๐Ÿ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since September 22nd 2025, 8:04 PM PDT

Report generated on September 23rd 2025, 8:04 PM PDT

๐Ÿ“Š Summary

20
Total Commits
0
New Files
14
Modified Files
0
Deleted Files
9
Contributors

๐Ÿ“ Modified Documentation Files

Modified by John Flores on Sep 23, 2025 6:29 PM
๐Ÿ“– View on learn.microsoft.com
+36 / -37 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
---
title: What is Conditional Access in Microsoft Entra ID?
description: Conditional Access is the Zero Trust policy engine at the heart of the new identity-driven control plane.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: overview
ms.date: 07/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
Conditional Access policies at their simplest are if-then statements; **if** a user wants to access a resource, **then** they must complete an action. For example: If a user wants to access an application or service like Microsoft 365, then they must perform multifactor authentication to gain access.
 
Administrators are faced with two primary goals:
 
- Empower users to be productive wherever and whenever
- Protect the organization's assets
 
## Common signals
---
title: "Microsoft Entra Conditional Access: Zero Trust Policy Engine"
description: Explore Microsoft Entra Conditional Access, the Zero Trust policy engine that integrates signals to secure access to resources.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: overview
ms.date: 09/23/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
 
Conditional Access policies at their simplest are if-then statements; **if** a user wants to access a resource, **then** they must complete an action. For example: If a user wants to access an application or service like Microsoft 365, then they must perform multifactor authentication to gain access.
 
Admins are faced with two primary goals:
 
- Empower users to be productive wherever and whenever
- Protect the organization's assets
 
## Common signals
+34 / -32 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
---
title: 'Conditional Access: Target Resources Overview'
description: Learn how to configure Conditional Access policies to target specific resources, actions, and authentication contexts in Microsoft Entra ID.
ms.service: entra-id
ms.subservice: conditional-access
ms.custom:
- has-azure-ad-ps-ref
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/25/2025
- ai-gen-description
ms.topic: how-to
ms.date: 07/25/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: lhuangnorth
---
# Conditional Access: Target resources
 
---
title: Targeting Resources in Conditional Access Policies
description: Learn how to configure Conditional Access policies to target specific resources, actions, and authentication contexts in Microsoft Entra ID.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: concept-article
ms.date: 09/22/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: lhuangnorth
ms.custom:
- has-azure-ad-ps-ref
- ai-gen-docs-bap
- ai-gen-title
- ai-seo-date:07/25/2025
- ai-gen-description
---
+31 / -31 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
---
title: Conditions in Conditional Access policy
description: What are conditions in a Microsoft Entra Conditional Access policy?
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 03/12/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Conditional Access: Conditions
 
Within a Conditional Access policy, an administrator can use one or more signals to enhance their policy decisions.
 
:::image type="content" source="media/concept-conditional-access-conditions/conditional-access-conditions.png" alt-text="Screenshot of available conditions for a Conditional Access policy in the Microsoft Entra admin center." lightbox="media/concept-conditional-access-conditions/conditional-access-conditions.png":::
 
Multiple conditions can be combined to create fine-grained and specific Conditional Access policies.
 
---
title: How to Use Conditions in Conditional Access Policies
description: Explore Conditional Access conditions, including user risk, sign-in risk, and insider risk, to secure your organization's resources with tailored policies.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: concept-article
ms.date: 09/22/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Conditional Access: Conditions
 
In a Conditional Access policy, admins use one or more signals to improve policy decisions.
 
:::image type="content" source="media/concept-conditional-access-conditions/conditional-access-conditions.png" alt-text="Screenshot of available conditions for a Conditional Access policy in the Microsoft Entra admin center." lightbox="media/concept-conditional-access-conditions/conditional-access-conditions.png":::
 
Admins combine multiple conditions to create specific, fine-grained Conditional Access policies.
 
+28 / -26 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
---
title: Network in Conditional Access policy
description: Using network locations as assignments in a Microsoft Entra Conditional Access policy
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 04/28/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
---
# Conditional Access: Network assignment
 
Administrators can create policies that target specific network locations as a signal along with other conditions in their decision making process. They can include or exclude these network locations as part of their policy configuration. These network locations might include public IPv4 or IPv6 network information, countries/regions, unknown areas that don't map to specific countries/regions, or [Global Secure Access' compliant network](../../global-secure-access/how-to-compliant-network.md).
 
:::image type="content" source="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png" alt-text="Diagram that shows the concept of Conditional Access signals and the decision to enforce organizational policy." lightbox="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png":::
 
> [!NOTE]
> Conditional Access policies are enforced after first-factor authentication completes. Conditional Access isn't intended to be an organization's frontline of defense for scenarios like denial-of-service (DoS) attacks, but it can use signals from these events to determine access.
 
---
title: "Conditional Access Policy: Using Network Signals"
description: Discover how to configure Conditional Access policies with network-based signals, including trusted locations, IP ranges, and GPS-based settings.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 09/22/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
---
# Conditional Access: Network assignment
 
Administrators can create policies that target specific network locations as a signal along with other conditions in their decision making process. They can include or exclude these network locations as part of their policy configuration. These network locations might include public IPv4 or IPv6 network information, countries or regions, unknown areas that don't map to specific countries or regions, or [Global Secure Access compliant network](../../global-secure-access/how-to-compliant-network.md).
 
:::image type="content" source="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png" alt-text="Diagram showing Conditional Access signals and the decision to enforce organizational policy." lightbox="media/common-conditional-access-media/conditional-access-signal-decision-enforcement.png":::
 
> [!NOTE]
+25 / -25 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
---
title: Session controls in Conditional Access policy
description: What are session controls in a Microsoft Entra Conditional Access policy
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 08/20/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer:
---
# Conditional Access: Session
 
Within a Conditional Access policy, an administrator can make use of session controls to enable limited experiences within specific cloud applications.
 
![Conditional Access policy with a grant control requiring multifactor authentication](./media/concept-conditional-access-session/conditional-access-session.png)
 
---
title: "Conditional Access: Manage Session Controls Effectively"
description: Learn how session controls in Microsoft Entra Conditional Access policies enable secure, limited experiences for cloud apps based on device compliance.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 09/23/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: joflore
---
# Conditional Access: Session
 
In a Conditional Access policy, an admin can use session controls to enable limited experiences in specific cloud applications.
 
![Screenshot of a Conditional Access policy with a grant control requiring multifactor authentication.](./media/concept-conditional-access-session/conditional-access-session.png)
 
+20 / -18 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
---
title: Configure Users, Groups, and Workload Identities in Conditional Access
description: Configure Conditional Access user assignments in Microsoft Entra ID. Target specific users, groups, directory roles, and workload identities while avoiding administrator lockout with proper exclusions.
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 07/21/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
---
# Conditional Access: Users, groups, and workload identities
 
A Conditional Access policy must include a user, group, or workload identity assignment as one of the signals in the decision process. These identities can be included or excluded from Conditional Access policies. Microsoft Entra ID evaluates all policies and ensures that all requirements are met before granting access.
 
## Include users
 
This list of users typically includes all of the users an organization is targeting in a Conditional Access policy.
 
The following options are available to include when creating a Conditional Access policy.
---
title: "Conditional Access Setup: Users, Groups, and Workload Identities"
description: Learn how to include or exclude users, groups, and workload identities in Conditional Access policies for secure and flexible access management.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: concept-article
ms.date: 09/22/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
---
# Conditional Access: Users, groups, and workload identities
 
A Conditional Access policy includes a user, group, or workload identity assignment as one of the signals in the decision process. These identities can be included or excluded from Conditional Access policies. Microsoft Entra ID evaluates all policies and ensures all requirements are met before granting access.
 
## Include users
 
This list typically includes all users an organization targets in a Conditional Access policy.
+9 / -9 lines changed
Commit: Update Entra Cloud Sync install and verification docs
Changes:
Before
After
title: Include file
description: Include file
 
author: billmath
ms.service: entra-id
ms.topic: include
ms.date: 11/11/2022
ms.author: billmath
ms.custom: include file
---
 
Agent verification occurs in the Azure portal and on the local server that runs the agent.
 
To verify that Microsoft Entra ID registers the agent, follow these steps:
 
1. Sign in to the [Azure portal](https://portal.azure.com).
1. Select **Microsoft Entra ID**.
1. Select **Microsoft Entra Connect**, and then select **Cloud Sync**.
 
:::image type="content" source="media/entra-cloud-sync-how-to-install/new-ux-1.png" alt-text="Screenshot that shows the Get started screen." lightbox="media/entra-cloud-sync-how-to-install/new-ux-1.png":::
title: Include file
description: Include file
 
author: omondiatieno
manager: mwongerapk
ms.service: entra-id
ms.topic: include
ms.date: 09/23/2025
ms.subservice: hybrid-cloud-sync
ms.author: jomondi
---
 
Agent verification occurs in the Azure portal and on the local server that runs the agent.
 
To verify that Microsoft Entra ID registers the agent, follow these steps:
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
1. Select **Entra Connect**, and then select **Cloud Sync**.
 
:::image type="content" source="media/entra-cloud-sync-how-to-install/new-ux-1.png" alt-text="Screenshot that shows the Get started screen." lightbox="media/entra-cloud-sync-how-to-install/new-ux-1.png":::
Modified by Justinha on Sep 23, 2025 3:58 PM
๐Ÿ“– View on learn.microsoft.com
+9 / -7 lines changed
Commit: Update cloud sync sign-in docs and image references
Changes:
Before
After
title: Include file
description: Include file
 
author: billmath
ms.service: entra-id
ms.topic: include
ms.date: 01/23/2022
ms.author: billmath
ms.custom: include file
---
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [hybrid identity administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
 
1. Browse to **Entra ID** > **Entra Connect** > **Cloud sync**.
 
:::image type="content" source="media/cloud-sync-sign-in/sign-in-1.png" alt-text="Screenshot that shows the Microsoft Entra Connect Cloud Sync home page." lightbox="media/cloud-sync-sign-in/sign-in-1.png":::
 
 
title: Include file
description: Include file
 
author: omondiatieno
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 09/23/2025
ms.subservice: hybrid-cloud-sync
ms.author: jomondi
ms.custom: include file, sfi-image-nochange
---
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
 
1. Browse to **Entra ID** > **Entra Connect** > **Cloud sync**.
 
:::image type="content" source="media/cloud-sync-sign-in/cloud-sync-configurations.png" alt-text="Screenshot that shows the Microsoft Entra Connect Cloud Sync home page." lightbox="media/cloud-sync-sign-in/cloud-sync-configurations.png":::
Modified by Jonathan Kapner on Sep 23, 2025 8:48 PM
๐Ÿ“– View on learn.microsoft.com
+3 / -8 lines changed
Commit: Update how-to-netskope-coexistence.md
Changes:
Before
After
1. Create [Real-time Protection policy](https://docs.netskope.com/en/inline-policies/) to allow access to Private Apps.
1. Install the [Netskope Private Access Publisher](https://docs.netskope.com/en/deploy-a-publisher).
 
#### Add Steering Configuration for Internet Access and Private Apps
 
1. Navigate to **Netskope portal** > **Settings** > **Security Cloud Platform** > **Steering Configuration**> **New Configuration**.
1. Add a **Configuration Name** such as `MSFTSSEPrivate`.
1. Choose a **User Group** or **OU** to apply the configuration to.
1. Under **Cloud, Web and Firewall** > **Web Traffic.**
1. **Bypass exception traffic at** > **Client.**
1. Under **Private Apps**, select **Specific Private Apps**.
1. On the next line > **Netskope will** > **Steer.**
1. Under **Borderless SD-WAN Apps** > **None**.
1. Set **Status** to **Disabled** and select **Save**.
1. Select the `MSFTSSEPrivate` configuration > **Exceptions**ย >ย **New Exception**ย >ย **Destination Locations** > Select `MSFT SSE Service` and `MSFT SSE M365` (Instructions for creating this object are listed in the Netskope profiles section).
1. Selectย **Bypass**ย andย **Treat it like local IP address**ย options.
1. Selectย **Exceptions**ย >ย **New Exception**ย >ย **Domains**ย and add these exceptions: `*.globalsecureaccess.microsoft.com`, `*.auth.microsoft.com`, `*.msftidentity.com`, `*.msidentity.com`, `*.onmicrosoft.com`, `*.outlook.com`, `*.protection.outlook.com`, `*.sharepoint.com`, `*.sharepointonline.com`, `*.svc.ms`, `*.wns.windows.com`, `account.activedirectory.windowsazure.com`, `accounts.accesscontrol.windows.net`, `admin.onedrive.com`, `adminwebservice.microsoftonline.com`, `api.passwordreset.microsoftonline.com`, `autologon.microsoftazuread-sso.com`, `becws.microsoftonline.com`, `ccs.login.microsoftonline.com`, `clientconfig.microsoftonline-p.net`, `companymanager.microsoftonline.com`, `device.login.microsoftonline.com`, `g.live.com`, `graph.microsoft.com`, `graph.windows.net`, `login-us.microsoftonline.com`, `login.microsoft.com`, `login.microsoftonline-p.com`, `login.microsoftonline.com`, `login.windows.net`, `logincert.microsoftonline.com`, `loginex.microsoftonline.com`, `nexus.microsoftonline-p.com`, `officeclient.microsoft.com`, `oneclient.sfx.ms`, `outlook.cloud.microsoft`, `outlook.office.com`, `outlook.office365.com`, `passwordreset.microsoftonline.com`, `provisioningapi.microsoftonline.com`, `spoprod-a.akamaihd.net`.
1. Select **Add Steered Item** > Select **Private App** and select the private applications for Netskope to steer > **Add**.
1. Ensure that theย `MSFTSSEPrivate` configuration is at the top of the list of steering configurations in your tenant. Then enable the configuration.
 
1. Create [Real-time Protection policy](https://docs.netskope.com/en/inline-policies/) to allow access to Private Apps.
1. Install the [Netskope Private Access Publisher](https://docs.netskope.com/en/deploy-a-publisher).
 
#### Add Steering Configuration for Private Apps
 
1. Navigate to **Netskope portal** > **Settings** > **Security Cloud Platform** > **Steering Configuration**> **New Configuration**.
1. Add a **Configuration Name** such as `MSFTSSEPrivate`.
1. Choose a **User Group** or **OU** to apply the configuration to.
1. Under **Cloud, Web and Firewall** > **None.**
1. Under **Private Apps**, select **All Private Apps**.
1. On the next line > **Netskope will** > **Steer.**
1. Under **Borderless SD-WAN Apps** > **None**.
1. Set **Status** to **Disabled** and select **Save**.
1. Ensure that theย `MSFTSSEPrivate` configuration is at the top of the list of steering configurations in your tenant. Then enable the configuration.
 
#### Add Netskope Private App Real-time Protection Policy
 
 
 
 
+5 / -5 lines changed
Commit: [Conditional Access] Core docs freshness pass
Changes:
Before
After
 
## Grant access
 
Administrators can choose to enforce one or more controls when granting access. These controls include the following options:
 
- [Require multifactor authentication (Microsoft Entra multifactor authentication)](~/identity/authentication/concept-mfa-howitworks.md)
- [Require authentication strength](#require-authentication-strength)
- [Require app protection policy](./policy-all-users-device-compliance.md)
- [Require password change](#require-password-change)
 
When administrators choose to combine these options, they can use the following methods:
 
- Require all the selected controls (control *and* control)
- Require one of the selected controls (control *or* control)
 
### Require authentication strength
 
Administrators can choose to require [specific authentication strengths](~/identity/authentication/concept-authentication-strengths.md) in their Conditional Access policies. These authentication strengths are defined in the **Microsoft Entra admin center** > **Entra ID** > **Authentication methods** > **Authentication strengths**. Administrators can choose to create their own or use the built-in versions.
 
### Require device to be marked as compliant
 
## Grant access
 
Admins can choose to enforce one or more controls when granting access. These controls include the following options:
 
- [Require multifactor authentication (Microsoft Entra multifactor authentication)](~/identity/authentication/concept-mfa-howitworks.md)
- [Require authentication strength](#require-authentication-strength)
- [Require app protection policy](./policy-all-users-device-compliance.md)
- [Require password change](#require-password-change)
 
When admins choose to combine these options, they can use the following methods:
 
- Require all the selected controls (control *and* control)
- Require one of the selected controls (control *or* control)
 
### Require authentication strength
 
Admins can choose to require [specific authentication strengths](~/identity/authentication/concept-authentication-strengths.md) in their Conditional Access policies. These authentication strengths are defined in the **Microsoft Entra admin center** > **Entra ID** > **Authentication methods** > **Authentication strengths**. Admins can choose to create their own or use the built-in versions.
 
### Require device to be marked as compliant
+4 / -6 lines changed
Commit: Update Entra Cloud Sync configuration steps
Changes:
Before
After
 
## Configure Microsoft Entra Cloud Sync
 
 
Use the following steps to configure and start the provisioning:
 
[!INCLUDE [sign in](~/includes/cloud-sync-sign-in.md)]
3. Select **New configuration**
4. On the configuration screen, enter a **Notification email**, move the selector to **Enable** and select **Save**.
5. The configuration status should now be **Healthy**.
 
For more information on configuring Microsoft Entra Cloud Sync, see [Provision Active Directory to Microsoft Entra ID](/entra/identity/hybrid/cloud-sync/how-to-configure).
 
## Verify users are created and synchronization is occurring
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
2. Browse to **Entra ID** > **Users**.
3. Verify that you see the new users in our tenant
 
 
## Configure Microsoft Entra Cloud Sync
 
Use the following steps to configure and start the provisioning:
 
[!INCLUDE [sign in](~/includes/cloud-sync-sign-in.md)]
3. Select **New configuration** > **AD to Microsoft Entra ID sync**.
4. Choose the domain that you want to sync, and select **Create**.
 
For more information about how to configure Microsoft Entra Cloud Sync, see [Provision Active Directory to Microsoft Entra ID](/entra/identity/hybrid/cloud-sync/how-to-configure).
 
## Verify users are created and synchronization is occurring
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
2. Browse to **Entra ID** > **Users**.
3. Verify that you see the new users in your tenant
 
## Test signing in with one of your users
 
+4 / -4 lines changed
Commit: Change 'App management policies' to 'Application policies'
Changes:
Before
After
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
 
1. Browse to **Entra ID** > **Enterprise apps** > **App management policies**.
 
1. Select **Block password addition**.
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
 
1. Browse to **Entra ID** > **Enterprise apps** > **App management policies**.
 
1. Select **Block custom identifier URIs**.
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
 
1. Browse to **Entra ID** > **Enterprise apps** > **App management policies**.
 
1. Select **Restrict max certificate lifetime**.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
 
1. Browse to **Entra ID** > **Enterprise apps** > **Application policies**.
 
1. Select **Block password addition**.
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
 
1. Browse to **Entra ID** > **Enterprise apps** > **Application policies**.
 
1. Select **Block custom identifier URIs**.
 
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
 
1. Browse to **Entra ID** > **Enterprise apps** > **Application policies**.
 
1. Select **Restrict max certificate lifetime**.
Modified by Justinha on Sep 23, 2025 3:26 PM
๐Ÿ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: Update Entra Cloud Sync install and verification docs
Changes:
Before
After
ms.custom: include file, sfi-image-nochange
---
 
1. In the Azure portal, select **Microsoft Entra ID**.
1. On the left pane, select **Microsoft Entra Connect**, and then select **Cloud Sync**.
 
:::image type="content" source="media/entra-cloud-sync-how-to-install/new-ux-1.png" alt-text="Screenshot that shows the Get started screen." lightbox="media/entra-cloud-sync-how-to-install/new-ux-1.png":::
 
ms.custom: include file, sfi-image-nochange
---
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Hybrid Identity Administrator](~/identity/role-based-access-control/permissions-reference.md#hybrid-identity-administrator).
1. On the left pane, select **Entra Connect**, and then select **Cloud Sync**.
 
:::image type="content" source="media/entra-cloud-sync-how-to-install/new-ux-1.png" alt-text="Screenshot that shows the Get started screen." lightbox="media/entra-cloud-sync-how-to-install/new-ux-1.png":::
 
+1 / -1 lines changed
Commit: TITypoFix
Changes:
Before
After
Since threat intelligence is critical for users' basic security posture, you can alternatively link your threat intelligence policy to the baseline security profile, which applies policy to all users' traffic in your tenant.
 
> [!NOTE]
> You can only configure threat intelligence policy per security profile. Rule priorities within each security control handle exceptions, and security controls follow the ordering, (1) TLS inspection > (2) Web content filtering > (3) Threat intelligence > (4) File type > (6) Data loss prevention > (7) Third-party
 
1. Browse to **Global Secure Access** > **Secure** > **Security profiles**.
2. Select **Create profile**.
Since threat intelligence is critical for users' basic security posture, you can alternatively link your threat intelligence policy to the baseline security profile, which applies policy to all users' traffic in your tenant.
 
> [!NOTE]
> You can only configure threat intelligence policy per security profile. Rule priorities within each security control handle exceptions, and security controls follow the ordering, (1) TLS inspection > (2) Web content filtering > (3) Threat intelligence > (4) File type > (5) Data loss prevention > (6) Third-party
 
1. Browse to **Global Secure Access** > **Secure** > **Security profiles**.
2. Select **Create profile**.