All accounts that sign in to perform operations cited in the [applications section](#application-ids-and-urls) must complete MFA when the enforcement begins. Users aren't required to use MFA if they access other applications, websites, or services hosted on Azure. Each application, website, or service owner listed earlier controls the authentication requirements for users.
24 April: Passkey registration campaigns are headed for an automatic mid-May–June rollout; most other changes clarify existing guidance
This was a documentation-heavy period: 55 Microsoft Learn pages were updated, with no new or removed items, alongside one Microsoft 365 Message Center notice. The consequential product update is that Microsoft Entra will continue supporting Passkeys (FIDO2) in Registration Campaigns’ Enabled and Microsoft-managed states. Eligible tenants will receive automatic campaign-setting updates and post-MFA registration nudges worldwide from mid-May through late June 2026, and the notice says no immediate action is required. The remaining notable items are documentation clarifications covering Workday termination timing, PIM workflows and preview tooling, and emergency-access security guidance. Nothing in the supplied records establishes a new general-availability launch or retirement.
- Registration Campaigns: passkey support continues with automatic tenant updates
Entra ID · Authentication
The Message Center update is a rollout and behavior notice, not a new passkey launch. Microsoft Entra will continue supporting Passkeys (FIDO2) in the Enabled and Microsoft-managed Registration Campaign states. Eligible tenants will receive automatic campaign-setting updates and passkey-registration nudges after MFA during the worldwide mid-May–late June 2026 rollout. No immediate administrator action is required.
- Workday provisioning: termination lookahead guidance exposes a Pacific Time dependency
Entra ID · Provisioning
The updated Workday connector guidance explains that the Integration System User retrieves worker data through the Get_Workers SOAP API but always operates in Pacific Time. This can delay termination-event processing for workers in time zones ahead of Pacific Time. This is an operational-behavior clarification rather than evidence of a new connector capability; time-sensitive offboarding plans should account for the documented lag.
- PIM role approvals: delegated requests expire after 24 hours
ID Governance · Governance
The updated Microsoft Entra role-approval guidance states that PIM can require approval and use one or more users or groups as delegated approvers. Approvers have 24 hours to act; an unapproved request must be submitted again, and the 24-hour window cannot be configured. This is a workflow clarification, not a newly announced capability.
- PIM Discovery and insights remains a preview action tool
ID Governance · Governance
The updated Discovery and insights page, formerly Security Wizard, describes a preview capability that analyzes privileged Microsoft Entra role assignments and lets administrators view or change permanent assignments to just-in-time assignments. The record confirms preview status and the documented actions; it does not establish general availability.
- Emergency-access guidance points to passwordless authentication
Entra ID · Authentication
The updated Security Emergency Access guidance instructs administrators to configure emergency access accounts to use passwordless authentication. This is security guidance in an updated document, not evidence of a new enforcement change or feature rollout; account configuration should be reviewed against the guidance.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
55 updates
Microsoft Entra ID
18 updates- [Choosing authentication methods for your organization](concept-authentication-methods.md)
Security Emergency Access
Updated1. [Configure your emergency access accounts](#configuration-requirements) to use passwordless authentication.
Fido2 Hardware Vendor
UpdatedIn the Microsoft Entra ID authentication methods policy, administrators can enforce attestation for FIDO2 security keys. When **Enforce attestation** is set to **Yes**, Microsoft requires extra metadata from passkeys (FIDO2) that are registered with the tenant. As a vendor, your passkey (FIDO2) is usable when attestation is enforced if the following requirements are met.
- Users are **3x more successful signing-in with synced passkey than legacy authentication methods (95% vs 30%)**
Whats New Ignite 2025
Updated- [Account recovery cost savings estimator](../identity/authentication/how-to-account-recovery-cost-savings-estimator.md) (New)
SMS-based authentication is available to Microsoft apps integrated with the Microsoft identity platform (Microsoft Entra ID). This article lists the web and mobile apps that support SMS-based authentication.
To simplify and secure sign-in to applications and services, Microsoft Entra ID provides SMS-based authentication. This method lets users such as frontline workers sign in using only a registered phone number and a one-time passcode (OTP) sent via SMS, without needing a username or password.
Whats New
Updated**Service category:** Authentications (Logins)
- [Enable passkeys (FIDO2) for your organization](how-to-authentication-passkeys-fido2.md)
| Windows Server 2019 | Microsoft Edge, [Chrome](#chrome-support) |
- You must have at least the [Microsoft Entra ID P1](../identity/conditional-access/overview.md#license-requirements) license.
Whats New Archive
Updated**Product capability:** Identity Security & Protection
- User Administrator
The Microsoft Entra Workday provisioning connector retrieves worker data using the Workday Integration System User (ISU) account via the `Get_Workers` SOAP API. However, the Workday ISU account always operates in the Pacific Time Zone (PT), causing delays in processing termination events for workers in time zones ahead of PT.
author: garrodonnell
Microsoft Entra ID Protection
1 updateIdentity Protection Risks
Updated| Sign-in risk detection | Detection type | Type | riskEventType |
Microsoft Entra ID Governance
34 updatesIf you're starting out using Privileged Identity Management (PIM) in Microsoft Entra ID to manage role assignments in your organization, you can use the **Discovery and insights (preview)** page to get started. This feature shows you who is assigned to privileged roles in your organization and how to use PIM to quickly change permanent role assignments into just-in-time assignments. You can view or make changes to your permanent privileged role assignments in **Discovery and insights (preview)**. It's an analysis tool and an action tool.
Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Alerts page.
Privileged Identity Management (PIM) generates alerts when there's suspicious or unsafe activity in your organization in Microsoft Entra ID. When an alert is triggered, it shows up on the Privileged Identity Management dashboard. Select the alert to see a report that lists the users or roles that triggered the alert.
The need for access to privileged Azure resource and Microsoft Entra roles by your users changes over time. To reduce the risk associated with stale role assignments, you should regularly review access. You can use Microsoft Entra Privileged Identity Management (PIM) to create access reviews for privileged access to Azure resource and Microsoft Entra roles. You can also configure recurring access reviews that occur automatically. This article describes how to create one or more access reviews.
The following table provides guidance on using the new PowerShell cmdlets in the newer Azure PowerShell module.
**Privileged Identity Management (PIM)** provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune.
You can use Privileged Identity Management (PIM) in Microsoft Entra ID to have just-in-time membership in the group or just-in-time ownership of the group.
With Privileged Identity Management (PIM) and Microsoft Entra ID, you can configure activation of group membership and ownership to require approval. You can also choose users or groups from your Microsoft Entra organization as delegated approvers.
Microsoft Entra Privileged Identity Management (PIM) enables you to configure roles so that they require approval for activation, and choose users or groups from your Microsoft Entra organization as delegated approvers. Select two or more approvers for each role to reduce workload for the Privileged Role Administrator. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must resubmit a new request. The 24-hour approval time window isn't configurable.
Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure roles to require approval for activation, and choose one or multiple users or groups as delegated approvers. Delegated approvers have 24 hours to approve requests. If a request isn't approved within 24 hours, then the eligible user must re-submit a new request. The 24-hour approval time window isn't configurable.
With Microsoft Entra Privileged Identity Management (PIM), you can manage the built-in Azure resource roles, and custom roles, including (but not limited to):
In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group.
With Microsoft Entra ID, a Global Administrator can make **permanent** Microsoft Entra admin role assignments. These role assignments can be created using the [Microsoft Entra admin center](~/identity/role-based-access-control/permissions-reference.md) or using [PowerShell commands](/powershell/module/azuread/#directory_roles).
When working with your organization's groups in Privileged Identity Management (PIM), you can view activity, activations, and audit history for Microsoft Entra group membership or ownership changes.
In Microsoft Entra ID, you can use Privileged Identity Management (PIM) to manage just-in-time membership in the group or just-in-time ownership of the group. Use groups to provide access to Microsoft Entra roles, Azure roles, and various other scenarios. To manage a Microsoft Entra group in PIM, you must bring it under management in PIM.
Privileged Role Administrators can review privileged access once an [access review starts](./pim-create-roles-and-resource-roles-review.md). Privileged Identity Management (PIM) in Microsoft Entra ID automatically sends an email that prompts users to review their access. If a user doesn't receive an email, you can send them the instructions for [how to perform an access review](./pim-perform-roles-and-resource-roles-review.md).
ai-usage: ai-assisted
ai-usage: ai-assisted
ai-usage: ai-assisted
You can use Privileged Identity Management (PIM) in Microsoft Entra ID, to improve the protection of your Azure resources. This helps:
Email notifications in PIM
UpdatedPrivileged Identity Management (PIM) lets you know when important events occur in your Microsoft Entra organization, such as when a role is assigned or activated. Privileged Identity Management keeps you informed by sending you and other participants email notifications. These emails might also include links to relevant tasks, such as activating or renewing a role. This article describes what these emails look like, when they are sent, and who receives them.
Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for Azure resources. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Microsoft Entra Privileged Identity Management (PIM) provides controls to manage the access and assignment lifecycle for roles in Microsoft Entra ID. Administrators can assign roles using start and end date-time properties. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to Microsoft Entra administrators to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Privileged Identity Management (PIM) in Microsoft Entra ID provides controls to manage the access and assignment lifecycle for group membership and ownership. Administrators can assign start and end date-time properties for group membership and ownership. When the assignment end approaches, Privileged Identity Management sends email notifications to the affected users or groups. It also sends email notifications to administrators of the resource to ensure that appropriate access is maintained. Assignments might be renewed and remain visible in an expired state for up to 30 days, even if access isn't extended.
Privileged Identity Management (PIM) simplifies how enterprises manage privileged access to resources in Microsoft Entra ID, and other Microsoft online services like Microsoft 365 or Microsoft Intune. Follow the steps in this article to perform reviews of access to roles.
Privileged Identity Management (PIM), part of Microsoft Entra, includes three providers:
You can manage just-in-time assignments to all [Microsoft Entra roles](~/identity/role-based-access-control/permissions-reference.md) and all [Azure roles](/azure/role-based-access-control/built-in-roles) using Privileged Identity Management (PIM) in Microsoft Entra ID. Azure roles include built-in and custom roles attached to your management groups, subscriptions, resource groups, and resources. However, there are a few roles that you can't manage. This article describes the roles you can't manage in Privileged Identity Management.
Use Privileged Identity Management (PIM) to manage, control, and monitor access within your Microsoft Entra organization. With PIM you can provide as-needed and just-in-time access to Azure resources, Microsoft Entra resources, and other Microsoft online services like Microsoft 365 or Microsoft Intune.
View activity and audit history for Azure resource roles in Privileged Identity Management (PIM).
You can use the Microsoft Entra Privileged Identity Management (PIM) audit history to see the role assignment changes and activations done through PIM. Data is available for the past 30 days. If you want to retain audit data for longer than the default retention period, you can use Azure Monitor to route it to an Azure storage account. For more information, see [Archive Microsoft Entra logs to an Azure storage account](~/identity/monitoring-health/howto-archive-logs-to-storage-account.md). To see full audit history of Microsoft Entra ID activity including administrator, end user, and synchronization activity, you can use the [Microsoft Entra security and activity reports](~/identity/monitoring-health/overview-monitoring-health.md).
Microsoft Entra ID allows you to grant users just-in-time membership and ownership of groups through Privileged Identity Management (PIM) for Groups. Groups can be used to control access to a variety of scenarios, including Microsoft Entra roles, Azure roles, Azure SQL, Azure Key Vault, Intune, other application roles, and third-party applications.
You can use a resource dashboard to perform an access review in Privileged Identity Management (PIM). The Admin View dashboard in Microsoft Entra ID, part of Microsoft Entra, has three primary components:
Privileged Identity Management (PIM) is a service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune. The following video explains important PIM concepts and features.
If you're experiencing issues with Privileged Identity Management (PIM) in Microsoft Entra ID, the information included in this article can help you resolve these issues.
Microsoft Entra External ID
1 updateTo federate users to your identity provider, first prepare your identity provider to accept federation requests from your external tenant. To do this preparation, add your redirect URIs and register your identity provider to be recognized.
Microsoft Entra Verified ID
1 update- [Face Check with Microsoft Entra Verified ID pricing](~/verified-id/verified-id-pricing.md)
