πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since July 20th 2025, 8:42 PM PDT

Report generated on July 21st 2025, 8:42 PM PDT

πŸ“Š Summary

22
Total Commits
0
New Files
80
Modified Files
0
Deleted Files
12
Contributors

πŸ“ Modified Documentation Files

Modified by shlipsey3 on Jul 21, 2025 5:04 PM
πŸ“– View on learn.microsoft.com
+118 / -178 lines changed
Commit: sec-recs-sfi-pillars-072125
Changes:
Before
After
ms.service: entra
ms.subservice: fundamentals
ms.topic: reference
ms.date: 07/14/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Configure Microsoft Entra for increased security (Preview)
 
In Microsoft Entra, we group our security recommendations into several main areas. This structure allows organizations to logically break up projects into related consumable chunks.
 
> [!TIP]
> Some organizations might take these recommendations exactly as written, while others might choose to make modifications based on their own business needs. In our initial release of this guidance, we focus on traditional [workforce tenants](/entra/external-id/tenant-configurations#workforce-tenants). These workforce tenants are for your employees, internal business apps, and other organizational resources.
 
We recommend that all of the following controls be implemented where licenses are available. This helps to provide a foundation for other resources built on top of this solution. More controls will be added to this document over time.
 
## Privileged access
 
### Privileged accounts are cloud native identities
ms.service: entra
ms.subservice: fundamentals
ms.topic: reference
ms.date: 07/21/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Configure Microsoft Entra for increased security (Preview)
 
The security recommendations in this document are designed to help you improve your security posture in Microsoft Entra. These recommendations are influenced by accepted industry standards like those developed by NIST, the configuration baselines we use internally at Microsoft, and our experiences with customers. The recommendations are organized by the [Secure Future Initiative](https://www.microsoft.com/trust-center/security/secure-future-initiative?msockid=2bad2df65a416adb0e5838355b3e6b95#SFI-pillars) pillars:
 
- Protect identities and secrets
- Protect tenants and isolate production systems
- Protect networks
- Protect engineering systems
- Monitor and detect cyberthreats
- Accelerate response and remediation
 
> [!TIP]
Modified by John Flores on Jul 21, 2025 6:24 PM
πŸ“– View on learn.microsoft.com
+19 / -14 lines changed
Commit: Freshness updates July1
Changes:
Before
After
---
title: Providing a default level of security in Microsoft Entra ID
description: Get protected from common identity threats using Microsoft Entra security defaults.
ms.service: entra
ms.subservice: fundamentals
ms.topic: conceptual
ms.date: 04/15/2024
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: sama
ms.custom: sfi-ga-nochange, sfi-image-nochange
---
# Security defaults in Microsoft Entra ID
 
### Require all users to register for Microsoft Entra multifactor authentication
 
> [!NOTE]
> Starting July 29, 2024, new tenants and existing tenants had the 14-day grace period for users to register for MFA removed. We are making this change to help reduce the risk of account compromise during the 14-day window, as MFA can block over 99.2% of identity-based attacks.
 
---
title: Configure Security Defaults for Microsoft Entra ID
description: Enable Microsoft Entra ID security defaults to strengthen your organization's security posture with preconfigured MFA requirements and legacy authentication protection.
ms.service: entra
ms.subservice: fundamentals
ms.topic: conceptual
ms.date: 07/21/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: sama
ms.custom:
- sfi-ga-nochange, sfi-image-nochange
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/21/2025
- ai-gen-description
---
# Security defaults in Microsoft Entra ID
 
Modified by John Flores on Jul 21, 2025 6:24 PM
πŸ“– View on learn.microsoft.com
+19 / -14 lines changed
Commit: Freshness updates July1
Changes:
Before
After
---
title: Terms of use in Microsoft Entra
description: Get started using Microsoft Entra terms of use to present information to employees or guests before getting access.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 03/11/2024
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: siz
ms.custom: sfi-image-nochange
---
# Microsoft Entra terms of use
 
Microsoft Entra terms of use policies provide a simple method to present information to end users. Organizations can use terms of use along with Conditional Access policies to require employees or guests to accept your terms of use policy before getting access. These terms of use statements can be generalized or specific to groups or users and provided in multiple languages. Administrators can determine who has or hasn't accepted terms of use with the provided logs or APIs.
 
[!INCLUDE [GDPR-related guidance](~/includes/azure-docs-pr/gdpr-intro-sentence.md)]
 
 
---
title: Set Up Microsoft Entra Terms of Use with Conditional Access
description: Set up Microsoft Entra terms of use with Conditional Access to require policy acceptance before resource access. Complete guide with prerequisites, step-by-step configuration, and troubleshooting tips.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 07/21/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: siz
ms.custom:
- sfi-image-nochange
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/21/2025
- ai-gen-description
---
# Set up Microsoft Entra terms of use with Conditional Access
 
Modified by John Flores on Jul 21, 2025 6:24 PM
πŸ“– View on learn.microsoft.com
+15 / -17 lines changed
Commit: Freshness updates July1
Changes:
Before
After
---
title: Secure your organization's identities
description: Improve your security posture and empower users with Microsoft Entra ID with the principles of Zero Trust architecture.
 
ms.service: entra
ms.subservice: fundamentals
ms.topic: conceptual
ms.date: 05/31/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
 
ms.reviewer: lhuangnorth, martinco
ms.custom: zt-include
---
 
# Secure your organization's identities with Microsoft Entra ID
 
It can seem daunting trying to secure your workers in today's world, especially when you have to respond rapidly and provide access to many services quickly. This article helps provide a concise list of actions to take, helping you identify and prioritize features based on the license type you own.
---
title: Secure Your Workforce with Microsoft Entra ID
description: Learn how to protect organizational identities with Microsoft Entra ID. Discover security recommendations, multifactor authentication setup, and Zero Trust implementation strategies.
ms.service: entra
ms.subservice: fundamentals
ms.topic: conceptual
ms.date: 07/21/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: lhuangnorth, martinco
ms.custom:
- zt-include
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/21/2025
- ai-gen-description
---
# Secure your organization's identities with Microsoft Entra ID
 
+8 / -12 lines changed
Commit: Freshness updates July1
Changes:
Before
After
---
title: Users and groups in Conditional Access policy
description: Who are users and groups in a Microsoft Entra Conditional Access policy?
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 05/21/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
 
A Conditional Access policy must include a user, group, or workload identity assignment as one of the signals in the decision process. These identities can be included or excluded from Conditional Access policies. Microsoft Entra ID evaluates all policies and ensures that all requirements are met before granting access.
 
> [!VIDEO https://www.youtube.com/embed/5DsW1hB3Jqs]
 
## Include users
 
This list of users typically includes all of the users an organization is targeting in a Conditional Access policy.
---
title: Configure Users, Groups, and Workload Identities in Conditional Access
description: Configure Conditional Access user assignments in Microsoft Entra ID. Target specific users, groups, directory roles, and workload identities while avoiding administrator lockout with proper exclusions.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 07/21/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
 
A Conditional Access policy must include a user, group, or workload identity assignment as one of the signals in the decision process. These identities can be included or excluded from Conditional Access policies. Microsoft Entra ID evaluates all policies and ensures that all requirements are met before granting access.
 
## Include users
 
This list of users typically includes all of the users an organization is targeting in a Conditional Access policy.
- Allows targeting of specific sets of users. For example, organizations can select a group that contains all members of the HR department when an HR app is selected as the cloud app. A group can be any type of user group in Microsoft Entra ID, including dynamic or assigned security and distribution groups. Policy is applied to nested users and groups.
 
> [!IMPORTANT]
> When selecting which users and groups are included in a Conditional Access Policy, there's a limit to the number of individual users that can be added directly to a Conditional Access policy. If there are a large number of individual users that need to be added directly to a Conditional Access policy, we recommend placing the users in a group, and assigning the group to the Conditional Access policy instead.
+6 / -7 lines changed
Commit: Freshness updates July1
Changes:
Before
After
 
Organizations that deploy Intune can use the information returned from their devices to identify devices that meet specific policy compliance requirements. Intune sends compliance information to Microsoft Entra ID so Conditional Access can decide to grant or block access to resources. For more information about compliance policies, see [Set rules on devices to allow access to resources in your organization by using Intune](/mem/intune/protect/device-compliance-get-started).
 
A device can be marked as compliant by Intune for any device operating system or by a third-party mobile device management system for Windows devices. You can find a list of supported third-party mobile device management systems in [Support third-party device compliance partners in Intune](/mem/intune/protect/device-compliance-partners).
 
Devices must be registered in Microsoft Entra ID before they can be marked as compliant. You can find more information about device registration in [What is a device identity?](~/identity/devices/overview.md).
 
The **Require device to be marked as compliant** control:
 
- Only supports Windows 10+, iOS, Android, macOS, and Linux Ubuntu devices registered with Microsoft Entra ID and enrolled with Intune.
- Microsoft Edge in InPrivate mode on Windows is considered a noncompliant device.
 
> [!NOTE]
> On Windows, iOS, Android, macOS, and some third-party web browsers, Microsoft Entra ID identifies the device by using a client certificate that is provisioned when the device is registered with Microsoft Entra ID. When a user first signs in through the browser, the user is prompted to select the certificate. The user must select this certificate before they can continue to use the browser.
 
You can use the Microsoft Defender for Endpoint app with the approved client app policy in Intune to set the device compliance policy to Conditional Access policies. There's no exclusion required for the Microsoft Defender for Endpoint app while you're setting up Conditional Access. Although Microsoft Defender for Endpoint on Android and iOS (app ID dd47d17a-3194-4d86-bfd5-c6ae6f5651e3) isn't an approved app, it has permission to report device security posture. This permission enables the flow of compliance information to Conditional Access.
 
Similarly, the **Require device to be marked as compliant** doesn't block Microsoft Authenticator app access to the UserAuthenticationMethod.Read scope. Authenticator needs access to the UserAuthenticationMethod.Read scope during Authenticator registration to determine which credentials a user can configure. Authenticator needs access to UserAuthenticationMethod.ReadWrite to register credentials, which doesn't bypass the **Require device to be marked as compliant** check.
 
<a name='require-hybrid-azure-ad-joined-device'></a>
 
Organizations that deploy Intune can use the information returned from their devices to identify devices that meet specific policy compliance requirements. Intune sends compliance information to Microsoft Entra ID so Conditional Access can decide to grant or block access to resources. For more information about compliance policies, see [Set rules on devices to allow access to resources in your organization by using Intune](/mem/intune/protect/device-compliance-get-started).
 
A device can be marked as compliant by Intune for any device operating system or by a non-Microsoft mobile device management system for Windows devices. You can find a list of supported non-Microsoft mobile device management systems in [Support non-Microsoft device compliance partners in Intune](/mem/intune/protect/device-compliance-partners).
 
Devices must be registered in Microsoft Entra ID before they can be marked as compliant. You can find more information about device registration in [What is a device identity?](~/identity/devices/overview.md).
 
The **Require device to be marked as compliant** control:
 
- Only supports Windows 10+, iOS, Android, macOS, and Linux Ubuntu devices registered with Microsoft Entra ID and enrolled with Intune.
- Microsoft Edge in InPrivate mode on Windows is considered as a noncompliant device.
 
> [!NOTE]
> On Windows, iOS, Android, macOS, and some non-Microsoft web browsers, Microsoft Entra ID identifies the device by using a client certificate that is provisioned when the device is registered with Microsoft Entra ID. When a user first signs in through the browser, the user is prompted to select the certificate. The user must select this certificate before they can continue to use the browser.
 
You can use the Microsoft Defender for Endpoint app with the approved client app policy in Intune to set the device compliance policy to Conditional Access policies. There's no exclusion required for the Microsoft Defender for Endpoint app while you're setting up Conditional Access. Although Microsoft Defender for Endpoint on Android and iOS (app ID dd47d17a-3194-4d86-bfd5-c6ae6f5651e3) isn't an approved app, it has permission to report device security posture. This permission enables the flow of compliance information to Conditional Access.
 
Similarly, the **Require device to be marked as compliant** doesn't block Microsoft Authenticator app access to the `UserAuthenticationMethod.Read` scope. Authenticator needs access to the `UserAuthenticationMethod.Read` scope during Authenticator registration to determine which credentials a user can configure. Authenticator needs access to `UserAuthenticationMethod.ReadWrite` to register credentials, which doesn't bypass the **Require device to be marked as compliant** check.
 
<a name='require-hybrid-azure-ad-joined-device'></a>
+4 / -4 lines changed
Commit: Restart numbering
Changes:
Before
After
 
If the agent identifies something that wasn't previously suggested, it takes the following steps. **The agent action steps consume SCUs.**
 
4. The agent identifies a policy gap or a pair of policies that can be consolidated.
5. The agent evaluates any custom instructions you provided.
6. The agent creates a new policy in report-only mode or provides the suggestion to modify a policy, including any logic provided by the custom instructions.
 
> [!TIP]
> Two policies can be consolidated if they differ by no more than two conditions or controls.
 
- [Review and approve agent suggestions](agent-optimization-review-suggestions.md)
- [Conditional Access policy templates](concept-conditional-access-policy-common.md?tabs=secure-foundation#template-categories)
- [Learn more about Microsoft Security Copilot](/copilot/security/microsoft-security-copilot)
 
If the agent identifies something that wasn't previously suggested, it takes the following steps. **The agent action steps consume SCUs.**
 
1. The agent identifies a policy gap or a pair of policies that can be consolidated.
1. The agent evaluates any custom instructions you provided.
1. The agent creates a new policy in report-only mode or provides the suggestion to modify a policy, including any logic provided by the custom instructions.
 
> [!TIP]
> Two policies can be consolidated if they differ by no more than two conditions or controls.
 
- [Review and approve agent suggestions](agent-optimization-review-suggestions.md)
- [Conditional Access policy templates](concept-conditional-access-policy-common.md?tabs=secure-foundation#template-categories)
- [Learn more about Microsoft Security Copilot](/copilot/security/microsoft-security-copilot)
+4 / -4 lines changed
Commit: added that SSPR with writeback isn't supported
Changes:
Before
After
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 04/09/2025
ms.subservice: hybrid-connect
ms.author: jomondi
ms.custom: sfi-image-nochange
 
- User sign-inΒ traffic on browsers and *modern authentication* clients. Applications or cloud services that use legacy authentication fall back to federated authentication flows. An example of legacy authentication might be Exchange online with modern authentication turned off, or Outlook 2010, which doesn't support modern authentication.
 
- Staged rollout supports groups of any size, provided they comply with the [Microsoft Entra directory service limits and restrictions](~/identity/users/directory-service-limits-restrictions.md)
 
- Windows 10 Hybrid Join or Microsoft Entra join primary refresh token acquisition without line-of-sight to the federation server for Windows 10 version 1903 and newer, when user's UPN is routable and domain suffix is verified in Microsoft Entra ID.
 
 
- Legacy authentication such as POP3 and SMTP aren't supported.
 
- Certain applications send the "domain_hint" query parameter to Microsoft Entra ID during authentication. These flows continue, and users who are enabled for Staged Rollout continue to use federation for authentication.
 
<!-- -->
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 07/21/2025
ms.subservice: hybrid-connect
ms.author: jomondi
ms.custom: sfi-image-nochange
 
- User sign-inΒ traffic on browsers and *modern authentication* clients. Applications or cloud services that use legacy authentication fall back to federated authentication flows. An example of legacy authentication might be Exchange online with modern authentication turned off, or Outlook 2010, which doesn't support modern authentication.
 
- Staged rollout supports groups of any size, provided they comply with the [Microsoft Entra directory service limits and restrictions](~/identity/users/directory-service-limits-restrictions.md).
 
- Windows 10 Hybrid Join or Microsoft Entra join primary refresh token acquisition without line-of-sight to the federation server for Windows 10 version 1903 and newer, when user's UPN is routable and domain suffix is verified in Microsoft Entra ID.
 
 
- Legacy authentication such as POP3 and SMTP aren't supported.
 
- Self-service password reset with writeback to an on-premises domain isn't supported.
 
- Certain applications send the "domain_hint" query parameter to Microsoft Entra ID during authentication. These flows continue, and users who are enabled for Staged Rollout continue to use federation for authentication.
+5 / -2 lines changed
Commit: added that staged rollout isn't supported
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: justinha
author: justinha
manager: dougeby
* [Pass-through authentication](~/identity/hybrid/connect/how-to-connect-pta.md)
* [Active Directory Federation Services](~/identity/hybrid/connect/how-to-connect-fed-management.md)
 
Password writeback provides the following features:
 
* **Enforcement of on-premises Active Directory Domain Services (AD DS) password policies**: When a user resets their password, it's checked to ensure it meets your on-premises AD DS policy before committing it to that directory. This review includes checking the history, complexity, age, password filters, and any other password restrictions that you define in AD DS.
To get started with SSPR writeback, complete either one or both of the following tutorials:
 
- [Tutorial: Enable self-service password reset (SSPR) writeback](tutorial-enable-sspr-writeback.md)
- [Tutorial: Enable Microsoft Entra Connect cloud sync self-service password reset writeback to an on-premises environment (Preview)](tutorial-enable-cloud-sync-sspr-writeback.md)
 
<a name='azure-ad-connect-and-cloud-sync-side-by-side-deployment'></a>
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 07/21/2025
ms.author: justinha
author: justinha
manager: dougeby
* [Pass-through authentication](~/identity/hybrid/connect/how-to-connect-pta.md)
* [Active Directory Federation Services](~/identity/hybrid/connect/how-to-connect-fed-management.md)
 
> [!NOTE]
> SSPR with writeback to an on-premises domain isn't supported when staged rollout is enabled for a security group.
 
Password writeback provides the following features:
 
* **Enforcement of on-premises Active Directory Domain Services (AD DS) password policies**: When a user resets their password, it's checked to ensure it meets your on-premises AD DS policy before committing it to that directory. This review includes checking the history, complexity, age, password filters, and any other password restrictions that you define in AD DS.
To get started with SSPR writeback, complete either one or both of the following tutorials:
 
- [Tutorial: Enable self-service password reset (SSPR) writeback](tutorial-enable-sspr-writeback.md)
- [Tutorial: Enable Microsoft Entra Connect cloud sync self-service password reset writeback to an on-premises environment](tutorial-enable-cloud-sync-sspr-writeback.md)
+3 / -3 lines changed
Commit: Freshness updates July1
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 05/29/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
Repeat the previous steps on all of your policies that use the approved client app grant.
 
> [!WARNING]
> Not all applications that are supported as approved applications are supported by application protection policies. For a list of some common client apps, seeβ€―[App protection policy requirement](concept-conditional-access-grant.md#require-app-protection-policy). If your application is not listed there, contact the application developer.
 
## Create a Conditional Access policy
 
[!INCLUDE [conditional-access-report-only-mode](../../includes/conditional-access-report-only-mode.md)]
 
> [!NOTE]
> If an app does not support **Require app protection policy**, end users trying to access resources from that app will be blocked.
 
## Next steps
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 07/21/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
Repeat the previous steps on all of your policies that use the approved client app grant.
 
> [!WARNING]
> Not all applications that are supported as approved applications support application protection policies. For a list of some common client apps, seeβ€―[App protection policy requirement](concept-conditional-access-grant.md#require-app-protection-policy). If your application isn't listed there, contact the application developer.
 
## Create a Conditional Access policy
 
[!INCLUDE [conditional-access-report-only-mode](../../includes/conditional-access-report-only-mode.md)]
 
> [!NOTE]
> If an app doesn't support **Require app protection policy**, end users trying to access resources from that app are blocked.
 
## Next steps
+3 / -2 lines changed
Commit: ca-agent-072125
Changes:
Before
After
ms.author: sarahlipsey
author: shlipsey3
ms.reviewer: lhuangnorth
ms.date: 07/13/2025
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
- We recommend running the agent from the Microsoft Entra admin center.
- Scanning is limited to a 24 hour period.
- Suggestions from the agent can't be customized or overridden.
 
## Agent summary
 
 
ms.author: sarahlipsey
author: shlipsey3
ms.reviewer: lhuangnorth
manager: pmwongera
ms.date: 07/21/2025
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
- We recommend running the agent from the Microsoft Entra admin center.
- Scanning is limited to a 24 hour period.
- Suggestions from the agent can't be customized or overridden.
- The agent can review up to 150 users and 100 applications in a single run.
 
## Agent summary
 
+3 / -2 lines changed
Commit: ca-agent-072125
Changes:
Before
After
ms.author: sarahlipsey
author: shlipsey3
ms.reviewer: lhuangnorth
ms.date: 07/13/2025
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
- We recommend running the agent from the Microsoft Entra admin center.
- Scanning is limited to a 24 hour period.
- Suggestions from the agent can't be customized or overridden.
 
## How it works
 
 
ms.author: sarahlipsey
author: shlipsey3
ms.reviewer: lhuangnorth
manager: pmwongera
ms.date: 07/21/2025
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
- We recommend running the agent from the Microsoft Entra admin center.
- Scanning is limited to a 24 hour period.
- Suggestions from the agent can't be customized or overridden.
- The agent can review up to 150 users and 100 applications in a single run.
 
## How it works
 
+2 / -3 lines changed
Commit: Update how-to-configure-domain-controllers.md
Changes:
Before
After
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 07/17/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.reviewer: shkhalid
### 6. Install the Private Access Sensor on the domain controller
 
1. Download the Private Access Sensor for DC from Microsoft Entra admin center at **Global Secure Access** > **Connect** > **Connectors and sensors** > **Private access sensors** > **Download private access sensor**.
1. Extract the zip file.
1. Install the sensor by running the `PrivateAccessSensorInstaller` batch file, or install the `PrivateAccessSensor` package followed by the `PrivateAccessSensorPolicyRetreiverInstaller` package.
1. During installation, sign in with a Microsoft Entra ID user when prompted.
1. After installation, in the Microsoft Entra admin center, go to **Global Secure Access** > **Connect** > **Connectors and sensors** > **Private access sensors** and verify the sensor status is **Active**.
 
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 07/21/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.reviewer: shkhalid
### 6. Install the Private Access Sensor on the domain controller
 
1. Download the Private Access Sensor for DC from Microsoft Entra admin center at **Global Secure Access** > **Connect** > **Connectors and sensors** > **Private access sensors** > **Download private access sensor**.
1. Install by clicking the Private Access Sensor Installer and follow the steps.
1. During installation, sign in with a Microsoft Entra ID user when prompted.
1. After installation, in the Microsoft Entra admin center, go to **Global Secure Access** > **Connect** > **Connectors and sensors** > **Private access sensors** and verify the sensor status is **Active**.
 
 
Modified by John Flores on Jul 21, 2025 8:50 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/includes/secure-recommendations/21851.md
Changes:
Before
After
ms.date: 07/10/2025
ms.custom: Identity-Secure-Recommendation
# sfipillar: Protect tenants and isolate production systems
# category:
# risklevel: Medium
# userimpact: Medium
# implementationcost: Medium
ms.date: 07/10/2025
ms.custom: Identity-Secure-Recommendation
# sfipillar: Protect tenants and isolate production systems
# category: External collaboration
# risklevel: Medium
# userimpact: Medium
# implementationcost: Medium
Modified by John Flores on Jul 21, 2025 8:45 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Add SFI pillar metadata
Changes:
Before
After
ms.topic: include
ms.date: 06/27/2025
ms.custom: Identity-Secure-Recommendation
 
# category: Credential management
# risklevel: Medium
# userimpact: Low
ms.topic: include
ms.date: 06/27/2025
ms.custom: Identity-Secure-Recommendation
# sfipillar: Protect identities and secrets
# category: Credential management
# risklevel: Medium
# userimpact: Low