This tutorial shows you how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to your iOS/macOS app using native authentication. MFA adds an extra layer of security by requiring a second verification step during sign-in.
AI Administrator RBAC expands for Agent 365; native-authentication OTP guidance points to a Private Preview
7 March was mostly a documentation-maintenance day: 58 of 67 records were updates, eight were new, and none were removals. The clearest operational change is the single Microsoft 365 Message Center notice about expanded AI Administrator permissions for Agent 365, with rollout starting in March 2026. Entra ID also added a coordinated set of native-authentication guides for email and SMS OTP MFA and strong authentication method registration; one updated tutorial explicitly points to a Private Preview. The 27 ID Governance records are chiefly PIM how-to updates, and their supplied summaries do not establish a new PIM capability or changed behavior.
- AI Administrator role gains Agent 365 and Identity Protection scope
ID Protection · Fundamentals
A Microsoft 365 Message Center notice says the AI Administrator role is being updated for Agent 365. Routine agent management can be delegated without Global Admin involvement; the expanded scope covers agent lifecycle management, tenant-wide consent except Microsoft Graph app permissions, and risk monitoring through Identity Protection. This is a service and RBAC rollout notice, not a documentation-only edit.
- New native-authentication guidance documents email and SMS OTP MFA for apps
Entra ID · Authentication
New Entra ID documentation shows how to add email and SMS one-time-passcode MFA to an Android app using native authentication. Related entries extend the implementation guidance to iOS/macOS and to registering email or SMS OTP as a strong authentication method. The feed supports a documentation expansion, not a stated feature launch or GA announcement.
- Native Authentication OTP MFA is explicitly presented as a Private Preview
Entra ID · Authentication
An updated Android strong authentication method registration tutorial tells implementers to enroll in a Private Preview of SMS and Email OTP MFA on Native Authentication. That status is the important availability boundary: the new material should be read as preview implementation guidance, and the supplied evidence provides no GA or broad-rollout statement.
- Dynamic-group security guidance focuses on attribute write access
Entra ID · Security
Updated Entra ID guidance says the security of a dynamic group’s membership depends on who can modify the attributes referenced by its rule. It specifically calls for reviewing write permissions in Microsoft Entra ID and connected source directories before choosing an attribute. This is security guidance and clarification, not evidence that dynamic-membership behavior changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
66 updates
Microsoft Entra ID
34 updates- Your native application integrates with a third‑party fraud protection provider to securely evaluate risk signals before issuing an SMS one‑time passcode (OTP).
This tutorial demonstrates how to implement Email strong authentication method registration into your Android app using native authentication. At least one strong authentication is mandatory for multifactor authentication (MFA) enabled users. Currently, we only support Email and SMS one-time passcode as strong authentication method.
1. Enroll in a Private Preview of SMS and Email OTP MFA on Native Authentication – [Fill out form](https://forms.office.com/r/P3m1q2j3hg)
Learn how to add multi-factor authentication (MFA) with email and SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add email one-time passcode (OTP) multi-factor authentication (MFA) to an iOS or macOS app by using native authentication and enforce MFA with authentication context.
Add email strong authentication method registration to an Android app using native authentication
NewLearn how to register an email one-time passcode as a strong authentication method for MFA-enabled users in an Android app using Microsoft Entra native authentication.
Learn how to register an email strong authentication method for MFA-enabled users in an iOS or macOS app by using native authentication.
Learn how to register phone SMS as a strong authentication method for MFA-enabled users in an iOS or macOS app using native authentication, including configuring client capabilities and handling registration challenges.
Learn how to add multi-factor authentication (MFA) with SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add multi-factor authentication (MFA) with SMS one-time passcode (OTP) to an iOS or macOS app using native authentication, including enforcing MFA with authentication context and handling MFA errors.
Learn how to register an SMS one-time passcode as a strong authentication method for MFA-enabled users in an Android app using Microsoft Entra native authentication.
To support multi-factor authentication (MFA), update the Android client configuration to include the required MFA capabilities.
To support multi-factor authentication (MFA), update the Android client configuration to include the required MFA capabilities.
To support strong authentication method, update the Android client configuration to include the required registration capabilities.
Set the registrationRequired capability during client initialization to support strong authentication method registration.
Learn how to add multifactor authentication (MFA) with SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add multifactor authentication (MFA) with email and SMS one-time passcodes to an Android app using Microsoft Entra native authentication.
Learn how to add email one-time passcode (OTP) multifactor authentication (MFA) to an iOS or macOS app by using native authentication and enforce MFA with authentication context.
> [!NOTE]
1. Complete the steps in [Tutorial: Add sign-in in Android app by using native authentication](tutorial-native-authentication-android-sign-in-sign-out.md).
Native Authentication Api
Updated| `continuation_token` | [Continuation token](#continuation-token) that Microsoft Entra returns. |
Change default subdomain authentication settings inherited from root domain settings in Microsoft Entra ID.
Privileged roles and permissions in Microsoft Entra ID.
Licensing Group Advanced
UpdatedMore scenarios limitations, and known issues for Microsoft Entra group-based licensing
How to take over a Domain name DNS domain name in an unmanaged Microsoft Entra organization (shadow tenant).
A Microsoft Entra documentation page was updated: Understand how multiple Microsoft Entra tenant organizations interact.
Use restricted management administrative units for more sensitive resources in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Licensing Groups Resolve Problems.
Management concepts and how-tos for managing a domain name in Microsoft Entra ID
Learn about Microsoft Entra bulk operations related to users, groups,
Use Microsoft Entra groups to simplify role assignment management in Microsoft Entra ID.
Overview
Updated:::image type="content" source="media/overview/conditional-access-overview.png" alt-text="Screenshot of the Conditional Access overview page." lightbox="media/overview/conditional-access-overview.png":::
Groups Dynamic Membership
UpdatedWhen you create a dynamic membership rule, the security of that group's membership depends on who can modify the attributes referenced in the rule. Before selecting an attribute, review the write permissions for that attribute—both in Microsoft Entra ID and in any connected source directories.
Microsoft Entra ID Governance
27 updatesDiscovery and insights (formerly Security Wizard) help you convert permanent Microsoft Entra role assignments to just-in-time assignments with Privileged Identity Management.
Learn how to configure security alerts for Azure resource roles in Privileged
Configure security alerts for Microsoft Entra roles Privileged Identity Management.
The following documentation provides guidance for Privileged Identity Management (PIM) PowerShell migration.
Learn how to approve or deny requests for Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to approve or deny requests for Azure resource roles in Privileged
Learn how to assign Azure resource roles in Privileged Identity Management (PIM).
Learn how to bring groups into Privileged Identity Management.
Learn how to complete an access review of Azure resource and Microsoft Entra roles Privileged Identity Management.
Learn how to configure Azure resource role settings in Privileged Identity Management (PIM).
Learn how to configure PIM for Groups settings.
Learn how to create an access review of Azure resource and Microsoft Entra roles in Privileged Identity Management (PIM).
Learn how to discover Azure resources to manage in Privileged Identity Management (PIM).
Learn how to extend or renew PIM for groups assignments.
Learn how to review access of Azure resource and Microsoft Entra roles
Learn how to extend or renew Azure resource role assignments in Privileged Identity Management (PIM).
Learn how to extend or renew Microsoft Entra role assignments in Microsoft Entra Privileged Identity Management (PIM)
Start using PIM
UpdatedLearn how to enable and get started using Privileged Identity Management (PIM) in the Microsoft Entra admin center.
Learn how to use Azure custom roles in Microsoft Entra Privileged Identity Management (PIM).
Learn how to view the audit log history for Microsoft Entra roles in
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
Learn how to activate your group membership or ownership in Privileged
Describes the roles you can't manage in Microsoft Entra Privileged Identity
How to manage Microsoft Entra Privileged Identity Management (PIM) for Groups.
Describes how to use a resource dashboard to perform an access review
Provides an overview of Microsoft Entra Privileged Identity Management (PIM).
Information for understanding the APIs in Microsoft Entra Privileged
Microsoft Entra Verified ID
2 updatesA design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Microsoft Entra Global Secure Access
3 updates```powershell
Enable Multi Geo
Updatedauthor: HULKsmashGithub
Powershell Samples
UpdatedUse these PowerShell samples for Global Secure Access.
