Privileged Identity Management Custom Extensions
The documentation now uses revised Application (client) ID examples in the endpoint URI and `resourceId` configuration sample.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra ID Governance.
Microsoft Learn documentation ↗The documentation now uses revised Application (client) ID examples in the endpoint URI and `resourceId` configuration sample.
The documentation now consistently uses a different application client ID in the endpoint URI, calling application claim, and `resourceId` examples.
The guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.
The documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.
The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.
The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.
The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.
Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.
The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.
The allowed offset for Days from event, and Days to event when using Between, increased from 180 to 365 days.
The Event user attribute description in the lifecycle workflow execution conditions documentation was reformatted.
Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.
The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.
The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.
The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.
The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.
The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.
The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.
The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.
The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.
The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.
The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).
The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.
The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.
The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.
The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.
The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.
The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.
The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.
The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.
The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.
The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.
The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.
The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.
The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.
The tutorial now includes a task that removes all access package assignments for a user, scheduled by default for 15 days.
The documentation now covers delegating multi-resource access reviews in addition to access package approvals. It also documents restrictions for delegate selection and maximum delegation duration.
The access package assignments page no longer includes a note stating that assignment managers cannot bypass required approval settings or directly assign identities without approval.
The documentation now expands its guidance that administrators must verify users meet existing access package policy requirements before assigning them; otherwise, assignment may fail.
The documentation removes an inaccurate statement implying that direct assignment to an access package requires approval. It now states only that assigned users must meet the policy’s eligibility requirements.
The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.
The documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.
The page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.
The guide removes the Preview label and adds steps for creating the resource and Logic App, automatic upload notifications, manual result application, and new resource parameters.
The page no longer labels the capability as Preview and now documents catalog resource setup, Logic App integration, manual uploads, and applying results to non-Approve decisions. The previous note about single-stage reviews with manager reviewers was removed.
The governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.
The documentation now states that support for the `memberOf` rule operator ends November 3, 2026, replacing October 27, 2026. Policies using it will be quarantined and stop processing assignments from that date.
The documentation states that, starting October 27, 2026, automatic assignment policies using memberOf will be quarantined. Assignment processing will stop, and no assignments will be added or removed until memberOf is removed.
When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.
Learn how to assign or remove the application permissions and roles that the Tenant Configuration Management service uses to create snapshots and run monitors
Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift
Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.
Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
This article walks you through managing unsponsored guests using the **Unsponsored guest cleanup (Preview)** workflow template.
Learn how to view monitor results and configuration drifts and manage configuration monitors in Microsoft Entra Tenant Governance
Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.
In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.
- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn how to use Microsoft Graph to retrieve the underlying users and applications behind Tenant Governance related tenant discovery signals.
With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.
The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.
Learn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.
Learn how Microsoft Entra ID is licensed for guest users.
Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Assign Azure RBAC roles to access packages and catalogs in Microsoft Entra Entitlement Management. Learn how to manage access with least privilege principles.
Learn how to set tenant-wide and workflow-specific execution limits and manage quarantined workflows in Lifecycle Workflows to prevent large-scale impact.
This article a tutorial on how to provision users and groups using cloud sync.
This article a tutorial on how to provision users and groups from and managed in Microsoft Entra ID to Active Directory.
This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
Learn how to set tenant-wide and workflow-specific execution limits and manage quarantined workflows in Lifecycle Workflows to prevent large-scale impact.
1. Assign all discovered users to a specific access package:
Learn how to configure whether requestors can see approver details for pending access package requests in the My Access portal at the tenant or package level.
In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.
Guest users that already existed in your tenant by being invited are ungoverned. After an ungoverned guest that requests access packages lose their last access package assignment, they'll remain in the tenant indefinitely. If there are guests that have an access package assignment, and only need access from that access package, and there's no other need for them to remain in the tenant, you can convert them to be governed during the time they have that access package assignment. You can directly convert those ungoverned users to be governed by using the **Mark Guests as Governed** functionality in the top menu bar of an access package.
To determine the least privileged role for a task, you can also reference [Least privileged roles by task in Microsoft Entra ID](../identity/role-based-access-control/delegate-by-task.md#entitlement-management-least-privileged-roles).
This article describes how to reprocess assignments in an existing access package.
- The ability to see active access package assignment of all of their direct reports.
This article a tutorial on how to provision users and groups using cloud sync.
This article a tutorial on how to provision users and groups using connect sync.
This article a tutorial on how to provision users and groups from and managed in Workday.
This article a tutorial on how to provision users and groups to AD with Workday.
This article a tutorial on how to provision users and groups to Active Directory using MIM.
This article describes use cases Microsoft Entra ID Governance.
This article is for use by the delivery expert that plans on delivering the Microsoft Entra Suite Workshop to customers. It aims to provide delivery experts with a comprehensive overview of the tasks that is required to successfully deliver the Microsoft Entra Suite Workshop to customers. It's structured chronologically following the standard and typical flow of a workshop delivery. It outlines how to use the Microsoft Entra Suite Workshop to deploy all the components of the suite. It gives organizations and IT admins a detailed plan to design and deploy Microsoft Entra ID Governance, Microsoft Entra Private Access, Microsoft Entra Internet Access, and Microsoft Entra Verified ID.
Learn how to configure custom extensions in Microsoft Entra Privileged Identity Management (PIM) to integrate custom business logic into role activation workflows.
Account Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).
1. Browse to **ID Governance** > **Entitlement management** > **Access packages**.
Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.
Learn how to view, add, and remove assignments for an access package in entitlement management.
Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.
Learn how Microsoft Entra Tenant Governance automatically establishes governance relationships when you create add-on tenants using secure tenant creation.
Learn about configuration management capabilities in Microsoft Entra Tenant Governance, including baselines and drift monitoring
Learn how to create a new Microsoft Entra tenant using the secure add-on tenant creation workflow in Tenant Governance
Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift
Learn about cross-tenant delegated administration and how it enables centralized management across tenants in Microsoft Entra
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization
Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Learn about governance relationships and how they enable centralized management of tenants in Microsoft Entra Tenant Governance
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn which Microsoft Entra Tenant Governance features are available with each license tier, including P1, P2, and ID Governance
Learn how to monitor and audit governing tenant administrator activity in your governed tenant using sign-in and audit logs
1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn how to view monitor results and detect configuration drifts in Microsoft Entra Tenant Governance using the admin center
Learn how to set up a governance relationship between a governing and governed tenant using the handshake process in Microsoft Entra
Learn how to set up the required application permissions and roles for tenant monitoring in Microsoft Entra Tenant Governance
Learn about the signals and metrics used in Microsoft Entra Tenant Governance to identify and evaluate related tenants
Learn how to terminate a governance relationship between tenants in Microsoft Entra Tenant Governance and understand what resources are removed