📋 Microsoft Entra Documentation Changes

Daily summary for changes since August 5th 2025, 8:49 PM PDT

Report generated on August 6th 2025, 8:49 PM PDT

📊 Summary

51
Total Commits
0
New Files
141
Modified Files
0
Deleted Files
13
Contributors

📝 Modified Documentation Files

+34 / -11 lines changed
Commit: Update manage-app-consent-policies.md
Changes:
Before
After
ms.subservice: enterprise-apps
 
ms.topic: how-to
ms.date: 03/31/2025
ms.author: jomondi
ms.reviewer: phsignor, yuhko
ms.custom: enterprise-apps
zone_pivot_groups: enterprise-apps-minus-portal-aad
 
 
# Manage app consent policies
 
App consent policies are a way to manage the permissions that apps have to access data in your organization. They're used to control what apps users can consent to and to ensure that apps meet certain criteria before they can access data. These policies help organizations maintain control over their data and ensure they only grant access to trusted apps.
 
In this article, you learn how to manage built-in and custom app consent policies to control when consent can be granted.
 
With [Microsoft Graph](/graph/overview) and [Microsoft Graph PowerShell](/powershell/microsoftgraph/get-started?view=graph-powershell-1.0&preserve-view=true), you can view and manage app consent policies.
 
An app consent policy consists of one or more "include" condition sets and zero or more "exclude" condition sets. For an event to be considered in an app consent policy, it must match *at least* one "include" condition set, and must not match *any* "exclude" condition set.
 
ms.subservice: enterprise-apps
 
ms.topic: how-to
ms.date: 08/05/2025
ms.author: jomondi
ms.reviewer: ergreenl, phsignor
ms.custom: enterprise-apps
zone_pivot_groups: enterprise-apps-minus-portal-aad
 
 
# Manage app consent policies
 
App consent policies are a way to manage the permissions that apps have to access data in your organization. They're used to control what apps users can consent to and to ensure that apps meet certain criteria before they can access data. These policies help organizations maintain control over their data and ensure they only grant access to trusted apps. With [Microsoft Graph](/graph/overview) and [Microsoft Graph PowerShell](/powershell/microsoftgraph/get-started?view=graph-powershell-1.0&preserve-view=true), you can view and manage app consent policies.
 
In this article, you learn how to manage built-in and custom app consent policies to control when consent can be granted. App consent policies can be assigned to specific users or groups by leveraging a custom role, or you can set a default app consent policy for end-users in your organization.
 
 
# App consent policy segments
An app consent policy consists of one or more "include" condition sets and zero or more "exclude" condition sets. For an event to be considered in an app consent policy, it must match *at least* one "include" condition set, and must not match *any* "exclude" condition set. These exclusion and inclusions are used to determine whether the actor affected by the given policy can grant consent or not.
 
Modified by omondiatieno on Aug 6, 2025 10:28 AM
📖 View on learn.microsoft.com
+8 / -16 lines changed
Commit: August whatsnew updates
Changes:
Before
After
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 07/02/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## June 2025
 
### Updated articles
 
- [AD FS application migration to move AD FS apps to Microsoft Entra ID](migrate-ad-fs-application-howto.md) - Revised for clarity and conciseness
- [Configure how users consent to applications](configure-user-consent.md) - Added clarity on authorization policies and app consent policies
 
 
## May 2025
 
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 08/06/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## July 2025
 
### Updated articles
 
- [Configure OIDC SSO for gallery and custom applications](add-application-portal-setup-oidc-sso.md) - Updates to add guidance for configuring OIDC SSO for a custom application
 
 
## June 2025
 
### Updated articles
+19 / -4 lines changed
Commit: Updated SRO section
Changes:
Before
After
 
# Migrate to cloud authentication using Staged Rollout
 
Staged Rollout lets you gradually test cloud authentication features with selected user groups. These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains.
 
Before you begin the Staged Rollout, you should consider the implications if one or more of the following conditions is true:
For an overview of the feature, view this "What is Staged Rollout?" video:
 
>[!VIDEO https://learn-video.azurefd.net/vod/player?id=252dc370-5709-4dfb-b346-2cbf76f1640f]
 
 
 
## Prerequisites
 
- If you have a Windows Hello for Business hybrid certificate trust with certs that are issued via your federation server acting as Registration Authority or smartcard users, the scenario isn't supported on a Staged Rollout.
 
>[!NOTE]
>You still need to make the final cutover from federated to cloud authentication by using Microsoft Entra Connect or PowerShell. Staged Rollout doesn't switch domains from federated to managed. For more information about domain cutover, see [Migrate from federation to password hash synchronization](./migrate-from-federation-to-cloud-authentication.md) and [Migrate from federation to pass-through authentication](./migrate-from-federation-to-cloud-authentication.md).
 
# Migrate to cloud authentication using Staged Rollout
 
## Overview
 
Staged rollout (SRO) is intended as a temporary testing mechanism for organizations with federated domains and allows to test cloud authentication with a group of users before [transitioning the entire domain from federated to managed](./migrate-from-federation-to-cloud-authentication.md#convert-domains-from-federated-to-managed). These features include Microsoft Entra multifactor authentication, Conditional Access, Identity Protection for leaked credentials, Identity Governance, and more. This approach allows you to validate functionality and user experience before fully transitioning your domains from federated to managed.
 
Before you begin the Staged Rollout, you should consider the implications if one or more of the following conditions is true:
For an overview of the feature, view this "What is Staged Rollout?" video:
 
>[!VIDEO https://learn-video.azurefd.net/vod/player?id=252dc370-5709-4dfb-b346-2cbf76f1640f]
>[!NOTE]
> Staged rollout is **not** designed to be a permanent configuration. Organizations should maintain a federated identity provider (IdP) as a fallback during staged rollout testing. Continuing to use staged rollout after
> migrating to managed authentication without a federated IdP in place can lead to unexpected authentication failures and degraded user experiences. To ensure a smooth transition, we recommend completing the [domain cut
> over to managed authentication](./migrate-from-federation-to-cloud-authentication.md#convert-domains-from-federated-to-managed) once testing is successful.
 
## Best Practices for Using Staged Rollout
+11 / -5 lines changed
Commit: maintenance-080625
Changes:
Before
After
description: Learn how notifications support your investigation activities.
ms.service: entra-id-protection
ms.topic: how-to
ms.date: 02/28/2025
author: shlipsey3
ms.author: sarahlipsey
manager: femila
ms.reviewer: chuqiaoshi
ms.custom: sfi-ga-nochange
---
 
This article provides you with an overview of both notification emails.
 
> [!NOTE]
> **We don't support sending emails to users in group-assigned roles.**
 
> [!IMPORTANT]
> By default users actively assigned Global Administrator, Security Administrator, or Security Reader roles are automatically added to this list if that user has a valid "Email" or "Alternate email" configured. If a user is enrolled in Privileged Identity Management (PIM) to elevate to one of these roles on demand, then **they will only receive emails if they are elevated at the time the email is sent**.
 
## Users at risk detected email
description: Learn how notifications support your investigation activities.
ms.service: entra-id-protection
ms.topic: how-to
ms.date: 08/06/2025
author: shlipsey3
ms.author: sarahlipsey
manager: pwongera
ms.reviewer: chuqiaoshi
ms.custom: sfi-ga-nochange
---
 
This article provides you with an overview of both notification emails.
 
> [!NOTE]
> **We don't support sending emails to users in group-assigned roles.**
 
> [!IMPORTANT]
> By default users actively assigned Global Administrator, Security Administrator, or Security Reader roles are automatically added to this list if that user has a valid "Email" or "Alternate email" configured. If a user is enrolled in Privileged Identity Management (PIM) to elevate to one of these roles on demand, then **they will only receive emails if they are elevated at the time the email is sent**.
 
## Prerequisites
+8 / -2 lines changed
Commit: maintenance-080625
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 02/28/2025
 
author: shlipsey3
ms.author: sarahlipsey
manager: femila
ms.reviewer: etbasser
---
# How To: Configure the multifactor authentication registration policy
 
For more information, see the article [Common Conditional Access policy: Require MFA for all users](../identity/conditional-access/policy-all-users-mfa-strength.md).
 
## Policy configuration
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Security Administrator](~/identity/role-based-access-control/permissions-reference.md#security-administrator).
 
 
 
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 08/06/2025
 
author: shlipsey3
ms.author: sarahlipsey
manager: pmwongera
ms.reviewer: etbasser
---
# How To: Configure the multifactor authentication registration policy
 
For more information, see the article [Common Conditional Access policy: Require MFA for all users](../identity/conditional-access/policy-all-users-mfa-strength.md).
 
## Prerequisites
 
- The Microsoft Entra ID P2 or Microsoft Entra Suite license is required for full access to Microsoft Entra ID Protection features, including modifying the MFA registration policy.
- For a detailed list of capabilities for each license tier, see [What is Microsoft Entra ID Protection](overview-identity-protection.md).
- The [Security Administrator](../identity/role-based-access-control/permissions-reference.md#security-administrator) role is the least privileged role required to **create or edit risk-based policies**.
 
+5 / -5 lines changed
Commit: idp-token-noise-080625
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: reference
ms.date: 07/16/2025
 
author: shlipsey3
ms.author: sarahlipsey
### Anomalous token (sign-in)
<a name='anomalous-token'></a>
 
This detection indicates abnormal characteristics in the token, such as an unusual lifetime or a token played from an unfamiliar location. This detection covers "Session Tokens" and "Refresh Tokens."
 
Anomalous token is tuned to incur more noise than other detections at the same risk level. This tradeoff is chosen to increase the likelihood of detecting replayed tokens that might otherwise go unnoticed. There's a higher than normal chance that some of the sessions flagged by this detection are false positives. We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user. If the location, application, IP address, User Agent, or other characteristics are unexpected for the user, the administrator should consider this risk as an indicator of potential token replay.
 
- Calculated in real-time or offline
- License requirement: Microsoft Entra ID P2
 
### Anomalous token (user)
 
This detection indicates abnormal characteristics in the token, such as an unusual lifetime or a token played from an unfamiliar location. This detection covers "Session Tokens" and "Refresh Tokens."
ms.service: entra-id-protection
 
ms.topic: reference
ms.date: 08/06/2025
 
author: shlipsey3
ms.author: sarahlipsey
### Anomalous token (sign-in)
<a name='anomalous-token'></a>
 
This detection indicates abnormal characteristics in the token, such as an unusual lifetime or a token played from an unfamiliar location. This detection covers "Session Tokens" and "Refresh Tokens." If the location, application, IP address, User Agent, or other characteristics are unexpected for the user, the administrator should consider this risk as an indicator of potential token replay.
 
Anomalous token was historically tuned to incur more noise than other detections. Recent improvements to the detection have reduced the noise; however, there's still a higher than normal chance that some of the sessions flagged by this detection are false positives at low and medium risk levels.
 
- Calculated in real-time or offline
- License requirement: Microsoft Entra ID P2
 
### Anomalous token (user)
 
This detection indicates abnormal characteristics in the token, such as an unusual lifetime or a token played from an unfamiliar location. This detection covers "Session Tokens" and "Refresh Tokens." If the location, application, IP address, User Agent, or other characteristics are unexpected for the user, the administrator should consider this risk as an indicator of potential token replay.
+8 / -1 lines changed
Commit: maintenance-080625
Changes:
Before
After
ms.date: 08/09/2024
author: shlipsey3
ms.author: sarahlipsey
manager: femila
ms.reviewer: cokoopma
ms.custom: sfi-image-nochange
---
 
Microsoft Entra ID Protection provides organizations with reporting they can use to investigate identity risks in their environment. These reports include risky users, risky sign-ins, risky workload identities, and risk detections. Investigation of events is key to better understanding and identifying any weak points in your security strategy. All these reports allow for downloading of events in .CSV format or integration with other security solutions like a dedicated Security Information and Event Management (SIEM) tool for further analysis. Organizations can also take advantage of Microsoft Defender and Microsoft Graph API integrations to aggregate data with other sources.
 
## Navigating the reports
 
The risk reports are found in the [Microsoft Entra admin center](https://entra.microsoft.com) under **ID Protection**. You can navigate directly to the reports or view a summary of important insights in the dashboard view and navigate to the corresponding reports from there.
 
 
 
 
 
 
 
ms.date: 08/09/2024
author: shlipsey3
ms.author: sarahlipsey
manager: pwongera
ms.reviewer: cokoopma
ms.custom: sfi-image-nochange
---
 
Microsoft Entra ID Protection provides organizations with reporting they can use to investigate identity risks in their environment. These reports include risky users, risky sign-ins, risky workload identities, and risk detections. Investigation of events is key to better understanding and identifying any weak points in your security strategy. All these reports allow for downloading of events in .CSV format or integration with other security solutions like a dedicated Security Information and Event Management (SIEM) tool for further analysis. Organizations can also take advantage of Microsoft Defender and Microsoft Graph API integrations to aggregate data with other sources.
 
## Prerequisites
 
- The Microsoft Entra ID P2 or Microsoft Entra Suite license is required for full access to Microsoft Entra ID Protection features.
- For a detailed list of capabilities for each license tier, see [What is Microsoft Entra ID Protection](overview-identity-protection.md).
- The [Global Reader](../identity/role-based-access-control/permissions-reference.md#global-reader) role is the least privileged role required to **view the risk reports**.
- The [Reports Reader](../identity/role-based-access-control/permissions-reference.md#reports-reader) role is the least privileged role required to **view the sign-in and audit logs**.
 
## Navigating the reports
 
The risk reports are found in the [Microsoft Entra admin center](https://entra.microsoft.com) under **ID Protection**. You can navigate directly to the reports or view a summary of important insights in the dashboard view and navigate to the corresponding reports from there.
+7 / -1 lines changed
Commit: maintenance-080625
Changes:
Before
After
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 06/12/2025
 
author: shlipsey3
ms.author: sarahlipsey
 
![Screenshot of a Conditional Access policy showing risk as conditions.](./media/howto-identity-protection-configure-risk-policies/sign-in-risk-conditions.png)
 
## Choosing acceptable risk levels
 
Organizations must decide the level of risk they want to require access control on balancing user experience and security posture.
 
 
 
 
 
 
ms.service: entra-id-protection
 
ms.topic: how-to
ms.date: 08/06/2025
 
author: shlipsey3
ms.author: sarahlipsey
 
![Screenshot of a Conditional Access policy showing risk as conditions.](./media/howto-identity-protection-configure-risk-policies/sign-in-risk-conditions.png)
 
## Prerequisites
 
- The Microsoft Entra ID P2 or Microsoft Entra Suite license is required for full access to Microsoft Entra ID Protection features.
- For a detailed list of capabilities for each license tier, see [What is Microsoft Entra ID Protection](overview-identity-protection.md).
- The [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role is the least privileged role required to **create or edit Conditional Access policies**.
 
## Choosing acceptable risk levels
 
Organizations must decide the level of risk they want to require access control on balancing user experience and security posture.
+3 / -3 lines changed
Commit: updates in fundamentals
Changes:
Before
After
---
title: Responsible AI FAQ - Security Copilot in Microsoft Entra
description: Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
author: cilwerner
ms.author: cwerner
manager: celestedg
ms.date: 10/29/2024
ms.topic: faq
ms.service: entra
---
title: Responsible AI FAQ - Security Copilot in Microsoft Entra
description: Frequently asked questions about related to Responsible AI as it relates to Copilot in Microsoft Entra.
author: cilwerner
ms.author: cwerner
manager: pmwongera
ms.date: 10/29/2024
ms.topic: faq
ms.service: entra
+5 / -0 lines changed
Commit: Add note about assigning app permissions to a user
Changes:
Before
After
- [Bring Your Own Application (BYOA)](#bring-your-own-application)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate)
 
## Managed by Microsoft Entra Connect (default)
 
Microsoft Entra Connect manages the application and certificate, which includes creation, rotation, and deletion of the certificate. The certificate is stored in the `CURRENT_USER` store. For optimal protection of the certificate's private key, we recommend that the machine should use a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary.
 
 
 
 
 
- [Bring Your Own Application (BYOA)](#bring-your-own-application)
- [Bring Your Own Certificate (BYOC)](#bring-your-own-certificate)
 
> [!NOTE]
> The [Application Administrator](~/identity/role-based-access-control/permissions-reference#application-administrator) role grants the ability to consent for application permissions, with the exception of application permissions for Azure AD Graph and Microsoft Graph. This means that the application administrator can still consent to application permissions for other apps, notably the AWS first-party app and SSPR first-party app.
>
> This role also grants the ability to manage application credentials. User assigned to this role can add credentials to an application (notably the Connect Sync) and use those credentials to impersonate the application's identity. This might be an elevation of privilege over what the user can do via their role assignments.
 
## Managed by Microsoft Entra Connect (default)
 
Microsoft Entra Connect manages the application and certificate, which includes creation, rotation, and deletion of the certificate. The certificate is stored in the `CURRENT_USER` store. For optimal protection of the certificate's private key, we recommend that the machine should use a Trusted Platform Module (TPM) solution to establish a hardware-based security boundary.
Modified by shlipsey3 on Aug 6, 2025 8:42 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: maintenance-080625
Changes:
Before
After
ms.date: 11/18/2024
author: shlipsey3
ms.author: sarahlipsey
manager: femila
ms.reviewer: cokoopma
ms.custom: sfi-image-nochange
# Customer intent: As an IT admin, I want to know how to export and use Microsoft Entra ID Protection data so that I can investigate using long-term data in Microsoft Entra ID Protection.
To export risk data for storage and analysis, you need:
 
- An Azure subscription to create a Log Analytics workspace, Azure event hub, or Azure storage account. If you don't have an Azure subscription, you can [sign up for a free trial](https://azure.microsoft.com/free/).
- [Security Administrator](../identity/role-based-access-control/permissions-reference.md#security-administrator) access to create general diagnostic settings for the Microsoft Entra tenant.
 
## Diagnostic settings
 
ms.date: 11/18/2024
author: shlipsey3
ms.author: sarahlipsey
manager: pwongera
ms.reviewer: cokoopma
ms.custom: sfi-image-nochange
# Customer intent: As an IT admin, I want to know how to export and use Microsoft Entra ID Protection data so that I can investigate using long-term data in Microsoft Entra ID Protection.
To export risk data for storage and analysis, you need:
 
- An Azure subscription to create a Log Analytics workspace, Azure event hub, or Azure storage account. If you don't have an Azure subscription, you can [sign up for a free trial](https://azure.microsoft.com/free/).
- The [Security Administrator](../identity/role-based-access-control/permissions-reference.md#security-administrator) role is the least privileged role required to **configure diagnostic settings for the Microsoft Entra tenant**.
 
## Diagnostic settings
 
Modified by vimrang on Aug 6, 2025 7:29 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Update tenant-restrictions-v2.md
Changes:
Before
After
 
When you enable tenant restrictions on a Windows device, corporate proxies aren't required for policy enforcement. Devices don't need to be Microsoft Entra ID managed to enforce tenant restrictions v2. Domain-joined devices that are managed with Group Policy are also supported.
 
> [!NOTE]
> Tenant restrictions v2 on Windows is a partial solution that helps protect the authentication and data planes for some scenarios. It works on managed Windows devices. It doesn't protect the .NET stack, Chrome, or Firefox.
 
#### Use Group Policy to deploy tenant restrictions
 
 
When you enable tenant restrictions on a Windows device, corporate proxies aren't required for policy enforcement. Devices don't need to be Microsoft Entra ID managed to enforce tenant restrictions v2. Domain-joined devices that are managed with Group Policy are also supported.
 
> [!IMPORTANT]
> Tenant restrictions v2 on Windows is a partial solution that helps protect the authentication and data planes for some scenarios. It works on managed Windows devices. It doesn't protect the .NET stack, Chrome, or Firefox. The Windows GPO solution provides a temporary solution in public preview until general availability of data plane support with Universal tenant restrictions in [Microsoft Entra Global Secure Access (preview)](/azure/global-secure-access/overview-what-is-global-secure-access).
 
#### Use Group Policy to deploy tenant restrictions
 
Modified by ArvindHarinder1 on Aug 6, 2025 5:28 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Update multi-tenant-common-considerations.md
Changes:
Before
After
ms.service: entra
ms.subservice: architecture
ms.topic: conceptual
ms.date: 09/25/2024
ms.author: jricketts
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
---
| - | - | - |
| User lifecycle management | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| File sharing and app access | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Support sync to/from sovereign clouds | | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Control sync from resource tenant | | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Sync Group objects | | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Sync Manager links | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
ms.service: entra
ms.subservice: architecture
ms.topic: conceptual
ms.date: 08/06/2025
ms.author: jricketts
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
---
| - | - | - |
| User lifecycle management | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| File sharing and app access | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Support sync to/from sovereign clouds | [Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Control sync from resource tenant | | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Sync Group objects | | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
| Sync Manager links | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) | ![Check mark icon](media/multi-tenant-user-management-scenarios/checkmark.svg) |
Modified by ArvindHarinder1 on Aug 6, 2025 4:49 PM
📖 View on learn.microsoft.com
+3 / -1 lines changed
Commit: Update feature-availability.md
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 03/04/2025
 
 
ms.author: justinha
|| Entitlement management | &#x2705; |
|| Privileged Identity Management (PIM) | &#x2705; |
|| Lifecycle workflows, in Microsoft Entra ID Governance | &#x2705; |
|**Event logging and reporting**|Basic security and usage reports | &#x2705; |
|| Advanced security and usage reports | &#x2705; |
|| ID Protection: vulnerabilities and risky accounts | &#x2705; |
 
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: conceptual
ms.date: 08/06/2025
 
 
ms.author: justinha
|| Entitlement management | &#x2705; |
|| Privileged Identity Management (PIM) | &#x2705; |
|| Lifecycle workflows, in Microsoft Entra ID Governance | &#x2705; |
|| Cross-tenant user synchronization (same cloud) | &#x2705; |
|| Cross-cloud synchronization | &#x2705; |
|**Event logging and reporting**|Basic security and usage reports | &#x2705; |
|| Advanced security and usage reports | &#x2705; |
|| ID Protection: vulnerabilities and risky accounts | &#x2705; |
Modified by Chris Werner on Aug 6, 2025 10:51 AM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Use Cline to update manager
Changes:
Before
After
title: "How to add a redirect URI to your application"
description: Learn how to add a redirect URI to your application in Microsoft Entra to securely handle authentication tokens and enhance app security.
author: cilwerner
manager: CelesteDG
ms.author: cwerner
ms.custom: mode-other
ms.date: 05/23/2025
 
- [Redirect URI (reply URL) restrictions and limitations](./reply-url.md).
- [Add credentials to your application](how-to-add-credentials.md)
- [Create a sign-up and sign-in user flow for an external tenant app](../external-id/customers/how-to-user-flow-sign-up-sign-in-customers.md)
title: "How to add a redirect URI to your application"
description: Learn how to add a redirect URI to your application in Microsoft Entra to securely handle authentication tokens and enhance app security.
author: cilwerner
manager: pmwongera
ms.author: cwerner
ms.custom: mode-other
ms.date: 05/23/2025
 
- [Redirect URI (reply URL) restrictions and limitations](./reply-url.md).
- [Add credentials to your application](how-to-add-credentials.md)
- [Create a sign-up and sign-in user flow for an external tenant app](../external-id/customers/how-to-user-flow-sign-up-sign-in-customers.md)