πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since October 30th 2025, 8:17 PM PDT

Report generated on October 31st 2025, 8:17 PM PDT

πŸ“Š Summary

30
Total Commits
0
New Files
11
Modified Files
0
Deleted Files
11
Contributors

πŸ“ Modified Documentation Files

Modified by Ortagus Winfrey on Oct 31, 2025 12:57 PM
πŸ“– View on learn.microsoft.com
+69 / -0 lines changed
Commit: Added to archive
Changes:
Before
After
 
---
 
## March 2025
 
### Microsoft Entra Permissions Management end of sale and retirement
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
---
 
## April 2025
 
### Public Preview - Conditional Access Optimization Agent in Microsoft Entra
 
**Type:** New feature
**Service category:** Conditional Access
**Product capability:** Identity Security & Protection
 
[Conditional Access Optimization Agent in Microsoft Entra](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-innovations-in-microsoft-entra-to-strengthen-ai-security-and-identity-protec/3827393) monitors for new users or apps not covered by existing policies, identifies necessary updates to close security gaps, and recommends quick fixes for identity teams to apply with a single selection. For more information, see: [Microsoft Entra Conditional Access optimization agent](../security-copilot/conditional-access-agent-optimization.md).
 
---
 
### Public Preview - Microsoft Entra ID Governance: Suggested access packages in My Access
 
**Type:** New feature
**Service category:** Entitlement Management
**Product capability:** Entitlement Management
Modified by Ortagus Winfrey on Oct 31, 2025 12:50 PM
πŸ“– View on learn.microsoft.com
+0 / -62 lines changed
Commit: April 2025 added to archive
Changes:
Before
After
 
---
 
 
## April 2025
 
### Public Preview - Conditional Access Optimization Agent in Microsoft Entra
 
**Type:** New feature
**Service category:** Conditional Access
**Product capability:** Identity Security & Protection
 
[Conditional Access Optimization Agent in Microsoft Entra](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-innovations-in-microsoft-entra-to-strengthen-ai-security-and-identity-protec/3827393) monitors for new users or apps not covered by existing policies, identifies necessary updates to close security gaps, and recommends quick fixes for identity teams to apply with a single selection. For more information, see: [Microsoft Entra Conditional Access optimization agent](../security-copilot/conditional-access-agent-optimization.md).
 
 
### Public Preview - Microsoft Entra ID Governance: Suggested access packages in My Access
 
**Type:** New feature
**Service category:** Entitlement Management
**Product capability:** Entitlement Management
 
---
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
+54 / -4 lines changed
Commit: Language Basics tab, intro para update
Changes:
Before
After
> Branding themes for applications are currently in PREVIEW.
> This information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
Previously, you could only use a single branding theme for your entire tenant when users sign in to your applications. Now you can create unique authentication experiences for applications in your tenant. Each application can have its own theme, which you can customize with a background image or color, favicon, layout, header, and footer. This customization overrides any configurations made to the default branding. If you don't make any changes to the elements, the default elements are displayed.
 
This article describes how you can create multiple branding themes for different applications in your tenant.
 
 
Branding themes build on neutral branding and default branding.
 
- Branding theme - Customizations of the default branding where you can have multiple themes.
- Default branding (company branding) - Customizations of the neutral branding for a tenant.
- Neutral branding - Initial branding for a tenant.
 
Here are some important things to know about how branding themes work.
 
:::image type="content" source="./media/how-to-customize-branding-themes-apps/languages-tab.png" alt-text="Screenshot of the Languages tab to add a language." lightbox="./media/how-to-customize-branding-themes-apps/languages-tab.png":::
 
## Related content
> Branding themes for applications are currently in PREVIEW.
> This information relates to a prerelease product that may be substantially modified before it's released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
You can create unique authentication experiences for applications in your tenant. Each application can have its own theme that you can customize with a background image or color, favicon, layout, header, and footer. This customization overrides any configurations made to the default branding. If you don't make any changes to the elements, the default elements are displayed.
 
This article describes how you can create multiple branding themes for different applications in your tenant.
 
 
Branding themes build on neutral branding and default branding.
 
- **Branding theme** - Customizations of the default branding where you can have multiple themes.
- **Default branding (company branding)** - Customizations of the neutral branding for a tenant.
- **Neutral branding** - Initial branding for a tenant.
 
Here are some important things to know about how branding themes work.
 
:::image type="content" source="./media/how-to-customize-branding-themes-apps/languages-tab.png" alt-text="Screenshot of the Languages tab to add a language." lightbox="./media/how-to-customize-branding-themes-apps/languages-tab.png":::
 
1. On the **Basics** tab, select a language.
Modified by Jill Grant on Oct 31, 2025 3:19 AM
πŸ“– View on learn.microsoft.com
+9 / -9 lines changed
Commit: Correct title and heading capitalization in documentation
Changes:
Before
After
---
title: Use Custom Attribute Triggers in Lifecycle Workflows (Preview)
description: This article discusses how to use Custom Attribute Triggers as an attribute change trigger within a workflow in Lifecycle Workflows.
author: owinfreyATL
ms.author: owinfrey
 
 
 
# Use Custom Attribute Triggers in Lifecycle Workflows (Preview)
 
Lifecycle Workflows allows you to trigger workflows to run automatically for users that meet the execution conditions of the workflow. There are many default attributes that you can use to trigger workflows, but sometimes you might require triggering a workflow based on a specific attribute not offered by default. Using custom attribute triggers, you can trigger a workflow to run for users based on when they move within your organization based on:
 
- [Custom security attributes (CSA)](manage-workflow-custom-security-attribute.md)
- directory extension attributes
- on-premises extension attributes (1-15)
- employeeOrgData attributes
 
## Prerequisites
 
[!INCLUDE [Microsoft Entra ID Governance license](../includes/entra-entra-governance-license.md)]
---
title: Use custom attribute triggers in lifecycle workflows (Preview)
description: This article discusses how to use Custom Attribute Triggers as an attribute change trigger within a workflow in Lifecycle Workflows.
author: owinfreyATL
ms.author: owinfrey
 
 
 
# Use Custom attribute triggers in lifecycle workflows (Preview)
 
Lifecycle Workflows allows you to trigger workflows to run automatically for users that meet the execution conditions of the workflow. There are many default attributes that you can use to trigger workflows, but sometimes you might require triggering a workflow based on a specific attribute not offered by default. Using custom attribute triggers, you can trigger a workflow to run for users based on when they move within your organization based on:
 
- [Custom security attributes (CSA)](manage-workflow-custom-security-attribute.md)
- Directory extension attributes
- On-premises extension attributes (1-15)
- EmployeeOrgData attributes
 
## Prerequisites
 
[!INCLUDE [Microsoft Entra ID Governance license](../includes/entra-entra-governance-license.md)]
+6 / -0 lines changed
Commit: ca-agent-updates-103125
Changes:
Before
After
 
To identify Intune device compliance and app protection policies, the agent must be running as a Global Administrator or Conditional Access Administrator AND Global Reader. Conditional Access Administrator isn't sufficient on its own for the agent to produce Intune suggestions.
 
## Remove agent
 
If you no longer wish to use the Conditional Access optimization agent, select **Remove agent** from the top of the agent window. The existing data (agent activity, suggestions, and metrics) is removed but any policies created or updated based on the agent suggestions remain intact. Previously applied suggestions remain unchanged so you can continue to use the policies created or modified by the agent.
 
 
 
 
 
 
 
To identify Intune device compliance and app protection policies, the agent must be running as a Global Administrator or Conditional Access Administrator AND Global Reader. Conditional Access Administrator isn't sufficient on its own for the agent to produce Intune suggestions.
 
## Global Secure Access integration
 
Microsoft Entra Internet Access and Microsoft Entra Private Access (collectively known as Global Secure Access) integrate with the Conditional Access Optimization Agent to provide suggestions specific to your organization's network access policies. The suggestion, **Turn on new policy to enforce Global Secure Access network access requirements**, helps you to align your Global Secure Access policies that include network locations and protected applications.
 
With this integration, the agent identifies users or groups that aren't covered by a Conditional Access policy to require access to corporate resources only through approved Global Secure Access channels. This policy requires users to connect to corporate resources using the organization's secure Global Secure Access network before accessing corporate apps and data. Users connecting from unmanaged or untrusted networks will be prompted to use the Global Secure Access client or web gateway. You can review sign-in logs to verify compliant connections.
 
## Remove agent
 
If you no longer wish to use the Conditional Access optimization agent, select **Remove agent** from the top of the agent window. The existing data (agent activity, suggestions, and metrics) is removed but any policies created or updated based on the agent suggestions remain intact. Previously applied suggestions remain unchanged so you can continue to use the policies created or modified by the agent.
+2 / -4 lines changed
Commit: Updates to Workday Termination Lookahead article and Authentication feature availability for HR provisioning apps
Changes:
Before
After
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 10/24/2025
ms.author: jfields
ms.reviewer: chmutali
ai-usage: ai-assisted
 
## Job configuration
 
1. Go to your [Microsoft Entra admin center](https://aka.ms/EnableLastDayOfWork).
> [!IMPORTANT]
> Test the configuration changes described in this document in your test environment, before enabling the configuration in your production setup.
> [!NOTE]
> This link includes a feature flag in the URL (`userProvisioningWorkdayLookaheadQueryForTerminations=true`) required to configure the lookahead query setting.
 
1. Open your Workday-to-AD/Microsoft Entra ID provisioning job.
 
ms.service: entra-id
ms.subservice: app-provisioning
ms.topic: how-to
ms.date: 10/31/2025
ms.author: jfields
ms.reviewer: chmutali
ai-usage: ai-assisted
 
## Job configuration
 
1. Go to your [Microsoft Entra admin center](https://entra.microsoft.com).
> [!IMPORTANT]
> Test the configuration changes described in this document in your test environment, before enabling the configuration in your production setup.
 
1. Open your Workday-to-AD/Microsoft Entra ID provisioning job.
 
 
 
Modified by jenniferf-skc on Oct 31, 2025 8:24 PM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: Updates to Workday Termination Lookahead article and Authentication feature availability for HR provisioning apps
Changes:
Before
After
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 10/14/2025
 
 
ms.author: justinha
|Workday Writeback | ✅ |
|SuccessFactors to Microsoft Entra user provisioning | ✅ |
|SuccessFactors to Writeback | ✅ |
|API-driven inbound provisioning | ❌ |
|Provisioning agent configuration and registration with Gov cloud tenant| Works with special undocumented command-line invocation:<br> `AADConnectProvisioningAgent.Installer.exe ENVIRONMENTNAME=AzureUSGovernment` |
 
## Other Microsoft Entra products
ms.service: entra-id
ms.subservice: authentication
ms.topic: article
ms.date: 10/31/2025
 
 
ms.author: justinha
|Workday Writeback | &#x2705; |
|SuccessFactors to Microsoft Entra user provisioning | &#x2705; |
|SuccessFactors to Writeback | &#x2705; |
|API-driven inbound provisioning | &#x2705; |
|Provisioning agent configuration and registration with Gov cloud tenant| Works with special undocumented command-line invocation:<br> `AADConnectProvisioningAgent.Installer.exe ENVIRONMENTNAME=AzureUSGovernment` |
 
## Other Microsoft Entra products
Modified by John Flores on Oct 31, 2025 1:43 PM
πŸ“– View on learn.microsoft.com
+2 / -2 lines changed
Commit: Thanks Jan Bakker
Changes:
Before
After
[!INCLUDE [21796](../includes/secure-recommendations/21796.md)]
 
### Temporary access pass is enabled
[!INCLUDE [21796](../includes/secure-recommendations/21796.md)]
 
### Restrict Temporary Access Pass to Single Use
[!INCLUDE [21846](../includes/secure-recommendations/21846.md)]
[!INCLUDE [21844](../includes/secure-recommendations/21844.md)]
 
### Enable Microsoft Entra ID security defaults
[!INCLUDE [21871](../includes/secure-recommendations/21871.md)]
[!INCLUDE [21796](../includes/secure-recommendations/21796.md)]
 
### Temporary access pass is enabled
[!INCLUDE [21845](../includes/secure-recommendations/21845.md)]
 
### Restrict Temporary Access Pass to Single Use
[!INCLUDE [21846](../includes/secure-recommendations/21846.md)]
[!INCLUDE [21844](../includes/secure-recommendations/21844.md)]
 
### Enable Microsoft Entra ID security defaults
[!INCLUDE [21871](../includes/secure-recommendations/21871.md)]
+2 / -1 lines changed
Commit: partnerecoadd
Changes:
Before
After
author: kenwith
manager: dougeby
ms.topic: overview
ms.date: 08/04/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
ai-usage: ai-assisted
| Partner | Partner documentation | Description |
|----------------|-----------------------|----------------|
| Arista Networks | [Arista deployment guide](https://www.arista.com/assets/data/pdf/microsoft-entra-internet-access-with-arista-cv-pathfinder.pdf) | Arista Networks integrates Microsoft Entra Internet Access with Arista CloudVision Pathfinder to deliver secure internet access to Arista Data Center, Campus, Branch, and remote locations. Arista WAN Routing Systems intelligently routes traffic to Microsoft's SASE platform for inspection, ensuring secure internet and SaaS access. |
| Check Point | [Check Point configuration guide](https://support.checkpoint.com/results/sk/sk182799) | Check Point's Quantum SD-WAN solution brings advanced security to WAN connectivity, seamlessly integrating with Microsoft's SASE platform to optimize and secure Microsoft 365 and internet traffic for customers across distributed locations. This solution combines threat prevention, intelligent traffic management, and streamlined workflows, reducing complexity and strengthening security posture across both network and cloud environments. |
| Cisco Catalyst | [Cisco Catalyst user guide](https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/sd-wan/catalyst-sd-wan-ms-sse-int-ug.html) | The Cisco Catalyst SD-WAN integrations with Microsoft's SASE platform use simplified network deployment and advanced threat protection capabilities to deliver comprehensive security for internet-bound traffic originating from branch offices. All internet traffic is routed to Microsoft's SASE platform for inspection, safeguarding users, devices, and data from evolving threats while securing public internet and SaaS access. |
| Cisco Meraki | [Meraki configuration guide](https://documentation.meraki.com/MX/Security_Service_Edge_Integrations/Meraki_Secure_SD-WAN_Microsoft_SSE_Configuration_Guide) |The Cisco Meraki SD-WAN integrations with Microsoft's SASE platform use simplified network deployment and advanced threat protection capabilities to deliver comprehensive security for internet-bound traffic originating from branch offices. All internet traffic is routed to Microsoft's SASE platform for inspection, safeguarding users, devices, and data from evolving threats while securing public internet and SaaS access. |
 
author: kenwith
manager: dougeby
ms.topic: overview
ms.date: 10/31/2025
ms.service: global-secure-access
ms.reviewer: abhijeetsinha
ai-usage: ai-assisted
| Partner | Partner documentation | Description |
|----------------|-----------------------|----------------|
| Arista Networks | [Arista deployment guide](https://www.arista.com/assets/data/pdf/microsoft-entra-internet-access-with-arista-cv-pathfinder.pdf) | Arista Networks integrates Microsoft Entra Internet Access with Arista CloudVision Pathfinder to deliver secure internet access to Arista Data Center, Campus, Branch, and remote locations. Arista WAN Routing Systems intelligently routes traffic to Microsoft's SASE platform for inspection, ensuring secure internet and SaaS access. |
| Arista VeloCloud | [Arista VeloCloud SD-WAN guide](https://www.arista.com/assets/data/pdf/Arista-Microsoft-SSE-VeloCloud-SD-WAN-Deployment-Guide.pdf) | Arista VeloCloud SD-WAN integrates with Microsoft’s SASE platform to provide secure, high-performance internet access across datacenter, campus and branch networks. This solution combines VeloCloud SD-WAN's dynamic path selection, application-aware routing, centralized orchestration to intelligently route traffic to Microsoft's SASE platform for inspection, ensuring secure internet and SaaS application access.|
| Check Point | [Check Point configuration guide](https://support.checkpoint.com/results/sk/sk182799) | Check Point's Quantum SD-WAN solution brings advanced security to WAN connectivity, seamlessly integrating with Microsoft's SASE platform to optimize and secure Microsoft 365 and internet traffic for customers across distributed locations. This solution combines threat prevention, intelligent traffic management, and streamlined workflows, reducing complexity and strengthening security posture across both network and cloud environments. |
| Cisco Catalyst | [Cisco Catalyst user guide](https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/sd-wan/catalyst-sd-wan-ms-sse-int-ug.html) | The Cisco Catalyst SD-WAN integrations with Microsoft's SASE platform use simplified network deployment and advanced threat protection capabilities to deliver comprehensive security for internet-bound traffic originating from branch offices. All internet traffic is routed to Microsoft's SASE platform for inspection, safeguarding users, devices, and data from evolving threats while securing public internet and SaaS access. |
| Cisco Meraki | [Meraki configuration guide](https://documentation.meraki.com/MX/Security_Service_Edge_Integrations/Meraki_Secure_SD-WAN_Microsoft_SSE_Configuration_Guide) |The Cisco Meraki SD-WAN integrations with Microsoft's SASE platform use simplified network deployment and advanced threat protection capabilities to deliver comprehensive security for internet-bound traffic originating from branch offices. All internet traffic is routed to Microsoft's SASE platform for inspection, safeguarding users, devices, and data from evolving threats while securing public internet and SaaS access. |
Modified by Stacy Chambers on Oct 31, 2025 2:43 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Apply suggestions from PR review
Changes:
Before
After
---
 
 
# Delegated Workflow Management (Preview)
 
Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.
 
---
 
 
# Delegated workflow management (preview)
 
Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.
 
Modified by Stacy Chambers on Oct 31, 2025 2:43 PM
πŸ“– View on learn.microsoft.com
+1 / -1 lines changed
Commit: Apply suggestions from PR review
Changes:
Before
After
 
7. Update the desired properties.
> [!NOTE]
> Display names can not be the same as other existing workflows. They must have their own unique name.
 
8. Select **save**.
 
 
7. Update the desired properties.
> [!NOTE]
> Display names cannot be the same as other existing workflows. They must have their own unique name.
 
8. Select **save**.