1. Navigate to the **User Management > User Provisioning** section of your settings.
Entra ID Governance Account Discovery is the day’s substantive rollout signal; most other changes clarify documentation
22 April was primarily a Microsoft Learn maintenance day: 15 documentation updates, no new or removed Learn items, and one Message Center announcement. The consequential product change is Entra ID Governance Account Discovery, which is announced for public preview in mid-April 2026 with general availability beginning in August 2026. The strongest documentation updates clarify ID Protection self-remediation across authentication methods, Microsoft Entra Internet Access content-policy scope, and Entra Connect password-hash synchronization behavior. None of those Learn updates is presented as a separate availability milestone.
- Entra ID Governance Account Discovery: public preview with August GA target
ID Governance · Governance
The Microsoft 365 Message Center says Account Discovery identifies local and orphaned application accounts outside Microsoft Entra ID to improve access visibility and control. Public preview starts in mid-April 2026 and general availability begins in August 2026. The capability is off by default and requires administrator opt-in, with no user impact unless an administrator acts.
- ID Protection documentation clarifies all-method risk self-remediation
ID Protection · Conditional Access
The updated Conditional Access Grant guidance says users whose risk is detected can self-remediate regardless of authentication method. It specifically states that the Microsoft-managed remediation policy accommodates both password-based and passwordless authentication. This is a documentation clarification of the supported remediation flow, not evidence of a separate feature rollout.
- Microsoft Entra Internet Access content-policy guidance details file and label filtering
Internet Access · Security
The updated tutorial describes network content filtering that can block uploads and downloads of selected file types, including .doc, .docx, .pdf, and .zip, when users access web applications. It also documents using Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels. The evidence describes an updated tutorial, not a new availability announcement.
- Entra Connect password-hash synchronization behavior is clarified
Entra ID · Authentication
Updated guidance states that users can continue signing in to cloud services with a synchronized password that has expired in the on-premises environment. The cloud password is updated the next time the user changes the password on-premises. This is a behavior clarification for administrator and support runbooks rather than a reported service change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
16 updates
Microsoft Entra ID
8 updates1. Log into LanSchool Air as Site Admin.
1. Sign in to https://app.kpifire.com with admin rights
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).
Kno2fy Provisioning Tutorial
Updated1. Select **+ New configuration**.
You can continue to sign in to your cloud services by using a synchronized password that is expired in your on-premises environment. Your cloud password is updated the next time you change the password in the on-premises environment.
Whats New
Updated**Service category:** Identity Protection
- onPremisesDistinguishedName
Microsoft Entra ID Protection
2 updatesConditional Access Grant
UpdatedWhen user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation control](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control).
Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Microsoft Entra ID Governance
1 updateMicrosoft Entra introduces cross-tenant security group synchronization to simplify collaboration and centralize group management across tenants. Public preview starts late January 2026; general availability by end of May 2026. Admins can enable sync by updating attribute mappings and access policies. No compliance issues identified.
Microsoft Entra Internet Access
5 updates| Aspect | FQDN filtering | URL filtering |
- **100 = highest priority**: Evaluated first.
*Shadow IT* refers to applications and services that are used by employees without the IT department's knowledge or approval. This use creates risk such as the following examples.
Network content filtering in Microsoft Entra Internet Access allows administrators to use content policies to prevent the transport of specific file types over the network. This feature helps protect sensitive data by blocking uploads and downloads of certain file formats (such as .doc, .docx, .pdf, and .zip) to and from web applications like ChatGPT, Gmail, and file-sharing apps. It can also use Microsoft Purview to scan files and apply network-level policies based on document sensitivity labels.
1. Download the GSA client for Windows 11 from one of the following links. You can also use the [sample PowerShell script](scripts/powershell-windows-client-install-proof-of-concept.md).
