Authenticate Application Id
Updated|**Automatic rotation enabled**|Whether automatic rotation or manual rotation is enabled|
Daily.Entra.NewsThe supplied record for the week of 18 May 2026 contains one consequential Microsoft 365 Message Center change and otherwise Learn-page revisions. External access tokens for actionable messages are being replaced by Microsoft Entra authentication; the notice says legacy-token messages will fail, lists 15 May 2026 as the retirement date, and says the phase-out completes by 8 June 2026. The remaining material does not identify a new feature, preview, general-availability milestone, or removal. It is chiefly implementation, security, governance, routing, licensing, and troubleshooting clarification.
The 22 May Microsoft 365 Message Center major update says external access tokens for actionable messages are being replaced by Microsoft Entra authentication. It says messages using legacy tokens will fail, gives 15 May 2026 as the retirement date, and says the phase-out completes by 8 June 2026. This is a breaking retirement notice, not a documentation clarification; the supplied notice gives no further integration requirements.
Three 21 May Learn updates explain how to attach custom x-* headers to native authentication requests in React or Angular JavaScript SPAs, iOS with Swift, and Android with Kotlin so fraud-detection SDKs can be integrated. This is platform-specific implementation guidance; the record does not identify a new preview, GA release, or tenant-wide configuration change.
The updated Entra ID registration-campaign guidance describes nudging users toward passkeys or Microsoft Authenticator. External ID customer user-flow guidance states that users see a Stay signed in? prompt by default: selecting Yes issues a persistent cookie across browser sessions, while No issues a non-persistent cookie. Related Conditional Access pages explain custom controls and provide migration guidance to external MFA. The evidence does not say that enrollment is mandatory, that the session default changed,
Updated Agent ID material says Conditional Access guidance extends Zero Trust principles to agent identities. It also states that owners can be individual users, including guest users, or service principals; groups are not supported, and owners are optional for agent identity blueprints and agent identities. A separate Conditional Access Agent Optimization note says a run cannot be stopped or paused once started and may take a few minutes. These are operational clarifications, not evidence of a new Agent ID release
The updated Connector Groups page states that a connector group selects which connector handles each request, with Random as the default routing option and Session persistence as an alternative. The Global Secure Access overview relates Entra P1/P2, Internet Access, and Private Access licenses to their traffic profiles, while the known-limitations page calls out GCC limitations and disclaimers. These are reference clarifications, not a reported launch or availability change.
Owners of integrations that use external access tokens for actionable messages should move them to Microsoft Entra authentication; the notice’s already-passed 15 May date makes this time-sensitive, even though phase-out completion is listed as 8 June. The Learn edits require conditional attention rather than a tenant-wide response: review them when using the affected External ID SDK patterns, authentication campaigns, Conditional Access controls, Agent ID governance, or Global Secure Access scenarios. The supplied evidence does not establish a mandatory change for those documentation updates.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
|**Automatic rotation enabled**|Whether automatic rotation or manual rotation is enabled|
Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
Learn how to migrate from custom controls to external multifactor authentication in Microsoft Entra Conditional Access.
Learn how custom controls in Microsoft Entra Conditional Access work.
- After the agent starts, you can't stop or pause the run. It might take a few minutes to run.
| **AADSTS500183: Certificate has been revoked. Please contact your administrator** | An Authentication attempt failed because the client device presented a certificate that was revoked by the issuing CA. | The certificate used for authentication is found in the Certificate Revocation List (CRL) or flagged as revoked by the CA. | - Tenant Administrator should ensure the new certificate is correctly provisioned and trusted by Microsoft Entra ID.<br/>- Verify that the CRLs and delta CRLs published by your CA are up to date and accessible for the devices. |
| Compliance Administrator | Knowledge Administrator | Teams Communications Administrator |
b. Copy the link from Post-back/ACS URL field in Samsara into the **Reply URL** text box in Entra ID.
Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).
External access tokens for actionable messages will be retired by May 15, 2026, replaced by Microsoft Entra authentication to enhance security. Organizations must update integrations before this date, as messages using legacy tokens will fail. The phase-out completes by June 8, 2026.
Learn how to troubleshoot user update issues with HR provisioning
Learn how Conditional Access for agent identities in Microsoft Entra ID extends Zero Trust principles to AI agents, ensuring secure access and governance.
Owners usually serve as technical administrators for agents, handling operational and configuration aspects. Individual users (including guest users) and service principals can be set as owners. Groups aren't supported as owners. Service principals as owners enable automated management of agent identities. Owners are optional for agent identity blueprints and agent identities.
Learn how to attach custom x-* headers to native authentication requests in a React or Angular SPA to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an iOS (Swift) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an Android (Kotlin) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain signed in across browser sessions. If they select **No**, a non-persistent cookie is issued.
1. On the **New SAML/WS-Fed IdP** page, enter the following:
To enable domainless federation for a new SAML IdP, follow these steps:
|---------|-------|
| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |
@{ Key="HKLM:\SOFTWARE\Policies\Microsoft\Edge"; Name="BuiltInDnsClientEnabled"; Type="DWord"; Value=0 },
When you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.
For usage in US Government community (GCC) cloud, known limitations/disclaimers include: