Existing FIDO2 tenants face automatic passkey-profile migration as Entra broadens passkey GA
The period is driven by two distinct passkey changes: tenant-side migration to passkey profiles and general availability of Entra passkeys on Windows. It also introduces a network-layer Microsoft Purview DLP integration through Entra Internet Access and replaces legacy CAPTCHA protection in self-service password reset with backend abuse detection.
- Passkey profiles and existing FIDO2 configurations move to general availability
Entra ID · Authentication
For tenants with Passkeys (FIDO2) enabled, Microsoft Entra is making passkey profiles and synced passkeys generally available. Existing configurations migrate to a Default passkey profile with a new passkeyType property, while automatic migration and registration-campaign updates roll out regionally through October 2026. This is a tenant-configuration behavior change, not merely a documentation update.
- Microsoft Purview DLP extends to the network layer through Entra Internet Access
ID Protection · Conditional Access
The integration enables inspection and protection of sensitive data in AI interactions and cloud services at the network layer, with policy enforcement, alerts, and auditing. The rollout is scheduled from July through October 2026 and spans Microsoft Purview, Microsoft Entra, and Defender administration.
- Microsoft Entra passkeys on Windows reach general availability
Entra ID · Conditional Access
The Windows capability is generally available from late April 2026, providing phishing-resistant, passwordless sign-in on corporate, personal, and shared Windows devices without explicit opt-in. Administrators can control the capability through Authentication Methods policies and Conditional Access; the notice says no action is needed unless blocking is desired.
- SSPR replaces legacy CAPTCHA with backend abuse detection
Entra ID · Authentication
Beginning in early August 2026, self-service password reset replaces legacy CAPTCHA with backend throttling and behavior-based abuse detection. The change is intended to improve security and accessibility while preserving current password-reset functionality, with no new controls and no user or administrator action required.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
0 updates
No tracked updates
Try the previous day or browse the weekly archive.
