Grant permissions for application access management in Microsoft Entra ID
6 June 2025: act on Workload ID’s service-principal-less authentication retirement; other notable items are guidance updates
6 June was primarily a documentation-maintenance day rather than a broad Entra release: 208 of 213 records were updates, two were new, and no Message Center item was supplied. The clearest operational consequence is the Workload ID retirement notice, which requires action before 31 March 2026 to avoid application authentication failures. Other high-signal items are revised Security Copilot Conditional Access guidance, macOS passwordless capability documentation, Global Secure Access recovery guidance, and an Entitlement Management Dynamic Approval setup clarification. The evidence does not establish a preview, general availability release, or tenant-wide behavior change for those items.
- Workload ID: service-principal-less authentication is on a retirement path
Workload ID · Authentication
The updated “Retire Service Principal Less Authentication” guidance gives a concrete deadline: administrators must act before 31 March 2026 or applications may experience authentication failure. This is an explicit retirement and application-owner action item, not a routine documentation edit.
- Security Copilot: Conditional Access optimization guidance is expanded
Security Copilot · Conditional Access
The updated Microsoft Entra Conditional Access optimization-agent article says the agent recommends policies and changes intended to help protect all users, using best practices aligned with Zero Trust and Microsoft’s learnings. This record is updated guidance, not evidence that the capability newly entered preview or general availability.
- Entra ID passwordless guidance documents Platform Credential for macOS
Entra ID · Authentication
The revised passwordless article describes users configuring Touch ID to unlock a macOS device, with phish-resistant credentials based on Windows Hello for Business technology and integration with the Secure Enclave. It documents capability behavior but does not identify a launch or a change to tenant defaults.
- Global Secure Access break-glass recovery is documented with a PowerShell sample
Global Secure Access · Conditional Access
The updated sample covers recovery from a Global Secure Access break-glass scenario by re-enabling Conditional Access policies that were disabled. This is operational security and recovery guidance, not evidence of a Global Secure Access behavior change or new availability stage.
- ID Governance Dynamic Approval guidance calls out a Logic App edit
ID Governance · Governance
The updated Entitlement Management Dynamic Approval article says that after the Azure Logic App receives the catalog’s access package assignment manager role, the Logic App must be edited to communicate with Microsoft Entra. This is a concrete setup clarification for that workflow, not evidence of a tenant-wide service change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
213 updates
Microsoft Entra ID
129 updatesUse Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Add an on-premises application for remote access through application proxy in Microsoft Entra ID.
UpdatedMicrosoft Entra ID has an application proxy service that enables users to access on-premises applications by signing in with their Microsoft Entra account. This tutorial shows you how to prepare your environment for use with application proxy. Then, it uses the Microsoft Entra admin center to add an on-premises application to your Microsoft Entra tenant.
How to publish on-premises ASP.NET applications that accept Active Directory Federation Services claims for secure remote access by your users.
Understand complex applications in Microsoft Entra application proxy.
Configure Sso
UpdatedUnderstand single sign-on with an on-premises app using application proxy.
Configure and manage custom domains in Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Learn about debugging issues that occur when configuring Microsoft Entra application proxy.
Covers the basics about how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Covers the basics about how to integrate on-premises SharePoint Server with Microsoft Entra application proxy.
How traffic distribution works with your application proxy deployment. Includes tips for how to optimize connector performance and use load balancing for back-end servers.
Covers how to provide single sign-on using Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Publish native client apps
UpdatedCovers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.
Covers how to configure application proxy with Remote Desktop Services (RDS)
Remove personal data from connectors installed on devices for Microsoft Entra application proxy.
Learn how to identify and resolve cross-origin resource sharing (CORS) issues in Microsoft Entra application proxy.
Learn how to redirect hard coded links for applications published with Microsoft Entra application proxy.
Learn how to use Wildcard applications in Microsoft Entra application proxy.
Covers how to work with existing on-premises proxy servers with Microsoft Entra ID.
This article lists all releases of Microsoft Entra Connect Provisioning Agent and describes new features and fixed issues.
Export a Microsoft Identity Manager connector for use with the Microsoft Entra ECMA Connector Host
UpdatedDescribes how to create and export a connector from MIM Sync to be used with the Microsoft Entra ECMA Connector Host.
This document describes how to configure Microsoft Entra ID to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer REST and SOAP APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer web services based APIs.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory.
This tutorial describes how to provision users from Microsoft Entra ID into a SQL database.
Preparing for Microsoft Entra provisioning to Active Directory Lightweight Directory Services
UpdatedThis document describes how to configure Microsoft Entra ID to provision users into Active Directory Lightweight Directory Services as an example of an LDAP directory.
Provisioning users into SQL based applications using the ECMA Connector host
Use partner driven integrations to provision accounts into all your applications.
When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
Learn how to use scoping filters to define attribute-based rules that determine which users or groups are provisioned in Microsoft Entra ID.
Learn how to export your Application Provisioning configuration and roll back to a known good state for disaster recovery in Microsoft Entra ID.
Expression Builder
UpdatedUnderstand how expression builder works with Application Provisioning in Microsoft Entra ID.
Find out when a specific user is able to access an app in Microsoft Entra Application Provisioning
UpdatedHow to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
How Provisioning Works
UpdatedUnderstand how Application Provisioning works in Microsoft Entra ID.
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID
Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
The Microsoft Entra provisioning service matches users in Microsoft Entra ID with users already in an application. In some cases, an application may have users that do not match with any in Microsoft Entra ID.
Learn how multitenant organizations identity provisioning and Microsoft 365 work together.
Learn how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and give them access to SAP ECC, SAP S/4HANA, and other apps.
Learn how to provision users on demand in Microsoft Entra ID.
Learn how to retrieve pronoun information from Workday
Learn which attributes from SuccessFactors are supported by SuccessFactors-HR driven provisioning in Microsoft Entra ID.
Technical deep dive into SAP SuccessFactors-HR driven provisioning for Microsoft Entra ID.
Learn how to override the default behavior of deprovisioning out of scope users in Microsoft Entra ID.
Learn about attribute mappings for Software as a Service (SaaS) apps in Microsoft Entra Application Provisioning. Learn what attributes are and how you can modify them to address your business needs.
Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
When configuring user provisioning with Microsoft Entra ID and SaaS apps, use the directory extension feature to add source attributes that aren't synchronized by default.
Workday Attribute Reference
UpdatedLearn which attributes that you can fetch from Workday using XPATH queries in Microsoft Entra ID.
App consent permissions for custom Microsoft Entra roles in the Microsoft Entra admin center, PowerShell, or Graph API.
Enterprise app permissions for custom Microsoft Entra roles in the Microsoft Entra admin center, PowerShell, or Graph API.
Assign Microsoft Entra roles
UpdatedLearn how to assign Microsoft Entra roles to users and groups at tenant, application registration, administrative unit scopes using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
Learn how to create a custom role to manage access to Microsoft Entra resources using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API
Learn how to a role-assignable group in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
Group management permissions for Microsoft Entra custom roles in the Microsoft Entra admin center, PowerShell, or Microsoft Graph API.
Remove role assignments in Microsoft Entra ID using the Microsoft Entra admin center, Microsoft Graph PowerShell, or Microsoft Graph API.
User management permissions for Microsoft Entra custom roles in the Microsoft Entra admin center, PowerShell, or Microsoft Graph API.
Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
Learn how to configure a multitenant organization in Microsoft Entra ID using Microsoft Graph PowerShell or Microsoft Graph API.
Learn how to configure multitenant organization policy templates in Microsoft Entra ID using the Microsoft Graph API.
Use Microsoft Entra groups to simplify role assignment management in Microsoft Entra ID.
Learn about protected actions in Microsoft Entra ID.
Describes overview of HR driven provisioning.
Copilot in Microsoft Entra
Updated**Applies to:** Microsoft Entra 
Learn about the multitenant organization scenario and capabilities in Microsoft Entra ID.
Learn how to use Microsoft Entra application proxy connectors.
Learn about cross-tenant synchronization in Microsoft Entra ID.
Learn about multitenant organizations in Microsoft Entra ID and Microsoft 365.
An introduction to how you can use Microsoft Entra ID to automatically provision, deprovision, and continuously update user accounts across multiple third-party applications.
A Microsoft Entra documentation page was updated: Copilot Entra Recommendations.
author: justinha
Authentication Passwordless
UpdatedPlatform Credential for macOS allows users to go passwordless by configuring Touch ID to unlock the device, and uses phish-resistant credentials, based on Windows Hello for Business technology. This saves customer organizations money by removing the need for security keys and advances Zero Trust objectives using integration with the Secure Enclave.
Learn how to provide single sign-on (SSO) for on-premises applications that are secured with Security Assertion Markup Language (SAML) authentication. Provide remote access to on-premises apps with application proxy.
What Is App Proxy
UpdatedUnderstand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedLearn how to provide single sign-on for on-premises applications that are secured with header-based authentication.
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
Learn how to resolve common access issues with Microsoft Entra application proxy applications.
Turn on single sign-on for your published on-premises applications with Microsoft Entra application proxy in the Microsoft Entra admin center.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Configure User Consent
Updated- A user account. If you don't already have one, you can [create an account for free](https://azure.microsoft.com/free/?WT.mc_id=A261C142F).
Mysdworxcom Tutorial
Updated* Enable your users to be automatically signed-in to my.sdworx.com with their Microsoft Entra accounts.
Use administrative units for more granular delegation of permissions in Microsoft Entra ID.
Prerequisites to use PowerShell or Graph Explorer for Microsoft Entra roles.
Use restricted management administrative units for more sensitive resources in Microsoft Entra ID.
Learn about the limitations when you work with multitenant organizations in Microsoft Entra ID.
Learn about multitenant organization optional policy templates in Microsoft Entra ID.
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
Learn how to provide security operations analysts access to resources across tenants.
Covers security considerations for using Microsoft Entra application proxy
Learn how to add, test, or remove protected actions in Microsoft Entra ID.
This article describes how to use emergency access accounts to help prevent being inadvertently locked out of your Microsoft Entra organization.
Ensure that your organization's administrative access and administrator accounts are secure. For system architects and IT pros who configure Microsoft Entra ID, Azure, and Microsoft Online Services.
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
Learn how to integrate an on premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
Scim Graph Scenarios
UpdatedUsing SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.
Scim Validator Tutorial
UpdatedThis tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.
Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.
Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
How to troubleshoot common issues faced when configuring user provisioning to an application already listed in the Microsoft Entra application gallery.
Presents an overview of on-premises application provisioning architecture.
Conceptual Deployment Plan
UpdatedAn end-to-end guide for planning the deployment of application proxy within your organization
Find content, API references, and audit and monitoring references related to role-based access control (RBAC) for Microsoft 365 and other services
Covers network topology considerations when using Microsoft Entra application proxy.
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
Microsoft Entra ID Governance
4 updatesCopilot Entra Access Reviews
RemovedA Microsoft Entra documentation page was updated: Copilot Entra Access Reviews.
A Microsoft Entra documentation page was updated: Copilot Entra Entitlement Management.
Migrate From Sap Idm
UpdatedOrganizations that have SAP SuccessFactors could use SAP IDM to [bring in employee data](https://help.sap.com/docs/SAP_IDENTITY_MANAGEMENT/4773a9ae1296411a9d5c24873a8d418c/4c54e007ab414f7da3854952cad00221.html) from SAP SuccessFactors. Those organizations with SAP SuccessFactors can easily migrate to bring identities for employees [from SuccessFactors into Microsoft Entra ID](~/identity/saas-apps/sap-successfactors-inbound-provisioning-cloud-only-tutorial.md) or [from SuccessFactors into on-premises Active Directory](~/identity/saas-apps/sap-successfactors-inbound-provisioning-tutorial.md), by using Microsoft Entra ID connectors. The connectors support the following scenarios:
With the Azure Logic App given the access package assignment manager role for the catalog, you must now go to logic app to edit it to communicate with Microsoft Entra. To do this, you'd do the following steps:
Microsoft Entra External ID
6 updatesLearn how to configure cross-tenant synchronization in Microsoft Entra ID using the Microsoft Entra admin center.
Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
Learn how to map directory extensions in cross-tenant synchronization using the Microsoft Entra admin center.
Learn about topologies for cross-tenant synchronization in Microsoft Entra ID.
Cross Tenant Access Overview
Updated- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.
A Microsoft Entra documentation page was updated: Configure cross-tenant synchronization using PowerShell or Microsoft Graph API.
Microsoft Entra Internet Access
8 updatesLearn how to configure web content filtering in Microsoft Entra Internet Access.
Data Storage And Privacy
UpdatedGlobal Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Points Of Presence
UpdatedGlobal Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
Clients
UpdatedLearn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Internet Access
UpdatedLearn about how Microsoft Entra Internet Access secures access to the Internet.
PowerShell examples for use in a Microsoft Entra Internet Access break glass scenario.
Event Enrichment Logs
UpdatedGlobal Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.
Microsoft Entra Private Access
11 updatesConfigure Connectors
UpdatedLearn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Configure Quick Access
UpdatedLearn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
author: kenwith
Covers how to provide single sign-on using Kerberos with Microsoft Entra Private Access.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
Connector Groups
UpdatedLearn how Microsoft Entra private network connector groups work and how they're used by Microsoft Entra Private Access and application proxy.
Connectors
UpdatedLearn how Microsoft Entra private network connectors work and how they're used by Microsoft Entra Private Access and application proxy.
Private Access
UpdatedLearn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Configure Per App Access
UpdatedLearn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Microsoft Entra Verified ID
1 updateEntra Admin Center
Updated* [Credentials](~/verified-id/verifiable-credentials-configure-tenant-quick.md)
Microsoft Entra Workload ID
2 updatesYou must act **before March 31, 2026**, to avoid authentication failure of applications.
Jason starts his assessment and signs in to [Microsoft Security Copilot](https://securitycopilot.microsoft.com/) or the Microsoft Entra admin center. In order to view application and service principal details, he signs in as at least a [Security Reader](/entra/identity/role-based-access-control/permissions-reference#security-reader) and needs an [Microsoft Entra role assignment](../identity/role-based-access-control/permissions-reference.md) of Application Administrator, Cloud Application Administrator, or similar Microsoft Entra administrator role that has permissions to manage application/workload identities in Microsoft Entra.
Microsoft Entra Global Secure Access
46 updatesThis article lists all releases of Microsoft Entra private network connector and describes new features and fixed issues.
author: kenwith
Learn how to assign a remote network to a traffic forwarding profile for Global Secure Access.
Compliant Network
Updatedauthor: kenwith
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
List Remote Networks
UpdatedLearn how to list remote networks for Global Secure Access.
Manage Microsoft Profile
UpdatedLearn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.
Manage Remote Networks
UpdatedLearn how to update and delete remote networks for Global Secure Access.
Learn how to roll out traffic forwarding profiles to users and groups with Global Secure Access
PowerShell example that gets the Auth Token for registering your Microsoft Entra private network connector through Azure, AWS, or GCP Marketplaces.
Use these PowerShell samples for Global Secure Access.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Quickstart Install Client
UpdatedLearn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
Quickstart Per App Access
UpdatedLearn how to configure per-app access to private resources in Global Secure Access.
Quickstart Quick Access
UpdatedLearn how to configure Quick Access to private resources in Global Secure Access.
Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.
Role Based Permissions
UpdatedLearn about the built-in administrator roles you can assign to manage Global Secure Access permissions.
Covers how to perform an unattended installation of the Microsoft Entra private network connector.
Simulate Remote Network
Updatedauthor: kenwith
Source Ip Restoration
Updatedauthor: kenwith
author: kenwith
author: kenwith
Global Secure Access Web content filtering categories
Zscaler Coexistence
Updatedauthor: kenwith
Cisco Coexistence
UpdatedMicrosoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
Netskope Coexistence
UpdatedMicrosoft and Netskope’s Security Service Edge (SSE) coexistence solution guide.
What Is Global Secure Access
UpdatedLearn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Learn about the available Global Secure Access logs and monitoring options.
Netskope Integration
UpdatedA comprehensive guide for configuring and testing the integration between Microsoft's and Netskope's Secure Access Service Edge (SASE) solutions.
Partner Ecosystems Overview
UpdatedLearn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
Remote Network Connectivity
UpdatedLearn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.
Traffic Dashboard
UpdatedMonitor the health and status of your network traffic with the Global Secure Access dashboard.
Traffic Forwarding
UpdatedLearn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.
Access Audit Logs
UpdatedLearn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
View Traffic Logs
UpdatedLearn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
Remote Network Health Logs
UpdatedLearn how to check the health of your remote networks with the Global Secure Access remote network health logs.
Use Workbooks
UpdatedWorkbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
View Deployment Logs
Updatedauthor: kenwith
View Enriched Logs
UpdatedLearn how to use enriched Microsoft 365 logs for Global Secure Access.
PowerShell examples that re-enable any Conditional Access policies that were disabled in a break glass scenario.
Quickstart Remote Network
UpdatedLearn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
Universal Conditional Access
Updatedauthor: kenwith
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
Troubleshoot problems installing the Microsoft Entra private network connector.
Secure private application access with Privileged Identity Management (PIM) and Global Secure Access
UpdatedLearn how to secure highly valued private application access with Privileged Identity Management (PIM) and Global Secure Access
Palo Alto Coexistence
UpdatedMicrosoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Security Copilot + Entra
6 updatesLearn how to use Microsoft Security Copilot with Microsoft Entra identity scenarios
Learn how to use Microsoft Security Copilot in the Microsoft Entra admin center for identity and security scenarios.
Microsoft Entra agents work seamlessly with [Microsoft Security Copilot](/copilot/security/microsoft-security-copilot). Microsoft Security Copilot agents automate repetitive tasks and reduce manual workloads. They enhance security and IT operations across cloud, data security and privacy, identity, and network security. These agents handle high-volume, time-consuming tasks by pairing data and code with an AI language model. They respond to user requests and system events, helping teams work more efficiently and focus on higher-impact tasks.
ms.service: entra-id
The Conditional Access optimization agent helps you ensure all users are protected by policy. It recommends policies and changes based on best practices aligned with [Zero Trust](/security/zero-trust/deploy/identity) and Microsoft's learnings.
- bb3d68c2-d09e-4455-94a0-e323996dbaa3 - Security Copilot API
