📋 Microsoft Entra Documentation Changes

Daily summary for changes since October 15th 2025, 8:07 PM PDT

Report generated on October 16th 2025, 8:07 PM PDT

📊 Summary

17
Total Commits
2
New Files
6
Modified Files
0
Deleted Files
9
Contributors

🆕 New Documentation Files

+34 lines added
Commit: 20251016 - Entra RBAC Reference Refresh
+29 lines added
Commit: 20251016 - Entra RBAC Reference Refresh

📝 Modified Documentation Files

Modified by Faith Moraa Ombongi on Oct 16, 2025 3:13 PM
📖 View on learn.microsoft.com
+11 / -1 lines changed
Commit: 20251016 - Entra RBAC Reference Refresh
Changes:
Before
After
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: reference
ms.date: 09/11/2025
ms.author: rolyon
ms.reviewer: abhijeetsinha
ms.custom: generated, it-pro, fasttrack-edit, has-azure-ad-ps-ref, azure-ad-ref-level-one-done, sfi-ga-nochange
> | [Dynamics 365 Business Central Administrator](#dynamics-365-business-central-administrator) | Access and perform all administrative tasks on Dynamics 365 Business Central environments. | 963797fb-eb3b-4cde-8ce3-5878b3f32a3f |
> | [Edge Administrator](#edge-administrator) | Manage all aspects of Microsoft Edge. | 3f1acade-1e04-4fbc-9b69-f0302cd84aef |
> | [Exchange Administrator](#exchange-administrator) | Can manage all aspects of the Exchange product. | 29232cdf-9323-42fd-ade2-1d097af3e4de |
> | [Exchange Recipient Administrator](#exchange-recipient-administrator) | Can create or update Exchange Online recipients within the Exchange Online organization. | 31392ffb-586c-42d1-9346-e59415a2cc4e |
> | [Extended Directory User Administrator](#extended-directory-user-administrator) | Manage all aspects of external user profiles in the extended directory for Teams. | dd13091a-6207-4fc0-82ba-3641e056ab95 |
> | [External ID User Flow Administrator](#external-id-user-flow-administrator) | Can create and manage all aspects of user flows. | 6e591065-9bad-43ed-90f3-e9424366d2f0 |
> | [Security Reader](#security-reader) | Can read security information and reports in Microsoft Entra ID and Office 365.<br/>[![Privileged label icon.](./media/permissions-reference/privileged-label.png)](privileged-roles-permissions.md) | 5d6b6bb7-de71-4623-b4af-96380a352509 |
> | [Service Support Administrator](#service-support-administrator) | Can read service health information and manage support tickets. | f023fd81-a637-4b56-95fd-791ac0226033 |
> | [SharePoint Administrator](#sharepoint-administrator) | Can manage all aspects of the SharePoint service. | f28a1f50-f6e7-4571-818b-6a12f2af6b6c |
> | [SharePoint Embedded Administrator](#sharepoint-embedded-administrator) | Manage all aspects of SharePoint Embedded containers. | 1a7d78b6-429f-476b-b8eb-35fb715fffd4 |
> | [Skype for Business Administrator](#skype-for-business-administrator) | Can manage all aspects of the Skype for Business product. | 75941009-915a-4869-abe7-691bff18279e |
> | [Teams Administrator](#teams-administrator) | Can manage the Microsoft Teams service. | 69091246-20e8-4a56-aa4d-066075b2a7a8 |
 
ms.service: entra-id
ms.subservice: role-based-access-control
ms.topic: reference
ms.date: 10/16/2025
ms.author: rolyon
ms.reviewer: abhijeetsinha
ms.custom: generated, it-pro, fasttrack-edit, has-azure-ad-ps-ref, azure-ad-ref-level-one-done, sfi-ga-nochange
> | [Dynamics 365 Business Central Administrator](#dynamics-365-business-central-administrator) | Access and perform all administrative tasks on Dynamics 365 Business Central environments. | 963797fb-eb3b-4cde-8ce3-5878b3f32a3f |
> | [Edge Administrator](#edge-administrator) | Manage all aspects of Microsoft Edge. | 3f1acade-1e04-4fbc-9b69-f0302cd84aef |
> | [Exchange Administrator](#exchange-administrator) | Can manage all aspects of the Exchange product. | 29232cdf-9323-42fd-ade2-1d097af3e4de |
> | [Exchange Backup Administrator](#exchange-backup-administrator) | Back up and restore content (including granular restore) for Exchange in Microsoft 365 Backup | 49eb8f75-97e9-4e37-9b2b-6c3ebfcffa31 |
> | [Exchange Recipient Administrator](#exchange-recipient-administrator) | Can create or update Exchange Online recipients within the Exchange Online organization. | 31392ffb-586c-42d1-9346-e59415a2cc4e |
> | [Extended Directory User Administrator](#extended-directory-user-administrator) | Manage all aspects of external user profiles in the extended directory for Teams. | dd13091a-6207-4fc0-82ba-3641e056ab95 |
> | [External ID User Flow Administrator](#external-id-user-flow-administrator) | Can create and manage all aspects of user flows. | 6e591065-9bad-43ed-90f3-e9424366d2f0 |
> | [Security Reader](#security-reader) | Can read security information and reports in Microsoft Entra ID and Office 365.<br/>[![Privileged label icon.](./media/permissions-reference/privileged-label.png)](privileged-roles-permissions.md) | 5d6b6bb7-de71-4623-b4af-96380a352509 |
> | [Service Support Administrator](#service-support-administrator) | Can read service health information and manage support tickets. | f023fd81-a637-4b56-95fd-791ac0226033 |
> | [SharePoint Administrator](#sharepoint-administrator) | Can manage all aspects of the SharePoint service. | f28a1f50-f6e7-4571-818b-6a12f2af6b6c |
> | [SharePoint Backup Administrator](#sharepoint-backup-administrator) | Back up and restore content (including granular restore) for SharePoint and OneDrive in Microsoft 365 Backup | 9d3e04ba-3ee4-4d1b-a3a7-9aef423a09be |
> | [SharePoint Embedded Administrator](#sharepoint-embedded-administrator) | Manage all aspects of SharePoint Embedded containers. | 1a7d78b6-429f-476b-b8eb-35fb715fffd4 |
> | [Skype for Business Administrator](#skype-for-business-administrator) | Can manage all aspects of the Skype for Business product. | 75941009-915a-4869-abe7-691bff18279e |
+3 / -3 lines changed
Commit: Oct 16 updates
Changes:
Before
After
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 09/10/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
|Return code|Code type|
|-----------|---------|
|0|Success|
|3010|Success|
|1618|Retry|
 
:::image type="content" source="media/how-to-install-windows-client/program-install-parameters.png" alt-text="Screenshot of Program to configure installation parameters." lightbox="media/how-to-install-windows-client/program-install-parameters.png":::
1. Select **OK**. Select **Next**.
1. Select **Next** twice to go to **Assignments**.
1. Under **Required**, select **+Add group**. Select a group of users or devices. Select **Select**.
1. The restart grace period is enabled, since the script prompts for a reboot.
 
:::image type="content" source="media/how-to-install-windows-client/restart-grace-period.png" alt-text="Screenshot of the Assignments tab showing the required groups and that restart grace period is enabled." lightbox="media/how-to-install-windows-client/restart-grace-period.png":::
description: The Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
ms.service: global-secure-access
ms.topic: how-to
ms.date: 10/16/2025
ms.author: jayrusso
author: HULKsmashGithub
manager: dougeby
|Return code|Code type|
|-----------|---------|
|0|Success|
|3010|Soft reboot|
|1618|Retry|
 
:::image type="content" source="media/how-to-install-windows-client/program-install-parameters.png" alt-text="Screenshot of Program to configure installation parameters." lightbox="media/how-to-install-windows-client/program-install-parameters.png":::
1. Select **OK**. Select **Next**.
1. Select **Next** twice to go to **Assignments**.
1. Under **Required**, select **+Add group**. Select a group of users or devices. Select **Select**.
1. Set the **Restart grace period** to **Enabled** to avoid disrupting users with an abrupt device reboot.
 
:::image type="content" source="media/how-to-install-windows-client/restart-grace-period.png" alt-text="Screenshot of the Assignments tab showing the required groups and that restart grace period is enabled." lightbox="media/how-to-install-windows-client/restart-grace-period.png":::
+2 / -2 lines changed
Commit: Clarify SSPR writeback support with staged rollout
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 07/21/2025
ms.author: justinha
author: justinha
manager: dougeby
* [Active Directory Federation Services](~/identity/hybrid/connect/how-to-connect-fed-management.md)
 
> [!NOTE]
> SSPR with writeback to an on-premises domain isn't supported when staged rollout is enabled for a security group.
 
Password writeback provides the following features:
 
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 10/25/2025
ms.author: justinha
author: justinha
manager: dougeby
* [Active Directory Federation Services](~/identity/hybrid/connect/how-to-connect-fed-management.md)
 
> [!NOTE]
> SSPR with writeback to an on-premises domain isn't supported when staged rollout is enabled for a security group. Although it works in some cases, SSPR can't be guaranteed to work consistently when staged rollout is enabled.
 
Password writeback provides the following features:
 
+2 / -2 lines changed
Commit: Clarify SSPR writeback support with staged rollout
Changes:
Before
After
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 07/21/2025
ms.subservice: hybrid-connect
ms.author: jomondi
ms.custom: sfi-image-nochange
 
- Legacy authentication such as POP3 and SMTP aren't supported.
 
- Self-service password reset with writeback to an on-premises domain isn't supported when staged rollout is enabled for a security group.
 
- Certain applications send the "domain_hint" query parameter to Microsoft Entra ID during authentication. These flows continue, and users who are enabled for Staged Rollout continue to use federation for authentication.
 
manager: mwongerapk
ms.service: entra-id
ms.topic: how-to
ms.date: 10/16/2025
ms.subservice: hybrid-connect
ms.author: jomondi
ms.custom: sfi-image-nochange
 
- Legacy authentication such as POP3 and SMTP aren't supported.
 
- Self-service password reset (SSPR) with writeback to an on-premises domain isn't supported when staged rollout is enabled for a security group. Although it works in some cases, SSPR can't be guaranteed to work consistently when staged rollout is enabled.
 
- Certain applications send the "domain_hint" query parameter to Microsoft Entra ID during authentication. These flows continue, and users who are enabled for Staged Rollout continue to use federation for authentication.
 
Modified by Sumeet Mittal on Oct 16, 2025 8:22 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Replace ConnectorDiagnosticsTool UI screenshot
Changes:
Before
After
 
Sample User Interface Output (Starting version 1.5.4522.0):
 
![Screenshot showing the "ConnectorDiagnosticsTool" application UI output.](https://github.com/user-attachments/assets/e04fd857-3495-48d0-a4f8-5938d19785ac)
 
## Verify connectivity to the cloud application proxy service and Microsoft sign in page
 
 
Sample User Interface Output (Starting version 1.5.4522.0):
 
<img width="1734" height="1235" alt="connector-diagnostic-tool-ui" src="https://github.com/user-attachments/assets/f8375772-2d0a-4228-bd77-7215107eaec8" />
 
## Verify connectivity to the cloud application proxy service and Microsoft sign in page
 
Modified by Alexander Pavlovsky on Oct 16, 2025 4:07 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update Anycast IP ranges instructions for GSA
Changes:
Before
After
The Global Secure Access service is accessed from the Global Secure Access client and is used for Microsoft Entra Internet Access (including Microsoft 365) and Microsoft Entra Private Access traffic. The Internet Protocol (IP) addresses are listed.
 
### FQDN and IP addresses where the Global Secure Access service receives traffic
Add Anycast IP ranges for accessing the Global Secure Access service edge to your enterprise Access Control Lists (ACLs) and firewalls. When operating in a side-by-side model with other Security Service Edge (SSE) clients, add the Anycast IP ranges to these other clients.
The Global Secure Access service receives traffic on these FQDNs and IP addresses:
- `*.globalsecureaccess.microsoft.com`
The Global Secure Access service is accessed from the Global Secure Access client and is used for Microsoft Entra Internet Access (including Microsoft 365) and Microsoft Entra Private Access traffic. The Internet Protocol (IP) addresses are listed.
 
### FQDN and IP addresses where the Global Secure Access service receives traffic
Add Anycast IP ranges for accessing the Global Secure Access service edge to your enterprise Access Control Lists (ACLs) and firewalls. When operating in a side-by-side model with other Security Service Edge (SSE) clients, add the Anycast IP ranges to these other clients. If you are using TLS inspection on your egress firewalls, exclude GSA traffic from TLS inspection.
The Global Secure Access service receives traffic on these FQDNs and IP addresses:
- `*.globalsecureaccess.microsoft.com`