If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.
15 May 2026: passkey recovery and Agent ID migration guidance stand out
This was a documentation-heavy Entra update: all 13 supplied items were updates, with no new or removed entries. The most consequential guidance concerns FIDO2 passkeys after UPN changes, the lack of an in-place path from Copilot Studio agents to Agent ID, and Authenticator Lite prerequisites. Other edits primarily clarify authentication behavior and setup instructions rather than announce new availability.
- UPN changes require passkey replacement
Entra ID · Authentication
The updated Entra ID guidance states that an existing FIDO2 passkey can no longer be modified after the user’s UPN changes. The documented recovery path is for the user to open Security info, delete the old passkey, and add a new one. This is an important identity-renaming dependency, but the evidence presents it as documentation of the behavior rather than a new feature or rollout.
- Agent ID migration is recreate-only today
Agent ID · Governance
The updated Agent ID guidance explains how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security, while explicitly stating that no in-place migration path exists today. Administrators should not plan on directly converting existing agents.
- Authenticator Lite prerequisites and exclusions are explicit
Entra ID · Authentication
The Entra ID guidance says the organization must enable Authenticator second-factor push notifications for all users or selected groups, with the modern Authentication methods policy recommended through the admin center or Microsoft Graph. Authenticator Lite is not eligible for on-premises user accounts or organizations with an active MFA server. This is a configuration and eligibility clarification, not evidence of a new availability announcement.
- System-preferred authentication behavior is clarified
Entra ID · Authentication
The updated fundamentals guidance explains that Entra ID evaluates available authentication methods and prompts users with the most secure sign-in option for both primary authentication and multifactor authentication. The supplied evidence describes how the behavior works but does not indicate that a tenant-wide default changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
13 updates
Microsoft Entra ID
11 updatesLearn how system-preferred authentication evaluates methods to prompt users with the most secure sign-in option for both primary and multifactor authentication.
| [Registration campaign](how-to-mfa-registration-campaign.md) | Enabled |
Users who are enabled for external MFA can use it when they sign-in and multifactor authentication is required.
Mfa Authenticator Lite
Updated- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.
Native Authentication
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
Native Authentication Api
UpdatedMicrosoft Entra determines the default MFA method for the user by priority as follows:
Add Redirect Uri
Updatedmanager: pmwongera
Quickstart Register App
Updatedmanager: pmwongera
Quickstart Register App
Updated1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.
Whats New Archive
Updated**Service category:** MFA
Microsoft Entra Agent ID
2 updatesAgent Identity Deletion
Updatedauthor: shlipsey3
Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.
