đź“‹ Microsoft Entra Documentation Changes

Daily summary for changes since September 3rd 2025, 8:04 PM PDT

Report generated on September 4th 2025, 8:04 PM PDT

📊 Summary

38
Total Commits
1
New Files
18
Modified Files
2
Deleted Files
14
Contributors

🆕 New Documentation Files

+158 lines added
Commit: Rename of GitHub AE to GitHub Enteprise Server

📝 Modified Documentation Files

+11 / -15 lines changed
Commit: fix blocking issues
Changes:
Before
After
---
title: Configure GitHub Enterprise Server for automatic user provisioning with Microsoft Entra ID
description: Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Server.
 
 
author: jeevansd
manager: mwongerapk
 
ms.service: entra-id
ms.subservice: saas-apps
 
ms.topic: how-to
ms.date: 03/25/2025
ms.author: jeedes
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Browse to **Entra ID** > **Enterprise apps**
 
![Enterprise applications blade](common/enterprise-applications.png)
 
1. In the applications list, select **GitHub Enterprise Server**.
---
title: Configure GitHub Enterprise Server for Automatic User Provisioning with Microsoft Entra ID
description: Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to GitHub Enterprise Server.
author: jeevansd
manager: mwongerapk
ms.service: entra-id
ms.subservice: saas-apps
ms.topic: how-to
ms.date: 03/25/2025
ms.author: jeedes
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Browse to **Entra ID** > **Enterprise apps**
 
![Screenshot of the Enterprise applications blade.](common/enterprise-applications.png)
 
1. In the applications list, select **GitHub Enterprise Server**.
 
![Screenshot of the GitHub Enterprise Server link highlighted in the Applications list.](common/all-applications.png)
 
1. Select the **Provisioning** tab.
+8 / -12 lines changed
Commit: Update SOA group sync prerequisites and setup steps
Changes:
Before
After
ms.service: entra-id
ms.subservice: hybrid
ms.topic: how-to
ms.date: 08/11/2025
ms.author: justinha
ms.reviewer: dhanyak
---
| **Roles** | [Hybrid Administrator](/entra/identity/role-based-access-control/permissions-reference#hybrid-administrator) is required to call the Microsoft Graph APIs to read and update SOA of groups.<br>[Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator) or [Cloud Application Administrator](/entra/identity/role-based-access-control/permissions-reference#cloud-application-administrator) is required to grant user consent to the required permissions to Microsoft Graph Explorer or the app used to call the Microsoft Graph APIs. |
| **Permissions** | For apps calling into the onPremisesSyncBehavior Microsoft Graph API, the Group-OnPremisesSyncBehavior.ReadWrite.All permission scope needs to be granted. For more information, see [how to grant this permission](#grant-permission-to-apps) to Graph Explorer or an existing app in your tenant. |
| **License needed** | Microsoft Entra Free license. |
| **Connect Sync client** | Minimum version is [2.5.76.0](/entra/identity/hybrid/connect/reference-connect-version-history#25760). You can use either sync client to synchronize SOA converted groups. |
| **Cloud Sync client** | Minimum version is [1.1.1370.0](/entra/identity/hybrid/cloud-sync/reference-version-history#1113700). To provision a SOA converted group from Microsoft Entra ID to Active Directory Domain Services (AD DS), you need to use Cloud Sync. |
 
## Setup
 
The next sections cover how to set up Connect Sync (optional) and Cloud Sync.
 
### Connect Sync client
 
1. Download the latest version of the Connect Sync build.
ms.service: entra-id
ms.subservice: hybrid
ms.topic: how-to
ms.date: 09/04/2025
ms.author: justinha
ms.reviewer: dhanyak
---
| **Roles** | [Hybrid Administrator](/entra/identity/role-based-access-control/permissions-reference#hybrid-administrator) is required to call the Microsoft Graph APIs to read and update SOA of groups.<br>[Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator) or [Cloud Application Administrator](/entra/identity/role-based-access-control/permissions-reference#cloud-application-administrator) is required to grant user consent to the required permissions to Microsoft Graph Explorer or the app used to call the Microsoft Graph APIs. |
| **Permissions** | For apps calling into the onPremisesSyncBehavior Microsoft Graph API, the Group-OnPremisesSyncBehavior.ReadWrite.All permission scope needs to be granted. For more information, see [how to grant this permission](#grant-permission-to-apps) to Graph Explorer or an existing app in your tenant. |
| **License needed** | Microsoft Entra Free license. |
| **Sync client** | You can use either sync client to to synchronize SOA converted groups. If you use Connect Sync, upgrade to the minimum version [2.5.76.0](/entra/identity/hybrid/connect/reference-connect-version-history#25760). If you use Cloud Sync, upgrade to Minimum version [1.1.1370.0](/entra/identity/hybrid/cloud-sync/reference-version-history#1113700). |
| **Provisioning to AD** | To provision a SOA converted group from Microsoft Entra ID to Active Directory Domain Services (AD DS), you need to use Cloud Sync. |
 
### Download Connect Sync client
 
1. Download Connect Sync build version [2.5.76.0](/entra/identity/hybrid/connect/reference-connect-version-history#25760) or later.
 
1. Go to **Programs** in Control Panel and confirm the version of Microsoft Entra Connect Sync.
 
### Download Cloud Sync client
+6 / -5 lines changed
Commit: Update concept-mandatory-multifactor-authentication.md
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 09/03/2025
ms.author: justinha
author: justinha
manager: dougeby
| [REST API (Control Plane)](/azure/azure-resource-manager/management/control-plane-and-data-plane#control-plane) | N/A | October 1, 2025 |
| [Azure SDK](/azure/developer/intro/azure-developer-create-resources#azure-sdk-and-rest-apis) | N/A | October 1, 2025 |
 
For the best compatability experience, ensure users in your tenant are using Azure CLI version 2.76 and Azure PowerShell version 14.3 or later. Otherwise, you can expect to see error messages as explained in these topics:
 
- [Troubleshoot MFA errors in Azure Powershell](/powershell/azure/troubleshooting#troubleshooting-multifactor-authentication-mfa)
- [Troubleshoot MFA errors in Azure CLI](/cli/azure/use-azure-cli-successfully-troubleshooting#troubleshooting-multifactor-authentication-mfa)
 
The following table lists affected apps and URLs for Microsoft 365.
 
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 09/04/2025
ms.author: justinha
author: justinha
manager: dougeby
| [REST API (Control Plane)](/azure/azure-resource-manager/management/control-plane-and-data-plane#control-plane) | N/A | October 1, 2025 |
| [Azure SDK](/azure/developer/intro/azure-developer-create-resources#azure-sdk-and-rest-apis) | N/A | October 1, 2025 |
 
>[!NOTE]
>For the best compatability experience, ensure users in your tenant are using Azure CLI version 2.76 and Azure PowerShell version 14.3 or later. Otherwise, you can expect to see error messages as explained in these topics:
>
>- [Troubleshoot MFA errors in Azure Powershell](/powershell/azure/troubleshooting#troubleshooting-multifactor-authentication-mfa)
>- [Troubleshoot MFA errors in Azure CLI](/cli/azure/use-azure-cli-successfully-troubleshooting#troubleshooting-multifactor-authentication-mfa)
 
The following table lists affected apps and URLs for Microsoft 365.
 
+3 / -3 lines changed
Commit: Apply suggestions from PR review
Changes:
Before
After
GET hhttps://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=msn.com/en-us/sports
```
 
Notes:
- If the URL contains characters that need encoding (for example, spaces or query strings), URL-encode the `@url` value.
- The feature is API-only at the moment; there's no UI in the Microsoft Entra admin center for this feature.
 
## Responses
 
GET hhttps://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=msn.com/en-us/sports
```
 
> [!Notes:]
> - If the URL contains characters that need encoding (for example, spaces or query strings), URL-encode the `@url` value.
-> The feature is API-only at the moment; there's no UI in the Microsoft Entra admin center for this feature.
 
## Responses
 
+3 / -3 lines changed
Commit: fix warnings
Changes:
Before
After
 
* GitHub Enterprise Server supports **SP** and **IDP** initiated SSO.
* GitHub Enterprise Server supports **Just In Time** user provisioning.
* GitHub Enterprise Server supports [Automated user provisioning](./github-server-provisioning-tutorial.md).
 
## Add GitHub Enterprise Server from the gallery
 
 
1. Select **Save**.
 
![Screenshot shows to manage claim for attributes.](./media/github-server-tutorial/administrator.png "Claims")
 
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
 
 
In this section, a user called B.Simon is created in GitHub Enterprise Server. GitHub Enterprise Server supports just-in-time user provisioning, which is enabled by default. There's no action item for you in this section. If a user doesn't already exist in GitHub Enterprise Server, a new one is created after authentication.
 
GitHub Enterprise Server also supports automatic user provisioning, you can find more details [here](./github-server-provisioning-tutorial.md) on how to configure automatic user provisioning.
 
## Test SSO
 
* GitHub Enterprise Server supports **SP** and **IDP** initiated SSO.
* GitHub Enterprise Server supports **Just In Time** user provisioning.
* GitHub Enterprise Server supports [Automated user provisioning](./github-enterprise-server-provisioning-tutorial.md).
 
## Add GitHub Enterprise Server from the gallery
 
 
1. Select **Save**.
 
![Screenshot shows to manage claim for attributes.](./media/github-ae-tutorial/administrator.png "Claims")
 
1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
 
 
In this section, a user called B.Simon is created in GitHub Enterprise Server. GitHub Enterprise Server supports just-in-time user provisioning, which is enabled by default. There's no action item for you in this section. If a user doesn't already exist in GitHub Enterprise Server, a new one is created after authentication.
 
GitHub Enterprise Server also supports automatic user provisioning, you can find more details [here](./github-enterprise-server-provisioning-tutorial.md) on how to configure automatic user provisioning.
 
## Test SSO
+3 / -3 lines changed
Commit: fix validation suggestions
Changes:
Before
After
 
## How to update these attributes
You can update these attributes via Microsoft Graph Beta with [Update User](/graph/api/user-update?view=graph-rest-beta&tabs=http) API call. These attributes can only be updated in Entra ID for native Cloud-Only users or for previously synced users that have been converted to Cloud-Only users after turning off synchronization in Entra ID.
 
 
### Required roles
 
### Prerequisites for managing on-premises attributes with ADSyncTools PowerShell module:
 
- [Windows PowerShell 7](/powershell/scripting/install/installing-powershell-on-windows?view=powershell-7.4)
- [Microsoft Graph SDK PowerShell module](/powershell/microsoftgraph/installation?view=graph-powershell-1.0)
 
In order to use [ADSyncTools](reference-connect-adsynctools.md) you need to install the module from PowerShell Gallery, as follows:
 
 
## How to update these attributes
You can update these attributes via Microsoft Graph Beta with [Update User](/graph/api/user-update) API call. These attributes can only be updated in Entra ID for native Cloud-Only users or for previously synced users that have been converted to Cloud-Only users after turning off synchronization in Entra ID.
 
 
### Required roles
 
### Prerequisites for managing on-premises attributes with ADSyncTools PowerShell module:
 
- [Windows PowerShell 7](/powershell/scripting/install/installing-powershell-on-windows)
- [Microsoft Graph SDK PowerShell module](/powershell/microsoftgraph/installation)
 
In order to use [ADSyncTools](reference-connect-adsynctools.md) you need to install the module from PowerShell Gallery, as follows:
 
+3 / -1 lines changed
Commit: Revert "Threat intel"
Changes:
Before
After
1. Enter a name, select a [web category](reference-web-content-filtering-categories.md) or a valid FQDN, and then select **Add**.
- Valid FQDNs in this feature can also include wildcards using the asterisk symbol, *.
1. Select **Next** to review the policy and then select **Create policy**.
 
## Create a security profile
 
 
The current blocking experience for all browsers includes a plaintext browser error for HTTP traffic and a "Connection Reset" browser error for HTTPS traffic.
 
![Screenshot showing a plaintext browser error for unencrypted or TLS inspected HTTP traffic.](media/how-to-configure-web-content-filtering/http-block-xbox.png)
 
![Screenshot showing a "Connection Reset" browser error for HTTPS traffic.](media/how-to-configure-web-content-filtering/https-block-xbox.png)
 
 
 
1. Enter a name, select a [web category](reference-web-content-filtering-categories.md) or a valid FQDN, and then select **Add**.
- Valid FQDNs in this feature can also include wildcards using the asterisk symbol, *.
1. Select **Next** to review the policy and then select **Create policy**.
> [!IMPORTANT]
> Changes to web content filtering can take up to one hour to deploy.
 
## Create a security profile
 
 
The current blocking experience for all browsers includes a plaintext browser error for HTTP traffic and a "Connection Reset" browser error for HTTPS traffic.
 
![Screenshot showing a plaintext browser error for HTTP traffic.](media/how-to-configure-web-content-filtering/http-block-xbox.png)
 
![Screenshot showing a "Connection Reset" browser error for HTTPS traffic.](media/how-to-configure-web-content-filtering/https-block-xbox.png)
 
+2 / -0 lines changed
Commit: [Conditional Access] Update Office 365 app group
Changes:
Before
After
- Augmentation Loop
- Call Recorder
- Connectors
- DataSecurityInvestigation
- Device Management Service
- EDU Assignments
- OneDrive
- OneDrive SyncEngine
- OneNote
- Outlook Browser Extension
- Outlook Service for Exchange
- PowerApps Service
 
 
- Augmentation Loop
- Call Recorder
- Connectors
- Copilot Data Platform
- DataSecurityInvestigation
- Device Management Service
- EDU Assignments
- OneDrive
- OneDrive SyncEngine
- OneNote
- OneOutlook
- Outlook Browser Extension
- Outlook Service for Exchange
- PowerApps Service
Modified by Julien-ROBERT LECADOU on Sep 4, 2025 6:55 PM
đź“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Fix URL formatting in custom domain documentation
Changes:
Before
After
 
# Configure custom domains with Microsoft Entra application proxy
 
When you publish an application through Microsoft Entra application proxy, you create an external URL for your users. This URL gets the default domain *`yourtenant.msappproxy.net`*. For example, if you publish an app named *Expenses* in your tenant named *Contoso*, the external URL is *`https:\//expenses-contoso.msappproxy.net`*. If you want to use your own domain name instead of *`msappproxy.net`*, you can configure a custom domain for your application.
 
## Benefits of custom domains
 
 
# Configure custom domains with Microsoft Entra application proxy
 
When you publish an application through Microsoft Entra application proxy, you create an external URL for your users. This URL gets the default domain *`yourtenant.msappproxy.net`*. For example, if you publish an app named *Expenses* in your tenant named *Contoso*, the external URL is *`https://expenses-contoso.msappproxy.net`*. If you want to use your own domain name instead of *`msappproxy.net`*, you can configure a custom domain for your application.
 
## Benefits of custom domains
 
+2 / -0 lines changed
Commit: additional updates
Changes:
Before
After
title: Set up self-service group management after Group SOA conversion (Preview)
description: Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
author: Justinha
ms.topic: how-to
ms.date: 08/01/2025
ms.author: justinha
 
 
title: Set up self-service group management after Group SOA conversion (Preview)
description: Configure self-service group management in Microsoft Entra for security groups, mail-enabled security groups, and distribution groups after SOA conversion.
author: Justinha
ms.service: entra-id
ms.subservice: hybrid
ms.topic: how-to
ms.date: 08/01/2025
ms.author: justinha
+2 / -0 lines changed
Commit: fix validation suggestions
Changes:
Before
After
description: Discover how linkable identifiers like session IDs and unique token identifiers in Microsoft Entra help track and investigate identity-related activities, enhancing security and transparency.
ms.topic: how-to
ms.date: 05/27/2025
ms.author: justinha
author: vimrang
manager: dougeby
 
 
description: Discover how linkable identifiers like session IDs and unique token identifiers in Microsoft Entra help track and investigate identity-related activities, enhancing security and transparency.
ms.topic: how-to
ms.date: 05/27/2025
ms.service: entra-id
ms.subservice: hybrid
ms.author: justinha
author: vimrang
manager: dougeby
+2 / -0 lines changed
Commit: fix validation suggestions
Changes:
Before
After
description: Learn how to preserve and use the original organizational unit (OU) for group provisioning in Microsoft Entra ID.
author: Justinha
manager: dougeby
ms.topic: concept-article
ms.date: 08/01/2025
ms.author: justinha
 
 
description: Learn how to preserve and use the original organizational unit (OU) for group provisioning in Microsoft Entra ID.
author: Justinha
manager: dougeby
ms.service: entra-id
ms.subservice: hybrid
ms.topic: concept-article
ms.date: 08/01/2025
ms.author: justinha
+2 / -0 lines changed
Commit: fix validation suggestions
Changes:
Before
After
description: Discover how to manage and transition Active Directory groups to Microsoft Entra ID using Group Source of Authority (SOA). Learn best practices for group management, provisioning, restoring, and rolling back changes in hybrid and cloud environments.
author: justinha
manager: dougeby
ms.topic: conceptual
ms.date: 08/07/2025
ms.author: justinha
 
 
description: Discover how to manage and transition Active Directory groups to Microsoft Entra ID using Group Source of Authority (SOA). Learn best practices for group management, provisioning, restoring, and rolling back changes in hybrid and cloud environments.
author: justinha
manager: dougeby
ms.service: entra-id
ms.subservice: hybrid
ms.topic: conceptual
ms.date: 08/07/2025
ms.author: justinha
+2 / -0 lines changed
Commit: fix validation suggestions
Changes:
Before
After
description: Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID using group source of authority (SOA).
author: justinha
manager: dougeby
ms.topic: conceptual
ms.date: 08/01/2025
ms.author: justinha
 
 
description: Learn how to convert group management from Active Directory Domain Services (AD DS) to Microsoft Entra ID using group source of authority (SOA).
author: justinha
manager: dougeby
ms.service: entra-id
ms.subservice: hybrid
ms.topic: conceptual
ms.date: 08/01/2025
ms.author: justinha
+1 / -1 lines changed
Commit: fix validation suggestions
Changes:
Before
After
| --- |:---:| --- |
| :::no-loc text="domainFQDN"::: | X | Also called dnsDomainName. For example, contoso.com. |
| :::no-loc text="domainNetBios"::: | X | Also called netBiosName. For example, CONTOSO. |
| :::no-loc text="msDS-KeyCredentialLink"::: | X | Once the user is enrolled in Windows Hello for Business. | |
 
## Exchange hybrid writeback
These attributes are written back from Microsoft Entra ID to on-premises Active Directory when you select to enable **Exchange hybrid**. Depending on your Exchange version, fewer attributes might be synchronized.
| --- |:---:| --- |
| :::no-loc text="domainFQDN"::: | X | Also called dnsDomainName. For example, contoso.com. |
| :::no-loc text="domainNetBios"::: | X | Also called netBiosName. For example, CONTOSO. |
| :::no-loc text="msDS-KeyCredentialLink"::: | X | Once the user is enrolled in Windows Hello for Business. |
 
## Exchange hybrid writeback
These attributes are written back from Microsoft Entra ID to on-premises Active Directory when you select to enable **Exchange hybrid**. Depending on your Exchange version, fewer attributes might be synchronized.

🗑️ Deleted Documentation Files

DELETED docs/identity/saas-apps/github-ae-provisioning-tutorial.md
Deleted by omondiatieno on Sep 4, 2025 8:49 AM
đź“– Was available at: https://learn.microsoft.com/en-us/entra/identity/saas-apps/github-ae-provisioning-tutorial
-150 lines removed
Commit: Rename of GitHub AE to GitHub Enteprise Server
DELETED docs/global-secure-access/how-to-configure-threat-intelligence.md
Deleted by fgomulka on Sep 4, 2025 9:25 PM
đź“– Was available at: https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-threat-intelligence
-132 lines removed
Commit: Revert "Threat intel"