MondayMon
TuesdayTue
WednesdayWed
ThursdayThu
FridayFri
SaturdaySat
SundaySun
222324252627282930121Entra ID34567891011121314151Workload ID1617181Entra ID1920212223241Entra ID2526272829303112
Month in brief

May 2024: Workload ID key disablement creates an urgent June deadline, alongside passkey, PIM, and Dataverse changes

The supplied May record is announcement-led: four Microsoft 365 Message Center notices, with no supplied documentation additions, updates, or removals. The most consequential change is the required replacement of symmetric keys for Microsoft Entra first-party application service principals. Other notices cover a staged passkey-related behavior improvement, general availability of Entra PIM role management for Dynamics 365 Apps and Power Platform, and a Dataverse cleanup capability entering public preview.

  • Symmetric keys for first-party service principals will be disabledWorkload ID

    Microsoft announced a security-related behavior change for Microsoft Entra first-party application service principals. Organizations must switch from symmetric to asymmetric keys by June 15, 2024, to avoid authentication failures.

  • Authentication-strength improvements begin supporting device-stored passkeysEntra ID

    Microsoft Entra ID is rolling out new authentication-strength support for passkeys stored on devices. Users will see additional registration options in My Security Info as the rollout proceeds from mid-May through early August 2024. No preparation is required, though administrators may update relevant documentation.

  • Entra PIM role management for Dynamics 365 and Power Platform reaches general availabilityEntra ID

    Beginning May 23, administrators can use Microsoft Entra Privileged Identity Management to assign Dynamics 365 Apps and Power Platform tenant admin roles for a defined period. The announcement does not identify additional prerequisites, migration work, or configuration changes.

  • Dataverse user cleanup enters public previewEntra ID / Dataverse

    Beginning May 1, the preview provides the ability to delete disabled-status users from Dataverse environments, including delete stubs, unlicensed users, and users removed from Microsoft Entra groups. Microsoft cites privacy and regulatory requirements and storage reduction as intended benefits; the supplied evidence does not make deletion mandatory or specify eligibility and configuration details.

For Entra administrators

Organizations using symmetric keys for Microsoft Entra first-party application service principals must replace them with asymmetric keys by June 15, 2024, or risk authentication failures. No preparation is required for the passkey rollout, although relevant user documentation may need updating. PIM is available for time-bounded tenant admin roles, while the Dataverse cleanup capability is preview functionality and is not described as mandatory.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

4 updates by product

Fundamentals

1

Dynamics 365 Apps – Public Preview of delete stub, unlicensed and removed Microsoft Entra group users from Dataverse

New

We are announcing the Public Preview of delete stub, unlicensed and removed Microsoft Entra group users from Dataverse environments. Launching May 1, 2024, this feature will provide you with the ability to delete users with a disabled status in your Dataverse environment, offering greater flexibility in adhering to privacy laws and regulatory requirements, and to free up storage space.

2 May 2024
Message CenterMC789466 on mc.merill.net ↗Stay informed

Monitoring

1

Troubleshooting

1

Authentication

1