Month in brief

Entra’s August deadlines span SMS first-factor sign-in, branding CSS, MemberOf, and SSPR

August was dominated by Microsoft Entra ID retirements and authentication behavior changes rather than a broad feature launch. SMS first-factor sign-in for Entra ID Free tenants reached its August 11 retirement date, while SMS MFA remains unaffected. Custom branding CSS layout and positioning properties face retirement by late October; the MemberOf rule operator retires November 3; and SSPR begins requiring explicitly registered authentication methods November 9 after a registration campaign starts October 5. System-preferred authentication is also rolling out through late September to first-factor sign-ins in Microsoft-managed-state tenants, selecting the most secure registered method. Notable procedural guidance added during the month covers Tenant Governance snapshots and monitor permissions, plus Global Secure Access V1-to-V2 web content filtering migration.

  • The August 11, 2026 retirement removes SMS as a first-factor sign-in method for Microsoft Entra ID Free tenants because of fraud risks. SMS used as a multifactor authentication method remains unaffected. Administrators should identify affected users and move them to another authentication method.

  • New use of custom CSS layout and positioning properties has been blocked since July 21, 2026. Existing branding configurations are scheduled for retirement by late October, after which branding reverts to default layouts. Audit company-branding configurations and replace affected properties before then.

  • Entra ID · Conditional Access
    MemberOf rule operator retires November 3

    Microsoft Entra ID will retire the MemberOf operator on November 3, 2026. Rules using it in dynamic groups, administrative units, or entitlement policies must be replaced to avoid stale access, licensing, and policy enforcement.

  • Starting November 9, 2026, self-service password reset will require explicitly registered authentication methods and will no longer accept directory-sourced contact information unless it is registered. A user registration campaign begins October 5, giving administrators time to prepare users.

  • For tenants in Microsoft’s managed state, system-preferred authentication now applies to first-factor sign-ins and selects the most secure registered method. The rollout runs from late June through late September 2026; administrators should review the setting and update user-facing sign-in guidance.

For Entra administrators

Verify that Entra ID Free users who relied on SMS first-factor sign-in have another method; do not confuse this retirement with SMS MFA. Audit company branding for custom CSS layout or positioning properties and replace affected configurations before late October. Inventory MemberOf rules in dynamic groups, administrative units, and entitlement policies ahead of the November 3 retirement. Prepare users for the October 5 SSPR registration campaign and November 9 enforcement. During the system-preferred authentication rollout, review the setting and update sign-in guidance. For Tenant Governance, validate Basic or Premium licensing, snapshot and monitor quotas, privileged-role and read permissions, and Tenant Configuration Management service authorization; missing service permissions canทำ?

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

363 updates by product

45

App Gallery User Provisioning Requirements

Doc updateAction required

The App Gallery provisioning requirements now instruct integrators to validate SCIM endpoints against the Microsoft Entra provisioning service and submit the results with their gallery submission.

29 August 2026

Tutorial: Govern access to an on-premises app (Preview)

New feature

The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.

28 August 2026

Plan Cloud Sync Topologies

Doc update

The documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.

28 August 2026

Microsoft Entra provisioning behavior (Preview)

Doc update

A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.

28 August 2026

Microsoft Entra provisioning setup (Preview)

New feature

The article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.

28 August 2026

Test Microsoft Entra provisioning (Preview)

New feature

A new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.

28 August 2026

Microsoft Entra prerequisites for AD (Preview)

Doc update

Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.

28 August 2026

On-demand provisioning - Microsoft Entra ID to Active Directory

Feature update

The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.

28 August 2026

On Demand Provision

Doc update

The article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.

28 August 2026

Tutorial Group Provisioning

Doc update

The tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.

28 August 2026

Clear attribute values (Preview)

Private preview

New documentation explains how provisioning can clear an existing target attribute when its source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.

20 August 2026

Customize Application Attributes

Private preview

The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.

20 August 2026

Inbound Provisioning Api Faqs

Doc update

The FAQ now states that the /bulkUpload endpoint can clear existing user attributes and links to configuration guidance. It also clarifies that the endpoint cannot delete users and recommends Lifecycle Workflows for automated deletion after termination or disablement.

20 August 2026

Synchronization

Public preview

The synchronization documentation now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance.

18 August 2026

Howto Analyze Provisioning Logs

Doc update

The article’s Microsoft MCP Server for Enterprise overview and setup links changed from Microsoft Learn paths to the EnterpriseMCP GitHub repository. The article continues to describe the service as preview, global-service-only, and read-only.

12 August 2026

Zscaler Zidentity Provisioning Tutorial

Doc update

The tutorial now documents entering a Tenant URL, Client identifier, Client secret, and OAuth token endpoint, and includes a list of SCIM user attributes and data types.

12 August 2026

Account Discovery

Doc update

The account discovery documentation now links to the Microsoft MCP Server for Enterprise GitHub repository instead of Microsoft Learn pages for investigating reports and provisioning an MCP client.

12 August 2026

Provision Custom Security Attributes

Doc update

The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.

7 August 2026

Sap Successfactors Integration Reference

Doc update

The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.

7 August 2026

Customize Application Attributes

Doc update

The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.

7 August 2026

Export Import Provisioning Configuration

Doc update

The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.

7 August 2026

Expression Builder

Doc update

The documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.

7 August 2026

Inbound Provisioning Api Custom Attributes

Doc update

The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.

7 August 2026

Inbound Provisioning Api Faqs

Doc update

The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.

7 August 2026

On Premises Ldap Connector Linux

Doc update

The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.

7 August 2026

On Premises Powershell Connector

Doc update

The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”

7 August 2026

On Premises Web Services Connector

Doc update

The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.

7 August 2026

Plan Cloud Hr Provision

Doc update

The guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.

7 August 2026

Workday Retrieve Pronoun Information

Doc update

The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.

7 August 2026

How to analyze the Microsoft Entra provisioning logs

Public preview

The article now explains viewing and downloading provisioning logs through the admin center, Microsoft Graph, and Microsoft MCP Server for Enterprise. The MCP integration supports natural-language, read-only analysis through delegated permissions and is currently limited to the global service.

5 August 2026

Extend Application Attributes

Doc update

The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.

4 August 2026

Customize Application Attributes

Doc update

The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.

4 August 2026
41

Assignment Network

Doc update

The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.

28 August 2026

Assignment Network

Doc update

The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.

28 August 2026

Assignment Network

Doc update

A link was fixed on the Conditional Access network assignment page.

27 August 2026

Assignment Network

Doc update

The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.

27 August 2026

Strengthen federated sign-in security

Doc update

The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.

26 August 2026

Howto Arc Sign In Windows

Doc update

The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.

25 August 2026

Howto Arc Sign In Windows

Doc update

The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.

25 August 2026

Howto Arc Sign In Windows

Doc update

The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.

25 August 2026

Howto Arc Sign In Windows

Doc update

The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.

25 August 2026

Howto Arc Sign In Windows

Doc update

The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.

25 August 2026

Microsoft Entra ID: Retirement of custom CSS layout and positioning properties in company branding

New

Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.

21 August 2026
Message CenterMC1458474 on mc.merill.net ↗Major updatePlan for change

Fido2 Hardware Vendor

Doc update

The security key entry’s table formatting was corrected by removing an extra space before a separator.

21 August 2026

Fido2 Hardware Vendor

Doc update

The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.

21 August 2026

Fido2 Hardware Vendor

Doc update

The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.

21 August 2026

Fido2 Hardware Vendor

Doc update

The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.

21 August 2026

Fido2 Hardware Vendor

Doc update

Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.

21 August 2026

Strengthen federated sign-in security

New feature

New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.

20 August 2026

Customize Branding

RetirementAction required

The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.

20 August 2026

Single Sign On Saml Protocol

Doc update

The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.

20 August 2026

Optional Claims Reference

Doc update

The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.

20 August 2026

Company Branding Css Template

RetirementAction required

The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.

20 August 2026

Deployment Guide Token Protection Apple

Doc update

The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.

20 August 2026

Policy Guests Mfa Strength

Doc update

The guidance now states that authentication strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts, alongside the previously listed methods. It directs administrators to use the MFA grant control instead.

15 August 2026

Authentication with Microsoft Entra ID Auth SDK (sidecar)

Doc update

The documentation now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” and expands “SPA” to “single-page application.” The described authentication flows and responsibilities are otherwise unchanged in the supplied diff.

14 August 2026

Microsoft Entra Connect: Cloud authentication via Staged Rollout

Doc update

The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.

12 August 2026

Managed Policies

Doc update

The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.

8 August 2026

Howto Arc Sign In Windows

Doc update

The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.

7 August 2026

Choose a telephony provider for SMS and voice authentication

Doc update

The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.

6 August 2026

Choose a telephony provider for SMS and voice authentication

Doc update

A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.

5 August 2026

Howto Sspr Authenticationdata

Doc update

The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.

5 August 2026

Sms Voice Retirement

Retirement

The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.

4 August 2026

Microsoft Entra ID SSPR will require registered authentication methods starting November 9, 2026

New

Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.

4 August 2026
Message CenterMC1325414 on mc.merill.net ↗Major updatePlan for change
27

Publish App Gallery

Doc update

The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.

29 August 2026

Preserve a group's organizational unit (Preview)

New featureAction required

A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.

28 August 2026

Group Source Of Authority Configure

Doc update

The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.

28 August 2026

Sap Netweaver Tutorial

Doc update

Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.

28 August 2026

Sap Netweaver Tutorial

Doc update

The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.

28 August 2026

Manage App Consent Policies

Doc update

The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.

27 August 2026

Exchange Hybrid

Doc update

The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.

27 August 2026

Assign App Owners

Doc update

The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.

27 August 2026

Publish your app to Microsoft Entra App Gallery

Doc update

A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.

26 August 2026

Plan Sso Deployment

Doc update

Removed an extra space from the Help desk admin row in the documentation table.

26 August 2026

Microsoft Entra: Domain update for My Account and identity self-service experiences

New

Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.

26 August 2026
Message CenterMC1462460 on mc.merill.net ↗Plan for change

Whats New Linux

Feature updateAction required

Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.

25 August 2026

Connect Health Version History

Doc update

The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.

24 August 2026

Connect Health Agent Install

Doc update

The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.

24 August 2026

Optional Claims Reference

Doc update

The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.

21 August 2026

Licensing Service Plan Reference

Doc update

The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.

20 August 2026

Licensing Service Plan Reference

Doc update

The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.

20 August 2026

Licensing Service Plan Reference

Doc update

The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.

20 August 2026

Licensing Service Plan Reference

Doc update

The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.

20 August 2026

Licensing Service Plan Reference

Doc update

The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.

18 August 2026

Manage rules for dynamic membership groups in Microsoft Entra ID

Doc update

The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.

14 August 2026

Import ADSyncTools module

Doc update

The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.

7 August 2026

Import ADSyncTools module

Doc update

The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.

7 August 2026

Whats New

Doc update

The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.

7 August 2026

Provide the user's identity.

Doc update

The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.

7 August 2026
23

Scim Validator Tutorial

Doc updateAction required

The tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.

29 August 2026

Entra Id Scim Api Reference

Feature update

The SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.

27 August 2026

Breaking Changes

Doc update

The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.

26 August 2026

Breaking Changes

Doc update

The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.

26 August 2026

SSO requirements for Microsoft Entra App Gallery

Doc update

Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.

26 August 2026

Groups Settings V2 Cmdlets

Doc update

The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.

26 August 2026

Breaking Changes

Doc update

The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

25 August 2026

Single Sign On Saml Protocol

Doc update

The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.

21 August 2026

Inbound Provisioning Api Concepts

New feature

The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.

20 August 2026

Orgvue Tutorial

Doc update

The tutorial replaces the Orgvue authentication and SAML callback URLs with orgvue-staging URLs and changes the Sign-on URL to include the application login path and domain parameter. It also clarifies that both Reply URL and Sign-on URL values are placeholders.

10 August 2026
18

What If Tool

Doc update

The Conditional Access What If tool table now uses a different sample UserId in all four examples.

28 August 2026

Manage App Consent Policies

Doc update

The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

28 August 2026

Manage App Consent Policies

Doc update

The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

28 August 2026

Grant Admin Consent

Doc update

The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.

28 August 2026

Grant Admin Consent

Doc update

The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.

28 August 2026

What If Tool

Doc update

The Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.

27 August 2026

Manage App Consent Policies

Doc update

The documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.

27 August 2026

Grant Admin Consent

Doc update

The grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.

27 August 2026

Prerequisites to validate and publish your app

Doc update

The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.

26 August 2026

Prerequisites to validate and publish your app

Doc update

The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.

26 August 2026

Howto Update Permissions

Doc update

The permission-addition and permission-removal examples now use different sample object and client IDs.

26 August 2026

Howto Update Permissions

Doc update

The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

26 August 2026

Howto Update Permissions

Doc update

The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.

26 August 2026

Howto Update Permissions

Doc update

The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.

26 August 2026

Howto Update Permissions

Doc update

The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.

25 August 2026
15

Microsoft Entra provisioning options (Preview)

Doc update

A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.

28 August 2026

Provision Microsoft Entra ID objects to AD

New feature

A new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.

28 August 2026

Group Source Of Authority Guidance

Doc update

The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.

28 August 2026

Primary Refresh Token

Doc update

The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.

25 August 2026

Secure add-on tenant creation

Doc update

The page title no longer includes “(preview),” and the prerelease product notice was removed.

22 August 2026

Quickstart - Access and create new tenant

Feature update

The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.

22 August 2026

Create New Tenant

Doc update

The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.

22 August 2026

Create New Tenant

Doc update

The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.

22 August 2026

Create New Tenant

Doc update

The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.

22 August 2026

Token Protection

Generally available

The documentation now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.

20 August 2026

Assign App Owners

Doc update

The documentation now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application scope.

19 August 2026

Concepts Replica Sets

Doc update

The documentation now states that replica sets require connectivity between all virtual networks hosting them. They are deployed in one Active Directory site and rely on a fully meshed virtual network topology for directory replication.

14 August 2026

Token Protection

Doc update

The page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. iOS/iPadOS browser support is not supported. The page also adds requirements for supported browsers, extensions, operating systems, and configurations.

10 August 2026

Token Protection

Doc update

The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.

7 August 2026
9

Protect M365 From On Premises Attacks

Doc update

The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.

28 August 2026

Road to the cloud: Introduction

Updated

Organizations are increasingly modernizing identity, access, and device management by reducing their dependence on on-premises Active Directory and adopting cloud-native capabilities in Microsoft Entra ID. Whether the goal is complete Active Directory retirement or a smaller, more secure on-premises footprint, this guidance helps you plan and execute that transformation.

1 August 2026
8

Clean broker state including certificates (requires sudo)

Feature updateAction required

Microsoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.

25 August 2026

Microsoft Entra ID: Passkey support for B2B users

New

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing resistance. This feature, enabled by default, rolls out from October 2026 to February 2027, requiring no admin action but recommending policy reviews to align user scopes and MFA settings.

21 August 2026
Message CenterMC1459133 on mc.merill.net ↗Stay informed

Token Protection Deployment Guide - Apple Platforms

Generally available

The guide removes the Preview designation, adds Microsoft Scout to the support matrix, and replaces detailed storage-flag instructions with updated Apple SSO plugin and Platform SSO guidance.

20 August 2026

Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

New

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.

11 August 2026
Message CenterMC1450133 on mc.merill.net ↗Stay informed

Token Protection

Doc update

The token protection article removes a screenshot of a Conditional Access policy requiring token protection as a session control. The Primary Refresh Token link remains.

10 August 2026

Token Protection deployment guide - Web apps (Preview)

Doc update

Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.

7 August 2026

Microsoft Entra ID: Replace MemberOf rules by November 3, 2026

New

Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.

5 August 2026
Message CenterMC1448379 on mc.merill.net ↗Major updatePlan for change
8

Manage Device Identities

Feature update

The documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.

25 August 2026

Tshoot Connect Sync Errors

Doc update

The troubleshooting guide now covers DataValidationFailed alongside IdentityDataValidationFailed, including cases where onPremisesObjectIdentifier changes during hard match operations. It also adds guidance for checking userPrincipalName formatting and using the documented hard match recovery paths.

20 August 2026

Tshoot Connect Sync Errors

Doc update

The troubleshooting documentation now directs administrators to the Hard match scenarios and recovery paths when DataValidationFailed occurs during a hard match operation, while retaining guidance to validate userPrincipalName characters and format.

20 August 2026

Connect to Microsoft Graph.

Doc update

The documentation now uses clearer commands to enable and verify `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`, and explicitly shows how to set it back to `$false` after remediation to re-enable hard match protection.

9 August 2026
2

Sla Performance

Doc update

The July row now includes an additional 99.999% value in the performance table; no product change is indicated.

8 August 2026
1

Discover identities in target applications with account discovery

Doc update

The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.

11 August 2026
1

Optional Claims

Doc update

The documentation now explains how to configure granular AMR values for SAML applications through the manifest or Microsoft Graph, since the admin center has no UI option for `include_granular_amr`. It also documents adding the `amr` claim to OIDC token types and clarifies that `include_granular_amr` applies only to SAML.

12 August 2026
1

SAM Account Name

Public preview

Enhanced synchronization can source sAMAccountName for hybrid users from onPremisesSamAccountName in Microsoft Entra ID. Existing domains retain current behavior until enabled; enabling updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation.

25 August 2026
14

Create Delete Agent Identities

Doc update

The documentation updates the C# sample’s imports, endpoint structure, downstream API call, and model declarations to provide valid create-agent-identity code.

14 August 2026

Call Api Microsoft Graph

Doc update

The documentation adds Microsoft Graph and Microsoft.Identity.Web imports, changes sample calls from Applications to Users, and clarifies that configured scopes must match the Graph resources used. Examples use User.Read and User.ReadBasic.All.

14 August 2026

Call Api Custom

Doc update

The documentation updates its C# examples, including distinct method names for UPN and object ID calls, a revised controller constructor signature, and clearer user-data method names.

14 August 2026

Microsoft Entra Sdk For Agent Identities

Doc update

The documentation now identifies app-only tokens as using client credentials, expands on-behalf-of to OBO, and consistently uses the `agent-identity-client-id` placeholder in request examples.

14 August 2026

Secure an Amazon Bedrock agent with Microsoft Entra Agent ID

Doc update

The Amazon Bedrock integration guide now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” in its description, explanations, container reference, and links. No behavior or availability change is described.

14 August 2026

Call Api Microsoft Graph

Doc update

The documentation adds an OpenID Connect using directive and renames two C# sample variables: `applications` to `applicationsForUser` and `me` to `meByOid`.

14 August 2026

Call Api Microsoft Graph

Doc update

The Agent ID Microsoft Graph documentation now labels sample variables as `usersAppOnly` and `usersOnBehalfOfUser`, clarifying the scenarios they represent.

14 August 2026

Microsoft Entra Sdk For Agent Identities

Doc update

The documentation replaces “Entra ID Auth SDK” with “Microsoft Entra ID Auth SDK” in two descriptions. The endpoint formats and behavior are unchanged.

14 August 2026

Agent Tokens

Doc update

The user delegation section now spells out “on-behalf-of (OBO)” on first use. No feature behavior or requirements changed in the supplied diff.

14 August 2026

Call Api Azure Services

Doc update

The code sample now uses `<your-tenant-id>` instead of `<your-tenant>` for the `TenantId` value.

14 August 2026

Call Api Custom

Doc update

The documentation now spells out “on-behalf-of (OBO)” on first use in the token scenario guidance. The referenced method is unchanged.

14 August 2026

Call Api Microsoft Graph

Doc update

The `TenantId` example value changed from `<my-test-tenant>` to `<your-tenant-id>` for clearer documentation.

14 August 2026

Configure Third Party Agents

Doc update

The third-party agents documentation now labels the sidecar setup link “Configure Microsoft Entra ID Auth SDK for agent identities” instead of “Configure Entra ID Auth SDK.”

14 August 2026

Grant Agent Access Microsoft 365

Doc update

The documentation now lists how an agent with its own identity can communicate through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, including the permissions required for inbound and outbound communication.

13 August 2026
10

Authentication protocols in agents

Doc update

The page description was shortened by removing the phrase “Key concepts.” The documented OAuth 2.0 protocols and token exchange patterns remain unchanged.

14 August 2026

Error Codes

Doc update

The error-code documentation now separates quota, blueprint, blueprint principal, agent identity, and agent identity creation errors, with clearer descriptions and table headings.

14 August 2026

Get the service principal for Microsoft Graph

Doc update

The documentation replaces inconsistent tenant placeholders with `<your-tenant-id>` and standardizes `<agent-blueprint-clientid>` to `<agent-blueprint-client-id>` in code samples.

14 August 2026

What Is Microsoft Entra Agent Id

Doc update

The page updates image accessibility text, refines wording about agent identities, and standardizes the name “Microsoft Entra ID Auth SDK (sidecar)” for third-party agent integrations.

14 August 2026

Validate agent identity tokens in a downstream API

Doc update

The documentation now refers to the “Microsoft Entra ID Auth SDK (sidecar)” instead of the “Microsoft Entra SDK auth sidecar.” The token-validation guidance is otherwise unchanged.

14 August 2026

Agent Token Claims

Doc update

The Agent ID token claims documentation no longer includes one `tid` claim table row.

14 August 2026
7

Agent Token Claims

Doc update

The documentation now shows different sample GUID values for the aud, appid, oid, sub, and tid claims.

27 August 2026

Integrate Aws Bedrock Agent

Doc update

The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.

14 August 2026

Create Delete Agent Identities

Doc update

The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.

14 August 2026

Manage agents in end user experience

Doc update

The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.

14 August 2026

Howto Delete Agent Identity

Doc update

The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.

14 August 2026

Howto Target Agent Identities

Doc update

The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.

7 August 2026

Howto Target Agent Identities

Doc update

The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.

7 August 2026
5

Security For Ai Overview

Doc update

The documentation now expands MCP, A2A, and OBO on first use to improve clarity and retrievability.

14 August 2026

Key Concepts

Doc update

The key concepts page now labels the link “Microsoft Entra Agent ID OAuth protocols” instead of “oauth protocols.”

14 August 2026

Inheritable Permissions

Doc update

The page no longer includes a TODO questioning support for enumerated scopes versus `allAllowed`/`none`. The diff provides no evidence of a product or feature change.

14 August 2026

Licensing Agent Id

Doc update

The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.

7 August 2026
3

Best Practices Agent Id

Doc update

The best-practices documentation now uses the full “Microsoft Entra Agent ID” and “Microsoft Entra ID” names in two recommendations. The guidance itself is unchanged.

14 August 2026

Integrate N8n Agent

Doc update

The n8n integration page now consistently calls the pattern “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK.”

14 August 2026

What Is Agent Id Platform

Doc update

The page’s bullet describing platforms and services that create agents retains the same wording and examples, including Copilot Studio, AWS Bedrock, and n8n. No substantive content change is shown.

14 August 2026
3

Best Practices Agent Id

Doc update

The documentation now recommends creating agent identities from an agent identity blueprint instead of using standard app registrations or service principals. It also adds .NET usage guidance and lists required roles and permission.

14 August 2026

Call Api Azure Services

Doc update

The documentation updates its C# examples, separating app-only, on-behalf-of-user, and user-identification scenarios. Samples now configure agent identity options and pass the credential to the Blob client correctly.

14 August 2026

Integrate Aws Bedrock Agent

Doc update

The guide updates “Entra” to “Microsoft Entra” in the diagram alt text, setup heading, and TENANT_ID descriptions. No technical procedure or feature change is shown.

14 August 2026
2

Plan Agent Identity Architecture

Doc update

The agent identity architecture planning page now links to the correct interactive agent authentication article instead of the previous broken path.

14 August 2026

Plan Agent Identity Architecture

Doc update

The documentation now explains that agents should use an agent identity blueprint and the `#Microsoft.Graph.AgentIdentity` object, rather than standard app-registration APIs. It also lists supported creation channels, roles, permissions, and .NET usage.

14 August 2026
2

Agent On Behalf Of Oauth Flow

Doc update

The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.

11 August 2026

Agent On Behalf Of Oauth Flow

Doc update

The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.

11 August 2026
1

Whats New Agent Id

Doc update

The Agent ID documentation now refers to the linked SDK as the “Microsoft Entra ID Auth SDK” instead of “Entra ID Auth SDK.”

14 August 2026
4

Identity Protection Policies

Doc update

The documentation now states that disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens.

15 August 2026

Identity Protection Policies

Doc update

The documentation replaces “Device disablement” with “Attacker-added device” and explains that the Entra device object is disabled, new token issuance is blocked, existing device-bound refresh tokens are revoked, and user sessions are revoked.

14 August 2026

Identity Protection Policies

Doc update

The documentation now describes a Device disablement response for users flagged by Microsoft threat intelligence as having an attacker-added device. The device is disabled, and the user is prompted to sign in from a trusted device.

14 August 2026

Connect Staged Rollout

Doc update

The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” No procedural content changed in the supplied diff.

12 August 2026
2

Licensing Conditional Access

Doc update

The documentation now lists two supported licensing options: Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.

7 August 2026

Licensing Conditional Access

Doc update

The documentation now states that Conditional Access for agents requires a Microsoft Agent 365 license to apply policies through Microsoft Entra Agent ID, replacing “Starting soon.”

7 August 2026
48

Create Tenant

Doc update

The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.

26 August 2026

Create Tenant

Feature updateAction required

The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.

26 August 2026

Understanding Lifecycle Workflows

Public preview

The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.

24 August 2026

Create Lifecycle Workflow

Public preview

Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.

24 August 2026

Lifecycle Workflow Execution Conditions

Public preview

Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.

24 August 2026

Entitlement Management Request Behalf

Doc update

The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.

24 August 2026

Create Lifecycle Workflow

Doc update

The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.

24 August 2026

Deploy Microsoft Entra Tenant Governance end to end

Feature update

The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.

22 August 2026

Create Lifecycle Workflow

New feature

The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.

22 August 2026

Create a governed workforce tenant

Feature update

The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.

22 August 2026

Automatic formation of governance relationships

Feature updateAction required

The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.

22 August 2026

Automatic formation of governance relationships

Feature update

The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.

22 August 2026

Create Tenant

Doc update

The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.

22 August 2026

Create Tenant

Feature update

The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).

22 August 2026

Create Tenant

Feature update

The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.

22 August 2026

Automatic Governance Relationships

Doc update

The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.

22 August 2026

Create Tenant

Doc update

The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.

22 August 2026

Create Tenant

Doc update

The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.

22 August 2026

Create Tenant

Doc update

The document’s `ms.author` metadata changed from `tafra00` to `tazkiaafra`.

22 August 2026

Create Tenant

Doc update

The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.

22 August 2026

Create Tenant

Doc update

The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.

22 August 2026

Create Tenant

Doc update

The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.

22 August 2026

Lifecycle Workflow Templates

Doc update

The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.

20 August 2026

Lifecycle Workflows Deployment

Feature update

The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.

20 August 2026

Lifecycle Workflows Tasks Table

Doc update

The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.

20 August 2026

Entitlement Management Access Package Request Policy

Doc update

The documentation now expands its guidance that administrators must verify users meet existing access package policy requirements before assigning them; otherwise, assignment may fail.

14 August 2026

Entitlement Management Access Package Request Policy

Doc update

The documentation removes an inaccurate statement implying that direct assignment to an access package requires approval. It now states only that assigned users must meet the policy’s eligibility requirements.

14 August 2026

Entitlement Management Access Package Assignments

Doc update

The access package assignments page no longer includes a note stating that assignment managers cannot bypass required approval settings or directly assign identities without approval.

14 August 2026

Entitlement Management Delegate

Doc update

The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.

14 August 2026

Catalog Access Reviews

Generally available

The documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.

13 August 2026

Catalog Access Reviews

Doc update

The page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.

13 August 2026

Licensing Governance

Doc update

The governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.

13 August 2026

Create configuration snapshots

New

Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence

1 August 2026

Create a configuration monitor

Updated

Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift

1 August 2026

Create a governed workforce tenant

Updated

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

1 August 2026

Automatic Governance Relationships

Updated

When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.

1 August 2026
6

Source Of Authority Overview

Doc update

The documentation now describes creating new cloud security groups in Microsoft Entra ID, provisioning them to AD DS as Universal groups, and updating applications to use the new group security identifiers.

28 August 2026

Understanding Lifecycle Workflows

Public preview

The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.

24 August 2026

Deployment Guide

Doc update

The secure tenant creation guidance now links the Microsoft Online Subscription Agreement (MOSA) reference alongside the existing Enterprise Agreement and Pay-As-You-Go links.

22 August 2026

Deployment Guide

Doc update

The deployment guide now refers to either a paid Enterprise Agreement or Pay-As-You-Go subscription and adds Microsoft Online Subscription Agreement terminology.

22 August 2026

Deployment Guide

Doc update

The secure tenant creation prerequisites were updated to clarify the required Azure Resource Manager permissions.

22 August 2026

Lifecycle Workflow Tasks

Feature update

The task now applies to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.

20 August 2026
2
1

Road To The Cloud Implement

Doc update

The guidance now links to a different Microsoft Entra Cloud Sync article for provisioning groups to Active Directory Domain Services.

28 August 2026
3

Sign In With Passkey

New feature

The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.

22 August 2026
3

Create Service Principal Cross Tenant

Doc update

The cross-tenant service principal article changes the example ServicePrincipalId from `bbbbbbbb-1111-2222-3333-cccccccccccc` to `aaaaaaaa-bbbb-cccc-1111-222222222222`.

27 August 2026

Allow Deny List

Doc update

The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.

14 August 2026
2

Configure cross-tenant synchronization

Doc update

The guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.

7 August 2026
1
3

Custom Proxy File Hosting

Doc update

The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.

11 August 2026

How to manage the Internet Access profile

Doc update

The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.

3 August 2026
2

Web filtering in Global Secure Access (V2)

Doc update

The documentation now explains that V2 selects the first applicable profile containing a V2 policy, does not support user or group targeting on individual rules, and may produce different enforcement from V1 during migration.

19 August 2026

Web filtering in Global Secure Access (V2)

Doc update

A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.

12 August 2026
4

How Managed Identities Work Vm

Doc update

The curl example now uses client_id `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous value.

28 August 2026

How Managed Identities Work Vm

Doc update

The VM managed identity documentation changes the client_id value in its curl token-request example.

28 August 2026

Federate a SPIFFE/SPIRE workload identity

Doc update

Adds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.

13 August 2026

Federate a Google Cloud workload identity

Doc update

Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.

13 August 2026
4

Set up a Flexible Federated identity credential (preview)

Feature updateAction required

The guidance now requires GitHub flexible federated identity credentials to match `sub` plus `repository_id`, `repository_owner_id`, or both. Portal and Microsoft Graph examples include these claims and optional workflow matching.

18 August 2026

Flexible federated identity credentials (preview)

Feature update

The documentation now states that GitHub flexible federated identity credentials must match `sub` and at least one immutable claim: `repository_id` or `repository_owner_id`. It also updates examples and operator support details.

18 August 2026
3

Hardening update to Microsoft Entra Connect Sync

Doc update

The documentation wording about the dedicated first-party application and service principal used for synchronization between Active Directory and Microsoft Entra ID was revised.

28 August 2026
2
1
1

Workload Identity Federation

Doc update

The concept page now points to first-party tutorials for Google Cloud and SPIFFE/SPIRE scenarios instead of the previous links. No product feature change is indicated.

13 August 2026
21

Version History

Doc updateAction required

The version-history section is now titled “Unsupported versions,” and guidance for version 1.5.612.0 or earlier recommends immediately updating to a newer version.

29 August 2026

Version History

RetirementAction required

The version history marks versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 as deprecated and instructs users of 1.5.612.0 or earlier to update immediately.

28 August 2026

Global Secure Access Client Release Notes

New feature

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

26 August 2026

Current Known Limitations

Doc update

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

26 August 2026

Current Known Limitations

Doc update

The documentation received a minor formatting change with no substantive content changes identified.

26 August 2026

Current Known Limitations

Doc update

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

26 August 2026

Global Secure Access Client for macOS Release Notes

New feature

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

24 August 2026

Install the Global Secure Access Client for macOS

Doc update

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

24 August 2026

Macos Client Release History

Doc update

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

24 August 2026

Global Secure Access Client for macOS Release Notes

Feature updateAction required

The release notes now document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes.

22 August 2026

Install the Global Secure Access Client for macOS

Doc update

The page no longer includes the note about `com.microsoft.autoupdate2` or the optional instruction to remove it from Intune detection rules. The metadata date and custom tag were also reverted.

22 August 2026

Install Macos Client

Doc update

The macOS client installation guidance now states that removing `com.microsoft.autoupdate2` from Intune detection rules is optional.

22 August 2026

Install Macos Client

Doc update

The documentation now warns that, starting with version 1.1.26060207, including the already-installed com.microsoft.autoupdate2 application in Intune detection rules might cause a conflict.

22 August 2026

Install Macos Client

Doc update

The macOS client installation guidance now clarifies that, starting with version 1.1.26060207, administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules.

22 August 2026

Macos Client Release History

Doc update

The macOS client release history now says administrators can optionally remove `com.microsoft.autoupdate2` from Intune detection rules; the app package includes this application.

22 August 2026

Migrate web content filtering policies from V1 to V2

Doc update

A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.

15 August 2026

Manage Microsoft Profile

Doc update

The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”

13 August 2026

Manage Microsoft Profile

Doc update

The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.

13 August 2026

Network Content Filtering

Doc update

The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.

5 August 2026
2

Netskope Integration

Doc update

The Netskope integration example now uses different values for the tenantId and userId fields.

25 August 2026

Web Filtering

Doc update

The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.

15 August 2026
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…