All accounts that sign in to perform operations cited in the [applications section](#application-ids-and-urls) must complete MFA when the enforcement begins. Users aren't required to use MFA if they access other applications, websites, or services hosted on Azure. Each application, website, or service owner listed earlier controls the authentication requirements for users.
Cross-tenant group sync, Account Discovery, and automatic passkey campaign updates lead a documentation-heavy week
The week of 20 April 2026 was mostly low-impact documentation maintenance: 97 Microsoft Learn entries were updated, with no items marked new or removed, alongside three Message Center notices. Those notices carry the substantive rollout information: ID Governance cross-tenant security group synchronization is in public preview with general availability announced by the end of May; ID Governance Account Discovery is an off-by-default public preview with general availability beginning in August; and Entra ID Registration Campaigns will receive automatic Passkeys (FIDO2) updates worldwide from mid-May through late June. The other notable material is documentation or security guidance around Agent ID backup and recovery, PIM, authentication, and MFA—not evidence of additional launches or retirements.
- Cross-tenant security group synchronization remains in preview, with GA planned by the end of MayID Governance
The 23 April Message Center notice describes Microsoft Entra cross-tenant security group synchronization as a capability for simplifying collaboration and centralizing group management across tenants. It places the public-preview start in late January 2026 and general availability by the end of May 2026. Administrators can enable synchronization by updating attribute mappings and access policies. This is a preview-to-GA timeline, not a GA announcement in the reporting week.
- Registration Campaigns will receive automatic passkey-related updatesEntra ID
The 24 April Message Center update is a rollout and behavior notice, not a new passkey method: Registration Campaigns will continue to support Passkeys (FIDO2) in both Enabled and Microsoft-managed states. From mid-May through late June 2026, eligible tenants will see automatic campaign-setting updates and passkey registration nudges after MFA worldwide. The message explicitly says no immediate admin action is required.
- Account Discovery is an opt-in public preview, not GAID Governance
The 22 April notice introduces Account Discovery under ID Governance, with public preview starting in mid-April 2026 and general availability beginning in August 2026. It is intended to identify local and orphaned application accounts outside Entra ID, improving access visibility and control. It is off by default and requires administrator opt-in; the notice says there is no user impact unless an admin acts.
- Agent ID backup-and-recovery content is a documentation update, not a dated launchAgent ID
An updated Agent ID What's New article says Microsoft Entra Backup and Recovery is built in and always on by default, automatically backing up critical directory objects including users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication and authorization policy. Because the supplied evidence is only a Learn-page update and gives no launch, preview, or GA status, it should not be treated as a confirmed product launch or as proofม
- PIM and authentication pages clarify existing operating and security guidanceID Governance and Entra ID
The 24 April PIM documentation refresh specifies that delegated approvers have 24 hours to approve Microsoft Entra and Azure resource role activation requests, and that the window is not configurable. It also describes Discovery and insights (preview) as an analysis-and-action tool for viewing permanent privileged assignments and changing them to just-in-time assignments, alongside guidance for PIM groups, alerts, and access reviews. Related Entra ID edits cover system-preferred authentication, Conditional Access:
The explicit actions are limited. If adopting cross-tenant group synchronization, the notice says to enable it through attribute mappings and access policies; Account Discovery requires administrator opt-in and otherwise has no user impact; and the passkey campaign notice says no immediate action is required because eligible tenants are updated automatically. Treat the Learn edits as reference or security guidance rather than assuming they changed tenant settings or enforcement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
40 updatesFundamentals
16- [Choosing authentication methods for your organization](concept-authentication-methods.md)
Fido2 Hardware Vendor
UpdatedIn the Microsoft Entra ID authentication methods policy, administrators can enforce attestation for FIDO2 security keys. When **Enforce attestation** is set to **Yes**, Microsoft requires extra metadata from passkeys (FIDO2) that are registered with the tenant. As a vendor, your passkey (FIDO2) is usable when attestation is enforced if the following requirements are met.
Whats New Archive
Updated**Product capability:** Identity Security & Protection
- Users are **3x more successful signing-in with synced passkey than legacy authentication methods (95% vs 30%)**
Whats New Ignite 2025
Updated- [Account recovery cost savings estimator](../identity/authentication/how-to-account-recovery-cost-savings-estimator.md) (New)
| Windows Server 2019 | Microsoft Edge, [Chrome](#chrome-support) |
Whats New
Updated**Service category:** Authentications (Logins)
- You must have at least the [Microsoft Entra ID P1](../identity/conditional-access/overview.md#license-requirements) license.
Learn how authentication transfer connects users to apps across desktop and mobile devices, including supported apps, end-user experience, limitations, and troubleshooting.
Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled for text message and voice call users |
Whats New
Updated**Service category:** Identity Protection
Fido2 Hardware Vendor
UpdatedFeitian ePass FIDO Authenticator (CTAP2.1, CTAP2.0, U2F)|12755c32-8ad1-46eb-881c-e0b38d848b09|❌|✅|❌|❌
Whats New Archive
Updated**Service category:** Authentications (Login)
Authentication
8V2 Protocols Oidc
Updated| `redirect_uri` | Recommended | The redirect URI of your app, where authentication responses can be sent and received by your app. It must exactly match one of the redirect URIs you registered in the portal, except that it must be URL-encoded. If not present, the endpoint picks one registered `redirect_uri` at random to send the user back to. |
Security Emergency Access
Updated1. [Configure your emergency access accounts](#configuration-requirements) to use passwordless authentication.
Microsoft Entra will continue supporting Passkeys (FIDO2) in Enabled and Microsoft-managed states for Registration Campaigns, rolling out worldwide from mid-May to late June 2026. Eligible tenants will see automatic updates to campaign settings and passkey registration nudges after MFA, with no immediate action required.
To simplify and secure sign-in to applications and services, Microsoft Entra ID provides SMS-based authentication. This method lets users such as frontline workers sign in using only a registered phone number and a one-time passcode (OTP) sent via SMS, without needing a username or password.
- [Enable passkeys (FIDO2) for your organization](how-to-authentication-passkeys-fido2.md)
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
You can continue to sign in to your cloud services by using a synchronized password that is expired in your on-premises environment. Your cloud password is updated the next time you change the password in the on-premises environment.
Provisioning
81. Log in to [Shopify Plus organization admin](https://shopify.plus). Navigate to **Users > Security**.
The Microsoft Entra Workday provisioning connector retrieves worker data using the Workday Integration System User (ISU) account via the `Get_Workers` SOAP API. However, the Workday ISU account always operates in the Pacific Time Zone (PT), causing delays in processing termination events for workers in time zones ahead of PT.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forms & Workflow.
1. Navigate to the **User Management > User Provisioning** section of your settings.
1. Log into LanSchool Air as Site Admin.
1. Sign in to https://app.kpifire.com with admin rights
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Kno2fy Provisioning Tutorial
Updated1. Select **+ New configuration**.
General
3- User Administrator
Learn how to configure single sign-on between Microsoft Entra ID and STACKIT Cloud.
- onPremisesDistinguishedName
Microsoft identity platform
2SMS-based authentication is available to Microsoft apps integrated with the Microsoft identity platform (Microsoft Entra ID). This article lists the web and mobile apps that support SMS-based authentication.
Mfa Authenticator Lite
Updated- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
Security
1Group Policy
UpdatedThe backup location and network share are configured with appropriate Active Directory security groups to ensure only authorized administrators can access the backup data. The ACL model aligns with the permissions used in Group Policy Management Console (GPMC), maintaining consistency with existing GPO management practices.
Standards
1author: garrodonnell
Troubleshooting
1If you still can't resolve your problem, contact ServiceNow support, and ask them to turn on SOAP debugging to help troubleshoot.
Microsoft Entra Agent ID
1 updateFundamentals
1Whats New
UpdatedMicrosoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.
Microsoft Entra ID Protection
3 updatesFundamentals
2Identity Protection Risks
Updated| Sign-in risk detection | Detection type | Type | riskEventType |
Conditional Access Grant
UpdatedWhen user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation control](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control).
Troubleshooting
1Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Microsoft Entra ID Governance
38 updatesGovernance
31If you're starting out using Privileged Identity Management (PIM) in Microsoft Entra ID to manage role assignments in your organization, you can use the **Discovery and insights (preview)** page to get started. This feature shows you who is assigned to privileged roles in your organization and how to use PIM to quickly change permanent role assignments into just-in-time assignments. You can view or make changes to your permanent privileged role assignments in **Discovery and insights (preview)**. It's an analysis tool and an action tool.
Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Alerts page.
Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Privileged Identity Management dashboard. Select the alert to see a report that lists the users or roles that triggered the alert.
The need for access to privileged Azure resource and Microsoft Entra roles by your users changes over time. To reduce the risk associated with stale role assignments, you should regularly review access. You can use Microsoft Entra Privileged Identity Management (PIM) to create access reviews for privileged access to Azure resource and Microsoft Entra roles. You can also configure recurring access reviews that occur automatically. This article describes how to create one or more access reviews.
The following table provides guidance on using the new PowerShell cmdlets in the newer Azure PowerShell module.
**Privileged Identity Management (PIM)** provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune.
You can use Privileged Identity Management (PIM) in Microsoft Entra ID to have just-in-time membership in the group or just-in-time ownership of the group.
With Privileged Identity Management (PIM) and Microsoft Entra ID, you can configure activation of group membership and ownership to require approval. You can also choose users or groups from your Microsoft Entra organization as delegated approvers.
Microsoft Entra Privileged Identity Management (PIM) enables you to configure roles so that they require approval for activation, and choose users or groups from your Microsoft Entra organization as delegated approvers. Select two or more approvers for each role to reduce workload for the Privileged Role Administrator. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must resubmit a new request. The 24-hour approval time window isn't configurable.
Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure roles to require approval for activation, and choose one or multiple users or groups as delegated approvers. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must re-submit a new request. The 24-hour approval time window isn't configurable.
With Microsoft Entra Privileged Identity Management (PIM), you can manage the built-in Azure resource roles, and custom roles, including (but not limited to):
In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.
With Microsoft Entra ID, a Global Administrator can make **permanent** Microsoft Entra admin role assignments. These role assignments can be created using the [Microsoft Entra admin center](~/identity/role-based-access-control/permissions-reference.md) or using [PowerShell commands](/powershell/module/azuread/#directory_roles).
When working with your organization's groups in Privileged Identity Management (PIM), you can view activity, activations, and audit history for Microsoft Entra group membership or ownership changes.
In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group. Use groups to provide access to Microsoft Entra roles, Azure roles, and various other scenarios. To manage a Microsoft Entra group in PIM, you must bring it under management in PIM.
Privileged Role Administrators can review privileged access once an [access review starts](./pim-create-roles-and-resource-roles-review.md). Privileged Identity Management (PIM) in Microsoft Entra ID automatically sends an email that prompts users to review their access. If a user doesn't receive an email, you can send them the instructions for [how to perform an access review](./pim-perform-roles-and-resource-roles-review.md).
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
You can use Privileged Identity Management (PIM) in Microsoft Entra ID, to improve the protection of your Azure resources. This helps:
Email notifications in PIM
UpdatedPrivileged Identity Management (PIM) lets you know when important events occur in your Microsoft Entra organization, such as when a role is assigned or activated. Privileged Identity Management keeps you informed by sending you and other participants email notifications. These emails might also include links to relevant tasks, such as activating or renewing a role. This article describes what these emails look like, when they are sent, and who receives them.
Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for Azure resources. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for roles in Microsoft Entra ID. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to Microsoft Entra administrators to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Privileged Identity Management (PIM) in Microsoft Entra ID provides controls to manage the access and assignment lifecycle for group membership and ownership. Administrators can assign start and end date-time properties for group membership and ownership. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Privileged Identity Management (PIM) simplifies how enterprises manage privileged access to resources in Microsoft Entra ID, and other Microsoft online services like Microsoft 365 or Microsoft Intune. Follow the steps in this article to perform reviews of access to roles.
Privileged Identity Management (PIM), part of Microsoft Entra, includes three providers:
You can manage just-in-time assignments to all [Microsoft Entra roles](~/identity/role-based-access-control/permissions-reference.md) and all [Azure roles](/azure/role-based-access-control/built-in-roles) using Privileged Identity Management (PIM) in Microsoft Entra ID. Azure roles include built-in and custom roles attached to your management groups, subscriptions, resource groups, and resources. However, there are a few roles that you can't manage. This article describes the roles you can't manage in Privileged Identity Management.
Use Privileged Identity Management (PIM) to manage, control, and monitor access within your Microsoft Entra organization. With PIM you can provide as-needed and just-in-time access to Azure resources, Microsoft Entra resources, and other Microsoft online services like Microsoft 365 or Microsoft Intune.
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
1. If your scenario requires the ability to override a separation of duties check, then you can also [set up additional access packages for those override scenarios](entitlement-management-access-package-incompatible.md#configuring-multiple-access-packages-for-override-scenarios).
Microsoft Entra ID Governance introduces Account Discovery to identify local and orphaned application accounts outside Entra ID, improving access visibility and control. Public preview starts mid-April 2026; general availability begins August 2026. The feature is off by default and requires admin opt-in, with no user impact unless acted upon.
Fundamentals
6You can use the Microsoft Entra Privileged Identity Management (PIM) audit history to see the role assignment changes and activations done through PIM. Data is available for the past 30 days. If you want to retain audit data for longer than the default retention period, you can use Azure Monitor to route it to an Azure storage account. For more information, see [Archive Microsoft Entra logs to an Azure storage account](~/identity/monitoring-health/howto-archive-logs-to-storage-account.md). To see full audit history of Microsoft Entra ID activity including administrator, end user, and synchronization activity, you can use the [Microsoft Entra security and activity reports](~/identity/monitoring-health/overview-monitoring-health.md).
Microsoft Entra ID allows you to grant users just-in-time membership and ownership of groups through Privileged Identity Management (PIM) for Groups. Groups can be used to control access to a variety of scenarios, including Microsoft Entra roles, Azure roles, Azure SQL, Azure Key Vault, Intune, other application roles, and third-party applications.
You can use a resource dashboard to perform an access review in Privileged Identity Management (PIM). The Admin View dashboard in Microsoft Entra ID, part of Microsoft Entra, has three primary components:
Privileged Identity Management (PIM) is a service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune. The following video explains important PIM concepts and features.
Microsoft Entra introduces cross-tenant security group synchronization to simplify collaboration and centralize group management across tenants. Public preview starts late January 2026; general availability by end of May 2026. Admins can enable sync by updating attribute mappings and access policies. No compliance issues identified.
Now that you have provided the connectivity details and matching attribute as part of your provisioning configuration, Microsoft Entra can discover the existing users in your application. Click on the [discover identities](~/identity/app-provisioning/how-to-account-discovery.md) button in the provisioning overview page. Once the report is generated, you will have a view of all the users in your application, which users in the application match with a Microsoft Entra ID user, which users are already assigned to the enterprise application in Microsoft Entra ID, and which users in the application are not matched with a Microsoft Entra ID user).
Troubleshooting
1If you're experiencing issues with Privileged Identity Management (PIM) in Microsoft Entra ID, the information included in this article can help you resolve these issues.
Microsoft Entra External ID
11 updatesGeneral
5Shows how an admin can add sponsors to guest users in Microsoft Entra B2B collaboration.
Learn about customizing the language experience in your user flows in Microsoft Entra External ID.
Learn how to give cloud B2B users access to on-premises apps with Microsoft Entra B2B collaboration.
Current limitations for Microsoft Entra B2B collaboration
> [!NOTE]
Authentication
2Learn about how to customize the browser language for your app's authentication experience to provide a personalized sign-in.
- Authentication context or step-up authentication.
Fundamentals
1Compare solutions for using Microsoft Entra External ID to work with people outside your organization, including B2B collaboration and Azure AD B2C.
Microsoft identity platform
1author: garrodonnell
Security
1Give locally managed external partners access to both local and cloud resources using the same credentials with Microsoft Entra B2B collaboration.
Standards
1To federate users to your identity provider, first prepare your identity provider to accept federation requests from your external tenant. To do this preparation, add your redirect URIs and register your identity provider to be recognized.
Microsoft Entra Internet Access
5 updatesGeneral
2| Aspect | FQDN filtering | URL filtering |
- **100 = highest priority**: Evaluated first.
Security
2*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.
Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.
Fundamentals
11. Download the GSA client for Windows 11 from one of the following links. You can also use the [sample PowerShell script](scripts/powershell-windows-client-install-proof-of-concept.md).
Microsoft Entra Verified ID
1 updateAuthentication
1- [Face Check with Microsoft Entra Verified ID pricing](~/verified-id/verified-id-pricing.md)
Microsoft Entra Workload ID
1 updateFundamentals
1Configurable Token Lifetimes
Updated- **Managed identities**: Configuring token lifetimes for [managed identity service principals](~/identity/managed-identities-azure-resources/overview.md) isn't supported.
