This tutorial shows you how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to your iOS/macOS app using native authentication. MFA adds an extra layer of security by requiring a second verification step during sign-in.
Week of 2 March 2026: Microsoft Entra AI Administrator RBAC expands for Agent 365; native-auth OTP guidance includes a private preview
This was a maintenance-heavy period rather than a broad release wave: 111 items were updated and 8 were new. Many representative Learn edits involve tutorial wording, links, metadata, and PIM procedure refreshes rather than product announcements. The clearest operational change is the Microsoft 365 Message Center notice for expanded AI Administrator permissions in Agent 365, with rollout starting in March 2026. The new Microsoft Entra native authentication material is significant for app teams, but it is implementation guidance and includes an explicit private-preview enrollment path—not evidence of general availability. Other specific admin-facing updates clarify Conditional Access phased-rollout suggestions, Global Secure Access source-IP behavior, and dynamic-group security. One removal is counted, but no title or product detail is supplied, so the evidence does not substantiate a retirement.
- AI Administrator permissions expand for Agent 365ID Protection / Agent 365
This is the period's clearest service-level change and comes from Message Center rather than a documentation-only edit. Microsoft says the AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Administrator involvement for routine tasks. The expanded scope includes agent lifecycle management, tenant-wide consent except Microsoft Graph app permissions, and risk monitoring through Identity Protection. Rollout starts in March 2026; no more precise date is supplied.
- Native Authentication guidance expands around email and SMS OTPEntra ID — Native Authentication
The supplied new entries provide platform-specific Android and iOS/macOS instructions for adding email or SMS one-time-passcode MFA and registering email or SMS OTP as a strong authentication method. Related updates call out required MFA and registration client capabilities; one iOS/macOS registration tutorial specifies `registrationRequired`, while the MFA tutorials cover authentication context and MFA error handling. Other guidance describes using a third-party fraud-protection provider before issuing SMS OTP. An
- Conditional Access phased-rollout guidance clarifies the agent's decision loopEntra ID — Conditional Access
The updated Conditional Access Agent Optimization guidance says that once a phased rollout starts, the agent's suggestion remains present throughout the rollout. It can show that no action is needed, suggest progressing to the next phase, or suggest rolling back. This is a documented rollout behavior clarification, not evidence of a new launch or a change in availability.
- Global Secure Access documentation clarifies source-IP behaviorGlobal Secure Access
When Global Secure Access is deployed as a cloud-based network proxy, Secure Service Edge infrastructure routes user traffic. If source IP restoration is not enabled, authentication requests come from the proxy's IP address rather than the user's actual public egress IP. This is an operational and architecture clarification that matters for authentication designs relying on the request source address.
- Dynamic-group and PIM guidance sharpen least-privilege expectationsEntra ID / ID Governance — Dynamic Groups and PIM
The dynamic-membership update makes security guidance explicit: group membership depends on who can modify the attributes referenced in a rule, both in Microsoft Entra ID and in connected source directories, so write permissions should be reviewed before selecting an attribute. Separately, an updated PIM page identifies Discovery and insights (preview) as the former Security Wizard and describes it as helping convert permanent Microsoft Entra role assignments to just-in-time assignments. The surrounding PIM edits—涵
If Agent 365 is in scope, review AI Administrator assignments and consent scope as the rollout begins; the expanded role covers routine agent lifecycle management, tenant-wide consent except Microsoft Graph app permissions, and risk monitoring through Identity Protection. Teams integrating Entra native authentication should review the Android, iOS, and macOS client-capability and registration guidance, including `registrationRequired`, authentication context, and MFA error handling, while treating the email/SMS OTP enrollment step as a private-preview dependency. Conditional Access operators running a phased rollout should expect the agent's suggestion to remain available and to provide no-action, advance, or rollback guidance. Global Secure Access operators should verify source-IP-based16
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
79 updatesAuthentication
26This tutorial demonstrates how to implement Email strong authentication method registration into your Android app using native authentication. At least one strong authentication is mandatory for multifactor authentication (MFA) enabled users. Currently, we only support Email and SMS one-time passcode as strong authentication method.
1. Enroll in a Private Preview of SMS and Email OTP MFA on Native Authentication – [Fill out form](https://forms.office.com/r/P3m1q2j3hg)
Learn how to add multi-factor authentication (MFA) with email and SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add email one-time passcode (OTP) multi-factor authentication (MFA) to an iOS or macOS app by using native authentication and enforce MFA with authentication context.
Add email strong authentication method registration to an Android app using native authentication
NewLearn how to register an email one-time passcode as a strong authentication method for MFA-enabled users in an Android app using Microsoft Entra native authentication.
Learn how to register an email strong authentication method for MFA-enabled users in an iOS or macOS app by using native authentication.
Learn how to register phone SMS as a strong authentication method for MFA-enabled users in an iOS or macOS app using native authentication, including configuring client capabilities and handling registration challenges.
Learn how to add multi-factor authentication (MFA) with SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to register an SMS one-time passcode as a strong authentication method for MFA-enabled users in an Android app using Microsoft Entra native authentication.
To support multi-factor authentication (MFA), update the Android client configuration to include the required MFA capabilities.
To support multi-factor authentication (MFA), update the Android client configuration to include the required MFA capabilities.
To support strong authentication method, update the Android client configuration to include the required registration capabilities.
Set the registrationRequired capability during client initialization to support strong authentication method registration.
Learn how to add multifactor authentication (MFA) with SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add multifactor authentication (MFA) with email and SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add email one-time passcode (OTP) multifactor authentication (MFA) to an iOS or macOS app by using native authentication and enforce MFA with authentication context.
1. Complete the steps in [Tutorial: Add sign-in in Android app by using native authentication](tutorial-native-authentication-android-sign-in-sign-out.md).
Native Authentication Api
Updated| `continuation_token` | [Continuation token](#continuation-token) that Microsoft Entra returns. |
Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.
Before enforcing the policy, deploy it in report-only mode to assess the effect and identify noncompliant sign-in sessions.
Use Vm Sign In
Updated> [!IMPORTANT]
Users with a TAP can navigate the setup process on Windows 10 and 11 to perform device join operations and configure Windows Hello for Business. TAP usage for setting up Windows Hello for Business varies based on the devices joined state.
Learn how to configure and enable users to sign-in to Microsoft Entra ID using SMS
Tutorial: Enable cloud sync self-service password reset writeback to an on-premises environment
Updated> [!NOTE]
Disable User Sign In Portal
UpdatedTo disable user sign-in, you need:
Fundamentals
18- Your native application integrates with a third‑party fraud protection provider to securely evaluate risk signals before issuing an SMS one‑time passcode (OTP).
Overview
Updated:::image type="content" source="media/overview/conditional-access-overview.png" alt-text="Screenshot of the Conditional Access overview page." lightbox="media/overview/conditional-access-overview.png":::
A Microsoft Entra documentation page was updated: Licensing Groups Resolve Problems.
Management concepts and how-tos for managing a domain name in Microsoft Entra ID
Learn about Microsoft Entra bulk operations related to users, groups,
Use Microsoft Entra groups to simplify role assignment management in Microsoft Entra ID.
Whats New
Updated**Note:** Currently, the new Bulk Operations service supports **Groups**, **Devices**, and **User Export** only. Support for additional entities, such as **Enterprise Applications**, is coming soon. For more information, see: [Bulk operations in Microsoft Entra ID (Preview)](../fundamentals/bulk-operations.md).
Whats New Archive
Updatedauthor: owinfreyATL
Token Protection
Updated- For detailed steps on how to register your device, see [Register your personal device on your work or school network](https://support.microsoft.com/account-billing/register-your-personal-device-on-your-work-or-school-network-8803dd61-a613-45e3-ae6c-bd1ab25bf8a8).
New values are added when native authentication supports new authentication methods.
- A basic understanding of the concepts covered in [Custom authentication extensions overview](custom-extension-overview.md).
New values are added when native authentication supports new authentication methods.
Learn about Microsoft Entra ID Account Recovery, which enables users to regain access to their accounts through identity verification when they've lost all authentication methods.
- A familiarity and understanding of the concepts covered in [custom authentication extensions](/entra/identity-platform/custom-extension-overview).
Token Protection
Updated- sfi-image-nochange
Overview
UpdatedTake a look at our short video to learn more about Microsoft Entra Domain Services.
Configure Security
UpdatedLearn how to improve your security posture with Microsoft Entra.
Zero Trust Protect Networks
UpdatedImprove your security posture with the Microsoft Entra Zero Trust assessment to protect networks.
Provisioning
13author: jeevansd
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Dialpad.
author: jeevansd
author: jeevansd
manager: pmwongera

This section guides you through connecting your Microsoft Entra ID to GoToMeeting's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in GoToMeeting based on user and group assignment in Microsoft Entra ID.
Gpad Prereqs
Updated- The provisioning agent must be installed on a server that runs Windows Server 2022, Windows Server 2019, or Windows Server 2016.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to AWS IAM Identity Center.
author: jeevansd
author: jeevansd
author: jeevansd
author: jeevansd
General
11Privileged roles and permissions in Microsoft Entra ID.
Licensing Group Advanced
UpdatedMore scenarios limitations, and known issues for Microsoft Entra group-based licensing
How to take over a Domain name DNS domain name in an unmanaged Microsoft Entra organization (shadow tenant).
A Microsoft Entra documentation page was updated: Understand how multiple Microsoft Entra tenant organizations interact.
Use restricted management administrative units for more sensitive resources in Microsoft Entra ID.
Delete users in bulk in Microsoft Entra ID
Peoplecart Tutorial
Updated`https://<tenantname>.peoplecart.com/SignIn.aspx`
Connect Sync Whatis
Updated<a name='azure-ad-connect-sync-topics'></a>
- To use Azure services, including Azure Functions, you need an Azure subscription. If you don't have an existing Azure account, you can sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).
- An Azure subscription with the ability to create Azure Functions. If you don't have an existing Azure account, sign up for a [free trial](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) or use your [Visual Studio Subscription](https://visualstudio.microsoft.com/subscriptions/) benefits when you [create an account](https://account.windowsazure.com/Home/Index).
Get Signed In Identity
Updated- An Azure account with an active subscription. [Create an account for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
Microsoft identity platform
3> [!NOTE]
Msal Node Migration
Updated});
Yet another common error you might face is `consent_required`, which occurs when permissions required for obtaining an access token for a protected resource aren't consented by the user. As in `interaction_required`, the solution for `consent_required` error is often initiating an interactive token acquisition prompt, using either `acquireTokenPopup` or `acquireTokenRedirect`.
Security
3Groups Dynamic Membership
UpdatedWhen you create a dynamic membership rule, the security of that group's membership depends on who can modify the attributes referenced in the rule. Before selecting an attribute, review the write permissions for that attribute—both in Microsoft Entra ID and in any connected source directories.
Token Protection on Windows platforms can be used to protect the following resources:
Deploy Defender XDR workloads to alert on suspicious or anomalous behaviors surrounding token theft.
Conditional Access
1Once you start a phased rollout, the agent helps you progress. The phased rollout suggestion is present throughout the rollout process and can show no action needed, suggest progressing to the next phase, or suggest rolling back.
Developer
1Delete Application Portal
UpdatedTo delete an enterprise application, you need:
Monitoring
1Reports Data Retention
Updated**No**, you can't. Azure stores up to seven days of activity data for a free version. When you switch from a free to a premium version, you can only see up to 7 days of data.
Standards
1Blackboard Learn Tutorial
Updated`https://<subdomain>.blackboard.com/auth-saml/saml/SSO/entity-id/SAML_AD`
Troubleshooting
1Learn how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to an iOS or macOS app using native authentication, including enforcing MFA with authentication context and handling MFA errors.
Microsoft Entra Agent ID
1 updateGeneral
1Agent Lists
UpdatedTo view agent identities in your Microsoft Entra tenant, you need:
Microsoft Entra ID Protection
1 updateFundamentals
1The AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Admin involvement for routine tasks. Rollout starts March 2026. AI Admins gain expanded permissions for agent lifecycle management, tenant-wide consent (excluding Microsoft Graph app permissions), and risk monitoring via Identity Protection, enhancing security and compliance.
Microsoft Entra ID Governance
30 updatesGovernance
26Discovery and insights (formerly Security Wizard) help you convert permanent Microsoft Entra role assignments to just-in-time assignments with Privileged Identity Management.
Learn how to configure security alerts for Azure resource roles in Privileged
Configure security alerts for Microsoft Entra roles Privileged Identity Management.
The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.
Learn how to approve or deny requests for Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to approve or deny requests for Azure resource roles in Privileged
Learn how to assign Azure resource roles in Privileged Identity Management (PIM).
Learn how to bring groups into Privileged Identity Management.
Learn how to complete an access review of Azure resource and Microsoft Entra roles Privileged Identity Management.
Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Learn how to create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to discover Azure resources to manage in Privileged Identity Management (PIM).
Learn how to extend or renew PIM for groups assignments.
Learn how to review access of Azure resource and Microsoft Entra roles
Learn how to extend or renew Azure resource role assignments in Privileged Identity Management (PIM).
Learn how to extend or renew Microsoft Entra role assignments in Microsoft Entra Privileged Identity Management (PIM)
Start using PIM
UpdatedLearn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.
Learn how to use Azure custom roles in Microsoft Entra Privileged Identity Management (PIM).
Learn how to view the audit log history for Microsoft Entra roles in
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
Learn how to activate your group membership or ownership in Privileged
Describes the roles you can't manage in Microsoft Entra Privileged Identity
Learn how Microsoft Entra ID is licensed for guest users.
Simulate Workflow Execution
RemovedA Microsoft Entra documentation page was updated: Simulate Workflow Execution.
Access Review Agent
Updated> [!NOTE]
Fundamentals
4How to manage Microsoft Entra Privileged Identity Management (PIM) for Groups.
Describes how to use a resource dashboard to perform an access review
Provides an overview of Microsoft Entra Privileged Identity Management (PIM).
Information for understanding the APIs in Microsoft Entra Privileged
Microsoft Entra External ID
3 updatesArchitecture
1B2c Deployment Plans
Updated- See, [Tutorial: Create an Azure Active Directory B2C tenant](/azure/active-directory-b2c/tutorial-create-tenant)
General
1Cross Cloud Settings
UpdatedThe following scenarios are supported when collaborating with an organization from a different Microsoft cloud:
Provisioning
1Known Issues
Updated- B2B users are unable to manage certain Microsoft 365 services in remote tenants (such as Exchange Online), as there's no directory picker.
Microsoft Entra Verified ID
2 updatesArchitecture
2A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Microsoft Entra Workload ID
1 updateGeneral
1- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).
Microsoft Entra Global Secure Access
4 updatesGeneral
3```powershell
Enable Multi Geo
Updatedauthor: HULKsmashGithub
Powershell Samples
UpdatedUse these PowerShell samples for Global Secure Access.
Authentication
1userimpact: Low
UpdatedWhen organizations deploy Global Secure Access as their cloud-based network proxy, Microsoft's Secure Service Edge infrastructure routes user traffic. If you don't enable source IP restoration, all authentication requests come from the proxy's IP address instead of the user's actual public egress IP.
