πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since October 21st 2025, 8:09 PM PDT

Report generated on October 22nd 2025, 8:09 PM PDT

πŸ“Š Summary

18
Total Commits
0
New Files
7
Modified Files
0
Deleted Files
10
Contributors

πŸ“ Modified Documentation Files

+5 / -6 lines changed
Commit: Suggested access package GA
Changes:
Before
After
---
title: Show suggested access packages for My Access in entitlement management (preview)
description: Learn how to show suggested access packages to users in My Access so they can quickly find the most relevant access packages.
author: owinfreyatl
manager: dougeby
#Customer intent: As an administrator, I want to allow my users to see the access packages that are most relevant to them.
---
 
# Suggested access packages in My Access (Preview)
 
In My Access, Microsoft Entra ID Governance users can see a curated list of suggested access packages in My Access. This capability allows users to quickly view the most relevant access packages for them based off their peers' access packages and previous assignments without scrolling through all their available access packages.
 
The suggested access packages list is created by finding people related to the user (manager, direct reports, organization, team members) and recommending access packages based on what the users’ peers have. The user is also suggested access packages that were previously assigned to them.
 
## Opt in for end users to see their suggested access packages in My Access
 
Follow these steps to enable suggested access packages in My Access.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
 
---
title: Show suggested access packages for My Access in entitlement management
description: Learn how to show suggested access packages to users in My Access so they can quickly find the most relevant access packages.
author: owinfreyatl
manager: dougeby
#Customer intent: As an administrator, I want to allow my users to see the access packages that are most relevant to them.
---
 
# Suggested access packages in My Access
 
In My Access, Microsoft Entra ID Governance users can see a curated list of suggested access packages in My Access. This capability allows users to quickly view the most relevant access packages for them based off their peers' access packages and previous assignments without scrolling through all their available access packages.
 
The suggested access packages list is created by finding people related to the user (manager, direct reports, organization, team members) and recommending access packages based on what the users’ peers have. The user is also suggested access packages that were previously assigned to them.
 
## Settings for end users to see their suggested access packages in My Access
 
Follow these steps to enable suggested access packages in My Access.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
 
+2 / -2 lines changed
Commit: Google update.
Changes:
Before
After
 
The following screenshots show the sign-in with Google experience. In the sign-in page, users select **Sign-in with Google**. At that point, the user is redirected to the Google identity provider to complete the sign-in.
 
:::image type="content" source="media/concept-authentication-methods-customers/google-sign-in.png" alt-text="Screenshots of google sign-in screens." border="false":::
 
Learn how to [add Google as an identity provider](how-to-google-federation-customers.md).
 
You can use the following `domain_hint` values to go directly to the sign-in page for these identity providers:
 
- **Facebook**: `domain_hint=facebook`.
- **Google**: `domain_hint=google`.
- **Apple**: `domain_hint=apple`.
- **Custom OIDC**: `domain_hint=<issuer URI>`. For a custom OIDC identity provider, use the domain part of the **Issuer URI** in the `domain_hint` syntax.
 
 
The following screenshots show the sign-in with Google experience. In the sign-in page, users select **Sign-in with Google**. At that point, the user is redirected to the Google identity provider to complete the sign-in.
 
:::image type="content" source="media/concept-authentication-methods-customers/google-sign-in.png" alt-text="Screenshots of Google sign-in screens." border="false":::
 
Learn how to [add Google as an identity provider](how-to-google-federation-customers.md).
 
You can use the following `domain_hint` values to go directly to the sign-in page for these identity providers:
 
- **Facebook**: `domain_hint=facebook`.
- **Google**: `domain_hint=Google`.
- **Apple**: `domain_hint=apple`.
- **Custom OIDC**: `domain_hint=<issuer URI>`. For a custom OIDC identity provider, use the domain part of the **Issuer URI** in the `domain_hint` syntax.
 
Modified by Jason Howell on Oct 22, 2025 6:47 PM
πŸ“– View on learn.microsoft.com
+3 / -0 lines changed
Commit: Add manager metadata to entra-azuread-dev.md
Changes:
Before
After
---
title: include file
description: include file
ms.service: identity-platform
ms.topic: include
ms.date: 10/13/2020
 
 
 
---
title: include file
description: include file
 
manager: CelesteDG
 
ms.service: identity-platform
ms.topic: include
ms.date: 10/13/2020
+1 / -2 lines changed
Commit: [Backup Authentication System] Update PM
Changes:
Before
After
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer:
---
 
# Conditional Access: Resilience defaults
 
If the primary authentication service is unavailable, the Microsoft Entra Backup Authentication Service automatically issues access tokens to applications for existing sessions. This functionality significantly improves Microsoft Entra resilience because reauthentications for existing sessions account for more than 90% of authentications to Microsoft Entra ID. The Backup Authentication Service doesn't support new sessions or authentications by guest users.
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: ludwignick
---
# Conditional Access: Resilience defaults
 
If the primary authentication service is unavailable, the Microsoft Entra Backup Authentication Service automatically issues access tokens to applications for existing sessions. This functionality significantly improves Microsoft Entra resilience because reauthentications for existing sessions account for more than 90% of authentications to Microsoft Entra ID. The Backup Authentication Service doesn't support new sessions or authentications by guest users.
 
Modified by John Flores on Oct 22, 2025 6:32 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: [Backup Authentication System] Update PM
Changes:
Before
After
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: joroja
ms.custom:
- sfi-ropc-nochange
- ai-gen-docs-bap
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: ludwignick
ms.custom:
- sfi-ropc-nochange
- ai-gen-docs-bap
Modified by John Flores on Oct 22, 2025 6:32 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: [Backup Authentication System] Update PM
Changes:
Before
After
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: joroja
ms.custom:
- ai-gen-docs-bap
- ai-gen-title
ms.author: joflore
author: MicrosoftGuyJFlo
manager: dougeby
ms.reviewer: ludwignick
ms.custom:
- ai-gen-docs-bap
- ai-gen-title
+0 / -1 lines changed
Commit: Clarify port configuration instructions
Changes:
Before
After
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
1. Go to **Global Secure Access** > **Applications** > **Quick Access** and then select **Add Quick Access application segment**. Use port `88` and select **TCP**.
1. You can configure the port in either a Quick Access or Enterprise Application.
1. Add the SPNs for the resources you want to secure. The system automatically delivers these SPNs to the Private Access Sensors installed on your domain controllers.
 
![Diagram showing Quick Access settings when configuring Microsoft Entra Private Access integration with Active Directory Domain Controllers.](media/how-to-configure-domain-controllers/quick-access-settings.png)
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
1. Go to **Global Secure Access** > **Applications** > **Quick Access** and then select **Add Quick Access application segment**. Use port `88` and select **TCP**.
1. Add the SPNs for the resources you want to secure. The system automatically delivers these SPNs to the Private Access Sensors installed on your domain controllers.
 
![Diagram showing Quick Access settings when configuring Microsoft Entra Private Access integration with Active Directory Domain Controllers.](media/how-to-configure-domain-controllers/quick-access-settings.png)