Group Source Of Authority Guidance
The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Fundamentals.
The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.
A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.
A new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.
The documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.
The Netskope integration example now uses different values for the tenantId and userId fields.
The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.
The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.
The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.
The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.
The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.
The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.
The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.
The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.
The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.
The page title no longer includes “(preview),” and the prerelease product notice was removed.
The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.
The documentation now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.
The documentation now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application scope.
The documentation now explains that V2 selects the first applicable profile containing a V2 policy, does not support user or group targeting on individual rules, and may produce different enforcement from V1 during migration.
The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.
The documentation now states that replica sets require connectivity between all virtual networks hosting them. They are deployed in one Active Directory site and rely on a fully meshed virtual network topology for directory replication.
The page no longer includes a TODO questioning support for enumerated scopes versus `allAllowed`/`none`. The diff provides no evidence of a product or feature change.
The key concepts page now labels the link “Microsoft Entra Agent ID OAuth protocols” instead of “oauth protocols.”
The document title was normalized by removing an extra space after the metadata colon. No substantive guidance or product behavior changed.
The documentation now expands MCP, A2A, and OBO on first use to improve clarity and retrievability.
The concept page now points to first-party tutorials for Google Cloud and SPIFFE/SPIRE scenarios instead of the previous links. No product feature change is indicated.
A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.
The page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. iOS/iPadOS browser support is not supported. The page also adds requirements for supported browsers, extensions, operating systems, and configurations.
The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.
The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:
For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).
- [Global Secure Access traffic forwarding profiles](concept-traffic-forwarding.md)
Learn how unified risk signals correlate identity risk across Microsoft Entra ID Protection and Microsoft Defender to calculate compounded user risk.
The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.
Learn about where Microsoft Entra ID stores identity-related data for its European customers.
Learn about where Microsoft Entra ID stores customer-related data for its Japan customers.
Learn about frontline worker management capabilities that are provided through the My Staff portal.
Learn about bring your own device (BYOD) with the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
This article describes shows the licensing requirements for Microsoft Entra ID Governance features.
Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.
- Cloud-created [security groups](../../../fundamentals/concept-learn-about-groups.md#group-types).
Now that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.md#create-a-basic-group-and-add-members).
- [Bulk operations service limitations](bulk-operations-service-limitations.md)
- To add users, see [Add or delete a new user](./how-to-create-delete-users.md).
Here are the least privileged roles you should use when performing tasks for [groups](../../fundamentals/how-to-manage-groups.md) in Microsoft Entra ID.
- [Manage Microsoft Entra groups and group membership](~/fundamentals/how-to-manage-groups.md)
Instructions about how to create and update Microsoft Entra groups, such as membership and settings.
- For more information, see [Learn about Microsoft 365 Groups](https://support.office.com/article/learn-about-office-365-groups-b565caa1-5c40-40ef-9915-60fdb2d97fa2).
Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.
An owner can also add or remove other owners. Unlike those users assigned at least the [Groups Administrator](../identity/role-based-access-control/permissions-reference.md#groups-administrator) role, owners can manage only the groups that they own and they can add or remove group members only if the group's membership type is **Assigned**.
- It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks).
Instructions about how to add an existing Azure subscription to your Microsoft Entra tenant.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
- It improves the accuracy of risk detection in [Microsoft Entra ID Protection risk detections](/entra/id-protection/concept-identity-protection-risks).
Instructions about how to add your custom domain name to your tenant.
Learn about the new Microsoft Entra bulk operations experience for managing users, groups, and devices.
Introduction to the Microsoft Entra product family including links to get started.
Compare the default user permissions available in Microsoft Entra ID and learn how to restrict access.
Managing user license assignments individually is time consuming and error prone. If you [assign licenses to groups](~/fundamentals/licensing.md?context=azure/active-directory/users-groups-roles/context/ugr-context) instead, you experience easier large-scale license management.
Learn about Microsoft Entra group-based licensing, including how it works,
This article documents licensing requirements for Microsoft Entra features.
How to view restorable users, restore a deleted user, or permanently delete a user with Microsoft Entra ID.
Learn about how Microsoft Entra ID Protection identifies risky agents.
Understand the difference between required resource access declarations and inheritable permissions for agent identity blueprints in Microsoft Entra Agent ID.
Learn about risk detections and risk levels, including the difference between real-time and offline detections.
Each layer addresses a different class of attacks, reducing the likelihood of compromise and limiting the blast radius.
Learn how AI agent discovery in Global Secure Access provides network-level visibility into managed and shadow AI agents reaching the internet from your environment.
Traditional service principals were designed for static, deterministic workloads. Microsoft Entra Agent ID exists because service principals lack the governance infrastructure AI agents need. There's no enforced sponsorship, no agent-aware audit entries, and no blueprint-managed lifecycle. For more information, see [Agent identities, service principals, and applications](agent-service-principals.md).
- [Call API: Azure services](../agent-id/call-api-azure-services.md) (New)
Learn how to add new custom security attribute definitions or deactivate custom security attribute definitions in Microsoft Entra ID.
Gain visibility into application traffic to gain insights into app categories, risk scores, transactions, and organizational usage patterns.
Learn how to create and manage custom attributes in a Domain Services managed domain.
Learn about where Microsoft Entra ID stores identity-related data for its European customers.
Learn about where Microsoft Entra ID stores customer-related data for its Japan customers.
A Microsoft Entra documentation page was updated: Customer intent: As an IT admin, I need to know what options are available for integrating Microsoft Entra activity logs with storage and analysis tools so I can choose the best option for my organization..
A Microsoft Entra documentation page was updated: Customer intent: As an IT admin, I want to know how to use the Identity Secure Score and related recommendations to improve the security posture of my Microsoft Entra tenant..
Learn how services store and retrieve Microsoft Entra object data through an RBAC authorization layer.
A Microsoft Entra documentation page was updated: Device Registration.
Learn about device soft delete (preview) in Microsoft Entra ID, which moves deleted devices to a recoverable state instead of permanently removing them.
Learn about Source of Authority (SOA) for users, including prerequisites and supported scenarios.
Learn about Explicit Forward Proxy session management concepts.
Learn to integrate your applications with Microsoft Entra ID by adding apps, discovery, and integration methods.
Learn about frontline worker management capabilities that are provided through the My Staff portal.
Learn how to protect your organization with Global Secure Access Advanced Threat Protection (ATP) and Data Loss Prevention (DLP) policies powered by Netskope.
Instructions for IT admins to create new users, invite external guests, and delete existing users in Microsoft Entra ID.
Understand the difference between required resource access declarations and inheritable permissions for agent identity blueprints in Microsoft Entra Agent ID.
Learn about Explicit Forward Proxy PAC file concepts.
Learn about bring your own device (BYOD) with the Global Secure Access clients for Microsoft Entra Private Access and Microsoft Entra Internet Access.
Learn how Global Secure Access alerts notify you about security issues and operational concerns, helping to strengthen your organization's security posture.
Learn how Global Secure Access enables secure external user access for partners through the Global Secure Access client and Azure Virtual Desktop.
Learn about the features and benefits of our Secure Web and AI Gateway for agents in Global Secure Access.
Learn how deleting an agent identity blueprint triggers automatic cleanup of child agent identities in Microsoft Entra, and how to restore deleted objects.
Overview of macOS Platform Single Sign On (PSSO) for Microsoft Entra ID registered devices.
Learn how to manage access to custom security attributes in Microsoft Entra ID.
Get an overview of the audit activities that can be logged in your audit logs in Microsoft Entra ID.
Use residency data to manage access, achieve mobility scenarios, and secure your organization.
Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.