đź“‹ Microsoft Entra Documentation Changes

Daily summary for changes since September 29th 2025, 8:16 PM PDT

Report generated on September 30th 2025, 8:16 PM PDT

📊 Summary

40
Total Commits
0
New Files
9
Modified Files
0
Deleted Files
17
Contributors

📝 Modified Documentation Files

+5 / -6 lines changed
Commit: service-now-images
Changes:
Before
After
manager: dougeby
ms.reviewer: lhuangnorth
 
ms.date: 08/28/2025
 
ms.update-cycle: 180-days
ms.service: entra-id
 
Organizations that use the [ServiceNow plugin for Security Copilot](/copilot/security/plugin-servicenow) can now have the Conditional Access optimization agent create ServiceNow incidents for each new suggestion the agent generates. This allows IT and security teams to track, review, and approve or reject agent suggestions within existing ServiceNow workflows. At this time, only change requests (CHG) are supported.
 
When the ServiceNow plugin is turned on in the Conditional Access optimization agent settings, each new suggestion from the agent creates a ServiceNow incident. The incident includes details about the suggestion, such as the type of policy, the users or groups affected, and the rationale behind the recommendation. The incident is assigned to a specified group or individual for review and approval.
 
The integration also provides a feedback loop: The agent monitors the state of the ServiceNow incident and can automatically implement the change when the incident is approved.
 
To use the ServiceNow integration:
 
- The organization must have the [ServiceNow plugin](/copilot/security/plugin-servicenow) configured.
- Your tenant ID must be added to the allow list, according to the plugin setup instructions.
 
### Custom instructions
manager: dougeby
ms.reviewer: lhuangnorth
 
ms.date: 09/30/2025
 
ms.update-cycle: 180-days
ms.service: entra-id
 
Organizations that use the [ServiceNow plugin for Security Copilot](/copilot/security/plugin-servicenow) can now have the Conditional Access optimization agent create ServiceNow incidents for each new suggestion the agent generates. This allows IT and security teams to track, review, and approve or reject agent suggestions within existing ServiceNow workflows. At this time, only change requests (CHG) are supported.
 
To use the ServiceNow integration, your organization must have the [ServiceNow plugin](/copilot/security/plugin-servicenow) configured.
 
:::image type="content" source="media/agent-optimization/agent-service-now-integration-setting.png" alt-text="Screenshot of the ServiceNow integration settings." lightbox="media/agent-optimization/agent-service-now-integration-setting.png":::
 
When the ServiceNow plugin is turned on in the Conditional Access optimization agent settings, each new suggestion from the agent creates a ServiceNow incident. The incident includes details about the suggestion, such as the type of policy, the users or groups affected, and the rationale behind the recommendation. The integration also provides a feedback loop: The agent monitors the state of the ServiceNow incident and can automatically implement the change when the incident is approved.
 
:::image type="content" source="media/agent-optimization/agent-service-now-integration-ticket.png" alt-text="Screenshot of the ServiceNow integration within an agent suggestion." lightbox="media/agent-optimization/agent-service-now-integration-ticket.png":::
 
### Custom instructions
 
+4 / -4 lines changed
Commit: tabs Bugfix
Changes:
Before
After
ms.author: henrymbugua
ms.service: identity-platform
ms.topic: tutorial
ms.date: 01/27/2025
ms.custom:
 
#Customer intent: As a developer, I want to authenticate users from a sample Android mobile app so that I can experience how Microsoft Entra External ID
Use these steps to create configuration file:
 
#### [Workforce tenant configuration](#tab/android-workforce)
 
1. In Android Studio's project pane, navigate to **app\src\main\res**.
1. Right-click **res** and choose **New** > **Directory**. Enter `raw` as the new directory name and select **OK**.
You can find these values in the Authentication blade of your app registration as well.
 
 
#### [External tenant configuration](#tab/android-external)
 
 
ms.author: henrymbugua
ms.service: identity-platform
ms.topic: tutorial
ms.date: 09/30/2025
ms.custom:
 
#Customer intent: As a developer, I want to authenticate users from a sample Android mobile app so that I can experience how Microsoft Entra External ID
Use these steps to create configuration file:
 
#### [Workforce tenant configuration](#tab/workforce-workforce)
 
1. In Android Studio's project pane, navigate to **app\src\main\res**.
1. Right-click **res** and choose **New** > **Directory**. Enter `raw` as the new directory name and select **OK**.
You can find these values in the Authentication blade of your app registration as well.
 
 
#### [External tenant configuration](#tab/external-tenant)
 
 
+3 / -4 lines changed
Commit: Fix numbering and formatting in export logs documentation
Changes:
Before
After
1. Download the Azure Arc agent setup script from the Azure portal.
1. Search for **Windows PowerShell ISE** in the search box on the Task bar. Right click on the application, then click **Run as administrator**.
From PowerShell, open the downloaded file labeled `OnboardingScript.ps1`.
1. Run the script. You can bypass the execution policy if needed by running: powershell -ExecutionPolicy Bypass - File "FilePath"
1. Log in on the pop-up window to authenticate using the Azure account credentials. The screen returns a message that reads:
`Authentication complete. You can return to the application. Feel free to close this browser tab.`
 
### Set up Log Analytics workspace
1. Go to the [Azure portal](https://portal.azure.com/).
2. Create a Data Collection Endpoint
3. Create a Log Analytics workspace:
1. In the search bar, type **Log Analytics** and select **Log Analytics workspaces**.
1. Click **Create**.
1. Fill in the necessary details:
- **Name**: Provide a unique name for the Log Analytics workspace.
- **Region**: Choose the region closest to your on-premises machine.
1. Click **Review + create**, then **Create**.
4. Create a table under the new workspace.
1. Select the workspace name you created.
1. Download the Azure Arc agent setup script from the Azure portal.
1. Search for **Windows PowerShell ISE** in the search box on the Task bar. Right click on the application, then click **Run as administrator**.
From PowerShell, open the downloaded file labeled `OnboardingScript.ps1`.
1. Run the script. You can bypass the execution policy if needed by running: powershell -ExecutionPolicy Bypass -File "FilePath"
1. Log in on the pop-up window to authenticate using the Azure account credentials. The screen returns a message that reads:
`Authentication complete. You can return to the application. Feel free to close this browser tab.`
 
### Set up Log Analytics workspace
1. Go to the [Azure portal](https://portal.azure.com/).
2. Create a Log Analytics workspace:
1. In the search bar, type **Log Analytics** and select **Log Analytics workspaces**.
1. Click **Create**.
1. Fill in the necessary details:
- **Name**: Provide a unique name for the Log Analytics workspace.
- **Region**: Choose the region closest to your on-premises machine.
1. Click **Review + create**, then **Create**.
3. Create a table under the new workspace.
1. Select the workspace name you created.
1. Navigate to **Workspace** > ** **Settings** > **Tables**.
+2 / -4 lines changed
Commit: Updates image to remove logos. Minor adjustments.
Changes:
Before
After
ms.author: kenwith
manager: dougeby
ms.topic: concept-article
ms.date: 09/29/2025
ms.service: global-secure-access
ms.reviewer: cagautham
ai-usage: ai-assisted
 
Global Secure Access, built into Microsoft Entra, addresses these challenges by leveraging existing B2B guest identities. This integration provides enhanced security features, including full Conditional Access, Continuous Access Evaluation, and cross-tenant trust, helping organizations manage and secure external user access more effectively.
 
[![Diagram showing an overview of B2B guest access in Global Secure Access.](media/concept-b2b-guest-access/guest-access-overview.png)](media/concept-b2b-guest-access/guest-access-overview.png#lightbox)
 
## Enable B2B guest access for Azure Virtual Desktop and Windows 365
 
You can enable Global Secure Access on Windows 365 and Azure Virtual Desktop instances that support external identities to provide B2B guest access. With this capability, external users—such as guests, partners, and contractors—from other organizations can securely access resources in your tenant (the resource tenant). As a resource tenant administrator, you can configure Private Access, Internet Access, and Microsoft 365 traffic policies for these third-party users, helping ensure secure and controlled access to your organization's resources.
 
## How B2B guest access works in Global Secure Access
 
To enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
 
ms.author: kenwith
manager: dougeby
ms.topic: concept-article
ms.date: 09/30/2025
ms.service: global-secure-access
ms.reviewer: cagautham
ai-usage: ai-assisted
 
Global Secure Access, built into Microsoft Entra, addresses these challenges by leveraging existing B2B guest identities. This integration provides enhanced security features, including full Conditional Access, Continuous Access Evaluation, and cross-tenant trust, helping organizations manage and secure external user access more effectively.
 
## Enable B2B guest access for Azure Virtual Desktop and Windows 365
 
You can enable Global Secure Access on Windows 365 and Azure Virtual Desktop instances that support external identities to provide B2B guest access. With this capability, external users—such as guests, partners, and contractors—from other organizations can securely access resources in your tenant (the resource tenant). As a resource tenant administrator, you can configure Private Access, Internet Access, and Microsoft 365 traffic policies for these third-party users, helping ensure secure and controlled access to your organization's resources.
 
[![Diagram showing an overview of B2B guest access in Global Secure Access.](media/concept-b2b-guest-access/guest-access-overview.png)](media/concept-b2b-guest-access/guest-access-overview.png#lightbox)
 
To enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
 
 
 
Modified by Ed McKillop on Sep 30, 2025 7:36 PM
đź“– View on learn.microsoft.com
+3 / -1 lines changed
Commit: Update howto-export-risk-data.md
Changes:
Before
After
 
Access more queries and visual insights based on AADUserRiskEvents and AADRisky Users logs in the [Impact analysis of risk-based access policies workbook](workbook-risk-based-policy-impact.md).
 
Organizations can reduce security operation center (SOC) workloads and support overhead with risk-based Conditional Access policies.
 
> [!VIDEO abb7d7fe-4155-4ee1-bcce-afa027d22f8d]
 
 
 
 
Access more queries and visual insights based on AADUserRiskEvents and AADRisky Users logs in the [Impact analysis of risk-based access policies workbook](workbook-risk-based-policy-impact.md).
 
### Risk analysis
 
Organizations can reduce security operation center (SOC) workloads and support overhead with risk-based Conditional Access policies. Learn more in the following video, **Mastering risk analysis with Microsoft Entra ID Protection**.
 
> [!VIDEO abb7d7fe-4155-4ee1-bcce-afa027d22f8d]
 
+2 / -2 lines changed
Commit: add preview to webcat checker
Changes:
Before
After
---
title: Check web content filtering categories
description: Use the web category checker to find which web content category a URL belongs to via Microsoft Graph.
author: fgomulka
ms.author: frankgomulka
ai-usage: ai-assisted
---
 
# Check web categories with the web category checker tool
 
The article shows how to use the web category checker tool to determine which content category a given Uniform Resource Locator (URL) belongs to. The tool is currently available only via Microsoft Graph API.
 
---
title: Check web content filtering categories (preview)
description: Use the web category checker to find which web content category a URL belongs to via Microsoft Graph.
author: fgomulka
ms.author: frankgomulka
ai-usage: ai-assisted
---
 
# Check web categories with the web category checker tool (preview)
 
The article shows how to use the web category checker tool to determine which content category a given Uniform Resource Locator (URL) belongs to. The tool is currently available only via Microsoft Graph API.
 
Modified by csmulligan on Sep 30, 2025 10:46 AM
đź“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: Minor updates.
Changes:
Before
After
 
## Deployment overview
 
The external tenant uses [Microsoft Entra monitoring](/entra/identity/monitoring-health/overview-monitoring-health). Unlike Microsoft Entra tenants, an external tenant can't have a subscription associated with it. So, we need to take extra steps to enable the integration between external tenant and Log Analytics, which is where we send the logs.
To enable [Diagnostic settings](/azure/azure-monitor/essentials/diagnostic-settings) in workforce tenant within your external tenant, you use [Azure Lighthouse](/azure/lighthouse/overview) to [delegate a resource](/azure/lighthouse/concepts/architecture), which allows your external tenant (the **Service Provider**) to manage a workforce tenant (the **Customer**) resource.
 
> [!TIP]
> Azure Lighthouse is typically used to manage resources for multiple customers. However, it can also be used to simplify cross-tenant administration [within an enterprise that has multiple Microsoft Entra tenants of its own](/azure/lighthouse/concepts/enterprise). In our case, we're using it to delegate management of a single resource group.
 
## Deployment overview
 
TThe external tenant uses [Microsoft Entra monitoring](/entra/identity/monitoring-health/overview-monitoring-health). Unlike Microsoft Entra tenants, an external tenant can't have a subscription associated with it. So, we need to take extra steps to enable the integration between external tenant and Log Analytics, which is where we send the logs.
To enable [Diagnostic settings](/azure/azure-monitor/essentials/diagnostic-settings) in the workforce tenant, use [Azure Lighthouse](/azure/lighthouse/overview). Azure Lighthouse [delegates the resource](/azure/lighthouse/concepts/architecture), allowing the external tenant (the **Service Provider**) to manage the resource in the workforce tenant (the **Customer**).
 
> [!TIP]
> Azure Lighthouse is typically used to manage resources for multiple customers. However, it can also be used to simplify cross-tenant administration [within an enterprise that has multiple Microsoft Entra tenants of its own](/azure/lighthouse/concepts/enterprise). In our case, we're using it to delegate management of a single resource group.
+3 / -0 lines changed
Commit: Update how-to-source-ip-restoration.md with Conditional Access note
Changes:
Before
After
- [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks) get a consistent view of original user Source IP address for assessing various risk scores.
- Original user Source IP is also made available in [Microsoft Entra sign-in logs](/azure/active-directory/reports-monitoring/concept-all-sign-ins) and in [Microsoft Entra audit logs](/entra/identity/monitoring-health/concept-audit-logs)
 
## Prerequisites
 
* Administrators who interact with **Global Secure Access** features must have both of the following role assignments depending on the tasks they're performing.
 
 
 
- [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks) get a consistent view of original user Source IP address for assessing various risk scores.
- Original user Source IP is also made available in [Microsoft Entra sign-in logs](/azure/active-directory/reports-monitoring/concept-all-sign-ins) and in [Microsoft Entra audit logs](/entra/identity/monitoring-health/concept-audit-logs)
 
> [!NOTE]
> To achieve source IP restoration for non-Microsoft apps, you must also configure Conditional Access policies and ensure traffic flows through a compliant network. To learn more, see [Enable compliant network check with Conditional Access](/entra/global-secure-access/how-to-compliant-network#protect-your-resources-behind-the-compliant-network).
 
## Prerequisites
 
* Administrators who interact with **Global Secure Access** features must have both of the following role assignments depending on the tasks they're performing.
Modified by Diana Richards on Sep 30, 2025 8:58 PM
đź“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: fixing link
Changes:
Before
After
 
- [Microsoft Entra Domain Services](/entra/identity/domain-services/overview)
- [Security Assertion Markup Language (SAML) token claims](~/identity-platform/saml-claims-customization.md)
- [JSON Web Token claims](https://learn.microsoft.com/en-us/entra/identity-platform/security-tokens)
 
## Features of custom security attributes
 
 
- [Microsoft Entra Domain Services](/entra/identity/domain-services/overview)
- [Security Assertion Markup Language (SAML) token claims](~/identity-platform/saml-claims-customization.md)
- [JSON Web Token claims](/entra/identity-platform/security-tokens)
 
## Features of custom security attributes