Week in brief

The clearest operational change is an Authentication Methods audit-log format update; Agent ID guidance and previews are the main substantive documentation signals

The week of 30 March 2026 is dominated by Microsoft Learn maintenance rather than release announcements. The Microsoft 365 Message Center notice is materially different: Microsoft Entra ID audit events for Authentication Methods Policy updates will change during an April 2026 worldwide rollout. The two new Agent ID pages provide architecture guidance, but the supplied evidence does not establish a product launch or general availability. The three records marked Removed concern documentation pages; they do not, on their own, establish retirement of the underlying capabilities.

  • Changed behavior: Authentication Methods Policy audit logs will show only changed propertiesEntra ID

    The Message Center notice says the worldwide rollout begins in April 2026. Audit events for Authentication Methods Policy updates will contain only properties that changed, with their old and new values. Event names and policy enforcement are unchanged, but organizations with automated log processing should review related parsing and reporting logic.

  • New documentation, not a launch: Agent ID architecture and registry guidance expandAgent ID

    Two pages marked New—Microsoft Entra Agent ID design patterns and Plan your agent identity architecture—provide a framework for choosing identity types, operation patterns, blueprints, agent identities, and an agent user account. Related updates explain how agent identities differ from traditional service principals and describe registry experiences converging under Microsoft Agent 365, including how to view organizational agents. These are architecture and experience updates, not evidence of GA.

  • Preview: Manage Agents documents owner and sponsor controlsAgent ID

    The updated Manage Agents in end user experience (Preview) article describes viewing agent identities that a user owns or sponsors, reviewing their details, and taking actions such as enabling, disabling, or requesting access. The explicit Preview label means the supplied update does not establish general availability or a tenant-wide behavior change.

  • Compatibility guidance: Apple applications and MDM solutions may need the Enterprise SSO plug-inEntra ID

    The updated Apple SSO Plugin article states that applications or MDM solutions relying on Microsoft Entra device-registration keys through Keychain must be updated to use the Microsoft Authentication Library and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform. The evidence presents this as compatibility guidance, not as a dated service-retirement announcement.

  • Provisioning guidance combines Account Discovery preview material with SCIM lifecycle clarificationEntra ID

    The updated Account Discovery (preview) article covers finding and categorizing existing accounts in target applications, matching them to Microsoft Entra users, and preparing for provisioning governance. Related SCIM API reference, schema, enablement, disablement, and troubleshooting pages were also refreshed; the disablement guidance states that turning off the feature makes all SCIM API calls to the tenant return errors and stops billing. The records do not say that either the preview or the SCIM behavior is a新l

For Entra administrators

Review automated processing of Authentication Methods Policy audit events before the April rollout; event names and policy enforcement remain unchanged, but the logged property set will change. If applications or MDM solutions access Entra device-registration keys through Apple Keychain, update them to use MSAL and the Enterprise SSO plug-in as the compatibility guidance states. Treat Manage Agents and Account Discovery as previews, and use the Agent ID and provisioning material for planning rather than assuming GA. No tenant-wide action is supported by the remaining table, author, screenshot, overview, and removed-page edits alone.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

7

Microsoft Entra admin center

Updated

Overview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.

4 April 2026

Authentication

Updated

| [Authenticator Lite](/entra/identity/authentication/how-to-mfa-authenticator-lite) | No | MFA |

2 April 2026

Microsoft single sign-on for Linux

Updated

Overview of Microsoft single sign-on for Linux that enables Microsoft Entra ID integration and seamless authentication.

1 April 2026

Native Authentication

Updated

| **Custom claims provider** | :heavy_check_mark: | :heavy_check_mark: |

1 April 2026

Standards

7

Disable Scim Api

Updated

1. Confirm the action when prompted. After the feature is turned off, all SCIM API calls to the tenant return an error and billing stops.

1 April 2026

Authentication

6

Known Issues

Updated

- Provisioning passwords isn't supported.

3 April 2026

General

6

Users Revoke Access

Updated

How to revoke all access for a user in Microsoft Entra ID

3 April 2026

Groups Settings V2 Cmdlets

Updated

This page provides PowerShell examples to help you manage your groups in Microsoft Entra ID

3 April 2026

Provisioning

3

Github Enterprise Server Tutorial

Updated

* GitHub Enterprise Server supports [Automated user provisioning](./github-enterprise-server-provisioning-tutorial.md).

3 April 2026

Security

2

Entra Agents

Updated

The following agents are currently available for Microsoft Entra. Due to the fast pace at which these agents are released and updated, each agent might have features at various stages of availability. Preview features are added frequently.

2 April 2026

Architecture

1

Secure Generative Ai

Updated

Enforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements where identities that meet certain criteria can only access resources if they meet specific requirements such as MFA or device compliance status.

3 April 2026

Governance

1

Microsoft identity platform

1

Apple Sso Plugin

Updated

If your applications or MDM solutions depend on accessing Microsoft Entra device registration keys through Keychain, you must update them to use the Microsoft Authentication Library (MSAL) and the Enterprise SSO plug-in to maintain compatibility with the Microsoft identity platform.

3 April 2026

Monitoring

1

Sla Performance

Updated

| --- | --- | --- | --- | --- | --- | --- |

3 April 2026

Architecture

4

Plan your agent identity architecture

New

Use this decision guide to choose the right identity type, operation pattern, and blueprint and agent identity structure for your AI agents in Microsoft Entra Agent ID.

4 April 2026

Agent Id Design Patterns

Updated

This article describes common AI agent deployment patterns and how they map to Microsoft Entra Agent ID. The article starts with a review of key identity concepts, describes permisssions and trust boundaries, and then walks through common deployment patterns.

4 April 2026

General

3

Manage Agents in end user experience (Preview)

Updated

The Manage Agents feature in Microsoft Entra lets you view and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-are-agent-identities.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.

1 April 2026

Agent Id Ai Guided Setup

Updated

1. **Validate prerequisites**: Confirms Frontier is enabled, checks Microsoft Entra roles, validates that PowerShell 7+ and the Microsoft Graph beta module are installed.

1 April 2026

Authentication

2

Fundamentals

2

Security For Ai Overview

Updated

- **External accessibility**: Many AI agents interact with external users, third-party systems, or the public internet. This exposure creates potential pathways for adversaries to compromise agents and access organizational systems.

1 April 2026

Governance

5

Access Review Agent

Removed

A Microsoft Entra documentation page was updated: Access Review Agent.

2 April 2026

Create Access Review

Updated

- **Reminders**: Select this checkbox to have Microsoft Entra ID send reminders of access reviews in progress to all reviewers. Reviewers receive the reminders halfway through the review, no matter if they've finished their review or not.

2 April 2026

Deploy Access Reviews

Updated

| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |

2 April 2026

Fundamentals

3

Identity Governance Overview

Updated

Organizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.

2 April 2026

Authentication

1

Delegated Administration

Updated

1. After successful sign-in, perform administrative tasks in the governed tenant based on the roles assigned to your security group.

31 March 2026

Fundamentals

3

Customers Ciam

Updated

You can create a simple sign-up and sign-in experience for your customers by adding a user flow to your application. The user flow defines the series of sign-up steps customers follow and the sign-in methods they can use (such as email and password, one-time passcodes, social accounts from [Google](how-to-google-federation-customers.md), [Facebook](how-to-facebook-federation-customers.md), or [Apple](how-to-apple-federation-customers.md), [Microsoft Entra ID](how-to-entra-id-federation-customers.md) federation, as well as [custom OIDC](how-to-custom-oidc-federation-customers.md) identity providers). You can also collect information from customers during sign-up by selecting from a series of user built-in attributes or adding your own custom attributes.

4 April 2026

Planning Your Solution

Updated

- **Requirements for token claims**. If your application requires specific user attributes, you can include them in the token sent to your application.

4 April 2026

Supported Features Customers

Updated

Compare features and capabilities of a workforce versus an external tenant configuration. Determine which tenant type applies to your external identities scenario.

4 April 2026

Authentication

1

General

2

Network Content Filtering

Updated

:::image type="content" source="media/how-to-network-content-filtering/file-rule-content-types.png" alt-text="Screenshot of the Add Content Rule page showing the Matching conditions section with Activities set to Upload, and the Content types dropdown expanded with PDF selected." lightbox="media/how-to-network-content-filtering/file-rule-content-types.png":::

2 April 2026

Fundamentals

1