Enable multifactor authentication (MFA) for your tenant by October 15, 2024, to access Microsoft Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. Set up MFA early or apply to postpone the enforcement date if necessary. Without MFA, admin access will be restricted.
Tenant MFA deadline leads August: privileged approval bypass ends and Edge mobile Copilot retires
August’s supplied Entra record is operational rather than documentation-led: all seven entries are Microsoft 365 Message Center notices, with no new, updated, or removed documentation items. The highest-impact item is the requirement to enable tenant MFA by 15 October 2024 to preserve access to three admin centers. Two other behavior changes affect users and privileged administrators: Copilot in Edge mobile retires for Entra ID users with version 128 in late August, and Entitlement Management will enforce access-package approvals for Global Administrators and Identity Governance Administrators from 26 August. The remaining substantive notices are general-availability rollouts for ID Protection detection, AD FS application migration, and Red Hat Enterprise Linux device-based Conditional Access.
- Tenant MFA is required for admin-portal access by 15 OctoberEntra ID
This is security-enforcement guidance, not a new capability: tenants must enable MFA by 15 October 2024 to access the Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center. The notice says tenants may set up MFA early or apply to postpone enforcement; without MFA, administrative access will be restricted.
- Entitlement Management removes privileged-administrator approval bypassID Governance
This behavior change takes effect on 26 August 2024: Global Administrators and Identity Governance Administrators can no longer bypass the approval settings configured in access package policies. Microsoft describes the update as automatic and says no organizational action is needed.
- Copilot in Edge mobile is retired for Entra ID usersEntra ID
This is a retirement, not a rollout: Copilot leaves the Microsoft Edge mobile application for Entra ID users with version 128 in late August 2024. No admin action is required, but Microsoft recommends informing affected users and directing them to the Microsoft 365 mobile app for work or to web chat.
- Attacker in the Middle detection reaches general availability in ID ProtectionID Protection
The security detection feature is scheduled to reach general availability by late August 2024. Its detection alert is intended to identify compromised user accounts in Microsoft Entra ID Protection. The notice states that no admin action is required before rollout.
- AD FS migration and RHEL device-based Conditional Access reach general availabilityEntra ID
The AD FS application migration wizard reaches general availability in mid-to-late August and provides a guided experience for migrating AD FS relying-party applications. Device-based Conditional Access for Microsoft 365 and Azure on Red Hat Enterprise Linux also goes generally available, including Entra ID registration, Conditional Access, SSO, Intune compliance, and Red Hat RPM package support. Neither notice requires action before rollout.
Enable MFA before 15 October, or use the stated postponement option if necessary; without it, access to the Azure portal, Microsoft Entra admin center, and Microsoft Intune admin center will be restricted. No pre-rollout action is stated for the general-availability notices or the automatic Entitlement Management change, but administrators should expect configured access-package approval requirements to apply to the two named privileged roles. For the Edge retirement, Microsoft recommends informing users and pointing them to the Microsoft 365 mobile app for work or web chat. The separate Dynamics 365 deletion notice confirms availability but provides too little detail to support a cleanup or configuration recommendation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
7 updates by product
Microsoft Entra ID
5 updatesAuthentication
1Developer
1The Copilot feature in the Microsoft Edge mobile app for Entra ID users will be retired with version 128 in late August 2024. Users should use the Microsoft 365 mobile app for work and web chat instead. No action is required, but informing users is recommended.
Monitoring
1Starting August 8, 2024, the Delete stub, unlicensed, and removed Microsoft Entra group users feature will be generally available. How does this affect me?
Standards
1Device-based Conditional Access for Microsoft 365 and Azure on Red Hat Enterprise Linux is going GA in mid to late August 2024. It brings Entra ID registration, Conditional Access policies, SSO, Intune compliance, and support for Red Hat RPM packages. No admin action is required before rollout.
Troubleshooting
1Microsoft Entra ID: Active Directory Federation Services (AD FS) application migration wizard is GA
NewThe AD FS application migration wizard for Microsoft Entra ID is now generally available, providing a guided experience for migrating AD FS relying party applications. Rollout begins mid-August 2024, with completion expected by late August. No admin action is required before the rollout.
Microsoft Entra ID Protection
1 updateFundamentals
1The Attacker in the Middle detection feature will be generally available in Microsoft Entra ID Protection by late August 2024, enhancing security by identifying compromised user accounts. No admin action is required before the rollout.
Microsoft Entra ID Governance
1 updateGovernance
1Starting August 26, 2024, changes to Entitlement Management will enforce approval settings for Global Administrators and Identity Governance Administrators, preventing them from bypassing access package policy approvals. No action is needed from your organization as this is an automatic update.
