author: justinha
8 June 2025: Global Secure Access lockout guidance and a new Internet Access bypass sample stand out amid a documentation-heavy refresh
The supplied period is dominated by Microsoft Learn maintenance: 453 updates, 14 new items, no removals, and no Message Center notices. The clearest operational issue is a Global Secure Access tunnel-authorization limitation that can make a Conditional Access block on a forwarding profile lock users out of their machines. A new PowerShell sample provides an Internet Access bypass-rule pattern. Other notable updates cover Entra Health and Security Copilot SLA reporting, MFA health signals, and External ID custom sign-in domains. The supplied evidence identifies no specific preview, general-availability launch, retirement, or confirmed product behavior change.
- Security guidance: Global Secure Access forwarding-profile blocks can cause lockouts
Global Secure Access · Conditional Access
An updated Global Secure Access page states that tunnel-authorization limitations mean a Conditional Access policy blocking a forwarding profile can inadvertently prevent users from accessing anything on their machine. This is a configuration-risk clarification, not a new feature or retirement.
- New documentation sample: add an Internet Access custom bypass rule
Internet Access · General
A new PowerShell sample shows how to bypass a specified FQDN or IP address from being acquired by the GSA Client in the Internet Access forwarding profile. It is an implementation example, not evidence that a new service capability or availability change shipped.
- Updated scenario guidance: Security Copilot and Entra authentication SLA reporting
Security Copilot · Authentication
The updated Copilot Entra Security Scenarios page describes Microsoft Entra Health's monthly SLA Attainment look-back for core Microsoft Entra ID authentication availability and says Security Copilot interacts with the SLA through Microsoft Graph API. The record supports a documentation update, not a newly announced SLA or Copilot launch.
- Ordinary documentation update: Entra Health signals for MFA-required sign-ins
Entra ID · Authentication
An updated Entra ID page covers the Microsoft Entra Health signals and alerts for sign-ins that require Microsoft Entra MFA. The supplied evidence does not indicate that new alerts, settings, or policy behavior were introduced.
- Ordinary documentation update: External ID custom URL domains
External ID · Authentication
Updated External ID guidance covers setting up custom URL domains to personalize authentication sign-in endpoints for external customers and consumers of an app. No new rollout, changed behavior, or additional requirement is identified in the supplied record.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
467 updates
Microsoft Entra ID
272 updatesauthor: justinha
Migrate applications away from secret-based authentication to improve security and user experience.
Learn about the differences between the Microsoft Authentication Library (MSAL) and Azure AD Authentication Library (ADAL) and how to migrate to MSAL.
author: justinha
author: justinha
author: justinha
author: justinha
author: najshahid
author: justinha
author: najshahid
Deployment frequently asked questions (FAQs) for hybrid FIDO2 security keys in Microsoft Entra ID
Updatedauthor: justinha
author: justinha
author: justinha
Mfa Server Migration Utility
Updatedauthor: justinha
author: justinha
author: camilasinelli
author: justinha
Learn about the Microsoft Entra Health signals and alerts for sign-ins that require Microsoft Entra multifactor authentication
Learn about the Microsoft Entra Health signals and alerts for sign-ins to applications that use SAML authentication
Learn how to build a desktop app that calls web APIs to acquire a token for the app using integrated Windows authentication
author: justinha
author: inbarckMS
Authentication Passwordless
Updatedauthor: justinha
author: aanjusingh
author: inbarckms
author: justinha
author: vimrang
author: vimrang
author: vimrang
author: vimrang
author: justinha
author: vimrang
author: justinha
author: justinha
author: vimrang
author: justinha
author: justinha
author: justinha
author: gregkmsft
author: justinha
author: aanjusingh
author: justinha
author: aanjusingh
author: justinha
author: justinha
author: justinha
author: mepples21
Learn how to edit profile with multifactor authentication protection in your external-facing Node.js web app
Enforce Microsoft Entra multifactor authentication with legacy applications using app passwords
Updatedauthor: justinha
author: justinha
author: justinha
author: justinha
author: sopand
author: justinha
author: justinha
author: justinha
author: tilarso
author: justinha
author: justinha
author: justinha
Microsoft Entra user data collection for multifactor authentication and self-service password reset
Updatedauthor: justinha
Find out how to use native authentication APIs to authenticate users into your customer-facing apps with the external tenant.
Learn how apps that use native authentication notify Microsoft Entra about the authentication methods that they support.
Learn how to use native authentication Android and iOS SDK attribute builders to prepare built-in and custom attributes.
Learn how you can use web fallback to improve the resilience of your customer apps that use native authentication.
author: justinha
author: mepples21
author: mepples21
Learn how to configure a sample web app to edit user's profile. The edit profile operation requires a customer user to complete multifactor authentication (MFA)
Register Passkey
Updatedauthor: justinha
author: justinha
Register Passkey Mobile
Updatedauthor: justinha
author: brozbab
Learn how to secure remote access to VMs using Network Policy Server (NPS) and Microsoft Entra multifactor authentication with a Remote Desktop Services deployment in a Microsoft Entra Domain Services managed domain.
Learn how to set up your Node.js web application for profile editing with multifactor authentication protection in your external tenant
Learn how to set up a reverse proxy for a single-page app that calls native authentication API by using Azure Function App.
Sign In Passkey
Updatedauthor: justinha
author: justinha
Learn how to configure a sample React single-page app (SPA) that uses native authentication API to sign up users.
author: justinha
author: inbarckms
Learn how to acquire multiple access tokens and call an API in Android app by using native authentication.
Learn how to build a React single-page app that reset password for users in an external tenant by using native authentication.
Learn how to set up a CORS proxy server for single-page application that uses native authentication API.
Learn how to build a React single-page app that signs in users in a React single-page app into an external tenant by using native authentication.
Learn how to build a React single-page application that uses native authentication API to sign up users.
Learn how to build a Node.js CLI app that signs in users in an external tenant
Prepare an Angular single-page app (SPA) in a Microsoft Entra tenant to manage authentication and secure user access.
Sign in user in an Angular single-page app (SPA) in a Microsoft Entra tenant to manage authentication and secure user access.
Learn how to set up Azure Front Door as a reverse proxy in a production environment for a single-page app that uses native authentication.
Learn how to use client certificate instead of secrets for authentication in your Node.js web app
Use Custom Domain Url
UpdatedUse a custom domain to fully brand the authentication URL. From a user perspective, users remain on your domain during the authentication process, rather than being redirected to *ciamlogin.com* domain name.
In this quickstart, you learn how to implement authentication with a Node.js web app and the Microsoft Authentication Library (MSAL) for Node.js.
author: justinha
author: HULKsmashGithub
Howto Mfa Mfasettings
Updatedauthor: justinha
Mfa Data Residency
UpdatedMicrosoft Entra ID stores customer data in a geographical location based on the address an organization provides when subscribing to a Microsoft online service such as Microsoft 365 or Azure. For information on where your customer data is stored, see [Where your data is located](https://www.microsoft.com/trust-center/privacy/data-location) in the Microsoft Trust Center.
Fido2 Compatibility
Updatedauthor: justinha
Learn about the Microsoft Entra Health signals and alerts for sign-ins that require a compliant or managed device
author: justinha
Learn how to build a desktop app that calls web APIs to acquire a token for the app using username and password.
author: justinha
author: vimrang
Learn how and why to use fine-grained password policies to secure and control account passwords in a Domain Services managed domain.
author: justinha
author: justinha
author: efdake
author: justinha
author: justinha
In this tutorial, learn how to enable password hash synchronization using Microsoft Entra Connect to a Microsoft Entra Domain Services managed domain.
Feature Availability
Updatedauthor: justinha
author: justinha
Howto Mfa Adfs
Updatedauthor: justinha
Howto Mfa Nps Extension
Updatedauthor: justinha
Howto Mfa Nps Extension Vpn
Updatedauthor: justinha
Howto Mfa Reporting
Updatedauthor: justinha
Howto Mfa Userstates
Updatedauthor: justinha
author: justinha
author: justinha
author: justinha
Howto Password Smart Lockout
Updatedauthor: justinha
Howto Sspr Customization
Updatedauthor: justinha
Howto Sspr Reporting
Updatedauthor: justinha
Howto Sspr Windows
Updatedauthor: justinha
author: justinha
author: justinha
Learn about how to administer a Microsoft Entra Domain Services managed domain and the behavior of user accounts and passwords
Mfa Licensing
Updatedauthor: justinha
Mfa Regional Opt In
Updatedauthor: justinha
Mfa Registration Campaign
Updatedauthor: mjsantani
Mfa Telephony Fraud
Updatedauthor: aloom3
author: justinha
Password Ban Bad
Updatedauthor: justinha
Password Ban Bad On Premises
Updatedauthor: justinha
Learn how to prepare your external tenant to sign in users and call an API in your Node.js web application.
Learn how to configure a Node.js web app code sample to sign in users and call an API in an external tenant.
Learn how to authenticate users in a sample Node.js Command Line Interface (CLI) application in your external tenant
Web app quickstart that shows how to configure a sample web app that signs in employees in workforce tenant or customers in external tenant
Quickstart V2 Java Webapp
UpdatedIn this quickstart, you'll learn how to add sign-in with Microsoft to a Java web application by using OpenID Connect.
author: justinha
Learn how to disable weak ciphers, old protocols, and NTLM password hash synchronization for a Microsoft Entra Domain Services managed domain.
Set up node web app project that signs in users into customer facing app by in an external tenant or employees in a workforce tenant
Sspr Policy
Updatedauthor: justinha
Learn how to troubleshoot common problems when you try to domain-join a VM or connect an application to Microsoft Entra Domain Services and you can't connect or authenticate to the managed domain.
Learn how to troubleshoot common user sign-in problems and errors in Microsoft Entra Domain Services.
Troubleshoot Sspr Writeback
Updatedauthor: justinha
author: justinha
Tutorial: Add add sign-in in your Node/Express.js web app by using Microsoft identity platform
UpdatedLearn how to add sign-in in your Node.js web app with an external tenant or workforce tenant by using Microsoft identity platform.
In this tutorial, learn how to add Shared Device Mode support to an Android device using the Microsoft Authenticator App or Intune
Learn how to authenticate users in a Node.js CLI application registered in an external tenant
Two-way SMS unsupported
Updatedauthor: rhicock
Learn how to acquire an access token for calling an API in your own Node.js web application.
In this quickstart, you learn how an app implements Microsoft sign-in on an ASP.NET Core web app by using OpenID Connect
In this quickstart, you'll learn how to add sign-in with Microsoft to a Java web application by using OpenID Connect.
In this article, learn how to create and configure a Microsoft Entra Domain Services forest trust to an on-premises Active Directory Domain Services environment using Azure PowerShell.
author: shlipsey3
author: shlipsey3
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: shlipsey3
author: shlipsey3
author: HULKsmashGithub
Agent Optimization
Updatedauthor: MicrosoftGuyJFlo
Delegate By Task
Updated> [!div class="mx-tableFixed"]
Learn how to the SKU tier for a Microsoft Entra Domain Services managed domain if your business requirements change
Learn how to check fleet metrics of a Microsoft Entra Domain Services managed domain.
Learn how to check the health of a Microsoft Entra Domain Services managed domain and understand status messages.
Learn about some of the common scenarios and use-cases for Microsoft Entra Domain Services to provide value and meet business needs.
Learn how to configure an app's publisher domain to let users know where their information is being sent.
Learn how to create and manage a custom Organizational Unit (OU) in a Microsoft Entra Domain Services managed domain.
Learn how to disable, or delete, a Microsoft Entra Domain Services managed domain
Learn how to configure email notifications to alert you about issues in a Microsoft Entra Domain Services managed domain
Learn how to configure and enable Microsoft Entra Domain Services using an Azure Resource Manager template.
Learn how to configure and enable Microsoft Entra Domain Services using Microsoft Graph PowerShell and Azure PowerShell.
Feature Availability
Updatedauthor: justinha
author: kengaderdus
Learn how to create a group managed service account (gMSA) for use with Microsoft Entra Domain Services managed domains
How It Works Daemon App
Updatedauthor: kengaderdus
author: Dickson-Mwendia
include file
Learn how to retrieve data from Microsoft Entra Domain Services.
Learn how to configure and join a CoreOS virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to configure and join a Red Hat Enterprise Linux virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to configure and join a SUSE Linux Enterprise virtual machine to a Microsoft Entra Domain Services managed domain.
Join a Windows Server VM to a Microsoft Entra Domain Services managed domain | Microsoft Docs
UpdatedIn this tutorial, learn how to join a Windows Server virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to configure and join an Ubuntu Linux virtual machine to a Microsoft Entra Domain Services managed domain.
Learn how to enable resource-based Kerberos constrained delegation (KCD) in a Microsoft Entra Domain Services managed domain.
Known Limitations Include
Updatedauthor: HULKsmashGithub
Macos Psso
Updatedauthor: garrodonnell
author: garrodonnell
Learn how to install the DNS Server Tools to manage DNS and create conditional forwarders for a Microsoft Entra Domain Services managed domain.
Learn about some of the virtual network design considerations and resources used for connectivity when you run Microsoft Entra Domain Services.
Sample Daemon App Output
Updatedauthor: kengaderdus
Select Tenant Type Statement
Updatedauthor: kengaderdus
Learn about the different health states for a Microsoft Entra Domain Services managed domain and how to restore a suspended domain.
In this tutorial, you learn how to configure secure lightweight directory access protocol (LDAPS) for a Microsoft Entra Domain Services managed domain.
In this tutorial, you learn how to create and configure an Azure virtual network subnet or network peering for a Microsoft Entra Domain Services managed domain using the Microsoft Entra admin center.
Tutorial - Create a customized Microsoft Entra Domain Services managed domain | Microsoft Docs
UpdatedIn this tutorial, you learn how to create and configure a customized Microsoft Entra Domain Services managed domain and specify advanced configuration options using the Microsoft Entra admin center.
In this tutorial, you learn how to create and configure a Windows virtual machine that you use to administer Microsoft Entra Domain Services managed domain.
In this tutorial, you learn how to create and configure a Microsoft Entra Domain Services managed domain using the Microsoft Entra admin center.
Learn how to create and use replica sets in the Microsoft Entra admin center for service resiliency with Microsoft Entra Domain Services
Tutorial - Perform a disaster recovery drill in Microsoft Entra Domain Services | Microsoft Docs
UpdatedLearn how to perform a disaster recovery drill using replica sets in Microsoft Entra Domain Services
Tutorial Create Forest Trust
UpdatedLearn how to create a one-way outbound forest to an on-premises AD DS domain in the Microsoft Entra admin center for Microsoft Entra Domain Services
Learn how extract user data using an Angular single-page app (SPA).
Learn how to use Azure Resource Manager templates to join a new or existing Windows Server VM to a Microsoft Entra Domain Services managed domain.
In this quickstart, learn how a Universal Windows Platform (UWP) application can get an access token and call an API protected by Microsoft identity platform.
Learn how to build a daemon app that calls web APIs - app registration
Learn how to log errors and exceptions in MSAL.js
Describes how to mark an app as publisher verified. When an application is marked as publisher verified, it means that the publisher (application developer) verified the authenticity of their organization using a Cloud Partner Program (CPP) account that completed the verification process and associated this CPP account with that application registration.
Learn about the UserInfo endpoint on the Microsoft identity platform.
Learn about benefits, program requirements, and frequently asked questions in the publisher verification program for the Microsoft identity platform.
A daemon app code sample quickstart that shows how to acquire an access token to call a protected web API by using Microsoft identity platform
Quickstart V2 Java Daemon
UpdatedIn this quickstart, you learn how a Java app can get an access token and call an API protected by Microsoft identity platform endpoint, using the app's own identity
Describes how to troubleshoot publisher verification for the Microsoft identity platform by calling Microsoft Graph APIs.
Learn how to acquire an access token in a Node/Express.js web to read user's profile detail from Microsoft Graph API
Protect the endpoint of an API, then run it to ensure it's listening for HTTP requests.
Learn how to call a web API whose endpoints are protected using the Microsoft identity platform
In this quickstart, you download and modify a code sample that demonstrates how to protect an ASP.NET Core web API by using the Microsoft identity platform for authorization.
In this quickstart, learn how to call an ASP.NET web API that's protected by the Microsoft identity platform from a Windows Desktop (WPF) application.
In this quickstart, learn how a Python web app can sign in users, get an access token from the Microsoft identity platform, and call the Microsoft Graph API.
author: HULKsmashGithub
Learn how to build a desktop app that calls web APIs to acquire a token for the app by using Web Account Manager.
Learn how to build a desktop app that calls web APIs to acquire a token for the app interactively.
Learn how to build a desktop app that calls web APIs to acquire a token for the app using device code flow
Learn how to build a daemon app that calls web APIs (acquiring tokens)
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
Deploy Azure App Proxy
UpdatedWith Microsoft Entra Domain Services, you can lift-and-shift legacy applications running on-premises into Azure. Microsoft Entra application proxy then helps you support remote workers by securely publishing those internal applications part of a Domain Services managed domain so they can be accessed over the internet.
Learn how to build a daemon app that calls a web API.
Learn how to configure the code for your daemon application that calls web APIs (app configuration)
In this quickstart, learn how a JavaScript single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow.
In this quickstart, learn how a JavaScript Angular single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
In this quickstart, learn how a JavaScript React single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
Learn about how to prepare your Node.js client daemon app, then configure it to acquire an access token for calling a web API.
Download and run a code sample that shows how an ASP.NET web app can sign in Microsoft Entra users.
Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.
Learn more about how forest trust work with Microsoft Entra Domain Services
The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.
In this overview, you compare the different identity offerings for Active Directory Domain Services, Microsoft Entra ID, and Microsoft Entra Domain Services.
Learn how to create and manage custom attributes in a Domain Services managed domain.
Learn about where Microsoft Entra ID stores identity-related data for its European customers.
Learn about where Microsoft Entra ID stores customer-related data for its Japan customers.
Frontline Worker Management
Updatedauthor: csmulligan
In this overview, learn what Microsoft Entra Domain Services provides and how to use it in your organization to provide identity services to applications and services in the cloud.
Learn what replica sets are in Microsoft Entra Domain Services and how they provide redundancy to applications that require identity services.
Learn how to troubleshoot and resolve network security group configuration alerts for Microsoft Entra Domain Services
Learn how to resolve common alerts generated as part of the health status for Microsoft Entra Domain Services
Learn what a mismatched directory error means and how to resolve it in Microsoft Entra Domain Services
Learn how to troubleshoot common errors when you create or manage Microsoft Entra Domain Services
Learn how to troubleshoot and resolve common alerts with secure LDAP for Microsoft Entra Domain Services.
Learn how to troubleshoot common problems that cause user accounts to be locked out in Microsoft Entra Domain Services.
Learn how to troubleshoot secure LDAP (LDAPS) for a Microsoft Entra Domain Services managed domain
Learn about the Microsoft Entra Health signals and alerts for Conditional Access block policy health scenarios
author: inbarckms
Learn how to handle errors and exceptions, Conditional Access claims challenges, and retries in MSAL.js applications.
author: inbarckms
1. **Conditional Access** to see policy failure and success. Scope your filter to show only failures to limit results.
- Except for credentials information, the synchronization configuration stored in the ADSync database is automatically recovered and used during installation. This includes custom synchronization rules, connectors, filtering, and optional features configuration.
Learn how to configure a Microsoft Entra Domain Services managed domain to support profile synchronization for SharePoint Server
Learn how the synchronization process works between Microsoft Entra ID or an on-premises environment to a Microsoft Entra Domain Services managed domain.
Learn how to use the Microsoft Entra admin center to configure scoped synchronization from Microsoft Entra ID to a Microsoft Entra Domain Services managed domain
Learn how to use Microsoft Graph PowerShell to configure scoped synchronization from Microsoft Entra ID to a Microsoft Entra Domain Services managed domain
Transport Layer Security (TLS) 1.2 enforcement for Microsoft Entra Domain Services | Microsoft Learn
UpdatedLearn how to enforce TLS 1.2 for a Microsoft Entra Domain Services managed domain.
Learn how to configure groups and user roles in your external tenant, so you can receive them as claims in a security token for your Node.js application
author: shlipsey3
Learn about the best practices and general guidance for protecting frontline workers in an organization
Client Credential Advice
Updatedauthor: kengaderdus
Learn how to enable security audits to centralize the logging of events for analysis and alerts in Microsoft Entra Domain Services
Learn how to use Azure Monitor Workbooks to review security audits and understand issues in a Microsoft Entra Domain Services managed domain.
Learn how to investigate Microsoft Entra health monitoring alerts to monitor and improve the health of your tenant.
Learn how to enforce secret and certificate standards using application management policies in Microsoft Entra ID.
Microsoft Entra ID Protection
1 updateauthor: justinha
Microsoft Entra External ID
170 updatesMigrate Users
UpdatedLearn how to migrate users from another identity provider to Microsoft Entra External ID.
Preview Alert Ciam
Updated> [!IMPORTANT]
author: shlipsey3
About Redirect Url
UpdatedA Microsoft Entra documentation page was updated: About Redirect Url.
Add Client App Certificate
UpdatedTo use your client app certificate, you need to associate the app you registered in the Microsoft Entra admin center with the certificate:
Add Optional Claims Id
Updated1. Under **Manage**, select the **Token configuration**.
Allow Deny List
Updatedauthor: csmulligan
Applies To External Only
Updated**Applies to**:  Workforce tenants  External tenants ([learn more](../tenant-configurations.md))
author: csmulligan
Applies To Workforce Only
Updated**Applies to**:  Workforce tenants  External tenants ([learn more](../tenant-configurations.md))
author: csmulligan
Use this quickstart to learn how Microsoft Entra admins can add B2B guest users in the Microsoft Entra admin center and walk through the B2B invitation workflow.
B2c Federation Customers
UpdatedLearn how to configure an Azure AD B2C tenant as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Create an External Tenant
UpdatedCreate an external tenant to get started with Microsoft Entra External ID as your customer identity and access management (CIAM) service.
Cross Cloud Settings
Updatedauthor: csmulligan
author: csmulligan
Current Limitations
Updatedauthor: csmulligan
Learn how your organization can define custom roles to manage cross-tenant access settings, allowing for precise control without relying on built-in management roles.
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
Declare App Roles
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Privileged Role Administrator](../../../../identity/role-based-access-control/permissions-reference.md#privileged-role-administrator).
Default Account
Updatedauthor: csmulligan
Delete an external tenant
UpdatedLearn how to delete an external tenant in the Microsoft Entra admin center.
Direct Federation
Updatedauthor: csmulligan
Direct Federation Adfs
Updatedauthor: csmulligan
Enable Implicit Hybrid Flows
UpdatedA Microsoft Entra documentation page was updated: Enable Implicit Hybrid Flows.
Enable Public Client Flow
UpdatedTo identify your app as a public client, follow these steps:
author: csmulligan
External Identities Pricing
Updatedauthor: csmulligan
Facebook Federation
Updatedauthor: csmulligan
Faq Customers
UpdatedGoogle Federation
Updatedauthor: csmulligan
Google Federation Customers
UpdatedLearn how to add Google as an identity provider for your external tenant.
Hybrid Cloud To On Premises
Updatedauthor: csmulligan
Identity Providers
Updatedauthor: csmulligan
Leave The Organization
Updatedauthor: csmulligan
Manage Admin Accounts
UpdatedManage Customer Accounts
UpdatedMicrosoft Account
Updatedauthor: csmulligan
Quickstart - Get started
UpdatedLearn how to get started with Microsoft Entra External ID. Customize your apps' look and feel, set up a user to test the sign-up flow, and configure a sample app in just a few minutes.
Quickstart Trial Setup
UpdatedUse our quickstart to set up the external tenant free trial.
Register Client App Common
UpdatedA Microsoft Entra documentation page was updated: Register Client App Common.
Register Daemon App
UpdatedThe following steps show you how to register your daemon app in the Microsoft Entra admin center:
Self Service Portal
Updatedauthor: csmulligan
author: csmulligan
Service Limits
UpdatedLearn about the service limits and restrictions in an external tenant.
Learn how to run a sample Angular SPA to sign in users
Learn how to run a sample React SPA to sign in users
Learn how to run a sample JavaScript SPA to sign in users
A Microsoft Entra documentation page was updated: Support Custom Claims Provider.
Tenant Configurations
UpdatedTenant Restrictions V2
Updatedauthor: csmulligan
Training Videos
Updatedauthor: csmulligan
1. Locate, then open *auth_config_native_auth.json*.
Use Custom Domain Url
UpdatedA Microsoft Entra documentation page was updated: Use Custom Domain Url.
A Microsoft Entra documentation page was updated: Use Custom Domain Url Android.
Use Dynamic Groups
Updatedauthor: csmulligan
User Flow Customize Language
UpdatedUser Permissions
UpdatedLearn about the default permissions for users in an external tenant.
Learn how to run a sample ASP.NET web app to sign in users
Learn how to run a sample Node.js/Express web app to sign in users
author: csmulligan
Custom Url Domain
UpdatedLearn about setting up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.
Custom Url Domain
UpdatedLearn how to set up custom URL domains to personalize the authentication sign-in endpoints for the external customers and consumers of your app.
author: gregkmsft
author: csmulligan
Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
Enable Native Authentication
UpdatedTo specify that this app is a public client and can use native authentication, enable public client and native authentication flows:
Learn how to add multifactor authentication (MFA) to your consumer and business customer (CIAM) application. For example, add email one-time passcode as a second authentication factor to your CIAM sign-up and sign-in user flows.
Native Authentication
UpdatedLearn how to set up native authentication in Microsoft Entra External ID. Customize the user interface for mobile and desktop apps, and provide a seamless sign-in experience.
Test User Flow
UpdatedTo test a [user flow](/entra/external-id/customers/how-to-user-flow-sign-up-sign-in-customers) with this app registration, enable the implicit grant flow for authentication.
Use Custom Domain Url Python
UpdatedUse a custom URL domain to fully brand the authentication URL. From a user perspective, users remain on your domain during the authentication process, rather than being redirected to *ciamlogin.com* domain name.
Add App Role
UpdatedAn API needs to publish a minimum of one app role for applications, also called [Application permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token as themselves. Application permissions are the type of permissions that APIs should publish when they want to enable client applications to successfully authenticate as themselves and not need to sign-in users. To publish an application permission, follow these steps:
Add App User Flow
UpdatedFor the customer users to see the sign-up or sign-in experience when they use your app, you need to associate your app with a user flow. Although many applications can be associated with your user flow, a single application can only be associated with one user flow.
Learn how to add Apple as an identity provider for your external tenant.
Add MSA for customer sign-in
UpdatedLearn how to add MSA as an identity provider for your external tenant.
Learn how to call a protected API in your Node.js web application using access tokens from Microsoft Entra External ID.
Learn how to prepare your Node.js client web app to call a protected API using access tokens from Microsoft Entra External ID.
Follow these steps to create a user flow a customer can use to sign in or sign up for an application.
Learn how to customize the sign-in and sign-up experiences for your customers.
Learn how to customize the look and feel of your customers' sign-in experiences.
Define Custom Attributes
UpdatedLearn how to create and define new custom attributes to be collected from users during sign-up and sign-in.
Learn how to enable self-service password reset so your customers can reset their own passwords without admin assistance.
Grant Api Permission Sign In
UpdatedOnce you register your application, it gets assigned the **User.Read** permission. However, since the tenant is an external tenant, the customer users themselves can't consent to this permission. You as the tenant administrator must consent to this permission on behalf of all the users in the tenant:
Quickstart Tenant Setup
UpdatedIn this quickstart, learn how to create an external tenant for customer identity and access management (CIAM). Customize a sign-in experience and try it out with a sample app.
Test User Flows
UpdatedLearn how to use the Run user flow feature to test your sign-up and sign-in user flow for your consumer and business customer apps.
Add sign-up and sign-in user flows for your consumer and business customers. Create a branded, customized user experience for apps in your external tenant.
Visual Studio Code Extension
UpdatedLearn how to use the Microsoft Entra External ID extension for Visual Studio Code. Use the application samples provided to set up a customized, branded sign-in experience for external users of your application without leaving the development environment.
Migrate To Xtap V2 Api
Updatedauthor: csmulligan
Add App Client Secret
UpdatedCreate a client secret for the registered application. The application uses the client secret to prove its identity when it requests for tokens:
Add Attributes To Token
UpdatedLearn how to add built-in user attributes and custom attributes as claims to the application token. Use directory extension attributes for sending user data to applications in token claims.
Create a client secret for the registered application. The application uses the client secret to prove its identity when it requests for tokens.
Add Optional Claims Access
UpdatedYou can add the **idtyp** optional claim to help the web API to determine whether a token is an **app** token or an **app + user** token. Although you can use a combination of **scp** and **roles** claims for the same purpose, using the **idtyp** claim is the easiest way to tell an app token and an app + user token apart. For example, the value of this claim is *app* when the token is an app-only token.
Assign Users Groups Roles
UpdatedOnce you've added app roles in your application, administrator can assign users and groups to the roles. Assignment of users and groups to roles can be done through the admin center, or programmatically using [Microsoft Graph](/graph/api/user-post-approleassignments). When the users assigned to the various app roles sign in to the application, their tokens have their assigned roles in the `roles` claim.
Learn how to manage your external tenant by calling the Azure REST API.
Code Samples
Updatedauthor: csmulligan
author: csmulligan
author: csmulligan
author: csmulligan
Learn how to add Facebook as an identity provider for your external tenant, enabling customers to sign in to your applications using their Facebook accounts.
Find Application Id
UpdatedA Microsoft Entra documentation page was updated: Find Application Id.
To grant your client app (*ciam-client-app*) API permissions, follow these steps:
Group App Roles Support
UpdatedFind out which core Microsoft Entra features related to the user and group management model and application assignment are available in external tenants.
One Time Passcode
Updatedauthor: csmulligan
Once your app acquires an ID token, you can retrieve the claims associated with the current account. To do so, use the following code snippet.
Region Code Opt In
Updatedauthor: csmulligan
Samples Ciam All
UpdatedLearn how to build and integrate apps with external tenants with scenarios such as sign-up, sign in, and getting an access token to call an API.
author: csmulligan
author: csmulligan
Use App Roles Customers
UpdatedLearn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.
User Flow Add Application
UpdatedUser Insights
UpdatedLearn about how to analyze user activity and engagement for your registered application in the external tenant.
Add Member To Group
UpdatedNow that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.yml#create-a-basic-group-and-add-members).
Security Customers
UpdatedAdd Api Mfa Scopes
UpdatedAn API needs to publish a minimum of one scope, also called [Delegated Permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token for a user successfully. To publish a scope, follow these steps:
Add Api Scopes
UpdatedAn API needs to publish a minimum of one scope, also called [Delegated Permission](~/identity-platform/permissions-consent-overview.md), for the client apps to obtain an access token for a user successfully. To publish a scope, follow these steps:
Api Connectors Overview
Updatedauthor: csmulligan
B2b Fundamentals
Updatedauthor: csmulligan
Custom Extensions
Updatedauthor: csmulligan
author: csmulligan
Customers Ciam
UpdatedDirect Federation Overview
Updatedauthor: csmulligan
External Identities Overview
Updatedauthor: csmulligan
Guide Explained
UpdatedLearn about the features you set up with the get started guide.
Planning Your Solution
Updatedauthor: csmulligan
author: csmulligan
Solutions Customers
UpdatedLearn about the customer identity and access management solutions for your consumer and business customer apps that are provided by Microsoft Entra External ID.
Supported Features Customers
UpdatedCompare features and capabilities of a workforce vs. an external tenant configuration. Determine which tenant type applies to your external identities scenario.
User Attributes
UpdatedUser profile attributes that you can collect from the user during sign-up, and how to extend user profile attributes by using custom user attributes.
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
To specify your app type to your app registration, follow these steps:
Learn how to use Visual Studio Connected Services to integrate Microsoft Entra ID into your applications right from your development environment.
Grant Api Access App
UpdatedFor your application to access data in Microsoft Graph API, grant the registered application the relevant application permissions. The effective permissions of your application are the full level of privileges implied by the permission. For example, to create, read, update, and delete every user in your external tenant, add the User.ReadWrite.All permission.
1. From the **App registrations** page, select the application that you created (such as *ciam-client-app*) to open its **Overview** page.
1. From the **App registrations** page, select the application that you created (such as *edit-profile-service*) to open its **Overview** page.
1. From the **App registrations** page, select the application that you created, such as *ciam-client-app*.
Register Api App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Developer](~/identity/role-based-access-control/permissions-reference.md#application-developer).
Register Mfa Api App
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Application Developer](~/identity/role-based-access-control/permissions-reference.md#application-developer).
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
author: csmulligan
Register Saml App
UpdatedLearn how to create and register a SAML app with External ID for customer identity and access management (CIAM). Choose your app type and get detailed steps.
author: csmulligan
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Learn how to set up Azure Monitor in external tenants to collect and analyze data in your tenant.
author: csmulligan
author: csmulligan
Add Group Claim In Token
UpdatedTo emit the group membership claims in security tokens, follow these steps:
Troubleshooting Known Issues
UpdatedMicrosoft Entra Internet Access
2 updatesPowerShell example that bypasses a certain fqdn or IP from being acquired by the GSA Client in the Internet Access forwarding profile.
PowerShell sample - Add Intune device compliance bypasses to Global Secure Access Internet Access
NewPowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Microsoft Entra Private Access
2 updatesCiphers
UpdatedLearn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Enable Multi Geo
UpdatedLearn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Microsoft Entra Workload ID
2 updatesmanager: CelesteDG
Learn how to troubleshoot service principal configuration alerts for Microsoft Entra Domain Services
Microsoft Entra Global Secure Access
17 updatesChina User Support
UpdatedLearn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.
Learn how to set up the bidirectional communication tunnel between Global Secure Access and your router.
Create Remote Networks
UpdatedLearn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.
Current Known Limitations
Updatedauthor: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
Customer intent: macOS users, I want to download and install the Global Secure Access client.
Updatedauthor: HULKsmashGithub
Customer intent: Windows users, I want to download and install the Global Secure Access client.
Updatedauthor: HULKsmashGithub
Learn how to add and delete customer premises equipment device links to remote networks for Global Secure Access.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
The [Universal Conditional Access documentation](../concept-universal-conditional-access#known-tunnel-authorization-limitations) notes that Global Secure Access has tunnel authoriziation limitations. This means that you can block access to a forwarding profile in Conditional Access and inadvertenty lock users out from accessing anything on their machine.
author: HULKsmashGithub
Security Copilot + Entra
1 updateMicrosoft Entra Health provides look-back reporting on Service Level Agreements (SLA) for authentication availability for your Microsoft Entra tenant. The SLA Attainment is a monthly look-back solution that shows the core authentication availability of Microsoft Entra ID each month. IT admins often need to review the SLA reports in conjuntion with service outages. Security Copilot interacts with the Microsoft Entra SLA using the Microsoft Graph API.
