The article updates navigation and steps for email notifications, server or service deletion, and role-based access control, with new screenshots.
Passkeys become default as SMS retirement and Graph permission changes reshape Entra
September’s most consequential Entra changes affected authentication and application permissions. Passkeys became the default Microsoft Entra authentication method on September 1, while Microsoft-provided SMS and voice authentication received staged 2027 retirement dates. Microsoft Graph also narrowed User.ReadBasic.All, removing access to user app role assignments and license details. Other notable developments included External ID browser-based federation, a guided Connect-to-Cloud Sync migration workflow, and preview evaluation behavior in Global Secure Access Web Filtering v2.
- Microsoft-provided SMS and voice authentication receive staged 2027 retirement dates
Entra ID · Authentication
Microsoft Entra made passkeys the default authentication method on September 1, 2026. Microsoft-provided SMS and voice authentication retire February 1, 2027, for users including internal guests; Global Administrators and external users have a July 1, 2027 deadline. After the applicable date, users whose only MFA method is SMS or voice receive a blocking passkey-registration prompt. Administrators should move affected users to phishing-resistant methods or use a customer-managed telecom provider where needed.
- User.ReadBasic.All loses access to app role assignments and license details
Entra ID · Microsoft identity platform
Starting in mid-September 2026, applications using User.ReadBasic.All no longer receive user app role assignments or license details. Applications that require this data must use User.Read.All or LicenseAssignment.Read.All instead to avoid disruption.
- External ID adds system-browser handoff for brokered identity-provider sign-in
External ID · Authentication
Microsoft Entra can hand external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and identity providers that block WebViews. Administrators must check the documented browser, broker, app-version, platform, federation-protocol, and cloud combinations before adoption.
- Connect 2.6.90.0 adds a guided Cloud Sync migration workflow
Entra ID · General
The 2.6.90.0 release documents a guided path covering configuration assessment, provisioning-agent setup, staged activation, and validation; the workflow is limited to the Azure public cloud. Administrators using recalled version 2.6.79.0 should uninstall it and install 2.6.90.0, while upgrades involving an existing ADSync database should use 2.6.90.0 or later.
- Global Secure Access Web Filtering v2 defines preview Continue Evaluation behavior
Internet Access · Fundamentals
With the preview Continue Evaluation action, unmatched traffic can pass to the next applicable security profile. Matching rules and Allow or Block stop evaluation, and the Baseline Profile must use Allow or Block. Administrators should review default actions when migrating policies or managing overlapping profiles.
Identify users dependent on Microsoft-provided SMS or voice authentication and move them to phishing-resistant methods before their applicable deadline, or use a customer-managed telecom provider where those methods must remain available. Inventory applications that rely on User.ReadBasic.All for app role assignments or license details and grant the replacement permissions where necessary. For the newer capabilities, verify External ID platform and broker prerequisites, account for the Azure public cloud limitation on the Connect migration workflow, and review Web Filtering default actions when composing or migrating profiles.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
176 updates by product
Microsoft Entra ID
119 updatesConnect Health Adfs
Doc updateThe documentation now describes the AD FS service overview, updated alert filtering and details, and the revised Usage Analytics experience with time-range controls. Screenshots and metadata were also refreshed.
Connect Health Data Retrieval
Doc updateThe guide now uses the Microsoft Entra Connect Health Sync errors area to access notification settings, review Global Administrator and custom recipients, and export recorded sync errors as a CSV from the command bar.
The page now explains selecting an alert row to view its details, including detection times, affected servers, resolution guidance, and related documentation. It also replaces the alert screenshot and improves image descriptions.
Connect Version History
Feature updateThe documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.
Connect Version History
New featureAction requiredThe 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.
Connect Version History
Doc updateThe entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.
Connect Version History
Doc updateThe version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.
Connect Version History
Doc updateAction requiredThe documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.
Connect Version History
Doc updateAction requiredThe documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.
Connect Version History
Doc updateThe documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.
Connect Version History
Doc updateFour references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.
Connect Version History
Feature updateThe documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.
Connect Version History
Doc updateAction requiredThe documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.
Connect Version History
Doc updateThe documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.
Using single sign-on with cloud sync
Doc updateThe article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.
Migrate Microsoft Entra Enterprise State Roaming
RetirementAction requiredAs of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.
Validate Oidc Multitenant App Gallery
Doc updateAction requiredThe documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.
Configure
Doc updateThe configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.
Use My Staff to delegate user management
RetirementMy Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.
Licensing Service Plan Reference
Doc updateSeveral licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.
Licensing Service Plan Reference
Doc updateSeveral entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.
My Staff Configure
Doc updateThe page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.
Whats New
New featureThe June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.
Delegate By Task
Feature updateThe documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.
Permissions Reference
Doc updateThe permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.
Least privileged roles by task
New featureThe task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.
Publish App Gallery
Doc updateThe documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.
V2 Howto App Gallery Listing
Doc updateThe app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.
V2 Howto App Gallery Listing
Doc updateThe app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.
Validate Oidc Multitenant App Gallery
Doc updateThe article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
Connect Install Roadmap
Doc updateThe roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
Validate Oidc Multitenant App Gallery
Doc updateThe documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.
Sspr Policy
Doc updateThe SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
RetirementAction requiredMicrosoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.
Sms Voice Retirement
RetirementAction requiredThe documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.
A how-to article explains how to enable FIDO2 and passkey methods, register credentials, configure a registry setting, and sign in to Microsoft Entra Connect Sync without a password.
The procedure now uses revised Microsoft Entra Connect paths and module-import commands, including the ADSync module and the AzureADSSO module. Step numbering and wording were also updated.
Howto Sspr Windows
Doc updateThe instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.
Connect Version History
Doc updateThe Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.
Authentication
Doc updateThe authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.
Connect Passwordless Authentication
Doc updateThe documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.
The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.
Connect Version History
Doc updateAction requiredThe documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.
Connect Version History
Doc updateThe version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.
Connect Version History
Doc updateThe version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.
Connect Version History
Doc updateThe Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.
The documentation now distinguishes Microsoft-managed and enabled campaigns. It specifies the MFA method required for each targeted authentication method and broadens eligible users from SMS or voice sign-ins to users signing in with any MFA method.
Authentication Qr Code
Doc updateThe QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.
Fido2 Compatibility
Doc updateThe table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.
The documentation now explains how supported audit events can include DUSI, maps linkable identifiers to audit-log attributes, and provides steps for correlating sign-ins with administrative activity. Some events may not include DUSI.
Sspr Writeback
Doc updateThe documentation now states that when Cloud Sync and Connect Sync are configured for the same domain, Cloud Sync processes password writeback for users synchronized from that domain.
The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
Permissions Reference
Doc updateThe permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.
Permissions Reference
Doc updateThe role description now states that Security Administrators can perform identity containment actions during security incidents.
Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.
The page title and heading no longer include “(preview).”
Test-only PFX password
Doc updateThe documented password example now includes an exclamation mark at the end.
A new article explains how to diagnose intermittent STATUS_ACCOUNT_DISABLED sign-in and unlock errors on Microsoft Entra hybrid joined Windows devices, including relevant event logs and the stale-cache and connectivity conditions that can cause them.
The documentation now states that Microsoft-managed system-preferred authentication deployment will continue through September 2026, rather than August 2026.
Microsoft Entra improves the iOS Microsoft Authenticator app's passkey restore experience with a clearer, guided flow for device migration, launching worldwide mid-September 2026. It affects iOS users with iCloud backup, requires no action, and includes updated user guidance without policy changes.
The article now documents configuring a SCIM endpoint that uses an OAuth2 client-credentials grant from a non-Entra issuer, including the token endpoint, client credentials, credential placement, and scopes.
Validate User Provisioning App Gallery
Doc updateThe documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.
Validate Saml Single Sign On App Gallery
Doc updateThe documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.
Validate Saml Single Sign On App Gallery
Doc updateThe article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.
Entra Id Scim Api Reference
Feature updateThe reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.
Enable Scim Api
Doc updateThe permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.
Entra Id Scim Api Reference
Feature updateAction requiredThe reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.
Enable Scim Api
Doc updateThe permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.
Entra Id Scim Api Schema Documentation
New featureThe schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.
Entra Id Scim Api Reference
Doc updateThe SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.
A new how-to explains registering an MCP server as an OAuth 2.0 protected resource, enabling v2 access tokens, and connecting MCP clients through Microsoft Entra Agent ID.
Publish App Gallery
Doc updateThe app gallery publishing documentation now refers to the required identifier as a Partner One ID and notes that it was formerly called the Microsoft Partner Network (MPN) ID.
Validate Saml Single Sign On App Gallery
Doc updateThe SAML App Gallery validation article adds lightbox support to screenshots and a Next step link to the validation-results section.
Validate Saml Single Sign On App Gallery
Doc updateThe documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”
Microsoft added documentation for using the guided migration tool to assess an environment, create Cloud Sync configurations, run a preactivation check, and validate synchronization after migration.
Connect Version History
Feature updateAction requiredMicrosoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.
Connect Version History
Doc updateThe version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.
Whatis Azure Ad Connect
Doc updateThe page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.
Connect Version History
Doc updateThe documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.
Clear attribute values (Preview)
Feature updateThe documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.
The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.
The documentation now explains how optional single-valued source attributes can clear mapped target attributes when SAP SuccessFactors returns null or empty values.
Hibob To Active Directory User Provisioning Tutorial
Feature updateAction requiredThe tutorial now requires Microsoft Entra ID P1, P2, or Governance licenses for every identity sourced through API-driven provisioning.
Validate User Provisioning App Gallery
Doc updateThe documentation and screenshot alt text now refer to the field as “Submission ID” instead of “submission request ID.”
New documentation explains how HiBob can provision and update users in on-premises Active Directory through Microsoft Entra API-driven provisioning and the provisioning agent. It covers prerequisites, permissions, configuration, and synchronization flow.
Validate User Provisioning App Gallery
Doc updateThe user provisioning validation guide now uses an updated Microsoft Entra admin center URL with additional parameters.
The Risky IP report
RetirementThe documentation now notes that the AD FS Risky IP report is being deprecated and links to the Risky IP report workbook. It also updates portal navigation, export handling, notification settings, and threshold guidance.
The guide now documents the updated service overview, alert details and search, domain controller filtering and column options, replication error details, and 24-hour authentication performance charts.
The page now reflects the Sync services overview, updated alert and monitoring workflows, revised settings instructions, and expanded sync-error filtering, details, and CSV export guidance.
Sla Performance
Doc updateThe August row on the SLA performance reference page now shows 99.999% in the previously blank final metric column.
Policy Teams Devices Device Code Flow
Doc updateAction requiredThe instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.
Policy Teams Devices Device Code Flow
Doc updateThe guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.
Privileged Roles Permissions
Doc updateThe documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.
The article now documents the guided workflow for duplicate-attribute errors, including finding affected objects, opening Error Details, using Troubleshoot, reviewing proposed resolutions, and applying supported fixes. Status descriptions and diagnostic images were also updated.
Tshoot Connect Sso
Doc updateThe procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.
The documentation now explains how to configure attribute value clearing, fallback values, or ignored values when HR applications return null or empty attributes during provisioning.
Hr User Update Issues
Doc updateThe documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.
The troubleshooting guidance for SEC_E_NO_AUTHENTICATING_AUTHORITY now links to Windows Server 2025 build 26100.6905 information.
Troubleshoot Primary Refresh Token
Doc updateThe troubleshooting guide now uses `-vAuth` instead of `-v` when starting `Start-auth.ps1`.
The hybrid join troubleshooting page was updated with revised guidance for AADSTS50034, and its date changed from July 27, 2025, to September 1, 2026.
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide starting February 1, 2027, to enhance security. Organizations must identify affected users, migrate them to phishing-resistant methods like passkeys, and update policies to avoid sign-in disruptions and comply with new requirements.
Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.
Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.
Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out in phases from October 2026 to February 2027, aims to increase adoption of phishing-resistant sign-in.
Connect Version History
Doc updateAction requiredThe version history entry now links readers to the latest available Microsoft Entra Connect Sync version.
The Windows token protection guide now refers to Microsoft Copilot instead of Microsoft 365 Copilot.
Credential Management Api
Doc updateThe Microsoft Entra External ID credential management API reference was deleted. It previously documented how applications let signed-in customers list, register, and delete passkeys.
Starting late September 2026, Microsoft Viva Engage will require Microsoft Entra permissions—Yammer Administrator role or Community Admin assignment—for community and membership management tasks previously allowed to Verified or Network Admins. Administrators should review and update role assignments accordingly.
End-user experiences for applications
RetirementThe documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.
Publish App Gallery
Doc updateThe app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.
Prerequisites to validate and publish your app
Feature updateAction requiredThe documentation now instructs app publishers to provide a Partner One ID associated with their Microsoft AI Cloud Partner Program organization and explains how to find help if they do not know it.
Account discovery now covers users and groups, classifying them as local, unassigned, or assigned identities. Group discovery is identified as being in preview, and correlation requires a direct matching attribute.
The documentation now explains how Entitlement Management integrates with ServiceNow for access package requests, request history, and approvals. It covers licensing, installation, configuration, and user workflows.
User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a security issue. Applications needing this data must switch to User.Read.All or LicenseAssignment.Read.All permissions and update accordingly to avoid disruptions.
Sample V2 Code
Doc updateThe Node.js Express and web application entries in the sample code documentation were updated, including their linked sample resources.
Tenant Estate Primary
Doc updateThe tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”
Connect Install Roadmap
Doc updateThe page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.
Microsoft Entra Agent ID
3 updatesPermissions Reference
Doc updateThe AI Administrator and AI Reader descriptions were updated from “Microsoft 365 Copilot” to “Microsoft Copilot.” Their role IDs remain unchanged.
Agent Owners Sponsors Managers
Doc updateSponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.
Manage Agent Identities End User
Doc updateThe documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.
Microsoft Entra ID Protection
1 updateHowto Export Risk Data
Doc updateThe page now distinguishes diagnostic setting categories from KQL table names and maps six ID Protection signals to their corresponding AAD-prefixed Log Analytics tables.
Microsoft Entra ID Governance
13 updatesThe documentation adds access package drift reporting for groups and enterprise applications, including detection, remediation, export, roles, licensing, refresh timing, and limitations. The reports are in preview.
Extend Application Attributes
Doc updateThe documentation now uses clearer wording for configuring LCW extensibility workflow mappings, creating an Azure Logic App and workflow, and configuring provisioning jobs with attribute mappings.
Licensing
Doc updateThe Tenant Governance licensing page now links to Microsoft Agent 365 licensing FAQs and guidance for using governance relationships with Microsoft Defender.
The access package creation documentation now explains that the search box can find matching SharePoint Online roles that are not initially displayed, especially on sites with many roles.
The documentation now recommends using the search box to find SharePoint Online roles when adding them to an access package. Search returns matching roles even when they are not initially displayed.
Licensing
Doc updateThe licensing documentation’s Microsoft author alias was updated from `tafra00` to `tazkiaafra`.
The documentation now specifies that existing guest users can be directly assigned, but external users who are not yet in the directory cannot be invited through direct assignment when access is limited to administrator direct assignments.
Apps
Doc updateThe HR integrations table now includes a link for HiBob to Microsoft Entra ID/Active Directory and updates the Rippling provisioning link text.
Pim How To Use Audit Log
Doc updateThe documentation explains that related PIM activation and deactivation events can have different CorrelationId values. It recommends using roleAssignmentRequestId to trace a complete request and adds Log Analytics query examples.
Entitlement Management Request Behalf
Doc updateThe documentation now directs administrators to the **Who can request access** section on the **Requests** tab, where selecting **Manager** enables managers to request access packages for employees.
The overview describes access drift, account discovery, access package drift detection, and enforcement and remediation approaches for aligning resource access with governance policies.
The licensing fundamentals page was updated to align the Account Discovery section and state that the feature requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite.
Licensing
Doc updateThe page now lists the Microsoft Agent 365 Licensing FAQs and governance relationships links without the previous section heading and introductory text.
Microsoft Entra External ID
15 updatesMicrosoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.
Apple Federation Customers
Doc updateThe article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.
Add an identity provider to a user flow
Doc updateA single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.
Entra Id Federation Customers
Doc updateThe article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.
Custom Oidc Federation Customers
Doc updateThe article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.
Facebook Federation Customers
Doc updateThe article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.
Google Federation Customers
Doc updateThe article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.
Sign In With Passkey
Feature updateThe documentation no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and states that low-privilege passkey credential management APIs are on the roadmap.
Microsoft Accounts Federation Customers
Doc updateThe article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.
Direct Federation
Doc updateThe External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.
Saml Ws Federation Self Service Sign Up
Doc updateThe standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.
Manage User Profile Info
Doc updateThe user profile information documentation no longer includes guidance that users can use My Apps preview features or that administrators can access My Staff.
Manage User Profile Info
Doc updateThe user profile information guidance no longer includes the “Manage user feature settings” reference.
Set up B2B direct connect
Doc updateThe documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.
Set up Microsoft Entra Verified ID
Doc updateThe new article explains how to use Quick setup, register applications, create credentials, and issue and verify credentials in a Microsoft Entra External ID tenant. It documents prerequisites and limits, including custom-domain requirements, shared signing keys, two requests per second per tenant, and six-month credential validity.
Microsoft Entra Internet Access
4 updatesThe documentation removes “preview” from the source traffic type and HTTP method request filtering conditions, updates their headings and links, and refreshes the page date.
Microsoft Purview DLP integrates with Entra Global Secure Access Internet Access to filter sensitive files at the network layer, preventing data leaks to unmanaged cloud apps. Public preview starts mid-November 2025; general availability by October 2026. Admins must configure policies, TLS inspection, and activate Purview pay-as-you-go.
Web filtering in Global Secure Access (V2)
New featureThe documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.
The Internet Access health-signal article now lists licensing, roles, Microsoft Graph permissions, and log access requirements. It also adds steps for investigating alerts and reviewing filtering and forwarding policies.
Microsoft Entra Private Access
1 updateHow to investigate private application access requiring Microsoft Entra Private Access connector
Feature updateThe documentation now requires a non-trial Microsoft Entra P1 or P2 license plus at least 100 monthly active users to view alerts and receive notifications. It also clarifies Private Access licensing, least-privilege roles, Graph permissions, and expanded signal and alert investigation guidance.
Microsoft Entra Workload ID
5 updatesConfigure Managed Identities Assignment Restriction
Doc updateAction requiredThe documentation now clarifies that Azure CLI commands and IaC templates must use the provider namespace Microsoft.Storage, while Microsoft.Storage/* is only an Azure portal display convention.
Managed Identities Assignment Restriction
Doc updateAction requiredThe documentation now clarifies that Azure CLI commands and IaC templates must use Microsoft.Storage. The Microsoft.Storage/* format shown in the portal is only a display convention and is not accepted by the API.
Managed Identities Faq
Feature updateThe documentation now states that creating a managed identity is blocked when the resulting directory usage reaches or exceeds 98% of the tenant quota. This applies to new or recreated service principals; existing identities and assignments continue to work.
The article now provides explicit prerequisites, required Microsoft Entra and SAP permissions, SAP IAS OIDC and JWT Trust-by-Issuer configuration details, and a clearer token flow and revocation explanation.
What Is Entra
Doc updateThe Entra documentation now uses the singular verb “needs” for “GitHub Actions” in an example about workload identities accessing Azure subscriptions.
Microsoft Entra Global Secure Access
14 updatesThe documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.
The page title now marks custom headers as preview and notes that rollout is expected to complete by September 10, 2026.
Configure Custom Headers
Doc updateConsistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.
Transport Layer Security
Doc updateThe TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.
Configure TLS inspection with a Microsoft-managed certificate
New featureAction requiredThe guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.
The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.
The AI prompt injection protection documentation now explains that TLS inspection can use either a Microsoft-managed certificate or an administrator-provided certificate before configuring TLS inspection policies.
Learn about Universal Continuous Evaluation
Feature updateThe documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.
Generative Ai Insights
Doc updateThe documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”
The documentation now provides separate links for configuring TLS inspection with a Microsoft-managed certificate and with your own certificate.
The article now distinguishes tunnel and BGP connectivity scenarios and adds investigation steps, licensing requirements, least-privilege roles, and Microsoft Graph permissions for viewing and managing signals and alerts.
Troubleshoot Transport Layer Security
Doc updateThe troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.
Troubleshoot App Access
Doc updateThe app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.
Security Copilot + Entra
1 updateSecure Generative Ai
Doc updateThe guidance now labels the link “Microsoft Copilot requirements” instead of “Microsoft 365 Copilot requirements.”
