Learn how to install the Microsoft Entra Connect Health agents for Active Directory Federation Services (AD FS) and for sync.
Conditional Access enrollment enforcement is the week’s key Entra change
The period’s clearest operational event is a scheduled behavior change, not a Learn-page launch: beginning July 6, 2026, Conditional Access policies will apply during Windows Hello for Business and macOS Platform SSO registration, with rollout completion scheduled for July 13. Other meaningful items are preview documentation for device soft delete, device-code-flow security guidance, and platform and licensing clarifications. Most remaining entries are routine Learn maintenance around Connect Health, synchronization, groups, and tutorials. The supplied evidence shows no retirement and does not establish general availability; the generic “What’s New” entry is not detailed enough to support a feature-launch claim.
- Conditional Access will apply to WHfB and macOS Platform SSO registrationEntra ID
Type: scheduled behavior change. The Message Center notice says Conditional Access policies will be enforced during Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, including requirements such as MFA and trusted locations. The rollout is scheduled to complete July 13, so this is the period’s clearest preparation item rather than a documentation-only update.
- Device soft delete is documented as a preview capabilityEntra ID
Type: new and updated preview documentation. Microsoft Learn now describes deleted Entra ID devices moving to a recoverable state instead of being permanently removed, with a companion page explicitly marked “preview.” The evidence establishes the deletion semantics being documented, but not general availability or a tenant-wide service behavior change this week.
- Device code flow guidance emphasizes attacker exposureEntra ID
Type: security guidance. The updated Managed Policies content says device code flow is rarely used by customers but frequently used by attackers, and that enabling the relevant Microsoft-managed policy helps remove the attack vector. This is guidance about using the policy; the supplied entry does not say the policy was automatically enabled or that device code flow was retired.
- MFA registration nudges are clarified by platformEntra ID
Type: documentation clarification. The MFA Registration Campaign update says a user with a Windows Hello for Business credential is not nudged when signing in on Windows with Chrome, but is nudged on a Mac with Chrome because the credential does not apply to that platform. This explains why enrollment prompts can differ across devices and should be considered separately from the scheduled Conditional Access registration change.
- Verified ID Face Check entitlement requirements are clarifiedVerified ID
Type: entitlement and configuration clarification. Face Check is identified as a premium Verified ID feature included with Microsoft Entra Suite. Customers not using the Suite must enable the Face Check Add-on in their Verified ID setup before performing Face Check verifications. The update does not announce new availability or general availability.
Prioritize the registration change: review and test affected Conditional Access policies before July 6, update enrollment documentation, and confirm users can meet requirements such as MFA and trusted locations, as the Message Center notice directs. Treat Device soft delete as preview documentation rather than GA. Organizations using device code flow should review the Microsoft-managed policy guidance; non-Suite Verified ID deployments need the Face Check add-on enabled before Face Check verifications. The MFA Registration Campaign edit mainly explains platform-specific prompting, while the supplied Connect Health and other setup-page edits do not themselves report a service behavior change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
26 updatesGeneral
11Purpose:
Newauthor: omondiatieno
Purpose:
Newauthor: omondiatieno
Purpose:
Newauthor: omondiatieno
Purpose:
Newauthor: omondiatieno
Groups Create Rule
UpdatedUsing dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).
User Administrator
UpdatedUser Administrator
* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.
Connect Install Roadmap
Updated<a name='download-and-install-azure-ad-connect-health-agent'></a>
Connect Ports
Updated<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>
b. In the **Reply URL** text box, type the URL:
Monitoring
5Describes the Microsoft Entra Connect Health AD FS risky IP report with Azure Monitor Workbooks.
This is the Microsoft Entra Connect Health page how to monitor your on-premises AD FS infrastructure.
This is the Microsoft Entra Connect Health page that discusses how to monitor Microsoft Entra Connect Sync.
The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.
Plan Cloud Sync Topologies
Updated> [!IMPORTANT]
Authentication
4Mfa Registration Campaign
UpdatedFor example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome, they're nudged because that credential doesn't apply to that platform.
Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.
This document describes how to integrate AD FS sign-ins with the Microsoft Entra Connect Health sign-ins report.
Connect Pta
Updated- Installing multiple agents provides high availability of sign-in requests.
Fundamentals
4Whats New
Updated**Type:** New feature
Learn about cross-tenant synchronization in Microsoft Entra ID.
Learn about device soft delete (preview) in Microsoft Entra ID, which moves deleted devices to a recoverable state instead of permanently removing them.
Learn about device soft delete in Microsoft Entra ID, which moves deleted devices to a recoverable state instead of permanently removing them.
Conditional Access
1- Contractors are governed by their own policies separate from the baseline
Developer
1Managed Policies
UpdatedDevice code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.
Microsoft Entra Agent ID
1 updateGeneral
1- Maximum of 50 resource apps per agent identity blueprint (for example, up to 50 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.
Microsoft Entra External ID
2 updatesFundamentals
1Supported Features Customers
Updated| Feature | Workforce tenant | External tenant |
Provisioning
1::: zone pivot="same-cloud-synchronization"
Microsoft Entra Verified ID
1 updateGeneral
1Using Facecheck
UpdatedFace Check is a premium feature within Verified ID. If you're a Microsoft Entra Suite customer, Face Check is included as part of the Suite. If you're not using Microsoft Entra Suite, you need to enable the Face Check Add-on in your Microsoft Entra Verified ID setup before doing Face Check verifications.
Microsoft Entra Workload ID
2 updatesDeveloper
11. Under **Assignments**, select **Users or workload identities**.
Provisioning
12. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in the SAP Cloud Identity Service admin console and returns a short-lived access token that can only be used to query the SAP SuccessFactors OData API.
