External access tokens for actionable messages will be retired by May 15, 2026, replaced by Microsoft Entra authentication to enhance security. Organizations must update integrations before this date, as messages using legacy tokens will fail. The phase-out completes by June 8, 2026.
21 May: updated guidance targets passkey enrollment and External ID native-app integrations
All six recorded items were Microsoft Learn documentation updates: four for Microsoft Entra External ID and two for Microsoft Entra ID. The most consequential content covers registration campaigns for passkeys or Microsoft Authenticator, custom headers for fraud-detection integrations in native apps, and customer user-flow cookie behavior. Nothing in the supplied evidence indicates a new feature launch, preview, general-availability change, retirement, or confirmed runtime behavior change.
- Entra ID registration-campaign guidance for passkeys and Microsoft Authenticator
Entra ID · Authentication
The updated Authentication guidance explains how to run a registration campaign that nudges users toward passkeys or Microsoft Authenticator. This is security and rollout guidance; the record does not establish a new campaign capability or a change to tenant configuration requirements.
- External ID native-authentication guidance covers custom headers for fraud-detection integrations
External ID · Authentication
Paired iOS (Swift) and Android (Kotlin) documentation updates describe attaching custom x-* headers to native authentication requests so apps can integrate fraud-detection SDKs. This is implementation guidance for app teams, not evidence of a newly released service-side feature or availability change.
- External ID customer user-flow documentation clarifies persistent sign-in cookies
External ID · Authentication
The updated sign-up/sign-in guidance states that the default Stay signed in? prompt issues a persistent authentication cookie when the customer selects Yes and a non-persistent cookie when the customer selects No. This should be treated as a documentation clarification of session behavior, not proof that the runtime default changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
7 updates
Microsoft Entra ID
3 updatesLearn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
Samsara Tutorial
Updatedb. Copy the link from Post-back/ACS URL field in Samsara into the **Reply URL** text box in Entra ID.
Microsoft Entra External ID
4 updatesLearn how to attach custom x-* headers to native authentication network requests in an iOS (Swift) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
Learn how to attach custom x-* headers to native authentication network requests in an Android (Kotlin) app to integrate fraud-detection SDKs with Microsoft Entra External ID.
By default, after a customer signs in to an app that uses your user flow, they see a **Stay signed in?** prompt asking whether to stay signed in across browser sessions. If the user selects **Yes**, a persistent authentication cookie is issued and they remain signed in across browser sessions. If they select **No**, a non-persistent cookie is issued.
Direct Federation
Updated1. On the **New SAML/WS-Fed IdP** page, enter the following:
