Product

Microsoft Entra ID

Track documentation and Message Center changes for Microsoft Entra ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra ID changes

App Gallery User Provisioning Requirements

Provisioning

The App Gallery provisioning requirements now instruct integrators to validate SCIM endpoints against the Microsoft Entra provisioning service and submit the results with their gallery submission.

Publish App Gallery

General

The documentation corrects list formatting and navigation numbering and adds a direct link to user provisioning validation instructions.

Scim Validator Tutorial

Standards

The tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.

Assignment Network

Authentication

The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.

Assignment Network

Authentication

The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.

Grant Admin Consent

Developer

The documentation examples now show revised object IDs for Microsoft Graph and other resource APIs while retaining the same consent scenarios and permissions.

Grant Admin Consent

Developer

The guide now uses different Microsoft Graph resource API object IDs in delegated- and application-permission consent examples; the documented permissions and consent type remain unchanged.

Group Source Of Authority Configure

General

The page now links to guidance on how provisioning from Microsoft Entra ID to Active Directory works and to a tutorial for governing access to an on-premises app.

Group Source Of Authority Guidance

Fundamentals

The guidance now links to the Microsoft Entra ID-to-Active Directory provisioning overview and its nested group membership behavior section.

Manage App Consent Policies

Developer

The consent policy documentation now lists revised application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

Manage App Consent Policies

Developer

The consent-policy documentation now lists new application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird.

Microsoft Entra prerequisites for AD (Preview)

Provisioning

Adds an article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises AD DS with Cloud Sync. It also links to configuration, testing, deployment, and agent-installation guidance.

Microsoft Entra provisioning behavior (Preview)

Provisioning

A new conceptual article describes how Cloud Sync scopes, matches, maps, and writes users, groups, and memberships from Microsoft Entra ID to AD DS, including anchor-based matching and user source-of-authority scenarios.

Microsoft Entra provisioning options (Preview)

Fundamentals

A new article compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also documents availability, domain and tenant configuration limits, and performance guidance.

Microsoft Entra provisioning setup (Preview)

Provisioning

The article now documents provisioning users and groups from Microsoft Entra ID to on-premises AD DS, including prerequisites, deployment options, scoping filters, attribute mappings, and testing. Users-only and users-and-groups options are marked Preview.

On Demand Provision

Provisioning

The article now states that it covers provisioning from Active Directory to Microsoft Entra ID and links to the separate article for provisioning from Microsoft Entra ID to Active Directory.

On-demand provisioning - Microsoft Entra ID to Active Directory

Provisioning

The guidance now describes testing Entra ID-to-Active Directory changes on a single user or group before enabling them broadly. It adds separate workflows, retains the five-member group limit, and explains result statuses, retries, and testing another object.

Plan Cloud Sync Topologies

Provisioning

The documentation updates diagram descriptions and the provisioning example link. It also clarifies that AD-provisioned group members must have AD accounts, including eligible cloud-managed users and cloud-created security groups; synchronized users still require onPremisesObjectIdentifier.

Preserve a group's organizational unit (Preview)

General

A new how-to explains how to create and populate a GroupDN directory extension so a group's original distinguished name is retained when its Source of Authority changes to Microsoft Entra ID.

Protect M365 From On Premises Attacks

Architecture

The guidance for controlling access to on-premises applications now links to the updated Microsoft Entra Cloud Sync documentation for provisioning groups to Active Directory.

Provision Microsoft Entra ID objects to AD

Fundamentals

A new overview explains how Cloud Sync provisions users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. User provisioning is in preview; group provisioning is generally available.

Sap Netweaver Tutorial

General

Two SAP Principal Propagation with Azure API Management references in the tutorial now use updated links; the surrounding guidance remains unchanged.

Sap Netweaver Tutorial

General

The tutorial updates two references to Azure API Management guidance for SAP Principal Propagation, including associated learning links.

Test Microsoft Entra provisioning (Preview)

Provisioning

A new guide documents testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting sync, and removing configurations. Group tests can include up to five members.

Tutorial Group Provisioning

Provisioning

The tutorial covering group provisioning to on-premises AD DS, scoping recommendations, and group/user SOA scenarios was deleted.

Tutorial: Govern access to an on-premises app (Preview)

Provisioning

The tutorial explains how Microsoft Entra Cloud Sync provisions cloud-managed users, a security group, and group membership to Active Directory Domain Services for access to a Kerberos-based on-premises application. User provisioning is identified as being in preview.

What If Tool

Developer

The Conditional Access What If tool table now uses a different sample UserId in all four examples.

Assign App Owners

General

The PowerShell example now uses a different sample ServicePrincipalId value in the New-MgServicePrincipalOwnerByRef command.

Assignment Network

Authentication

A link was fixed on the Conditional Access network assignment page.

Assignment Network

Authentication

The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.

Entra Id Scim Api Reference

Standards

The SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.

Exchange Hybrid

General

The article now describes Entra2ADExchangeOnlineAttributeWriteback (LES Writeback), including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.

Grant Admin Consent

Developer

The grant-admin-consent documentation updates the resource API object IDs shown in delegated- and application-permission examples.

Manage App Consent Policies

General

The examples now define cmdlet parameters in `$params` hashtables before creating custom consent policies and configuring inclusions or exclusions.

Manage App Consent Policies

Developer

The documented application IDs for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird were replaced.

What If Tool

Developer

The Conditional Access What If tool documentation replaces the sample UserId in four example rows with a new sample identifier.

Breaking Changes

Standards

The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.

Breaking Changes

Standards

The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.

Groups Settings V2 Cmdlets

Standards

The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.

Howto Update Permissions

Developer

The permission-addition and permission-removal examples now use different sample object and client IDs.

Howto Update Permissions

Developer

The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

Howto Update Permissions

Developer

The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.

Howto Update Permissions

Developer

The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.

Microsoft Entra: Domain update for My Account and identity self-service experiences

Message CenterMC1462460 on mc.merill.net ↗Plan for change
General

Microsoft Entra is updating its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft, consolidating related sites for a unified experience. The change rolls out worldwide in late November 2026. Users need no action; administrators should ensure *.cloud.microsoft domains are allowed in network policies.

Plan Sso Deployment

General

Removed an extra space from the Help desk admin row in the documentation table.

Prerequisites to validate and publish your app

Developer

The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.

Prerequisites to validate and publish your app

Developer

The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.

Publish your app to Microsoft Entra App Gallery

General

A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.

SSO requirements for Microsoft Entra App Gallery

Standards

Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.

Strengthen federated sign-in security

Authentication

The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.

Breaking Changes

Standards

The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

Clean broker state including certificates (requires sudo)

Conditional Access

Microsoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.

Howto Arc Sign In Windows

Authentication

The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.

Howto Arc Sign In Windows

Authentication

The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.

Howto Arc Sign In Windows

Authentication

The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.

Howto Arc Sign In Windows

Authentication

The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.

Howto Arc Sign In Windows

Authentication

The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.

Howto Update Permissions

Developer

The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.

Manage Device Identities

Troubleshooting

The documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.

Primary Refresh Token

Fundamentals

The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.

SAM Account Name

Security

Enhanced synchronization can source sAMAccountName for hybrid users from onPremisesSamAccountName in Microsoft Entra ID. Existing domains retain current behavior until enabled; enabling updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation.

Whats New Linux

General

Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.

Connect Health Agent Install

General

The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.

Connect Health Version History

General

The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.

Create New Tenant

Fundamentals

The Governed Workforce tenant creation guidance now links the Microsoft Online Subscription Agreement and related billing agreement references.

Create New Tenant

Fundamentals

The documentation now describes the requirement as an Enterprise Agreement (EA) or Pay-As-You-Go subscription and references MOSA and MCA billing agreements.

Create New Tenant

Fundamentals

The documentation refreshes troubleshooting guidance for creating Governed Workforce tenants, including paid Azure subscription and billing-account requirements.

Quickstart - Access and create new tenant

Fundamentals

The documentation now lists a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, replacing the previous MCA subscription requirement.

Secure add-on tenant creation

Fundamentals

The page title no longer includes “(preview),” and the prerelease product notice was removed.

Fido2 Hardware Vendor

Authentication

The security key entry’s table formatting was corrected by removing an extra space before a separator.

Fido2 Hardware Vendor

Authentication

Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.

Fido2 Hardware Vendor

Authentication

The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.

Fido2 Hardware Vendor

Authentication

The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.

Fido2 Hardware Vendor

Authentication

The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.

Microsoft Entra ID: Passkey support for B2B users

Message CenterMC1459133 on mc.merill.net ↗Stay informed
Conditional Access

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing resistance. This feature, enabled by default, rolls out from October 2026 to February 2027, requiring no admin action but recommending policy reviews to align user scopes and MFA settings.

Microsoft Entra ID: Retirement of custom CSS layout and positioning properties in company branding

Message CenterMC1458474 on mc.merill.net ↗Major updatePlan for change
Authentication

Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.

Optional Claims Reference

General

The reference now explicitly labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA.

Single Sign On Saml Protocol

Standards

The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.

Clear attribute values (Preview)

Provisioning

New documentation explains how provisioning can clear an existing target attribute when its source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.

Company Branding Css Template

Authentication

The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.

Customize Application Attributes

Provisioning

The documentation now states that null values are not sent by default. Clearing attribute values is available only in preview for API-driven inbound provisioning apps and isn’t supported for other provisioning scenarios.

Customize Branding

Authentication

The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.

Deployment Guide Token Protection Apple

Authentication

The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.

Inbound Provisioning Api Concepts

Standards

The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.

Inbound Provisioning Api Faqs

Provisioning

The FAQ now states that the /bulkUpload endpoint can clear existing user attributes and links to configuration guidance. It also clarifies that the endpoint cannot delete users and recommends Lifecycle Workflows for automated deletion after termination or disablement.

Licensing Service Plan Reference

General

The page now states that its information was last updated on August 19, 2026; the CSV download link remains unchanged.

Licensing Service Plan Reference

General

The page’s last-updated date now reads October 29, 2025, and two Teams Calling Plan names use “country/region” instead of “country.” The downloadable CSV link is unchanged.

Licensing Service Plan Reference

General

The document’s metadata date changed from July 1, 2026, to August 18, 2026. No product behavior or guidance changed.

Licensing Service Plan Reference

General

The reference was updated August 19, 2026, adding entries for several Dynamics 365 and Microsoft 365 plans and refreshing listed Microsoft 365 licensing rows.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…