Week in brief

Preview PIM role-activation extensions and dynamic-membership incident samples headline a documentation-heavy Entra week

For the week of 8 June 2026, the supplied record is primarily a Microsoft Learn update cycle: 38 documentation changes, including 7 new and 31 updated items, with no removals or Message Center entries. The most consequential additions are a new preview guide for custom extensions in Microsoft Entra Privileged Identity Management (PIM) role activation and a new PowerShell sample set for pausing and resuming dynamic membership during incidents. Other notable updates clarify Microsoft Entra ID Protection reauthentication behavior and expand Agent ID, Conditional Access optimization, and authentication-registration guidance. No supplied item indicates general availability or retirement.

  • PIM role-activation custom extensions are documented as PreviewID Governance — Privileged Identity Management

    A new ID Governance article, explicitly labeled Preview, explains how to configure custom extensions in Microsoft Entra Privileged Identity Management so custom business logic can be integrated into role-activation workflows. This is a new preview documentation item—not evidence of general availability, a tenant-wide rollout, or a retirement. The supplied material provides no prerequisites or rollout requirements.

  • Dynamic-membership incident response gets a new PowerShell sample setEntra ID — Dynamic membership processing

    New Entra ID samples cover pausing all dynamic-membership groups and administrative units; pausing all except specified IDs; pausing specified objects; and resuming either noncritical objects in batches of up to 100 of each per run or specified critical objects. The set is explicitly framed for mitigating ongoing membership-processing issues and incident response. It adds operational guidance, not evidence that the service’s dynamic-membership behavior changed.

  • Agent ID and Conditional Access optimization guidance expandsAgent ID and Entra ID — Conditional Access

    Updated pages describe targeting agent identities in Conditional Access policies, using Knowledge Bases to help the Conditional Access Optimization Agent create recommendations based on organizational standards, and configuring settings for triggers, notifications, scope, custom instructions, Intune integrations, and permissions. The What If Tool update also identifies the What If Evaluation API as a Microsoft Graph API used by the Conditional Access experience and notes differences from the legacy evaluation. The

  • Identity Protection documentation clarifies automatic reauthentication controlsEntra ID Protection

    The updated Identity Protection Policies page states that Require authentication strength and Sign-in frequency set to Every time are automatically applied to the policy. Its stated purpose is to ensure that, after session revocation, end users are immediately prompted to reauthenticate with the specified authentication strength. Because this is marked as an update, the evidence supports a documented behavior or security clarification, not a confirmed new enforcement change.

  • Registration guidance is refreshed for passkeys, Authenticator, and combined MFA/SSPR registrationEntra ID — Authentication

    Updated Entra ID authentication guidance covers running a registration campaign to nudge users toward passkeys or Microsoft Authenticator, enabling combined multifactor authentication and self-service password reset security-information registration, and troubleshooting combined registration. These are guidance updates for stronger-authentication enrollment and user support; the supplied material does not establish a new launch, general-availability status, or required tenant configuration change.

For Entra administrators

Treat the PIM item as preview documentation, not a general-availability signal. If dynamic-membership processing is relevant to incident response, the new samples provide scoped, exception-based, and batched pause/resume procedures. Review the Identity Protection wording when validating session-revocation behavior, and use the Agent ID, Conditional Access, and registration updates for policy or enrollment work rather than assuming a new service capability. The evidence does not establish a tenant-wide configuration change or mandatory action.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

11

Assign App Owners

Updated

"@odata.id" = "https://graph.microsoft.com/v1.0/directoryObjects/aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb"

12 June 2026

Authentication

6

Standards

3

Breaking Changes

Updated

`https://login.microsoftonline.com/contoso.com/oauth2/authorize?resource=https://gateway.contoso.com/api&response_type=token&client_id=00001111-aaaa-2222-bbbb-3333cccc4444&...`

12 June 2026

Conditional Access Agent Optimization Settings

Updated

The agent settings described in this article cover standard options like triggers, notifications, and scope. But the settings also include advanced options like custom instructions, Intune integrations, and permissions.

12 June 2026

Conditional Access

1

Developer

1

Howto Update Permissions

Updated

1. Identify the permissions your app requires, their permission IDs, and whether they're app roles (application permissions) or delegated permissions. For example, if you want to request Microsoft Graph permissions, see [Microsoft Graph permissions](/graph/permissions-reference#permission-scenarios) for a list of permissions and their IDs.

12 June 2026

Fundamentals

1

Microsoft identity platform

1

What If Tool

Updated

The [What If Evaluation API](/graph/api/conditionalaccessroot-evaluate) is a Microsoft Graph API that is called by the Conditional Access experience. The API is different from the legacy What If evaluation in a few ways:

12 June 2026

Provisioning

1

Troubleshooting

1

Conditional Access

1

Target agent identities in Conditional Access policies

Updated

Conditional Access policies for agent identities let you control how AI agents access corporate resources. As your organization deploys more agents, you need policies that target the right agents, evaluate the right signals, and enforce the right controls. To learn more about how Conditional Access policies for agents work for different scenarios, see [Conditional Access policies for agents](agent-id.md).

12 June 2026

Fundamentals

1

Agent Id

Updated

- High-level overview of Conditional Access: [What is Conditional Access?](overview.md)

12 June 2026

General

1

Microsoft identity platform

1

Fundamentals

1

Identity Protection Policies

Updated

- **Require authentication strength** and **Sign-in frequency - Every time** are automatically applied to the policy to ensure that after session revocation, end users are immediately prompted to reauthenticate with the specified authentication strength.

12 June 2026

Governance

1

Standards

2

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

12 June 2026

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

12 June 2026

Authentication

1

About B2B Invitations

Updated

Learn about the B2B collaboration invitation email you can send to business partners and external guest users who need to authenticate and access your apps.

13 June 2026

General

1

Authentication

1

Idv Partners

Updated

| 1Kosmos | [1Kosmos offer](https://aka.ms/1kosmos) | [VerifiedIdentity](https://verifiedid.did.msidentity.com/v1.0/tenants/8108e610-606c-4dc3-ae95-d3ad8be3b24c/verifiableCredentials/contracts/1197e066-a9a2-2dc5-f245-4c31d1f4b456/manifest) | 1Kosmos and Microsoft Entra Verified ID unite to deliver trusted, privacy-preserving identity verification that empowers secure, passwordless access across ecosystems. |

12 June 2026

Fundamentals

1

External User Access

Updated

:::image type="content" source="media/concept-external-user-access/guest-access-overview.png" alt-text="Diagram showing an overview of external user access in Global Secure Access." lightbox="media/concept-external-user-access/guest-access-overview.png":::

13 June 2026