← Previous day

Next day →
Day in brief

Conditional Access enforcement completes as Entra expands passkey guidance

7 July is primarily a documentation and service-behavior update rather than a broad feature-launch day. Microsoft reports completion of the Conditional Access enforcement update for policies with resource exclusions. The main documentation theme is passkeys: synced-passkey workflows were added, Windows Hello-based Microsoft Entra passkey guidance was expanded but remains explicitly in preview, and Authenticator troubleshooting now documents a potential Conditional Access loop. Microsoft Entra External ID also gained a new Amazon Cognito migration guide. No supplied item announces general availability, and the two removed passkey pages do not by themselves establish retirement of the underlying capability.

  • The Microsoft 365 Message Center records the Conditional Access enforcement update for policies with resource exclusions as completed in the tenant. This is a completed service-behavior notification, not a documentation change; the supplied summary does not specify the enforcement semantics or a required administrator action.

  • A new Microsoft Learn article covers how to configure, register, and sign in with synced passkeys in Microsoft Entra ID. It gives administrators a consolidated workflow reference, but the evidence describes a documentation addition rather than a new feature launch, availability change, or general-availability announcement.

  • The updated enablement material describes Microsoft Entra passkey on Windows, using Windows Hello as a FIDO2 passkey provider for phishing-resistant work or school account sign-in; new registration and sign-in pages accompany it. The explicit preview label means these changes should be treated as preview guidance rather than evidence of GA.

  • Updated External ID troubleshooting guidance warns that organizations deploying passkeys can encounter a loop when a Conditional Access policy requires phishing-resistant authentication for All resources and a user attempts to add a passkey to Microsoft Authenticator. The page points to workarounds, making this an actionable enrollment and security-guidance change rather than a stated change to Conditional Access behavior.

  • A new guide provides step-by-step guidance, feature mapping, and validation strategies for migrating from Amazon Cognito to Microsoft Entra External ID. This is planning and documentation support; the supplied evidence does not indicate an automated migration tool or a change in product availability.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

21 updates

15

Register a synced passkey (FIDO2)

Updated

Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.

Sign in with a synced passkey (FIDO2)

Updated

Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.

2
1
1

Snowflake Provisioning Tutorial

Updated

With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.

1

Troubleshoot

Updated

Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…