The article updates navigation and steps for email notifications, server or service deletion, and role-based access control, with new screenshots.
Microsoft Entra sets passkeys as default and schedules Microsoft-provided SMS and voice retirement
Authentication drove the week: passkeys became Microsoft Entra’s default authentication on September 1, 2026, while Microsoft-provided SMS and voice authentication now has staged 2027 retirement dates. Other substantive updates cover first-MFA passkey registration, an October B2B passkey rollout, browser handoff guidance for External ID, and preview Continue Evaluation behavior in Web Filtering (v2). Much of the remaining activity was maintenance to Connect and Connect Health navigation, screenshots, release-history links, and terminology.
- Microsoft-provided SMS and voice get staged 2027 retirement deadlines
Entra ID · Authentication
Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow July 1, 2027; users whose only MFA method is SMS or voice receive a blocking passkey-registration prompt after their applicable date.
- Passkey or passwordless registration can be the first MFA method
Entra ID · Conditional Access
Users can register a passkey or passwordless sign-in as their first multifactor authentication method instead of setting up weaker methods first. The rollout is phased from October 2026 through February 2027.
- B2B users gain resource-tenant passkey registration and sign-in
Entra ID · Conditional Access
Passkey registration and sign-in for B2B users is scheduled to begin rolling out in October 2026. Eligible users are automatically enabled, with resource-tenant passkeys providing phishing-resistant MFA.
- External ID guidance covers browser handoff for brokered external-IdP sign-in
External ID · Authentication
The new guidance describes handing external-IdP authentication from an embedded WebView to the system browser, supporting external-IdP passkeys, browser SSO, and identity providers that block WebViews. It lists supported platforms, brokers, versions, apps, and cloud availability.
- Web Filtering (v2) guidance specifies preview Continue Evaluation behavior
Internet Access · Fundamentals
With Continue Evaluation as the default action, unmatched traffic can pass to the next applicable security profile. Matching rules and Allow or Block stop evaluation, while the Baseline Profile must use Allow or Block.
Identify users dependent on SMS or voice and move them to phishing-resistant methods before their applicable deadline; if those methods must remain, use a customer-managed telecom provider. Review B2B authentication policies before the October rollout, although Microsoft says no immediate action is required. For External ID, check the supported browser, broker, app, platform, federation, and cloud combinations before adoption. In Web Filtering (v2), review default actions and keep the Baseline Profile set to Allow or Block.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
61 updatesConnect Health Adfs
Doc updateThe documentation now describes the AD FS service overview, updated alert filtering and details, and the revised Usage Analytics experience with time-range controls. Screenshots and metadata were also refreshed.
Connect Health Data Retrieval
Doc updateThe guide now uses the Microsoft Entra Connect Health Sync errors area to access notification settings, review Global Administrator and custom recipients, and export recorded sync errors as a CSV from the command bar.
The page now explains selecting an alert row to view its details, including detection times, affected servers, resolution guidance, and related documentation. It also replaces the alert screenshot and improves image descriptions.
Connect Version History
Feature updateThe documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.
Connect Version History
New featureAction requiredThe 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.
Connect Version History
Doc updateThe entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.
Connect Version History
Doc updateThe version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.
Connect Version History
Doc updateAction requiredThe documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.
Connect Version History
Doc updateAction requiredThe documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.
Connect Version History
Doc updateThe documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.
Connect Version History
Doc updateFour references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.
Connect Version History
Feature updateThe documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.
Connect Version History
Doc updateAction requiredThe documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.
Connect Version History
Doc updateThe documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.
Using single sign-on with cloud sync
Doc updateThe article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.
Migrate Microsoft Entra Enterprise State Roaming
RetirementAction requiredAs of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.
Validate Oidc Multitenant App Gallery
Doc updateAction requiredThe documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.
Configure
Doc updateThe configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.
Sspr Policy
Doc updateThe SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
RetirementAction requiredMicrosoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.
Sms Voice Retirement
RetirementAction requiredThe documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.
A how-to article explains how to enable FIDO2 and passkey methods, register credentials, configure a registry setting, and sign in to Microsoft Entra Connect Sync without a password.
The procedure now uses revised Microsoft Entra Connect paths and module-import commands, including the ADSync module and the AzureADSSO module. Step numbering and wording were also updated.
Howto Sspr Windows
Doc updateThe instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.
Connect Version History
Doc updateThe Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.
Authentication
Doc updateThe authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.
Connect Passwordless Authentication
Doc updateThe documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.
The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.
Connect Version History
Doc updateAction requiredThe documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.
Connect Version History
Doc updateThe version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.
Connect Version History
Doc updateThe version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.
Connect Version History
Doc updateThe Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.
The documentation now distinguishes Microsoft-managed and enabled campaigns. It specifies the MFA method required for each targeted authentication method and broadens eligible users from SMS or voice sign-ins to users signing in with any MFA method.
Microsoft added documentation for using the guided migration tool to assess an environment, create Cloud Sync configurations, run a preactivation check, and validate synchronization after migration.
Connect Version History
Feature updateAction requiredMicrosoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.
Connect Version History
Doc updateThe version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.
Whatis Azure Ad Connect
Doc updateThe page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.
Connect Version History
Doc updateThe documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.
Clear attribute values (Preview)
Feature updateThe documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.
The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.
The documentation now explains how optional single-valued source attributes can clear mapped target attributes when SAP SuccessFactors returns null or empty values.
Hibob To Active Directory User Provisioning Tutorial
Feature updateAction requiredThe tutorial now requires Microsoft Entra ID P1, P2, or Governance licenses for every identity sourced through API-driven provisioning.
The article now documents the guided workflow for duplicate-attribute errors, including finding affected objects, opening Error Details, using Troubleshoot, reviewing proposed resolutions, and applying supported fixes. Status descriptions and diagnostic images were also updated.
Tshoot Connect Sso
Doc updateThe procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.
The documentation now explains how to configure attribute value clearing, fallback values, or ignored values when HR applications return null or empty attributes during provisioning.
Hr User Update Issues
Doc updateThe documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.
The troubleshooting guidance for SEC_E_NO_AUTHENTICATING_AUTHORITY now links to Windows Server 2025 build 26100.6905 information.
Troubleshoot Primary Refresh Token
Doc updateThe troubleshooting guide now uses `-vAuth` instead of `-v` when starting `Start-auth.ps1`.
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide starting February 1, 2027, to enhance security. Organizations must identify affected users, migrate them to phishing-resistant methods like passkeys, and update policies to avoid sign-in disruptions and comply with new requirements.
Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.
Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.
Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out in phases from October 2026 to February 2027, aims to increase adoption of phishing-resistant sign-in.
The Risky IP report
RetirementThe documentation now notes that the AD FS Risky IP report is being deprecated and links to the Risky IP report workbook. It also updates portal navigation, export handling, notification settings, and threshold guidance.
The guide now documents the updated service overview, alert details and search, domain controller filtering and column options, replication error details, and 24-hour authentication performance charts.
The page now reflects the Sync services overview, updated alert and monitoring workflows, revised settings instructions, and expanded sync-error filtering, details, and CSV export guidance.
Sla Performance
Doc updateThe August row on the SLA performance reference page now shows 99.999% in the previously blank final metric column.
Connect Install Roadmap
Doc updateThe page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.
Account discovery now covers users and groups, classifying them as local, unassigned, or assigned identities. Group discovery is identified as being in preview, and correlation requires a direct matching attribute.
Connect Version History
Doc updateAction requiredThe version history entry now links readers to the latest available Microsoft Entra Connect Sync version.
The article now documents configuring a SCIM endpoint that uses an OAuth2 client-credentials grant from a non-Entra issuer, including the token endpoint, client credentials, credential placement, and scopes.
Microsoft Entra ID Governance
9 updatesThe documentation adds access package drift reporting for groups and enterprise applications, including detection, remediation, export, roles, licensing, refresh timing, and limitations. The reports are in preview.
Extend Application Attributes
Doc updateThe documentation now uses clearer wording for configuring LCW extensibility workflow mappings, creating an Azure Logic App and workflow, and configuring provisioning jobs with attribute mappings.
Licensing
Doc updateThe Tenant Governance licensing page now links to Microsoft Agent 365 licensing FAQs and guidance for using governance relationships with Microsoft Defender.
The access package creation documentation now explains that the search box can find matching SharePoint Online roles that are not initially displayed, especially on sites with many roles.
The documentation now recommends using the search box to find SharePoint Online roles when adding them to an access package. Search returns matching roles even when they are not initially displayed.
Licensing
Doc updateThe licensing documentation’s Microsoft author alias was updated from `tafra00` to `tazkiaafra`.
The overview describes access drift, account discovery, access package drift detection, and enforcement and remediation approaches for aligning resource access with governance policies.
The licensing fundamentals page was updated to align the Account Discovery section and state that the feature requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite.
Licensing
Doc updateThe page now lists the Microsoft Agent 365 Licensing FAQs and governance relationships links without the previous section heading and introductory text.
Microsoft Entra External ID
1 updateMicrosoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.
Microsoft Entra Internet Access
3 updatesThe documentation removes “preview” from the source traffic type and HTTP method request filtering conditions, updates their headings and links, and refreshes the page date.
Web filtering in Global Secure Access (V2)
New featureThe documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.
The Internet Access health-signal article now lists licensing, roles, Microsoft Graph permissions, and log access requirements. It also adds steps for investigating alerts and reviewing filtering and forwarding policies.
Microsoft Entra Private Access
1 updateHow to investigate private application access requiring Microsoft Entra Private Access connector
Feature updateThe documentation now requires a non-trial Microsoft Entra P1 or P2 license plus at least 100 monthly active users to view alerts and receive notifications. It also clarifies Private Access licensing, least-privilege roles, Graph permissions, and expanded signal and alert investigation guidance.
Microsoft Entra Global Secure Access
3 updatesLearn about Universal Continuous Evaluation
Feature updateThe documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.
The documentation now states that custom headers are available only with Web Filtering (v2) policies and links to the related guidance.
The article now distinguishes tunnel and BGP connectivity scenarios and adds investigation steps, licensing requirements, least-privilege roles, and Microsoft Graph permissions for viewing and managing signals and alerts.
