Microsoft Entra ID is optimizing passkey registration via Registration Campaign, Authentication Strengths, and My Sign-Ins to improve compliance with passkey policies and prioritize local device passkeys. These changes, rolling out in late August 2026, require no user interface changes or action from organizations.
What changed in July
123 documentation updates and 16 Message Center announcements were tracked during July. Activity centred on General, Authentication, and Fundamentals, with the most changes affecting Entra ID and Global Secure Access.
139 updates by product
Microsoft Entra ID
77 updatesAuthentication
21| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |
Microsoft Entra will enable passwordless users to change their passwords via My Sign-Ins using strong credentials like passkeys or Windows Hello, without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally in late October 2026.
Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.
Microsoft Entra passkeys on Windows will be generally available from late April 2026, enabling phishing-resistant, passwordless sign-in on Windows devices without explicit opt-in. This supports corporate, personal, and shared devices, with admin controls via Authentication Methods policies and Conditional Access. No action is needed unless blocking is desired.
Configure Netskope User Authentication for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication.
Microsoft Entra improves the Microsoft Authenticator passkey restore experience on iOS with a clearer, guided flow for device migration, available worldwide in August 2026. It affects iOS users with iCloud backups, is enabled by default, requires no admin changes, and no action is needed.
Learn how to back up and restore Microsoft Authenticator account entries when you switch to a new phone, including passkey setup steps.
Learn how to register passkeys in Microsoft Authenticator on Android and iOS. Sign in to the app, use Security info, or register cross-device.
Learn how to enable passwordless security key sign-in to Windows with Microsoft Entra ID using FIDO2 security keys.
Learn how to register a passkey with a FIDO2 security key in Microsoft Entra ID. Use Security info or a prompted sign-in flow.
Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.
Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.
Learn how to register a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant sign-in.
Learn how to sign in with a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant authentication.
Learn about synced passkeys in Microsoft Entra ID, including how to configure, register, and sign in with synced passkeys.
Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.
Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.
Learn how to sign in with passkeys in Microsoft Authenticator for Android and iOS. Use same-device, cross-device, or native app authentication.
Register Passkey Mobile
RemovedA Microsoft Entra documentation page was updated: Register Passkey Mobile.
A Microsoft Entra documentation page was updated: Support Authenticator Passkey.
Standards
13Starting June 15, 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Some users may face new challenges like MFA. Most organizations need no action, but custom apps requesting only these scopes should be evaluated.
|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|
V2 Howto App Gallery Listing
Updated- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Azure Databricks using SCIM.
Fortigate Ssl Vpn Tutorial
Updated`https://<FortiGate IP or FQDN address>:<Custom SSL VPN port>/remote/saml/login`.
Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027, replacing them with External MFA for standardized third-party MFA integration. Administrators must migrate policies by September 2026, updating Conditional Access to use External MFA to ensure continued support and security.
Conditional Access enforcement update completed in your tenant
App Manifest
UpdatedSpecifies whether this web app can request OAuth2.0 implicit flow ID tokens. The default is false. This flag is used for browser-based apps, like JavaScript single-page apps. We, however, discourage the use of implicit grant even in SPAs and recommend using the [authorization code flow](./v2-oauth2-auth-code-flow.md) with PKCE.
Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.
Map each Microsoft identity platform OpenID Connect (OIDC) extensibility surface to the configuration article and the Microsoft Graph API resource that programs it.
Sign in Microsoft Entra users by using the Microsoft identity platform's implementation of the OpenID Connect extension to OAuth 2.0.
Enable Scim Api
Updated- **Cost:** See [API call pricing](https://aka.ms/EntraSCIMAPIPricing).
Entra Id Scim Api Reference
UpdatedBefore you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).
General
11Salesforce Tutorial
Updated* Manage your accounts in one central location.
Salesforce Sandbox Tutorial
Updated* Manage your accounts in one central location.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Describes the Microsoft Entra built-in roles and permissions.
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.
Connect Version History
UpdatedThis article lists all releases of Microsoft Entra Connect and Azure AD Sync.
ai-usage: ai-assisted
* [Federated MFA](/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa)
Global Administrator
UpdatedGlobal Administrator
Describes the Microsoft Entra built-in roles and permissions.
A Microsoft Entra documentation page was updated: Entra Customer Lockbox Approver.
Fundamentals
9Sms Voice Retirement
UpdatedThis timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.
Microsoft Entra will make passkeys the default authentication method starting September 1, 2026, retiring Microsoft-provided SMS and voice authentication by February 1, 2027. Customers must configure telecom providers for SMS/voice via the Microsoft Security Store or face disruptions. Passkeys offer stronger, phishing-resistant security at no extra cost.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Microsoft Entra now applies system-preferred authentication to first-factor sign-in for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout starts late June 2026. Tenants can keep or change this setting and should update user guidance accordingly.
Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
Primary Refresh Token
Updated| **Term** | **Description** |
- [Office 365 app in Conditional Access](concept-conditional-access-cloud-apps.md#office-365)
Branding
4Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting October 2026 to enhance security and phishing resistance. Existing users must remove these properties by then, as no migration path exists. Branding elements remain visible but may revert to default placement.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Provisioning
4With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.
Learn how Microsoft Entra Connect matches and synchronizes on-premises objects with an existing Microsoft Entra tenant, and how to resolve hard match conflicts.
> [!NOTE]
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Harness.
Troubleshooting
4> [!NOTE]
Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID.
ai-usage: ai-assisted
Troubleshooting
Updated- The object or property isn't supported for preview in the current release.
Developer
3After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.
V2 Protocols Oidc
Updated1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.
This article shows the new and updated documentation for the Microsoft Entra application management.
Monitoring
3Sla Performance
Updated| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% | 99.999% |
| `logoUrl` | Relocated as a property of the `info` attribute |
How to choose the right method for accessing and integrating the activity logs in Microsoft Entra ID.
Security
2Connect Health Agent Install
Updated> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.
We are announcing the ability to manage users through Microsoft Entra security groups in Dynamics 365 Contact Center. This feature will reach general availability on July 24, 2026.
Conditional Access
1- **Conditional Access**: The new policy evaluated and granted access
Governance
1Prerequisites
Updated- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
Microsoft identity platform
1Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.
Microsoft Entra Agent ID
1 updateGeneral
1In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.
Microsoft Entra ID Protection
4 updatesFundamentals
2Learn how unified risk signals correlate identity risk across Microsoft Entra ID Protection and Microsoft Defender to calculate compounded user risk.
Risky User Report
UpdatedTo see risk sign-in events together with risky user events, select the **Aggregate risk signals by risky sign-ins** checkbox.
Security
1Id Protection Dashboard
UpdatedMicrosoft Entra ID Protection provides unified risk signals that aggregate correlated risk signals from Microsoft Entra ID Protection, Microsoft Defender, and other Microsoft security products. Instead of evaluating alerts in isolation, this capability correlates identity-related signals across products and evaluates them together within the same time window to calculate a compounded user risk score.
Standards
1Microsoft Purview extends data loss prevention to the network layer via integration with Entra Internet Access, enabling inspection and protection of sensitive data in AI interactions and cloud services. It supports policy enforcement, alerts, and auditing, with rollout from July to October 2026, affecting Purview, Entra, and Defender administrators.
Microsoft Entra ID Governance
14 updatesGovernance
14Learn how to use Microsoft Graph to retrieve the underlying users and applications behind Tenant Governance related tenant discovery signals.
Lifecycle Workflow Tasks
UpdatedWith customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:
Customize Workflow Email
UpdatedIn the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
Governance Policy Templates
Updated- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
Tenant Governance Administrator
Learn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.
1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.
Lifecycle Workflow Templates
UpdatedThe **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.
Learn how Microsoft Entra ID is licensed for guest users.
Governance Policy Templates
UpdatedLearn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Microsoft Entra External ID
10 updatesGeneral
4> [!IMPORTANT]
Use the Migration Policy Analyzer to scan Azure AD B2C custom policies and generate a detailed migration assessment for Microsoft Entra External ID. Start your migration today.
Licensing Guest Users
UpdatedGlobal Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.
Learn to migrate from Amazon Cognito to Microsoft Entra External ID with step-by-step guidance, feature mapping, and validation strategies.
Fundamentals
2Sms Voice Retirement
UpdatedPasskey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
Standards
2Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.
Architecture
1Gsa Poc Internet Access
Updated1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
Troubleshooting
1Troubleshoot
UpdatedOrganizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).
Microsoft Entra Internet Access
5 updatesGeneral
2With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).
Learn how to upload and host your own Proxy Auto-Configuration (PAC) files
Architecture
1Gsa Poc Internet Access
Updated1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
Authentication
1Explicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.
Conditional Access
1Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.
Microsoft Entra Workload ID
7 updatesSecurity
4"audiences": ["api://AzureADTokenExchange"]
Learn how to migrate a Microsoft Entra federated identity credential for GitHub Actions from a mutable subject to GitHub's immutable subject format.
Learn how mutable OIDC subject claims expose Microsoft Entra federated identity credentials to subject recycling, and how immutable claims reduce the risk.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
Microsoft identity platform
2Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.
Workload Identity Federation
Updated- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.
General
1Learn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Microsoft Entra Global Secure Access
20 updatesGeneral
8Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
Points Of Presence
Updated| South India | Chennai, India | ✅ | ✅ |
- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.
Learn how to enable the Microsoft traffic profile in Global Secure Access, assign users, install the client, and verify traffic forwarding.
Learn about Microsoft traffic labs for Global Secure Access, including source IP restoration, compliant network checks, and universal tenant restrictions.
Learn how to configure universal tenant restrictions with Global Secure Access for Microsoft traffic.
Fundamentals
5Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).
Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:
External User Access
Updated> [!TIP]
- [Global Secure Access traffic forwarding profiles](concept-traffic-forwarding.md)
Authentication
3- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.
Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.
Conditional Access
1Learn how to configure a Conditional Access policy that requires a compliant network with Global Secure Access.
Developer
1You can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge by using an Intune mobile application management (MAM) policy. The policy can take advantage of the Explicit Forward Proxy feature of Global Secure Access.
Microsoft identity platform
1Configure Per App Access
UpdatedReplace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).
Security
1Discover how to configure network content filtering with Global Secure Access to enforce data protection policies for files and text content in real time.
Security Copilot + Entra
1 updateConditional Access
1Learn how to review and apply suggestions provided by the Security Copilot for Microsoft Entra optimization agent.
