πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since September 24th 2025, 8:05 PM PDT

Report generated on September 25th 2025, 8:05 PM PDT

πŸ“Š Summary

18
Total Commits
0
New Files
6
Modified Files
0
Deleted Files
9
Contributors

πŸ“ Modified Documentation Files

Modified by Ken Withee on Sep 25, 2025 6:01 PM
πŸ“– View on learn.microsoft.com
+32 / -37 lines changed
Commit: Updates for readability and consistency.
Changes:
Before
After
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 02/21/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
 
# Understand the Microsoft Entra private network connector
 
Connectors are what make Microsoft Entra Private Access and application proxy possible. They're simple, easy to deploy and maintain, and super powerful. This article discusses what connectors are, how they work, and some suggestions for how to optimize your deployment.
 
## What is a private network connector?
 
Connectors are lightweight agents that sit in a private network and facilitate the outbound connection to the Microsoft Entra Private Access and application proxy services. Connectors must be installed on a Windows Server that has access to the backend resources. You can organize connectors into connector groups, with each group handling traffic to specific resources. For more information on application proxy and a diagrammatic representation of application proxy architecture, see [Using Microsoft Entra application proxy to publish on-premises apps for remote users](../identity/app-proxy/overview-what-is-app-proxy.md).
 
 
To learn how to configure the Microsoft Entra private network connector, see [How to configure private network connectors for Microsoft Entra Private Access](how-to-configure-connectors.md).
 
Private network connectors are lightweight agents deployed on-premises that facilitate the outbound connection to the application proxy service in the cloud. The connectors must be installed on a Windows Server that has access to the backend application. Users connect to the application proxy cloud service that routes their traffic to the apps via the connectors.
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 09/25/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
 
# Understand Microsoft Entra private network connector
 
Connectors make Microsoft Entra Private Access and Application Proxy possible. They're simple to deploy and maintain, and powerful. This article explains what connectors are, how they work, and how to optimize your deployment.
 
## What is a private network connector?
 
Private network connectors are lightweight agents you install on a Windows Server inside your network. They create outbound connections to Microsoft Entra Private Access and the application proxy service to reach backend resources. Organize connectors into connector groups that handle traffic for specific resources. For an architecture overview, see [Using Microsoft Entra application proxy to publish on-premises apps for remote users](../identity/app-proxy/overview-what-is-app-proxy.md). To set them up, see [How to configure private network connectors for Microsoft Entra Private Access](how-to-configure-connectors.md). Users connect to the cloud service, which routes traffic to apps through the connectors.
 
Set up and register a connector with the application proxy service:
1. Open outbound ports 80 and 443 and allow access to the required service and Microsoft Entra ID URLs.
1. Sign in to the Microsoft Entra admin center and run the installer on an on-premises Windows Server.
1. Start the connector so it listens to the application proxy service.
+34 / -33 lines changed
Commit: Updates to bring in alignment with content type.
Changes:
Before
After
ms.author: kenwith
manager: dougeby
ms.topic: concept-article
ms.date: 05/01/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
 
# Understand Microsoft Entra private network connector groups
 
Use private network connector groups to assign specific connectors to specific applications. Connector groups give you more control and let you optimize your deployments.
 
Each private network connector is assigned to a connector group. All the connectors that belong to the same connector group act as a separate unit for high-availability and load balancing. All connectors belong to a connector group. If you don't create groups, then all your connectors are in a default group. You create new connector groups and assign connectors in the Microsoft Entra admin center.
 
Connector groups are useful if your applications are hosted in different locations. You create connector groups based on location. Applications use connectors that are physically close to them.
 
> [!TIP]
> If you have a large application proxy deployment, don't assign any applications to the default connector group. That way, new connectors don't receive any live traffic until you assign them to an active connector group. This configuration also enables you to put connectors in an idle mode by moving them back to the default group, so that you can perform maintenance without impacting your users.
 
## Prerequisites
ms.author: kenwith
manager: dougeby
ms.topic: concept-article
ms.date: 09/25/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
 
# Microsoft Entra private network connector groups
 
Use private network connector groups to assign connectors to applications. Connector groups give you more control and help you optimize deployments.
 
Each private network connector is in a connector group. Connectors in the same group act as a unit for high availability and load balancing. If you don't create groups, all connectors are in the default group. Create new groups and assign connectors in the Microsoft Entra admin center.
 
Use connector groups when applications run in different locations. Create groups by location so each application uses nearby connectors.
 
> [!TIP]
> If you have a large Application Proxy deployment, don't assign applications to the default connector group. New connectors don't receive live traffic until you move them to an active group. You can also idle connectors by moving them back to the default group so you can do maintenance without affecting users.
 
## Prerequisites
Modified by Lesia Nalepa on Sep 25, 2025 8:53 PM
πŸ“– View on learn.microsoft.com
+4 / -2 lines changed
Commit: Fixed instructions for editing/removing delegate
Changes:
Before
After
 
1. On the left menu, select the **Approvals** page.
 
1. Select **Edit delegate** on the Approvals page.
 
1. Update the delegate to another user.
 
1. Select **Save**.
 
### To remove the delegate, you'd:
 
1. Sign in to the [My Access portal](https://myaccess.microsoft.com).
 
1. On the left menu, select the **Approvals** page.
 
1. Select **Remove delegate**.
 
1. Select **Save**.
 
 
 
1. On the left menu, select the **Approvals** page.
 
1. Select **Delegate approvals** on the Approvals page.
 
1. Update the delegate to another user.
 
1. Select **Save**.
 
#### To remove the delegate, you'd:
 
1. Sign in to the [My Access portal](https://myaccess.microsoft.com).
 
1. On the left menu, select the **Approvals** page.
 
1. Select **Delegate approvals** on the Approvals page.
 
1. Select **Remove delegate**.
 
1. Select **Save**.
Modified by Ken Withee on Sep 25, 2025 3:37 PM
πŸ“– View on learn.microsoft.com
+3 / -3 lines changed
Commit: Updates to align with topic type.
Changes:
Before
After
ai-usage: ai-assisted
---
 
# Global Secure Access clients
 
The Global Secure Access client allows organizations control over network traffic at the end-user computing device, giving organizations the ability to route specific traffic profiles through Microsoft Entra Internet Access and Microsoft Entra Private Access. Routing traffic in this method allows for more controls like continuous access evaluation (CAE), device compliance, or multifactor authentication to be required for resource access.
 
The Global Secure Access client acquires traffic using a lightweight filter (LWF) driver, while many other Security Service Edge (SSE) solutions integrate as a virtual private network (VPN) connection. This distinction allows the Global Secure Access client to coexist with these other solutions. The Global Secure Access client acquires traffic based on the traffic forwarding profiles you configure.
 
 
## Available clients
ai-usage: ai-assisted
---
 
# Global Secure Access client overview
 
The Global Secure Access client gives organizations control over network traffic at the end-user computing device. With this client, organizations can route specific traffic profiles through Microsoft Entra Internet Access and Microsoft Entra Private Access. Routing traffic in this method allows for more controls like continuous access evaluation (CAE), device compliance, or multifactor authentication to be required for resource access.
 
The Global Secure Access client uses a lightweight filter (LWF) driver to acquire traffic. In contrast, many other Security Service Edge (SSE) solutions integrate as a virtual private network (VPN) connection. This distinction allows the Global Secure Access client to coexist with these other solutions. The Global Secure Access client acquires traffic based on the traffic forwarding profiles you configure.
 
 
## Available clients
+4 / -2 lines changed
Commit: add feedback from code review
Changes:
Before
After
---
# Hardening update to Microsoft Entra Connect Sync
 
In May 2025, we released a new version (2.5.79.0) of Microsoft Entra Connect Sync. This version contains a back-end service change that further hardens our services.Β **All customers are required to upgrade**Β to the minimum versions byΒ **September 30, 2026** to avoid service disruptions.
 
## Expected impacts
 
If you aren’t upgraded to the minimum required version, you might encounter the following impact to the Microsoft Entra Connect Sync service when the service change takes effect:
 
All synchronization services in Microsoft Entra Connect Sync will fail.
 
 
 
---
# Hardening update to Microsoft Entra Connect Sync
 
As part of increasing the security posture of Microsoft Entra Connect, Microsoft deployed a dedicated first-party application to enable the synchronization between Active Directory and Microsoft Entra ID. This new application will manifest as a first party service principal called the "Microsoft Entra AD Synchronization Service" (Application Id: `6bf85cfa-ac8a-4be5-b5de-425a0d0dc016`) and will be visible in the Enterprise Applications experience within the Microsoft Entra admin center. This application is critical for the continued operation of on-premises to Microsoft Entra ID synchronization functionality through Entra Connect.
 
We have since released a new version (2.5.79.0) of Microsoft Entra Connect that contains this service change. All customers are required to upgrade to the minimum versions by September 30, 2026 to avoid service disruptions.
 
## Expected impacts
 
If you aren’t upgraded to the minimum required version (2.5.79.0), you might encounter the following impact to the Microsoft Entra Connect Sync service when the service change takes effect:
 
All synchronization services in Microsoft Entra Connect Sync will fail.
 
Modified by Keith Brewer (MSFT) on Sep 25, 2025 4:12 PM
πŸ“– View on learn.microsoft.com
+2 / -1 lines changed
Commit: Update workload-identities-faqs.md
Changes:
Before
After
## Is the Workload ID Premium plan available on Azure Government clouds?
Yes. For Azure Government cloud customers, contact your account manager to proceed with the trial.
<a name='is-it-possible-to-have-a-mix-of-azure-ad-premium-p1-azure-ad-premium-p2-and-workload-identities-premium-licenses-in-one-tenant'></a>
## Next steps
Learn more about [workload identities](workload-identities-overview.md).
 
## Is the Workload ID Premium plan available on Azure Government clouds?
Yes. For Azure Government cloud customers, contact your account manager.
<a name='is-it-possible-to-have-a-mix-of-azure-ad-premium-p1-azure-ad-premium-p2-and-workload-identities-premium-licenses-in-one-tenant'></a>
## Next steps
Learn more about [workload identities](workload-identities-overview.md).