Week in brief

Conditional Access enforcement changes lead a week of Entra policy, billing, and authentication decisions

The week of 13 April 2026 was mainly a documentation-maintenance cycle—75 updates, two new entries, and one removal—but its meaningful exceptions are operationally important. New and revised Conditional Access guidance describes a behavior rollout; Message Center updates cover a guest-governance subscription prerequisite and the withdrawal of planned passkey registration-campaign changes; and targeted updates add a regional External ID SMS requirement and a provisioning security warning. The supplied evidence does not state a general-availability launch. Account Discovery and Global Secure Access MCP traffic logs are explicitly marked preview, while many remaining edits are tutorials, cross-links, or setup clarification.

  • Conditional Access enforcement for resource exclusions is changingEntra ID — Conditional Access

    Changed behavior / rollout. Microsoft Entra ID is rolling out improved enforcement for policies that target 'All resources' and include one or more resource exclusions. The stated target behavior gives sign-ins requesting only baseline scopes the same Conditional Access protections as other resource access. Related guidance says the only-scope flow also applies to policies explicitly targeting Azure AD Graph; when an application requests any additional scope, behavior is unchanged. Administrators can preview the改行为

  • Guest governance now has an Azure subscription prerequisiteID Governance

    Message Center major update, not a feature launch. The item says Microsoft Entra ID Governance requires a tenant to link an Azure subscription, beginning January 30, 2026, to use guest governance features. Without the link, creating or updating guest-scoped policies is blocked; existing policies continue to run, while new actions need subscription-linked billing under the Monthly Active User model. The feed supplies no broader billing requirement for other Governance features.

  • Passkeys will not be added to Microsoft Registration Campaigns as plannedEntra ID — Passkeys and Registration Campaigns

    Message Center plan withdrawal. Microsoft says it will not proceed with adding Passkeys (FIDO2) as an authentication method in Microsoft Registration Campaigns starting April 2026. The previously planned automatic updates and nudges for MFA-capable users are also not being implemented at this time. This changes the campaign plan; it is not a statement that passkeys generally are retired from Microsoft Entra ID.

  • External ID SMS verification gets regional opt-in guidance (preview)External ID

    Preview documentation for Microsoft Entra External ID says some regions require administrators to enable country codes before external tenants can receive SMS telephony verification. The supplied summary does not identify the regions or the exact setting, so this is a regional requirement rather than evidence of a tenant-wide change.

  • Global Relay provisioning connector carries a security warningEntra ID — Provisioning

    Security guidance in the Entra ID provisioning tutorial says Global Relay Identity Sync uses a SCIM authorization method that is no longer supported because of security concerns. It also says work is underway with Global Relay to move to a more secure authorization method. The supplied update does not announce a connector shutdown, retirement date, or replacement procedure.

For Entra administrators

Assess Conditional Access policies that target All resources with resource exclusions; the supplied guidance supports previewing the improved behavior and retaining legacy behavior, but provides no rollout date. Tenants using guest governance should verify the required Azure subscription linkage because guest-scoped policy creation or updates can be blocked without it. Registration-campaign plans should not depend on the planned passkey additions or MFA nudges. External ID tenants using SMS should check regional country-code requirements, and organizations using Global Relay Identity Sync should flag the connector's SCIM authorization warning for vendor follow-up. The evidence supplies no affected-region list or Global Relay deadline.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Provisioning

19

Clear on-premises attributes from migrated Microsoft Entra ID users

Updated

After migrating your users and groups to Microsoft Entra ID, you may be ready to decommission your on-premises Active Directory and uninstall sync tools. After turning off directory synchronization, you can manage these objects directly in Microsoft Entra ID.

15 April 2026

Leapsome Provisioning Tutorial

Updated

1. Sign in to your [Leapsome Admin Console](https://www.Leapsome.com/app/#/login). Navigate to **Settings > Admin Settings**.

15 April 2026

Jostle Provisioning Tutorial

Updated

Before you begin, you’ll need to create an **Automation user** in your Jostle intranet. This is the account you’ll use to configure with Azure. Automation users can be created in Admin **Settings > User accounts and data > Manage Automation users**.

15 April 2026

Keepabl Provisioning Tutorial

Updated

1. Sign in to [Keepabl Admin Portal](https://app.keepabl.com) and then navigate to **Account Settings > Your Organization**, where you’ll see the **Single Sign-On (SSO)** section.

15 April 2026

Functions For Customizing Application Data

Updated

[Append](#append)      [AppRoleAssignmentsComplex](#approleassignmentscomplex)      [BitAnd](#bitand)      [CBool](#cbool)      [CDate](#cdate)      [Coalesce](#coalesce)      [ConvertToBase64](#converttobase64)      [ConvertToUTF8Hex](#converttoutf8hex)      [Count](#count)      [CStr](#cstr)      [DateAdd](#dateadd)      [DateDiff](#datediff)      [DateFromNum](#datefromnum)  [DefaultDomain](#defaultdomain)      [FormatDateTime](#formatdatetime)      [Guid](#guid)      [IgnoreFlowIfNullOrEmpty](#ignoreflowifnullorempty)     [IIF](#iif)     [InStr](#instr)      [IsNull](#isnull)      [IsNullOrEmpty](#isnullorempty)      [IsPresent](#ispresent)      [IsString](#isstring)      [Item](#item)      [Join](#join)      [Left](#left)      [Len](#len)      [Mid](#mid)      [NormalizeDiacritics](#normalizediacritics)       [Not](#not)      [Now](#now)      [NumFromDate](#numfromdate)      [PCase](#pcase)      [RandomString](#randomstring)      [Redact](#redact)      [RemoveDuplicates](#removeduplicates)      [Replace](#replace)      [SelectUniqueValue](#selectuniquevalue)     [SingleAppRoleAssignment](#singleapproleassignment)     [Split](#split)    [StripSpaces](#stripspaces)      [Switch](#switch)     [ToLower](#tolower)     [ToUpper](#toupper)     [Word](#word)

14 April 2026

Cisco User Management For Secure Access Provisioning Tutorial

Updated

1. In the **Tenant URL** field, input your Cisco User Management for Secure Access Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Cisco User Management for Secure Access. If the connection fails, ensure your Cisco User Management for Secure Access account has the required admin permissions and try again.

14 April 2026

Golinks Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

14 April 2026

Gong Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

14 April 2026

Chaos Provisioning Tutorial

Updated

1. In the **Tenant URL** field, input your Chaos Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Chaos. If the connection fails, ensure your Chaos account has the required admin permissions and try again.

14 April 2026

Chatwork Provisioning Tutorial

Updated

1. In the **Tenant URL** field, input your Chatwork Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Chatwork. If the connection fails, ensure your Chatwork account has the required admin permissions and try again.

14 April 2026

Checkproof Provisioning Tutorial

Updated

1. In the **Tenant URL** field, input your CheckProof Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to CheckProof. If the connection fails, ensure your CheckProof account has the required admin permissions and try again.

14 April 2026

Cinode Provisioning Tutorial

Updated

1. In the **Tenant URL** field, input your Cinode Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Cinode. If the connection fails, ensure your Cinode account has the required admin permissions and try again.

14 April 2026

Fundamentals

6

Conditional Access Cloud Apps

Updated

Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, are enforced in user sign-in flows where the client application requests only these scopes. There is no change in behavior when an application requests any additional scope beyond those listed above.

15 April 2026

Fido2 Compatibility

Updated

For more information about how to sign in with FIDO2 security keys on a Windows device, see [Enable FIDO2 security key sign-in to Windows 10 and 11 devices with Microsoft Entra ID](howto-authentication-passwordless-security-key-windows.md).

14 April 2026

Authentication Passkeys Fido2

Updated

For more information about passkey authentication, see [Support for FIDO2 authentication with Microsoft Entra ID](~/identity/authentication/concept-fido2-compatibility.md).

14 April 2026

Wrike Provisioning Tutorial

Updated

Microsoft Entra ID uses a concept called *assignments* to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users or groups that were assigned to an application in Microsoft Entra ID are synchronized.

14 April 2026

General

6

Configure App Management Policies

Updated

- [Attribute Definition Administrator](/entra/identity/role-based-access-control/permissions-reference#attribute-definition-administrator)

17 April 2026

Standards

4

On Premises Scim Provisioning

Updated

8. Leave the portal and open the provisioning agent installer, agree to the terms of service, and select **Install**.

15 April 2026

Global Relay Identity Sync Provisioning Tutorial

Updated

> Global Relay Identity Sync provisioning connector utilizes a SCIM authorization method that's no longer supported due to security concerns. Efforts are underway with Global Relay to switch to a more secure authorization method.

14 April 2026

Use Scim To Provision Users And Groups

Updated

![Provisioning from Microsoft Entra ID to an app with SCIM](media/use-scim-to-provision-users-and-groups/scim-provisioning-overview.png)

14 April 2026

Workgrid Provisioning Tutorial

Updated

![Screenshot of the Account Management A P I section with the Create Credentials option called out.](media/Workgrid-provisioning-tutorial/scim.png)

14 April 2026

Authentication

3

Improved Enforcement Resource Exclusions

Updated

Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target **All resources** and include one or more **resource exclusions**. This change ensures that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access.

15 April 2026

Kerberos

Updated

- Microsoft Entra Kerberos doesn't issue partial TGTs to identities that aren't synced to Microsoft Entra ID.

15 April 2026

Conditional Access

3

Developer

1

V2 Howto App Gallery Listing

Updated

Here's the quick checklist for you before you submit the application request to list your application in Microsoft Entra App Gallery.

17 April 2026

Governance

1

General

2

Agent Id Ai Guided Setup

Updated

The blueprint principal must be created as a separate step after the blueprint. Run:

18 April 2026

Governance

5

Automatic Governance Relationships

Updated

If you defined a default [governance policy template](governance-policy-templates.md), a new governance relationship forms between the home (governing) tenant and the newly created add-on (governed) tenant, using the default policy template.

18 April 2026

Microsoft Entra ID Governance: Azure subscription required to continue using guest governance features

New

Starting January 30, 2026, Microsoft Entra ID Governance requires tenants to link an Azure subscription to use guest governance features. Without this, creating or updating guest-scoped policies will be blocked. Existing policies run, but new actions need subscription-linked billing under the Monthly Active User model.

17 April 2026
Message CenterMC1225192 on mc.merill.net ↗Major updatePlan for change

Entitlement Management Catalog Create

Updated

This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).

15 April 2026

What Are Lifecycle Workflows

Updated

- Manage user lifecycle at scale. As your organization grows, the need for other resources to manage user lifecycle decreases.

15 April 2026

Fundamentals

2

Entitlement Management Overview

Updated

| access package | A bundle of resources that a team or project needs and is governed with policies. An access package is always contained in a catalog. You would create a new access package for a scenario in which identities need to request access for themselves. |

15 April 2026

Authentication

4

Quickstart: Add a guest user with PowerShell

Updated

In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.

18 April 2026

General

3

Add Facebook as an identity provider

Updated

Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.

18 April 2026

Add custom attributes

Updated

Learn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.

18 April 2026

Add and manage admin accounts

Updated

Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.

18 April 2026

Standards

2

Set up AD FS federation

Updated

Learn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.

18 April 2026

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

18 April 2026

Developer

1

Using role-based access control for apps

Updated

Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.

18 April 2026

Fundamentals

1

Microsoft identity platform

1

Reset guest redemption status

Updated

Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.

18 April 2026

Security

1

Invite internal users to B2B collaboration

Updated

If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can move to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials. Use either PowerShell or the Microsoft Graph invitation API.

18 April 2026

Security

1

Fundamentals

1

Decentralized Identifier Overview

Updated

The issuer is an organization that creates an issuance solution requesting information from a user. The information is used to verify the user’s identity. For example, Woodgrove, Inc. has an issuance solution that enables them to create and distribute verifiable credentials (VCs) to all their employees. The employee uses the Authenticator app to sign in with their username and password, which passes an ID token to the issuing service. Once Woodgrove, Inc. validates the ID token submitted, the issuance solution creates a VC that includes claims about the employee and is signed with Woodgrove, Inc. DID. The employee now has an employer signed verifiable credential which includes the employee's DID as the subject DID.

15 April 2026

Fundamentals

6

Install Android Client

Updated

- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).

18 April 2026

External User Access

Updated

**Q: Is this feature supported from a windows Entra registered device(BYOD)?**

17 April 2026

What is Global Secure Access?

Updated

Learn how Microsoft's Security Service Edge (SSE) solution, Global Secure Access, provides network access control and visibility to users and devices inside and outside a traditional office.

16 April 2026

Remote Network Connectivity

Updated

Learn how remote network connectivity in Global Secure Access allows users to connect to your corporate network from a remote location, such as a branch office.

16 April 2026

Licensing Guest Users

Updated

Global Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).

15 April 2026

Licensing Guest Users

Updated

Global Secure Access uses Monthly Active User (MAU) licensing for guest users. This model is different from licensing for employees. For complete details on licensing for employees, see [Global Secure Access licensing overview](overview-what-is-global-secure-access.md#licensing-overview).

13 April 2026

General

3

Developer

1

Microsoft identity platform

1

Monitoring

1

Security

1