← Previous day

Next day →
Day in brief

First-method passkey registration rolls out from October 2026 through February 2027

The period’s consequential item is a Microsoft Entra rollout announcement: users will be able to register a passkey or passwordless sign-in as their first multifactor authentication method, without setting up weaker methods first. The remaining changes are documentation clarifications covering Agent ID token exchange, a Microsoft Graph permission prerequisite, account discovery limits, workload identity guidance links, and PAC-file syntax. No new or removed documentation items are recorded, and the evidence does not establish a separate preview, general-availability, or retirement event.

  • The Message Center announcement says users can register a passkey or passwordless sign-in as their first multifactor authentication method, eliminating the need to configure weaker methods first. Rollout is stated for October 2026 through February 2027, with no administrator action required.

  • Updated Agent ID on-behalf-of guidance says Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated against the blueprint and child agent identity. It also clarifies that agent identities cannot use interactive consent and that delegated permissions must be preauthorized through inheritable blueprint permissions. This is a documentation clarification with concrete configuration implications.

  • The passkey and Microsoft-provided SMS and voice authentication page now states that opting out through Microsoft Graph requires Policy.ReadWrite.AuthenticationMethod. The supplied evidence supports this as a documentation prerequisite clarification, not a new retirement date or separately documented API behavior change.

  • The account discovery article now uses lowercase “account discovery” and clarifies connector requirements, direct attribute matching, SCIM support, unsupported scenarios, the GitHub reference, and the expectation that reports take at least 30 minutes. It continues to describe the existing process; no launch or required action is indicated.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

8 updates

1
1

Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

New

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.

Message CenterMC1450133 on mc.merill.net ↗Stay informed
1

Discover identities in target applications with account discovery

Updated

The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.

2

Agent On Behalf Of Oauth Flow

Updated

The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.

Agent On Behalf Of Oauth Flow

Updated

The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.

1

Custom Proxy File Hosting

Updated

The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.

2
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…