Cross-product topic

Microsoft identity platform

A cross-product view of Microsoft Entra changes related to Microsoft identity platform.

Latest Microsoft identity platform changes

Best Practices Agent Id

Microsoft identity platform

The best-practices documentation now uses the full “Microsoft Entra Agent ID” and “Microsoft Entra ID” names in two recommendations. The guidance itself is unchanged.

Integrate N8n Agent

Microsoft identity platform

The n8n integration page now consistently calls the pattern “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK.”

What Is Agent Id Platform

Microsoft identity platform

The page’s bullet describing platforms and services that create agents retains the same wording and examples, including Copilot Studio, AWS Bedrock, and n8n. No substantive content change is shown.

Optional Claims

Microsoft identity platform

The documentation now explains how to configure granular AMR values for SAML applications through the manifest or Microsoft Graph, since the admin center has no UI option for `include_granular_amr`. It also documents adding the `amr` claim to OIDC token types and clarifies that `include_granular_amr` applies only to SAML.

Workload Identities Github Immutable Subjects

Microsoft identity platform

Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.

Configure Per App Access

Microsoft identity platform

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

Workload Identity Federation

Microsoft identity platform

- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.

Access token claims reference

Microsoft identity platform

Claims reference with details on the claims included in access tokens issued by the Microsoft identity platform.

Application model

Microsoft identity platform

Learn about the process of registering your application so it can integrate with the Microsoft identity platform.

Authorization basics

Microsoft identity platform

Learn about the basics of authorization in the Microsoft identity platform.

Call a web API from a web app

Microsoft identity platform

Learn how to build a web app that calls protected web APIs using the Microsoft identity platform. Explore options for ASP.NET Core, ASP.NET, Java, Node.js, and Python.

Claims customization

Microsoft identity platform

Learn about the custom claims policy and claims mapping policy types, which are used to modify the claims emitted in tokens in the Microsoft identity platform.

Configure optional claims

Microsoft identity platform

Learn how to configure optional claims and attributes in access tokens issued by Microsoft identity platform; optional claims can add useful user information for your app.

Create an agent identity blueprint

Microsoft identity platform

Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.

Customize app JSON Web Token (JWT) claims

Microsoft identity platform

Learn how to customize the claims issued by Microsoft identity platform in the JSON web token (JWT) token for enterprise applications.

How to configure an application to expose a web API

Microsoft identity platform

In this how-to guide, register a web API with the Microsoft identity platform and configure its scopes, exposing it to clients for permissions-based access to the API's resources.

ID token claims reference

Microsoft identity platform

Learn the details of the claims included in ID tokens issued by the Microsoft identity platform.

Mark an app as publisher verified

Microsoft identity platform

Describes how to mark an app as publisher verified. When an application is marked as publisher verified, it means that the publisher (application developer) verified the authenticity of their organization using a Cloud Partner Program (CPP) account that completed the verification process and associated this CPP account with that application registration.

Microsoft identity platform overview

Microsoft identity platform

Learn about the components of the Microsoft identity platform and how they can help you build identity and access management (IAM) support into your applications.

Optional claims reference

Microsoft identity platform

Claims reference with details on the optional claims that can be included in tokens in the Microsoft identity platform.

Prefer MSAL

Microsoft identity platform

Include file indicating that it's best to use MSAL.

Publisher verification overview

Microsoft identity platform

Learn about benefits, program requirements, and frequently asked questions in the publisher verification program for the Microsoft identity platform.

Quickstart: Call Microsoft Graph from a Node.js console app

Microsoft identity platform

In this quickstart, you download and run a code sample that shows how a Node.js console application can get an access token and call an API protected by a Microsoft identity platform endpoint, using the app's own identity

Quickstart: Call Microsoft Graph from a Node.js console app

Microsoft identity platform

In this quickstart, you download and run a code sample that shows how a Node.js console application can get an access token and call an API protected by a Microsoft identity platform endpoint, using the app's own identity

Set up a test environment for your app

Microsoft identity platform

Learn how to set up a Microsoft Entra test environment so you can test your application integrated with Microsoft identity platform. Evaluate whether you need a separate tenant for testing or if you can use your production tenant.

Shared device mode overview

Microsoft identity platform

Learn how Microsoft Entra ID's shared device mode feature enables device sharing for your frontline workers.

Supported account types

Microsoft identity platform

Conceptual documentation about audiences and supported account types in in the Microsoft identity platform

Troubleshoot publisher verification

Microsoft identity platform

Describes how to troubleshoot publisher verification for the Microsoft identity platform by calling Microsoft Graph APIs.

Updates and breaking changes

Microsoft identity platform

Learn about changes to the Microsoft identity platform that can impact your application.

Validation differences by supported account types

Microsoft identity platform

Learn about the validation differences of various properties for different supported account types when registering your app with the Microsoft identity platform.

Web API app registration and API permissions

Microsoft identity platform

In this quickstart, you learn how to configure app registration and API permissions for a Web API, and how to grant admin consent to these permissions.

Web API that calls web APIs

Microsoft identity platform

Build a web API that calls other APIs using the Microsoft identity platform. Learn how to acquire tokens and make secure API calls.

Create an agent identity blueprint

Microsoft identity platform

Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.

Reset guest redemption status

Microsoft identity platform

Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.

Simplifying agent management with Agent 365

Message CenterMC1275311 on mc.merill.net ↗Major updatePlan for change
Microsoft identity platform

Starting May 1, 2026, Microsoft is retiring the Agent registry and Agent collections blades in the Microsoft Entra admin center. Agent 365 will be the unified platform for agent management, with a new API replacing the existing one. No immediate admin action is required.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…