Week in brief

Conditional Access enrollment enforcement is the week’s key Entra change

The period’s clearest operational event is a scheduled behavior change, not a Learn-page launch: beginning July 6, 2026, Conditional Access policies will apply during Windows Hello for Business and macOS Platform SSO registration, with rollout completion scheduled for July 13. Other meaningful items are preview documentation for device soft delete, device-code-flow security guidance, and platform and licensing clarifications. Most remaining entries are routine Learn maintenance around Connect Health, synchronization, groups, and tutorials. The supplied evidence shows no retirement and does not establish general availability; the generic “What’s New” entry is not detailed enough to support a feature-launch claim.

  • Conditional Access will apply to WHfB and macOS Platform SSO registrationEntra ID

    Type: scheduled behavior change. The Message Center notice says Conditional Access policies will be enforced during Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, including requirements such as MFA and trusted locations. The rollout is scheduled to complete July 13, so this is the period’s clearest preparation item rather than a documentation-only update.

  • Device soft delete is documented as a preview capabilityEntra ID

    Type: new and updated preview documentation. Microsoft Learn now describes deleted Entra ID devices moving to a recoverable state instead of being permanently removed, with a companion page explicitly marked “preview.” The evidence establishes the deletion semantics being documented, but not general availability or a tenant-wide service behavior change this week.

  • Device code flow guidance emphasizes attacker exposureEntra ID

    Type: security guidance. The updated Managed Policies content says device code flow is rarely used by customers but frequently used by attackers, and that enabling the relevant Microsoft-managed policy helps remove the attack vector. This is guidance about using the policy; the supplied entry does not say the policy was automatically enabled or that device code flow was retired.

  • MFA registration nudges are clarified by platformEntra ID

    Type: documentation clarification. The MFA Registration Campaign update says a user with a Windows Hello for Business credential is not nudged when signing in on Windows with Chrome, but is nudged on a Mac with Chrome because the credential does not apply to that platform. This explains why enrollment prompts can differ across devices and should be considered separately from the scheduled Conditional Access registration change.

  • Verified ID Face Check entitlement requirements are clarifiedVerified ID

    Type: entitlement and configuration clarification. Face Check is identified as a premium Verified ID feature included with Microsoft Entra Suite. Customers not using the Suite must enable the Face Check Add-on in their Verified ID setup before performing Face Check verifications. The update does not announce new availability or general availability.

For Entra administrators

Prioritize the registration change: review and test affected Conditional Access policies before July 6, update enrollment documentation, and confirm users can meet requirements such as MFA and trusted locations, as the Message Center notice directs. Treat Device soft delete as preview documentation rather than GA. Organizations using device code flow should review the Microsoft-managed policy guidance; non-Suite Verified ID deployments need the Face Check add-on enabled before Face Check verifications. The MFA Registration Campaign edit mainly explains platform-specific prompting, while the supplied Connect Health and other setup-page edits do not themselves report a service behavior change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

11

Purpose:

New

author: omondiatieno

27 May 2026

Purpose:

New

author: omondiatieno

27 May 2026

Purpose:

New

author: omondiatieno

27 May 2026

Purpose:

New

author: omondiatieno

27 May 2026

Groups Create Rule

Updated

Using dynamic membership groups requires a Microsoft Entra ID P1 license or an Intune for Education license. For more information, see [Manage rules for dynamic membership groups in Microsoft Entra ID](./groups-dynamic-membership.md).

27 May 2026

Connect Health Data Freshness

Updated

* Make sure that Microsoft Entra Connect Health Agents services are **running** on the machine. For example, Connect Health for AD FS should have two services.

27 May 2026

Connect Ports

Updated

<a name='7b---endpoints-for-azure-ad-connect-health-agent-for-ad-fssync-and-azure-ad'></a>

27 May 2026

Monitoring

5

Using Microsoft Entra Connect Health with AD DS

Updated

The following documentation is specific to monitoring Active Directory Domain Services with Microsoft Entra Connect Health. The supported versions of AD DS are Windows Server 2016, 2019, 2022, and 2025.

27 May 2026

Authentication

4

Mfa Registration Campaign

Updated

For example, if a user has a Windows Hello for Business credential and signs in on Windows with Chrome, the nudge is suppressed. But if the same user signs in on a Mac with Chrome, they're nudged because that credential doesn't apply to that platform.

31 May 2026

Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration

New

Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.

30 May 2026
Message CenterMC1326253 on mc.merill.net ↗Stay informed

Connect Pta

Updated

- Installing multiple agents provides high availability of sign-in requests.

27 May 2026

Fundamentals

4

Whats New

Updated

**Type:** New feature

30 May 2026

Conditional Access

1

Developer

1

Managed Policies

Updated

Device code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.

29 May 2026

General

1

Configure Inheritable Permissions Blueprints

Updated

- Maximum of 50 resource apps per agent identity blueprint (for example, up to 50 entries in the *inheritablePermissions* collection). If you exceed this limit, reduce the number of resource apps to stay within the supported boundary.

27 May 2026

Fundamentals

1

Provisioning

1

General

1

Using Facecheck

Updated

Face Check is a premium feature within Verified ID. If you're a Microsoft Entra Suite customer, Face Check is included as part of the Suite. If you're not using Microsoft Entra Suite, you need to enable the Face Check Add-on in your Microsoft Entra Verified ID setup before doing Face Check verifications.

30 May 2026

Developer

1

Provisioning

1

Configure Workload Identity Sap Successfactors Provisioning

Updated

2. **SAP Cloud Identity Service exchanges the JWT for an access token.** The signed JWT is presented to SAP Cloud Identity Service, which is trusted by SAP SuccessFactors. SAP Cloud Identity Service validates the JWT against the trust rules you configure in the SAP Cloud Identity Service admin console and returns a short-lived access token that can only be used to query the SAP SuccessFactors OData API.

28 May 2026