Instructions for IT admins to create new users, invite external guests, and delete existing users in Microsoft Entra ID.
9 May 2026: one new user-management guide, plus sharper hybrid-recovery, CMMC, and agent-identity guidance
This was a documentation-led day: one new Microsoft Learn page and 49 updates, with no removals or Message Center notices. The new page covers creating users, inviting external guests, and deleting users; the strongest updates clarify operational, compliance, and security guidance rather than announce a feature launch, preview, GA release, retirement, or product behavior change.
- New Entra ID guide covers core user lifecycle tasks
Entra ID · Fundamentals
Microsoft added a new fundamentals page for IT administrators covering how to create users, invite external guests, and delete existing users. This is a documentation addition; the supplied record does not show a new lifecycle capability or altered deletion policy.
- PTA guidance emphasizes a cloud-only administrative fallback
Entra ID · Fundamentals
The updated Connect PTA quick start instructs administrators to create a cloud-only Hybrid Identity Administrator account so they can manage the tenant if on-premises services fail or become unavailable. It describes the step as critical to preventing tenant lockout, making this an operational guidance clarification rather than a change to PTA behavior.
- CMMC Level 2 documentation states how Entra handles identifier reuse
Entra ID · Authentication
The updated CMMC Level 2 identification and authentication page addresses IA.L2-3.5.5 by stating that user, group, and device object GUIDs are guaranteed to be unique and non-reusable for the lifetime of the Microsoft Entra tenant. This clarifies documented platform behavior for compliance mapping; it does not announce a new control.
- Agent ID guidance assigns ownership responsibility
Agent ID · Fundamentals
The updated Agent ID security overview calls for sponsors and owners to be assigned and maintained for each agent identity to prevent orphaned identities. Teams using Agent ID should include those assignments in identity-lifecycle ownership checks; the supplied evidence provides no availability or rollout details.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
50 updates
Microsoft Entra ID
36 updatesEntra Admin Center
Updated| Task | Description | Learn more |
Users Restore
UpdatedYou can permanently delete a user from your organization without waiting the 30 days for automatic deletion. A permanently deleted user can't be restored by anyone, including Microsoft customer support.
Add Custom Domain
Updated- [How to assign roles and administrators](./how-subscriptions-associated-directory.md)
Connect Pta Quick Start
Updated1. Create a cloud-only Hybrid Identity Administrator account or a Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.
Create New Tenant
Updated- To change or add other domain names, see [How to add a custom domain name to Microsoft Entra ID](add-custom-domain.md).
Delegate By Task
UpdatedHere are the least privileged roles you should use when performing tasks for [users](../../fundamentals/how-to-create-delete-users.md) in Microsoft Entra ID.
See [How to create, invite, and delete users](../../fundamentals/how-to-create-delete-users.md).
Manage User Profile Info
Updated- [Add or delete users](how-to-create-delete-users.md)
- [Synchronize users in multitenant organizations in Microsoft 365](/microsoft-365/enterprise/sync-users-multi-tenant-orgs)
Prerequisites
Updated1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant if your on-premises services fail or become unavailable. Learn about how to [add a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Finishing this step is critical to ensure that you don't get locked out of your tenant.
Tutorial Existing Forest
Updated1. Create a cloud-only Hybrid Identity Administrator account on your Microsoft Entra tenant. This way, you can manage the configuration of your tenant should your on-premises services fail or become unavailable. Learn about [adding a cloud-only Hybrid Identity Administrator account](~/fundamentals/how-to-create-delete-users.md). Completing this step is critical to ensure that you don't get locked out of your tenant.
Users Default Permissions
Updated* To learn more about how to assign Microsoft Entra administrator roles, see [Assign a user to administrator roles in Microsoft Entra ID](./how-subscriptions-associated-directory.md).
Migrate Adfs Apps Stages
UpdatedDuring the process of moving your app authentication to Microsoft Entra ID, test your apps and configuration. We recommend that you continue to use existing test environments for migration testing before you move to the production environment. If a test environment isn't currently available, you can set one up using [Azure App Service](https://azure.microsoft.com/services/app-service/) or [Azure Virtual Machines](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn), depending on the architecture of the application.
| IA.L2-3.5.5<br><br>**Practice statement:** Prevent reuse of identifiers for a defined period.<br><br>**Objectives:**<br>Determine if:<br>[a.] a period within which identifiers can't be reused is defined; and<br>[b.] reuse of identifiers is prevented within the defined period. | All user, group, device object globally unique identifiers (GUIDs) are guaranteed unique and non-reusable for the lifetime of the Microsoft Entra tenant.<br>[user resource type - Microsoft Graph v1.0](/graph/api/resources/user?view=graph-rest-1.0&preserve-view=true)<br>[group resource type - Microsoft Graph v1.0](/graph/api/resources/group?view=graph-rest-1.0&preserve-view=true)<br>[device resource type - Microsoft Graph v1.0](/graph/api/resources/device?view=graph-rest-1.0&preserve-view=true) |
Quickstart Analyze Sign In
Updated- An Azure subscription. If you don't have one, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
Sspr Deploy
UpdatedTo ensure that your deployment works as expected, plan a set of test cases to validate the implementation. To assess the test cases, you need a non-administrator test user with a password. If you need to create a user, see [Add new users to Microsoft Entra ID](~/fundamentals/how-to-create-delete-users.md).
* If needed, [create one for free](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn).
Tutorial Enable Sspr
Updated* A working Microsoft Entra tenant with at least a Microsoft Entra ID P1 license is required for password reset. For more information about license requirements for password change and password reset in Microsoft Entra ID, see [Licensing requirements for Microsoft Entra self-service password reset](concept-sspr-licensing.md).
- [Add or delete users](./how-to-create-delete-users.md)
Ensure the following prerequisites are met:
Datawiza Sso Oracle Jde
UpdatedEnsure the following prerequisites are met.
Ensure the following prerequisites are met.
Tutorial Basic Ad Azure
UpdatedThe following are prerequisites required for completing this tutorial
Users Search Enhanced
Updated**User operations**
Fedramp Access Controls
Updated| FedRAMP Control ID and description | Microsoft Entra guidance and recommendations |
Hipaa Access Controls
Updated| Recommendation | Action |
Plan Conditional Access
Updated- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)
Tutorial Enable Azure Mfa
Updated* An account with at least the [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role. Some MFA settings can also be managed by an [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator).
Entra Agents
Updated- You must have available [security compute units (SCU)](/copilot/security/manage-usage).
Get Started Premium
UpdatedNow that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.yml) and [users](./how-to-create-delete-users.md).
To complete the scenario in this quickstart, you need:
Add GitHub Enterprise Managed User (OIDC) from the Microsoft Entra application gallery to start managing provisioning to GitHub Enterprise Managed User (OIDC). If you have previously setup GitHub Enterprise Managed User (OIDC) for SSO, you can use the same application. However it's recommended that you create a separate app when testing out the integration initially. Learn more about adding an application from the gallery [here](~/identity/enterprise-apps/add-application-portal.md).
Microsoft Entra Agent ID
1 updateSecurity For Ai Overview
Updated- Ensure sponsors and owners are assigned and maintained for each agent identity, preventing orphaned agent identities.
Microsoft Entra ID Protection
2 updatesDeploy Identity Protection
Updated* Create or modify Conditional Access policies
- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)
Microsoft Entra ID Governance
3 updatesMigrate From Sap Idm
UpdatedIn SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.
1. Browse to **ID Governance** > **Entitlement management** > **Access packages**.
Identity Governance Overview
UpdatedMicrosoft Entra ID Governance enables you to balance your organization's need for security and end user productivity with the right processes and visibility.
Microsoft Entra External ID
5 updatesUser Permissions
UpdatedTo better understand the typical use cases for users in an external tenant, we can categorize them as follows:
In this quickstart, you'll learn how to add a new guest user to your Microsoft Entra directory in the Microsoft Entra admin center. You'll also send an invitation and see what the guest user's invitation redemption process looks like.
An external user can self-register in the External ID tenant by using the sign-up and sign-in user flow. When the user selects the federated Microsoft Entra ID identity provider on the sign-in page and authenticates with their organizational account, a user account is automatically created in the external tenant. For more information, see [Create a sign-up and sign-in user flow for customers](how-to-user-flow-sign-up-sign-in-customers.md).
Manage Admin Accounts
UpdatedUse the following steps to create a new user account and to grant admin permissions to the account by adding a Microsoft Entra role. (Only required steps are described here. For a complete description of all properties, see the Microsoft Entra ID article [How to create users](~/fundamentals/how-to-create-delete-users.md#create-a-new-user).)
- If you're already using Microsoft Entra cross-tenant synchronization, for various [multi-hub multi-spoke topologies](cross-tenant-synchronization-topology.md), you don't need to use the Microsoft 365 admin center share users functionality. Instead, you might want to continue using your existing Microsoft Entra cross-tenant synchronization jobs.
Microsoft Entra Verified ID
1 update1. [Create a new user](../fundamentals/how-to-create-delete-users.md#create-a-new-user) to use in your testing.
Microsoft Entra Workload ID
2 updatesWorkload identities
UpdatedUnderstand the concepts and supported scenarios for using workload identity in Microsoft Entra.
Before you begin, ensure you have the following:
