Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
SharePoint OTP retirement leads the period; Entra Internet Access has a DLP rollout timeline and proxy security guidance
A Microsoft 365 Message Center major update says SharePoint One-Time Passcode authentication will retire in October 2026, with new external sharing using Microsoft Entra B2B from May 2026. A second message sets out the Microsoft Purview DLP integration timeline for Entra Internet Access, while updated Explicit Forward Proxy documentation provides Conditional Access guidance. The other supplied changes are ordinary documentation updates, with no specific new behavior identified in their summaries.
- SharePoint One-Time Passcode retires as external sharing moves to Microsoft Entra B2B
External ID · Conditional Access
Microsoft 365 Message Center classifies this as a major update: SharePoint One-Time Passcode authentication retires in October 2026. The transition is tied to new external sharing using Entra B2B from May 2026; external users need guest accounts for access, and administrators are told to update policies and manage those guests.
- Purview DLP integration with Entra Internet Access has a stated preview-to-GA timeline
Internet Access · Conditional Access
The message describes Microsoft Purview DLP integrating with Microsoft Entra Global Secure Access Internet Access to filter sensitive files at the network layer and help prevent leaks to unmanaged cloud apps. It lists mid-November 2025 as the public-preview start and September 2026 as the general-availability target, with granular policies managed through Purview and Defender. This is a rollout timeline, not evidence of a July 18 launch.
- Updated Explicit Forward Proxy guidance emphasizes Conditional Access
Internet Access · Conditional Access
The updated guidance says a Conditional Access policy isn't required for Explicit Forward Proxy, but recommends using one to restrict proxy use to trusted networks. It also describes using Conditional Access to assign Microsoft Entra Internet Access security profiles to users. This is security and deployment guidance, not an announced change in proxy availability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Entra ID
3 updatesDescribes the Microsoft Entra built-in roles and permissions.
Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.
Microsoft Entra ID Governance
1 updateTenant Governance Administrator
Microsoft Entra Internet Access
2 updatesExplicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.
With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).
