- Devices must support passkey (FIDO2) authentication. For Windows devices that are joined to Microsoft Entra ID, the best experience is on Windows 10 version 1903 or higher. Hybrid-joined devices must run Windows 10 version 2004 or higher.
Week of 11 May 2026: passkey re-enrollment, Conditional Access analysis, and Agent ID migration guidance stand out
The supplied feed is best read as a documentation-clarification cycle: 42 items are marked Updated, with no new or removed items and no Message Center entries. The meaningful exceptions are concrete guidance on Entra ID authentication and Conditional Access Agent Optimization, an explicit Agent ID migration constraint, runbook-level operations for Global Secure Access, Private Access, and Internet Access, and several support or licensing boundaries. No supplied item identifies a new feature, preview, general-availability announcement, retirement, or tenant-wide service-behavior change; much of the remainder is reference, tutorial, or maintenance text.
- Entra ID authentication guidance clarifies passkey re-enrollment and deployment boundariesEntra ID — FIDO2 passkeys, phishing-resistant passwordless authentication, and Authenticator Lite
The updated FIDO2 guidance states that after a user's UPN changes, an existing passkey cannot be modified for the new UPN: the user must open Security info, delete the old passkey, and add a new one. It also says devices must support passkey authentication; the best experience on Entra-joined Windows devices is Windows 10 version 1903 or later, while hybrid-joined devices must run version 2004 or later. Related updates address Remote Desktop in phishing-resistant passwordless deployments, explain that system-preเพr
There is no evidenced broad tenant change to implement from this period. Follow up only where relevant: include the documented UPN-change/passkey re-registration path in support planning; account for the P2 requirement attached to the risky-sign-in MFA suggestion; plan Copilot Studio-to-Agent ID moves as recreation; use the access-operation health and connector guidance; and check the documented support, licensing, and schema limits before relying on those capabilities. These are documentation-led follow-ups, not evidence of automatic configuration changes.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
23 updatesAuthentication
8If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
Native Authentication Api
UpdatedMicrosoft Entra determines the default MFA method for the user by priority as follows:
- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.
Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.
Remote desktop connection guidance to deploy passwordless and phishing-resistant authentication for organizations that use Microsoft Entra ID.
Account Recovery Enable
Updated- **Exact** — Claims must match exactly.
Fundamentals
4Learn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both primary and multifactor authentication.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled |
Native Authentication
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
Whats New Archive
Updated**Service category:** MFA
General
4Add Redirect Uri
Updatedmanager: pmwongera
Quickstart Register App
Updatedmanager: pmwongera
Quickstart Register App
Updated1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.
Confluencemicrosoft Tutorial
UpdatedAs of now, following versions of Confluence are supported:
Provisioning
2The scenario outlined in this article assumes that you already have the following prerequisites:
This article describes the steps you need to perform in both Atlassian Cloud and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Atlassian Cloud](https://www.atlassian.com/cloud) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).
Developer
1Entra Service Limits Include
Updated| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li> Only the "equals" operator is supported for DateTime-type extensions. Range operators like "greater than" or "less than" are not supported.</li></ul> |
Microsoft identity platform
1Mfa Authenticator Lite
Updated- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
Security
1Assign, update, list, or remove custom security attributes for a user in Microsoft Entra ID.
Standards
1author: dhivyagana
Troubleshooting
1Error Codes
Updated| Error | Description |
Microsoft Entra Agent ID
3 updatesFundamentals
1Agent Identity Deletion
Updatedauthor: shlipsey3
General
1Agent Id Ai Guided Setup
UpdatedIf you have the GitHub Copilot for Azure extension installed, ask Copilot to set up Agent ID. For example:
Governance
1Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.
Microsoft Entra ID Governance
1 updateFundamentals
1Licensing Fundamentals
UpdatedAccount Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).
Microsoft Entra External ID
1 updateMonitoring
1Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.
Microsoft Entra Internet Access
1 updateGeneral
1Operate Internet Access
Updated| Alert | Condition | Role | Automated by | What to do next |
Microsoft Entra Private Access
4 updatesGeneral
3Post-deployment operations guide for Microsoft Entra Private Access, the Zero Trust network access (ZTNA) capability, covering alerting, health checks, integration, automation, and operational metrics.
Private Access Health Check
Updated| # | Check | How | Status | What to do if it fails |
Licensing Guest Users
UpdatedGuest users are only billed when they actively sign in to the Global Secure Access client for Private Access.
Monitoring
1Operate Private Access
Updated| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |
Microsoft Entra Global Secure Access
9 updatesGeneral
7Change Request Template
Updated**Affected Global Secure Access capability:**
Operations Common
Updated- [Remote Networks operations](how-to-operate-remote-networks.md)
Operate Remote Networks
Updated| Alert | Condition | Role | What to do next |
Communication Plan
Updated- Prechange notification drafted and reviewed
Daily Health Check
Updated| # | Check | Status | What to do if it fails |
Install Android Client
Updated| Configuration key | Value | Details |
Install Ios Client
Updated|Key |Value |Details |
Fundamentals
1Operations
Updated- **Platform operations and monitoring engineers** who manage health checks, automation, and dashboards
Monitoring
1Operate Microsoft Traffic
UpdatedThis section is organized in the order you should implement monitoring for Microsoft traffic:
