Grant Admin Consent
The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Developer.
The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.
The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.
The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
The Conditional Access What If tool table now uses a different sample UserId in all four examples.
The PowerShell example now uses a different Subject value for the managed identity federated credential.
The documentation changes the example `-Subject` value in the `New-AzADAppFederatedCredential` command.
The grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.
The documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.
The Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.
The permission-addition and permission-removal examples now use different sample object and client IDs.
The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.
The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.
The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.
The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.
The documentation explains how to access the Microsoft Application Network portal and submit requests to update SSO, MDM, or user provisioning details, upgrade SSO, or remove an application listing.
The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.
The user delegation section now spells out “on-behalf-of (OBO)” on first use. No feature behavior or requirements changed in the supplied diff.
The code sample now uses `<your-tenant-id>` instead of `<your-tenant>` for the `TenantId` value.
The documentation updates its C# examples, including distinct method names for UPN and object ID calls, a revised controller constructor signature, and clearer user-data method names.
The documentation now spells out “on-behalf-of (OBO)” on first use in the token scenario guidance. The referenced method is unchanged.
The Agent ID Microsoft Graph documentation now labels sample variables as `usersAppOnly` and `usersOnBehalfOfUser`, clarifying the scenarios they represent.
The documentation adds Microsoft Graph and Microsoft.Identity.Web imports, changes sample calls from Applications to Users, and clarifies that configured scopes must match the Graph resources used. Examples use User.Read and User.ReadBasic.All.
The documentation adds an OpenID Connect using directive and renames two C# sample variables: `applications` to `applicationsForUser` and `me` to `meByOid`.
The `TenantId` example value changed from `<my-test-tenant>` to `<your-tenant-id>` for clearer documentation.
The third-party agents documentation now labels the sidecar setup link “Configure Microsoft Entra ID Auth SDK for agent identities” instead of “Configure Entra ID Auth SDK.”
The documentation updates the C# sample’s imports, endpoint structure, downstream API call, and model declarations to provide valid create-agent-identity code.
The documentation now identifies app-only tokens as using client credentials, expands on-behalf-of to OBO, and consistently uses the `agent-identity-client-id` placeholder in request examples.
The documentation replaces “Entra ID Auth SDK” with “Microsoft Entra ID Auth SDK” in two descriptions. The endpoint formats and behavior are unchanged.
The Amazon Bedrock integration guide now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” in its description, explanations, container reference, and links. No behavior or availability change is described.
The documentation now lists how an agent with its own identity can communicate through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, including the permissions required for inbound and outbound communication.
The page title capitalization and image alt text were revised. No configuration or product behavior changes are shown.
The reference now links to license management in the Azure portal, updates the table as of August 3, 2026, adds Agent 365, and revises service and plan identifier entries.
You can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge by using an Intune mobile application management (MAM) policy. The policy can take advantage of the Explicit Forward Proxy feature of Global Secure Access.
After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.
1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.
This article shows the new and updated documentation for the Microsoft Entra application management.
ai-usage: ai-assisted
Learn how to publish your application in Microsoft Entra application gallery.
Learn how to use the Microsoft Entra Auth SDK (sidecar) to secure an Amazon Bedrock AI agent with its own identity for calling downstream APIs.
Learn how to validate Microsoft Entra Agent ID tokens in a downstream API by checking the signature, issuer, audience, and agent identity marker claim.
Learn how autonomous agents acquire tokens using the Microsoft Entra ID Auth SDK (sidecar) to call downstream APIs independently.
- [Configure Entra ID Auth SDK (sidecar) for agent identities](microsoft-entra-sdk-for-agent-identities.md)
Learn how to configure daemon apps that call web APIs using secrets, certificates, or client assertions.
This article shows the new and updated documentation for the Microsoft Entra application management.
Learn how to build a desktop app that calls web APIs to acquire a token for the app
Learn how to build a mobile app that calls web APIs. (Get a token for the app.)
Learn how to build a desktop app that calls web APIs to acquire a token for the app by using Web Account Manager.
Learn how to build a desktop app that calls web APIs to acquire a token for the app interactively.
Learn how to build a desktop app that calls web APIs to acquire a token for the app using device code flow
Learn how to build a daemon app that calls web APIs (acquiring tokens)
Learn how to add app roles to an application registered in Microsoft Entra ID. Assign users and groups to these roles, and receive them in the 'roles' claim in the token.
Add linked single sign-on to an application in Microsoft Entra ID.
Use Application discovery to detect the applications accessed by users and create separate private applications.
Learn answers to frequently asked questions (FAQ) about managing certificates for apps using Microsoft Entra ID as an Identity Provider (IdP).
Learn about the relationship between application and service principal objects in Microsoft Entra ID.
Learn how to build a single-page application that calls a web API
Learn how to build a mobile app that calls web APIs. (Call a web API.)
Learn how to configure and set up a custom email provider with the One Time Passcode Send event type.
Learn how to build a web API that calls web APIs (app's code configuration)
Learn how to configure the code of a web app that calls web APIs
Learn how to configure an application to trust a managed identity in Microsoft Entra ID.
Learn about multi-instancing, which is needed for configuring multiple instances of the same application within a tenant.
Learn how to configure the code of a desktop app that calls web APIs
Learn how to configure F5 BIG-IP Access Policy Manager and Microsoft Entra ID for secure hybrid access (SHA) to form-based applications.
Learn to implement secure hybrid access (SHA) with single sign-on (SSO) to header-based applications using F5 BIG-IP Easy Button Guided Configuration.
Learn to implement secure hybrid access (SHA) with single sign-on (SSO) to Kerberos applications using F5 BIG-IP Easy Button guided configuration.
Configure user consent settings in Microsoft Entra ID to control when and how users grant permissions to your organization's data. Secure your environment with step‑by‑step guidance.
A Microsoft Entra documentation page was updated: Configure Microsoft Edge with Explicit Forward Proxy (preview) by using an Intune application management policy.
Learn how to configure Microsoft Entra External ID with Azure Web Application Firewall.
Learn how to configure your mobile app's code to call a web API
Configure app management policies in Microsoft Entra ID to set restrictions on how apps and service principals in your tenant can be configured. Secure your environment with step‑by‑step guidance.
Learn how to build a single-page application (app's code configuration)
Learn to configure the F5 BIG-IP Access Policy Manager (APM) and Microsoft Entra ID for secure hybrid access to header-based applications that also require session augmentation through Lightweight Directory Access Protocol (LDAP) sourced attributes.
A Microsoft Entra documentation page was updated: Configure Workday Mobile Application for Single sign-on with Microsoft Entra ID.
Learn more about the Microsoft Entra consent experiences to see how you can use it when managing and developing applications on Microsoft Entra ID
Create an enterprise application using the client ID for a multitenant application.
A Microsoft Entra documentation page was updated: Customer intent: As an organization administrator, I want to customize the invitation process for external users using the Microsoft Graph REST API, so that I can tailor the onboarding experience and control the notifications sent to the users..
Describes directory extension attributes that are used for sending user data to applications in token claims.
Include file warning that access tokens for Microsoft Graph should be considered opaque and should never be validated by customer code. Only Microsoft Graph validates Microsoft Graph access tokens.
Learn about the customizable ways to deploy applications to end users in your organization with Microsoft Entra ID.
Learn how to acquire a token for a web app that calls web APIs
This article is a getting started guide for integrating Microsoft Entra ID with on-premises applications, and cloud applications.
Learn how to grant tenant-wide consent to an application so that end-users aren't prompted for consent when signing in to an application.
What does it mean for an application to be added to Microsoft Entra ID and how do they get there?
Learn how to build a daemon app that calls a web API.
Learn how to configure the code for your daemon application that calls web APIs (app configuration)
A Microsoft Entra documentation page was updated: How to use managed identities for Azure resources on an Azure VM with Azure SDKs .
Learn how to implement role-based access control in your applications.
manager: pmwongera
manager: pmwongera
manager: pmwongera
Discover how to configure agent identities for enterprise applications in Microsoft Entra ID. Assign roles, manage permissions, and streamline app interactions.
Comprehensive guide for the Microsoft Entra ID Windows Account Manager (WAM) API, detailing its usage, parameters, and integration in Windows applications.
This article describes phase 1 of planning migration of applications from AD FS to Microsoft Entra ID
This article describes phase 2 of planning migration of applications from AD FS to Microsoft Entra ID
This article describes phase 3 of planning migration of applications from AD FS to Microsoft Entra ID
This article describes phase 4 of planning migration of applications from AD FS to Microsoft Entra ID
Learn about tenant-level restrictions and controls for users, groups, and applications, along with policy management in a cloud-based portal.
These PowerShell samples are used for apps you manage in your Microsoft Entra tenant. You can use these sample scripts to find expiration information about secrets and certificates.
Learn best practices for transitioning from VPN replacement with Quick Access to per-application segmentation using Microsoft Entra Private Access.
Learn about the properties of an enterprise application in Microsoft Entra ID.
Learn to add pre-integrated apps to your Microsoft Entra tenant with clear, step-by-step instructions.
Download and run a code sample that shows how an ASP.NET web app can sign in Microsoft Entra users.
Download and run a code sample that shows how an ASP.NET web app can sign in Microsoft Entra users.
In this quickstart, learn how a JavaScript Angular single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
In this quickstart, learn how a JavaScript Angular single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
In this quickstart, learn how a JavaScript React single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
In this quickstart, learn how a JavaScript React single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow and call Microsoft Graph.
In this quickstart, learn how a JavaScript single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow.
In this quickstart, learn how a JavaScript single-page application (SPA) can sign in users of personal accounts, work accounts, and school accounts by using the authorization code flow.
Restore a soft deleted enterprise application in Microsoft Entra ID.
Learn how to review and restore revoked permissions for an application in Microsoft Entra ID.
Understand why an app management policy may block the addition of an identifier URI, and learn more about the policy and the restrictions it enforces on identifier URIs
Configure Microsoft Entra Private Access to tunnel specific application traffic through a private network for application's network-based access control policy.
Learn how to manage your external tenant by calling the Azure REST API.