MicrosoftDocs/entra-docs/docs/external-id

Last 20 commits touching this section.

9608dc1

Revert passkey credential management documentation (#14532) * Revert passkey credential management documentation Roll back the documentation changes from #14510 and #14523, restore the Microsoft Graph redirect, and retain safe passkey sample guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove future API availability promise Update the passkey FAQ to document only the currently supported Microsoft Graph provisioning API. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

3a58306

Merge pull request #14529 from MicrosoftDocs/repo_sync_working_branch Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/entra-docs (branch main)

fb3cbd9

Remove straggler ms.author and author fields for MSec files (#14465)

884f73d

SMS verification is available for self-service password reset (#2127)

10b432f

Document the delegated passkey credential management sample Update the API reference, passkey sign-in guide, and sample catalog for delegated listing and registration. Retain the Graph deletion and test-only warnings, and align sample links across catalog views. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956

75ba36f

Add credential management API reference for passkeys (#14510) * Add credential management API reference for native authentication Document the credential management API that lets customers self-manage their credential methods (passkeys/FIDO) in customer-facing apps. Covers authentication and authorization, continuation tokens, supported methods, listing, provisioning, and deleting credential methods, with HAL+JSON responses and sequence diagrams. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Revise credential management API reference Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0cc72ab1-ca85-4f69-b0b5-38edff4f97da * Restructure credential API prerequisites Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0cc72ab1-ca85-4f69-b0b5-38edff4f97da * Set credential management API application ID Replace the service-principal provisioning placeholder with the public credential management API application ID provided by Reshu Agarwal during product-team review. Application ID: 6bf38b3c-a70f-49aa-a1d9-10e4cc74dde9 Source: Reshu Agarwal, [EEID] 3P Cred Mgt APIs Public Documentation meeting chat https://teams.microsoft.com/l/message/19:meeting_MTZkMTEyODgtY2I3NS00NDlmLWI5YTMtOGU5YzVkY2ZjOTcz@thread.v2/1784912888035?context=%7B%22contextType%22%3A%22chat%22%7D Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 75306884-be29-48dc-9a1c-c2075d7ca40f * Remove redundant Graph view parameter Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR review feedback Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify passkey deletion support and sample guidance Direct passkey deletion to Microsoft Graph until credential management API support is available. Explain unsupported delete links, add the JavaScript sample reference, and align the passkey sign-in article. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956 * Remove deferred passkey sample references Remove the sample-app references from the credential management API reference and passkey sign-in guide, and refresh their article dates. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956 * Remove obsolete credential management API redirect Remove the redirect entry for the restored credential management API reference while preserving the article and all other redirects. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956 * Remove preview wording * Restore the Microsoft Graph passkey sample reference Restore the testing-only sample paragraph in the passkey sign-in guide, including its administrator-controlled provisioning and self-service caveats. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956 * Restore the passkey deletion experience bullet Undo the removal of the original "Delete a passkey." bullet at line 86 of the passkey sign-in guide. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956 --------- Co-authored-by: Derdus Kenga <kengaderdus@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: marshmacy <253514592+mmacy-msft@users.noreply.github.com> Copilot-Session: 0cc72ab1-ca85-4f69-b0b5-38edff4f97da Copilot-Session: 75306884-be29-48dc-9a1c-c2075d7ca40f Copilot-Session: b75dbcdc-e93a-45d4-8f27-0efcb6d84956

12aaf65

Consolidate 'Add identity provider to user flow' into a single article referenced by all federation docs (#13312) * Clarify that adding IdP to user flow is only needed for self-service sign-up Update all 7 federation articles (custom OIDC, Entra ID, Microsoft accounts, Apple, Google, Facebook, SAML/WS-Fed) to clarify that adding an identity provider to a user flow is only required for self-service sign-up. If users are invited using the domain_hint parameter, the identity provider does not need to be added to the user flow. Also update custom OIDC and Entra ID federation articles to describe both approaches (self-service sign-up vs invitation) in the intro section. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Consolidate 'Add IdP to user flow' into single generic article Transform how-to-saml-ws-federation-self-service-sign-up.md from a SAML-specific article into a generic 'Add an identity provider to a user flow' article that applies to all identity provider types. Replace inline 'Add to user flow' steps in all 6 federation articles (custom OIDC, Entra ID, Microsoft accounts, Apple, Google, Facebook) with a cross-reference to the consolidated article. Update TOC entry from 'Self-service sign-up for federated users' to 'Add an identity provider to a user flow'. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove inline 'Add to user flow' sections, add two-approach intros Remove the 'Add XXX identity provider to a user flow' sections from all 6 federation articles. Instead, update each article's intro to describe the two ways to enable users to authenticate with the identity provider: 1. Add the identity provider to a user flow (for self-service sign-up) 2. Invite users with domain_hint (for invite-only scenarios) Both options link to the respective canonical articles. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Move two-approach section to end of each IdP article Move the 'two ways to enable users to authenticate' content from the intro to a new 'Enable users to authenticate with the identity provider' section at the end of each federation article (before Related content). This keeps the intro focused on what the IdP is and how federation works, while the end section guides users to the appropriate next step (add to user flow for self-service, or invite users with domain_hint). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rename add-idp-to-user-flow article, reorder sections, update links - Rename how-to-saml-ws-federation-self-service-sign-up.md to how-to-add-idp-to-user-flow-customers.md - Move 'Enable users to sign-in and sign-up' section before FAQ/Known Limitations - Update all cross-references to new filename - Remove invite article references from all federation articles - Standardize 'Enable users' wording across all IdP articles Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: Gearoid O'Donnell <110535959+garrodonnell@users.noreply.github.com> * Fix build warnings: update stale link in direct-federation.md, add redirect - Update reference to renamed file in direct-federation.md - Add redirect from old URL to new how-to-add-idp-to-user-flow-customers Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add blank line before Related content lists in federation docs, as suggested by docs team Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Spell out identity provider in article path Rename the consolidated user-flow article and media folder, and update all links, TOC entries, and the redirect target. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Gearoid O'Donnell <110535959+garrodonnell@users.noreply.github.com> Copilot-Session: 9f5f4dc7-8de7-472f-8187-b81a9e4dfcbe

e04d2d6

Remove credential management API reference and redirect to Graph (#14341) Remove the article and four images added by MicrosoftDocs/entra-docs-pr#13863, remove its TOC entry, and replace all references in the passkey guide with the Microsoft Graph FIDO2 documentation. Restore the pre-PR low-privilege API guidance while retaining unrelated fixes and the sample warning. Add the redirect in the same change as the deletion, following docs-help-pr retirement guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

05b335f

Expand compliant device trust guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

ed9dbfa

Add Verified ID setup guidance for external tenants (#14324) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

2d2d9ad

Merge pull request #13606 from MicrosoftDocs/learn-build-service-prodbot/docutune-autopr-20260623-010826-4681132-ignore-build [BULK] - DocuTune remediation - Content SFI - docs/external-id

281a7d3

[REST] Add credential management API reference for native authentication (#13863) * Add credential management API reference for native authentication Document the credential management API that lets customers self-manage their credential methods (passkeys/FIDO) in customer-facing apps. Covers authentication and authorization, continuation tokens, supported methods, listing, provisioning, and deleting credential methods, with HAL+JSON responses and sequence diagrams. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Revise credential management API reference Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0cc72ab1-ca85-4f69-b0b5-38edff4f97da * Restructure credential API prerequisites Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0cc72ab1-ca85-4f69-b0b5-38edff4f97da * Set credential management API application ID Replace the service-principal provisioning placeholder with the public credential management API application ID provided by Reshu Agarwal during product-team review. Application ID: 6bf38b3c-a70f-49aa-a1d9-10e4cc74dde9 Source: Reshu Agarwal, [EEID] 3P Cred Mgt APIs Public Documentation meeting chat https://teams.microsoft.com/l/message/19:meeting_MTZkMTEyODgtY2I3NS00NDlmLWI5YTMtOGU5YzVkY2ZjOTcz@thread.v2/1784912888035?context=%7B%22contextType%22%3A%22chat%22%7D Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 75306884-be29-48dc-9a1c-c2075d7ca40f * Remove redundant Graph view parameter Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR review feedback Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Derdus Kenga <kengaderdus@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0cc72ab1-ca85-4f69-b0b5-38edff4f97da Copilot-Session: 75306884-be29-48dc-9a1c-c2075d7ca40f

579d06f

Merge pull request #14130 from jconley76/jconley76-allow-deny-list-size-limit Clarify approximate domain capacity for allow/block list policy

8075d65

Add example of approximate domain count for allow/block list policy size limit Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

2ea7a11

Merge branch 'main' into update-oidc-federation-known-limitations

0af00c3

Update OIDC federation known limitations Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

b69da92

Merge pull request #13929 from vimrang/docs/cross-cloud-b2b-login-hint-known-behavior Add known behavior note for cross-cloud B2B login_hint

c370726

Update cross-cloud B2B authentication behavior details Clarified the behavior of the `login_hint` in cross-cloud B2B scenarios, emphasizing the importance of matching the guest user's mail attribute with their home UPN for a seamless SSO experience.

e3e0d41

Add known behavior note for cross-cloud B2B login_hint Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

305eba4

Remove email OTP MFA note and limitation bullet Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: fdced7b6-18b8-43e4-963c-91aa8b7d7bc2