πŸ“‹ Microsoft Entra Documentation Changes

Daily summary for changes since July 28th 2026, 8:12 PM PDT

Report generated on July 29th 2026, 8:12 PM PDT

πŸ“Š Summary

24
Total Commits
3
New Files
12
Modified Files
0
Deleted Files
12
Contributors

πŸ†• New Documentation Files

+134 lines added
Commit: Add workload identity immutable subject articles (#13956)
+106 lines added
Commit: Add workload identity immutable subject articles (#13956)
+83 lines added
Commit: akhil potturi/tenant governance drilldown docs (#13860)

πŸ“ Modified Documentation Files

+53 / -29 lines changed
Commit: Update Tenant Governance GDAP relationship docs (#13934)
Changes:
Before
After
---
title: Cross-tenant delegated administration
titleSuffix: Microsoft Entra ID Governance
description: Learn about cross-tenant delegated administration and how it enables centralized management across tenants in Microsoft Entra
ms.topic: concept-article
ms.date: 03/10/2026
---
 
<!-- source: Cross-tenant delegated administration.docx -->
 
# Cross-tenant delegated administration
 
Cross-tenant delegated administration is a capability within Tenant Governance that enables administrators to monitor and manage multiple tenants using accounts from a central governing tenant. Administrators don't need to create local accounts or business-to-business (B2B) guest accounts in every governed tenant. This capability uses granular delegated admin privileges (GDAP) technology to provide secure, least-privileged access across tenant boundaries.
 
Before you can use cross-tenant delegated administration, you must first create a governance relationship between the governing tenant and each governed tenant. The governance relationship establishes the trust boundary. It also defines the delegated administration policies that control which roles and permissions are available to governing tenant administrators.
 
Cross-tenant delegated administration also gives governed tenants full visibility into governing tenant admin activity within their environment. The governed tenant's sign-in and audit logs capture all actions that delegated administrators perform, ensuring that governed tenant stakeholders can independently monitor, review, and audit administrative operations.
 
## How cross-tenant delegated administration works
 
---
title: Cross-tenant delegated administration
titleSuffix: Microsoft Entra ID Governance
description: Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.
ms.topic: concept-article
ms.date: 07/27/2026
ai-usage: ai-assisted
---
 
<!-- source: Cross-tenant delegated administration - GDAP documentation draft.md -->
 
# Cross-tenant delegated administration
 
Cross-tenant delegated administration is a capability in Tenant Governance that enables administrators in one tenant to manage another tenant by using their home tenant credentials. Administrators don't need local accounts or business-to-business (B2B) guest accounts in every tenant. This capability uses granular delegated admin privileges (GDAP) technology to provide delegated, least-privileged administration and access across tenant boundaries.
 
This article explains the GDAP-based permission model that Tenant Governance and other Microsoft services use. It serves as the central reference for customers, partners, and Microsoft workloads that expose delegated administration capabilities through their own products and services.
 
## How the permission model works
 
Cross-tenant delegated administration has two permission layers:
Modified by Alexander Pavlovsky on Jul 29, 2026 7:05 PM
πŸ“– View on learn.microsoft.com
+9 / -50 lines changed
Commit: Update how-to-universal-tenant-restrictions.md (#13959)
Changes:
Before
After
title: Global Secure Access and Universal Tenant Restrictions
description: Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
ms.topic: how-to
ms.date: 04/03/2026
ms.author: alexpav
ms.reviewer: dhruvinrshah
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
---
 
# Turn on universal tenant restrictions
 
## Overview
 
Universal tenant restrictions enhance the functionality of [tenant restrictions v2](https://aka.ms/tenant-restrictions-enforcement). They use Global Secure Access to tag all traffic no matter the operating system, browser, or device form factor. They allow support for both client and remote network connectivity.
 
Administrators no longer have to manage proxy server configurations or complex network configurations. They can apply tenant restrictions v2 on any platform by using the Global Secure Access client or remote networks.
 
When you enable universal tenant restrictions, Global Secure Access adds policy information for tenant restrictions v2 to the authentication plane's network traffic. This traffic is from Microsoft Entra ID and Microsoft Graph. As a result, users who use devices and networks in your organization must use only authorized external tenants. This restriction helps prevent data exfiltration for any application integrated with your Microsoft Entra ID tenant through single sign-on (SSO).
 
title: Global Secure Access and Universal Tenant Restrictions
description: Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
ms.topic: how-to
ms.date: 07/29/2026
ms.author: alexpav
ms.reviewer: dhruvinrshah
ai-usage: ai-assisted
ms.custom: sfi-image-nochange
---
 
# Turn on Universal Tenant Restrictions
 
## Overview
 
Universal Tenant Restrictions (UTR) enhance the functionality of [tenant restrictions v2 (TRv2)](https://aka.ms/tenant-restrictions-enforcement). UTR applies tenant restrictions policies to any devices with the GSA client or on the GSA Remote Network, without having to steer network traffic through company-managed proxy service.
 
When you enable UTR, Microsoft Entra ID tenant restrictions policy is applied to all applications protected by Entra ID. Users on your devices with GSA or GSA Remote Networks can only sign in to tenants and applications authorized in your TRv2 policy.
 
## Prerequisites
 
+36 / -8 lines changed
Commit: Update Tenant Governance GDAP relationship docs (#13934)
Changes:
Before
After
titleSuffix: Microsoft Entra ID Governance
description: Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
ms.topic: how-to
ms.date: 03/10/2026
---
 
# Use cross-tenant delegated administration
 
## Sign in to a governed tenant as a delegated administrator
 
After the governance relationship is active and GDAP role assignments are in place, members of the configured security group can sign in to the governed tenant.
 
1. Confirm that your account is a member of a security group in the governing tenant that is assigned roles in the governance policy template.
 
1. Open a supported admin portal URL and append the domain or tenant ID of the governed tenant. For a list of supported portals and workloads, see [GDAP supported workloads](/partner-center/customers/gdap-supported-workloads). For example:
 
`https://entra.microsoft.com/{governed-tenant-domain-or-id}`
 
1. Sign in with your governing tenant credentials.
 
titleSuffix: Microsoft Entra ID Governance
description: Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
ms.topic: how-to
ms.date: 07/27/2026
ai-usage: ai-assisted
---
 
# Use cross-tenant delegated administration
 
## Sign in to a governed tenant as a delegated administrator
 
After the governance relationship is active and GDAP role assignments are in place, members of the configured security group can sign in to the governed tenant. Confirm that your account is a member of a security group in the governing tenant that's assigned roles in the governance policy template.
 
You can sign in to a governed tenant in two ways:
 
- From the **Governed tenants** page in the Microsoft Entra admin center.
- By opening a supported admin portal URL directly.
 
### Sign in from the Microsoft Entra admin center
 
Modified by Kristina Smith on Jul 29, 2026 7:17 PM
πŸ“– View on learn.microsoft.com
+28 / -11 lines changed
Commit: docs: expand dynamic attributes table in lifecycle-workflow-tasks
Changes:
Before
After
 
### Dynamic attributes within email
 
With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. The list of dynamic attributes that can be included are as follows:
 
 
|Attribute |Definition |
|---------|---------|
|userDisplayName | The user’s display name. |
|userEmployeeHireDate | The user’s employee hire date. |
|userEmployeeLeaveDateTime | The user’s employee leave date and time. |
|managerDisplayName | The display name of the user’s manager. |
|temporaryAccessPass | The generated Temporary Access Pass. Only available with the **Generate TAP And Send Email** task. |
|userPrincipalName | The user’s userPrincipalName. |
|managerEmail | The manager’s email. |
|userSurname | User’s family name. |
|userGivenName | User’s first name. |
 
 
> [!NOTE]
 
### Dynamic attributes within email
 
With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:
 
**User attributes**
 
|Attribute |Definition |
|---------|---------|
|`{{user.displayName}}` | The user's display name. |
|`{{user.userPrincipalName}}` | The user's user principal name. |
|`{{user.employeeHireDate}}` | The user's employee hire date. |
|`{{user.employeeLeaveDateTime}}` | The user's employee leave date and time. |
|`{{user.createdDateTime}}` | The date and time the user was created. |
|`{{user.employeeType}}` | The user's employee type. |
|`{{user.department}}` | The user's department. |
|`{{user.companyName}}` | The user's company name. |
|`{{user.jobTitle}}` | The user's job title. |
|`{{temporaryAccessPass}}` | The generated Temporary Access Pass. Only available with the **Generate TAP And Send Email** task. |
 
+28 / -2 lines changed
Commit: akhil potturi/tenant governance drilldown docs (#13860)
Changes:
Before
After
titleSuffix: Microsoft Entra ID Governance
description: Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
ms.topic: how-to
ms.date: 03/05/2026
---
 
# Interpret tenant discovery data
- **How many related tenants exist**
- **Which signals caused discovery**
- **Whether the tenant appears active or historical**
 
This step establishes scope, not judgment.
 
 
A tenant with recent, increasing activity typically warrants closer scrutiny than one with only historical, initial signals. For example, a tenant with active B2B guest users, active administrative sign-ins, and a shared billing account represents a stronger operational relationship. Compare this to a tenant surfaced only through historical B2B guest user presence captured at the time of discovery.
 
## Step 4: Classify the related tenant
 
Based on signals and metrics, classify each related tenant into one of three practical categories.
 
titleSuffix: Microsoft Entra ID Governance
description: Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
ms.topic: how-to
ms.date: 07/14/2026
---
 
# Interpret tenant discovery data
- **How many related tenants exist**
- **Which signals caused discovery**
- **Whether the tenant appears active or historical**
- **Whether the tenant is Microsoft managed** (a Microsoft-owned infrastructure tenant)
 
This step establishes scope, not judgment.
 
 
A tenant with recent, increasing activity typically warrants closer scrutiny than one with only historical, initial signals. For example, a tenant with active B2B guest users, active administrative sign-ins, and a shared billing account represents a stronger operational relationship. Compare this to a tenant surfaced only through historical B2B guest user presence captured at the time of discovery.
 
## Step 4: Drill into a signal to see the underlying entities
 
Discovery metrics are aggregated to orders of magnitude. For example, a returned value of 100 represents an actual value between 100 and 999. To move from a high-level count to specific evidence, drill into a signal to see the underlying users or applications that contribute to it.
Modified by marinasanchezz1 on Jul 29, 2026 6:42 PM
πŸ“– View on learn.microsoft.com
+19 / -2 lines changed
Commit: Add passkeyDynamicMigration opt-out details to SMS/voice retirement FAQ
Changes:
Before
After
title: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
description: Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
ms.topic: how-to
ms.date: 06/10/2026
author: marinasanchezz1
ms.author: marisanchez
ai-usage: ai-assisted
 
### What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?
 
A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods. API support and information for opting out will be available starting August 1, 2026.
 
However, if your tenant still has users enabled for Microsoft-managed SMS or voice on February 1, 2027, and you have not configured a customer-managed telecom provider through the Security Store, those users will no longer be able to use SMS or voice to satisfy MFA requirements and continue signing in.
 
 
 
 
 
 
 
title: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
description: Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
ms.topic: how-to
ms.date: 07/29/2026
author: marinasanchezz1
ms.author: marisanchez
ai-usage: ai-assisted
 
### What if I have different plans for my tenant than enabling passkeys for SMS/voice users (such as configuring a customer configured telecom provider or migrating users to another authentication method)?
 
A temporary opt-out will be available for the September 1, 2026 through February 1, 2027 changes. This allows you to delay passkey and Registration Campaign enablement while you complete transition activities, such as configuring customer-managed telecom providers or migrating to other authentication methods.
 
To opt out, update your authentication methods policy using Microsoft Graph and set the `passkeyDynamicMigration` property to `true`.
 
**Request**
 
```http
PATCH https://graph.microsoft.com/beta/policies/authenticationmethodspolicy
Content-Type: application/json
 
Modified by Kristina Smith on Jul 29, 2026 7:13 PM
πŸ“– View on learn.microsoft.com
+15 / -4 lines changed
Commit: docs: expand dynamic attribute support in lifecycle workflow custom emails
Changes:
Before
After
 
### Format attributes within customized emails
 
To further personalize customized emails, you can take advantage of dynamic attributes. By placing dynamic attributes in your emails, you can specifically call out values such as a user's name, their generated Temporary Access Pass, or even their manager's email.
 
To use dynamic attributes within your customized emails, you must follow formatting rules. The proper format is:
 
`{{dynamic attribute}}`
 
The following screenshot is an example of the proper format for dynamic attributes within a customized email:
 
When you're typing a dynamic attribute, the email is written in the following way:
 
```html
Welcome to the team, {{userGivenName}}
 
We're excited to have you join our growing team and look forward to a successful and memorable journey together.
 
 
```
 
### Format attributes within customized emails
 
In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.
 
To use dynamic attributes within your customized emails, you must follow formatting rules. The proper format for user attributes is:
 
`{{user.graphPropertyName}}`
 
The following screenshot is an example of the proper format for dynamic attributes within a customized email:
 
When you're typing a dynamic attribute, the email is written in the following way:
 
```html
Welcome to the team, {{user.displayName}}
 
We're excited to have you join our growing team and look forward to a successful and memorable journey together.
 
 
```
+11 / -4 lines changed
Commit: Update OIDC federation known limitations
Changes:
Before
After
title: Add OIDC for customer sign-in
description: Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
ms.topic: how-to
ms.date: 09/15/2025
ms.reviewer: brozbab
ms.custom: it-pro, msecd-doc-authoring-1012
 
#customer intent: As a developer, devops, or it administrator, I want to learn how to add an OpenID Connect identity provider for my external tenant.
---
 
## Known limitations
 
Conditional Access policies that require MFA registration don't function as expected when an External ID tenant is federated with an external identity provider (IdP). This can result in one of the following behaviors:
 
- Users are unable to register an MFA method and can't complete sign-in, often encountering an error.
- Users aren't redirected to the MFA registration (sign-up) flow during sign-in as expected.
 
## Related content
 
 
title: Add OIDC for customer sign-in
description: Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
ms.topic: how-to
ms.date: 07/29/2026
ms.reviewer: brozbab
ms.custom: it-pro, msecd-doc-authoring-1012
ai-usage: ai-assisted
 
#customer intent: As a developer, devops, or it administrator, I want to learn how to add an OpenID Connect identity provider for my external tenant.
---
 
## Known limitations
 
### Issuer URI updates
 
When you update the Issuer URI for an existing OIDC identity provider (IdP), the updated configuration might not automatically take effect in user flows. As a result, the IdP sign-in option might not appear on the sign-in page.
 
To apply the change:
 
1. Disable the IdP in the user flow.
Modified by Akhil Potturi on Jul 29, 2026 2:15 PM
πŸ“– View on learn.microsoft.com
+9 / -1 lines changed
Commit: akhil potturi/tenant governance drilldown docs (#13860)
Changes:
Before
After
titleSuffix: Microsoft Entra ID Governance
description: Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
ms.topic: concept-article
ms.date: 03/10/2026
---
 
# Related tenants in Tenant Governance
 
These metrics describe how tenants are connected. They don't assign qualitative scores or imply that every related tenant must be governed. Instead, they provide the evidence needed to determine whether governance action is warranted.
 
## Why related tenants matter
 
Related tenants provide value in several key areas, from surfacing unsanctioned tenants to enabling informed governance decisions.
 
 
 
 
 
 
 
titleSuffix: Microsoft Entra ID Governance
description: Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
ms.topic: concept-article
ms.date: 07/14/2026
---
 
# Related tenants in Tenant Governance
 
These metrics describe how tenants are connected. They don't assign qualitative scores or imply that every related tenant must be governed. Instead, they provide the evidence needed to determine whether governance action is warranted.
 
## Microsoft-managed tenants
 
Some discovered related tenants are Microsoft-owned infrastructure tenants rather than tenants that belong to your organization or your partners. Tenant Governance identifies these tenants and flags them as **Microsoft managed**.
 
Microsoft-managed tenants appear because routine Microsoft cloud operations create observable cross-tenant activity. They're expected and generally require no governance action. The **Microsoft managed** indicator helps you quickly recognize and set aside this class of related tenant so you can focus on tenants that need attention.
 
The Microsoft managed indicator is available to administrators who have a Tenant Governance license and permission to read related tenants.
 
## Why related tenants matter
 
Modified by copilot-swe-agent[bot] on Jul 29, 2026 1:31 PM
πŸ“– View on learn.microsoft.com
+0 / -5 lines changed
Commit: Remove obsolete KB5070773 Windows Server 2025 callout
Changes:
Before
After
 
- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
 
 
> [!IMPORTANT]
> There is a known issue on Windows Server 2025 that can cause Microsoft Entra Cloud Sync to encounter synchronization problems. If you're running Windows Server 2025, make sure you have installed [October 20, 2025 - KB5070773](https://support.microsoft.com/topic/october-20-2025-kb5070773-os-build-26100-6901-out-of-band-f8effaa1-1c73-41e5-bcb3-e58a46c7601e) update, or later. After installing this update, restart the server for the changes to take effect.
 
- This server should be a tier 0 server based on the [Active Directory administrative tier model](/security/privileged-access-workstations/privileged-access-access-model). Installing the agent on a domain controller is supported. For more information, see [Harden your Microsoft Entra provisioning agent server](#harden-your-microsoft-entra-provisioning-agent-server)
 
- The Active Directory Schema is required to have the attribute msDS-ExternalDirectoryObjectId, which is available in Windows Server 2016 and later.
 
- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
 
- This server should be a tier 0 server based on the [Active Directory administrative tier model](/security/privileged-access-workstations/privileged-access-access-model). Installing the agent on a domain controller is supported. For more information, see [Harden your Microsoft Entra provisioning agent server](#harden-your-microsoft-entra-provisioning-agent-server)
 
- The Active Directory Schema is required to have the attribute msDS-ExternalDirectoryObjectId, which is available in Windows Server 2016 and later.
 
 
 
 
 
+1 / -1 lines changed
Commit: Update Tenant Governance GDAP relationship docs (#13934)
Changes:
Before
After
 
- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
 
Each group can have multiple role assignments, and each policy template can have multiple groups defined. When you create the governance relationship, Tenant Governance creates [granular delegated admin privileges (GDAP)](/partner-center/customers/gdap-introduction) role assignments in the governed tenant.
 
## Multitenant application configuration
 
 
- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
 
Each group can have multiple role assignments, and each policy template can have multiple groups defined. When you create the governance relationship, Tenant Governance creates [granular delegated admin privileges (GDAP)](cross-tenant-delegated-administration.md) role assignments in the governed tenant.
 
## Multitenant application configuration
 
Modified by Alexander Pavlovsky on Jul 29, 2026 7:05 PM
πŸ“– View on learn.microsoft.com
+0 / -2 lines changed
Commit: Update how-to-universal-tenant-restrictions.md (#13959)
Changes:
Before
After
 
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
 
1. [Validate Universal Tenant Restrictions enforcement](../global-secure-access/how-to-universal-tenant-restrictions.md#validate-tenant-restrictions-enforcement).
 
## Troubleshoot
 
If you have problems with your PoC, these articles can help you with troubleshooting, logging, and monitoring:
 
1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
 
## Troubleshoot
 
If you have problems with your PoC, these articles can help you with troubleshooting, logging, and monitoring: