Learn how to migrate from custom controls to external multifactor authentication in Microsoft Entra Conditional Access.
20 May 2026: Conditional Access migration guidance leads a documentation-focused Entra update
The clearest administrator-relevant change is the updated Microsoft Entra ID page on migrating from custom controls to external MFA, paired with an update to the page explaining custom controls. That pairing is useful for tenants already using the capability, but the supplied evidence does not announce deprecation, a retirement date, changed enforcement behavior, or a required migration. The other updates are ordinary documentation clarifications for Agent ID ownership and Global Secure Access licensing and IPv4 setup; no supplied item is identified as a new feature, preview, GA release, security advisory, or Message Center announcement.
- Conditional Access migration path to external MFA is documented
Entra ID · Conditional Access
The updated Entra ID Authentication page is specifically about moving from custom controls to external multifactor authentication. It gives the period a migration-oriented theme, but the record does not say that custom controls are retired, deprecated, or behaviorally changed, nor does it provide a deadline.
- Custom controls documentation updated as the companion reference
Entra ID · Conditional Access
The Conditional Access page covering how custom controls work was updated. Read with the migration page, it is a documentation reference for existing deployments; the supplied summary does not identify a new control, changed policy evaluation, or security requirement.
- Agent ID ownership rules are spelled out
Agent ID · General
The updated Agent ID guidance states that individual users, including guests, and service principals can be owners, while groups are not supported. Owners are optional for agent identity blueprints and agent identities, and service-principal ownership supports automated management. This is clarified ownership guidance, not evidence of a new owner capability.
- Global Secure Access fundamentals page includes license-to-profile mapping
Internet Access · Fundamentals
The updated What Is Global Secure Access page presents a comparison of Entra P1/P2 with the Microsoft traffic profile and separate Internet Access and Private Access licenses with their corresponding profiles. This is a reference-table clarification; no entitlement or availability change is stated.
- Global Secure Access IPv4-preferred setup tracking gets a registry check
Global Secure Access · Fundamentals
The updated page titled Track whether the IPv4-preferred setting was already correct includes an Edge policy registry check for BuiltInDnsClientEnabled as a DWORD with value 0 under HKLM\SOFTWARE\Policies\Microsoft\Edge. It is operational setup or troubleshooting guidance, not evidence that Global Secure Access changed its IPv4 behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Entra ID
2 updatesLearn how custom controls in Microsoft Entra Conditional Access work.
Microsoft Entra Agent ID
1 updateOwners usually serve as technical administrators for agents, handling operational and configuration aspects. Individual users (including guest users) and service principals can be set as owners. Groups aren't supported as owners. Service principals as owners enable automated management of agent identities. Owners are optional for agent identity blueprints and agent identities.
Microsoft Entra Internet Access
1 updateWhat Is Global Secure Access
Updated| Feature | Entra P1/P2 License - Microsoft traffic profile | Internet Access License¹ - Internet Access profile | Private Access License¹ - Private Access profile |
@{ Key="HKLM:\SOFTWARE\Policies\Microsoft\Edge"; Name="BuiltInDnsClientEnabled"; Type="DWord"; Value=0 },
