06/27/2025
ms.custom: include file
---
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/01/2025
ms.custom: include file
---