πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since October 8th 2025, 8:06 PM PDT

Report generated on October 9th 2025, 8:06 PM PDT

πŸ“Š Summary

14
Total Commits
0
New Files
5
Modified Files
0
Deleted Files
5
Contributors

πŸ“ Modified Documentation Files

Modified by Mark Wahl on Oct 9, 2025 6:38 PM
πŸ“– View on learn.microsoft.com
+8 / -8 lines changed
Commit: mention guest billing in examples
Changes:
Before
After
ms.custom: include file
---
 
The following table shows the licensing requirements for Microsoft Entra ID Governance features. Microsoft Entra Suite includes all features of Microsoft Entra ID Governance. Licensing information and example license scenarios for Entitlement management, Access reviews, and Lifecycle Workflows are provided following the table.
 
### Features by license
 
 
### Entitlement Management
 
Using this feature requires Microsoft Entra ID Governance subscriptions for your organization's users. Some capabilities within this feature can operate with a Microsoft Entra ID P2 subscription.
 
#### Example license scenarios
 
 
### Access reviews
 
Using this feature requires Microsoft Entra ID Governance subscriptions for your organization's users, including for all employees who are reviewing access or having their access reviewed. Some capabilities within this feature might operate with a Microsoft Entra ID P2 subscription.
 
#### Example license scenarios
ms.custom: include file
---
 
The following table shows the licensing requirements for Microsoft Entra ID Governance features for member users. Microsoft Entra Suite includes all features of Microsoft Entra ID Governance. Licensing information and example license scenarios for Entitlement management, Access reviews, and Lifecycle Workflows are provided following the table.
 
### Features by license
 
 
### Entitlement Management
 
Using this feature requires a Microsoft Entra ID Governance subscription for your organization's member users. Some capabilities within this feature can operate with a Microsoft Entra ID P2 subscription. Some capabilities within this feature require guest billing.
 
#### Example license scenarios
 
 
### Access reviews
 
Using this feature requires a Microsoft Entra ID Governance subscription for your organization's member users, including for all employees who are reviewing access or having their access reviewed. Some capabilities within this feature might operate with a Microsoft Entra ID P2 subscription. Some capabilities within this feature require guest billing.
 
#### Example license scenarios
Modified by Mark Wahl on Oct 9, 2025 6:04 PM
πŸ“– View on learn.microsoft.com
+4 / -2 lines changed
Commit: add more mention of guest billing
Changes:
Before
After
- **Free** - Included with Microsoft cloud subscriptions such as Microsoft Azure, Microsoft 365, and others.
- **Microsoft Entra ID P1** - Microsoft Entra ID P1 is available as a standalone product or included with Microsoft 365 E3 for enterprise customers and Microsoft 365 Business Premium for small to medium businesses.
- **Microsoft Entra ID P2** - Microsoft Entra ID P2 is available as a standalone product or included with Microsoft 365 E5 for enterprise customers.
- **Microsoft Entra ID Governance** - Microsoft Entra ID Governance is an advanced set of identity governance capabilities available for Microsoft Entra ID P1 and P2 customers. Microsoft Entra ID Governance is available as six products **Microsoft Entra ID Governance**, **Microsoft Entra ID Governance Step Up for Microsoft Entra ID P2**, **Entra ID Governance Frontline Worker**, **Microsoft Entra ID Governance Step up for Microsoft Entra ID F2**, **Microsoft Entra ID Governance for Government** and **Microsoft Entra ID Governance Add-on for Microsoft Entra ID P2 for Government**. These six products differ only in their prerequisites; they contain both the entitlement management, privileged identity management and access reviews capabilities that were in Microsoft Entra ID P2, and additional advanced identity governance capabilities.
- **Microsoft Entra Suite** - Microsoft Entra Suite is a complete cloud-based solution for workforce access, available for Microsoft Entra ID P1 and P2 customers. Microsoft Entra Suite brings together **Microsoft Entra Private Access**, **Microsoft Entra Internet Access**, **Microsoft Entra ID Governance**, **Microsoft Entra ID Protection**, and **Microsoft Entra Verified ID**. The Microsoft Entra ID Governance portion provides the same identity governance capabilities as the **Microsoft Entra ID Governance** product. The difference is that they have different prerequisites.
 
>[!NOTE]
 
1. To view the existing products in the tenant, in the **Manage** menu, select **All products**.
 
## Starting a trial
 
A Global Administrator in a commercial tenant that has an appropriate prerequisite product, such as Microsoft Entra ID P1, already purchased, and isn't already using or has previously trialed Microsoft Entra ID Governance, can request a trial of Microsoft Entra ID Governance in their tenant.
 
### Do licenses need to be assigned to users to use Identity Governance features?
 
Users don't need to be assigned a Microsoft Entra ID Governance license, but there needs to be as many licenses to include all users in scope of, or who configures, the Identity Governance features.
 
### How can I license usage of Microsoft Entra ID Governance features for business guests?
 
- **Free** - Included with Microsoft cloud subscriptions such as Microsoft Azure, Microsoft 365, and others.
- **Microsoft Entra ID P1** - Microsoft Entra ID P1 is available as a standalone product or included with Microsoft 365 E3 for enterprise customers and Microsoft 365 Business Premium for small to medium businesses.
- **Microsoft Entra ID P2** - Microsoft Entra ID P2 is available as a standalone product or included with Microsoft 365 E5 for enterprise customers.
- **Microsoft Entra ID Governance** - Microsoft Entra ID Governance is an advanced set of identity governance capabilities available for Microsoft Entra ID P1 and P2 customers. Microsoft Entra ID Governance is available as six products **Microsoft Entra ID Governance**, **Microsoft Entra ID Governance Step Up for Microsoft Entra ID P2**, **Entra ID Governance Frontline Worker**, **Microsoft Entra ID Governance Step up for Microsoft Entra ID F2**, **Microsoft Entra ID Governance for Government** and **Microsoft Entra ID Governance Add-on for Microsoft Entra ID P2 for Government**. These six products differ only in their prerequisites; they contain both the entitlement management, privileged identity management and access reviews capabilities that were in Microsoft Entra ID P2, and additional advanced identity governance capabilities. The following section goes into more detail on the different prerequisites of these products.
- **Microsoft Entra Suite** - Microsoft Entra Suite is a complete cloud-based solution for workforce access, available for Microsoft Entra ID P1 and P2 customers. Microsoft Entra Suite brings together **Microsoft Entra Private Access**, **Microsoft Entra Internet Access**, **Microsoft Entra ID Governance**, **Microsoft Entra ID Protection**, and **Microsoft Entra Verified ID**. The Microsoft Entra ID Governance portion provides the same identity governance capabilities as the **Microsoft Entra ID Governance** product. The difference is that they have different prerequisites.
 
>[!NOTE]
 
1. To view the existing products in the tenant, in the **Manage** menu, select **All products**.
 
Governance of guest users requires an Azure subscription be selected for guest billing. For more information, see: [Microsoft Entra ID Governance licensing for guest users](microsoft-entra-id-governance-licensing-for-guest-users.md).
 
## Starting a trial
 
A Global Administrator in a commercial tenant that has an appropriate prerequisite product, such as Microsoft Entra ID P1, already purchased, and isn't already using or has previously trialed Microsoft Entra ID Governance, can request a trial of Microsoft Entra ID Governance in their tenant.
 
### Do licenses need to be assigned to users to use Identity Governance features?
 
Users don't need to be assigned a Microsoft Entra ID Governance license, but there needs to be as many licenses to include all member users in scope of, or who configures, the Identity Governance features. In addition, the guest billing model must be enabled if there are guest users to be governed, as described in the next answer.
 
Modified by Mark Wahl on Oct 9, 2025 4:23 PM
πŸ“– View on learn.microsoft.com
+1 / -4 lines changed
Commit: update links to github enterprise server
Changes:
Before
After
| [Genesys Cloud for Azure](../identity/saas-apps/purecloud-by-genesys-provisioning-tutorial.md) | ● | ● |
| [getAbstract](../identity/saas-apps/getabstract-provisioning-tutorial.md) | ● | ● |
| [Getty Images](../identity/saas-apps/getty-images-tutorial.md) | | ● |
| [GitHub AE](../identity/saas-apps/github-ae-provisioning-tutorial.md) | ● | ● |
| [GitHub Enterprise Cloud - Enterprise Account](../identity/saas-apps/github-enterprise-cloud-enterprise-account-tutorial.md) | | ● |
| [GitHub Enterprise Managed User (OIDC)](../identity/saas-apps/github-enterprise-managed-user-oidc-provisioning-tutorial.md) | ● | ● |
| [GitHub Enterprise Managed User](../identity/saas-apps/github-enterprise-managed-user-provisioning-tutorial.md) | ● | ● |
| [GitHub Enterprise Server](../identity/saas-apps/github-ae-tutorial.md) | | ● |
| [GitHub](../identity/saas-apps/github-provisioning-tutorial.md) | ● | ● |
| [Global Relay Identity Sync](../identity/saas-apps/global-relay-identity-sync-provisioning-tutorial.md) | ● | |
| [GlobalOne](../identity/saas-apps/globalone-tutorial.md) | | ● |
| [goFLUENT](../identity/saas-apps/gofluent-tutorial.md) | | ● |
| [GoLinks](../identity/saas-apps/golinks-provisioning-tutorial.md) | ● | ● |
| [Gong](../identity/saas-apps/gong-provisioning-tutorial.md) | ● | |
| [Google Cloud Platform](../identity/saas-apps/g-suite-provisioning-tutorial.md) | ● | ● |
| [GoProfiles](../identity/saas-apps/goprofiles-tutorial.md) | | ● |
| [GoSearch](../identity/saas-apps/gosearch-tutorial.md) | | ● |
| [GoTo](../identity/saas-apps/goto-provisioning-tutorial.md) | ● | ● |
| [MIC SAAS Portal](../identity/saas-apps/mic-saas-portal-tutorial.md) | | ● |
| [MicroFocus Novell eDirectory (LDAP connector)](../identity/app-provisioning/on-premises-ldap-connector-configure.md) | ● | |
| [Genesys Cloud for Azure](../identity/saas-apps/purecloud-by-genesys-provisioning-tutorial.md) | ● | ● |
| [getAbstract](../identity/saas-apps/getabstract-provisioning-tutorial.md) | ● | ● |
| [Getty Images](../identity/saas-apps/getty-images-tutorial.md) | | ● |
| [GitHub Enterprise Cloud - Enterprise Account](../identity/saas-apps/github-enterprise-cloud-enterprise-account-tutorial.md) | | ● |
| [GitHub Enterprise Managed User (OIDC)](../identity/saas-apps/github-enterprise-managed-user-oidc-provisioning-tutorial.md) | ● | ● |
| [GitHub Enterprise Managed User](../identity/saas-apps/github-enterprise-managed-user-provisioning-tutorial.md) | ● | ● |
| [GitHub Enterprise Server](../identity/saas-apps/github-enterprise-server-provisioning-tutorial.md) | ● | ● |
| [GitHub](../identity/saas-apps/github-provisioning-tutorial.md) | ● | ● |
| [Global Relay Identity Sync](../identity/saas-apps/global-relay-identity-sync-provisioning-tutorial.md) | ● | |
| [GlobalOne](../identity/saas-apps/globalone-tutorial.md) | | ● |
| [goFLUENT](../identity/saas-apps/gofluent-tutorial.md) | | ● |
| [GoLinks](../identity/saas-apps/golinks-provisioning-tutorial.md) | ● | ● |
| [Gong](../identity/saas-apps/gong-provisioning-tutorial.md) | ● | |
| [GoProfiles](../identity/saas-apps/goprofiles-tutorial.md) | | ● |
| [GoSearch](../identity/saas-apps/gosearch-tutorial.md) | | ● |
| [GoTo](../identity/saas-apps/goto-provisioning-tutorial.md) | ● | ● |
| [MIC SAAS Portal](../identity/saas-apps/mic-saas-portal-tutorial.md) | | ● |
| [MicroFocus Novell eDirectory (LDAP connector)](../identity/app-provisioning/on-premises-ldap-connector-configure.md) | ● | |
| [Microsoft 365](../fundamentals/concept-group-based-licensing.md) | ● | ● |
| [Microsoft Azure SQL (SQL connector)](../identity/app-provisioning/tutorial-ecma-sql-connector.md) | ● | |
+1 / -1 lines changed
Commit: Clarify Global Secure Access usage scenarios in China
Changes:
Before
After
There are two scenarios that are applicable to Global Secure Access in China:
- Global Secure Access availability for **customer tenants deployed on Microsoft Azure in China**. **Microsoft currently doesn’t support this scenario**.
- Global Secure Access availability for **customer tenants deployed on Microsoft Azure outside China**. **Microsoft supports this scenario**.
- This scenario includes use cases where Global Secure Access (GSA) customers with a presence in multiple geographies and tenants deployed outside China use GSA while in China. For example, when an employee of USA-based company Contoso, using GSA, travels to China.
 
However, it’s important to recognize the specific connectivity disclaimers that apply to Secure Access Service Edge (SASE) providers operating in China. Because of regulatory restrictions and local infrastructure requirements, SASE providers might encounter:
- **Service limitations**: Connectivity performance can vary because of internet regulations and restrictions on VPN usage. Local routing policies can also affect network latency and bandwidth. Because connectivity is unpredictable, user experience might vary.
There are two scenarios that are applicable to Global Secure Access in China:
- Global Secure Access availability for **customer tenants deployed on Microsoft Azure in China**. **Microsoft currently doesn’t support this scenario**.
- Global Secure Access availability for **customer tenants deployed on Microsoft Azure outside China**. **Microsoft supports this scenario**.
- This scenario includes use cases where Global Secure Access (GSA) customers with a presence in multiple geographies and tenants deployed outside China use Global Secure Access while in China. For example, when an employee of USA-based company Contoso, using Global Secure Access, travels to China.
 
However, it’s important to recognize the specific connectivity disclaimers that apply to Secure Access Service Edge (SASE) providers operating in China. Because of regulatory restrictions and local infrastructure requirements, SASE providers might encounter:
- **Service limitations**: Connectivity performance can vary because of internet regulations and restrictions on VPN usage. Local routing policies can also affect network latency and bandwidth. Because connectivity is unpredictable, user experience might vary.
+1 / -1 lines changed
Commit: Minor update.
Changes:
Before
After
ms.date: 09/24/2025
#Customer intent: As an IT admin, I want to integrate Arkose Labs and Human with Microsoft Entra External ID to prevent fake account sign-ups and bot attacks using the Microsoft Entra admin center.
---
# Integrate Microsoft Entra External ID with Arkose Labs and Human for fraud protection (preview)
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]
 
ms.date: 09/24/2025
#Customer intent: As an IT admin, I want to integrate Arkose Labs and Human with Microsoft Entra External ID to prevent fake account sign-ups and bot attacks using the Microsoft Entra admin center.
---
# Integrate Microsoft Entra External ID with Arkose Labs and HUMAN Security for fraud protection (preview)
 
[!INCLUDE [applies-to-external-only](../includes/applies-to-external-only.md)]