Describes how to create and export a connector from MIM Sync to be used with the Microsoft Entra ECMA Connector Host.
Application Proxy and provisioning guidance were the clearest changes on 6 February; External ID redemption was clarified, with no new Entra release evidenced.
This was a documentation-heavy period: 135 items were updated, 3 were removed, and there were no new items or Message Center notices. The most meaningful cluster was Microsoft Entra application proxy guidance, including PingAccess header-based authentication, header-based SSO, and Defender for Cloud Apps Conditional Access App Control, alongside API-driven inbound provisioning and its safeguards. The supplied records support documentation clarification and a named page removal—not a feature launch, preview or GA announcement, service retirement, or confirmed behavior change.
- PingAccess header-based authentication guidance was updated
Entra ID · Authentication
The updated Entra ID Microsoft Learn page covers header-based authentication with PingAccess and Microsoft Entra application proxy. It is an updated integration guide, not a stated introduction, preview, GA change, or authentication-behavior change. Administrators using this pattern should check the current guidance, but no specific tenant configuration change is identified.
- API-driven inbound provisioning documentation was refreshed
Entra ID · Fundamentals
The updated concepts page provides an overview of API-driven inbound provisioning. Related updates in the period cover implementations with Azure Logic Apps and PowerShell, provisioning-app configuration, API access, Microsoft Graph automation, and custom-attribute synchronization. This is a documentation refresh; the evidence does not establish a new API, changed availability, or migration requirement.
- Accidental-deletion prevention guidance for provisioning was updated
External ID · Provisioning
The updated provisioning-service page explains how to enable accidental-deletion prevention for applications and cross-tenant synchronization. It describes a safeguard administrators can configure; it does not say protection became the default or was automatically deployed. Relevant provisioning owners can verify the control, but the period supplies no mandatory change.
- External ID guest-redemption consent lifecycle was clarified
External ID · General
The updated Redemption Experience page states that a guest remains PendingAcceptance until accepting the invitation and agreeing to the privacy policy and terms of use; the status then becomes Accepted and the consent pages stop appearing. This is a clarification of documented behavior, not evidence of a behavior change. Because the status is viewable in PowerShell, it can help administrators diagnose incomplete redemption.
- The Federation Overview page was removed from Microsoft Learn
Entra ID · Fundamentals
The representative removed item is the Entra ID page titled Federation Overview. The evidence identifies a documentation-page removal only; it does not support calling the federation capability retired or require changes for federated tenants. Treat this as a documentation-lifecycle event.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
138 updates
Microsoft Entra ID
134 updatesLearn how to provision custom security attributes from HR sources.
This article lists all releases of Microsoft Entra Connect Provisioning Agent and describes new features and fixed issues.
Learn how to implement API-driven inbound provisioning with Azure Logic Apps.
Learn how to implement API-driven inbound provisioning with a PowerShell script.
Learn how to configure API-driven inbound provisioning app.
Enable Termination Lookahead query for your Workday-to-AD/Microsoft Entra ID provisioning job.
A guide for independent software vendors for enabling automated provisioning in Microsoft Entra ID
Learn how to export your Application Provisioning configuration and roll back to a known good state for disaster recovery in Microsoft Entra ID.
Learn how to extend API-driven inbound provisioning to sync custom attributes.
Find out when a specific user is able to access an app in Microsoft Entra Application Provisioning
UpdatedHow to find out when a critically important user is able to access an application you have configured for user provisioning with Microsoft Entra ID.
Learn more about the capabilities and integration scenarios supported by API-driven inbound provisioning.
Learn how to grant access to the inbound provisioning API.
Learn how to get index the employeeId attribute to automate user account creation and updates from Inbound Provisioning to Active Directory
Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.
Learn how to integrate Microsoft Entra Provisioning logs with Azure Monitor logs and use the associated workbooks.
Technical deep dive into SAP SuccessFactors-HR driven provisioning for Microsoft Entra ID.
Technical deep dive into Workday-HR driven provisioning in Microsoft Entra ID
This document describes how to configure Microsoft Entra ID to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer REST and SOAP APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer Windows PowerShell based APIs.
This document describes how to configure Microsoft Entra ID to provision users with external systems that offer web services based APIs.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory.
Use partner driven integrations to provision accounts into all your applications.
Guidance for planning and executing automatic user provisioning in Microsoft Entra ID
Preparing for Microsoft Entra provisioning to Active Directory Lightweight Directory Services
UpdatedThis document describes how to configure Microsoft Entra ID to provision users into Active Directory Lightweight Directory Services as an example of an LDAP directory.
Learn how to provision users on demand in Microsoft Entra ID.
Learn how to simplify user provisioning with Expression Builder, handle duplicate users, and transform user attributes for seamless integration.
Provisioning users into SQL based applications using the ECMA Connector host
Provisioning Workbook
UpdatedThis article describes the Azure Monitor workbook for provisioning.
When you've configured an application for automatic user provisioning, learn what a provisioning status of Quarantine means and how to clear it.
Learn how to get started quickly with API-driven inbound provisioning using Graph Explorer
This tutorial provides step-by-step instructions so you can get started with API-driven inbound provisioning using cURL.
Reference for writing expressions for attribute mappings in Microsoft Entra Application Provisioning
UpdatedLearn how to use expression mappings to transform attribute values into an acceptable format during automated provisioning of SaaS app objects in Microsoft Entra ID. Includes a reference list of functions.
Learn how to retrieve pronoun information from Workday
Learn which attributes from SuccessFactors are supported by SuccessFactors-HR driven provisioning in Microsoft Entra ID.
Learn how to use scoping filters to define attribute-based rules that determine which users or groups are provisioned in Microsoft Entra ID.
Learn how to override the default behavior of deprovisioning out of scope users in Microsoft Entra ID.
A comprehensive guide to commonly used expression mapping functions when configuring SuccessFactors to Microsoft Entra ID user provisioning. These functions help transform and map data from SuccessFactors to create appropriate user attributes in Microsoft Entra ID.
When configuring user provisioning with Microsoft Entra ID and SaaS apps, use the directory extension feature to add source attributes that aren't synchronized by default.
Learn about attribute mappings for Software as a Service (SaaS) apps in Microsoft Entra Application Provisioning. Learn what attributes are and how you can modify them to address your business needs.
Tutorial Ecma Sql Connector
UpdatedThis tutorial describes how to provision users from Microsoft Entra ID into a SQL database.
Understand how Application Provisioning works in Microsoft Entra ID.
Understand how expression builder works with Application Provisioning in Microsoft Entra ID.
Learn how to manage user account provisioning for enterprise apps using the Microsoft Entra ID.
New and updated documentation for the Azure Active Directory application provisioning.
Learn which attributes that you can fetch from Workday using XPATH queries in Microsoft Entra ID.
A comprehensive guide to commonly used expression mapping functions when configuring Workday to on-premises Active Directory/Microsoft Entra ID user provisioning. These functions help transform and map data from Workday to create appropriate user attributes in Microsoft Entra ID.
Use Microsoft Entra application proxy to access your on-premises application through Microsoft Teams.
Access on-premises Application Programming Interface (API) with Microsoft Entra application proxy
UpdatedUse Microsoft Entra application proxy to provide secure access to an Application Programming Interface (API) hosted in a private cloud or on premises.
Add an on-premises application for remote access through application proxy in Microsoft Entra ID.
UpdatedMicrosoft Entra ID has an application proxy service that enables users to access on-premises applications by signing in with their Microsoft Entra account. This tutorial shows you how to prepare your environment for use with application proxy. Then, it uses the Microsoft Entra admin center to add an on-premises application to your Microsoft Entra tenant.
Learn how to combine the application proxy service with a Traffic Manager solution.
Microsoft Entra ID uses access and session cookies to access on-premises applications through application proxy. This article explains how to use and configure the cookie settings.
How to publish on-premises ASP.NET applications that accept Active Directory Federation Services claims for secure remote access by your users.
Understand complex applications in Microsoft Entra application proxy.
Configure and manage custom domains in Microsoft Entra application proxy.
Learn how to set a custom home page for published apps using Microsoft Entra application proxy to ensure users land on the correct page.
Learn about debugging issues that occur when configuring Microsoft Entra application proxy.
Covers the basics about how to integrate an on-premises Power BI with Microsoft Entra application proxy.
Covers the basics about how to integrate on-premises SharePoint Server with Microsoft Entra application proxy.
How traffic distribution works with your application proxy deployment. Includes tips for how to optimize connector performance and use load balancing for back-end servers.
Covers how to provide single sign-on using Microsoft Entra application proxy.
PowerShell example that lists all Microsoft Entra private network connector groups with the assigned applications.
Integrate Microsoft Entra application proxy with Qlik Sense.
Learn how to use Microsoft Entra application proxy to provide remote access for your Tableau deployment.
PowerShell example that assigns a group to a Microsoft Entra application proxy application.
PowerShell example that assigns a user to a Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications in your directory that have a lifetime token policy.
PowerShell example that lists Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), and object ID (ObjId).
PowerShell example that lists all Microsoft Entra application proxy applications that are using wildcards.
PowerShell example that lists all the users and groups assigned to a specific Microsoft Entra application proxy application.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains and certificate information.
PowerShell example that lists all Microsoft Entra application proxy applications that are using default domains (.msappproxy.net).
PowerShell example that lists all Microsoft Entra application proxy applications that are published with the identical certificate.
PowerShell example that lists all Microsoft Entra application proxy applications that are using custom domains but don't have a valid TLS/SSL certificate uploaded.
Microsoft Entra application proxy PowerShell example used to move all applications currently assigned to a connector group to a different connector group.
PowerShell example that bulk replaces a certificate across Microsoft Entra application proxy applications.
Use these PowerShell samples for Microsoft Entra application proxy to get information about application proxy apps and connectors in your directory, assign users and groups to apps, and get certificate information.
Publish native client apps
UpdatedCovers how to enable native client apps to communicate with the Microsoft Entra private network connector to provide secure remote access to your on-premises apps.
Covers how to configure application proxy with Remote Desktop Services (RDS)
Remove personal data from connectors installed on devices for Microsoft Entra application proxy.
Learn how to identify and resolve cross-origin resource sharing (CORS) issues in Microsoft Entra application proxy.
Learn how to redirect hard coded links for applications published with Microsoft Entra application proxy.
Understand single sign-on with an on-premises app using application proxy.
Optimize performance for global connectivity scenarios using Azure Front Door for geo-acceleration with Microsoft Entra application proxy.
Learn how to use Wildcard applications in Microsoft Entra application proxy.
Covers how to work with existing on-premises proxy servers with Microsoft Entra ID.
Troubleshoot problems with broken links in application proxy apps that are integrated with Microsoft Entra ID.
Describes how to troubleshoot various issues you might encounter when you install and use the ECMA Connector Host.
Learn how to check the status of automatic user account provisioning jobs, and how to troubleshoot the provisioning of individual users.
Learn how to troubleshoot errors in Microsoft Entra application proxy.
Learn how to troubleshoot attribute retrieval issues with HR provisioning
Learn how to troubleshoot InsufficientAccessRights error when provisioning to on-premises Active Directory.
This article provides potential issues and resolutions that guide you in how to troubleshoot issues with the inbound provisioning API.
Learn how to troubleshoot a Kerberos constrained delegation (KCD) configuration in Microsoft Entra application proxy.
This article provides potential issues and resolutions that show you how to troubleshoot manager update issues with HR provisioning
How to troubleshoot common issues faced when configuring user provisioning to an application already listed in the Microsoft Entra application gallery.
Learn how to troubleshoot user creation issues with HR provisioning
Learn how to troubleshoot user update issues with HR provisioning
This article provides potential issues and resolutions so you can troubleshoot writeback issues with HR provisioning.
Troubleshoot common issues faced when a user isn't appearing in a Microsoft Entra Gallery Application configured for user provisioning with Microsoft Entra ID.
Understand why to use application proxy to publish on-premises web applications externally to remote users. Learn about application proxy architecture, connectors, authentication methods, and security benefits.
Learn how to provide single sign-on (SSO) for on-premises applications that are secured with Security Assertion Markup Language (SAML) authentication. Provide remote access to on-premises apps with application proxy.
Support header-based authentication with PingAccess and Microsoft Entra application proxy.
Header-based single sign-on (SSO) for on-premises apps with Microsoft Entra application proxy
UpdatedLearn how to provide single sign-on for on-premises applications that are secured with header-based authentication.
This document describes how to configure Microsoft Entra ID to provision users into an LDAP directory so that the users can then sign into a Linux or other POSIX system using pluggable authentication.
PowerShell example that lists all Microsoft Entra application proxy applications along with the application ID (AppId), name (DisplayName), external URL (ExternalUrl), internal URL (InternalUrl), and authentication type (ExternalAuthenticationType).
Learn how to resolve common access issues with Microsoft Entra application proxy applications.
Turn on single sign-on for your published on-premises applications with Microsoft Entra application proxy in the Microsoft Entra admin center.
Sspr
RemovedA Microsoft Entra documentation page was updated: Sspr.
An overview of API-driven inbound provisioning.
Federation Overview
RemovedA Microsoft Entra documentation page was updated: Federation Overview.
An end-to-end guide for planning the deployment of application proxy within your organization
Sso Overview
RemovedA Microsoft Entra documentation page was updated: Sso Overview.
Learn how to use Microsoft Entra application proxy connectors.
An introduction to how you can use Microsoft Entra ID to automatically provision, deprovision, and continuously update user accounts across multiple third-party applications.
Describes overview of HR driven provisioning.
Learn how to integrate an on premises SharePoint farm with Microsoft Entra application proxy using Security Assertion Markup Language (SAML).
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
How to solve common protocol compatibility issues faced when adding a non-gallery application that supports SCIM 2.0 to Microsoft Entra ID
This article describes how to use the Microsoft Entra provisioning service to provision users into an on-premises app that's SCIM enabled.
System for Cross-domain Identity Management (SCIM) standardizes automatic user provisioning. In this tutorial, you learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and start automating provisioning users and groups into your cloud applications.
Tutorial - Test your SCIM endpoint for compatibility with the Microsoft Entra provisioning service.
UpdatedThis tutorial describes how to use the Microsoft Entra SCIM Validator to validate that your provisioning server is compatible with the Azure SCIM client.
Use SCIM, Microsoft Graph, and Microsoft Entra ID to provision users and enrich apps with data
UpdatedUsing SCIM and the Microsoft Graph together to provision users and enrich your application with the data it needs in Microsoft Entra ID.
Covers security considerations for using Microsoft Entra application proxy
Learn how to use Microsoft Entra application proxy to protect your Network Device Enrollment Service (NDES).
How to add Web Application Firewall (WAF) protection for apps published with Microsoft Entra application proxy.
Covers network topology considerations when using Microsoft Entra application proxy.
Securely integrate Azure Logic Apps with on premises APIs using Microsoft Entra application proxy
UpdatedMicrosoft Entra application proxy lets cloud-native logic apps securely access on premises APIs to bridge your workload.
Presents an overview of on-premises application provisioning architecture.
Use Microsoft Defender for Cloud Apps with on-premises applications in Microsoft Entra ID. Use the Defender for Cloud Apps Conditional Access App Control to monitor and control sessions in real-time based on Conditional Access policies. You apply these policies to on-premises applications that use application proxy in Microsoft Entra ID.
PowerShell example that lists all Microsoft Entra private network connector groups and connectors in your directory.
This article describes the deployment process of integrating cloud HR systems, such as Workday and SuccessFactors, with Microsoft Entra ID. Integrating Microsoft Entra ID with your cloud HR system results in a complete identity lifecycle management system.
Learn how to save time by using the Microsoft Graph APIs to automate the configuration of automatic provisioning.
Microsoft Entra ID Governance
1 update| Catalog owner | `ae79f266-94d4-4dab-b730-feca7e132178` | Edit and manage access packages and other resources in a catalog. Typically an IT administrator or resource owners, or an identity who the catalog owner chooses. |
Microsoft Entra External ID
3 updatesRedemption Experience
UpdatedWhen you add a guest user to your directory, the guest user account has a consent status (viewable in PowerShell) that's initially set to **PendingAcceptance**. This setting remains until the guest accepts your invitation and agrees to your privacy policy and terms of use. After that, the consent status changes to **Accepted**, and the consent pages are no longer presented to the guest.
If you don’t have an Azure subscription, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin.
Enable accidental deletions prevention in the Microsoft Entra provisioning service for applications and cross-tenant synchronization.
