📋 Microsoft Entra Documentation Changes

Daily summary for changes since August 20th 2025, 8:13 PM PDT

Report generated on August 21st 2025, 8:13 PM PDT

📊 Summary

8
Total Commits
0
New Files
28
Modified Files
0
Deleted Files
6
Contributors

📝 Modified Documentation Files

Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
# What is the Microsoft Entra architecture?
 
Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/whatis.md)
 
With Microsoft Entra, you can create and manage users and groups, and enable permissions to allow and deny access to enterprise resources. For information about identity management, see the [fundamentals of identity management](~/fundamentals/whatis.md).
 
<a name='azure-ad-architecture'></a>
 
 
# What is the Microsoft Entra architecture?
 
Microsoft Entra enables you to securely manage user access to services and resources. Included with Microsoft Entra is a family of identity management and network access capabilities. For information about Microsoft Entra features, see [What is Microsoft Entra?](~/fundamentals/what-is-entra.md)
 
With Microsoft Entra, you can create and manage users and groups, and enable permissions to allow and deny access to enterprise resources. For information about identity management, see the [fundamentals of identity management](~/fundamentals/identity-fundamental-concepts.md).
 
<a name='azure-ad-architecture'></a>
 
+2 / -2 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
To ensure that the users can easily and securely access applications, your goal is to have a single set of access controls and policies across your on-premises and cloud environments.
 
[Microsoft Entra ID](~/fundamentals/whatis.md) offers a universal identity platform that provides your employees, partners, and customers a single identity to access the applications they want. The platform boosts collaboration from any platform and device.
 
:::image type="content" source="media/migrate-adfs-apps-phases-overview/connectivity.png" alt-text="Diagram showing Microsoft Entra connectivity." lightbox="media/migrate-adfs-apps-phases-overview/connectivity.png":::
 
Microsoft Entra ID has a [full suite of identity management capabilities](~/fundamentals/whatis.md#which-features-work-in-azure-ad). Standardizing your app authentication and authorization to Microsoft Entra ID gets you the benefits that these capabilities provide.
 
You can find more migration resources at [https://aka.ms/migrateapps](./migration-resources.md)
 
 
To ensure that the users can easily and securely access applications, your goal is to have a single set of access controls and policies across your on-premises and cloud environments.
 
[Microsoft Entra ID](~/fundamentals/what-is-entra.md) offers a universal identity platform that provides your employees, partners, and customers a single identity to access the applications they want. The platform boosts collaboration from any platform and device.
 
:::image type="content" source="media/migrate-adfs-apps-phases-overview/connectivity.png" alt-text="Diagram showing Microsoft Entra connectivity." lightbox="media/migrate-adfs-apps-phases-overview/connectivity.png":::
 
Microsoft Entra ID has a full suite of identity management capabilities. Standardizing your app authentication and authorization to Microsoft Entra ID gets you the benefits that these capabilities provide.
 
You can find more migration resources at [https://aka.ms/migrateapps](./migration-resources.md)
 
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
Learn more on [Microsoft Azure platform is HITRUST CSF certified](https://azure.microsoft.com/blog/microsoft-azure-achieves-hitrust-csf-certification/), which includes identity and access management:
* [Microsoft Entra ID](~/fundamentals/whatis.md), formerly known as Azure Active Directory
* Rights management with [Microsoft Purview](https://techcommunity.microsoft.com/t5/healthcare-and-life-sciences/microsoft-purview-compliance-score-part-3-hitrust/ba-p/3614103)
* [Microsoft Entra multifactor authentication (MFA)](~/identity/authentication/concept-mfa-howitworks.md)
| HITRUST control, objective, and HSR | Microsoft Entra guidance and recommendation |
| - | - |
|**CSF Control V11**<br>01.b User Registration<br><br>**Control category**<br>Access Control – User Registration and De-Registration<br><br>**Control specification**<br>The organization uses a formal user registration and deregistration process to enable assignment of access rights.<br><br>**Objective name**<br>Authorized Access to Information Systems<br><br>**HIPAA Security Rule**<br>§ 164.308(a)(3)(ii)(A)<br>§ 164.308(a)(4)(i)<br>§ 164.308(a)(3)(ii)(B)<br>§ 164.308(a)(4)(ii)(C)<br>§ 164.308(a)(4)(ii)(B)<br>§ 164.308(a)(5)(ii)(D)<br>§ 164.312(a)(2)(i)<br>§ 164.312(a)(2)(ii)<br>§ 164.312(d) |[Microsoft Entra ID](~/fundamentals/whatis.md) is an identity platform for verification, [authentication](~/identity/authentication/overview-authentication.md), and credential management when an identity signs in to their device, application, or server. It’s a cloud-based identity and access management service with single sign-on (SSO), MFA, and [Conditional Access](~/identity/conditional-access/overview.md) to guard against security attacks. Authentication ensures only authorized identities gain access to resources and data.<br><br>[Lifecycle workflows](~/id-governance/understanding-lifecycle-workflows.md) enable identity governance to automate the joiner, mover, leaver (JML) lifecycle. It centralizes the workflow process by using the built-in templates or you create custom workflows. This practice helps reduce, or potentially remove, manual tasks for organizational JML strategy requirements. On the Azure portal, navigate to **ID Governance** in the Microsoft Entra ID menu to review or configure tasks for your organizational requirements.<br><br>[Microsoft Entra Connect](~/identity/hybrid/connect/how-to-connect-install-roadmap.md) integrates on-premises directories with Microsoft Entra ID, supporting the use of single identities to access on-premises applications and cloud services such as Microsoft 365. It orchestrates synchronization between Active Directory (AD) and Microsoft Entra ID. To get started with Microsoft Entra Connect, review the prerequisites. Note the server requirements and how to prepare your Microsoft Entra tenant for management.<br><br>[Microsoft Entra Connect Sync](~/identity/hybrid/cloud-sync/tutorial-pilot-aadc-aadccp.md) is a provisioning agent managed on the cloud, which supports synchronization to Microsoft Entra ID from a multi-forest disconnected AD environment. Use the lightweight agents with Microsoft Entra Connect. We recommend password hash sync to help reduce the number of passwords and protect against leaked credential detection.|
|**CSF Control V11**<br>01.c Privilege Management<br><br>**Control category**<br>Access Control – Privileged Accounts<br><br>**Control specification**<br>The organization ensures authorized user accounts are registered, tracked, and periodically validated to prevent unauthorized access to information systems<br><br>**Objective name**<br>Authorized Access to Information Systems<br><br>**HIPAA Security Rule**<br>§ 164.308(a)(1)(i)<br>§ 164.308(a)(1)(ii)(B)<br>§ 164.308(a)(2)<br>§ 164.308(a)(3)(ii)(B)<br>§ 164.308(a)(3)(ii)(A)<br>§ 164.308(a)(4)(i)<br>§ 164.308(a)(4)(ii)(B)<br>§ 164.308(a)(4)(ii)(C)<br>§ 164.310(a)(2)(ii)<br>§ 164.310(a)(1)<br>§ 164.310(a)(2)(iii)<br>§ 164.312(a)(1)|[Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) is a service in Microsoft Entra ID to manage, control and monitor access to important resources in an organization. It minimizes the number of people with access to secure information to help prevent malicious actors from getting access.<br><br>PIM has time and approval-based access, to mitigate the risks of excessive, unnecessary, or misused access permissions. It helps identify and analyze privileged accounts to ensure you provide just enough access (JEA) for a user to perform their role.<br><br>[Monitoring and generating alerts](~/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts.md) prevent suspicious activities, listing the users and roles that trigger the alert, while reducing the risk of unauthorized access. Customize alerts for your organizational security strategy.<br><br>[Access reviews](~/id-governance/access-reviews-overview.md) enable organizations to manage role assignments and group membership efficiently. Maintain security and compliance by evaluating which accounts have access and ensure access is revoked when needed, thus minimizing the risks from excessive or outdated permissions. |
|**CSF Control V11**<br>0.1d User Password Management<br><br>**Control category**<br>Access Control - Procedures<br><br>**Control specification**<br>To ensure authorized user accounts are registered, tracked, and periodically validated to prevent unauthorized access to information systems.<br><br>**Objective name**<br>Authorized Access to Information Systems<br><br>**HIPAA Security Rule**<br>§164.308(a)(5)(ii)(D)|[Password management](/azure/security/fundamentals/identity-management-best-practices) is a critical aspect of security infrastructure. Align with best practices to create a robust security posture, Microsoft Entra ID helps facilitate with a comprehensive strategy support: [SSO](~/identity/enterprise-apps/add-application-portal-setup-sso.md) and [MFA](~/identity/authentication/concept-mfa-howitworks.md) also [passwordless authentication](~/identity/authentication/concept-authentication-passwordless.md), such as FIDO2 security keys and Windows Hello for Business (WHfB) mitigate user risk and streamline the user authentication experience.<br><br>Microsoft Entra Password Protection detects, and blocks, known weak passwords. It incorporates password [policies](~/identity/authentication/tutorial-configure-custom-password-protection.md) and has the flexibility to define a custom password list and build a password management strategy to safeguard password use.<br><br>HITRUST password length and strength requirements align with the National Institute of Standards and Technology [NIST 800-63B](https://pages.nist.gov/800-63-3/sp800-63b.html), which includes a minimum of eight characters for a password, or 15 characters for accounts with the most privileged access. Complexity measures include at least one number and/or special character and at least one upper- and lower-case letter for privileged accounts.|
|**CSF Control V11**<br>01.p Secure Log-on Procedures<br><br>**Control category**<br>Access Control – Secure Logon<br><br>**Control specification**<br>The organization controls access to information assets using a secure logon procedure.<br><br>**Objective name**<br>Operating System Access Control<br><br>**HIPAA Security Rule**<br>§ 164.308(a)(5)(i)<br>§ 164.308(a)(5)(ii)(C)<br>§ 164.308(a)(5)(ii)(D)|Secure sign-in is the process to authenticate an identity securely when they attempt to access a system.<br><br>**The control focuses on the [operating system](/azure/governance/policy/samples/hipaa-hitrust-9-2), Microsoft Entra services help strengthen the secure sign in.**<br><br>[Conditional Access](~/identity/conditional-access/overview.md) policies help organizations restrict access to approved applications, resources, and ensure devices are secure. Microsoft Entra ID analyzes the signals from Conditional Access [policies](~/identity/conditional-access/concept-conditional-access-policies.md) from the identity, location, or device to automate the decision and enforce organizational policies for access to resources and data.<br><br>[Role-based access control (RBAC)](~/identity/role-based-access-control/custom-overview.md) helps you manage access and managed resources in your organization. RBAC helps implement the principle of least privilege, ensuring users have the permissions they need to perform their tasks. This action minimizes the risk of accidental or intentional misconfiguration.<br><br>As noted for control 0.1d User Password Management, passwordless authentication uses biometrics because they are difficult to forge, thus providing more secure authentication. |
Learn more on [Microsoft Azure platform is HITRUST CSF certified](https://azure.microsoft.com/blog/microsoft-azure-achieves-hitrust-csf-certification/), which includes identity and access management:
* [Microsoft Entra ID](~/fundamentals/what-is-entra.md), formerly known as Azure Active Directory
* Rights management with [Microsoft Purview](https://techcommunity.microsoft.com/t5/healthcare-and-life-sciences/microsoft-purview-compliance-score-part-3-hitrust/ba-p/3614103)
* [Microsoft Entra multifactor authentication (MFA)](~/identity/authentication/concept-mfa-howitworks.md)
| HITRUST control, objective, and HSR | Microsoft Entra guidance and recommendation |
| - | - |
|**CSF Control V11**<br>01.b User Registration<br><br>**Control category**<br>Access Control – User Registration and De-Registration<br><br>**Control specification**<br>The organization uses a formal user registration and deregistration process to enable assignment of access rights.<br><br>**Objective name**<br>Authorized Access to Information Systems<br><br>**HIPAA Security Rule**<br>§ 164.308(a)(3)(ii)(A)<br>§ 164.308(a)(4)(i)<br>§ 164.308(a)(3)(ii)(B)<br>§ 164.308(a)(4)(ii)(C)<br>§ 164.308(a)(4)(ii)(B)<br>§ 164.308(a)(5)(ii)(D)<br>§ 164.312(a)(2)(i)<br>§ 164.312(a)(2)(ii)<br>§ 164.312(d) |[Microsoft Entra ID](~/fundamentals/what-is-entra.md) is an identity platform for verification, [authentication](~/identity/authentication/overview-authentication.md), and credential management when an identity signs in to their device, application, or server. It’s a cloud-based identity and access management service with single sign-on (SSO), MFA, and [Conditional Access](~/identity/conditional-access/overview.md) to guard against security attacks. Authentication ensures only authorized identities gain access to resources and data.<br><br>[Lifecycle workflows](~/id-governance/understanding-lifecycle-workflows.md) enable identity governance to automate the joiner, mover, leaver (JML) lifecycle. It centralizes the workflow process by using the built-in templates or you create custom workflows. This practice helps reduce, or potentially remove, manual tasks for organizational JML strategy requirements. On the Azure portal, navigate to **ID Governance** in the Microsoft Entra ID menu to review or configure tasks for your organizational requirements.<br><br>[Microsoft Entra Connect](~/identity/hybrid/connect/how-to-connect-install-roadmap.md) integrates on-premises directories with Microsoft Entra ID, supporting the use of single identities to access on-premises applications and cloud services such as Microsoft 365. It orchestrates synchronization between Active Directory (AD) and Microsoft Entra ID. To get started with Microsoft Entra Connect, review the prerequisites. Note the server requirements and how to prepare your Microsoft Entra tenant for management.<br><br>[Microsoft Entra Connect Sync](~/identity/hybrid/cloud-sync/tutorial-pilot-aadc-aadccp.md) is a provisioning agent managed on the cloud, which supports synchronization to Microsoft Entra ID from a multi-forest disconnected AD environment. Use the lightweight agents with Microsoft Entra Connect. We recommend password hash sync to help reduce the number of passwords and protect against leaked credential detection.|
|**CSF Control V11**<br>01.c Privilege Management<br><br>**Control category**<br>Access Control – Privileged Accounts<br><br>**Control specification**<br>The organization ensures authorized user accounts are registered, tracked, and periodically validated to prevent unauthorized access to information systems<br><br>**Objective name**<br>Authorized Access to Information Systems<br><br>**HIPAA Security Rule**<br>§ 164.308(a)(1)(i)<br>§ 164.308(a)(1)(ii)(B)<br>§ 164.308(a)(2)<br>§ 164.308(a)(3)(ii)(B)<br>§ 164.308(a)(3)(ii)(A)<br>§ 164.308(a)(4)(i)<br>§ 164.308(a)(4)(ii)(B)<br>§ 164.308(a)(4)(ii)(C)<br>§ 164.310(a)(2)(ii)<br>§ 164.310(a)(1)<br>§ 164.310(a)(2)(iii)<br>§ 164.312(a)(1)|[Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) is a service in Microsoft Entra ID to manage, control and monitor access to important resources in an organization. It minimizes the number of people with access to secure information to help prevent malicious actors from getting access.<br><br>PIM has time and approval-based access, to mitigate the risks of excessive, unnecessary, or misused access permissions. It helps identify and analyze privileged accounts to ensure you provide just enough access (JEA) for a user to perform their role.<br><br>[Monitoring and generating alerts](~/id-governance/privileged-identity-management/pim-how-to-configure-security-alerts.md) prevent suspicious activities, listing the users and roles that trigger the alert, while reducing the risk of unauthorized access. Customize alerts for your organizational security strategy.<br><br>[Access reviews](~/id-governance/access-reviews-overview.md) enable organizations to manage role assignments and group membership efficiently. Maintain security and compliance by evaluating which accounts have access and ensure access is revoked when needed, thus minimizing the risks from excessive or outdated permissions. |
|**CSF Control V11**<br>0.1d User Password Management<br><br>**Control category**<br>Access Control - Procedures<br><br>**Control specification**<br>To ensure authorized user accounts are registered, tracked, and periodically validated to prevent unauthorized access to information systems.<br><br>**Objective name**<br>Authorized Access to Information Systems<br><br>**HIPAA Security Rule**<br>§164.308(a)(5)(ii)(D)|[Password management](/azure/security/fundamentals/identity-management-best-practices) is a critical aspect of security infrastructure. Align with best practices to create a robust security posture, Microsoft Entra ID helps facilitate with a comprehensive strategy support: [SSO](~/identity/enterprise-apps/add-application-portal-setup-sso.md) and [MFA](~/identity/authentication/concept-mfa-howitworks.md) also [passwordless authentication](~/identity/authentication/concept-authentication-passwordless.md), such as FIDO2 security keys and Windows Hello for Business (WHfB) mitigate user risk and streamline the user authentication experience.<br><br>Microsoft Entra Password Protection detects, and blocks, known weak passwords. It incorporates password [policies](~/identity/authentication/tutorial-configure-custom-password-protection.md) and has the flexibility to define a custom password list and build a password management strategy to safeguard password use.<br><br>HITRUST password length and strength requirements align with the National Institute of Standards and Technology [NIST 800-63B](https://pages.nist.gov/800-63-3/sp800-63b.html), which includes a minimum of eight characters for a password, or 15 characters for accounts with the most privileged access. Complexity measures include at least one number and/or special character and at least one upper- and lower-case letter for privileged accounts.|
|**CSF Control V11**<br>01.p Secure Log-on Procedures<br><br>**Control category**<br>Access Control – Secure Logon<br><br>**Control specification**<br>The organization controls access to information assets using a secure logon procedure.<br><br>**Objective name**<br>Operating System Access Control<br><br>**HIPAA Security Rule**<br>§ 164.308(a)(5)(i)<br>§ 164.308(a)(5)(ii)(C)<br>§ 164.308(a)(5)(ii)(D)|Secure sign-in is the process to authenticate an identity securely when they attempt to access a system.<br><br>**The control focuses on the [operating system](/azure/governance/policy/samples/hipaa-hitrust-9-2), Microsoft Entra services help strengthen the secure sign in.**<br><br>[Conditional Access](~/identity/conditional-access/overview.md) policies help organizations restrict access to approved applications, resources, and ensure devices are secure. Microsoft Entra ID analyzes the signals from Conditional Access [policies](~/identity/conditional-access/concept-conditional-access-policies.md) from the identity, location, or device to automate the decision and enforce organizational policies for access to resources and data.<br><br>[Role-based access control (RBAC)](~/identity/role-based-access-control/custom-overview.md) helps you manage access and managed resources in your organization. RBAC helps implement the principle of least privilege, ensuring users have the permissions they need to perform their tasks. This action minimizes the risk of accidental or intentional misconfiguration.<br><br>As noted for control 0.1d User Password Management, passwordless authentication uses biometrics because they are difficult to forge, thus providing more secure authentication. |
+0 / -3 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
* [Lifecycle workflows](../id-governance/what-are-lifecycle-workflows.md)
* [Microsoft Entra](../fundamentals/what-is-entra.md)
* [Microsoft Entra ID](../fundamentals/whatis.md)
* [Microsoft Entra Connect](../identity/hybrid/connect/whatis-azure-ad-connect.md)
* [Microsoft Entra Cloud Sync](../identity/hybrid/cloud-sync/what-is-cloud-sync.md)
* [Azure Logic Apps](/azure/logic-apps/logic-apps-overview)
With the Microsoft Entra ID Governance solution, organizations improve productivity, strengthen security, and meet compliance and regulatory requirements. Use Microsoft Entra ID Governance to ensure the right people have the right access to the right resources at the right time. Learn more about Microsoft Entra ID Governance [use cases](../id-governance/scenarios/identity-governance-use-cases.md) and [documentation](../id-governance/identity-governance-overview.md).
Learn more about [Microsoft Entra ID](../fundamentals/whatis.md).
## HR-driven provisioning
HR-driven provisioning creates digital identities based on a human resources (HR) system, which becomes the source of authority. This juncture is the starting point for numerous provisioning processes.
* [Microsoft Entra ID Governance](../id-governance/identity-governance-overview.md)
* [Lifecycle workflows](../id-governance/what-are-lifecycle-workflows.md)
* [Microsoft Entra](../fundamentals/what-is-entra.md)
* [Microsoft Entra Connect](../identity/hybrid/connect/whatis-azure-ad-connect.md)
* [Microsoft Entra Cloud Sync](../identity/hybrid/cloud-sync/what-is-cloud-sync.md)
* [Azure Logic Apps](/azure/logic-apps/logic-apps-overview)
With the Microsoft Entra ID Governance solution, organizations improve productivity, strengthen security, and meet compliance and regulatory requirements. Use Microsoft Entra ID Governance to ensure the right people have the right access to the right resources at the right time. Learn more about Microsoft Entra ID Governance [use cases](../id-governance/scenarios/identity-governance-use-cases.md) and [documentation](../id-governance/identity-governance-overview.md).
## HR-driven provisioning
HR-driven provisioning creates digital identities based on a human resources (HR) system, which becomes the source of authority. This juncture is the starting point for numerous provisioning processes.
 
 
 
+1 / -1 lines changed
Commit: [Conditional Access] Public PR 1702 contribution fix
Changes:
Before
After
When you target the Windows Azure Service Management API application, policy is enforced for tokens issued to a set of services closely bound to the portal. This grouping includes the application IDs of:
 
- Azure Resource Manager
- Azure portal, which also covers the Microsoft Entra admin center
- Azure Data Lake
- Application Insights API
- Log Analytics API
When you target the Windows Azure Service Management API application, policy is enforced for tokens issued to a set of services closely bound to the portal. This grouping includes the application IDs of:
 
- Azure Resource Manager
- Azure portal, which also covers the Microsoft Entra admin center and the Microsoft Engage Center
- Azure Data Lake
- Application Insights API
- Log Analytics API
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
# Microsoft Entra deployment plans
 
Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/whatis.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.
 
Use this article's guidance to help build your plan to deploy Microsoft Entra ID. Learn about plan-building basics and then use the following sections for authentication deployment, apps and devices, hybrid scenarios, user identity, and more.
 
 
# Microsoft Entra deployment plans
 
Azure Active Directory is now [Microsoft Entra ID](~/fundamentals/what-is-entra.md), which can safeguard your organization with cloud identity and access management. The solution connects employees, customers, and partners to their apps, devices, and data.
 
Use this article's guidance to help build your plan to deploy Microsoft Entra ID. Learn about plan-building basics and then use the following sections for authentication deployment, apps and devices, hybrid scenarios, user identity, and more.
 
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
---
# Microsoft Entra ID Guide for independent software developers
[Microsoft Entra ID](~/fundamentals/whatis.md) is a cloud-based identity and access management service that enables employees to access resources. Industry analysts consistently recognize Microsoft Entra ID as a leader. It's a seven-time Leader in the [Gartner Magic Quadrant for Access Management](https://go.microsoft.com/fwlink/p/?linkid=2215126). [KuppingerCole rates Microsoft Entra ID](https://www.kuppingercole.com/reprints/62c08b4d46f70b1c19245b8f09011f5e) as positive across all dimensions in access management. Frost & Sullivan named Microsoft the [2022 Company of the Year](https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE58dFV) for the Global Identity and Access Management industry. [Read stories](https://customers.microsoft.com/search?sq=%22Entra%20ID%22&ff=language%26%3EEnglish&p=6&so=story_publish_date%20desc) about some of more than 300,000 organizations that use Microsoft Entra ID.
This article is the first in a series on how independent software developers (ISVs) can build and optimize applications for Microsoft Entra ID. In this series, you can learn more about these topics:
---
# Microsoft Entra ID Guide for independent software developers
[Microsoft Entra ID](~/fundamentals/what-is-entra.md) is a cloud-based identity and access management service that enables employees to access resources. Industry analysts consistently recognize Microsoft Entra ID as a leader. It's a seven-time Leader in the [Gartner Magic Quadrant for Access Management](https://go.microsoft.com/fwlink/p/?linkid=2215126). [KuppingerCole rates Microsoft Entra ID](https://www.kuppingercole.com/reprints/62c08b4d46f70b1c19245b8f09011f5e) as positive across all dimensions in access management. Frost & Sullivan named Microsoft the [2022 Company of the Year](https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE58dFV) for the Global Identity and Access Management industry. [Read stories](https://customers.microsoft.com/search?sq=%22Entra%20ID%22&ff=language%26%3EEnglish&p=6&so=story_publish_date%20desc) about some of more than 300,000 organizations that use Microsoft Entra ID.
This article is the first in a series on how independent software developers (ISVs) can build and optimize applications for Microsoft Entra ID. In this series, you can learn more about these topics:
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
## Microsoft Entra functional areas
 
These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/whatis.md).
 
### Authentication
 
 
## Microsoft Entra functional areas
 
These functional areas are provided by Microsoft Entra ID that are relevant to isolated environments. To learn more about the capabilities of Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).
 
### Authentication
 
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
## Prerequisites
 
- [Microsoft Entra ID license that includes Privileged Identity Management (PIM)](~/fundamentals/whatis.md)
- [Microsoft Entra Private Access](concept-private-access.md)
 
## Secure private access
 
## Prerequisites
 
- [Microsoft Entra ID license that includes Privileged Identity Management (PIM)](~/fundamentals/licensing.md)
- [Microsoft Entra Private Access](concept-private-access.md)
 
## Secure private access
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
This article describes features and methods that allow you to pinpoint and select external identities so that you can review them and remove them from Microsoft Entra ID if they're no longer needed. The cloud makes it easier than ever to collaborate with internal or external users. When embracing Office 365, organizations start to see the proliferation of external identities (including guests), as users work together on data, documents, or digital workspaces such as Teams. Organizations need to balance, enabling collaboration and meeting security and governance requirements. Part of these efforts should include evaluating and cleaning out external users, who were invited for collaboration into your tenant, that originating from partner organizations, and removing them from your Microsoft Entra ID when they're no longer needed.
 
>[!NOTE]
>A valid Microsoft Entra ID P2 or Microsoft Entra ID Governance, Enterprise Mobility + Security E5 paid, or trial license is required to use Microsoft Entra access reviews. For more information, see [Microsoft Entra editions](../fundamentals/whatis.md).
 
## Why review users from external organizations in your tenant?
 
This article describes features and methods that allow you to pinpoint and select external identities so that you can review them and remove them from Microsoft Entra ID if they're no longer needed. The cloud makes it easier than ever to collaborate with internal or external users. When embracing Office 365, organizations start to see the proliferation of external identities (including guests), as users work together on data, documents, or digital workspaces such as Teams. Organizations need to balance, enabling collaboration and meeting security and governance requirements. Part of these efforts should include evaluating and cleaning out external users, who were invited for collaboration into your tenant, that originating from partner organizations, and removing them from your Microsoft Entra ID when they're no longer needed.
 
>[!NOTE]
>A valid Microsoft Entra ID P2 or Microsoft Entra ID Governance, Enterprise Mobility + Security E5 paid, or trial license is required to use Microsoft Entra access reviews. For more information, see [Microsoft Entra editions](../fundamentals/licensing.md).
 
## Why review users from external organizations in your tenant?
 
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
In an ideal world, all users follow the access policies to secure access to your organization's resources. However, sometimes there are business cases that require you to make exceptions. This article goes over some examples of situations where exclusions could be necessary. You, as the IT administrator, can manage this task, avoid oversight of policy exceptions, and provide auditors with proof that these exceptions are reviewed regularly using Microsoft Entra access reviews.
 
>[!NOTE]
> A valid Microsoft Entra ID P2 or Microsoft Entra ID Governance, Enterprise Mobility + Security E5 paid, or trial license is required to use Microsoft Entra access reviews. For more information, see [Microsoft Entra editions](../fundamentals/whatis.md).
 
## Why would you exclude users from policies?
 
In an ideal world, all users follow the access policies to secure access to your organization's resources. However, sometimes there are business cases that require you to make exceptions. This article goes over some examples of situations where exclusions could be necessary. You, as the IT administrator, can manage this task, avoid oversight of policy exceptions, and provide auditors with proof that these exceptions are reviewed regularly using Microsoft Entra access reviews.
 
>[!NOTE]
> A valid Microsoft Entra ID P2 or Microsoft Entra ID Governance, Enterprise Mobility + Security E5 paid, or trial license is required to use Microsoft Entra access reviews. For more information, see [Microsoft Entra editions](../fundamentals/licensing.md).
 
## Why would you exclude users from policies?
 
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
| | Description |
| --- | --- |
| **Why do I get this alert?** | The current Microsoft Entra organization doesn't have Microsoft Entra ID P2 or Microsoft Entra ID Governance. |
| **How to fix?** | Review information about [Microsoft Entra editions](~/fundamentals/whatis.md). Upgrade to Microsoft Entra ID P2 or Microsoft Entra ID Governance. |
 
### Potential stale accounts in a privileged role
 
| | Description |
| --- | --- |
| **Why do I get this alert?** | The current Microsoft Entra organization doesn't have Microsoft Entra ID P2 or Microsoft Entra ID Governance. |
| **How to fix?** | Review information about [Microsoft Entra editions](~/fundamentals/licensing.md). Upgrade to Microsoft Entra ID P2 or Microsoft Entra ID Governance. |
 
### Potential stale accounts in a privileged role
 
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
### Prerequisites
 
Microsoft Entra Conditional Access is a feature included in [Microsoft Entra ID P1 or P2](~/fundamentals/whatis.md). Customers with [Microsoft 365 Business licenses](/office365/servicedescriptions/office-365-service-descriptions-technet-library) also have access to Conditional Access features.
 
### Considerations for specific scenarios
 
 
### Prerequisites
 
Microsoft Entra Conditional Access is a feature included in [Microsoft Entra ID P1 or P2](~/fundamentals/licensing.md). Customers with [Microsoft 365 Business licenses](/office365/servicedescriptions/office-365-service-descriptions-technet-library) also have access to Conditional Access features.
 
### Considerations for specific scenarios
 
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
You need a license for PingAccess and Microsoft Entra ID. However, Microsoft Entra ID P1 or P2 subscriptions include a basic PingAccess license that covers up to 20 applications. If you need to publish more than 20 header-based applications, you can purchase more licenses from PingAccess.
 
For more information, see [Microsoft Entra editions](~/fundamentals/whatis.md).
 
## Publish your application in Microsoft Entra
 
 
You need a license for PingAccess and Microsoft Entra ID. However, Microsoft Entra ID P1 or P2 subscriptions include a basic PingAccess license that covers up to 20 applications. If you need to publish more than 20 header-based applications, you can purchase more licenses from PingAccess.
 
For more information, see [Microsoft Entra editions](~/fundamentals/licensing.md).
 
## Publish your application in Microsoft Entra
 
Modified by John Flores on Aug 21, 2025 2:43 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: [BULK] Link fix for consolidated topic whatis to what-is-entra
Changes:
Before
After
 
## Next steps
 
For more information about Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/whatis.md).
 
## Next steps
 
For more information about Microsoft Entra ID, see [What is Microsoft Entra ID?](~/fundamentals/what-is-entra.md).