📋 Microsoft Entra Documentation Changes

Daily summary for changes since September 14th 2025, 8:01 PM PDT

Report generated on September 15th 2025, 8:01 PM PDT

📊 Summary

21
Total Commits
0
New Files
6
Modified Files
0
Deleted Files
12
Contributors

📝 Modified Documentation Files

+14 / -13 lines changed
Commit: [Conditional Access] Insights freshness
Changes:
Before
After
---
title: Analyze Conditional Access policy impact
description: Analyze Conditional Access policy impact using report-only mode and other tools.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 03/12/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: kvenkit
ms.custom: sfi-image-nochange
---
# Analyze Conditional Access Policy Impact
 
Conditional Access helps organizations stay secure by applying the right security access controls under the right circumstances. Understanding the impact of these policies can be challenging, especially when deploying new policies. This article explains how to analyze Conditional Access policy impact using report-only mode and other tools.
 
There are several options available to administrators based on report-only mode. Report-only mode is a policy state letting administrators test most Conditional Access policies before enabling them.
 
- Conditional Access policies can be evaluated in report-only mode except for items included in the "User Actions" scope.
---
title: "Conditional Access Policy Insights: Monitoring and Evaluation"
description: Discover how to analyze Conditional Access policy results with tools like Azure Monitor and insights workbooks for better policy management.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 09/15/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: kvenkit
ms.custom: sfi-image-nochange
---
 
# Analyze Conditional Access Policy Impact
 
Conditional Access helps organizations stay secure by applying the appropriate security access controls in the right circumstances. Understanding the impact of these policies is challenging, especially when deploying new policies. This article explains how to analyze the impact of Conditional Access policies using report-only mode and other tools.
 
Administrators have several options based on report-only mode. Report-only mode is a policy state that lets administrators test most Conditional Access policies before enabling them.
 
+12 / -12 lines changed
Commit: revised png and passkey FIDO2
Changes:
Before
After
---
title: Overview of custom authentication strengths and advanced options for FIDO2 security keys and certificate-based authentication in Microsoft Entra ID
description: Learn how admins can create custom authentication strengths with advanced options for FIDO2 security keys and certificate-based authentication.
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 03/04/2025
ms.author: justinha
author: inbarckms
manager: dougeby
To check if an authentication strength is referenced by a Conditional Access policy, click the **Conditional Access policies** column.
 
 
## FIDO2 security key advanced options
You can restrict the usage of FIDO2 security keys based on their Authenticator Attestation GUIDs (AAGUIDs). This capability allows administrators to require a FIDO2 security key from a specific manufacturer in order to access the resource. To require a specific FIDO2 security key, first create a custom authentication strength. Then select **FIDO2 Security Key**, and click **Advanced options**.
 
:::image type="content" border="true" source="./media/concept-authentication-strengths/key.png" alt-text="Screenshot showing Advanced options for FIDO2 security key.":::
 
Next to **Allowed FIDO2 Keys** click **+**, copy the AAGUID value, and click **Save**.
 
---
title: Overview of custom authentication strengths and advanced options for passkey (FIDO2) and certificate-based authentication in Microsoft Entra ID
description: Learn how admins can create custom authentication strengths with advanced options for passkey (FIDO2) security keys and certificate-based authentication.
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 09/15/2025
ms.author: justinha
author: inbarckms
manager: dougeby
To check if an authentication strength is referenced by a Conditional Access policy, click the **Conditional Access policies** column.
 
 
## Passkey (FIDO2) advanced options
You can restrict the usage of passkeys (FIDO2) based on their Authenticator Attestation GUIDs (AAGUIDs). This capability allows administrators to require a FIDO2 security key from a specific manufacturer in order to access the resource. To require a specific FIDO2 security key, first create a custom authentication strength. Then select **Passkeys (FIDO2)**, and click **Advanced options**.
 
:::image type="content" border="true" source="./media/concept-authentication-strengths/key.png" alt-text="Screenshot showing Advanced options for passkey (FIDO2).":::
 
Next to **Add AAGUID**, click **+**, copy the AAGUID value, and click **Save**.
 
Modified by Jackline Omondi on Sep 15, 2025 11:35 AM
📖 View on learn.microsoft.com
+12 / -12 lines changed
Commit: Remove references to manual option
Changes:
Before
After
ms.subservice: enterprise-apps
 
ms.topic: troubleshooting
ms.date: 08/21/2025
ms.author: jomondi
ms.reviewer: alamaral
ms.custom: enterprise-apps
 
## Capture sign-in fields for an app
 
Sign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps manually.
 
### Manually capture sign-in fields for an app
 
To manually capture sign-in fields, you must have the My Apps browser extension installed. Also, your browser can't be running in *inPrivate*, *incognito*, or *private* mode.
 
To configure password-based SSO for an app by using manual sign-in field capture, follow these steps:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Browse to **Entra ID** > **Enterprise apps** > **All applications**.
ms.subservice: enterprise-apps
 
ms.topic: troubleshooting
ms.date: 09/15/2025
ms.author: jomondi
ms.reviewer: alamaral
ms.custom: enterprise-apps
 
## Capture sign-in fields for an app
 
Sign-in field capture is supported only for HTML-enabled sign-in pages. It's not supported for non-standard sign-in pages, like those that use Adobe Flash or other non-HTML-enabled technologies. The following section shows how to capture sign-in fields for your custom apps.
 
### Capture sign-in fields for an app
 
To capture sign-in fields, you must have the My Apps browser extension installed. Also, your browser can't be running in *inPrivate*, *incognito*, or *private* mode.
 
To configure password-based SSO for an app, follow these steps:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Browse to **Entra ID** > **Enterprise apps** > **All applications**.
+11 / -11 lines changed
Commit: Tenant clarification.
Changes:
Before
After
ms.subservice: external
ms.topic: how-to
ms.date: 03/12/2025
ms.author: cmulligan
ms.reviewer: brozbab
ms.custom: it-pro
## Prerequisites
 
- An [external tenant](how-to-create-external-tenant-portal.md).
- A [registered application](/entra/identity-platform/quickstart-register-app) in the tenant.
- A [sign-up and sign-in user flow](how-to-user-flow-sign-up-sign-in-customers.md).
 
## Set up your OpenID Connect identity provider
 
To be able to federate users to your identity provider, you first need to prepare your identity provider to accept federation requests from your Microsoft Entra ID tenant. To do that, you need to populate your redirect URIs and register to your identity provider to be recognized.
 
Before moving to next step, populate your redirect URIs as follows:
 
## Enable sign-in and sign-up with your identity provider
ms.subservice: external
ms.topic: how-to
ms.date: 09/15/2025
ms.author: cmulligan
ms.reviewer: brozbab
ms.custom: it-pro
## Prerequisites
 
- An [external tenant](how-to-create-external-tenant-portal.md).
- A [registered application](/entra/identity-platform/quickstart-register-app) in the external tenant.
- A [sign-up and sign-in user flow](how-to-user-flow-sign-up-sign-in-customers.md).
 
## Set up your OpenID Connect identity provider
 
To be able to federate users to your identity provider, you first need to prepare your identity provider to accept federation requests from your external tenant. To do that, you need to populate your redirect URIs and register to your identity provider to be recognized.
 
Before moving to next step, populate your redirect URIs as follows:
 
## Enable sign-in and sign-up with your identity provider
Modified by Chris Werner on Sep 15, 2025 7:36 PM
📖 View on learn.microsoft.com
+7 / -2 lines changed
Commit: minor tweaks
Changes:
Before
After
 
This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.
 
This feature requires at least the roles of [Security Administrator](/entra/identity/role-based-access-control/permissions-reference#security-administrator), [Global Reader](/entra/identity/role-based-access-control/permissions-reference#global-reader), [Global Secure Access Administrator](/entra/identity/role-based-access-control/permissions-reference#global-secure-access-administrator), or [Global Secure Access Log Reader](/entra/identity/role-based-access-control/permissions-reference#global-secure-access-log-reader).
 
You will also need a [Microsoft Entra ID P1 or P2 license](/entra/id-protection/overview-identity-protection#license-requirements), an Entra Private Access License (for private access traffic), Entra Internet Access License (for general internet traffic outside Microsoft services). Your tenant must also have Global Secure Access configured and Microsoft Security Copilot enabled.
 
- *List all applications with high-risk scores accessed in the last 24 hours.*
- *List all applications that user {user principal name} has accessed in the last 24 hours based on network traffic.*
- *List of the top 10 accessed applications in the last week.*
- *Show all cross-tenant traffic to tenant [tenant-id] in the last day.*
 
## See also
 
 
 
 
 
 
 
This enhancement provides an interactive method for analyzing network traffic logs, allowing users to obtain valuable insights without the need to write complex queries. Users can analyze user, device, and branch network usage, identify network issues, and detect threats or policy violations in real time. As a result, the investigation process is significantly streamlined and more effective.
 
Users assigned the following roles can use this feature:
 
- [Security Administrator](/entra/identity/role-based-access-control/permissions-reference#security-administrator)
- [Global Reader](/entra/identity/role-based-access-control/permissions-reference#global-reader)
- [Global Secure Access Administrator](/entra/identity/role-based-access-control/permissions-reference#global-secure-access-administrator)
- [Global Secure Access Log Reader](/entra/identity/role-based-access-control/permissions-reference#global-secure-access-log-reader).
 
You will also need a [Microsoft Entra ID P1 or P2 license](/entra/id-protection/overview-identity-protection#license-requirements), an Entra Private Access License (for private access traffic), Entra Internet Access License (for general internet traffic outside Microsoft services). Your tenant must also have Global Secure Access configured and Microsoft Security Copilot enabled.
 
- *List all applications with high-risk scores accessed in the last 24 hours.*
- *List all applications that user {user principal name} has accessed in the last 24 hours based on network traffic.*
- *List of the top 10 accessed applications in the last week.*
- *Show all cross-tenant traffic to tenant {Enter_Tenant_ID_Here} in the last day.*
 
## See also
 
Modified by vimrang on Sep 15, 2025 5:31 PM
📖 View on learn.microsoft.com
+5 / -2 lines changed
Commit: Added a known limitation
Changes:
Before
After
 
## Known limitations
 
Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.
 
Tenant restrictions v2 doesn't work with the [macOS Platform SSO](~/identity/devices/troubleshoot-macos-platform-single-sign-on-extension.md) feature with client signaling via corporate proxy. Customers who use tenant restrictions v2 and Platform SSO should use universal tenant restrictions v2 with Global Secure Access client signaling. This is an Apple limitation in which Platform SSO is not compatible with tenant restrictions when an intermediary network solution injects headers. An example of such a solution is a proxy that uses a certificate trust chain outside Apple system root certificates.
 
## Related content
 
 
 
 
 
## Known limitations
 
- Tenant restrictions v2 is supported on all clouds. However, tenant restrictions v2 is not enforced with cross-cloud requests.
 
- Tenant restrictions v2 doesn't work with the [macOS Platform SSO](~/identity/devices/troubleshoot-macos-platform-single-sign-on-extension.md) feature with client signaling via corporate proxy. Customers who use tenant restrictions v2 and Platform SSO should use universal tenant restrictions v2 with Global Secure Access client signaling. This is an Apple limitation in which Platform SSO is not compatible with tenant restrictions when an intermediary network solution injects headers. An example of such a solution is a proxy that uses a certificate trust chain outside Apple system root certificates.
 
- When TRv2 is enabled, accessing the Microsoft Entra admin center may result in an "Access denied" error. To resolve this issue, append the following feature flags to the Microsoft Entra admin center URL: `?feature.msaljs=true&exp.msaljsexp=true`. If you're accessing the admin center for a partner tenant (e.g., Fabrikam) and encounter the error at `https://entra.microsoft.com/`, update the URL as follows: `https://entra.microsoft.com/?feature.msaljs%253Dtrue%2526exp.msaljsexp%253Dtrue#home`. This will enable the necessary flags and restore access.
 
 
## Related content