đź“‹ Microsoft Entra Documentation Changes

Daily summary for changes since September 4th 2025, 7:59 PM PDT

Report generated on September 5th 2025, 7:59 PM PDT

📊 Summary

45
Total Commits
0
New Files
10
Modified Files
0
Deleted Files
16
Contributors

📝 Modified Documentation Files

Modified by barclayn on Sep 5, 2025 6:22 PM
đź“– View on learn.microsoft.com
+29 / -29 lines changed
Commit: minor edits
Changes:
Before
After
>[!IMPORTANT]
> Currently, Microsoft Entra Kerberos only works with hybrid identities.
 
## Key Features and Benefits
 
**Seamless Hybrid Authentication**: Microsoft Entra Kerberos allows users whose accounts reside in on-premises Active Directory Domain Services (AD DS) and are synchronized to Microsoft Entra ID to authenticate across cloud and on-premises resources. It reduces and in some cases eliminates the need for direct connectivity to domain controllers. For example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.
 
**Enhanced Security with Modern Credentials Support**: Users can sign in using passwordless methods such as Windows Hello for Business or FIDO2 security keys yet still access on-premises resources protected by Kerberos. Enables multifactor and password-less authentication, reducing risks associated with password theft and phishing attacks.
 
**Simplified Hybrid Join** Microsoft Entra Kerberos supports hybrid join scenarios without requiring ADFS or Microsoft Entra Connect sync. This is ideal for non-persistent virtual desktop infrastructure (VDI), disconnected forests, and Azure Virtual Desktop
 
**Secure Ticket Exchange**: Microsoft Entra Kerberos uses a secure Ticket Granting Ticket (TGT) exchange model.
 
**Scalable Group Memberships**: Addresses traditional Kerberos limitations with large or dynamic group memberships, improving reliability and user experience. In scenarios involving large groups of users, performance is optimized through automatic load distribution across all domain controllers (DCs) within a site. For deployments in Azure Virtual Desktop (AVD) environments, we recommend ensuring that sufficient DCs are available and geographically close to the environment to maintain responsiveness.
 
 
## How Microsoft Entra Kerberos Works
 
**Microsoft Entra Kerberos** allows your Microsoft Entra ID tenant to operate as a dedicated Kerberos realm alongside your existing on-premises Active Directory realm. When a user signs in to a Windows device that is either Microsoft Entra ID‑joined or hybrid joined, the device authenticates with Microsoft Entra ID and receives a [Primary Refresh Token](../devices/concept-primary-refresh-token.md).
 
>[!IMPORTANT]
> Currently, Microsoft Entra Kerberos only works with hybrid identities.
 
## Key features and benefits
 
**Seamless Hybrid authentication**: Microsoft Entra Kerberos allows users whose accounts reside in on-premises Active Directory Domain Services (AD DS) and are synchronized to Microsoft Entra ID to authenticate across cloud and on-premises resources. It reduces and in some cases eliminates the need for direct connectivity to domain controllers. For example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.
 
**Enhanced security with modern credentials support**: Users can sign in using passwordless methods such as Windows Hello for Business or FIDO2 security keys yet still access on-premises resources protected by Kerberos. Enables multifactor and password-less authentication, reducing risks associated with password theft and phishing attacks.
 
**Simplified Hybrid join**: Microsoft Entra Kerberos supports hybrid join scenarios without requiring ADFS or Microsoft Entra Connect sync. This is ideal for non-persistent virtual desktop infrastructure (VDI), disconnected forests, and Azure Virtual Desktop.
 
**Secure ticket exchange**: Microsoft Entra Kerberos uses a secure Ticket Granting Ticket (TGT) exchange model.
 
**Scalable group memberships**: Addresses traditional Kerberos limitations with large or dynamic group memberships, improving reliability and user experience. In scenarios involving large groups of users, performance is optimized through automatic load distribution across all domain controllers (DCs) within a site. For deployments in Azure Virtual Desktop (AVD) environments, we recommend ensuring that sufficient DCs are available and geographically close to the environment to maintain responsiveness.
 
 
## How Microsoft Entra Kerberos works
 
**Microsoft Entra Kerberos** allows your Microsoft Entra ID tenant to operate as a dedicated Kerberos realm alongside your existing on-premises Active Directory realm. When a user signs in to a Windows device that is either Microsoft Entra ID‑joined or hybrid joined, the device authenticates with Microsoft Entra ID and receives a [Primary Refresh Token](../devices/concept-primary-refresh-token.md).
 
+29 / -18 lines changed
Commit: investigate-risky-apps-090525
Changes:
Before
After
author: shlipsey3
ms.author: sarahlipsey
manager: pmwongera
ms.date: 12/12/2024
ms.update-cycle: 180-days
ms.topic: how-to
ms.service: entra
- *Are any apps at risk of being malicious or compromised?*
- *List 5 apps with High Risk Level. Format the table as follows: Display Name | ID | Risk State*
- *List the apps with Risk State “Confirmed compromise”.*
- *Show me the details of risky app with ID {ServicePrincipalObjectId} (or App ID {ApplicationId})*
 
>[!IMPORTANT]
>You must use an account that is authorized to administer ID Protection for this skill to return risk information. Your tenant must also be licensed for [Workload Identities Premium](https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-workload-id#office-StandaloneSKU-k3hubfz).
 
### Explore Microsoft Entra service principals
 
He uses the following prompts to get the information he needs:
 
- *Tell me more about these service principals (from previous response)*
author: shlipsey3
ms.author: sarahlipsey
manager: pmwongera
ms.date: 09/05/2025
ms.update-cycle: 180-days
ms.topic: how-to
ms.service: entra
- *Are any apps at risk of being malicious or compromised?*
- *List 5 apps with High Risk Level. Format the table as follows: Display Name | ID | Risk State*
- *List the apps with Risk State “Confirmed compromise”.*
- *Show me the details of risky app with ID {ServicePrincipalObjectId}*
- *Show me the details of risky app with AppID {ApplicationId})*
 
> [!IMPORTANT]
> You must use an account that is authorized to administer ID Protection for this skill to return risk information. Your tenant must also be licensed for [Workload Identities Premium](https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-workload-id#office-StandaloneSKU-k3hubfz).
 
### Explore Microsoft Entra service principals
 
He uses the following prompts to get the information he needs:
 
Modified by yurikatanabe on Sep 5, 2025 3:30 PM
đź“– View on learn.microsoft.com
+4 / -4 lines changed
Commit: Change bullet points to numbered list for clarity
Changes:
Before
After
> [!NOTE]
> User granularity isn't supported with Microsoft accounts, so the **Select <organization> users and groups** capability isn't available. For other organizations, you could choose **Select <organization> users and groups**, and then perform these steps:
>
>- Select **Add external users and groups**.
>- In the **Add external user or group id** pane, type the object ID of the user or group you want to add.
>- In the right dropdown, select whether it is a user or group.
>- If you want to add more, select **Add** and repeat these steps. When you're done entering the users and groups you want to add, select **Submit**.
 
1. Select the **External applications** tab. Under **Access status**, choose whether to allow or block access to external applications:
 
> [!NOTE]
> User granularity isn't supported with Microsoft accounts, so the **Select <organization> users and groups** capability isn't available. For other organizations, you could choose **Select <organization> users and groups**, and then perform these steps:
>
> 1. Select **Add external users and groups**.
> 1. In the **Add external user or group id** pane, type the object ID of the user or group you want to add.
> 1. In the right dropdown, select whether it is a user or group.
> 1. If you want to add more, select **Add** and repeat these steps. When you're done entering the users and groups you want to add, select **Submit**.
 
1. Select the **External applications** tab. Under **Access status**, choose whether to allow or block access to external applications:
 
Modified by Ortagus Winfrey on Sep 5, 2025 3:27 AM
đź“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: lightbox added
Changes:
Before
After
# Access Review Agent
Say goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.
 
:::image type="content" source="media/access-review-agent/access-review-agent-prompt.png" alt-text="Screenshot of the initial prompt in the access review agent chat.":::
 
## Prerequisites
- You must have [Microsoft Entra ID Governance or Microsoft Entra Suite licenses](licensing-fundamentals.md).
- [Security Copilot Contributor](/copilot/security/authentication#assign-security-copilot-access)
1. From the new home page, select **Go to agents** from the agent notification card.
- You can also select **Agents** from the left navigation menu.
:::image type="content" source="media/access-review-agent/start-access-review-agent.png" alt-text="Screenshot of starting the Access Review Agent.":::
1. Select **View details** on the Access Review Agent tile.
1. Select **Start agent** to begin your first run.
:::image type="content" source="media/access-review-agent/access-review-agent-teams.png" alt-text="Screenshot of the Access Review Agent application in Microsoft Teams.":::
1. Once the agent is added, select **Open**.
1. When open, you can select the available prompt to start the chat with the agent
:::image type="content" source="media/access-review-agent/access-review-agent-prompt.png" alt-text="Screenshot of the initial prompt in the access review agent chat.":::
 
## Settings
# Access Review Agent
Say goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.
 
:::image type="content" source="media/access-review-agent/access-review-agent-prompt.png" alt-text="Screenshot of the initial prompt in the access review agent chat." lightbox="media/access-review-agent/access-review-agent-prompt.png":::
 
## Prerequisites
- You must have [Microsoft Entra ID Governance or Microsoft Entra Suite licenses](licensing-fundamentals.md).
- [Security Copilot Contributor](/copilot/security/authentication#assign-security-copilot-access)
1. From the new home page, select **Go to agents** from the agent notification card.
- You can also select **Agents** from the left navigation menu.
:::image type="content" source="media/access-review-agent/start-access-review-agent.png" alt-text="Screenshot of starting the Access Review Agent." lightbox="media/access-review-agent/start-access-review-agent.png":::
1. Select **View details** on the Access Review Agent tile.
1. Select **Start agent** to begin your first run.
:::image type="content" source="media/access-review-agent/access-review-agent-teams.png" alt-text="Screenshot of the Access Review Agent application in Microsoft Teams.":::
1. Once the agent is added, select **Open**.
1. When open, you can select the available prompt to start the chat with the agent
:::image type="content" source="media/access-review-agent/access-review-agent-prompt.png" alt-text="Screenshot of the initial prompt in the access review agent chat." lightbox="media/access-review-agent/access-review-agent-prompt.png":::
 
## Settings
Modified by Ortagus Winfrey on Sep 5, 2025 3:29 AM
đź“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: lightboxes added
Changes:
Before
After
 
To view information about the Access Review Agent, open up the Access Review Agent to get to the overview page. The highlight of the overview page is the Agent summary, which provides a quick summary of agent actions over the course of the last 30 days.
 
:::image type="content" source="media/access-review-agent-logs-metrics/access-review-agent-overview.png" alt-text="Screenshot of the overview screen in the Access Review Agent overview.":::
 
 
The **Agent Summary** shows:
 
From the overview page, you can select the **Activities** tab to view a full list of the activities of the Access Review Agent. A run is generated for each active access review instance the agent analyzes. A run is also generated if the agent hasn't identified any new active access review instances to analyze. Each access review instance is analyzed once and generates a signal run.
 
:::image type="content" source="media/access-review-agent-logs-metrics/access-review-agents-activities.png" alt-text="Screenshot of a list of activities in the Access Review Agent.":::
 
For each activity, you can see:
 
 
The **Summary of agent activity** is a natural language description of the activity illustrated in the **Agent activity map**. These details help you understand the logic behind the agent and you can view the recommendations and justification summaries on the last card in the activity map.
 
:::image type="content" source="media/access-review-agent-logs-metrics/access-agent-review-card-justification.png" alt-text="Screenshot of Access Review Agent justification in activity card.":::
 
 
 
To view information about the Access Review Agent, open up the Access Review Agent to get to the overview page. The highlight of the overview page is the Agent summary, which provides a quick summary of agent actions over the course of the last 30 days.
 
:::image type="content" source="media/access-review-agent-logs-metrics/access-review-agent-overview.png" alt-text="Screenshot of the overview screen in the Access Review Agent overview." lightbox="media/access-review-agent-logs-metrics/access-review-agent-overview.png":::
 
 
The **Agent Summary** shows:
 
From the overview page, you can select the **Activities** tab to view a full list of the activities of the Access Review Agent. A run is generated for each active access review instance the agent analyzes. A run is also generated if the agent hasn't identified any new active access review instances to analyze. Each access review instance is analyzed once and generates a signal run.
 
:::image type="content" source="media/access-review-agent-logs-metrics/access-review-agents-activities.png" alt-text="Screenshot of a list of activities in the Access Review Agent." lightbox="media/access-review-agent-logs-metrics/access-review-agents-activities.png":::
 
For each activity, you can see:
 
 
The **Summary of agent activity** is a natural language description of the activity illustrated in the **Agent activity map**. These details help you understand the logic behind the agent and you can view the recommendations and justification summaries on the last card in the activity map.
 
:::image type="content" source="media/access-review-agent-logs-metrics/access-agent-review-card-justification.png" alt-text="Screenshot of Access Review Agent justification in activity card." lightbox="media/access-review-agent-logs-metrics/access-agent-review-card-justification.png":::
 
 
+2 / -2 lines changed
Commit: fixes
Changes:
Before
After
 
1. [Agent creates a report-only policy with a phased rollout](#agent-creates-a-report-only-policy-with-a-phased-rollout)
1. [Administrator reviews, edits, and accepts the rollout plan](#administrator-reviews-edits-and-accepts-the-rollout-plan)
1. [Agent or Administrator executes the rollout plan](#agent-or-administrator-executes-the-rollout-plan)
 
You can review the groups included in each phase and the number of days between each phase and make changes before and during the phased rollout. At any time during the rollout, you can choose to have the plan executed by the agent or you can manually execute each phase of the plan.
 
- **Automatically roll out phases**: Agent automatically rolls out each phase, based on timing and impact signals.
- **Manually roll out phases**: Administrator manually advances each phase of the rollout.
 
:::image type="content" source="media/agent-optimization-phased-rollout/phased-rollout-execution-mode-button.png" alt-text="Screenshot of the phases that can be edited with the edit groups button highlighted." lightbox="media/agent-optimization-phased-rollout/phased-rollout-execution-mode-button.png":::
 
> [!TIP]
> You can intervene at any time with automatic and manual rollout plans. You can also change execution modes at any time during rollout.
 
1. [Agent creates a report-only policy with a phased rollout](#agent-creates-a-report-only-policy-with-a-phased-rollout)
1. [Administrator reviews, edits, and accepts the rollout plan](#administrator-reviews-edits-and-accepts-the-rollout-plan)
1. [Agent or Administrator executes the approved rollout plan](#agent-or-administrator-executes-the-approved-rollout-plan)
 
You can review the groups included in each phase and the number of days between each phase and make changes before and during the phased rollout. At any time during the rollout, you can choose to have the plan executed by the agent or you can manually execute each phase of the plan.
 
- **Automatically roll out phases**: Agent automatically rolls out each phase, based on timing and impact signals.
- **Manually roll out phases**: Administrator manually advances each phase of the rollout.
 
:::image type="content" source="media/agent-optimization-phased-rollout/phased-rollout-execution-mode-button.png" alt-text="Screenshot of the option to change execution mode." lightbox="media/agent-optimization-phased-rollout/phased-rollout-execution-mode-button.png":::
 
> [!TIP]
> You can intervene at any time with automatic and manual rollout plans. You can also change execution modes at any time during rollout.
Modified by Ortagus Winfrey on Sep 5, 2025 3:08 PM
đź“– View on learn.microsoft.com
+2 / -1 lines changed
Commit: Updates
Changes:
Before
After
 
### Prerequisites
 
- You must have at least the [Microsoft Entra ID P1](licensing.md) license.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
- In order to purchase security compute units, you need to have an Azure subscription. [Create your free Azure account](https://azure.microsoft.com/free).
- [Security Administrator](../identity/role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../identity/role-based-access-control/permissions-reference.md#global-administrator) automatically have the required permissions to configure the Conditional Access optimization agent.
 
 
### Prerequisites
 
- You must have at least the [Microsoft Entra ID P1](licensing.md) license for the Conditional Access optimization agent.
- You must have at least the [Microsoft Entra ID Governance or Microsoft Entra Suite licenses](../id-governance/licensing-fundamentals.md) for the Access Review Agent.
- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
- In order to purchase security compute units, you need to have an Azure subscription. [Create your free Azure account](https://azure.microsoft.com/free).
- [Security Administrator](../identity/role-based-access-control/permissions-reference.md#security-administrator) or [Global Administrator](../identity/role-based-access-control/permissions-reference.md#global-administrator) automatically have the required permissions to configure the Conditional Access optimization agent.
+1 / -1 lines changed
Commit: Formatting
Changes:
Before
After
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
 
1. Browse to **ID Governance** > **Access Reviews** >.
 
1. Select **New access review** to create a new access review.
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
 
1. Browse to **ID Governance** > **Access Reviews**.
 
1. Select **New access review** to create a new access review.
 
+1 / -1 lines changed
Commit: fix png citation
Changes:
Before
After
1. To test allow-listing, create a rule in the Threat Intelligence policy to allow access to the site. Within 2 minutes, you should be able to access it. (You may need to clear your browser cache.)
1. Evaluate the rest of the threat feed against your known threat indicators.
 
![Screenshot showing a plaintext browser error for unencrypted or TLS inspected HTTP traffic.](media/how-to-configure-threat-intelligence/http-block-ti.png)
 
> [!CAUTION]
> Testing with real malicious sites should be performed in a sandbox or test environment to protect your device and enterprise.
1. To test allow-listing, create a rule in the Threat Intelligence policy to allow access to the site. Within 2 minutes, you should be able to access it. (You may need to clear your browser cache.)
1. Evaluate the rest of the threat feed against your known threat indicators.
 
![Screenshot showing a plaintext browser error for unencrypted or TLS inspected HTTP traffic.](media/how-to-configure-threat-intelligence/http-block-threat-intelligence.png)
 
> [!CAUTION]
> Testing with real malicious sites should be performed in a sandbox or test environment to protect your device and enterprise.
+1 / -1 lines changed
Commit: Update docs/identity/conditional-access/agent-optimization.md
Changes:
Before
After
- **Risky users**: The agent suggests a policy to require secure password change for high risk users. Requires Microsoft Entra ID P2 license.
- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.
- **Policy consolidation**: The agent scans your policy and identifies overlapping settings. For example, if you have more than one policy that has the same grant controls, the agent suggests consolidating those policies into one.
- **Deep Analysis**: The agent looks at policies that correspond to key scenarios to identify outlier policies that have more than a recommended number of exceptions (leading to unexpected gaps in coverage) or no exceptions (leading to possible lockout).
 
> [!IMPORTANT]
> The agent doesn't make any changes to existing policies unless an administrator explicitly approves the suggestion.
- **Risky users**: The agent suggests a policy to require secure password change for high risk users. Requires Microsoft Entra ID P2 license.
- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.
- **Policy consolidation**: The agent scans your policy and identifies overlapping settings. For example, if you have more than one policy that has the same grant controls, the agent suggests consolidating those policies into one.
- **Deep analysis**: The agent looks at policies that correspond to key scenarios to identify outlier policies that have more than a recommended number of exceptions (leading to unexpected gaps in coverage) or no exceptions (leading to possible lockout).
 
> [!IMPORTANT]
> The agent doesn't make any changes to existing policies unless an administrator explicitly approves the suggestion.