We are announcing the Public Preview of delete stub, unlicensed and removed Microsoft Entra group users from Dataverse environments. Launching May 1, 2024, this feature will provide you with the ability to delete users with a disabled status in your Dataverse environment, offering greater flexibility in adhering to privacy laws and regulatory requirements, and to free up storage space.
May 2024: Workload ID key disablement creates an urgent June deadline, alongside passkey, PIM, and Dataverse changes
The supplied May record is announcement-led: four Microsoft 365 Message Center notices, with no supplied documentation additions, updates, or removals. The most consequential change is the required replacement of symmetric keys for Microsoft Entra first-party application service principals. Other notices cover a staged passkey-related behavior improvement, general availability of Entra PIM role management for Dynamics 365 Apps and Power Platform, and a Dataverse cleanup capability entering public preview.
- Symmetric keys for first-party service principals will be disabledWorkload ID
Microsoft announced a security-related behavior change for Microsoft Entra first-party application service principals. Organizations must switch from symmetric to asymmetric keys by June 15, 2024, to avoid authentication failures.
- Authentication-strength improvements begin supporting device-stored passkeysEntra ID
Microsoft Entra ID is rolling out new authentication-strength support for passkeys stored on devices. Users will see additional registration options in My Security Info as the rollout proceeds from mid-May through early August 2024. No preparation is required, though administrators may update relevant documentation.
- Entra PIM role management for Dynamics 365 and Power Platform reaches general availabilityEntra ID
Beginning May 23, administrators can use Microsoft Entra Privileged Identity Management to assign Dynamics 365 Apps and Power Platform tenant admin roles for a defined period. The announcement does not identify additional prerequisites, migration work, or configuration changes.
- Dataverse user cleanup enters public previewEntra ID / Dataverse
Beginning May 1, the preview provides the ability to delete disabled-status users from Dataverse environments, including delete stubs, unlicensed users, and users removed from Microsoft Entra groups. Microsoft cites privacy and regulatory requirements and storage reduction as intended benefits; the supplied evidence does not make deletion mandatory or specify eligibility and configuration details.
Organizations using symmetric keys for Microsoft Entra first-party application service principals must replace them with asymmetric keys by June 15, 2024, or risk authentication failures. No preparation is required for the passkey rollout, although relevant user documentation may need updating. PIM is available for time-bounded tenant admin roles, while the Dataverse cleanup capability is preview functionality and is not described as mandatory.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
4 updates by product
Microsoft Entra ID
3 updatesFundamentals
1Monitoring
1General availability of managing admin roles using Entra Privileged Identity Management announcement
NewWe are announcing the general availability of managing admin roles with Microsoft Entra Privileged Identity Management (PIM) for Dynamics 365 Apps and Power Platform. Beginning on May 23, 2024, this feature enables you to use Entra PIM to assign tenant admin roles for a certain time period.
Troubleshooting
1Microsoft Entra ID will improve authentication strength to support passkeys stored on devices. Users will see new registration options in My Security Info. The rollout will begin in mid-May 2024 and is expected to complete by early August 2024. No action is needed to prepare for this change, but you may want to update relevant documentation.
Microsoft Entra Workload ID
1 updateAuthentication
1Symmetric keys for Microsoft Entra first-party applications' Service Principals will be disabled to enhance security. Organizations must switch to Asymmetric keys by June 15, 2024, to avoid authentication failures. Preparation involves replacing Symmetric with Asymmetric keys as detailed in the provided link.
