Week in brief

Federated sign-in hardening and App Instance Lock are the week’s consequential Entra changes

The week is maintenance-heavy, but not change-free. Four Microsoft 365 Message Center notices announce concrete behavior or rollout changes: stricter federated sign-in validation, a new default for App Instance Lock, a public preview for Dataverse Agent users, and a service transition for an early-access Power Apps capability. The 120 Microsoft Learn updates are mostly maintenance involving licensing, role prerequisites, checklist criteria, and how-to wording. The single new Learn page is an administrative guide for creating, inviting, and deleting users—not evidence of a product launch. No specific product retirement is identified in the supplied details for the five removed items.

  • Stricter federated sign-in validation begins in mid-August 2026External ID

    Microsoft Entra will enforce stricter federatedTokenValidationPolicy defaults starting in mid-August 2026. The stated impact is on tenants with federated domains configured before December 2025: federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. This is a security-related behavior change aimed at cross-domain sign-in risk, so affected tenants have a concrete federation and domain-alignment review ahead of enforcement.

  • App Instance Lock becomes the default for new applicationsWorkload ID

    Starting in June 2026, Microsoft Entra will enable App Instance Lock by default for new applications. The lock protects sensitive properties from unauthorized changes outside the application’s home tenant. Existing applications are unaffected, administrators can disable the lock, and Microsoft specifically calls for reviewing or updating automation and scripts before rollout. This is a changed provisioning default, not a retroactive change to existing applications.

  • Dataverse Agent users enter public previewAgent ID

    Microsoft is introducing Dataverse Agent users, powered by Microsoft Entra Agent ID, as a public preview. Rollout starts on 4 May 2026 and is expected to reach North America by 22 May. The notice establishes preview status and phased timing only; it does not establish general availability or a requirement to enable the feature.

  • An early-access Power Apps control moves to a new underlying serviceEntra ID

    For tenants that activated early access to the Entra Group control for model-driven app in-app skills in Power Apps or Dynamics 365 Apps, Microsoft will switch the feature to a new underlying service on 21 May 2026 in preparation for general availability. This is a service transition for the early-access cohort, not the general-availability announcement itself.

  • Global Secure Access documentation clarifies Explicit Forward Proxy preview limitsGlobal Secure Access

    An updated Global Secure Access page describes Explicit Forward Proxy (preview) validating access with Microsoft Entra authentication and authorization before allowing network traffic. It documents support for adaptive Conditional Access policies, passkeys, and Continuous Access Evaluation session revocation, while stating that basic, digest, NTLM, and Kerberos proxy authorization methods are unsupported. This is documentation clarification about the preview’s control model and limitations, not evidence of a new GA

For Entra administrators

Prioritize tenants with federated domains configured before December 2025 by reviewing whether internalDomainFederation matches users’ UPN domains before the mid-August 2026 enforcement. Owners of automation that creates new applications should test for App Instance Lock before its June 2026 default takes effect; existing applications are explicitly unaffected, and administrators can disable the lock. Tenants using the early-access Power Apps/Dynamics 365 in-app-skills control should account for the 21 May 2026 switch to a new underlying service. Dataverse Agent users should be treated as a public preview with phased rollout, not as a generally available feature. For Global Secure Access Explicit Forward Proxy, designs must not depend on basic, digest, NTLM, or Kerberos proxy authorization

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

30

21782

Removed

A Microsoft Entra documentation page was updated: 21782.

6 May 2026

Create New Tenant

Removed

A Microsoft Entra documentation page was updated: Create New Tenant.

6 May 2026

Create New Tenant

Removed

A Microsoft Entra documentation page was updated: Create New Tenant.

6 May 2026

Entra Msi Tut Prereqs

Removed

A Microsoft Entra documentation page was updated: Entra Msi Tut Prereqs.

6 May 2026

Fundamentals

21

Fido2 Compatibility

Updated

- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.

10 May 2026

Users Restore

Updated

You can permanently delete a user from your organization without waiting the 30 days for automatic deletion. A permanently deleted user can't be restored by anyone, including Microsoft customer support.

9 May 2026

Add Custom Domain

Updated

- [How to assign roles and administrators](./how-subscriptions-associated-directory.md)

9 May 2026

Connect Pta Quick Start

Updated

1. Create a cloud-only Hybrid Identity Administrator account or a Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.

9 May 2026

Create New Tenant

Updated

- To change or add other domain names, see [How to add a custom domain name to Microsoft Entra ID](add-custom-domain.md).

9 May 2026

Delegate By Task

Updated

Here are the least privileged roles you should use when performing tasks for [users](../../fundamentals/how-to-create-delete-users.md) in Microsoft Entra ID.

9 May 2026

Multi Tenant Organization Overview

Updated

- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)

9 May 2026

Prerequisites

Updated

1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant if your on-premises services fail or become unavailable. Learn about how to [add a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Finishing this step is critical to ensure that you don't get locked out of your tenant.

9 May 2026

Sspr Deploy

Updated

To ensure that your deployment works as expected, plan a set of test cases to validate the implementation. To assess the test cases, you need a non-administrator test user with a password. If you need to create a user, see [Add new users to Microsoft Entra ID](~/fundamentals/how-to-create-delete-users.md).

9 May 2026

Tutorial Enable Sspr

Updated

* A working Microsoft Entra tenant with at least a Microsoft Entra ID P1 license is required for password reset. For more information about license requirements for password change and password reset in Microsoft Entra ID, see [Licensing requirements for Microsoft Entra self-service password reset](concept-sspr-licensing.md).

9 May 2026

Tutorial Existing Forest

Updated

1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.

9 May 2026

Users Default Permissions

Updated

* To learn more about how to assign Microsoft Entra administrator roles, see [Assign a user to administrator roles in Microsoft Entra ID](./how-subscriptions-associated-directory.md).

9 May 2026

Fido2 Compatibility

Updated

- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.

8 May 2026

Fido2 Hardware Vendor

Updated

ACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌

6 May 2026

Users Default Permissions

Updated

| Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul> |

5 May 2026

Authentication

13

Tutorial Enable Azure Mfa

Updated

* An account with at least the [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role. Some MFA settings can also be managed by an [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator).

9 May 2026

Quickstart Analyze Sign In

Updated

- An Azure subscription. If you don't have one, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).

9 May 2026

Developer

5

Security

5

Entra Agents

Updated

- You must have available [security compute units (SCU)](/copilot/security/manage-usage).

9 May 2026

Architecture

4

Migrate Adfs Apps Stages

Updated

During the process of moving your app authentication to Microsoft Entra ID, test your apps and configuration. We recommend that you continue to use existing test environments for migration testing before you move to the production environment. If a test environment isn't currently available, you can set one up using [Azure App Service](https://azure.microsoft.com/services/app-service/) or [Azure Virtual Machines](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn), depending on the architecture of the application.

9 May 2026

Connect To Cloud Sync Decision Guide

Updated

Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.

8 May 2026

Recoverability Overview

Updated

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

5 May 2026

Microsoft identity platform

4

Standards

4

Configure Cmmc Level 2 Identification And Authentication

Updated

| IA.L2-3.5.5<br><br>**Practice statement:** Prevent reuse of identifiers for a defined period.<br><br>**Objectives:**<br>Determine if:<br>[a.] a period within which identifiers can't be reused is defined; and<br>[b.] reuse of identifiers is prevented within the defined period. | All user, group, device object globally unique identifiers (GUIDs) are guaranteed unique and non-reusable for the lifetime of the Microsoft Entra tenant.<br>[user resource type - Microsoft Graph v1.0](/graph/api/resources/user?view=graph-rest-1.0&preserve-view=true)<br>[group resource type - Microsoft Graph v1.0](/graph/api/resources/group?view=graph-rest-1.0&preserve-view=true)<br>[device resource type - Microsoft Graph v1.0](/graph/api/resources/device?view=graph-rest-1.0&preserve-view=true) |

9 May 2026

Fedramp Access Controls

Updated

| FedRAMP Control ID and description | Microsoft Entra guidance and recommendations |

9 May 2026

Monitoring

3

Security Audit Events

Updated

View all Kerberos ticket-granting (event ID 4768) and service ticket (event ID 4769) events that used RC4 encryption in the last seven days, to identify workloads and service accounts that still rely on RC4:

7 May 2026

Provisioning

3

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).

9 May 2026

Jive Provisioning Tutorial

Updated

This section guides you through connecting your Microsoft Entra ID to Jive's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in Jive based on user and group assignment in Microsoft Entra ID.

6 May 2026

Branding

2

Get Started Premium

Updated

Now that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.md).

9 May 2026

Customize Branding

Updated

:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::

8 May 2026

Conditional Access

2

Plan Conditional Access

Updated

- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)

9 May 2026

Troubleshooting

1

Fundamentals

2

Security For Ai Overview

Updated

- Ensure sponsors and owners are assigned and maintained for each agent identity, preventing orphaned agent identities.

9 May 2026

Conditional Access

1

Licensing Agent Id

Updated

- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.

8 May 2026

Microsoft identity platform

1

Standards

1

Architecture

1

Id Protection Guide Introduction

Updated

- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)

9 May 2026

Conditional Access

1

Governance

4

Migrate From Sap Idm

Updated

In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.

9 May 2026

Lifecycle Workflow Tasks

Updated

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

5 May 2026

Fundamentals

1

Identity Governance Overview

Updated

Microsoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.

9 May 2026

General

2

User Permissions

Updated

To better understand the typical use cases for users in an external tenant, we can categorize them as follows:

9 May 2026

B2b Quickstart Add Guest Users Portal

Updated

In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.

9 May 2026

Branding

1

Entra Id Federation Customers

Updated

An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user account is automatically created in the external tenant. For more information, see [Create a sign-up and sign-in user flow for customers](how-to-user-flow-sign-up-sign-in-customers.md).

9 May 2026

Fundamentals

1

Manage Admin Accounts

Updated

Use the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How to create users](~/fundamentals/how-to-create-delete-users.md#create-a-new-user).)

9 May 2026

Microsoft identity platform

1

Provisioning

1

Multi Tenant Organization Known Issues

Updated

- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you might want to continue using your existing Microsoft Entra cross-tenant synchronization jobs.

9 May 2026

General

2

Whats New

Updated

- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.

8 May 2026

Fundamentals

1

Use Quickstart Verifiedemployee

Updated

1. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.

9 May 2026

Security

1

General

6

Managed Identities Status

Updated

| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|

5 May 2026

Developer

1

Fundamentals

1

Workload identities

Updated

Understand the concepts and supported scenarios for using workload identity in Microsoft Entra.

9 May 2026

Microsoft identity platform

1

Fundamentals

2

Explicit Forward Proxy (preview) session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

8 May 2026

Explicit Forward Proxy

Updated

During the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.

8 May 2026