Week in brief

Week of 11 May 2026: passkey re-enrollment, Conditional Access analysis, and Agent ID migration guidance stand out

The supplied feed is best read as a documentation-clarification cycle: 42 items are marked Updated, with no new or removed items and no Message Center entries. The meaningful exceptions are concrete guidance on Entra ID authentication and Conditional Access Agent Optimization, an explicit Agent ID migration constraint, runbook-level operations for Global Secure Access, Private Access, and Internet Access, and several support or licensing boundaries. No supplied item identifies a new feature, preview, general-availability announcement, retirement, or tenant-wide service-behavior change; much of the remainder is reference, tutorial, or maintenance text.

  • Entra ID authentication guidance clarifies passkey re-enrollment and deployment boundariesEntra ID — FIDO2 passkeys, phishing-resistant passwordless authentication, and Authenticator Lite

    The updated FIDO2 guidance states that after a user's UPN changes, an existing passkey cannot be modified for the new UPN: the user must open Security info, delete the old passkey, and add a new one. It also says devices must support passkey authentication; the best experience on Entra-joined Windows devices is Windows 10 version 1903 or later, while hybrid-joined devices must run version 2004 or later. Related updates address Remote Desktop in phishing-resistant passwordless deployments, explain that system-preเพr

For Entra administrators

There is no evidenced broad tenant change to implement from this period. Follow up only where relevant: include the documented UPN-change/passkey re-registration path in support planning; account for the P2 requirement attached to the risky-sign-in MFA suggestion; plan Copilot Studio-to-Agent ID moves as recreation; use the access-operation health and connector guidance; and check the documented support, licensing, and schema limits before relying on those capabilities. These are documentation-led follow-ups, not evidence of automatic configuration changes.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Authentication

8

Authentication Passkeys Fido2

Updated

- Devices must support passkey (FIDO2) authentication. For Windows devices that are joined to Microsoft Entra ID, the best experience is on Windows 10 version 1903 or higher. Hybrid-joined devices must run Windows 10 version 2004 or higher.

16 May 2026

Authentication Passkeys Fido2

Updated

If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.

15 May 2026

Native Authentication Api

Updated

Microsoft Entra determines the default MFA method for the user by priority as follows:

15 May 2026

Conditional Access Agent Optimization

Updated

- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.

14 May 2026

Conditional Access Agent Optimization Review Suggestions

Updated

Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.

14 May 2026

Fundamentals

4

Native Authentication

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).

15 May 2026

General

4

Quickstart Register App

Updated

1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.

15 May 2026

Provisioning

2

Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Atla…

Updated

This article describes the steps you need to perform in both Atlassian Cloud and Microsoft Entra ID to configure automatic user provisioning. When configured, Microsoft Entra ID automatically provisions and de-provisions users and groups to [Atlassian Cloud](https://www.atlassian.com/cloud) using the Microsoft Entra provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).

12 May 2026

Developer

1

Entra Service Limits Include

Updated

| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li> Only the "equals" operator is supported for DateTime-type extensions. Range operators like "greater than" or "less than" are not supported.</li></ul> |

14 May 2026

Microsoft identity platform

1

Mfa Authenticator Lite

Updated

- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.

15 May 2026

Security

1

Standards

1

Troubleshooting

1

Fundamentals

1

General

1

Agent Id Ai Guided Setup

Updated

If you have the GitHub Copilot for Azure extension installed, ask Copilot to set up Agent ID. For example:

14 May 2026

Governance

1

Migrate Copilot Studio agents to Agent ID

Updated

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

15 May 2026

Fundamentals

1

Licensing Fundamentals

Updated

Account Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).

14 May 2026

Monitoring

1

Backup Difference Report Recovery Model

Updated

Microsoft Entra Backup and Recovery is available for workforce tenants only. Microsoft Entra External ID tenants and Azure AD B2C tenants aren't supported.

13 May 2026

General

1

General

3

Operate Microsoft Entra Private Access

Updated

Post-deployment operations guide for Microsoft Entra Private Access, the Zero Trust network access (ZTNA) capability, covering alerting, health checks, integration, automation, and operational metrics.

13 May 2026

Licensing Guest Users

Updated

Guest users are only billed when they actively sign in to the Global Secure Access client for Private Access.

13 May 2026

Monitoring

1

Operate Private Access

Updated

| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |

14 May 2026

General

7

Operations Common

Updated

- [Remote Networks operations](how-to-operate-remote-networks.md)

13 May 2026

Fundamentals

1

Operations

Updated

- **Platform operations and monitoring engineers** who manage health checks, automation, and dashboards

13 May 2026

Monitoring

1

Operate Microsoft Traffic

Updated

This section is organized in the order you should implement monitoring for Microsoft traffic:

13 May 2026