Microsoft Entra External ID
Architecture

Gsa Poc Internet Access

In brief

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  1. Set up tenant restrictions v2. If your organization currently uses tenant restrictions v1, review the guide for migrating to tenant restrictions v2.

  2. Enable Global Secure Access signaling for tenant restrictionsEnable Universal Tenant Restrictions.

  3. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

  4. Validate Universal Tenant RestrictionsValidate Universal Tenant Restrictions enforcement.

Troubleshoot

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…