Month in brief

January 2026: two Entra authentication retirements outweigh a month of documentation maintenance

January’s consequential administrator work is deadline-driven rather than a feature-release cycle. The record contains 299 changes—292 updates, one new page, three removals, and three Message Center notices. The notices announce the retirement of Conditional Access’s “Require approved client app” control in June 2026 and custom greetings for voice-call MFA on February 28, 2026. Microsoft Purview DLP also renamed its Enforcement plane from “Entra” to “Application,” without functional or user impact. The supplied evidence establishes no new preview or general-availability release. The sole new page is an EcoOnline Info Exchange SSO configuration tutorial, not evidence of a new Entra capability; the three removed Purview workload-content pages have no stated retirement rationale.

  • Conditional Access will retire the “Require approved client app” controlMicrosoft Entra ID — Conditional Access

    Retirement notice: Microsoft says the control will retire in June 2026 and will no longer be enforceable afterward. The stated replacement is “Require application protection policy,” described as providing equivalent and enhanced protection. Administrators should identify policies using the old control and update them ahead of the retirement.

  • Custom voice-MFA greetings will be replaced by default recordingsMicrosoft Entra ID — voice-call authentication

    Retirement notice: custom greetings in voice-call authentication end on February 28, 2026. Voice MFA calls will use Microsoft’s default recordings after that date. The notice concerns the greeting experience, not a stated retirement of voice MFA itself; the supported preparation is to inform users and review relevant MFA configurations.

  • Purview DLP’s Enforcement plane label changes from “Entra” to “Application”Microsoft Purview DLP — Enforcement plane

    Naming clarification: Microsoft Purview DLP began renaming the Enforcement plane in mid-January. There is no stated functional, user, or compliance impact. New audit logs use “Application,” while existing logs retain “Entra,” so scripts and documentation that depend on the label may need updating.

  • Conditional Access Optimization Agent guidance documents an activator-identity distinctionMicrosoft Entra ID — Conditional Access Optimization Agent

    A coordinated update to five Entra Conditional Access Optimization Agent pages records that agents enabled after November 17, 2025 no longer use the identity of the user who activated them. Earlier agents may fail when the activating account relied on Privileged Identity Management but lacked the required permissions when the agent ran. This is operational documentation and troubleshooting guidance; it does not establish a preview, general-availability event, or January-wide rollout.

  • External ID guidance adds an explicit Akamai WAF verification stepMicrosoft Entra External ID

    The updated Akamai integration guidance tells administrators to verify after configuration that Akamai WAF is protecting the external tenant by connecting the authentication credentials to the WAF configuration. Related External ID security guidance frames credential stuffing, automated bot sign-ups, account takeover, and traffic spikes as CIAM threats requiring layered controls and integrations. These are implementation and security clarifications, not evidence of a new External ID capability or availability shift

For Entra administrators

Inventory Conditional Access policies that use “Require approved client app” and plan migration to “Require application protection policy” before the June retirement. Prepare voice-MFA users for Microsoft’s default recordings and review relevant configurations before February 28. Update Purview DLP scripts and internal documentation to recognize “Application” in new audit logs while retaining “Entra” for existing logs. For deployments in scope, review the revised Conditional Access Optimization Agent, ID Protection, Microsoft Entra Connect Sync, and External ID/Akamai WAF guidance. The evidence supports targeted runbook checks, not a blanket tenant reconfiguration.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

299 updates by product

General

116

Entra Offerings

Updated

**Microsoft Entra ID P2** - Microsoft Entra ID P2 is available as a standalone product. It is also included with the following offers for enterprise customers:

30 January 2026

Attack Payload Author

Updated

- [Get started using Attack simulation training](/defender-office-365/attack-simulation-training-get-started)

29 January 2026

Groups Dynamic Rule Member Of

Updated

- The `memberOf` attribute can't be used with other operators. For example, you can't create a rule that states "Members Of group A can't be in Dynamic group B."

28 January 2026

21793

Updated

If this check passes, your tenant has a TRv2 policy configured but more steps are required to validate the scenario end-to-end.

23 January 2026

21824

Updated

Without proper session controls, threat actors can achieve lateral movement across the organization's infrastructure, accessing critical data and systems that extend far beyond the original guest account's intended scope of access.

23 January 2026

Ecoonline Info Tutorial

Updated

In this article, you configure and test Microsoft Entra single sign-on in a test environment.

20 January 2026

Connect Health Adfs

Updated

- [Download the Microsoft Entra Connect Health agent for AD FS](https://go.microsoft.com/fwlink/?LinkID=518973).

17 January 2026

Connect Version History

Updated

You can upgrade your Microsoft Entra Connect server from all supported versions with the latest versions:

17 January 2026

Dirsync Upgrade Get Started

Updated

DirSync and Azure AD Sync aren't supported and no longer work. If you're still using DirSync or Azure AD Sync, you *must* upgrade to Microsoft Entra Connect to resume your sync process.

17 January 2026

Troubleshooting

28

21790

Updated

**Remediation action**

23 January 2026

21804

Updated

**Remediation action**

23 January 2026

21806

Updated

**Remediation action**

23 January 2026

21884

Updated

**Remediation action**

23 January 2026

21985

Updated

**Remediation action**

23 January 2026

21817

Updated

**Remediation action**

23 January 2026

21825

Updated

**Remediation action**

23 January 2026

21776

Updated

**Remediation action**

23 January 2026

21777

Updated

**Remediation action**

23 January 2026

21786

Updated

**Remediation action**

23 January 2026

21798

Updated

**Remediation action**

23 January 2026

21799

Updated

**Remediation action**

23 January 2026

21802

Updated

**Remediation action**

23 January 2026

21812

Updated

**Remediation action**

23 January 2026

21818

Updated

**Remediation action**

23 January 2026

21828

Updated

**Remediation action**

23 January 2026

21847

Updated

**Remediation action**

23 January 2026

21865

Updated

**Remediation action**

23 January 2026

21867

Updated

**Remediation action**

23 January 2026

21868

Updated

**Remediation action**

23 January 2026

21870

Updated

**Remediation action**

23 January 2026

21877

Updated

**Remediation action**

23 January 2026

21883

Updated

**Remediation action**

23 January 2026

21886

Updated

**Remediation action**

23 January 2026

21891

Updated

**Remediation action**

23 January 2026

22128

Updated

**Remediation action**

23 January 2026

22659

Updated

**Remediation action**

23 January 2026

Authentication

20

Kerberos

Updated

Cloud-only user accounts managed solely in Microsoft Entra ID are supported for Kerberos authentication by workloads like Azure Files, Azure Virtual Desktop and Windows authentication access to Azure SQL Managed Instance.

31 January 2026

Manage Roles Portal

Updated

| [User Administrator](permissions-reference.md#user-administrator) | Can manage all aspects of users and groups, including resetting passwords for limited admins within the assigned administrative unit only. Cannot currently manage users' profile photographs. |

31 January 2026

Privileged Authentication Administrator

Updated

>* Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Authentication Administrators. Through this path an Authentication Administrator can assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

29 January 2026

Customer Lockbox Access Approver

Updated

Manages [Microsoft Purview Customer Lockbox requests](/purview/customer-lockbox-requests) in your organization. They receive email notifications for Customer Lockbox requests and can approve and deny requests from the Microsoft 365 admin center. They can also turn the Customer Lockbox feature on or off. Only Global Administrators can reset the passwords of people assigned to this role.

29 January 2026

Global Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have access to all administrative features in Microsoft Entra ID, as well as services that use Microsoft Entra identities like the Microsoft 365 Defender portal, the Microsoft Purview portal, Exchange Online, SharePoint Online, and Skype for Business Online. Global Administrators can view Directory Activity logs. Furthermore, Global Administrators can [elevate their access](/azure/role-based-access-control/elevate-access-global-admin) to manage all Azure subscriptions and management groups. This allows Global Administrators to get full access to all Azure resources using the respective Microsoft Entra tenant. The person who signs up for the Microsoft Entra organization becomes a Global Administrator. There can be more than one Global Administrator at your company. Global Administrators can reset the password for any user and all other administrators. A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has zero Global Administrators.

29 January 2026

Microsoft Entra built-in roles

Updated

In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.

23 January 2026

Migrate Adfs Represent Security Policies

Updated

When you map authorization rules, apps that authenticate with AD FS may use Active Directory groups for permissions. In such a case, use [Microsoft Entra Connect](https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted) to sync these groups with Microsoft Entra ID before migrating the applications. Make sure that you verify those groups and membership before migration so that you can grant access to the same users when the application is migrated.

17 January 2026

Connect Install Express

Updated

If you have a single-forest topology and use [password hash sync](how-to-connect-password-hash-synchronization.md) for authentication, express settings are a good option to use when you install Microsoft Entra Connect Sync. Express settings the default option to install Microsoft Entra Connect Sync, and it's used for the most commonly deployed scenario. It's only a few short steps to extend your on-premises directory to the cloud.

17 January 2026

Reports Data Retention

Updated

Log storage within Microsoft Entra varies by report type and license type. You can retain the audit and sign-in activity data for longer than the default retention period outlined in the previous table by routing it to an Azure storage account using Azure Monitor. For more information, see [Archive Microsoft Entra logs to an Azure storage account](./howto-archive-logs-to-storage-account.md).

8 January 2026

Device Join Macos Platform Single Sign On Kerberos Configuration

Updated

The macOS Platform single sign-on (PSSO) is a capability on macOS that is enabled using the [Microsoft Enterprise Single Sign-on Extension](../../identity-platform/apple-sso-plugin.md). Platform SSO enables users to Entra join their macOS devices and sign in using a hardware-bound key, smart card, or their Microsoft Entra ID password through a PSSO Primary Refresh Token (PRT).

1 January 2026

Fundamentals

20

Configure Security

Updated

| [Applications don't have client secrets configured](zero-trust-protect-identities.md#applications-dont-have-client-secrets-configured) | None (included with Microsoft Entra ID) |

29 January 2026

Conditional Access Session

Updated

![Screenshot of a Conditional Access policy with a grant control requiring multifactor authentication.](./media/concept-conditional-access-session/conditional-access-session.png)

29 January 2026

Conditional Access Cloud Apps

Updated

In the following example, the tenant has a Conditional Access policy with the following details:

29 January 2026

Groups Concept

Updated

- *Microsoft Entra ID P2 licensed customers only*: Even after deleting the group, it's still shown as an eligible member of the role in PIM UI. Functionally there's no problem; it's just a cache issue in the Microsoft Entra admin center.

29 January 2026

Security Defaults

Updated

If your tenant was created on or after October 22, 2019, security defaults might be enabled in your tenant. To protect all of our users, security defaults are being rolled out to all new tenants at creation.

27 January 2026

Add Your Work or School Account to a macOS Device

Updated

Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using browsers such as Microsoft Edge or Google Chrome.

26 January 2026

Macos Get Started

Updated

Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using applications such as Microsoft Outlook or Microsoft Edge.

22 January 2026

Assignment Network

Updated

- The country code returned depends on the device platform API: For example one platform might report US for Puerto Rico, while another reports PR.

16 January 2026

Primary Refresh Token

Updated

Once issued, a PRT is valid for 90 days and is continuously renewed as long as the user actively uses the device. Organizations can require users re-authenticate in order to access resources using the Sign-in [frequency session control](../conditional-access/concept-conditional-access-session.md).

15 January 2026

Application Gallery

Updated

- **Risk Score** – View applications by their calculated security risk score from 1 (highest risk) to 10 (lowest risk). This score helps identify applications that meet your organization's security requirements.

10 January 2026

Security

12

Manage Device Identities

Updated

`id,deviceId,displayName,accountEnabled,operatingSystem,operatingSystemVersion,trustType(joinType),mdm,securitySettingsManagement,isCompliant,registrationDateTime,approximateLastSignInDateTime,owner,upnName`

30 January 2026

Compliance Administrator

Updated

Users with this role have permissions to manage compliance-related features in the Microsoft Purview portal, Microsoft 365 admin center, Azure, and Microsoft 365 Defender portal. Assignees can also manage all features within the Exchange admin center and create support tickets for Azure and Microsoft 365. For more information, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Compliance Data Administrator

Updated

Users with this role have permissions to track data in the Microsoft Purview portal, Microsoft 365 admin center, and Azure. Users can also track compliance data within the Exchange admin center, Compliance Manager, and Teams & Skype for Business admin center and create support tickets for Azure and Microsoft 365. For more information about the differences between Compliance Administrator and Compliance Data Administrator, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Helpdesk Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to Helpdesk Administrators. Through this path a Helpdesk Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

29 January 2026

User Administrator

Updated

>- Application Registration and Enterprise Application owners, who can manage credentials of apps they own. Those apps may have privileged permissions in Microsoft Entra ID and elsewhere not granted to User Administrators. Through this path a User Administrator may be able to assume the identity of an application owner and then further assume the identity of a privileged application by updating the credentials for the application.

29 January 2026

21830

Updated

- [Deploy a privileged access workstation solution](/security/privileged-access-workstations/privileged-access-deployment)

23 January 2026

21823

Updated

Additionally, compromised guest identities can be used to establish credential persistence and potentially escalate privileges. Attackers can exploit trust relationships between guest accounts and internal resources, or use the guest account as a staging ground for lateral movement toward more privileged organizational assets.

23 January 2026

Monitoring

11

Global Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users in this role can read settings and administrative information across Microsoft 365 services but can't take management actions. Global Reader is the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations. Use Global Reader in combination with other limited admin roles like Exchange Administrator to make it easier to get work done without the assigning the Global Administrator role. Global Reader works with Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Teams admin center, Microsoft 365 Defender portal, Microsoft Purview portal, Azure portal, and Device Management admin center.

29 January 2026

21773

Updated

- [Define certificate based application configuration](https://devblogs.microsoft.com/identity/app-management-policy/)

23 January 2026

21858

Updated

The prolonged dormancy of these accounts provides attackers with extended dwell time to conduct reconnaissance, exfiltrate sensitive data, and establish backdoors without detection, as organizations typically focus monitoring efforts on active internal users rather than external guest accounts.

23 January 2026

Howto Configure Recommendation Email Notifications

Updated

The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, aren't promotional or marketing emails, and don't contain any upselling content. These emails are purely informational and designed to help you act quickly when a new recommendation is available.

21 January 2026

Connect Install Custom

Updated

Use *custom settings* in Microsoft Entra Connect when you want more options for the installation. Use these settings, for example, if you have multiple forests or if you want to configure optional features. Use custom settings in all cases where [express installation](how-to-connect-install-express.md) doesn't satisfy your deployment or topology needs.

17 January 2026

Sla Performance

Updated

| September | 99.999% | 99.998% | 99.999% | 99.999% | 99.999% |

10 January 2026

Conditional Access

9

Managed Policies

Updated

These Microsoft-managed policies allow administrators to make simple modifications like excluding users or turning them from report-only mode to on or off. Organizations can't rename or delete any Microsoft-managed policies. As administrators get more comfortable with Conditional Access policy, they might choose to duplicate the policy to create custom versions.

24 January 2026

Conditional Access Agent Optimization

Updated

It's possible that the agent was enabled before Microsoft Ignite 2025 with an account that required role activation with Privileged Identity Management (PIM). So when the agent attempted to run, it failed because the account didn't have the required permissions at that time. Conditional Access Optimization Agents that were turned on after November 17, 2025 no longer use the identity of the user who activated the agent.

21 January 2026

Provisioning

8

On Premises Web Services Connector

Updated

- SOAP Discovery: Allows the administrator to enter the WSDL path exposed by the target web service. Discovery produces a tree structure of the application's hosted web services with their inner endpoints or operations along with the operation’s Meta data description. There's no limit to the number of discovery operations that can be done (step by step). The discovered operations are used later to configure the flow of operations that implement the connector’s operations against the data-source (as Import/Export).

17 January 2026

Functions For Customizing Application Data

Updated

[Append](#append)      [AppRoleAssignmentsComplex](#approleassignmentscomplex)      [BitAnd](#bitand)      [CBool](#cbool)      [CDate](#cdate)      [Coalesce](#coalesce)      [ConvertToBase64](#converttobase64)      [ConvertToUTF8Hex](#converttoutf8hex)      [Count](#count)      [CStr](#cstr)      [DateAdd](#dateadd)      [DateDiff](#datediff)      [DateFromNum](#datefromnum)  [FormatDateTime](#formatdatetime)      [Guid](#guid)      [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty)     [IIF](#iif)     [InStr](#instr)      [IsNull](#isnull)      [IsNullOrEmpty](#isnullorempty)      [IsPresent](#ispresent)      [IsString](#isstring)      [Item](#item)      [Join](#join)      [Left](#left)      [Len](#len)      [Mid](#mid)      [NormalizeDiacritics](#normalizediacritics)       [Not](#not)      [Now](#now)      [NumFromDate](#numfromdate)      [PCase](#pcase)      [RandomString](#randomstring)      [Redact](#redact)      [RemoveDuplicates](#removeduplicates)      [Replace](#replace)      [SelectUniqueValue](#selectuniquevalue)     [SingleAppRoleAssignment](#singleapproleassignment)     [Split](#split)    [StripSpaces](#stripspaces)      [Switch](#switch)     [ToLower](#tolower)     [ToUpper](#toupper)     [Word](#word)

16 January 2026

App Provisioning Sap

Updated

> - Keep user attributes synchronized between Microsoft Entra ID and SAP ECC.

8 January 2026

Configuring Microsoft Entra ID to provision users into SAP ECC with NetWeaver AS ABAP 7.0 or later

Updated

The following documentation provides configuration and tutorial information demonstrating how to provision users from Microsoft Entra ID into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver 7.0 or later. If you're using other versions of SAP R/3, you can still use the guides provided in the [Connectors for Microsoft Identity Manager 2016](https://www.microsoft.com/download/details.aspx?id=51495) download as a reference to build your own template for provisioning.

8 January 2026

Plan Sap User Source And Target

Updated

The Microsoft Entra provisioning agent and generic web services connector provides connectivity to on-premises SAP ECC SOAP endpoints, including SAP BAPIs.

8 January 2026

Standards

7

Hipaa Audit Controls

Updated

| Configure Azure Monitor | [Use Azure Monitor Logs](/azure/azure-monitor/logs/data-security) collects and organizes logs, expanding to cloud and hybrid environments. It provides recommendations on key areas on how to protect resources combined with Azure trust center. |

29 January 2026

Configure a GitHub enterprise with Enterprise Managed Users for SAML Single sign-on with Microsoft Entra ID

Updated

In this article, you learn how to set up a SAML integration for a GitHub enterprise with Enterprise Managed Users with Microsoft Entra ID. Setting up a SAML or [OIDC](https://docs.github.com/enterprise-cloud@latest/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-oidc-for-enterprise-managed-users) authentication integration, in addition to setting up [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md), is required for a GitHub enterprise with Enterprise Managed Users. Setting up authentication and [SCIM provisioning](./github-enterprise-managed-user-provisioning-tutorial.md) for a GitHub enterprise with Enterprise Managed Users allows an admin to:

29 January 2026

V2 Oauth2 Implicit Grant Flow

Updated

![Diagram showing the implicit sign-in flow.](./media/v2-oauth2-implicit-grant-flow/convergence-scenarios-implicit.svg)

15 January 2026

Microsoft identity platform

5

Troubleshoot Connect Sync Application Authentication

Updated

The same issue occurs when a server with Microsoft Entra Connect installed is cloned into another production server, which isn't a supported method of deploying this product as these servers with share the same machine identifier. In short, the server's identity conflicts because they get tied to one app registration. The Microsoft Entra Connect wizard by default uses unique accounts per server because it uses the server's name to identify the application registration instead of the Microsoft Entra connector's service account, which avoids this issue.

22 January 2026

Security Best Practices For App Registration

Updated

:::image type="content" source="./media/application-registration-best-practices/implict-grant-flow.png" alt-text="Screenshot that shows where the implicit flow property is located.":::

15 January 2026

Identity Platform Integration Checklist

Updated

![checkbox](./media/integration-checklist/checkbox-two.svg) If your app is registered in a directory, minimize and manually monitor the list of app registration owners.

15 January 2026

Developer

4

Manage App Consent Policies

Updated

Every tenant comes with a set of app consent policies that are the same across all tenants. Some of these built-in policies are used in existing built-in directory roles. For example, the `microsoft-application-admin` app consent policy describes the conditions under which the Application Administrator and Cloud Application Administrator roles are allowed to grant tenant-wide admin consent. Built-in policies can be used in custom directory roles or to configure an organization's default consent policy. These policies can't be edited. A list of the built-in policies are:

6 January 2026

Branding

3

Governance

3

21869

Updated

While an application with open assignment but proper provisioning scoping (such as department-based filters or group membership requirements) maintains security controls through the provisioning layer, applications lacking both controls create unrestricted access pathways that threat actors can exploit. When applications provision accounts for all users without assignment restrictions, threat actors can abuse compromised accounts to conduct reconnaissance activities, enumerate sensitive data across multiple systems, or use the applications as staging points for further attacks against connected resources. This unrestricted access model is dangerous for applications that have elevated permissions or are connected to critical business systems. Threat actors can use any compromised user account to access sensitive information, modify data, or perform unauthorized actions that the application's permissions allow. The absence of both assignment controls and provisioning scoping also prevents organizations from implementing proper access governance. Without proper governance, it's difficult to track who has access to which applications, when access was granted, and whether access should be revoked based on role changes or employment status. Furthermore, applications with broad provisioning scopes can create cascading security risks where a single compromised account provides access to an entire ecosystem of connected applications and services.

23 January 2026

Cloud Governed Management For On Premises

Updated

Identity governance helps organizations achieve a balance between *productivity* --- how quickly can a person have access to the resources they need, such as when they join the organization? --- and *security* --- how should their access change over time, such as when that person's employment status changes? Identity lifecycle management is the foundation for identity governance, and effective governance at scale requires modernizing the identity lifecycle management infrastructure for applications.

17 January 2026

Architecture

2

General

1

Microsoft identity platform

1

Standards

1

Agent Id Governance Overview

Updated

When created, agent identities have limited permissions, such as OAuth 2 delegated permission scopes [inherited from their parent agent identity blueprint](../agent-id/identity-professional/configure-inheritable-permissions-blueprints.md). In addition, agent identities can have resource access assigned to them directly via access packages. Agent identities can request an access package for themselves, or have their owner or sponsor request one on their behalf. With access packages, you're able to assign agent identities access to the following resources:

15 January 2026

Fundamentals

4

Identity Protection Policies

Updated

The Microsoft-managed remediation risk-based Conditional Access policy lets you author a risk policy that accommodates all authentication methods, including password-based and passwordless. This means that when you select "Require risk remediation" in your policy's grant controls, Microsoft Entra ID Protection manages the appropriate remediation flow based on the threat observed and the user's authentication method. For detailed steps on how to enable Microsoft-managed remediation, see [Configure risk policies](howto-identity-protection-configure-risk-policies.md#microsoft-recommendations).

16 January 2026

Howto Identity Protection Remediate Unblock

Updated

If a user is prompted to use self-service password reset (SSPR) to remediate user risk, they are prompted to update their password as shown in the [Microsoft Entra ID Protection user experience](concept-identity-protection-user-experience.md) article. Once they update their password, the user risk is remediated. A secure password change (MFA and password change) can also remediate user risk. The user can then proceed to sign in with their new password. The risk state and risk details for the user, sign-ins, and corresponding risk detections are updated as follows:

8 January 2026

Authentication

3

Security Administrator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have permissions to manage security-related features in the Microsoft 365 Defender portal, Microsoft Entra ID Protection, Microsoft Entra Authentication, Azure Information Protection, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Security Reader

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role have global read-only access on security-related feature, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and the ability to read Microsoft Entra sign-in reports and audit logs, and in Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Security

1

Security Operator

Updated

This is a [privileged role](../privileged-roles-permissions.md). Users with this role can manage alerts and have global read-only access on security-related features, including all information in Microsoft 365 Defender portal, Microsoft Entra ID Protection, Privileged Identity Management, and Microsoft Purview portal. For more information about Office 365 permissions, see [Roles and role groups in Microsoft Defender for Office 365 and Microsoft Purview compliance](/microsoft-365/security/office-365-security/scc-permissions).

29 January 2026

Troubleshooting

1

Governance

8

Pim Roles

Updated

> For information about delays activating the Microsoft Entra Joined Device Local Administrator role, see [How to manage the local administrators group on Microsoft Entra joined devices](../../identity/devices/assign-local-admin.md#manage-the-microsoft-entra-joined-device-local-administrator-role).

29 January 2026

Entitlement Management Sap Integration

Updated

- The Microsoft Entra User Account configuring the connector and Access Packages must be synced to SAP Cloud Identity Services (IAS) and SAP IAG.

9 January 2026

Sap

Updated

Once you have users in Microsoft Entra ID, you can provision those users from Microsoft Entra ID to SAP Cloud Identity Services or SAP ECC, to enable them to sign in to SAP applications. If you have [`SAP S/4HANA On-Premise`](https://help.sap.com/docs/identity-provisioning/identity-provisioning/target-sap-s-4hana-on-premise), then provision users from Microsoft Entra ID to SAP Cloud Identity Directory. SAP Cloud Identity Services then provisions the users originating from Microsoft Entra ID that are in the SAP Cloud Identity Directory into the downstream SAP applications to SAP S/4HANA On-Premise through the SAP cloud connector.

8 January 2026

Fundamentals

4

Pim For Groups

Updated

1. Make active assignments of users to the group, and then assign the group to a role as eligible for activation.

29 January 2026

Identity Governance Overview

Updated

In Microsoft Entra ID Governance, you can enable business groups to determine which of these guests should have access, and for how long, using:

23 January 2026

Apps

Updated

| HR | [API-driven connector from any HR source](../identity/app-provisioning/inbound-provisioning-api-concepts.md)<br>[Rippling HCM integration with Microsoft Entra ID/Active Directory](../identity/saas-apps/rippling-hcm-microsoft-entra-id-integration-tutorial.md)<br>[Oracle HCM API-driven connector](../identity/saas-apps/oracle-hcm-provisioning-tutorial.md)<br>[Darwinbox to Microsoft Entra ID](../identity/saas-apps/darwinbox-entra-integration-tutorial.md)<br>[SAP HCM to Microsoft Entra ID](../identity/saas-apps/sap-hcm-microsoft-entra-identity-provisioning.md) |

17 January 2026

What Is Provisioning

Updated

1. For organizations with a single subscription to Workday or SuccessFactors, and don't use Active Directory

17 January 2026

General

8

External Identities Pricing

Updated

- External users in Microsoft Entra [external tenants](tenant-configurations.md#external-tenants), which includes consumers and business guests (users without directory roles), and admins (users with directory roles). MAU billing applies to all users in an external tenant regardless of their **UserType** setting.

24 January 2026

Connect Health Agent Install

Updated

- [Download the Microsoft Entra Connect Health agent for AD FS](https://download.microsoft.com/download/9577dcd4-71d4-4607-8950-3b2b97f499f4/MicrosoftEntraConnectHealthAgentSetup.exe).

17 January 2026

Fundamentals

4

Microsoft Entra External ID overview

Updated

Microsoft Entra External ID allows you to collaborate with or publish apps to people outside your organization. Compare solutions for External ID, including Microsoft Entra B2B collaboration, Microsoft Entra B2B collaboration, and Azure AD B2C.

31 January 2026

Security Customers

Updated

External-facing identity systems support a wide range of customer experiences. That wide range also makes them attractive targets for common customer identity and access management (CIAM) attack patterns such as credential stuffing, automated bot sign-ups, account takeover attempts, and high-volume traffic spikes. Understanding these threats helps explain why a clear, layered security approach is essential. Microsoft Entra External ID provides foundational capabilities you can build on. This guide helps you understand how to strengthen that foundation with recommended controls and integrations based on common CIAM threat patterns.

29 January 2026

Supported Features Customers

Updated

|**Target resources**|<ul><li>[Cloud apps](~/identity/conditional-access/concept-conditional-access-cloud-apps.md)</li><li>[User actions](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#user-actions)</li><li>[Global Secure Access](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#traffic-forwarding-profiles)</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|<ul><li>[All resources, selected apps](./how-to-multifactor-authentication-customers.md), or [filter applications](~/identity/conditional-access/concept-filter-for-applications.md).</li><li>[Authentication context](~/identity/conditional-access/concept-conditional-access-cloud-apps.md#authentication-context)</li></ul>|

29 January 2026

Standards

2

External ID in external tenants

Updated

- [Configure a new OpenID connect identity provider in the admin center](customers/how-to-custom-oidc-federation-customers.md) - Client secret updates

7 January 2026

Authentication

1

Configure Akamai Integration

Updated

After completing the configuration steps, verify that Akamai WAF is protecting your external tenant by connecting the authentication credentials to the WAF configuration.

30 January 2026

Branding

1

Architecture

1

Fundamentals

1

Traffic Forwarding

Updated

Internet access traffic can be forwarded to the service by connecting through the [Global Secure Access desktop client](how-to-install-windows-client.md).

15 January 2026

Monitoring

1

Configure Domain Controllers

Updated

- Use **Event Viewer** from **Application and Service Logs** > **Microsoft** > **Windows** > **Private Access Sensor** to review Private Access Sensor logs.

10 January 2026

Monitoring

2

21836

Updated

If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.

23 January 2026

General

4

Powershell Get Token

Updated

Write-Output "Access Token that you acquired is available in C:\token.txt. "

30 January 2026

Monitoring

1

Security

1

Network Content Filtering

Updated

Discover how to configure network content filtering with Global Secure Access to enforce data protection policies and secure sensitive files in real time.

27 January 2026