author: MicrosoftGuyJFlo
External ID MFA regional opt-in clarification leads an otherwise documentation-only day
On 18 April 2026, all 20 recorded changes were Microsoft Learn documentation updates: there were no new items, removals, or Message Center notices. The most consequential update is preview guidance that some regions require country codes to be enabled for SMS telephony verification in Microsoft Entra External ID external tenants. Other meaningful edits clarify Agent ID setup sequencing, ID Governance relationship behavior, and Global Secure Access cloud-firewall configuration. The remaining updates are primarily routine External ID how-to documentation for federation, social sign-in, B2B collaboration, claims, API connectors, attributes, and administration; the evidence does not support treating them as launches or general-availability changes.
- Preview: regional opt-in for External ID MFA telephony verification
External ID · Authentication
The updated guidance says some regions require administrators to enable country codes before external tenants can receive SMS telephony verification. This is a configuration and security prerequisite for affected regions, not evidence of a new generally available capability.
The Agent ID AI-guided setup guidance states that the blueprint principal must be created as a separate step after the blueprint. Teams using automation or runbooks should account for that ordering; the supplied evidence supports a procedure clarification, not a product launch.
- Default policy behavior for automatic governance relationships is clarified
ID Governance · Governance
The ID Governance guidance explains that, when a default governance policy template is defined, creating an add-on governed tenant forms a relationship with the home governing tenant and applies that default template. Administrators should verify that the default policy reflects their intended cross-tenant governance behavior.
- Global Secure Access cloud-firewall guidance covers Remote Networks for Internet Access
Internet Access · Security
The updated Internet Access documentation describes configuring cloud firewall to protect branch-office internet access through Remote Networks. This is security configuration guidance for deployments using that topology; the evidence does not establish new availability or changed enforcement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
20 updates
Microsoft Entra ID
2 updatesAccount Discovery
Updated- Atlassian Cloud
Microsoft Entra Agent ID
2 updatesCreate Blueprint
Updated$response = Invoke-MgGraphRequest `
Agent Id Ai Guided Setup
UpdatedThe blueprint principal must be created as a separate step after the blueprint. Run:
Microsoft Entra ID Governance
1 updateIf you defined a default [governance policy template](governance-policy-templates.md), a new governance relationship forms between the home (governing) tenant and the newly created add-on (governed) tenant, using the default policy template.
Microsoft Entra External ID
13 updatesTo protect customers, some regions require you to enable the country codes to receive SMS telephony verification for Microsoft Entra External ID external tenants.
Add MSA for customer sign-in
UpdatedLearn how to add MSA as an identity provider for your external tenant.
In this quickstart, you learn how to use PowerShell to send an invitation to a Microsoft Entra B2B collaboration user. You'll use the Microsoft Graph Identity Sign-ins and the Microsoft Graph Users PowerShell modules.
Learn how to add Apple as an identity provider for your external tenant.
Federate with Facebook to enable external users (guests) to sign in to your Microsoft Entra apps with their own Facebook accounts.
Add custom attributes
UpdatedLearn how to add custom attributes to self-service sign-up flows in Microsoft Entra External ID. Extend the set of attributes stored on a guest account and customize the user experience.
Learn how to add and manage admin accounts in your external tenant with Microsoft Entra External ID.
Set up AD FS federation
UpdatedLearn how to set up SAML/WS-Fed IdP federation with AD FS for B2B collaboration in Microsoft Entra External ID. Configure AD FS as a SAML 2.0 or WS-Fed IdP and manage attributes and claims.
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Learn how to define application roles for your consumer and business customer applications and assign those roles to users and groups in external tenants.
Use Microsoft Entra API connectors to customize and extend your self-service sign-up user flows by using web APIs.
Learn how to reset the redemption status for a guest user in Microsoft Entra External ID. This guide covers using the admin center, PowerShell, and Microsoft Graph API.
If you have internal user accounts for partners, distributors, suppliers, vendors, and other guests, you can move to Microsoft Entra B2B collaboration by inviting them to sign in with their own external credentials. Use either PowerShell or the Microsoft Graph invitation API.
Microsoft Entra Internet Access
1 updateLearn how to configure and use cloud firewall to protect against unauthorized internet access from branch offices using Remote Networks for Internet Access.
Install Android Client
Updated- The product requires licensing. For details, see the licensing section of [What is Global Secure Access](overview-what-is-global-secure-access.md). If needed, [purchase licenses or get trial licenses](https://aka.ms/azureadlicense).
