Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Preview PIM role-activation extensions and dynamic-membership incident samples headline a documentation-heavy Entra week
For the week of 8 June 2026, the supplied record is primarily a Microsoft Learn update cycle: 38 documentation changes, including 7 new and 31 updated items, with no removals or Message Center entries. The most consequential additions are a new preview guide for custom extensions in Microsoft Entra Privileged Identity Management (PIM) role activation and a new PowerShell sample set for pausing and resuming dynamic membership during incidents. Other notable updates clarify Microsoft Entra ID Protection reauthentication behavior and expand Agent ID, Conditional Access optimization, and authentication-registration guidance. No supplied item indicates general availability or retirement.
- PIM role-activation custom extensions are documented as PreviewID Governance — Privileged Identity Management
A new ID Governance article, explicitly labeled Preview, explains how to configure custom extensions in Microsoft Entra Privileged Identity Management so custom business logic can be integrated into role-activation workflows. This is a new preview documentation item—not evidence of general availability, a tenant-wide rollout, or a retirement. The supplied material provides no prerequisites or rollout requirements.
- Dynamic-membership incident response gets a new PowerShell sample setEntra ID — Dynamic membership processing
New Entra ID samples cover pausing all dynamic-membership groups and administrative units; pausing all except specified IDs; pausing specified objects; and resuming either noncritical objects in batches of up to 100 of each per run or specified critical objects. The set is explicitly framed for mitigating ongoing membership-processing issues and incident response. It adds operational guidance, not evidence that the service’s dynamic-membership behavior changed.
- Agent ID and Conditional Access optimization guidance expandsAgent ID and Entra ID — Conditional Access
Updated pages describe targeting agent identities in Conditional Access policies, using Knowledge Bases to help the Conditional Access Optimization Agent create recommendations based on organizational standards, and configuring settings for triggers, notifications, scope, custom instructions, Intune integrations, and permissions. The What If Tool update also identifies the What If Evaluation API as a Microsoft Graph API used by the Conditional Access experience and notes differences from the legacy evaluation. The
- Identity Protection documentation clarifies automatic reauthentication controlsEntra ID Protection
The updated Identity Protection Policies page states that Require authentication strength and Sign-in frequency set to Every time are automatically applied to the policy. Its stated purpose is to ensure that, after session revocation, end users are immediately prompted to reauthenticate with the specified authentication strength. Because this is marked as an update, the evidence supports a documented behavior or security clarification, not a confirmed new enforcement change.
- Registration guidance is refreshed for passkeys, Authenticator, and combined MFA/SSPR registrationEntra ID — Authentication
Updated Entra ID authentication guidance covers running a registration campaign to nudge users toward passkeys or Microsoft Authenticator, enabling combined multifactor authentication and self-service password reset security-information registration, and troubleshooting combined registration. These are guidance updates for stronger-authentication enrollment and user support; the supplied material does not establish a new launch, general-availability status, or required tenant configuration change.
Treat the PIM item as preview documentation, not a general-availability signal. If dynamic-membership processing is relevant to incident response, the new samples provide scoped, exception-based, and batched pause/resume procedures. Review the Identity Protection wording when validating session-revocation behavior, and use the Agent ID, Conditional Access, and registration updates for policy or enrollment work rather than assuming a new service capability. The evidence does not establish a tenant-wide configuration change or mandatory action.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
26 updatesGeneral
11PowerShell sample that pauses all groups and administrative units with dynamic membership in your Microsoft Entra tenant to mitigate ongoing membership-processing issues.
PowerShell sample that pauses every group and administrative unit with dynamic membership in your Microsoft Entra tenant except for the IDs you specify.
PowerShell sample that pauses specific groups and administrative units with dynamic membership in your Microsoft Entra tenant by accepting a list of IDs.
PowerShell sample that resumes dynamic membership processing for noncritical groups and administrative units in your Microsoft Entra tenant, up to 100 of each per run.
PowerShell sample - Resume specific critical groups and administrative units with dynamic membership
NewPowerShell sample that resumes dynamic membership processing for specific critical groups and administrative units in your Microsoft Entra tenant after pausing.
Use these PowerShell samples to pause and resume dynamic membership rule processing for Microsoft Entra groups and administrative units during incident response.
Global Administrator
UpdatedGlobal Administrator
Assign App Owners
Updated"@odata.id" = "https://graph.microsoft.com/v1.0/directoryObjects/aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb"
- Each dynamic group can have up to 50 member groups.
```json
Authentication
6Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
Learn how to simplify the user experience with combined Microsoft Entra multifactor authentication and self-service password reset registration.
```kql
- Replace `{authenticationeventsAPI_AppId}` with the **appId** you recorded earlier.
1. Select **Add**.
1. Select **Add**.
Standards
3Breaking Changes
Updated`https://login.microsoftonline.com/contoso.com/oauth2/authorize?resource=https://gateway.contoso.com/api&response_type=token&client_id=00001111-aaaa-2222-bbbb-3333cccc4444&...`
Learn how Knowledge Bases help the Conditional Access Optimization Agent create tailored policy recommendations based on your organization's unique standards.
The agent settings described in this article cover standard options like triggers, notifications, and scope. But the settings also include advanced options like custom instructions, Intune integrations, and permissions.
Conditional Access
1author: shlipsey3
Developer
1Howto Update Permissions
Updated1. Identify the permissions your app requires, their permission IDs, and whether they're app roles (application permissions) or delegated permissions. For example, if you want to request Microsoft Graph permissions, see [Microsoft Graph permissions](/graph/permissions-reference#permission-scenarios) for a list of permissions and their IDs.
Fundamentals
1Learn about requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID.
Microsoft identity platform
1What If Tool
UpdatedThe [What If Evaluation API](/graph/api/conditionalaccessroot-evaluate) is a Microsoft Graph API that is called by the Conditional Access experience. The API is different from the legacy What If evaluation in a few ways:
Provisioning
1"displayName": "AWS Contoso",
Troubleshooting
1Troubleshoot Microsoft Entra multifactor authentication and self-service password reset combined registration.
Microsoft Entra Agent ID
4 updatesConditional Access
1Conditional Access policies for agent identities let you control how AI agents access corporate resources. As your organization deploys more agents, you need policies that target the right agents, evaluate the right signals, and enforce the right controls. To learn more about how Conditional Access policies for agents work for different scenarios, see [Conditional Access policies for agents](agent-id.md).
Fundamentals
1Agent Id
Updated- High-level overview of Conditional Access: [What is Conditional Access?](overview.md)
General
1Agent ID Administrator
UpdatedAgent ID Administrator
Microsoft identity platform
1Agent ID Developer
UpdatedAgent ID Developer
Microsoft Entra ID Protection
1 updateFundamentals
1Identity Protection Policies
Updated- **Require authentication strength** and **Sign-in frequency - Every time** are automatically applied to the policy to ensure that after session revocation, end users are immediately prompted to reauthenticate with the specified authentication strength.
Microsoft Entra ID Governance
1 updateGovernance
1Learn how to configure custom extensions in Microsoft Entra Privileged Identity Management (PIM) to integrate custom business logic into role activation workflows.
Microsoft Entra External ID
4 updatesStandards
2Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Authentication
1About B2B Invitations
UpdatedLearn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.
General
1```powershell
Microsoft Entra Verified ID
1 updateAuthentication
1Idv Partners
Updated| 1Kosmos | [1Kosmos offer](https://aka.ms/1kosmos) | [VerifiedIdentity](https://verifiedid.did.msidentity.com/v1.0/tenants/8108e610-606c-4dc3-ae95-d3ad8be3b24c/verifiableCredentials/contracts/1197e066-a9a2-2dc5-f245-4c31d1f4b456/manifest) | 1Kosmos and Microsoft Entra Verified ID unite to deliver trusted, privacy-preserving identity verification that empowers secure, passwordless access across ecosystems. |
Fundamentals
1External User Access
Updated:::image type="content" source="media/concept-external-user-access/guest-access-overview.png" alt-text="Diagram showing an overview of external user access in Global Secure Access." lightbox="media/concept-external-user-access/guest-access-overview.png":::
