During account recovery, a user who has lost all authentication methods must re-establish their identity. The custom authentication extension adds a claim validation step into this flow:
Federation validation tightening and Verified ID key retirement are the main 8 May watch items
This was primarily an update and clarification day rather than a broad product launch. The most consequential changes are a planned stricter federated sign-in default for affected External ID tenants, the 1 July 2026 retirement of non-FIPS Verified ID signing keys, and a 21 May backend transition for an early-access Entra Group control. Other notable updates clarify preview behavior and passkey compatibility.
- External ID: stricter federated sign-in validation is scheduled for mid-August
External ID · Conditional Access
Microsoft Entra will apply stricter federatedTokenValidationPolicy defaults starting in mid-August 2026. For tenants with federated domains configured before December 2025, federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. This is a planned security-related default-behavior change; review affected federation configurations before enforcement.
- Verified ID: non-FIPS P-256K signing keys retire on 1 July 2026
Verified ID · General
The updated Verified ID What's New entry says non-FIPS-compliant P-256K signing keys will be retired on 1 July 2026. Administrators are directed to upgrade their signing keys to become FIPS compliant, making this a concrete migration deadline rather than ordinary documentation maintenance.
For tenants that activated early access to the Entra Group control for model-driven app in-app skills in Power Apps or Dynamics 365 Apps, Microsoft says the feature will switch to a new underlying service on 21 May 2026 in preparation for general availability. The notice describes a service transition, not a general-availability announcement.
- Global Secure Access Explicit Forward Proxy preview documentation clarifies its Entra-based session model
Global Secure Access · Conditional Access
The updated guidance says Explicit Forward Proxy uses Microsoft Entra authentication and authorization before allowing network traffic, enabling Conditional Access, passkeys, and Continuous Access Evaluation with session revocation. Basic, digest, NTLM, and Kerberos proxy authorization methods are not supported. This is a preview behavior and configuration clarification, not evidence of a new GA release.
- Entra ID FIDO2 compatibility guidance sets a Google Play Services requirement for passkeys
Entra ID · Authentication
The compatibility update states that passkey sign-in requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication. Teams planning or troubleshooting passkey sign-in should account for this client compatibility requirement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
10 updates
Microsoft Entra ID
4 updatesFido2 Compatibility
Updated- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.
Customize Branding
Updated:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::
Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.
Microsoft Entra Agent ID
1 updateLicensing Agent Id
Updated- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.
Microsoft Entra ID Governance
1 updateLearn how to view, add, and remove assignments for an access package in entitlement management.
Microsoft Entra Verified ID
2 updatesWhats New
Updated- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.
Learn how to set up and use Face Check with Microsoft Entra Verified ID for high-assurance facial matching verifications that protect user privacy at enterprise scale.
Microsoft Entra Global Secure Access
2 updatesExplicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
Explicit Forward Proxy
UpdatedDuring the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.
