📋 Microsoft Entra Documentation Changes

Changes for July 9th 2025

Period: July 8th 2025, 12:00 AM to July 9th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on July 9th 2025.

📊 Summary

30
Total Commits
0
New Files
52
Modified Files
0
Deleted Files
11
Contributors

📝 Modified Documentation Files

+327 / -65 lines changed
Commit: July 07 new pull request for Netskope
Changes:
Before
After
---
title: Learn about integrations between Microsoft and Netskope.
description: A comprehensive guide for configuring and testing the integration between Microsoft's and Netskope's Secure Access Service Edge (SASE) solutions.
author: kenwith
ms.author: kenwith
manager: dougeby
ms.topic: concept-article
ms.date: 02/21/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.reviewer: feperezc
ai-usage: ai-assisted
#customer intent: As a administrator, I want to understand the integration between Microsoft and Netskope SASE solutions so that I can decide on using both and how they will integrate.
---
 
# Learn about Secure Access Service Edge (SASE) integrations between Microsoft and Netskope (Preview)
The integration between Microsoft and Netskope's Secure Access Service Edge (SASE) solutions enhances security and simplifies network traffic management. By combining Microsoft Entra Internet Access with Netskope Advanced Threat Protection (ATP), administrators can securely and efficiently manage threats for internet traffic. This integration involves several steps: configuring prerequisites, installing and configuring the Global Secure Access client, enabling internet access traffic profiles, setting up Transport Layer Security (TLS) termination, creating and linking Netskope ATP policies to Global Secure Access Security Profiles, and thorough testing and monitoring. The collaboration provides a strong security framework for organizations using Microsoft but want to enjoy Netskope Advance Threat Protection functionality.
 
> [!NOTE]
> Previews are made available to you under the terms applicable to previews, which are outlined in the overall Microsoft Product Terms for [online services](https://www.microsoft.com/licensing/terms/product/ForOnlineServices/all).
---
title: "Global Secure Access: Advanced Threat Protection (Preview)"
description: "Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope."
author: HULKsmashGithub
ms.author: jayrusso
ms.service: global-secure-access
ms.topic: how-to
ms.date: 07/07/2025
manager: dougeby
ms.reviewer: abhijeetsinha
ai-usage: ai-assisted
 
#customer intent: As an IT administrator, I want to configure Advanced Threat Protection and Data Loss Prevention policies so that I can protect my organization from malware and data leaks.
---
# Protect your organization with Global Secure Access Advanced Threat Protection (preview)
 
In today's evolving threat landscape, organizations face challenges protecting sensitive data and systems from cyberattacks. Global Secure Access Advanced Threat Protection (ATP) combines Microsoft Security Service Edge (SSE) with Netskope's advanced threat detection and data loss prevention (DLP) capabilities to deliver a comprehensive security solution. This integration offers real-time protection against malware, zero-day vulnerabilities, and data leaks, and simplifies management through a unified platform.
 
This guide provides step-by-step instructions for configuring ATP and DLP policies to safeguard your organization. By following these steps, IT administrators can apply the power of Microsoft SSE and Netskope to enhance their organization's security posture and streamline threat management.
 
+54 / -222 lines changed
Commit: Update how-to-netskope-coexistence.md
Changes:
Before
After
author: kenwith
contributors:
ms.topic: concept-article
ms.date: 06/09/2025
ms.author: kenwith
ms.reviewer: shkhalid
ai-usage: ai-assisted
---
 
# Security Service Edge (SSE) Coexistence With Microsoft and Netskope
 
Learn about Security Service Edge (SSE) coexistence with Microsoft and Netskope
 
 
To configure Microsoft and Netskope for a unified SASE solution, start by setting up Microsoft Entra Internet Access and Microsoft Entra Private Access. Next, configure Netskope Private Access and Internet Access. Finally, make sure to establish the required Fully Qualified Domain Name (FQDN) and IP bypasses to ensure smooth integration between the two platforms.
 
- Set up Microsoft Entra Internet Access and Microsoft Entra Private Access. These products make up the Global Secure Access solution.
 
- Set up Netskope Private Access and Internet Access
 
author: kenwith
contributors:
ms.topic: concept-article
ms.date: 07/07/2025
ms.author: kenwith
ms.reviewer: shkhalid
ai-usage: ai-assisted
---
 
# Security Service Edge (SSE) coexistence With Microsoft and Netskope
 
Learn about Security Service Edge (SSE) coexistence with Microsoft and Netskope
 
 
To configure Microsoft and Netskope for a unified SASE solution, start by setting up Microsoft Entra Internet Access and Microsoft Entra Private Access. Next, configure Netskope Private Access and Internet Access. Finally, make sure to establish the required Fully Qualified Domain Name (FQDN) and IP bypasses to ensure smooth integration between the two platforms.
 
1. Set up Microsoft Entra Internet Access and Microsoft Entra Private Access. These products make up the Global Secure Access solution.
1. Set up Netskope Private Access and Internet Access
1. Configure the Global Secure Access FQDN and IP bypasses
 
+19 / -15 lines changed
Commit: revised phase enforcement to clarify Read operations won't require MFA in phase 2
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 06/25/2025
ms.author: justinha
author: justinha
manager: dougeby
 
## Scope of enforcement
The scope of enforcement includes which applications plan to enforce MFA, applications that are out of scope, when enforcement is planned to occur, and which accounts have a mandatory MFA requirement.
 
### Applications
 
> [!NOTE]
> The date of enforcement for Phase 2 has changed to September 1, 2025.
 
The following table lists affected apps, app IDs, and URLs for Azure.
 
| Application Name | App ID | Enforcement starts |
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 07/07/2025
ms.author: justinha
author: justinha
manager: dougeby
 
## Scope of enforcement
The scope of enforcement includes when enforcement is planned to occur, which applications plan to enforce MFA, applications that are out of scope, and which accounts have a mandatory MFA requirement.
 
## Enforcement phases
 
> [!NOTE]
> The date of enforcement for Phase 2 has changed to September 1, 2025.
 
The enforcement of MFA for applications rolls out in two phases.
 
### Applications that enforce MFA in phase 1
+1 / -29 lines changed
Commit: added-faqs
Changes:
Before
After
description: Learn how the Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot can help secure your organization.
ms.author: joflore
author: MicrosoftGuyJFlo
 
ms.date: 07/02/2025
 
ms.service: entra-id
 
Use the **Give Microsoft feedback** button at the top of the agent window to provide feedback to Microsoft about the agent.
 
## FAQs
 
### When should I use the Conditional Access optimization agent vs Copilot Chat?
 
Both features provide different insights into your Conditional Access policies. The following table provides a comparison of the two features:
 
| Scenario | Conditional Access Optimization Agent | Copilot Chat |
|----------|---------------------------------------|--------------|
| **Generic Scenarios** |||
| Utilize tenant-specific configuration | ✅ | |
description: Learn how the Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot can help secure your organization.
ms.author: joflore
author: MicrosoftGuyJFlo
ms.reviewer: lhuangnorth
ms.date: 07/02/2025
 
ms.service: entra-id
 
Use the **Give Microsoft feedback** button at the top of the agent window to provide feedback to Microsoft about the agent.
 
## Related content
 
- [Conditional Access policy templates](concept-conditional-access-policy-common.md?tabs=secure-foundation#template-categories)
 
 
 
 
 
 
 
Modified by csmulligan on Jul 8, 2025 12:17 AM
📖 View on learn.microsoft.com
+5 / -5 lines changed
Commit: Freshness update.
Changes:
Before
After
ms.subservice: external
ms.topic: reference
ms.date: 10/07/2024
ms.author: cmulligan
ms.custom: it-pro
 
|Sign in |4 |
|Password reset |4 |
 
When you add more features to a user flow, such as multifactor authentication, more requests are consumed. The following table shows how many additional requests are consumed when a user interacts with one of these features.
 
|Feature |Additional requests consumed |
|---------|---------|
|Email one-time password |2 |
 
|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |
|Number of [custom authentication extensions](/entra/identity-platform/custom-extension-overview) |100 |
|Number of event listener policies |249 |
|Maximum custom authentication extension timeout |2000 ms |
ms.subservice: external
ms.topic: reference
ms.date: 07/07/2025
ms.author: cmulligan
ms.custom: it-pro
 
|Sign in |4 |
|Password reset |4 |
 
When you add more features to a user flow, such as multifactor authentication, more requests are consumed. The following table shows how many other requests are consumed when a user interacts with one of these features.
 
|Feature |Other requests consumed |
|---------|---------|
|Email one-time password |2 |
 
|Total number of objects (user accounts and applications) per tenant. If you want to increase this limit, contact [Microsoft Support](/entra/identity-platform/developer-support-help-options?toc=%2Fentra%2Fexternal-id%2Ftoc.json&bc=%2Fentra%2Fexternal-id%2Fbreadcrumb%2Ftoc.json#create-an-azure-support-request). | 300,000 |
|Number of [custom authentication extensions](/entra/identity-platform/custom-extension-overview) |100 |
|Number of event listener policies |249 |
|Maximum custom authentication extension timeout |2,000 ms |
+4 / -4 lines changed
Commit: Freshness update.
Changes:
Before
After
description: Learn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.
ms.service: entra-external-id
ms.topic: how-to
ms.date: 04/29/2024
ms.author: cmulligan
author: csmulligan
manager: dougeby
Learn more about using cross-tenant access settings to [manage B2B direct connect](b2b-direct-connect-overview.md#managing-cross-tenant-access-for-b2b-direct-connect).
 
> [!IMPORTANT]
> Microsoft is beginning to move customers using cross-tenant access settings to a new storage model on August 30, 2023. You may notice an entry in your audit logs informing you that your cross-tenant access settings were updated as our automated task migrates your settings. For a brief window while the migration processes, you will be unable to make changes to your settings. If you are unable to make a change, you should wait a few moments and try the change again. Once the migration completes, [you will no longer be capped with 25kb of storage space](./faq.yml#how-many-organizations-can-i-add-in-cross-tenant-access-settings-) and there will be no more limits on the number of partners you can add.
 
## Before you begin
 
- Select **Add**.
 
> [!NOTE]
> You cannot target users or groups in inbound default settings.
 
![Screenshot showing adding external users for inbound b2b direct connect](media/cross-tenant-access-settings-b2b-direct-connect/b2b-direct-connect-inbound-external-users-groups-add.png)
description: Learn how to configure B2B direct connect with other Microsoft Entra organizations, using cross-tenant access settings to manage outbound and inbound access.
ms.service: entra-external-id
ms.topic: how-to
ms.date: 07/07/2025
ms.author: cmulligan
author: csmulligan
manager: dougeby
Learn more about using cross-tenant access settings to [manage B2B direct connect](b2b-direct-connect-overview.md#managing-cross-tenant-access-for-b2b-direct-connect).
 
> [!IMPORTANT]
> Microsoft is beginning to move customers using cross-tenant access settings to a new storage model on August 30, 2023. You may notice an entry in your audit logs informing you that your cross-tenant access settings were updated as our automated task migrates your settings. For a brief window while the migration processes, you will be unable to make changes to your settings. If you're unable to make a change, you should wait a few moments and try the change again. Once the migration completes, [you'll no longer be capped with 25kb of storage space,](./faq.yml#how-many-organizations-can-i-add-in-cross-tenant-access-settings-) and there will be no more limits on the number of partners you can add.
 
## Before you begin
 
- Select **Add**.
 
> [!NOTE]
> You can't target users or groups in inbound default settings.
 
![Screenshot showing adding external users for inbound b2b direct connect](media/cross-tenant-access-settings-b2b-direct-connect/b2b-direct-connect-inbound-external-users-groups-add.png)
+2 / -2 lines changed
Commit: PM-updates
Changes:
Before
After
 
The **Agent summary** at the top of the Conditional Access optimization agent page provides a quick summary of what the agent has discovered in the last 30 days. The total number of [security compute units (SCU)](/copilot/security/manage-usage) consumed by the agent is also provided.
 
:::image type="content" source="media/agent-optimization-logs-metrics/agent-summary-tile.png" alt-text="Screenshot of the details of a policy suggestion." lightbox="media/agent-optimization/agent-summary-tile.png":::
 
- **Unprotected users discovered**: The number of users who were identified by the agent and protected by a policy suggested by the agent.
- **Unprotected apps discovered**: The number of applications that were identified by the agent and protected by a policy suggested by the agent.
 
Policies created or modified by the agent are tagged with **Conditional Access Optimization Agent** in the Conditional Access policies pane.
 
:::image type="content" source="media/agent-optimization/created-by-conditional-access-optimization-agent.png" alt-text="Screenshot of the details of a policy suggestion." lightbox="media/agent-optimization/created-by-conditional-access-optimization-agent-expanded.png":::
 
In the **Audit logs** the **Initiated by (actor)** field show the name of the user who started the agent.
 
The **Agent summary** at the top of the Conditional Access optimization agent page provides a quick summary of what the agent has discovered in the last 30 days. The total number of [security compute units (SCU)](/copilot/security/manage-usage) consumed by the agent is also provided.
 
:::image type="content" source="media/agent-optimization-logs-metrics/agent-summary-tile.png" alt-text="Screenshot of the agent summary tile." lightbox="media/agent-optimization/agent-summary-tile.png":::
 
- **Unprotected users discovered**: The number of users who were identified by the agent and protected by a policy suggested by the agent.
- **Unprotected apps discovered**: The number of applications that were identified by the agent and protected by a policy suggested by the agent.
 
Policies created or modified by the agent are tagged with **Conditional Access Optimization Agent** in the Conditional Access policies pane.
 
:::image type="content" source="media/agent-optimization-logs-metrics/created-by-conditional-access-optimization-agent.png" alt-text="Screenshot of the details of a policy suggestion." lightbox="media/agent-optimization-logs-metrics/created-by-conditional-access-optimization-agent-expanded.png":::
 
In the **Audit logs** the **Initiated by (actor)** field show the name of the user who started the agent.
Modified by Chris Werner on Jul 8, 2025 1:18 AM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
title: Manage lifecycle workflows with Microsoft Security Copilot
description: Use Microsoft Security Copilot in the Microsoft Entra admin center to create lifecycle workflows for Joiner, Mover, and Leaver scenarios. Execute workflows on-demand and use workflow insights to monitor execution and troubleshoot as needed.
keywords:
author: rwike77
ms.author: ryanwi
manager: celestedg
ms.date: 02/19/2025
ms.topic: conceptual
title: Manage lifecycle workflows with Microsoft Security Copilot
description: Use Microsoft Security Copilot in the Microsoft Entra admin center to create lifecycle workflows for Joiner, Mover, and Leaver scenarios. Execute workflows on-demand and use workflow insights to monitor execution and troubleshoot as needed.
keywords:
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 02/19/2025
ms.topic: conceptual
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
title: Investigate risky users with Copilot
description: Use Copilot in Microsoft Entra to quickly respond to identity threats by summarizing the risk level for a user and receiving insights relevant to the incident.
keywords:
author: rwike77
ms.author: ryanwi
manager: celestedg
ms.date: 11/07/2024
ms.topic: conceptual
title: Investigate risky users with Copilot
description: Use Copilot in Microsoft Entra to quickly respond to identity threats by summarizing the risk level for a user and receiving insights relevant to the incident.
keywords:
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 11/07/2024
ms.topic: conceptual
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
title: Investigate identity risk in Microsoft Security Copilot
description: Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate identity-based security incident.
keywords:
author: rwike77
ms.author: ryanwi
manager: celestedg
ms.date: 11/7/2024
ms.topic: conceptual
title: Investigate identity risk in Microsoft Security Copilot
description: Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate identity-based security incident.
keywords:
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 11/7/2024
ms.topic: conceptual
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
title: Investigate app risk in Microsoft Security Copilot
description: Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate potential risky applications.
keywords:
author: rwike77
ms.author: ryanwi
manager: celestedg
ms.date: 12/12/2024
ms.topic: conceptual
title: Investigate app risk in Microsoft Security Copilot
description: Use Microsoft Security Copilot and Microsoft Entra skills to quickly investigate potential risky applications.
keywords:
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 12/12/2024
ms.topic: conceptual
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
---
title: Responsible AI FAQ - Security Copilot in Microsoft Entra
description: Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
author: rwike77
ms.author: ryanwi
manager: celestedg
ms.date: 10/29/2024
ms.topic: faq
---
title: Responsible AI FAQ - Security Copilot in Microsoft Entra
description: Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 10/29/2024
ms.topic: faq
Modified by Chris Werner on Jul 8, 2025 1:18 AM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
title: Respond to identity threats using Copilot.
description: Use Copilot in Microsoft Entra to investigate identity risks and troubleshoot identity tasks quickly.
keywords:
author: rwike77
ms.author: ryanwi
manager: celestedg
ms.date: 12/10/2024
ms.topic: conceptual
title: Respond to identity threats using Copilot.
description: Use Copilot in Microsoft Entra to investigate identity risks and troubleshoot identity tasks quickly.
keywords:
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 12/10/2024
ms.topic: conceptual
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
---
title: Apps & service principals in Microsoft Entra ID
description: Learn about the relationship between application and service principal objects in Microsoft Entra ID.
author: rwike77
manager: CelesteDG
ms.author: ryanwi
ms.date: 10/01/2024
ms.reviewer: sureshja
ms.service: identity-platform
---
title: Apps & service principals in Microsoft Entra ID
description: Learn about the relationship between application and service principal objects in Microsoft Entra ID.
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.date: 10/01/2024
ms.reviewer: sureshja
ms.service: identity-platform
Modified by Chris Werner on Jul 8, 2025 1:18 AM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: reassign articles
Changes:
Before
After
---
title: App sign-in flow with the Microsoft identity platform
description: Learn about the sign-in flow of web, desktop, and mobile apps in Microsoft identity platform.
author: rwike77
manager: CelesteDG
ms.author: ryanwi
ms.custom: scenarios:getting-started
ms.date: 08/11/2023
ms.reviewer: jmprieur, sureshja, ludwignick
---
title: App sign-in flow with the Microsoft identity platform
description: Learn about the sign-in flow of web, desktop, and mobile apps in Microsoft identity platform.
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.custom: scenarios:getting-started
ms.date: 08/11/2023
ms.reviewer: jmprieur, sureshja, ludwignick