📋 Microsoft Entra Documentation Changes

Changes for July 5th 2025

Period: July 4th 2025, 12:00 AM to July 5th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on July 5th 2025.

📊 Summary

21
Total Commits
2
New Files
73
Modified Files
0
Deleted Files
13
Contributors

🆕 New Documentation Files

+88 lines added
Commit: ca-toc-070325
+48 lines added
Commit: images

📝 Modified Documentation Files

+7 / -60 lines changed
Commit: ca-toc-070325
Changes:
Before
After
 
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
 
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion, you can have the agent update the associated policy with one click-remediation.
 
## Prerequisites
 
 
:::image type="content" source="media/agent-optimization/start-agent.png" alt-text="Screenshot showing the Conditional Access Optimization agent start agent page." lightbox="media/agent-optimization/start-agent.png":::
 
1. When the agent overview page loads, any suggestions appear in the **Recent suggestions** box. If a suggestion was identified, select **Review suggestion** to see the details, review the policy, determine policy impact, and apply the changes if needed. These options are covered in detail in the [Reviewing results](#reviewing-results) section.
 
:::image type="content" source="media/agent-optimization/review-suggestions.png" alt-text="Screenshot of agent summary and recent suggestions with the review suggestion buttons highlighted." lightbox="media/agent-optimization/review-suggestions.png":::
 
## Reviewing results
 
The agent might run and:
 
- Not identify any unprotected users or recommend any changes
- Suggest creating a new Conditional Access policy in report-only mode
 
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
 
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion you can have the agent update the associated policy with one click-remediation.
 
## Prerequisites
 
 
:::image type="content" source="media/agent-optimization/start-agent.png" alt-text="Screenshot showing the Conditional Access Optimization agent start agent page." lightbox="media/agent-optimization/start-agent.png":::
 
1. When the agent overview page loads, any suggestions appear in the **Recent suggestions** box. If a suggestion was identified, select **Review suggestion** to see the details, review the policy, determine policy impact, and apply the changes if needed. These options are covered in detail in the [Review and approve suggestions](agent-optimization-review-suggestions.md) article.
 
:::image type="content" source="media/agent-optimization/review-suggestions.png" alt-text="Screenshot of agent summary and recent suggestions with the review suggestion buttons highlighted." lightbox="media/agent-optimization/review-suggestions.png":::
 
## Audit and policy logs
 
Policies created or modified by the agent are tagged with **Conditional Access Optimization Agent** in the Conditional Access policies pane.
 
In the **Audit logs** the **Initiated by (actor)** field show the name of the user who started the agent.
 
Modified by Michael Greene on Jul 4, 2025 10:34 AM
📖 View on learn.microsoft.com
+23 / -23 lines changed
Commit: Suggestions from AnnaMHuff
Changes:
Before
After
 
## Configure role assignments
 
A User account in Microsoft Entra must be added to a role assignment in Azure before the user is allowed to sign in to Azure virtual machines or Arc-connected Windows Server. The same roles are use for both Azure virtual machines and Arc-enabled Windows Server.
 
To assign user roles, you must have the [Virtual Machine Data Access Administrator](/azure/role-based-access-control/built-in-roles#virtual-machine-data-access-administrator-preview) role, or any role that includes the `Microsoft.Authorization/roleAssignments/write` action such as the [Role Based Access Control Administrator](/azure/role-based-access-control/built-in-roles#role-based-access-control-administrator-preview) role. However, if you use a different role than Virtual Machine Data Access Administrator, we recommend you [add a condition to reduce the permission to create role assignments](/azure/role-based-access-control/delegate-role-assignments-overview).
 
 
You can sign in over RDP using one of two methods:
 
1. Passwordless using any of the supported Microsoft Entra credentials (recommended)
1. Password/limited passwordless using Windows Hello for Business deployed using certificate trust model
 
<a name='log-in-using-passwordless-authentication-with-azure-ad'></a>
 
 
1. Connect to the device and examine the *CommandExecution.log* file under *C:\WindowsAzure\Logs\Plugins\Microsoft.Azure.ActiveDirectory.AADLoginForWindows\1.0.0.1*.
 
If the extension restarts after the initial failure, the log with the deployment error will be saved as *CommandExecution_YYYYMMDDHHMMSSSSS.log*.
 
 
## Configure role assignments
 
A User account in Microsoft Entra must be added to a role assignment in Azure before the user is allowed to sign in to Azure virtual machines or Arc-connected Windows Server. The same roles are used for both Azure virtual machines and Arc-enabled Windows Server.
 
To assign user roles, you must have the [Virtual Machine Data Access Administrator](/azure/role-based-access-control/built-in-roles#virtual-machine-data-access-administrator-preview) role, or any role that includes the `Microsoft.Authorization/roleAssignments/write` action such as the [Role Based Access Control Administrator](/azure/role-based-access-control/built-in-roles#role-based-access-control-administrator-preview) role. However, if you use a different role than Virtual Machine Data Access Administrator, we recommend you [add a condition to reduce the permission to create role assignments](/azure/role-based-access-control/delegate-role-assignments-overview).
 
 
You can sign in over RDP using one of two methods:
 
- Passwordless using any of the supported Microsoft Entra credentials (recommended)
- Password/limited passwordless using Windows Hello for Business deployed using certificate trust model
 
<a name='log-in-using-passwordless-authentication-with-azure-ad'></a>
 
 
1. Connect to the device and examine the *CommandExecution.log* file under *C:\WindowsAzure\Logs\Plugins\Microsoft.Azure.ActiveDirectory.AADLoginForWindows\1.0.0.1*.
 
If the extension restarts after the initial failure, the log with the deployment error will be saved as *CommandExecution_YYYYMMDDHHMMSSSSS.log*.
 
+3 / -5 lines changed
Commit: images
Changes:
Before
After
- You must have at least the [Microsoft Entra ID P1](overview.md#license-requirements) license.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
- On average, each agent run consumes less than one SCU.
- To activate the agent the first time, you need the [Security Administrator](../role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../role-based-access-control/permissions-reference.md#global-administrator) role during the preview.
- You can assign [Conditional Access Administrators](../role-based-access-control/permissions-reference.md#conditional-access-administrator) with Security Copilot access, which gives your Conditional Access Administrators the ability to use the agent as well.
- For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access)
- Device-based controls require [Microsoft Intune licenses](/intune/intune-service/fundamentals/licenses).
- Review [Privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security)
 
### Limitations
 
From the details panel that opens, select **Policy impact** to see a visualization of the potential impact of the policy.
 
:::image type="content" source="media/agent-optimization/policy-impact-button.png" alt-text="Screenshot of the policy suggestion details with the policy impact button highlighted." lightbox="media/agent-optimization/policy-impact-button.png":::
 
Adjust the filters and the display as needed. Select a point on the graph to see a sample of the data that would be affected by the policy. For example, for a policy to require multifactor authentication (MFA), the graph shows a sample of sign-in events where the Conditional Access policy wasn't applied. For more information, see [Policy impact](concept-conditional-access-report-only.md#reviewing-results).
 
 
To see a detailed summary of the agent's activity and how it calculated the suggestion, select **View agent's full activity**.
 
- You must have at least the [Microsoft Entra ID P1](overview.md#license-requirements) license.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
- On average, each agent run consumes less than one SCU.
- You can assign [Conditional Access Administrators](../role-based-access-control/permissions-reference.md#conditional-access-administrator) with Security Copilot access, which gives your Conditional Access Administrators the ability to use the agent as well.
- For more information, see [Assign Security Copilot access](/copilot/security/authentication#assign-security-copilot-access)
- Review [Privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security)
 
### Limitations
 
From the details panel that opens, select **Policy impact** to see a visualization of the potential impact of the policy.
 
:::image type="content" source="media/agent-optimization-review-suggestions/policy-impact-button.png" alt-text="Screenshot of the policy suggestion details with the policy impact button highlighted." lightbox="media/agent-optimization-review-suggestions/policy-impact-button.png":::
 
Adjust the filters and the display as needed. Select a point on the graph to see a sample of the data that would be affected by the policy. For example, for a policy to require multifactor authentication (MFA), the graph shows a sample of sign-in events where the Conditional Access policy wasn't applied. For more information, see [Policy impact](concept-conditional-access-report-only.md#reviewing-results).
 
 
To see a detailed summary of the agent's activity and how it calculated the suggestion, select **View agent's full activity**.
 
:::image type="content" source="media/agent-optimization-review-suggestions/view-agent-activity-link.png" alt-text="Screenshot of the policy suggestion details with the view agent's full activity link highlighted." lightbox="media/agent-optimization-review-suggestions/view-agent-activity-link.png":::
 
+2 / -2 lines changed
Commit: Update defender-xdr-microsoft-entra-mto.md
Changes:
Before
After
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: overview
ms.date: 03/14/2025
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, DevOps, or it admin, I want to
 
[Learn more](../../id-governance/entitlement-management-organization.md)
 
**Cross-tenant synchronization** allows the source tenant to automate creating, updating, and deleting B2B users across tenants in an organization. Cross-tenant synchronization is only intended to be used within an organization.
 
[Learn more](cross-tenant-synchronization-overview.md)
 
ms.service: entra-id
ms.subservice: multitenant-organizations
ms.topic: overview
ms.date: 07/03/2025
ms.author: kenwith
ms.custom: it-pro
#Customer intent: As a dev, DevOps, or it admin, I want to
 
[Learn more](../../id-governance/entitlement-management-organization.md)
 
**Cross-tenant synchronization** allows the source tenant to automate creating, updating, and deleting B2B users across tenants in an organization.
 
[Learn more](cross-tenant-synchronization-overview.md)
 
+1 / -1 lines changed
Commit: Update plan-connect-performance-factors.md
Changes:
Before
After
 
The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.
 
![Diagram shows how the Connected Directories and Microsoft Entra Connect provisioning engine interact, including Connector Space and Metaverse components in an SQL Database.](media/plan-connect-performance-factors/AzureADConnentInternal.png)
 
The provisioning engine connects to each Active Directory forest and to Microsoft Entra ID. The process of reading information from each directory is called Import. Export refers to updating the directories from the provisioning engine. Sync evaluates the rules of how the objects flow inside the provisioning engine. For a deeper dive, can refer to [Microsoft Entra Connect Sync: Understanding the architecture](./concept-azure-ad-connect-sync-architecture.md).
 
 
The following diagram shows a high-level architecture of provisioning engine connecting to a single forest, although multiple forests are supported. This architecture shows how the various components interact with each other.
 
![Diagram shows how the Connected Directories and Microsoft Entra Connect provisioning engine interact, including Connector Space and Metaverse components in an SQL Database.](media/plan-connect-performance-factors/entra-connect-architecture.png)
 
The provisioning engine connects to each Active Directory forest and to Microsoft Entra ID. The process of reading information from each directory is called Import. Export refers to updating the directories from the provisioning engine. Sync evaluates the rules of how the objects flow inside the provisioning engine. For a deeper dive, can refer to [Microsoft Entra Connect Sync: Understanding the architecture](./concept-azure-ad-connect-sync-architecture.md).
 
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: View a list and description of all system reports available in Permissions Management reports
description: View a list and description of all system reports available in Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: View a list and description of all system reports available in Permissions Management reports
description: View a list and description of all system reports available in Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Error codes when onboarding Permissions Management
description: Understand potential error codes that may appear during onboarding of Microsoft Entra Permissions Management
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: reference
title: Error codes when onboarding Permissions Management
description: Understand potential error codes that may appear during onboarding of Microsoft Entra Permissions Management
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: reference
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Frequently asked questions (FAQs) about Microsoft Entra Permissions Management
description: Frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: faq
title: Frequently asked questions (FAQs) about Microsoft Entra Permissions Management
description: Frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: faq
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Add and remove roles and tasks for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management
description: How to attach and detach permissions for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Add and remove roles and tasks for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management
description: How to attach and detach permissions for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Add or remove a user in Microsoft Entra Permissions Management through the Microsoft Entra admin center
description: How to add or remove a user in Microsoft Entra Permissions Management through the Microsoft Enter admin center.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Add or remove a user in Microsoft Entra Permissions Management through the Microsoft Entra admin center
description: How to add or remove a user in Microsoft Entra Permissions Management through the Microsoft Enter admin center.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard
description: How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard
description: How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Generate an on-demand report from a query in the Audit dashboard in Permissions Management
description: How to generate an on-demand report from a query in the **Audit** dashboard in Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Generate an on-demand report from a query in the Audit dashboard in Permissions Management
description: How to generate an on-demand report from a query in the **Audit** dashboard in Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Clone a role/policy in the Remediation dashboard in Microsoft Entra Permissions Management
description: How to clone a role/policy in Microsoft Entra Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Clone a role/policy in the Remediation dashboard in Microsoft Entra Permissions Management
description: How to clone a role/policy in Microsoft Entra Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
Modified by jenniferf-skc on Jul 4, 2025 4:36 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Configure AWS IAM Identity Center as an identity provider
description: How to configure AWS IAM Identity Center as an identity provider.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Configure AWS IAM Identity Center as an identity provider
description: How to configure AWS IAM Identity Center as an identity provider.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to
+1 / -1 lines changed
Commit: Updating Manager metadata
Changes:
Before
After
title: Configure Okta as an identity provider
description: How to configure Okta as an identity provider in Microsoft Entra Permissions Management.
author: jenniferf-skc
manager: femila
ms.service: entra-permissions-management
 
ms.topic: how-to
title: Configure Okta as an identity provider
description: How to configure Okta as an identity provider in Microsoft Entra Permissions Management.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-permissions-management
 
ms.topic: how-to