📋 Microsoft Entra Documentation Changes

Daily summary for changes since October 1st 2025, 8:02 PM PDT

Report generated on October 2nd 2025, 8:02 PM PDT

📊 Summary

28
Total Commits
0
New Files
148
Modified Files
0
Deleted Files
10
Contributors

📝 Modified Documentation Files

+47 / -14 lines changed
Commit: [Conditional Access] Deployment plan order of deployment updates
Changes:
Before
After
 
Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
 
| Conditional Access policy | Scenario | License requirement |
| --- | --- | --- |
| [Block legacy authentication](/entra/fundamentals/configure-security#block-legacy-authentication) | All users | Microsoft Entra ID P1 |
| [Privileged Microsoft Entra built-in roles enforce phishing-resistant methods](/entra/fundamentals/configure-security#privileged-microsoft-entra-built-in-roles-are-targeted-with-conditional-access-policies-to-enforce-phishing-resistant-methods) | Privileged users | Microsoft Entra ID P1 |
| [All user sign-in activity uses strong authentication methods](/entra/fundamentals/configure-security#all-user-sign-in-activity-uses-strong-authentication-methods) | All users | Microsoft Entra ID P1 |
| [Guest access is protected by strong authentication methods](/entra/fundamentals/configure-security#guest-access-is-protected-by-strong-authentication-methods) | Guest access | Microsoft Entra ID P1 |
| [Secure the MFA registration (My Security Info) page](/entra/fundamentals/configure-security#secure-the-mfa-registration-my-security-info-page) | All users | Microsoft Entra ID P1 |
| [Require multifactor authentication for device join and device registration using user action](/entra/fundamentals/configure-security#require-multifactor-authentication-for-device-join-and-device-registration-using-user-action) | All users | Microsoft Entra ID P1 |
| [User sign-in activity uses token protection](/entra/fundamentals/configure-security#user-sign-in-activity-uses-token-protection) | All users | Microsoft Entra ID P1 |
| [Restrict device code flow](/entra/fundamentals/configure-security#restrict-device-code-flow) | All users | Microsoft Entra ID P1 |
| [Authentication transfer is blocked](/entra/fundamentals/configure-security#authentication-transfer-is-blocked) | All users | Microsoft Entra ID P1 |
| [Restrict access to high risk users](/entra/fundamentals/configure-security#restrict-access-to-high-risk-users) | All users | Microsoft Entra ID P2 |
| [Restrict high risk sign-ins](/entra/fundamentals/configure-security#restrict-high-risk-sign-ins) | All users | Microsoft Entra ID P2 |
| [Conditional Access policies for Privileged Access Workstations are configured](/entra/fundamentals/configure-security#conditional-access-policies-for-privileged-access-workstations-are-configured) | Privileged users | Microsoft Entra ID P1 |
 
#### Evaluate the policy impact
 
 
Start with a few core Conditional Access policies like the ones that follow. Many policies are available as [Conditional Access policy templates](concept-conditional-access-policy-common.md). By default, each policy created from a template is in report-only mode. Test and monitor usage, to ensure the intended result, before turning on each policy.
 
Deploy policies in the following three phases to balance security improvements with minimal user disruption. Organizations can adjust timelines based on their size, complexity, and change management capabilities.
 
#### Phase 1: Foundation (Week 1-2)
 
Establish baseline security controls and prepare for MFA enforcement. **Prerequisites:** Ensure users can register for MFA before enabling enforcement policies.
 
| Order | Conditional Access policy | Scenario | License requirement |
| --- | --- | --- | --- |
| 1 | [Block legacy authentication](/entra/fundamentals/configure-security#block-legacy-authentication) | All users | Microsoft Entra ID P1 |
| 2 | [Secure the MFA registration (My Security Info) page](/entra/fundamentals/configure-security#secure-the-mfa-registration-my-security-info-page) | All users | Microsoft Entra ID P1 |
| 3 | [Privileged Microsoft Entra built-in roles enforce phishing-resistant methods](/entra/fundamentals/configure-security#privileged-microsoft-entra-built-in-roles-are-targeted-with-conditional-access-policies-to-enforce-phishing-resistant-methods) | Privileged users | Microsoft Entra ID P1 |
 
#### Phase 2: Core authentication (Week 2-3)
 
Enforce MFA for all users and guests. **Key impact:** Users will be required to use MFA for all sign-ins. Ensure communication plan is executed and support resources are available.
 
| Order | Conditional Access policy | Scenario | License requirement |
Modified by Henry Mbugua on Oct 2, 2025 9:38 AM
📖 View on learn.microsoft.com
+8 / -13 lines changed
Commit: What's new - September 2025
Changes:
Before
After
 
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
 
## August 2025
 
### Updated articles
 
- [Microsoft Enterprise SSO plug-in for Apple devices](apple-sso-plugin.md) - We adjusted Apple SSO, updated the token protection image, and troubleshot secure enclave issues.
 
## July 2025
 
### Updated articles
 
- [What is the Microsoft identity platform?](v2-overview.md) - The update improved content clarity.
 
## June 2025
 
### New articles
 
- [Restrictions on identifier URIs of Microsoft Entra applications](identifier-uri-restrictions.md)
 
Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
 
## September 2025
 
### Updated articles
 
- [Desktop app that calls web APIs: Code configuration](scenario-desktop-app-configuration.md) - The update improved content clarity.
- [Configure a mobile app that calls web APIs](scenario-mobile-app-configuration.md) - The update improved content clarity.
- [Web app that signs in users: Code configuration](scenario-web-app-sign-user-app-configuration.md) - The update improved content clarity.
 
## August 2025
 
### Updated articles
 
- [Microsoft Enterprise SSO plug-in for Apple devices](apple-sso-plugin.md) - We adjusted Apple SSO, updated the token protection image, and troubleshot secure enclave issues.
 
## July 2025
 
### Updated articles
+2 / -3 lines changed
Commit: Security operations cross links
Changes:
Before
After
manager: martinco
ms.service: entra-external-id
ms.topic: concept-article
ms.date: 09/10/2025
ms.author: gasinh
#customer intent: I need to understand subscriptions and billing, consumer app security, and how to prevent fraud tactics in Microsoft Entra External ID.
* [Introduction to Microsoft Entra External ID deployment guide](deployment-external-intro.md)
* [Tenant design](deployment-external-tenant-design.md)
* [Customer authentication experience](deployment-external-customer-authentication.md)
* Security operations
* [Authentication and access control architecture](deployment-external-authentication-access-control.md)
manager: martinco
ms.service: entra-external-id
ms.topic: concept-article
ms.date: 10/02/2025
ms.author: gasinh
#customer intent: I need to understand subscriptions and billing, consumer app security, and how to prevent fraud tactics in Microsoft Entra External ID.
* [Introduction to Microsoft Entra External ID deployment guide](deployment-external-intro.md)
* [Tenant design](deployment-external-tenant-design.md)
* [Customer authentication experience](deployment-external-customer-authentication.md)
* [Authentication and access control architecture](deployment-external-authentication-access-control.md)
* [Security fundamentals for external tenants](../external-id/customers/concept-security-customers.md)
 
+3 / -2 lines changed
Commit: Security operations cross links
Changes:
Before
After
 
ms.subservice: external
ms.topic: concept-article
ms.date: 04/03/2025
 
ms.custom: it-pro, seo-july-2024
 
- [Start a free trial](https://aka.ms/ciam-free-trial?wt.mc_id=ciamcustomertenantfreetrial_linkclick_content_cnl) or [create your external tenant](how-to-create-external-tenant-portal.md).
- [Find samples and guidance for integrating your app](samples-ciam-all.md).
- [Learn how to migrate users from your current identity provider](how-to-migrate-users.md).
- See also the [Microsoft Entra External ID Developer Center](https://aka.ms/ciam/dev) for the latest developer content and resources.
 
 
ms.subservice: external
ms.topic: concept-article
ms.date: 10/02/2025
 
ms.custom: it-pro, seo-july-2024
 
- [Start a free trial](https://aka.ms/ciam-free-trial?wt.mc_id=ciamcustomertenantfreetrial_linkclick_content_cnl) or [create your external tenant](how-to-create-external-tenant-portal.md).
- [Find samples and guidance for integrating your app](samples-ciam-all.md).
- [Learn how to migrate users from your current identity provider](how-to-migrate-users.md).
- See also the [Microsoft Entra External ID Developer Center](https://aka.ms/ciam/dev) for the latest developer content and resources.
- [Microsoft Entra External ID deployment guide for security operations](../../architecture/deployment-external-operations.md)
+2 / -2 lines changed
Commit: final cleanup
Changes:
Before
After
ms.author: cwerner
ms.date: 05/12/2025
ms.reviewer: stsoneff
ms.service: azure-app-service
ms.subservice: web-apps
ms.topic: tutorial
ms.custom: subject-rbac-steps, sfi-image-nochange
#Customer intent: As an application developer, I want to learn how to access Azure Storage for an app by using managed identities.
---
 
ms.author: cwerner
ms.date: 05/12/2025
ms.reviewer: stsoneff
ms.service: identity-platform
ms.subservice: web-apps
ms.topic: tutorial
ms.custom: sfi-image-nochange
#Customer intent: As an application developer, I want to learn how to access Azure Storage for an app by using managed identities.
---
 
+2 / -2 lines changed
Commit: final cleanup
Changes:
Before
After
ms.author: cwerner
ms.date: 02/17/2024
ms.reviewer: stsoneff
ms.service: azure-app-service
ms.subservice: web-apps
ms.topic: tutorial
ms.custom: app-service-web, sfi-image-nochange
#Customer intent: As an application developer, enable authentication and authorization for a web app running on Azure App Service.
---
 
ms.author: cwerner
ms.date: 02/17/2024
ms.reviewer: stsoneff
ms.service: identity-platform
ms.subservice: web-apps
ms.topic: tutorial
ms.custom: sfi-image-nochange
#Customer intent: As an application developer, enable authentication and authorization for a web app running on Azure App Service.
---
 
Modified by OwenRichards1 on Oct 2, 2025 2:32 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: final cleanup
Changes:
Before
After
author: cilwerner
manager: pmwongera
ms.author: cwerner
ms.custom: app-service-web, storage, microsoft-graph
ms.date: 02/07/2024
ms.reviewer: stsoneff
ms.service: azure-app-service
ms.subservice: web-apps
ms.topic: tutorial
#Customer intent: As an application developer, I want to learn how to secure access to a web app running on Azure App Service.
author: cilwerner
manager: pmwongera
ms.author: cwerner
ms.custom:
ms.date: 02/07/2024
ms.reviewer: stsoneff
ms.service: identity-platform
ms.subservice: web-apps
ms.topic: tutorial
#Customer intent: As an application developer, I want to learn how to secure access to a web app running on Azure App Service.
+2 / -1 lines changed
Commit: Security operations cross links
Changes:
Before
After
ms.subservice: external
ms.topic: concept-article
ms.date: 06/11/2025
ms.custom: it-pro
---
 
 
- [Planning for customer identity and access management](concept-planning-your-solution.md)
- [Microsoft Entra Blog: Built-in security controls for external-facing apps](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/built-in-security-controls-for-external-facing-apps/4175879)
 
ms.subservice: external
ms.topic: concept-article
ms.date: 10/02/2025
ms.custom: it-pro
---
 
 
- [Planning for customer identity and access management](concept-planning-your-solution.md)
- [Microsoft Entra Blog: Built-in security controls for external-facing apps](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/built-in-security-controls-for-external-facing-apps/4175879)
- [Microsoft Entra External ID deployment guide for security operations](../../architecture/deployment-external-operations.md)
Modified by jenniferf-skc on Oct 2, 2025 4:08 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# View a list and description of system reports
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
Microsoft Entra Permissions Management has various types of system reports that capture specific sets of data. These reports allow management, auditors, and administrators to:
 
# View a list and description of system reports
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
Microsoft Entra Permissions Management has various types of system reports that capture specific sets of data. These reports allow management, auditors, and administrators to:
 
Modified by jenniferf-skc on Oct 2, 2025 4:08 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# Error codes: Microsoft Entra Permissions Management
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
During onboarding, Microsoft Entra Permissions Management may return error messages that an admin can triage. This article lists data collection error messages and their descriptions shown in the Permissions Management UI, along with proposed solutions.
 
# Error codes: Microsoft Entra Permissions Management
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
During onboarding, Microsoft Entra Permissions Management may return error messages that an admin can triage. This article lists data collection error messages and their descriptions shown in the Permissions Management UI, along with proposed solutions.
 
Modified by jenniferf-skc on Oct 2, 2025 4:08 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# Frequently asked questions (FAQs)
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article answers frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
 
# Frequently asked questions (FAQs)
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article answers frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
 
Modified by jenniferf-skc on Oct 2, 2025 4:08 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# Add and remove roles and tasks for Microsoft Azure and Google Cloud Platform (GCP) identities
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can add and remove roles and tasks for Microsoft Azure and Google Cloud Platform (GCP) identities using the **Remediation** dashboard.
 
# Add and remove roles and tasks for Microsoft Azure and Google Cloud Platform (GCP) identities
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can add and remove roles and tasks for Microsoft Azure and Google Cloud Platform (GCP) identities using the **Remediation** dashboard.
 
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# Add or remove a user in Microsoft Entra Permissions Management
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can add or remove a new user for a group in Permissions Management.
 
# Add or remove a user in Microsoft Entra Permissions Management
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can add or remove a new user for a group in Permissions Management.
 
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# Attach and detach policies for Amazon Web Services (AWS) identities
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities using the **Remediation** dashboard.
 
# Attach and detach policies for Amazon Web Services (AWS) identities
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities using the **Remediation** dashboard.
 
Modified by jenniferf-skc on Oct 2, 2025 4:08 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Updating retirement date to November 1, 2025
Changes:
Before
After
# Generate an on-demand report from a query
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on October 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can generate an on-demand report from a query in the **Audit** dashboard in Permissions Management. You can:
 
# Generate an on-demand report from a query
 
> [!NOTE]
> Effective April 1, 2025, Microsoft Entra Permissions Management will no longer be available for purchase, and on November 1, 2025, we'll retire and discontinue support of this product. More information can be found [here](https://aka.ms/MEPMretire).
 
This article describes how you can generate an on-demand report from a query in the **Audit** dashboard in Permissions Management. You can: