Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecated functionality, and upcoming changes.
24 June 2026: Documentation-led Entra update—Internet Access readiness, ID Protection testing, and new SSO/group guidance
The period is dominated by Microsoft Learn documentation work rather than a product-release announcement. The most actionable updates are an Internet Access deployment-readiness checkpoint and ID Protection guidance to test policies with a non-administrator account. Entra ID also added new group-management and application-SSO guidance. The supplied evidence contains no Message Center items or removals and does not establish a new feature, preview, general availability, retirement, or changed service behavior; the Windows passkey update, for example, has no substantive change description in the record.
- Microsoft Entra Internet Access guidance now marks the post-planning handoff
Internet Access · Architecture
The updated GSA deployment guide says the initiate and plan stages are complete once the organization has defined which users to enable in each wave, set a deployment schedule, and met licensing requirements; it then says the project is ready to enable Microsoft Entra Internet Access. This is deployment guidance, not evidence of a new feature, preview, or GA event.
- ID Protection rollout guidance calls for a non-administrator test user
ID Protection · Architecture
The updated ID Protection introduction instructs administrators to use a test user who isn’t an administrator to verify policies before deploying them to real users. That is security and rollout guidance; the record does not indicate a change to policy behavior or availability.
- New SSO guidance adds a SAML 2.0 versus OIDC decision reference
Entra ID · Standards
A new Entra ID article compares SAML 2.0 and OpenID Connect for selecting an application’s SSO approach. It is part of a same-day set of new SSO material that also includes an ISV planning guide and an explanation of Microsoft’s centralized SSO model. These are architecture and planning references; no protocol-support change or release status is stated.
- A new group-management reference covers core group administration
Entra ID · Fundamentals
The new “How to manage groups” article covers creating and updating Microsoft Entra groups, including membership and settings. It is new documentation for administrators, not evidence that group capabilities or defaults changed.
- Updated permissions guidance defines the boundary for group owners
Entra ID · Fundamentals
The updated “Users Default Permissions” page states that a group owner can add or remove other owners, can manage only groups they own, and can add or remove members only when the group’s membership type is Assigned; it contrasts this with users assigned at least the Groups Administrator role. This is a documentation clarification of the stated scope, not evidence that the permission model changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
53 updates
Microsoft Entra ID
37 updatesWhats New Archive
Updated**Type:** New feature
Instructions about how to create and update Microsoft Entra groups, such as membership and settings.
Learn About Groups
Updated- For more information, see [Learn about Microsoft 365 Groups](https://support.office.com/article/learn-about-office-365-groups-b565caa1-5c40-40ef-9915-60fdb2d97fa2).
Entra Admin Center
Updated| Task | Description | Learn more |
Bulk Operations
Updated- [Bulk operations service limitations](bulk-operations-service-limitations.md)
Compare
Updated|**Users**|||
Create New Tenant
Updated- To add users, see [Add or delete a new user](./how-to-create-delete-users.md).
Delegate By Task
UpdatedHere are the least privileged roles you should use when performing tasks for [groups](../../fundamentals/how-to-manage-groups.md) in Microsoft Entra ID.
Groups Concept
Updated- [Create a role-assignable group](groups-create-eligible.md)
Groups Dynamic Membership
Updated- [Manage Microsoft Entra groups and group membership](~/fundamentals/how-to-manage-groups.md)
Manage User Profile Info
Updated- [Add or delete users](how-to-create-delete-users.md)
Users Default Permissions
UpdatedAn owner can also add or remove other owners. Unlike those users assigned at least the [Groups Administrator](../identity/role-based-access-control/permissions-reference.md#groups-administrator) role, owners can manage only the groups that they own and they can add or remove group members only if the group's membership type is **Assigned**.
Account Discovery
Updated- ServiceNow
Plan Auto User Provisioning
Updated| Resources| Link and Description |
Zscaler Beta is available in the following [national cloud deployments](/graph/deployments).
Zscaler One is available in the following [national cloud deployments](/graph/deployments).
Zscaler Three is available in the following [national cloud deployments](/graph/deployments).
Zscaler Two is available in the following [national cloud deployments](/graph/deployments).
Zscaler ZSCloud is available in the following [national cloud deployments](/graph/deployments).
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zoom.
High-level planning and decision guide for Independent Software Vendors (ISVs) preparing to integrate single sign-on (SSO) with Microsoft Entra ID.
Connect Version History
UpdatedThis article lists all releases of Microsoft Entra Connect and Azure AD Sync.
Groups Members Owners Search
UpdatedThese articles provide additional information on working with groups in Microsoft Entra ID.
Groups Naming Policy
UpdatedFor more information on Microsoft Entra groups, see:
Zoom Tutorial
UpdatedZoom is available in the following [national cloud deployments](/graph/deployments).
Zscaler Beta Tutorial
UpdatedZscaler Beta is available in the following [national cloud deployments](/graph/deployments).
Excel Power Query is updating its authentication flow for Organizational Accounts (Microsoft Entra ID) to enhance security and reliability. Users on Excel 2021 version 21.08 or older must update to build 16.0.14334.20754 or later by July 24, 2026, or upgrade to a newer version to avoid authentication loss. Microsoft 365 and newer Excel versions are unaffected.
ai-usage: ai-assisted
Learn about how to administer a Microsoft Entra Domain Services managed domain and the behavior of user accounts and passwords
Compare SAML 2.0 and OpenID Connect (OIDC) protocols to choose the right approach for your application's SSO integration with Microsoft Entra ID.
Learn how Microsoft Entra ID implements single sign-on (SSO) as a centralized identity platform for both SAML and OpenID Connect protocols.
Learn about single sign-on for enterprise applications in Microsoft Entra ID, including SAML and OpenID Connect protocols.
Get Started Premium
UpdatedNow that you have Microsoft Entra ID P1 or P2, you can [customize your domain](add-custom-domain.md), add your [corporate branding](./how-to-customize-branding.md), [create a tenant](create-new-tenant.md), and [add groups](./how-to-manage-groups.md) and [users](./how-to-create-delete-users.md).
V2 Howto App Gallery Listing
UpdatedLearn how to publish your application in Microsoft Entra application gallery.
Groups Lifecycle
UpdatedFor more information on Microsoft Entra groups, see:
Microsoft Entra ID Protection
1 update- A test user who isn't an administrator to verify that policies work as expected before you deploy real users. To create a user, follow the steps in [How to create, invite, and delete users](../fundamentals/how-to-create-delete-users.md).
Microsoft Entra ID Governance
1 update> [!NOTE]
Microsoft Entra External ID
2 updatesAdd Member To Group
UpdatedNow that you've added app groups claim in your application, add users to the security groups. If you don't have security group, [create one](~/fundamentals/how-to-manage-groups.md#create-a-basic-group-and-add-members).
Zscaler B2B User Portal is available in the following [national cloud deployments](/graph/deployments).
Microsoft Entra Internet Access
7 updatesZscaler Internet Access Administrator is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSCloud is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSNet is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSOne is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSThree is available in the following [national cloud deployments](/graph/deployments).
Zscaler Internet Access ZSTwo is available in the following [national cloud deployments](/graph/deployments).
At this point, you completed initiate and plan stages of your Secure Access Services Edge (SASE) deployment project. You understand what you need to implement for whom. You defined which users to enable in each wave. You have a schedule for each wave's deployment. You have met [licensing requirements](../global-secure-access/overview-what-is-global-secure-access.md#licensing-overview). You're ready to enable Microsoft Entra Internet Access.
Microsoft Entra Private Access
4 updatesZscaler Private Access (ZPA) is available in the following [national cloud deployments](/graph/deployments).
Zscaler Private Access Administrator is available in the following [national cloud deployments](/graph/deployments).
1. Create end user communications to set expectations and provide an escalation path.
Zscaler Private Access (ZPA) is available in the following [national cloud deployments](/graph/deployments).
1. Create end user communications to set expectations and provide an escalation path.
