After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.
Authenticator passkey restore on iOS is getting a guided August rollout; the remaining updates are mainly documentation
The most consequential change is an announced improvement to Microsoft Authenticator passkey restoration for iOS users with iCloud backups. The guided device-migration flow is expected worldwide in August 2026, enabled by default, with no administrator changes required. The other entries update guidance for a Workload ID preview capability, Application Proxy setup, and guest-user licensing; they do not establish a new GA release, retirement, or licensing-policy change.
- Microsoft Authenticator passkey restore on iOS will use a guided flow
Entra ID · Authentication
Microsoft Entra Message Center announces a clearer, guided restore experience for Authenticator passkeys during iOS device migration. It affects iOS users with iCloud backups, is expected to be available worldwide in August 2026, is enabled by default, and requires no admin action.
- Workload ID preview guidance documents resource-provider assignment restrictions
Workload ID · General
Updated guidance explains how to configure assignment restriction for a user-assigned managed identity in the Azure portal, limiting it to specified resource providers. This is documentation for a preview capability; the supplied evidence does not indicate general availability, a new rollout, or a required migration.
- Application Proxy setup guidance calls out User.Read admin consent
Entra ID · Developer
The updated connection guidance says that after creating a new Application Proxy application, administrators should grant admin consent for the User.Read delegated permission in the Microsoft Entra admin center or through Microsoft Graph PowerShell. The evidence supports a setup clarification, not a change to the permission model.
- Guest-user licensing documentation was updated without evidence of a licensing-policy change
ID Governance · Governance
The updated Microsoft Entra ID Governance page explains how Microsoft Entra ID is licensed for guest users. The supplied summary identifies no new SKU, entitlement, price, or policy, so this should be treated as reference documentation rather than a licensing launch or change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
4 updates
Microsoft Entra ID
1 updateMicrosoft Entra ID Governance
1 updateLearn how Microsoft Entra ID is licensed for guest users.
Microsoft Entra Workload ID
2 updatesLearn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
