📋 Microsoft Entra Documentation Changes

Daily summary for changes since October 16th 2025, 8:00 PM PDT

Report generated on October 17th 2025, 8:00 PM PDT

📊 Summary

23
Total Commits
0
New Files
5
Modified Files
0
Deleted Files
10
Contributors

📝 Modified Documentation Files

Modified by jayrusso on Oct 17, 2025 5:48 PM
📖 View on learn.microsoft.com
+24 / -24 lines changed
Commit: Oct 17 added images to Media folder and cleaned up article
Changes:
Before
After
manager: dougeby
ms.service: global-secure-access
ms.topic: troubleshooting
ms.date: 05/07/2025
ms.author: kenwith
ms.reviewer: ashishj,dhruvinshah
ai-usage: ai-assisted
- Connector service running
- Backend service endpoint accessibility
 
The tool also provides additional information, such as certificate details (if the cert is valid), tenant and connector ID, and TLS versions. To ensure that no checks are missed due to network or intermittent issues, the tool contains retries and prints out exception messages for any connectivity failures.
 
**How to get the tool:** The connector diagnostics tool is available in the connector installation package starting version 1.5.4287.0. Previous versions don't contain the tool. A new connector installation is needed to get the tool if you are using the previous version. A user interface is also introduced starting version 1.5.4522.0.
 
**How to use the tool:** After verifying successful installation, the tool can be found in the connector installation folder, located by default in C:/Program Files/Microsoft Entra Private Network Connector. Double click the application "ConnectorDiagnosticsTool" to launch the tool.
 
![Screenshot showing the "ConnectorDiagnosticsTool" application selected in file explorer.](https://github.com/user-attachments/assets/76feaf98-9f2c-492c-bb66-7d65fa4dc576)
 
Sample PowerShell Output:
 
manager: dougeby
ms.service: global-secure-access
ms.topic: troubleshooting
ms.date: 10/17/2025
ms.author: kenwith
ms.reviewer: ashishj,dhruvinshah
ai-usage: ai-assisted
- Connector service running
- Backend service endpoint accessibility
 
The tool also provides additional information, such as certificate details (if the cert is valid), tenant and connector ID, and TLS versions. To ensure that no checks are missed due to network or intermittent issues, the tool contains retries and prints exception messages for any connectivity failures.
 
**How to get the tool:** The connector diagnostics tool is available in the connector installation package starting version 1.5.4287.0. Previous versions don't contain the tool. A new connector installation is needed to get the tool if you're using the previous version. A user interface is also introduced starting version 1.5.4522.0.
 
**How to use the tool:** After you verify the installation, you can find the tool in the connector installation folder. The default location is `C:/Program Files/Microsoft Entra Private Network Connector`. Select the application **ConnectorDiagnosticsTool** to launch the tool.
 
:::image type="content" source="media/troubleshoot-connectors/diagnostics-tool-download.png" alt-text="Screenshot of the "ConnectorDiagnosticsTool" application selected in file explorer." lightbox="media/troubleshoot-connectors/diagnostics-tool-download.png":::
 
Sample PowerShell Output:
 
+4 / -4 lines changed
Commit: Feedbak updates.
Changes:
Before
After
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Extensibility Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-extensibility-administrator) or [Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator).
1. If you have access to multiple tenants, use the **Settings** icon :::image type="icon" source="media/common/admin-center-settings-icon.png" border="false"::: in the top menu to switch to the external tenant from the **Directories + subscriptions** menu.
1. Browse to **Home** > **Service Integrations** > **Sign-up protection (Preview)** to start the wizard.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/configure-sign-up-protection.png" alt-text="Screenshot showing the Sign-up protection (Preview) page.":::
 
 
## Edit the Arkose Labs configuration in the Microsoft Entra admin center
 
1. Browse to **Home** > **Service Integrations** > **Sign-up protection (Preview)** to view the list of configurations.
1. Select the **Edit provider configurations** option to edit the Arkose Labs policy. If you want to edit the fraud protection policy, select the pencil icon.
1. In the **Configure Arkose Labs for sign-up protection** step, select the configuration you want to edit and select **Next**.
1. Select the app you want to protect with Arkose Labs fraud protection or remove the existing ones. You can select one or more applications that you have registered in your external tenant. Once you selected the app, select **Next**.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Extensibility Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-extensibility-administrator) or [Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator).
1. If you have access to multiple tenants, use the **Settings** icon :::image type="icon" source="media/common/admin-center-settings-icon.png" border="false"::: in the top menu to switch to the external tenant from the **Directories + subscriptions** menu.
1. Browse to **Home** > **Service Integrations** > **Sign-up protection (Preview)** to start the wizard.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/configure-sign-up-protection.png" alt-text="Screenshot showing the Sign-up protection (Preview) page.":::
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Extensibility Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-extensibility-administrator) or [Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator).
1. If you have access to multiple tenants, use the **Settings** icon :::image type="icon" source="media/common/admin-center-settings-icon.png" border="false"::: in the top menu to switch to the external tenant from the **Directories + subscriptions** menu.
1. Browse to **Home** > **Security Store** > **Sign-up protection (Preview)** to start the wizard.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/configure-sign-up-protection.png" alt-text="Screenshot showing the Sign-up protection (Preview) page.":::
 
 
## Edit the Arkose Labs configuration in the Microsoft Entra admin center
 
1. Browse to **Home** > **Security Store** > **Sign-up protection (Preview)** to view the list of configurations.
1. Select the **Edit provider configurations** option to edit the Arkose Labs policy. If you want to edit the fraud protection policy, select the pencil icon.
1. In the **Configure Arkose Labs for sign-up protection** step, select the configuration you want to edit and select **Next**.
1. Select the app you want to protect with Arkose Labs fraud protection or remove the existing ones. You can select one or more applications that you have registered in your external tenant. Once you selected the app, select **Next**.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Authentication Extensibility Administrator](/entra/identity/role-based-access-control/permissions-reference#authentication-extensibility-administrator) or [Application Administrator](/entra/identity/role-based-access-control/permissions-reference#application-administrator).
1. If you have access to multiple tenants, use the **Settings** icon :::image type="icon" source="media/common/admin-center-settings-icon.png" border="false"::: in the top menu to switch to the external tenant from the **Directories + subscriptions** menu.
1. Browse to **Home** > **Security Store** > **Sign-up protection (Preview)** to start the wizard.
 
:::image type="content" source="media/how-to-integrate-fraud-protection/configure-sign-up-protection.png" alt-text="Screenshot showing the Sign-up protection (Preview) page.":::
+3 / -3 lines changed
Commit: Update FIDO2 hardware vendor attestation table
Changes:
Before
After
---
title: Microsoft Entra ID attestation for FIDO2 security key vendors
description: Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
ms.date: 10/03/2025
ms.service: entra-id
ms.subservice: authentication
author: justinha
IDEMIA ID-ONE Card|8d1b1fcb-3c76-49a9-9129-5515b346aa02|❌|✅|✅|❌
IDEMIA SOLVO Fly 80 R3 FIDO Card c|dda9aa35-aaf1-4d3c-b6db-7902fd7dbbbf|❌|❌|✅|❌
IDEMIA SOLVO Fly 80 R3 FIDO Card e|def8ab1a-9f91-44f1-a103-088d8dc7d681|❌|❌|✅|❌
IDmelon Android Authenticator|39a5647e-1853-446c-a1f6-a79bae9f5bc7|✅|❌|❌|❌
IDmelon iOS Authenticator|820d89ed-d65a-409e-85cb-f73f0578f82a|✅|❌|❌|❌
ID-One Card|bb405265-40cf-4115-93e5-a332c1968d8c|❌|❌|✅|❌
ID-One Key|82b0a720-127a-4788-b56d-d1d4b2d82eac|❌|✅|✅|❌
ID-One Key|f2145e86-211e-4931-b874-e22bba7d01cc|❌|✅|✅|❌
---
title: Microsoft Entra ID attestation for FIDO2 security key vendors
description: Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
ms.date: 10/17/2025
ms.service: entra-id
ms.subservice: authentication
author: justinha
IDEMIA ID-ONE Card|8d1b1fcb-3c76-49a9-9129-5515b346aa02|❌|✅|✅|❌
IDEMIA SOLVO Fly 80 R3 FIDO Card c|dda9aa35-aaf1-4d3c-b6db-7902fd7dbbbf|❌|❌|✅|❌
IDEMIA SOLVO Fly 80 R3 FIDO Card e|def8ab1a-9f91-44f1-a103-088d8dc7d681|❌|❌|✅|❌
IDmelon Android Authenticator|39a5647e-1853-446c-a1f6-a79bae9f5bc7|✅|✅|❌|✅
IDmelon iOS Authenticator|820d89ed-d65a-409e-85cb-f73f0578f82a|✅|✅|❌|✅
ID-One Card|bb405265-40cf-4115-93e5-a332c1968d8c|❌|❌|✅|❌
ID-One Key|82b0a720-127a-4788-b56d-d1d4b2d82eac|❌|✅|✅|❌
ID-One Key|f2145e86-211e-4931-b874-e22bba7d01cc|❌|✅|✅|❌
+4 / -1 lines changed
Commit: add ps reference
Changes:
Before
After
```openssl x509 -req -in <CSR file> -CA rootCAchain.pem -CAkey rootCAchain.key -CAcreateserial -out signedcertificate.pem -days 370 -sha256 -extfile openssl.cnf -extensions signedCA_ext```
1. Upload the signed certificates (```signedcertificate.pem```and ```rootCAchain.pem```) according to the steps in [Create a CSR and upload the signed certificate for TLS termination](#step-1-global-secure-access-admin-create-a-csr-and-upload-the-signed-certificate-for-tls-termination).
 
## Related content
 
* [What is Transport Layer Security inspection?](concept-transport-layer-security.md)
* [Frequently asked questions for Transport Layer Security inspection](faq-transport-layer-security.yml)
 
 
 
```openssl x509 -req -in <CSR file> -CA rootCAchain.pem -CAkey rootCAchain.key -CAcreateserial -out signedcertificate.pem -days 370 -sha256 -extfile openssl.cnf -extensions signedCA_ext```
1. Upload the signed certificates (```signedcertificate.pem```and ```rootCAchain.pem```) according to the steps in [Create a CSR and upload the signed certificate for TLS termination](#step-1-global-secure-access-admin-create-a-csr-and-upload-the-signed-certificate-for-tls-termination).
 
Examples of configuring TLS certificate using powershell are listed in the below related content section.
 
## Related content
* [Create a TLS certificates using ADCS](powershell-active-directory-certificate-service)
* [Create a TLS certificate using OpenSSL](powershell-active-directory-certificate-service)
* [What is Transport Layer Security inspection?](concept-transport-layer-security.md)
* [Frequently asked questions for Transport Layer Security inspection](faq-transport-layer-security.yml)
+1 / -1 lines changed
Commit: Clarifying location of presentation
Changes:
Before
After
- References:
- [Replicating employee data from SAP ERP HCM](https://help.sap.com/doc/2eff62546be748739ca05477c2ab7ba7/2505/en-US/SF_ERP_EC_EE_Data_HCI_en-US.pdf)
- [2214465 - Integration Add-On 3.0 for SAP ERP HCM - SAP for Me](https://me.sap.com/notes/0002214465) (requires SAP support login)
- Slide deck explaining the integration between **SAP ERP HCM and SuccessFactors**, presented at the [SBN Conference 2019](https://sbn.no/2019_sbnconference).
> [!NOTE]
> CSV Files can have delta (or incremental) data.
- **Step 2**: In Microsoft Entra, configure the API-driven provisioning app to receive employee data from SAP HCM.
- References:
- [Replicating employee data from SAP ERP HCM](https://help.sap.com/doc/2eff62546be748739ca05477c2ab7ba7/2505/en-US/SF_ERP_EC_EE_Data_HCI_en-US.pdf)
- [2214465 - Integration Add-On 3.0 for SAP ERP HCM - SAP for Me](https://me.sap.com/notes/0002214465) (requires SAP support login)
- Slide deck explaining the integration between **SAP ERP HCM and SuccessFactors**, presented at the [SBN Conference 2019](https://sbn.no/2019_sbnconference). To download the presentation from the conference site, go to **Day 1 > Wed 13:30-14:10 > Integration between SAP ERP HCM and SuccessFactors Trygve Berg, Capgemini**.
> [!NOTE]
> CSV Files can have delta (or incremental) data.
- **Step 2**: In Microsoft Entra, configure the API-driven provisioning app to receive employee data from SAP HCM.