Month in brief

What changed in July

123 documentation updates and 16 Message Center announcements were tracked during July. Activity centred on General, Authentication, and Fundamentals, with the most changes affecting Entra ID and Global Secure Access.

139 updates by product

Authentication

21

Access Token Claims Reference

Updated

| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |

25 July 2026

General Availability: Microsoft Entra passkeys on Windows

New

Microsoft Entra passkeys on Windows will be generally available from late April 2026, enabling phishing-resistant, passwordless sign-in on Windows devices without explicit opt-in. This supports corporate, personal, and shared devices, with admin controls via Authentication Methods policies and Conditional Access. No action is needed unless blocking is desired.

20 July 2026
Message CenterMC1282568 on mc.merill.net ↗Stay informed

Sign in with a FIDO2 security key

New

Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.

7 July 2026

Register a synced passkey (FIDO2)

Updated

Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.

7 July 2026

Sign in with a synced passkey (FIDO2)

Updated

Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.

7 July 2026

Register Passkey Mobile

Removed

A Microsoft Entra documentation page was updated: Register Passkey Mobile.

7 July 2026

Standards

13

Use Scim To Provision Users And Groups

Updated

|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|

25 July 2026

V2 Howto App Gallery Listing

Updated

- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)

25 July 2026

App Manifest

Updated

Specifies whether this web app can request OAuth2.0 implicit flow ID tokens. The default is false. This flag is used for browser-based apps, like JavaScript single-page apps. We, however, discourage the use of implicit grant even in SPAs and recommend using the [authorization code flow](./v2-oauth2-auth-code-flow.md) with PKCE.

4 July 2026

OAuth 2.0 and OpenID Connect protocols

Updated

Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.

1 July 2026

Enable Scim Api

Updated

- **Cost:** See [API call pricing](https://aka.ms/EntraSCIMAPIPricing).

1 July 2026

Entra Id Scim Api Reference

Updated

Before you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).

1 July 2026

General

11

Admin Control for SSO prompts

New

IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.

16 July 2026

Connect Version History

Updated

This article lists all releases of Microsoft Entra Connect and Azure AD Sync.

8 July 2026

Fundamentals

9

Sms Voice Retirement

Updated

This timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.

31 July 2026

(Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants

New

Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.

20 July 2026
Message CenterMC1221452 on mc.merill.net ↗Major updatePlan for change

Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

New

Microsoft Entra will make passkeys the default authentication method starting September 1, 2026, retiring Microsoft-provided SMS and voice authentication by February 1, 2027. Customers must configure telecom providers for SMS/voice via the Microsoft Security Store or face disruptions. Passkeys offer stronger, phishing-resistant security at no extra cost.

16 July 2026
Message CenterMC1426371 on mc.merill.net ↗Major updatePlan for change

Branding

4

Company Branding Css Template

Updated

Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.

22 July 2026

Provisioning

4

Snowflake Provisioning Tutorial

Updated

With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.

7 July 2026

Troubleshooting

4

Troubleshooting

Updated

- The object or property isn't supported for preview in the current release.

1 July 2026

Developer

3

Connect with the required scope

Updated

After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.

11 July 2026

V2 Protocols Oidc

Updated

1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.

4 July 2026

Monitoring

3

Sla Performance

Updated

| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% | 99.999% |

16 July 2026

Security

2

Connect Health Agent Install

Updated

> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.

29 July 2026

Conditional Access

1

Governance

1

Prerequisites

Updated

- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).

30 July 2026

Microsoft identity platform

1

Access tokens in the Microsoft identity platform

Updated

Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.

18 July 2026

General

1

Agent Owners Sponsors Managers

Updated

In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.

22 July 2026

Fundamentals

2

Risky User Report

Updated

To see risk sign-in events together with risky user events, select the **Aggregate risk signals by risky sign-ins** checkbox.

1 July 2026

Security

1

Id Protection Dashboard

Updated

Microsoft Entra ID Protection provides unified risk signals that aggregate correlated risk signals from Microsoft Entra ID Protection, Microsoft Defender, and other Microsoft security products. Instead of evaluating alerts in isolation, this capability correlates identity-related signals across products and evaluates them together within the same time window to calculate a compounded user risk score.

1 July 2026

Standards

1

Microsoft Purview | Data Loss Prevention - Extend Purview data security to the network layer via Entra GSA integration

New

Microsoft Purview extends data loss prevention to the network layer via integration with Entra Internet Access, enabling inspection and protection of sensitive data in AI interactions and cloud services. It supports policy enforcement, alerts, and auditing, with rollout from July to October 2026, affecting Purview, Entra, and Defender administrators.

20 July 2026
Message CenterMC1419797 on mc.merill.net ↗Major updatePlan for change

Governance

14

Lifecycle Workflow Tasks

Updated

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:

30 July 2026

Customize Workflow Email

Updated

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.

30 July 2026

Interpret tenant discovery data

Updated

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

30 July 2026

Related tenants in Tenant Governance

Updated

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

30 July 2026

Governance Policy Templates

Updated

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

30 July 2026

Lifecycle Workflow Inactive Users

Updated

1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.

16 July 2026

Lifecycle Workflow Templates

Updated

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

16 July 2026

Governance Policy Templates

Updated

Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra

2 July 2026

General

4

Licensing Guest Users

Updated

Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.

8 July 2026

Fundamentals

2

Sms Voice Retirement

Updated

Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.

22 July 2026

Standards

2

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

30 July 2026

Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B

New

SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.

17 July 2026
Message CenterMC1243549 on mc.merill.net ↗Major updatePlan for change

Architecture

1

Gsa Poc Internet Access

Updated

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

22 July 2026

Troubleshooting

1

Troubleshoot

Updated

Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).

7 July 2026

General

2

Configure Explicit Forward Proxy

Updated

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

18 July 2026

Architecture

1

Gsa Poc Internet Access

Updated

1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.

30 July 2026

Authentication

1

Configure a Microsoft Entra Conditional Access policy for Explicit Forward Proxy

Updated

Explicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.

18 July 2026

Conditional Access

1

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

New

Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.

17 July 2026
Message CenterMC1181769 on mc.merill.net ↗Stay informed

Security

4

Microsoft identity platform

2

Workload Identities Github Immutable Subjects

Updated

Replace `<application-object-id>` with the object ID of your app registration. Create one credential for each subject the workflow presents, such as a different branch or environment.

31 July 2026

Workload Identity Federation

Updated

- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.

24 July 2026

General

1

General

8

Global Secure Access egress IP ranges

New

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

24 July 2026

Configure Web Content Filtering

Updated

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

22 July 2026

Configure Web Content Filtering

Updated

- **HTTP method request filtering (preview)**: Block or allow specific HTTP methods, such as GET, POST, PUT, PATCH, and DELETE.

1 July 2026

Fundamentals

5

Explicit Forward Proxy session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

14 July 2026

Proxy Automatic Configuration Files

Updated

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

14 July 2026

Explicit Forward Proxy overview

Updated

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

14 July 2026

Authentication

3

Universal Tenant Restrictions

Updated

- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.

22 July 2026

Configure HTTP header session management (preview)

Updated

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

14 July 2026

Conditional Access

1

Developer

1

Microsoft identity platform

1

Configure Per App Access

Updated

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

24 July 2026

Security

1

Conditional Access

1