📋 Microsoft Entra Documentation Changes

Changes for July 12th 2025

Period: July 11th 2025, 12:00 AM to July 12th 2025, 12:00 AM

📚 Historical Report: This report shows documentation changes that occurred during the 24-hour period ending on July 12th 2025.

📊 Summary

33
Total Commits
0
New Files
9
Modified Files
1
Deleted Files
13
Contributors

📝 Modified Documentation Files

+7 / -21 lines changed
Commit: acrolinx edits
Changes:
Before
After
ms.service: entra-id
ms.subservice: domain-services
ms.topic: how-to
ms.date: 06/29/2025
ms.author: justinha
ms.reviewer: bochingwa
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
 
Microsoft Entra Domain Services supports TLS versions 1.0 and 1.1, but they're disabled by default.
Domain Services will use the following retirement path for TLS versions 1.0 and 1.1:
 
1. Domain Services has removed the ability to disable the TLS 1.2 only mode. Customers who disable TLS 1.2 only mode can enable it.
1. Customers can not disable TLS 1.2 only mode once they have enabled it.
 
 
You can use the Azure portal or PowerShell to enable **TLS 1.2 Only Mode**.
 
 
## Identify applications that use deprecated TLS versions
ms.service: entra-id
ms.subservice: domain-services
ms.topic: how-to
ms.date: 07/10/2025
ms.author: justinha
ms.reviewer: bochingwa
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
Microsoft is enhancing security by disabling TLS versions 1.0 and 1.1 as communicated on November 10, 2023. While the Microsoft implementation of TLS 1.0 and TLS 1.1 versions isn't known to have vulnerabilities, TLS 1.2 or later versions provide improved security features, including perfect forward secrecy and stronger cipher suites. This change helps protect customer data and ensures compliance with industry standards.
 
Microsoft Entra Domain Services supports TLS versions 1.0 and 1.1, but they're disabled by default.
The following retirement path for TLS versions 1.0 and 1.1 is used for Domain Services:
 
1. Domain Services has removed the ability to disable **TLS 1.2 Only Mode**. Customers who disable **TLS 1.2 Only Mode** can enable it.
1. Customers can't disable TLS 1.2 only mode once they have enabled it.
 
You can use the Azure portal or PowerShell to enable **TLS 1.2 Only Mode**.
 
## Identify applications that use deprecated TLS versions
 
Before you enable **TLS 1.2 Only Mode**, it's important to identify applications that still use TLS 1.0 or 1.1, and update them or replace them with alternatives that support TLS 1.2. You can inspect TLS handshake versions from an administrative workstation by using network monitoring tools, such as Wireshark or Microsoft Message Analyzer.
Modified by Custodio Alexandre Rodrigues on Jul 11, 2025 11:40 PM
📖 View on learn.microsoft.com
+6 / -6 lines changed
Commit: Learn Editor: Update how-to-connect-sso.md
Changes:
Before
After
- It's supported on web browser-based clients and Office clients that support [modern authentication](/microsoft-365/enterprise/modern-auth-for-office-2013-and-2016) on platforms and browsers capable of Kerberos authentication:
 
| OS\Browser |Internet Explorer|Microsoft Edge\*\*\*\*|Google Chrome|Mozilla Firefox|Safari|
| --- | --- |--- | --- | --- | --
|Windows 10|Yes\*|Yes|Yes|Yes\*\*\*|N/A
|Windows 8.1|Yes\*|Yes*\*\*\*|Yes|Yes\*\*\*|N/A
|Windows 8|Yes\*|N/A|Yes|Yes\*\*\*|N/A
|Windows Server 2012 R2 or above|Yes\*\*|N/A|Yes|Yes\*\*\*|N/A
|Mac OS X|N/A|N/A|Yes\*\*\*|Yes\*\*\*|Yes\*\*\*
 
> [!NOTE]
>Microsoft Edge legacy is no longer supported
- It's supported on web browser-based clients and Office clients that support [modern authentication](/microsoft-365/enterprise/modern-auth-for-office-2013-and-2016) on platforms and browsers capable of Kerberos authentication:
 
| OS\Browser |Internet Explorer|Microsoft Edge\*\*\*\*|Google Chrome|Mozilla Firefox|Safari|
| --- | --- |--- | --- | --- | -- |
|Windows 10/11|Yes\*|Yes|Yes|Yes\*\*\*|N/A|
|Windows 8.1|Yes\*|Yes*\*\*\*|Yes|Yes\*\*\*|N/A|
|Windows 8|Yes\*|N/A|Yes|Yes\*\*\*|N/A|
|Windows Server 2012 R2 or above|Yes\*\*|Yes****|Yes|Yes\*\*\*|N/A|
|Mac OS X|N/A|N/A|Yes\*\*\*|Yes\*\*\*|Yes\*\*\*|
 
> [!NOTE]
>Microsoft Edge legacy is no longer supported
+5 / -5 lines changed
Commit: Requested changes
Changes:
Before
After
---
title: Understanding access package visibility in the My Access portal
description: A conceptual article describing access package visibility in the My Access portal.
author: owinfreyATL
manager: dougeby
---
 
 
# Understanding access package visibility in the My Access portal
 
The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.
 
When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and planned changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, explains how it currently works, and highlights important changes effective October 10, 2025.
 
## Discovering requestable access packages
 
When a user lands on the "*Available*" tab, searches for requestable packages, or selects "*View all*," Microsoft Entra evaluates which access packages they should be able to see and potentially request. This visibility is determined by a specific sequence of checks.
 
 
1. **Is the end-user an external user?** The system checks if the user is an external user or an internal user. This affects the next step.
---
title: Understand access package visibility in the My Access portal
description: A conceptual article describing access package visibility in the My Access portal.
author: owinfreyATL
manager: dougeby
---
 
 
# Understand access package visibility in the My Access portal
 
The [My Access portal](https://myaccess.microsoft.com) is the central place for users to request, approve, and review their access to resources within Microsoft Entra. For administrators, the Microsoft Entra admin center provides extra functionalities, enabling configuration of access packages and the ability to conduct access reviews.
 
When you manage access to resources in Microsoft Entra, understanding how access packages appear to users in the [My Access portal](https://myaccess.microsoft.com) is essential. Access package visibility determines which packages users can discover and request, and is influenced by several configuration settings and planned changes. This article provides a detailed overview of the factors that control access package visibility in the My Access portal, explains how it currently works, and highlights important changes effective October 10, 2025.
 
## Discover requestable access packages
 
When a user lands on the "*Available*" tab, searches for requestable packages, or selects "*View all*," Microsoft Entra evaluates which access packages they should be able to see and potentially request. This visibility is determined by a specific sequence of checks.
 
 
1. **Is the end-user an external user?** The system checks if the user is an external user or an internal user. This affects the next step.
Modified by Barclay Neira on Jul 11, 2025 3:52 AM
📖 View on learn.microsoft.com
+4 / -4 lines changed
Commit: updating includes
Changes:
Before
After
manager: pmwongera
ms.service: entra-id
ms.topic: include
ms.date: 06/23/2025
ms.custom: Identity-Secure-Recommendation
# category:
# risklevel: medium
# userimpact: medium
# implementationcost: medium
---
External user accounts are often used to provide access to business partners who belong to organizations that have a business relationship with your organization. If these accounts are compromised in their organization, attackers can use the valid credentials to gain initial access to your environment, often bypassing traditional defenses due to their legitimacy.
 
manager: pmwongera
ms.service: entra-id
ms.topic: include
ms.date: 07/10/2025
ms.custom: Identity-Secure-Recommendation
# category:
# risklevel: Medium
# userimpact: Medium
# implementationcost: Medium
---
External user accounts are often used to provide access to business partners who belong to organizations that have a business relationship with your organization. If these accounts are compromised in their organization, attackers can use the valid credentials to gain initial access to your environment, often bypassing traditional defenses due to their legitimacy.
 
+4 / -4 lines changed
Commit: Acrolinx fixes
Changes:
Before
After
 
Template ID: d24aef57-1500-4070-84db-2666f29cf966
 
Do not use. This role isn't returned by PowerShell or the Microsoft Graph API. It's automatically assigned from Commerce, and is not intended or supported for any other use.
 
The Modern Commerce Administrator role gives certain users permission to access Microsoft 365 admin center and see the left navigation entries for **Home**, **Billing**, and **Support**. The content available in these areas is controlled by [commerce-specific roles](/azure/cost-management-billing/manage/understand-mca-roles) assigned to users to manage products that they bought for themselves or your organization. This might include tasks like paying bills, or for access to billing accounts and billing profiles.
 
Users with the Modern Commerce Administrator role typically have administrative permissions in other Microsoft purchasing systems, but do not have Global Administrator or Billing Administrator roles used to access the admin center.
 
**When is the Modern Commerce Administrator role assigned?**
 
* **Self-service purchase in Microsoft 365 admin center** – Self-service purchase gives users a chance to try out new products by buying or signing up for them on their own. These products are managed in the admin center. Users who make a self-service purchase are assigned a role in the commerce system, and the Modern Commerce Administrator role so they can manage their purchases in admin center. Admins can block self-service purchases (for Fabric, Power BI, Power Apps, Power automate) through [PowerShell](/microsoft-365/commerce/subscriptions/allowselfservicepurchase-powershell). For more information, see [Self-service purchase FAQ](/microsoft-365/commerce/subscriptions/self-service-purchase-faq).
* **Purchases from Microsoft commercial marketplace** – Similar to self-service purchase, when a user buys a product or service from Microsoft AppSource or Azure Marketplace, the Modern Commerce Administrator role is assigned if they don't have the Global Administrator or Billing Administrator role. In some cases, users might be blocked from making these purchases. For more information, see [Microsoft commercial marketplace](/azure/marketplace/marketplace-faq-publisher-guide#what-could-block-a-customer-from-completing-a-purchase-).
* **Proposals from Microsoft** – A proposal is a formal offer from Microsoft for your organization to buy Microsoft products and services. When the person who is accepting the proposal doesn't have a Global Administrator or Billing Administrator role in Microsoft Entra ID, they are assigned both a commerce-specific role to complete the proposal and the Modern Commerce Administrator role to access admin center. When they access the admin center they can only use features that are authorized by their commerce-specific role.
* **Commerce-specific roles** – Some users are assigned commerce-specific roles. If a user isn't a Global Administrator or Billing Administrator, they get the Modern Commerce Administrator role so they can access the admin center.
 
If the Modern Commerce Administrator role is unassigned from a user, they lose access to Microsoft 365 admin center. If they were managing any products, either for themselves or for your organization, they won't be able to manage them. This might include assigning licenses, changing payment methods, paying bills, or other tasks for managing subscriptions.
 
Template ID: d24aef57-1500-4070-84db-2666f29cf966
 
Don't use. This role isn't returned by PowerShell or the Microsoft Graph API. It's automatically assigned from Commerce, and isn't intended or supported for any other use.
 
The Modern Commerce Administrator role gives certain users permission to access Microsoft 365 admin center and see the left navigation entries for **Home**, **Billing**, and **Support**. The content available in these areas is controlled by [commerce-specific roles](/azure/cost-management-billing/manage/understand-mca-roles) assigned to users to manage products that they bought for themselves or your organization. This might include tasks like paying bills, or for access to billing accounts and billing profiles.
 
Users with the Modern Commerce Administrator role typically have administrative permissions in other Microsoft purchasing systems, but don't have Global Administrator or Billing Administrator roles used to access the admin center.
 
**When is the Modern Commerce Administrator role assigned?**
 
* **Self-service purchase in Microsoft 365 admin center** – Self-service purchase gives users a chance to try out new products by buying or signing up for them on their own. These products are managed in the admin center. Users who make a self-service purchase are assigned a role in the commerce system, and the Modern Commerce Administrator role so they can manage their purchases in admin center. Admins can block self-service purchases (for Fabric, Power BI, Power Apps, Power Automate) through [PowerShell](/microsoft-365/commerce/subscriptions/allowselfservicepurchase-powershell). For more information, see [Self-service purchase FAQ](/microsoft-365/commerce/subscriptions/self-service-purchase-faq).
* **Purchases from Microsoft commercial marketplace** – Similar to self-service purchase, when a user buys a product or service from Microsoft AppSource or Azure Marketplace, the Modern Commerce Administrator role is assigned if they don't have the Global Administrator or Billing Administrator role. In some cases, users might be blocked from making these purchases. For more information, see [Microsoft commercial marketplace](/azure/marketplace/marketplace-faq-publisher-guide#what-could-block-a-customer-from-completing-a-purchase-).
* **Proposals from Microsoft** – A proposal is a formal offer from Microsoft for your organization to buy Microsoft products and services. When the person who is accepting the proposal doesn't have a Global Administrator or Billing Administrator role in Microsoft Entra ID, they're assigned both a commerce-specific role to complete the proposal and the Modern Commerce Administrator role to access admin center. When they access the admin center, they can only use features that are authorized by their commerce-specific role.
* **Commerce-specific roles** – Some users are assigned commerce-specific roles. If a user isn't a Global Administrator or Billing Administrator, they get the Modern Commerce Administrator role so they can access the admin center.
 
If the Modern Commerce Administrator role is unassigned from a user, they lose access to Microsoft 365 admin center. If they were managing any products, either for themselves or for your organization, they won't be able to manage them. This might include assigning licenses, changing payment methods, paying bills, or other tasks for managing subscriptions.
Modified by Barclay Neira on Jul 11, 2025 3:52 AM
📖 View on learn.microsoft.com
+3 / -3 lines changed
Commit: updating includes
Changes:
Before
After
manager: pmwongera
ms.service: entra-id
ms.topic: include
ms.date: 03/05/2025
ms.custom: Identity-Secure-Recommendation
# 21885, 23183 are similar content.
# category: Application management
# userimpact: Low
# implementationcost: High
---
OAuth applications configured with URLs that include wildcards, localhost, or URL shorteners increase the attack surface for threat actors. Insecure redirect URIs (reply URLs) might allow adversaries to manipulate authentication requests, hijack authorization codes, and intercept tokens by directing users to attacker-controlled endpoints. Wildcard entries expand the risk by permitting unintended domains to process authentication responses, while localhost and shortener URLs might facilitate phishing and token theft in uncontrolled environments.
 
Without strict validation of redirect URIs, attackers can bypass security controls, impersonate legitimate applications, and escalate their privileges. This misconfiguration enables persistence, unauthorized access, and lateral movement, as adversaries exploit weak OAuth enforcement to infiltrate protected resources undetected.
 
**Remediation action**
 
- [Check the redirect URIs for your application registrations.](/entra/identity-platform/reply-url) Make sure the redirect URIs don't have localhost, *.azurewebsites.net, wildcards, or URL shorteners.
manager: pmwongera
ms.service: entra-id
ms.topic: include
ms.date: 07/10/2025
ms.custom: Identity-Secure-Recommendation
# 21885, 23183 are similar content.
# category: Application management
# userimpact: Low
# implementationcost: High
---
OAuth applications configured with URLs that include wildcards, or URL shorteners increase the attack surface for threat actors. Insecure redirect URIs (reply URLs) might allow adversaries to manipulate authentication requests, hijack authorization codes, and intercept tokens by directing users to attacker-controlled endpoints. Wildcard entries expand the risk by permitting unintended domains to process authentication responses, while shortener URLs might facilitate phishing and token theft in uncontrolled environments.
 
Without strict validation of redirect URIs, attackers can bypass security controls, impersonate legitimate applications, and escalate their privileges. This misconfiguration enables persistence, unauthorized access, and lateral movement, as adversaries exploit weak OAuth enforcement to infiltrate protected resources undetected.
 
**Remediation action**
 
- [Check the redirect URIs for your application registrations.](/entra/identity-platform/reply-url) Make sure the redirect URIs don't have *.azurewebsites.net, wildcards, or URL shorteners.
Modified by John Flores on Jul 11, 2025 1:24 AM
📖 View on learn.microsoft.com
+3 / -3 lines changed
Commit: Update recoverability-overview.md
Changes:
Before
After
- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
- [Microsoft Entra Exporter](https://github.com/microsoft/entraexporter) is a tool you can use to export your configuration settings.
- [Microsoft 365 Desired State Configuration](https://github.com/microsoft/Microsoft365DSC/wiki/What-is-Microsoft365DSC) is a module of the PowerShell Desired State Configuration framework. You can use it to export configurations for reference and application of the prior state of many settings.
- [Conditional Access APIs](https://github.com/Azure-Samples/azure-ad-conditional-access-apis) can be used to manage your Conditional Access policies as code.
 
In the rare case that an API is not available for a certain configuration setting, screenshot(s) can be taken to enable manual recovery.
 
> Settings in the legacy multifactor authentication portal for Application Proxy and federation settings might not be exported with the Microsoft Entra Exporter, or with the Microsoft Graph API.
The [Microsoft 365 Desired State Configuration](https://github.com/microsoft/Microsoft365DSC/wiki/What-is-Microsoft365DSC) module uses Microsoft Graph and PowerShell to retrieve the state of many of the configurations in Microsoft Entra ID. This information can be used as reference information or, by using PowerShell Desired State Configuration scripting, to reapply a known good state.
 
Use [Conditional Access Graph APIs](https://github.com/Azure-Samples/azure-ad-conditional-access-apis) to manage policies like code. Automate approvals to promote policies from preproduction environments, backup and restore, monitor change, and plan ahead for emergencies.
 
### Map the dependencies among objects
 
The deletion of some objects can cause a ripple effect because of dependencies. For example, deletion of a security group used for application assignment would result in users who were members of that group being unable to access the applications to which the group was assigned.
- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
- [Microsoft Entra Exporter](https://github.com/microsoft/entraexporter) is a tool you can use to export your configuration settings.
- [Microsoft 365 Desired State Configuration](https://github.com/microsoft/Microsoft365DSC/wiki/What-is-Microsoft365DSC) is a module of the PowerShell Desired State Configuration framework. You can use it to export configurations for reference and application of the prior state of many settings.
- [Conditional Access APIs](/graph/api/resources/conditionalaccesspolicy) can be used to manage your Conditional Access policies as code.
 
In the rare case that an API is not available for a certain configuration setting, screenshot(s) can be taken to enable manual recovery.
 
> Settings in the legacy multifactor authentication portal for Application Proxy and federation settings might not be exported with the Microsoft Entra Exporter, or with the Microsoft Graph API.
The [Microsoft 365 Desired State Configuration](https://github.com/microsoft/Microsoft365DSC/wiki/What-is-Microsoft365DSC) module uses Microsoft Graph and PowerShell to retrieve the state of many of the configurations in Microsoft Entra ID. This information can be used as reference information or, by using PowerShell Desired State Configuration scripting, to reapply a known good state.
 
Use [Conditional Access Graph APIs](/graph/api/resources/conditionalaccesspolicy) to manage policies like code.
### Map the dependencies among objects
 
The deletion of some objects can cause a ripple effect because of dependencies. For example, deletion of a security group used for application assignment would result in users who were members of that group being unable to access the applications to which the group was assigned.
Modified by OwenRichards1 on Jul 11, 2025 12:53 AM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: update-client-cred-doc
Changes:
Before
After
author: OwenRichards1
manager: CelesteDG
ms.author: owenrichards
ms.date: 01/04/2025
ms.service: identity-platform
ms.reviewer: jmprieur, ludwignick
ms.topic: reference
 
This article describes how to program directly against the protocol in your application. When possible, we recommend you use the supported Microsoft Authentication Libraries (MSAL) instead to [acquire tokens and call secured web APIs](authentication-flows-app-scenarios.md#scenarios-and-supported-authentication-flows). You can also refer to the [sample apps that use MSAL](sample-v2-code.md). As a side note, refresh tokens will never be granted with this flow as `client_id` and `client_secret` (which would be required to obtain a refresh token) can be used to obtain an access token instead.
 
For a higher level of assurance, the Microsoft identity platform also allows the calling service to authenticate using a [certificate](#second-case-access-token-request-with-a-certificate) or federated credential instead of a shared secret. Because the application's own credentials are being used, these credentials must be kept safe. *Never* publish that credential in your source code, embed it in web pages, or use it in a widely distributed native application.
 
## Protocol diagram
 
author: OwenRichards1
manager: CelesteDG
ms.author: owenrichards
ms.date: 07/10/2025
ms.service: identity-platform
ms.reviewer: jmprieur, ludwignick
ms.topic: reference
 
This article describes how to program directly against the protocol in your application. When possible, we recommend you use the supported Microsoft Authentication Libraries (MSAL) instead to [acquire tokens and call secured web APIs](authentication-flows-app-scenarios.md#scenarios-and-supported-authentication-flows). You can also refer to the [sample apps that use MSAL](sample-v2-code.md). As a side note, refresh tokens will never be granted with this flow as `client_id` and `client_secret` (which would be required to obtain a refresh token) can be used to obtain an access token instead.
 
For a higher level of assurance, the Microsoft identity platform also allows the calling service to authenticate using a [certificate](#second-case-access-token-request-with-a-certificate) or federated credential instead of a shared secret. Because the application's own credentials are being used, these credentials must be kept safe. *Never* publish that credential in your source code, embed it in web pages, or use it in a widely distributed native application. Authentication requests using the client credentials flow pages will not be allowed.
 
## Protocol diagram
 
Modified by Michael Morten Sonne | Microsoft MVP on Jul 11, 2025 10:00 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update concept-connector-groups.md
Changes:
Before
After
 
## Prerequisites
 
You must have multiple connectors to use connector groups. New connectors are automatically added to the **Default** connector group. For more information on installing connectors, see [configure connectorsD](how-to-configure-connectors.md).
 
 
## Assign applications to your connector groups
 
## Prerequisites
 
You must have multiple connectors to use connector groups. New connectors are automatically added to the **Default** connector group. For more information on installing connectors, see [configure connectors](how-to-configure-connectors.md).
 
 
## Assign applications to your connector groups

🗑️ Deleted Documentation Files

DELETED docs/verified-id/linkedin-employment-verification.md
Deleted by Barclay Neira on Jul 11, 2025 12:26 AM
📖 Was available at: https://learn.microsoft.com/en-us/entra/verified-id/linkedin-employment-verification
-89 lines removed
Commit: removing linkedin article