📋 Microsoft Entra Documentation Changes

Daily summary for changes since October 6th 2025, 8:03 PM PDT

Report generated on October 7th 2025, 8:03 PM PDT

📊 Summary

64
Total Commits
0
New Files
16
Modified Files
0
Deleted Files
17
Contributors

📝 Modified Documentation Files

+9 / -9 lines changed
Commit: Revise headings and update date in coexistence guide
Changes:
Before
After
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 05/23/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.reviewer: shkhalid
 
This document contains steps to deploy these solutions side by side across several different access scenarios.
 
1. [**Configuration 1: Microsoft Entra Private Access with Palo Alto Prisma Access for secure Internet Access**](#configuration-1-microsoft-entra-private-access-with-palo-alto-prisma-access-for-secure-internet-access)
 
In this scenario Global Secure Access will handle private application traffic. Prisma Access will only capture Internet traffic.
 
2. [**Configuration 2: Microsoft Entra Private Access with Palo Alto Prisma Access for Private Application and Internet Access**](#configuration-2-microsoft-entra-private-access-with-palo-alto-prisma-access-for-private-application-and-internet-access)
 
In this scenario both clients will handle traffic for separate private applications. Private applications in Microsoft Entra Private Access will be handled by Global Secure Access while private applications in Prisma Access service connections, or ZTNA connectors, will be accessed through GlobalProtect client. Internet traffic will be handled by Prisma Access.
 
3. [**Configuration 3: Microsoft Entra Microsoft Access with Palo Alto Prisma Access for Private Application and Internet Access**](#configuration-3-microsoft-entra-microsoft-access-with-palo-alto-prisma-access-for-private-application-and-internet-access)
 
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 10/07/2025
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.reviewer: shkhalid
 
This document contains steps to deploy these solutions side by side across several different access scenarios.
 
1. [**Microsoft Entra Private Access with Palo Alto Prisma Access for secure Internet Access**](#microsoft-entra-private-access-with-palo-alto-prisma-access-for-secure-internet-access)
 
In this scenario Global Secure Access will handle private application traffic. Prisma Access will only capture Internet traffic.
 
2. [**Microsoft Entra Private Access with Palo Alto Prisma Access for Private Application and Internet Access**](#microsoft-entra-private-access-with-palo-alto-prisma-access-for-private-application-and-internet-access)
 
In this scenario both clients will handle traffic for separate private applications. Private applications in Microsoft Entra Private Access will be handled by Global Secure Access while private applications in Prisma Access service connections, or ZTNA connectors, will be accessed through GlobalProtect client. Internet traffic will be handled by Prisma Access.
 
3. [**Microsoft Entra Microsoft Access with Palo Alto Prisma Access for Private Application and Internet Access**](#microsoft-entra-microsoft-access-with-palo-alto-prisma-access-for-private-application-and-internet-access)
 
Modified by Ken Withee on Oct 7, 2025 6:05 PM
📖 View on learn.microsoft.com
+8 / -8 lines changed
Commit: Refactor headings and links in Zscaler coexistence guide
Changes:
Before
After
In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
 
 
3. **Microsoft Entra Microsoft Access with Zscaler Private Access and Zscaler Internet Access**
 
In this scenario, Global Secure Access handles all Microsoft 365 traffic. Zscaler Private Access handles Private application traffic and Zscaler Internet Access handles Internet traffic.
 
4. **Microsoft Entra Internet Access and Microsoft Entra Microsoft Access with Zscaler Private Access**
 
In this scenario, Global Secure Access handles Internet and Microsoft 365 traffic. Zscaler only captures Private application traffic. Therefore, the Zscaler Internet Access module is disabled from the Zscaler portal.
 
1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. In the **Traffic** dialog box, select **Stop collecting**.
1. Scroll to confirm the Global Secure Access client handled private application traffic for the SMB file share and didn't handle the RDP session traffic.
 
## Configuration 3: Microsoft Entra Microsoft Access with Zscaler Private Access and Zscaler Internet Access
 
In this scenario, Global Secure Access handles all Microsoft 365 traffic. Zscaler Private Access handles Private application traffic and Zscaler Internet Access handles Internet traffic.
 
### Microsoft Entra Microsoft Access configuration 3
 
In this scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Zscaler use the Zscaler Private Access module. Zscaler Internet Access handles Internet traffic.
 
 
3. [**Microsoft Entra Microsoft Access with Zscaler Private Access and Zscaler Internet Access**](#microsoft-entra-microsoft-access-with-zscaler-private-access-and-zscaler-internet-access)
 
In this scenario, Global Secure Access handles all Microsoft 365 traffic. Zscaler Private Access handles Private application traffic and Zscaler Internet Access handles Internet traffic.
 
4. [**Microsoft Entra Internet Access and Microsoft Entra Microsoft Access with Zscaler Private Access**](#microsoft-entra-internet-access-and-microsoft-entra-microsoft-access-and-with-zscaler-private-access)
 
In this scenario, Global Secure Access handles Internet and Microsoft 365 traffic. Zscaler only captures Private application traffic. Therefore, the Zscaler Internet Access module is disabled from the Zscaler portal.
 
1. In the system tray, right-click **Global Secure Access Client** and then select **Advanced Diagnostics**. In the **Traffic** dialog box, select **Stop collecting**.
1. Scroll to confirm the Global Secure Access client handled private application traffic for the SMB file share and didn't handle the RDP session traffic.
 
## Microsoft Entra Microsoft Access with Zscaler Private Access and Zscaler Internet Access
 
In this scenario, Global Secure Access handles all Microsoft 365 traffic. Zscaler Private Access handles Private application traffic and Zscaler Internet Access handles Internet traffic.
 
### Microsoft Entra Microsoft Access
 
+8 / -8 lines changed
Commit: Refactor section headers in Netskope coexistence guide
Changes:
Before
After
 
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
 
1. **[Microsoft Entra Private Access with Netskope Internet Access](#configuration-1-microsoft-entra-private-access-with-netskope-internet-access)**
 
In the first scenario, Global Secure Access handles private application traffic. Netskope only captures Internet traffic.
 
2. **[Microsoft Entra Private Access with Netskope Private Access and Netskope Internet Access](#configuration-2-microsoft-entra-private-access-with-netskope-private-access-and-netskope-internet-access)**
 
In the second scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Netskope Private Access are accessed through the Netskope client. Netskope handles Internet traffic.
 
3. **[Microsoft Entra Microsoft Access with Netskope Private Access and Netskope Internet Access](#configuration-3-microsoft-entra-microsoft-access-with-netskope-private-access-and-netskope-internet-access)**
 
In the third scenario, Global Secure Access handles all Microsoft 365 traffic. Netskope handles private application and Internet traffic.
 
4. **[Microsoft Entra Internet Access and Microsoft Entra Microsoft Access with Netskope Private Access](#configuration-4-microsoft-entra-internet-access-and-microsoft-entra-microsoft-access-with-netskope-private-access)**
 
In the fourth scenario, Global Secure Access handles Internet and Microsoft 365 traffic. Netskope only captures Private application traffic.
 
 
 
This guide outlines how to configure and deploy Microsoft Entra solutions alongside Netskope's Security Service Edge (SSE) offerings. By using the strengths of both platforms, you can optimize your organization's security posture while maintaining high-performance connectivity for private applications, Microsoft 365 traffic, and internet access.
 
1. **[Microsoft Entra Private Access with Netskope Internet Access](#microsoft-entra-private-access-with-netskope-internet-access)**
 
In the first scenario, Global Secure Access handles private application traffic. Netskope only captures Internet traffic.
 
2. **[Microsoft Entra Private Access with Netskope Private Access and Netskope Internet Access](#microsoft-entra-private-access-with-netskope-private-access-and-netskope-internet-access)**
 
In the second scenario, both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access. Private applications in Netskope Private Access are accessed through the Netskope client. Netskope handles Internet traffic.
 
3. **[Microsoft Entra Microsoft Access with Netskope Private Access and Netskope Internet Access](#microsoft-entra-microsoft-access-with-netskope-private-access-and-netskope-internet-access)**
 
In the third scenario, Global Secure Access handles all Microsoft 365 traffic. Netskope handles private application and Internet traffic.
 
4. **[Microsoft Entra Internet Access and Microsoft Entra Microsoft Access with Netskope Private Access](#microsoft-entra-internet-access-and-microsoft-entra-microsoft-access-with-netskope-private-access)**
 
In the fourth scenario, Global Secure Access handles Internet and Microsoft 365 traffic. Netskope only captures Private application traffic.
 
 
+12 / -3 lines changed
Commit: Oct 07 draft complete
Changes:
Before
After
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 07/29/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
- **Unhealthy remote network**: An unhealthy remote network has one or more device links disconnected.
- **Increased external tenants activity**: The number of users accessing external tenants has increased.
- **Token and device inconsistency**: The original token is used on a different device.
- **Web content blocked**: Access to the website has been blocked.
 
![Screenshot of the alerts and notifications widget showing two alert types.](media/concept-traffic-dashboard/dashboard-alerts-notifications.png)
 
 
## Device status
 
The **Device status** widgets display the active and inactive devices that you have deployed.
 
- **Active devices**: The number of distinct device IDs seen in the last 24 hours and the % change during that time.
ms.author: kenwith
manager: dougeby
ms.topic: how-to
ms.date: 10/07/2025
ms.service: global-secure-access
ai-usage: ai-assisted
---
- **Unhealthy remote network**: An unhealthy remote network has one or more device links disconnected.
- **Increased external tenants activity**: The number of users accessing external tenants has increased.
- **Token and device inconsistency**: The original token is used on a different device.
- **Web content blocked**: Access to the website is blocked.
 
![Screenshot of the alerts and notifications widget showing two alert types.](media/concept-traffic-dashboard/dashboard-alerts-notifications.png)
 
 
## Device status
 
The **Device status** widgets display the active and inactive devices that you deployed.
 
- **Active devices**: The number of distinct device IDs seen in the last 24 hours and the % change during that time.
+4 / -4 lines changed
Commit: Fixes bookmark links after rename.
Changes:
Before
After
## Cisco Secure Access VPNaaS
 
### Cisco Secure Access VPNaaS - scenarios
1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-internet-and-microsoft-traffic-with-cisco-secure-access-vpnaas-for-private-access).**
Global Secure Access handles internet and Microsoft traffic. Cisco Secure Access VPNaaS captures only private application traffic.
 
2. **[Microsoft Entra Private Access, Internet Access, and Microsoft Access with Cisco Secure Access VPNaaS](#2-internet-private-access-and-microsoft-traffic-with-cisco-secure-access-vpn-for-split-private-access).**
Both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access, while private applications hosted through Cisco Secure Access VPNaaS are accessed through Cisco Secure Client VPN. Global Secure Access handles internet and Microsoft traffic.
 
### Cisco Secure Access VPNaaS - prerequisites
 
### Cisco ASA Remote Access VPN - scenarios
 
1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco ASA Remote Access VPN for private access](#1-internet-and-microsoft-traffic-with-cisco-asa-private-access).**
Global Secure Access handles internet and Microsoft traffic. Cisco ASA captures only private application traffic.
 
2. **[Microsoft Entra Private Access, Internet Access, and Microsoft Access with Cisco ASA Remote Access VPN](#2-internet-private-access-and-microsoft-traffic-with-cisco-asa-private-access).**
Both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access, while private applications hosted through Cisco ASA are accessed through Cisco Secure Client VPN. Global Secure Access handles internet and Microsoft traffic.
 
### Cisco ASA Remote Access VPN - prerequisites
## Cisco Secure Access VPNaaS
 
### Cisco Secure Access VPNaaS - scenarios
1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco Secure Access VPNaaS for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-secure-access-vpnaas-for-private-access).**
Global Secure Access handles internet and Microsoft traffic. Cisco Secure Access VPNaaS captures only private application traffic.
 
2. **[Microsoft Entra Private Access, Internet Access, and Microsoft Access with Cisco Secure Access VPNaaS](#2-microsoft-entra-private-access-internet-access-and-microsoft-access-with-cisco-secure-access-vpn-for-private-access).**
Both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access, while private applications hosted through Cisco Secure Access VPNaaS are accessed through Cisco Secure Client VPN. Global Secure Access handles internet and Microsoft traffic.
 
### Cisco Secure Access VPNaaS - prerequisites
 
### Cisco ASA Remote Access VPN - scenarios
 
1. **[Microsoft Entra Internet Access and Microsoft Access with Cisco ASA Remote Access VPN for private access](#1-microsoft-entra-internet-access-and-microsoft-access-with-cisco-asa-remote-access-vpn-for-private-access).**
Global Secure Access handles internet and Microsoft traffic. Cisco ASA captures only private application traffic.
 
2. **[Microsoft Entra Private Access, Internet Access, and Microsoft Access with Cisco ASA Remote Access VPN](#2-microsoft-entra-private-access-internet-access-and-microsoft-access-with-cisco-asa-remote-access-vpn-for-private-access).**
Both clients handle traffic for separate private applications. Global Secure Access handles private applications in Microsoft Entra Private Access, while private applications hosted through Cisco ASA are accessed through Cisco Secure Client VPN. Global Secure Access handles internet and Microsoft traffic.
 
### Cisco ASA Remote Access VPN - prerequisites
+4 / -4 lines changed
Commit: Update CAE documentation for preview release
Changes:
Before
After
---
title: Learn about Continuous Access Evaluation (CAE) for Application Proxy
description: Learn about Continuous Access Evaluation (CAE) for Application Proxy
author: kenwith
ms.author: kenwith
manager: dougeby
ms.topic: article
ms.date: 09/19/2025
ms.service: global-secure-access
ms.subservice: entra-internet-access
ms.reviewer: dhruvinshah
ai-usage: ai-assisted
---
 
# Learn about Continuous Access Evaluation (CAE) for Application Proxy
 
Continuous Access Evaluation (CAE) is a security feature designed to provide real-time access control based on policy changes and user risk. CAE enables enforcement of access policies in near real-time by continuously evaluating session validity. When a policy change, user risk update, or other critical security event occurs, CAE can revoke or refresh tokens, ensuring that user access is always in compliance with the latest security requirements. Traditionally Entra ID CAE requires each workload to adopt special libraries and is limited to first-party applications only.
 
---
title: Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
description: Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
author: kenwith
ms.author: kenwith
manager: dougeby
ms.topic: article
ms.date: 10/07/2025
ms.service: global-secure-access
ms.subservice: entra-internet-access
ms.reviewer: dhruvinshah
ai-usage: ai-assisted
---
 
# Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
 
Continuous Access Evaluation (CAE) is a security feature designed to provide real-time access control based on policy changes and user risk. CAE enables enforcement of access policies in near real-time by continuously evaluating session validity. When a policy change, user risk update, or other critical security event occurs, CAE can revoke or refresh tokens, ensuring that user access is always in compliance with the latest security requirements. Traditionally Entra ID CAE requires each workload to adopt special libraries and is limited to first-party applications only.
 
+7 / -0 lines changed
Commit: Document September 2025 updates for Connect Health
Changes:
Before
After
 
For feature feedback, vote at [Connect Health User Voice channel](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789)
 
## March 2025
**Agent Updates**
 
 
 
 
 
 
 
 
 
For feature feedback, vote at [Connect Health User Voice channel](https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789)
 
## September 2025
**Agent Updates**
 
Microsoft Entra Connect Health (version 4.5.2528.0)
- Updated installer to default to US Government cloud for US Government cloud users
- Quality improvements & bug fixes
## March 2025
**Agent Updates**
 
+3 / -3 lines changed
Commit: PR-review-fixes
Changes:
Before
After
 
## Mitigate future risks
 
1. Add corporate VPNs and IP address ranges to [named locations](../identity/conditional-access/concept-assignment-network.md) in your Conditional Access policies to reduce false positives.
1. Consider creating a known traveler database for updated organizational travel reporting and use it to cross-reference travel activity.
1. [Provide feedback in ID Protection](howto-identity-protection-risk-feedback.md) to improve detection accuracy and reduce false positives.
 
## Next steps
 
 
## Mitigate future risks
 
- Add corporate VPNs and IP address ranges to [named locations](../identity/conditional-access/concept-assignment-network.md) in your Conditional Access policies to reduce false positives.
- Consider creating a known traveler database for updated organizational travel reporting and use it to cross-reference travel activity.
- [Provide feedback in ID Protection](howto-identity-protection-risk-feedback.md) to improve detection accuracy and reduce false positives.
 
## Next steps
 
+3 / -3 lines changed
Commit: Update based on review.
Changes:
Before
After
---
title: Fraud protection integration
description: Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.
author: csmulligan
ms.author: cmulligan
1. Enter a name for the policy, such as *ArkosePolicy*.
1. Select the scenarios to apply the fraud protection policy to and select **Next**.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/policy-setup.png" alt-text="Screenshot showing setting up a protection policy.":::
 
1. In the **Choose a fraud protection provider for sign-up** step, select **Arkose Labs** as the provider and select **Next**.
 
1. Enter a name for the policy, such as *HUMANPolicy*.
1. Select the scenarios to apply the fraud protection policy to and select **Next**.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/policy-setup-human.png" alt-text="Screenshot showing setting up a protection policy.":::
 
1. In the **Choose a fraud protection provider for sign-up** step, select **HUMAN Security** as the provider and select **Next**.
 
---
title: Fraud Protection Integration
description: Learn how to configure Arkose Labs and Human fraud protection with Microsoft Entra External ID to block bot attacks and fake account creation during user sign-up flows.
author: csmulligan
ms.author: cmulligan
1. Enter a name for the policy, such as *ArkosePolicy*.
1. Select the scenarios to apply the fraud protection policy to and select **Next**.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/policy-set-up.png" alt-text="Screenshot showing setting up a protection policy.":::
 
1. In the **Choose a fraud protection provider for sign-up** step, select **Arkose Labs** as the provider and select **Next**.
 
1. Enter a name for the policy, such as *HUMANPolicy*.
1. Select the scenarios to apply the fraud protection policy to and select **Next**.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/policy-set-up-human.png" alt-text="Screenshot showing setting up a protection policy.":::
 
1. In the **Choose a fraud protection provider for sign-up** step, select **HUMAN Security** as the provider and select **Next**.
 
Modified by csmulligan on Oct 7, 2025 12:56 PM
📖 View on learn.microsoft.com
+0 / -5 lines changed
Commit: Removed Woodgrove.
Changes:
Before
After
 
This article describes how to register your own SAML application in your external tenant by creating a *non-gallery* app in **Enterprise applications**.
 
> [!TIP]
> [![Try it now](./media/common/try-it-now.png)](https://woodgrovebanking.com/)
>
> To try out SAML app with External ID for customer identity and access management (CIAM), go to the Woodgrove live demo and select the sign-in option.
 
## Prerequisites
 
- An Azure account that has an active subscription. <a href="https://azure.microsoft.com/free/?WT.mc_id=A261C142F" target="_blank">Create an account for free</a>.
 
This article describes how to register your own SAML application in your external tenant by creating a *non-gallery* app in **Enterprise applications**.
 
## Prerequisites
 
- An Azure account that has an active subscription. <a href="https://azure.microsoft.com/free/?WT.mc_id=A261C142F" target="_blank">Create an account for free</a>.
 
 
 
 
 
Modified by Ortagus Winfrey on Oct 7, 2025 3:23 PM
📖 View on learn.microsoft.com
+2 / -2 lines changed
Commit: required updates
Changes:
Before
After
1. Sign in to the My Access portal at [https://myaccess.microsoft.com](https://myaccess.microsoft.com) as the direct manager of the team who you want to manage access package assignments for. For US Government, the domain in the My Access portal link is `myaccess.microsoft.us`.
 
1. In the left menu, select **Manage team** to see a list of your direct reports.
:::image type="content" source="media/entitlement-management-request-behalf/manage-team-list.png" alt-text="Screenshot of the list of team members on the manage team page.":::
1. Select an employee to see a list of their assignments.
 
1. On the assignments page, you can see a list of their current access package assignments. You can also select **Remove access** to end that specific access package assignment for the user.
:::image type="content" source="media/entitlement-management-request-behalf/manage-team-reviews.png" alt-text="Screenshot of managing team in the my access portal.":::
 
## Next steps
 
1. Sign in to the My Access portal at [https://myaccess.microsoft.com](https://myaccess.microsoft.com) as the direct manager of the team who you want to manage access package assignments for. For US Government, the domain in the My Access portal link is `myaccess.microsoft.us`.
 
1. In the left menu, select **Manage team** to see a list of your direct reports.
:::image type="content" source="media/entitlement-management-request-behalf/manage-team-list.png" alt-text="Screenshot of the list of team members on the manage team page." lightbox="media/entitlement-management-request-behalf/manage-team-list.png":::
1. Select an employee to see a list of their assignments.
 
1. On the assignments page, you can see a list of their current access package assignments. You can also select **Remove access** to end that specific access package assignment for the user.
:::image type="content" source="media/entitlement-management-request-behalf/manage-team-reviews.png" alt-text="Screenshot of managing team in the my access portal." lightbox="media/entitlement-management-request-behalf/manage-team-reviews.png":::
 
## Next steps
 
+2 / -2 lines changed
Commit: Update download links for Entra Connect Health agent
Changes:
Before
After
 
- Make sure that you satisfy the [requirements](how-to-connect-health-agent-install.md#requirements) to install Microsoft Entra Connect Health.
- Get started using Microsoft Entra Connect Health for AD FS:
- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/07e33770-970b-424b-95a2-e99dfe5f5e8d/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-ad-fs).
- Get started using Microsoft Entra Connect Health for sync:
- [Download and install the latest version of Microsoft Entra Connect](https://go.microsoft.com/fwlink/?linkid=615771). The health agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or later).
- Get started using Microsoft Entra Connect Health for AD Domain Services:
- [Download the Microsoft Entra Connect Health agent for AD Domain Services](https://download.microsoft.com/download/07e33770-970b-424b-95a2-e99dfe5f5e8d/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-azure-ad-ds).
 
## Install the agent for AD FS
 
- Make sure that you satisfy the [requirements](how-to-connect-health-agent-install.md#requirements) to install Microsoft Entra Connect Health.
- Get started using Microsoft Entra Connect Health for AD FS:
- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-ad-fs).
- Get started using Microsoft Entra Connect Health for sync:
- [Download and install the latest version of Microsoft Entra Connect](https://go.microsoft.com/fwlink/?linkid=615771). The health agent for sync is installed as part of the Microsoft Entra Connect installation (version 1.0.9125.0 or later).
- Get started using Microsoft Entra Connect Health for AD Domain Services:
- [Download the Microsoft Entra Connect Health agent for AD Domain Services](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).
- See the [installation instructions](#install-the-agent-for-azure-ad-ds).
 
## Install the agent for AD FS
Modified by Stacy Chambers on Oct 7, 2025 9:02 PM
📖 View on learn.microsoft.com
+0 / -3 lines changed
Commit: pencil edit
Changes:
Before
After
5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.
6. Restart Cisco Umbrella client services or restart the machine where the clients are installed.
 
 
## Configuration scenarios
 
### 1. Microsoft Entra Internet Access and Microsoft Entra Microsoft Access with Cisco Umbrella DNS security.
7. Access a site blocked by Cisco and validate that the Cisco block page is displayed.
8. In Global Secure Access, stop collecting traffic and confirm correct traffic handling.
 
 
### 2. Microsoft Entra Internet Access, Microsoft Access, and Microsoft Entra Private Access with Cisco Umbrella DNS security.
 
**Global Secure Access configuration:**
8. Access a Microsoft Entra private application (for example, SMB file share) and validate that Global Secure Access **is** capturing traffic and Cisco isn't.
9. In Global Secure Access, stop collecting traffic and confirm correct traffic handling.
 
 
> [!NOTE]
> For troubleshooting health check failures, see [Troubleshoot the Global Secure Access client: Health check](troubleshoot-global-secure-access-client-diagnostics-health-check.md).
5. Add DNS suffixes defined in your Private DNS or Enterprise App segments (only required if Private Access traffic forwarding profile is enabled). For example, if your Private DNS suffix is `contoso.local` and you have a private app at `contoso.com`, add both suffixes.
6. Restart Cisco Umbrella client services or restart the machine where the clients are installed.
 
## Configuration scenarios
 
### 1. Microsoft Entra Internet Access and Microsoft Entra Microsoft Access with Cisco Umbrella DNS security.
7. Access a site blocked by Cisco and validate that the Cisco block page is displayed.
8. In Global Secure Access, stop collecting traffic and confirm correct traffic handling.
 
### 2. Microsoft Entra Internet Access, Microsoft Access, and Microsoft Entra Private Access with Cisco Umbrella DNS security.
 
**Global Secure Access configuration:**
8. Access a Microsoft Entra private application (for example, SMB file share) and validate that Global Secure Access **is** capturing traffic and Cisco isn't.
9. In Global Secure Access, stop collecting traffic and confirm correct traffic handling.
 
> [!NOTE]
> For troubleshooting health check failures, see [Troubleshoot the Global Secure Access client: Health check](troubleshoot-global-secure-access-client-diagnostics-health-check.md).
 
 
 
+1 / -1 lines changed
Commit: Clarify role assignments for Conditional Access
Changes:
Before
After
- Admins who interact with Conditional Access need one of the following role assignments, depending on the tasks they're performing. To follow the [Zero Trust principle of least privilege](/security/zero-trust/), consider using [Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) to activate privileged role assignments just in time.
- Read Conditional Access policies and configurations.
- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)
- Create or modify Conditional Access policies.
- [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)
- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).
- A group that includes the test user. If you need to create a group, see [Create a group and add members in Microsoft Entra ID](/entra/fundamentals/how-to-manage-groups).
- Admins who interact with Conditional Access need one of the following role assignments, depending on the tasks they're performing. To follow the [Zero Trust principle of least privilege](/security/zero-trust/), consider using [Privileged Identity Management (PIM)](~/id-governance/privileged-identity-management/pim-configure.md) to activate privileged role assignments just in time.
- Read Conditional Access policies and configurations.
- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)
- Create, modify, or restore soft-deleted Conditional Access policies.
- [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)
- A test user (not an admin) to check that policies work as expected before deploying to real users. If you need to create a user, see [Quickstart: Add new users to Microsoft Entra ID](~/fundamentals/add-users.md).
- A group that includes the test user. If you need to create a group, see [Create a group and add members in Microsoft Entra ID](/entra/fundamentals/how-to-manage-groups).
+1 / -1 lines changed
Commit: PR-review-fixes
Changes:
Before
After
 
### Attacker in the Middle
 
Also referred to as Adversary in the Middle, this high precision detection is triggered when an authentication session is linked to a malicious reverse proxy. In this kind of attack, the adversary can intercept the user's credentials, including tokens issued to the user. The Microsoft Security Research team uses Microsoft 365 Defender for Office to capture the identified risk and raises the user to **High** risk. We recommend administrators manually investigate the user when this detection is triggered to ensure the risk is cleared. Clearing this risk might require secure password reset or revocation of existing sessions.
 
- Calculated offline
- License requirement:
 
### Attacker in the Middle
 
Also referred to as Adversary in the Middle, this high precision detection is triggered when an authentication session is linked to a malicious reverse proxy. In this kind of attack, the adversary can intercept the user's credentials, including tokens issued to the user. The Microsoft Security Research team uses Microsoft Defender for Cloud Apps to capture the identified risk and raises the user to **High** risk. We recommend administrators manually investigate the user when this detection is triggered to ensure the risk is cleared. Clearing this risk might require secure password reset or revocation of existing sessions.
 
- Calculated offline
- License requirement: