Ensure the following prerequisites are met:
Federated sign-in hardening and App Instance Lock are the week’s consequential Entra changes
The week is maintenance-heavy, but not change-free. Four Microsoft 365 Message Center notices announce concrete behavior or rollout changes: stricter federated sign-in validation, a new default for App Instance Lock, a public preview for Dataverse Agent users, and a service transition for an early-access Power Apps capability. The 120 Microsoft Learn updates are mostly maintenance involving licensing, role prerequisites, checklist criteria, and how-to wording. The single new Learn page is an administrative guide for creating, inviting, and deleting users—not evidence of a product launch. No specific product retirement is identified in the supplied details for the five removed items.
- Stricter federated sign-in validation begins in mid-August 2026External ID
Microsoft Entra will enforce stricter federatedTokenValidationPolicy defaults starting in mid-August 2026. The stated impact is on tenants with federated domains configured before December 2025: federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. This is a security-related behavior change aimed at cross-domain sign-in risk, so affected tenants have a concrete federation and domain-alignment review ahead of enforcement.
- App Instance Lock becomes the default for new applicationsWorkload ID
Starting in June 2026, Microsoft Entra will enable App Instance Lock by default for new applications. The lock protects sensitive properties from unauthorized changes outside the application’s home tenant. Existing applications are unaffected, administrators can disable the lock, and Microsoft specifically calls for reviewing or updating automation and scripts before rollout. This is a changed provisioning default, not a retroactive change to existing applications.
- Dataverse Agent users enter public previewAgent ID
Microsoft is introducing Dataverse Agent users, powered by Microsoft Entra Agent ID, as a public preview. Rollout starts on 4 May 2026 and is expected to reach North America by 22 May. The notice establishes preview status and phased timing only; it does not establish general availability or a requirement to enable the feature.
- An early-access Power Apps control moves to a new underlying serviceEntra ID
For tenants that activated early access to the Entra Group control for model-driven app in-app skills in Power Apps or Dynamics 365 Apps, Microsoft will switch the feature to a new underlying service on 21 May 2026 in preparation for general availability. This is a service transition for the early-access cohort, not the general-availability announcement itself.
- Global Secure Access documentation clarifies Explicit Forward Proxy preview limitsGlobal Secure Access
An updated Global Secure Access page describes Explicit Forward Proxy (preview) validating access with Microsoft Entra authentication and authorization before allowing network traffic. It documents support for adaptive Conditional Access policies, passkeys, and Continuous Access Evaluation session revocation, while stating that basic, digest, NTLM, and Kerberos proxy authorization methods are unsupported. This is documentation clarification about the preview’s control model and limitations, not evidence of a new GA
Prioritize tenants with federated domains configured before December 2025 by reviewing whether internalDomainFederation matches users’ UPN domains before the mid-August 2026 enforcement. Owners of automation that creates new applications should test for App Instance Lock before its June 2026 default takes effect; existing applications are explicitly unaffected, and administrators can disable the lock. Tenants using the early-access Power Apps/Dynamics 365 in-app-skills control should account for the 21 May 2026 switch to a new underlying service. Dataverse Agent users should be treated as a public preview with phased rollout, not as a generally available feature. For Global Secure Access Explicit Forward Proxy, designs must not depend on basic, digest, NTLM, or Kerberos proxy authorization
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
97 updatesGeneral
30Datawiza Sso Oracle Jde
UpdatedEnsure the following prerequisites are met.
Ensure the following prerequisites are met.
Tutorial Basic Ad Azure
UpdatedThe following are prerequisites required for completing this tutorial
Users Search Enhanced
Updated**User operations**
We have identified that you have activated early access to the Entra Group control for model-driven app in-app skills in Power Apps and/or Dynamics 365 Apps. On May 21, 2026, we will switch this feature to a new underlying service in preparation for general availability.
author: kenwith
author: kenwith
Licensing Change
Updatedauthor: kenwith
Licensing Pim
Updatedauthor: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
include file
Updatedinclude file
Include file
UpdatedInclude file
author: kenwith
author: kenwith
Licensing Roles
Updatedauthor: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
21782
RemovedA Microsoft Entra documentation page was updated: 21782.
Create New Tenant
RemovedA Microsoft Entra documentation page was updated: Create New Tenant.
Create New Tenant
RemovedA Microsoft Entra documentation page was updated: Create New Tenant.
Entra Msi Tut Prereqs
RemovedA Microsoft Entra documentation page was updated: Entra Msi Tut Prereqs.
Fundamentals
21Fido2 Compatibility
Updated- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
Instructions for IT admins to create new users, invite external guests, and delete existing users in Microsoft Entra ID.
Entra Admin Center
Updated| Task | Description | Learn more |
Users Restore
UpdatedYou can permanently delete a user from your organization without waiting the 30 days for automatic deletion. A permanently deleted user can't be restored by anyone, including Microsoft customer support.
Add Custom Domain
Updated- [How to assign roles and administrators](./how-subscriptions-associated-directory.md)
Connect Pta Quick Start
Updated1. Create a cloud-only Hybrid Identity Administrator account or a Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.
Create New Tenant
Updated- To change or add other domain names, see [How to add a custom domain name to Microsoft Entra ID](add-custom-domain.md).
Delegate By Task
UpdatedHere are the least privileged roles you should use when performing tasks for [users](../../fundamentals/how-to-create-delete-users.md) in Microsoft Entra ID.
See [How to create, invite, and delete users](../../fundamentals/how-to-create-delete-users.md).
Manage User Profile Info
Updated- [Add or delete users](how-to-create-delete-users.md)
- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)
Prerequisites
Updated1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant if your on-premises services fail or become unavailable. Learn about how to [add a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Finishing this step is critical to ensure that you don't get locked out of your tenant.
Sspr Deploy
UpdatedTo ensure that your deployment works as expected, plan a set of test cases to validate the implementation. To assess the test cases, you need a non-administrator test user with a password. If you need to create a user, see [Add new users to Microsoft Entra ID](~/fundamentals/how-to-create-delete-users.md).
Tutorial Enable Sspr
Updated* A working Microsoft Entra tenant with at least a Microsoft Entra ID P1 license is required for password reset. For more information about license requirements for password change and password reset in Microsoft Entra ID, see [Licensing requirements for Microsoft Entra self-service password reset](concept-sspr-licensing.md).
Tutorial Existing Forest
Updated1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.
Users Default Permissions
Updated* To learn more about how to assign Microsoft Entra administrator roles, see [Assign a user to administrator roles in Microsoft Entra ID](./how-subscriptions-associated-directory.md).
- [Add or delete users](./how-to-create-delete-users.md)
Fido2 Compatibility
Updated- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
Fido2 Hardware Vendor
UpdatedACS FIDO Authenticator NFC|c89e6a38-6c00-5426-5aa5-c9cbf48f0382|❌|✅|✅|❌
Users Default Permissions
Updated| Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul> |
Authentication
13Tutorial Enable Azure Mfa
Updated* An account with at least the [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role. Some MFA settings can also be managed by an [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator).
Quickstart Analyze Sign In
Updated- An Azure subscription. If you don't have one, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
* If needed, [create one for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
During account recovery, a user who has lost all authentication methods must re-establish their identity. The custom authentication extension adds a claim validation step into this flow:
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
author: kenwith
Use cloud authentication
Updatedauthor: kenwith
author: kenwith
Developer
5author: kenwith
author: kenwith
author: kenwith
Restrict device code flow
Updatedauthor: kenwith
Licensing Application Proxy
RemovedA Microsoft Entra documentation page was updated: Licensing Application Proxy.
Security
5Entra Agents
Updated- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
author: kenwith
author: kenwith
author: kenwith
Architecture
4Migrate Adfs Apps Stages
UpdatedDuring the process of moving your app authentication to Microsoft Entra ID, test your apps and configuration. We recommend that you continue to use existing test environments for migration testing before you move to the production environment. If a test environment isn't currently available, you can set one up using [Azure App Service](https://azure.microsoft.com/services/app-service/) or [Azure Virtual Machines](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn), depending on the architecture of the application.
Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.
Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
Recoverability Overview
Updated- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.
Microsoft identity platform
4To complete the scenario in this quickstart, you need:
author: kenwith
author: kenwith
author: kenwith
Standards
4| IA.L2-3.5.5<br><br>**Practice statement:** Prevent reuse of identifiers for a defined period.<br><br>**Objectives:**<br>Determine if:<br>[a.] a period within which identifiers can't be reused is defined; and<br>[b.] reuse of identifiers is prevented within the defined period. | All user, group, device object globally unique identifiers (GUIDs) are guaranteed unique and non-reusable for the lifetime of the Microsoft Entra tenant.<br>[user resource type - Microsoft Graph v1.0](/graph/api/resources/user?view=graph-rest-1.0&preserve-view=true)<br>[group resource type - Microsoft Graph v1.0](/graph/api/resources/group?view=graph-rest-1.0&preserve-view=true)<br>[device resource type - Microsoft Graph v1.0](/graph/api/resources/device?view=graph-rest-1.0&preserve-view=true) |
Fedramp Access Controls
Updated| FedRAMP Control ID and description | Microsoft Entra guidance and recommendations |
Hipaa Access Controls
Updated| Recommendation | Action |
Monitoring
3Security Audit Events
UpdatedView all Kerberos ticket-granting (event ID 4768) and service ticket (event ID 4769) events that used RC4 encryption in the last seven days, to identify workloads and service accounts that still rely on RC4:
> [!NOTE]
author: kenwith
Provisioning
3Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).
Licensing App Provisioning
Updatedauthor: kenwith
Jive Provisioning Tutorial
UpdatedThis section guides you through connecting your Microsoft Entra ID to Jive's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in Jive based on user and group assignment in Microsoft Entra ID.
Branding
2Get Started Premium
UpdatedNow that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.md).
Customize Branding
Updated:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::
Conditional Access
2Plan Conditional Access
Updated- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)
author: kenwith
Troubleshooting
1author: kenwith
Microsoft Entra Agent ID
5 updatesFundamentals
2Security For Ai Overview
Updated- Ensure sponsors and owners are assigned and maintained for each agent identity, preventing orphaned agent identities.
Understand the difference between required resource access declarations and inheritable permissions for agent identity blueprints in Microsoft Entra Agent ID.
Conditional Access
1Licensing Agent Id
Updated- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.
Microsoft identity platform
1We’re introducing a new feature in public preview, Dataverse Agent users, powered by Microsoft Entra Agent ID. Rollout of this feature will start on May 4, 2026, and is expected to reach North America by May 22, 2026.
Standards
1Learn how to configure inheritable permissions for agent identity blueprints to automatically grant OAuth 2.0 delegated permission scopes and application roles to agent identities.
Microsoft Entra ID Protection
2 updatesArchitecture
1- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)
Conditional Access
1Deploy Identity Protection
Updated* Create or modify Conditional Access policies
Microsoft Entra ID Governance
5 updatesGovernance
4Migrate From Sap Idm
UpdatedIn SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.
1. Browse to **ID Governance** > **Entitlement management** > **Access packages**.
Learn how to view, add, and remove assignments for an access package in entitlement management.
Lifecycle Workflow Tasks
UpdatedLifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.
Fundamentals
1Identity Governance Overview
UpdatedMicrosoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
Microsoft Entra External ID
6 updatesGeneral
2User Permissions
UpdatedTo better understand the typical use cases for users in an external tenant, we can categorize them as follows:
In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.
Branding
1An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user account is automatically created in the external tenant. For more information, see [Create a sign-up and sign-in user flow for customers](how-to-user-flow-sign-up-sign-in-customers.md).
Fundamentals
1Manage Admin Accounts
UpdatedUse the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How to create users](~/fundamentals/how-to-create-delete-users.md#create-a-new-user).)
Microsoft identity platform
1Microsoft Entra will enforce stricter federatedTokenValidationPolicy by default starting mid-August 2026, blocking federated sign-ins when internalDomainFederation doesn't match the user's UPN domain. This affects tenants with federated domains configured before December 2025 and aims to enhance security against cross-domain sign-in risks.
Provisioning
1- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you might want to continue using your existing Microsoft Entra cross-tenant synchronization jobs.
Microsoft Entra Verified ID
4 updatesGeneral
2Whats New
Updated- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.
Licensing Verified Id
Updatedauthor: kenwith
Fundamentals
11. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.
Security
1Learn how to set up and use Face Check with Microsoft Entra Verified ID for high-assurance facial matching verifications that protect user privacy at enterprise scale.
Microsoft Entra Workload ID
9 updatesGeneral
6Before you begin, ensure you have the following:
Documentation for the Azure Policy that can be used to assign managed identities to Azure resources.
Licensing Managed Identities
Updatedauthor: kenwith
author: kenwith
Managed Identities Status
Updated| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
Developer
1author: kenwith
Fundamentals
1Workload identities
UpdatedUnderstand the concepts and supported scenarios for using workload identity in Microsoft Entra.
Microsoft identity platform
1Microsoft Entra ID will enable App Instance Lock by default for new applications starting June 2026, protecting sensitive properties from unauthorized changes outside the home tenant. Existing apps are unaffected. Admins can disable the lock if needed. Review and update automation or scripts accordingly before rollout.
Microsoft Entra Global Secure Access
2 updatesFundamentals
2Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
Explicit Forward Proxy
UpdatedDuring the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.
