Doc updateAction required The App Gallery provisioning requirements now instruct integrators to validate SCIM endpoints against the Microsoft Entra provisioning service and submit the results with their gallery submission.
29 August 2026
The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.
28 August 2026
The documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.
28 August 2026
A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.
28 August 2026
The article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.
28 August 2026
A new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.
28 August 2026
Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.
28 August 2026
The article now explains using directory extensions to filter groups for provisioning and to map attribute values to Active Directory users. It adds separate Groups and Users examples, prerequisites, and related guidance.
28 August 2026
The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.
28 August 2026
The article now covers directory extensions for users and groups when provisioning from Microsoft Entra ID to Active Directory, with updated examples, prerequisite wording, links, and related content.
28 August 2026
The documentation removed the Repair-AADCloudSyncToolsAccount section because the cmdlet is obsolete.
28 August 2026
The article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.
28 August 2026
The tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.
28 August 2026
The documented ServicePrincipalId example was replaced with a generic UUID.
27 August 2026
The Microsoft Entra tutorial for configuring automatic user provisioning to Rouse Sales has been deleted.
22 August 2026
New documentation explains how provisioning can clear an existing target attribute when its source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.
20 August 2026
The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.
20 August 2026
The configuration article now links to documentation for clearing attribute values (Preview).
20 August 2026
The FAQ now states that the /bulkUpload endpoint can clear existing user attributes and links to configuration guidance. It also clarifies that the endpoint cannot delete users and recommends Lifecycle Workflows for automated deletion after termination or disablement.
20 August 2026
The synchronization documentation now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance.
18 August 2026
The tutorial now explains that `{enterprise}` in the GitHub.com SCIM tenant URL is the enterprise slug (account name).
14 August 2026
The article’s Microsoft MCP Server for Enterprise overview and setup links changed from Microsoft Learn paths to the EnterpriseMCP GitHub repository. The article continues to describe the service as preview, global-service-only, and read-only.
12 August 2026
The Puzzel provisioning article now documents OAuth2 Client Credentials Grant authentication. It adds steps to create an OIDC client, set token lifetimes to 3600, generate a shared secret, and enter the client ID, secret, and token endpoint.
12 August 2026
The tutorial now states that Client Credentials Authentication is supported.
12 August 2026
The tutorial now documents entering a Tenant URL, Client identifier, Client secret, and OAuth token endpoint, and includes a list of SCIM user attributes and data types.
12 August 2026
The account discovery documentation now links to the Microsoft MCP Server for Enterprise GitHub repository instead of Microsoft Learn pages for investigating reports and provisioning an MCP client.
12 August 2026
The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.
7 August 2026
The documentation replaces the former Mappings-based steps with a Scoping filters wizard covering assignment-based and attribute-based filtering for users and groups. Existing operator details and limitations remain documented.
7 August 2026
The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.
7 August 2026
The article now directs administrators to Manage > Attribute Mapping, with mappings organized by Users and Groups. It documents row-level edit and delete controls, group sync via Scoping filters, and the Advanced Options menu for custom attributes.
7 August 2026
The documentation now says to open Expression Builder from the left navigation menu instead of Attribute Mapping > Advanced Options. The page date was also updated from March 4, 2025, to August 6, 2026, and the access screenshot was removed.
7 August 2026
The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.
7 August 2026
The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.
7 August 2026
The documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.
7 August 2026
The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.
7 August 2026
The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.
7 August 2026
The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.
7 August 2026
The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”
7 August 2026
The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.
7 August 2026
The guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.
7 August 2026
The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.
7 August 2026
The article now explains viewing and downloading provisioning logs through the admin center, Microsoft Graph, and Microsoft MCP Server for Enterprise. The MCP integration supports natural-language, read-only analysis through delegated permissions and is currently limited to the global service.
5 August 2026
The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.
4 August 2026
The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.
4 August 2026
> [!NOTE]
1 August 2026
The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
28 August 2026
The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.
28 August 2026
A link was fixed on the Conditional Access network assignment page.
27 August 2026
The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.
27 August 2026
The documented query now filters for UserId `00aa00aa-bb11-cc22-dd33-44ee44ee44ee` instead of the previous identifier.
27 August 2026
The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.
26 August 2026
The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.
25 August 2026
The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.
25 August 2026
The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.
25 August 2026
The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.
25 August 2026
The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.
25 August 2026
Microsoft Entra now applies system-preferred authentication to first-factor sign-ins for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout is from late June to late September 2026. Tenants can keep or change this setting and should update user guidance accordingly.
Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.
21 August 2026Message CenterMC1458474 on mc.merill.net ↗Major updatePlan for change The document date changed from August 18 to August 20, 2026, and existing vendor entries were reordered. Their displayed identifiers and support indicators remain unchanged.
21 August 2026
The security key entry’s table formatting was corrected by removing an extra space before a separator.
21 August 2026
The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.
21 August 2026
The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.
21 August 2026
The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.
21 August 2026
Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.
21 August 2026
New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.
20 August 2026
RetirementAction required The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.
20 August 2026
RetirementAction required The documentation now covers custom CSS layout and positioning properties, and updates its publication date to August 18, 2026. It describes support for these properties as being retired under the Secure Future Initiative.
20 August 2026
The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.
20 August 2026
The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.
20 August 2026
RetirementAction required The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.
20 August 2026
The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.
20 August 2026
The guidance now states that authentication strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts, alongside the previously listed methods. It directs administrators to use the MFA grant control instead.
15 August 2026
The article title and heading no longer include “(preview).” No other change is shown.
14 August 2026
The page title and heading no longer include “(preview).” No other change is shown, and the diff does not explicitly announce general availability or a product launch.
14 August 2026
The documentation now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” and expands “SPA” to “single-page application.” The described authentication flows and responsibilities are otherwise unchanged in the supplied diff.
14 August 2026
The local-development article now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK,” including its title, description, intent, link text, and container description.
14 August 2026
Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on August 11, 2026, due to fraud risks. Users must switch to other authentication methods before then. SMS as a multifactor method remains unaffected. Admins should identify affected users and update authentication policies accordingly.
13 August 2026Message CenterMC1448374 on mc.merill.net ↗Plan for change The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.
12 August 2026
The documentation now states that opting out requires the Microsoft Graph `Policy.ReadWrite.AuthenticationMethod` permission. The page date changed from July 29 to August 10, 2026.
11 August 2026
The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.
8 August 2026
The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.
7 August 2026
The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.
6 August 2026
A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.
5 August 2026
The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.
5 August 2026
The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.
4 August 2026
Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.
4 August 2026Message CenterMC1325414 on mc.merill.net ↗Major updatePlan for change The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.
29 August 2026
New featureAction required A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.
28 August 2026
The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.
28 August 2026
Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.
28 August 2026
The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.
28 August 2026
The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.
27 August 2026
The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.
27 August 2026
The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.
27 August 2026
A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.
26 August 2026
The page title now says “Microsoft Entra ID,” and several table separators were reformatted for consistent Markdown presentation.
26 August 2026
The documentation now explains that Agent ID objects are covered through their underlying directory object types, including user accounts as user objects and identity blueprints as application objects.
26 August 2026
Removed an extra space from the Help desk admin row in the documentation table.
26 August 2026
Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.
26 August 2026Message CenterMC1462460 on mc.merill.net ↗Plan for change Feature updateAction required Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.
25 August 2026
The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.
24 August 2026
The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.
24 August 2026
The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.
21 August 2026
The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.
20 August 2026
The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.
20 August 2026
The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.
20 August 2026
The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.
20 August 2026
The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.
18 August 2026
The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.
14 August 2026
The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.
7 August 2026
The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.
7 August 2026
The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.
7 August 2026
The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.
7 August 2026
The article explains how to inspect failed Azure Logic Apps validation runs, identify root causes, and resolve common SCIM endpoint, authentication, permissions, filtering, and conflict errors.
29 August 2026
A new guide explains how ISVs create an Entra Gallery Provisioning Test App, deploy the Azure Logic Apps validation template, configure permissions and parameters, and run SCIM provisioning tests.
29 August 2026
A new article explains how to validate SCIM user and group provisioning with an Azure Logic Apps template, run 25 tests, and submit the results with a Logic App run ID for App Gallery review. It covers both AI-agent and Azure portal setup methods.
29 August 2026
The page author changed from hsaini to himanshusainig.
29 August 2026
The document’s author metadata changed from hsaini to himanshusainig.
29 August 2026
The page author changed from `hsaini` to `himanshusainig`.
29 August 2026
The documentation replaces its embedded onboarding checklist with links to current requirements and validation instructions. App publishers validate their SCIM integration and submit the results with their gallery application; customers obtain OAuth configuration values from the app’s admin experience.
29 August 2026
Doc updateAction required The tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.
29 August 2026
The SCIM provisioning documentation now links to guidance for the OAuth 2.0 client credentials grant.
29 August 2026
The SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.
27 August 2026
The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
26 August 2026
The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.
26 August 2026
The new page lists SCIM API, authentication, testing, support, documentation, customer deployment, and cloud compliance requirements for publishing user provisioning integrations in Microsoft Entra App Gallery.
26 August 2026
A tutorial now explains how to use the Microsoft Entra App Validator browser extension with non-gallery enterprise applications, including IdP- and SP-initiated SSO, certificate scenarios, optional Single Logout, and result submission.
26 August 2026
Doc updateAction required The documentation explains how to use the Microsoft Entra App Validator browser extension to test an OIDC multitenant app, review fixes, and generate the Test ID required for gallery publishing.
26 August 2026
Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.
26 August 2026
The guide title now uses quoted punctuation, and the table separator spacing was standardized.
26 August 2026
The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.
26 August 2026
The page title changed from “What is single sign-on (SSO) in Microsoft Entra ID?” to “What is single sign-on in Microsoft Entra ID?”
26 August 2026
The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
25 August 2026
The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.
21 August 2026
The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.
20 August 2026
The tutorial replaces the Orgvue authentication and SAML callback URLs with orgvue-staging URLs and changes the Sign-on URL to include the application login path and domain parameter. It also clarifies that both Reply URL and Sign-on URL values are placeholders.
10 August 2026
The Conditional Access What If tool table now uses a different sample UserId in all four examples.
28 August 2026
The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
28 August 2026
The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.
28 August 2026
The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.
28 August 2026
The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.
28 August 2026
The Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.
27 August 2026
The documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.
27 August 2026
The grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.
27 August 2026
The documentation explains how to access the Microsoft Application Network portal and submit requests to update SSO, MDM, or user provisioning details, upgrade SSO, or remove an application listing.
26 August 2026
The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.
26 August 2026
The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.
26 August 2026
The permission-addition and permission-removal examples now use different sample object and client IDs.
26 August 2026
The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
26 August 2026
The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.
26 August 2026
The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.
26 August 2026
The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.
25 August 2026
The page title capitalization and image alt text were revised. No configuration or product behavior changes are shown.
5 August 2026
The reference now links to license management in the Azure portal, updates the table as of August 3, 2026, adds Agent 365, and revises service and plan identifier entries.
4 August 2026
A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.
28 August 2026
A new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.
28 August 2026
The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.
28 August 2026
The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.
25 August 2026
The page title no longer includes “(preview),” and the prerelease product notice was removed.
22 August 2026
The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.
22 August 2026
The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.
22 August 2026
The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.
22 August 2026
The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.
22 August 2026
The documentation now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.
20 August 2026
The documentation now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application scope.
19 August 2026
The documentation now states that replica sets require connectivity between all virtual networks hosting them. They are deployed in one Active Directory site and rely on a fully meshed virtual network topology for directory replication.
14 August 2026
The page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. iOS/iPadOS browser support is not supported. The page also adds requirements for supported browsers, extensions, operating systems, and configurations.
10 August 2026
The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.
7 August 2026
Instructions about how to find Microsoft Entra ID and how to create a new tenant for your organization.
1 August 2026
Feature updateAction required Microsoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.
25 August 2026
Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing resistance. This feature, enabled by default, rolls out from October 2026 to February 2027, requiring no admin action but recommending policy reviews to align user scopes and MFA settings.
The guide removes the Preview designation, adds Microsoft Scout to the support matrix, and replaces detailed storage-flag instructions with updated Apple SSO plugin and Platform SSO guidance.
20 August 2026
Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are needed, but organizations should update onboarding and MFA registration guidance accordingly.
18 August 2026Message CenterMC1450134 on mc.merill.net ↗Plan for change Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.
The token protection article removes a screenshot of a Conditional Access policy requiring token protection as a session control. The Primary Refresh Token link remains.
10 August 2026
Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.
7 August 2026
Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.
5 August 2026Message CenterMC1448379 on mc.merill.net ↗Major updatePlan for change