Customize Application Attributes
The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra ID.
Microsoft Learn documentation ↗The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.
The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.
The reference now links to license management in the Azure portal, updates the table as of August 3, 2026, adds Agent 365, and revises service and plan identifier entries.
The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.
Learn about Microsoft Entra tenant architecture for collaborating production tenants so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for hybrid identity and isolation so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for nonproduction environments so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for primary production tenants so that you can identify your needs and compare architectural options.
Learn how to compose your Microsoft Entra tenant estate from common tenant architecture patterns so that you can meet your requirements with as few tenants as possible.
Learn about Microsoft Entra tenant architecture for business partner access so that you can identify your needs and compare architectural options.
Learn about Microsoft Entra tenant architecture for critical business systems so that you can identify your needs and compare architectural options.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.
Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting October 2026 to enhance security and phishing resistance. Existing users must remove these properties by then, as no migration path exists. Branding elements remain visible but may revert to default placement.
This timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.
Starting June 15, 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Some users may face new challenges like MFA. Most organizations need no action, but custom apps requesting only these scopes should be evaluated.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
> If you have a highly locked-down and restricted environment, you need to add more URLs than the URLs the table lists for Internet Explorer enhanced security. Also add URLs that are listed in the table in the next section.
Microsoft Entra ID is optimizing passkey registration via Registration Campaign, Authentication Strengths, and My Sign-Ins to improve compliance with passkey policies and prioritize local device passkeys. These changes, rolling out in late August 2026, require no user interface changes or action from organizations.
| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |
|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|
- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Azure Databricks using SCIM.
`https://<FortiGate IP or FQDN address>:<Custom SSL VPN port>/remote/saml/login`.
Microsoft Entra will enable passwordless users to change their passwords via My Sign-Ins using strong credentials like passkeys or Windows Hello, without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally in late October 2026.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.
Microsoft Entra passkeys on Windows will be generally available from late April 2026, enabling phishing-resistant, passwordless sign-in on Windows devices without explicit opt-in. This supports corporate, personal, and shared devices, with admin controls via Authentication Methods policies and Conditional Access. No action is needed unless blocking is desired.
Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.
Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.
Microsoft Entra will make passkeys the default authentication method starting September 1, 2026, retiring Microsoft-provided SMS and voice authentication by February 1, 2027. Customers must configure telecom providers for SMS/voice via the Microsoft Security Store or face disruptions. Passkeys offer stronger, phishing-resistant security at no extra cost.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.
Microsoft Entra improves the Microsoft Authenticator passkey restore experience on iOS with a clearer, guided flow for device migration, available worldwide in August 2026. It affects iOS users with iCloud backups, is enabled by default, requires no admin changes, and no action is needed.
- **Conditional Access**: The new policy evaluated and granted access
We are announcing the ability to manage users through Microsoft Entra security groups in Dynamics 365 Contact Center. This feature will reach general availability on July 24, 2026.
Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027, replacing them with External MFA for standardized third-party MFA integration. Administrators must migrate policies by September 2026, updating Conditional Access to use External MFA to ensure continued support and security.
Microsoft Entra now applies system-preferred authentication to first-factor sign-in for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout starts late June 2026. Tenants can keep or change this setting and should update user guidance accordingly.
This article lists all releases of Microsoft Entra Connect and Azure AD Sync.
Learn how to back up and restore Microsoft Authenticator account entries when you switch to a new phone, including passkey setup steps.
Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID.
Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.
Learn about synced passkeys in Microsoft Entra ID, including how to configure, register, and sign in with synced passkeys.
Learn how to enable passwordless security key sign-in to Windows with Microsoft Entra ID using FIDO2 security keys.
* [Federated MFA](/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa)
Learn how to register a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant sign-in.
Learn how to register a passkey with a FIDO2 security key in Microsoft Entra ID. Use Security info or a prompted sign-in flow.
Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.
A Microsoft Entra documentation page was updated: Register Passkey Mobile.
Learn how to register passkeys in Microsoft Authenticator on Android and iOS. Sign in to the app, use Security info, or register cross-device.
Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.
Learn how to sign in with a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant authentication.
Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.
Learn how to sign in with passkeys in Microsoft Authenticator for Android and iOS. Use same-device, cross-device, or native app authentication.
With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.
A Microsoft Entra documentation page was updated: Support Authenticator Passkey.
Conditional Access enforcement update completed in your tenant
Specifies whether this web app can request OAuth2.0 implicit flow ID tokens. The default is false. This flag is used for browser-based apps, like JavaScript single-page apps. We, however, discourage the use of implicit grant even in SPAs and recommend using the [authorization code flow](./v2-oauth2-auth-code-flow.md) with PKCE.
| `logoUrl` | Relocated as a property of the `info` attribute |
1. Under Redirect URIs, add the redirect URI of your application. For example, `https://localhost:8080/`.
Learn how Microsoft Entra Connect matches and synchronizes on-premises objects with an existing Microsoft Entra tenant, and how to resolve hard match conflicts.
This article shows the new and updated documentation for the Microsoft Entra application management.
A Microsoft Entra documentation page was updated: Entra Customer Lockbox Approver.
- [Office 365 app in Conditional Access](concept-conditional-access-cloud-apps.md#office-365)
How to choose the right method for accessing and integrating the activity logs in Microsoft Entra ID.
Learn how to configure Microsoft Entra ID to automatically provision and deprovision user accounts to Harness.
Before you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).
Map each Microsoft identity platform OpenID Connect (OIDC) extensibility surface to the configuration article and the Microsoft Graph API resource that programs it.
Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.
Sign in Microsoft Entra users by using the Microsoft identity platform's implementation of the OpenID Connect extension to OAuth 2.0.
- The object or property isn't supported for preview in the current release.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Visa Spend Clarity for Enterprise.
Microsoft Entra will block new assignments to Partner Tier1 and Tier2 Support roles starting August 3, 2026, as these roles are retired. Existing assignments remain valid. Admins should update scripts and use alternative roles like User Administrator. No impact if these roles aren't used.
.\Set-CloudSyncSOAPolicy.ps1 -EnforcementMode Audit -Credential (Get-Credential -Message "Enter Domain Admin credentials (format: DOMAIN\Username)")
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AlertMedia.
The What's new release notes in the Overview section of this content set contain six months of activity. After six months, the items are removed from the main article and put into this archive article.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Atlassian Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AuditBoard.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to ThousandEyes.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bentley - Automatic User Provisioning.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BIC Cloud Design.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to BlogIn.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Boxcryptor.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Bpanda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BrowserStack Single Sign-on.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to BullseyeTDP.
A Microsoft Entra documentation page was updated: Certificate Based Authentication Certificate Revocation List.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to CheckProof.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Cisco User Management for Secure Access.
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Clarizen One.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Clebex.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to QA.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Coda.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Code42.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Acunetix 360.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (OIDC).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML).