How to transition off of Microsoft Entra Permissions Management for the anticipated product deprecation.
Permissions Management publishes offboarding guidance for an anticipated deprecation; 2 October is otherwise a documentation-heavy day
The clearest lifecycle signal is a new Microsoft Entra Permissions Management article explaining how to transition off the product for an anticipated deprecation. The same period adds a broad Learn runbook covering quickstart onboarding, AWS/Azure/GCP onboarding, analytics, alerts, remediation, and administration, but no supplied entry identifies a specific new feature, preview, or general-availability change. With 68 new and 68 removed records, 14 updates, and no Message Center entries, this is primarily Learn-content movement rather than evidence of a broad feature release. The meaningful exceptions are the deprecation guidance, updated ID Protection risk-based access guidance, and External ID Azure Monitor deployment instructions.
A new Microsoft Learn article explains how to transition off Microsoft Entra Permissions Management and explicitly ties that transition to an anticipated product deprecation. This is the period’s strongest retirement signal, but it does not establish that the service is already retired or provide a date or migration deadline.
- Permissions Management publishes a Quickstart Guide amid broader onboarding coverage
Entra ID · General
The new Quickstart Guide describes how to quickly onboard Microsoft Entra Permissions Management. Related new pages cover AWS accounts, Azure subscriptions, GCP projects, and adding resources after onboarding. These are documentation additions and operational reference material, not evidence of a newly launched onboarding capability or changed availability.
- Permissions Management documents permission-cleanup actions in the Remediation dashboard
Entra ID · Troubleshooting
A new procedure covers revoking access to high-risk and unused tasks or assigning read-only status for Azure and GCP identities. It gives administrators a documented remediation workflow; the supplied record does not show that the underlying controls themselves are newly available.
- ID Protection updates elevated-user-risk password-change guidance
ID Protection · Conditional Access
The updated article explains how to use Conditional Access with Microsoft Entra ID Protection to require secure password changes for users with elevated user risk. This supports a security-guidance update only; it does not establish a change to policy behavior or defaults.
- External ID Azure Monitor guidance sets out the cross-tenant deployment context
External ID · Monitoring
The updated article says logs and the Log Analytics workspace are configured in the external tenant; the relevant external-tenant accounts should have Global Administrator, the deployment account should have Owner in the Microsoft Entra subscription, and operators must sign into the correct directory at each step. This is configuration guidance, not evidence of a new monitoring feature.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
151 updates
Microsoft Entra ID
145 updatesView the latest public preview and general availability of features in Permissions Management.
How to add an account/subscription/project to Permissions Management after onboarding is complete.
How to configure Okta as an identity provider in Microsoft Entra Permissions Management.
How to create and view activity alerts and alert triggers in Microsoft Entra Permissions Management.
How to create and view permission analytics triggers in the Permission analytics tab in Permissions Management.
How to create and view rule-based anomaly alerts and alert triggers in Permissions Management.
How to create and view statistical anomaly alerts and alert triggers in the Statistical Anomaly tab in Permissions Management.
How to define and manage users, roles, and access levels in the Permissions Management User management dashboard.
How to enable or disable the controller in Permissions Management after onboarding is complete.
Frequently asked questions (FAQs) about Microsoft Entra Permissions Management.
Quickstart guide - How to quickly onboard your Microsoft Entra Permissions Management product
How to onboard a Google Cloud Platform (GCP) project on Permissions Management.
How to a Microsoft Azure subscription on Permissions Management.
How to onboard an Amazon Web Services (AWS) account to Permissions Management.
How to view analytic information about access keys in Permissions Management.
How to view usage analytics about active resources in Permissions Management.
How to view analytic information about active tasks in Permissions Management.
How to view analytic information about groups in Permissions Management.
How to view analytic information about serverless functions in Permissions Management.
How to view analytic information about users in Permissions Management.
How to view and configure settings for collecting data from your authorization system.
How to view statistics and data about your authorization system in the Permissions Management.
Microsoft Entra Permissions Management glossary
How to generate, view, and apply rule recommendations in the Microsoft Entra Permissions Management Autopilot dashboard.
How to manage users and groups in the User management dashboard in Permissions Management.
How to view information about alerts and alert triggers in the Alerts dashboard in Permissions Management.
How to view data about the activity in your authorization system in the Microsoft Entra Permissions Management Dashboard.
How to view information about rules in the Autopilot dashboard in Permissions Management.
How to view information about identities that can access accounts from an external account in Permissions Management.
How to enable Microsoft Entra Permissions Management in your organization.
Review roles and the level of permissions assigned in Microsoft Entra Permissions Management.
How to create a rule in the Autopilot dashboard in Microsoft Entra Permissions Management.
How to configure AWS IAM Identity Center as an identity provider.
View current Microsoft Entra Permissions Management partners and their websites.
How to select group-based permissions settings with the User management dashboard.
How to add or remove a user in Microsoft Entra Permissions Management through the Microsoft Enter admin center.
How to use the Analytics dashboard in Permissions Management to view details about users, groups, active resources, active tasks, access keys, and serverless functions.
How to view current billable resources in your authorization system in Microsoft Entra Permissions Management.
How to view personal and organization information in the Account settings dashboard in Microsoft Entra Permissions Management.
How to view current privileged role assignments in the Microsoft Entra Insights tab.
How to view information about active and completed tasks in the Activities pane in Permissions Management.
How to create folders to organize Authorization Systems - accounts, subscriptions, and projects - in Microsoft Entra Permissions Management.
Teams Reader
UpdatedAssign the Teams Reader role to users who need to do the following tasks:
Dragon Administrator
UpdatedAssign the Dragon Administrator role to users who need to do the following tasks:
Agent Optimization
Updatedmanager: dougeby
Whats New
Updated| Date | Area | Description |
Tutorial Create Instance
Updated>
Add Remove Role Task
RemovedA Microsoft Entra documentation page was updated: Add Remove Role Task.
Add Remove User To Group
RemovedA Microsoft Entra documentation page was updated: Add Remove User To Group.
Attach Detach Permissions
RemovedA Microsoft Entra documentation page was updated: Attach Detach Permissions.
Clone Role Policy
RemovedA Microsoft Entra documentation page was updated: Clone Role Policy.
Configure Aws Iam
RemovedA Microsoft Entra documentation page was updated: Configure Aws Iam.
A Microsoft Entra documentation page was updated: Configure Okta As An Identity Provider.
Create Alert Trigger
RemovedA Microsoft Entra documentation page was updated: Create Alert Trigger.
A Microsoft Entra documentation page was updated: Create Approve Privilege Request.
Create Custom Queries
RemovedA Microsoft Entra documentation page was updated: Create Custom Queries.
Create Folders
RemovedA Microsoft Entra documentation page was updated: Create Folders.
A Microsoft Entra documentation page was updated: Create Group Based Permissions.
Create Role Policy
RemovedA Microsoft Entra documentation page was updated: Create Role Policy.
Create Rule
RemovedA Microsoft Entra documentation page was updated: Create Rule.
Delete Role Policy
RemovedA Microsoft Entra documentation page was updated: Delete Role Policy.
Faqs
RemovedA Microsoft Entra documentation page was updated: Faqs.
Modify Role Policy
RemovedA Microsoft Entra documentation page was updated: Modify Role Policy.
Multi Cloud Glossary
RemovedA Microsoft Entra documentation page was updated: Multi Cloud Glossary.
A Microsoft Entra documentation page was updated: Offboard Permissions Management.
A Microsoft Entra documentation page was updated: Onboard Add Account After Onboarding.
Onboard Aws
RemovedA Microsoft Entra documentation page was updated: Onboard Aws.
Onboard Azure
RemovedA Microsoft Entra documentation page was updated: Onboard Azure.
A Microsoft Entra documentation page was updated: Onboard Enable Controller After Onboarding.
Onboard Enable Tenant
RemovedA Microsoft Entra documentation page was updated: Onboard Enable Tenant.
Onboard Gcp
RemovedA Microsoft Entra documentation page was updated: Onboard Gcp.
Partner List
RemovedA Microsoft Entra documentation page was updated: Partner List.
A Microsoft Entra documentation page was updated: Permissions Management For Defender For Cloud.
A Microsoft Entra documentation page was updated: Permissions Management Quickstart Guide.
Permissions Reference
UpdatedA Microsoft Entra documentation page was updated: Permissions Reference.
Product Account Explorer
RemovedA Microsoft Entra documentation page was updated: Product Account Explorer.
Product Account Settings
RemovedA Microsoft Entra documentation page was updated: Product Account Settings.
Product Dashboard
RemovedA Microsoft Entra documentation page was updated: Product Dashboard.
A Microsoft Entra documentation page was updated: Product Data Billable Resources.
Product Data Sources
RemovedA Microsoft Entra documentation page was updated: Product Data Sources.
A Microsoft Entra documentation page was updated: Product Define Permission Levels.
Product Permission Analytics
RemovedA Microsoft Entra documentation page was updated: Product Permission Analytics.
A Microsoft Entra documentation page was updated: Product Privileged Role Insights.
Product Roles Permissions
RemovedA Microsoft Entra documentation page was updated: Product Roles Permissions.
Product Rule Based Anomalies
RemovedA Microsoft Entra documentation page was updated: Product Rule Based Anomalies.
A Microsoft Entra documentation page was updated: Product Statistical Anomalies.
Recommendations Rule
RemovedA Microsoft Entra documentation page was updated: Recommendations Rule.
Revoke Task Readonly Status
RemovedA Microsoft Entra documentation page was updated: Revoke Task Readonly Status.
Ui Autopilot
RemovedA Microsoft Entra documentation page was updated: Ui Autopilot.
Ui Dashboard
RemovedA Microsoft Entra documentation page was updated: Ui Dashboard.
Ui Tasks
RemovedA Microsoft Entra documentation page was updated: Ui Tasks.
Ui Triggers
RemovedA Microsoft Entra documentation page was updated: Ui Triggers.
Ui User Management
RemovedA Microsoft Entra documentation page was updated: Ui User Management.
Usage Analytics Access Keys
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Access Keys.
A Microsoft Entra documentation page was updated: Usage Analytics Active Resources.
Usage Analytics Active Tasks
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Active Tasks.
Usage Analytics Groups
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Groups.
Usage Analytics Home
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Home.
A Microsoft Entra documentation page was updated: Usage Analytics Serverless Functions.
Usage Analytics Users
RemovedA Microsoft Entra documentation page was updated: Usage Analytics Users.
View Role Policy
RemovedA Microsoft Entra documentation page was updated: View Role Policy.
A Microsoft Entra documentation page was updated: Whats New In Permissions Management.
How to create a custom query in the Audit dashboard in Microsoft Entra Permissions Management.
How to create, view, and share a custom report in the Permissions Management.
How to filter and query user activity in Microsoft Entra Permissions Management.
How to view and download the Permissions Analytics Report in Permissions Management.
How to view system reports in the Reports dashboard in Permissions Management.
Use queries to see how users access information in an authorization system in Permissions Management
NewHow to use queries to see how users access information in an authorization system in Permissions Management.
How to generate and view a system report in the Permissions Management.
View a list and description of all system reports available in Permissions Management.
How to generate an on-demand report from a query in the **Audit** dashboard in Permissions Management.
All Reports
RemovedA Microsoft Entra documentation page was updated: All Reports.
Audit Trail Results
RemovedA Microsoft Entra documentation page was updated: Audit Trail Results.
Product Audit Trail
RemovedA Microsoft Entra documentation page was updated: Product Audit Trail.
A Microsoft Entra documentation page was updated: Product Permissions Analytics Reports.
Product Reports
RemovedA Microsoft Entra documentation page was updated: Product Reports.
Report Create Custom Report
RemovedA Microsoft Entra documentation page was updated: Report Create Custom Report.
Report View System Report
RemovedA Microsoft Entra documentation page was updated: Report View System Report.
Ui Audit Trail
RemovedA Microsoft Entra documentation page was updated: Ui Audit Trail.
How to revoke access to high-risk and unused tasks or assign read-only status for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard.
How to attach and detach permissions for groups, users, and service accounts for Microsoft Azure and Google Cloud Platform (GCP) identities in the Remediation dashboard in Permissions Management.
How to create a role/policy in the Remediation dashboard.
How to create or approve a request for permissions in the Remediation dashboard.
Understand potential error codes that may appear during onboarding of Microsoft Entra Permissions Management
How to view existing roles/policies and requests for permission in the Remediation dashboard in Permissions Management.
How to view and filter information about roles/policies in the Microsoft Entra Permissions Management Remediation dashboard.
How to attach and detach permissions for users, roles, and groups for Amazon Web Services (AWS) identities in the Remediation dashboard in Permissions Management.
How to clone a role/policy in Microsoft Entra Permissions Management.
How to delete a role/policy in the Microsoft Entra Permissions Management Remediation dashboard.
How to modify a role/policy in the Remediation dashboard in Microsoft Entra Permissions Management.
Troubleshoot issues with Permissions Management
Error Codes Onboarding
RemovedA Microsoft Entra documentation page was updated: Error Codes Onboarding.
Troubleshoot
RemovedA Microsoft Entra documentation page was updated: Troubleshoot.
Ui Remediation
RemovedA Microsoft Entra documentation page was updated: Ui Remediation.
How to view the Permissions Management API integration settings and create service accounts and roles.
How to configure ServiceNow with Microsoft Entra Permissions Management.
4. Select the app, then click **Install**.
A Microsoft Entra documentation page was updated: Configure Servicenow Application.
Integration Api
RemovedA Microsoft Entra documentation page was updated: Integration Api.
An introduction to Microsoft Entra Permissions Management.
Overview
RemovedA Microsoft Entra documentation page was updated: Overview.
Microsoft Intune and Microsoft Entra work together to secure your organization through [device compliance policies](/mem/intune/protect/device-compliance-get-started) and Conditional Access. Device compliance policies ensure user devices meet minimum configuration requirements. The requirements can be enforced when users access services protected with Conditional Access policies.
How objects and credentials are synchronized in a Microsoft Entra Domain Services managed domain
UpdatedObjects and credentials in a Microsoft Entra Domain Services managed domain can either be created locally within the domain, or synchronized from a Microsoft Entra tenant. When you first deploy Domain Services, an automatic one-way synchronization is configured and started to replicate the objects from Microsoft Entra ID. This one-way synchronization continues to run in the background to keep the Domain Services managed domain up-to-date with any changes from Microsoft Entra ID. No synchronization occurs from Domain Services back to Microsoft Entra ID.
Learn how Microsoft Entra Permissions Management helps strengthen security in cloud environments as an enhancement for Defender for Cloud
Microsoft Entra ID Protection
2 updatesLearn how to create Conditional Access policies using Microsoft Entra ID Protection to enforce secure password changes for users with elevated risk.
Protect your organization by implementing Conditional Access policies that address sign-in risks using Microsoft Entra ID Protection.
Microsoft Entra ID Governance
1 updateMicrosoft Entra's cross-cloud synchronization, in public preview and opt-in, automates user lifecycle management across Microsoft commercial, US Government, and China clouds. General availability is late September to early October 2025. It requires specific licenses, admin enablement, and supports configuration via portal, PowerShell, and API.
Microsoft Entra External ID
3 updatesB2b Guest Access
UpdatedTo enable B2B guest access for Windows 365 or Azure Virtual Desktop (AVD) virtual machines using Global Secure Access, follow these steps:
Azure Monitor
UpdatedDuring this deployment, you'll configure your external tenant where logs are generated. You'll also configure your external tenant where the Log Analytics workspace will be hosted. The external tenant accounts used (such as your admin account) should be assigned the [Global Administrator](/entra/identity/role-based-access-control/permissions-reference#global-administrator) role on the external tenant. The account you'll use to run the deployment in the external tenant must be assigned the [Owner](/azure/role-based-access-control/built-in-roles#owner) role in the Microsoft Entra subscription. It's also important to make sure you're signed in to the correct directory as you complete each step as described.
- [Register a SAML app in your external tenant](customers/how-to-register-saml-app.md) - Enterprise applications and SAML SSO are generally available
