Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Security guidance leads 30 July: immutable GitHub Actions subjects, passkey migration, and Tenant Governance preview
30 July was primarily a Microsoft Learn documentation day, but it contained two important security threads. New Workload ID guidance covers the risk of mutable OIDC subjects and migration of GitHub Actions federated identity credentials to GitHub's immutable subject format; updated Entra ID guidance covers preparation for retiring Microsoft-provided SMS and voice authentication in favor of passkeys. ID Governance also added documented Microsoft Graph investigation guidance for related-tenant signals, explicitly in preview, and updated its delegated-administration guidance. The remaining edits, including Lifecycle Workflow email attributes, External ID OIDC setup, Global Secure Access tenant restrictions, and Cloud Sync prerequisites, are best read as instructional clarifications rather than confirmed launches or behavior changes.
- Workload ID: new guidance moves GitHub Actions credentials toward immutable subjects
Workload ID · Security
Two new Workload ID pages form a related security guidance package: mutable OIDC subject claims can expose federated identity credentials to subject recycling, and GitHub Actions credentials can be migrated from mutable subjects to GitHub's immutable subject format. This is documentation and security guidance, not evidence of a new feature launch or an automatic tenant-wide change.
- Entra ID: updated preparation guidance covers passkeys and SMS/voice retirement
Entra ID · Authentication
The updated page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. The supplied evidence does not provide a retirement date or establish that passkeys became the default, or that SMS and voice were disabled, on 30 July.
- Tenant Governance: related-tenant signal investigation is documented through Microsoft Graph (preview)
ID Governance · Governance
A new ID Governance page documents how Microsoft Graph can retrieve the underlying users and applications behind Tenant Governance related-tenant discovery signals. Because the route is explicitly preview, this is newly documented preview usage rather than evidence of general availability or a production behavior change.
- ID Governance: updated guidance clarifies cross-tenant delegated administration
ID Governance · Governance
Updated guidance describes cross-tenant delegated administration and its GDAP-based permission model for managing tenants in Microsoft Entra. This clarifies the documented operating model; the supplied evidence does not announce a new permission set or rollout on this date.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
15 updates
Microsoft Entra ID
2 updatesPrerequisites
Updated- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).
Microsoft Entra ID Governance
8 updatesLearn how to use Microsoft Graph to retrieve the underlying users and applications behind Tenant Governance related tenant discovery signals.
Lifecycle Workflow Tasks
UpdatedWith customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:
Customize Workflow Email
UpdatedIn the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.
Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants
Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization
Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.
Learn how to use cross-tenant delegated administration to sign in to and manage governed tenants using your governing tenant credentials
Governance Policy Templates
Updated- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.
Microsoft Entra External ID
1 updateLearn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Microsoft Entra Internet Access
1 updateGsa Poc Internet Access
Updated1. Sign in to your test device and use a private browser window to sign in to any application that is protected by Entra ID in a different tenant, using member account credentials from that tenant.
Microsoft Entra Workload ID
2 updatesLearn how to migrate a Microsoft Entra federated identity credential for GitHub Actions from a mutable subject to GitHub's immutable subject format.
Learn how mutable OIDC subject claims expose Microsoft Entra federated identity credentials to subject recycling, and how immutable claims reduce the risk.
Learn about how Global Secure Access helps secure access to your corporate network by restricting access to external tenants.
