Week in brief

Two Entra authentication retirements set the agenda: migrate Conditional Access and prepare for default voice-MFA recordings

Two announced retirements are the period’s main admin actions: the Conditional Access “Require approved client app” control is scheduled to retire in June 2026, and custom greetings in voice-call authentication retire on 28 February 2026. Beyond those notices, the week is mostly documentation maintenance rather than a feature-release cycle; many remaining Entra entries are numbered troubleshooting pages whose supplied summary is only “Remediation action.” The substantive exceptions clarify Connect Sync deployment constraints, Conditional Access Optimization Agent identity behavior, External ID MAU billing scope, and security risks around workload identities, guests, session controls, and provisioning scope. The lone new entry is an EcoOnline Info Exchange SSO configuration guide—not evidence of a new Entra capability, preview, or GA release. The three removed Purview workload-content pages have no retirement rationale in the supplied record.

  • The Microsoft 365 Message Center reminder says this control retires in June 2026 and will no longer be enforceable afterward. Organizations are directed to update policies to use “Require application protection policy,” described as providing equivalent and enhanced protection. This is a planned policy transition, not a preview or GA announcement.

  • Microsoft Entra ID — voice call authenticationRetirement — custom greetings in voice call authentication

    Custom greetings retire on 28 February 2026. Afterward, voice calls for multifactor authentication will use Microsoft’s default recordings. The notice specifically calls for preparing users and reviewing relevant MFA configurations.

  • Microsoft Entra Connect Sync; Microsoft Entra ID — Conditional Access Optimization AgentsOperational clarifications — Connect Sync cloning and Optimization Agent identity

    The Connect Sync troubleshooting update says cloning a server with Entra Connect installed into another production server is unsupported because the clone shares the machine identifier and conflicts with the application registration identity. It also explains that the wizard normally uses unique accounts per server and the server name—not the connector service account—to identify the application registration. Separately, the Optimization Agent guidance says agents enabled after 17 November 2025 no longer use the20

  • Microsoft Entra Workload ID; Microsoft Entra ID; Microsoft Entra ID GovernanceSecurity guidance — privileged workload identities and guest or application exposure

    Updated material warns that privileged roles on service principals or managed identities can create significant risk if compromised, including reconnaissance, privilege escalation, lateral movement, persistence, and data manipulation or exfiltration. Other updates identify open application assignment without provisioning scoping, compromised or dormant guest accounts, and inadequate session controls as exposure paths. Identity Governance documentation also describes using business groups to determine which guests;

  • The updated External Identities Pricing page says MAU billing applies to every user in an external tenant, including consumers, business guests without directory roles, and administrators with directory roles, regardless of UserType. This clarifies billing scope; no rate or effective date is supplied.

For Entra administrators

Inventory Conditional Access policies that use “Require approved client app” and move them to “Require application protection policy” ahead of the June 2026 retirement; the old control will no longer be enforceable afterward. For voice MFA, prepare users for Microsoft’s default recordings and review relevant MFA configurations before 28 February. If a Connect Sync deployment plan relies on cloning a production server, revisit it because the updated guidance calls that method unsupported. If an Optimization Agent enabled before Microsoft Ignite 2025 is failing, check whether the activating account depended on PIM role activation and lacked the required permissions when the agent ran. Include all users in external tenants in MAU billing assumptions regardless of UserType. The security edits‍

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Troubleshooting

27

21790

Updated

**Remediation action**

23 January 2026

21804

Updated

**Remediation action**

23 January 2026

21806

Updated

**Remediation action**

23 January 2026

21884

Updated

**Remediation action**

23 January 2026

21985

Updated

**Remediation action**

23 January 2026

21817

Updated

**Remediation action**

23 January 2026

21825

Updated

**Remediation action**

23 January 2026

21776

Updated

**Remediation action**

23 January 2026

21777

Updated

**Remediation action**

23 January 2026

21786

Updated

**Remediation action**

23 January 2026

21798

Updated

**Remediation action**

23 January 2026

21799

Updated

**Remediation action**

23 January 2026

21802

Updated

**Remediation action**

23 January 2026

21812

Updated

**Remediation action**

23 January 2026

21818

Updated

**Remediation action**

23 January 2026

21828

Updated

**Remediation action**

23 January 2026

21847

Updated

**Remediation action**

23 January 2026

21865

Updated

**Remediation action**

23 January 2026

21867

Updated

**Remediation action**

23 January 2026

21868

Updated

**Remediation action**

23 January 2026

21870

Updated

**Remediation action**

23 January 2026

21877

Updated

**Remediation action**

23 January 2026

21883

Updated

**Remediation action**

23 January 2026

21886

Updated

**Remediation action**

23 January 2026

21891

Updated

**Remediation action**

23 January 2026

22128

Updated

**Remediation action**

23 January 2026

22659

Updated

**Remediation action**

23 January 2026

General

10

21793

Updated

If this check passes, your tenant has a TRv2 policy configured but more steps are required to validate the scenario end-to-end.

23 January 2026

21824

Updated

Without proper session controls, threat actors can achieve lateral movement across the organization's infrastructure, accessing critical data and systems that extend far beyond the original guest account's intended scope of access.

23 January 2026

Ecoonline Info Tutorial

Updated

In this article, you configure and test Microsoft Entra single sign-on in a test environment.

20 January 2026

Conditional Access

3

Managed Policies

Updated

These Microsoft-managed policies allow administrators to make simple modifications like excluding users or turning them from report-only mode to on or off. Organizations can't rename or delete any Microsoft-managed policies. As administrators get more comfortable with Conditional Access policy, they might choose to duplicate the policy to create custom versions.

24 January 2026

Conditional Access Agent Optimization

Updated

It's possible that the agent was enabled before Microsoft Ignite 2025 with an account that required role activation with Privileged Identity Management (PIM). So when the agent attempted to run, it failed because the account didn't have the required permissions at that time. Conditional Access Optimization Agents that were turned on after November 17, 2025 no longer use the identity of the user who activated the agent.

21 January 2026

Monitoring

3

21773

Updated

- [Define certificate based application configuration](https://devblogs.microsoft.com/identity/app-management-policy/)

23 January 2026

21858

Updated

The prolonged dormancy of these accounts provides attackers with extended dwell time to conduct reconnaissance, exfiltrate sensitive data, and establish backdoors without detection, as organizations typically focus monitoring efforts on active internal users rather than external guest accounts.

23 January 2026

Howto Configure Recommendation Email Notifications

Updated

The email notifications provide a basic summary of the specific recommendation with a link to the related area of the Microsoft Entra admin center. The email also includes a link to related documentation so you can learn more about the recommendation and how to resolve it. These emails are enabled by default, aren't promotional or marketing emails, and don't contain any upselling content. These emails are purely informational and designed to help you act quickly when a new recommendation is available.

21 January 2026

Security

2

21830

Updated

- [Deploy a privileged access workstation solution](/security/privileged-access-workstations/privileged-access-deployment)

23 January 2026

21823

Updated

Additionally, compromised guest identities can be used to establish credential persistence and potentially escalate privileges. Attackers can exploit trust relationships between guest accounts and internal resources, or use the guest account as a staging ground for lateral movement toward more privileged organizational assets.

23 January 2026

Authentication

1

Microsoft Entra built-in roles

Updated

In Microsoft Entra ID, if another administrator or nonadministrator needs to manage Microsoft Entra resources, you assign them a Microsoft Entra role that provides the permissions they need. For example, you can assign roles to allow adding or changing users, resetting user passwords, managing user licenses, or managing domain names.

23 January 2026

Branding

1

Fundamentals

1

Macos Get Started

Updated

Adding a work or school account to macOS is a straightforward process that enhances your access to organizational resources and services. This article provides an overview and answers to some Frequently Asked Questions (FAQs) about adding a work or school account to your macOS device using applications such as Microsoft Outlook or Microsoft Edge.

22 January 2026

Governance

1

21869

Updated

While an application with open assignment but proper provisioning scoping (such as department-based filters or group membership requirements) maintains security controls through the provisioning layer, applications lacking both controls create unrestricted access pathways that threat actors can exploit. When applications provision accounts for all users without assignment restrictions, threat actors can abuse compromised accounts to conduct reconnaissance activities, enumerate sensitive data across multiple systems, or use the applications as staging points for further attacks against connected resources. This unrestricted access model is dangerous for applications that have elevated permissions or are connected to critical business systems. Threat actors can use any compromised user account to access sensitive information, modify data, or perform unauthorized actions that the application's permissions allow. The absence of both assignment controls and provisioning scoping also prevents organizations from implementing proper access governance. Without proper governance, it's difficult to track who has access to which applications, when access was granted, and whether access should be revoked based on role changes or employment status. Furthermore, applications with broad provisioning scopes can create cascading security risks where a single compromised account provides access to an entire ecosystem of connected applications and services.

23 January 2026

Microsoft identity platform

1

Troubleshoot Connect Sync Application Authentication

Updated

The same issue occurs when a server with Microsoft Entra Connect installed is cloned into another production server, which isn't a supported method of deploying this product as these servers with share the same machine identifier. In short, the server's identity conflicts because they get tied to one app registration. The Microsoft Entra Connect wizard by default uses unique accounts per server because it uses the server's name to identify the application registration instead of the Microsoft Entra connector's service account, which avoids this issue.

22 January 2026

Fundamentals

1

Identity Governance Overview

Updated

In Microsoft Entra ID Governance, you can enable business groups to determine which of these guests should have access, and for how long, using:

23 January 2026

Governance

1

General

1

External Identities Pricing

Updated

- External users in Microsoft Entra [external tenants](tenant-configurations.md#external-tenants), which includes consumers and business guests (users without directory roles), and admins (users with directory roles). MAU billing applies to all users in an external tenant regardless of their **UserType** setting.

24 January 2026

Architecture

1

Monitoring

1

21836

Updated

If administrators assign privileged roles to workload identities, such as service principals or managed identities, the tenant can be exposed to significant risk if those identities are compromised. Threat actors who gain access to a privileged workload identity can perform reconnaissance to enumerate resources, escalate privileges, and manipulate or exfiltrate sensitive data. The attack chain typically begins with credential theft or abuse of a vulnerable application. Next step is privilege escalation through the assigned role, lateral movement across cloud resources, and finally persistence via other role assignments or credential updates. Workload identities are often used in automation and might not be monitored as closely as user accounts. Compromise can then go undetected, allowing threat actors to maintain access and control over critical resources. Workload identities aren't subject to user-centric protections like MFA, making least-privilege assignment and regular review essential.

23 January 2026

General

1