📋 Microsoft Entra Documentation Changes

Daily summary for changes since September 23rd 2025, 8:07 PM PDT

Report generated on September 24th 2025, 8:07 PM PDT

📊 Summary

22
Total Commits
0
New Files
5
Modified Files
0
Deleted Files
9
Contributors

📝 Modified Documentation Files

+4 / -7 lines changed
Commit: [Conditional Access] Log Analytics Permissions clarification
Changes:
Before
After
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 04/14/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
 
To enable the insights and reporting workbook, your tenant must have:
 
- A Log Analytics workspace to retain sign-in logs data.
- Microsoft Entra ID P1 licenses to use Conditional Access.
 
Users must have at least the Security Reader role assigned and Log Analytics workspace Contributor roles assigned.
 
### Stream sign-in logs from Microsoft Entra ID to Azure Monitor logs
 
If you haven't integrated Microsoft Entra logs with Azure Monitor logs, you need to take the following steps before the workbook loads:
 
1. [Create a Log Analytics workspace in Azure Monitor](/azure/azure-monitor/logs/quick-create-workspace).
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: article
ms.date: 09/24/2025
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
 
To enable the insights and reporting workbook, your tenant must have:
 
- A Log Analytics workspace to retain sign-in logs data and access to that workspace.
- Microsoft Entra ID P1 licenses to use Conditional Access.
 
Users must have at least the Security Reader role assigned and Log Analytics workspace Contributor roles assigned.
 
### Stream sign-in logs from Microsoft Entra ID to Azure Monitor logs
 
If you haven't integrated Microsoft Entra logs with Azure Monitor logs, you must [Integrate Microsoft Entra logs with Azure Monitor logs](../monitoring-health/howto-integrate-activity-logs-with-azure-monitor-logs.yml).
 
## How it works
+2 / -2 lines changed
Commit: pm-update
Changes:
Before
After
> [!WARNING]
> Policies in report-only mode that require a compliant device might prompt users on macOS, iOS, and Android devices to select a device certificate during policy evaluation, even though device compliance isn't enforced. These prompts might repeat until the device is compliant. To prevent end users from receiving prompts during sign-in, exclude device platforms Mac, iOS, and Android from report-only policies that perform device compliance checks.
 
## Review policy reports (Preview)
 
The Conditional Access optimization agent also detects spikes and dips in activity related to existing policies. These anomalies often indicate a misconfiguration of a policy that needs to be investigated. If the agent identifies a significant change in activity, a report appears in the list of suggestions. The reports apply to both active and report-only policies. In the **Actions taken by agent** column, you'll see **Suggested policy review** as the value.
 
> [!IMPORTANT]
> The policy reports in the Conditional Access Optimization agent are currently in PREVIEW.
> [!WARNING]
> Policies in report-only mode that require a compliant device might prompt users on macOS, iOS, and Android devices to select a device certificate during policy evaluation, even though device compliance isn't enforced. These prompts might repeat until the device is compliant. To prevent end users from receiving prompts during sign-in, exclude device platforms Mac, iOS, and Android from report-only policies that perform device compliance checks.
 
## Review policy reports
 
The Conditional Access optimization agent also detects spikes and dips in activity related to existing policies. These anomalies often indicate a misconfiguration of a policy that needs to be investigated. If the agent identifies a significant change in activity, a report appears in the list of suggestions. The reports apply to both active and report-only policies that the agent suggests turning on. In the **Actions taken by agent** column, you'll see **Suggested policy review** as the value.
 
> [!IMPORTANT]
> The policy reports in the Conditional Access Optimization agent are currently in PREVIEW.
+2 / -2 lines changed
Commit: Update FIDO2 compatibility doc for Android support
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 06/09/2025
 
author: justinha
ms.author: justinha
### Android
- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
- BLE security keys aren't supported on Android by Google.
- Security key registration with Microsoft Entra ID isn't yet supported on Android.
- Sign-in with passkey isn't supported in Firefox on Android.
 
## Known issues
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 09/24/2025
 
author: justinha
ms.author: justinha
### Android
- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
- BLE security keys aren't supported on Android by Google.
- NFC security keys aren't supported on Android in web browser or native app scenarios.
- Sign-in with passkey isn't supported in Firefox on Android.
 
## Known issues
+1 / -2 lines changed
Commit: Clarify firewall settings for outbound connections
Changes:
Before
After
- The client machine is at least Windows 10 and is Microsoft Entra joined or hybrid joined device. The client machine must also have line of sight to the private resources and DC (user is in a corporate network and accessing on-premises resources). User identity used for joining the device and accessing these resources was created in Active Directory (AD) and synced to Microsoft Entra ID using Microsoft Entra Connect.
- The latest Microsoft Entra Private network connector is installed and has a line of sight to the DC.
- Open inbound Transmission Control Protocol (TCP) port `1337` in the Windows Firewall on the DCs.
- Ensure your firewall permits outbound traffic to TCP port `443`.
- Allow outbound connections to the wildcard domain suffix `*.msappproxy.net:443`.
- Identify the Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.
> [!NOTE]
> The SPNs are *case insensitive* and should be an *exact match* or a wildcard in the format `<serviceclass>/*` such as `cifs/*`.
- The client machine is at least Windows 10 and is Microsoft Entra joined or hybrid joined device. The client machine must also have line of sight to the private resources and DC (user is in a corporate network and accessing on-premises resources). User identity used for joining the device and accessing these resources was created in Active Directory (AD) and synced to Microsoft Entra ID using Microsoft Entra Connect.
- The latest Microsoft Entra Private network connector is installed and has a line of sight to the DC.
- Open inbound Transmission Control Protocol (TCP) port `1337` in the Windows Firewall on the DCs.
- Ensure your firewall or proxy allows outbound connections to the wildcard domain suffix `*.msappproxy.net:443`. Private Access Sensor uses this secure channel to register and fetch policies from Microsoft's Entra cloud service.
- Identify the Service Principal Names (SPNs) of the private apps you want to protect. You add these SPNs in the policy for Private Access Sensors that are installed on the DCs.
> [!NOTE]
> The SPNs are *case insensitive* and should be an *exact match* or a wildcard in the format `<serviceclass>/*` such as `cifs/*`.
 
Modified by Regan Downer on Sep 24, 2025 3:54 PM
📖 View on learn.microsoft.com
+2 / -1 lines changed
Commit: Update SSPR policy details and exceptions
Changes:
Before
After
 
* Microsoft Entra Connect synchronizes identities from your on-premises directory
 
You can disable the use of SSPR for administrator accounts by setting the value of the `AllowedToUseSspr` property on the tenant authorization policy to `false`. Policy changes to enable or disable SSPR for administrator accounts can take up to 60 minutes to take effect. To
 
# [PowerShell](#tab/ms-powershell)
 
"allowedToUseSSPR":false
}
```
 
### Exceptions
 
 
 
* Microsoft Entra Connect synchronizes identities from your on-premises directory
 
You can disable the use of SSPR for administrator accounts by setting the value of the `AllowedToUseSspr` property on the tenant authorization policy to `false`. Policy changes to enable or disable SSPR for administrator accounts can take up to 60 minutes to take effect.
 
# [PowerShell](#tab/ms-powershell)
 
"allowedToUseSSPR":false
}
```
---
 
### Exceptions