📋 Microsoft Entra Documentation Changes

Daily summary for changes since July 24th 2025, 8:39 PM PDT

Report generated on July 25th 2025, 8:39 PM PDT

📊 Summary

19
Total Commits
0
New Files
6
Modified Files
0
Deleted Files
12
Contributors

📝 Modified Documentation Files

+33 / -31 lines changed
Commit: [Conditional Access] Freshness Target Resources
Changes:
Before
After
---
title: Cloud apps, actions, and authentication context in Conditional Access policy
description: What are cloud apps, actions, and authentication context in a Microsoft Entra Conditional Access policy
 
ms.service: entra-id
ms.subservice: conditional-access
ms.custom: has-azure-ad-ps-ref
ms.topic: conceptual
 
ms.date: 07/07/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
---
# Conditional Access: Target resources
 
Target resources (formerly Cloud apps, actions, and authentication context) are key signals in a Conditional Access policy. Conditional Access policies allow administrators to assign controls to specific applications, services, actions, or authentication context.
 
- Administrators can choose from the list of applications or services that include built-in Microsoft applications and any [Microsoft Entra integrated applications](~/identity/enterprise-apps/what-is-application-management.md) including gallery, non-gallery, and applications published through [Application Proxy](~/identity/app-proxy/overview-what-is-app-proxy.md).
---
title: 'Conditional Access: Target Resources Overview'
description: Learn how to configure Conditional Access policies to target specific resources, actions, and authentication contexts in Microsoft Entra ID.
ms.service: entra-id
ms.subservice: conditional-access
ms.custom:
- has-azure-ad-ps-ref
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/25/2025
- ai-gen-description
ms.topic: conceptual
ms.date: 07/25/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
---
# Conditional Access: Target resources
 
Target resources (formerly cloud apps, actions, and authentication context) are key signals in a Conditional Access policy. Conditional Access policies let administrators assign controls to specific applications, services, actions, or authentication context.
+0 / -29 lines changed
Commit: Remove August future changes from guest users governance dashboard
Changes:
Before
After
- Tailspin creates a second access review for a security group with 300 guest users with the user-to-group affiliation feature enabled.
- Billing: For May, Tailspin is billed for 500 users – 200 for the inactive guest access review and 300 for the review with user-to-group affiliation.
 
### Link your tenant to a subscription
 
Your tenants must be linked to an Azure subscription for proper billing and access to features. To link your tenant to a subscription, follow these steps.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/) with an account that has at least the Contributor role within the subscription or a resource group within the subscription.
 
2. Select the directory you want to link: In the Microsoft Entra admin center toolbar, select the **Settings** icon in the portal toolbar. Then on the **Portal settings \| Directories + subscriptions** page, find your workforce tenant in the **Directory name** list, and then select **Switch**.
 
3. Browse to **Entra ID** > **ID Governance** > **Dashboard**.
 
4. On the governance dashboard, locate the guest governance panel and select **Get Started**.
 
5. In the **Link a subscription** pane, select a **Subscription** and a **Resource group**. Then select **Turn on**.
 
After you complete these steps, your Azure subscription is billed based on your Azure Direct or Enterprise Agreement details, if applicable.
 
## What if I can't find a subscription?
- Tailspin creates a second access review for a security group with 300 guest users with the user-to-group affiliation feature enabled.
- Billing: For May, Tailspin is billed for 500 users – 200 for the inactive guest access review and 300 for the review with user-to-group affiliation.
 
 
## Guest user licensing FAQs
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
+2 / -2 lines changed
Commit: Update entra-entitlement-management-lifecycle-policy.md
Changes:
Before
After
 
This approval will use the same approval settings that you specified on the **Requests** tab.
 
1. If you want to **Require an access review** for this access package, move the toggle to **Yes**. Refer to the [detailed article on configuring the access review](/entra/id-governance/entitlement-management-access-reviews-create) and then return back here to finish setting up the access package.
3. If you did not require an access review, or once you have configured it, select **Next** or **Update**.
 
This approval will use the same approval settings that you specified on the **Requests** tab.
 
1. If you want to **Require an access review** for this access package, move the toggle to **Yes**. Refer to the [detailed article on configuring the access review](/entra/id-governance/entitlement-management-access-reviews-create) and then return back here to finish setting up the access package.
3. If you didn't require an access review, or once you have configured it, select **Next** or **Update**.
+2 / -2 lines changed
Commit: July 25 replaced Netskope automation URL
Changes:
Before
After
author: kenwith
manager: dougeby
ms.topic: overview
ms.date: 07/23/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
ai-usage: ai-assisted
| Partner | Docs | Description |
|----------------|-------------------|----------------|
| Aviatrix | [Deployment guide](https://resources.aviatrix.com/home/aviatrixentra-gsa-configuration-guide-getting-started-with-aviatrix-secure-connectivity-to-entra-gsa) | Aviatrix enables secure, instant access to Microsoft's SASE platform for any application or workload worldwide, offering identity-based zero-trust access to Microsoft 365, the Internet, and public PaaS/SaaS endpoints. Aviatrix Secure Access supports always-on connectivity to Microsoft's SASE for diverse environments, including containers, without needing agents or host configuration.|
| Netskope | [Configuration guide](https://community.netskope.com/discussions-37/microsoft-s-sse-netskope-sd-wan-configuration-guide-7854?tid=7854&fid=37) | Netskope One SD-WAN directs Microsoft traffic to Microsoft's SASE platform for fast, secure access. With powerful automation for Zero Touch Provisioning, this solution streamlines deployment at scale. Customers and partners can quickly onboard sites and reduce operational costs. |
| Teridion | [Deployment guide (PDF format)](https://www.teridion.com/wp-content/uploads/2024/11/Teridion-Secure-Connect.pdf) | Teridion Secure Connect combines Teridion Connect with Microsoft's SASE platform to deliver fast, secure internet access. This integration, designed for telecommunications companies and Global System Integrators (GSIs), simplifies operations and enhances service management, benefiting end customers.|
 
For organizations seeking customization according to their unique network architecture, Microsoft offers templatized integrations with the following partners:
author: kenwith
manager: dougeby
ms.topic: overview
ms.date: 07/25/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
ai-usage: ai-assisted
| Partner | Docs | Description |
|----------------|-------------------|----------------|
| Aviatrix | [Deployment guide](https://resources.aviatrix.com/home/aviatrixentra-gsa-configuration-guide-getting-started-with-aviatrix-secure-connectivity-to-entra-gsa) | Aviatrix enables secure, instant access to Microsoft's SASE platform for any application or workload worldwide, offering identity-based zero-trust access to Microsoft 365, the Internet, and public PaaS/SaaS endpoints. Aviatrix Secure Access supports always-on connectivity to Microsoft's SASE for diverse environments, including containers, without needing agents or host configuration.|
| Netskope | [Deployment guide](https://community.netskope.com/additional-discussions-9/automating-netskope-one-sd-wan-and-microsoft-entra-sse-integration-7967) | Netskope One SD-WAN directs Microsoft traffic to Microsoft's SASE platform for fast, secure access. With powerful automation for Zero Touch Provisioning, this solution streamlines deployment at scale. Customers and partners can quickly onboard sites and reduce operational costs. |
| Teridion | [Deployment guide (PDF format)](https://www.teridion.com/wp-content/uploads/2024/11/Teridion-Secure-Connect.pdf) | Teridion Secure Connect combines Teridion Connect with Microsoft's SASE platform to deliver fast, secure internet access. This integration, designed for telecommunications companies and Global System Integrators (GSIs), simplifies operations and enhances service management, benefiting end customers.|
 
For organizations seeking customization according to their unique network architecture, Microsoft offers templatized integrations with the following partners:
Modified by Faith Moraa Ombongi on Jul 25, 2025 11:16 AM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Added resource action overrides + refreshed RBAC reference
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: reference
ms.date: 07/09/2025
ms.author: barclayn
ms.reviewer: abhijeetsinha
ms.custom: generated, it-pro, fasttrack-edit, has-azure-ad-ps-ref, azure-ad-ref-level-one-done, sfi-ga-nochange
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: reference
ms.date: 07/25/2025
ms.author: barclayn
ms.reviewer: abhijeetsinha
ms.custom: generated, it-pro, fasttrack-edit, has-azure-ad-ps-ref, azure-ad-ref-level-one-done, sfi-ga-nochange
+0 / -1 lines changed
Commit: Added resource action overrides + refreshed RBAC reference
Changes:
Before
After
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices<br/>[![Privileged label icon.](../media/permissions-reference/privileged-label.png)](../privileged-roles-permissions.md) |
> | microsoft.directory/bulkJobs/basic/update | Update all the bulk jobs in a directory |
> | microsoft.directory/bulkJobs/create | Create all bulk jobs in a directory |
> | microsoft.directory/bulkJobs/standard/read | Read all bulk jobs in a directory |
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps |
> | microsoft.directory/conditionalAccessPolicies/allProperties/allTasks | Manage all properties of Conditional Access policies |
> | microsoft.directory/connectorGroups/allProperties/read | Read all properties of application proxy connector groups |
> | microsoft.directory/bitlockerKeys/key/read | Read bitlocker metadata and key on devices<br/>[![Privileged label icon.](../media/permissions-reference/privileged-label.png)](../privileged-roles-permissions.md) |
> | microsoft.directory/bulkJobs/basic/update | Update all the bulk jobs in a directory |
> | microsoft.directory/bulkJobs/create | Create all bulk jobs in a directory |
> | microsoft.directory/cloudAppSecurity/allProperties/allTasks | Create and delete all resources, and read and update standard properties in Microsoft Defender for Cloud Apps |
> | microsoft.directory/conditionalAccessPolicies/allProperties/allTasks | Manage all properties of Conditional Access policies |
> | microsoft.directory/connectorGroups/allProperties/read | Read all properties of application proxy connector groups |