πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since August 19th 2025, 8:12 PM PDT

Report generated on August 20th 2025, 8:12 PM PDT

πŸ“Š Summary

30
Total Commits
0
New Files
15
Modified Files
1
Deleted Files
13
Contributors

πŸ“ Modified Documentation Files

+0 / -14 lines changed
Commit: Revert Update
Changes:
Before
After
 
After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
 
## Configure whether requestors can see approver details (preview)
 
You can control whether requestors see approver details for pending access package requests in the My Access portal. You can set this at the access package level or at the tenant level (default for all packages). The access package setting overrides the tenant setting when explicitly set to Yes or No.
 
1. When creating a new access package or editing a policy for an existing access package, under **Approval** expand **Advanced request settings**.
 
1. Set Show approver details on pending access package requests (preview) to one of the following:
- Yes – All users in scope of this access package will see the approver’s name and email address on their pending requests in My Access.
- No – Users won’t see any approver information for this access package.
- Default – Inherit the tenant-level setting.
 
>[!IMPORTANT]
>If the access package setting is set to Yes or No, it overrides the tenant-level setting. If it’s set to Default, it respects the tenant-level setting.
 
## Next steps
 
- [Change lifecycle settings for an access package](entitlement-management-access-package-lifecycle-policy.md)
 
After you configure requestor information in your access package's policy, can view the requestor's responses to the questions. For guidance on seeing requestor information, see [View requestor's answers to questions](entitlement-management-request-approve.md#view-requestors-answers-to-questions).
 
## Next steps
 
- [Change lifecycle settings for an access package](entitlement-management-access-package-lifecycle-policy.md)
 
 
 
 
 
 
 
 
 
 
 
 
 
 
+5 / -4 lines changed
Commit: added heading title and service fpr metadata
Changes:
Before
After
---
title: Embrace cloud-first posture and convert Group Source of Authority (SOA) to the cloud (Preview)
description: Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
author: Justinha
ms.topic: conceptual
ms.date: 08/19/2025
ms.author: justinha
ms.reviewer: justinha
---
# Embrace cloud-first posture: Convert Group Source of Authority to the cloud (Preview)
 
 
This article describes how Group SOA can help IT administrators transition group management from AD DS to the cloud. You can also enable advanced scenarios like access governance with Microsoft Entra ID Governance.
 
## Video:
 
Check out our video for an introduction to SOA and how it can help your organization shift to the cloud.
 
 
---
title: Embrace cloud-first posture and convert Group Source of Authority (SOA) to the cloud (Preview)
description: Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.
author: justinha
ms.date: 08/19/2025
ms.author: justinha
ms.reviewer: dhanyahk
ms.service: entra-id
ms.topic: article
---
# Embrace cloud-first posture: Convert Group Source of Authority to the cloud (Preview)
 
 
This article describes how Group SOA can help IT administrators transition group management from AD DS to the cloud. You can also enable advanced scenarios like access governance with Microsoft Entra ID Governance.
 
## Video: Microsoft Entra Group Source of Authority
 
Check out our video for an introduction to SOA and how it can help your organization shift to the cloud.
 
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+2 / -4 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
For more information on Microsoft Entra groups, see:
 
- [Existing groups](~/fundamentals/groups-view-azure-portal.md)
- [Manage settings of a group](/entra/fundamentals/how-to-manage-groups)
- [Manage members of a group](/entra/fundamentals/how-to-manage-groups)
- [Manage memberships of a group](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups](groups-dynamic-membership.md)
 
For more information on Microsoft Entra groups, see:
 
 
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups](groups-dynamic-membership.md)
 
 
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+1 / -4 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
For more information on Microsoft Entra groups, see:
 
- [Existing groups](~/fundamentals/groups-view-azure-portal.md)
- [Expiration policy for Microsoft 365 groups](groups-lifecycle.md)
- [Manage settings of a group](/entra/fundamentals/how-to-manage-groups)
- [Manage members of a group](/entra/fundamentals/how-to-manage-groups)
- [Manage memberships of a group](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups](groups-dynamic-membership.md)
 
For more information on Microsoft Entra groups, see:
 
- [Expiration policy for Microsoft 365 groups](groups-lifecycle.md)
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups](groups-dynamic-membership.md)
 
 
 
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+1 / -4 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
For more information on Microsoft Entra groups:
 
* [See existing groups](~/fundamentals/groups-view-azure-portal.md)
* [Manage settings of a group](/entra/fundamentals/how-to-manage-groups)
* [Manage members of a group](/entra/fundamentals/how-to-manage-groups)
* [Manage memberships of a group](/entra/fundamentals/how-to-manage-groups)
* [Manage rules for dynamic membership groups](groups-dynamic-membership.md)
 
For more information on Microsoft Entra groups:
 
* [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
* [Manage rules for dynamic membership groups](groups-dynamic-membership.md)
 
 
 
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+1 / -3 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
These articles provide additional information on working with groups in Microsoft Entra ID.
 
- [View your groups and members](~/fundamentals/groups-view-azure-portal.md)
- [Manage group memberships](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups](groups-create-rule.md)
- [Edit your group settings](/entra/fundamentals/how-to-manage-groups)
- [Manage access to resources using groups](~/fundamentals/concept-learn-about-groups.md)
- [Manage access to SaaS apps using groups](groups-saasapps.md)
- [Manage groups using PowerShell commands](~/identity/users/groups-settings-v2-cmdlets.md)
 
These articles provide additional information on working with groups in Microsoft Entra ID.
 
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups](groups-create-rule.md)
- [Manage access to resources using groups](~/fundamentals/concept-learn-about-groups.md)
- [Manage access to SaaS apps using groups](groups-saasapps.md)
- [Manage groups using PowerShell commands](~/identity/users/groups-settings-v2-cmdlets.md)
 
 
+1 / -1 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
There are scenarios when it's necessary to allow access for a small, specific group.
 
Before you begin, we recommend you create a security group, which contains external users who access resources. See, [Manage Microsoft Entra groups and group membership](~/fundamentals/how-to-manage-groups.md).
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Browse to **Entra ID** > **Conditional Access**.
 
There are scenarios when it's necessary to allow access for a small, specific group.
 
Before you begin, we recommend you create a security group, which contains external users who access resources. See, [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups).
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator).
1. Browse to **Entra ID** > **Conditional Access**.
+1 / -1 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.
1. Create a [new user-assigned managed identity](how-manage-user-assigned-managed-identities.md?pivots=identity-mi-methods-powershell#create-a-user-assigned-managed-identity-2) at the target region.
1. Grant the managed identity the same permissions as the original identity that it's replacing, including Group membership. You can review [Assign Azure roles to a managed identity](/azure/role-based-access-control/role-assignments-portal-managed-identity), and [Group membership](~/fundamentals/how-to-manage-groups.md).
1. Specify the new identity in the properties of the resource instance that uses the newly created user assigned managed identity.
 
## Verify
 
1. Copy user-assigned managed identity assigned permissions. You can list [Azure role assignments](/azure/role-based-access-control/role-assignments-list-powershell) but that may not be enough depending on how permissions were granted to the user-assigned managed identity. You should confirm that your solution doesn't depend on permissions granted using a service specific option.
1. Create a [new user-assigned managed identity](how-manage-user-assigned-managed-identities.md?pivots=identity-mi-methods-powershell#create-a-user-assigned-managed-identity-2) at the target region.
1. Grant the managed identity the same permissions as the original identity that it's replacing, including Group membership. You can review [Assign Azure roles to a managed identity](/azure/role-based-access-control/role-assignments-portal-managed-identity), and [Group membership](/entra/fundamentals/how-to-manage-groups).
1. Specify the new identity in the properties of the resource instance that uses the newly created user assigned managed identity.
 
## Verify
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
## Related content
 
- [Create a group with members and view all groups and members](~/fundamentals/groups-view-azure-portal.md)
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups in Microsoft Entra ID](groups-dynamic-membership.md)
 
## Related content
 
 
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups in Microsoft Entra ID](groups-dynamic-membership.md)
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
## Related content
 
- [Create a group with members and view all groups and members](~/fundamentals/groups-view-azure-portal.md)
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups in Microsoft Entra ID](groups-dynamic-membership.md)
 
## Related content
 
 
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Manage rules for dynamic membership groups in Microsoft Entra ID](groups-dynamic-membership.md)
Modified by John Flores on Aug 20, 2025 8:05 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: [Fundamentals] IAM Concepts Curation
Changes:
Before
After
 
## Related content
 
- [Create a group with members and view all groups and members](~/fundamentals/groups-view-azure-portal.md)
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Create or update a dynamic membership group in Microsoft Entra ID](groups-create-rule.md)
 
## Related content
 
 
- [Manage Microsoft Entra groups and group membership](/entra/fundamentals/how-to-manage-groups)
- [Create or update a dynamic membership group in Microsoft Entra ID](groups-create-rule.md)
Modified by Sander Berkouwer on Aug 20, 2025 12:38 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update how-to-prerequisites.md
Changes:
Before
After
|-----|-----|
|`*.msappproxy.us`</br>`*.servicebus.usgovcloudapi.net`|The agent uses these URLs to communicate with the Microsoft Entra cloud service. |
|`mscrl.microsoft.us:80` </br>`crl.microsoft.us:80` </br>`ocsp.msocsp.us:80` </br>`www.microsoft.us:80`| The agent uses these URLs to verify certificates.|
|`login.windows.us` </br>`secure.aadcdn.microsoftonline-p.com` </br>`*.microsoftonline.us` </br>`*.microsoftonline-p.us` </br>`*.msauth.net` </br>`*.msauthimages.net` </br>`*.msecnd.net`</br>`*.msftauth.net` </br>`*.msftauthimages.net`</br>`*.phonefactor.net` </br>`enterpriseregistration.windows.net`</br>`management.azure.com` </br>`policykeyservice.dc.ad.msft.net`</br>`ctldl.windowsupdate.us:80` </br>`aadcdn.msftauthimages.us` </br>`*.microsoft.us` </br>`msauthimages.us` </br>`mfstauthimages.us`| The agent uses these URLs during the registration process.
 
 
 
|-----|-----|
|`*.msappproxy.us`</br>`*.servicebus.usgovcloudapi.net`|The agent uses these URLs to communicate with the Microsoft Entra cloud service. |
|`mscrl.microsoft.us:80` </br>`crl.microsoft.us:80` </br>`ocsp.msocsp.us:80` </br>`www.microsoft.us:80`| The agent uses these URLs to verify certificates.|
|`login.windows.us` </br>`secure.aadcdn.microsoftonline-p.com` </br>`*.microsoftonline.us` </br>`*.microsoftonline-p.us` </br>`*.msauth.net` </br>`*.msauthimages.net` </br>`*.msecnd.net`</br>`*.msftauth.net` </br>`*.msftauthimages.net`</br>`*.phonefactor.net` </br>`enterpriseregistration.windows.net`</br>`management.azure.com` </br>`policykeyservice.dc.ad.msft.net`</br>`ctldl.windowsupdate.us:80` </br>`aadcdn.msftauthimages.us` </br>`*.microsoft.us` </br>`msauthimages.us` </br>`msftauthimages.us`| The agent uses these URLs during the registration process.
 
 
 
Modified by Ortagus Winfrey on Aug 20, 2025 11:37 AM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updates
Changes:
Before
After
 
If for any reason Secure Enclave needs to be disabled, follow these recommended steps:
 
1. **Update the configuration**: Disable `use_most_secure_storage` by setting the flag to `false` for Boolean type or `0` for Integer type in your MDM configuration.
 
2. **Unregister the device**: Remove the device registration using one of these methods:
- **Microsoft Authenticator**: Navigate to the device registration menu and follow the unregistration steps:
 
If for any reason Secure Enclave needs to be disabled, follow these recommended steps:
 
1. **Update the configuration**: Disable `use_most_secure_storage` by setting the flag to `0` for Integer type in your MDM configuration.
 
2. **Unregister the device**: Remove the device registration using one of these methods:
- **Microsoft Authenticator**: Navigate to the device registration menu and follow the unregistration steps:
+1 / -1 lines changed
Commit: (AzureCXP) fixes MicrosoftDocs/entra-docs-pr
Changes:
Before
After
1. Run `sudo apt remove --purge aadlogin` (Ubuntu/Debian), `sudo yum remove aadlogin` (RHEL), or `sudo zypper remove aadlogin` (openSUSE or SLES).
1. If the command fails, try the low-level tools with scripts disabled:
1. For Ubuntu/Debian, run `sudo dpkg --purge aadlogin`. If it's still failing because of the script, delete the `/var/lib/dpkg/info/aadlogin.prerm` file and try again.
1. For everything else, run `rpm -e --noscripts aadogin`.
1. Repeat steps 3-4 for package `aadlogin-selinux`.
 
### Extension installation errors
1. Run `sudo apt remove --purge aadlogin` (Ubuntu/Debian), `sudo yum remove aadlogin` (RHEL), or `sudo zypper remove aadlogin` (openSUSE or SLES).
1. If the command fails, try the low-level tools with scripts disabled:
1. For Ubuntu/Debian, run `sudo dpkg --purge aadlogin`. If it's still failing because of the script, delete the `/var/lib/dpkg/info/aadlogin.prerm` file and try again.
1. For everything else, run `rpm -e --noscripts aadlogin`.
1. Repeat steps 3-4 for package `aadlogin-selinux`.
 
### Extension installation errors
+1 / -1 lines changed
Commit: fix: typo
Changes:
Before
After
npx create-react-app reactspa --template typescript
cd reactspa
npm install ajv
npm installreact-router-dom
npm install
```
 
npx create-react-app reactspa --template typescript
cd reactspa
npm install ajv
npm install react-router-dom
npm install
```
 

πŸ—‘οΈ Deleted Documentation Files

DELETED docs/fundamentals/whatis.md
Deleted by John Flores on Aug 20, 2025 8:40 PM
πŸ“– Was available at: https://learn.microsoft.com/en-us/entra/fundamentals/whatis
-91 lines removed
Commit: [Fundamentals] IAM Concepts Curation