πŸ“‹ Microsoft Entra Documentation Changes

Changes for July 11th 2025

Period: July 10th 2025, 12:00 AM to July 11th 2025, 12:00 AM

πŸ“š Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on July 11th 2025.

πŸ“Š Summary

50
Total Commits
0
New Files
130
Modified Files
0
Deleted Files
14
Contributors

πŸ“ Modified Documentation Files

+31 / -30 lines changed
Commit: updated to mds 173
Changes:
Before
After
---
title: Microsoft Entra ID attestation for FIDO2 security key vendors
description: Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
ms.date: 06/19/2025
ms.service: entra-id
ms.subservice: authentication
author: justinha
 
## FIDO2 security keys eligible for attestation with Microsoft Entra ID
 
The following table includes each FIDO2 security key model listed in MDS version 169 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
Description|AAGUID|Bio|USB|NFC|BLE
-----------|------|---------|-----|----|------
ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌
Allthenticator Android App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-fa57-1337-f1d0-a117371ca702|✅|✅|❌|❌
Allthenticator iOS App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-1337-fa57-f1d0-a117e71ca702|✅|✅|❌|❌
Arculus FIDO 2.1 Key Card \[P71\]|3f59672f-20aa-4afe-b6f4-7e5e916b6d98|❌|✅|✅|❌
Arculus FIDO2/U2F Key Card|9d3df6ba-282f-11ed-a261-0242ac120002|❌|✅|✅|❌
ATKey.Card CTAP2.0|d41f5a69-b817-4144-a13c-9ebd6d9254d6|✅|✅|❌|✅
---
title: Microsoft Entra ID attestation for FIDO2 security key vendors
description: Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
ms.date: 07/09/2025
ms.service: entra-id
ms.subservice: authentication
author: justinha
 
## FIDO2 security keys eligible for attestation with Microsoft Entra ID
 
The following table includes each FIDO2 security key model listed in MDS version 173 that's eligible for attestation with Microsoft Entra ID. For each model, the table shows its Authenticator Attestation Globally Unique Identifier (AAGUID) and feature capabilities.
 
Description|AAGUID|Bio|USB|NFC|BLE
-----------|------|---------|-----|----|------
ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌
Allthenticator Android App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-fa57-1337-f1d0-a117371ca702|✅|✅|❌|❌
Allthenticator iOS App: roaming BLE FIDO2 Allthenticator for Windows, Mac, Linux, and Allthenticate door readers|5ca1ab1e-1337-fa57-f1d0-a117e71ca702|✅|✅|❌|❌
Arculus FIDO 2.1 Key Card \[P71\]|3f59672f-20aa-4afe-b6f4-7e5e916b6d98|❌|✅|❌|❌
Arculus FIDO2/U2F Key Card|9d3df6ba-282f-11ed-a261-0242ac120002|❌|✅|❌|❌
ATKey.Card CTAP2.0|d41f5a69-b817-4144-a13c-9ebd6d9254d6|✅|❌|❌|❌
+41 / -13 lines changed
Commit: PM-updates
Changes:
Before
After
 
# How to review and apply suggestions from the Conditional Access optimization agent
 
The Microsoft Entra Conditional Access optimization agent provides suggestions for your Conditional Access policies. The suggestions vary based on what the agent finds. As the administrator, you need to review the suggestions and decide what to do. No changes are made without your approval.
 
This article provides an overview of the logic behind the suggestions and how to review the details of the suggestions.
 
- Scanning is limited to a 24 hour period.
- Suggestions from the agent can't be customized or overridden.
 
## Reviewing results
 
The agent might run and:
 
- Not identify any unprotected users or recommend any changes
- Suggest creating a new Conditional Access policy in report-only mode
- Suggest modifying an existing policy
- Suggest consolidating overlapping policies
 
When you select **Review suggestion**, you're provided a thorough overview of the suggestion, including the logic used to identify the suggestion and the potential impact of the policy.
 
# How to review and apply suggestions from the Conditional Access optimization agent
 
The Microsoft Entra Conditional Access optimization agent provides suggestions for your Conditional Access policies. The suggestions vary based on what the agent finds. As the administrator, you need to review the suggestions and decide what to do.
 
This article provides an overview of the logic behind the suggestions and how to review the details of the suggestions.
 
- Scanning is limited to a 24 hour period.
- Suggestions from the agent can't be customized or overridden.
 
## How it works
 
The agent might run and:
 
- Not identify any unprotected users or recommend any changes
- Create a new Conditional Access policy *in report-only mode*
- Suggest modifying an existing policy
- Suggest consolidating overlapping policies
 
Because Conditional Access policies can be complex and cover a wide range of scenarios, we want to provide as much information as possible about the logic used to identify the suggestions. As a best practice, review the information provided before applying a suggestion or changing a report-only policy to an active policy.
+33 / -0 lines changed
Commit: Learn Editor: Update how-to-connect-syncservice-features.md
Changes:
Before
After
 
After enabling this feature, existing userPrincipalName values remain as-is. On next change of the userPrincipalName attribute on-premises, the normal delta sync on users updates the UPN. Once this feature is enabled, it's not possible to disable it.
 
## See also
 
* [Microsoft Entra Connect Sync](how-to-connect-sync-whatis.md)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
After enabling this feature, existing userPrincipalName values remain as-is. On next change of the userPrincipalName attribute on-premises, the normal delta sync on users updates the UPN. Once this feature is enabled, it's not possible to disable it.
 
## Password Hash Sync
 
This feature allows the sync engine to use password hash sync and is automatically enabled by the sync client.
 
You can see if this feature is enabled for you by running:
 
```powershell
# Connect Microsoft Graph
Connect-MgGraph -Scopes "OnPremDirectorySynchronization.Read.All"
 
# Get DirSync service features
$DirectorySync = Get-MgDirectoryOnPremiseSynchronization
$DirectorySync.Features.PasswordSyncEnabled
```
 
 
If this feature is no longer needed, for instance after decommissioning synchronization from on-premises Active Directory, you can disable it by running:
Modified by Faith Moraa Ombongi on Jul 10, 2025 5:50 PM
πŸ“– View on learn.microsoft.com
+1 / -26 lines changed
Commit: Clean up include titles, descriptions + modern commerce administrator
Changes:
Before
After
 
### Modern Commerce Administrator
 
Template ID: d24aef57-1500-4070-84db-2666f29cf966
 
This role isn't returned by PowerShell of the Microsoft Graph API. It's automatically assigned from Commerce, and is not intended or supported for any other use.
 
The Modern Commerce Administrator role gives certain users permission to access Microsoft 365 admin center and see the left navigation entries for **Home**, **Billing**, and **Support**. The content available in these areas is controlled by [commerce-specific roles](/azure/cost-management-billing/manage/understand-mca-roles) assigned to users to manage products that they bought for themselves or your organization. This might include tasks like paying bills, or for access to billing accounts and billing profiles.
 
Users with the Modern Commerce Administrator role typically have administrative permissions in other Microsoft purchasing systems, but do not have Global Administrator or Billing Administrator roles used to access the admin center.
 
**When is the Modern Commerce Administrator role assigned?**
 
* **Self-service purchase in Microsoft 365 admin center** – Self-service purchase gives users a chance to try out new products by buying or signing up for them on their own. These products are managed in the admin center. Users who make a self-service purchase are assigned a role in the commerce system, and the Modern Commerce Administrator role so they can manage their purchases in admin center. Admins can block self-service purchases (for Fabric, Power BI, Power Apps, Power automate) through [PowerShell](/microsoft-365/commerce/subscriptions/allowselfservicepurchase-powershell). For more information, see [Self-service purchase FAQ](/microsoft-365/commerce/subscriptions/self-service-purchase-faq).
* **Purchases from Microsoft commercial marketplace** – Similar to self-service purchase, when a user buys a product or service from Microsoft AppSource or Azure Marketplace, the Modern Commerce Administrator role is assigned if they don't have the Global Administrator or Billing Administrator role. In some cases, users might be blocked from making these purchases. For more information, see [Microsoft commercial marketplace](/azure/marketplace/marketplace-faq-publisher-guide#what-could-block-a-customer-from-completing-a-purchase-).
* **Proposals from Microsoft** – A proposal is a formal offer from Microsoft for your organization to buy Microsoft products and services. When the person who is accepting the proposal doesn't have a Global Administrator or Billing Administrator role in Microsoft Entra ID, they are assigned both a commerce-specific role to complete the proposal and the Modern Commerce Administrator role to access admin center. When they access the admin center they can only use features that are authorized by their commerce-specific role.
* **Commerce-specific roles** – Some users are assigned commerce-specific roles. If a user isn't a Global Administrator or Billing Administrator, they get the Modern Commerce Administrator role so they can access the admin center.
 
If the Modern Commerce Administrator role is unassigned from a user, they lose access to Microsoft 365 admin center. If they were managing any products, either for themselves or for your organization, they won't be able to manage them. This might include assigning licenses, changing payment methods, paying bills, or other tasks for managing subscriptions.
 
 
### Modern Commerce Administrator
 
[!INCLUDE [modern-commerce-administrator](includes/modern-commerce-administrator.md)]
 
## Next steps
 
 
 
 
 
 
 
 
 
 
 
 
 
 
+15 / -6 lines changed
Commit: Clean up include titles, descriptions + modern commerce administrator
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 06/20/2025
ms.custom: include file
---
 
Do not use. This role is automatically assigned from Commerce, and is not intended or supported for any other use. See details below.
 
The Modern Commerce Administrator role gives certain users permission to access Microsoft 365 admin center and see the left navigation entries for **Home**, **Billing**, and **Support**. The content available in these areas is controlled by [commerce-specific roles](/azure/cost-management-billing/manage/understand-mca-roles) assigned to users to manage products that they bought for themselves or your organization. This might include tasks like paying bills, or for access to billing accounts and billing profiles.
 
**When is the Modern Commerce Administrator role assigned?**
 
* **Self-service purchase in Microsoft 365 admin center** – Self-service purchase gives users a chance to try out new products by buying or signing up for them on their own. These products are managed in the admin center. Users who make a self-service purchase are assigned a role in the commerce system, and the Modern Commerce Administrator role so they can manage their purchases in admin center. Admins can block self-service purchases (for Fabric, Power BI, Power Apps, Power automate) through [PowerShell](/microsoft-365/commerce/subscriptions/allowselfservicepurchase-powershell). For more information, see [Self-service purchase FAQ](/microsoft-365/commerce/subscriptions/self-service-purchase-faq).
* **Purchases from Microsoft commercial marketplace** – Similar to self-service purchase, when a user buys a product or service from Microsoft AppSource or Azure Marketplace, the Modern Commerce Administrator role is assigned if they don’t have the Global Administrator or Billing Administrator role. In some cases, users might be blocked from making these purchases. For more information, see [Microsoft commercial marketplace](/azure/marketplace/marketplace-faq-publisher-guide#what-could-block-a-customer-from-completing-a-purchase-).
* **Proposals from Microsoft** – A proposal is a formal offer from Microsoft for your organization to buy Microsoft products and services. When the person who is accepting the proposal doesn’t have a Global Administrator or Billing Administrator role in Microsoft Entra ID, they are assigned both a commerce-specific role to complete the proposal and the Modern Commerce Administrator role to access admin center. When they access the admin center they can only use features that are authorized by their commerce-specific role.
* **Commerce-specific roles** – Some users are assigned commerce-specific roles. If a user isn't a Global Administrator or Billing Administrator, they get the Modern Commerce Administrator role so they can access the admin center.
 
If the Modern Commerce Administrator role is unassigned from a user, they lose access to Microsoft 365 admin center. If they were managing any products, either for themselves or for your organization, they won’t be able to manage them. This might include assigning licenses, changing payment methods, paying bills, or other tasks for managing subscriptions.
<!-- autogenerated content starts here -->
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/10/2025
ms.custom: include file
---
 
Template ID: d24aef57-1500-4070-84db-2666f29cf966
 
Do not use. This role isn't returned by PowerShell of the Microsoft Graph API. It's automatically assigned from Commerce, and is not intended or supported for any other use.
 
The Modern Commerce Administrator role gives certain users permission to access Microsoft 365 admin center and see the left navigation entries for **Home**, **Billing**, and **Support**. The content available in these areas is controlled by [commerce-specific roles](/azure/cost-management-billing/manage/understand-mca-roles) assigned to users to manage products that they bought for themselves or your organization. This might include tasks like paying bills, or for access to billing accounts and billing profiles.
 
**When is the Modern Commerce Administrator role assigned?**
 
* **Self-service purchase in Microsoft 365 admin center** – Self-service purchase gives users a chance to try out new products by buying or signing up for them on their own. These products are managed in the admin center. Users who make a self-service purchase are assigned a role in the commerce system, and the Modern Commerce Administrator role so they can manage their purchases in admin center. Admins can block self-service purchases (for Fabric, Power BI, Power Apps, Power automate) through [PowerShell](/microsoft-365/commerce/subscriptions/allowselfservicepurchase-powershell). For more information, see [Self-service purchase FAQ](/microsoft-365/commerce/subscriptions/self-service-purchase-faq).
* **Purchases from Microsoft commercial marketplace** – Similar to self-service purchase, when a user buys a product or service from Microsoft AppSource or Azure Marketplace, the Modern Commerce Administrator role is assigned if they don't have the Global Administrator or Billing Administrator role. In some cases, users might be blocked from making these purchases. For more information, see [Microsoft commercial marketplace](/azure/marketplace/marketplace-faq-publisher-guide#what-could-block-a-customer-from-completing-a-purchase-).
* **Proposals from Microsoft** – A proposal is a formal offer from Microsoft for your organization to buy Microsoft products and services. When the person who is accepting the proposal doesn't have a Global Administrator or Billing Administrator role in Microsoft Entra ID, they are assigned both a commerce-specific role to complete the proposal and the Modern Commerce Administrator role to access admin center. When they access the admin center they can only use features that are authorized by their commerce-specific role.
* **Commerce-specific roles** – Some users are assigned commerce-specific roles. If a user isn't a Global Administrator or Billing Administrator, they get the Modern Commerce Administrator role so they can access the admin center.
 
+8 / -9 lines changed
Commit: July freshness work
Changes:
Before
After
---
title: 'Create an enterprise application from a multitenant application'
description: Create an enterprise application using the client ID for a multitenant application.
 
author: omondiatieno
ms.subservice: enterprise-apps
ms.topic: how-to
 
ms.date: 07/19/2024
ms.author: jomondi
ms.reviewer: karavar
ms.custom: mode-other, devx-track-azurecli
 
---
 
# Create an enterprise application from a multitenant application in Microsoft Entra ID
 
In this article, you'll learn how to create an enterprise application in your tenant using the client ID for a multitenant application. An enterprise application refers to a service principal within a tenant. The service principal discussed in this article is the local representation, or application instance, of a global application object in a single tenant or directory.
 
Before you proceed to add the application using any of these options, check whether the enterprise application is already in your tenant by attempting to sign in to the application. If the sign-in is successful, the enterprise application already exists in your tenant.
---
title: Create an enterprise application from a multitenant application
description: Create an enterprise application using the client ID for a multitenant application.
 
author: omondiatieno
ms.subservice: enterprise-apps
ms.topic: how-to
 
ms.date: 07/10/2025
ms.author: jomondi
ms.reviewer: karavar
ms.custom: mode-other, devx-track-azurecli
 
---
 
# Create an enterprise application from a multitenant application
 
In this article, you learn how to create an enterprise application in your tenant using the client ID for a multitenant application. An enterprise application refers to a service principal within a tenant. The service principal discussed in this article is the local representation, or application instance, of a global application object in a single tenant or directory.
 
Before you proceed to add the application using any of these options, check whether the enterprise application is already in your tenant by attempting to sign in to the application. If the sign-in is successful, the enterprise application already exists in your tenant.
+7 / -7 lines changed
Commit: July freshness work
Changes:
Before
After
---
title: Advanced certificate signing options in a SAML token
description: Learn how to use advanced certificate signing options in the SAML token for preintegrated apps in Microsoft Entra ID
author: omondiatieno
manager: mwongerapk
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: concept-article
ms.date: 07/19/2024
ms.author: jomondi
ms.reviewer: saumadan
ms.collection: M365-identity-device-management
#customer intent: As an administrator managing SAML-based single sign-on in Microsoft Entra ID, I want to change the certificate signing options and signing algorithm for an application, so that I can ensure the security and compatibility of the SAML tokens used for authentication.
---
 
# Advanced certificate signing options in a SAML token
 
Today Microsoft Entra ID supports thousands of preintegrated applications in the Microsoft Entra App Gallery. Over 500 of the applications support single sign-on by using the [Security Assertion Markup Language (SAML)](https://wikipedia.org/wiki/Security_Assertion_Markup_Language) 2.0 protocol, such as the [NetSuite](https://azuremarketplace.microsoft.com/marketplace/apps/aad.netsuite) application. When a customer authenticates to an application through Microsoft Entra ID by using SAML, Microsoft Entra ID sends a token to the application (via an HTTP POST). The application then validates and uses the token to sign in the customer instead of prompting for a username and password. These SAML tokens are signed with the unique certificate generated in Microsoft Entra ID and by specific standard algorithms.
 
1. In the left pane of the application overview page, select **Single sign-on**.
---
title: Certificate signing options in a SAML token
description: Learn how to use advanced certificate signing options in the SAML token for preintegrated apps in Microsoft Entra ID
author: omondiatieno
manager: mwongerapk
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: concept-article
ms.date: 07/10/2025
ms.author: jomondi
ms.reviewer: saumadan
ms.collection: M365-identity-device-management
#customer intent: As an administrator managing SAML-based single sign-on in Microsoft Entra ID, I want to change the certificate signing options and signing algorithm for an application, so that I can ensure the security and compatibility of the SAML tokens used for authentication.
---
 
# Certificate signing options in a SAML token
 
Today Microsoft Entra ID supports thousands of preintegrated applications in the Microsoft Entra App Gallery. Over 500 of the applications support single sign-on by using the [Security Assertion Markup Language (SAML)](https://wikipedia.org/wiki/Security_Assertion_Markup_Language) 2.0 protocol, such as the [NetSuite](https://azuremarketplace.microsoft.com/marketplace/apps/aad.netsuite) application. When a customer authenticates to an application through Microsoft Entra ID by using SAML, Microsoft Entra ID sends a token to the application (via an HTTP POST). The application then validates and uses the token to sign in the customer instead of prompting for a username and password. These SAML tokens are signed with the unique certificate generated in Microsoft Entra ID and by specific standard algorithms.
 
1. In the left pane of the application overview page, select **Single sign-on**.
+12 / -2 lines changed
Commit: added how to disable software OATH tokens
Changes:
Before
After
ms.custom: sfi-image-nochange
# Customer intent: As an identity administrator, I want to understand how to manage OATH tokens in Microsoft Entra ID to improve and secure user sign-in events.
---
# How to manage hardware OATH tokens in Microsoft Entra ID (Preview)
 
This topic covers how to manage hardware oath tokens in Microsoft Entra ID, including Microsoft Graph APIs that you can use to upload, activate, and assign hardware OATH tokens.
 
## Enable hardware OATH tokens in the Authentication methods policy
 
You can view and enable hardware OATH tokens in the Authentication methods policy by using Microsoft Graph APIs or the Microsoft Entra admin center.
 
 
We recommend that you [migrate to the Authentication methods policy](how-to-authentication-methods-manage.md) to manage hardware OATH tokens. If you enable OATH tokens in the legacy MFA policy, browse to the policy in the Microsoft Entra admin center as an Authentication Policy Administrator: **Entra ID** > **Multifactor authentication** > **Additional cloud-based multifactor authentication settings**. Clear the checkbox for **Verification code from mobile app or hardware token**.
 
 
## Scenario: Admin creates, assigns, and activates a hardware OATH token
 
DELETE https://graph.microsoft.com/beta/directory/authenticationMethodDevices/hardwareOathDevices/{legacyHardwareOathMethodId}
```
 
ms.custom: sfi-image-nochange
# Customer intent: As an identity administrator, I want to understand how to manage OATH tokens in Microsoft Entra ID to improve and secure user sign-in events.
---
# How to manage OATH tokens in Microsoft Entra ID (Preview)
 
This topic covers how to manage hardware oath tokens in Microsoft Entra ID, including Microsoft Graph APIs that you can use to upload, activate, and assign hardware OATH tokens.
 
## Manage hardware OATH tokens in the Authentication methods policy (Preview)
 
You can view and enable hardware OATH tokens in the Authentication methods policy by using Microsoft Graph APIs or the Microsoft Entra admin center.
 
 
We recommend that you [migrate to the Authentication methods policy](how-to-authentication-methods-manage.md) to manage hardware OATH tokens. If you enable OATH tokens in the legacy MFA policy, browse to the policy in the Microsoft Entra admin center as an Authentication Policy Administrator: **Entra ID** > **Multifactor authentication** > **Additional cloud-based multifactor authentication settings**. Clear the checkbox for **Verification code from mobile app or hardware token**.
 
## Manage third-party software OATH tokens
 
Third-party software OATH tokens are enabled for sign in by default. An [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator) can disable them for sign in to prevent users from
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Policy Administrator](~/identity/role-based-access-control/permissions-reference.md#authentication-policy-administrator).
1. Browse to **Entra ID** > **Authentication methods** > **Third-party software OATH tokens**.
+7 / -6 lines changed
Commit: PM-updates
Changes:
Before
After
---
# Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot
 
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
 
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion, you can have the agent update the associated policy with one click-remediation.
 
 
## How it works
 
The Conditional Access optimization agent scans your tenant for new users and applications and determines if Conditional Access policies are applicable. If the agent finds users or applications that aren't protected by Conditional Access policies, it provides suggested next steps, such as creating or modifying a Conditional Access policy. You can review the suggestion, how the agent identified the solution, and what would be included in the policy.
 
Each time the agent runs, it takes the following steps. **The initial scanning steps do not consume any SCUs.**
 
- **Require device-based controls**: The agent can enforce device-based controls, such as device compliance, app protection policies, and domain-joined devices.
- **Block legacy authentication**: User accounts with legacy authentication are blocked from signing in.
- **Block device code flow**: The agent looks for a policy blocking device code flow authentication.
- **Policy consolidation**: The agent scans your policy and identifies overlapping settings. For example, if you have more than one policy that has the same grant controls, the agent suggests consolidating those policies into one.
 
> [!IMPORTANT]
---
# Microsoft Entra Conditional Access optimization agent with Microsoft Security Copilot
 
The Conditional Access optimization agent helps you ensure all users and applications are protected by Conditional Access policies. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
 
In preview, the Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion, you can have the agent update the associated policy with one click-remediation.
 
 
## How it works
 
The Conditional Access optimization agent scans your tenant for new users and applications from the last 24 hours and determines if Conditional Access policies are applicable. If the agent finds users or applications that aren't protected by Conditional Access policies, it provides suggested next steps, such as turning on or modifying a Conditional Access policy. You can review the suggestion, how the agent identified the solution, and what would be included in the policy.
 
Each time the agent runs, it takes the following steps. **The initial scanning steps do not consume any SCUs.**
 
- **Require device-based controls**: The agent can enforce device-based controls, such as device compliance, app protection policies, and domain-joined devices.
- **Block legacy authentication**: User accounts with legacy authentication are blocked from signing in.
- **Block device code flow**: The agent looks for a policy blocking device code flow authentication.
- **Risky users**: The agent suggests a policy to require secure password change for high risk users. Requires Microsoft Entra ID P2 license.
- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.
- **Policy consolidation**: The agent scans your policy and identifies overlapping settings. For example, if you have more than one policy that has the same grant controls, the agent suggests consolidating those policies into one.
+6 / -6 lines changed
Commit: July freshness work
Changes:
Before
After
manager: mwongerapk
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: concept-article
ms.date: 07/19/2024
ms.author: jomondi
ms.reviewer: alamaral
ms.collection: M365-identity-device-management
 
# Enforce signed SAML authentication requests
 
SAML Request Signature Verification is a functionality that validates the signature of signed authentication requests. An App Admin now can enable and disable the enforcement of signed requests and upload the public keys that should be used to do the validation.
 
If enabled Microsoft Entra ID validates the requests against the public keys configured. There are some scenarios where the authentication requests can fail:
 
- Protocol not allowed for signed requests. Only SAML protocol is supported.
- Request not signed, but verification is enabled.
- Signature algorithm not allowed. Only RSA-SHA256 is supported.
 
> [!NOTE]
manager: mwongerapk
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: how-to
ms.date: 07/10/2025
ms.author: jomondi
ms.reviewer: alamaral
ms.collection: M365-identity-device-management
 
# Enforce signed SAML authentication requests
 
SAML Request Signature Verification is a functionality that validates the signature of signed authentication requests. An App Admin can enable and disable the enforcement of signed requests and upload the public keys that should be used to do the validation.
 
If enabled, Microsoft Entra ID validates the requests against the public keys configured. There are some scenarios where the authentication requests can fail:
 
- Protocol not allowed for signed requests. Only SAML protocol is supported.
- Request not signed, but verification is enabled.
- Signature algorithm not allowed. Only RSA-SHA256 is supported.
 
> [!NOTE]
+0 / -10 lines changed
Commit: Update entitlement-management-access-package-visibility.md
Changes:
Before
After
 
The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."
 
The following flow diagram illustrates the logic, effective October 10, 2025, used to determine if an access package appears in the browse/search view for a specific user:
 
:::image type="content" source="media/entitlement-management-access-package-visibility/visibility-diagram-2-small.png" alt-text="Diagram of access package visibility flow after October 2025." lightbox="media/entitlement-management-access-package-visibility/visibility-diagram-2.png":::
 
 
### Next Steps
 
We recommend you review the access packages currently configured with policies scoped to "Specific users and groups" in your tenant. If the access package name, description, or the name and description of the contained resource roles are sensitive information that you wouldn't want all members, excluding guests, to see, hide the access package by **October 10, 2025** to ensure the desired end-user experience on the My Access portal.
 
To hide an access package, follow these steps: [Change the Hidden section](entitlement-management-access-package-edit.md#change-the-hidden-setting).
 
To see all access packages that are scoped to specific users and groups in your tenant, see the following PowerShell script:
 
<span class="mark">\[PowerShell script/ MS Graph call to see all access
packages scoped to users and groups\]</span>
 
## Resource role visibility control
 
The visibility change will only impact how end-users can discover access packages via the "Available" tab, the "View all" option, or when using the search bar within these sections to find requestable access packages. The change won't impact the visibility logic for other tabs like "Suggested," "Active," or "Expired" (even when using search within those tabs), nor does it impact other My Access portal sections such as "Request history" or "Approvals."
 
### Next Steps
 
We recommend you review the access packages currently configured with policies scoped to "Specific users and groups" in your tenant. If the access package name, description, or the name and description of the contained resource roles are sensitive information that you wouldn't want all members, excluding guests, to see, hide the access package by **October 10, 2025** to ensure the desired end-user experience on the My Access portal.
 
To hide an access package, follow these steps: [Change the Hidden section](entitlement-management-access-package-edit.md#change-the-hidden-setting).
 
## Resource role visibility control
 
Coinciding with this change, we're also introducing a **new tenant-wide setting** that allows you to control the end-user visibility of the resource roles (for example, group and app names) contained within access packages. This setting applies tenant-wide to *all* access packages and offers the following visibility options:
 
 
 
 
 
 
 
 
+3 / -3 lines changed
Commit: July freshness work
Changes:
Before
After
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: how-to
ms.date: 07/02/2024
ms.author: jomondi
ms.reviewer: ergleenl
ms.custom: mode-other, enterprise-apps, sfi-image-nochange
 
Microsoft Entra ID has a gallery that contains thousands of preintegrated applications that use SSO. This article uses an enterprise application named **Microsoft Entra SAML Toolkit 1** as an example, but the concepts apply for most preconfigured enterprise applications in the Microsoft Entra application gallery.
 
If your application will not integrate directly with Microsoft Entra for single sign-on, and instead tokens are provided to the application by a relying party Security Token Service (STS), then see the article [Enable single sign-on for an enterprise application with a relying party security token service](add-application-portal-setup-sso-rpsts.md).
 
We recommend that you use a nonproduction environment to test the steps in this article.
 
1. In the **Test single sign-on with Microsoft Entra SAML Toolkit 1** section, on the **Set up single sign-on with SAML** pane, select **Test**.
1. Sign in to the application using the Microsoft Entra credentials of the user account that you assigned to the application.
 
## Next steps
 
- [Manage self service access](manage-self-service-access.md)
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: how-to
ms.date: 07/10/2025
ms.author: jomondi
ms.reviewer: ergleenl
ms.custom: mode-other, enterprise-apps, sfi-image-nochange
 
Microsoft Entra ID has a gallery that contains thousands of preintegrated applications that use SSO. This article uses an enterprise application named **Microsoft Entra SAML Toolkit 1** as an example, but the concepts apply for most preconfigured enterprise applications in the Microsoft Entra application gallery.
 
If your application doesn't integrate directly with Microsoft Entra ID for single sign-on, and instead tokens are provided to the application by a relying party Security Token Service (STS), then see the article [Enable single sign-on for an enterprise application with a relying party security token service](add-application-portal-setup-sso-rpsts.md).
 
We recommend that you use a nonproduction environment to test the steps in this article.
 
1. In the **Test single sign-on with Microsoft Entra SAML Toolkit 1** section, on the **Set up single sign-on with SAML** pane, select **Test**.
1. Sign in to the application using the Microsoft Entra credentials of the user account that you assigned to the application.
 
## Related content
 
- [Manage self service access](manage-self-service-access.md)
+3 / -3 lines changed
Commit: Clean up include titles, descriptions + modern commerce administrator
Changes:
Before
After
---
title: role
description: role
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
> [!IMPORTANT]
> This exception means that you can still consent to application permissions for _other_ apps (for example, other Microsoft apps, 3rd-party apps, or apps that you have registered). You can still _request_ these permissions as part of the app registration, but _granting_ (that is, consenting to) these permissions requires a more privileged administrator, such as Privileged Role Administrator.
>
>This role grants the ability to manage application credentials. Users assigned this role can add credentials to an application, and use those credentials to impersonate the application’s identity. If the application’s identity has been granted access to a resource, such as the ability to create or update User or other objects, then a user assigned to this role could perform those actions while impersonating the application. This ability to impersonate the application’s identity may be an elevation of privilege over what the user can do via their role assignments. It is important to understand that assigning a user to the Application Administrator role gives them the ability to impersonate an application’s identity.
 
<!-- autogenerated content starts here -->
 
---
title: Cloud Application Administrator
description: Cloud Application Administrator
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
> [!IMPORTANT]
> This exception means that you can still consent to application permissions for _other_ apps (for example, other Microsoft apps, 3rd-party apps, or apps that you have registered). You can still _request_ these permissions as part of the app registration, but _granting_ (that is, consenting to) these permissions requires a more privileged administrator, such as Privileged Role Administrator.
>
>This role grants the ability to manage application credentials. Users assigned this role can add credentials to an application, and use those credentials to impersonate the application's identity. If the application's identity has been granted access to a resource, such as the ability to create or update User or other objects, then a user assigned to this role could perform those actions while impersonating the application. This ability to impersonate the application's identity may be an elevation of privilege over what the user can do via their role assignments. It is important to understand that assigning a user to the Application Administrator role gives them the ability to impersonate an application's identity.
 
<!-- autogenerated content starts here -->
 
Modified by Jackline Omondi on Jul 10, 2025 11:43 PM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: UUF -444618 - Clarify the scope of the article to set customer expectations
Changes:
Before
After
ms.subservice: enterprise-apps
 
ms.topic: concept-article
ms.date: 06/20/2025
ms.author: jomondi
ms.reviewer: phsignor
ms.custom: enterprise-apps
 
After disabling or restricting user consent, you have several important steps to take to help keep your organization secure as you continue to allow business-critical applications to be used. These steps are crucial to minimize impact on your organization's support team and IT administrators, and to help prevent the use of unmanaged accounts in non-Microsoft applications.
 
This article provides guidance on managing consent to applications and evaluating consent requests in Microsoft's recommendations, including restricting user consent to verified publishers and selected permissions. It covers concepts such as process changes, education for administrators, auditing and monitoring, and managing tenant-wide admin consent.
 
## Process changes and education
 
ms.subservice: enterprise-apps
 
ms.topic: concept-article
ms.date: 07/20/2025
ms.author: jomondi
ms.reviewer: phsignor
ms.custom: enterprise-apps
 
After disabling or restricting user consent, you have several important steps to take to help keep your organization secure as you continue to allow business-critical applications to be used. These steps are crucial to minimize impact on your organization's support team and IT administrators, and to help prevent the use of unmanaged accounts in non-Microsoft applications.
 
This article explains the main concepts on managing consent to applications and evaluating consent requests in Microsoft's recommendations, including restricting user consent to verified publishers and selected permissions. It covers concepts such as process changes, education for administrators, auditing and monitoring, and managing tenant-wide admin consent.
 
## Process changes and education
 
Modified by Barclay Neira on Jul 10, 2025 10:32 PM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: updating anchor
Changes:
Before
After
author: barclayn
ms.service: entra-id
ms.topic: include
ms.date: 06/17/2025
ms.custom: Identity-Secure-Recommendation
# category: Monitoring
# risklevel: High
 
**Remediation action**
 
- [Configure Microsoft Entra role settings in Privileged Identity Management](/entra/id-governance/privileged-identity-management/pim-how-to-change-default-setting.md#require-justification-on-active-assignment)
author: barclayn
ms.service: entra-id
ms.topic: include
ms.date: 07/10/2025
ms.custom: Identity-Secure-Recommendation
# category: Monitoring
# risklevel: High
 
**Remediation action**
 
- [Configure Microsoft Entra role settings in Privileged Identity Management](/entra/id-governance/privileged-identity-management/pim-how-to-change-default-settings.md#require-justification-on-activation)