← Previous day

Next day →
Day in brief

Entra ID adds passkey-migration guidance as Explicit Forward Proxy documentation expands

The 14 July period was documentation-led rather than a clearly evidenced product-availability day. The most consequential new item is Entra ID guidance to prepare for retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. A concentrated set of Global Secure Access and Microsoft Entra Internet Access updates clarifies Explicit Forward Proxy authentication, a preview session-management method, custom PAC-file hosting, and Edge deployment through Intune. Related updates also document PAC delivery options for unmanaged devices.

  • The new Microsoft Learn page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. This is new security and migration guidance; the evidence does not establish that the retirement or a passkeys-by-default behavior took effect on 14 July.

  • The updated Global Secure Access page says Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization before allowing traffic. That model supports adaptive Microsoft Entra Conditional Access policies, passkeys, and Continuous Access Evaluation with session revocation, while basic, digest, NTLM, and Kerberos proxy authorization methods are not supported. This is a documentation clarification, not evidence of a new GA release.

  • The updated preview guidance says Explicit Forward Proxy can associate an authenticated user with a device by using the device’s private IP address. Organizations using this method must securely communicate that private IP address to the feature. The update describes a preview deployment model, not a general-availability announcement.

  • A new Internet Access page documents how to upload and host an organization’s own Proxy Auto-Configuration files for Explicit Forward Proxy. It adds configuration guidance, but the new page alone does not establish a product launch or an availability change.

  • The updated Global Secure Access implementation page says an Intune mobile application management policy can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge for Explicit Forward Proxy. This is updated deployment guidance; the evidence does not indicate a changed availability status.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

7 updates

1
1
2

Proxy Automatic Configuration Files

Updated

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

Explicit Forward Proxy overview

Updated

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

1

Configure HTTP header session management (preview)

Updated

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

1

Explicit Forward Proxy session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…