← Previous day

Next day →
Day in brief

Plan for the upcoming Entra ID passwordless password-change flow; Global Secure Access guidance adds concrete egress and per-app configuration details.

The most consequential item is Message Center notice MC1437671: Microsoft Entra will let passwordless users change passwords in My Sign-Ins with passkeys or Windows Hello, without knowing the current password or using SSPR. It is disabled by default and planned for global rollout in late October 2026. The remaining notable changes are documentation updates or new integration guidance for Global Secure Access, Azure Databricks provisioning, and GitHub Actions federation. No retirement or GA/preview announcement is evidenced; the FortiGate entry is a narrow URL-level tutorial edit.

  • Microsoft Entra is announcing a future My Sign-Ins flow in which passwordless users can change passwords using strong credentials such as passkeys or Windows Hello, without the current password or SSPR. The feature is disabled by default, requires administrator activation, and is scheduled for global rollout in late October 2026. This is a future Message Center announcement, not evidence that the capability is generally available today.

  • A new Global Secure Access page lists the IP ranges used for outbound internet traffic, giving administrators the information needed to allowlist those ranges on target services. The evidence supports a new reference document, not a claim that the service itself launched or that its egress behavior changed.

  • The updated instructions tell administrators to replace `{appRegistrationObjectId}` with the application registration's Object ID, located in the Microsoft Entra admin center under the app registration's Overview page. They also specify that setting `trafficRoutingMethod` to `random` returns Per App Access to its default behavior. This is a configuration-documentation update; the record does not establish a broader service behavior change.

  • A new integration guide explains how to configure Microsoft Entra ID to automatically provision and de-provision user accounts in Azure Databricks using SCIM. It is implementation guidance for the integration, not evidence of a newly announced provisioning feature or availability milestone.

  • The updated Workload Identity Federation guidance describes establishing trust between a user-assigned managed identity or application in Microsoft Entra ID and a GitHub repository, using the admin center or Microsoft Graph, followed by configuring a GitHub Actions workflow to obtain an access token and access Azure resources. This is clarification of the setup path rather than a stated new capability or rollout.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

5 updates

2
1

Workload Identity Federation

Updated

- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.

1

Global Secure Access egress IP ranges

New

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

1

Configure Per App Access

Updated

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…