Cross-product topic

Developer

A cross-product view of Microsoft Entra changes related to Developer.

Latest Developer changes

Grant Admin Consent

Developer

The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.

Grant Admin Consent

Developer

The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.

Manage App Consent Policies

Developer

The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

Manage App Consent Policies

Developer

The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

What If Tool

Developer

The Conditional Access What If tool table now uses a different sample UserId in all four examples.

Grant Admin Consent

Developer

The grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.

Manage App Consent Policies

Developer

The documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.

What If Tool

Developer

The Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.

Howto Update Permissions

Developer

The permission-addition and permission-removal examples now use different sample object and client IDs.

Howto Update Permissions

Developer

The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

Howto Update Permissions

Developer

The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.

Howto Update Permissions

Developer

The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.

Prerequisites to validate and publish your app

Developer

The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.

Prerequisites to validate and publish your app

Developer

The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.

Howto Update Permissions

Developer

The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.

Agent Tokens

Developer

The user delegation section now spells out “on-behalf-of (OBO)” on first use. No feature behavior or requirements changed in the supplied diff.

Call Api Azure Services

Developer

The code sample now uses `<your-tenant-id>` instead of `<your-tenant>` for the `TenantId` value.

Call Api Custom

Developer

The documentation updates its C# examples, including distinct method names for UPN and object ID calls, a revised controller constructor signature, and clearer user-data method names.

Call Api Custom

Developer

The documentation now spells out “on-behalf-of (OBO)” on first use in the token scenario guidance. The referenced method is unchanged.

Call Api Microsoft Graph

Developer

The Agent ID Microsoft Graph documentation now labels sample variables as `usersAppOnly` and `usersOnBehalfOfUser`, clarifying the scenarios they represent.

Call Api Microsoft Graph

Developer

The documentation adds Microsoft Graph and Microsoft.Identity.Web imports, changes sample calls from Applications to Users, and clarifies that configured scopes must match the Graph resources used. Examples use User.Read and User.ReadBasic.All.

Call Api Microsoft Graph

Developer

The documentation adds an OpenID Connect using directive and renames two C# sample variables: `applications` to `applicationsForUser` and `me` to `meByOid`.

Call Api Microsoft Graph

Developer

The `TenantId` example value changed from `<my-test-tenant>` to `<your-tenant-id>` for clearer documentation.

Configure Third Party Agents

Developer

The third-party agents documentation now labels the sidecar setup link “Configure Microsoft Entra ID Auth SDK for agent identities” instead of “Configure Entra ID Auth SDK.”

Create Delete Agent Identities

Developer

The documentation updates the C# sample’s imports, endpoint structure, downstream API call, and model declarations to provide valid create-agent-identity code.

Microsoft Entra Sdk For Agent Identities

Developer

The documentation now identifies app-only tokens as using client credentials, expands on-behalf-of to OBO, and consistently uses the `agent-identity-client-id` placeholder in request examples.

Microsoft Entra Sdk For Agent Identities

Developer

The documentation replaces “Entra ID Auth SDK” with “Microsoft Entra ID Auth SDK” in two descriptions. The endpoint formats and behavior are unchanged.

Secure an Amazon Bedrock agent with Microsoft Entra Agent ID

Developer

The Amazon Bedrock integration guide now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” in its description, explanations, container reference, and links. No behavior or availability change is described.

Grant Agent Access Microsoft 365

Developer

The documentation now lists how an agent with its own identity can communicate through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, including the permissions required for inbound and outbound communication.

Connect with the required scope

Developer

After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.

V2 Protocols Oidc

Developer

1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.

Validate Agent Tokens Downstream Api

Developer

Learn how to validate Microsoft Entra Agent ID tokens in a downstream API by checking the signature, issuer, audience, and agent identity marker claim.

Configure Third Party Agents

Developer

- [Configure Entra ID Auth SDK (sidecar) for agent identities](microsoft-entra-sdk-for-agent-identities.md)

Add app roles and get them from a token

Developer

Learn how to add app roles to an application registered in Microsoft Entra ID. Assign users and groups to these roles, and receive them in the 'roles' claim in the token.

Application Discovery

Developer

Use Application discovery to detect the applications accessed by users and create separate private applications.

Configure app multi-instancing

Developer

Learn about multi-instancing, which is needed for configuring multiple instances of the same application within a tenant.

Configure how users consent to applications

Developer

Configure user consent settings in Microsoft Entra ID to control when and how users grant permissions to your organization's data. Secure your environment with step‑by‑step guidance.

Configure the F5 BIG-IP Easy Button for Header-based and LDAP SSO

Developer

Learn to configure the F5 BIG-IP Access Policy Manager (APM) and Microsoft Entra ID for secure hybrid access to header-based applications that also require session augmentation through Lightweight Directory Access Protocol (LDAP) sourced attributes.

Don't validate access tokens for Microsoft Graph

Developer

Include file warning that access tokens for Microsoft Graph should be considered opaque and should never be validated by customer code. Only Microsoft Graph validates Microsoft Graph access tokens.

PowerShell samples in Application Management

Developer

These PowerShell samples are used for apps you manage in your Microsoft Entra tenant. You can use these sample scripts to find expiration information about secrets and certificates.

Private Access Segmentation Strategies

Developer

Learn best practices for transitioning from VPN replacement with Quick Access to per-application segmentation using Microsoft Entra Private Access.

Source IP anchoring with Global Secure Access

Developer

Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…