Day in brief

Federation validation tightening and Verified ID key retirement are the main 8 May watch items

This was primarily an update and clarification day rather than a broad product launch. The most consequential changes are a planned stricter federated sign-in default for affected External ID tenants, the 1 July 2026 retirement of non-FIPS Verified ID signing keys, and a 21 May backend transition for an early-access Entra Group control. Other notable updates clarify preview behavior and passkey compatibility.

  • Microsoft Entra will apply stricter federatedTokenValidationPolicy defaults starting in mid-August 2026. For tenants with federated domains configured before December 2025, federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. This is a planned security-related default-behavior change; review affected federation configurations before enforcement.

  • The updated Verified ID What's New entry says non-FIPS-compliant P-256K signing keys will be retired on 1 July 2026. Administrators are directed to upgrade their signing keys to become FIPS compliant, making this a concrete migration deadline rather than ordinary documentation maintenance.

  • For tenants that activated early access to the Entra Group control for model-driven app in-app skills in Power Apps or Dynamics 365 Apps, Microsoft says the feature will switch to a new underlying service on 21 May 2026 in preparation for general availability. The notice describes a service transition, not a general-availability announcement.

  • The updated guidance says Explicit Forward Proxy uses Microsoft Entra authentication and authorization before allowing network traffic, enabling Conditional Access, passkeys, and Continuous Access Evaluation with session revocation. Basic, digest, NTLM, and Kerberos proxy authorization methods are not supported. This is a preview behavior and configuration clarification, not evidence of a new GA release.

  • The compatibility update states that passkey sign-in requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication. Teams planning or troubleshooting passkey sign-in should account for this client compatibility requirement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

3

Fido2 Compatibility

Updated

- Sign-in with passkey requires Google Play Services 21 or later because Microsoft Entra ID requires user verification for multifactor authentication.

Customize Branding

Updated

:::image type="content" source="media/how-to-customize-branding/sign-in-page-map.png" alt-text="Screenshot of the sign-in page, with each of the company branding elements highlighted." lightbox="media/how-to-customize-branding/sign-in-page-map-expanded.png":::

1

Connect To Cloud Sync Decision Guide

Updated

Cloud Sync natively supports synchronization from multiple disconnected Active Directory forests. These scenarios are commonly required during mergers, acquisitions, or complex organizational structures. Unlike Connect sync, which requires complicated configurations or multiple instances for disconnected forests, Cloud Sync handles these scenarios through its multitenant architecture.

1

Licensing Agent Id

Updated

- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.

1
1

Whats New

Updated

- **Non-FIPS compliant signing keys (P-256K) retirement**: Non-FIPS compliant signing keys (P-256K) will be retired on July 1, 2026. If you haven't already, [upgrade your signing keys](signing-key-upgrade.md) to become FIPS compliant.

1
1

Explicit Forward Proxy (preview) session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

1

Explicit Forward Proxy

Updated

During the session lifetime, Explicit Forward Proxy attempts to revalidate the user at regular intervals by using single sign-on. If validation is successful, Explicit Forward Proxy extends the user's cache entry by the lifetime of the new access token.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…