📋 Microsoft Entra Documentation Changes

Daily summary for changes since December 8th 2025, 7:37 PM PST

Report generated on December 9th 2025, 7:37 PM PST

📊 Summary

11
Total Commits
0
New Files
2
Modified Files
0
Deleted Files
7
Contributors

📝 Modified Documentation Files

Modified by Janice Ricketts on Dec 9, 2025 6:32 PM
📖 View on learn.microsoft.com
+7 / -8 lines changed
Commit: Revise Kerberos SSO configuration guide
Changes:
Before
After
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.topic: how-to
ms.date: 04/10/2025
ms.author: kenwith
ms.reviewer: ashishj
ai-usage: ai-assisted
- You enabled the Microsoft Entra Private Access forwarding profile.
- The latest version of the Microsoft Entra Private Access connector is installed on a Windows server that has access to your domain controllers.
- The latest version of the Global Secure Access client. For more information on the client, see [Global Secure Access clients](concept-clients.md).
 
### Publish resources for use with single sign-on
To test single sign-on, create a new enterprise application that publishes a file share. Using an enterprise application to publish your file share lets you assign a Conditional Access policy to the resource and enforce extra security controls, such as multifactor authentication.
|88 |User Datagram Protocol (UDP) / Transmission Control Protocol (TCP) |Kerberos |
|123 |UDP |Network Time Protocol (NTP) |
|135 |UDP/TCP |Domain controller to domain controller and client to domain controller operations |
|138 |UDP |File replication service between domain controllers |
|139 |TCP |File replication service between domain controllers |
|389 |UDP |DC locator |
|445 |UDP/TCP |Replication, User and Computer Authentication, Group Policy |
ms.service: global-secure-access
ms.subservice: entra-private-access
ms.topic: how-to
ms.date: 12/9/2025
ms.author: kenwith
ms.reviewer: ashishj
ai-usage: ai-assisted
- You enabled the Microsoft Entra Private Access forwarding profile.
- The latest version of the Microsoft Entra Private Access connector is installed on a Windows server that has access to your domain controllers.
- The latest version of the Global Secure Access client. For more information on the client, see [Global Secure Access clients](concept-clients.md).
- Servers running Active Directory have a supported version of Windows Server installed.
 
### Publish resources for use with single sign-on
To test single sign-on, create a new enterprise application that publishes a file share. Using an enterprise application to publish your file share lets you assign a Conditional Access policy to the resource and enforce extra security controls, such as multifactor authentication.
|88 |User Datagram Protocol (UDP) / Transmission Control Protocol (TCP) |Kerberos |
|123 |UDP |Network Time Protocol (NTP) |
|135 |UDP/TCP |Domain controller to domain controller and client to domain controller operations |
|389 |UDP/TCP |DC locator |
|445 |UDP/TCP |Replication, User and Computer Authentication, Group Policy |
|464 |UDP/TCP |Password Change Request |
Modified by Ortagus Winfrey on Dec 9, 2025 10:52 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: Scale fix
Changes:
Before
After
|Scoping Mode |Number of in-scope groups | Number of membership links (Direct members only) |Notes |
|---------|---------|---------|---------|
|"Selected security groups" mode | Up to 10K groups. The CloudSync pane in Microsoft Entra portal only allows selecting up to 999 groups as well as displaying up to 999 groups. If you need to add more than 1000 groups into scope, see: [Expanded group selection via API](#expanded-group-selection-via-api). | Up to 250K total members across all the groups **in scope**. | Use this scoping mode if your tenant exceeds ANY of these limits<br> 1. Tenant has more than 200k users<br>2. Tenant has more than 40K groups<br> 3. Tenant has more than 1M group memberships.|
|“All Security groups” mode with at least one attribute scoping filter. | Up to 20K groups. | Up to 500K total members across all the groups **in scope**. | Use this scoping mode if your tenant satisfies ALL the below limits:<br>1. Tenant has less than 200k users<br>2. Tenant has less than 40K groups<br>3. Tenant has more than 1M group memberships. |
 
### What to do if you exceed limits
Exceeding the recommended limits will slow initial and delta sync, possibly causing sync errors. If this happens, follow these steps:
|Scoping Mode |Number of in-scope groups | Number of membership links (Direct members only) |Notes |
|---------|---------|---------|---------|
|"Selected security groups" mode | Up to 10K groups. The CloudSync pane in Microsoft Entra portal only allows selecting up to 999 groups as well as displaying up to 999 groups. If you need to add more than 1000 groups into scope, see: [Expanded group selection via API](#expanded-group-selection-via-api). | Up to 250K total members across all the groups **in scope**. | Use this scoping mode if your tenant exceeds ANY of these limits<br> 1. Tenant has more than 200k users<br>2. Tenant has more than 40K groups<br> 3. Tenant has more than 1M group memberships.|
|“All Security groups” mode with at least one attribute scoping filter. | Up to 20K groups. | Up to 500K total members across all the groups **in scope**. | Use this scoping mode if your tenant satisfies ALL the below limits:<br>1. Tenant has less than 200k users<br>2. Tenant has less than 40K groups<br>3. Tenant has less than 1M group memberships. |
 
### What to do if you exceed limits
Exceeding the recommended limits will slow initial and delta sync, possibly causing sync errors. If this happens, follow these steps: