Week in brief

Agent registry and collections retire on 1 May 2026; Conditional Access guidance carries the main admin impact.

For the week of 6 April 2026, the supplied feed contains 95 updated entries, no new or removed entries, and one Microsoft 365 Message Center major update. Most representative Learn changes are routine documentation maintenance. The substantive exceptions are the Agent ID blade retirement, guidance to replace Conditional Access custom controls, a Windows 11 Conditional Access exclusion clarification, a Global Secure Access security preview, and a clarified Conditional Access policy limit.

  • Agent ID is retiring the Agent registry and Agent collections bladesAgent ID

    The Message Center major update says Microsoft will retire both blades in the Microsoft Entra admin center starting 1 May 2026. Agent 365 is identified as the unified platform for agent management, and a new API will replace the existing API. The notice explicitly says no immediate admin action is required and supplies no migration procedure beyond the retirement announcement.

  • Microsoft directs custom-control users toward external authentication methodsEntra ID

    Security guidance in the updated Managed Policies documentation says custom controls do not satisfy multifactor authentication claim requirements and identifies external authentication methods as their replacement. Organizations using custom controls are told to migrate, subject to their external provider supporting external authentication methods and providing integration guidance. No retirement date for custom controls is supplied.

  • Conditional Access guidance changes the Windows 11 23H2 exclusion storyEntra ID

    The updated policy guidance says Windows 11, version 23H2, with KB5034848 or later no longer needs a Conditional Access exclusion intended to avoid the authentication prompt. The prompt generally occurs after an extended offline period, and a Conditional Access policy can still be used if the authentication toast is not desired. This supports reviewing existing exclusions, but the evidence does not establish that this documentation update itself introduced the underlying Windows change.

  • Global Secure Access documents AI Gateway prompt-injection protection as a previewGlobal Secure Access

    The updated Global Secure Access article describes Microsoft's AI Gateway prompt injection protection for enterprise generative AI applications. The capability is explicitly labeled preview; the supplied evidence does not state prerequisites, rollout scope, or general-availability timing.

  • The Conditional Access limit includes report-only and disabled policiesEntra ID

    Planning guidance states that a tenant can have at most 240 Conditional Access policies and that policies in every state—report-only, on, or off—count toward the limit. It also warns that creating a separate policy for each app is inefficient. This is a documentation clarification, not evidence that the limit changed during the period; capacity reviews should include test and disabled policies.

For Entra administrators

Track the 1 May 2026 Agent ID transition, although the Message Center notice says no immediate admin action is required. Organizations using custom controls have an explicit migration signal. Conditional Access administrators should review relevant Windows 11 exclusions and include report-only and disabled policies when assessing the 240-policy limit. Treat the Global Secure Access capability as a preview; the supplied evidence provides no general-availability or rollout details.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

61

What Is Entra

Updated

The Microsoft Entra product family spans identity, access, governance, and security. It covers secure end-to-end access for employees, customers, partners, workloads, and AI agents across any cloud environment.

10 April 2026

Customer intent: As an IT admin responsible for application integration, I want to learn how to integrate my company's applications with Microsoft En…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As an IT admin responsible for application integration, I want to learn how to integrate my company's applications with Microsoft Entra ID, so that I can improve security, reduce costs, increase productivity, and enable compliance through centralized Identity and Access Management..

10 April 2026

Quickstart: Create a new tenant in Microsoft Entra ID

Updated

- To learn about access management, see [Azure role-based access control (RBAC)](/azure/role-based-access-control/overview) and [Conditional Access](~/identity/conditional-access/overview.md) to help manage your organization's application and resource access.

10 April 2026

Inaccessible Tenant

Updated

- [Quickstart: Create a new tenant in Microsoft Entra ID](create-new-tenant.md)

10 April 2026

Trial user guide: Microsoft Entra Suite

Updated

- [Microsoft Entra Suite now generally available - Microsoft Community Hub](https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-suite-now-generally-available/ba-p/2520427)

10 April 2026

Reset a user's password

Updated

A Microsoft Entra documentation page was updated: Reset a user's password.

10 April 2026

Whats New Archive

Updated

In January 2024, we added the following new applications in our App gallery with Federation support:

10 April 2026

Customer intent: As a new or existing customer, I want to learn more about the new name for Azure Active Directory (Azure AD) and understand the impa…

Updated

A Microsoft Entra documentation page was updated: Customer intent: As a new or existing customer, I want to learn more about the new name for Azure Active Directory (Azure AD) and understand the impact the name change may have on other products, new or existing license(s), what I need to do, and where I can learn more about Microsoft Entra products..

10 April 2026

Policy Block By Location

Updated

- [Conditional Access templates](concept-conditional-access-policy-common.md)

8 April 2026

Conditional Access Cloud Apps

Updated

Admins can select published authentication contexts in Conditional Access policies by going to **Assignments** > **Target resources** and selecting **Authentication context** from the **Select what this policy applies to** menu.

8 April 2026

Whats New

Updated

**Type:** Plan for change

8 April 2026

Filter For Applications

Updated

1. Under **Exclude**, select **Users and groups** and choose your organization's emergency access or break-glass accounts.

8 April 2026

Microsoft Entra admin center

Updated

Overview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.

7 April 2026

Authentication

6

Optional Claims Reference

Updated

| `acrs` | Auth Context IDs | JWT | Microsoft Entra ID | Indicates the Auth Context IDs of the operations that the bearer is eligible to perform. Auth Context IDs can be used to trigger a demand for step-up authentication from within your application and services. Often used along with the `xms_cc` claim. |

9 April 2026

Authentication Passkeys Fido2

Updated

:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png" alt-text="Screenshot that shows how to delete a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png":::

8 April 2026

Policy Alt All Users Compliant Hybrid Or Mfa

Updated

The prompt for authentication usually occurs when a device is offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired.

8 April 2026

Managed Policies

Updated

[Custom controls don't satisfy multifactor authentication claim requirements](controls.md#creating-custom-controls). If your organization uses custom controls you should [migrate to external authentication methods](/entra/identity/authentication/how-to-authentication-external-method-manage), the replacement of custom controls. Your external authentication provider must support external authentication methods and provide the necessary configuration guidance for integration.

7 April 2026

Provisioning

6

Unifi Provisioning Tutorial

Updated

![Screenshot of Enterprise Application SSO View.](media/unifi-provisioning-tutorial/enterprise-application-view.png)

11 April 2026

Gtmhub Provisioning Tutorial

Updated

This article describes the steps you need to perform in both Gtmhub and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Gtmhub](https://www.gtmhub.com/) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

11 April 2026

Branding

3

Sign up for Microsoft Entra ID P1 or P2 editions

Updated

Now that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.yml).

10 April 2026

Conditional Access

3

Plan Conditional Access

Updated

Creating a policy for each app isn't efficient and makes managing policies difficult. Conditional Access has a limit of 240 policies per tenant. This 240-policy limit includes Conditional Access policies in any state, including report-only mode, on, or off.

7 April 2026

Standards

2

Architecture

1

Resilience In Credentials

Updated

|Certificate Based Authentication (CBA)|In most cases (depending on configuration) CBA will require a revocation check. This adds an external dependency on the CRL distribution point (CDP) |[Understanding the certificate revocation process](~/identity/authentication/concept-certificate-based-authentication-certificate-revocation-list.md#enforce-crl-validation-for-cas)|

7 April 2026

Developer

1

General

1

Monitoring

1

Policy All Users Require Terms Of Use

Updated

To test your policy, try to sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a test account. You should see a dialog that requires you to accept your terms of use.

8 April 2026

Security

1

Policy All Users Windows App Protection

Updated

There's a known issue where there's a pre-existing, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.

8 April 2026

Microsoft identity platform

1

Simplifying agent management with Agent 365

New

Starting May 1, 2026, Microsoft is retiring the Agent registry and Agent collections blades in the Microsoft Entra admin center. Agent 365 will be the unified platform for agent management, with a new API replacing the existing one. No immediate admin action is required.

10 April 2026
Message CenterMC1275311 on mc.merill.net ↗Major updatePlan for change

Governance

1

General

2

Services Integration Partners

Updated

|[Grit](https://www.gritiam.com/migration.html) |"Grit Software has deep expertise in consumer identity and access management, with a strong track record of helping Fortune 500 and mid-market companies execute complex transformation projects successfully and on time. For Azure AD B2C to Microsoft Entra External ID migrations, Grit's AI-powered migration service uses advanced coding agents to deliver accurate migrations in days, while ensuring customer data isn't sent to the underlying AI models." | [email protected] |

9 April 2026

General

1

Conditional Access

1

Plan Conditional Access

Updated

- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?

8 April 2026

Fundamentals

1

Mandatory Multifactor Authentication

Updated

Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md).

7 April 2026

General

1

Security

1

Troubleshooting

1