Migrate Approved Client App
Updatedauthor: shlipsey3
Daily.Entra.NewsThe period contains 514 updated items, with no new or removed items and no Message Center notices. The supplied representative records are Microsoft Learn documentation updates rather than release announcements. The most actionable items cover Conditional Access for high-risk Agent ID identities, Global Secure Access break-glass recovery, governance of Conditional Access exclusions, and an SAP provisioning prerequisite. Nothing supplied establishes a new feature, preview, general availability milestone, retirement, or runtime behavior change; many other entries expose only generic author or page-update text.
The updated page explains how to configure Conditional Access policies to block risky agent identities and emphasizes security best practices. This is security guidance in Agent ID documentation, not evidence of a new control or changed enforcement. Teams using agent identities should compare their current policies and runbooks with the guidance.
The updated PowerShell sample documents recovery from a Global Secure Access break-glass scenario by re-enabling Conditional Access policies that were disabled during the scenario. This is operational recovery guidance, not evidence of a new Global Secure Access feature or changed Conditional Access behavior. Global Secure Access operators should validate their recovery runbooks against the sample.
The updated guidance explains how to use access reviews to manage users excluded from Conditional Access policies. This is governance and security guidance; it does not indicate that exclusions or access reviews now behave differently. Tenants that maintain Conditional Access exclusion lists should review the process described.
The updated SAP Cloud Platform provisioning tutorial states that, before configuring automatic provisioning into SAP Cloud Identity Services, administrators must add the service from the Microsoft Entra application gallery to the tenant’s enterprise applications. The tutorial identifies both the Microsoft Entra admin center and Graph API as ways to do this. This is an ordinary setup clarification, not evidence of a new provisioning capability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
author: shlipsey3
author: shlipsey3
include file Microsoft Entra ID preview program information
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
* Manage your accounts in one central location.
* Manage your accounts in one central location.
include file Microsoft Entra workbook instructions
include file
include file
include file
include file
include file
Include file
Include file
Include file
author: barclayn
author: barclayn
author: barclayn
author: barclayn
author: barclayn
keywords: Azure Active Directory licensing service plans
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
How to close your work or school account in an unmanaged Microsoft Entra ID.
author: shlipsey3
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Use Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Microsoft Entra ID has an application proxy service that enables users to access on-premises applications by signing in with their Microsoft Entra account. This tutorial shows you how to prepare your environment for use with application proxy. Then, it uses the Microsoft Entra admin center to add an on-premises application to your Microsoft Entra tenant.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
How to publish on-premises ASP.NET applications that accept Active Directory Federation Services claims for secure remote access by your users.
Understand complex applications in Microsoft Entra application proxy.
Understand single sign-on with an on-premises app using application proxy.
Configure and manage custom domains in Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Learn about debugging issues that occur when configuring Microsoft Entra application proxy.
Covers the basics about how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Covers the basics about how to integrate on-premises SharePoint Server with Microsoft Entra application proxy.
How traffic distribution works with your application proxy deployment. Includes tips for how to optimize connector performance and use load balancing for back-end servers.
Include file
Covers how to provide single sign-on using Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Covers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.
Covers how to configure application proxy with Remote Desktop Services (RDS)
Remove personal data from connectors installed on devices for Microsoft Entra application proxy.
Learn how to identify and resolve cross-origin resource sharing (CORS) issues in Microsoft Entra application proxy.
Learn how to redirect hard coded links for applications published with Microsoft Entra application proxy.
Learn how to use Wildcard applications in Microsoft Entra application proxy.
Covers how to work with existing on-premises proxy servers with Microsoft Entra ID.
Learn how to provide single sign-on (SSO) for on-premises applications that are secured with Security Assertion Markup Language (SAML) authentication. Provide remote access to on-premises apps with application proxy.
Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
author: shlipsey3
Before configuring Microsoft Entra ID to have automatic user provisioning into SAP Cloud Identity Services, you need to add SAP Cloud Identity Services from the Microsoft Entra application gallery to your tenant's list of enterprise applications. You can do this step in the Microsoft Entra admin center, or via the Graph API.
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Learn how to provide single sign-on for on-premises applications that are secured with header-based authentication.
author: mepples21
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
author: custorod
include file
Learn how to resolve common access issues with Microsoft Entra application proxy applications.
Turn on single sign-on for your published on-premises applications with Microsoft Entra application proxy in the Microsoft Entra admin center.
author: justinha
Learn how to add new custom security attribute definitions or deactivate custom security attribute definitions in Microsoft Entra ID.
Learn how to manage access to custom security attributes in Microsoft Entra ID.
Learn how to troubleshoot custom security attributes in Microsoft Entra ID.
Learn about custom security attributes in Microsoft Entra ID.
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Learn about Microsoft Entra groups, including how they work, what they can access, and how membership and access is assigned.
author: jenniferf-skc
Learn how to use Microsoft Entra application proxy connectors.
Describes overview of identity provisioning and the ILM scenarios.
Create a custom Conditional Access policy to block access to resources by IP location.
Create a custom Conditional Access policy require approved app or app protection policy
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Covers security considerations for using Microsoft Entra application proxy
author: shlipsey3
include file
author: jenniferf-skc
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
This article describes how to use the Microsoft Entra provisioning service to provision users into Azure Databricks with Private Link Workspace.
Integrating Oracle Fusion Cloud Human Capital Management (HCM) with Microsoft Entra ID and on-premises Active Directory using the Inbound Provisioning API.
Learn how to configure inbound provisioning from SuccessFactors
Learn how to configure inbound provisioning from SuccessFactors to Microsoft Entra ID
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Workday.
Include file
author: barclayn
Learn how to configure inbound provisioning from Workday to Microsoft Entra ID
author: shlipsey3
author: shlipsey3
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Learn how to troubleshoot sign-up errors using Microsoft Entra reports in the Microsoft Entra admin center
include file
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can use entitlement management and other identity governance features to enforce the policies for access.
Describes how to check the users who fall into the execution scope of a Lifecycle Workflow.
Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID.
This article a tutorial on how to provision users and groups from on-premises to cloud using MIM.
Planning for a successful access reviews campaign for a particular application includes identifying if any users in that application have access that doesn't derive from Microsoft Entra ID. If the application does not support provisioning, then you will need to create application role assignments for the application, and supply the list of changes when a review completes.
Learn how to set up group writeback in entitlement management.
Learn how to configure the automatically generated Microsoft Entra recommendation email notification settings for your tenant.
Include file
Covers network topology considerations when using Microsoft Entra application proxy.
Learn about the architecture of Microsoft Entra ID, including service design, scalability, availability, and data consistency.
An end-to-end guide for planning the deployment of application proxy within your organization
Learn how to integrate an on premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
author: shlipsey3
author: SHERMANOUKO
Access Microsoft Entra admin center to effortlessly view and filter agent identities. Streamline tenant oversight and take charge now.
Learn how to structure agent metadata for optimal discoverability in Microsoft Entra Agent Registry and understand how the collections model affects agent visibility.
author: SHERMANOUKO
author: shlipsey3
Learn how to navigate, create, and manage agent collections in Microsoft Entra Agent Registry.
author: SHERMANOUKO
This article explains how to manage agent blueprints and registry-only agents using the Microsoft Entra Admin Center.
Learn about agent identities in Microsoft Entra ID, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.
Learn how to call Microsoft Graph API from an agent using agent identities or agent users, including authentication configuration and implementation steps.
Learn about agent identities, specialized identity constructs that enable secure authentication and authorization for AI agents in enterprise environments.
Learn about the Microsoft Agent Identity Platform, a comprehensive identity, and authorization framework designed specifically for AI agents. Key concepts include agent registry, authentication protocols, tokens, claims, and agent discovery capabilities.
Learn how to call Azure services using .NET Azure SDK from an agent using agent identities.
Learn how to enable secure agent communication through the Microsoft Entra Agent Registry API.
Learn how autonomous agents acquire tokens using the Microsoft Entra SDK for Agent ID to call downstream APIs independently.
Learn how to register agents to the Agent Registry in Microsoft Entra Agent ID through automatic registration or manual API calls for agent discovery and management.
Learn how agent identities operate autonomously without user context using app-only protocol with OAuth 2.0 client credentials flows.
Learn how agent applications operate on behalf of signed-in users using OAuth 2.0 On-Behalf-Of flows with agent identity blueprints and agent identities.
Learn how agent identities operate with user context through agent users using the agent user impersonation protocol with OAuth 2.0 token exchange.
Learn how to configure Conditional Access policies to block risky agent identities. Follow best practices to enhance security in Microsoft Entra.
Learn about the Agent Registry, a centralized metadata repository that enables agent discovery, and secure communication in enterprise environments.
Learn about the Agent ID, Agent Blueprint, and Agent Identity error codes.
Learn how to call custom protected APIs from an agent using different approaches including IDownstreamApi, MicrosoftIdentityMessageHandler, and IAuthorizationHeaderProvider.
Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
author: shlipsey3
Discovery and insights (formerly Security Wizard) help you convert permanent Microsoft Entra role assignments to just-in-time assignments with Privileged Identity Management.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can define policies for how users should obtain access to your business critical applications integrated with Microsoft Entra ID Governance.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. These features can be used for your existing business critical third party on-premises and cloud-based applications.
Microsoft Entra ID Governance allows you to model organizational roles using access packages, so you can migrate your existing role definitions to entitlement management.
Microsoft Entra ID Governance allows you to balance your organization's need for security and employee productivity with the right processes and visibility. You can integrate your existing business critical third party on-premises and cloud-based applications with Microsoft Entra ID for identity governance scenarios.
Learn the detailed steps for how to bring identities from SAP SuccessFactors and other sources into Microsoft Entra ID and provision those identities with access to SAP ECC, SAP S/4HANA, and other SAP and non-SAP applications, for organizations that were previously using SAP IDM.
The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.
Learn how to configure security alerts for Azure resource roles in Privileged
Configure security alerts for Microsoft Entra roles Privileged Identity Management.
Learn how to use custom security attribute to configure the scope of a workflow with lifecycle workflows.
Learn how to assign Microsoft Entra roles with access packages.
Learn how to create an access review of PIM for Groups in Microsoft Entra ID.
Frequently asked questions about Access Reviews.
Learn how to approve activation requests for group members and owners in Microsoft Entra Privileged Identity Management (PIM).
Learn how to use the My Access portal to approve or deny requests to an access package in Microsoft Entra entitlement management.
Learn how to approve or deny requests for Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to archive logs and create reports with Azure Monitor in entitlement management.
Learn how to assign eligibility for a group in Privileged Identity Management.
Learn how to assign Microsoft Entra roles in Privileged Identity Management (PIM).
View activity and audit activity history for group assignments in Privileged Identity Management (PIM).
Tutorial for moving users that change jobs using Lifecycle workflows with the Microsoft Entra admin center.
Tutorial for post off-boarding users from an organization using Lifecycle workflows with the Microsoft Entra admin center.
Tutorial for onboarding users to an organization using Lifecycle workflows with the Microsoft Entra admin center.
author: owinfreyATL
Learn how to write PowerShell scripts in Azure Automation to interact with Microsoft Entra entitlement management and other features.
services: entra-id-governance
Learn how to bring groups into Privileged Identity Management.
Learn how to change approval and requestor information settings for an access package in entitlement management.
Learn how to change requestor information & lifecycle settings for an access package in entitlement management.
Learn how to change request settings for an access package in entitlement management.
Learn how to change the resource roles for an existing access package in entitlement management.
This article guides a user on checking the status of a Lifecycle workflow
Learn how to check workflow insights within your Microsoft Entra tenant.
Learn the high-level steps you should follow for common scenarios in Microsoft Entra entitlement management.
Learn how to complete an access review of Azure resource and Microsoft Entra roles Privileged Identity Management.
Learn how to complete an access review of group members or application access in Microsoft Entra access reviews.
Learn how to configure automatic assignments based on rules for an access package in entitlement management.
Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure Microsoft Entra role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Learn how to configure separation of duties enforcement for requests for an access package in entitlement management.
Learn how to configure verified ID settings for an access package in entitlement management.
Learn how to convert guest user access package assignments for an access package in entitlement management.
You can use Microsoft Entra entitlement management to enforce the policies for who can get assigned access to an application.
Learn how to create an access package of resources that you want to share in Microsoft Entra entitlement management.
Learn how to set up an access review in a policy for entitlement management access packages in Microsoft Entra ID part of Microsoft Entra.
Learn how to create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to create an access review of group members or application access in Microsoft Entra ID.
Learn how to create a new container of resources and access packages in entitlement management.
Using Microsoft Entra access reviews, you can download a review history for access reviews in your organization.
This tutorial describes how to create customized reports in Azure Data Explorer by using data from more sources in addition to Microsoft Entra
This tutorial describes how to create customized reports in Azure Data Explorer by using data from Microsoft Entra.
This article guides you in creating a lifecycle workflow.
Learn how to customize the schedule of a lifecycle workflow.
Get a step-by-step guide for customizing emails that you send by using tasks within lifecycle workflows.
Learn how to delegate access governance from IT administrators to access package managers and project managers so that they can manage access themselves.
Learn how to delegate access governance from IT administrators to catalog creators and project managers so that they can manage access themselves.
Learn how to delegate access governance from IT administrators to department managers and project managers so that they can manage access themselves.
Learn how to delete a lifecycle workflow.
author: owinfreyATL
Learn how to discover Azure resources to manage in Privileged Identity Management (PIM).
Describes email notifications in Microsoft Entra Privileged Identity Management (PIM).
This article serves as a reference for Microsoft Entra ID behavior when assignment periods of an access package and PIM policy don't align.
author: owinfreyATL
include file
Learn how to remove users from an organization in real time on their last day of work by using lifecycle workflows in the Microsoft Entra admin center.
Learn how to extend or renew PIM for groups assignments.
A how-to guide on dynamically determining the approval requirements for an access package externally using a custom extension.
Learn about the settings you can specify to govern access for external users in entitlement management.
This article a tutorial on how to provision users and groups using cloud sync.
This article a tutorial on how to provision users and groups using connect sync.
This article a tutorial on how to provision users and groups from and managed in Workday.
This article a tutorial on how to provision users and groups from and managed in Microsoft Entra ID to Active Directory.
This article a tutorial on how to provision users and groups to AD with Workday.
This article a tutorial on how to provision users and groups to Active Directory using MIM.
This article details service limits for offerings within Microsoft Entra ID Governance
Learn how to activate your group membership or ownership in Privileged
Learn how to hide or delete an access package in Microsoft Entra entitlement management.
This article shows how to create custom alerts with Microsoft Entra ID Governance
This article shows how to use the new identity governance dashboard
This article describes use cases Microsoft Entra ID Governance.
include file
Include file
author: owinfreyATL
Information about audit logs with Lifecycle Workflows
This article walks you through managing inactive users with Lifecycle Workflows.
This article guides a user on Workflow task definitions and task parameters.
An article discussing Lifecycle workflow versioning and history
Frequently asked questions about Lifecycle workflows.
Learn how to bring identities from SAP SuccessFactors into Microsoft Entra ID and provision access to SAP ERP Central Component (ECC), SAP S/4HANA, and other SAP applications.
Learn how to manage user and guest access as membership of a group or assignment to an application with Microsoft Entra access reviews.
Learn how to allow people outside your organization to request access packages so that you can collaborate on projects.
Manage guest users as members of a group or assigned to an application with Microsoft Entra access reviews.
Learn how to manage users' access as membership of a group or assignment to an application with Microsoft Entra access reviews
A how to article on how to edit a user account related task to run for users synchronized from Active Directory Domain Services (AD DS) with Lifecycle workflows.
This article guides a user to editing a workflow's properties using Lifecycle Workflows.
This article guides a user on managing workflow versions with Lifecycle Workflows.
Learn how Microsoft Entra ID is licensed for guest users.
This article guides a user to running a workflow on demand using Lifecycle Workflows.
Learn how to simplify approving access to applications and resources for onboarding external users to your organization.
Information for understanding the APIs in Microsoft Entra Privileged
Learn how to view the audit log history for Microsoft Entra roles in
Learn how to review access of Azure resource and Microsoft Entra roles
Learn how to approve or deny requests for Azure resource roles in Privileged
Learn how to assign Azure resource roles in Privileged Identity Management (PIM).
Describes the roles you can't manage in Microsoft Entra Privileged Identity
Learn how to deploy Privileged Identity Management (PIM) in your Microsoft Entra organization.
Planning for a successful access reviews campaign for a particular application starts with understanding how to model access for that application in Microsoft Entra ID.
This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.
This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host
Learn how to extend or renew Azure resource role assignments in Privileged Identity Management (PIM).
Learn how to extend or renew Microsoft Entra role assignments in Microsoft Entra Privileged Identity Management (PIM)
Learn how to reprocess assignments for an access package in entitlement management.
Learn how to reprocess a request for an access package in entitlement management.
This article guides a user on reprocessing workflow runs using Lifecycle Workflows
Learn how to use the My Access portal to request access to an access package in Microsoft Entra entitlement management.
Learn about the request process for an access package and when email notifications are sent in entitlement management.
Learn how to complete an access review of entitlement management access packages in access reviews.
Learn how to review access of group members or application access in Microsoft Entra access reviews.
Learn how to review access of group members with review recommendations in Microsoft Entra access reviews.
Learn how to review your own access to groups or applications in access reviews.
Learn how to review your own access to resources in access reviews.
documentationcenter: ''
Learn how to review user access of entitlement management access packages in access reviews.
Learn about partners who can help with deployment and integration of identity management (IAM) and identity governance scenarios.
Learn how to share link to request an access package in entitlement management.
Learn how to show suggested access packages to users in My Access so they can quickly find the most relevant access packages.
Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.
Trigger Logic Apps based on custom task extensions
Learn how to configure and use custom logic app workflows in entitlement management.
Step-by-step tutorial for how to create your first access package using the Microsoft Entra admin center in entitlement management.
Tutorial for preparing user accounts for Lifecycle workflows.
Learn how to use Azure custom roles in Microsoft Entra Privileged Identity Management (PIM).
Learn how you can use entitlement management and Global Secure Access to restrict employee access to cloud apps.
Use Access Reviews to extend of remove access from members of partner organizations.
Learn how to use multi-stage reviews to design more efficient reviews with Microsoft Entra.
Learn how to view requests and remove for an access package in entitlement management.
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
Learn how to view the identity assignments report and audit logs in entitlement management.
Learn how to view, add, and remove assignments for an access package in entitlement management.
Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
Using access reviews, you can control group membership and application access to meet governance, risk management, and compliance initiatives in your organization.
Describes overview of identity lifecycle management and what is meant by governing the employee lifecycle.
Describes overview of Lifecycle workflow attributes.
Conceptual article about Lifecycle workflows execution conditions.
Conceptual article discussing workflow extensibility with Lifecycle Workflows
Conceptual article about Lifecycle Workflows reporting and history capabilities
Conceptual article about Lifecycle Workflows reporting and history capabilities.
Conceptual article discussing managing Users synchronized from Active Directory Domain Services (AD DS) to Microsoft Entra with Lifecycle Workflows.
Conceptual article discussing workflow templates and categories with Lifecycle Workflows.
This page provides an overview of the Microsoft Entra ID Governance integrations available to automate provisioning and governance controls.
This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
Describes how to use a resource dashboard to perform an access review
Describes overview of getting started with new business partner and external user scenarios.
How to manage Microsoft Entra Privileged Identity Management (PIM) for Groups.
A conceptual article describing access package visibility in the My Access portal.
Describes an overview of Lifecycle workflows and the various parts.
Get an overview of the lifecycle workflow feature of Microsoft Entra ID.
Get an overview of entitlement management and how you can use it to manage access to groups, applications, and SharePoint Online sites for internal and external identities.
Provides an overview of Microsoft Entra Privileged Identity Management (PIM).
Planning guide for a successful Lifecycle Workflow deployment.
Planning guide for a successful access reviews deployment.
Learn about some items you should check to help you troubleshoot Microsoft Entra entitlement management.
Learn how to troubleshoot system errors with roles in Microsoft Entra Privileged Identity Management (PIM).
Learn how to use access reviews to manage users that have been excluded from Conditional Access policies
include file
Include file
Learn how Global Secure Access enables secure B2B guest access for external partners through the Global Secure Access client and Azure Virtual Desktop.
Learn how to configure threat intelligence in Microsoft Entra Internet Access.
Learn how to configure web content filtering in Microsoft Entra Internet Access.
Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article outlines data storage and privacy information.
Learn how to manage the Internet Access traffic forwarding profile for Microsoft Entra Internet Access.
Global Secure Access points of presence and IP addresses for Microsoft Entra Internet Access and Microsoft Entra Private Access.
PowerShell example that bypasses a certain fqdn or IP from being acquired by the Global Secure Access Client in the Internet Access forwarding profile.
PowerShell example that adds Intune-related endpoints to the Global Secure Access Internet Access custom bypass policy to mitigate device compliance issues.
Learn about the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Learn about how Microsoft Entra Internet Access secures access to the Internet.
PowerShell examples for use in a Microsoft Entra Internet Access break glass scenario.
Global Secure Access includes Microsoft Entra Private Access and Microsoft Entra Internet Access. This article references event enrichment in Microsoft 365 enriched logs.
Learn how to configure and use GSA Cloud Firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Learn about the supported cryptographic algorithms, or ciphers, used for Microsoft Entra Private Access.
Learn how to configure Microsoft Entra private network connectors for Microsoft Entra Private Access.
Learn how to configure Microsoft Entra Private Access for Active Directory Domain Controllers.
Learn how to specify the internal resources to secure with Microsoft Entra Private Access using a Quick Access app.
Learn how to enable Multi-Geo Capability for Microsoft Entra Private Access to optimize traffic flow from Microsoft Entra Clients to Microsoft Entra Apps.
Learn how to manage the Private Access traffic forwarding profile for Microsoft Entra Private Access.
author: kenwith
Covers how to provide single sign-on using Kerberos with Microsoft Entra Private Access.
Learn how to access an Azure Storage account behind Azure Private Link using Microsoft Entra Private Access.
Learn how to access Azure SQL with a service endpoint using Microsoft Entra Private Access.
Learn how Microsoft Entra private network connector groups work, and how Microsoft Entra Private Access and application proxy use them.
Learn how Microsoft Entra private network connectors work and how Microsoft Entra Private Access and application proxy use them.
Learn about how Microsoft Entra Private Access secures access to your private corporate resources through the creation of Quick Access and Global Secure Access apps.
Learn how to configure per-app access to your private, internal resources using Global Secure Access applications for Microsoft Entra Private Access.
Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.
Learn to configure and establish a Secure Shell (SSH) connection using Microsoft Entra Private Access for enhanced security.
Learn how to link your domain to your decentralized identifier (DID).
author: barclayn
In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.
In this tutorial, you learn how to configure your tenant to verify credentials.
A design pattern describing how to verify in helpdesk scenarios
author: shlipsey3
author: barclayn
This article lists all releases of Microsoft Entra private network connector and describes new features and fixed issues.
author: kenwith
author: HULKsmashGithub
Learn how to assign a remote network to a traffic forwarding profile for Global Secure Access.
Learn about how Microsoft is dedicated to supporting Global Secure Access capabilities in China.
Microsoft and Cisco’s Secure Access coexistence solution guide.
Microsoft and Cisco VPNs coexistence solution guide.
author: kenwith
Learn how to configure the connectivity between your customer premises equipment and the Global Secure Access network.
Learn how to set up the bidirectional communication tunnel between Global Secure Access and your router.
Learn how to create remote networks, for remote locations such as branch offices, for Global Secure Access.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
author: jenniferf-skc
Global Secure Access maintains a compliance portfolio. This article lists the current, supported certifications.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
Learn how to list remote networks for Global Secure Access.
author: HULKsmashGithub
Learn how to enable and manage the Microsoft traffic forwarding profile for Global Secure Access.
Learn how to add and delete customer premises equipment device links to remote networks for Global Secure Access.
Learn how to update and delete remote networks for Global Secure Access.
Learn how to roll out traffic forwarding profiles to users and groups with Global Secure Access
author: HULKsmashGithub
Use this PowerShell script to create a TLS certificate using Active Directory Certificate Services (ADCS) in a test environment.
PowerShell example that gets the Auth Token for registering your Microsoft Entra private network connector through Azure, AWS, or GCP Marketplaces.
Use these PowerShell samples for Global Secure Access.
Learn how to access the Global Secure Access area of the Microsoft Entra admin center.
Learn how to Install the Windows client to acquire Microsoft traffic in Global Secure Access.
Learn how to configure per-app access to private resources in Global Secure Access.
Learn how to configure Quick Access to private resources in Global Secure Access.
Valid Global Secure Access configurations for custom remote network device links settings, including IKE, ASN, IPSec, and DH group.
ai-usage: ai-assisted
Learn about the built-in administrator roles you can assign to manage Global Secure Access permissions.
ai-usage: ai-assisted
Covers how to perform an unattended installation of the Microsoft Entra private network connector.
author: kenwith
author: kenwith
author: kenwith
Global Secure Access Threat intelligence threat types
author: kenwith
Global Secure Access Web content filtering categories
author: HULKsmashGithub
author: kenwith
This article provides an overview of the Transport Layer Security (TLS) inspection process and how it increases security between two communicating parties.
Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.
Learn about Continuous Access Evaluation (CAE) for Application Proxy (preview)
ai-usage: ai-assisted
A Microsoft Entra documentation page was updated: Application Usage Analytics.
Learn about endpoint detection and response and antivirus solution coexistence with Global Secure Access client.
Learn about the available Global Secure Access logs and monitoring options.
Learn about the capabilities and traffic handling in the Microsoft traffic profile
ai-usage: ai-assisted
Learn about the Microsoft Secure Access Service Edge (SASE) partner ecosystem. Learn about partner integrations and partner coexistence.
Install the Global Secure Access Windows client as a proof of concept. This script automates installation and applies essential configurations.
Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.
ai-usage: ai-assisted
Monitor the health and status of your network traffic with the Global Secure Access dashboard.
Learn about how traffic forwarding profiles for Global Secure Access streamline how you route traffic through your network.
author: idmdev
author: HULKsmashGithub
author: HULKsmashGithub
Understand critical IP address ranges to consider when configuring and troubleshooting internet over remote network connectivity.
Learn how to troubleshoot application access problems with the Global Secure Access Windows client.
A troubleshooting article that includes a workaround for a case where a Distributed File System (DFS) doesn't operate correctly with Global Secure Access.
author: HULKsmashGithub
author: HULKsmashGithub
author: HULKsmashGithub
Troubleshoot problems installing the Microsoft Entra private network connector.
Learn how to access, archive, and analyze the audit logs for Microsoft's Security Service Edge solution.
Learn how to use Global Secure Access traffic logs (preview) to monitor connections to the service, the type of traffic, and who's connecting.
author: jenniferf-skc
Learn how to check the health of your remote networks with the Global Secure Access remote network health logs.
Workbooks provide rich, interactive reports for Global Secure Access. Learn how to integrate workbooks with log analytics for Global Secure Access.
author: kenwith
Learn how to use enriched Microsoft 365 logs for Global Secure Access.
Microsoft and Cisco’s Security Service Edge (SSE) coexistence solution guide.
ai-usage: ai-assisted
Microsoft and Palo Alto Network’s Security Service Edge (SSE) coexistence solution guide.
Use this PowerShell script to generate and sign Transport Layer Security (TLS) certificates using OpenSSL in a test environment.
Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
ai-usage: ai-assisted
PowerShell examples that re-enable any Conditional Access policies that were disabled in a break glass scenario.
Learn how to Create a remote network, apply Conditional Access, and review the logs in Global Secure Access.
author: kenwith
author: HULKsmashGithub
Learn how to secure highly valued private application access with Privileged Identity Management (PIM) and Global Secure Access
author: shlipsey3