1. Select **Reveal** on your Recovery Key and store this entire key in a safe place. **IMPORTANT!** If you're ever locked out of your Microsoft accounts and need to disconnect SSO without access, you be required to relay the Recovery Key to Simple In/Out technical support.
Tenant Governance preview documentation expands across discovery and drift control; Agent ID’s GA capability set and Explicit Forward Proxy are the week’s other substantive signals
The week of 27 April 2026 was primarily documentation-led rather than a product-release record: 127 pages were updated, one Agent ID page was new, and there were no removals or Message Center entries. The most meaningful change was a coordinated set of Microsoft Entra Tenant Governance preview pages covering tenant discovery, governance relationships, secure tenant creation, licensing, permissions, and configuration drift. Agent ID documentation now describes a general-availability capability set and related administration and integration workflows. Global Secure Access and Internet Access documentation identifies Explicit Forward Proxy as preview. Entra ID updates mainly refresh security and migration recommendations, while Workload ID adds a concrete Conditional Access scope and licensing clarification. Other supplied edits are largely provisioning tutorials, troubleshooting content, and reference clarifications.
- Tenant Governance (preview) now has documentation for the full operating workflowMicrosoft Entra ID Governance — Tenant Governance (preview)
A coordinated set of 1 May updates covers secure add-on tenant creation, automatic governance relationships, tenant discovery, relationship updates and termination, configuration baselines, drift monitoring, monitor management, permissions, licensing, and end-to-end deployment. The documentation says discovery uses identity, application, and billing signals, and that secure tenant creation can automatically establish governance relationships. This is an expansion of preview guidance, not evidence of general-
- Agent ID documentation moves from overview material to GA-era administration and integrationMicrosoft Entra Agent ID
The new “What’s new in Microsoft Entra Agent ID” page labels its covered capabilities as generally available and highlights third-party integrations, migration guides, and enterprise governance. Related updates describe two integration patterns—the Microsoft Entra Auth SDK sidecar and federation—for platforms such as AWS Bedrock and n8n, allowing third-party agents to authenticate to APIs without handling credentials directly. Administration pages cover centralized agent search, filtering, sorting, registry-only एज
- Explicit Forward Proxy is documented as a preview path for Entra Internet AccessMicrosoft Entra Global Secure Access / Internet Access
Updates in Global Secure Access and Internet Access state that Explicit Forward Proxy is currently in preview. The Internet Access guidance describes using Secure Web and AI Gateway capabilities without installing the Global Secure Access client when a browser supports proxy automatic configuration (PAC). Companion material covers Conditional Access policy configuration and configuring Microsoft Edge through an Intune Mobile Application Management policy. The evidence supports an evaluation path, not a general-
- Authentication updates reinforce migration and MFA security guidanceMicrosoft Entra ID — Authentication and Security Defaults
Several Entra ID recommendation pages were refreshed to promote migration to Microsoft Authenticator, migration of application authentication from AD FS to Microsoft Entra ID, migration from MFA Server to Microsoft Entra MFA, minimizing prompts from known devices, and turning off per-user MFA. Security Defaults guidance adds a specific procedure: revoke existing tokens with Revoke-MgUserSignInSession so previously authenticated users must authenticate and register for MFA. Combined registration guidance says MFA-
- Workload ID guidance clarifies Conditional Access boundaries and license behaviorMicrosoft Entra Workload ID
Updated Workload ID pages state that Conditional Access policies can apply to single-tenant service principals registered in the tenant. Non-Microsoft SaaS and multitenant applications are out of scope, and managed identities are not covered. In directories without appropriate licenses, existing workload-identity policies continue to function but cannot be modified. This is a scope and licensing clarification; the supplied evidence does not show a new enforcement change.
Do not treat the volume of Learn updates as evidence of a tenant-wide behavior change. Administrators evaluating Tenant Governance or Explicit Forward Proxy should use the relevant preview documentation, including its licensing, permissions, Conditional Access, browser/PAC, and Intune Mobile Application Management guidance. Workload ID teams should verify whether their service principals fall within the stated Conditional Access scope and whether they can modify policies under their licensing. Identity teams should review the refreshed MFA, AD FS, MFA Server, and per-user MFA guidance; if enabling Security Defaults, note the documented instruction to revoke existing tokens. Agent ID owners have new material for agent inventory, third-party integration, audit visibility, and owner or end-
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
72 updatesProvisioning
28The scenario outlined in this article assumes that you already have the following prerequisites:
1. In the **Tenant URL** field, enter your SAS Viya SSO Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to SAS Viya SSO. If the connection fails, ensure your SAS Viya SSO account has the required admin permissions and try again.
1. Sign in to [Preciate Admin Portal](https://preciate.com/web/admin/keys) and navigate to the **Integrations** page.
1. Sign in to [Plandisc](https://create.plandisc.com) and navigate to **Enterprise**
2. Select **Create API Key**.
The objective of this article is to demonstrate the steps to be performed in Dropbox for Business and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Dropbox for Business.
The scenario outlined in this article assumes that you already have the following prerequisites:
1. Select the **Provisioning** tab.
1. Log on to the Oracle Cloud Infrastructure Console admin portal. On the top left corner of the screen navigate to **Identity > Federation**.
1. log into your [directprint.io account](https://directprint.io/login/).
Druva Provisioning Tutorial
Updated1. Sign in to your [Druva Admin Console](https://console.druva.com). Navigate to **Druva** > **inSync**.
1. Select your instance of Pingboard, and then select the **Provisioning** tab.
1. Browse to **Entra ID** > **Enterprise apps** > **New application**.
Documo Provisioning Tutorial
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Rfpio Provisioning Tutorial
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

1. Select the **Provisioning** tab.




1. Select **+ New configuration**.
Humbol Provisioning Tutorial
Updated1. Select **+ New configuration**.
Moqups Provisioning Tutorial
Updated1. In the **Tenant URL** field, enter your Moqups Tenant URL and Secret Token. Select **Test Connection** to ensure Microsoft Entra ID can connect to Moqups. If the connection fails, ensure your Moqups account has the required admin permissions and try again.
1. Select the pencil to edit the properties. Enable notification emails and provide an email to receive quarantine emails. Enable accidental deletions prevention. Select **Apply** to save the changes.
1. Select the pencil to edit the properties. Enable notification emails and provide an email to receive quarantine emails. Enable accidental deletions prevention. Select **Apply** to save the changes.
Fundamentals
14Security Defaults
UpdatedAs part of enabling security defaults, administrators should revoke all existing tokens to require all users to register for multifactor authentication. This revocation event forces previously authenticated users to authenticate and register for multifactor authentication. This task can be accomplished using the [Revoke-MgUserSignInSession](/powershell/module/microsoft.graph.users.actions/revoke-mgusersigninsession) cmdlet in the Microsoft Graph PowerShell SDK.
By default, Combined registration enforces all MFA-capable users to strongly authenticate prior to registering or managing their security info.
Whats New
Updated**Service category:** User Experience and Management
In addition, use the Active Directory Federation Services (AD FS) in the Azure portal to discover AD FS apps in your organization. Discover unique users that signed in to the apps, and see information about integration compatibility.
- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)
When a problem prevents Microsoft Entra from downloading the CRL, the cause is often firewall restrictions. In most cases, you can resolve the issue by updating firewall rules to allow the required IP addresses so Microsoft Entra can successfully download the CRL. For more information, see [Download Azure IP Ranges and Service Tags – Public Cloud from Official Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=56519).
Provides a general overview of Microsoft Entra recommendations so you can keep your tenant secure and healthy.
Directory Join
Updated| **Definition** | <ul><li>Joined only to Microsoft Entra ID requiring organizational account to sign in to the device</li></ul> |
Explore Microsoft Entra Conditional Access, the Zero Trust policy engine that integrates signals to secure access to resources.
Fido2 Hardware Vendor
UpdatedPasskeys (FIDO2) enable phishing-resistant authentication. They can replace weak credentials with strong phishing-resistant public/private-key credentials that can't be reused, replayed, or shared across services. They can be stored securely on a device or synced across trusted devices through an encrypted cloud service.
Depending on the environment, synced users might also be subject to Microsoft Entra ID restrictions such as the global banned password list. For more information, see the [FAQ section](#faq).
Learn about cross-tenant synchronization in Microsoft Entra ID.
Data Storage Eu
UpdatedA Microsoft Entra documentation page was updated: Data Storage Eu.
General
11Service Dependencies
Updated| | Microsoft Stream | Late-bound |
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
AI Administrator
UpdatedAI Administrator
Entra Backup Administrator
UpdatedEntra Backup Administrator
Entra Backup Reader
UpdatedEntra Backup Reader
author: FaithOmbongi
Describes the Microsoft Entra built-in roles and permissions.
Sso Linux
UpdatedMicrosoft single sign-on for Linux is supported on the following operating systems (physical or Hyper-V machines with x86/64 CPUs):
Whats New Linux
Updated- Ensure that all browser calls are done in the same thread
Connect Install Roadmap
Updated* Make sure that you [satisfy the requirements](how-to-connect-health-agent-install.md#requirements) for Microsoft Entra Connect Health.
Authentication
71. Ensure the application is accessible. Sign in directly from the browser on the connector host using the internal URL defined in the Azure portal. If the sign-in succeeds, the application is accessible.
1. Review the user attributes that are synchronized from Microsoft Entra ID to Netskope User Authentication in the **Attribute-Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Netskope User Authentication for update operations. If you choose to change the [matching target attribute](~/identity/app-provisioning/customize-application-attributes.md), you need to ensure that the Netskope User Authentication API supports filtering users based on that attribute. Select the **Save** button to commit any changes.
Learn the importance of migrating your users to the Microsoft authenticator app in Microsoft Entra ID.
Learn about the recommendation to migrate application authentication from AD FS to Microsoft Entra ID
Learn about the Microsoft Entra recommendation to migrate to Microsoft Entra multifactor authentication from MFA server
Learn about the recommendation to minimize multifactor authentication prompts from known devices in Microsoft Entra ID.
In this article, you add an admin system in SAP Cloud Identity Services and then configure Microsoft Entra.
Standards
3|urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department|String||
Learn to develop a SCIM endpoint, integrate your SCIM API with Microsoft Entra ID, and automatically provision users and groups into your cloud applications.
:::image type="content" source="./media/lucidchart-provisioning-tutorial/scim.png" alt-text="Screenshot of the Lucidchart admin console. Within a large S C I M button, the text S C I M is highlighted, and an enabled banner is visible." border="false":::
Developer
2>
* [Configure group claims for applications by using Microsoft Entra ID](../hybrid/connect/how-to-connect-fed-group-claims.md)
Microsoft identity platform
2Frontline Worker Management
UpdatedFrontline workers in many companies use shared devices to do inventory management and sales transactions. Sharing devices reduces the IT burden of provisioning and tracking them individually. With shared device sign-out, it's easy for a frontline worker to securely sign out of all apps on any shared device before handing it back to a hub or passing it off to a teammate on the next shift. Frontline workers can use Microsoft Teams to view their assigned tasks. Once a worker signs out of a shared device, Intune and Microsoft Entra ID clear all of the company data so the device can safely be handed off to the next associate. You can choose to integrate this capability into all your line of business [iOS](/entra/msal/objc/shared-devices-ios) and [Android](~/identity-platform/msal-shared-devices.md) apps using the [Microsoft Authentication Library](~/identity-platform/msal-overview.md).
Learn about the Microsoft Entra recommendation to migrate from Azure Active Directory Graph APIs to Microsoft Graph APIs.
Monitoring
2Entra Service Limits Include
Updated| Reports | A maximum of 1,000 rows can be viewed or downloaded in any report. Any additional data is truncated. |
Learn why you should turn off per user MFA in Microsoft Entra ID with Microsoft Entra recommendations
Security
2There's a known issue where there's a preexisting, unregistered account, like `[email protected]` in Microsoft Edge, or if a user signs in without registering using the Heads Up Page, then the account isn't properly enrolled in MAM. This configuration blocks the user from being properly enrolled in MAM.
Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Branding
1Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Microsoft Entra Agent ID
16 updatesGeneral
9Whats New Agent Id
UpdatedThis article summarizes the key capabilities and documentation currently available.
Agent Lists
UpdatedAccess Microsoft Entra admin center to view and filter agent identities. Streamline tenant oversight with search, filters, and column customization.
The Microsoft Entra admin center provides a centralized interface to view all agent identities in your tenant. You can search, filter, sort, and customize columns to find specific agents.
This article explains how to manage registry-only agents that don't have associated agent identities in Microsoft Entra ID.
Learn how to manage agent identities in the end user experience within Microsoft Entra. View, control, and take action on agents you own or sponsor with ease.
Agent Id Ai Guided Setup
Updatedauthor: arlucaID
Learn how to grant access to agents through consent, manual authorization, and other authorization systems for Microsoft 365 resources.
Learn how to add and manage owners and sponsors for agent identity blueprints and agent identities in the Microsoft Entra admin center.
Disable Agent Identities
Updated- Existing agents running in your organization might begin to fail.
Authentication
2Microsoft Entra Agent ID enables AI agents from third-party platforms to authenticate and access your APIs securely without handling credentials directly. This article covers two integration patterns - the Microsoft Entra Auth SDK (sidecar) and federation - for platforms such as Amazon Web Service (AWS) Bedrock and n8n.
Learn how audit and sign-in activities associated with agent identities are logged in Microsoft Entra ID.
Governance
2Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.
This article explains how access packages provide governance for agent identity access to resources.
Fundamentals
1Whats New Ignite 2025
Updated- [Sign-in and audit logs for agents](../agent-id/sign-in-audit-logs-agents.md) (New)
Microsoft identity platform
1Learn how to create an agent identity blueprint that serves as a template for multiple agent identities using Microsoft Graph APIs and PowerShell.
Security
1Learn how to manage agent identity blueprints in the Microsoft Entra admin center, including viewing permissions, managing credentials, and configuring owners and sponsors.
Microsoft Entra ID Governance
25 updatesGovernance
23Learn how Microsoft Entra Tenant Governance automatically establishes governance relationships when you create add-on tenants using secure tenant creation.
Learn about configuration management capabilities in Microsoft Entra Tenant Governance, including baselines and drift monitoring
Learn how to create a new Microsoft Entra tenant using the secure add-on tenant creation workflow in Tenant Governance
Create a monitor (preview)
UpdatedLearn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift
Learn how to deploy Microsoft Entra Tenant Governance from setup through tenant discovery, governance, and configuration monitoring
Learn how to enable tenant discovery in Microsoft Entra Tenant Governance to identify related tenants across your organization
Learn about governance relationships and how they enable centralized management of tenants in Microsoft Entra Tenant Governance
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn which Microsoft Entra Tenant Governance features are available with each license tier, including P1, P2, and ID Governance
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn how to view monitor results and detect configuration drifts in Microsoft Entra Tenant Governance using the admin center
Learn how to set up the required application permissions and roles for tenant monitoring in Microsoft Entra Tenant Governance
Learn about the signals and metrics used in Microsoft Entra Tenant Governance to identify and evaluate related tenants
Learn how to terminate a governance relationship between tenants in Microsoft Entra Tenant Governance and understand what resources are removed
Learn how to update an existing governance relationship between a governing and governed tenant in Microsoft Entra Tenant Governance
Learn how to update or delete a configuration monitor in Microsoft Entra Tenant Governance when baselines or requirements change
Learn about cross-tenant delegated administration and how it enables centralized management across tenants in Microsoft Entra
Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra
Learn how to set up a governance relationship between a governing and governed tenant using the handshake process in Microsoft Entra
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
**May**:
Pim How To Add Role To User
Updated1. Select a role you want to assign, select a member you want to assign to the role, and then select **Next**.
| Access Reviews | [Access Review – inactive users](../identity/users/clean-up-stale-guest-accounts.md#monitor-guest-accounts-at-scale-with-inactive-guest-insights) | Bill when guest user is included in review.<br><br>**API**<br> https://graph.microsoft.com/v1.0/identityGovernance/accessReviews/definitions where inactive guest reviews are included in the policy for a group resource. | Decision item summary. |
Authentication
1Learn how to monitor and audit governing tenant administrator activity in your governed tenant using sign-in and audit logs
Fundamentals
1Learn about Microsoft Entra Tenant Governance and how it helps organizations discover, manage, and govern tenants across their environment
Microsoft Entra External ID
1 updateProvisioning
1|externalId|String||✓|
Microsoft Entra Internet Access
1 updateGeneral
1Explicit Forward Proxy (EFP) allows you to use Secure Web and AI Gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access (GSA) client. EFP works with any browser that supports proxy automatic configuration (PAC).
Microsoft Entra Private Access
1 updateGeneral
1Intelligent Local Access capability can help optimize the traffic flow from Microsoft Entra clients to Microsoft Entra Private Access apps when the client is on a corporate/private network. This article explains how to enable the Intelligent Private Network for Microsoft Entra Private Access.
Microsoft Entra Verified ID
2 updatesSecurity
1Using Facecheck
Updated"requestedCredentials": [
Troubleshooting
1Register Didwebsite
UpdatedThe portal verifies that `did.json` is reachable and correct when you select **Refresh registration status**. You should also consider verifying that you can request that URL in a browser to avoid errors like not using HTTPS, a bad TLS/SSL certificate, or the URL not being public. If the `did.json` file can't be requested anonymously in a browser or via tools such as `curl`, without warnings or errors, the portal won't be able to complete the **Refresh registration status** step.
Microsoft Entra Workload ID
2 updatesConditional Access
1Workload Identity
Updated> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).
Fundamentals
1A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.
Microsoft Entra Global Secure Access
8 updatesFundamentals
3Bring Your Own Device
Updated1. Install Microsoft Authenticator from the App Store and register the device to the tenant or install the Company Portal app (no device enrollment required).
Explicit Forward Proxy (EFP) is one of the traffic acquisition mechanisms that's useful in scenarios where installation of the Global Secure Access (GSA) client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from:
A PAC file is a mechanism used to automatically determine which proxy server a web browser or application should use for a given request. PAC files are an integral part of Explicit Forward Proxy configuration, enabling flexible and dynamic traffic steering decisions. In the context of Global Secure Access, PAC files are similar to the traffic forwarding policies of the GSA client.
General
2Use these PowerShell samples to automate common Global Secure Access tasks, including connector registration, client install, traffic forwarding bypasses, break glass scenarios, and TLS certificate creation.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
Conditional Access
1> The Explicit Forward Proxy feature is currently in PREVIEW.
Developer
1author: idmdev
Security
1Protect your enterprise generative AI apps from prompt injection attacks with Microsoft's AI Gateway prompt injection protection.
