Learn how to run a registration campaign in Microsoft Entra ID to nudge users toward passkeys or Microsoft Authenticator for stronger sign-in security.
12 June 2026: New PIM preview guidance, with sharper Entra coverage for agent controls and reauthentication
The period was dominated by targeted Microsoft Learn updates rather than announced service launches. The only new item documents a Preview approach for adding custom business logic to Microsoft Entra Privileged Identity Management role activation. Other notable updates clarify Conditional Access for agent identities, organization-specific recommendations from the Conditional Access Optimization Agent, post-revocation behavior in Identity Protection, and stronger-sign-in registration campaigns. The supplied evidence contains no general-availability announcement, retirement, or Message Center notice.
- PIM custom extensions are documented as a Preview workflow
ID Governance · Governance
A new ID Governance article explains how to configure custom extensions in Microsoft Entra Privileged Identity Management so custom business logic can be integrated into role-activation workflows. It is explicitly marked Preview; the record does not establish general availability or a service launch.
- Conditional Access guidance now covers targeting agent identities
Agent ID · Conditional Access
Updated Agent ID guidance describes using Conditional Access policies for agent identities, including targeting the appropriate agents, evaluating signals, and enforcing controls as organizations deploy more agents. This is expanded documentation coverage, not evidence of a newly announced availability status.
- The Conditional Access Optimization Agent guidance addresses organization-specific standards
Entra ID · Conditional Access
The updated knowledge-base article explains that knowledge bases help the Conditional Access Optimization Agent produce policy recommendations tailored to an organization’s unique standards. Administrators assessing this workflow should review the related standards and knowledge-base guidance rather than treat the update as a standalone product launch.
- Identity Protection guidance clarifies reauthentication after session revocation
ID Protection · Authentication
The updated Identity Protection Policies guidance states that Require authentication strength and Sign-in frequency – Every time are automatically applied so that, after session revocation, users are immediately prompted to reauthenticate with the specified authentication strength. The evidence supports a documentation clarification of expected behavior, so administrators should check their policy and user-experience expectations.
- Registration-campaign guidance reinforces passkey and Authenticator adoption
Entra ID · Authentication
Updated Entra ID guidance explains how to run a registration campaign that nudges users toward passkeys or Microsoft Authenticator for stronger sign-in security. It is rollout and security guidance, not evidence that a new campaign capability launched during this period.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
26 updates
Microsoft Entra ID
18 updatesLearn how to simplify the user experience with combined Microsoft Entra multifactor authentication and self-service password reset registration.
Learn about requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID.
Troubleshoot Microsoft Entra multifactor authentication and self-service password reset combined registration.
```kql
- Replace `{authenticationeventsAPI_AppId}` with the **appId** you recorded earlier.
1. Select **Add**.
1. Select **Add**.
Learn how Knowledge Bases help the Conditional Access Optimization Agent create tailored policy recommendations based on your organization's unique standards.
author: shlipsey3
What If Tool
UpdatedThe [What If Evaluation API](/graph/api/conditionalaccessroot-evaluate) is a Microsoft Graph API that is called by the Conditional Access experience. The API is different from the legacy What If evaluation in a few ways:
The agent settings described in this article cover standard options like triggers, notifications, and scope. But the settings also include advanced options like custom instructions, Intune integrations, and permissions.
Assign App Owners
Updated"@odata.id" = "https://graph.microsoft.com/v1.0/directoryObjects/aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb"
- Each dynamic group can have up to 50 member groups.
```json
Howto Update Permissions
Updated1. Identify the permissions your app requires, their permission IDs, and whether they're app roles (application permissions) or delegated permissions. For example, if you want to request Microsoft Graph permissions, see [Microsoft Graph permissions](/graph/permissions-reference#permission-scenarios) for a list of permissions and their IDs.
"displayName": "AWS Contoso",
Breaking Changes
Updated`https://login.microsoftonline.com/contoso.com/oauth2/authorize?resource=https://gateway.contoso.com/api&response_type=token&client_id=00001111-aaaa-2222-bbbb-3333cccc4444&...`
Microsoft Entra Agent ID
2 updatesAgent Id
Updated- High-level overview of Conditional Access: [What is Conditional Access?](overview.md)
Conditional Access policies for agent identities let you control how AI agents access corporate resources. As your organization deploys more agents, you need policies that target the right agents, evaluate the right signals, and enforce the right controls. To learn more about how Conditional Access policies for agents work for different scenarios, see [Conditional Access policies for agents](agent-id.md).
Microsoft Entra ID Protection
1 updateIdentity Protection Policies
Updated- **Require authentication strength** and **Sign-in frequency - Every time** are automatically applied to the policy to ensure that after session revocation, end users are immediately prompted to reauthenticate with the specified authentication strength.
Microsoft Entra ID Governance
1 updateLearn how to configure custom extensions in Microsoft Entra Privileged Identity Management (PIM) to integrate custom business logic into role activation workflows.
Microsoft Entra External ID
3 updatesLearn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
```powershell
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.
Microsoft Entra Verified ID
1 updateIdv Partners
Updated| 1Kosmos | [1Kosmos offer](https://aka.ms/1kosmos) | [VerifiedIdentity](https://verifiedid.did.msidentity.com/v1.0/tenants/8108e610-606c-4dc3-ae95-d3ad8be3b24c/verifiableCredentials/contracts/1197e066-a9a2-2dc5-f245-4c31d1f4b456/manifest) | 1Kosmos and Microsoft Entra Verified ID unite to deliver trusted, privacy-preserving identity verification that empowers secure, passwordless access across ecosystems. |
