Week in brief

Actionable-message token retirement is the week’s clearest breaking change; most other entries clarify guidance

The supplied record for the week of 18 May 2026 contains one consequential Microsoft 365 Message Center change and otherwise Learn-page revisions. External access tokens for actionable messages are being replaced by Microsoft Entra authentication; the notice says legacy-token messages will fail, lists 15 May 2026 as the retirement date, and says the phase-out completes by 8 June 2026. The remaining material does not identify a new feature, preview, general-availability milestone, or removal. It is chiefly implementation, security, governance, routing, licensing, and troubleshooting clarification.

  • Actionable-message external tokens are being retiredEntra ID

    The 22 May Microsoft 365 Message Center major update says external access tokens for actionable messages are being replaced by Microsoft Entra authentication. It says messages using legacy tokens will fail, gives 15 May 2026 as the retirement date, and says the phase-out completes by 8 June 2026. This is a breaking retirement notice, not a documentation clarification; the supplied notice gives no further integration requirements.

  • External ID guidance covers custom headers across web and mobile authenticationExternal ID

    Three 21 May Learn updates explain how to attach custom x-* headers to native authentication requests in React or Angular JavaScript SPAs, iOS with Swift, and Android with Kotlin so fraud-detection SDKs can be integrated. This is platform-specific implementation guidance; the record does not identify a new preview, GA release, or tenant-wide configuration change.

  • Authentication and Conditional Access documentation clarifies security rollout and session behaviorEntra ID / External ID

    The updated Entra ID registration-campaign guidance describes nudging users toward passkeys or Microsoft Authenticator. External ID customer user-flow guidance states that users see a Stay signed in? prompt by default: selecting Yes issues a persistent cookie across browser sessions, while No issues a non-persistent cookie. Related Conditional Access pages explain custom controls and provide migration guidance to external MFA. The evidence does not say that enrollment is mandatory, that the session default changed,

  • Agent ID documentation clarifies ownership and Conditional Access executionAgent ID / Entra ID

    Updated Agent ID material says Conditional Access guidance extends Zero Trust principles to agent identities. It also states that owners can be individual users, including guest users, or service principals; groups are not supported, and owners are optional for agent identity blueprints and agent identities. A separate Conditional Access Agent Optimization note says a run cannot be stopped or paused once started and may take a few minutes. These are operational clarifications, not evidence of a new Agent ID release

  • Global Secure Access references make connector routing and license scope explicitGlobal Secure Access / Internet Access

    The updated Connector Groups page states that a connector group selects which connector handles each request, with Random as the default routing option and Session persistence as an alternative. The Global Secure Access overview relates Entra P1/P2, Internet Access, and Private Access licenses to their traffic profiles, while the known-limitations page calls out GCC limitations and disclaimers. These are reference clarifications, not a reported launch or availability change.

For Entra administrators

Owners of integrations that use external access tokens for actionable messages should move them to Microsoft Entra authentication; the notice’s already-passed 15 May date makes this time-sensitive, even though phase-out completion is listed as 8 June. The Learn edits require conditional attention rather than a tenant-wide response: review them when using the affected External ID SDK patterns, authentication campaigns, Conditional Access controls, Agent ID governance, or Global Secure Access scenarios. The supplied evidence does not establish a mandatory change for those documentation updates.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Authentication

3

Conditional Access

2

Fundamentals

2

Certificate Based Authentication Certificate Revocation List

Updated

| **AADSTS500183: Certificate has been revoked. Please contact your administrator** | An Authentication attempt failed because the client device presented a certificate that was revoked by the issuing CA. | The certificate used for authentication is found in the Certificate Revocation List (CRL) or flagged as revoked by the CA. | - Tenant Administrator should ensure the new certificate is correctly provisioned and trusted by Microsoft Entra ID.<br/>- Verify that the CRLs and delta CRLs published by your CA are up to date and accessible for the devices. |

19 May 2026

Sspr Policy

Updated

| Compliance Administrator | Knowledge Administrator | Teams Communications Administrator |

19 May 2026

General

1

Samsara Tutorial

Updated

b. Copy the link from Post-back/ACS URL field in Samsara into the **Reply URL** text box in Entra ID.

21 May 2026

Provisioning

1

Github Enterprise Managed User Oidc Provisioning Tutorial

Updated

Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).

19 May 2026

Standards

1

Troubleshooting

1

Conditional Access

1

General

1

Agent Owners Sponsors Managers

Updated

Owners usually serve as technical administrators for agents, handling operational and configuration aspects. Individual users (including guest users) and service principals can be set as owners. Groups aren't supported as owners. Service principals as owners enable automated management of agent identities. Owners are optional for agent identity blueprints and agent identities.

20 May 2026

Authentication

4

User Flow Sign Up Sign In Customers

Updated

By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain signed in across browser sessions. If they select **No**, a non-persistent cookie is issued.

21 May 2026

Standards

2

Direct Federation

Updated

1. On the **New SAML/WS-Fed IdP** page, enter the following:

21 May 2026

Direct Federation

Updated

To enable domainless federation for a new SAML IdP, follow these steps:

19 May 2026

General

1

Fundamentals

1

What Is Global Secure Access

Updated

| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |

20 May 2026

Fundamentals

2

Connector Groups

Updated

When you add multiple connectors to a connector group, the group selects which connector handles each request. Routing options include Random (default) and Session persistence.

19 May 2026

General

1

Current Known Limitations

Updated

For usage in US Government community (GCC) cloud, known limitations/disclaimers include:

19 May 2026