[{"author":"ArieHein","date":"2026-10-06T14:47:13+00:00","message":"Spelling fixes (#2125)\n\n* spelling an auto space removal\n\n* Apply suggestion from @ShawnKupfer\n\n---------\n\nCo-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>","sha":"12cb62ac91e33e82c48d712b8cb2936f3e15b2b8","url":"https://github.com/MicrosoftDocs/entra-docs/commit/12cb62ac91e33e82c48d712b8cb2936f3e15b2b8"},{"author":"markwahl-msft","date":"2026-09-28T16:41:42+00:00","message":"remove references to Meta Workplace (#14467)","sha":"dafedf1c80bcad96244837ea7ce040b37ddafa78","url":"https://github.com/MicrosoftDocs/entra-docs/commit/dafedf1c80bcad96244837ea7ce040b37ddafa78"},{"author":"Albertyang0","date":"2026-09-24T16:04:06+00:00","message":"release-preview-entra-provision-to-ad -> main -- 9/24 10AM PDT (#14417)\n\n* Reapply \"Users and Groups Provision to AD docs (#14052)\" (#14263) (#14268)\n\nThis reverts commit 2b47765dfd4bb42ecbecdf3e717959d6f189731f.\n\n* Retire the duplicate Microsoft Entra ID to Active Directory attribute mapping article (#14206)\n\n* Retire the duplicate Microsoft Entra ID to Active Directory attribute mapping article\n\nThe configure article covers scoping filters and attribute mapping for both users and groups in the Microsoft Entra ID to Active Directory direction, so this article duplicates it.\n\nDelete the article and the nine images only it used, remove its table of contents entry, add a redirect to the configure article, and repoint the three inbound links.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Fix link to retired attribute mapping article\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Correct Cloud Sync subservice metadata\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n---------\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Update Source of Authority guidance for provisioning to Active Directory (#14205)\n\n* Update Source of Authority guidance for provisioning to Active Directory\n\nCover the scenarios that provisioning Microsoft Entra ID users and groups to Active Directory enables: keeping an Active Directory account for Kerberos applications after converting a user's Source of Authority, and governing that user's lifecycle from the cloud.\n\nCorrect the ms.reviewer alias across the Source of Authority set.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Apply the pre-review guidance to the Source of Authority articles\n\nThe same issues the review team blocked on the provisioning pull request apply here: Learn doesn't allow future product plans, and file names shouldn't use internal abbreviations.\n\nState the password writeback limitation without dates in five places, and remove the commented-out section describing it, along with the diagram only that section used.\n\nRename the lifecycle diagram so the file name says what it shows instead of using the UPAD abbreviation.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Use Markdown headings for bookmarks and correct on-premises terminology\n\nRemove the two leftover HTML anchors before the headings; nothing links to\nthem, and the headings already generate their own bookmarks. Expand the\nremaining on-prem abbreviations to on-premises.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove the future availability promise from the readiness diagram\n\nLearn publishing policy doesn't allow future product plans, so drop\n'(available Sep 2026)' from the LDAP bind node. The first two lines wrap\nunchanged without it, so only the third line is repainted.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Correct the Active Directory object enforcement link target\n\nThe article is how-to-active-directory-object-enforcement.md, so the two\nlinks to how-to-ad-object-enforcement.md were reported as file-not-found.\nAll remaining cloud-sync links resolve against the articles PR 14052 adds.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Spell out the abbreviations in the lifecycle management diagram\n\nRegenerated from the PowerPoint source rather than patching the export:\nAD Users becomes Active Directory Users, SOA: AD becomes SOA: Active\nDirectory, MIM becomes Microsoft Identity Manager, and On-Prem HR source\nbecomes On-premises HR source. Resized the title to a single line and\nrepositioned the two left-hand labels so the longer text clears the\nconnector line and its containing shape.\n\npre-hire is left as is. It's the product name of the built-in Lifecycle\nWorkflows template, Onboard pre-hire employee, shown in an embedded\nscreenshot of that UI.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Update Source of Authority subservice metadata\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n---------\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove invalid hybrid landing page subservice\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Retrigger documentation validation\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n---------\n\nCo-authored-by: Dhanyah Krishnamoorthy <dhanyahk@users.noreply.github.com>\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Alma Jenks <v-alje@microsoft.com>\nCo-authored-by: Dhanyah Krishnamoorthy (SHE/HER) <dhanyahk@microsoft.com>\nCo-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3","sha":"e12ee33874afa8164c88fed97789e51592c56c32","url":"https://github.com/MicrosoftDocs/entra-docs/commit/e12ee33874afa8164c88fed97789e51592c56c32"},{"author":"mestew","date":"2026-09-10T17:45:39+00:00","message":"[BULK cpcli] Rebrand Microsoft 365 Copilot to Microsoft Copilot MAXADO-12279337\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 4829db76-3855-456d-a4c0-9931bdb6e163","sha":"bf45f8ce25e7399b24936ec9ecab0e29d79d95f6","url":"https://github.com/MicrosoftDocs/entra-docs/commit/bf45f8ce25e7399b24936ec9ecab0e29d79d95f6"},{"author":"dhanyahk","date":"2026-08-31T07:24:01+00:00","message":"Revert \"Users and Groups Provision to AD docs (#14052)\" (#14263)\n\nThis reverts commit 10c83918fad008a4b10314fe2c4e3cb75d73eec7.","sha":"2b47765dfd4bb42ecbecdf3e717959d6f189731f","url":"https://github.com/MicrosoftDocs/entra-docs/commit/2b47765dfd4bb42ecbecdf3e717959d6f189731f"},{"author":"dhanyahk","date":"2026-08-28T15:34:57+00:00","message":"Users and Groups Provision to AD docs (#14052)\n\n* Update provisioning guidance for users and groups\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Add updated provisioning screenshots\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Correct provisioning screenshot sequence\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Rename provisioning configuration article\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Render provisioning screenshots in Markdown previews\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Add Entra to Active Directory documentation set\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Expand Entra ID to AD provisioning documentation\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Share Entra to AD prerequisites across guides\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Apply documentation copy-edit recommendations\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Clarify provisioning licensing and release timing\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Expand Entra to AD provisioning guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\n\n* Correct Entra to AD technical guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: 636f04f7-246d-4c40-ac81-6e0ddd9b2a8f\n\n* Restore provisioning licensing requirements\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: 636f04f7-246d-4c40-ac81-6e0ddd9b2a8f\n\n* Copy edit Entra to AD provisioning docs\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Mark Entra to AD guidance as preview\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Merge AD user and group enforcement guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Move app governance article under Group SOA\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Update cloud-first architect guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Update SOA readiness decision tree\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Add missing UPAD scenarios and directory extension guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Revise User SOA lifecycle and password guidance\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Address AD enforcement review feedback\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\n\n* Address review feedback on scoping filter and test/enable docs\n\n- Replace duplicated prerequisites include in the configure and test/enable\n  articles with a single funnel link, so prerequisites contain no calls to\n  action, steps, or commands.\n- Drop the redundant Prerequisites H2 from the prerequisites article and\n  promote the include headings to H2.\n- Trim redundancy in the Preserve the OU path section.\n- Remove the group target container screenshot from the Preserve a group's\n  original organizational unit section; it shows a Switch() expression.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n* Document moving a provisioned user to a different OU\n\nAdds guidance for the reported scenario where changing the target\ncontainer doesn't move an already-provisioned user, because the default\nparentDistinguishedName expression derives the OU from\nonPremisesDistinguishedName when that attribute is populated.\n\n- Add \"Move a provisioned user to a different organizational unit\" to the\n  configure how-to, covering the cause, the three ways to move a user,\n  and how to verify the move in provisioning logs.\n- Add a \"Common tasks\" table to the concept article so the task-level\n  sections in the how-to are discoverable, plus a line explaining the\n  target container precedence rule.\n- Add a \"Provisioning users to Active Directory\" FAQ entry.\n- Apply the funnel-of-success prerequisites pattern to the test and\n  enable how-to.\n- Copy edits: restore the deployment options enumeration, expand SOA on\n  first use, remove a stray comma, and drop a duplicate link.\n\nScreenshots are redacted to remove object IDs, SIDs, and account names.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Note the role required to edit onPremisesDistinguishedName\n\nThe attribute is read-only for non-privileged users, so calling out the\nHybrid Identity Administrator requirement prevents readers from hitting an\nauthorization failure when following the single-user move steps.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Fix heading contradiction, stale link text, and reviewer alias in SOA articles\n\n- Rename 'Recommended Solution: Microsoft Entra Domain Services' to 'Another option' so the heading matches the body text this PR changed to 'Another option'.\n\n- Update link text in concept-source-of-authority-overview.md to the IT architects article's new title, matching the sibling reference already updated in user-source-of-authority-overview.md.\n\n- Correct ms.reviewer to dhanyahk in four articles (was dhanyak / dahnyahk).\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Correct ms.reviewer alias to dhanyahk in remaining SOA articles\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Resequence the configure article to match the setup order\n\nThe article presented three setup H2s for the portal's two configuration sections, and mixed post-deployment tasks into the middle of setup.\n\n- Move 'Scope using directory extensions' under 'Configure scoping filters'; it was filed under 'Configure the target container' despite being a scoping topic.\n\n- Group post-deployment tasks (verify, AD-skip behavior, move a user's OU, roll back) under a new 'Verify and manage provisioned objects' section after attribute mapping, instead of nesting them under 'Preserve the OU path'.\n\n- Promote the OU-preservation and post-deployment task headings from H4 to H3 so they appear in the on-page navigation, which renders only H2 and H3. Maximum heading depth drops from H5 to H4. Anchors are generated from heading text, so no links break.\n\n- Move the orphaned 'select Save' step out of the rollback section to the end of the target container section, and reword the duplicated closing sentence so each configuration section ends with its own step.\n\nNo prose was rewritten; the diff is heading levels, section order, and the two closing steps.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Document user SOA provisioning scenarios and on-premises attribute writeback\n\nThe 'Group and user SOA scenarios' table covered only group and membership provisioning, so there was no reference for how a user is provisioned based on the user's own source of authority.\n\n- Add a 'User SOA scenarios' table under 'How users are provisioned' covering cloud-native, SOA-converted, and B2B guest users in both directions. Users follow the same rule as groups: an on-premises source of authority blocks provisioning to AD, and a cloud source of authority blocks sync back to Microsoft Entra ID.\n\n- Add 'On-premises attributes written back to Microsoft Entra ID' listing the five attributes stamped on the cloud object after provisioning. This explains how a cloud-native user acquires an onPremisesDistinguishedName, which the OU-move procedure depends on, and cross-link the two.\n\n- Rename the existing table to 'Group membership SOA scenarios' to match what it documents.\n\nCopy-edit and security review fixes:\n\n- Spell out Source of Authority and business-to-business on first use.\n\n- Use 'Microsoft Entra ID' instead of bare 'Entra' in 18 sync-direction table cells.\n\n- Remove a duplicated explanation and a repeated SID expansion.\n\n- Remove the stale sfi-image-nochange tag from the configure article. It attested that the article's images needed no review, but three screenshots were added after that attestation, so the new images would have been skipped by image scanning.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Correct group membership behavior for user provisioning to AD\n\nThree articles stated that groups provisioned to AD DS can contain only on-premises synchronized users or cloud-created security groups. That was true when only group provisioning existed, but user provisioning gives cloud-managed users an AD account, so those users can be written as members.\n\nMembership depends on whether the member has an AD account, not on the member's source of authority. A member can have one because it's synchronized from AD or because user provisioning created it.\n\n- Correct the claim in the deployment options article, the shared prerequisites include, and the multi-forest section of the topologies article.\n\n- Rewrite the group membership scenarios table. Split it by source direction, replace the sync direction column with the member's AD account, and add the two cases that user provisioning changes: cloud members of a cloud group are now written as member references when those members are provisioned to AD.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Correct membership behavior, apply review feedback, and extract group OU setup\n\nReview feedback (SahaAditi):\n\n- Only users retain their original organizational unit automatically. Groups need a directory extension, so the overview no longer claims both.\n\n- Rewrite the deployment options table. What's generally available is memberships to on-premises owned users, which the previous wording overstated.\n\n- Replace the combined-versus-standalone section. Separate user and group configurations aren't possible for one domain, because there's one configuration per AD domain.\n\n- Generalize scale limits from groups to objects, and add limits for users. Users, groups, and membership links count toward the same total.\n\n- Reword the licensing row so it states what existing configurations need rather than inviting comparison with new ones.\n\nTechnical corrections:\n\n- Group membership now depends on whether the member has an AD account, not on the member's source of authority alone. Rebuild the scenarios table around the configuration, and note that the on-premises membership setting must be enabled.\n\n- Add the out-of-scope row to the deletes table, correct the agent build to 1.1.2334.0, remove the password hash sync option, and add the Mooncake app role ID.\n\n- One provisioning job now handles users and groups, so drop 'group' from the job references and remove the suggestion to split a domain across multiple jobs.\n\nStructure and formatting:\n\n- Extract the GroupDN setup procedure into its own how-to. It's a one-time task performed before Source of Authority conversion, it carried a nested tab group, and it made the target container section 37 percent of the configure article. That article drops from 549 to 433 lines.\n\n- Convert 28 images to the Learn :::image::: syntax used elsewhere in this docset, which also adds borders and completes the alt text.\n\n- Render prerequisites as a checklist, and fix three alt-text values that lacked a media type and a period.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Note the built-in isWritebackEnabled property in the directory extension tutorial\n\nThe tutorial teaches a custom WritebackEnabled extension attribute so that scoping filters can select which groups are written back. Microsoft Entra ID now exposes a built-in isWritebackEnabled property through Microsoft Graph that attribute value filtering can use directly, so readers should know the workaround is optional before they follow the steps.\n\n- Add a note at the start of the group scoping scenario pointing to the built-in property and to attribute value filtering.\n\n- Repoint the tip that referenced the writeback flag. Its link resolved to docs/identity/users/groups-write-back-portal.md, which doesn't exist in this repo, so the tip now refers to the built-in property described earlier in the article.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Retitle the group organizational unit article and align its link text\n\nThe H1 read 'Set up organizational unit preservation for a group', which named the mechanism rather than the outcome and didn't match the article's own metadata title or its TOC label.\n\nThe H1 now states the reader's goal and the trigger, and the three articles that link to it use matching link text.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Rewrite the provisioning walkthrough around a governance scenario\n\nThe tutorial was four disconnected examples, and two of them didn't work as written. Example 2 told the reader to provision Britta Simon while explaining that the default dirSyncEnabled IS FALSE clause admits only cloud-managed users, and she's a synchronized user. Each example also opened by creating a new configuration for the same domain, which a domain doesn't allow.\n\nThe tutorial now follows one scenario. Contoso runs a Kerberos expense application that authorizes on an AD DS group, the cloud group that decides access holds both synchronized and cloud-managed members, and the cloud-managed members can't reach the application because they have no AD DS account to reference.\n\n- Add cloud-managed users to the cast, since user provisioning exists for them, and keep the synchronized users so the group has mixed membership.\n\n- Use one configuration throughout, and cover both scoping modes: Selected for the fastest sync, and All with attribute value filtering when the scope needs to hold at scale.\n\n- Test on demand before enabling, rather than after.\n\n- Explain that a provisioned account exists so Kerberos works, that the user signs in with a passwordless method through Cloud Kerberos Trust, and that applications requiring a password aren't supported until password writeback.\n\n- Connect the result to Microsoft Entra ID Governance, so access packages, access reviews, and lifecycle workflows reach the on-premises application.\n\n- Drop 11 bookmark anchors that preserved headings from an unpublished draft rather than any published anchor.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove the user default security clause and add lifecycle and enforcement steps\n\nThe docs stated a default security clause of dirSyncEnabled IS FALSE for users. The source article documents that condition only as part of the group default security grouping, so the user variant was an extrapolation. Removed it from the configure article, the deployment options article, and the tutorial.\n\nSynchronized users are already excluded because their Source of Authority is on-premises, so the tutorial now explains the exclusion that way instead of attributing it to a filter clause.\n\nTutorial additions:\n\n- Add a step to mark the provisioned users and group for AD object enforcement, so the objects accept changes only from the provisioning service, with a recommendation to install the policy in Audit mode first.\n\n- Replace the governance section with the full lifecycle, from HR-driven provisioning into Microsoft Entra ID through access assignment, provisioning to AD DS, attribute changes, and offboarding, so the tutorial shows where provisioning sits in a joiner, mover, and leaver flow.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Retire the superseded Entra ID to AD attribute mapping article\n\nTwo articles covered scoping filters and attribute mapping for the Microsoft Entra ID to Active Directory direction. The older one predates user provisioning: its schema table lists only group attributes, it has no user schema, and it marks six mappings as not updatable in the UI even though the portal now supports adding mappings per object type for user, group, and contact.\n\nThe configure article covers every section the older article had, for both users and groups, so the older article is removed rather than repaired.\n\n- Delete how-to-attribute-mapping-entra-to-active-directory.md and add a redirect to the configure article.\n\n- Remove its TOC entry and repoint the one inbound link in group-writeback-cloud-sync.md.\n\n- Remove nine images that no other article referenced.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove Entra ID to AD content from the AD to Entra ID attribute mapping article\n\nThe Active Directory to Microsoft Entra ID attribute mapping article carried a section for the opposite direction, so the Microsoft Entra ID to Active Directory procedure lived in an article whose title says it covers AD to Microsoft Entra ID.\n\n- Move the procedure for adding an attribute mapping into the configure article, which is now the only article covering the Microsoft Entra ID to Active Directory direction. The steps include selecting the object type, so they apply to users, groups, and contacts.\n\n- Remove the section and its bookmark from the AD to Microsoft Entra ID article, and repoint its opening cross-reference, which still named the article retired in the previous commit.\n\n- Remove the screenshot that no other article referenced.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Fix two bookmarks left dangling by the attribute mapping consolidation\n\nRetiring the Microsoft Entra ID to Active Directory attribute mapping article, and removing the Entra ID to AD section from the AD to Entra ID article, left two links pointing at headings that no longer exist. The build reported the first as a bookmark-not-found warning.\n\n- migrate-group-writeback.md now points to the add-a-mapping steps in the configure article.\n\n- The governance include now points to the target container section of the configure article.\n\n- Expand Source of Authority on first use in the tutorial.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Add recommended configuration guidance and correct attribute value filtering behavior\n\nAttribute value filtering is now available with the Selected users and groups scope. The admin center warns against it rather than blocking it, so three statements that described the old enforcement were wrong.\n\n- Correct the two statements in the configure article and one in the tutorial.\n\n- Add a Recommended configuration section to the deployment options article, covering the two scoping modes and the on-premises membership setting, with the reason each choice affects cycle time.\n\nThe two scoping modes have opposite filter requirements, so the section states that directly and tells readers to remove filters when changing a configuration from All to Selected.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Recommend cloud-managed groups over provisioning membership to on-premises users\n\nThe guidance for the on-premises membership setting described it as a per-cycle cost to enable only when needed. The actual recommendation is architectural: convert the group's Source of Authority to the cloud and provision that cloud-managed group, which removes the need for membership links to synchronized users.\n\n- Rewrite the table row to say the setting is transitional.\n\n- Add a short section explaining the recommended end state and linking to group Source of Authority configuration.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove remaining enforcement language for attribute value filtering\n\nAttribute value filtering is now warned about rather than blocked, so the surrounding text no longer describes it as a constraint.\n\n- Drop the unsupported-configuration bullet for unfiltered All scoping. It's covered by the Recommended configuration section, and it isn't a support boundary now.\n\n- Correct the scope-by-assignment intro, which said the choice determines whether filtering is available. It determines whether filtering is appropriate.\n\n- Change 'you must configure' and 'requires at least one attribute filter' to recommendations.\n\n- Correct alt text that described attribute filters as required, and add TODO comments marking two screenshots for recapture.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Attribute scoping warnings to the provisioning configuration\n\nThe warnings come from the provisioning configuration experience, not the Microsoft Entra admin center generally, so name the surface that shows them.\n\nAlso correct the attribute value filtering guidance, which still called a filter 'required' with All users and groups. It's recommended, not enforced.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Clarify why attribute value filtering suits only one scoping mode\n\nThe guidance said a filter 'does real work' with All users and groups and 'only adds work' with Selected, using the same word for two different things. Name what the filter actually does: it narrows the scope in one mode, and adds processing time in the other.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Correct on-demand provisioning direction and align both TOC trees\n\nThe two on-demand articles each described the other direction. The Microsoft Entra ID to Active Directory article said it covered provisioning to Microsoft Entra ID, and pointed to itself as the article for the other direction. Correct both intros and point each at its counterpart.\n\nAlso state that on-demand provisioning applies to a single user or group, matching the unified job, and flag the group-only steps and screenshots for update.\n\nIn the TOC, list the same articles in the same order in both Provision Microsoft Entra ID to Active Directory trees, and move the directory extensions concept next to the tutorial that implements it.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Restore the Active Directory to Microsoft Entra ID on-demand article\n\nThat article is outside the scope of provisioning Microsoft Entra ID to Active Directory. Its intro has the same swapped-direction defect as its counterpart, but the fix belongs in separate work.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Add a user example to the directory extensions tutorial\n\nThe tutorial covered only groups, and only the scoping-filter use. Directory extensions also carry values into Active Directory attributes, and both uses work for users and groups.\n\nRestructure the article around Groups and Users tabs so the shared setup (Graph PowerShell SDK, CloudSyncCustomExtensionsApp, and its service principal) is written once instead of repeated per scenario. Add the user example: create a User-targeted extension, populate it, map it to an Active Directory attribute, and verify the result.\n\nAdd a section for users whose Source of Authority is converted, which map from extensions that already hold the values rather than creating new ones.\n\nIn the concept article, repair the table row that was missing its leading pipe, and point to the tutorial as covering both users and groups.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Let readers expand the diagrams added in this pull request\n\nSix diagrams and illustrations were added without a lightbox, so readers couldn't enlarge them. Diagrams carry detail that's hard to read at inline width.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Match each example's setup to the example, and correct stale link text\n\nThe directory extensions tutorial listed one merged set of assumptions, so Users-tab readers saw four named users and three organizational units that only the Groups example uses, and never saw their own prerequisites. Tab the environment list, restore the user prerequisites, and move the group writeback diagram into the Groups tab.\n\nThe provisioning walkthrough was retitled to reflect its governance scenario, but four links still called it 'Provision users and groups to Active Directory'. Point them at the current title.\n\nRename two closing sections to Related content so the article set is consistent, and add the missing tutorial link to the directory extensions concept article.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Give the provisioning articles a next step\n\nThe articles form a sequence, from the overview through deployment options, prerequisites, configuration, testing, the tutorial, and enforcement, but each one ended in an undifferentiated list of related links. A reader finishing an article had no signal about which link continues the path.\n\nAdd a Next step action to each article in the sequence, and route the three side branches (preserve a group's organizational unit, directory extensions, and the extensions tutorial) back to test and enable. Remove the promoted link from Related content so it isn't listed twice.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Follow the task path in the next step, not the table of contents order\n\nThe next step chain was built from table of contents order, which groups conceptual material ahead of procedures. That routed a reader who just chose a deployment option into How provisioning to Active Directory works, a reference article about Source of Authority scenarios, membership, and deletes, instead of into the setup they were ready to start.\n\nPoint deployment options at the prerequisites, and keep how provisioning works reachable from Related content everywhere with its own next step back onto the path.\n\nPoint test and enable at enforcement. The tutorial covers the same configuration end to end, so it reads as a parallel entry point rather than a follow-on step; it stays in Related content and still leads to enforcement.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Describe the shipping behavior, not how it changed during development\n\nThis is the first release of the feature, so readers have no earlier version to contrast against. Two screenshot notes described attribute value filtering as having changed from blocking to warning, and attributed the warning to the admin center rather than the provisioning configuration.\n\nRewrite both notes to state what the capture should show. Also drop 'no longer required' from the isWritebackEnabled note, which implied a prior requirement the reader never saw.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove the scope by attribute screenshot that shows filters as required\n\nThe capture presents an attribute filter as required for each enabled object type, which isn't how the feature behaves. Removing it is better than shipping a screenshot that contradicts the surrounding text; the section reads fine without it, and a correct capture can be added later.\n\nDrop the speculative recapture note on the Selected users and groups screenshot. That capture shows the Scope by assignment step, which is accurate as it stands.\n\nIn the on-demand article, generalize the procedure to cover selecting a user or a group, and note that the screenshots show the group flow. Preserve the old verify-a-group anchor on the renamed heading.\n\nRemove the directory extension questions about dropdown naming and repeated writes. The section doesn't assert either behavior, so the notes asked for detail to add rather than flagging anything incorrect.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Set the users-only scale limit to 200K\n\nThe previous 500K value was provisional and carried a note asking Engineering to confirm it. The supported ceiling is 200K users, matching the tenant scale conditions that group provisioning already documents: fewer than 200K users, fewer than 40K groups, and fewer than 1M group memberships.\n\nAdd a Notes column so the users table explains the limit the way the groups table above it does.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Shorten two titles past the search-result cutoff and break up dense sentences\n\nSearch results and browser tabs truncate around 60 characters. The preserve-OU title ran to 85 and the tutorial to 79, so both lost their ending. Shorten each to lead with what the reader searches for; the H1 keeps the full phrasing.\n\nTrim the tutorial description from 214 characters, which also truncates in search results.\n\nSplit four sentences that ran past 35 words, including the membership rule and the enforcement script prerequisite, where the length was burying the instruction. Convert the shared setup sentence in the directory extensions tutorial into the list it was describing.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Show the Provision on demand experience for users and for groups\n\nThe procedure described a single group-only flow, but the page has separate Users and Groups tabs that ask for different input: a user is chosen by name, while a group also asks which members to test. The two screenshots were generic and predated user provisioning.\n\nMirror the page with Users and Groups tabs, add screenshots for each path, and describe the result page: the four steps it reports, what Success and Skipped mean, and the Retry and Provision another object buttons.\n\nBlur the tenant domain, configuration name, signed-in account, user and group names, the user principal name, and the group object ID in all five captures.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Move the Source of Authority guidance updates out of this pull request\n\nThose articles describe converting Source of Authority, not provisioning to Active Directory, and their changes stand on their own. Three of them link to articles this pull request adds, so they follow it rather than ship with it.\n\nThe full set is preserved on the upad-full-backup branch and reapplies once this pull request merges.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Keep the duplicate attribute mapping article until its replacement ships\n\nRetiring that article depends on this pull request: the configure article only covers both object types for the Microsoft Entra ID to Active Directory direction once these changes merge, and one inbound link targets a heading this pull request adds.\n\nRestore the article, its nine images, its table of contents entry, and the two inbound links, and drop its redirect. The retirement follows as its own pull request.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Repoint the Source of Authority links to the tutorial this pull request deletes\n\nTwo Source of Authority articles link to the group provisioning tutorial that this pull request replaces. Reverting those articles to their published state reintroduced the links, and a relative link to a deleted file is a broken link no matter what redirect exists.\n\nPoint them at how provisioning works, which now carries the nested membership behavior the second link was citing. Those two files otherwise stay at their published state and move with the rest of the Source of Authority work.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Keep the image the published attribute mapping article still uses\n\nThe image was deleted along with the group provisioning tutorial, but the Active Directory to Microsoft Entra ID attribute mapping article references it too, and that article stays at its published state in this pull request. Deleting the image left a broken reference behind.\n\nThe image goes when the section that uses it goes, in the pull request that retires the duplicate article.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Show the attribute value filtering warnings and refresh the outdated wizard captures\n\nAttribute value filtering is now reachable from Selected users and groups, so the wizard gained a Scope by attribute step and the captures showing six steps no longer match. Replace the Scope by assignment and Configure group membership captures with the current seven-step wizard, which also picked up revised on-screen text.\n\nAdd captures of the Scope by attribute step for both scoping modes, showing the warning each one raises: add a filter with All users and groups, remove filtering with Selected users and groups.\n\nCorrect the target container section, where two captures were transposed. The introduction showed the edit mapping pane while the expression bullet showed the wizard step, so neither matched its alt text.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Repoint the last two links to the tutorial this pull request deletes\n\nBoth use the site-relative form, so they weren't caught by the earlier pass that searched for the file path. The redirect resolves the address, but each link is labeled with an article title that no longer exists.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Resolve the pre-review blocking issues\n\nState the password writeback limitation without dates. Learn doesn't allow future product plans, and every occurrence was about when password writeback ships, so each one now describes only what's true today: it isn't available, and Kerberos applications work through passwordless authentication instead.\n\nRebuild the provisioning flow diagram without the Coming September badges, and keep the generator alongside it so the next edit doesn't need pixel work.\n\nReplace blurring with solid color blocks in nine screenshots, as the secure screenshot guidance requires. Crop the review and enable capture to the panel the step is about, which removes the surrounding tenant details and real job identifiers.\n\nSpell out the abbreviations two file names used: how-to-ad-object-enforcement becomes how-to-active-directory-object-enforcement, and the organizational unit image name is written out. Retarget the two existing enforcement redirects at the new name so they don't chain.\n\nRemove a hyphen that made a single instruction look like a list.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Replace blurring in the two remaining flagged screenshots\n\nThe distinguished name and Microsoft Graph captures still used blurring, which the secure screenshot guidance doesn't accept. Cover the SAM account name, security identifier, user principal name, organizational unit path, and the user identifier in the request URL with blocks matching the background.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\n\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Rework the flagged screenshots to meet the redaction guidance\n\nReplace every remaining blurred area with a flat block sampled from the\nsurrounding chrome, and crop the SOA-Policies capture to its callout since\nthe rest of that screenshot was blur. Match the admin center's dark top bar\ninstead of covering the account chip with white, and measure each block\nagainst the actual glyph and control bounds so no letter is half covered and\nno dialog border is cut.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Point cross-references at the Entra ID to Active Directory articles\n\nSeveral links in the Entra ID to AD set resolved to the AD to Entra ID twin,\nwhich sends readers into the opposite provisioning direction:\n\n- Configure and Preserve OU both pointed at custom-attribute-mapping.md\n  instead of custom-attribute-mapping-entra-to-active-directory.md.\n- The directory extensions article listed the AD to Entra ID attribute\n  mapping article in Related content.\n- Object enforcement pointed at the general cloud sync prerequisites rather\n  than the Entra ID to AD prerequisites.\n- Reworded the directory extensions intro so its link to the AD to Entra ID\n  article reads as a cross-direction pointer rather than further reading.\n\nLinks that intentionally cross directions, the shared provisioning agent\nrequirements, and references to the cloud sync product overview are left\nas they were.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Move on-demand provisioning under Configure provisioning to AD\n\nOn-demand provisioning is how you validate a single user or group before\nenabling the job, so it belongs beside Test and enable provisioning rather\nthan as a sibling of the Configure node. Applied to both the task tree and\nthe cloud sync reference tree so the two stay aligned.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Convert the remaining single-bullet prerequisites into sentences\n\nThe pre-review asked for these one-item lists to be removed. The blocking\ninstance was fixed, but the non-blocking ones were reported as done without\nactually being changed. This corrects all three.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* State the correct provisioning direction in the on-demand article intro\n\nThe Active Directory to Microsoft Entra ID article said it covered\nprovisioning from Microsoft Entra ID to Active Directory, then offered the\nsame direction as the alternative, so both halves of the sentence pointed\nreaders away from the article they were already on.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Point to the on-demand article instead of repeating its steps\n\nThe Test and enable article carried an abbreviated copy of the on-demand\nprocedure and then linked to the full one, so readers met the same steps\ntwice. The section now explains why you test on demand and what the results\nshow, and sends readers to the article that documents the procedure for both\nusers and groups. Removed the screenshot that duplicated one already in that\narticle.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Apply copy-edit findings and remove images this pull request orphaned\n\nCopy edit: align the on-demand article intro with its sibling's wording and\nstate the direction consistently, move the post-test pointer above the link\nso the section doesn't end mid-flow, name what the portal message refers to,\nand drop the redundant extend-with-extensions phrasing.\n\nThe eleven deleted images were referenced only by the tutorial this pull\nrequest removes or by the configure article before it was rewritten, so\nnothing points at them anymore.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Replace tenant account data in the on-demand screenshots\n\nThe result cards showed a real test tenant: a user principal name including\nthe tenant's onmicrosoft.com domain, and a group object identifier. Both are\nnow fictitious, using contoso.com and an approved sample object ID, rendered\nin the same face and size so the cards still read as product UI.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n* Remove the settings icon left partly covered in the top bar\n\nThe account chip block began mid-icon on three of the captures, leaving a\nfive to eight pixel sliver of the settings gear. Removed the icon on all\nfive rather than only the three reported, so the set doesn't end up showing\na gear on two captures and none on the others.\n\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: c4c9f8b7-6dbe-4b35-add8-014778a06938\nCopilot-Session: 636f04f7-246d-4c40-ac81-6e0ddd9b2a8f\nCopilot-Session: acef19f5-c154-4e27-936a-d80cb58f71b6\nCopilot-Session: f42d872e-d26f-4e7c-91bc-cdab386b3ed3","sha":"10c83918fad008a4b10314fe2c4e3cb75d73eec7","url":"https://github.com/MicrosoftDocs/entra-docs/commit/10c83918fad008a4b10314fe2c4e3cb75d73eec7"},{"author":"ichristian01","date":"2026-07-31T21:33:18+00:00","message":"Update road-to-the-cloud-introduction.md (#13968)\n\n* Learn Editor: Update road-to-the-cloud-introduction.md\n\n* Learn Editor: Update road-to-the-cloud-introduction.md","sha":"e86cc7358afa62588bea23ef44e673022d589bdb","url":"https://github.com/MicrosoftDocs/entra-docs/commit/e86cc7358afa62588bea23ef44e673022d589bdb"},{"author":"mmacy-msft","date":"2026-07-31T20:41:58+00:00","message":"New multitenant arch guide per Ben Athawes, Ramiro Calderon (#13857)\n\n* New multitenant arch guide per Ben Athawes, Ramiro Calderon\n\n* fix issues 0.1\n\n* fix issues 0.2\n\n* fix issues 0.3\n\n* change request 0.1\n\n* fix issues 0.4\n\n* fix issues 0.5\n\n* change 0.6\n\n* change 0.7\n\n* change 0.8\n\n* change 0.9\n\n* change 1.0\n\n* change 1.1\n\n* Update description of separate tenant architecture (#9)\n\nClarified that the separate tenant architecture decouples collaboration workloads rather than critical workloads from the main workforce tenant.\n\n* Enhance detail on administrative access approaches (#10)\n\nAdded details on administrative access approaches in multitenant architecture.\n\n* Revise single production tenant article for clarity (#11)\n\nUpdated the article to clarify the focus on operating a single production tenant, including workforce identities and external collaboration.\n\n* Apply suggestions from code review\n\nCo-authored-by: bathawes <61694741+bathawes@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: bathawes <61694741+bathawes@users.noreply.github.com>\n\n* Fix invalid file link: Tenant Governance FAQ is faq.yml, not faq.md\n\nResolves the Learn build warning 'file-not-found' at line 66 of\ndocs/architecture/multitenant-architecture-guide.md.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: fc4d71de-b3ea-423a-91d5-40c82cc22dd1\n\n* Apply suggestions from code review\n\nApplies the 33 suggested changes from Ben Athawes's review\n(pullrequestreview-4796399609) across the seven tenant estate\nguidance articles:\n\n- Rename the \"Separate tenants for ...\" pattern references to\n  \"Isolated tenants for ...\" throughout the series.\n- Broaden the intended audience in the guide intro.\n- Add a \"When to integrate an app or workload with an existing tenant\"\n  section to the guide, with a pointer to it from the baseline article.\n- Link parallel-identity-options.md from the guide body and Related content.\n- Retitle \"People who shape architecture decisions\" to\n  \"People whose needs shape tenant architecture\".\n- Consolidate the cross-tenant topology diagrams in\n  multitenant-organization.md to a single application-hub diagram and\n  defer to the canonical topologies article.\n- Fix the broken in-article reference to the B2B limitations section.\n\nTwo single-line suggestions on multitenant-organization.md lines 30 and 32\nare superseded by the later lines 30-48 rewrite and were not applied\nseparately.\n\nCo-authored-by: Ben Athawes <bathawes@users.noreply.github.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 161e45b8-d1b4-4739-a5f0-4565ce997925\n\n* Add ai-usage metadata to the tenant estate guidance articles\n\nThe seven articles were edited with AI assistance, so they carry\nai-usage: ai-assisted. Placement follows the repo convention of\ndeclaring ai-usage after ms.date.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 161e45b8-d1b4-4739-a5f0-4565ce997925\n\n* Apply suggestions from code review\n\nCo-authored-by: bathawes <61694741+bathawes@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: bathawes <61694741+bathawes@users.noreply.github.com>\n\n* Rename multitenant-* articles to tenant-estate-* and fix TOC labels (#14)\n\nRename the 7 net-new tenant estate articles so their URL slugs reflect the\ntenant estate terminology (slug = file name), update all internal\ncross-article links, and correct the TOC node/group labels.\n\n- multitenant-architecture-guide -> tenant-estate-guide\n- multitenant-single-production -> tenant-estate-primary\n- multitenant-organization -> tenant-estate-collaborating\n- multitenant-nonproduction-environment -> tenant-estate-nonproduction\n- multitenant-critical-production -> tenant-estate-critical-production\n- multitenant-business-partner-access -> tenant-estate-business-partner\n- multitenant-hybrid-identity-isolation -> tenant-estate-hybrid-identity\n\nTOC: parent group -> \"Microsoft Entra tenant estate guidance\";\n\"Single production tenants\" -> \"Primary production tenants\";\n\"Multitenant organizations\" -> \"Collaborating production tenants\".\n\nNo redirects needed (all files are net-new/unpublished).\n\nCo-authored-by: bathawes <bathawes@users.noreply.github.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: 5c5a15dd-b13b-4111-93d6-fb00ee45fd66\n\n* Apply suggestions from code review\n\nCo-authored-by: Marsh Macy <253514592+mmacy-msft@users.noreply.github.com>\n\n* Apply suggestions from code review\n\nCo-authored-by: Marsh Macy <253514592+mmacy-msft@users.noreply.github.com>\n\n* Apply suggestion from @mmacy-msft\n\n---------\n\nCo-authored-by: Lynne O'Connor <103511101+lynneoconnor@users.noreply.github.com>\nCo-authored-by: bathawes <61694741+bathawes@users.noreply.github.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Ben Athawes <bathawes@users.noreply.github.com>\nCopilot-Session: fc4d71de-b3ea-423a-91d5-40c82cc22dd1\nCopilot-Session: 161e45b8-d1b4-4739-a5f0-4565ce997925\nCopilot-Session: 5c5a15dd-b13b-4111-93d6-fb00ee45fd66","sha":"7eb64a786de183ec4cb0483b41187ac879813984","url":"https://github.com/MicrosoftDocs/entra-docs/commit/7eb64a786de183ec4cb0483b41187ac879813984"},{"author":"idMdev","date":"2026-07-29T19:05:52+00:00","message":"Update how-to-universal-tenant-restrictions.md (#13959)\n\n* Update how-to-universal-tenant-restrictions.md\n\n* Update GSA PoC internet access documentation\n\nRemoved validation step for Universal Tenant Restrictions from the documentation.","sha":"b7b4e3606e4e8b755d5c485d73d62361288237de","url":"https://github.com/MicrosoftDocs/entra-docs/commit/b7b4e3606e4e8b755d5c485d73d62361288237de"},{"author":"idMdev","date":"2026-07-21T07:23:09+00:00","message":"Revise tenant restrictions documentation for clarity (#13885)\n\n* Revise tenant restrictions documentation for clarity\n\nUpdated sections on tenant restrictions, including enforcement points and validation steps. Modified headings and clarified details regarding Microsoft Entra ID and Microsoft Graph.\n\n* Update links and terminology for tenant restrictions","sha":"5c361264b31884588743680d98c57b612ebe62f3","url":"https://github.com/MicrosoftDocs/entra-docs/commit/5c361264b31884588743680d98c57b612ebe62f3"},{"author":"kenwith","date":"2026-07-01T22:48:15+00:00","message":"Redirect Entra group licensing UI docs to Microsoft 365 (#13731)\n\n* Redirect Entra group licensing UI docs to Microsoft 365\n\nAB#593418 AB#592863\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Add preserve-view to Microsoft 365 licensing links\n\nAB#593418 AB#592863\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Flatten users troubleshooting TOC entries\n\nAB#593418 AB#592863\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"ee4e287dab1def2a6212f0bdc83e1d2b2fea1d9b","url":"https://github.com/MicrosoftDocs/entra-docs/commit/ee4e287dab1def2a6212f0bdc83e1d2b2fea1d9b"},{"author":"rolyon","date":"2026-06-27T22:52:01+00:00","message":"step-up MFA using authentication context","sha":"337c7a9a03538a58f8aac93f7696ec76d4a26be5","url":"https://github.com/MicrosoftDocs/entra-docs/commit/337c7a9a03538a58f8aac93f7696ec76d4a26be5"},{"author":"rolyon","date":"2026-06-27T21:56:28+00:00","message":"Update Sign-up protection section with partner solutions","sha":"b97c58b4ba4f3f9e8822cf61646cf336782e3d39","url":"https://github.com/MicrosoftDocs/entra-docs/commit/b97c58b4ba4f3f9e8822cf61646cf336782e3d39"},{"author":"lynneoconnor","date":"2026-06-26T19:43:09+00:00","message":"new and updated articles per Ben Athawes (ADO 28575) (#13644)\n\n* new and updated articles per Ben Athawes (ADO 28575)\n\n* add files\n\n* fix issue 0.01","sha":"572a585809c1b6f1c66792dc7e79a7c52cdddb43","url":"https://github.com/MicrosoftDocs/entra-docs/commit/572a585809c1b6f1c66792dc7e79a7c52cdddb43"},{"author":"kenwith","date":"2026-06-24T18:49:58+00:00","message":"Add security operations for network access guide (#13531)\n\n* Add GSA security operations guide\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Fix GSA SecOps validation feedback\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Add GSA SecOps metadata reviewer\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Improve GSA SecOps article clarity\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Add architecture TOC pointer for GSA SecOps guide\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Rename GSA SecOps guide for network access\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Move GSA SecOps acronym table to end\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Revert \"Move GSA SecOps acronym table to end\"\n\nThis reverts commit 5970e1d59edba962320b95cf79bae3b1147cc451.\n\n* Spell out Global Secure Access in SecOps guide\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Incorporate Global Secure Access SecOps feedback\n\nUpdates the SecOps guide from Thomas Detzner's engineering feedback commits:\n\n- 6a4b566 Replace traffic-based new source IP rule with RN config-change hunting summary\n\n- 5574096 Restructure remote-network config-change detection proposal\n\n- 42f2407 Fix Private Access SecOps detections\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Update SecOps what to look for links\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"a66e48ddae70d8787e2c1c0876fc96c5fff10963","url":"https://github.com/MicrosoftDocs/entra-docs/commit/a66e48ddae70d8787e2c1c0876fc96c5fff10963"},{"author":"shlipsey3","date":"2026-06-23T21:35:19+00:00","message":"yml-conversion1-061926 (#13583)\n\n* yml-conversion1-061926\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n* Remove circular redirect for how-to-manage-groups.yml\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"bd700e840f49d4b2e406530d6640e3880f0c3b50","url":"https://github.com/MicrosoftDocs/entra-docs/commit/bd700e840f49d4b2e406530d6640e3880f0c3b50"},{"author":"ShawnKupfer","date":"2026-06-15T16:45:39+00:00","message":"[BULK UPDATE] User Story 573314: Ensure every doc in MSec repos has an author from MSec Docs (entra-docs-pr 1) (#13305)\n\n* [BULK UPDATE] User Story 573314: Ensure every doc in MSec repos has an author from MSec Docs (entra-docs-pr 1)\n\n* Fix duplicate reviewer\n\n* Remove from individual files","sha":"fcc5c73aed5dc4dec675d62ce9a4f6ba99b6311d","url":"https://github.com/MicrosoftDocs/entra-docs/commit/fcc5c73aed5dc4dec675d62ce9a4f6ba99b6311d"},{"author":"prmerger-automator","date":"2026-06-04T03:21:19+00:00","message":"Merge pull request #13379 from kenwith/kenwith/ado-582534-fix-ca-link\n\nFix broken 'What is Conditional Access?' link in ID Protection analyze guide","sha":"c65def89cda8cf8716c65eac6597524ccb3ceca3","url":"https://github.com/MicrosoftDocs/entra-docs/commit/c65def89cda8cf8716c65eac6597524ccb3ceca3"},{"author":"kenwith","date":"2026-06-04T02:44:01+00:00","message":"Fix product name: 'Azure AD FS' -> 'AD FS'\n\nThe hybrid authentication components list referred to 'Active Directory Federation Services (Azure AD FS)'. The correct product name is 'Active Directory Federation Services (AD FS)' \u2014 there is no 'Azure AD FS'. The same article already uses '(AD FS)' correctly elsewhere (line 82).\n\nAddresses AI-suggested content update entra-docs #12953 / ADO 582524.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"f5b4c1b9f6240f6143375cf3b1b4047d8f92a49a","url":"https://github.com/MicrosoftDocs/entra-docs/commit/f5b4c1b9f6240f6143375cf3b1b4047d8f92a49a"},{"author":"kenwith","date":"2026-06-04T02:34:57+00:00","message":"Fix broken 'What is Conditional Access?' link\n\nThe link pointed to /azure/data-explorer/security-conditional-access (an Azure Data Explorer path) instead of the Conditional Access overview. Repointed to the Conditional Access overview article via a relative repo link.\n\nAddresses AI-suggested content update entra-docs #12772 / ADO 582534.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>","sha":"825b367d0d63368be07f842788e8445aa7e5cda5","url":"https://github.com/MicrosoftDocs/entra-docs/commit/825b367d0d63368be07f842788e8445aa7e5cda5"}]
