← Previous day

Next day →
Day in brief

Entra ID Governance Account Discovery is the day’s substantive rollout signal; most other changes clarify documentation

22 April was primarily a Microsoft Learn maintenance day: 15 documentation updates, no new or removed Learn items, and one Message Center announcement. The consequential product change is Entra ID Governance Account Discovery, which is announced for public preview in mid-April 2026 with general availability beginning in August 2026. The strongest documentation updates clarify ID Protection self-remediation across authentication methods, Microsoft Entra Internet Access content-policy scope, and Entra Connect password-hash synchronization behavior. None of those Learn updates is presented as a separate availability milestone.

  • The Microsoft 365 Message Center says Account Discovery identifies local and orphaned application accounts outside Microsoft Entra ID to improve access visibility and control. Public preview starts in mid-April 2026 and general availability begins in August 2026. The capability is off by default and requires administrator opt-in, with no user impact unless an administrator acts.

  • The updated Conditional Access Grant guidance says users whose risk is detected can self-remediate regardless of authentication method. It specifically states that the Microsoft-managed remediation policy accommodates both password-based and passwordless authentication. This is a documentation clarification of the supported remediation flow, not evidence of a separate feature rollout.

  • The updated tutorial describes network content filtering that can block uploads and downloads of selected file types, including .doc, .docx, .pdf, and .zip, when users access web applications. It also documents using Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels. The evidence describes an updated tutorial, not a new availability announcement.

  • Updated guidance states that users can continue signing in to cloud services with a synchronized password that has expired in the on-premises environment. The cloud password is updated the next time the user changes the password on-premises. This is a behavior clarification for administrator and support runbooks rather than a reported service change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

16 updates

5

Kpn Grip Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

1

Connect Password Hash Synchronization

Updated

You can continue to sign in to your cloud services by using a synchronized password that is expired in your on-premises environment. Your cloud password is updated the next time you change the password in the on-premises environment.

1

Whats New

Updated

**Service category:** Identity Protection

1
1

Conditional Access Grant

Updated

When user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation control](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control).

1
1

Microsoft Entra: Cross-tenant security group synchronization

New

Microsoft Entra introduces cross-tenant security group synchronization to simplify collaboration and centralize group management across tenants. Public preview starts late January 2026; general availability by end of May 2026. Admins can enable sync by updating attribute mappings and access policies. No compliance issues identified.

Message CenterMC1198077 on mc.merill.net ↗Stay informed
2
2

Tutorial Internet Access Application Discovery

Updated

*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.

Tutorial: Configure content policies

Updated

Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…