author: jeevansd
6 March 2026: Entra ID documents Bulk Operations preview limits and staged Token Protection rollout
This was a documentation-update day rather than a confirmed release or retirement: all 22 records were updates, with no new or removed entries. The most consequential changes clarify the current scope of Entra ID Bulk Operations (Preview), provide more explicit Token Protection rollout and token-theft monitoring guidance, and document an External ID cross-tenant limitation. The remaining updates are mainly provisioning connector tutorials, app integration instructions, and other how-to maintenance; the evidence does not support treating them as new feature launches or general availability announcements.
- Entra ID Bulk Operations preview scope is specified
Entra ID · Fundamentals
The updated What's New entry describes the Bulk Operations service as Preview and says it currently supports Groups, Devices, and User Export. Enterprise Applications are not yet supported and are described as coming soon. This is a scope and availability clarification, not evidence of general availability or a launch date.
- Token Protection guidance requires a report-only phase before enforcement
Entra ID · Authentication
The updated Apple deployment guide instructs administrators to deploy the Token Protection policy in report-only mode first, assess its effect, and identify noncompliant sign-in sessions before enforcing it. This is rollout guidance, not evidence of a change to enforcement behavior or availability.
- Token-theft defense guidance points to Defender XDR monitoring
Entra ID · Security
The updated Protecting Tokens guidance tells administrators to deploy Defender XDR workloads to alert on suspicious or anomalous behavior surrounding token theft. The supplied evidence supports this as security guidance and does not indicate that a new Defender XDR integration launched.
- External ID documents a cross-tenant B2B management limitation
External ID · Provisioning
The updated Known Issues page states that B2B users are unable to manage certain Microsoft 365 services in remote tenants, such as Exchange Online, because there is no directory picker. This records a known limitation rather than a fix or changed product behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
23 updates
Microsoft Entra ID
19 updatesLearn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Dialpad.
author: jeevansd
author: jeevansd
manager: pmwongera

This section guides you through connecting your Microsoft Entra ID to GoToMeeting's user account provisioning API, and configuring the provisioning service to create, update, and disable assigned user accounts in GoToMeeting based on user and group assignment in Microsoft Entra ID.
Whats New
Updated**Note:** Currently, the new Bulk Operations service supports **Groups**, **Devices**, and **User Export** only. Support for additional entities, such as **Enterprise Applications**, is coming soon. For more information, see: [Bulk operations in Microsoft Entra ID (Preview)](../fundamentals/bulk-operations.md).
Whats New Archive
Updatedauthor: owinfreyATL
Token Protection
Updated- For detailed steps on how to register your device, see [Register your personal device on your work or school network](https://support.microsoft.com/account-billing/register-your-personal-device-on-your-work-or-school-network-8803dd61-a613-45e3-ae6c-bd1ab25bf8a8).
Before enforcing the policy, deploy it in report-only mode to assess the effect and identify noncompliant sign-in sessions.
Use Vm Sign In
Updated> [!IMPORTANT]
Delete users in bulk in Microsoft Entra ID
Peoplecart Tutorial
Updated`https://<tenantname>.peoplecart.com/SignIn.aspx`
Msal Node Migration
Updated});
Yet another common error you might face is `consent_required`, which occurs when permissions required for obtaining an access token for a protected resource aren't consented by the user. As in `interaction_required`, the solution for `consent_required` error is often initiating an interactive token acquisition prompt, using either `acquireTokenPopup` or `acquireTokenRedirect`.
Token Protection on Windows platforms can be used to protect the following resources:
Deploy Defender XDR workloads to alert on suspicious or anomalous behaviors surrounding token theft.
Blackboard Learn Tutorial
Updated`https://<subdomain>.blackboard.com/auth-saml/saml/SSO/entity-id/SAML_AD`
Microsoft Entra ID Protection
1 updateThe AI Administrator role is updated to support Agent 365, enabling delegated agent management without Global Admin involvement for routine tasks. Rollout starts March 2026. AI Admins gain expanded permissions for agent lifecycle management, tenant-wide consent (excluding Microsoft Graph app permissions), and risk monitoring via Identity Protection, enhancing security and compliance.
Microsoft Entra External ID
2 updatesCross Cloud Settings
UpdatedThe following scenarios are supported when collaborating with an organization from a different Microsoft cloud:
Known Issues
Updated- B2B users are unable to manage certain Microsoft 365 services in remote tenants (such as Exchange Online), as there's no directory picker.
Microsoft Entra Workload ID
1 update- Using the Azure portal, give an Azure virtual machine scale set managed identity [access to another Azure resource](~/identity/managed-identities-azure-resources/grant-managed-identity-resource-access-azure-portal.md).
