← Previous day

Next day →
Day in brief

June 2026: App Instance Lock becomes the default for new apps; Dataverse Agent users enter public preview

The period’s consequential changes are a planned Microsoft Entra behavior change and a staged Agent ID preview. Starting in June 2026, App Instance Lock will be enabled by default for new applications, while Dataverse Agent users are rolling out as a public preview. The other useful updates are documentation clarifications: Recoverability Overview now points to Microsoft Graph export of many Entra configurations, and Lifecycle Workflow Tasks documents customizable task names and descriptions.

  • Microsoft Entra will enable App Instance Lock by default for new applications starting in June 2026. The lock is intended to protect sensitive properties from unauthorized changes outside the home tenant. Existing applications are unaffected, administrators can disable the lock if necessary, and automation or scripts should be reviewed before rollout.

  • Agent ID · Microsoft identity platform
    Dataverse Agent users enter public preview

    Microsoft is introducing Dataverse Agent users, powered by Microsoft Entra Agent ID, as a new feature in public preview. Rollout began on 4 May 2026 and is expected to reach North America by 22 May 2026; this is a preview rollout rather than a general-availability announcement.

  • The Recoverability Overview documentation now states that Microsoft Graph APIs can export the current state of many Microsoft Entra configurations. This is documentation guidance; the update does not by itself establish a new export feature or recovery service.

  • The Lifecycle Workflow Tasks documentation states that the task that automates user-attribute updates can have its name and description customized in the Microsoft Entra admin center. This is a documentation clarification, with no new rollout or availability change stated.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

5 updates

1

Recoverability Overview

Updated

- [Microsoft Graph APIs](/graph/overview) can be used to export the current state of many Microsoft Entra configurations.

1

Users Default Permissions

Updated

| Users and contacts | <ul><li>Enumerate the list of all users and contacts<li>Read all public properties of users and contacts</li><li>Invite guests<li>Change their own password<li>Manage their own mobile phone number<li>Manage their own photo<li>Invalidate their own refresh tokens</li></ul> | <ul><li>Read their own properties<li>Read display name, email, sign-in name, photo, user principal name, and user type properties of other users and contacts<li>Change their own password<li>Search for another user by object ID (if allowed)<li>Read manager and direct report information of other users</li></ul> | <ul><li>Read their own properties<li>Change their own password</li><li>Manage their own mobile phone number</li></ul> |

1
1

Lifecycle Workflow Tasks

Updated

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

1

Managed Identities Status

Updated

| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…