Product

Microsoft Entra ID Governance

Track documentation and Message Center changes for Microsoft Entra ID Governance.

Microsoft Learn documentation ↗

Latest Microsoft Entra ID Governance changes

Road To The Cloud Implement

Architecture

The guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.

Source Of Authority Overview

Fundamentals

The documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.

Create Tenant

Governance

The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.

Create Tenant

Governance

The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.

Create Lifecycle Workflow

Governance

The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.

Create Lifecycle Workflow

Governance

Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.

Entitlement Management Request Behalf

Governance

The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.

Lifecycle Workflow Execution Conditions

Governance

Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.

Understanding Lifecycle Workflows

Governance

The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.

Understanding Lifecycle Workflows

Fundamentals

The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.

Automatic formation of governance relationships

Governance

The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.

Automatic formation of governance relationships

Governance

The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.

Automatic Governance Relationships

Governance

The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.

Create a governed workforce tenant

Governance

The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.

Create Lifecycle Workflow

Governance

The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.

Create Tenant

Governance

The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.

Create Tenant

Governance

The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.

Create Tenant

Governance

The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).

Create Tenant

Governance

The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.

Create Tenant

Governance

The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.

Create Tenant

Governance

The document’s `ms.author` metadata changed from `tafra00` to `tazkiaafra`.

Create Tenant

Governance

The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.

Create Tenant

Governance

The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.

Create Tenant

Governance

The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.

Deploy Microsoft Entra Tenant Governance end to end

Governance

The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.

Deployment Guide

Fundamentals

The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.

Deployment Guide

Fundamentals

The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.

Deployment Guide

Fundamentals

The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.

Lifecycle Workflow Tasks

Fundamentals

The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.

Lifecycle Workflow Templates

Governance

The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.

Lifecycle Workflows Deployment

Governance

The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.

Lifecycle Workflows Tasks Table

Governance

The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.

Entitlement Management Access Package Assignments

Governance

The access package assignments page no longer includes a note stating that assignment managers cannot bypass required approval settings or directly assign identities without approval.

Entitlement Management Access Package Request Policy

Governance

The documentation now expands its guidance that administrators must verify users meet existing access package policy requirements before assigning them; otherwise, assignment may fail.

Entitlement Management Access Package Request Policy

Governance

The documentation removes an inaccurate statement implying that direct assignment to an access package requires approval. It now states only that assigned users must meet the policy’s eligibility requirements.

Entitlement Management Delegate

Governance

The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.

Catalog Access Reviews

Governance

The documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.

Catalog Access Reviews

Governance

The page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.

Licensing Governance

Governance

The governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.

Automatic Governance Relationships

Governance

When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.

Create a configuration monitor

Governance

Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift

Create a governed workforce tenant

Governance

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

Create configuration snapshots

Governance

Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence

Cross-tenant delegated administration

Governance

Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.

Customize Workflow Email

Governance

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.

Governance Policy Templates

Governance

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

Interpret tenant discovery data

Governance

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

Lifecycle Workflow Tasks

Governance

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:

Related tenants in Tenant Governance

Governance

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

Lifecycle Workflow Inactive Users

Governance

1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.

Lifecycle Workflow Templates

Governance

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

Governance Policy Templates

Governance

Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra

Entitlement Management Access Package Assignments

Governance

In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.

Entitlement Management Access Package Manage Lifecycle

Governance

Guest users that already existed in your tenant by being invited are ungoverned. After an ungoverned guest that requests access packages lose their last access package assignment, they'll remain in the tenant indefinitely. If there are guests that have an access package assignment, and only need access from that access package, and there's no other need for them to remain in the tenant, you can convert them to be governed during the time they have that access package assignment. You can directly convert those ungoverned users to be governed by using the **Mark Guests as Governed** functionality in the top menu bar of an access package.

Entitlement Management Delegate

Governance

To determine the least privileged role for a task, you can also reference [Least privileged roles by task in Microsoft Entra ID](../identity/role-based-access-control/delegate-by-task.md#entitlement-management-least-privileged-roles).

Microsoft Entra Suite workshop delivery guide

Architecture

This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entra Suite Workshop to customers. It's structured chronologically following the standard and typical flow of a workshop delivery. It outlines how to use the Microsoft Entra Suite Workshop to deploy all the components of the suite. It gives organizations and IT admins a detailed plan to design and deploy Microsoft Entra ID Governance, Microsoft Entra Private Access, Microsoft Entra Internet Access, and Microsoft Entra Verified ID.

Licensing Fundamentals

Fundamentals

Account Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).

Identity Governance Overview

Fundamentals

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

Migrate From Sap Idm

Governance

In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.

Lifecycle Workflow Tasks

Governance

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

Create a monitor (preview)

Governance

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

Enable tenant discovery (preview)

Governance

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

Pim How To Add Role To User

Governance

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…