<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-entra/ct-p/microsoft-entra</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Fri, 31 Jul 2026 17:27:55 GMT</pubDate>
    <dc:creator>microsoft-entra</dc:creator>
    <dc:date>2026-07-31T17:27:55Z</dc:date>
    <item>
      <title>Verifying domain name issue</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/verifying-domain-name-issue/m-p/4541541#M10423</link>
      <description>&lt;P&gt;We're trying to verify our custom domain in Entra ID, but it turns out the domain is already claimed on another tenant that we have no access to (unknown account, no admin credentials). Because of that, verification on our own tenant fails.&lt;/P&gt;&lt;P&gt;Normally the fix for a claimed-domain conflict is to open a support request so Microsoft can help release it. The problem: doing that requires a support plan, and purchasing one doesn't work for us. "payment" always succeeds and we dont get an error, but we don't get charged and the account status doesn't change, we have nothing more to go on.&lt;/P&gt;&lt;P&gt;So we're stuck in a loop: we need support to release the domain, but we can't buy the support plan needed to reach support.&lt;/P&gt;&lt;P&gt;Has anyone dealt with a domain claimed on an inaccessible tenant? And is there another route to Microsoft support when the support plan purchase itself fails?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 11:34:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/verifying-domain-name-issue/m-p/4541541#M10423</guid>
      <dc:creator>I-Leadership</dc:creator>
      <dc:date>2026-07-28T11:34:53Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Entra: July 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-july-2026/ba-p/4534631</link>
      <description>&lt;P&gt;Welcome to the July edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What went into General Availability (GA) since June 2026?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/backup/overview" target="_blank"&gt;&lt;STRONG&gt;Microsoft Entra Backup and Recovery&lt;/STRONG&gt;&lt;/A&gt; - A&amp;nbsp;capability that helps organizations restore a tenant after accidental or malicious changes. On by default, it automatically backs up critical directory objects, including users, groups, applications, Service Principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication and authorization policies, so admins can return&amp;nbsp;to a known good state. The service takes daily backups of supported objects and retains them for 7 days with Microsoft Entra ID P1 or P2 licenses. Admins can view snapshots, compare changes, and run recovery jobs. This feature is a reliable safety net to minimize downtime and strengthen protection against misconfigurations and security incidents.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-access-package-assignments#directly-assign-any-identity" target="_blank"&gt;&lt;STRONG&gt;Direct admin assignment to external users using email address&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Entitlement management admins can assign external users, not in the directory, to an access package with the user's email. Users are invited into the tenant as Guest users and are governed when Microsoft Entra ID Governance is configured.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-bring-your-own-device" target="_blank"&gt;&lt;STRONG&gt;Bring your own device (BYOD) support for the Global Secure Access Windows client using Microsoft Entra‑registered devices&lt;/STRONG&gt;&lt;/A&gt; - Enable&amp;nbsp;users and partners&amp;nbsp;to access corporate resources from their own devices. Administrators can assign the&amp;nbsp;Private Application&amp;nbsp;traffic profile to users with internal accounts, including&amp;nbsp;internal guest users. This removes the previous requirement for Windows devices to be domain‑joined.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/kerberos-server-key-rotation" target="_blank"&gt;&lt;STRONG&gt;Microsoft Entra Kerberos key rotation&lt;/STRONG&gt;&lt;/A&gt; - Improves reliability for environments by using incoming trust referral flows. The update enhances authentication resiliency during key rollover by validating referral tickets with primary and secondary Kerberos keys. This combination reduces the likelihood of authentication failures and minimizes disruption during rotation events.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/direct-federation#domainless-saml-idp-federation-preview" target="_blank"&gt;&lt;STRONG&gt;Domainless SAML federation with a SAML identity provider&lt;/STRONG&gt;&lt;/A&gt; - Enable external users to sign in to applications or workforce resources using their Identity Provider (IdP)-managed credentials, regardless of their email domain. With no need to match user email domains with preconfigured identity provider domains, this capability simplifies onboarding and access for external users, streamlines invitation redemption, and improves flexibility for cross-organization collaboration in Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;New in Public Preview&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/howto-target-agent-identities" target="_blank"&gt;&lt;STRONG&gt;Strengthen AI agent security with Conditional Access&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra Conditional Access has broader controls to secure AI agents that leverage&amp;nbsp;user&amp;nbsp;accounts. Administrators can target agent user accounts more precisely by including, or excluding, agents, or by using custom security attributes for dynamic grouping. Organizations can apply Conditional Access policies, based on agent risk, require compliant devices for agents running on managed endpoints, including Windows 365 for Agents, and enforce device, network, and platform-based access conditions. These enhancements extend Zero Trust protections to agent user accounts while using the familiar Conditional Access policy experience.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/hybrid/cloud-sync/how-to-ad-group-enforcement" target="_blank"&gt;&lt;STRONG&gt;Restrict AD group changes to Microsoft Entra provisioning&lt;/STRONG&gt;&lt;/A&gt; - Designate specific Active Directory (AD) groups so all modifications are managed through the Microsoft Entra provisioning service. This capability helps maintain consistency between Microsoft Entra ID and AD by ensuring group changes are centrally controlled. Reduce configuration drift and improve alignment across identity systems.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;Generate unique aliases with custom call-outs&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;- Use custom call-outs with Azure Logic Apps during user provisioning to perform advanced attribute transformations that meet your organization's requirements. Custom call-outs can generate values such as unique employee aliases and are supported for create events in HR inbound, SaaS outbound, and cross-tenant synchronization provisioning flows in Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;Announcements&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-US/authenticator/jailbreak-root-detection-in-microsoft-authenticator" target="_blank"&gt;&lt;STRONG&gt;Jailbreak/root detection in Microsoft Authenticator&lt;/STRONG&gt;&amp;nbsp;&lt;/A&gt;- This feature strengthens security by preventing Microsoft Entra credentials from being added or used on jailbroken or rooted devices. Users move to compliant devices to continue using work or school accounts in Authenticator.&amp;nbsp;It is secure by default, requires no admin configuration, and applies to iOS and Android. Personal and third-party accounts are not affected.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Starting August 2026, Microsoft Authenticator on iOS will offer an improved backup and restore experience&lt;/STRONG&gt; - Users can back up account names securely by using iCloud and iCloud Keychain with end-to-end encryption. This experience includes work or school accounts, Microsoft personal accounts, and non-Microsoft accounts like Amazon or Google, also third-party time-based one-time password (TOTP). No other credentials are included in the backup. This update removes the need for a Microsoft personal account and simplifies device setup by automatically restoring account names on new iOS devices. Users manage the feature through iCloud settings&lt;/P&gt;
&lt;H2&gt;New guidance and information&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/app-provisioning/enable-scim-api" target="_blank"&gt;&lt;STRONG&gt;SCIM APIs available in U.S. Government Cloud&lt;/STRONG&gt;&lt;/A&gt; -&amp;nbsp;Microsoft Entra SCIM 2.0 APIs, which went into GA, in the public cloud, earlier in 2026, are available in Microsoft U.S. Government Cloud. Organizations can use standards-based SCIM operations to provision and manage users and groups in Microsoft Entra ID from external SCIM-compatible identity sources. Enable scalable identity lifecycle management, while you reduce the need for custom integrations.&lt;/P&gt;
&lt;H2&gt;Tell us what you think!&lt;/H2&gt;
&lt;P&gt;If you have feedback on this newsletter, fill out the dedicated &lt;A href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR3tZ6taaY2dAnA0rWwJeTkRUM1BUWjM5TjI5Sk1HME45TVVYOEdBNkJRNy4u" target="_blank"&gt;Microsoft Form&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Blogs&lt;/H2&gt;
&lt;P&gt;Check out the latest blog posts on our &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity" target="_blank"&gt;Microsoft Entra Blog&lt;/A&gt; and our &lt;A href="https://aka.ms/devblog/ms-entra" target="_blank"&gt;Microsoft Entra Identity Developer Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What's new in Microsoft Entra?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new" target="_blank"&gt;Learn what is new with Microsoft Entra&lt;/A&gt;, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find &lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new-sovereign-clouds" target="_blank"&gt;releases specific for Sovereign Clouds&lt;/A&gt; on a dedicated release notes page.&lt;/P&gt;
&lt;H2&gt;Become a certified Microsoft Identity and Access Administrator&lt;/H2&gt;
&lt;P&gt;Check out the &lt;A href="https://learn.microsoft.com/credentials/certifications/exams/sc-300/" target="_blank"&gt;certification&lt;/A&gt; and related &lt;A href="https://learn.microsoft.com/credentials/certifications/identity-and-access-administrator/" target="_blank"&gt;training&lt;/A&gt; for the Microsoft Identity and Access Administrator available for customers and partners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Martin Coetzer&lt;/P&gt;
&lt;P&gt;Principal Product Manager, Identity and Network Access, Customer Experience Engineering (CXE)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra" target="_blank"&gt;Microsoft Entra Community | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 24 Jul 2026 17:47:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-july-2026/ba-p/4534631</guid>
      <dc:creator>Martin_Coetzer</dc:creator>
      <dc:date>2026-07-24T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Modernize SAP Identity Management with Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/modernize-sap-identity-management-with-microsoft-entra/ba-p/4528596</link>
      <description>&lt;P&gt;Many organizations are rethinking how they manage identity across their SAP landscape as they move away from on-premises identity management systems and adopt a more unified cloud strategy. That shift often starts with a practical question: how do you connect SAP identity processes with the rest of your application estate without introducing more complexity?&lt;/P&gt;
&lt;P&gt;That is where the ongoing work between Microsoft Entra and SAP can help. Over the past several years, we have continued to expand integration points that help organizations automate lifecycle changes, apply access policies more consistently, and strengthen governance across SAP and non-SAP applications.&lt;/P&gt;
&lt;P&gt;If you are transitioning from SAP Identity Management (SAP IDM), modernizing an existing SAP identity architecture, or looking for better access governance across business-critical systems, the &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/scenarios/migrate-from-sap-idm" target="_blank" rel="noopener"&gt;latest integrations&lt;/A&gt; in Microsoft Entra can help.&lt;/P&gt;
&lt;P&gt;In this post, I’ll highlight what’s new, recap the key integration points, and explain how these capabilities can support your identity modernization journey.&lt;/P&gt;
&lt;H2&gt;What’s new in Microsoft Entra and SAP integrations&lt;/H2&gt;
&lt;P&gt;Over the &lt;A href="https://techcommunity.microsoft.com/discussions/microsoft-entra/new-blog--sap-identity-management-to-microsoft-entra-id-migration-guidance-now-a/4164406" target="_blank" rel="noopener"&gt;past two years&lt;/A&gt;, Microsoft Entra and SAP have continued to deepen interoperability and support more deployment models. Key updates include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;More flexible provisioning patterns between Microsoft Entra and SAP Cloud Identity Services&lt;/LI&gt;
&lt;LI&gt;Support for custom extension attributes on Microsoft Entra users for SAP-specific scenarios&lt;/LI&gt;
&lt;LI&gt;Account discovery to identify accounts in SAP Cloud Identity Services that are not yet correlated with users in Microsoft Entra&lt;/LI&gt;
&lt;LI&gt;OAuth 2.0 client credentials support to secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services&lt;/LI&gt;
&lt;LI&gt;Integration between Microsoft Entra ID Governance and SAP Identity Access Governance (SAP Identity Access Governance), so organizations can request and govern SAP business roles alongside other access rights&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities help organizations create a more unified identity control plane across SAP and the rest of the enterprise.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;“This partnership brings together the best of both worlds: Microsoft Entra’s identity-first foundation and SAP Access Governance’s (SAP Identity Access Governance and SAP Access Control) deep business and access risk context, enriched with AI to transform access governance into a continuous, intelligent trust model.”&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Swetta Singh, Strategic Product Manager for Access Governance solutions, SAP&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;A centralized identity control plane for SAP and beyond&lt;/H2&gt;
&lt;P&gt;Microsoft Entra provides a centralized identity layer that integrates with SAP applications and platforms. With it, organizations can automate joiner, mover, and leaver processes, apply access policies more consistently, and strengthen governance across a broader set of systems.&lt;/P&gt;
&lt;P&gt;That kind of consistency matters in complex environments. For example, &lt;A href="https://www.microsoft.com/en/customers/story/26155-cenibra-celulose-nipo-brasileira-sa-microsoft-entra-id-governance" target="_blank" rel="noopener"&gt;Cenibra&lt;/A&gt; used Microsoft Entra ID Governance to modernize identity management across more than 80 systems, including SAP as a core platform. That approach helped reduce manual work, improve audit readiness, and create a more scalable foundation for managing access.&lt;/P&gt;
&lt;H2&gt;SAP Cloud Identity Services: More flexible provisioning&lt;/H2&gt;
&lt;P&gt;SAP Cloud Identity Services centralizes authentication and provisioning across SAP applications. It provides single sign-on and helps organizations provision users and groups more consistently to downstream SAP systems.&lt;/P&gt;
&lt;P&gt;The latest integration improvements with Microsoft Entra give organizations more flexibility in synchronizing users and groups across both environments through standards-based approaches. This flexibility helps teams maintain consistent identity data between Microsoft Entra and SAP environments while using SAP Cloud Identity Services to distribute identities to downstream cloud-hosted and on-premises SAP applications.&lt;/P&gt;
&lt;P&gt;Some of the recent updates include:&lt;/P&gt;
&lt;H3&gt;Custom extension attributes for SAP-specific scenarios&lt;/H3&gt;
&lt;P&gt;Many SAP environments depend on attributes tied to business processes, regions, or organizational structures. Microsoft Entra now supports provisioning custom extension attributes on users in those scenarios, making it easier to align identity data with the needs of SAP applications.&lt;/P&gt;
&lt;H3&gt;Account discovery for SAP Cloud Identity Services&lt;/H3&gt;
&lt;P&gt;Microsoft Entra account discovery retrieves accounts from SAP Cloud Identity Services so you can identify accounts that are not yet correlated with users in Microsoft Entra. This visibility can help teams reduce manual investigation and strengthen governance.&lt;/P&gt;
&lt;H3&gt;OAuth 2.0 client credentials for connector authentication&lt;/H3&gt;
&lt;P&gt;We have also updated connector authentication to use OAuth 2.0 client credentials. This change helps secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services and supports a more modern integration approach.&lt;/P&gt;
&lt;H2&gt;SAP Identity Access Governance integration&lt;/H2&gt;
&lt;P&gt;SAP Identity Access Governance is SAP’s cloud-based access governance solution. The integration between Microsoft Entra ID Governance and SAP Identity Access Governance connects SAP role governance to a broader access strategy, allowing users to request or receive SAP business roles through Microsoft Entra access packages alongside non-SAP access rights.&lt;/P&gt;
&lt;P&gt;This integration matters because access governance often spans applications: employees, contractors, and partners may need coordinated access across SAP and non-SAP resources. Organizations can use the integration to manage those requests consistently across applications.&lt;/P&gt;
&lt;P&gt;When a user requests assignment to an access package with an SAP business role through Microsoft Entra, the request is sent automatically to SAP Identity Access Governance. SAP Identity Access Governance then enforces approvals and additional checks within its own governance process. This approach helps organizations connect enterprise-wide access packages in Microsoft Entra with the business role and risk context available in SAP Identity Access Governance.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra integrates with SAP Cloud Identity Services and SAP Identity Access Governance to support authentication, user provisioning, and identity governance across SAP applications.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Migration projects move faster with the right partner support&lt;/H2&gt;
&lt;P&gt;A successful transition from legacy IAM products such as SAP IDM often depends on practical experience across both SAP environments and enterprise identity platforms. Many organizations work with partners who can support SAP system integration, Microsoft Entra identity and governance capabilities, and identity strategies that connect SAP with the rest of the application estate.&lt;/P&gt;
&lt;P&gt;If you are planning a migration and want to involve a partner, review the partner list in &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/scenarios/migrate-from-sap-idm" target="_blank" rel="noopener"&gt;Migrate identity management scenarios from SAP IDM to Microsoft Entra&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Beyond identity: Microsoft Security for SAP&lt;/H2&gt;
&lt;P&gt;Identity establishes the foundation for securing SAP in your security environment. In addition to Microsoft Entra, Microsoft delivers SAP-aware capabilities aligned with the NIST Cybersecurity Framework:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Identify&lt;/STRONG&gt;: Microsoft Purview discovers and classifies sensitive SAP data—including data mirrored into Microsoft Fabric through SAP Datasphere—helping organizations apply more consistent data security policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Protect&lt;/STRONG&gt;: Microsoft Defender safeguards the endpoints, servers, and cloud resources surrounding SAP applications with continuous, adaptive controls.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt;: &lt;SPAN data-teams="true"&gt;Microsoft Sentinel connects SAP signals across your estate to detect incidents, with built-in analytics rules in an SAP-certified solution that cover known threats. Through strategic partnership with SAP, organizations can also incorporate security telemetry from SAP Enterprise Threat Detection (ETD) and SAP LogServ, providing broader visibility into SAP-specific threats and activities alongside the rest of the enterprise security estate&lt;/SPAN&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Respond&lt;/STRONG&gt;: Microsoft Security Copilot accelerates investigation and guides response, helping teams contain SAP incidents faster.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together with the identity investments described above, these capabilities advance an identity-first Zero Trust strategy across the SAP environment. Microsoft uses these same capabilities across its global SAP estate.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;If you are evaluating your SAP identity strategy, now is a good time to review how your current architecture maps to the latest integration options in Microsoft Entra.&lt;/P&gt;
&lt;P&gt;Start with these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MigrateFromSAPIDM" target="_blank" rel="noopener"&gt;Read the SAP IDM to Microsoft Entra migration guidance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/sap" target="_blank" rel="noopener"&gt;Manage access to your SAP applications&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://demos.microsoft.com/Microsoft/play/6373/securing-sap-workloads-end-to-end-protection-with-microsoft-security#/0/0" target="_blank" rel="noopener"&gt;Watch a demo of Securing SAP Workloads: End-to-End Protection with Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As always, I would love to hear about your SAP identity modernization journey and the topics you would like us to cover next.&lt;/P&gt;
&lt;P&gt;Thanks for reading,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Mark Wahl&lt;BR /&gt;Product Architect, Microsoft Entra&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/mawahl/" target="_blank" rel="noopener"&gt;Mark Wahl | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en/customers/story/26155-cenibra-celulose-nipo-brasileira-sa-microsoft-entra-id-governance" target="_blank" rel="noopener"&gt;Microsoft ID Governance Case Study&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/plan-sap-user-source-and-target" target="_blank" rel="noopener"&gt;Plan deploying Microsoft Entra for user provisioning with SAP | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 17:54:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/modernize-sap-identity-management-with-microsoft-entra/ba-p/4528596</guid>
      <dc:creator>Mark_Wahl</dc:creator>
      <dc:date>2026-07-24T17:54:07Z</dc:date>
    </item>
    <item>
      <title>Best practices: Open OneDrive/SharePoint sharing but restrict Teams guest access by domain</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/best-practices-open-onedrive-sharepoint-sharing-but-restrict/m-p/4540110#M10414</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Since SharePoint Online and OneDrive moved fully to Microsoft Entra B2B for external sharing, we've run into a policy conflict and would like to hear how others are handling it.&lt;/P&gt;&lt;H4&gt;Our requirements&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Enable OneDrive and SharePoint file sharing with external users, regardless of their email domain.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Restrict Microsoft Teams guest access to a predefined list of approved partner domains.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Continue allowing Teams external access (federated chat and meetings) for all domains.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;The problem:&lt;/H4&gt;&lt;UL&gt;&lt;LI&gt;Teams guests, SharePoint guests, and OneDrive guests are now governed by the same Microsoft Entra B2B invitation framework and the single&amp;nbsp;&lt;STRONG&gt;Collaboration restrictions&lt;/STRONG&gt; allow/deny list under:&lt;BR /&gt;&lt;STRONG&gt;External Identities → External collaboration settings&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;As a result, restricting guest invitations by domain also restricts OneDrive and SharePoint sharing for domains not on the allowlist.&lt;/LI&gt;&lt;LI&gt;According to Microsoft's response in the following Q&amp;amp;A, this behavior is currently &lt;STRONG&gt;by design&lt;/STRONG&gt;:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/5954975/onedrive-external-sharing-no-longer-working-with-a" target="_blank"&gt;OneDrive external sharing no longer working with "Allow invitations only to the specified domains" - Microsoft Q&amp;amp;A&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H4&gt;Questions to the community&lt;/H4&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Has anyone implemented a solution where OneDrive/SharePoint sharing remains open to all domains while Teams guest access is restricted to approved domains only?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there recommended approaches using Entitlement Management, Access Packages, Connected Organizations, or other Entra capabilities?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Is there any roadmap item for workload-specific collaboration restrictions (e.g., separate policies for Teams guest invitations and SharePoint/OneDrive sharing)?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any real-world experience or best practices would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bejhan&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 05:49:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/best-practices-open-onedrive-sharepoint-sharing-but-restrict/m-p/4540110#M10414</guid>
      <dc:creator>Bejhan</dc:creator>
      <dc:date>2026-07-24T05:49:11Z</dc:date>
    </item>
    <item>
      <title>Microsoft Entra ID enhances security of branded sign-ins</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-enhances-security-of-branded-sign-ins/ba-p/4537471</link>
      <description>&lt;P&gt;To align with Microsoft’s &lt;A href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative?msockid=22346ecb805f631739b27a6e81726266" target="_blank" rel="noopener"&gt;Secure Future Initiative&lt;/A&gt;&amp;nbsp;and its focus on identity security and phishing resistance, we’re evolving &lt;A href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding" target="_blank" rel="noopener"&gt;Microsoft Entra custom branding&lt;/A&gt; to help customers deliver sign-in experiences that are more secure, reliable, and consistent.&lt;/P&gt;
&lt;P&gt;Beginning&amp;nbsp;&lt;STRONG&gt;October 26, 2026&lt;/STRONG&gt;, Microsoft Entra will retire support for&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fentra%2Ffundamentals%2Freference-company-branding-css-template%23deprecation-of-custom-css-positioning-properties&amp;amp;data=05%7C02%7Cmkokkalera%40microsoft.com%7C5db9189be1024d5cdb6708dee1ff5ea1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639196684102815380%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=RxKo2Q49Kz4IBUAZ%2F5EbyrAWWHQukpqG29LWg3UlQho%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt; &lt;STRONG&gt;custom CSS positioning properties&lt;/STRONG&gt;&lt;/A&gt; used in custom branding. &lt;STRONG&gt;Full retirement of all custom CSS&lt;/STRONG&gt; is planned for &lt;STRONG&gt;later in 2027&lt;/STRONG&gt;. Microsoft will provide advance notice ahead of this milestone, along with alternative customization options.&lt;/P&gt;
&lt;P&gt;These changes add an additional layer of security by reducing opportunities for deceptive page layouts and helping ensure trusted, recognizable sign-in experiences that better protect users from phishing attacks.&lt;/P&gt;
&lt;H2&gt;When will this happen?&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;July 21, 2026: &lt;/STRONG&gt;Microsoft Entra ID tenants &lt;STRONG&gt;not &lt;/STRONG&gt;using custom CSS positioning properties before July 21, 2026, will not be able to configure them going forward.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;October 26, 2026: &lt;/STRONG&gt;Microsoft Entra ID will retire custom CSS positioning properties globally.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Later in 2027: &lt;/STRONG&gt;Microsoft Entra plans to move towards full custom CSS retirement, with advance notice provided.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Who will be affected?&lt;/H2&gt;
&lt;P&gt;To retire support for positioning properties, Microsoft is helping prevent tenants from creating new dependencies on custom CSS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Tenants that will be affected and need to take action by October 26, 2026:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Entra ID tenants that already use custom CSS positioning properties. After this date, these properties will be blocked and will no longer function.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tenants that are not affected:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Entra ID tenants that&amp;nbsp;&lt;STRONG&gt;do not&lt;/STRONG&gt; already use custom CSS positioning properties will not be able to configure them after July 21, 2026.&lt;/LI&gt;
&lt;LI&gt;New Microsoft Entra ID tenants created after January 5, 2026, do not have custom CSS available for custom branding.&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra External ID tenants.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;How will this affect your organization?&lt;/H2&gt;
&lt;P&gt;Microsoft Entra ID customers using the deprecated positioning properties may see changes to the layout of their branded sign-in experience after October 26, 2026, and won’t have a supported migration or replacement. In most cases, branding elements such as logos, images, or text will remain visible but will appear in their default state once the positioning properties are no longer honored.&lt;/P&gt;
&lt;P&gt;If your Microsoft Entra ID tenant uses any of these custom CSS positioning properties below in either &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding" target="_blank" rel="noopener"&gt;Company Branding&lt;/A&gt; or &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding-themes-apps" target="_blank" rel="noopener"&gt;Branding Themes&lt;/A&gt; , we recommend removing them from your configuration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;position (including top&lt;/STRONG&gt;, &lt;STRONG&gt;right&lt;/STRONG&gt;, &lt;STRONG&gt;bottom&lt;/STRONG&gt;, &lt;STRONG&gt;left&lt;/STRONG&gt;, and &lt;STRONG&gt;z-index)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;margin&lt;/STRONG&gt;&lt;STRONG&gt; (including margin-top, margin-bottom, margin-left, &lt;/STRONG&gt;&lt;STRONG&gt;and &lt;/STRONG&gt;&lt;STRONG&gt;margin-right)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;transform&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;opacity&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;overflow&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;filter&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;pointer&lt;/STRONG&gt;&lt;STRONG&gt;-events&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;clip&lt;/STRONG&gt;&lt;STRONG&gt;-path&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;mix&lt;/STRONG&gt;&lt;STRONG&gt;-blend-mode&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;translate&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft Entra ID customers who use the properties above will be notified directly in advance.&lt;/P&gt;
&lt;H2&gt;What do you need to do to prepare?&lt;/H2&gt;
&lt;P&gt;To determine whether your tenant uses positioning properties and requires you to take action:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure you use a global administrator or branding administrator role.&lt;/LI&gt;
&lt;LI&gt;Navigate to &lt;A href="https://developer.microsoft.com/en-us/graph/graph-explorer" target="_blank" rel="noopener"&gt;MS Graph Explorer&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Sign in into your tenant using the 'profile/sign in' button at the top right corner.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;If you have your tenantID, skip to step 5. Otherwise, you can get this by sending a GET request to the organization resource on the MS Graph Explorer. To do this, enter &lt;STRONG&gt;https://graph.microsoft.com/v1.0/organization &lt;/STRONG&gt;and run the query. Then, copy the “id” value of the response.&amp;nbsp;&lt;img /&gt;&lt;/LI&gt;
&lt;LI&gt;Get all the configured company branding locales by sending a GET request to the branding resource. To do this, enter &lt;STRONG&gt;https://graph.microsoft.com/v1.0/organization/&amp;lt;your tenant ID here&lt;/STRONG&gt;&lt;STRONG&gt;&amp;gt;/branding/localizations&lt;/STRONG&gt; and run the query.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="6"&gt;
&lt;LI&gt;Copy the contents of the response or export it to a JSON file&lt;/LI&gt;
&lt;LI&gt;Navigate to this &lt;A href="https://entra-branding-tools.github.io/tenant-branding-inspector/" target="_blank" rel="noopener"&gt;tool&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Paste the contents from step 6 or upload the exported JSON file to the input in the tool. You should get a list of locales and the properties impacted for each locale. These properties will be deprecated and are encouraged to be removed from your configuration.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Next steps&lt;/H2&gt;
&lt;P&gt;With these updates, Microsoft Entra custom branding continues to evolve as part of our proactive investment in secure, trusted, and consistent sign-in experiences.&lt;/P&gt;
&lt;P&gt;To ensure a smooth transition, we encourage you to review your custom CSS configurations and remove any affected properties ahead of time. This will help you catch and address potential layout issues early, so your users stay protected and your branded sign-in experience remains seamless.&lt;/P&gt;
&lt;P&gt;We’ll provide advance notice, guidance, and alternative customization options before broader custom CSS retirement. Thank you for your partnership as we make this transition.&lt;/P&gt;
&lt;P&gt;-Adam Steenwyk&lt;/P&gt;
&lt;P&gt;Principal Lead Product Manager, Microsoft Identity, Authentication Experiences&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fentra%2Ffundamentals%2Freference-company-branding-css-template%23deprecation-of-custom-css-positioning-properties&amp;amp;data=05%7C02%7Cmkokkalera%40microsoft.com%7C5db9189be1024d5cdb6708dee1ff5ea1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639196684102815380%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=RxKo2Q49Kz4IBUAZ%2F5EbyrAWWHQukpqG29LWg3UlQho%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Custom CSS overview &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding-themes-apps" target="_blank" rel="noopener"&gt;Customize the sign-in experience for your application with branding themes&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding" target="_blank" rel="noopener"&gt;Configure your Company Branding&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative?msockid=22346ecb805f631739b27a6e81726266" target="_blank" rel="noopener"&gt;Microsoft Secure Future Initiative (SFI)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least-privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and cloud environments.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 21 Jul 2026 17:58:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-enhances-security-of-branded-sign-ins/ba-p/4537471</guid>
      <dc:creator>Adam Steenwyk</dc:creator>
      <dc:date>2026-07-21T17:58:43Z</dc:date>
    </item>
    <item>
      <title>Secure AI, web, and private apps with Zero Trust</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-web-and-private-apps-with-zero-trust/ba-p/4516387</link>
      <description>&lt;P&gt;Today's threats don't respect boundaries. As AI agents proliferate across enterprise workflows, employees work from everywhere, and organizations adopt cloud-first architectures, the attack surface has fundamentally shifted. Traditional perimeter security can no longer keep pace with how work actually happens.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-internet-access" target="_blank" rel="noopener"&gt;Microsoft Entra Internet Access&lt;/A&gt; and &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access" target="_blank" rel="noopener"&gt;Microsoft Entra Private Access&lt;/A&gt; extend Zero Trust principles to all traffic, ensuring that every access request is verified against identity, device, and risk context, whether it originates from a user, a device, or an AI agent.&lt;/P&gt;
&lt;P&gt;Today, we're building on our &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/lock-down-ai-web-and-private-apps-what%E2%80%99s-new-in-internet-access-and-private-acce/3847825" target="_blank" rel="noopener"&gt;recent announcement&lt;/A&gt;, where we introduced a significant wave of new capabilities across both public preview and general availability. These updates span AI security, data protection, private access, and connectivity resilience, bringing the breadth of our SASE platform to meet the security demands of the AI era.&lt;/P&gt;
&lt;H1&gt;Now in public preview: deeper controls for AI, data, and access&lt;/H1&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Entra Internet Access and Microsoft Entra Private Access&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This July, we’re introducing new capabilities in public preview to help you secure AI interactions, protect sensitive data, strengthen access controls, and improve operational resilience—all through an identity-first approach to security. These capabilities bring deeper visibility and policy enforcement across users, AI agents, devices, locations, and applications, helping you innovate with confidence while maintaining Zero Trust principles.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with-microsoft-purview-/4529310" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Network Data Loss Protection (DLP) &lt;/STRONG&gt;&lt;/A&gt;extends Microsoft Purview data security to the network layer with Microsoft Entra Internet Access. Discover sensitive content in risky AI and cloud apps, block unsafe sharing (including file uploads, prompts, and responses), and apply context-aware controls based on identity and activity.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra network controls are now available for agents, &lt;/STRONG&gt;&lt;/A&gt;including Microsoft Copilot Studio agents and those running on user endpoint devices, and local agents such as OpenClaw. These controls can help identify unsanctioned AI usage, restrict connections to only approved web destinations, filter risky file movement, and help block malicious prompt-based attacks before they lead to harmful actions.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-manage-internet-access-profile" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Custom Acquire and Agentic Acquire&lt;/STRONG&gt;&lt;/A&gt; on Entra Internet Access traffic profile enables side by side deployment of Global Secure Access for AI Gateway and Agentic scenarios with other vendors.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/agents/network-security-globalsecureaccess" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 365 for Agents&lt;/STRONG&gt;&lt;/A&gt; integrates with Global Secure Access platform to provide enterprise-grade network security to agentic Cloud PCs with traffic monitoring, web filtering and threat blocking on agentic sessions.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1: Demo of Network data security&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;&lt;SPAN data-teams="true"&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank" rel="noopener" aria-label="Link See the full demo here"&gt;See the full demo here.&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Now generally available: broader coverage and stronger controls for users, applications, and AI&lt;/H2&gt;
&lt;P&gt;As secure access becomes foundational to every AI, cloud, and hybrid work initiative, organizations need solutions that are both powerful and operationally simple. The latest generally available capabilities for Microsoft Entra Internet Access and Microsoft Entra Private Access help organizations accelerate Zero Trust adoption, extend protection to unmanaged and remote environments, and gain greater visibility into how users, applications, and AI services interact with enterprise resources. The following capabilities are now GA and ready for organizations to deploy:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-explicit-forward-proxy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Browser-based access to internet resources&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;for&lt;STRONG&gt; &lt;/STRONG&gt;Microsoft Entra Internet Access&lt;STRONG&gt; &lt;/STRONG&gt;extends secure web access to kiosk and BYOD devices using PAC file-based proxy configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-bring-your-own-device" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;BYOD with Client &lt;/STRONG&gt;&lt;/A&gt;in Microsoft Entra Private Access lets you enforce Zero Trust for unmanaged devices, so employees and contractors can securely access private apps without compromising security or user experience.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-view-model-context-protocol-logging" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Shadow MCP Visibility &lt;/STRONG&gt;&lt;/A&gt;provides advanced monitoring and analysis capabilities for MCP traffic between client MCP on devices and remote MCP servers. This feature provides thorough visibility into which MCP servers are being used, what tools and resources they expose, and how those tools are invoked.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Want to Learn More?&lt;/H1&gt;
&lt;P&gt;Join our three-part webinar series, &lt;STRONG&gt;Securing Data and Access in the Era of AI&lt;/STRONG&gt; (July 21–23, 9:00 AM PDT), where Microsoft Entra and Microsoft Purview product leaders will share practical guidance for securing data, governing access, and scaling AI adoption with confidence. &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/securing-data-and-access-in-the-era-of-ai-with-microsoft-entra-and-microsoft-pur/4529488" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Save the dates and register to attend&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;-Sinead O’Donovan | VP of Product Management, Identity and Network Access&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/sineadco/" target="_blank" rel="noopener"&gt;Sinead O'Donovan | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with-microsoft-purview-/4529310" target="_blank" rel="noopener"&gt;Protect sensitive data in motion across SaaS and AI apps with Microsoft Purview and Microsoft Entra&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/secure-ai-at-scale-join-the-microsoft-entra--purview-webinar-series/4530257" target="_blank" rel="noopener"&gt;Secure AI at scale: Join the Microsoft Entra + Purview webinar series | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/lock-down-ai-web-and-private-apps-what%E2%80%99s-new-in-internet-access-and-private-acce/3847825?afd_azwaf_tok=eyJraWQiOiIxNkY3M0JFMkNDMjZDOUM1ODBGMzM4NjAzN0I1ODRCQTc4REQ1ODcwQUFFRkJGNEZDRUJFOUZEQkNGMENGMTNEIiwiYWxnIjoiUlMyNTYifQ.eyJhdWQiOiJ0ZWNoY29tbXVuaXR5Lm1pY3Jvc29mdC5jb20iLCJleHAiOjE3ODEyOTMyMjAsImlhdCI6MTc4MTI5MzIxMCwiaXNzIjoidGllcjEtNzlkNjZkNmJjNC12cHdseiIsInN1YiI6IjQuMTk0LjEyMi4xNzAiLCJkYXRhIjp7InR5cGUiOiJpc3N1ZWQiLCJyZWYiOiIyMDI2MDYxMlQxOTQwMTBaLTE3OWQ2NmQ2YmM0dnB3bHpoQzFJQURyNDIwMDAwMDAwMDRiMDAwMDAwMDAwNjlnZCIsImIiOiJ6akpLY3dSOVRBZEZFb20xamdtQmlJb2YwVVJ2cXRHRXpyQnRBVTBOV2RJIiwiaCI6IjFMeXQ5V2xqYm91MUhRaGgySjU1Zk9xS1g1VmY0dzdfYmtKeHRGVVJUUVEifX0.h86gKB4lhy7qwzePrV7-KLzLc1zwm3AZl2qB5ERV7DfxMyTaU-eAN2Cu3dLQeER-Q2RwUeTxCJEc0Gy6tNOWko7TzAzRtYuPmuAJoXx3jiEJ75hW5IyIHkDq0HpP0Ld-VaTCTq2BJ4DztT5KcfzNKzvbSbxl1ChkBuLdDHUkc4Hkvyr28gnKETNR54OYUimxk9DEETWO5F_SbVEVYrISxsF9S0sDfGOex0Dkef3xNbqjHaSuzVu-xdzKThqbtKjXTIpnITXrnW_3Y7T0SI7UfE4oLFCOFtvq0rglqd9wAR05bOncmb3l9IJVnMlqUdi6wU7tYT-994uUtvfgOCYR-Q.WF3obl2IDtqgvMFRqVdYkD5s" target="_blank" rel="noopener"&gt;Lock down AI, web, and private apps: what’s new in Internet Access and Private Access&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access" target="_blank" rel="noopener"&gt;Microsoft Entra Private Access | Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-internet-access" target="_blank" rel="noopener"&gt;Microsoft Entra Internet Access | Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 05:13:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-web-and-private-apps-with-zero-trust/ba-p/4516387</guid>
      <dc:creator>Sinead_ODonovan</dc:creator>
      <dc:date>2026-07-21T05:13:32Z</dc:date>
    </item>
    <item>
      <title>Plan your Azure AD B2C migration with the Migration Policy Analyzer</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/plan-your-azure-ad-b2c-migration-with-the-migration-policy/ba-p/4532874</link>
      <description>&lt;H2&gt;Migration planning starts with visibility&lt;/H2&gt;
&lt;P&gt;One of the first challenges organizations face when &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930about:blank" target="_blank" rel="noopener"&gt;planning a migration from Azure AD B2C to Microsoft Entra External ID&lt;/A&gt; is understanding exactly what is implemented in their tenant today.&lt;/P&gt;
&lt;P&gt;Over time, Azure AD B2C deployments often grow to include custom user journeys, federation integrations, claims transformations, API connections, and tailored sign-up and sign-in experiences. As teams change and solutions evolve, assessing migration scope can become time-consuming and complex.&lt;/P&gt;
&lt;P&gt;To help organizations accelerate migration planning, the&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-analyze-azure-ad-b2c-custom-policies" target="_blank"&gt; &lt;STRONG&gt;Migration Policy Analyzer&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;is now &lt;STRONG&gt;Generally Available&lt;/STRONG&gt; (&lt;STRONG&gt;GA&lt;/STRONG&gt;).&amp;nbsp; This capability analyzes your Azure AD B2C custom policies and generates a structured assessment of the authentication features implemented, reducing the manual effort and guesswork that typically slow down early migration planning.&lt;/P&gt;
&lt;P&gt;The resulting report helps architects and technical decision-makers understand migration readiness, identify implementation gaps, and prioritize next steps.&lt;/P&gt;
&lt;H2&gt;Understand your current implementation&lt;/H2&gt;
&lt;P&gt;Available through the&lt;A href="https://learn.microsoft.com/en-us/azure/active-directory-b2c/custom-policy-overview" target="_blank"&gt; &lt;STRONG&gt;Identity Experience Framework&lt;/STRONG&gt;&lt;/A&gt; experience in Azure AD B2C, Migration Policy Analyzer performs a deterministic analysis of custom policy definitions. It is important to note that the analysis is scoped to the Azure AD B2C custom policies within IEF; it is not a full tenant-wide scan and produces an inventory of the authentication capabilities implemented in those policies.&lt;/P&gt;
&lt;P&gt;The assessment provides guidance on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Authentication features detected in custom policies&lt;/LI&gt;
&lt;LI&gt;Migration paths to Microsoft Entra External ID&lt;/LI&gt;
&lt;LI&gt;Scenarios that may require custom development&lt;/LI&gt;
&lt;LI&gt;Areas where an alternative architectural approach may be recommended&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Rather than manually reviewing policy files, teams receive a structured assessment that can serve as a starting point for migration planning and technical discovery.&lt;/P&gt;
&lt;H2&gt;Generate a migration assessment in three steps&lt;/H2&gt;
&lt;P&gt;Getting started requires no policy modifications or additional configuration:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the &lt;STRONG&gt;Identity Experience Framework&lt;/STRONG&gt; in your Azure AD B2C tenant.&lt;/LI&gt;
&lt;LI&gt;Select a policy and click on &lt;STRONG&gt;Analyze policy&lt;/STRONG&gt; to begin policy analysis.&lt;/LI&gt;
&lt;LI&gt;Review and download the generated migration assessment report.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;The analyzer scans your custom policy definitions and produces a report that can be shared across engineering, architecture, and business stakeholders.&lt;/P&gt;
&lt;H2&gt;See Migration Policy Analyzer in action&lt;/H2&gt;
&lt;P&gt;Migration Policy Analyzer analyzes Azure AD B2C custom policies and generates a migration assessment to help organizations plan their move to Microsoft Entra External ID.&lt;/P&gt;
&lt;DIV style="position: relative; width: 100%; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;&lt;IFRAME src="https://medius.microsoft.com/Embed/video-nc/11e93c1a-e082-4914-b903-7b83bb7ee7e0?r=75985634368" title="Demo" allowfullscreen="allowfullscreen" frameborder="0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The Migration Policy Analyzer analyzes Azure AD B2C custom policies and generates a&lt;/EM&gt; migration &lt;EM&gt;assessment to help organizations plan their move to Microsoft Entra External ID.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Understand migration readiness&lt;/H2&gt;
&lt;P&gt;Each detected capability is categorized to help organizations evaluate migration complexity and planning requirements:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Available - Capabilities that can be implemented using existing Microsoft Entra External ID functionality, including common sign-up and sign-in experiences, federation scenarios, verification workflows, and account recovery experiences.&lt;/LI&gt;
&lt;LI&gt;Requires Custom Development -&amp;nbsp;Capabilities that may require extensibility mechanisms, API integrations, partner-developed solutions, or additional application logic.&lt;/LI&gt;
&lt;LI&gt;Architecture Change Recommended- Scenarios that may be better served by a different implementation pattern in Microsoft Entra External ID.&lt;/LI&gt;
&lt;LI&gt;Not Currently Supported-&amp;nbsp;Capabilities that do not currently have a direct implementation path and may require alternative approaches or future evaluation.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For example, a policy that combines social identity federation, REST API claims enrichment, and a custom password reset flow might be categorized as Available for the federation and password reset experiences and Requires Custom Development for the REST API claims enrichment, giving you an immediate sense of where effort will be concentrated.&lt;/P&gt;
&lt;P&gt;For each finding, the report provides migration guidance and recommended next steps to support planning discussions.&lt;/P&gt;
&lt;H2&gt;Turn discovery into a migration plan&lt;/H2&gt;
&lt;P&gt;The value of the Migration Policy Analyzer extends beyond identifying features; it helps you move from discovery to an actionable plan while reducing migration risk and effort. With a categorized inventory in hand, teams can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Estimate migration scope and effort&lt;/LI&gt;
&lt;LI&gt;Prioritize proof-of-concept activities&lt;/LI&gt;
&lt;LI&gt;Highlight areas requiring redesign or additional development&lt;/LI&gt;
&lt;LI&gt;Build a phased migration strategy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By establishing a shared understanding of the current state, architects, developers, and business stakeholders can align on migration priorities before implementation begins.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;If you are evaluating a &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/migrate-to-external-id" target="_blank" rel="noopener"&gt;transition from Azure AD B2C to Microsoft Entra External ID&lt;/A&gt;, migration planning starts with understanding what is deployed today.&lt;/P&gt;
&lt;P&gt;Use the Migration Policy Analyzer to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Generate an inventory of custom policy capabilities&lt;/LI&gt;
&lt;LI&gt;Understand migration readiness&lt;/LI&gt;
&lt;LI&gt;Identify scenarios requiring additional planning&lt;/LI&gt;
&lt;LI&gt;Evaluate areas that may require redesign or custom development&lt;/LI&gt;
&lt;LI&gt;Begin building your migration strategy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Open your Azure AD B2C tenant, navigate to &lt;STRONG&gt;Identity Experience Framework&lt;/STRONG&gt;, and run an analysis to generate your migration assessment. In minutes, you'll have the visibility needed to move from assessment to action, with less manual effort and lower migration risk.&lt;/P&gt;
&lt;P&gt;The Migration Policy Analyzer provides the visibility needed to move from assessment to action.&lt;/P&gt;
&lt;P&gt;-Namita Singh&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-analyze-azure-ad-b2c-custom-policies" target="_blank" rel="noopener"&gt;Analyze Azure AD B2C custom policies for Microsoft Entra External ID migration&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930" target="_blank" rel="noopener"&gt;Plan your migration from Azure AD B2C to External ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/active-directory-b2c/custom-policy-overview" target="_blank" rel="noopener"&gt;Identity Experience Framework&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/" target="_blank" rel="noopener"&gt;Microsoft Entra External ID documentation&lt;/A&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/migrate-to-external-id" target="_blank" rel="noopener"&gt;Transition to Microsoft Entra External ID for CIAM&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 20 Jul 2026 17:18:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/plan-your-azure-ad-b2c-migration-with-the-migration-policy/ba-p/4532874</guid>
      <dc:creator>NamitaSingh</dc:creator>
      <dc:date>2026-07-20T17:18:24Z</dc:date>
    </item>
    <item>
      <title>Is system-preferred first factor overriding Single Sign-On?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/is-system-preferred-first-factor-overriding-single-sign-on/m-p/4538363#M10396</link>
      <description>&lt;P&gt;My colleagues and I have noticed that we've started being prompted to perform a Windows Hello for Business authentication when we use Edge to access web resources that are authenticated with Entra. Previously, this authentication occurred silently through Single Sign-On with the PRT, per&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/concept-primary-refresh-token?tabs=windows-prt-issued%2Cbrowser-behavior-windows%2Cwindows-prt-used%2Cwindows-prt-renewal%2Cwindows-prt-protection%2Cwindows-apptokens%2Cwindows-browsercookies%2Cwindows-mfa" target="_blank"&gt;Understanding Primary Refresh Token (PRT) in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;While investigating what might have caused this change in behavior, I found&amp;nbsp;&lt;A class="lia-external-url" href="https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1411574" target="_blank"&gt;MC1411574&lt;/A&gt; in the M365 Message Center, which talks about a change to system-preferred authentication that started rolling out in late June 2026, whereby it now applies to the first factor as well as multi-factor authentication.&amp;nbsp;I excluded myself from system-preferred authentication and sure enough, that seems to have restored the previous behavior.&lt;/P&gt;&lt;P&gt;Is it intended that this change to system-preferred authentication will disable SSO, or do we have something misconfigured?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 23:02:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/is-system-preferred-first-factor-overriding-single-sign-on/m-p/4538363#M10396</guid>
      <dc:creator>RyanSteele-CoV</dc:creator>
      <dc:date>2026-07-17T23:02:31Z</dc:date>
    </item>
    <item>
      <title>Looking for an on-prem MFA solution for Active Directory and RDP</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/looking-for-an-on-prem-mfa-solution-for-active-directory-and-rdp/m-p/4537446#M10388</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We're reviewing options for adding MFA to our on-premises Active Directory environment.&lt;/P&gt;&lt;P&gt;Most of our users authenticate with Active Directory, while administrators also use RDP for managing Windows servers.&lt;/P&gt;&lt;P&gt;Because part of our infrastructure is isolated from the Internet, we'd prefer an on-premises MFA solution instead of relying on a cloud-only service.&lt;/P&gt;&lt;P&gt;Has anyone implemented something similar recently?&lt;/P&gt;&lt;P&gt;I'm interested in hearing:&lt;/P&gt;&lt;P&gt;Which solution did you choose?&lt;BR /&gt;How difficult was the deployment?&lt;BR /&gt;Did you run into any compatibility or performance issues?&lt;BR /&gt;Is there anything you'd do differently if you were deploying it again?&lt;/P&gt;&lt;P&gt;Any real-world experience or recommendations would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 18:07:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/looking-for-an-on-prem-mfa-solution-for-active-directory-and-rdp/m-p/4537446#M10388</guid>
      <dc:creator>Grey_ai1</dc:creator>
      <dc:date>2026-07-15T18:07:23Z</dc:date>
    </item>
    <item>
      <title>AI agents are everywhere. Are your access controls ready?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/ai-agents-are-everywhere-are-your-access-controls-ready/ba-p/4531379</link>
      <description>&lt;P&gt;At Identiverse 2026, Microsoft Security hosted a Power Breakfast that brought together 150 identity professionals across 10 simultaneous roundtable discussions. Participants came from industries including financial services, healthcare, government, and energy, and represented every stage of AI adoption.&lt;BR /&gt;&lt;BR /&gt;We asked participants what they’ve built to secure agents, what they’ve rolled back, and where control is breaking down.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“The pace has been crazy fast. We have thousands of agents. Most of them are unmanaged.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;What your peers are saying about securing agents&lt;/H2&gt;
&lt;H3&gt;Agent sprawl is already here and bigger than most teams realize&lt;/H3&gt;
&lt;P&gt;Nine in 10 roundtables described unmanaged agent sprawl not as a future risk, but as a present reality. What started as dozens of agents became tens of thousands in months or even weeks. No single audit could capture the full picture. Practitioners described discovering the true number by accident, often finding far more than they expected: &lt;EM&gt;“I was doing a demo one day, I looked at our corporate tenant, and we had like 44,000 agents. I just couldn’t believe it, after so little time.”&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Agents are proliferating across every cloud, SaaS platform, and vendor environment simultaneously&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Nine in 10 roundtables reported agents running across SaaS, multicloud, and third-party environments with no governance visibility. Eight in 10 said shadow AI is already present in their organizations, running across platforms that no single governance layer currently covers and tracked only through network logs, if tracked at all. The challenge isn’t unique to any one platform: every SaaS vendor is now shipping with an agent, every cloud provider has a builder framework, and every team has a developer standing up something new.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“When everybody has a single pane of glass, nobody has a single pane of glass.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;Assigning human ownership to agents becomes complex when people change roles or leave organizations&lt;/H3&gt;
&lt;P&gt;Nine in 10 roundtables raised the ownerless-agents problem. Agents get built, tied to their creator’s identity, and keep running long after that person has changed roles or left the organization—unreviewed, over-permissioned, and undetected. This results in agents with no clear accountability, stale permissions, and no obvious path for review, reassignment, or decommissioning.&lt;/P&gt;
&lt;H3&gt;Agent-to-agent interactions are where control fails hardest&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Eight in 10 roundtables identified agent-to-agent chains as the most difficult security challenge they had encountered. Multiple teams rolled back agent-to-agent deployments after finding they could not maintain consistent governance across the chain.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“I can control point A to point B, but point B needs to talk to point C, and that’s where context was lost. I can control permissions. I can control authentication. I do not know how to control the impact.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H2&gt;How Microsoft Entra Agent ID can help&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra Agent ID&lt;/STRONG&gt; is the identity foundation for every AI agent, and it’s where your control starts. Every governance, access, and lifecycle decision flows through agent identity. Without it, none of the controls below are possible. Microsoft Agent 365 builds on that foundation as the unified control plane, giving IT and security teams a single place to see and act on every agent across the organization.&lt;/P&gt;
&lt;P&gt;If you have similar pain points around managing agents, here are three actionable starting points for securing them:&lt;/P&gt;
&lt;H3&gt;1. Build your inventory before you do anything else&lt;/H3&gt;
&lt;P&gt;You cannot govern what you cannot see. Start here.&lt;/P&gt;
&lt;P&gt;The Microsoft Entra admin center shows every agent identity in your tenant across Copilot Studio, Microsoft Foundry, and third-party platforms in one view. Start in &lt;STRONG&gt;Microsoft Entra ID &amp;gt; Agents &amp;gt; Agents overview&lt;/STRONG&gt; to get a full picture of the total number of agents with identities, how many were recently created, how many are active, and how many are unmanaged. Then go to &lt;STRONG&gt;Microsoft Entra ID &amp;gt; Agents &amp;gt; Agent identities&lt;/STRONG&gt; and run your first audit. Agents without an Agent ID appear as classic agents with no governance controls attached. That list is your backlog and needs to be addressed right away to prevent sprawl.&lt;/P&gt;
&lt;P&gt;For agents running outside the Microsoft ecosystem, register them using the Agent 365 CLI and SDK or federated identity credentials. You do not need to migrate them; you need to get them into the registry so they are visible and can be governed.&lt;/P&gt;
&lt;P&gt;For third-party agents, running the Agent 365 SDK assigns each agent an agent identity blueprint, an agent identity, and a sponsor from the start, helping ensure that agents are trackable and more secure. A blueprint is a template that defines permissions, policies, and metadata for every agent instance created from it. It provides centralized control, allowing you to manage or disable agents created from it at scale. Skipping blueprints and creating agents as ad hoc service principals is how you end up with the sprawl the roundtable participants described.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;Get started with Microsoft Entra Agent ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/how-to-plan-agent-identity-architecture" target="_blank" rel="noopener"&gt;Plan your agent identity architecture&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-blueprint" target="_blank" rel="noopener"&gt;Agent identity blueprints&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;2. Assign an owner and a sponsor to every agent, then automate what happens when they leave&lt;/H3&gt;
&lt;P&gt;The orphaned-agent problem practitioners described has a direct solution. Every agent identity in Microsoft Entra Agent ID requires a &lt;STRONG&gt;sponsor&lt;/STRONG&gt; (the person accountable for what the agent does) and an &lt;STRONG&gt;owner&lt;/STRONG&gt; (the person responsible for its technical management). Assign both at creation time, at the blueprint layer. If you have existing agents with neither, start there.&lt;/P&gt;
&lt;P&gt;When someone leaves your organization,&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra lifecycle workflows&lt;/STRONG&gt;&lt;/A&gt; can automatically trigger an ownership review for every agent associated with that person. You define the escalation path and the window: reassign, pause, or decommission. This replaces the manual scripts your team has been running for service accounts.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Set up recurring &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;access reviews&lt;/STRONG&gt;&lt;/A&gt; for agent identities. Scope them to surface active permissions, usage signals, and business justification—not just whether the agent still exists. Agents that cannot be justified should be decommissioned, not left running.&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/best-practices-agent-id" target="_blank" rel="noopener"&gt;Best practices for Microsoft Entra Agent ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview" target="_blank" rel="noopener"&gt;Govern agent identities and lifecycle&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows" target="_blank" rel="noopener"&gt;Lifecycle Workflows overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-overview" target="_blank" rel="noopener"&gt;Access reviews for agents overview&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;3. Scope permissions tightly, and apply Conditional Access and RBAC at the blueprint level&lt;/H3&gt;
&lt;P&gt;Start with enumerated scopes on every blueprint: only the specific delegated permissions the agent needs, nothing more. This is not optional. Agents do not self-restrict.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“An agent doesn’t self-restrict. It’s going to do whatever it feels like it needs to do.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;For agents acting on behalf of a user, use the on-behalf-of flow so that user-level access policies apply. For autonomous agents, use the client credentials flow, scoped narrowly. Do not grant application-level permissions when delegated permissions accomplish the same task.&lt;/P&gt;
&lt;P&gt;Apply &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/security-for-ai-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Conditional Access policies&lt;/STRONG&gt;&lt;/A&gt; at the blueprint level, not agent by agent. Every agent instance created from that blueprint inherits the policy automatically. This is how you extend Zero Trust controls from your workforce to your agents. Next, Microsoft Entra ID Protection analyzes agent behavior to detect anomalies such as unusual access patterns, spikes in activity, or interactions with unfamiliar resources. When an agent is flagged as risky, those signals automatically trigger Conditional Access policies to block or restrict access in real time, moving you from static policies to adaptive protection.&lt;/P&gt;
&lt;P&gt;Lastly, turn on sign-in and audit logs in the Microsoft Entra admin center. Agent-initiated events are flagged separately from human-initiated ones. This is your baseline for detecting unauthorized access and demonstrating compliance.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin" target="_blank" rel="noopener"&gt;Manage agent identities and inheritable permissions&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/security-for-ai-overview" target="_blank" rel="noopener"&gt;Security for AI overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID documentation&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;If you have had a similar experience, please share your learnings in the comments!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Kaitlin Murphy&lt;/P&gt;
&lt;P&gt;Senior Director, Identity and Network Access Product Marketing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Microsoft Entra Agent ID documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 15 Jul 2026 18:16:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/ai-agents-are-everywhere-are-your-access-controls-ready/ba-p/4531379</guid>
      <dc:creator>Kaitlin_Murphy</dc:creator>
      <dc:date>2026-07-15T18:16:41Z</dc:date>
    </item>
    <item>
      <title>Can the built-in "No account? Create one" link redirect to a custom sign-up page?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/can-the-built-in-quot-no-account-create-one-quot-link-redirect/m-p/4536451#M10386</link>
      <description>&lt;P&gt;I'm using Microsoft Entra External ID with a built-in sign-in/sign-up user flow.&lt;/P&gt;&lt;P&gt;On the Microsoft-hosted sign-in page, the "No account? Create one" link always redirects users to the default Entra sign-up page.&lt;/P&gt;&lt;P&gt;I already have a custom registration page and would like this built-in link to redirect to my custom URL instead.&lt;/P&gt;&lt;P&gt;Is there any supported way to customize the destination of this link in a built-in user flow? If not, could someone confirm whether this behavior is fixed by design?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 10:13:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/can-the-built-in-quot-no-account-create-one-quot-link-redirect/m-p/4536451#M10386</guid>
      <dc:creator>Lipikasree</dc:creator>
      <dc:date>2026-07-13T10:13:42Z</dc:date>
    </item>
    <item>
      <title>Using Cloud sync to sync AD to existing Entra Accounts</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/using-cloud-sync-to-sync-ad-to-existing-entra-accounts/m-p/4535450#M10369</link>
      <description>&lt;P&gt;I want to sync in premise AD accounts with existing Entra accounts. The email on both accounts is the same, and I added the Entra/o365 suffix to the domain and set the UPN to that suffix, making both UPN(s) the same. It did not sync. It created a NEW Entra account. I thought I covered all my bases.&lt;BR /&gt;&lt;BR /&gt;How can I get on premise AD and existing Entra accounts to sync?&lt;BR /&gt;&lt;BR /&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 22:32:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/using-cloud-sync-to-sync-ad-to-existing-entra-accounts/m-p/4535450#M10369</guid>
      <dc:creator>tjcooper2</dc:creator>
      <dc:date>2026-07-09T22:32:31Z</dc:date>
    </item>
    <item>
      <title>Group-Based Licensing (E3 → Business Premium): MutuallyExclusiveViolation – Months Unresolved</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/group-based-licensing-e3-business-premium/m-p/4534721#M10362</link>
      <description>&lt;P&gt;We operate a Microsoft 365 environment with Entra ID, Intune, and Exchange Online. For &lt;STRONG&gt;months&lt;/STRONG&gt;, we have been dealing with a critical issue that remains unresolved to this day — despite an active Microsoft Support ticket.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Technical Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;During the migration of approximately 87 user accounts from Microsoft 365 E3 to Business Premium (SPB) via group-based licensing in Entra ID, all affected accounts receive a MutuallyExclusiveViolation error. Microsoft's backend treats E3 and Business Premium as mutually exclusive, blocking the SPB assignment — despite sufficient licenses being available.&lt;/P&gt;&lt;P&gt;A sequential approach (removing E3 first, then assigning Business Premium) is not an acceptable solution: a test run proved that this causes a complete loss of Exchange Online access. For a rollout across 87 productive user accounts, this is not viable. What is required is a &lt;STRONG&gt;seamless, atomic license swap at the backend level&lt;/STRONG&gt; — exclusively via group-based licensing.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Support Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Two support engineers&lt;/STRONG&gt; assigned — zero technical progress.&lt;/LI&gt;&lt;LI&gt;Instead of a substantive solution, we received &lt;STRONG&gt;standard documentation steps&lt;/STRONG&gt; that do not address the actual problem.&lt;/LI&gt;&lt;LI&gt;A &lt;STRONG&gt;false resolution notice&lt;/STRONG&gt; was issued — the issue had demonstrably not been resolved. Our own PowerShell tests (Get-MgUser, Get-MgSubscribedSku) and CSV exports from the Entra ID portal disproved this conclusively.&lt;/LI&gt;&lt;LI&gt;Committed updates from the Engineering Team were &lt;STRONG&gt;not delivered&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Instead, &lt;STRONG&gt;automatically generated follow-up emails&lt;/STRONG&gt; were sent with no substantive relation to the ongoing case.&lt;/LI&gt;&lt;LI&gt;An additional unexplained behavior: a test user appears in the error report of a license group they were &lt;STRONG&gt;never added to&lt;/STRONG&gt; — a further backend inconsistency that has not been investigated.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Current Status:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The ticket has been open for months. 87 user accounts cannot be migrated to Business Premium. An escalation to the Team Manager has been initiated. No resolution is in sight.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Question to the Community:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced a similar issue with MutuallyExclusiveViolation in group-based licensing (E3 → Business Premium)? Is there a known workaround or an official Microsoft statement on this?&lt;/P&gt;&lt;P&gt;Ticket Reference: &lt;STRONG&gt;#2604241410000669&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 06:32:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/group-based-licensing-e3-business-premium/m-p/4534721#M10362</guid>
      <dc:creator>DanielZieb</dc:creator>
      <dc:date>2026-07-08T06:32:59Z</dc:date>
    </item>
    <item>
      <title>Govern AI agent identities and access the same way you govern your employees</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/govern-ai-agent-identities-and-access-the-same-way-you-govern/ba-p/4529302</link>
      <description>&lt;P&gt;In our conversations with customers, we’ve heard consistent feedback: organizations want to embrace AI agents, but they need the same governance rigor they apply to human identities—adapted for the speed and scale of AI. As agents take on real work, the critical question becomes: how do you give each agent the access it needs to be productive without letting that access become a risk?&lt;/P&gt;
&lt;P&gt;For example, an agent tasked with analyzing purchase trends and delivering a report needs the ability to read transaction data from an ERP system. Historically, agents may have used shared credentials or access rights borrowed from an employee. As AI adoption grows, organizations are increasingly adopting dedicated agent identities that provide clearer ownership, accountability, and governance. This gives each agent a distinct identity with a named human sponsor and governed access, while providing enterprise security and lifecycle management.&lt;/P&gt;
&lt;P&gt;With a distinct identity for each agent, ownership becomes clear, organizations gain visibility into each agent’s access, and access does not accumulate over time. Knowing which agent has what access, who is responsible for it, and whether that access is appropriate is foundational to secure and govern agents—just as it is for your human workforce.&lt;/P&gt;
&lt;P&gt;Microsoft Entra surfaces agent identity governance capabilities that are generally available as part of &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;New challenges for governing agent access&lt;/H2&gt;
&lt;P&gt;Traditional software is relatively static. Once deployed, its capabilities and permissions don’t change without a deliberate software update. Agents are fundamentally different; their capabilities evolve over time, and each new capability represents a change in the agent’s access footprint. This constant evolution means their access needs to change too, and without governance, that access compounds organizational risk.&lt;BR /&gt;&lt;BR /&gt;As organizations scale their AI agent deployments, security and IT teams are facing new challenges that traditional identity governance wasn’t designed for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Overprivileged access:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Agents often receive access at runtime, accumulate access over time, and retain it indefinitely, multiplying security risk across the organization.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;No human accountability:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;When an agent acts autonomously, who is accountable for it? Without clear accountability, no person is responsible for its access or lifecycle.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Manual lifecycle management policies don’t scale: &lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Organizations managing hundreds or thousands of agents across multiple platforms need consistent access governance policies that admins can manage at scale. They can’t rely on manual processes to track sponsors or determine which agent identities and access assignments are still needed.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Govern agent identity and access with Microsoft Entra Agent ID&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt; enables organizations to govern agent identities and access at scale throughout the agent lifecycle. For example, an agent identity should follow the below identity and access lifecycle process:&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1: Agent identity and access lifecycle.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Govern access for agents with Microsoft Entra access packages&lt;/H2&gt;
&lt;P&gt;Access packages, a capability within &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-overview" target="_blank" rel="noopener"&gt;Microsoft Entra Entitlement Management&lt;/A&gt;, brings structure and accountability to the entire access lifecycle for agent identities. Organizations can provide access policies that governs how access is requested, approved, and scoped in the first place, and ensures access is reviewed and expires when it's no longer needed. The result is access that's intentional, right-sized, time-bound, and easy to prove in an audit, without slowing teams down. &amp;nbsp;This applies to both assistive agents that require delegated OAuth permissions to act on behalf of users and autonomous agents that operate independently with their own application roles and permissions.&lt;/P&gt;
&lt;P&gt;By managing access assignments through access packages, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Scale efficiently when many agents need similar access rights&lt;/LI&gt;
&lt;LI&gt;Delegate approvals to the right decision-makers—application owners, compliance teams, or business stakeholders—for high-risk or compliance-sensitive access&lt;/LI&gt;
&lt;LI&gt;Time-limit access assignments so agents don’t retain access indefinitely&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Now consider a scenario where a DevOps agent needs access to certain OAuth permissions. An admin creates an access package policy scoped to agents, with approvals and access expiration settings, so its sponsor can request access on behalf of the agent identity:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure &lt;/EM&gt;&lt;EM&gt;2: &lt;/EM&gt;&lt;EM&gt;Admin experience with &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-access-packages" target="_blank" rel="noopener"&gt;&lt;EM&gt;access package policy for agents.&lt;/EM&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Sponsors from across your organization, who don’t need to be IT admins, can use the &lt;A href="https://myaccess.microsoft.com/" target="_blank" rel="noopener"&gt;My Access portal&lt;/A&gt; to submit the access request on behalf of the agent identity. The request goes through an approval flow before time-limited access is assigned.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure &lt;/EM&gt;&lt;EM&gt;3:&lt;/EM&gt;&lt;EM&gt; Sponsor experience for &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-request-behalf#request-an-access-package-on-behalf-of-an-agent-identity" target="_blank" rel="noopener"&gt;&lt;EM&gt;requesting an access package&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; on behalf of an agent.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Additionally, Microsoft 365 administrators can use custom policy templates that leverage Microsoft Entra access packages, providing a streamlined experience for governing agent access during onboarding. The AI admin in Microsoft Agent 365 can request Microsoft Entra access packages through Microsoft Agent 365 policy templates. This ensures an agent’s access is secure from day one with approval flows and access expiration, so that the access does not persist longer than needed.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 4: The &lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/admin/agent-template#access-packages" target="_blank" rel="noopener"&gt;Agent 365 template&lt;/A&gt; to apply access package policy during agent onboarding.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Hold every agent accountable with a named sponsor&lt;/H2&gt;
&lt;P&gt;Every agent identity and &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-blueprint" target="_blank" rel="noopener"&gt;agent identity blueprint&lt;/A&gt; in Microsoft Entra can have a designated sponsor—a person accountable for that agent’s access and lifecycle. You can learn more about sponsor responsibilities &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-owners-sponsors-managers" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Agent sponsors provide the human accountability needed to govern agent identities at enterprise scale. By assigning sponsors, organizations can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Establish clear ownership for every agent identity&lt;/LI&gt;
&lt;LI&gt;Enable business stakeholders, not just IT administrators, to participate in governance decisions&lt;/LI&gt;
&lt;LI&gt;Ensure a responsible person reviews and requests access on behalf of the agent&lt;/LI&gt;
&lt;LI&gt;Empower sponsors to make lifecycle decisions for agent identities, including renewing, extending, or removing agent identities based on ongoing business need&lt;/LI&gt;
&lt;LI&gt;Provide a designated contact for audit, compliance and security reviews&lt;/LI&gt;
&lt;LI&gt;Reduce the risk of orphaned and unmanaged agent identities&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 5: &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-owners-sponsors-managers" target="_blank" rel="noopener"&gt;Owners and Sponsors&lt;/A&gt; of agent identities&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Automate the agent lifecycle with Lifecycle Workflows&lt;/H2&gt;
&lt;P&gt;With Microsoft Entra Lifecycle Workflows, you can add tasks for agent sponsors to your workflows so that as employees change roles, Microsoft Entra automatically:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Notifies the manager and co-sponsors when an agent’s sponsor moves or leaves, helping ensure no agent is left without accountability&lt;/LI&gt;
&lt;LI&gt;Transfers sponsorship automatically to a co-worker or manager, so there’s always a human accountable for every agent, even during organizational transitions&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 6: &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/agent-sponsor-tasks" target="_blank" rel="noopener"&gt;Lifecycle Workflows&lt;/A&gt; automate sponsor maintenance when sponsors move or leave.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Sponsors can then see a list of agent identities they are responsible for and take lifecycle actions, such as disabling agent identities when they are no longer needed.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 7: The &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-end-user" target="_blank" rel="noopener"&gt;Manage Agents&lt;/A&gt; end-user experience enables sponsors to make lifecycle decisions.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;The path forward&lt;/H2&gt;
&lt;P&gt;Organizations benefit most from AI agents when governance is an enabler, not an afterthought—with guardrails in place from the moment an agent is onboarded. The agentic era extends identity governance to a new class of non-human identities that are more dynamic and numerous than the service accounts of the past. The principles stay the same—least privilege, accountability, lifecycle management, and continuous governance—but the mechanisms must evolve to match the speed and scale of agentic AI.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Ready to bring your AI agents under control with &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview" target="_blank" rel="noopener"&gt;Microsoft Entra ID Governance&lt;/A&gt; for agent identities? Explore &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=3937ac211e5f69b11004ba2c1f136810" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt; to start a trial and see how you can observe, govern, and secure agents across your organization.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Chirag Dayani&lt;BR /&gt;Sr Product Manager, Microsoft Entra Identity and Access Management&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/chiragdayani/" target="_blank" rel="noopener"&gt;Connect on LinkedIn&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Mark Wahl&lt;BR /&gt;Principal Product Architect&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/mawahl/" target="_blank" rel="noopener"&gt;Connect on LinkedIn&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;What is Microsoft Entra Agent ID?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview" target="_blank" rel="noopener"&gt;Learn about governing agent identities&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 07 Jul 2026 21:34:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/govern-ai-agent-identities-and-access-the-same-way-you-govern/ba-p/4529302</guid>
      <dc:creator>chiragdayani</dc:creator>
      <dc:date>2026-07-07T21:34:53Z</dc:date>
    </item>
    <item>
      <title>Made a self-hosted Entra ID governance portal for app/identity sprawl (open source)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/made-a-self-hosted-entra-id-governance-portal-for-app-identity/m-p/4533415#M10353</link>
      <description>&lt;P&gt;Our tenant ended up with hundreds of app registrations and enterprise apps, and the native portal makes you dig through a separate blade for every basic question. Who owns this app? Which secrets die next month? What hasn't been signed into in a year? Which ones have scary Graph permissions? There's no single view for any of it, and half the ownership info was missing anyway.&lt;/P&gt;&lt;P&gt;Entra ID Governance, access reviews, PIM all exist, but they felt heavy (and licensed) for what I actually wanted, which was just a fast list I could scan for routine cleanup.&lt;/P&gt;&lt;P&gt;So I built one. Lightweight portal that runs entirely in your own subscription:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;One grid for App Registrations, Enterprise Apps, Managed Identities and Privileged Users&lt;/LI&gt;&lt;LI&gt;Risk flags per identity: expiring/expired creds, high-risk permissions, no owner, stale sign-in, no CA coverage&lt;/LI&gt;&lt;LI&gt;Ownership tracking, review and owner-change workflow, CSV export&lt;/LI&gt;&lt;LI&gt;Tenant health score and a consent posture dashboard&lt;/LI&gt;&lt;LI&gt;Optional expiry email notifications (needs a SendGrid key)&lt;/LI&gt;&lt;LI&gt;Reads Graph through a managed identity, so no app secrets for data access and nothing leaves your tenant&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Runs about $26-30/month (one B2 App Service plan). B1 is also supported, but it's noticeably slower.&lt;/P&gt;&lt;P&gt;It's not a replacement for Entra ID Governance or PIM, more of a cheap everyday hygiene thing.&lt;/P&gt;&lt;P&gt;Full disclosure, I used AI building this and writing this up. I designed the architecture and functionality, tested it and ran it against my own tenant. It's open source and deployable with Azure DevOps or an Azure CLI script. Data never leaves your own tenant.&lt;/P&gt;&lt;P&gt;Repo (screenshots + setup): &lt;A class="lia-external-url" href="https://github.com/nicolaibaralmueller/entra-identity-governance-portal" target="_blank"&gt;Github Repository&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Would love feedback, especially what you'd want it to flag that it doesn't, or where the risk scoring feels off. Been building it on and off for a few months with a lot of iteration. Hopefully this could be useful for others as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2026 08:46:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/made-a-self-hosted-entra-id-governance-portal-for-app-identity/m-p/4533415#M10353</guid>
      <dc:creator>AzAutomationEngineer</dc:creator>
      <dc:date>2026-07-03T08:46:42Z</dc:date>
    </item>
    <item>
      <title>Bring business logic into PIM role activation workflows</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bring-business-logic-into-pim-role-activation-workflows/ba-p/4531380</link>
      <description>&lt;P&gt;Privileged access often depends on business context that lives outside Privileged identity Management (PIM)—ticket validity, HR status, compliance checks, or on-call schedules. With custom extensions for Microsoft Entra Privileged Identity Management, organizations can bring that context directly into activation workflows.&lt;/P&gt;
&lt;P&gt;We’re excited to announce the preview of custom extensions for Microsoft Entra Privileged Identity Management (PIM), a powerful new capability that lets you integrate your organization’s business logic directly into PIM role activation workflows.&lt;/P&gt;
&lt;H2&gt;The challenge&lt;/H2&gt;
&lt;P&gt;Many organizations need governance controls that go beyond what PIM offers natively. While PIM already supports MFA, justification, and approval workflows, organizations also often want to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validate ticket numbers against an ITSM system&lt;/LI&gt;
&lt;LI&gt;Enforce HR-based access rules, such as employment status&lt;/LI&gt;
&lt;LI&gt;Integrate compliance or audit workflows before granting activation&lt;/LI&gt;
&lt;LI&gt;Apply dynamic approval logic based on the specific context of a request&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Until now, these validations required manual processes outside of PIM, which can create gaps in enforcement and auditability.&lt;/P&gt;
&lt;H2&gt;Introducing PIM custom extensions&lt;/H2&gt;
&lt;P&gt;With custom extensions, PIM can now call your REST API during role activation. Your API evaluates the request against your business rules and returns a decision that PIM enforces automatically.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it works:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A user requests role activation in PIM.&lt;/LI&gt;
&lt;LI&gt;PIM sends a structured request payload to your custom extension API, including details like principalId, roleDefinitionId, justification, ticketInfo, and scheduleInfo.&lt;/LI&gt;
&lt;LI&gt;Your API applies your business logic and validates the ticket, checks HR status, or runs compliance checks.&lt;/LI&gt;
&lt;LI&gt;Your API returns a decision—Approved, AutoApproved, or Denied—along with a reason.&lt;/LI&gt;
&lt;LI&gt;PIM enforces the decision and logs the interaction for audit.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Supported scope&lt;/H2&gt;
&lt;P&gt;In this preview, custom extensions support:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PIM for Groups&lt;/LI&gt;
&lt;LI&gt;PIM for Microsoft Entra roles&lt;/LI&gt;
&lt;LI&gt;PIM for Azure resources&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The extension is invoked synchronously during the activation workflow (pre-approval stage), enabling real-time decisioning.&lt;/P&gt;
&lt;H2&gt;Audit and traceability&lt;/H2&gt;
&lt;P&gt;Every extension interaction is fully auditable. Each response includes an evaluationId, evaluationOutcome, and reason, giving you end-to-end traceability for compliance reviews and security investigations.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Setting up PIM custom extensions involves five steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create a new custom extension API — a REST API (HTTP POST) that implements your business logic.&lt;/LI&gt;
&lt;LI&gt;Secure the API with Microsoft Entra ID — register an app and implement token validation.&lt;/LI&gt;
&lt;LI&gt;Onboard the extension in PIM — use Microsoft Graph API to create the custom extension object.&lt;/LI&gt;
&lt;LI&gt;Link the extension to role settings — enable Require pre-approval custom extension in PIM role settings.&lt;/LI&gt;
&lt;LI&gt;Activate and validate — test the end-to-end flow by activating a role.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Example scenarios&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-align-center"&gt;&lt;table border="1" style="width: 81.4815%; height: 499px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Scenario&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Extension logic&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;Ticket validation&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Verify that the ticket ID is valid and assigned to the requester&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;HR compliance gate&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Confirm that the requester meets the required criteria&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;Auto-approval for on-call&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Auto-approve activation for users who are currently on call&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;Deny after hours&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deny activation outside approved maintenance windows&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;What's next&lt;/H2&gt;
&lt;P&gt;Microsoft Entra ID Governance helps you protect, monitor, and audit access to critical assets while ensuring employee productivity. It gives you the ability to ensure the right people have the right access to the right resources with the right controls—preventing identity attacks, enforcing least privilege access, and unifying access control across your environment.&lt;/P&gt;
&lt;P&gt;We’re continuing to enhance custom extensions, and your feedback during this preview will shape the future of extensible governance in Microsoft Entra. We recommend enabling PIM custom extensions end-to-end and sharing your feedback &lt;A href="https://forms.cloud.microsoft/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR28-budnJ4dIuN_0D601vJtUNEdJNlJKUVlXWUdRTjRSSFBJVUdXRDRVMC4u" target="_blank" rel="noopener"&gt;here.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;-Kaitlin Murphy&lt;/P&gt;
&lt;P&gt;Senior Director, Product Marketing&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/kaitmurphy/" target="_blank" rel="noopener"&gt;Kaitlin Murphy | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/privileged-identity-management-custom-extensions" target="_blank" rel="noopener"&gt;Configure custom extensions for PIM role activation (preview) - Microsoft Entra ID Governance | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/graph/api/resources/privilegedidentitymanagementv3-overview" target="_blank" rel="noopener"&gt;Microsoft Graph API reference for PIM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/privileged-identity-management/pim-deployment-plan" target="_blank" rel="noopener"&gt;PIM deployment plan&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;Microsoft Entra blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra" target="_blank" rel="noopener"&gt;Microsoft Entra documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/ct-p/MicrosoftEntra" target="_blank" rel="noopener"&gt;Microsoft Entra community discussions&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 16:35:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bring-business-logic-into-pim-role-activation-workflows/ba-p/4531380</guid>
      <dc:creator>Kaitlin_Murphy</dc:creator>
      <dc:date>2026-07-01T16:35:45Z</dc:date>
    </item>
    <item>
      <title>Protect sensitive data in motion across SaaS and AI apps with Microsoft Purview and Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with/ba-p/4529310</link>
      <description>&lt;P&gt;Once, securing data meant protecting them within the confines of endpoints and managed apps. It lived inside boundaries you controlled. Today, those boundaries have disappeared—and with them, the old playbook for data security.&lt;/P&gt;
&lt;H2&gt;Data security must keep up with how data moves in the AI-era&lt;/H2&gt;
&lt;P&gt;Organizational data now travels constantly between trusted endpoints and unmanaged web apps, SaaS apps, and most critically, generative AI tools over the network. Employees type and paste sensitive information into prompts, upload work-related files to external services or personal cloud storage, and interact with systems that sit entirely outside the traditional enterprise perimeter. AI has expanded the risk surface for potential enterprise data loss.&lt;/P&gt;
&lt;P&gt;Traditional data loss prevention (DLP) approaches lack real-time visibility and enforcement, often flagging incidents after data has already left the organization. In other cases, vendors rely heavily on physical network appliances that are complex and expensive to deploy, or compute-intensive resources that can add latency. In the era of AI, that model breaks down quickly.&lt;/P&gt;
&lt;H2&gt;Enabling real-time data protection for how work happens&lt;/H2&gt;
&lt;P&gt;To address this shift, &lt;STRONG&gt;we’re announcing the&lt;/STRONG&gt; &lt;STRONG&gt;extension of data security to the network layer, powered by Microsoft Purview and Microsoft Entra&lt;/STRONG&gt;, now in public preview.&lt;/P&gt;
&lt;P&gt;This integration brings together data context and identity-aware enforcement to help protect sensitive data in transit, in real-time:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Detect how sensitive data is shared to shadow AI tools, unmanaged SaaS apps, and personal cloud repositories.&lt;/LI&gt;
&lt;LI&gt;Help block or limit data exposure in real-time based on identity, user activity, and data context.&lt;/LI&gt;
&lt;LI&gt;Unify investigation workflows by correlating identity, data, and insider risk signals across Microsoft Purview, Microsoft Entra, and Microsoft Defender.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By combining Microsoft Purview data classification, DLP policies, and insider risk detection with identity-aware enforcement at the network layer through Microsoft Entra, organizations can dynamically apply protections based on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The sensitivity of the data&lt;/LI&gt;
&lt;LI&gt;Who the user is&lt;/LI&gt;
&lt;LI&gt;How that user has interacted with sensitive data over time&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities help protect data in motion across browser sessions, SaaS usage, and AI interactions (including prompts and responses), all at the speed and scale that today’s work demands. The result is a more complete, consistent approach to data protection that follows the data instead of relying on fixed, at-rest controls.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H2&gt;What this changes in practice&lt;/H2&gt;
&lt;P&gt;With network-level visibility and enforcement, security teams can finally understand how sensitive data is moving across unmanaged SaaS and AI apps, not just within Microsoft applications or endpoint devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;Prevent employees from sharing proprietary or sensitive organizational data to potentially risky locations such as consumer AI apps.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That includes scenarios that have historically been difficult to see and protect, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Text that’s inputted directly into unmanaged apps and email services, such as prompts and responses&lt;/LI&gt;
&lt;LI&gt;Files that are uploaded to personal cloud storage repositories&lt;/LI&gt;
&lt;LI&gt;Files and text that could be scanned and processed by unsanctioned plugins or add-ins&lt;/LI&gt;
&lt;LI&gt;Files and text that are shared outside of a managed browser session&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank" rel="noopener"&gt;See the full demo here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Most importantly, protection preempts data leakage. Instead of relying on downstream detection, organizations can detect and block sensitive data in transit before it’s exposed. Because enforcement is tied to identity and user context, policies can adapt based on risk without introducing unnecessary friction for end users.&lt;/P&gt;
&lt;P&gt;Underneath, this is powered by a unified policy model, where the classification and protection policies defined in Microsoft Purview for the rest of your data estate are also enforced consistently at the network layer through Microsoft Entra. This reduces the need to juggle multiple point solutions to secure data holistically across your environment.&lt;/P&gt;
&lt;H2&gt;A shift to real-time data protection&lt;/H2&gt;
&lt;P&gt;This shift reflects a broader transformation in how data and network security teams must operate.&lt;/P&gt;
&lt;P&gt;Traditional approaches rely on static boundaries and after-the-fact controls. That model breaks down when data is continuously exchanged across SaaS apps and AI systems.&lt;/P&gt;
&lt;P&gt;Data protection now needs to operate in real-time and in the flow of user activity.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Network data security&lt;/STRONG&gt; – now available in Microsoft 365 E7* – plays a critical role in enabling this shift by extending enforcement beyond endpoints and applications to the network itself, helping protect data wherever it moves.&lt;/P&gt;
&lt;H2&gt;Learn more&lt;/H2&gt;
&lt;P&gt;As organizations adopt AI at scale, securing data and access during AI and agent use becomes mission-critical.&lt;/P&gt;
&lt;P&gt;Join our &lt;STRONG&gt;three-part webinar series, Securing Data and Access in the Era of AI&lt;/STRONG&gt;, to see how Microsoft Entra and Microsoft Microsoft Purview help protect data, govern access, and reduce risk across your AI journey.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Register for the webinar series: &lt;/STRONG&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/securing-data-and-access-in-the-era-of-ai-with-microsoft-entra-and-microsoft-pur/4529488" target="_blank" rel="noopener"&gt;Securing data and access in the era of AI with Microsoft Entra and Microsoft Purview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;See it in action&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Sule Tatar, &lt;/EM&gt;Senior Product Marketing Manager, SCI Identity&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-Vivian Ma, &lt;/EM&gt;Senior Product Marketing Manager, Microsoft Purview Data Security&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/vivian-y-ma/" target="_blank" rel="noopener"&gt;Vivian Ma | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;*Network data security capabilities are also available to customers with &lt;U&gt;both&lt;/U&gt; a Purview ME5 (or equivalent) and Entra Internet Access (or equivalent) license.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Microsoft Purview&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Dynamically secure your data with an integrated approach across your multi-structured data estate, devices, and generative AI apps and agents.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/product/microsoft-purview/" target="_blank" rel="noopener"&gt;Microsoft Purview news and insights | Microsoft Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/tag/microsoft%20purview?nodeId=board%3Amicrosoft-security-blog" target="_blank" rel="noopener"&gt;Microsoft Purview community blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/" target="_blank" rel="noopener"&gt;Microsoft Purview documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra news and insights | Microsoft Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 16:32:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with/ba-p/4529310</guid>
      <dc:creator>SuleTatar</dc:creator>
      <dc:date>2026-07-01T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Best approach to detect multiple user accounts signing in from the same physical device</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/best-approach-to-detect-multiple-user-accounts-signing-in-from/m-p/4532446#M10348</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;Working on environment: D365 Finance &amp;amp; Operations (cloud).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Goal:&lt;BR /&gt;I need to detect when more than one Dynamics user account is being used&lt;BR /&gt;from the same physical device, and ideally count how many distinct users&lt;BR /&gt;are active on that device. The business reason is this is not permissible to login with more than one account in the same device.&lt;BR /&gt;&lt;BR /&gt;For example:&lt;BR /&gt;User X has device D1, User Y has device D2.&lt;BR /&gt;User X logged in with his account using Device D2 (which is user's Y device).&lt;BR /&gt;&lt;BR /&gt;I want to know if this happened, cause it's not permissible behavior in the organization.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For more illustration some users have blank devices id when I see Microsoft Entra.&lt;BR /&gt;&lt;BR /&gt;Or if I could find out when a user logs in and integrate it with D365 F&amp;amp;O to store the device the user logged into in a custom log table or anything that tells me that this user account is opened on more than one device or this device has more than one logged-in user account.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 09:10:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/best-approach-to-detect-multiple-user-accounts-signing-in-from/m-p/4532446#M10348</guid>
      <dc:creator>RaedSalah</dc:creator>
      <dc:date>2026-07-01T09:10:12Z</dc:date>
    </item>
    <item>
      <title>Microsoft Entra Backup and Recovery is now generally available</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-backup-and-recovery-is-now-generally-available/ba-p/4521997</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Entra Backup and Recovery is now generally available.&lt;/STRONG&gt; Microsoft Entra customers licensed for Entra ID P1 or P2 now can restore supported critical identity data after accidental changes or malicious updates, rolling out to all workforce tenants this week.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity resilience and disaster recovery are top challenges for IT teams. Microsoft Entra Backup and Recovery helps address both by automatically backing up core directory objects daily. Supported objects include &lt;STRONG&gt;users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and authentication and authorization policy,&lt;/STRONG&gt; helping administrators return their environment to a previously known‑good state.&lt;/P&gt;
&lt;img&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/backup/" target="_blank" rel="noopener"&gt;Microsoft Entra Backup and Recovery&lt;/A&gt; is a built-in backup and recovery solution that lets you recover critical Microsoft Entra directory objects to a previously known good state after accidental changes or security compromises. The overview dashboard highlights alerts, recent backups, difference reports, and protected actions.&lt;/img&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-clear-both"&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/backup/overview" target="_blank" rel="noopener"&gt;Get started today with the built-in backup and recovery solution in Microsoft Entra | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;What's changed since public preview?&lt;/H3&gt;
&lt;P&gt;Based on feedback from the Backup and Recovery &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426?previewMessage=true" target="_blank" rel="noopener"&gt;public preview&lt;/A&gt;, we’ve increased the retention period for supported directory objects from 5 days to 7 days to provide extended protection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity admins now have more flexibility when viewing available snapshots, generating difference reports to understand what changed, and running recovery jobs to restore objects to a prior state. These capabilities help teams quickly assess what changed and take action to return to a known good state.&lt;/P&gt;
&lt;P&gt;But recovery is not just about restoring objects. It’s about being prepared to return your tenant to a known‑good state under pressure. Entra Backup and Recovery fits into a broader tenant recoverability strategy so you can reduce disruption, respond to common recovery scenarios, and recover with confidence.&lt;/P&gt;
&lt;H2&gt;Why recoverability matters&lt;/H2&gt;
&lt;P&gt;Accidental deletion, misconfiguration, and malicious changes can disrupt sign‑in, block access to business‑critical applications, and quickly impact downstream operations.&lt;/P&gt;
&lt;P&gt;Backup and Recovery provides an important foundation for restoring supported objects, but tenant recoverability requires a broader approach. Recoverability is the ability to restore tenant configuration and identity objects to a known‑good state after unintended or malicious changes, using clear processes and supported recovery paths.&lt;/P&gt;
&lt;P&gt;This means recovery readiness is not a single solution. It is a combination of capabilities, processes, and preparation across your organization.&lt;/P&gt;
&lt;H3&gt;Layers of Recovery: Best Practices&lt;/H3&gt;
&lt;P&gt;Organizations that recover quickly combine built‑in capabilities like Backup and Recovery with additional layers of preparation and control.&lt;/P&gt;
&lt;P&gt;Key elements of a strong tenant recoverability strategy include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Built&lt;/STRONG&gt;‑&lt;STRONG&gt;in recovery for supported objects&lt;/STRONG&gt;: Use Microsoft Entra Backup and Recovery to restore supported objects and configuration changes within the retention window.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Maintaining a known&lt;/STRONG&gt;‑&lt;STRONG&gt;good configuration state&lt;/STRONG&gt;: Regularly capture tenant configuration using tools such as Tenant Configuration Management APIs and Microsoft Graph exports to support recovery beyond built‑in capabilities.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Operational readiness&lt;/STRONG&gt;: Define recovery processes, retain audit and sign‑in logs, and establish recovery objectives so that recovery actions can be executed under pressure.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reducing blast radius&lt;/STRONG&gt;: Apply least‑privilege access, Privileged Identity Management, and protected actions to limit the scope of potential incidents and simplify recovery.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these layers help organizations move from reactive fixes to a structured recovery strategy.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;"Overall, we like the functionality offered by Microsoft Entra Backup and Recovery. The API support looks solid as well."&lt;/P&gt;
&lt;P class="lia-align-right"&gt;&lt;EM&gt;– A large European automobile manufacturer&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Scenario: Conflicting identity changes disrupt access&lt;/H2&gt;
&lt;P&gt;To illustrate how organizations can use Backup and Recovery, let’s walk through a potential scenario using a fictitious company called “Contoso”.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here's the situation:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The IT team at Contoso relies on Microsoft Entra&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/conditional-access/concept-conditional-access-policies" target="_blank" rel="noopener"&gt;Conditional Access policies&lt;/A&gt; and &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/role-based-access-control/security-planning?toc=/entra/identity/privileged-identity-management/toc.json&amp;amp;bc=/entra/identity/id-governance/privileged-identity-management/breadcrumb/toc.json" target="_blank" rel="noopener"&gt;Privileged Identity Management&lt;/A&gt; to protect access to business-critical applications. Policies are tightly controlled, and administrative access is granted just in time.&lt;/P&gt;
&lt;P&gt;But during a routine day, remote workers suddenly can’t sign in to a critical ordering application. Nothing appears compromised, and the application itself is healthy. &lt;STRONG&gt;The team needs to understand what changed—and restore access quickly.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;Step 1: Identify and restore application access.&lt;/H3&gt;
&lt;P&gt;An administrator runs a Microsoft Entra Backup and Recovery difference report against a recent snapshot and correlates it with Entra audit logs to identify recent changes. The report shows a Conditional Access policy was modified by a known administrator. The update accidentally blocked the remote worker group from accessing the ordering application. Using Backup and Recovery, the administrator restores the policy to a previous state. Access is quickly re‑enabled.&lt;/P&gt;
&lt;H3&gt;Step 2: Investigate beyond the initial fix.&lt;/H3&gt;
&lt;P&gt;With access restored, the team continues investigating to understand how an unintended policy change reached production. They review&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/id-governance/tenant-governance/overview" target="_blank" rel="noopener"&gt;Microsoft Entra Tenant Governance&lt;/A&gt; monitoring signals to identify any related configuration changes.&lt;/P&gt;
&lt;H3&gt;Step 3: Detect configuration drift.&lt;/H3&gt;
&lt;P&gt;Tenant Governance signals reveal drift in role governance configuration during the same timeframe: a change to role eligibility settings broadened who could administer the Conditional Access policy. This change does not align with the approved configuration baseline.&lt;/P&gt;
&lt;H3&gt;Step 4: Confirm conflicting changes.&lt;/H3&gt;
&lt;P&gt;Correlating audit logs with the drift findings, the team reconstructs the sequence. To resolve an urgent, unrelated issue, an administrator had temporarily modified role-eligibility settings — unintentionally allowing a second administrator to edit the Conditional Access policy and block the remote worker group. Two well-intended changes, made independently, combined to cause the outage.&lt;/P&gt;
&lt;H3&gt;Step 5: Restore governance baseline and prevent recurrence.&lt;/H3&gt;
&lt;P&gt;The team initiates an established workflow to restore role governance configuration to the approved baseline. Because Contoso routinely practices scenarios like this during Business Continuity and Disaster Recovery (BCDR) drills, the team is able to coordinate rapidly. They restore both application access and governance controls, reducing the likelihood of similar issues in the future.&lt;/P&gt;
&lt;H2&gt;Recover with confidence: Get started today&lt;/H2&gt;
&lt;P&gt;Microsoft Entra Backup and Recovery provides a built‑in foundation for restoring supported identity data that organizations can adopt as part of a layered recoverability approach that combines built‑in capabilities with preparation, governance, and operational discipline.&lt;/P&gt;
&lt;P&gt;Microsoft Entra Backup and Recovery is built as an API‑first, extensible platform that gives customers the flexibility to design backup and recovery workflows aligned to their operational needs. These same APIs enable independent software vendors (ISVs) to integrate and deliver complementary solutions that extend Entra with their domain expertise.&lt;/P&gt;
&lt;P&gt;By aligning Backup and Recovery with a broader identity resilience strategy, organizations can reduce downtime, respond faster to change‑related incidents, and maintain confidence in the integrity of their identity environment.&lt;/P&gt;
&lt;H4&gt;Ready to strengthen your identity resilience?&lt;/H4&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/backup/" target="_blank" rel="noopener"&gt;Learn how to enable Microsoft Entra Backup and Recovery in your production environment with Microsoft Learn documentation.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;-&lt;/EM&gt; &lt;EM&gt;Cindy Crane, Principal Product Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/architecture/recoverability-tenant" target="_blank" rel="noopener"&gt;Learn more about how to plan for Tenant recoverability &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://techcommunity.microsoft.com/event/microsoft-security-events/recover-with-confidence-using-microsoft-entra-backup-and-recovery/4504269" target="_blank" rel="noopener"&gt;Watch the webinar: Microsoft Entra Backup and Recovery: Recover with confidence&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426?previewMessage=true" target="_blank" rel="noopener"&gt;Learn how to Strengthen Identity Resilience with Microsoft Entra Backup and Recovery&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/backup/" target="_blank" rel="noopener"&gt;Microsoft Entra Backup and Recovery documentation on Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/architecture/recoverability-overview" target="_blank" rel="noopener"&gt;Learn more about Recoverability best practices in Microsoft Entra ID&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;A class="lia-external-url" href="https://www.microsoft.com/security/blog/tag/in-the-loop/" target="_blank" rel="noopener"&gt;Read the new monthly blog series: What’s new in Microsoft Security&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 30 Jun 2026 18:27:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-backup-and-recovery-is-now-generally-available/ba-p/4521997</guid>
      <dc:creator>CindyCrane</dc:creator>
      <dc:date>2026-06-30T18:27:57Z</dc:date>
    </item>
    <item>
      <title>EntraID integration with Biostar 2</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/entraid-integration-with-biostar-2/m-p/4531322#M10352</link>
      <description>&lt;P&gt;Hi all, I have issue integrate entra ID with biostar. The sync keep fail, anyone have done the integration before? Need advise on the integration steps. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2026 12:05:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/entraid-integration-with-biostar-2/m-p/4531322#M10352</guid>
      <dc:creator>SancroNelly</dc:creator>
      <dc:date>2026-06-26T12:05:16Z</dc:date>
    </item>
  </channel>
</rss>

