Cross-product topic

Standards

A cross-product view of Microsoft Entra changes related to Standards.

Latest Standards changes

Direct Federation

Standards

The External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.

Microsoft Accounts Federation Customers

Standards

The article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.

Saml Ws Federation Self Service Sign Up

Standards

The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.

Validate Saml Single Sign On App Gallery

Standards

The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.

Validate Saml Single Sign On App Gallery

Standards

The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.

Validate User Provisioning App Gallery

Standards

The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.

Enable Scim Api

Standards

The permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.

Enable Scim Api

Standards

The permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.

Entra Id Scim Api Reference

Standards

The SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.

Entra Id Scim Api Reference

Standards

The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.

Entra Id Scim Api Reference

Standards

The reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.

Entra Id Scim Api Schema Documentation

Standards

The schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.

Publish App Gallery

Standards

The app gallery publishing documentation now refers to the required identifier as a Partner One ID and notes that it was formerly called the Microsoft Partner Network (MPN) ID.

Validate Saml Single Sign On App Gallery

Standards

The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”

Scim Validator Tutorial

Standards

The tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.

Entra Id Scim Api Reference

Standards

The SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.

Breaking Changes

Standards

The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.

Breaking Changes

Standards

The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.

Groups Settings V2 Cmdlets

Standards

The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.

SSO requirements for Microsoft Entra App Gallery

Standards

Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.

Breaking Changes

Standards

The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

Single Sign On Saml Protocol

Standards

The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.

Inbound Provisioning Api Concepts

Standards

The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.

Agent On Behalf Of Oauth Flow

Standards

The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.

Agent On Behalf Of Oauth Flow

Standards

The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.

Orgvue Tutorial

Standards

The tutorial replaces the Orgvue authentication and SAML callback URLs with orgvue-staging URLs and changes the Sign-on URL to include the application login path and domain parameter. It also clarifies that both Reply URL and Sign-on URL values are placeholders.

V2 Howto App Gallery Listing

Standards

- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)

App Manifest

Standards

Specifies whether this web app can request OAuth2.0 implicit flow ID tokens. The default is false. This flag is used for browser-based apps, like JavaScript single-page apps. We, however, discourage the use of implicit grant even in SPAs and recommend using the [authorization code flow](./v2-oauth2-auth-code-flow.md) with PKCE.

Enable Scim Api

Standards

- **Cost:** See [API call pricing](https://aka.ms/EntraSCIMAPIPricing).

Entra Id Scim Api Reference

Standards

Before you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).

Direct Federation

Standards

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Understand Microsoft's SSO model

Standards

Learn how Microsoft Entra ID implements single sign-on (SSO) as a centralized identity platform for both SAML and OpenID Connect protocols.

Direct Federation

Standards

1. On the **New SAML/WS-Fed IdP** page, enter the following:

Configurable Token Lifetimes

Standards

Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.

Configure the role claim

Standards

Learn how to configure the role claim issued in the SAML token for enterprise applications in Microsoft Entra ID.

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Adob…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML) so that I can streamline the user management process and ensure that users have the appropriate access to Adobe Identity Management (SAML)..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insi…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insightly SAML so that I can streamline the user management process and ensure that users have the appropriate access to Insightly SAML..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Klax…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Klaxoon SAML so that I can streamline the user management process and ensure that users have the appropriate access to Klaxoon SAML..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Lexm…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Lexmark Cloud Services (SAML) so that I can streamline the user management process and ensure that users have the appropriate access to Lexmark Cloud Services (SAML)..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Palo…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Palo Alto Networks SCIM Connector so that I can streamline the user management process and ensure that users have the appropriate access to Palo Alto Networks SCIM Connector..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Temp…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Templafy OpenID Connect so that I can streamline the user management process and ensure that users have the appropriate access to Templafy OpenID Connect..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Temp…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Templafy SAML2 so that I can streamline the user management process and ensure that users have the appropriate access to Templafy SAML2..

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Time…

Standards

A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Timeclock 365 SAML so that I can streamline the user management process and ensure that users have the appropriate access to Timeclock 365 SAML..

Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and OpenID Connect OAuth so that…

Standards

This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md) and [Configure OIDC SSO for custom (non-gallery) applications](~/identity/enterprise-apps/add-application-portal-setup-oidc-sso.md?#configure-oidc-sso-for-custom-non-gallery-applications).

Customize SAML token claims

Standards

Learn how to customize the claims issued by Microsoft identity platform in the SAML token for enterprise applications.

Direct Federation

Standards

Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.

Entra Id Federation Customers

Standards

Learn how to configure a Microsoft Entra ID tenant as an OpenID Connect identity provider in Microsoft Entra External ID, enabling users to sign in using their existing organizational accounts.

Microsoft Entra ID SCIM API

Standards

Build custom integrations to provision users and groups to Microsoft Entra ID using the System for Cross-domain Identity Management (SCIM) v2.0 protocol.

Microsoft Entra ID SCIM API schema documentation

Standards

This article provides a reference for SCIM schema attributes, including core user and group attributes, enterprise extensions, and Microsoft Entra-specific extensions, along with their mappings to Microsoft Entra ID properties.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…