📋 Microsoft Entra Documentation Changes

Daily summary for changes since October 23rd 2025, 8:09 PM PDT

Report generated on October 24th 2025, 8:09 PM PDT

📊 Summary

24
Total Commits
0
New Files
7
Modified Files
0
Deleted Files
9
Contributors

📝 Modified Documentation Files

+15 / -15 lines changed
Commit: PR reviewer edits
Changes:
Before
After
---
title: Configure Workday Termination Lookahead
description: Enable Termination Lookahead query for your Workday-to-AD/Entra ID provisioning job.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-id
ms.reviewer: chmutali
ai-usage: ai-assisted
 
#customer intent: As an IT admin, I want to understand how to enable the Workday Termination Lookahead query so I can leverage it for Workday-to-AD/Entra ID provisioning.
---
 
# Configure Workday termination lookahead (Preview)
 
For a user in Japan whose last working day is 14-May-2025, the connector starts including the attributes `StatusTerminationLastDayOfWork` and `StatusTerminationDate`, starting Japan time 4:00pm on 14-May-2025, which corresponds to the 16-hour time difference between PDT and Japan Standard time in May.
 
This adjustment ensures the termination data is available earlier for workers in time zones ahead of Pacific Time. By updating attribute mapping rules in Entra ID, you can then implement time-zone aware terminations.
 
## Job Configuration
 
---
title: Configure Workday Termination Lookahead
description: Enable Termination Lookahead query for your Workday-to-AD/Microsoft Entra ID provisioning job.
author: jenniferf-skc
manager: pmwongera
ms.service: entra-id
ms.reviewer: chmutali
ai-usage: ai-assisted
 
#customer intent: As an IT admin, I want to understand how to enable the Workday Termination Lookahead query so I can leverage it for Workday-to-AD/Microsoft Entra ID provisioning.
---
 
# Configure Workday termination lookahead (Preview)
 
For a user in Japan whose last working day is 14-May-2025, the connector starts including the attributes `StatusTerminationLastDayOfWork` and `StatusTerminationDate`, starting Japan time 4:00pm on 14-May-2025, which corresponds to the 16-hour time difference between PDT and Japan Standard time in May.
 
This adjustment ensures the termination data is available earlier for workers in time zones ahead of Pacific Time. By updating attribute mapping rules in Microsoft Entra ID, you can then implement time-zone aware terminations.
 
## Job configuration
 
+12 / -3 lines changed
Commit: add links to plan integration
Changes:
Before
After
 
Before integrating applications with Microsoft Entra ID, it's important to know where you are and where you want to go. The following questions are intended to help you think about your Microsoft Entra application integration project.
 
### Application inventory
 
- Where are all of your applications? Who owns them?
- Where do your user accounts reside?
- On-premises Active Directory
- Microsoft Entra ID
- Within a separate application database that you own
- In unsanctioned applications
- All of the listed options
- What permissions and role assignments do individual users currently have? Do you need to review their access or are you sure that your user access and role assignments are appropriate now?
 
- [Using applications in the Azure application gallery](what-is-single-sign-on.md)
- [Integrating SaaS applications tutorials list](~/identity/saas-apps/tutorial-list.md)
 
<a name='capabilities-for-apps-not-listed-in-the-azure-ad-gallery'></a>
 
 
 
Before integrating applications with Microsoft Entra ID, it's important to know where you are and where you want to go. The following questions are intended to help you think about your Microsoft Entra application integration project.
 
### Policy inventory
 
- What are your organization's policies for governing access to the applications
- What are the compliance requirements for the applications to be integrated and properly licensed
 
### Application inventory
 
- Where are all of your applications? Who owns them?
- Where do your user accounts reside?
- On-premises Active Directory
- Microsoft Entra ID
- Another LDAP directory
- Within a separate application database that you own
- In other applications such as within SAP Cloud Identity Services
- In unsanctioned applications
- All of the listed options
- What permissions and role assignments do individual users currently have? Do you need to review their access or are you sure that your user access and role assignments are appropriate now?
+8 / -6 lines changed
Commit: add links to governance, private access etc
Changes:
Before
After
 
## Develop, add, or connect
 
There are several ways that you might manage applications in Microsoft Entra ID. The easiest way to start managing an application is to use a preintegrated application from the Microsoft Entra gallery. Developing your own application and registering it in Microsoft Entra ID is an option, or you can continue to use an on-premises application.
 
The following image shows how these applications interact with Microsoft Entra ID.
 
 
### On-premises applications
 
If you want to continue using an on-premises application, but take advantage of what Microsoft Entra ID offers, connect it with Microsoft Entra ID using [Microsoft Entra application proxy](/entra/identity/app-proxy). Application Proxy can be implemented when you want to publish on-premises applications externally. Remote users who need access to internal applications can then access them in a secure manner.
 
## Manage access
 
 
### User, group, and owner assignment
 
By default, all users can access your enterprise applications without being assigned to them. However, if you want to assign the application to a set of users, configure the application to require user assignment and assign the select users to the application. For a simple example of how to create and assign a user account to an application, see [Quickstart: Create and assign a user account](add-application-portal-assign-users.md).
 
If included in your subscription, [assign groups to an application](assign-user-or-group-access-portal.md) so that you can delegate ongoing access management to the group owner.
 
## Develop, add, or connect
 
There are several ways that you might manage applications in Microsoft Entra ID. The easiest way to start managing an application is to use a preintegrated application from the Microsoft Entra gallery, for both SaaS and on-premises or private cloud hosted applications. Developing your own application and registering it in Microsoft Entra ID is an option.
 
The following image shows how these applications interact with Microsoft Entra ID.
 
 
### On-premises applications
 
If you want to deploy an on-premises application or continue using an existing on-premises application, but take advantage of what Microsoft Entra ID offers, connect it with Microsoft Entra ID using [Microsoft Entra Private Access](../../global-secure-access/overview-what-is-global-secure-access.md), [Microsoft Entra application proxy](/entra/identity/app-proxy) or [provisioning](../app-provisioning/user-provisioning.md), depending on the supported protocols of the application. Application Proxy can be implemented when you want to publish on-premises applications externally. Remote users who need access to internal applications can then access them in a secure manner.
 
## Manage access
 
 
### User, group, and owner assignment
 
You can select that all users in your tenant can access your enterprise applications without being assigned to them. However, if you want to assign the application to a set of users, configure the application to require user assignment and assign the select users to the application. For a simple example of how to create and assign a user account to an application, see [Quickstart: Create and assign a user account](add-application-portal-assign-users.md).
 
If included in your subscription, [assign groups to an application](assign-user-or-group-access-portal.md) or [include the application role in an access package](../../id-governance/entitlement-management-access-package-create.md) so that you can delegate ongoing access management to the group owner. You can also [bring in the existing users of an application to Microsoft Entra](../../id-governance/identity-governance-applications-existing-users.md).
+7 / -6 lines changed
Commit: add license prerequisite
Changes:
Before
After
 
> [!div class="checklist"]
> * Create an access review
> * Access the audit logs
> * Access the sign-ins
> * Send logs to Azure Monitor
 
## Prerequisites
 
- An Azure account with an active subscription. If you don't already have one, [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
- One of the following roles: Identity Governance Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
- An enterprise application that has been configured in your Microsoft Entra tenant.
 
 
The **Results** page provides information on each user under review in the instance, including the ability to Stop, Reset, and Download results. To learn more, check out the [Complete an access review of groups and applications in Microsoft Entra access reviews](~/id-governance/complete-access-review.md) article.
 
## Access the audit logs
 
The Microsoft Entra audit logs capture a wide variety of activities within your tenant. These logs provide valuable insights into the activities you need to monitor. For more information, see [Audit logs in Microsoft Entra ID](~/identity/monitoring-health/concept-audit-logs.md).
 
 
> [!div class="checklist"]
> * Create an access review
> * View the audit logs
> * View the sign-ins
> * Send logs to Azure Monitor
 
## Prerequisites
 
- An Azure account with an active subscription. If you don't already have one, [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
- A Microsoft Entra ID Governance subscription for your organization's member users, including for all employees who are reviewing access or having their access reviewed. Some capabilities within this feature might operate with a Microsoft Entra ID P2 subscription.
- One of the following roles: Identity Governance Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
- An enterprise application that has been configured in your Microsoft Entra tenant.
 
 
The **Results** page provides information on each user under review in the instance, including the ability to Stop, Reset, and Download results. To learn more, check out the [Complete an access review of groups and applications in Microsoft Entra access reviews](~/id-governance/complete-access-review.md) article.
 
## View the audit logs
 
The Microsoft Entra audit logs capture a wide variety of activities within your tenant. These logs provide valuable insights into the activities you need to monitor. For more information, see [Audit logs in Microsoft Entra ID](~/identity/monitoring-health/concept-audit-logs.md).
+1 / -1 lines changed
Commit: update module link
Changes:
Before
After
 
To assign a group to an enterprise app, replace `Get-EntraUser` with `Get-EntraGroup` and replace `New-EntraUserAppRoleAssignment` with `New-EntraGroupAppRoleAssignment`.
 
For more information on how to assign a group to an application role, see the documentation for [New-EntraGroupAppRoleAssignment](/powershell/module/microsoft.entra/new-entragroupapproleassignment).
 
## Unassign users and groups from an application using Microsoft Entra PowerShell
 
 
To assign a group to an enterprise app, replace `Get-EntraUser` with `Get-EntraGroup` and replace `New-EntraUserAppRoleAssignment` with `New-EntraGroupAppRoleAssignment`.
 
For more information on how to assign a group to an application role, see the documentation for [New-EntraGroupAppRoleAssignment](/powershell/module/microsoft.entra.groups/new-entragroupapproleassignment).
 
## Unassign users and groups from an application using Microsoft Entra PowerShell
 
Modified by Shannon Leavitt on Oct 24, 2025 7:14 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Update docs/architecture/backup-authentication-system.md
Changes:
Before
After
 
### How does certificate revocation work in an outage?
 
To enhance its resilience posture, the backup authentication system does not have the ability to perform fresh revocation checks. Instead it relies on the state of the certificate revocation list (CRL) check performed when the session was last backed up. If you need to revoke before this backup expires, you should explicitly revoke the session instead of waiting for the CRL.
 
## Workload identity resilience in the backup authentication system
 
 
### How does certificate revocation work in an outage?
 
To enhance its resilience posture, the backup authentication system can't perform fresh revocation checks. Instead, it relies on the state of the certificate revocation list (CRL) check that's performed when the session was last backed up. If you need to revoke before this backup expires, you should explicitly revoke the session instead of waiting for the CRL.
 
## Workload identity resilience in the backup authentication system
 
+1 / -1 lines changed
Commit: Update notification recipient details in documentation
Changes:
Before
After
 
1. At the bottom of the main **Settings** page, select the **Save** button.
 
You can select up to 10 recipients to receive notifications. You can select a group to receive the notifications, but the membership of that group can't exceed 10 users. If you select a group that has fewer than 10 users but more are added later, the group no longer receives notifications. Similarly, the notifications can only be sent to five objects, such as a combination of individual users or groups.
 
At this time, the agent's communication is one direction, so you can receive notifications but can't respond to them in Microsoft Teams. To take action on a suggestion, select **Review suggestion** from the chat to open the Conditional Access optimization agent in the Microsoft Entra admin center.
 
 
1. At the bottom of the main **Settings** page, select the **Save** button.
 
You can select up to 10 recipients to receive notifications. You can select a group to receive the notifications, but the membership of that group can't exceed 10 users. If you select a group that has fewer than 10 users but more are added later, the group no longer receives notifications. Similarly, the notifications can only be sent to five objects, such as a combination of individual users or groups. To stop receiving notifications, remove your user object or the group you're included in from the recipient's list.
 
At this time, the agent's communication is one direction, so you can receive notifications but can't respond to them in Microsoft Teams. To take action on a suggestion, select **Review suggestion** from the chat to open the Conditional Access optimization agent in the Microsoft Entra admin center.