author: MicrosoftGuyJFlo
Agent registry and collections retire on 1 May 2026; Conditional Access guidance carries the main admin impact.
For the week of 6 April 2026, the supplied feed contains 95 updated entries, no new or removed entries, and one Microsoft 365 Message Center major update. Most representative Learn changes are routine documentation maintenance. The substantive exceptions are the Agent ID blade retirement, guidance to replace Conditional Access custom controls, a Windows 11 Conditional Access exclusion clarification, a Global Secure Access security preview, and a clarified Conditional Access policy limit.
- Agent ID is retiring the Agent registry and Agent collections bladesAgent ID
The Message Center major update says Microsoft will retire both blades in the Microsoft Entra admin center starting 1 May 2026. Agent 365 is identified as the unified platform for agent management, and a new API will replace the existing API. The notice explicitly says no immediate admin action is required and supplies no migration procedure beyond the retirement announcement.
- Microsoft directs custom-control users toward external authentication methodsEntra ID
Security guidance in the updated Managed Policies documentation says custom controls do not satisfy multifactor authentication claim requirements and identifies external authentication methods as their replacement. Organizations using custom controls are told to migrate, subject to their external provider supporting external authentication methods and providing integration guidance. No retirement date for custom controls is supplied.
- Conditional Access guidance changes the Windows 11 23H2 exclusion storyEntra ID
The updated policy guidance says Windows 11, version 23H2, with KB5034848 or later no longer needs a Conditional Access exclusion intended to avoid the authentication prompt. The prompt generally occurs after an extended offline period, and a Conditional Access policy can still be used if the authentication toast is not desired. This supports reviewing existing exclusions, but the evidence does not establish that this documentation update itself introduced the underlying Windows change.
- Global Secure Access documents AI Gateway prompt-injection protection as a previewGlobal Secure Access
The updated Global Secure Access article describes Microsoft's AI Gateway prompt injection protection for enterprise generative AI applications. The capability is explicitly labeled preview; the supplied evidence does not state prerequisites, rollout scope, or general-availability timing.
- The Conditional Access limit includes report-only and disabled policiesEntra ID
Planning guidance states that a tenant can have at most 240 Conditional Access policies and that policies in every state—report-only, on, or off—count toward the limit. It also warns that creating a separate policy for each app is inefficient. This is a documentation clarification, not evidence that the limit changed during the period; capacity reviews should include test and disabled policies.
Track the 1 May 2026 Agent ID transition, although the Message Center notice says no immediate admin action is required. Organizations using custom controls have an explicit migration signal. Conditional Access administrators should review relevant Windows 11 exclusions and include report-only and disabled policies when assessing the 240-policy limit. Treat the Global Secure Access capability as a preview; the supplied evidence provides no general-availability or rollout details.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
86 updatesFundamentals
61What Is Entra
UpdatedThe Microsoft Entra product family spans identity, access, governance, and security. It covers secure end-to-end access for employees, customers, partners, workloads, and AI agents across any cloud environment.
A Microsoft Entra documentation page was updated: Add or deactivate custom security attribute definitions in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Manage access to custom security attributes in Microsoft Entra ID.
- ai-gen-title
A Microsoft Entra documentation page was updated: Troubleshoot custom security attributes in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: What are custom security attributes in Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: Customer intent: As an IT admin responsible for application integration, I want to learn how to integrate my company's applications with Microsoft Entra ID, so that I can improve security, reduce costs, increase productivity, and enable compliance through centralized Identity and Access Management..
A Microsoft Entra documentation page was updated: Bulk operations in Microsoft Entra ID (Preview).
A Microsoft Entra documentation page was updated: Customer intent: I am trying to find information on the terms and conditions for Microsoft Entra ID preview programs..
- To learn about access management, see [Azure role-based access control (RBAC)](/azure/role-based-access-control/overview) and [Conditional Access](~/identity/conditional-access/overview.md) to help manage your organization's application and resource access.
author: shlipsey
- [Microsoft Entra releases and announcements](./whats-new.md)
Each assistant response includes a feedback prompt for rating, comments, or suggestions. Use the "thumbs up" or "thumbs down" buttons to provide feedback on the responses. This feedback is important and is used to improve the accuracy of Self-Service Support.
Inaccessible Tenant
Updated- [Quickstart: Create a new tenant in Microsoft Entra ID](create-new-tenant.md)
- [Microsoft Entra Suite now generally available - Microsoft Community Hub](https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-suite-now-generally-available/ba-p/2520427)
author: shlipsey
A Microsoft Entra documentation page was updated: Add or update a user's profile information and settings in the Microsoft Entra admin center.
A Microsoft Entra documentation page was updated: Add your custom domain name to your tenant.
A Microsoft Entra documentation page was updated: Add your organization's privacy information to Microsoft Entra.
A Microsoft Entra documentation page was updated: Associate or add an Azure subscription to your Microsoft Entra tenant.
A Microsoft Entra documentation page was updated: Bulk operations service limitations.
author: shlipsey
author: shlipsey
author: shlipsey
author: shlipsey
A Microsoft Entra documentation page was updated: Customer data storage for Australian and New Zealand customers in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Customer data storage for Japan customers in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Find help and get support for Microsoft Entra.
A Microsoft Entra documentation page was updated: How to find your Microsoft Entra tenant ID.
Identify and resolve license assignment problems for a group in the Microsoft 365 Admin Portal
UpdatedA Microsoft Entra documentation page was updated: Identify and resolve license assignment problems for a group in the Microsoft 365 Admin Portal.
- ai-gen-title
A Microsoft Entra documentation page was updated: Identity data storage for Australian and New Zealand customers in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Learn about group types, membership types, and access management .
ai-usage: ai-assisted
Microsoft Entra licensing
UpdatedThis article documents licensing requirements for Microsoft Entra features.
A Microsoft Entra documentation page was updated: Microsoft Entra releases and announcements.
Reset a user's password
UpdatedA Microsoft Entra documentation page was updated: Reset a user's password.
A Microsoft Entra documentation page was updated: Restore or remove a recently deleted user.
A Microsoft Entra documentation page was updated: What are the default user permissions in Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: What is group-based licensing in Microsoft Entra ID?.
A Microsoft Entra documentation page was updated: What's new at Microsoft Ignite 2025 - Microsoft Entra.
Whats New Archive
UpdatedIn January 2024, we added the following new applications in our App gallery with Federation support:
A Microsoft Entra documentation page was updated: Customer intent: As a cloud administrator, I want to understand how Microsoft Entra ID handles data residency, so that I can ensure compliance with data residency requirements and make informed decisions about storing and managing identity and access data in the cloud..
A Microsoft Entra documentation page was updated: Customer intent: As a new or existing customer, I want to learn more about the new name for Azure Active Directory (Azure AD) and understand the impact the name change may have on other products, new or existing license(s), what I need to do, and where I can learn more about Microsoft Entra products..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to compare Active Directory to Microsoft Entra ID, so that I can understand the differences and similarities between the on-premises and cloud identity and access management solutions..
Continuous Access Evaluation
Updated- has-adal-ref
Policy Block By Location
Updated- [Conditional Access templates](concept-conditional-access-policy-common.md)
Admins can select published authentication contexts in Conditional Access policies by going to **Assignments** > **Target resources** and selecting **Authentication context** from the **Select what this policy applies to** menu.
- [Conditional Access: Target resources](concept-conditional-access-cloud-apps.md)
[Conditional Access templates](concept-conditional-access-policy-common.md)
- [Conditional Access templates](concept-conditional-access-policy-common.md)
[Conditional Access templates](concept-conditional-access-policy-common.md)
[Conditional Access templates](concept-conditional-access-policy-common.md)
Policy Old Require Mfa Guest
Updated[Conditional Access templates](concept-conditional-access-policy-common.md)
Whats New
Updated**Type:** Plan for change
- [App protection policies overview](/mem/intune/apps/app-protection-policy)
Filter For Applications
Updated1. Under **Exclude**, select **Users and groups** and choose your organization's emergency access or break-glass accounts.
Microsoft Entra admin center
UpdatedOverview of the Microsoft Entra admin center interface for configuring and managing Microsoft Entra products.
Authentication
6Optional Claims Reference
Updated| `acrs` | Auth Context IDs | JWT | Microsoft Entra ID | Indicates the Auth Context IDs of the operations that the bearer is eligible to perform. Auth Context IDs can be used to trigger a demand for step-up authentication from within your application and services. Often used along with the `xms_cc` claim. |
1. Confirm your settings and set **Enable policy** to **Enabled**.
:::image type="content" border="true" source="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png" alt-text="Screenshot that shows how to delete a passkey profile." lightbox="media/how-to-authentication-passkey-profiles/delete-passkey-profile.png":::
The prompt for authentication usually occurs when a device is offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired.
Block Password Addition
Updated1. Go to the admin center and select Org settings.
Managed Policies
Updated[Custom controls don't satisfy multifactor authentication claim requirements](controls.md#creating-custom-controls). If your organization uses custom controls you should [migrate to external authentication methods](/entra/identity/authentication/how-to-authentication-external-method-manage), the replacement of custom controls. Your external authentication provider must support external authentication methods and provide the necessary configuration guidance for integration.
Provisioning
6Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Velpic.
|name.givenName|String|
Unifi Provisioning Tutorial
Updated
Vonage Provisioning Tutorial
Updated1. Log in to [Vonage admin portal](http://admin.vonage.com) with an admin user.
Gtmhub Provisioning Tutorial
UpdatedThis article describes the steps you need to perform in both Gtmhub and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Gtmhub](https://www.gtmhub.com/) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
H5mag Provisioning Tutorial
Updated1. Select the **Save** button to store the generated token.
Branding
3Now that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.yml).
CSS template reference guide
UpdatedA Microsoft Entra documentation page was updated: CSS template reference guide.
A Microsoft Entra documentation page was updated: Customer intent: As a Microsoft Entra administrator, I want to customize the sign-in experience for my organization's users so that I can provide a consistent look and feel across all sign-ins..
Conditional Access
3The **Capabilities** category includes important settings that you should review.
Learn how custom controls in Microsoft Entra Conditional Access work.
Plan Conditional Access
UpdatedCreating a policy for each app isn't efficient and makes managing policies difficult. Conditional Access has a limit of 240 policies per tenant. This 240-policy limit includes Conditional Access policies in any state, including report-only mode, on, or off.
Standards
2A Microsoft Entra documentation page was updated: Add a Microsoft Entra ID tenant as an OpenID Connect identity provider (Preview).
Entra Id Scim Api Reference
Updatedai-usage: ai-assisted
Architecture
1Resilience In Credentials
Updated|Certificate Based Authentication (CBA)|In most cases (depending on configuration) CBA will require a revocation check. This adds an external dependency on the CRL distribution point (CDP) |[Understanding the certificate revocation process](~/identity/authentication/concept-certificate-based-authentication-certificate-revocation-list.md#enforce-crl-validation-for-cas)|
Developer
1- App Studio for Microsoft Teams
General
1Policy Block Example
Updated> [!NOTE]
Monitoring
1To test your policy, try to sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) using a test account. You should see a dialog that requires you to accept your terms of use.
Security
1There's a known issue where there's a pre-existing, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
Microsoft Entra Agent ID
1 updateMicrosoft identity platform
1Starting May 1, 2026, Microsoft is retiring the Agent registry and Agent collections blades in the Microsoft Entra admin center. Agent 365 will be the unified platform for agent management, with a new API replacing the existing one. No immediate admin action is required.
Microsoft Entra ID Governance
1 updateGovernance
1- Tailspin creates a second access review for a security group with 300 guest users with the user-to-group affiliation feature enabled.
Microsoft Entra External ID
2 updatesGeneral
2|[Grit](https://www.gritiam.com/migration.html) |"Grit Software has deep expertise in consumer identity and access management, with a strong track record of helping Fortune 500 and mid-market companies execute complex transformation projects successfully and on time. For Azure AD B2C to Microsoft Entra External ID migrations, Grit's AI-powered migration service uses advanced coding agents to deliver accurate migrations in days, while ensuring customer data isn't sent to the underlying AI models." | [email protected] |
Learn about partners who can help with deployment and integration of customer identity and access management (CIAM) scenarios using Microsoft Entra External ID.
Microsoft Entra Internet Access
1 updateGeneral
1> 1. Client sees a certificate signed by your enterprise CA.
Microsoft Entra Workload ID
2 updatesConditional Access
1Plan Conditional Access
Updated- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?
Fundamentals
1Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md).
Microsoft Entra Global Secure Access
2 updatesGeneral
1Licensing Guest Users
Updated> [!NOTE]
Security
1Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
Security Copilot + Entra
1 updateTroubleshooting
11. Browse to **Entra ID** > **Conditional Access**.
