Product

Microsoft Entra External ID

Track documentation and Message Center changes for Microsoft Entra External ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra External ID changes

Browser authentication for external identity providers in Microsoft Entra ID

Authentication

Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.

Add an identity provider to a user flow

Authentication

A single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.

Apple Federation Customers

Authentication

The article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.

Custom Oidc Federation Customers

Authentication

The article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.

Direct Federation

Standards

The External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.

Entra Id Federation Customers

Authentication

The article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.

Facebook Federation Customers

Authentication

The article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.

Google Federation Customers

Authentication

The article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.

Manage User Profile Info

Fundamentals

The user profile information guidance no longer includes the “Manage user feature settings” reference.

Manage User Profile Info

Fundamentals

The user profile information documentation no longer includes guidance that users can use My Apps preview features or that administrators can access My Staff.

Microsoft Accounts Federation Customers

Standards

The article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.

Saml Ws Federation Self Service Sign Up

Standards

The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.

Sign In With Passkey

Authentication

The documentation no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and states that low-privilege passkey credential management APIs are on the roadmap.

Set up B2B direct connect

General

The documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.

Set up Microsoft Entra Verified ID

Security

The new article explains how to use Quick setup, register applications, create credentials, and issue and verify credentials in a Microsoft Entra External ID tenant. It documents prerequisites and limits, including custom-domain requirements, shared signing keys, two requests per second per tenant, and six-month credential validity.

Create Service Principal Cross Tenant

General

The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.

Migrate Passwords Just In Time

Authentication

The password migration documentation now uses a different example API application identifier.

Sign In With Passkey

Authentication

The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.

Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings

Message CenterMC1303719 on mc.merill.net ↗Plan for change
Conditional Access

Microsoft Entra will update federatedTokenValidationPolicy by mid-August 2026 to block federated sign-ins when internalDomainFederation doesn't match the user's UPN domain, enhancing security. This affects federated domains configured before December 2025. Admins can customize the policy via Microsoft Graph but it's discouraged.

Allow Deny List

General

The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.

Configure cross-tenant synchronization

Provisioning

The guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.

Add OIDC for customer sign-in

Authentication

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Gsa Poc Internet Access

Architecture

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

Sms Voice Retirement

Authentication

Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.

Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B

Message CenterMC1243549 on mc.merill.net ↗Major updatePlan for change
Conditional Access

SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.

Licensing Guest Users

General

Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.

Troubleshoot

Conditional Access

Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).

Deployment External Operations

Architecture

Learn about edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations for Microsoft Entra External ID.

Choose Authentication Approach

Authentication

Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.

Direct Federation

Standards

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Sign in with alias

Authentication

Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

Tenant Configurations

General

Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.

Add Member To Group

Fundamentals

Now that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.md#create-a-basic-group-and-add-members).

External ID Pricing

General

Learn about the pricing and billing structure for Microsoft Entra External ID, along with steps for linking an external tenant to an Azure subscription.

Faq Customers

Authentication

Microsoft Entra External ID pricing is based on monthly active users (MAU), which is the count of unique users with authentication activity within a calendar month. External ID consists of a core offer and premium add-ons. The Microsoft Entra External ID core offering is free for the first 50,000 MAU. For the latest information about usage billing and pricing, see [Billing model for Microsoft Entra External ID](../external-identities-pricing.md).

Direct Federation

Standards

1. On the **New SAML/WS-Fed IdP** page, enter the following:

Authentication Methods Customers

Authentication

With Microsoft Entra External ID, you can create secure, customized sign-in experiences for your consumer- and business customer-facing apps. In an external tenant, there are several ways for users to sign up for your app. They can create an account using their email and either a password or a one-time passcode. Or, if you enable sign-in with Facebook, Google, Apple, a Microsoft Entra ID tenant, or a custom OIDC or SAML/WS-Fed identity provider (IdP), users can sign in using their credentials in the external identity provider. A user object is created for them in your directory with the identity information collected during sign-up.

Custom Extensions

Authentication

Microsoft Entra External ID user flows are designed for flexibility. Within a sign-up and sign-in user flow, there are built-in authentication events. You can also add custom authentication extensions at specific points within the authentication flow. A custom authentication extension is essentially an event listener that, when activated, makes an HTTP call to a REST API endpoint where you define a workflow action. For example, you could add an [attribute collection](#attribute-collection-start-and-submit-events) workflow to validate the attributes a user enters during sign-up, or you could use a [custom claims provider](#token-issuance-start-event) to add external user data to the token before the token is issued.

Frequently asked questions

General

Find answers to frequently asked questions about Microsoft Entra External ID. Learn about pricing, features, and the future of Azure AD B2C and External Identities.

Multifactor Authentication Customers

Authentication

Enforcing MFA enhances your organization's security by adding an extra layer of verification, making it more difficult for unauthorized users to gain access.

Planning Your Solution

Authentication

Discover the steps for setting up a customer identity and access management (CIAM) solution in an external tenant, including creating a tenant, registering apps, and setting up user flows for sign-in.

Samples Ciam All

Authentication

Microsoft maintains code samples that demonstrate how to integrate various application types with Microsoft Entra External ID. We provide instructions for downloading and using samples or building your own app based on common authentication and authorization scenarios, development languages, and platforms. Included are instructions for building the project (if applicable) and running the sample application. Within the sample code, comments help you understand how these libraries are used in the application to perform authentication and authorization in an external tenant.

Security Customers

Fundamentals

Each layer addresses a different class of attacks, reducing the likelihood of compromise and limiting the blast radius.

B2b Government National Clouds

General

Learn what features are available in Microsoft Entra B2B collaboration in US Government and national clouds

B2c Deployment Plans

Architecture

Azure Active Directory B2C deployment guide for planning, implementation, and monitoring

Choose Authentication Approach

Authentication

Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.

Current Limitations

General

Current limitations for Microsoft Entra B2B collaboration

Custom roles for cross-tenant access settings

General

Learn how your organization can define custom roles to manage cross-tenant access settings, allowing for precise control without relying on built-in management roles.

Direct Federation

Standards

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Entra Id Federation Customers

Standards

Learn how to configure a Microsoft Entra ID tenant as an OpenID Connect identity provider in Microsoft Entra External ID, enabling users to sign in using their existing organizational accounts.

Hybrid Cloud To On Premises

General

Learn how to give cloud B2B users access to on-premises apps with Microsoft Entra B2B collaboration.

Leave The Organization

General

As a B2B collaboration user, learn how to leave an organization if you no longer need guest user access to apps. If you're an admin, see how to allow external users to leave.

Native authentication

Authentication

Learn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.

Self Service Portal

General

Learn how to customize the onboarding workflow for Microsoft Entra B2B users to fit your organization’s needs.

Self Service Sign Up Overview

Fundamentals

Learn how to enable self-service sign-up for Microsoft Entra External ID. Allow external users to sign up for your applications themselves, customize the sign-up experience, and manage user flows.

Sign in with alias

Authentication

Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

Tenant Configurations

General

Learn about tenant configurations in Microsoft Entra External ID, including the differences between workforce and external tenants.

Use MSAL.js with Azure AD B2C

Authentication

The Microsoft Authentication Library for JavaScript (MSAL.js) enables applications to work with Azure AD B2C and acquire tokens to call secured web APIs. These web APIs can be Microsoft Graph, other Microsoft APIs, web APIs from others, or your own web API.

User profile attributes

Fundamentals

User profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.

About B2B Invitations

Authentication

Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.

Add OIDC for customer sign-in

Authentication

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Set up claims mapping for OIDC

Standards

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…