← Previous day

Next day →
Day in brief

15 May 2026: passkey recovery and Agent ID migration guidance stand out

This was a documentation-heavy Entra update: all 13 supplied items were updates, with no new or removed entries. The most consequential guidance concerns FIDO2 passkeys after UPN changes, the lack of an in-place path from Copilot Studio agents to Agent ID, and Authenticator Lite prerequisites. Other edits primarily clarify authentication behavior and setup instructions rather than announce new availability.

  • Entra ID · Authentication
    UPN changes require passkey replacement

    The updated Entra ID guidance states that an existing FIDO2 passkey can no longer be modified after the user’s UPN changes. The documented recovery path is for the user to open Security info, delete the old passkey, and add a new one. This is an important identity-renaming dependency, but the evidence presents it as documentation of the behavior rather than a new feature or rollout.

  • The updated Agent ID guidance explains how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security, while explicitly stating that no in-place migration path exists today. Administrators should not plan on directly converting existing agents.

  • The Entra ID guidance says the organization must enable Authenticator second-factor push notifications for all users or selected groups, with the modern Authentication methods policy recommended through the admin center or Microsoft Graph. Authenticator Lite is not eligible for on-premises user accounts or organizations with an active MFA server. This is a configuration and eligibility clarification, not evidence of a new availability announcement.

  • The updated fundamentals guidance explains that Entra ID evaluates available authentication methods and prompts users with the most secure sign-in option for both primary authentication and multifactor authentication. The supplied evidence describes how the behavior works but does not indicate that a tenant-wide default changed.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

13 updates

7

Authentication Passkeys Fido2

Updated

If a user's UPN changes, you can no longer modify passkeys (FIDO2) to account for the change. If the user has a passkey (FIDO2), they need to sign in to [Security info](https://mysignins.microsoft.com/security-info), delete the old passkey (FIDO2), and add a new one.

Mfa Authenticator Lite

Updated

- Your organization needs to enable Authenticator (second factor) push notifications for all users or select groups. We recommend that you enable Authenticator by using the modern [Authentication methods policy](concept-authentication-methods-manage.md#authentication-methods-policy). You can edit the Authentication methods policy by using the Microsoft Entra admin center or Microsoft Graph API. Authenticator Lite isn't eligible for on-premises user accounts or organizations with an active MFA server.

Native Authentication

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).

3

Quickstart Register App

Updated

1. Leave **Redirect URI (optional)** alone for now as you configure a redirect URI in the next section.

1
1
1

Migrate Copilot Studio agents to Agent ID

Updated

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…