What changed on this day
13 changes were tracked across 4 Microsoft Entra products. The leading updates include Microsoft Entra: Passkeys in registration campaigns update; Plan Your Migration From B2c To External Id; Migrate From B2c To External Id.
Daily.Entra.News13 changes were tracked across 4 Microsoft Entra products. The leading updates include Microsoft Entra: Passkeys in registration campaigns update; Plan Your Migration From B2c To External Id; Migrate From B2c To External Id.
Learn how authentication transfer connects users to apps across desktop and mobile devices, including supported apps, end-user experience, limitations, and troubleshooting.
Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled for text message and voice call users |
Microsoft Entra will continue supporting Passkeys (FIDO2) in Enabled and Microsoft-managed states for Registration Campaigns, rolling out worldwide from mid-May to late June 2026. Eligible tenants will see automatic updates to campaign settings and passkey registration nudges after MFA, with no immediate action required.
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
Learn how to configure single sign-on between Microsoft Entra ID and STACKIT Cloud.
- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forms & Workflow.
Microsoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.
Now that you have provided the connectivity details and matching attribute as part of your provisioning configuration, Microsoft Entra can discover the existing users in your application. Click on the [discover identities](~/identity/app-provisioning/how-to-account-discovery.md) button in the provisioning overview page. Once the report is generated, you will have a view of all the users in your application, which users in the application match with a Microsoft Entra ID user, which users are already assigned to the enterprise application in Microsoft Entra ID, and which users in the application are not matched with a Microsoft Entra ID user).
1. If your scenario requires the ability to override a separation of duties check, then you can also [set up additional access packages for those override scenarios](entitlement-management-access-package-incompatible.md#configuring-multiple-access-packages-for-override-scenarios).
- Authentication context or step-up authentication.
> [!NOTE]