📋 Microsoft Entra Documentation Changes

Daily summary for changes since September 2nd 2025, 8:00 PM PDT

Report generated on September 3rd 2025, 8:00 PM PDT

📊 Summary

24
Total Commits
0
New Files
5
Modified Files
0
Deleted Files
15
Contributors

📝 Modified Documentation Files

Modified by Henry Mbugua on Sep 3, 2025 8:12 AM
📖 View on learn.microsoft.com
+6 / -16 lines changed
Commit: What's new - August 2025
Changes:
Before
After
 
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
 
## July 2025
 
### Updated articles
- [Security best practices for application properties in Microsoft Entra ID](security-best-practices-for-app-registration.md) - Update security best practices
- [Run automated integration tests](test-automate-integration-testing.md) - The update improved content clarity.
 
## May 2025
 
### New articles
 
- [Email OTP send event reference](custom-extension-email-otp-send-data.md)
 
### Updated articles
 
- [Custom claims provider reference](custom-claims-provider-reference.md) - The update improved content clarity.
- [Application configuration options](msal-client-application-configuration.md) - The update improved content clarity.
- [Custom authentication extensions overview](custom-extension-overview.md) - The update improved content clarity.
 
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
 
## August 2025
 
### Updated articles
 
- [Microsoft Enterprise SSO plug-in for Apple devices](apple-sso-plugin.md) - We adjusted Apple SSO, updated the token protection image, and troubleshot secure enclave issues.
 
## July 2025
 
### Updated articles
- [Security best practices for application properties in Microsoft Entra ID](security-best-practices-for-app-registration.md) - Update security best practices
- [Run automated integration tests](test-automate-integration-testing.md) - The update improved content clarity.
 
 
 
 
 
 
Modified by omondiatieno on Sep 3, 2025 11:29 AM
📖 View on learn.microsoft.com
+9 / -7 lines changed
Commit: Sept whatsnew updates
Changes:
Before
After
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 08/06/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## July 2025
 
### Updated articles
- [Configure how users consent to applications](configure-user-consent.md) - Added clarity on authorization policies and app consent policies
 
 
## May 2025
 
### Updated articles
 
---
title: What's new in Microsoft Entra application management
description: This article shows the new and updated documentation for the Microsoft Entra application management.
ms.date: 09/03/2025
ms.service: entra-id
ms.subservice: enterprise-apps
ms.topic: whats-new
 
Welcome to what's new in Microsoft Entra application management documentation. This article lists new docs and those articles that had significant updates in the last three months. To learn what's new with the application management service, see [What's new in Microsoft Entra ID](~/fundamentals/whats-new.md).
 
## August 2025
 
 
### Updated articles
 
- [Manage app consent policies](manage-app-consent-policies.md) - Revised for technical accuracy
 
 
## July 2025
 
+7 / -2 lines changed
Commit: added roles
Changes:
Before
After
ms.service: entra-id
ms.subservice: domain-services
ms.topic: how-to
ms.date: 08/15/2025
ms.author: justinha
ms.reviewer: bochingwa
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
 
You can use the Azure portal or PowerShell to enable **TLS 1.2 Only Mode**.
 
## Identify applications that use deprecated TLS versions
 
Before you enable **TLS 1.2 Only Mode**, it's important to identify applications that still use TLS 1.0 or 1.1, and update them or replace them with alternatives that support TLS 1.2. For more information about apps that are expected to be impacted, see [TLS 1.0 and TLS 1.1 deprecation in Windows](/windows/win32/secauthn/tls-10-11-deprecation-in-windows).
 
## [**Azure portal**](#tab/portal)
 
1. In the Azure portal, search for **Domain Services**, and select your Domain Services instance.
1. Select **Security Settings**.
1. If **TLS 1.2 Only Mode** is set to **Disable**, the instance enables TLS versions 1.0 and 1.1. Set **TLS 1.2 Only Mode** to **Enable**, and then click **Save**.
 
ms.service: entra-id
ms.subservice: domain-services
ms.topic: how-to
ms.date: 09/03/2025
ms.author: justinha
ms.reviewer: bochingwa
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
 
You can use the Azure portal or PowerShell to enable **TLS 1.2 Only Mode**.
 
## Prerequisites
 
You need the [Application Administrator](../role-based-access-control/permissions-reference.md#application-administrator) and [Groups Administrator](../role-based-access-control/permissions-reference.md#groups-administrator) roles in Microsoft Entra ID to change security settings such as **TLS 1.2 Only Mode**.
 
## Identify applications that use deprecated TLS versions
 
Before you enable **TLS 1.2 Only Mode**, it's important to identify applications that still use TLS 1.0 or 1.1, and update them or replace them with alternatives that support TLS 1.2. For more information about apps that are expected to be impacted, see [TLS 1.0 and TLS 1.1 deprecation in Windows](/windows/win32/secauthn/tls-10-11-deprecation-in-windows).
 
## [**Azure portal**](#tab/portal)
 
Modified by Kristina Smith on Sep 3, 2025 5:20 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: Update execution user scope description for clarity
Changes:
Before
After
 
1. On the Execution conditions page, select the **Execution User Scope** tab.
 
1. On this page you're presented with a list of users who currently meet the scope for execution for the workflow.
:::image type="content" source="media/check-workflow-execution-scope/execution-user-scope-list.png" alt-text="Screenshot of users under scope of workflow execution." lightbox="media/check-workflow-execution-scope/execution-user-scope-list.png":::
 
> [!NOTE]
> The workflow engine routinely evaluates the users that meet the execution conditions. The results will not be up to date if the execution conditions have been changed recently, relevant attributes on the user have been changed recently, or the time based trigger has recently passed.
 
## Check execution user scope of a workflow using Microsoft Graph
 
 
1. On the Execution conditions page, select the **Execution User Scope** tab.
 
1. On this page you're presented with a list of users who currently meet the scope for execution for the workflow regardless of whether they have already been processed by the workflow.
:::image type="content" source="media/check-workflow-execution-scope/execution-user-scope-list.png" alt-text="Screenshot of users under scope of workflow execution." lightbox="media/check-workflow-execution-scope/execution-user-scope-list.png":::
 
> [!NOTE]
> The workflow engine routinely evaluates the users that meet the execution conditions regardless of whether they have already been processed by the workflow. The results will not be up to date if the execution conditions have been changed recently, relevant attributes on the user have been changed recently, or the time based trigger has recently passed.
 
## Check execution user scope of a workflow using Microsoft Graph
 
+1 / -1 lines changed
Commit: Sep 02 fixed link
Changes:
Before
After
### I have guests on my network who don't have the client installed.
Guest devices on your network might not have the client installed. To ensure that those devices adhere to your network security policies, you need their traffic routed through the Global Secure Access endpoint. Remote network connectivity solves this problem. No clients need to be installed on guest devices. All outgoing traffic from the remote network is going through security evaluation by default.
 
### How much bandwidth is allocated per tenant
 
The total bandwidth you're allocated is determined by the number of licenses purchased. Each Microsoft Entra ID P1 license, Microsoft Entra Internet Access license, or Microsoft Entra Suite license contributes to your total bandwidth. Bandwidth for remote networks can be assigned to IPsec tunnels in increments of 250 Mbps, 500 Mbps, 750 Mbps, or 1,000 Mbps. This flexibility allows you to allocate bandwidth to different remote network locations according to your specific needs. For optimal performance, Microsoft recommends configuring at least two IPsec tunnels per location for high availability. The table below details the total bandwidth based on the number of licenses purchased.
 
### I have guests on my network who don't have the client installed.
Guest devices on your network might not have the client installed. To ensure that those devices adhere to your network security policies, you need their traffic routed through the Global Secure Access endpoint. Remote network connectivity solves this problem. No clients need to be installed on guest devices. All outgoing traffic from the remote network is going through security evaluation by default.
 
### How much bandwidth will be allocated per tenant
 
The total bandwidth you're allocated is determined by the number of licenses purchased. Each Microsoft Entra ID P1 license, Microsoft Entra Internet Access license, or Microsoft Entra Suite license contributes to your total bandwidth. Bandwidth for remote networks can be assigned to IPsec tunnels in increments of 250 Mbps, 500 Mbps, 750 Mbps, or 1,000 Mbps. This flexibility allows you to allocate bandwidth to different remote network locations according to your specific needs. For optimal performance, Microsoft recommends configuring at least two IPsec tunnels per location for high availability. The table below details the total bandwidth based on the number of licenses purchased.