Learn how to install the Microsoft Entra Connect Health agents for Active Directory Federation Services (AD FS) and for sync.
What changed in May
281 documentation updates and 6 Message Center announcements were tracked during May. Activity centred on General, Fundamentals, and Authentication, with the most changes affecting Entra ID and ID Governance.
287 updates by product
Microsoft Entra ID
170 updatesGeneral
47Purpose:
Newauthor: omondiatieno
Purpose:
Newauthor: omondiatieno
Purpose:
Newauthor: omondiatieno
Purpose:
Newauthor: omondiatieno
Groups Create Rule
UpdatedUsing dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).
User Administrator
UpdatedUser Administrator
* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.
Connect Install Roadmap
Updated<a name='download-and-install-azure-ad-connect-health-agent'></a>
Connect Ports
Updated<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>
b. In the **Reply URL** text box, type the URL:
Samsara Tutorial
Updatedb. Copy the link from Post-back/ACS URL field in Samsara into the **Reply URL** text box in Entra ID.
Add Redirect Uri
Updatedmanager: pmwongera
Quickstart Register App
Updatedmanager: pmwongera
Quickstart Register App
Updated1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.
Confluencemicrosoft Tutorial
UpdatedAs of now, following versions of Confluence are supported:
Ensure the following prerequisites are met:
Datawiza Sso Oracle Jde
UpdatedEnsure the following prerequisites are met.
Ensure the following prerequisites are met.
Tutorial Basic Ad Azure
UpdatedThe following are prerequisites required for completing this tutorial
Users Search Enhanced
Updated**User operations**
We have identified that you have activated early access to the Entra Group control for model-driven app in-app skills in Power Apps and/or Dynamics 365 Apps. On May 21, 2026, we will switch this feature to a new underlying service in preparation for general availability.
author: kenwith
author: kenwith
Licensing Change
Updatedauthor: kenwith
Licensing Pim
Updatedauthor: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
include file
Updatedinclude file
Include file
UpdatedInclude file
author: kenwith
author: kenwith
Licensing Roles
Updatedauthor: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
21782
RemovedA Microsoft Entra documentation page was updated: 21782.
Create New Tenant
RemovedA Microsoft Entra documentation page was updated: Create New Tenant.
Create New Tenant
RemovedA Microsoft Entra documentation page was updated: Create New Tenant.
Entra Msi Tut Prereqs
RemovedA Microsoft Entra documentation page was updated: Entra Msi Tut Prereqs.
Service Dependencies
Updated| | Microsoft Stream | Late-bound |
Fundamentals
37Whats New
Updated**Type:** New feature
Learn about cross-tenant synchronization in Microsoft Entra ID.
Learn about device soft delete (preview) in Microsoft Entra ID, which moves deleted devices to a recoverable state instead of permanently removing them.
Learn about device soft delete in Microsoft Entra ID, which moves deleted devices to a recoverable state instead of permanently removing them.
| **AADSTS500183: Certificate has been revoked. Please contact your administrator** | An Authentication attempt failed because the client device presented a certificate that was revoked by the issuing CA. | The certificate used for authentication is found in the Certificate Revocation List (CRL) or flagged as revoked by the CA. | - Tenant Administrator should ensure the new certificate is correctly provisioned and trusted by Microsoft Entra ID.<br/>- Verify that the CRLs and delta CRLs published by your CA are up to date and accessible for the devices. |
Sspr Policy
Updated| Compliance Administrator | Knowledge Administrator | Teams Communications Administrator |
Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both primary and multifactor authentication.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled |
Native Authentication
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
Whats New Archive
Updated**Service category:** MFA
Fido2 Compatibility
Updated- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
Instructions for IT admins to create new users, invite external guests, and delete existing users in Microsoft Entra ID.
Entra Admin Center
Updated| Task | Description | Learn more |
Users Restore
UpdatedYou can permanently delete a user from your organization without waiting the 30 days for automatic deletion. A permanently deleted user can't be restored by anyone, including Microsoft customer support.
Add Custom Domain
Updated- [How to assign roles and administrators](./how-subscriptions-associated-directory.md)
Connect Pta Quick Start
Updated1. Create a cloud-only Hybrid Identity Administrator account or a Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.
Create New Tenant
Updated- To change or add other domain names, see [How to add a custom domain name to Microsoft Entra ID](add-custom-domain.md).
Delegate By Task
UpdatedHere are the least privileged roles you should use when performing tasks for [users](../../fundamentals/how-to-create-delete-users.md) in Microsoft Entra ID.
See [How to create, invite, and delete users](../../fundamentals/how-to-create-delete-users.md).
Manage User Profile Info
Updated- [Add or delete users](how-to-create-delete-users.md)
- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)
Prerequisites
Updated1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant if your on-premises services fail or become unavailable. Learn about how to [add a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Finishing this step is critical to ensure that you don't get locked out of your tenant.
Sspr Deploy
UpdatedTo ensure that your deployment works as expected, plan a set of test cases to validate the implementation. To assess the test cases, you need a non-administrator test user with a password. If you need to create a user, see [Add new users to Microsoft Entra ID](~/fundamentals/how-to-create-delete-users.md).
Tutorial Enable Sspr
Updated* A working Microsoft Entra tenant with at least a Microsoft Entra ID P1 license is required for password reset. For more information about license requirements for password change and password reset in Microsoft Entra ID, see [Licensing requirements for Microsoft Entra self-service password reset](concept-sspr-licensing.md).
Tutorial Existing Forest
Updated1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.
Users Default Permissions
Updated* To learn more about how to assign Microsoft Entra administrator roles, see [Assign a user to administrator roles in Microsoft Entra ID](./how-subscriptions-associated-directory.md).
- [Add or delete users](./how-to-create-delete-users.md)
Fido2 Compatibility
Updated- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Fido2 Hardware Vendor
UpdatedACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌
Users Default Permissions
Updated| Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul> |
Security Defaults
UpdatedAs part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.
By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.
Whats New
Updated**Service category:** User Experience and Management
In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.
- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)
Authentication
29Mfa Registration Campaign
UpdatedFor example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome, they're nudged because that credential doesn't apply to that platform.
Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.
This document describes how to integrate AD FS sign-ins with the Microsoft Entra Connect Health sign-ins report.
Connect Pta
Updated- Installing multiple agents provides high availability of sign-in requests.
Authenticate Application Id
Updated|**Automatic rotation enabled**|Whether automatic rotation or manual rotation is enabled|
Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
Learn how to migrate from custom controls to external multifactor authentication in Microsoft Entra Conditional Access.
- Devices must support passkey (FIDO2) authentication. For Windows devices that are joined to Microsoft Entra ID, the best experience is on Windows 10 version 1903 or higher. Hybrid-joined devices must run Windows 10 version 2004 or higher.
If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
Native Authentication Api
UpdatedMicrosoft Entra determines the default MFA method for the user by priority as follows:
- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.
Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.
Remote desktop connection guidance to deploy passwordless and phishing-resistant authentication for organizations that use Microsoft Entra ID.
Account Recovery Enable
Updated- **Exact** — Claims must match exactly.
Tutorial Enable Azure Mfa
Updated* An account with at least the [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role. Some MFA settings can also be managed by an [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator).
Quickstart Analyze Sign In
Updated- An Azure subscription. If you don't have one, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
* If needed, [create one for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
During account recovery, a user who has lost all authentication methods must re-establish their identity. The custom authentication extension adds a claim validation step into this flow:
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
Use cloud authentication
Updatedauthor: kenwith
author: kenwith
1. Ensure the application is accessible. Sign in directly from the browser on the connector host using the internal URL defined in the Azure portal. If the sign-in succeeds, the application is accessible.
Developer
9Managed Policies
UpdatedDevice code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.
Entra Service Limits Include
Updated| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li> Only the "equals" operator is supported for DateTime-type extensions. Range operators like "greater than" or "less than" are not supported.</li></ul> |
author: kenwith
author: kenwith
author: kenwith
Restrict device code flow
Updatedauthor: kenwith
Licensing Application Proxy
RemovedA Microsoft Entra documentation page was updated: Licensing Application Proxy.
>
* [Configure group claims for applications by using Microsoft Entra ID](../hybrid/connect/how-to-connect-fed-group-claims.md)
Monitoring
9Describes the Microsoft Entra Connect Health AD FS risky IP report with Azure Monitor Workbooks.
This is the Microsoft Entra Connect Health page how to monitor your on-premises AD FS infrastructure.
This is the Microsoft Entra Connect Health page that discusses how to monitor Microsoft Entra Connect Sync.
The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.
Plan Cloud Sync Topologies
Updated> [!IMPORTANT]
Security Audit Events
UpdatedView all Kerberos ticket-granting (event ID 4768) and service ticket (event ID 4769) events that used RC4 encryption in the last seven days, to identify workloads and service accounts that still rely on RC4:
> [!NOTE]
author: kenwith
Entra Service Limits Include
Updated| Reports | A maximum of 1,000 rows can be viewed or downloaded in any report. Any additional data is truncated. |
Security
7Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Entra Agents
Updated- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
author: kenwith
author: kenwith
author: kenwith
There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
Microsoft identity platform
6Mfa Authenticator Lite
Updated- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
To complete the scenario in this quickstart, you need:
author: kenwith
author: kenwith
author: kenwith
Frontline Worker Management
UpdatedFrontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).
Provisioning
6Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).
The scenario outlined in this article assumes that you already have the following prerequisites:
This article describes the steps you need to perform in both Atlassian Cloud and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Atlassian Cloud](https://www.atlassian.com/cloud) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).
Licensing App Provisioning
Updatedauthor: kenwith
Jive Provisioning Tutorial
UpdatedThis section guides you through connecting your Microsoft Entra ID to Jive's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in Jive based on user and group assignment in Microsoft Entra ID.
Standards
6External access tokens for actionable messages will be retired by May 15, 2026, replaced by Microsoft Entra authentication to enhance security. Organizations must update integrations before this date, as messages using legacy tokens will fail. The phase-out completes by June 8, 2026.
author: dhivyagana
| IA.L2-3.5.5<br><br>**Practice statement:** Prevent reuse of identifiers for a defined period.<br><br>**Objectives:**<br>Determine if:<br>[a.] a period within which identifiers can't be reused is defined; and<br>[b.] reuse of identifiers is prevented within the defined period. | All user, group, device object globally unique identifiers (GUIDs) are guaranteed unique and non-reusable for the lifetime of the Microsoft Entra tenant.<br>[user resource type - Microsoft Graph v1.0](/graph/api/resources/user?view=graph-rest-1.0&preserve-view=true)<br>[group resource type - Microsoft Graph v1.0](/graph/api/resources/group?view=graph-rest-1.0&preserve-view=true)<br>[device resource type - Microsoft Graph v1.0](/graph/api/resources/device?view=graph-rest-1.0&preserve-view=true) |
Fedramp Access Controls
Updated| FedRAMP Control ID and description | Microsoft Entra guidance and recommendations |
Hipaa Access Controls
Updated| Recommendation | Action |
Conditional Access
5- Contractors are governed by their own policies separate from the baseline
Learn how custom controls in Microsoft Entra Conditional Access work.
- After the agent starts, you can't stop or pause the run. It might take a few minutes to run.
Plan Conditional Access
Updated- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)
author: kenwith
Architecture
4Migrate Adfs Apps Stages
UpdatedDuring the process of moving your app authentication to Microsoft Entra ID, test your apps and configuration. We recommend that you continue to use existing test environments for migration testing before you move to the production environment. If a test environment isn't currently available, you can set one up using [Azure App Service](https://azure.microsoft.com/services/app-service/) or [Azure Virtual Machines](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn), depending on the architecture of the application.
Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
Recoverability Overview
Updated- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
Troubleshooting
3Hr User Update Issues
UpdatedLearn how to troubleshoot user update issues with HR provisioning
Error Codes
Updated| Error | Description |
author: kenwith
Branding
2Get Started Premium
UpdatedNow that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.md).
Customize Branding
Updated:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::
Microsoft Entra Agent ID
27 updatesGeneral
12- Maximum of 50 resource apps per agent identity blueprint (for example, up to 50 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.
Owners usually serve as technical administrators for agents, handling operational and configuration aspects. Individual users (including guest users) and service principals can be set as owners. Groups aren't supported as owners. Service principals as owners enable automated management of agent identities. Owners are optional for agent identity blueprints and agent identities.
Agent Id Ai Guided Setup
UpdatedIf you have the GitHub Copilot for Azure extension installed, ask Copilot to set up Agent ID. For example:
Whats New Agent Id
UpdatedThis article summarizes the key capabilities and documentation currently available.
Agent Lists
UpdatedAccess Microsoft Entra admin center to view and filter agent identities. Streamline tenant oversight with search, filters, and column customization.
The Microsoft Entra admin center provides a centralized interface to view all agent identities in your tenant. You can search, filter, sort, and customize columns to find specific agents.
This article explains how to manage registry-only agents that don't have associated agent identities in Microsoft Entra ID.
Learn how to manage agent identities in the end user experience within Microsoft Entra. View, control, and take action on agents you own or sponsor with ease.
Agent Id Ai Guided Setup
Updatedauthor: arlucaID
Learn how to grant access to agents through consent, manual authorization, and other authorization systems for Microsoft 365 resources.
Learn how to add and manage owners and sponsors for agent identity blueprints and agent identities in the Microsoft Entra admin center.
Disable Agent Identities
Updated- Existing agents running in your organization might begin to fail.
Fundamentals
4Agent Identity Deletion
Updatedauthor: shlipsey3
Security For Ai Overview
Updated- Ensure sponsors and owners are assigned and maintained for each agent identity, preventing orphaned agent identities.
Understand the difference between required resource access declarations and inheritable permissions for agent identity blueprints in Microsoft Entra Agent ID.
Whats New Ignite 2025
Updated- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)
Governance
3Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.
Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.
This article explains how access packages provide governance for agent identity access to resources.
Authentication
2Microsoft Entra Agent ID enables AI agents from third-party platforms to authenticate and access your APIs securely without handling credentials directly. This article covers two integration patterns - the Microsoft Entra Auth SDK (sidecar) and federation - for platforms such as Amazon Web Service (AWS) Bedrock and n8n.
Learn how audit and sign-in activities associated with agent identities are logged in Microsoft Entra ID.
Conditional Access
2Learn how Conditional Access for agent identities in Microsoft Entra ID extends Zero Trust principles to AI agents, ensuring secure access and governance.
Licensing Agent Id
Updated- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.
Microsoft identity platform
2We’re introducing a new feature in public preview, Dataverse Agent users, powered by Microsoft Entra Agent ID. Rollout of this feature will start on May 4, 2026, and is expected to reach North America by May 22, 2026.
Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.
Security
1Learn how to manage agent identity blueprints in the Microsoft Entra admin center, including viewing permissions, managing credentials, and configuring owners and sponsors.
Standards
1Learn how to configure inheritable permissions for agent identity blueprints to automatically grant OAuth 2.0 delegated permission scopes and application roles to agent identities.
Microsoft Entra ID Protection
2 updatesArchitecture
1- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)
Conditional Access
1Deploy Identity Protection
Updated* Create or modify Conditional Access policies
Microsoft Entra ID Governance
30 updatesGovernance
26Migrate From Sap Idm
UpdatedIn SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.
1. Browse to **ID Governance** > **Entitlement management** > **Access packages**.
Learn how to view, add, and remove assignments for an access package in entitlement management.
Lifecycle Workflow Tasks
UpdatedLifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.
Learn how Microsoft Entra Tenant Governance automatically establishes governance relationships when you create add-on tenants using secure tenant creation.
Learn about configuration management capabilities in Microsoft Entra Tenant Governance, including baselines and drift monitoring
Learn how to create a new Microsoft Entra tenant using the secure add-on tenant creation workflow in Tenant Governance
Create a monitor (preview)
UpdatedLearn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization
Learn about governance relationships and how they enable centralized management of tenants in Microsoft Entra Tenant Governance
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn which Microsoft Entra Tenant Governance features are available with each license tier, including P1, P2, and ID Governance
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn how to view monitor results and detect configuration drifts in Microsoft Entra Tenant Governance using the admin center
Learn how to set up the required application permissions and roles for tenant monitoring in Microsoft Entra Tenant Governance
Learn about the signals and metrics used in Microsoft Entra Tenant Governance to identify and evaluate related tenants
Learn how to terminate a governance relationship between tenants in Microsoft Entra Tenant Governance and understand what resources are removed
Learn how to update an existing governance relationship between a governing and governed tenant in Microsoft Entra Tenant Governance
Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change
Learn about cross-tenant delegated administration and how it enables centralized management across tenants in Microsoft Entra
Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Learn how to set up a governance relationship between a governing and governed tenant using the handshake process in Microsoft Entra
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
**May**:
Pim How To Add Role To User
Updated1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.
Fundamentals
3Licensing Fundamentals
UpdatedAccount Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).
Identity Governance Overview
UpdatedMicrosoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
Learn about Microsoft Entra Tenant Governance and how it helps organizations discover, manage, and govern tenants across their environment
Authentication
1Learn how to monitor and audit governing tenant administrator activity in your governed tenant using sign-in and audit logs
Microsoft Entra External ID
16 updatesAuthentication
4Learn how to attach custom x-* headers to native authentication requests in a React or Angular SPA to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an iOS (Swift) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an Android (Kotlin) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain signed in across browser sessions. If they select **No**, a non-persistent cookie is issued.
General
3|---------|-------|
User Permissions
UpdatedTo better understand the typical use cases for users in an external tenant, we can categorize them as follows:
In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.
Fundamentals
2Supported Features Customers
Updated| Feature | Workforce tenant | External tenant |
Manage Admin Accounts
UpdatedUse the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How to create users](~/fundamentals/how-to-create-delete-users.md#create-a-new-user).)
Provisioning
2::: zone pivot="same-cloud-synchronization"
- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you might want to continue using your existing Microsoft Entra cross-tenant synchronization jobs.
Standards
2Direct Federation
Updated1. On the **New SAML/WS-Fed IdP** page, enter the following:
Direct Federation
UpdatedTo enable domainless federation for a new SAML IdP, follow these steps:
Branding
1An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user account is automatically created in the external tenant. For more information, see [Create a sign-up and sign-in user flow for customers](how-to-user-flow-sign-up-sign-in-customers.md).
Microsoft identity platform
1Microsoft Entra will enforce stricter federatedTokenValidationPolicy by default starting mid-August 2026, blocking federated sign-ins when internalDomainFederation doesn't match the user's UPN domain. This affects tenants with federated domains configured before December 2025 and aims to enhance security against cross-domain sign-in risks.
Monitoring
1Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.
Microsoft Entra Internet Access
2 updatesFundamentals
1What Is Global Secure Access
Updated| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |
General
1Operate Internet Access
Updated| Alert | Condition | Role | Automated by | What to do next |
Microsoft Entra Private Access
5 updatesGeneral
4Post-deployment operations guide for Microsoft Entra Private Access, the Zero Trust network access (ZTNA) capability, covering alerting, health checks, integration, automation, and operational metrics.
Private Access Health Check
Updated| # | Check | How | Status | What to do if it fails |
Licensing Guest Users
UpdatedGuest users are only billed when they actively sign in to the Global Secure Access client for Private Access.
Intelligent Local Access capability can help optimize the traffic flow from Microsoft Entra clients to Microsoft Entra Private Access apps when the client is on a corporate/private network. This article explains how to enable the Intelligent Private Network for Microsoft Entra Private Access.
Monitoring
1Operate Private Access
Updated| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |
Microsoft Entra Verified ID
7 updatesGeneral
3Using Facecheck
UpdatedFace Check is a premium feature within Verified ID. If you're a Microsoft Entra Suite customer, Face Check is included as part of the Suite. If you're not using Microsoft Entra Suite, you need to enable the Face Check Add-on in your Microsoft Entra Verified ID setup before doing Face Check verifications.
Whats New
Updated- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.
Licensing Verified Id
Updatedauthor: kenwith
Security
2Learn how to set up and use Face Check with Microsoft Entra Verified ID for high-assurance facial matching verifications that protect user privacy at enterprise scale.
Using Facecheck
Updated"requestedCredentials": [
Fundamentals
11. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.
Troubleshooting
1Register Didwebsite
UpdatedThe portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.
Microsoft Entra Workload ID
13 updatesGeneral
6Before you begin, ensure you have the following:
Documentation for the Azure Policy that can be used to assign managed identities to Azure resources.
Licensing Managed Identities
Updatedauthor: kenwith
author: kenwith
Managed Identities Status
Updated| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
Developer
21. Under **Assignments**, select **Users or workload identities**.
author: kenwith
Fundamentals
2Workload identities
UpdatedUnderstand the concepts and supported scenarios for using workload identity in Microsoft Entra.
A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.
Conditional Access
1Workload Identity
Updated> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).
Microsoft identity platform
1Microsoft Entra ID will enable App Instance Lock by default for new applications starting June 2026, protecting sensitive properties from unauthorized changes outside the home tenant. Existing apps are unaffected. Admins can disable the lock if needed. Review and update automation or scripts accordingly before rollout.
Provisioning
12. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in the SAP Cloud Identity Service admin console and returns a short-lived access token that can only be used to query the SAP SuccessFactors OData API.
Microsoft Entra Global Secure Access
15 updatesGeneral
8Current Known Limitations
UpdatedFor usage in US Government community (GCC) cloud, known limitations/disclaimers include:
Change Request Template
Updated**Affected Global Secure Access capability:**
Operations Common
Updated- [Remote Networks operations](how-to-operate-remote-networks.md)
Operate Remote Networks
Updated| Alert | Condition | Role | What to do next |
Communication Plan
Updated- Prechange notification drafted and reviewed
Daily Health Check
Updated| # | Check | Status | What to do if it fails |
Install Android Client
Updated| Configuration key | Value | Details |
Install Ios Client
Updated|Key |Value |Details |
Fundamentals
6@{ Key="HKLM:\SOFTWARE\Policies\Microsoft\Edge"; Name="BuiltInDnsClientEnabled"; Type="DWord"; Value=0 },
Connector Groups
UpdatedWhen you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.
Operations
Updated- **Platform operations and monitoring engineers** who manage health checks, automation, and dashboards
Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
Explicit Forward Proxy
UpdatedDuring the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.
Bring Your Own Device
Updated1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).
Monitoring
1Operate Microsoft Traffic
UpdatedThis section is organized in the order you should implement monitoring for Microsoft traffic:
