Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
August 2026
August 2026: public-cloud SMS/voice MFA gets a retirement timetable as Entra governance and architecture guidance expand
The period’s clearest operational change is updated Microsoft Entra ID guidance stating that passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, public-cloud tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA; Azure AD B2C and Microsoft Entra External ID are excluded. The remaining updates are primarily Microsoft Learn guidance: expanded Tenant Governance procedures, a new tenant-estate architecture series, and broader Global Secure Access and provisioning documentation. A licensing reference was also refreshed, including Agent 365 and revised service-plan identifiers. There were no Message Center notices or removals, and the new pages do not by themselves establish a product launch or general availability.
- SMS and voice MFA receive an explicit public-cloud retirement pathEntra ID
The updated Entra ID guidance says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. Beginning February 1, 2027, tenants without a customer-managed telecom provider will not be able to use SMS or voice for MFA. The scope is public cloud; Azure AD B2C and Entra External ID are excluded. This is retirement and behavior-change guidance, not a stated new feature or GA announcement.
- Tenant Governance documentation now covers snapshots, drift monitoring, and service permissionsID Governance
A new article documents configuration snapshots for baselines or audit evidence. Related updates describe creating monitors, viewing results and configuration drift, deploying Tenant Governance end to end, and assigning the application permissions and roles used by the Tenant Configuration Management service. These changes expand the operating guidance for Microsoft Entra Tenant Governance but do not, on the supplied evidence, establish a separate launch or availability milestone.
- A new tenant-estate architecture guidance set organizes common Entra patternsEntra ID
New guidance covers primary and collaborating production tenants, nonproduction multitenant environments, business-partner access, critical business systems, and hybrid identity and isolation, alongside an introduction to composing an estate from common patterns. The stated aim is to meet requirements with as few tenants as possible. This is architecture and planning guidance rather than a documented change to tenant behavior or a required topology.
- Internet Access guidance adds coexistence and a more detailed traffic-policy modelInternet Access
A new page explains how Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps can coexist without proxying traffic twice. The updated Internet Access profile guidance now describes forwarding through the Global Secure Access client and remote networks, six policies rather than three, Microsoft Traffic Bypass, Custom Acquire, Agentic Acquire, and custom-bypass settings for destinations, ports, and protocols. The evidence identifies documentation and configuration clarification, not a launch or GAสถาน
- Provisioning extensibility is documented with a preview-labeled workflowEntra ID
The Entra ID attribute-extensibility guidance now explains creating custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is explicitly labeled Preview, and related attribute-customization guidance links to LCW extensibility workflows. Administrators can use the documented Graph procedures, but the update does not establish general availability.
For public-cloud Entra ID, identify users who rely on SMS or voice and plan a transition before September 1, 2026. Supported options in the updated guidance include moving users out of SMS or voice policies, using the temporary opt-out, configuring a customer-managed telecom provider, or migrating users to another method before the February 1, 2027 cutoff. Teams using Tenant Governance, Internet Access, or provisioning extensibility should review the corresponding permissions and configuration procedures. Administrators whose licensing automation uses APIs, PowerShell, or CSV data should check the revised product and service-plan identifiers.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
24 updates by product
Microsoft Entra ID
14 updatesArchitecture
8Learn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for nonproduction environments so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for primary production tenants so that you can identify your needs and compare architectural options.
Learn how to compose your Microsoft Entra tenant estate from common tenant architecture patterns so that you can meet your requirements with as few tenants as possible.
Learn about Microsoft Entra tenant architecture for business partner access so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for critical business systems so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for hybrid identity and isolation so that you can identify your needs and compare architectural options.
Provisioning
3The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.
The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.
> [!NOTE]
Fundamentals
2Sms Voice Retirement
UpdatedThe updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Developer
1The reference now links to license management in the Azure portal, updates the table as of August 3, 2026, adds Agent 365, and revises service and plan identifier entries.
Microsoft Entra ID Governance
8 updatesGovernance
8Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence
Learn how to view monitor results and configuration drifts and manage configuration monitors in Microsoft Entra Tenant Governance
Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift
This article walks you through managing unsponsored guests using the **Unsponsored guest cleanup (Preview)** workflow template.
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to assign or remove the application permissions and roles that the Tenant Configuration Management service uses to create snapshots and run monitors
Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.
When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.
Microsoft Entra Internet Access
2 updatesGeneral
2The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.
Learn how to configure Microsoft Entra Internet Access and Microsoft Defender for Cloud Apps side by side without proxying traffic twice.
