πŸ“‹ Microsoft Entra Documentation Changes

Changes for July 4th 2025

Period: July 3rd 2025, 12:00 AM to July 4th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on July 4th 2025.

πŸ“Š Summary

71
Total Commits
0
New Files
16
Modified Files
0
Deleted Files
20
Contributors

πŸ“ Modified Documentation Files

+365 / -365 lines changed
Commit: fix over-localized issues
Changes:
Before
After
## Microsoft 365 Apps for enterprise
| Attribute Name | User | Comment |
| --- |:---:| --- |
| accountEnabled |X |Defines if an account is enabled. |
| cn |X | |
| displayName |X | |
| objectSID |X |mechanical property. AD user identifier used to maintain sync between Microsoft Entra ID and AD. |
| pwdLastSet |X |mechanical property. Used to know when to invalidate already issued tokens. Used by both password hash sync, pass-through authentication and federation. |
|samAccountName|X| |
| sourceAnchor |X |mechanical property. Immutable identifier to maintain relationship between ADDS and Microsoft Entra ID. |
| usageLocation |X |mechanical property. The user’s country/region. Used for license assignment. |
| userPrincipalName |X |UPN is the login ID for the user. Most often the same as [mail] value. |
 
## Exchange Online
| Attribute Name | User | Contact | Group | Comment |
| --- |:---:|:---:|:---:| --- |
| accountEnabled |X | | |Defines if an account is enabled. |
| altRecipient |X | | |Requires Microsoft Entra Connect build 1.1.552.0 or after. |
| authOrig |X |X |X | |
| c |X |X | | |
## Microsoft 365 Apps for enterprise
| Attribute Name | User | Comment |
| --- |:---:| --- |
| :::no-loc text="accountEnabled"::: | X | Defines if an account is enabled. |
| :::no-loc text="cn"::: | X | |
| :::no-loc text="displayName"::: | X | |
| :::no-loc text="objectSID"::: | X | mechanical property. AD user identifier used to maintain sync between Microsoft Entra ID and AD. |
| :::no-loc text="pwdLastSet"::: | X | mechanical property. Used to know when to invalidate already issued tokens. Used by both password hash sync, pass-through authentication and federation. |
| :::no-loc text="samAccountName"::: | X | |
| :::no-loc text="sourceAnchor"::: | X | mechanical property. Immutable identifier to maintain relationship between ADDS and Microsoft Entra ID. |
| :::no-loc text="usageLocation"::: | X | mechanical property. The user’s country/region. Used for license assignment. |
| :::no-loc text="userPrincipalName"::: | X | UPN is the login ID for the user. Most often the same as [mail] value. |
 
## Exchange Online
| Attribute Name | User | Contact | Group | Comment |
| --- |:---:|:---:|:---:| --- |
| :::no-loc text="accountEnabled"::: | X | | | Defines if an account is enabled. |
| :::no-loc text="altRecipient"::: | X | | | Requires Microsoft Entra Connect build 1.1.552.0 or after. |
| :::no-loc text="authOrig"::: | X | X | X | |
| :::no-loc text="c"::: | X | X | | |
+63 / -44 lines changed
Commit: Revised based on feedback
Changes:
Before
After
- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.
 
> [!IMPORTANT]
> After you enable this capability, your Azure virtual machine / Arc-enabled machine will be Microsoft Entra joined. You can't join them to another domain, like on-premises Active Directory or Microsoft Entra Domain Services. If you need to do so, disconnect the device from Microsoft Entra by uninstalling the extension. In addition, if you deploy a supported golden image, you can enable Microsoft Entra ID authentication installing after the deployment the dedicated extension.
 
## Requirements
 
 
This feature currently supports the following Windows distributions:
 
- Windows 11 with [2022-10 Cumulative Updates for Windows 11 (KB5018418)](https://support.microsoft.com/kb/KB5018418) or later installed.
- Windows 10, version 20H2 or later with [2022-10 Cumulative Updates for Windows 10 (KB5018410)](https://support.microsoft.com/kb/KB5018410) or later installed.
- Windows Server 2022 with [2022-10 Cumulative Update for Microsoft server operating system (KB5018421)](https://support.microsoft.com/kb/KB5018421) or later installed.
 
This feature is now available in the following Azure clouds:
 
- `https://login.chinacloudapi.cn`: Authentication flows.
- `https://pas.chinacloudapi.cn`: Azure role-based access control flows.
 
::: zone pivot="identity-extension-hybrid"
- Use Intune to automate and scale Microsoft Entra join with mobile device management (MDM) autoenrollment of Azure Windows VMs that are part of your virtual desktop infrastructure (VDI) deployments. MDM autoenrollment requires Microsoft Entra ID P1 licenses. Windows Server VMs don't support MDM enrollment.
 
> [!IMPORTANT]
> After you enable this capability, your Azure virtual machine / Arc-enabled machine will be Microsoft Entra joined. You can't join them to another domain, like on-premises Active Directory or Microsoft Entra Domain Services. If you need to do so, disconnect the device from Microsoft Entra by uninstalling the extension. In addition, if you deploy a supported golden image, you can enable Microsoft Entra ID authentication by installing the extension.
 
## Requirements
 
 
This feature currently supports the following Windows distributions:
 
::: zone pivot="identity-extension-vm"
- Windows 11 with [2022-10 Cumulative Updates for Windows 11 (KB5018418)](https://support.microsoft.com/kb/KB5018418) or later installed.
- Windows 10, version 20H2 or later with [2022-10 Cumulative Updates for Windows 10 (KB5018410)](https://support.microsoft.com/kb/KB5018410) or later installed.
- Windows Server 2022 with [2022-10 Cumulative Update for Microsoft server operating system (KB5018421)](https://support.microsoft.com/kb/KB5018421) or later installed.
::: zone-end
 
::: zone pivot="identity-extension-hybrid"
- Windows 11 24H2 and later
- Windows Server 2025 and later, with Desktop Experience.
::: zone-end
+42 / -39 lines changed
Commit: removed preview
Changes:
Before
After
### Configure certificate authorities by using the Microsoft Entra admin center
 
#### Create a PKI container object
1. Create a PKI container object.
1. Sign in to the Microsoft Entra admin center as an [Privilege Authentication Administrator](../role-based-access-control/permissions-reference.md#privileged-authentication-administrator).
1. Browse to **Entra ID** > **Identity Secure Score** > **Public key infrastructure (Preview)**.
1. Click **+ Create PKI**.
1. Enter **Display Name**.
1. Click **Create**.
 
:::image type="content" border="true" source="./media/how-to-certificate-based-authentication/new-public-key-infrastructure.png" alt-text="Diagram of the steps required to create a PKI.":::
 
1. Select **Columns** to add or delete columns.
1. Select **Refresh** to refresh the list of PKIs.
 
#### Delete a PKI container object
1. To delete a PKI, select the PKI and select **Delete**. If the PKI has CAs in it, enter the name of the PKI to acknowledge the deletion of all CAs within it and select **Delete**.
 
:::image type="content" border="true" source="./media/how-to-certificate-based-authentication/new-public-key-infrastructure.png" alt-text="Diagram of the steps required to delete a PKI.":::
 
### Configure certificate authorities by using the Microsoft Entra admin center
 
#### Create a PKI container object
 
To create a PKI container object:
 
1. Sign in to the Microsoft Entra admin center as an [Privilege Authentication Administrator](../role-based-access-control/permissions-referencemd#privileged-authentication-administrator).
1. Browse to **Entra ID** > **Identity Secure Score** > **Public key infrastructure (Preview)**.
1. Click **+ Create PKI**.
1. Enter **Display Name**.
1. Click **Create**.
:::image type="content" border="true" source="./media/how-to-certificate-based-authentication/new-public-key-infrastructure.png" alt-text="Diagram of the steps required tocreate a PKI.":::
1. Select **Columns** to add or delete columns.
1. Select **Refresh** to refresh the list of PKIs.
 
#### Delete a PKI container object
 
To delete a PKI, select the PKI and select **Delete**. If the PKI has CAs in it, enter the name of the PKI to acknowledge the deletion of all CAs within it and select **Delete**.
 
:::image type="content" border="true" source="./media/how-to-certificate-based-authentication/new-public-key-infrastructure.png" alt-text="Diagram of the steps required to delete a PKI.":::
+20 / -13 lines changed
Commit: cleanup
Changes:
Before
After
 
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
 
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. With **one-click remediation**, when the agent identifies a suggestion you can have the agent update the associated policy with one click.
 
## Prerequisites
 
 
The Conditional Access optimization agent scans your tenant for new users and applications and determines if Conditional Access policies are applicable. If the agent finds users or applications that aren't protected by Conditional Access policies, it provides suggested next steps, such as creating or modifying a Conditional Access policy. You can review the suggestion, how the agent identified the solution, and what would be included in the policy.
 
In preview, the policy suggestions reviewed by the agent include:
 
- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.
- **Require device-based controls**: The agent can enforce device-based controls, such as device compliance, app protection policies, and domain-joined devices.
 
1. Select **Start agent** to begin your first run.
- Avoid using an account with a role activated through PIM.
- All logs for the agent will be associated with the user who started the agent.
- A message that says "The agent is starting its first run" appears in the upper-right corner.
- The first run might take a few minutes to complete.
 
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
 
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion you can have the agent update the associated policy with one click-remediation.
 
## Prerequisites
 
 
The Conditional Access optimization agent scans your tenant for new users and applications and determines if Conditional Access policies are applicable. If the agent finds users or applications that aren't protected by Conditional Access policies, it provides suggested next steps, such as creating or modifying a Conditional Access policy. You can review the suggestion, how the agent identified the solution, and what would be included in the policy.
 
In preview, the policy suggestions identified by the agent include:
 
- **Require MFA**: The agent identifies users who aren't covered by a Conditional Access policy that requires MFA and can update the policy.
- **Require device-based controls**: The agent can enforce device-based controls, such as device compliance, app protection policies, and domain-joined devices.
 
1. Select **Start agent** to begin your first run.
- Avoid using an account with a role activated through PIM.
- A message that says "The agent is starting its first run" appears in the upper-right corner.
- The first run might take a few minutes to complete.
- Running the agent doesn't apply any changes.
Modified by omondiatieno on Jul 3, 2025 4:30 AM
πŸ“– View on learn.microsoft.com
+10 / -19 lines changed
Commit: July whatsnew updates
Changes:
Before
After
---
title: What's new in Microsoft Entra application management
description: "This article shows the new and updated documentation for the Microsoft Entra application management."
ms.date: 06/03/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## May 2025
 
### Updated articles
- [Review and take action on admin consent requests](review-admin-consent-requests.md)
- [Tutorial: Configure F5 BIG-IP Access Policy Manager for Kerberos authentication](f5-big-ip-kerberos-advanced.md)
- [Tutorial: Manage certificates for federated single sign-on](tutorial-manage-certificates-for-federated-single-sign-on.md)
 
## March 2025
 
### Updated articles
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 07/02/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## June 2025
 
### Updated articles
 
- [AD FS application migration to move AD FS apps to Microsoft Entra ID](migrate-ad-fs-application-howto.md) - Revised for clarity and conciseness
- [Configure how users consent to applications](configure-user-consent.md) - Added clarity on authorization policies and app consent policies
 
 
## May 2025
 
+12 / -12 lines changed
Commit: added voice messages and revised order
Changes:
Before
After
Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.
Fraud greeting | This is Microsoft. If you are trying to sign in, press the # key to finish signing in. If you are not trying to sign in, press 0 and #.
Fraud reported | We have notified your IT team, no further action is required. For help, please contact your company's IT team. Goodbye.
Activation | script
Authentication denied retry | I'm sorry we can't sign you in at this time. Please try again later.
Retry (Standard) | script
Greeting (Standard) | This is Microsoft. If you are trying to sign in, press the # key to finish signing in.
OTP extension prompt | This is Microsoft. If you are trying to sign in, press the # key to continue.
OTP fraud greeting | This is Microsoft. If you are trying to sign in, press the # key to continue. If you are not trying to sign in, press 0 and #.
OTP fraud confirm | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.
OTP fraud confirmed | We have notified your IT team, no further action is required. For help, please contact your company's IT team. Goodbye.
OTP goodbye | Goodbye.
OTP greeting | This is Microsoft. If you are trying to sign in, press the # key to continue.
OTP last verification code | Again, your code is
Greeting | This is Microsoft. If you are trying to sign in, press the # key to finish signing in.
 
Authentication failed | I'm sorry we can't sign you in at this time. Please try again later.
 
### Set up a custom message
 
Fraud confirmation | If this was not you trying to sign in, protect your account by notifying your IT team by pressing 1.
Fraud greeting | This is Microsoft. If you are trying to sign in, press the # key to finish signing in. If you are not trying to sign in, press 0 and #.
Fraud reported | We have notified your IT team, no further action is required. For help, please contact your company's IT team. Goodbye.
Activation | Thank you for using the Microsoft's sign-in verification system. Please press the # key to finish your verification.
Authentication denied retry | I'm sorry we can't sign you in at this time. Please try again later.
Retry (Standard) | Thank you for using the Microsoft's sign-in verification system. Please press the # key to finish your verification.
Greeting (Standard) | This is Microsoft. If you are trying to sign in, press the # key to finish signing in.
Greeting (PIN) | This is Microsoft. If you are trying to sign in, enter your PIN to finish signing in.
Fraud greeting (PIN) | This is Microsoft. If you are trying to sign in, enter your PIN to finish signing in. If you are not trying to sign in, press 0 and #.
Retry (PIN) | Thank you for using Microsoft's sign-in verification system. Please enter your PIN followed by the # key to finish your verification.
Extension prompt after digits | If already at this extension, press the # key to continue.
Authentication denied | I'm sorry we can't sign you in at this time. Please try again later.
Activation greeting (Standard) | Thank you for using the Microsoft's sign-in verification system. Please press the # key to finish your verification.
Activation retry (Standard)| Thank you for using the Microsoft's sign-in verification system. Please press the # key to finish your verification.
Activation greeting (PIN) | Thank you for using Microsoft's sign-in verification system. Please enter your PIN followed by the # key to finish your verification.
Extension prompt before digits | Thank you for using Microsoft's sign-in verification system. Please transfer this call to extension {0}.
 
 
### Set up a custom message
 
Modified by csmulligan on Jul 3, 2025 7:43 PM
πŸ“– View on learn.microsoft.com
+8 / -13 lines changed
Commit: What's new in June.
Changes:
Before
After
---
title: What's new in Microsoft Entra External ID
description: New and updated documentation for the Microsoft Entra External ID.
ms.date: 06/05/2025
ms.service: entra-external-id
ms.topic: whats-new
 
 
# [External ID in external tenants](#tab/external-tenants)
 
## May 2025
 
### Updated articles
- [Default user permissions in external tenants](customers/reference-user-permissions.md) - Updated default permissions
- [Supported features in workforce and external tenants](customers/concept-supported-features-customers.md) - Added default permissions
 
## February 2025
 
### New articles
 
---
title: What's new in Microsoft Entra External ID
description: New and updated documentation for the Microsoft Entra External ID.
ms.date: 07/04/2025
ms.service: entra-external-id
ms.topic: whats-new
 
 
# [External ID in external tenants](#tab/external-tenants)
 
## June 2025
 
### Updated articles
 
- [Supported features in workforce and external tenants](customers/concept-supported-features-customers.md) - Added activity logs and reports
- [Microsoft Entra External ID training, live demo, and videos](customers/reference-training-videos.md) - Added video on configuring OpenID Connect identity providers
 
## May 2025
 
### Updated articles
+6 / -6 lines changed
Commit: Update concept-authentication-flows.md
Changes:
Before
After
 
## Protocol tracking
 
To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Nondevice code flow or authentication transfer flows can be subject to enforcement of authentication flows policies if the session is protocol tracked.
 
For example:
 
1. You configure a policy to block device code flow everywhere except for SharePoint.
1. You use device code flow to sign-in to SharePoint, as allowed by the configured policy. At this point, the session is considered protocol tracked
1. You try to sign in to Exchange within the context of the same session using any authentication flow not just device code flow.
1. You're blocked by the configured policy due to the protocol tracked state of the session
 
## Sign-in logs
 
 
## Troubleshooting unexpected blocks
 
If you have a sign-in unexpectedly blocked by a Conditional Access policy, you should confirm whether the policy was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, clicking on the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.
 
If device code flow was matched but device code flow wasn't the flow performed for that sign-in, the refresh token was protocol tracked. You can verify this case by clicking on the blocked sign-in and searching for the **Original transfer method** property in the **Basic info** portion of the **Activity details: sign-ins** pane.
 
## Protocol tracking
 
To ensure Conditional Access policies are accurately enforced on specified authentication flows, we use functionality called protocol tracking. This tracking is applied to the session using device code flow or authentication transfer. In these cases, the sessions are considered protocol tracked. Any protocol tracked sessions are subject to policy enforcement if a policy exists. Protocol tracking state is sustained through subsequent refreshes. Given this, it is possible for non device code flow or authentication transfer flows to be subject to enforcement of authentication flows policies.
 
For example:
 
1. You configure a policy to block device code flow everywhere except for SharePoint.
1. You use device code flow to sign-in to SharePoint, as allowed by the configured policy. At this point, the session is considered protocol tracked.
1. You try to sign in to Exchange within the context of the same session using any authentication flow not just device code flow.
1. You're blocked by the configured policy due to the protocol tracked state of the session.
 
## Sign-in logs
 
 
## Troubleshooting unexpected blocks
 
If you have a sign-in unexpectedly blocked by a Conditional Access policy, or you're unexpectedly signed out of a device, you should confirm whether root cause was an authentication flows policy. You can do this confirmation by going to **sign-in logs**, clicking on the blocked sign-in, and then navigating to the **Conditional Access** tab in the **Activity details: sign-ins** pane. If the policy enforced was an authentication flows policy, select the policy to determine which authentication flow was matched.
 
If device code flow was matched but device code flow wasn't the flow performed for that sign-in, the refresh token was protocol tracked. You can verify this case by clicking on the blocked sign-in and searching for the **Original transfer method** property in the **Basic info** portion of the **Activity details: sign-ins** pane. If your configured policy is applied to all applications, you can also determine a protocol tracking related error by searching for the following error code and message: `AADSTS530036: The refresh token is invalid due to authentication flow checks by Conditional Access. Additionally, since the authentication flows policy applies to all applications, the token will never be usable and should be deleted.`.
+2 / -2 lines changed
Commit: Updated author
Changes:
Before
After
---
title: Configurable Token Lifetimes
description: Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
author: rwike77
manager: CelesteDG
ms.author: ryanwi
ms.custom:
ms.date: 05/9/2025
ms.reviewer:
---
title: Configurable Token Lifetimes
description: Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.custom:
ms.date: 05/9/2025
ms.reviewer:
+2 / -2 lines changed
Commit: fix queries, toc link
Changes:
Before
After
> Error code 1002013 indicates an expected (and successful) interrupt of the sign-up flow. [Learn more](howto-troubleshoot-sign-up-errors.md#sign-up-error-codes)
 
- For sign-ups during a date range:
- GETβ€―`https://graph.microsoft.com/v1.0/auditLogs/signUps?&$filter=(createdDateTime ge 2024-01-13T14:13:32Z and createdDateTime le 2024-01-14T17:43:26Z)`
 
- For sign-ups for a specific application:
- GETβ€―`https://graph.microsoft.com/beta/signupLogs/signUps?$filter=appId eq 'AppId'`
 
- For local account sign-ups:
- GET `https://graph.microsoft.com/beta/auditLogs/signUps?$filter=signUpIdentityProvider eq 'Email OTP' or signUpIdentityProvider eq 'Email Password'`
> Error code 1002013 indicates an expected (and successful) interrupt of the sign-up flow. [Learn more](howto-troubleshoot-sign-up-errors.md#sign-up-error-codes)
 
- For sign-ups during a date range:
- GETβ€―`https://graph.microsoft.com/beta/auditLogs/signUps?&$filter=(createdDateTime ge 2024-01-13T14:13:32Z and createdDateTime le 2024-01-14T17:43:26Z)`
 
- For sign-ups for a specific application:
- GETβ€―`https://graph.microsoft.com/beta/auditLogs/signUps?$filter=appId eq 'AppId'`
 
- For local account sign-ups:
- GET `https://graph.microsoft.com/beta/auditLogs/signUps?$filter=signUpIdentityProvider eq 'Email OTP' or signUpIdentityProvider eq 'Email Password'`
+2 / -2 lines changed
Commit: removed preview
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: how-to
ms.date: 03/04/2025
ms.author: justinha
author: vimrang
manager: dougeby
---
# How to configure certificate authorities for Microsoft Entra certificate-based authentication
 
The best way to configure the certificate authorities (CAs) is with the PKI-based trust store (Preview). You can delegate configuration with a PKI-based trust store to least privileged roles. For more information see, [Step 1: Configure the certificate authorities with PKI-based trust store (Preview)](how-to-certificate-based-authentication.md#step-1-configure-the-certificate-authorities-with-pki-based-trust-store).
 
As an alternative, a Global Administrator can follow steps in this topic to configure CAs by using the Microsoft Entra admin center, or Microsoft Graph REST APIs and the supported software development kits (SDKs), such as Microsoft Graph PowerShell.
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: how-to
ms.date: 07/02/2025
ms.author: justinha
author: vimrang
manager: dougeby
---
# How to configure certificate authorities for Microsoft Entra certificate-based authentication
 
The best way to configure the certificate authorities (CAs) is with the PKI-based trust store. You can delegate configuration with a PKI-based trust store to least privileged roles. For more information see, [Step 1: Configure the certificate authorities with PKI-based trust store](how-to-certificate-based-authentication.md#step-1-configure-the-certificate-authorities-with-pki-based-trust-store).
 
As an alternative, a Global Administrator can follow steps in this topic to configure CAs by using the Microsoft Entra admin center, or Microsoft Graph REST APIs and the supported software development kits (SDKs), such as Microsoft Graph PowerShell.
 
Modified by csmulligan on Jul 3, 2025 10:27 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Minor update.
Changes:
Before
After
| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
| For an optimal sign-in experience, federate with identity providers | Whenever possible, federate directly with identity providers to allow invited users to sign in to your shared apps and resources without having to create Microsoft Accounts (MSAs) or Microsoft Entra accounts. You can use the [Google federation feature](google-federation.md) to allow B2B guest users to sign in with their Google accounts. Or, you can use the [SAML/WS-Fed identity provider feature](direct-federation.md) to set up federation with any organization whose identity provider (IdP) supports the SAML 2.0 or WS-Fed protocol. |
| Use the Email one-time passcode feature for B2B guests who can’t authenticate by other means | The [Email one-time passcode](one-time-passcode.md) feature authenticates B2B guest users when they can't be authenticated through other means like Microsoft Entra ID, a Microsoft account (MSA), or Google federation. When the guest user redeems an invitation or accesses a shared resource, they can request a temporary code, which is sent to their email address. Then they enter this code to continue signing in. |
| Add company branding to your sign-in page | You can customize your sign-in page so builds trust and helps B2B guest users recognize your organization during sign-in. Effective July 2025, Microsoft begins rolling out an update to the guest user sign-in experience for B2B collaboration. The rollout continues through the end of 2025. With this update, guest users initially access your organization's branded sign-in page. After entering their email address and selecting **Next**, they're redirected to their own organization's sign-in page to provide their credentials. Following successful authentication in their own organization, guest users are returned to your organization to complete the sign-in process. See how to [add company branding to sign in and Access Panel pages](~/fundamentals/how-to-customize-branding.md). |
| Add your privacy statement to the B2B guest user redemption experience | You can add the URL of your organization's privacy statement to the first time invitation redemption process so that an invited user must consent to your privacy terms to continue. See [How-to: Add your organization's privacy info in Microsoft Entra ID](~/fundamentals/properties-area.yml). |
| Use the bulk invite (preview) feature to invite multiple B2B guest users at the same time | Invite multiple guest users to your organization at the same time by using the bulk invite preview feature in the Azure portal. This feature lets you upload a CSV file to create B2B guest users and send invitations in bulk. See [Tutorial for bulk inviting B2B users](tutorial-bulk-invite.md). |
| Enforce Conditional Access policies for Microsoft Entra multifactor authentication | We recommend enforcing MFA policies on the apps you want to share with partner B2B users. This way, MFA will be consistently enforced on the apps in your tenant regardless of whether the partner organization is using MFA. See [Conditional Access for B2B collaboration users](authentication-conditional-access.md). If you have a close business relationship with an organization and you've verified their MFA practices, you can configure cross-tenant access settings to accept their MFA claims ([learn more](cross-tenant-access-overview.md#organizational-settings)). |
| Use tenant restrictions to control how external accounts are used on your networks and managed devices. | With tenant restrictions, you can prevent your users from using accounts they've created in unknown tenants or accounts they've received from external organizations. We recommend you disallow these accounts and use B2B collaboration instead. |
| For an optimal sign-in experience, federate with identity providers | Whenever possible, federate directly with identity providers to allow invited users to sign in to your shared apps and resources without having to create Microsoft Accounts (MSAs) or Microsoft Entra accounts. You can use the [Google federation feature](google-federation.md) to allow B2B guest users to sign in with their Google accounts. Or, you can use the [SAML/WS-Fed identity provider feature](direct-federation.md) to set up federation with any organization whose identity provider (IdP) supports the SAML 2.0 or WS-Fed protocol. |
| Use the Email one-time passcode feature for B2B guests who can’t authenticate by other means | The [Email one-time passcode](one-time-passcode.md) feature authenticates B2B guest users when they can't be authenticated through other means like Microsoft Entra ID, a Microsoft account (MSA), or Google federation. When the guest user redeems an invitation or accesses a shared resource, they can request a temporary code, which is sent to their email address. Then they enter this code to continue signing in. |
| Add company branding to your sign-in page | You can customize your sign-in page so it's more intuitive for your B2B guest users. See how to [add company branding to sign in and Access Panel pages](~/fundamentals/how-to-customize-branding.md). |
| Add your privacy statement to the B2B guest user redemption experience | You can add the URL of your organization's privacy statement to the first time invitation redemption process so that an invited user must consent to your privacy terms to continue. See [How-to: Add your organization's privacy info in Microsoft Entra ID](~/fundamentals/properties-area.yml). |
| Use the bulk invite (preview) feature to invite multiple B2B guest users at the same time | Invite multiple guest users to your organization at the same time by using the bulk invite preview feature in the Azure portal. This feature lets you upload a CSV file to create B2B guest users and send invitations in bulk. See [Tutorial for bulk inviting B2B users](tutorial-bulk-invite.md). |
| Enforce Conditional Access policies for Microsoft Entra multifactor authentication | We recommend enforcing MFA policies on the apps you want to share with partner B2B users. This way, MFA will be consistently enforced on the apps in your tenant regardless of whether the partner organization is using MFA. See [Conditional Access for B2B collaboration users](authentication-conditional-access.md). If you have a close business relationship with an organization and you've verified their MFA practices, you can configure cross-tenant access settings to accept their MFA claims ([learn more](cross-tenant-access-overview.md#organizational-settings)). |
+1 / -1 lines changed
Commit: Learn Editor: Update reference-sla-performance.md
Changes:
Before
After
| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |
| April | 99.999% | 99.999% | 99.999% | 99.999% | 99.999%*|
| May | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
| June | 99.999% | 99.999% | 99.999% | 99.999% | |
| July | 99.999% | 99.999% | 99.999% | 99.999% | |
| August | 99.999% | 99.999% | 99.999% | 99.999% | |
| September | 99.999% | 99.998% | 99.999% | 99.999% | |
| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% |
| April | 99.999% | 99.999% | 99.999% | 99.999% | 99.999%*|
| May | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
| June | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
| July | 99.999% | 99.999% | 99.999% | 99.999% | |
| August | 99.999% | 99.999% | 99.999% | 99.999% | |
| September | 99.999% | 99.998% | 99.999% | 99.999% | |
Modified by Janice Ricketts on Jul 3, 2025 2:55 AM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update how-to-configure-connectors.md
Changes:
Before
After
- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).
- Make sure the connector server and the web application servers are in the same Active Directory domain or span trusting domains. Having the servers in the same domain or trusting domains is a requirement for using single sign-on (SSO) with integrated Windows authentication (IWA) and Kerberos Constrained Delegation (KCD). If the connector server and web application servers are in different Active Directory domains, use resource-based delegation for single sign-on.
- Consider [performance and scalability](concept-connectors.md#performance-and-scalability) of your connector deployment, including [extending the TCP and UDP ephemeral ports](concept-connectors.md#expanding-ephemeral-port-range) on your connector server. See [Understand the Microsoft Entra private network connector](concept-connectors.md) for more information.
- Consider creating a [performance baseline](~/MicrosoftDocs/SupportArticles-docs-pr/blob/main/support/windows-server/performance/troubleshoot-performance-problems-in-windows) for your private network connectors.
 
### Prepare your on-premises environment
 
- Optimize performance between the connector and the application. Physically locate the connector server close to the application servers. For more information, see [Optimize traffic flow with Microsoft Entra application proxy](../identity/app-proxy/application-proxy-network-topology.md).
- Make sure the connector server and the web application servers are in the same Active Directory domain or span trusting domains. Having the servers in the same domain or trusting domains is a requirement for using single sign-on (SSO) with integrated Windows authentication (IWA) and Kerberos Constrained Delegation (KCD). If the connector server and web application servers are in different Active Directory domains, use resource-based delegation for single sign-on.
- Consider [performance and scalability](concept-connectors.md#performance-and-scalability) of your connector deployment, including [extending the TCP and UDP ephemeral ports](concept-connectors.md#expanding-ephemeral-port-range) on your connector server. See [Understand the Microsoft Entra private network connector](concept-connectors.md) for more information.
- Consider creating a [performance baseline](https://learn.microsoft.com/troubleshoot/windows-server/performance/troubleshoot-performance-problems-in-windows) for your private network connectors.
 
### Prepare your on-premises environment
 
Modified by Matt Dahlgren on Jul 3, 2025 2:26 AM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update getty-images-tutorial.md
Changes:
Before
After
1. If you wish to configure the application in **SP** initiated mode, then perform the following step:
 
In the **Sign on URL** textbox, type the URL:
`https://www.gettyimages.in/sign-in/sso`
 
> [!NOTE]
> The Reply URL value isn't real. Update this value with the actual Reply URL. Contact [Getty Images support team](mailto:[email protected]) to get the value. You can also refer to the patterns shown in the **Basic SAML Configuration** section.
1. If you wish to configure the application in **SP** initiated mode, then perform the following step:
 
In the **Sign on URL** textbox, type the URL:
`https://www.gettyimages.com/sign-in/sso`
 
> [!NOTE]
> The Reply URL value isn't real. Update this value with the actual Reply URL. Contact [Getty Images support team](mailto:[email protected]) to get the value. You can also refer to the patterns shown in the **Basic SAML Configuration** section.