📋 Microsoft Entra Documentation Changes

Daily summary for changes since December 17th 2025, 7:39 PM PST

Report generated on December 18th 2025, 7:39 PM PST

📊 Summary

43
Total Commits
0
New Files
7
Modified Files
0
Deleted Files
11
Contributors

📝 Modified Documentation Files

Modified by Alexander Filipin on Dec 18, 2025 3:41 PM
📖 View on learn.microsoft.com
+52 / -26 lines changed
Commit: Update licensing governance document with new entries
Changes:
Before
After
|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Cross-tenant user synchronization (same cloud)](~/identity/multi-tenant-organizations/cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Cross-cloud synchronization](~/identity/multi-tenant-organizations/cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization)|||| :white_check_mark: | :white_check_mark: |
|**Lifecycle Workflows**|**Free**|**Microsoft Entra ID P1**|**Microsoft Entra ID P2**|**Microsoft Entra ID Governance**| **Microsoft Entra Suite** |
|[Lifecycle Workflows](~/id-governance/what-are-lifecycle-workflows.md)|||| :white_check_mark: | :white_check_mark: |
|[Lifecycle Workflows + Custom Extensions (Logic Apps)](~/id-governance/lifecycle-workflow-extensibility.md)|||| :white_check_mark: | :white_check_mark: |
|**Access reviews**|**Free**|**Microsoft Entra ID P1**|**Microsoft Entra ID P2**|**Microsoft Entra ID Governance**| **Microsoft Entra Suite** |
|[Access reviews - Capabilities previously generally available in Microsoft Entra ID P2](~/id-governance/access-reviews-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Access reviews - PIM For Groups (Preview)](~/id-governance/create-access-review-pim-for-groups.md)|||| :white_check_mark: | :white_check_mark: |
|[Access reviews - Inactive Users reviews](~/id-governance/create-access-review.md)|||| :white_check_mark: | :white_check_mark: |
|[Access Reviews - Inactive Users recommendations](~/id-governance/review-recommendations-access-reviews.md#inactive-user-recommendations)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Access reviews - Machine learning assisted access certifications and reviews](~/id-governance/review-recommendations-access-reviews.md#user-to-group-affiliation)|||| :white_check_mark: | :white_check_mark: |
|[Access Review Agent (Preview)](~/id-governance/access-review-agent.md)|| | | :white_check_mark: | :white_check_mark: |
|**Entitlement management**|**Free**|**Microsoft Entra ID P1**|**Microsoft Entra ID P2**|**Microsoft Entra ID Governance**| **Microsoft Entra Suite** |
|[Entitlement management - Capabilities previously generally available in Microsoft Entra ID P2](~/id-governance/entitlement-management-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Entitlement management - Users assigned to access packages](~/id-governance/entitlement-management-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Entitlement management - Conditional Access Scoping](~/id-governance/entitlement-management-external-users.md#review-your-conditional-access-policies)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Entitlement management My Access Search](~/id-governance/my-access-portal-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Entitlement management My Access Delegation](~/id-governance/my-access-portal-overview.md)||| | :white_check_mark: | :white_check_mark: |
|[Entitlement management with Verified ID](~/id-governance/entitlement-management-verified-id-settings.md)|||| :white_check_mark: | :white_check_mark: |
|[Automated provisioning to on-premises apps](~/identity/app-provisioning/on-premises-application-provisioning-architecture.md)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Cross-tenant user synchronization (same cloud)](~/identity/multi-tenant-organizations/cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization)|| :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[Cross-cloud synchronization](~/identity/multi-tenant-organizations/cross-tenant-synchronization-configure.md?pivots=cross-cloud-synchronization)|||| :white_check_mark: | :white_check_mark: |
|**Lifecycle Workflows (LCW)**|**Free**|**Microsoft Entra ID P1**|**Microsoft Entra ID P2**|**Microsoft Entra ID Governance**| **Microsoft Entra Suite** |
|[Lifecycle Workflows](~/id-governance/what-are-lifecycle-workflows.md)|||| :white_check_mark: | :white_check_mark: |
|[LCW + Custom Extensions (Logic Apps)](~/id-governance/lifecycle-workflow-extensibility.md)|||| :white_check_mark: | :white_check_mark: |
|**Access reviews (AR)**|**Free**|**Microsoft Entra ID P1**|**Microsoft Entra ID P2**|**Microsoft Entra ID Governance**| **Microsoft Entra Suite** |
|[AR - Capabilities previously generally available in Microsoft Entra ID P2](~/id-governance/access-reviews-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[AR - PIM For Groups (Preview)](~/id-governance/create-access-review-pim-for-groups.md)|||| :white_check_mark: | :white_check_mark: |
|[AR - Inactive Users reviews](~/id-governance/create-access-review.md)|||| :white_check_mark: | :white_check_mark: |
|[AR - Inactive Users recommendations](~/id-governance/review-recommendations-access-reviews.md#inactive-user-recommendations)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[AR - Machine learning assisted access certifications and reviews](~/id-governance/review-recommendations-access-reviews.md#user-to-group-affiliation)|||| :white_check_mark: | :white_check_mark: |
|[AR Agent (Preview)](~/id-governance/access-review-agent.md)|| | | :white_check_mark: | :white_check_mark: |
|**Entitlement management (EM)**|**Free**|**Microsoft Entra ID P1**|**Microsoft Entra ID P2**|**Microsoft Entra ID Governance**| **Microsoft Entra Suite** |
|[EM - Capabilities previously generally available in Microsoft Entra ID P2](~/id-governance/entitlement-management-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|Requests and assignment|
|[EM - Users assigned to access packages](~/id-governance/tbd.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[EM - Agents and service principals assigned to access packages](~/id-governance/tbd.md)| Identity governance for agents, now in preview, is part of Microsoft Agent 365, the control plane for agents. Get early access to Agent 365 via the Frontier program. |
|[EM - Users request access for themselves](~/id-governance/entitlement-management-overview.md)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
|[EM - Admins directly assign an user - selecting existing users in your directory (including guests)](~/id-governance/entitlement-management-access-package-assignments.md#directly-assign-an-identity)||| :white_check_mark: | :white_check_mark: | :white_check_mark: |
+8 / -8 lines changed
Commit: Update app analytics doc and image references per PM feedback
Changes:
Before
After
ms.author: jayrusso
ms.service: global-secure-access
ms.topic: overview
ms.date: 12/15/2025
manager: dougeby
ms.reviewer: kerenSemel
 
#customer intent: As an IT admin, I want to analyze and visualize application use to better understand organizational usage patterns.
---
<!-- The images in this article have been modified to use approved, fictitious company names from https://microsoft.sharepoint.com/:b:/r/sites/CELAWeb-Copyrights-Trademarks-And-Patents/Shared%20Documents/Approved%20Fictitious%20Company%20Names%20and%20Domain%20Names%20-%20Oct%202024.pdf?csf=1&web=1&e=2JKgvG. -->
 
# What is application usage analytics? (preview)
Application usage analytics gives IT admins actionable insights into their organization's app use by analyzing traffic patterns, data usage, and which users access the app. By using these analytics, admins can identify shadow IT, generative AI apps, and potential security or compliance risks. Usage analytics helps organizations increase visibility, improve their security posture, and optimize app use across their environment.
 
> [!IMPORTANT]
> The application usage analytics feature is currently in PREVIEW.
 
## Insights and Analytics dashboard
To access the **Insights and Analytics** dashboard:
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](/azure/active-directory/roles/permissions-reference#global-secure-access-administrator).
ms.author: jayrusso
ms.service: global-secure-access
ms.topic: overview
ms.date: 12/18/2025
manager: dougeby
ms.reviewer: kerenSemel
 
#customer intent: As an IT admin, I want to analyze and visualize application use to better understand organizational usage patterns.
---
<!-- The images in this article use approved, fictitious company names from https://microsoft.sharepoint.com/:b:/r/sites/CELAWeb-Copyrights-Trademarks-And-Patents/Shared%20Documents/Approved%20Fictitious%20Company%20Names%20and%20Domain%20Names%20-%20Oct%202024.pdf?csf=1&web=1&e=2JKgvG. -->
 
# What is application usage analytics? (preview)
Application usage analytics gives IT admins actionable insights into their organization's app use by analyzing traffic patterns, data usage, and which users access the app. Admins can use these analytics to identify shadow IT, generative AI apps, and potential security or compliance risks. Usage analytics helps organizations increase visibility, improve their security posture, and optimize app use across their environment.
 
> [!IMPORTANT]
> The application usage analytics feature is currently in PREVIEW.
 
## Insights and Analytics dashboard
To access the **Insights and Analytics** dashboard:
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Log Reader](/azure/active-directory/roles/permissions-reference#global-secure-access-log-reader).
+7 / -7 lines changed
Commit: Small changes
Changes:
Before
After
 
| Metadata value | Value | Comments |
|-----------------------|--------|----------|
| Issuer | | Must be an HTTPS URL.<br><br>The issuer value *must* match character-for-character for the configured issuer, the issuer value in the discovery document, and the `iss` claim in the tokens issued by the provider's service.<br><br>The issuer *might* include a port or path segment, but *must not* contain query parameters or fragment identifiers. |
| `authorization_endpoint` | | The endpoint that Microsoft Entra ID communicates with for authorization. This endpoint must be present as one of the reply URLs for the allowed applications. |
| `jwks_uri` | | The location where Microsoft Entra ID can find the public keys it needs to verify the signatures issued by the provider. The `jwks_uri` *must* be an HTTPS endpoint and *must not* include query parameters or fragment identifiers.<br><br>The JSON Web Key (JWK) `x5c` parameter must be present to provide X.509 representations of provided keys. |
| `scopes_supported` | `openid` | Other values might also be included but aren't required. |
 
#### Provider metadata caching
 
To improve performance, Microsoft Entra ID caches metadata that the provider returns, including the keys. Provider metadata caching prevents a discovery call each time Microsoft Entra ID talks to an external identity provider.
 
This cache is refreshed every 24 hours. We recommend that providers follow these steps to roll over their keys:
 
1. Publish the **Existing Cert** and **New Cert** in the `jwks_uri`.
1. Keep signing in with **Existing Cert** until the Microsoft Entra ID cache is refreshed, expired, or updated (every 2 days).
1. Switch to signing in with **New Cert**.
 
After validation succeeds, you can work with the claims payload to get details about the user and their tenant.
 
 
| Metadata value | Value | Comments |
|-----------------------|--------|----------|
| `Issuer` | | Must be an HTTPS URL.<br><br>The issuer value *must* match character-for-character for the configured issuer, the issuer value in the discovery document, and the `iss` claim in the tokens issued by the provider's service.<br><br>The issuer *might* include a port or path segment, but *must not* contain query parameters or fragment identifiers. |
| `authorization_endpoint` | | The endpoint that Microsoft Entra ID communicates with for authorization. This endpoint must be present as one of the reply URLs for the allowed applications. |
| `jwks_uri` | | The location where Microsoft Entra ID can find the public keys it needs to verify the signatures issued by the provider. The `jwks_uri` *must* be an HTTPS endpoint and *must not* include query parameters or fragment identifiers.<br><br>The JSON Web Key (JWK) `x5c` parameter must be present to provide X.509 representations of provided keys. |
| `scopes_supported` | `openid` | Other values might also be included but aren't required. |
 
#### Provider metadata caching
 
To improve performance, Microsoft Entra ID caches metadata that the provider returns, including the keys. Provider metadata caching prevents a discovery call each time Microsoft Entra ID communicates with an external identity provider.
 
This cache is refreshed every 24 hours. We recommend that providers follow these steps to roll over their keys:
 
1. Publish the **Existing Cert** and **New Cert** in `jwks_uri`.
1. Keep signing in with **Existing Cert** until the Microsoft Entra ID cache is refreshed, expired, or updated (every 2 days).
1. Switch to signing in with **New Cert**.
 
After validation succeeds, you can work with the claims payload to get details about the user and their tenant.
 
+4 / -3 lines changed
Commit: Make a few updates to agent docs and webcat checker docs
Changes:
Before
After
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).
1. Browse to **Global Secure Access** > **Secure** > **Web content filtering policies**.
1. Select **Create policy**.
1. Enter a descriptive name such as *Copilot Studio Agent web repositories* and a description for the policy, then select **Next**.
1. Select **Add rule**.
1. Configure rules specific to Copilot Studio agent requirements:
- **Block web repositories**: Add destinations to block web repositories and related domains.
1. Select **Next** to review the policy.
1. Select **Create policy**.
 
## Link policies to the baseline profile
 
Group your security policies by linking them to the baseline profile to apply them to Copilot Studio agent traffic. Security profiles linked to Conditional Access policies aren't currently supported for Copilot Studio agents.
 
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as a [Global Secure Access Administrator](../identity/role-based-access-control/permissions-reference.md#global-secure-access-administrator).
1. Browse to **Global Secure Access** > **Secure** > **Web content filtering policies**.
1. Select **Create policy**.
1. Enter a descriptive name and a description for the policy, then select **Next**.
1. Select **Add rule**.
1. Configure rules based on your security to Copilot Studio agent requirements. For example, block access to `Web respositories`, `Illegal software`, not safe for work (NSFW) sites, and more.
1. Select **Next** to review the policy.
1. Select **Create policy**.
 
Next, you can create policies like [threat intelligence](how-to-configure-threat-intelligence.md) to protect agents against malicious destinations or [file policy](how-to-network-content-filtering.md) to safeguard against unintended data exposure and prevent inline data leaks.
 
## Link policies to the baseline profile
 
Group your security policies by linking them to the baseline profile to apply them to Copilot Studio agent traffic. Security profiles linked to Conditional Access policies aren't currently supported for Copilot Studio agents.
+2 / -2 lines changed
Commit: Make a few updates to agent docs and webcat checker docs
Changes:
Before
After
3. Use the following request format, replacing example.com with the host/path you want to check (for example, `msn.com/en-us/sports`):
 
```http
GET https://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=example.com
```
 
Example:
 
```http
GET https://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoryByUrl(url='@url')?@url=msn.com/en-us/sports
```
 
> [!NOTE]
3. Use the following request format, replacing example.com with the host/path you want to check (for example, `msn.com/en-us/sports`):
 
```http
GET https://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoriesByUrl(url='@url')?@url=example.com
```
 
Example:
 
```http
GET https://graph.microsoft.com/beta/networkaccess/connectivity/microsoft.graph.networkaccess.getWebCategoriesByUrl(url='@url')?@url=msn.com/en-us/sports
```
 
> [!NOTE]
+3 / -1 lines changed
Commit: Update Conditional Access policy creation steps
Changes:
Before
After
1. Create or modify an existing policy.
1. Under **Target resources** > **Resources (formerly cloud apps)** > **Include**, select > **Select resources** > **Edit filter**.
1. Adjust the filter to include your attribute set and definition from earlier.
1. Save the policy
 
> [!NOTE]
> Configure this policy as described in the guidance above. Any deviations in creating the policy as described (such as defining app exclusions) may result in low privilege scopes being excluded and the policy not applying as intended.
 
 
1. Create or modify an existing policy.
1. Under **Target resources** > **Resources (formerly cloud apps)** > **Include**, select > **Select resources** > **Edit filter**.
1. Adjust the filter to include your attribute set and definition from earlier.
1. Under **Access controls** > **Grant**, select **Grant access**, **Require authentication strength**, select **Multifactor authentication**, then select **Select**.
1. Confirm your settings and set **Enable policy** to **Report-only**.
1. Select **Create** to create to enable your policy.
 
> [!NOTE]
> Configure this policy as described in the guidance above. Any deviations in creating the policy as described (such as defining app exclusions) may result in low privilege scopes being excluded and the policy not applying as intended.
Modified by Mark Wahl on Dec 18, 2025 8:13 PM
📖 View on learn.microsoft.com
+1 / -1 lines changed
Commit: add second link
Changes:
Before
After
---
# Configure an OpenID Connect OAuth application from Microsoft Entra app gallery
 
This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md).
 
## Process of adding an OpenID application from the gallery
 
---
# Configure an OpenID Connect OAuth application from Microsoft Entra app gallery
 
This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md) and [Configure OIDC SSO for custom (non-gallery) applications](~/identity/enterprise-apps/add-application-portal-setup-oidc-sso.md?#configure-oidc-sso-for-custom-non-gallery-applications).
 
## Process of adding an OpenID application from the gallery