← Previous day

Next day →
Day in brief

Cross-tenant group synchronization leads the day; Entra guidance adds important recovery and authentication detail

23 April was primarily a documentation-update period, with no new or removed items in the supplied set. The clearest product announcement is Microsoft Entra ID Governance’s cross-tenant security group synchronization, which is described as being in public preview with general availability planned by the end of May 2026. Other notable items are updated capability documentation for backup and recovery and more specific Authenticator Lite guidance; the remaining edits are largely procedural or reference clarifications.

  • A Message Center notice announces cross-tenant security group synchronization to centralize group management across tenants. It places the public preview start in late January 2026 and forecasts general availability by the end of May 2026. Administrators can enable synchronization by updating attribute mappings and access policies; the notice is a rollout timeline, not confirmation that GA has already occurred.

  • The updated Agent ID What's New documentation describes Microsoft Entra Backup and Recovery as built in and always on by default, with automatic backups of critical directory objects including agent IDs, users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and authentication and authorization policy. Because the evidence is an updated Learn page, it should be read as capability documentation rather than a separate launch or configuration-change notice.

  • Updated Entra ID guidance says organizations need to enable Authenticator second-factor push notifications for all users or selected groups, preferably through the modern Authentication methods policy. It also states that Authenticator Lite is not eligible for on-premises user accounts or organizations with an active MFA Server. Administrators planning to use Lite should validate policy scope and these exclusions.

  • The updated Conditional Access: Authentication transfer page covers supported applications, the desktop-to-mobile end-user experience, limitations, and troubleshooting. The entry remains explicitly labeled as a preview, and the supplied evidence does not indicate a new availability milestone or behavior change; teams evaluating the capability should use the documented constraints when assessing it.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

13 updates

5

Microsoft Entra: Passkeys in registration campaigns update

New

Microsoft Entra will continue supporting Passkeys (FIDO2) in Enabled and Microsoft-managed states for Registration Campaigns, rolling out worldwide from mid-May to late June 2026. Eligible tenants will see automatic updates to campaign settings and passkey registration nudges after MFA, with no immediate action required.

Message CenterMC1279092 on mc.merill.net ↗Stay informed

Mfa Authenticator Lite

Updated

- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.

1
1
1
1

Whats New

Updated

Microsoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.

1

Identity Governance Applications Existing Users

Updated

Now that you have provided the connectivity details and matching attribute as part of your provisioning configuration, Microsoft Entra can discover the existing users in your application. Click on the [discover identities](~/identity/app-provisioning/how-to-account-discovery.md) button in the provisioning overview page. Once the report is generated, you will have a view of all the users in your application, which users in the application match with a Microsoft Entra ID user, which users are already assigned to the enterprise application in Microsoft Entra ID, and which users in the application are not matched with a Microsoft Entra ID user).

1

Entitlement Management Access Package Create App

Updated

1. If your scenario requires the ability to override a separation of duties check, then you can also [set up additional access packages for those override scenarios](entitlement-management-access-package-incompatible.md#configuring-multiple-access-packages-for-override-scenarios).

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…