📋 Microsoft Entra Documentation Changes

Daily summary for changes since July 21st 2025, 8:44 PM PDT

Report generated on July 22nd 2025, 8:44 PM PDT

📊 Summary

23
Total Commits
0
New Files
78
Modified Files
0
Deleted Files
10
Contributors

📝 Modified Documentation Files

+15 / -10 lines changed
Commit: Freshness updates July2
Changes:
Before
After
---
title: Simplify Conditional Access policy deployment with templates
description: Deploy recommended Conditional Access policies from easy to use templates.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 08/28/2024
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: lhuangnorth
ms.custom: sfi-image-nochange
---
# Conditional Access policy templates
 
 
# [Secure foundation](#tab/secure-foundation)
 
Microsoft recommends these policies as the base for all organizations. We recommend these policies be deployed as a group.
 
---
title: 'Conditional Access Templates: Simplify Security'
description: Learn how Conditional Access templates provide preconfigured policies to secure your environment, aligned with Microsoft recommendations.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 07/22/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: lhuangnorth
ms.custom:
- sfi-image-nochange
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/22/2025
- ai-gen-description
---
# Conditional Access policy templates
 
+12 / -11 lines changed
Commit: Freshness updates July2
Changes:
Before
After
---
title: Continuous access evaluation in Microsoft Entra
description: Responding to changes in user state faster with continuous access evaluation in Microsoft Entra
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 03/14/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: vmahtani
ms.custom: has-adal-ref
 
---
# Continuous access evaluation
 
This process enables the scenario where users lose access to files, email, calendar, or tasks from Microsoft 365 client apps or SharePoint Online immediately after network location changes.
 
---
title: Continuous access evaluation in Microsoft Entra
description: Learn how continuous access evaluation in Microsoft Entra enhances security by responding to user state changes in near real time.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 07/22/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: vmahtani
ms.custom:
- has-adal-ref
- ai-gen-docs-bap
- ai-gen-description
- ai-seo-date:07/22/2025
---
# Continuous access evaluation
 
This process enables the scenario where users lose access to files, email, calendar, or tasks from Microsoft 365 client apps or SharePoint Online immediately after network location changes.
+11 / -8 lines changed
Commit: Freshness updates July2
Changes:
Before
After
---
title: Building a Conditional Access policy
description: What are all of the options available to build a Conditional Access policy and what do they mean?
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 03/29/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: lhuangnorth
---
# Building a Conditional Access policy
 
 
### Users and groups
 
[Users and groups](concept-conditional-access-users-groups.md) assign who the policy include or exclude when applied. This assignment can include all users, specific groups of users, directory roles, or external guest users.
---
title: Building Conditional Access policies in Microsoft Entra
description: Understand the phases of Conditional Access policy enforcement in Microsoft Entra and how to apply them to secure user access.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 07/22/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: lhuangnorth
ms.custom:
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/22/2025
- ai-gen-description
---
# Building a Conditional Access policy
 
 
Modified by John Flores on Jul 22, 2025 6:04 PM
📖 View on learn.microsoft.com
+10 / -7 lines changed
Commit: Freshness updates July2
Changes:
Before
After
---
title: Microsoft Entra ID's backup authentication system
description: Increasing the resilience of the authentication plane with the backup authentication system.
 
ms.service: entra
ms.subservice: architecture
ms.topic: conceptual
ms.date: 05/29/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: joroja
---
# Microsoft Entra ID's backup authentication system
 
- Software as a service (SaaS) applications available in the app gallery, like ADP, Atlassian, AWS, GoToMeeting, Kronos, Marketo, SAP, Trello, Workday, and more.
- Selected line of business applications, based on their authentication patterns.
 
Service to service authentication that relies on managed identities for Azure resources or are built on Azure services, like virtual machines, cloud storage, Azure AI services, and App Service, receives increased resilience from the backup authentication system.
---
title: Backup Authentication System for Microsoft Entra ID
description: Explore the resilience features of Microsoft Entra ID's backup authentication system, designed to maintain authentication availability for users and services.
ms.service: entra
ms.subservice: architecture
ms.topic: conceptual
ms.date: 07/22/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: joroja
ms.custom:
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/22/2025
- ai-gen-description
---
# Microsoft Entra ID's backup authentication system
 
- Software as a service (SaaS) applications available in the app gallery, like ADP, Atlassian, AWS, GoToMeeting, Kronos, Marketo, SAP, Trello, Workday, and more.
+9 / -7 lines changed
Commit: Freshness updates July2
Changes:
Before
After
---
title: Filter for applications in Conditional Access policy
description: Use filter for applications in Conditional Access to manage conditions.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 03/11/2024
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: calebb, oanae
 
ms.custom: subject-rbac-steps
---
# Conditional Access: Filter for applications
 
Currently Conditional Access policies can be applied to all apps or to individual apps. Organizations with a large number of apps might find this process difficult to manage across multiple Conditional Access policies.
 
Application filters for Conditional Access allow organizations to tag service principals with custom attributes. These custom attributes are then added to their Conditional Access policies. Filters for applications are evaluated at token issuance runtime, a common question is if apps are assigned at runtime or configuration time.
---
title: Filter for applications in Conditional Access policy
description: Discover how to use Conditional Access filters for applications to streamline policy management and enhance security in Microsoft Entra ID.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: conceptual
ms.date: 07/22/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: femila
ms.reviewer: calebb, oanae
ms.custom:
- subject-rbac-steps
- ai-gen-docs-bap
- ai-gen-description
- ai-seo-date:07/22/2025
---
# Conditional Access: Filter for applications
 
Currently Conditional Access policies can be applied to all apps or to individual apps. Organizations with a large number of apps might find this process difficult to manage across multiple Conditional Access policies.
Modified by Justin Ploegert on Jul 22, 2025 4:17 PM
📖 View on learn.microsoft.com
+5 / -5 lines changed
Commit: updated link to relative link
Changes:
Before
After
ms.service: entra-id
ms.subservice: devices
ms.topic: conceptual
ms.date: 03/03/2025
 
ms.author: owinfrey
author: owinfreyATL
manager: femila
ms.reviewer:
---
# Understanding Primary Refresh Token (PRT)
 
### [Windows](#tab/windows-browsercookies)
 
- In Windows 10 or newer, Microsoft Entra ID supports browser SSO in Microsoft Edge natively, in Google Chrome via native support or [extension](https://chromewebstore.google.com/detail/microsoft-single-sign-on/ppnbnpeolgkicgegkbkbjmhlideopiji) and in Mozilla Firefox v91+ via a browser setting. The security is built not only to protect the cookies but also the endpoints to which the cookies are sent.
- When a user initiates a browser interaction, the browser (or the extension) invokes a [platform API](https://learn.microsoft.com/windows/win32/api/proofofpossessioncookieinfo/nf-proofofpossessioncookieinfo-iproofofpossessioncookieinfomanager-getcookieinfoforuri). The extension calls this API via a native messaging host. The API ensures that the page is from one of the allowed domains. The browser sends full query string, which includes a nonce. The platform API creates a PRT and device header, which are signed with the TPM-protected keys. The PRT-header is signed by the session key, the device header by device key, thus it's difficult to tamper with. These headers are included in all requests for Microsoft Entra ID to validate the device it's originating from and the user. Once Microsoft Entra ID validates those headers, it issues a session cookie to the browser. This session cookie also contains the same session or device key used to sign the request. During subsequent requests, the session key is validated effectively binding the cookie to the device and preventing replays from elsewhere.
 
 
### [iOS and Mac](#tab/iOS-browsercookies)
ms.service: entra-id
ms.subservice: devices
ms.topic: conceptual
ms.date: 07/22/2025
 
ms.author: jploegert
author: ploegert
manager: femila
ms.reviewer: owinfrey
---
# Understanding Primary Refresh Token (PRT)
 
### [Windows](#tab/windows-browsercookies)
 
- In Windows 10 or newer, Microsoft Entra ID supports browser SSO in Microsoft Edge natively, in Google Chrome via native support or [extension](https://chromewebstore.google.com/detail/microsoft-single-sign-on/ppnbnpeolgkicgegkbkbjmhlideopiji) and in Mozilla Firefox v91+ via a browser setting. The security is built not only to protect the cookies but also the endpoints to which the cookies are sent.
- When a user initiates a browser interaction, the browser (or the extension) invokes a [platform API](/windows/win32/api/proofofpossessioncookieinfo/nf-proofofpossessioncookieinfo-iproofofpossessioncookieinfomanager-getcookieinfoforuri.md). The extension calls this API via a native messaging host. The API ensures that the page is from one of the allowed domains. The browser sends full query string, which includes a nonce. The platform API creates a PRT and device header, which are signed with the TPM-protected keys. The PRT-header is signed by the session key, the device header by device key, thus it's difficult to tamper with. These headers are included in all requests for Microsoft Entra ID to validate the device it's originating from and the user. Once Microsoft Entra ID validates those headers, it issues a session cookie to the browser. This session cookie also contains the same session or device key used to sign the request. During subsequent requests, the session key is validated effectively binding the cookie to the device and preventing replays from elsewhere.
 
 
### [iOS and Mac](#tab/iOS-browsercookies)
+6 / -4 lines changed
Commit: add minor fixes
Changes:
Before
After
ms.subservice: enterprise-apps
ms.topic: how-to
 
ms.date: 07/15/2025
ms.author: jomondi
ms.reviewer: ergreenl
ms.custom: enterprise-apps
After entering the sign-in credentials, the consent screen appears. The consent screen provides information about the application and the permissions it requires.
1. Select **Consent on behalf of your organization** and then select **Accept**. The application is added to your tenant and the application home page appears.
 
> [!NOTE]
> You can add only one instance of a gallery application. Once you add an application and try to provide consent again, you can't add it again to the tenant.
 
 
If your application needs to support users from multiple organizations:
 
1. Configure the app registration with **Accounts in any organizational directory**
2. Use the common endpoint: `https://login.microsoftonline.com/common/`
3. Implement proper tenant validation in your application logic
 
ms.subservice: enterprise-apps
ms.topic: how-to
 
ms.date: 07/22/2025
ms.author: jomondi
ms.reviewer: ergreenl
ms.custom: enterprise-apps
After entering the sign-in credentials, the consent screen appears. The consent screen provides information about the application and the permissions it requires.
1. Select **Consent on behalf of your organization** and then select **Accept**. The application is added to your tenant and the application home page appears.
 
Contact the application vendor to learn about any additional configuration steps required for the application.
 
> [!NOTE]
> You can add only one instance of a gallery application. Once you add an application and try to provide consent again, you can't add it again to the tenant.
 
 
If your application needs to support users from multiple organizations:
 
- Configure the app registration with **Accounts in any organizational directory**
- Use the common endpoint: `https://login.microsoftonline.com/common/`
Modified by jenniferf-skc on Jul 22, 2025 5:05 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
---
title: Enable accidental deletions prevention in the Microsoft Entra provisioning service
description: Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 03/04/2025
ms.author: kenwith
ms.reviewer: arvinh
zone_pivot_groups: app-provisioning-cross-tenant-synchronization
ai-usage: ai-assisted
---
title: Enable accidental deletions prevention in the Microsoft Entra provisioning service
description: Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 03/04/2025
ms.author: jfields
ms.reviewer: arvinh
zone_pivot_groups: app-provisioning-cross-tenant-synchronization
ai-usage: ai-assisted
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
title: Users aren't being provisioned in my application
description: Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
#customer intent: As an IT admin, I want to troubleshoot why users aren't being provisioned in a Microsoft Entra Gallery Application so that I can resolve the issue and ensure proper user access.
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 04/15/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
---
title: Users aren't being provisioned in my application
description: Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
#customer intent: As an IT admin, I want to troubleshoot why users aren't being provisioned in a Microsoft Entra Gallery Application so that I can resolve the issue and ensure proper user access.
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 04/15/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
---
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
---
title: Known issues with System for Cross-Domain Identity Management (SCIM) 2.0 protocol compliance
description: How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: reference
ms.date: 04/15/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
---
title: Known issues with System for Cross-Domain Identity Management (SCIM) 2.0 protocol compliance
description: How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: reference
ms.date: 04/15/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
title: Configure provisioning using Microsoft Graph APIs
description: Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
 
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
---
title: Configure provisioning using Microsoft Graph APIs
description: Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
 
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
---
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
---
title: Learn how Provisioning logs integrate with Azure Monitor
description: Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
---
title: Learn how Provisioning logs integrate with Azure Monitor
description: Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: conceptual
ms.date: 03/04/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
title: Quarantine status in Microsoft Entra Application Provisioning
description: When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
 
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: troubleshooting
ms.date: 03/04/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
---
title: Quarantine status in Microsoft Entra Application Provisioning
description: When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
 
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: troubleshooting
ms.date: 03/04/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
---
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
---
title: Find out when a specific user is able to access an app in Microsoft Entra Application Provisioning
description: How to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 03/04/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
---
title: Find out when a specific user is able to access an app in Microsoft Entra Application Provisioning
description: How to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 03/04/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
+2 / -2 lines changed
Commit: Updating App Provisioning author metadata
Changes:
Before
After
---
title: User provisioning management for enterprise apps in Microsoft Entra ID
description: Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
author: kenwith
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 03/04/2025
ms.author: kenwith
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
---
title: User provisioning management for enterprise apps in Microsoft Entra ID
description: Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
author: jenniferf-skc
manager: dougeby
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 03/04/2025
ms.author: jfields
ms.reviewer: arvinh
ai-usage: ai-assisted
ms.custom: sfi-image-nochange