App Gallery User Provisioning Requirements
The App Gallery provisioning requirements now instruct integrators to validate SCIM endpoints against the Microsoft Entra provisioning service and submit the results with their gallery submission.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Provisioning.
The App Gallery provisioning requirements now instruct integrators to validate SCIM endpoints against the Microsoft Entra provisioning service and submit the results with their gallery submission.
The documentation removed the Repair-AADCloudSyncToolsAccount section because the cmdlet is obsolete.
The documentation updates the name or identifier of the dedicated first-party service principal used to synchronize Active Directory with Microsoft Entra ID.
The documentation wording about the dedicated first-party application and service principal used for synchronization between Active Directory and Microsoft Entra ID was revised.
The article now covers directory extensions for users and groups when provisioning from Microsoft Entra ID to Active Directory, with updated examples, prerequisite wording, links, and related content.
Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.
A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.
The article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.
The article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.
The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.
The documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.
A new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.
The tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.
The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.
The article now explains using directory extensions to filter groups for provisioning and to map attribute values to Active Directory users. It adds separate Groups and Users examples, prerequisites, and related guidance.
The documented ServicePrincipalId example was replaced with a generic UUID.
The Microsoft Entra tutorial for configuring automatic user provisioning to Rouse Sales has been deleted.
New documentation explains how provisioning can clear an existing target attribute when its source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.
The page no longer lists SAP’s November 20, 2026 basic-authentication deprecation date and removes the note describing current and planned workload identity support scenarios.
The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.
The configuration article now links to documentation for clearing attribute values (Preview).
The FAQ now states that the /bulkUpload endpoint can clear existing user attributes and links to configuration guidance. It also clarifies that the endpoint cannot delete users and recommends Lifecycle Workflows for automated deletion after termination or disablement.
The synchronization documentation now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance.
The tutorial now explains that `{enterprise}` in the GitHub.com SCIM tenant URL is the enterprise slug (account name).
The Agent ID documentation now refers to the linked SDK as the “Microsoft Entra ID Auth SDK” instead of “Entra ID Auth SDK.”
The account discovery documentation now links to the Microsoft MCP Server for Enterprise GitHub repository instead of Microsoft Learn pages for investigating reports and provisioning an MCP client.
The Puzzel provisioning article now documents OAuth2 Client Credentials Grant authentication. It adds steps to create an OIDC client, set token lifetimes to 3600, generate a shared secret, and enter the client ID, secret, and token endpoint.
The article’s Microsoft MCP Server for Enterprise overview and setup links changed from Microsoft Learn paths to the EnterpriseMCP GitHub repository. The article continues to describe the service as preview, global-service-only, and read-only.
The tutorial now states that Client Credentials Authentication is supported.
The tutorial now documents entering a Tenant URL, Client identifier, Client secret, and OAuth token endpoint, and includes a list of SCIM user attributes and data types.
The guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.
The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.
The documentation now directs administrators to Entra ID > Cross-tenant Synchronization > Configurations, removing the External Identities step.
The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.
The documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.
The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.
The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.
The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.
The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”
The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.
The guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.
The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.
The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.
The documentation replaces the former Mappings-based steps with a Scoping filters wizard covering assignment-based and attribute-based filtering for users and groups. Existing operator details and limitations remain documented.
The article now directs administrators to Manage > Attribute Mapping, with mappings organized by Users and Groups. It documents row-level edit and delete controls, group sync via Scoping filters, and the Advanced Options menu for custom attributes.
The documentation now says to open Expression Builder from the left navigation menu instead of Attribute Mapping > Advanced Options. The page date was also updated from March 4, 2025, to August 6, 2026, and the access screenshot was removed.
The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.
The article now explains viewing and downloading provisioning logs through the admin center, Microsoft Graph, and Microsoft MCP Server for Enterprise. The MCP integration supports natural-language, read-only analysis through delegated permissions and is currently limited to the global service.
The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.
The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.
With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.
Learn how Microsoft Entra Connect matches and synchronizes on-premises objects with an existing Microsoft Entra tenant, and how to resolve hard match conflicts.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Harness.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Visa Spend Clarity for Enterprise.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlertMedia.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atlassian Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AuditBoard.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to ThousandEyes.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bentley - Automatic User Provisioning.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIC Cloud Design.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to BlogIn.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Boxcryptor.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bpanda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BrowserStack Single Sign-on.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BullseyeTDP.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CheckProof.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cisco User Management for Secure Access.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Clarizen One.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Clebex.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to QA.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Coda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Code42.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Acunetix 360.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (OIDC).
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Airbase.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Airtable.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Akamai Enterprise Application Access.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Albert.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlexisHR.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Alohi.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Amazon Business.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Appaegis Isolation Access Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Ardoq.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Asana.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to askSpoke.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Astro.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atea.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atmos.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Autodesk SSO.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AWS IAM Identity Center.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Axiad Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BenQ IAM.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIS.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Bizagi Studio for Digital Process Automation.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BLDNG APP.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Blinq.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Britive.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Bustle B2B Transport Systems.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Canva.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cato Networks.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cerby.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Chaos.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Chatwork.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cinode.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cleanmail Swiss.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ClearView Trade.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cofense Recipient Sync.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Colloquial.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Playvox.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Connecter.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Contentstack.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to ContractS CLM.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to CultureHQ.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Cybozu.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CybSafe.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Dagster Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Datadog.