Microsoft Entra will continue supporting Passkeys (FIDO2) in Enabled and Microsoft-managed states for Registration Campaigns, rolling out worldwide from mid-May to late June 2026. Eligible tenants will see automatic updates to campaign settings and passkey registration nudges after MFA, with no immediate action required.
Cross-tenant group synchronization leads the day; Entra guidance adds important recovery and authentication detail
23 April was primarily a documentation-update period, with no new or removed items in the supplied set. The clearest product announcement is Microsoft Entra ID Governance’s cross-tenant security group synchronization, which is described as being in public preview with general availability planned by the end of May 2026. Other notable items are updated capability documentation for backup and recovery and more specific Authenticator Lite guidance; the remaining edits are largely procedural or reference clarifications.
- ID Governance cross-tenant security group synchronization is in preview, with GA planned
ID Governance · Fundamentals
A Message Center notice announces cross-tenant security group synchronization to centralize group management across tenants. It places the public preview start in late January 2026 and forecasts general availability by the end of May 2026. Administrators can enable synchronization by updating attribute mappings and access policies; the notice is a rollout timeline, not confirmation that GA has already occurred.
- Agent ID documentation describes built-in, always-on backup and recovery
Agent ID · Conditional Access
The updated Agent ID What's New documentation describes Microsoft Entra Backup and Recovery as built in and always on by default, with automatic backups of critical directory objects including agent IDs, users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and authentication and authorization policy. Because the evidence is an updated Learn page, it should be read as capability documentation rather than a separate launch or configuration-change notice.
- Authenticator Lite guidance clarifies prerequisites and unsupported environments
Entra ID · Authentication
Updated Entra ID guidance says organizations need to enable Authenticator second-factor push notifications for all users or selected groups, preferably through the modern Authentication methods policy. It also states that Authenticator Lite is not eligible for on-premises user accounts or organizations with an active MFA Server. Administrators planning to use Lite should validate policy scope and these exclusions.
- Authentication transfer preview documentation clarifies scope and limitations
Entra ID · Conditional Access
The updated Conditional Access: Authentication transfer page covers supported applications, the desktop-to-mobile end-user experience, limitations, and troubleshooting. The entry remains explicitly labeled as a preview, and the supplied evidence does not indicate a new availability milestone or behavior change; teams evaluating the capability should use the documented constraints when assessing it.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
13 updates
Microsoft Entra ID
8 updatesLearn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option.
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled for text message and voice call users |
Mfa Authenticator Lite
Updated- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
Learn how authentication transfer connects users to apps across desktop and mobile devices, including supported apps, end-user experience, limitations, and troubleshooting.
Learn how to configure single sign-on between Microsoft Entra ID and STACKIT Cloud.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forms & Workflow.
Microsoft Entra Agent ID
1 updateWhats New
UpdatedMicrosoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.
Microsoft Entra ID Governance
2 updatesNow that you have provided the connectivity details and matching attribute as part of your provisioning configuration, Microsoft Entra can discover the existing users in your application. Click on the [discover identities](~/identity/app-provisioning/how-to-account-discovery.md) button in the provisioning overview page. Once the report is generated, you will have a view of all the users in your application, which users in the application match with a Microsoft Entra ID user, which users are already assigned to the enterprise application in Microsoft Entra ID, and which users in the application are not matched with a Microsoft Entra ID user).
1. If your scenario requires the ability to override a separation of duties check, then you can also [set up additional access packages for those override scenarios](entitlement-management-access-package-incompatible.md#configuring-multiple-access-packages-for-override-scenarios).
Microsoft Entra External ID
2 updates- Authentication context or step-up authentication.
> [!NOTE]
