Cross-product topic

Fundamentals

A cross-product view of Microsoft Entra changes related to Fundamentals.

Latest Fundamentals changes

Group Source Of Authority Guidance

Fundamentals

The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.

Microsoft Entra provisioning options (Preview)

Fundamentals

A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.

Provision Microsoft Entra ID objects to AD

Fundamentals

A new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.

Source Of Authority Overview

Fundamentals

The documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.

Netskope Integration

Fundamentals

The Netskope integration example now uses different values for the tenantId and userId fields.

Primary Refresh Token

Fundamentals

The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.

Understanding Lifecycle Workflows

Fundamentals

The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.

Create New Tenant

Fundamentals

The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.

Create New Tenant

Fundamentals

The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.

Create New Tenant

Fundamentals

The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.

Deployment Guide

Fundamentals

The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.

Deployment Guide

Fundamentals

The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.

Deployment Guide

Fundamentals

The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.

Quickstart - Access and create new tenant

Fundamentals

The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.

Secure add-on tenant creation

Fundamentals

The page title no longer includes “(preview),” and the prerelease product notice was removed.

Lifecycle Workflow Tasks

Fundamentals

The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.

Token Protection

Fundamentals

The documentation now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.

Assign App Owners

Fundamentals

The documentation now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application scope.

Web filtering in Global Secure Access (V2)

Fundamentals

The documentation now explains that V2 selects the first applicable profile containing a V2 policy, does not support user or group targeting on individual rules, and may produce different enforcement from V1 during migration.

Web Filtering

Fundamentals

The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.

Concepts Replica Sets

Fundamentals

The documentation now states that replica sets require connectivity between all virtual networks hosting them. They are deployed in one Active Directory site and rely on a fully meshed virtual network topology for directory replication.

Inheritable Permissions

Fundamentals

The page no longer includes a TODO questioning support for enumerated scopes versus `allAllowed`/`none`. The diff provides no evidence of a product or feature change.

Key Concepts

Fundamentals

The key concepts page now labels the link “Microsoft Entra Agent ID OAuth protocols” instead of “oauth protocols.”

Security For Ai Overview

Fundamentals

The documentation now expands MCP, A2A, and OBO on first use to improve clarity and retrievability.

Workload Identity Federation

Fundamentals

The concept page now points to first-party tutorials for Google Cloud and SPIFFE/SPIRE scenarios instead of the previous links. No product feature change is indicated.

Web filtering in Global Secure Access (V2)

Fundamentals

A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.

Token Protection

Fundamentals

The page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. iOS/iPadOS browser support is not supported. The page also adds requirements for supported browsers, extensions, operating systems, and configurations.

Licensing Agent Id

Fundamentals

The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.

Token Protection

Fundamentals

The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.

Explicit Forward Proxy overview

Fundamentals

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

Proxy Automatic Configuration Files

Fundamentals

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

Archive for Microsoft Entra releases and announcements

Fundamentals

The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.

Configure Security

Fundamentals

A Microsoft Entra documentation page was updated: Configure Security.

Frontline Worker Management

Fundamentals

Learn about frontline worker management capabilities that are provided through the My Staff portal.

Microsoft Entra releases and announcements

Fundamentals

Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.

Migrate Group Writeback

Fundamentals

- Cloud-created [security groups](../../../fundamentals/concept-learn-about-groups.md#group-types).

Overview

Fundamentals

> [!IMPORTANT]

Operations

Fundamentals

| Guide | What it covers |

Add Member To Group

Fundamentals

Now that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.md#create-a-basic-group-and-add-members).

Bulk Operations

Fundamentals

- [Bulk operations service limitations](bulk-operations-service-limitations.md)

Compare

Fundamentals

|**Users**|||

Create New Tenant

Fundamentals

- To add users, see [Add or delete a new user](./how-to-create-delete-users.md).

Delegate By Task

Fundamentals

Here are the least privileged roles you should use when performing tasks for [groups](../../fundamentals/how-to-manage-groups.md) in Microsoft Entra ID.

Groups Concept

Fundamentals

- [Create a role-assignable group](groups-create-eligible.md)

Groups Dynamic Membership

Fundamentals

- [Manage Microsoft Entra groups and group membership](~/fundamentals/how-to-manage-groups.md)

How to manage groups

Fundamentals

Instructions about how to create and update Microsoft Entra groups, such as membership and settings.

Learn About Groups

Fundamentals

- For more information, see [Learn about Microsoft 365 Groups](https://support.office.com/article/learn-about-office-365-groups-b565caa1-5c40-40ef-9915-60fdb2d97fa2).

Microsoft Entra releases and announcements

Fundamentals

Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.

Users Default Permissions

Fundamentals

An owner can also add or remove other owners. Unlike those users assigned at least the [Groups Administrator](../identity/role-based-access-control/permissions-reference.md#groups-administrator) role, owners can manage only the groups that they own and they can add or remove group members only if the group's membership type is **Assigned**.

Source Ip Restoration

Fundamentals

- It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks).

Source Ip Restoration

Fundamentals

- It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks).

Add your custom domain

Fundamentals

Instructions about how to add your custom domain name to your tenant.

Default user permissions

Fundamentals

Compare the default user permissions available in Microsoft Entra ID and learn how to restrict access.

Directory Overview User Model

Fundamentals

Managing user license assignments individually is time consuming and error prone. If you [assign licenses to groups](~/fundamentals/licensing.md?context=azure/active-directory/users-groups-roles/context/ugr-context) instead, you experience easier large-scale license management.

Group Based Licensing

Fundamentals

Learn about Microsoft Entra group-based licensing, including how it works,

Risk Detection Types

Fundamentals

Learn about risk detections and risk levels, including the difference between real-time and offline detections.

Security Customers

Fundamentals

Each layer addresses a different class of attacks, reducing the likelihood of compromise and limiting the blast radius.

Key Concepts

Fundamentals

Traditional service principals were designed for static, deterministic workloads. Microsoft Entra Agent ID exists because service principals lack the governance infrastructure AI agents need. There's no enforced sponsorship, no agent-aware audit entries, and no blueprint-managed lifecycle. For more information, see [Agent identities, service principals, and applications](agent-service-principals.md).

Whats New Ignite 2025

Fundamentals

- [Call API: Azure services](../agent-id/call-api-azure-services.md) (New)

Application Usage Analytics Overview

Fundamentals

Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.

Data protection considerations

Fundamentals

Learn how services store and retrieve Microsoft Entra object data through an RBAC authorization layer.

Device Registration

Fundamentals

A Microsoft Entra documentation page was updated: Device Registration.

Directory Join

Fundamentals

A Microsoft Entra documentation page was updated: Directory Join.

Frontline Worker Management

Fundamentals

Learn about frontline worker management capabilities that are provided through the My Staff portal.

Hybrid Join

Fundamentals

A Microsoft Entra documentation page was updated: Hybrid Join.

Learn about Global Secure Access Alerts

Fundamentals

Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.

Learn how agent identity deletion works

Fundamentals

Learn how deleting an agent identity blueprint triggers automatic cleanup of child agent identities in Microsoft Entra, and how to restore deleted objects.

Macos Psso

Fundamentals

Overview of macOS Platform Single Sign On (PSSO) for Microsoft Entra ID registered devices.

Microsoft Entra releases and announcements

Fundamentals

Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…