Microsoft 365 Migration Administrator
Microsoft Entra B2B guest sign-in changes from July; targeted authentication and Seamless SSO guidance follow
The most consequential item on 26 June is a Microsoft Entra ID service-experience change: B2B guests will sign in through their home organization’s sign-in page, rolling out from July and completing by December 2025. The 259 recorded changes otherwise center on documentation maintenance, with no removals; the most useful exceptions clarify Android authentication behavior, highlight risks in legacy Seamless SSO deployments, and document privileged federation authority in External ID. No preview, general-availability launch, or retirement is identified in the supplied evidence.
- B2B collaboration is adopting home-organization guest sign-in
Entra ID · Authentication
A Microsoft Entra ID Message Center major update says the B2B guest authentication experience will change starting in July 2025, with completion by December 2025. Guest users will authenticate through their home organization’s sign-in page, which Microsoft says should improve usability and reduce confusion. The notice says no administrative action is required, while still recommending a review of B2B configuration.
- Android QR-code/PIN authentication documentation records an Authenticator dependency
Entra ID · Authentication
An updated Entra ID authentication item states that getPreferredAuthConfiguration requires the Microsoft Authenticator app to be installed; if it is absent, the method returns None. This is a documented method behavior or clarification, not evidence of a tenant-wide policy change or rollout.
- Updated guidance flags legacy Seamless SSO exposure
Entra ID · Authentication
The updated credential-management guidance describes Microsoft Entra Seamless SSO as a legacy feature, primarily useful for older Windows 7 and Windows 8.1 scenarios that do not support Primary Refresh Tokens. It warns that, when those legacy systems are no longer present, continued use adds complexity and potential security exposure involving stale or misconfigured Kerberos tickets and the AZUREADSSOACC computer account. The supplied item provides security guidance; it does not announce retirement.
- External ID documentation clarifies privileged federation authority
External ID · Authentication
An updated External ID role page describes the External Identity Provider Administrator as a privileged role able to add identity providers, configure settings such as authentication path, service ID, and assigned key containers, and enable trust in authentications from external identity providers. This is a clarification of delegated authority, not evidence that the role or its permissions were newly introduced.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
260 updates
Microsoft Entra ID
233 updatesPartner Tier2 Support
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
Partner Tier1 Support
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Do not use. This role has been deprecated and will be removed from Microsoft Entra ID in the future. This role is intended for use by a small number of Microsoft resale partners, and is not intended for general use.
A Microsoft Entra documentation page was updated: Microsoft 365 Migration Administrator.
Global Administrator
Global Reader
Permissions Reference
UpdatedThis article lists the Microsoft Entra built-in roles you can assign to allow management of Microsoft Entra resources. For information about how to assign roles, see [Assign Microsoft Entra roles](manage-roles-portal.md). If you are looking for roles to manage Azure resources, see [Azure built-in roles](/azure/role-based-access-control/built-in-roles).
User Administrator
Hybrid Identity Administrator
Directory Readers
Partner Tier2 Support
Intune Administrator
Directory Writers
Partner Tier1 Support
Windows 365 Administrator
Privileged Role Administrator
SharePoint Administrator
Teams Administrator
Exchange Administrator
Helpdesk Administrator
Groups Administrator
Yammer Administrator
role
Newrole
IoT Device Administrator
AI Administrator
Dynamics 365 Business Central Administrator
Microsoft Graph Data Connect Administrator
role
Newrole
Guest Inviter
Microsoft Hardware Warranty Administrator
SharePoint Embedded Administrator
Teams Telephony Administrator
Attribute Assignment Administrator
Knowledge Administrator
Microsoft Hardware Warranty Specialist
role
Newrole
role
Newrole
Viva Glint Tenant Administrator
Viva Pulse Administrator
Virtual Visits Administrator
Microsoft 365 Backup Administrator
User Experience Success Manager
Attribute Assignment Reader
Insights Analyst
Knowledge Manager
Teams Communications Administrator
Viva Goals Administrator
Skype for Business Administrator
Attack Payload Author
Attack Simulation Administrator
Insights Administrator
License Administrator
Service Support Administrator
People Administrator
role
Newrole
Attribute Definition Administrator
Attribute Definition Reader
Assign the Dynamics 365 Administrator role to users who need to manage all aspects of Dynamics 365 services, including configuration, user management, and support tickets.
Extended Directory User Administrator
Fabric Administrator
Modern Commerce Administrator
Organizational Data Source Administrator
Power Platform Administrator
role
Newrole
role
Newrole
Teams Communications Support Specialist
Domain Name Administrator
Edge Administrator
role
Newrole
Teams Communications Support Engineer
Desktop Analytics Administrator
Insights Business Leader
Permissions Management Administrator
Kaizala Administrator
Printer Technician
Search Administrator
Search Editor
Tenant Creator
Exchange Recipient Administrator
Message Center Privacy Reader
Message Center Reader
Microsoft Entra Joined Device Local Administrator
Teams Devices Administrator
author: shlipsey3
Azure DevOps Administrator
Microsoft Entra Domain Services supports TLS versions 1.0 and 1.1, but they're disabled by default.
role
Newrole
role
Newrole
Teams Reader
NewTeams Reader
Printer Administrator
Windows Update Deployment Administrator
User Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the User Administrator role to users who need to do the following:
To enable group writeback, you must have:
Cloud Device Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can enable, disable, and delete devices in Microsoft Entra ID and read Windows 10 BitLocker keys (if present) in the Azure portal. The role does not grant permissions to manage any other properties on the device.
manager: CelesteDG
author: MicrosoftGuyJFlo
This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage role assignments in Microsoft Entra ID, as well as within Microsoft Entra Privileged Identity Management. They can create and manage groups that can be assigned to Microsoft Entra roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units.
Connect Version History
Updated> [!IMPORTANT]
Ai Administrator
UpdatedA Microsoft Entra documentation page was updated: Ai Administrator.
Attack Payload Author
UpdatedA Microsoft Entra documentation page was updated: Attack Payload Author.
A Microsoft Entra documentation page was updated: Attack Simulation Administrator.
Azure Devops Administrator
UpdatedA Microsoft Entra documentation page was updated: Azure Devops Administrator.
Billing Administrator
UpdatedA Microsoft Entra documentation page was updated: Billing Administrator.
Compliance Administrator
UpdatedA Microsoft Entra documentation page was updated: Compliance Administrator.
A Microsoft Entra documentation page was updated: Compliance Data Administrator.
A Microsoft Entra documentation page was updated: Customer Lockbox Access Approver.
A Microsoft Entra documentation page was updated: Desktop Analytics Administrator.
Directory Readers
UpdatedA Microsoft Entra documentation page was updated: Directory Readers.
Dynamics 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Dynamics 365 Administrator.
A Microsoft Entra documentation page was updated: Dynamics 365 Business Central Administrator.
Edge Administrator
UpdatedA Microsoft Entra documentation page was updated: Edge Administrator.
Exchange Administrator
UpdatedA Microsoft Entra documentation page was updated: Exchange Administrator.
A Microsoft Entra documentation page was updated: Exchange Recipient Administrator.
A Microsoft Entra documentation page was updated: Extended Directory User Administrator.
Fabric Administrator
UpdatedA Microsoft Entra documentation page was updated: Fabric Administrator.
Groups Administrator
UpdatedA Microsoft Entra documentation page was updated: Groups Administrator.
Guest Inviter
UpdatedA Microsoft Entra documentation page was updated: Guest Inviter.
Insights Administrator
UpdatedA Microsoft Entra documentation page was updated: Insights Administrator.
Insights Analyst
UpdatedA Microsoft Entra documentation page was updated: Insights Analyst.
Insights Business Leader
UpdatedA Microsoft Entra documentation page was updated: Insights Business Leader.
Iot Device Administrator
UpdatedA Microsoft Entra documentation page was updated: Iot Device Administrator.
Kaizala Administrator
UpdatedA Microsoft Entra documentation page was updated: Kaizala Administrator.
Knowledge Administrator
UpdatedA Microsoft Entra documentation page was updated: Knowledge Administrator.
Knowledge Manager
UpdatedA Microsoft Entra documentation page was updated: Knowledge Manager.
License Administrator
UpdatedA Microsoft Entra documentation page was updated: License Administrator.
A Microsoft Entra documentation page was updated: Message Center Privacy Reader.
Message Center Reader
UpdatedA Microsoft Entra documentation page was updated: Message Center Reader.
A Microsoft Entra documentation page was updated: Microsoft 365 Backup Administrator.
A Microsoft Entra documentation page was updated: Microsoft Entra Joined Device Local Administrator.
A Microsoft Entra documentation page was updated: Microsoft Graph Data Connect Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Administrator.
A Microsoft Entra documentation page was updated: Microsoft Hardware Warranty Specialist.
Network Administrator
UpdatedA Microsoft Entra documentation page was updated: Network Administrator.
Office Apps Administrator
UpdatedA Microsoft Entra documentation page was updated: Office Apps Administrator.
A Microsoft Entra documentation page was updated: Organizational Data Source Administrator.
A Microsoft Entra documentation page was updated: Organizational Messages Approver.
A Microsoft Entra documentation page was updated: Organizational Messages Writer.
People Administrator
UpdatedA Microsoft Entra documentation page was updated: People Administrator.
A Microsoft Entra documentation page was updated: Permissions Management Administrator.
Printer Administrator
UpdatedA Microsoft Entra documentation page was updated: Printer Administrator.
Printer Technician
UpdatedA Microsoft Entra documentation page was updated: Printer Technician.
Search Administrator
UpdatedA Microsoft Entra documentation page was updated: Search Administrator.
Search Editor
UpdatedA Microsoft Entra documentation page was updated: Search Editor.
A Microsoft Entra documentation page was updated: Service Support Administrator.
Sharepoint Administrator
UpdatedA Microsoft Entra documentation page was updated: Sharepoint Administrator.
A Microsoft Entra documentation page was updated: Sharepoint Embedded Administrator.
A Microsoft Entra documentation page was updated: Skype For Business Administrator.
Teams Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Administrator.
A Microsoft Entra documentation page was updated: Teams Communications Support Engineer.
A Microsoft Entra documentation page was updated: Teams Communications Support Specialist.
Teams Devices Administrator
UpdatedA Microsoft Entra documentation page was updated: Teams Devices Administrator.
Teams Reader
UpdatedA Microsoft Entra documentation page was updated: Teams Reader.
A Microsoft Entra documentation page was updated: Teams Telephony Administrator.
Tenant Creator
UpdatedA Microsoft Entra documentation page was updated: Tenant Creator.
A Microsoft Entra documentation page was updated: User Experience Success Manager.
Virtual Visits Administrator
UpdatedA Microsoft Entra documentation page was updated: Virtual Visits Administrator.
A Microsoft Entra documentation page was updated: Viva Glint Tenant Administrator.
Viva Goals Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Goals Administrator.
Viva Pulse Administrator
UpdatedA Microsoft Entra documentation page was updated: Viva Pulse Administrator.
Windows 365 Administrator
UpdatedA Microsoft Entra documentation page was updated: Windows 365 Administrator.
A Microsoft Entra documentation page was updated: Windows Update Deployment Administrator.
Yammer Administrator
UpdatedA Microsoft Entra documentation page was updated: Yammer Administrator.
Microsoft Entra seamless single sign-on (Seamless SSO) is a legacy authentication feature designed to provide passwordless access for domain-joined devices that are not hybrid Microsoft Entra ID joined. Seamless SSO relies on Kerberos authentication and is primarily beneficial for older operating systems like Windows 7 and Windows 8.1, which do not support Primary Refresh Tokens (PRT). If these legacy systems are no longer present in the environment, continuing to use Seamless SSO introduces unnecessary complexity and potential security exposure. Threat actors could exploit misconfigured or stale Kerberos tickets, or compromise the `AZUREADSSOACC` computer account in Active Directory, which holds the Kerberos decryption key used by Microsoft Entra ID. Once compromised, attackers could impersonate users, bypass modern authentication controls, and gain unauthorized access to cloud resources. Disabling Seamless SSO in environments where it is no longer needed reduces the attack surface and enforces the use of modern, token-based authentication mechanisms that offer stronger protections.
Authenticate Application Id
UpdatedTo enhance the security of the service, we're rolling out an application identity that uses Oauth 2.0 client credential flow with certificate credentials. In this new method, Microsoft Entra or an administrator creates a single tenant non-Microsoft application in Microsoft Entra ID and uses one of the following relevant certificate management options for the credentials.
Microsoft Entra ID will update the guest authentication experience for B2B collaboration starting July 2025, completing by December 2025. Guest users will sign in via their home organization’s sign-in page, enhancing usability and reducing confusion. No administrative action is required, but review your B2B configuration.
Authentication Administrator
Privileged Authentication Administrator
Authentication Policy Administrator
Authentication Extensibility Administrator
The `getPreferredAuthConfiguration` method requires the Microsoft Authenticator app to be installed on the device. If the Microsoft Authenticator app isn't installed, the method returns `None`.
This is a [privileged role](../privileged-roles-permissions.md). Assign the Privileged Authentication Administrator role to users who need to do the following:
Authentication Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Administrator role to users who need to do the following:
Enable Authenticator Passkey
Updatedauthor: justinha
Users with this role **cannot** do the following:
This is a [privileged role](../privileged-roles-permissions.md). Users in this role can create, manage and deploy provisioning configuration setup from Active Directory to Microsoft Entra ID using Cloud Provisioning as well as manage Microsoft Entra Connect, pass-through authentication (PTA), password hash synchronization (PHS), seamless single sign-on (seamless SSO), and federation settings. Does not have access to manage Microsoft Entra Connect Health. Users can also troubleshoot and monitor logs using this role.
This is a [privileged role](../privileged-roles-permissions.md). Assign the Authentication Extensibility Administrator role to users who need to do the following tasks:
Authentication Qr Code
Updatedauthor: aanjusingh
Authentication Table Include
UpdatedA Microsoft Entra documentation page was updated: Authentication Table Include.
Password Administrator
Global Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview compliance portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.
Microsoft Entra Connect deployments vary from a single forest Express mode installation to complex deployments that are synced across multiple forests by using custom synchronization rules. Because of the large number of configuration options and mechanisms, it's essential to understand what settings are in effect and be able to quickly deploy a server with an identical configuration. This feature introduces the ability to catalog the configuration of a specific synchronization server and import the settings into a new deployment. You can compare different synchronization settings snapshots to easily visualize the differences between two servers or the same server over time.
Howto Mfa Reporting
Updatedauthor: justinha
Helpdesk Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can change passwords, invalidate refresh tokens, create and manage support requests with Microsoft for Azure and Microsoft 365 services, and monitor service health. Invalidating a refresh token forces the user to sign in again. Whether a Helpdesk Administrator can reset a user's password and invalidate refresh tokens depends on the role the user is assigned. For a list of the roles that a Helpdesk Administrator can reset passwords for and invalidate refresh tokens, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).
Domain Name Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage (read, add, verify, update, and delete) domain names. They can also read directory information about users, groups, and applications, as these objects possess domain dependencies. For on-premises environments, users with this role can configure domain names for federation so that associated users are always authenticated on-premises. These users can then sign into Microsoft Entra based services with their on-premises passwords via single sign-on. Federation settings need to be synced via Microsoft Entra Connect, so users also have permissions to manage Microsoft Entra Connect.
Password Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have limited ability to manage passwords. This role does not grant the ability to manage service requests or monitor service health. Whether a Password Administrator can reset a user's password depends on the role the user is assigned. For a list of the roles that a Password Administrator can reset passwords for, see [Who can reset passwords](privileged-roles-permissions.md#who-can-reset-passwords).
Customize Branding
UpdatedThe default background image behind the sign-in box is changing later this year. The change is only to the image, requires no action, and doesn't affect any functionality. We know that the default background image is often used for training and documentation to demonstrate the sign-in experience. Providing the updated image allows you to update your documentation so you can demonstrate the exact sign-in experience that your users will see. For details on the upcoming change, see [Microsoft Entra releases and announcements](../fundamentals/whats-new.md).
Attribute Log Reader
Attribute Log Administrator
Usage Summary Reports Reader
Reports Reader
Admin Audit Logging
UpdatedThe following table is a list of events that are logged with the new auditing feature. To view the events, use the Event Viewer and view the Application log.
Global Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview compliance portal, Azure portal, and Device Management admin center.
Power Platform Administrator
UpdatedUsers in this role can create and manage all aspects of environments, Power Apps, Flows, Data Loss Prevention policies. Additionally, users with this role have the ability to manage support tickets and monitor service health.
Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Reports Reader.
Usage Summary Reports Reader
UpdatedA Microsoft Entra documentation page was updated: Usage Summary Reports Reader.
author: MicrosoftGuyJFlo
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
Attribute Assignment Reader
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
For more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
Attribute Definition Reader
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID](../../../fundamentals/custom-security-attributes-manage.md).
Attribute Log Administrator
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).
Attribute Log Reader
UpdatedFor more information, see [Manage access to custom security attributes in Microsoft Entra ID]((../../../fundamentals/custom-security-attributes-manage.md)).
Intune Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global permissions within Microsoft Intune Online, when the service is present. Additionally, this role contains the ability to manage users and devices in order to associate policy, as well as create and manage groups. For more information, see [Role-based administration control (RBAC) with Microsoft Intune](/mem/intune/fundamentals/role-based-access-control).
This example includes custom security attributes that you could add to your tenant. Use the attribute set `HRConfidentialData` and then add the following attributes to:
Attribute Provisioning Administrator
Attribute Provisioning Reader
Directory Synchronization Accounts
This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Administrator role to users who need to do the following tasks:
This is a [privileged role](../privileged-roles-permissions.md). Assign the Attribute Provisioning Reader role to users who need to do the following tasks:
A Microsoft Entra documentation page was updated: Directory Synchronization Accounts.
Security Administrator
Security Reader
Security Operator
A Microsoft Entra documentation page was updated: Cloud App Security Administrator.
Azure Information Protection Administrator
role
Newrole
A Microsoft Entra documentation page was updated: Azure Information Protection Administrator.
> [!NOTE]
Conditional Access Grant
Updatedauthor: MicrosoftGuyJFlo
This is a [privileged role](../privileged-roles-permissions.md). Users with this role have the ability to manage Microsoft Entra Conditional Access settings.
- Results are logged in the **Conditional Access** and **Report-only** tabs of the Sign-in log details.
Application Administrator
role
Newrole
Application Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Note that users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
This is a [privileged role](../privileged-roles-permissions.md). Users in this role have the same permissions as the Application Administrator role, excluding the ability to manage application proxy. This role grants the ability to create and manage all aspects of enterprise applications and application registrations. Users assigned to this role are not added as owners when creating new application registrations or enterprise applications.
role
Newrole
A Microsoft Entra documentation page was updated: Organizational Branding Administrator.
Identity Governance Administrator
A Microsoft Entra documentation page was updated: Identity Governance Administrator.
Application Developer
Application Developer
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can create application registrations when the "Users can register applications" setting is set to No. This role also grants permission to consent on one's own behalf when the "Users can consent to apps accessing company data on their behalf" setting is set to No. Users assigned to this role are added as owners when creating new application registrations.
Getthere Tutorial
UpdatedTo configure single sign-on on **GetThere** side, you need to send the downloaded **Certificate (Base64)** and appropriate copied URLs from the application configuration to [GetThere support team](mailto:dataintegration@serko.com). They set this setting to have the SAML SSO connection set properly on both sides.
Microsoft Entra ID Protection
3 updatesSecurity Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Reader
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, as well as the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Security Operator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management and Microsoft Purview compliance portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).
Microsoft Entra ID Governance
2 updatesLifecycle Workflows Administrator
This is a [privileged role](../privileged-roles-permissions.md). Assign the Lifecycle Workflows Administrator role to users who need to do the following tasks:
Microsoft Entra External ID
12 updatesExternal Identity Provider Administrator
B2C IEF Keyset Administrator
B2C IEF Policy Administrator
External ID User Flow Administrator
External ID User Flow Attribute Administrator
Training Videos
Updated> [!VIDEO https://www.youtube.com/embed/_CD3shvqpx4?si=cYvAO8CyXuI9YPiS]
B2c Ief Policy Administrator
UpdatedA Microsoft Entra documentation page was updated: B2c Ief Policy Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Administrator.
A Microsoft Entra documentation page was updated: External Id User Flow Attribute Administrator.
This is a [privileged role](../privileged-roles-permissions.md). This administrator manages federation between Microsoft Entra organizations and external identity providers. With this role, users can add new identity providers and configure all available settings (e.g. authentication path, service ID, assigned key containers). This user can enable the Microsoft Entra organization to trust authentications from external identity providers. The resulting impact on end-user experiences depends on the type of organization:
B2c Ief Keyset Administrator
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). User can create and manage policy keys and secrets for token encryption, token signatures, and claim encryption/decryption. By adding new keys to existing key containers, this limited administrator can roll over secrets as needed without impacting existing applications. This user can see the full content of these secrets and their expiration dates even after their creation.
Effective July 1, 2025, external users will lose access to content shared via SharePoint One Time Passcode (OTP) before enabling Microsoft SharePoint and OneDrive integration with Microsoft Entra B2B. Resharing is required to restore access. Notify users and update internal documentation accordingly.
Microsoft Entra Workload ID
1 updateDirectory Writers
UpdatedThis is a [privileged role](../privileged-roles-permissions.md). Users in this role can read and update basic information of users, groups, and service principals.
Microsoft Entra Global Secure Access
9 updatesGlobal Secure Access Administrator
Customer intent: Windows users, I want to download and install the Global Secure Access client.
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the Windows client.
Install Macos Client
UpdatedThe Global Secure Access client secures network traffic at the end-user device. This article describes how to download and install the macOS client.
A Microsoft Entra documentation page was updated: Global Secure Access Administrator.
1. Choose the right connector group with the connector deployed in the service endpoint subnet.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Global Secure Access Log Reader
A Microsoft Entra documentation page was updated: Global Secure Access Log Reader.
Troubleshoot the Global Secure Access client using the health check tab in the advanced diagnostics utility.
