📋 Microsoft Entra Documentation Changes

Daily summary for changes since July 14th 2025, 8:40 PM PDT

Report generated on July 15th 2025, 8:40 PM PDT

📊 Summary

23
Total Commits
3
New Files
9
Modified Files
0
Deleted Files
10
Contributors

🆕 New Documentation Files

+19 lines added
Commit: missing-includes
+17 lines added
Commit: missing-includes
+17 lines added
Commit: missing-includes

📝 Modified Documentation Files

Modified by shlipsey3 on Jul 15, 2025 9:05 PM
📖 View on learn.microsoft.com
+12 / -0 lines changed
Commit: missing-includes
Changes:
Before
After
 
[!INCLUDE [21797](../includes/secure-recommendations/21797.md)]
 
### Restrict device code flow
 
[!INCLUDE [21808](../includes/secure-recommendations/21808.md)]
 
### Require multifactor authentication for device join and device registration using user action
 
[!INCLUDE [21872](../includes/secure-recommendations/21872.md)]
 
 
 
 
 
 
 
 
 
 
 
[!INCLUDE [21797](../includes/secure-recommendations/21797.md)]
 
### Restrict high risk sign-ins
 
[!INCLUDE [21799](../includes/secure-recommendations/21799.md)]
 
### Secure the MFA registration (My Security Info) page
 
[!INCLUDE [21806](../includes/secure-recommendations/21806.md)]
 
### Restrict device code flow
 
[!INCLUDE [21808](../includes/secure-recommendations/21808.md)]
 
### Authentication transfer is blocked
 
[!INCLUDE [21828](../includes/secure-recommendations/21828.md)]
 
### Require multifactor authentication for device join and device registration using user action
Modified by shlipsey3 on Jul 15, 2025 9:05 PM
📖 View on learn.microsoft.com
+8 / -4 lines changed
Commit: missing-includes
Changes:
Before
After
author: barclayn
ms.service: entra-id
ms.topic: include
ms.date: 06/17/2025
ms.custom: Identity-Secure-Recommendation
# category: Credential management
# risklevel: High
# userimpact: Medium
# implementationcost: Medium
---
When weak authentication methods like SMS and voice calls remain enabled in Microsoft Entra ID, threat actors can exploit these vulnerabilities through multiple attack vectors. Initially, attackers often conduct reconnaissance to identify organizations using these weaker authentication methods through social engineering or technical scanning. They then execute initial access through credential stuffing attacks, password spraying, or phishing campaigns targeting user credentials. Once basic credentials are compromised, threat actors use the inherent weaknesses in SMS and voice-based authentication - SMS messages can be intercepted through SIM swapping attacks, SS7 network vulnerabilities, or malware on mobile devices, while voice calls are susceptible to voice phishing (vishing) and call forwarding manipulation. With these weak second factors bypassed, attackers achieve persistence by registering their own authentication methods. This enables privilege escalation as compromised accounts can be used to target higher-privileged users through internal phishing or social engineering. Finally, threat actors achieve their objectives through data exfiltration, lateral movement to critical systems, or deployment of other malicious tools, all while maintaining stealth by using legitimate authentication pathways that appear normal in security logs.
 
**Remediation action**
 
- [Enable combined security information registration](/entra/identity/authentication/howto-registration-mfa-sspr-combined)
- [How to migrate MFA and SSPR policy settings to the Authentication methods policy for Microsoft Entra ID](/entra/identity/authentication/how-to-authentication-methods-manage)
 
 
 
 
author: barclayn
ms.service: entra-id
ms.topic: include
ms.date: 07/15/2025
ms.custom: Identity-Secure-Recommendation
# category: Credential management
# risklevel: High
# userimpact: Medium
# implementationcost: Medium
---
When weak authentication methods like SMS and voice calls remain enabled in Microsoft Entra ID, threat actors can exploit these vulnerabilities through multiple attack vectors. Initially, attackers often conduct reconnaissance to identify organizations using these weaker authentication methods through social engineering or technical scanning. Then they can execute initial access through credential stuffing attacks, password spraying, or phishing campaigns targeting user credentials.
 
Once basic credentials are compromised, threat actors use these weaknesses in SMS and voice-based authentication. SMS messages can be intercepted through SIM swapping attacks, SS7 network vulnerabilities, or malware on mobile devices, while voice calls are susceptible to voice phishing (vishing) and call forwarding manipulation. With these weak second factors bypassed, attackers achieve persistence by registering their own authentication methods. Compromised accounts can be used to target higher-privileged users through internal phishing or social engineering, allowing attackers to escalate privileges within the organization. Finally, threat actors achieve their objectives through data exfiltration, lateral movement to critical systems, or deployment of other malicious tools, all while maintaining stealth by using legitimate authentication pathways that appear normal in security logs.
 
**Remediation action**
 
- [Deploy authentication method registration campaigns to encourage stronger methods](/graph/api/authenticationmethodspolicy-update?view=graph-rest-beta&preserve-view=true)
- [Disable authentication methods](../../identity/authentication/concept-authentication-methods-manage.md)
- [Disable phone-based methods in legacy MFA settings](../../identity/authentication/howto-mfa-mfasettings.md)
- [Deploy Conditional Access policies using authentication strength](../../identity/authentication/concept-authentication-strength-how-it-works.md)
Modified by Ortagus Winfrey on Jul 15, 2025 5:18 PM
📖 View on learn.microsoft.com
+8 / -4 lines changed
Commit: Updated Customized Email fixes
Changes:
Before
After
 
1. On the pane that lists tasks, select the task for which you want to customize the email.
 
1. On the pane for the specific task under **Basics**, you can edit the task name or description, along with configuring which recipient or recipients you want to send the email to outside the default audience.
:::image type="content" source="media/customize-workflow-email/email-recipient-list.png" alt-text="Screenshot of the recipient list for an email customization task.":::
> [!NOTE]
> CC recipients are only available if the recipient is the user themselves or their manager. If there are multiple CC recipients, they're copied on the single individual email.
1. Select the **Email Customization** tab.
 
1. Enter a custom subject, a message body, and the email language translation option that will be used to translate the message body of the email.
 
 
 
 
 
1. On the pane that lists tasks, select the task for which you want to customize the email.
 
1. On the pane for the specific task under **Basics**, you can edit the task name or description, along with configuring which recipient or recipients you want to send the email to outside the default audience. You can set the To recipient to the user, their manager, their sponsor, or specific users, and Cc additional users as needed. If the user is the recipient, you can select which of their available email addresses to use from the mail, otherMails, directoryExtensions, or custom security attributes fields.
 
:::image type="content" source="media/customize-workflow-email/email-recipient-list-new.png" alt-text="Screenshot of the recipient list for an email customization task.":::
:::image type="content" source="media/customize-workflow-email/email-recipient-address-property.png" alt-text="Screenshot of the recipient list property for an email customization task.":::
 
> [!NOTE]
> CC recipients are only available if the recipient is the user themselves or their manager. If there are multiple CC recipients, they're copied on the single individual email.
1. Select the **Email Customization** tab.
 
1. Enter a custom subject, a message body, and the email language translation option that will be used to translate the message body of the email.
+5 / -5 lines changed
Commit: PR review: Update retire-service-principal-less-authentication.md
Changes:
Before
After
 
## Blocking app authentication without a service principal
 
Microsoft Entra ID will block authentication for all non-Microsoft multi-tenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.
 
App authentication without a service principal allows a multi-tenant client application to obtain an app-only token from a tenant without an object identifier (object ID) claim. In most cases, the absence of a service principal means the app hasn't been granted authorization to access any data, and this is harmless. However, in rare cases where the target API has implemented improper authorization checks, this capability could lead to unauthorized access. Microsoft has already verified that Microsoft-published APIs aren't vulnerable to this type of abuse. Disabling this behavior entirely also protects non-Microsoft APIs with insufficient authorization checks.
 
Additionally, by enforcing the requirement that all applications must have a service principal in every tenant where they authenticate, we facilitate tenant administrator's governance of all access, including the ability to target these apps individually with Conditional Access policies.
 
If applications you rely on are authenticating without a service principal in your tenant, you must act **before March 31, 2026** to avoid disruption.
 
5. Set the date range to **Last 1 month**.
6. Click on a log entry to view the details, and identify the app's **Application ID**. You'll need this in the next step.
 
:::image type="content" source="media/retire-service-principal-less-authentication/sign-in-logs.png" alt-text="Screenshot showing sign-in logs page of the Microsoft Entra admin center with filters applied to extract on SP-less auth sign ins.":::
 
## Create a service principal
 
 
## Verify the changes you made
 
## Blocking app authentication without a service principal
 
Microsoft Entra ID will block authentication for all non-Microsoft multitenant applications that don't have a service principal in the tenant where they're authenticating. This scenario is also known as service principal-less authentication. This behavior has already been disabled for most non-Microsoft applications. This change addresses a few remaining exceptions and is a preventive security measure.
 
App authentication without a service principal allows a multitenant client application to obtain an app-only token from a tenant without an object identifier (object ID) claim. In most cases, the absence of a service principal means the app hasn't been granted authorization to access any data, and this is harmless. However, in rare cases where the target API has implemented improper authorization checks, this capability could lead to unauthorized access. Microsoft has already verified that Microsoft-published APIs aren't vulnerable to this type of abuse. Disabling this behavior entirely also protects non-Microsoft APIs with insufficient authorization checks.
 
Additionally, by enforcing the requirement that all applications must have a service principal in every tenant where they authenticate, we facilitate the tenant administrator's governance of all access, including the ability to target these apps individually with Conditional Access policies.
 
If applications you rely on are authenticating without a service principal in your tenant, you must act **before March 31, 2026** to avoid disruption.
 
5. Set the date range to **Last 1 month**.
6. Click on a log entry to view the details, and identify the app's **Application ID**. You'll need this in the next step.
 
:::image type="content" source="media/retire-service-principal-less-authentication/sign-in-logs.png" alt-text="Screenshot showing sign-in logs page of the Microsoft Entra admin center with filters applied to extract on SP-less auth sign ins." lightbox="media/retire-service-principal-less-authentication/sign-in-logs.png":::
 
## Create a service principal
 
 
## Verify the changes you made
Modified by Sumeet Mittal on Jul 15, 2025 6:05 PM
📖 View on learn.microsoft.com
+2 / -7 lines changed
Commit: Update how-to-enable-multi-geo.md
Changes:
Before
After
---
title: Multi-Geo for Microsoft Entra Private Access (Preview)
description: "Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps."
ms.author: jayrusso
author: HULKsmashGithub
#customer intent: As an IT admin, I want to enable Multi-Geo Capability for Microsoft Entra Private Access so that I can optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
 
---
# Enable multi-Geo capability for Microsoft Entra Private Access (Preview)
Multi-Geo capability can help optimize the traffic flow from Microsoft Entra clients to Microsoft Entra apps through private access. This article explains how to enable the multi-Geo capability for Microsoft Entra Private Access.
 
> [!IMPORTANT]
> Multi-Geo capability for Microsoft Entra Private Access is currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
> The preview is for testing purposes; don't use the preview for production traffic. We recommend that you use a test tenant for the preview. If you must use a production tenant for testing, don't use production connector groups. Instead, create a separate test connector group.
 
## Prerequisites
 
- You must have a Microsoft Entra Private Access license.
---
title: Multi-Geo for Microsoft Entra Private Access
description: "Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps."
ms.author: jayrusso
author: HULKsmashGithub
#customer intent: As an IT admin, I want to enable Multi-Geo Capability for Microsoft Entra Private Access so that I can optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
 
---
# Enable multi-Geo capability for Microsoft Entra Private Access
Multi-Geo capability can help optimize the traffic flow from Microsoft Entra clients to Microsoft Entra apps through private access. This article explains how to enable the multi-Geo capability for Microsoft Entra Private Access.
 
## Prerequisites
 
- You must have a Microsoft Entra Private Access license.
 
 
 
 
 
Modified by Ortagus Winfrey on Jul 15, 2025 3:22 PM
📖 View on learn.microsoft.com
+3 / -3 lines changed
Commit: Remove refresh token preview tag
Changes:
Before
After
}
```
 
### Revoke all refresh tokens for user (Preview)
 
Allows all refresh and browser session tokens to be revoked for a user. This invalidates all the refresh tokens and browser session tokens issued to applications for a user, except external user sign-in sessions because external users sign in through their home tenant.
 
|Parameter |Definition |
|---------|---------|
|category | leaver,mover |
|displayName | Revoke all refresh tokens for user (Preview) |
|description | Revoke all refresh tokens for user |
|taskDefinitionId | 509589a4-0466-4471-829e-49c5e502bdee |
 
{
"category": "leaver, mover",
"continueOnError": false,
"description": "Revoke all refresh tokens for user (Preview)",
"displayName": "Revoke all refresh tokens for user",
"isEnabled": true,
}
```
 
### Revoke all refresh tokens for user
 
Allows all refresh and browser session tokens to be revoked for a user. This invalidates all the refresh tokens and browser session tokens issued to applications for a user, except external user sign-in sessions because external users sign in through their home tenant.
 
|Parameter |Definition |
|---------|---------|
|category | leaver,mover |
|displayName | Revoke all refresh tokens for user |
|description | Revoke all refresh tokens for user |
|taskDefinitionId | 509589a4-0466-4471-829e-49c5e502bdee |
 
{
"category": "leaver, mover",
"continueOnError": false,
"description": "Revoke all refresh tokens for user",
"displayName": "Revoke all refresh tokens for user",
"isEnabled": true,
Modified by Ortagus Winfrey on Jul 15, 2025 3:28 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updates
Changes:
Before
After
**Service category:** Lifecycle Workflows
**Product capability:** Identity Governance
 
Now customers can configure a Lifecycle workflows task to automatically revoke access tokens when employees move within, or leave, the organization. For more information, see: [Revoke all refresh tokens for user (Preview)](../id-governance/lifecycle-workflow-tasks.md#revoke-all-refresh-tokens-for-user-preview).
 
---
 
**Service category:** Lifecycle Workflows
**Product capability:** Identity Governance
 
Now customers can configure a Lifecycle workflows task to automatically revoke access tokens when employees move within, or leave, the organization. For more information, see: [Revoke all refresh tokens for user](../id-governance/lifecycle-workflow-tasks.md#revoke-all-refresh-tokens-for-user).
 
---
 
Modified by Ortagus Winfrey on Jul 15, 2025 3:27 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Includes file fixed
Changes:
Before
After
| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |
| [Cancel all pending access package assignment requests for user](../id-governance/lifecycle-workflow-tasks.md#cancel-all-pending-access-package-assignment-requests-for-user) | 498770d9-bab7-4e4c-b73d-5ded82a1d0b3 | Leaver |
| [Remove selected license assignments from user](../id-governance/lifecycle-workflow-tasks.md#remove-selected-license-assignments-from-user) | 5fc402a8-daaf-4b7b-9203-da868b05fc5f | Leaver, Mover |
| [Revoke all refresh tokens for user (Preview)](../id-governance/lifecycle-workflow-tasks.md#revoke-all-refresh-tokens-for-user-preview) | 509589a4-0466-4471-829e-49c5e502bdee | Leaver, Mover |
| [Remove all license assignments from user](../id-governance/lifecycle-workflow-tasks.md#remove-all-license-assignments-from-user) | 8fa97d28-3e52-4985-b3a9-a1126f9b8b4e | Leaver |
| [Delete user](../id-governance/lifecycle-workflow-tasks.md#delete-user) | 8d18588d-9ad3-4c0f-99d0-ec215f0e3dff | Leaver |
| [Send email to manager before user's last day](../id-governance/lifecycle-workflow-tasks.md#send-email-to-manager-before-users-last-day) | 52853a3e-f4e5-4eb8-bb24-1ac09a1da935 | Leaver |
| [Remove all access package assignments for user](../id-governance/lifecycle-workflow-tasks.md#remove-all-access-package-assignments-for-user) | 42ae2956-193d-4f39-be06-691b8ac4fa1d | Leaver |
| [Cancel all pending access package assignment requests for user](../id-governance/lifecycle-workflow-tasks.md#cancel-all-pending-access-package-assignment-requests-for-user) | 498770d9-bab7-4e4c-b73d-5ded82a1d0b3 | Leaver |
| [Remove selected license assignments from user](../id-governance/lifecycle-workflow-tasks.md#remove-selected-license-assignments-from-user) | 5fc402a8-daaf-4b7b-9203-da868b05fc5f | Leaver, Mover |
| [Revoke all refresh tokens for user](../id-governance/lifecycle-workflow-tasks.md#revoke-all-refresh-tokens-for-user) | 509589a4-0466-4471-829e-49c5e502bdee | Leaver, Mover |
| [Remove all license assignments from user](../id-governance/lifecycle-workflow-tasks.md#remove-all-license-assignments-from-user) | 8fa97d28-3e52-4985-b3a9-a1126f9b8b4e | Leaver |
| [Delete user](../id-governance/lifecycle-workflow-tasks.md#delete-user) | 8d18588d-9ad3-4c0f-99d0-ec215f0e3dff | Leaver |
| [Send email to manager before user's last day](../id-governance/lifecycle-workflow-tasks.md#send-email-to-manager-before-users-last-day) | 52853a3e-f4e5-4eb8-bb24-1ac09a1da935 | Leaver |
Modified by Ortagus Winfrey on Jul 15, 2025 12:13 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: workflow limit update
Changes:
Before
After
 
|Item|Description|
|-----|-----|
|Workflows|50 workflow limit per tenant|
|Number of custom tasks|limit of 25 per workflow|
|Value range for offsetInDays|Between -180 and 180 days|
|Workflow execution schedule|Default every 3 hours - can be set to run anywhere from 1 to 24 hours|
 
|Item|Description|
|-----|-----|
|Workflows|100 workflow limit per tenant|
|Number of custom tasks|limit of 25 per workflow|
|Value range for offsetInDays|Between -180 and 180 days|
|Workflow execution schedule|Default every 3 hours - can be set to run anywhere from 1 to 24 hours|