📋 Microsoft Entra Documentation Changes

Daily summary for changes since September 30th 2025, 8:03 PM PDT

Report generated on October 1st 2025, 8:03 PM PDT

📊 Summary

41
Total Commits
68
New Files
14
Modified Files
68
Deleted Files
14
Contributors

🆕 New Documentation Files

+398 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
+273 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
+228 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
Added by Huaping Yu on Oct 1, 2025 7:30 PM
📖 View on learn.microsoft.com
+211 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
Added by Huaping Yu on Oct 1, 2025 7:30 PM
📖 View on learn.microsoft.com
+203 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
+196 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
+165 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
+160 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
Added by Huaping Yu on Oct 1, 2025 7:30 PM
📖 View on learn.microsoft.com
+149 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"
+149 lines added
Commit: Revert "[DocsArchive-1.0.25146.1](2025-07-01-22-37-46)Auto archive content"

📝 Modified Documentation Files

+16 / -1 lines changed
Commit: Add Teams Reader description to include
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 07/09/2025
ms.custom: include file
---
 
<!-- autogenerated content starts here -->
 
> [!div class="mx-tableFixed"]
 
 
 
 
 
 
 
 
 
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 10/02/2025
ms.custom: include file
---
 
Assign the Teams Reader role to users who need to do the following tasks:
 
- Read settings and administrative information in the Teams admin center, but not perform any management actions
- Read the Microsoft Call Quality Dashboard (CQD), but not access any troubleshooting capabilities
 
Users with this role **cannot** do the following tasks:
 
- Cannot view Teams management
- Cannot access Meetings & Calls details of users
- Cannot access Notifications & Rules management
- Cannot access Frontline worker deployment management
- Cannot access the advanced collaboration insights dashboard
 
+10 / -6 lines changed
Commit: [Conditional Access] Device Compliance policy freshness
Changes:
Before
After
---
# Require device compliance with Conditional Access
 
Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies are a great way to ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.
 
Some organizations might not be ready to require device compliance for all users. These organizations might instead choose to deploy the following policies:
 
- [Require compliant or Microsoft Entra hybrid joined device for their administrators](policy-alt-admin-device-compliand-hybrid.md)
- [Require a compliant device, Microsoft Entra hybrid joined device, **OR** multifactor authentication for all users](policy-alt-all-users-compliant-hybrid-or-mfa.md)
- [Block unknown or unsupported device platforms](policy-all-users-device-unknown-unsupported.md)
- [Disable browser persistence](policy-all-users-persistent-browser.md)
 
On iOS, Android, macOS, and some non-Microsoft web browsers, Microsoft Entra ID identifies the device using a client certificate that is provisioned when the device is registered with Microsoft Entra ID. When a user first signs in through the browser the user is prompted to select the certificate. The end user must select this certificate before they can continue to use the browser.
 
#### Subscription activation
 
Organizations that use the [Subscription Activation](/windows/deployment/windows-10-subscription-activation) feature to enable users to "step-up" from one version of Windows to another, might want to exclude the Windows Store for Business, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f from their device compliance policy.
 
## Related content
 
---
# Require device compliance with Conditional Access
 
Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.
 
Some organizations might not be ready to require device compliance for all users. These organizations might instead choose to deploy the following policies:
 
- [Require a compliant or Microsoft Entra hybrid joined device for administrators](policy-alt-admin-device-compliand-hybrid.md)
- [Require a compliant device, Microsoft Entra hybrid joined device, **OR** multifactor authentication for all users](policy-alt-all-users-compliant-hybrid-or-mfa.md)
- [Block unknown or unsupported device platforms](policy-all-users-device-unknown-unsupported.md)
- [Disable browser persistence](policy-all-users-persistent-browser.md)
 
On iOS, Android, macOS, and some non-Microsoft web browsers, Microsoft Entra ID identifies the device using a client certificate that is provisioned when the device is registered with Microsoft Entra ID. When a user first signs in through the browser the user is prompted to select the certificate. The end user must select this certificate before they can continue to use the browser.
 
### B2B scenarios
 
For organizations you have a relationship with and trust, you might trust their device compliance claims. To configure this setting, see the article [Manage cross-tenant access settings for B2B collaboration](../../external-id/cross-tenant-access-settings-b2b-collaboration.yml#to-change-inbound-trust-settings-for-mfa-and-device-claims).
 
### Subscription activation
 
+0 / -13 lines changed
Commit: Add Teams Reader description to include
Changes:
Before
After
 
[!INCLUDE [teams-reader](includes/teams-reader.md)]
 
## Teams Reader
 
Assign the Teams Reader role to users who need to do the following tasks:
 
- Read settings and administrative information in the Teams admin center, but not perform any management actions
- Read the Microsoft Call Quality Dashboard (CQD), but not access any troubleshooting capabilities
 
> [!div class="mx-tableFixed"]
> | Actions | Description |
> | --- | --- |
> | microsoft.office365.webPortal/allEntities/standard/read | Read basic properties on all resources in the Microsoft 365 admin center |
> | microsoft.teams/allEntities/allProperties/read | Read all properties of Microsoft Teams |
 
## Teams Telephony Administrator
 
[!INCLUDE [teams-telephony-administrator](includes/teams-telephony-administrator.md)]
 
[!INCLUDE [teams-reader](includes/teams-reader.md)]
 
## Teams Telephony Administrator
 
[!INCLUDE [teams-telephony-administrator](includes/teams-telephony-administrator.md)]
 
 
 
 
 
 
 
 
 
 
 
 
 
+6 / -6 lines changed
Commit: Tweak bullets based on feedback
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 09/25/2025
ms.custom: include file
---
 
Assign the Dragon Administrator role to users who need to do the following tasks:
 
- Manage all aspects of the administrative experience in the Dragon admin center
- Provision products
- Create an organizational hierarchy
- Oversee healthcare groups
- Manage experiences in the embedded versions of the Dragon Copilot application within electronic health records (EHRs)
- Configure the Dragon Copilot application, such as manage settings, view analytics, and handle library objects
- Create, manage, and view support tickets for their organization in the Dragon admin center
- Create, view, manage, and monitor billing plans for licenses purchased by their organization through the Dragon admin center (additional roles may be required)
 
[Learn more](/industry/healthcare/dragon-admin-center/get-started/)
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: include
ms.date: 10/02/2025
ms.custom: include file
---
 
Assign the Dragon Administrator role to users who need to do the following tasks:
 
- Manage all aspects of the administrative experience in the Dragon admin center
- Provision clinical applications
- Create and manage the organization hierarchy
- Oversee healthcare groups
- Manage experiences of various clinical applications embedded in Electronic Health Record (EHR) systems
- Configure clinical applications, such as manage settings, view analytics, and handle library objects
- Create, manage, and view support tickets for their organization in the Dragon admin center
- Create, view, manage, and monitor billing plans for licenses purchased by their organization (additional roles may be required)
 
[Learn more](/industry/healthcare/dragon-admin-center/get-started/)
 
+5 / -5 lines changed
Commit: [Conditional Access] Risk policy cross linking
Changes:
Before
After
---
title: Sign-in risk-based multifactor authentication
description: Create Conditional Access policies using Microsoft Entra ID Protection sign-in risk.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 04/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Require multifactor authentication for elevated sign-in risk
 
Most users have a normal behavior that can be tracked, when they fall outside of this norm it could be risky to allow them to just sign in. You might want to block that user or maybe ask them to perform multifactor authentication to prove that they're really who they say they are.
 
A sign-in risk represents the probability that a given authentication request isn't the identity owner. Organizations with Microsoft Entra ID P2 licenses can create Conditional Access policies incorporating [Microsoft Entra ID Protection sign-in risk detections](~/id-protection/concept-identity-protection-risks.md).
 
The Sign-in risk-based policy protects users from registering MFA in risky sessions. If users aren't registered for MFA, their risky sign-ins are blocked, and they see an AADSTS53004 error.
 
---
title: Sign-in risk-based multifactor authentication
description: Protect your organization by implementing Conditional Access policies that address sign-in risks using Microsoft Entra ID Protection.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 10/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Require multifactor authentication for elevated sign-in risk
 
Most users have normal behavior that can be tracked. When their behavior falls outside this norm, it might be risky to let them sign in. You might want to block the user or ask them to complete multifactor authentication to confirm their identity.
 
Sign-in risk represents the likelihood that an authentication request isn't from the identity owner. Organizations with Microsoft Entra ID P2 licenses can create Conditional Access policies incorporating [Microsoft Entra ID Protection sign-in risk detections](~/id-protection/concept-identity-protection-risks.md).
 
The sign-in risk-based policy prevents users from registering MFA during risky sessions. If users aren't registered for MFA, their risky sign-ins are blocked, and they receive an AADSTS53004 error.
 
+6 / -4 lines changed
Commit: [Conditional Access] Risk policy cross linking
Changes:
Before
After
---
title: User risk-based password change
description: Create Conditional Access policies using Microsoft Entra ID Protection user risk.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 04/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Require a secure password change for elevated user risk
 
Microsoft works with researchers, law enforcement, various security teams at Microsoft, and other trusted sources to find leaked username and password pairs. Organizations with Microsoft Entra ID P2 licenses can create Conditional Access policies incorporating [Microsoft Entra ID Protection user risk detections](~/id-protection/concept-identity-protection-risks.md).
 
## User exclusions
[!INCLUDE [active-directory-policy-exclusions](~/includes/entra-policy-exclude-user.md)]
 
 
---
title: Enforce Password Changes for Elevated User Risk
description: Learn how to create Conditional Access policies using Microsoft Entra ID Protection to enforce secure password changes for users with elevated risk.
 
ms.service: entra-id
ms.subservice: conditional-access
ms.topic: how-to
ms.date: 10/01/2025
 
ms.author: joflore
author: MicrosoftGuyJFlo
---
# Require a secure password change for elevated user risk
 
Microsoft works with researchers, law enforcement, security teams at Microsoft, and other trusted sources to find leaked username and password pairs. Organizations with Microsoft Entra ID P2 licenses can create Conditional Access policies that incorporate [Microsoft Entra ID Protection user risk detections](~/id-protection/concept-identity-protection-risks.md).
 
Use this policy with [Microsoft Entra Password Protection](../authentication/concept-password-ban-bad.md) to block known weak passwords, their variants, and specific terms in your organization. Using Microsoft Entra Password Protection ensures that changed passwords are stronger.
 
## User exclusions
[!INCLUDE [active-directory-policy-exclusions](~/includes/entra-policy-exclude-user.md)]
Modified by csmulligan on Oct 1, 2025 1:35 PM
📖 View on learn.microsoft.com
+4 / -4 lines changed
Commit: Minor updates.
Changes:
Before
After
 
During this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.
 
In summary, you'll use Azure Lighthouse to allow a user or group in your external tenant to manage a resource group in a subscription associated with a different tenant (the workforce tenant). After this authorization is completed, the subscription and log analytics workspace can be selected as a target in the Diagnostic settings in external tenant.
 
## Prerequisites
 
 
1. Give your setting a name if it doesn't already have one.
1. Select **AuditLogs** and **SignInLogs**.
1. Select **Send to Log Analytics Workspace**, and then:
1. Under **Subscription**, select your subscription.
2. Under **Log Analytics Workspace**, select the name of the workspace you created earlier such as _ExtIDLogAnalytics_.
 
1. Select **Save**.
 
 
## Step 5: Workforce tenant configuration – visualize your data
 
Now you can configure your Log Analytics workspace to visualize your data and set up alerts. You can make these configurations in both your workspace and external tenant.
 
During this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.
 
In summary, you'll use Azure Lighthouse to allow a user or group in your external tenant to manage a resource group in a subscription associated with a different tenant (the workforce tenant). After this authorization is completed, the subscription and Log Analytics workspace can be selected as a target in the Diagnostic settings in external tenant.
 
## Prerequisites
 
 
1. Give your setting a name if it doesn't already have one.
1. Select **AuditLogs** and **SignInLogs**.
1. Select **Send to Log Analytics workspace**, and then:
1. Under **Subscription**, select your subscription.
2. Under **Log Analytics workspace**, select the name of the workspace you created earlier such as _ExtIDLogAnalytics_.
 
1. Select **Save**.
 
 
## Step 5: Workforce tenant configuration – visualize your data
 
Now you can configure your Log Analytics workspace to visualize your data and set up alerts. You can make these configurations in both your workforce and external tenant.
Modified by Csilla Mulligan on Oct 1, 2025 1:22 PM
📖 View on learn.microsoft.com
+0 / -7 lines changed
Commit: Update whats-new-docs.md
Changes:
Before
After
- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available
- [Supported features in workforce and external tenants](customers/concept-supported-features-customers.md) - Added enterprise applications update
 
## June 2025
 
### Updated articles
 
- [Supported features in workforce and external tenants](customers/concept-supported-features-customers.md) - Added activity logs and reports
- [Microsoft Entra External ID training, live demo, and videos](customers/reference-training-videos.md) - Added video on configuring OpenID Connect identity providers
 
# [External ID in workforce tenants](#tab/workforce-tenants)
 
## September 2025
- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available
- [Supported features in workforce and external tenants](customers/concept-supported-features-customers.md) - Added enterprise applications update
 
# [External ID in workforce tenants](#tab/workforce-tenants)
 
## September 2025
 
 
 
 
 
 
 
+3 / -3 lines changed
Commit: ca-agent-fix-100125
Changes:
Before
After
manager: dougeby
ms.reviewer: lhuangnorth
 
ms.date: 09/30/2025
 
ms.update-cycle: 180-days
ms.service: entra-id
 
### ServiceNow integration
 
Organizations that use the [ServiceNow plugin for Security Copilot](/copilot/security/plugin-servicenow) can now have the Conditional Access optimization agent create ServiceNow incidents for each new suggestion the agent generates. This allows IT and security teams to track, review, and approve or reject agent suggestions within existing ServiceNow workflows. At this time, only change requests (CHG) are supported.
 
To use the ServiceNow integration, your organization must have the [ServiceNow plugin](/copilot/security/plugin-servicenow) configured.
 
:::image type="content" source="media/agent-optimization/agent-service-now-integration-setting.png" alt-text="Screenshot of the ServiceNow integration settings." lightbox="media/agent-optimization/agent-service-now-integration-setting.png":::
 
When the ServiceNow plugin is turned on in the Conditional Access optimization agent settings, each new suggestion from the agent creates a ServiceNow incident. The incident includes details about the suggestion, such as the type of policy, the users or groups affected, and the rationale behind the recommendation. The integration also provides a feedback loop: The agent monitors the state of the ServiceNow incident and can automatically implement the change when the incident is approved.
 
:::image type="content" source="media/agent-optimization/agent-service-now-integration-ticket.png" alt-text="Screenshot of the ServiceNow integration within an agent suggestion." lightbox="media/agent-optimization/agent-service-now-integration-ticket.png":::
 
manager: dougeby
ms.reviewer: lhuangnorth
 
ms.date: 10/01/2025
 
ms.update-cycle: 180-days
ms.service: entra-id
 
### ServiceNow integration
 
Organizations that use the [ServiceNow plugin for Security Copilot](/copilot/security/plugin-servicenow) can now have the Conditional Access optimization agent create ServiceNow change requests for each new suggestion the agent generates. This allows IT and security teams to track, review, and approve or reject agent suggestions within existing ServiceNow workflows. At this time, only change requests (CHG) are supported.
 
To use the ServiceNow integration, your organization must have the [ServiceNow plugin](/copilot/security/plugin-servicenow) configured.
 
:::image type="content" source="media/agent-optimization/agent-service-now-integration-setting.png" alt-text="Screenshot of the ServiceNow integration settings." lightbox="media/agent-optimization/agent-service-now-integration-setting.png":::
 
When the ServiceNow plugin is turned on in the Conditional Access optimization agent settings, each new suggestion from the agent creates a ServiceNow change request. The change request includes details about the suggestion, such as the type of policy, the users or groups affected, and the rationale behind the recommendation. The integration also provides a feedback loop: The agent monitors the state of the ServiceNow change request and can automatically implement the change when the change request is approved.
 
:::image type="content" source="media/agent-optimization/agent-service-now-integration-ticket.png" alt-text="Screenshot of the ServiceNow integration within an agent suggestion." lightbox="media/agent-optimization/agent-service-now-integration-ticket.png":::
 
+2 / -2 lines changed
Commit: Tweak bullets based on feedback
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: whats-new
ms.date: 09/25/2025
ms.author: rolyon
 
---
 
| Date | Area | Description |
| --- | --- | --- |
| Sept 2025 | Roles | Added [Dragon Administrator](permissions-reference.md#dragon-administrator) role. |
| June 2025 | Roles | Added [Organizational Data Source Administrator](permissions-reference.md#organizational-data-source-administrator) role. |
| June 2025 | Administrative units | General availability of restricted management administrative units. See [Restricted management administrative units in Microsoft Entra ID](admin-units-restricted-management.md). |
| May 2025 | Roles | Updated permissions for multiple roles. See [Microsoft Entra built-in roles](permissions-reference.md). |
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: whats-new
ms.date: 10/02/2025
ms.author: rolyon
 
---
 
| Date | Area | Description |
| --- | --- | --- |
| Oct 2025 | Roles | Added [Dragon Administrator](permissions-reference.md#dragon-administrator) role. |
| June 2025 | Roles | Added [Organizational Data Source Administrator](permissions-reference.md#organizational-data-source-administrator) role. |
| June 2025 | Administrative units | General availability of restricted management administrative units. See [Restricted management administrative units in Microsoft Entra ID](admin-units-restricted-management.md). |
| May 2025 | Roles | Updated permissions for multiple roles. See [Microsoft Entra built-in roles](permissions-reference.md). |
+1 / -1 lines changed
Commit: Fix image formatting in ServiceNow configuration guide
Changes:
Before
After
4. Select the app, then click **Install**.
The installation process begins and the application is installed in your instance.
5. Configure the app by following the instructions.
:::image type="content" source="media/configure-servicenow-application/servicenow_microsoft-entra-permissions-management-installation.png" alt-text="Screenshot of ServiceNow Microsoft Entra Permissions Management installation." lightbox="media/configure-servicenow-application/servicenow-microsoft-entra-permissions-management-installation.png":::
 
 
## Next steps
4. Select the app, then click **Install**.
The installation process begins and the application is installed in your instance.
5. Configure the app by following the instructions.
:::image type="content" source="media/configure-servicenow-application/servicenow-microsoft-entra-permissions-management-installation.png" alt-text="Screenshot of ServiceNow Microsoft Entra Permissions Management installation." lightbox="media/configure-servicenow-application/servicenow-microsoft-entra-permissions-management-installation.png":::
 
 
## Next steps
Modified by Ken Withee on Oct 1, 2025 2:50 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update link reference for external ID linking
Changes:
Before
After
 
To enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
 
1. Configure your Windows 365 or Azure Virtual Desktop VM instance to use external ID linking. Learn more in [Configure external ID linking](/azure/virtual-desktop/authentication#external-identity).
 
1. Onboard your organization to Global Secure Access. See [onboarding instructions](/entra/global-secure-access/overview-what-is-global-secure-access#licensing-overview).
 
 
To enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
 
1. Configure your Windows 365 or Azure Virtual Desktop VM instance to use external ID linking. Learn more in [Configure external ID linking](/azure/virtual-desktop/authentication#external-identity-preview).
 
1. Onboard your organization to Global Secure Access. See [onboarding instructions](/entra/global-secure-access/overview-what-is-global-secure-access#licensing-overview).
 
Modified by Justinha on Oct 1, 2025 12:46 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update Domain Services sync documentation for clarity
Changes:
Before
After
---
# How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain
 
Objects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.
 
In a hybrid environment, objects and credentials from an on-premises AD DS domain can be synchronized to Microsoft Entra ID using Microsoft Entra Connect. Once those objects are successfully synchronized to Microsoft Entra ID, the automatic background sync then makes those objects and credentials available to applications using the managed domain.
 
---
# How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain
 
Objects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.
 
In a hybrid environment, objects and credentials from an on-premises AD DS domain can be synchronized to Microsoft Entra ID using Microsoft Entra Connect. Once those objects are successfully synchronized to Microsoft Entra ID, the automatic background sync then makes those objects and credentials available to applications using the managed domain.
 
+1 / -1 lines changed
Commit: Update Domain Services sync documentation for clarity
Changes:
Before
After
>
> Synchronized credential information in Microsoft Entra ID can't be re-used if you later create a managed domain - you must reconfigure the password hash synchronization to store the password hashes again. Previously domain-joined VMs or users won't be able to immediately authenticate - Microsoft Entra ID needs to generate and store the password hashes in the new managed domain.
>
> [Microsoft Entra Connect cloud sync is not supported with Domain Services](/azure/active-directory/hybrid/cloud-sync/what-is-cloud-sync#comparison-between-azure-ad-connect-and-cloud-sync). On-premises users need to be synced using Microsoft Entra Connect in order to be able to access domain-joined VMs. For more information, see [Password hash sync process for Domain Services and Microsoft Entra Connect][password-hash-sync-process].
 
The steps to generate and store these password hashes are different for cloud-only user accounts created in Microsoft Entra ID versus user accounts that are synchronized from your on-premises directory using Microsoft Entra Connect.
 
>
> Synchronized credential information in Microsoft Entra ID can't be re-used if you later create a managed domain - you must reconfigure the password hash synchronization to store the password hashes again. Previously domain-joined VMs or users won't be able to immediately authenticate - Microsoft Entra ID needs to generate and store the password hashes in the new managed domain.
>
> [Microsoft Entra Cloud sync isn't supported with Domain Services](/azure/active-directory/hybrid/cloud-sync/what-is-cloud-sync#comparison-between-azure-ad-connect-and-cloud-sync). On-premises users need to be synced using Microsoft Entra Connect sync in order to be able to access domain-joined VMs. Connect sync must be installed on Windows Server 2022, Windows Server 2019, or Windows Server 2016. For more information, see [Password hash sync process for Domain Services and Microsoft Entra Connect][password-hash-sync-process].
 
The steps to generate and store these password hashes are different for cloud-only user accounts created in Microsoft Entra ID versus user accounts that are synchronized from your on-premises directory using Microsoft Entra Connect.
 

🗑️ Deleted Documentation Files

DELETED docs/permissions-management/product-audit-trail.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/product-audit-trail
-396 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/product-define-permission-levels.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/product-define-permission-levels
-271 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/ui-remediation.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/ui-remediation
-226 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/onboard-aws.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/onboard-aws
-209 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/faqs.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/faqs
-201 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/permissions-management-quickstart-guide.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/permissions-management-quickstart-guide
-194 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/how-to-create-role-policy.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/how-to-create-role-policy
-163 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/usage-analytics-users.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/usage-analytics-users
-158 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/onboard-gcp.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/onboard-gcp
-147 lines removed
Commit: Delete docs/permissions-management directory
DELETED docs/permissions-management/usage-analytics-groups.md
Deleted by Huaping Yu on Oct 1, 2025 3:48 PM
📖 Was available at: https://learn.microsoft.com/en-us/entra/permissions-management/usage-analytics-groups
-147 lines removed
Commit: Delete docs/permissions-management directory