Microsoft Entra admin center
UpdatedOverview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.
Daily.Entra.NewsThe week of 30 March 2026 is dominated by Microsoft Learn maintenance rather than release announcements. The Microsoft 365 Message Center notice is materially different: Microsoft Entra ID audit events for Authentication Methods Policy updates will change during an April 2026 worldwide rollout. The two new Agent ID pages provide architecture guidance, but the supplied evidence does not establish a product launch or general availability. The three records marked Removed concern documentation pages; they do not, on their own, establish retirement of the underlying capabilities.
The Message Center notice says the worldwide rollout begins in April 2026. Audit events for Authentication Methods Policy updates will contain only properties that changed, with their old and new values. Event names and policy enforcement are unchanged, but organizations with automated log processing should review related parsing and reporting logic.
Two pages marked New—Microsoft Entra Agent ID design patterns and Plan your agent identity architecture—provide a framework for choosing identity types, operation patterns, blueprints, agent identities, and an agent user account. Related updates explain how agent identities differ from traditional service principals and describe registry experiences converging under Microsoft Agent 365, including how to view organizational agents. These are architecture and experience updates, not evidence of GA.
The updated Manage Agents in end user experience (Preview) article describes viewing agent identities that a user owns or sponsors, reviewing their details, and taking actions such as enabling, disabling, or requesting access. The explicit Preview label means the supplied update does not establish general availability or a tenant-wide behavior change.
The updated Apple SSO Plugin article states that applications or MDM solutions relying on Microsoft Entra device-registration keys through Keychain must be updated to use the Microsoft Authentication Library and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform. The evidence presents this as compatibility guidance, not as a dated service-retirement announcement.
The updated Account Discovery (preview) article covers finding and categorizing existing accounts in target applications, matching them to Microsoft Entra users, and preparing for provisioning governance. Related SCIM API reference, schema, enablement, disablement, and troubleshooting pages were also refreshed; the disablement guidance states that turning off the feature makes all SCIM API calls to the tenant return errors and stops billing. The records do not say that either the preview or the SCIM behavior is a新l
Review automated processing of Authentication Methods Policy audit events before the April rollout; event names and policy enforcement remain unchanged, but the logged property set will change. If applications or MDM solutions access Entra device-registration keys through Apple Keychain, update them to use MSAL and the Enterprise SSO plug-in as the compatibility guidance states. Treat Manage Agents and Account Discovery as previews, and use the Agent ID and provisioning material for planning rather than assuming GA. No tenant-wide action is supported by the remaining table, author, screenshot, overview, and removed-page edits alone.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Overview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.
| [Authenticator Lite](/entra/identity/authentication/how-to-mfa-authenticator-lite) | No | MFA |
* Passkey in Microsoft Authenticator
- clicktale
Overview of Microsoft single sign-on for Linux that enables Microsoft Entra ID integration and seamless authentication.
| **Custom claims provider** | :heavy_check_mark: | :heavy_check_mark: |
<sup>3</sup>Includes SMS and voice calls.
ai-usage: ai-assisted
| Endpoint | Supported HTTP methods | Description |
1. Confirm the action when prompted. After the feature is turned off, all SCIM API calls to the tenant return an error and billing stops.
author: jenniferf-skc
| SCIM Attribute | Microsoft Entra ID Attribute | Notes / Restrictions |
ai-usage: ai-assisted
author: jenniferf-skc
This feature currently supports the following Windows Server distributions:
This feature currently supports the following Windows Server distributions:
- Provisioning passwords isn't supported.
Microsoft Entra ID audit logs for Authentication Methods Policy updates will now show only changed properties with old and new values, improving readability. Rollout begins April 2026 worldwide. No changes to event names or policy enforcement. Organizations using automated log processing should review related logic.
Learn how to add social sign-in with Apple, Facebook and Google identity providers to your React SPA using native authentication JavaScript SDK.
Learn how to add social sign-in with Apple, Facebook and Google identity providers to your Angular SPA using native authentication JavaScript SDK.
Learn how to assign Azure roles to the local administrators group of a Windows device.
How to revoke all access for a user in Microsoft Entra ID
Staging mode can be used for several scenarios, including:
This page provides PowerShell examples to help you manage your groups in Microsoft Entra ID
Discusses new feature releases of Microsoft single sign-on for Linux
This article describes how to install cloud sync.
* GitHub Enterprise Server supports [Automated user provisioning](./github-enterprise-server-provisioning-tutorial.md).
Display name | Distinguished name
Learn about known issues when you work with automated application provisioning or cross-tenant synchronization in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Policy All Users Copilot Ai Security.
The following agents are currently available for Microsoft Entra. Due to the fast pace at which these agents are released and updated, each agent might have features at various stages of availability. Preview features are added frequently.
Enforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements where identities that meet certain criteria can only access resources if they meet specific requirements such as MFA or device compliance status.
Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.
If your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.
| --- | --- | --- | --- | --- | --- | --- |
Learn how to map your AI agent architecture to Microsoft Entra Agent ID, including blueprints, agent identities, and an agent's user account.
Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.
This article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.
1. **How many blueprints** your system requires.
The Manage Agents feature in Microsoft Entra lets you view and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-are-agent-identities.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
1. **Validate prerequisites**: Confirms Frontier is enabled, checks Microsoft Entra roles, validates that PowerShell 7+ and the Microsoft Graph beta module are installed.
Learn how agent registry experiences are converging under Microsoft Agent 365, what the change means for Microsoft Entra Agent ID, and how to view all agents in your organization.
Learn about agent service principals in Microsoft Entra and how they differ from traditional service principals in authentication, permissions, and lifecycle management.
Understand agent identity blueprints, how agents are defined, and how authentication works within the Agent ID platform.
Discover the role of agent identities in AI authentication. Understand their unique identifiers, token usage, and how they enable secure access to systems.
- **External accessibility**: Many AI agents interact with external users, third-party systems, or the public internet. This exposure creates potential pathways for adversaries to compromise agents and access organizational systems.
A Microsoft Entra documentation page was updated: Access Review Agent.
A Microsoft Entra documentation page was updated: Access Review Agent Logs Metrics.
- **Reminders**: Select this checkbox to have Microsoft Entra ID send reminders of access reviews in progress to all reviewers. Reviewers receive the reminders halfway through the review, no matter if they've finished their review or not.
| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |
- **approve** the review if the user has signed-in at least once during the last 30 days.
Conceptual article discussing workflow templates and categories with Lifecycle Workflows.
Organizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.
>[!NOTE]
1. After successful sign-in, perform administrative tasks in the governed tenant based on the roles assigned to your security group.
You can create a simple sign-up and sign-in experience for your customers by adding a user flow to your application. The user flow defines the series of sign-up steps customers follow and the sign-in methods they can use (such as email and password, one-time passcodes, social accounts from [Google](how-to-google-federation-customers.md), [Facebook](how-to-facebook-federation-customers.md), or [Apple](how-to-apple-federation-customers.md), [Microsoft Entra ID](how-to-entra-id-federation-customers.md) federation, as well as [custom OIDC](how-to-custom-oidc-federation-customers.md) identity providers). You can also collect information from customers during sign-up by selecting from a series of user built-in attributes or adding your own custom attributes.
- **Requirements for token claims**. If your application requires specific user attributes, you can include them in the token sent to your application.
Compare features and capabilities of a workforce versus an external tenant configuration. Determine which tenant type applies to your external identities scenario.
ai-usage: ai-assisted
:::image type="content" source="media/how-to-network-content-filtering/file-rule-content-types.png" alt-text="Screenshot of the Add Content Rule page showing the Matching conditions section with Activities set to Upload, and the Content types dropdown expanded with PDF selected." lightbox="media/how-to-network-content-filtering/file-rule-content-types.png":::
author: HULKsmashGithub
author: jenniferf-skc