Week in brief

Week of 2 March 2026: Microsoft Entra AI Administrator RBAC expands for Agent 365; native-auth OTP guidance includes a private preview

This was a maintenance-heavy period rather than a broad release wave: 111 items were updated and 8 were new. Many representative Learn edits involve tutorial wording, links, metadata, and PIM procedure refreshes rather than product announcements. The clearest operational change is the Microsoft 365 Message Center notice for expanded AI Administrator permissions in Agent 365, with rollout starting in March 2026. The new Microsoft Entra native authentication material is significant for app teams, but it is implementation guidance and includes an explicit private-preview enrollment path—not evidence of general availability. Other specific admin-facing updates clarify Conditional Access phased-rollout suggestions, Global Secure Access source-IP behavior, and dynamic-group security. One removal is counted, but no title or product detail is supplied, so the evidence does not substantiate a retirement.

  • AI Administrator permissions expand for Agent 365ID Protection / Agent 365

    This is the period's clearest service-level change and comes from Message Center rather than a documentation-only edit. Microsoft says the AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Administrator involvement for routine tasks. The expanded scope includes agent lifecycle management, tenant-wide consent except Microsoft Graph app permissions, and risk monitoring through Identity Protection. Rollout starts in March 2026; no more precise date is supplied.

  • Native Authentication guidance expands around email and SMS OTPEntra ID — Native Authentication

    The supplied new entries provide platform-specific Android and iOS/macOS instructions for adding email or SMS one-time-passcode MFA and registering email or SMS OTP as a strong authentication method. Related updates call out required MFA and registration client capabilities; one iOS/macOS registration tutorial specifies `registrationRequired`, while the MFA tutorials cover authentication context and MFA error handling. Other guidance describes using a third-party fraud-protection provider before issuing SMS OTP. An

  • Conditional Access phased-rollout guidance clarifies the agent's decision loopEntra ID — Conditional Access

    The updated Conditional Access Agent Optimization guidance says that once a phased rollout starts, the agent's suggestion remains present throughout the rollout. It can show that no action is needed, suggest progressing to the next phase, or suggest rolling back. This is a documented rollout behavior clarification, not evidence of a new launch or a change in availability.

  • Global Secure Access documentation clarifies source-IP behaviorGlobal Secure Access

    When Global Secure Access is deployed as a cloud-based network proxy, Secure Service Edge infrastructure routes user traffic. If source IP restoration is not enabled, authentication requests come from the proxy's IP address rather than the user's actual public egress IP. This is an operational and architecture clarification that matters for authentication designs relying on the request source address.

  • Dynamic-group and PIM guidance sharpen least-privilege expectationsEntra ID / ID Governance — Dynamic Groups and PIM

    The dynamic-membership update makes security guidance explicit: group membership depends on who can modify the attributes referenced in a rule, both in Microsoft Entra ID and in connected source directories, so write permissions should be reviewed before selecting an attribute. Separately, an updated PIM page identifies Discovery and insights (preview) as the former Security Wizard and describes it as helping convert permanent Microsoft Entra role assignments to just-in-time assignments. The surrounding PIM edits—涵

For Entra administrators

If Agent 365 is in scope, review AI Administrator assignments and consent scope as the rollout begins; the expanded role covers routine agent lifecycle management, tenant-wide consent except Microsoft Graph app permissions, and risk monitoring through Identity Protection. Teams integrating Entra native authentication should review the Android, iOS, and macOS client-capability and registration guidance, including `registrationRequired`, authentication context, and MFA error handling, while treating the email/SMS OTP enrollment step as a private-preview dependency. Conditional Access operators running a phased rollout should expect the agent's suggestion to remain available and to provide no-action, advance, or rollback guidance. Global Secure Access operators should verify source-IP-based16

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Authentication

26

Tutorial: Add SMS one-time passcode MFA to your iOS/macOS app

Updated

This tutorial shows you how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to your iOS/macOS app using native authentication. MFA adds an extra layer of security by requiring a second verification step during sign-in.

7 March 2026

Tutorial: Add Email strong authentication method registration to your Android app

Updated

This tutorial demonstrates how to implement Email strong authentication method registration into your Android app using native authentication. At least one strong authentication is mandatory for multifactor authentication (MFA) enabled users. Currently, we only support Email and SMS one-time passcode as strong authentication method.

7 March 2026

Native Authentication Api

Updated

| `continuation_token` | [Continuation token](#continuation-token) that Microsoft Entra returns. |

7 March 2026

Domains Verify Custom Subdomain

Updated

Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.

7 March 2026

Howto Authentication Temporary Access Pass

Updated

Users with a TAP can navigate the setup process on Windows 10 and 11 to perform device join operations and configure Windows Hello for Business. TAP usage for setting up Windows Hello for Business varies based on the devices joined state.

5 March 2026

Fundamentals

18

Overview

Updated

:::image type="content" source="media/overview/conditional-access-overview.png" alt-text="Screenshot of the Conditional Access overview page." lightbox="media/overview/conditional-access-overview.png":::

7 March 2026

Whats New

Updated

**Note:** Currently, the new Bulk Operations service supports **Groups**, **Devices**, and **User Export** only. Support for additional entities, such as **Enterprise Applications**, is coming soon. For more information, see: [Bulk operations in Microsoft Entra ID (Preview)](../fundamentals/bulk-operations.md).

6 March 2026

Token Protection

Updated

- For detailed steps on how to register your device, see [Register your personal device on your work or school network](https://support.microsoft.com/account-billing/register-your-personal-device-on-your-work-or-school-network-8803dd61-a613-45e3-ae6c-bd1ab25bf8a8).

6 March 2026

Overview of Microsoft Entra ID Account Recovery

Updated

Learn about Microsoft Entra ID Account Recovery, which enables users to regain access to their accounts through identity verification when they've lost all authentication methods.

4 March 2026

Custom Extension Email Otp Get Started

Updated

- A familiarity and understanding of the concepts covered in [custom authentication extensions](/entra/identity-platform/custom-extension-overview).

4 March 2026

Overview

Updated

Take a look at our short video to learn more about Microsoft Entra Domain Services.

4 March 2026

Configure Security

Updated

Learn how to improve your security posture with Microsoft Entra.

3 March 2026

Zero Trust Protect Networks

Updated

Improve your security posture with the Microsoft Entra Zero Trust assessment to protect networks.

3 March 2026

Provisioning

13

Citrixgotomeeting Provisioning Tutorial

Updated

This section guides you through connecting your Microsoft Entra ID to GoToMeeting's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in GoToMeeting based on user and group assignment in Microsoft Entra ID.

6 March 2026

Gpad Prereqs

Updated

- The provisioning agent must be installed on a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016.

5 March 2026

General

11

Licensing Group Advanced

Updated

More scenarios limitations, and known issues for Microsoft Entra group-based licensing

7 March 2026

Custom Extension Attribute Collection

Updated

- To use Azure services, including Azure Functions, you need an Azure subscription. If you don't have an existing Azure account, you can sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).

4 March 2026

Custom Extension Tokenissuancestart Configuration

Updated

- An Azure subscription with the ability to create Azure Functions. If you don't have an existing Azure account, sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).

4 March 2026

Get Signed In Identity

Updated

- An Azure account with an active subscription. [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).

4 March 2026

Microsoft identity platform

3

Msal Compare Msal Js And Adal Js

Updated

Yet another common error you might face is `consent_required`, which occurs when permissions required for obtaining an access token for a protected resource aren't consented by the user. As in `interaction_required`, the solution for `consent_required` error is often initiating an interactive token acquisition prompt, using either `acquireTokenPopup` or `acquireTokenRedirect`.

6 March 2026

Security

3

Groups Dynamic Membership

Updated

When you create a dynamic membership rule, the security of that group's membership depends on who can modify the attributes referenced in the rule. Before selecting an attribute, review the write permissions for that attribute—both in Microsoft Entra ID and in any connected source directories.

7 March 2026

Conditional Access

1

Conditional Access Agent Optimization Phased Rollout

Updated

Once you start a phased rollout, the agent helps you progress. The phased rollout suggestion is present throughout the rollout process and can show no action needed, suggest progressing to the next phase, or suggest rolling back.

3 March 2026

Developer

1

Monitoring

1

Reports Data Retention

Updated

**No**, you can't. Azure stores up to seven days of activity data for a free version. When you switch from a free to a premium version, you can only see up to 7 days of data.

5 March 2026

Standards

1

Troubleshooting

1

General

1

Agent Lists

Updated

To view agent identities in your Microsoft Entra tenant, you need:

4 March 2026

Fundamentals

1

AI Admin RBAC updates

New

The AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Admin involvement for routine tasks. Rollout starts March 2026. AI Admins gain expanded permissions for agent lifecycle management, tenant-wide consent (excluding Microsoft Graph app permissions), and risk monitoring via Identity Protection, enhancing security and compliance.

7 March 2026
Message CenterMC1245636 on mc.merill.net ↗Stay informed

Governance

26

Start using PIM

Updated

Learn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.

7 March 2026

Fundamentals

4

Architecture

1

B2c Deployment Plans

Updated

- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)

4 March 2026

General

1

Cross Cloud Settings

Updated

The following scenarios are supported when collaborating with an organization from a different Microsoft cloud:

6 March 2026

Provisioning

1

Known Issues

Updated

- B2B users are unable to manage certain Microsoft 365 services in remote tenants (such as Exchange Online), as there's no directory picker.

6 March 2026

Architecture

2

General

1

Qs Configure Portal Windows Vmss

Updated

- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).

6 March 2026

General

3

Powershell Samples

Updated

Use these PowerShell samples for Global Secure Access.

7 March 2026

Authentication

1

userimpact: Low

Updated

When organizations deploy Global Secure Access as their cloud-based network proxy, Microsoft's Secure Service Edge infrastructure routes user traffic. If you don't enable source IP restoration, all authentication requests come from the proxy's IP address instead of the user's actual public egress IP.

3 March 2026