Month in brief

What changed in May

281 documentation updates and 6 Message Center announcements were tracked during May. Activity centred on General, Fundamentals, and Authentication, with the most changes affecting Entra ID and ID Governance.

287 updates by product

General

47

Purpose:

New

author: omondiatieno

27 May 2026

Purpose:

New

author: omondiatieno

27 May 2026

Purpose:

New

author: omondiatieno

27 May 2026

Purpose:

New

author: omondiatieno

27 May 2026

Groups Create Rule

Updated

Using dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).

27 May 2026

Connect Health Data Freshness

Updated

* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.

27 May 2026

Connect Ports

Updated

<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>

27 May 2026

Samsara Tutorial

Updated

b. Copy the link from Post-back/ACS URL field in Samsara into the **Reply URL** text box in Entra ID.

21 May 2026

Quickstart Register App

Updated

1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.

15 May 2026

21782

Removed

A Microsoft Entra documentation page was updated: 21782.

6 May 2026

Create New Tenant

Removed

A Microsoft Entra documentation page was updated: Create New Tenant.

6 May 2026

Create New Tenant

Removed

A Microsoft Entra documentation page was updated: Create New Tenant.

6 May 2026

Entra Msi Tut Prereqs

Removed

A Microsoft Entra documentation page was updated: Entra Msi Tut Prereqs.

6 May 2026

Fundamentals

37

Whats New

Updated

**Type:** New feature

30 May 2026

Certificate Based Authentication Certificate Revocation List

Updated

| **AADSTS500183: Certificate has been revoked. Please contact your administrator** | An Authentication attempt failed because the client device presented a certificate that was revoked by the issuing CA. | The certificate used for authentication is found in the Certificate Revocation List (CRL) or flagged as revoked by the CA. | - Tenant Administrator should ensure the new certificate is correctly provisioned and trusted by Microsoft Entra ID.<br/>- Verify that the CRLs and delta CRLs published by your CA are up to date and accessible for the devices. |

19 May 2026

Sspr Policy

Updated

| Compliance Administrator | Knowledge Administrator | Teams Communications Administrator |

19 May 2026

Native Authentication

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).

15 May 2026

Fido2 Compatibility

Updated

- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.

10 May 2026

Users Restore

Updated

You can permanently delete a user from your organization without waiting the 30 days for automatic deletion. A permanently deleted user can't be restored by anyone, including Microsoft customer support.

9 May 2026

Add Custom Domain

Updated

- [How to assign roles and administrators](./how-subscriptions-associated-directory.md)

9 May 2026

Connect Pta Quick Start

Updated

1. Create a cloud-only Hybrid Identity Administrator account or a Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.

9 May 2026

Create New Tenant

Updated

- To change or add other domain names, see [How to add a custom domain name to Microsoft Entra ID](add-custom-domain.md).

9 May 2026

Delegate By Task

Updated

Here are the least privileged roles you should use when performing tasks for [users](../../fundamentals/how-to-create-delete-users.md) in Microsoft Entra ID.

9 May 2026

Multi Tenant Organization Overview

Updated

- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)

9 May 2026

Prerequisites

Updated

1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant if your on-premises services fail or become unavailable. Learn about how to [add a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Finishing this step is critical to ensure that you don't get locked out of your tenant.

9 May 2026

Sspr Deploy

Updated

To ensure that your deployment works as expected, plan a set of test cases to validate the implementation. To assess the test cases, you need a non-administrator test user with a password. If you need to create a user, see [Add new users to Microsoft Entra ID](~/fundamentals/how-to-create-delete-users.md).

9 May 2026

Tutorial Enable Sspr

Updated

* A working Microsoft Entra tenant with at least a Microsoft Entra ID P1 license is required for password reset. For more information about license requirements for password change and password reset in Microsoft Entra ID, see [Licensing requirements for Microsoft Entra self-service password reset](concept-sspr-licensing.md).

9 May 2026

Tutorial Existing Forest

Updated

1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.

9 May 2026

Users Default Permissions

Updated

* To learn more about how to assign Microsoft Entra administrator roles, see [Assign a user to administrator roles in Microsoft Entra ID](./how-subscriptions-associated-directory.md).

9 May 2026

Fido2 Compatibility

Updated

- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.

8 May 2026

Fido2 Hardware Vendor

Updated

ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|&#10060;|&#x2705;|&#x2705;|&#10060;

6 May 2026

Users Default Permissions

Updated

| Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul> |

5 May 2026

Security Defaults

Updated

As part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.

1 May 2026

Registration Mfa Sspr Combined

Updated

By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.

1 May 2026

Whats New

Updated

**Service category:** User Experience and Management

1 May 2026

Five Steps To Full Application Integration

Updated

In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.

1 May 2026

Multi Tenant Organization Overview

Updated

- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)

1 May 2026

Authentication

29

Mfa Registration Campaign

Updated

For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome, they're nudged because that credential doesn't apply to that platform.

31 May 2026

Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration

New

Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.

29 May 2026
Message CenterMC1326253 on mc.merill.net ↗Stay informed

Connect Pta

Updated

- Installing multiple agents provides high availability of sign-in requests.

27 May 2026

Authentication Passkeys Fido2

Updated

- Devices must support passkey (FIDO2) authentication. For Windows devices that are joined to Microsoft Entra ID, the best experience is on Windows 10 version 1903 or higher. Hybrid-joined devices must run Windows 10 version 2004 or higher.

16 May 2026

Authentication Passkeys Fido2

Updated

If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.

15 May 2026

Native Authentication Api

Updated

Microsoft Entra determines the default MFA method for the user by priority as follows:

15 May 2026

Conditional Access Agent Optimization

Updated

- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.

14 May 2026

Conditional Access Agent Optimization Review Suggestions

Updated

Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.

14 May 2026

Tutorial Enable Azure Mfa

Updated

* An account with at least the [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role. Some MFA settings can also be managed by an [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator).

9 May 2026

Quickstart Analyze Sign In

Updated

- An Azure subscription. If you don't have one, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).

9 May 2026

Developer

9

Managed Policies

Updated

Device code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.

29 May 2026

Entra Service Limits Include

Updated

| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li> Only the "equals" operator is supported for DateTime-type extensions. Range operators like "greater than" or "less than" are not supported.</li></ul> |

14 May 2026

Monitoring

9

Using Microsoft Entra Connect Health with AD DS

Updated

The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.

27 May 2026

Security Audit Events

Updated

View all Kerberos ticket-granting (event ID 4768) and service ticket (event ID 4769) events that used RC4 encryption in the last seven days, to identify workloads and service accounts that still rely on RC4:

7 May 2026

Entra Service Limits Include

Updated

| Reports | A maximum of 1,000 rows can be viewed or downloaded in any report. Any additional data is truncated. |

2 May 2026

Security

7

Entra Agents

Updated

- You must have available [security compute units (SCU)](/copilot/security/manage-usage).

9 May 2026

Policy All Users Windows App Protection

Updated

There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

1 May 2026

Microsoft identity platform

6

Mfa Authenticator Lite

Updated

- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.

15 May 2026

Frontline Worker Management

Updated

Frontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).

1 May 2026

Provisioning

6

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).

19 May 2026

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Atla…

Updated

This article describes the steps you need to perform in both Atlassian Cloud and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Atlassian Cloud](https://www.atlassian.com/cloud) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

12 May 2026

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).

9 May 2026

Jive Provisioning Tutorial

Updated

This section guides you through connecting your Microsoft Entra ID to Jive's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in Jive based on user and group assignment in Microsoft Entra ID.

6 May 2026

Standards

6

Configure Cmmc Level 2 Identification And Authentication

Updated

| IA.L2-3.5.5<br><br>**Practice statement:** Prevent reuse of identifiers for a defined period.<br><br>**Objectives:**<br>Determine if:<br>[a.] a period within which identifiers can't be reused is defined; and<br>[b.] reuse of identifiers is prevented within the defined period. | All user, group, device object globally unique identifiers (GUIDs) are guaranteed unique and non-reusable for the lifetime of the Microsoft Entra tenant.<br>[user resource type - Microsoft Graph v1.0](/graph/api/resources/user?view=graph-rest-1.0&preserve-view=true)<br>[group resource type - Microsoft Graph v1.0](/graph/api/resources/group?view=graph-rest-1.0&preserve-view=true)<br>[device resource type - Microsoft Graph v1.0](/graph/api/resources/device?view=graph-rest-1.0&preserve-view=true) |

9 May 2026

Fedramp Access Controls

Updated

| FedRAMP Control ID and description | Microsoft Entra guidance and recommendations |

9 May 2026

Conditional Access

5

Plan Conditional Access

Updated

- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)

9 May 2026

Architecture

4

Migrate Adfs Apps Stages

Updated

During the process of moving your app authentication to Microsoft Entra ID, test your apps and configuration. We recommend that you continue to use existing test environments for migration testing before you move to the production environment. If a test environment isn't currently available, you can set one up using [Azure App Service](https://azure.microsoft.com/services/app-service/) or [Azure Virtual Machines](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn), depending on the architecture of the application.

9 May 2026

Connect To Cloud Sync Decision Guide

Updated

Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.

8 May 2026

Recoverability Overview

Updated

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

5 May 2026

Troubleshooting

3

Branding

2

Get Started Premium

Updated

Now that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.md).

9 May 2026

Customize Branding

Updated

:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::

8 May 2026

General

12

Configure Inheritable Permissions Blueprints

Updated

- Maximum of 50 resource apps per agent identity blueprint (for example, up to 50 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.

27 May 2026

Agent Owners Sponsors Managers

Updated

Owners usually serve as technical administrators for agents, handling operational and configuration aspects. Individual users (including guest users) and service principals can be set as owners. Groups aren't supported as owners. Service principals as owners enable automated management of agent identities. Owners are optional for agent identity blueprints and agent identities.

20 May 2026

Agent Id Ai Guided Setup

Updated

If you have the GitHub Copilot for Azure extension installed, ask Copilot to set up Agent ID. For example:

14 May 2026

Whats New Agent Id

Updated

This article summarizes the key capabilities and documentation currently available.

2 May 2026

Agent Lists

Updated

Access Microsoft Entra admin center to view and filter agent identities. Streamline tenant oversight with search, filters, and column customization.

2 May 2026

Manage Agent Identities Admin

Updated

The Microsoft Entra admin center provides a centralized interface to view all agent identities in your tenant. You can search, filter, sort, and customize columns to find specific agents.

2 May 2026

Manage agents in end user experience

Updated

Learn how to manage agent identities in the end user experience within Microsoft Entra. View, control, and take action on agents you own or sponsor with ease.

2 May 2026

Fundamentals

4

Security For Ai Overview

Updated

- Ensure sponsors and owners are assigned and maintained for each agent identity, preventing orphaned agent identities.

9 May 2026

Whats New Ignite 2025

Updated

- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)

1 May 2026

Governance

3

Migrate Copilot Studio agents to Agent ID

Updated

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

15 May 2026

What's new in Microsoft Entra Agent ID

New

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.

2 May 2026

Authentication

2

Integrate third-party agents with Microsoft Entra Agent ID

Updated

Microsoft Entra Agent ID enables AI agents from third-party platforms to authenticate and access your APIs securely without handling credentials directly. This article covers two integration patterns - the Microsoft Entra Auth SDK (sidecar) and federation - for platforms such as Amazon Web Service (AWS) Bedrock and n8n.

2 May 2026

Microsoft Entra Agent ID logs

Updated

Learn how audit and sign-in activities associated with agent identities are logged in Microsoft Entra ID.

2 May 2026

Conditional Access

2

Licensing Agent Id

Updated

- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.

8 May 2026

Microsoft identity platform

2

Create an agent identity blueprint

Updated

Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.

2 May 2026

Security

1

Standards

1

Architecture

1

Id Protection Guide Introduction

Updated

- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)

9 May 2026

Conditional Access

1

Governance

26

Migrate From Sap Idm

Updated

In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.

9 May 2026

Lifecycle Workflow Tasks

Updated

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

5 May 2026

Create a monitor (preview)

Updated

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

1 May 2026

Enable tenant discovery (preview)

Updated

Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization

1 May 2026

Update or delete a monitor (preview)

Updated

Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change

1 May 2026

Pim How To Add Role To User

Updated

1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.

1 May 2026

Fundamentals

3

Licensing Fundamentals

Updated

Account Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).

14 May 2026

Identity Governance Overview

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

9 May 2026

Authentication

1

Authentication

4

User Flow Sign Up Sign In Customers

Updated

By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain signed in across browser sessions. If they select **No**, a non-persistent cookie is issued.

21 May 2026

General

3

User Permissions

Updated

To better understand the typical use cases for users in an external tenant, we can categorize them as follows:

9 May 2026

B2b Quickstart Add Guest Users Portal

Updated

In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.

9 May 2026

Fundamentals

2

Manage Admin Accounts

Updated

Use the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How to create users](~/fundamentals/how-to-create-delete-users.md#create-a-new-user).)

9 May 2026

Provisioning

2

Multi Tenant Organization Known Issues

Updated

- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you might want to continue using your existing Microsoft Entra cross-tenant synchronization jobs.

9 May 2026

Standards

2

Direct Federation

Updated

1. On the **New SAML/WS-Fed IdP** page, enter the following:

21 May 2026

Direct Federation

Updated

To enable domainless federation for a new SAML IdP, follow these steps:

19 May 2026

Branding

1

Entra Id Federation Customers

Updated

An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user account is automatically created in the external tenant. For more information, see [Create a sign-up and sign-in user flow for customers](how-to-user-flow-sign-up-sign-in-customers.md).

9 May 2026

Microsoft identity platform

1

Monitoring

1

Backup Difference Report Recovery Model

Updated

Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.

13 May 2026

Fundamentals

1

What Is Global Secure Access

Updated

| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |

20 May 2026

General

1

General

4

Operate Microsoft Entra Private Access

Updated

Post-deployment operations guide for Microsoft Entra Private Access, the Zero Trust network access (ZTNA) capability, covering alerting, health checks, integration, automation, and operational metrics.

13 May 2026

Licensing Guest Users

Updated

Guest users are only billed when they actively sign in to the Global Secure Access client for Private Access.

13 May 2026

Monitoring

1

Operate Private Access

Updated

| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |

14 May 2026

General

3

Using Facecheck

Updated

Face Check is a premium feature within Verified ID. If you're a Microsoft Entra Suite customer, Face Check is included as part of the Suite. If you're not using Microsoft Entra Suite, you need to enable the Face Check Add-on in your Microsoft Entra Verified ID setup before doing Face Check verifications.

30 May 2026

Whats New

Updated

- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.

8 May 2026

Security

2

Fundamentals

1

Use Quickstart Verifiedemployee

Updated

1. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.

9 May 2026

Troubleshooting

1

Register Didwebsite

Updated

The portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.

1 May 2026

General

6

Managed Identities Status

Updated

| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|

5 May 2026

Developer

2

Fundamentals

2

Workload identities

Updated

Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.

9 May 2026

Conditional Access Users Groups

Updated

A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.

1 May 2026

Conditional Access

1

Workload Identity

Updated

> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).

1 May 2026

Microsoft identity platform

1

Provisioning

1

Configure Workload Identity Sap Successfactors Provisioning

Updated

2. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in the SAP Cloud Identity Service admin console and returns a short-lived access token that can only be used to query the SAP SuccessFactors OData API.

28 May 2026

General

8

Current Known Limitations

Updated

For usage in US Government community (GCC) cloud, known limitations/disclaimers include:

19 May 2026

Operations Common

Updated

- [Remote Networks operations](how-to-operate-remote-networks.md)

13 May 2026

Fundamentals

6

Connector Groups

Updated

When you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.

19 May 2026

Operations

Updated

- **Platform operations and monitoring engineers** who manage health checks, automation, and dashboards

13 May 2026

Explicit Forward Proxy (preview) session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

8 May 2026

Explicit Forward Proxy

Updated

During the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.

8 May 2026

Bring Your Own Device

Updated

1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).

1 May 2026

Monitoring

1

Operate Microsoft Traffic

Updated

This section is organized in the order you should implement monitoring for Microsoft traffic:

13 May 2026