<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Entra.News Daily summaries</title>
    <link>https://daily.entra.news/</link>
    <description>Plain-English daily summaries of Microsoft Entra documentation and Message Center changes.</description>
    <language>en</language>
    <atom:link href="https://daily.entra.news/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>App Gallery SCIM publishing guidance adds a 25-test Logic Apps validation workflow — 29 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-29/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-29/</guid>
      <pubDate>Sat, 29 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 29 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/" style="color:#11181d;text-decoration:none">App Gallery SCIM publishing guidance adds a 25-test Logic Apps validation workflow</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft published new preview guidance for validating SCIM user and group provisioning before Microsoft Entra App Gallery review. The workflow uses an Azure Logic Apps template, runs 25 tests, and requires submission of the results with a Logic App run ID. Related guidance now distinguishes ordinary SCIM endpoint testing from the validation evidence required for App Gallery publishing. Global Secure Access guidance separately flags version 1.5.612.0 or earlier as unsupported and recommends immediate updating. Most remaining changes were metadata, navigation, and cross-linking edits.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-validate-user-provisioning-for-microsoft-entra-app-gallery-preview-02" style="color:#11181d;text-decoration:none">Preview guidance defines the App Gallery validation workflow</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new guide explains how to validate SCIM user and group provisioning with an Azure Logic Apps template, run 25 tests, and submit the results with a Logic App run ID for App Gallery review. It documents both AI-agent and Azure portal setup methods.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-scim-validator-tutorial-10" style="color:#11181d;text-decoration:none">SCIM Validator guidance separates endpoint tests from gallery evidence</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated tutorial says the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-set-up-the-validation-logic-app-in-the-azure-portal-preview-03" style="color:#11181d;text-decoration:none">Portal instructions add the provisioning test-app setup sequence</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new setup guide covers creating an Entra Gallery Provisioning Test App, deploying the Azure Logic Apps validation template, configuring permissions and parameters, and running SCIM provisioning tests. It also points supporting teams to a verified tenant domain and Azure PowerShell or CLI workflow.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-troubleshoot-user-provisioning-validation-for-microsoft-entra-app-gallery-preview-01" style="color:#11181d;text-decoration:none">Troubleshooting guidance covers failed Logic Apps validation runs</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A companion preview article explains how to inspect failed validation runs and address common SCIM endpoint, authentication, permissions, filtering, and conflict errors before submission.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-version-history-04" style="color:#11181d;text-decoration:none">Global Secure Access flags older client versions for immediate updates</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The version-history guidance now uses an “Unsupported versions” section and recommends immediately updating Global Secure Access version 1.5.612.0 or earlier to a newer version.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-29/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 29 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 29 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/" style="color:#11181d;text-decoration:none">App Gallery SCIM publishing guidance adds a 25-test Logic Apps validation workflow</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft published new preview guidance for validating SCIM user and group provisioning before Microsoft Entra App Gallery review. The workflow uses an Azure Logic Apps template, runs 25 tests, and requires submission of the results with a Logic App run ID. Related guidance now distinguishes ordinary SCIM endpoint testing from the validation evidence required for App Gallery publishing. Global Secure Access guidance separately flags version 1.5.612.0 or earlier as unsupported and recommends immediate updating. Most remaining changes were metadata, navigation, and cross-linking edits.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-validate-user-provisioning-for-microsoft-entra-app-gallery-preview-02" style="color:#11181d;text-decoration:none">Preview guidance defines the App Gallery validation workflow</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new guide explains how to validate SCIM user and group provisioning with an Azure Logic Apps template, run 25 tests, and submit the results with a Logic App run ID for App Gallery review. It documents both AI-agent and Azure portal setup methods.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-scim-validator-tutorial-10" style="color:#11181d;text-decoration:none">SCIM Validator guidance separates endpoint tests from gallery evidence</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated tutorial says the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-set-up-the-validation-logic-app-in-the-azure-portal-preview-03" style="color:#11181d;text-decoration:none">Portal instructions add the provisioning test-app setup sequence</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new setup guide covers creating an Entra Gallery Provisioning Test App, deploying the Azure Logic Apps validation template, configuring permissions and parameters, and running SCIM provisioning tests. It also points supporting teams to a verified tenant domain and Azure PowerShell or CLI workflow.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-troubleshoot-user-provisioning-validation-for-microsoft-entra-app-gallery-preview-01" style="color:#11181d;text-decoration:none">Troubleshooting guidance covers failed Logic Apps validation runs</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A companion preview article explains how to inspect failed validation runs and address common SCIM endpoint, authentication, permissions, filtering, and conflict errors before submission.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-29/#doc-2026-08-29-version-history-04" style="color:#11181d;text-decoration:none">Global Secure Access flags older client versions for immediate updates</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The version-history guidance now uses an “Unsupported versions” section and recommends immediately updating Global Secure Access version 1.5.612.0 or earlier to a newer version.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-29/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 29 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Cloud-to-AD provisioning guidance separates generally available groups from preview users — 28 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-28/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-28/</guid>
      <pubDate>Fri, 28 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 28 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/" style="color:#11181d;text-decoration:none">Cloud-to-AD provisioning guidance separates generally available groups from preview users</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra’s Cloud Sync material now forms an end-to-end guide for provisioning users, groups, and memberships from Entra ID to on-premises AD DS. The new overview labels group provisioning generally available and user provisioning preview; companion guidance covers groups-only, users-only, and users-and-groups scoping, limits, filters, mappings, performance, prerequisites, and on-demand testing. A separate preview procedure preserves a group’s original distinguished name with a GroupDN directory extension when its source of authority changes to Microsoft Entra ID. Elsewhere, Global Secure Access marks four versions deprecated and tells users of version 1.5.612.0 or earlier to update immediately. Cloud Sync guidance also removes the obsolete Repair-AADCloudSyncToolsAccount procedure, while Conditional Access guidance states that Android Authenticator uses Google Play Integrity for jailbreak detection and denies requests when the API is unavailable unless the policy is disabled. Most remaining changes are routine example-ID, link, and reference maintenance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-provision-microsoft-entra-id-objects-to-ad-06" style="color:#11181d;text-decoration:none">Cloud Sync overview sets group GA and user preview boundaries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new overview covers provisioning users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. It explicitly states that group provisioning is generally available while user provisioning is in preview.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-microsoft-entra-provisioning-options-preview-01" style="color:#11181d;text-decoration:none">Three provisioning scopes are documented with filters and limits</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The preview guidance compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also records availability, domain and tenant configuration limits, and performance guidance to help administrators choose an appropriate scope and avoid unnecessary processing.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-test-microsoft-entra-provisioning-preview-05" style="color:#11181d;text-decoration:none">On-demand testing can validate objects before broad synchronization</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new testing guide covers testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting synchronization, and removing configurations. A group test can include up to five members.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-preserve-a-group-s-organizational-unit-preview-04" style="color:#11181d;text-decoration:none">GroupDN setup preserves distinguished names across source-of-authority changes</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The preview how-to explains how to create and populate a GroupDN directory extension so a group’s original distinguished name is retained when its source of authority changes to Microsoft Entra ID. The one-time setup includes Universal scope, extension creation, and attribute mapping.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-version-history-08" style="color:#11181d;text-decoration:none">Global Secure Access version history marks four versions deprecated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 are marked deprecated. Users of version 1.5.612.0 or earlier are instructed to update immediately.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-28/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 28 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 28 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/" style="color:#11181d;text-decoration:none">Cloud-to-AD provisioning guidance separates generally available groups from preview users</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra’s Cloud Sync material now forms an end-to-end guide for provisioning users, groups, and memberships from Entra ID to on-premises AD DS. The new overview labels group provisioning generally available and user provisioning preview; companion guidance covers groups-only, users-only, and users-and-groups scoping, limits, filters, mappings, performance, prerequisites, and on-demand testing. A separate preview procedure preserves a group’s original distinguished name with a GroupDN directory extension when its source of authority changes to Microsoft Entra ID. Elsewhere, Global Secure Access marks four versions deprecated and tells users of version 1.5.612.0 or earlier to update immediately. Cloud Sync guidance also removes the obsolete Repair-AADCloudSyncToolsAccount procedure, while Conditional Access guidance states that Android Authenticator uses Google Play Integrity for jailbreak detection and denies requests when the API is unavailable unless the policy is disabled. Most remaining changes are routine example-ID, link, and reference maintenance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-provision-microsoft-entra-id-objects-to-ad-06" style="color:#11181d;text-decoration:none">Cloud Sync overview sets group GA and user preview boundaries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new overview covers provisioning users, groups, and memberships from Microsoft Entra ID to on-premises AD, including supported scenarios, configuration options, synchronization behavior, and limitations. It explicitly states that group provisioning is generally available while user provisioning is in preview.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-microsoft-entra-provisioning-options-preview-01" style="color:#11181d;text-decoration:none">Three provisioning scopes are documented with filters and limits</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The preview guidance compares groups-only, users-only, and users-and-groups provisioning through scoping filters. It also records availability, domain and tenant configuration limits, and performance guidance to help administrators choose an appropriate scope and avoid unnecessary processing.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-test-microsoft-entra-provisioning-preview-05" style="color:#11181d;text-decoration:none">On-demand testing can validate objects before broad synchronization</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new testing guide covers testing users or groups on demand, reviewing safeguards and notifications, enabling configurations, handling quarantines, restarting synchronization, and removing configurations. A group test can include up to five members.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-preserve-a-group-s-organizational-unit-preview-04" style="color:#11181d;text-decoration:none">GroupDN setup preserves distinguished names across source-of-authority changes</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The preview how-to explains how to create and populate a GroupDN directory extension so a group’s original distinguished name is retained when its source of authority changes to Microsoft Entra ID. The one-time setup includes Universal scope, extension creation, and attribute mapping.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-28/#doc-2026-08-28-version-history-08" style="color:#11181d;text-decoration:none">Global Secure Access version history marks four versions deprecated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Versions 1.5.612.0, 1.5.402.0, 1.5.132.0, and 1.5.36.0 are marked deprecated. Users of version 1.5.612.0 or earlier are instructed to update immediately.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-28/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 28 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>LES Writeback, Android Play Integrity, and SCIM mailNickname rules sharpen Entra guidance — 27 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-27/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-27/</guid>
      <pubDate>Thu, 27 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 27 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/" style="color:#11181d;text-decoration:none">LES Writeback, Android Play Integrity, and SCIM mailNickname rules sharpen Entra guidance</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period was dominated by ordinary documentation maintenance—sample GUIDs, example identifiers, a corrected link, and PowerShell example syntax. The substantive updates were clearer Conditional Access guidance for Android integrity checks, new Exchange Hybrid detail on LES Writeback, and a precise SCIM description of how Entra ID handles mailNickname during user creation.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-assignment-network-08" style="color:#11181d;text-decoration:none">Conditional Access guidance documents Android Play Integrity enforcement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Assignment Network guidance now says Microsoft Authenticator for Android uses the Google Play Integrity API for jailbreak detection and denies access when the API is unavailable, unless the policy is disabled. Use this detail when troubleshooting blocked Android access under Conditional Access.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-exchange-hybrid-03" style="color:#11181d;text-decoration:none">Exchange Hybrid guidance adds Entra2ADExchangeOnlineAttributeWriteback detail</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The article now documents Entra2ADExchangeOnlineAttributeWriteback, also called LES Writeback, including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-entra-id-scim-api-reference-01" style="color:#11181d;text-decoration:none">SCIM reference clarifies mailNickname creation and PATCH limits</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">When creating a user, mailNickname may be omitted, null, or empty. Entra ID derives it from the characters before the first @ in userName, and after creation it cannot be removed with PATCH.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-manage-app-consent-policies-14" style="color:#11181d;text-decoration:none">Consent policy examples replace documented application IDs</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Manage App Consent Policies guidance replaces the application IDs shown for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird. Administrators using those identifiers in consent-policy rules should verify them against the updated examples.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-27/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 27 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 27 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/" style="color:#11181d;text-decoration:none">LES Writeback, Android Play Integrity, and SCIM mailNickname rules sharpen Entra guidance</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period was dominated by ordinary documentation maintenance—sample GUIDs, example identifiers, a corrected link, and PowerShell example syntax. The substantive updates were clearer Conditional Access guidance for Android integrity checks, new Exchange Hybrid detail on LES Writeback, and a precise SCIM description of how Entra ID handles mailNickname during user creation.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-assignment-network-08" style="color:#11181d;text-decoration:none">Conditional Access guidance documents Android Play Integrity enforcement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Assignment Network guidance now says Microsoft Authenticator for Android uses the Google Play Integrity API for jailbreak detection and denies access when the API is unavailable, unless the policy is disabled. Use this detail when troubleshooting blocked Android access under Conditional Access.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-exchange-hybrid-03" style="color:#11181d;text-decoration:none">Exchange Hybrid guidance adds Entra2ADExchangeOnlineAttributeWriteback detail</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The article now documents Entra2ADExchangeOnlineAttributeWriteback, also called LES Writeback, including its cloud-managed attribute flow, distinction from Exchange hybrid writeback, supported attributes, mappings, and related guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-entra-id-scim-api-reference-01" style="color:#11181d;text-decoration:none">SCIM reference clarifies mailNickname creation and PATCH limits</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">When creating a user, mailNickname may be omitted, null, or empty. Entra ID derives it from the characters before the first @ in userName, and after creation it cannot be removed with PATCH.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-27/#doc-2026-08-27-manage-app-consent-policies-14" style="color:#11181d;text-decoration:none">Consent policy examples replace documented application IDs</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Manage App Consent Policies guidance replaces the application IDs shown for Apple Mail, Spark Email, eM Client, Android-Samsung, Android-Mail, and Thunderbird. Administrators using those identifiers in consent-policy rules should verify them against the updated examples.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-27/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 27 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra self-service identity management shifts to cloud.microsoft worldwide in late November — 26 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-26/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-26/</guid>
      <pubDate>Wed, 26 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 26 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/" style="color:#11181d;text-decoration:none">Entra self-service identity management shifts to cloud.microsoft worldwide in late November</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra will move its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft worldwide in late November 2026. Global Secure Access release notes also set out automatic Windows Update upgrades for eligible clients beginning in November, while new App Gallery guidance and revised administration documentation clarify publishing, group creation, and tenant-creation requirements.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#MC1462460" style="color:#11181d;text-decoration:none">Self-service identity sites move to cloud.microsoft in late November</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra is updating the self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft and consolidating related sites. The worldwide rollout is planned for late November 2026; users need no action, but administrators should allow *.cloud.microsoft in network policies.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-global-secure-access-client-release-notes-27" style="color:#11181d;text-decoration:none">Eligible Global Secure Access Windows clients will receive automatic upgrades</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Starting in November 2026, eligible Windows clients will receive Global Secure Access upgrades through Windows Update. Version 2.32.294 adds Prefer local network, faster tunnel creation, and other fixes and improvements. Administrators opting out must use the documented installer parameter and maintain updates manually.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-publish-your-app-to-microsoft-entra-app-gallery-01" style="color:#11181d;text-decoration:none">New App Gallery workflow details validation, submission, and review</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new tutorial documents the self-service publishing workflow: complete validation prerequisites, create a submission, select capabilities, provide required application details, submit for Microsoft review, and track drafts. The guidance is primarily relevant to administrators supporting application publishers.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-create-tenant-24" style="color:#11181d;text-decoration:none">Tenant Creator is required regardless of the tenant restriction setting</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Create Tenant guidance now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting. Accounts expected to create add-on tenants therefore need that role.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-groups-settings-v2-cmdlets-25" style="color:#11181d;text-decoration:none">SSGM guidance scopes its control to the My Groups portal</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Groups Settings V2 guidance now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed from the documentation.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-26/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 26 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 26 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/" style="color:#11181d;text-decoration:none">Entra self-service identity management shifts to cloud.microsoft worldwide in late November</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra will move its self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft worldwide in late November 2026. Global Secure Access release notes also set out automatic Windows Update upgrades for eligible clients beginning in November, while new App Gallery guidance and revised administration documentation clarify publishing, group creation, and tenant-creation requirements.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#MC1462460" style="color:#11181d;text-decoration:none">Self-service identity sites move to cloud.microsoft in late November</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra is updating the self-service identity management domain from myaccount.microsoft.com to myaccount.cloud.microsoft and consolidating related sites. The worldwide rollout is planned for late November 2026; users need no action, but administrators should allow *.cloud.microsoft in network policies.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-global-secure-access-client-release-notes-27" style="color:#11181d;text-decoration:none">Eligible Global Secure Access Windows clients will receive automatic upgrades</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Starting in November 2026, eligible Windows clients will receive Global Secure Access upgrades through Windows Update. Version 2.32.294 adds Prefer local network, faster tunnel creation, and other fixes and improvements. Administrators opting out must use the documented installer parameter and maintain updates manually.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-publish-your-app-to-microsoft-entra-app-gallery-01" style="color:#11181d;text-decoration:none">New App Gallery workflow details validation, submission, and review</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new tutorial documents the self-service publishing workflow: complete validation prerequisites, create a submission, select capabilities, provide required application details, submit for Microsoft review, and track drafts. The guidance is primarily relevant to administrators supporting application publishers.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-create-tenant-24" style="color:#11181d;text-decoration:none">Tenant Creator is required regardless of the tenant restriction setting</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Create Tenant guidance now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting. Accounts expected to create add-on tenants therefore need that role.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-26/#doc-2026-08-26-groups-settings-v2-cmdlets-25" style="color:#11181d;text-decoration:none">SSGM guidance scopes its control to the My Groups portal</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Groups Settings V2 guidance now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed from the documentation.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-26/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 26 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Linux broker 2.0.2 now uses Entra join for device trust — 25 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-25/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-25/</guid>
      <pubDate>Tue, 25 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 25 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/" style="color:#11181d;text-decoration:none">Linux broker 2.0.2 now uses Entra join for device trust</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential update affects Microsoft Single Sign-On for Linux: version 2.0.2 and later uses Microsoft Entra join instead of device registration for device trust, and existing upgraded devices must be re-joined and re-enrolled. New Entra ID guidance also details enhanced synchronization for sourcing sAMAccountName. Most remaining updates are mechanical example-ID, browser-reference, or wording changes.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/#doc-2026-08-25-whats-new-linux-04" style="color:#11181d;text-decoration:none">Linux broker 2.0.2 switches device trust from registration to join</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Single Sign-On for Linux version 2.0.2 and later uses Microsoft Entra join for device trust. Existing upgraded devices must be re-joined and re-enrolled, with the documented upgrade process covering broker-state removal, reinstallation, and device re-join.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/#doc-2026-08-25-sam-account-name-01" style="color:#11181d;text-decoration:none">Enhanced synchronization can source sAMAccountName for hybrid users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">New guidance documents sourcing hybrid users’ sAMAccountName from onPremisesSamAccountName. Existing domains retain current behavior until the setting is enabled; enabling it updates existing hybrid users during synchronization. Cloud-only users without the source value continue using mailNickname-based generation.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/#doc-2026-08-25-howto-arc-sign-in-windows-14" style="color:#11181d;text-decoration:none">Arc sign-in guidance limits the scenario to machines without another domain</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The revised guidance states that enabling sign-in joins an Arc-enabled machine to Microsoft Entra and is intended for machines not planned to join another domain, including on-premises Active Directory or Microsoft Entra Domain Services. Administrators should confirm domain-join plans before enabling the capability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-25/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 25 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 25 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/" style="color:#11181d;text-decoration:none">Linux broker 2.0.2 now uses Entra join for device trust</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential update affects Microsoft Single Sign-On for Linux: version 2.0.2 and later uses Microsoft Entra join instead of device registration for device trust, and existing upgraded devices must be re-joined and re-enrolled. New Entra ID guidance also details enhanced synchronization for sourcing sAMAccountName. Most remaining updates are mechanical example-ID, browser-reference, or wording changes.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/#doc-2026-08-25-whats-new-linux-04" style="color:#11181d;text-decoration:none">Linux broker 2.0.2 switches device trust from registration to join</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Single Sign-On for Linux version 2.0.2 and later uses Microsoft Entra join for device trust. Existing upgraded devices must be re-joined and re-enrolled, with the documented upgrade process covering broker-state removal, reinstallation, and device re-join.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/#doc-2026-08-25-sam-account-name-01" style="color:#11181d;text-decoration:none">Enhanced synchronization can source sAMAccountName for hybrid users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">New guidance documents sourcing hybrid users’ sAMAccountName from onPremisesSamAccountName. Existing domains retain current behavior until the setting is enabled; enabling it updates existing hybrid users during synchronization. Cloud-only users without the source value continue using mailNickname-based generation.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-25/#doc-2026-08-25-howto-arc-sign-in-windows-14" style="color:#11181d;text-decoration:none">Arc sign-in guidance limits the scenario to machines without another domain</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The revised guidance states that enabling sign-in joins an Arc-enabled machine to Microsoft Entra and is intended for machines not planned to join another domain, including on-premises Active Directory or Microsoft Entra Domain Services. Administrators should confirm domain-join plans before enabling the capability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-25/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 25 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>First-factor system-preferred authentication rolls out as Lifecycle Workflow guidance expands to 365 days — 24 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-24/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-24/</guid>
      <pubDate>Mon, 24 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 24 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/" style="color:#11181d;text-decoration:none">First-factor system-preferred authentication rolls out as Lifecycle Workflow guidance expands to 365 days</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra is applying system-preferred authentication to first-factor sign-ins for tenants in the Microsoft-managed state, with rollout continuing through late September 2026. ID Governance guidance now documents 365-day event offsets and clarifies the Time based attribute V2 trigger, while Global Secure Access records an August macOS client release with new controls and deployment considerations. Most remaining updates are documentation maintenance, including Connect Health version and download references and lifecycle-page reorganization.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#MC1411574" style="color:#11181d;text-decoration:none">System-preferred authentication now covers first-factor sign-ins</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">For tenants in the Microsoft-managed state, Microsoft Entra now selects the most secure registered authentication method for first-factor sign-ins. Rollout runs from late June through late September 2026; administrators can keep or change the setting and should update user guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-lifecycle-workflow-execution-conditions-06" style="color:#11181d;text-decoration:none">Lifecycle Workflow guidance documents 365-day event offsets</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Execution Conditions page now states that the limits for Days from event, and Days to event when using Between, increased from 180 to 365 days. It describes conditions up to one year before or after an event and states that no administrator action is required.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-understanding-lifecycle-workflows-12" style="color:#11181d;text-decoration:none">Time based attribute V2 guidance clarifies comparisons and catch-up behavior</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The documentation describes Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after supported date attributes. It also says both the workflow and schedule must be enabled, V2 has no three-day catch-up window, and the preview admin center may show two choices representing the same trigger.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-global-secure-access-client-for-macos-release-notes-05" style="color:#11181d;text-decoration:none">Global Secure Access macOS release adds controls and Secure DNS bypass</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Release notes for August 21, 2026 list Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass, along with connectivity, sign-in, tunnel, cache-reset, and crash fixes. Administrators should review the release when planning macOS deployments.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-install-the-global-secure-access-client-for-macos-04" style="color:#11181d;text-decoration:none">macOS installation guidance flags an Intune detection conflict</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The installation page states that client version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It advises optionally removing that app from the Included apps list.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-24/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 24 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 24 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/" style="color:#11181d;text-decoration:none">First-factor system-preferred authentication rolls out as Lifecycle Workflow guidance expands to 365 days</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra is applying system-preferred authentication to first-factor sign-ins for tenants in the Microsoft-managed state, with rollout continuing through late September 2026. ID Governance guidance now documents 365-day event offsets and clarifies the Time based attribute V2 trigger, while Global Secure Access records an August macOS client release with new controls and deployment considerations. Most remaining updates are documentation maintenance, including Connect Health version and download references and lifecycle-page reorganization.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#MC1411574" style="color:#11181d;text-decoration:none">System-preferred authentication now covers first-factor sign-ins</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">For tenants in the Microsoft-managed state, Microsoft Entra now selects the most secure registered authentication method for first-factor sign-ins. Rollout runs from late June through late September 2026; administrators can keep or change the setting and should update user guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-lifecycle-workflow-execution-conditions-06" style="color:#11181d;text-decoration:none">Lifecycle Workflow guidance documents 365-day event offsets</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Execution Conditions page now states that the limits for Days from event, and Days to event when using Between, increased from 180 to 365 days. It describes conditions up to one year before or after an event and states that no administrator action is required.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-understanding-lifecycle-workflows-12" style="color:#11181d;text-decoration:none">Time based attribute V2 guidance clarifies comparisons and catch-up behavior</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The documentation describes Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after supported date attributes. It also says both the workflow and schedule must be enabled, V2 has no three-day catch-up window, and the preview admin center may show two choices representing the same trigger.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-global-secure-access-client-for-macos-release-notes-05" style="color:#11181d;text-decoration:none">Global Secure Access macOS release adds controls and Secure DNS bypass</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Release notes for August 21, 2026 list Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass, along with connectivity, sign-in, tunnel, cache-reset, and crash fixes. Administrators should review the release when planning macOS deployments.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-24/#doc-2026-08-24-install-the-global-secure-access-client-for-macos-04" style="color:#11181d;text-decoration:none">macOS installation guidance flags an Intune detection conflict</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The installation page states that client version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It advises optionally removing that app from the Included apps list.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-24/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 24 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>External ID guidance details delegated API for customer-owned passkeys — 22 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-22/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-22/</guid>
      <pubDate>Sat, 22 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 22 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/" style="color:#11181d;text-decoration:none">External ID guidance details delegated API for customer-owned passkeys</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">A new External ID reference describes delegated credential management for signed-in customers’ passkeys, while ID Governance guidance now spells out the billing, role, and policy prerequisites for governed workforce tenant creation. Global Secure Access also records macOS client version 1.1.26060207, including Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and fixes. Most remaining changes refine terminology, links, and procedures; one Rouse Sales provisioning tutorial was removed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-microsoft-entra-external-id-credential-management-api-reference-01" style="color:#11181d;text-decoration:none">Delegated passkey management API is now documented for External ID customer apps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Applications can use delegated access tokens to list, register, and delete signed-in customers’ passkeys. The service principal must be provisioned manually, and app-only tokens aren&#039;t supported.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-create-a-governed-workforce-tenant-33" style="color:#11181d;text-decoration:none">Governed workforce tenant guidance now specifies paid billing and role prerequisites</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The guidance specifies a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, along with the required tenant-creation permission, role, and default governance-policy prerequisites. Free or trial tenants cannot create additional tenants.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-create-tenant-06" style="color:#11181d;text-decoration:none">Governing-tenant default policy template is now optional in creation guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The governing tenant’s default governance policy template is labeled optional rather than required. The tenant-creation service still uses only the template with ID `default`.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-global-secure-access-client-for-macos-release-notes-17" style="color:#11181d;text-decoration:none">Global Secure Access macOS notes add version 1.1.26060207 deployment details</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The release notes document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes. The Intune deployment guidance says to remove `com.microsoft.autoupdate2` from detection rules.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-22/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 22 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 22 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/" style="color:#11181d;text-decoration:none">External ID guidance details delegated API for customer-owned passkeys</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">A new External ID reference describes delegated credential management for signed-in customers’ passkeys, while ID Governance guidance now spells out the billing, role, and policy prerequisites for governed workforce tenant creation. Global Secure Access also records macOS client version 1.1.26060207, including Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and fixes. Most remaining changes refine terminology, links, and procedures; one Rouse Sales provisioning tutorial was removed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-microsoft-entra-external-id-credential-management-api-reference-01" style="color:#11181d;text-decoration:none">Delegated passkey management API is now documented for External ID customer apps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Applications can use delegated access tokens to list, register, and delete signed-in customers’ passkeys. The service principal must be provisioned manually, and app-only tokens aren&#039;t supported.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-create-a-governed-workforce-tenant-33" style="color:#11181d;text-decoration:none">Governed workforce tenant guidance now specifies paid billing and role prerequisites</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The guidance specifies a paid Azure subscription associated with an Enterprise Agreement or pay-as-you-go billing account, along with the required tenant-creation permission, role, and default governance-policy prerequisites. Free or trial tenants cannot create additional tenants.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-create-tenant-06" style="color:#11181d;text-decoration:none">Governing-tenant default policy template is now optional in creation guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The governing tenant’s default governance policy template is labeled optional rather than required. The tenant-creation service still uses only the template with ID `default`.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-22/#doc-2026-08-22-global-secure-access-client-for-macos-release-notes-17" style="color:#11181d;text-decoration:none">Global Secure Access macOS notes add version 1.1.26060207 deployment details</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The release notes document version 1.1.26060207, released August 21, 2026, with Home Network traffic control, a Connections page, agentic detection support, Secure DNS bypass, and several fixes. The Intune deployment guidance says to remove `com.microsoft.autoupdate2` from detection rules.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-22/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 22 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Custom CSS branding faces late-October retirement after July 21 new-use cutoff — 21 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-21/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-21/</guid>
      <pubDate>Fri, 21 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 21 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/" style="color:#11181d;text-decoration:none">Custom CSS branding faces late-October retirement after July 21 new-use cutoff</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra’s most consequential change is the planned retirement of custom CSS layout and positioning properties in company branding by late October 2026. The schedule blocks new use from July 21, 2026, and affected branding will revert to default layouts after retirement. Other updates primarily refresh FIDO2 hardware references and clarify authentication terminology.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#MC1458474" style="color:#11181d;text-decoration:none">Custom CSS company-branding properties will retire in late October</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. New use is blocked from July 21, 2026, and branding will revert to default layouts after retirement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-fido2-hardware-vendor-08" style="color:#11181d;text-decoration:none">FIDO attestation data now reflects Metadata Service version 275</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The FIDO2 hardware reference now reflects FIDO Metadata Service version 275, with updated model entries, AAGUIDs, capability indicators, and newly listed authenticators. Use the refreshed table to verify hardware eligibility and supported capabilities.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-fido2-hardware-vendor-07" style="color:#11181d;text-decoration:none">Compatibility indicators change for several FIDO2 vendor entries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Compatibility indicators were updated for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators, while multiple vendor entries were removed. Use the revised compatibility table when evaluating or deploying FIDO2 authenticators.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-single-sign-on-saml-protocol-01" style="color:#11181d;text-decoration:none">SAML guidance now labels synced passkeys as phishing-resistant MFA</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The SAML protocol reference now labels synced passkeys as phishing-resistant MFA and clarifies that the certificate-based authentication designation applies to multi-factor CBA. The associated SAML mappings are unchanged.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-optional-claims-reference-02" style="color:#11181d;text-decoration:none">Optional claims reference explicitly identifies PRMFA authentication entries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Optional Claims Reference now labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA. The clearer labels help distinguish authentication methods when interpreting optional claims.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-21/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 21 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 21 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/" style="color:#11181d;text-decoration:none">Custom CSS branding faces late-October retirement after July 21 new-use cutoff</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra’s most consequential change is the planned retirement of custom CSS layout and positioning properties in company branding by late October 2026. The schedule blocks new use from July 21, 2026, and affected branding will revert to default layouts after retirement. Other updates primarily refresh FIDO2 hardware references and clarify authentication terminology.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#MC1458474" style="color:#11181d;text-decoration:none">Custom CSS company-branding properties will retire in late October</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. New use is blocked from July 21, 2026, and branding will revert to default layouts after retirement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-fido2-hardware-vendor-08" style="color:#11181d;text-decoration:none">FIDO attestation data now reflects Metadata Service version 275</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The FIDO2 hardware reference now reflects FIDO Metadata Service version 275, with updated model entries, AAGUIDs, capability indicators, and newly listed authenticators. Use the refreshed table to verify hardware eligibility and supported capabilities.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-fido2-hardware-vendor-07" style="color:#11181d;text-decoration:none">Compatibility indicators change for several FIDO2 vendor entries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Compatibility indicators were updated for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators, while multiple vendor entries were removed. Use the revised compatibility table when evaluating or deploying FIDO2 authenticators.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-single-sign-on-saml-protocol-01" style="color:#11181d;text-decoration:none">SAML guidance now labels synced passkeys as phishing-resistant MFA</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The SAML protocol reference now labels synced passkeys as phishing-resistant MFA and clarifies that the certificate-based authentication designation applies to multi-factor CBA. The associated SAML mappings are unchanged.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-21/#doc-2026-08-21-optional-claims-reference-02" style="color:#11181d;text-decoration:none">Optional claims reference explicitly identifies PRMFA authentication entries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Optional Claims Reference now labels synced passkeys as PRMFA and specifies that the PRMFA certificate-based authentication entry applies to multi-factor CBA. The clearer labels help distinguish authentication methods when interpreting optional claims.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-21/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 21 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Custom CSS branding guidance spells out July 21 cutoff and property retirement — 20 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-20/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-20/</guid>
      <pubDate>Thu, 20 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 20 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/" style="color:#11181d;text-decoration:none">Custom CSS branding guidance spells out July 21 cutoff and property retirement</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Most of the day&#039;s entries were documentation maintenance, but several updates have direct planning or configuration implications. Entra ID branding guidance says tenants created after January 5, 2026, cannot use custom CSS, older tenants not already using it cannot configure it after July 21, 2026, and custom CSS layout and positioning properties are being retired. A new federated sign-in page documents cross-root-domain blocking and related Microsoft Graph beta APIs; provisioning, Token Protection, and Lifecycle Workflows also received substantive guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-customize-branding-20" style="color:#11181d;text-decoration:none">Company branding CSS restrictions and retirement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Entra ID branding guidance says tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants that were not already using it cannot configure it; support for custom CSS layout and positioning properties is being retired.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-strengthen-federated-sign-in-security-01" style="color:#11181d;text-decoration:none">Federated sign-in security policy guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Entra ID page explains that the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents related Microsoft Graph beta APIs, which are subject to change and unsupported for production applications.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-clear-attribute-values-preview-02" style="color:#11181d;text-decoration:none">Inbound provisioning null-value clearing preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">New Entra ID provisioning guidance documents clearing an existing target attribute when the source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-token-protection-25" style="color:#11181d;text-decoration:none">Apple Token Protection support status</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID Token Protection reference now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-lifecycle-workflow-tasks-03" style="color:#11181d;text-decoration:none">Mover workflow access-removal timing</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">ID Governance task guidance now applies “Remove all access package assignments for user” to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-20/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 20 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 20 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/" style="color:#11181d;text-decoration:none">Custom CSS branding guidance spells out July 21 cutoff and property retirement</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Most of the day&#039;s entries were documentation maintenance, but several updates have direct planning or configuration implications. Entra ID branding guidance says tenants created after January 5, 2026, cannot use custom CSS, older tenants not already using it cannot configure it after July 21, 2026, and custom CSS layout and positioning properties are being retired. A new federated sign-in page documents cross-root-domain blocking and related Microsoft Graph beta APIs; provisioning, Token Protection, and Lifecycle Workflows also received substantive guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-customize-branding-20" style="color:#11181d;text-decoration:none">Company branding CSS restrictions and retirement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Entra ID branding guidance says tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants that were not already using it cannot configure it; support for custom CSS layout and positioning properties is being retired.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-strengthen-federated-sign-in-security-01" style="color:#11181d;text-decoration:none">Federated sign-in security policy guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Entra ID page explains that the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents related Microsoft Graph beta APIs, which are subject to change and unsupported for production applications.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-clear-attribute-values-preview-02" style="color:#11181d;text-decoration:none">Inbound provisioning null-value clearing preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">New Entra ID provisioning guidance documents clearing an existing target attribute when the source value is null or empty. The capability is opt-in, requires enabling “Flow null values” on both source and target mappings, and supports only single-valued attributes in specified inbound scenarios.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-token-protection-25" style="color:#11181d;text-decoration:none">Apple Token Protection support status</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID Token Protection reference now lists token protection for iOS/iPadOS and macOS as generally available. Supported web apps accessing Azure Resource Manager on macOS remain in preview.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-20/#doc-2026-08-20-lifecycle-workflow-tasks-03" style="color:#11181d;text-decoration:none">Mover workflow access-removal timing</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">ID Governance task guidance now applies “Remove all access package assignments for user” to both leaver and mover templates. For mover templates, scheduled removal defaults to 15 days; administrators can customize the timing or choose immediate removal.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-20/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 20 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Global Secure Access V2 guidance now spells out profile order and migration differences — 19 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-19/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-19/</guid>
      <pubDate>Wed, 19 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 19 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/" style="color:#11181d;text-decoration:none">Global Secure Access V2 guidance now spells out profile order and migration differences</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period&#039;s clearest administrator-relevant update concerns Global Secure Access web filtering: V2 selects the first applicable profile containing a V2 policy, individual rules do not support user or group targeting, and enforcement may differ from V1 during migration. ID Governance guidance also expands delegation coverage to multi-resource access reviews, while Entra ID clarifies the scope of application-owner permissions.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-web-filtering-in-global-secure-access-v2-03" style="color:#11181d;text-decoration:none">V2 profile selection and rule-targeting limits are now explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated web-filtering guidance says V2 selects the first applicable profile containing a V2 policy. It also states that individual rules do not support user or group targeting and that enforcement may differ from V1 during migration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-delegate-approvals-and-access-reviews-in-my-access-preview-02" style="color:#11181d;text-decoration:none">My Access guidance adds delegated multi-resource access reviews</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated preview guidance covers delegating multi-resource access reviews in addition to access package approvals. Administrators can control delegation to a manager, specific groups, or any directory user, apply delegate-selection restrictions, set maximum delegation duration, and require expiration dates. Single-resource access reviews are not included.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-assign-app-owners-01" style="color:#11181d;text-decoration:none">Application-owner permissions are clarified by application scope</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Assign App Owners guidance now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application&#039;s scope.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-migrate-web-content-filtering-policies-04" style="color:#11181d;text-decoration:none">V1-to-V2 migration instructions are now presented as numbered steps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The migration guide now presents the V1-to-V2 procedure and migration options as numbered steps, making the sequence clearer to follow. No administrator action is required.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-19/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 19 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 19 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/" style="color:#11181d;text-decoration:none">Global Secure Access V2 guidance now spells out profile order and migration differences</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period&#039;s clearest administrator-relevant update concerns Global Secure Access web filtering: V2 selects the first applicable profile containing a V2 policy, individual rules do not support user or group targeting, and enforcement may differ from V1 during migration. ID Governance guidance also expands delegation coverage to multi-resource access reviews, while Entra ID clarifies the scope of application-owner permissions.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-web-filtering-in-global-secure-access-v2-03" style="color:#11181d;text-decoration:none">V2 profile selection and rule-targeting limits are now explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated web-filtering guidance says V2 selects the first applicable profile containing a V2 policy. It also states that individual rules do not support user or group targeting and that enforcement may differ from V1 during migration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-delegate-approvals-and-access-reviews-in-my-access-preview-02" style="color:#11181d;text-decoration:none">My Access guidance adds delegated multi-resource access reviews</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated preview guidance covers delegating multi-resource access reviews in addition to access package approvals. Administrators can control delegation to a manager, specific groups, or any directory user, apply delegate-selection restrictions, set maximum delegation duration, and require expiration dates. Single-resource access reviews are not included.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-assign-app-owners-01" style="color:#11181d;text-decoration:none">Application-owner permissions are clarified by application scope</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Assign App Owners guidance now compares application owners with application administrators, stating that owners can manage only the enterprise applications they own and have equivalent permissions within that application&#039;s scope.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-19/#doc-2026-08-19-migrate-web-content-filtering-policies-04" style="color:#11181d;text-decoration:none">V1-to-V2 migration instructions are now presented as numbered steps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The migration guide now presents the V1-to-V2 procedure and migration options as numbered steps, making the sequence clearer to follow. No administrator action is required.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-19/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 19 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Federated sign-in validation tightens as Windows Hello and macOS SSO gain standalone MFA — 18 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-18/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-18/</guid>
      <pubDate>Tue, 18 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 18 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/" style="color:#11181d;text-decoration:none">Federated sign-in validation tightens as Windows Hello and macOS SSO gain standalone MFA</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The day’s consequential changes are two Entra authentication behavior updates. Microsoft says the federatedTokenValidationPolicy default will block federated sign-ins when internalDomainFederation does not match the user’s UPN domain for federated domains configured before December 2025. Starting in October 2026, Windows Hello for Business and macOS Platform SSO will count as standalone MFA factors. Workload ID’s flexible federated identity credential preview guidance also tightens GitHub claim matching, while the remaining updates are lower-impact synchronization and licensing reference maintenance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#MC1303719" style="color:#11181d;text-decoration:none">FederatedTokenValidationPolicy default will block mismatched federated domains</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft’s Message Center notice describes a mid-August 2026 default change affecting federated domains configured before December 2025. Federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. Administrators can customize the policy through Microsoft Graph, although Microsoft discourages customization.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#MC1450134" style="color:#11181d;text-decoration:none">Windows Hello and macOS Platform SSO become standalone MFA factors</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Starting in October 2026, Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors, allowing users to satisfy MFA requirements without an additional passkey. Microsoft says no configuration changes are required, but onboarding and MFA-registration guidance should be updated.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#doc-2026-08-18-flexible-federated-identity-credentials-preview-01" style="color:#11181d;text-decoration:none">GitHub flexible FIC preview guidance requires immutable repository claims</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated preview documentation says GitHub flexible federated identity credentials must match sub and at least one immutable claim: repository_id or repository_owner_id. The examples and operator guidance now use these claims with the eq operator when defining or reviewing trust.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#doc-2026-08-18-synchronization-04" style="color:#11181d;text-decoration:none">Synchronization guidance adds sAMAccountName coverage for Domain Services</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Synchronization page now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance for that scenario.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#doc-2026-08-18-licensing-service-plan-reference-03" style="color:#11181d;text-decoration:none">Licensing reference adds Windows 10 ESU identifiers to Windows 365 entries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The reference, updated August 14, 2026, adds Windows 10 ESU service-plan identifiers to two Windows 365 plan entries. No administrator action is stated beyond using the updated reference when matching those plans.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-18/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 18 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 18 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/" style="color:#11181d;text-decoration:none">Federated sign-in validation tightens as Windows Hello and macOS SSO gain standalone MFA</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The day’s consequential changes are two Entra authentication behavior updates. Microsoft says the federatedTokenValidationPolicy default will block federated sign-ins when internalDomainFederation does not match the user’s UPN domain for federated domains configured before December 2025. Starting in October 2026, Windows Hello for Business and macOS Platform SSO will count as standalone MFA factors. Workload ID’s flexible federated identity credential preview guidance also tightens GitHub claim matching, while the remaining updates are lower-impact synchronization and licensing reference maintenance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#MC1303719" style="color:#11181d;text-decoration:none">FederatedTokenValidationPolicy default will block mismatched federated domains</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft’s Message Center notice describes a mid-August 2026 default change affecting federated domains configured before December 2025. Federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. Administrators can customize the policy through Microsoft Graph, although Microsoft discourages customization.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#MC1450134" style="color:#11181d;text-decoration:none">Windows Hello and macOS Platform SSO become standalone MFA factors</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Starting in October 2026, Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors, allowing users to satisfy MFA requirements without an additional passkey. Microsoft says no configuration changes are required, but onboarding and MFA-registration guidance should be updated.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#doc-2026-08-18-flexible-federated-identity-credentials-preview-01" style="color:#11181d;text-decoration:none">GitHub flexible FIC preview guidance requires immutable repository claims</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated preview documentation says GitHub flexible federated identity credentials must match sub and at least one immutable claim: repository_id or repository_owner_id. The examples and operator guidance now use these claims with the eq operator when defining or reviewing trust.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#doc-2026-08-18-synchronization-04" style="color:#11181d;text-decoration:none">Synchronization guidance adds sAMAccountName coverage for Domain Services</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Synchronization page now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance for that scenario.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-18/#doc-2026-08-18-licensing-service-plan-reference-03" style="color:#11181d;text-decoration:none">Licensing reference adds Windows 10 ESU identifiers to Windows 365 entries</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The reference, updated August 14, 2026, adds Windows 10 ESU service-plan identifiers to two Windows 365 plan entries. No administrator action is stated beyond using the updated reference when matching those plans.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-18/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 18 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Global Secure Access guidance details guided V1-to-V2 web filtering migration — 15 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-15/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-15/</guid>
      <pubDate>Sat, 15 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 15 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/" style="color:#11181d;text-decoration:none">Global Secure Access guidance details guided V1-to-V2 web filtering migration</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The main substantive addition is a new Global Secure Access how-to for migrating eligible web content filtering policies from V1 to V2. The existing Web Filtering page now links to that guidance. Separate Entra ID and ID Protection updates clarify documented limitations and remediation behavior rather than announcing new features.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/#doc-2026-08-15-migrate-web-content-filtering-policies-from-v1-to-v2-01" style="color:#11181d;text-decoration:none">New guidance maps V1 web filtering policies into V2 rules</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Global Secure Access migration guide covers eligible and ineligible security profiles, naming, and the guided migration process. Each V1 policy becomes a rule in one enabled V2 policy while preserving destinations, actions, and priorities. Profiles that already contain V2 policies require manual handling, and evaluation across multiple security profiles differs between V1 and V2.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/#doc-2026-08-15-policy-guests-mfa-strength-04" style="color:#11181d;text-decoration:none">Authentication-strength guidance excludes MSA-authenticated external users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Entra ID guidance states that authentication-strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts. It directs administrators to use the MFA grant control instead. This documents a limitation and alternative control; it does not establish a newly introduced product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/#doc-2026-08-15-identity-protection-policies-02" style="color:#11181d;text-decoration:none">ID Protection revises the documented device-block remediation behavior</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated guidance says disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens, making this a documentation clarification rather than evidence of a behavior change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-15/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 15 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 15 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/" style="color:#11181d;text-decoration:none">Global Secure Access guidance details guided V1-to-V2 web filtering migration</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The main substantive addition is a new Global Secure Access how-to for migrating eligible web content filtering policies from V1 to V2. The existing Web Filtering page now links to that guidance. Separate Entra ID and ID Protection updates clarify documented limitations and remediation behavior rather than announcing new features.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/#doc-2026-08-15-migrate-web-content-filtering-policies-from-v1-to-v2-01" style="color:#11181d;text-decoration:none">New guidance maps V1 web filtering policies into V2 rules</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Global Secure Access migration guide covers eligible and ineligible security profiles, naming, and the guided migration process. Each V1 policy becomes a rule in one enabled V2 policy while preserving destinations, actions, and priorities. Profiles that already contain V2 policies require manual handling, and evaluation across multiple security profiles differs between V1 and V2.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/#doc-2026-08-15-policy-guests-mfa-strength-04" style="color:#11181d;text-decoration:none">Authentication-strength guidance excludes MSA-authenticated external users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Entra ID guidance states that authentication-strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts. It directs administrators to use the MFA grant control instead. This documents a limitation and alternative control; it does not establish a newly introduced product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-15/#doc-2026-08-15-identity-protection-policies-02" style="color:#11181d;text-decoration:none">ID Protection revises the documented device-block remediation behavior</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated guidance says disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens, making this a documentation clarification rather than evidence of a behavior change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-15/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 15 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Agent ID guidance now directs provisioning through identity blueprints, not app registrations — 14 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-14/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-14/</guid>
      <pubDate>Fri, 14 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 14 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/" style="color:#11181d;text-decoration:none">Agent ID guidance now directs provisioning through identity blueprints, not app registrations</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">14 August produced no new or removed entries and was dominated by documentation maintenance, particularly across Microsoft Entra Agent ID. The most consequential update clarifies that agents should use identity blueprints and the #Microsoft.Graph.AgentIdentity object rather than standard application-registration APIs. Other notable edits clarify Identity Protection remediation, dynamic-group treatment of agent accounts, replica-set networking, and a Windows passkey preview label; none of the supplied diffs independently announces a new feature or general availability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-plan-agent-identity-architecture-27" style="color:#11181d;text-decoration:none">Agent ID provisioning guidance moves to identity blueprints</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The architecture guidance now directs administrators to create agents from an agent identity blueprint and the #Microsoft.Graph.AgentIdentity object, rather than through standard application-registration APIs. It also documents supported creation channels, roles, permissions, and .NET usage. This is a guidance clarification, not a separately announced launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-identity-protection-policies-52" style="color:#11181d;text-decoration:none">Identity Protection clarifies the attacker-added-device response</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Identity Protection Policies article replaces “Device disablement” with “Attacker-added device” and spells out the documented response: the Entra device object is disabled, new token issuance is blocked, device-bound refresh tokens are revoked, and user sessions are revoked. The supplied change clarifies the remediation scope rather than announcing a new control.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-manage-rules-for-dynamic-membership-groups-in-microsoft-entra-id-16" style="color:#11181d;text-decoration:none">Dynamic-group guidance now covers agent user accounts</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID guidance now explains that agent user accounts are evaluated by user-based membership rules and are not distinguished from other users by default. Administrators can explicitly include or exclude them, including accounts associated with a particular agent identity blueprint.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-concepts-replica-sets-51" style="color:#11181d;text-decoration:none">Replica-set guidance makes full virtual-network meshing explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The replica-set documentation now states that all virtual networks hosting replica sets must be connected. It also specifies that replica sets are deployed in one Active Directory site and depend on a fully meshed virtual-network topology, clarifying a deployment prerequisite.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-register-a-microsoft-entra-passkey-on-windows-17" style="color:#11181d;text-decoration:none">Windows passkey registration loses its preview label</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The “Register a Microsoft Entra passkey on Windows” page no longer includes “(preview)” in its title or heading. No procedural change is shown, and the supplied diff does not explicitly announce general availability or a product launch.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-14/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 14 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 14 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/" style="color:#11181d;text-decoration:none">Agent ID guidance now directs provisioning through identity blueprints, not app registrations</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">14 August produced no new or removed entries and was dominated by documentation maintenance, particularly across Microsoft Entra Agent ID. The most consequential update clarifies that agents should use identity blueprints and the #Microsoft.Graph.AgentIdentity object rather than standard application-registration APIs. Other notable edits clarify Identity Protection remediation, dynamic-group treatment of agent accounts, replica-set networking, and a Windows passkey preview label; none of the supplied diffs independently announces a new feature or general availability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-plan-agent-identity-architecture-27" style="color:#11181d;text-decoration:none">Agent ID provisioning guidance moves to identity blueprints</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The architecture guidance now directs administrators to create agents from an agent identity blueprint and the #Microsoft.Graph.AgentIdentity object, rather than through standard application-registration APIs. It also documents supported creation channels, roles, permissions, and .NET usage. This is a guidance clarification, not a separately announced launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-identity-protection-policies-52" style="color:#11181d;text-decoration:none">Identity Protection clarifies the attacker-added-device response</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Identity Protection Policies article replaces “Device disablement” with “Attacker-added device” and spells out the documented response: the Entra device object is disabled, new token issuance is blocked, device-bound refresh tokens are revoked, and user sessions are revoked. The supplied change clarifies the remediation scope rather than announcing a new control.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-manage-rules-for-dynamic-membership-groups-in-microsoft-entra-id-16" style="color:#11181d;text-decoration:none">Dynamic-group guidance now covers agent user accounts</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID guidance now explains that agent user accounts are evaluated by user-based membership rules and are not distinguished from other users by default. Administrators can explicitly include or exclude them, including accounts associated with a particular agent identity blueprint.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-concepts-replica-sets-51" style="color:#11181d;text-decoration:none">Replica-set guidance makes full virtual-network meshing explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The replica-set documentation now states that all virtual networks hosting replica sets must be connected. It also specifies that replica sets are deployed in one Active Directory site and depend on a fully meshed virtual-network topology, clarifying a deployment prerequisite.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-14/#doc-2026-08-14-register-a-microsoft-entra-passkey-on-windows-17" style="color:#11181d;text-decoration:none">Windows passkey registration loses its preview label</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The “Register a Microsoft Entra passkey on Windows” page no longer includes “(preview)” in its title or heading. No procedural change is shown, and the supplied diff does not explicitly announce general availability or a product launch.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-14/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 14 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID Free SMS first-factor sign-in retirement makes alternate authentication necessary — 13 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-13/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-13/</guid>
      <pubDate>Thu, 13 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 13 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/" style="color:#11181d;text-decoration:none">Entra ID Free SMS first-factor sign-in retirement makes alternate authentication necessary</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period’s main administrator-impacting notice is Microsoft’s planned retirement of SMS first-factor sign-in for Microsoft Entra ID Free tenants on 11 August 2026 because of fraud risks; SMS used for multifactor authentication remains unaffected. Microsoft also added first-party Workload ID federation tutorials for Google Cloud and SPIFFE/SPIRE, expanded Agent ID permission guidance, and revised Catalog Access Reviews documentation. Most remaining edits were maintenance, including a corrected Global Secure Access section name and updated links.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#MC1448374" style="color:#11181d;text-decoration:none">SMS first-factor sign-in retirement for Entra ID Free tenants</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Microsoft 365 Message Center notice says Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on 11 August 2026 because of fraud risks. Users must switch to another authentication method before retirement; SMS as a multifactor method is unaffected. This is a security-related product retirement, not a documentation clarification.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-catalog-access-reviews-10" style="color:#11181d;text-decoration:none">Catalog Access Reviews documentation adds a 12-hour data-freshness caveat</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated ID Governance guidance removes Preview labels, broadens reviewer terminology beyond managers, and warns that changes made within 12 hours before a review starts may not appear. The supplied evidence does not explicitly announce general availability, so the status change should not be treated as a confirmed GA announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-federate-a-google-cloud-workload-identity-01" style="color:#11181d;text-decoration:none">Google Cloud workload federation gets a first-party Workload ID tutorial</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new tutorial shows how an Entra application can trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets. It documents a configuration scenario rather than announcing a new product launch and requires permission to add a federated identity credential.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-federate-a-spiffe-spire-workload-identity-02" style="color:#11181d;text-decoration:none">SPIFFE/SPIRE workload federation gets a first-party Workload ID tutorial</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new tutorial documents exchanging a Kubernetes workload’s SPIFFE JWT-SVID for a Microsoft Entra access token so it can access Azure resources without stored secrets. The page is implementation guidance for an existing federation scenario, not evidence of a new product launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-grant-agent-access-microsoft-365-03" style="color:#11181d;text-decoration:none">Agent ID guidance maps Microsoft 365 channels to required permissions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated guidance now covers agents communicating through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, with permissions for receiving events and sending responses. Administrators can use the channel-by-channel table to configure agent access; no underlying product behavior change is stated.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-13/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 13 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 13 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/" style="color:#11181d;text-decoration:none">Entra ID Free SMS first-factor sign-in retirement makes alternate authentication necessary</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period’s main administrator-impacting notice is Microsoft’s planned retirement of SMS first-factor sign-in for Microsoft Entra ID Free tenants on 11 August 2026 because of fraud risks; SMS used for multifactor authentication remains unaffected. Microsoft also added first-party Workload ID federation tutorials for Google Cloud and SPIFFE/SPIRE, expanded Agent ID permission guidance, and revised Catalog Access Reviews documentation. Most remaining edits were maintenance, including a corrected Global Secure Access section name and updated links.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#MC1448374" style="color:#11181d;text-decoration:none">SMS first-factor sign-in retirement for Entra ID Free tenants</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Microsoft 365 Message Center notice says Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on 11 August 2026 because of fraud risks. Users must switch to another authentication method before retirement; SMS as a multifactor method is unaffected. This is a security-related product retirement, not a documentation clarification.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-catalog-access-reviews-10" style="color:#11181d;text-decoration:none">Catalog Access Reviews documentation adds a 12-hour data-freshness caveat</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated ID Governance guidance removes Preview labels, broadens reviewer terminology beyond managers, and warns that changes made within 12 hours before a review starts may not appear. The supplied evidence does not explicitly announce general availability, so the status change should not be treated as a confirmed GA announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-federate-a-google-cloud-workload-identity-01" style="color:#11181d;text-decoration:none">Google Cloud workload federation gets a first-party Workload ID tutorial</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new tutorial shows how an Entra application can trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets. It documents a configuration scenario rather than announcing a new product launch and requires permission to add a federated identity credential.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-federate-a-spiffe-spire-workload-identity-02" style="color:#11181d;text-decoration:none">SPIFFE/SPIRE workload federation gets a first-party Workload ID tutorial</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new tutorial documents exchanging a Kubernetes workload’s SPIFFE JWT-SVID for a Microsoft Entra access token so it can access Azure resources without stored secrets. The page is implementation guidance for an existing federation scenario, not evidence of a new product launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-13/#doc-2026-08-13-grant-agent-access-microsoft-365-03" style="color:#11181d;text-decoration:none">Agent ID guidance maps Microsoft 365 channels to required permissions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated guidance now covers agents communicating through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, with permissions for receiving events and sending responses. Administrators can use the channel-by-channel table to configure agent access; no underlying product behavior change is stated.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-13/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 13 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>External ID on-behalf-of ordering targets Dynamics 365 Commerce general availability on 11 September 2026 — 12 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-12/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-12/</guid>
      <pubDate>Wed, 12 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 12 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/" style="color:#11181d;text-decoration:none">External ID on-behalf-of ordering targets Dynamics 365 Commerce general availability on 11 September 2026</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The clearest product announcement is a Microsoft 365 Message Center notice that on-behalf-of ordering for Dynamics 365 Commerce with Microsoft Entra External ID is scheduled for general availability on 11 September 2026. A new Microsoft Entra Internet Access article documents the V2 web-filtering model and its coexistence with V1. Most other updates are documentation clarifications or connector setup changes, including sharper Staged Rollout troubleshooting and more explicit application-claim configuration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#MC1453678" style="color:#11181d;text-decoration:none">On-behalf-of ordering gets a scheduled External ID availability milestone</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft announces that on-behalf-of ordering for Microsoft Entra External ID in Dynamics 365 Commerce will reach general availability on 11 September 2026. This is a product availability announcement; the supplied notice does not provide further configuration or migration guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-web-filtering-in-global-secure-access-v2-01" style="color:#11181d;text-decoration:none">V2 web filtering is documented as a distinct Internet Access model</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new Global Secure Access V2 article describes one policy per security profile, multiple rules with individual actions, a default action, and URL-based FQDN destinations. Existing V1 web-content-filtering policies continue to function until migration. The new article documents the model but does not by itself establish a separate availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-microsoft-entra-connect-cloud-authentication-via-staged-rollout-05" style="color:#11181d;text-decoration:none">Staged Rollout guidance now details additional sign-in scenarios</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Microsoft Entra Connect article replaces general transition language with scenarios involving extra interactive sign-ins when users are added to or removed from Staged Rollout, including certain Microsoft Entra ID Protection remediation events such as SSPR and risk remediation. The supported administrator outcome is better troubleshooting guidance, not evidence of a newly changed sign-in behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-optional-claims-02" style="color:#11181d;text-decoration:none">Optional Claims guidance clarifies granular AMR configuration paths</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated article explains that SAML applications must configure the `include_granular_amr` setting through the application manifest or Microsoft Graph because the admin center has no corresponding UI. It also documents adding the `amr` optional claim for OIDC token types and clarifies that `include_granular_amr` applies only to SAML.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-configure-puzzel-for-automatic-user-provisioning-with-microsoft-entra-id-07" style="color:#11181d;text-decoration:none">Puzzel provisioning adds OAuth2 client-credentials instructions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Puzzel integration guide now covers OAuth2 Client Credentials Grant authentication, including creating an OIDC client, setting 3600-second token lifetimes, generating a shared secret, and entering the client ID, secret, and token endpoint. This is connector-specific setup guidance rather than a new general provisioning capability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-12/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 12 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 12 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/" style="color:#11181d;text-decoration:none">External ID on-behalf-of ordering targets Dynamics 365 Commerce general availability on 11 September 2026</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The clearest product announcement is a Microsoft 365 Message Center notice that on-behalf-of ordering for Dynamics 365 Commerce with Microsoft Entra External ID is scheduled for general availability on 11 September 2026. A new Microsoft Entra Internet Access article documents the V2 web-filtering model and its coexistence with V1. Most other updates are documentation clarifications or connector setup changes, including sharper Staged Rollout troubleshooting and more explicit application-claim configuration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#MC1453678" style="color:#11181d;text-decoration:none">On-behalf-of ordering gets a scheduled External ID availability milestone</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft announces that on-behalf-of ordering for Microsoft Entra External ID in Dynamics 365 Commerce will reach general availability on 11 September 2026. This is a product availability announcement; the supplied notice does not provide further configuration or migration guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-web-filtering-in-global-secure-access-v2-01" style="color:#11181d;text-decoration:none">V2 web filtering is documented as a distinct Internet Access model</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new Global Secure Access V2 article describes one policy per security profile, multiple rules with individual actions, a default action, and URL-based FQDN destinations. Existing V1 web-content-filtering policies continue to function until migration. The new article documents the model but does not by itself establish a separate availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-microsoft-entra-connect-cloud-authentication-via-staged-rollout-05" style="color:#11181d;text-decoration:none">Staged Rollout guidance now details additional sign-in scenarios</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Microsoft Entra Connect article replaces general transition language with scenarios involving extra interactive sign-ins when users are added to or removed from Staged Rollout, including certain Microsoft Entra ID Protection remediation events such as SSPR and risk remediation. The supported administrator outcome is better troubleshooting guidance, not evidence of a newly changed sign-in behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-optional-claims-02" style="color:#11181d;text-decoration:none">Optional Claims guidance clarifies granular AMR configuration paths</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated article explains that SAML applications must configure the `include_granular_amr` setting through the application manifest or Microsoft Graph because the admin center has no corresponding UI. It also documents adding the `amr` optional claim for OIDC token types and clarifies that `include_granular_amr` applies only to SAML.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-12/#doc-2026-08-12-configure-puzzel-for-automatic-user-provisioning-with-microsoft-entra-id-07" style="color:#11181d;text-decoration:none">Puzzel provisioning adds OAuth2 client-credentials instructions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Puzzel integration guide now covers OAuth2 Client Credentials Grant authentication, including creating an OIDC client, setting 3600-second token lifetimes, generating a shared secret, and entering the client ID, secret, and token endpoint. This is connector-specific setup guidance rather than a new general provisioning capability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-12/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 12 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>First-method passkey registration rolls out from October 2026 through February 2027 — 11 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-11/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-11/</guid>
      <pubDate>Tue, 11 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 11 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/" style="color:#11181d;text-decoration:none">First-method passkey registration rolls out from October 2026 through February 2027</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period’s consequential item is a Microsoft Entra rollout announcement: users will be able to register a passkey or passwordless sign-in as their first multifactor authentication method, without setting up weaker methods first. The remaining changes are documentation clarifications covering Agent ID token exchange, a Microsoft Graph permission prerequisite, account discovery limits, workload identity guidance links, and PAC-file syntax. No new or removed documentation items are recorded, and the evidence does not establish a separate preview, general-availability, or retirement event.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#MC1450133" style="color:#11181d;text-decoration:none">First-method passkey and passwordless registration is scheduled to roll out</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Message Center announcement says users can register a passkey or passwordless sign-in as their first multifactor authentication method, eliminating the need to configure weaker methods first. Rollout is stated for October 2026 through February 2027, with no administrator action required.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#doc-2026-08-11-agent-on-behalf-of-oauth-flow-05" style="color:#11181d;text-decoration:none">Agent ID guidance clarifies audiences and the preauthorization requirement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Agent ID on-behalf-of guidance says Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated against the blueprint and child agent identity. It also clarifies that agent identities cannot use interactive consent and that delegated permissions must be preauthorized through inheritable blueprint permissions. This is a documentation clarification with concrete configuration implications.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#doc-2026-08-11-passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-03" style="color:#11181d;text-decoration:none">Graph opt-out guidance now names the required authentication-method permission</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The passkey and Microsoft-provided SMS and voice authentication page now states that opting out through Microsoft Graph requires Policy.ReadWrite.AuthenticationMethod. The supplied evidence supports this as a documentation prerequisite clarification, not a new retirement date or separately documented API behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#doc-2026-08-11-discover-identities-in-target-applications-with-account-discovery-06" style="color:#11181d;text-decoration:none">Account discovery documentation tightens prerequisites and limitation wording</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The account discovery article now uses lowercase “account discovery” and clarifies connector requirements, direct attribute matching, SCIM support, unsupported scenarios, the GitHub reference, and the expectation that reports take at least 30 minutes. It continues to describe the existing process; no launch or required action is indicated.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-11/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 11 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 11 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/" style="color:#11181d;text-decoration:none">First-method passkey registration rolls out from October 2026 through February 2027</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period’s consequential item is a Microsoft Entra rollout announcement: users will be able to register a passkey or passwordless sign-in as their first multifactor authentication method, without setting up weaker methods first. The remaining changes are documentation clarifications covering Agent ID token exchange, a Microsoft Graph permission prerequisite, account discovery limits, workload identity guidance links, and PAC-file syntax. No new or removed documentation items are recorded, and the evidence does not establish a separate preview, general-availability, or retirement event.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#MC1450133" style="color:#11181d;text-decoration:none">First-method passkey and passwordless registration is scheduled to roll out</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Message Center announcement says users can register a passkey or passwordless sign-in as their first multifactor authentication method, eliminating the need to configure weaker methods first. Rollout is stated for October 2026 through February 2027, with no administrator action required.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#doc-2026-08-11-agent-on-behalf-of-oauth-flow-05" style="color:#11181d;text-decoration:none">Agent ID guidance clarifies audiences and the preauthorization requirement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Agent ID on-behalf-of guidance says Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated against the blueprint and child agent identity. It also clarifies that agent identities cannot use interactive consent and that delegated permissions must be preauthorized through inheritable blueprint permissions. This is a documentation clarification with concrete configuration implications.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#doc-2026-08-11-passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-03" style="color:#11181d;text-decoration:none">Graph opt-out guidance now names the required authentication-method permission</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The passkey and Microsoft-provided SMS and voice authentication page now states that opting out through Microsoft Graph requires Policy.ReadWrite.AuthenticationMethod. The supplied evidence supports this as a documentation prerequisite clarification, not a new retirement date or separately documented API behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-11/#doc-2026-08-11-discover-identities-in-target-applications-with-account-discovery-06" style="color:#11181d;text-decoration:none">Account discovery documentation tightens prerequisites and limitation wording</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The account discovery article now uses lowercase “account discovery” and clarifies connector requirements, direct attribute matching, SCIM support, unsupported scenarios, the GitHub reference, and the expectation that reports take at least 30 minutes. It continues to describe the existing process; no launch or required action is indicated.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-11/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 11 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Token Protection now documents Preview browser support for selected Azure Resource Manager web apps — 10 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-10/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-10/</guid>
      <pubDate>Mon, 10 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 10 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/" style="color:#11181d;text-decoration:none">Token Protection now documents Preview browser support for selected Azure Resource Manager web apps</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period was dominated by Entra ID documentation updates. The meaningful change is expanded Token Protection guidance covering browser-based applications in Preview; the other updates revise Orgvue URL examples and remove a Conditional Access screenshot without indicating product-behavior changes.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/#doc-2026-08-10-token-protection-03" style="color:#11181d;text-decoration:none">Browser-based Token Protection guidance expands</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Token Protection page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. Browser support on iOS and iPadOS is not supported. The update adds requirements for supported browsers, extensions, operating systems, and configurations, and identifies the Conditional Access resource used for enforcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/#doc-2026-08-10-orgvue-tutorial-01" style="color:#11181d;text-decoration:none">Orgvue tutorial URLs and placeholders are revised</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The tutorial replaces authentication and SAML callback URLs with orgvue-staging URLs, changes the Sign-on URL to include the application login path and domain parameter, and clarifies that Reply URL and Sign-on URL values are placeholders. Administrators using the tutorial should substitute the actual domain and correct application URLs.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/#doc-2026-08-10-token-protection-02" style="color:#11181d;text-decoration:none">Token Protection policy screenshot removed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A screenshot showing a Conditional Access policy requiring Token Protection as a session control was removed. The Primary Refresh Token link remains. This is a presentation-only documentation change, with no administrator action or product-behavior change indicated.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-10/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 10 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 10 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/" style="color:#11181d;text-decoration:none">Token Protection now documents Preview browser support for selected Azure Resource Manager web apps</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period was dominated by Entra ID documentation updates. The meaningful change is expanded Token Protection guidance covering browser-based applications in Preview; the other updates revise Orgvue URL examples and remove a Conditional Access screenshot without indicating product-behavior changes.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/#doc-2026-08-10-token-protection-03" style="color:#11181d;text-decoration:none">Browser-based Token Protection guidance expands</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Token Protection page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. Browser support on iOS and iPadOS is not supported. The update adds requirements for supported browsers, extensions, operating systems, and configurations, and identifies the Conditional Access resource used for enforcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/#doc-2026-08-10-orgvue-tutorial-01" style="color:#11181d;text-decoration:none">Orgvue tutorial URLs and placeholders are revised</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The tutorial replaces authentication and SAML callback URLs with orgvue-staging URLs, changes the Sign-on URL to include the application login path and domain parameter, and clarifies that Reply URL and Sign-on URL values are placeholders. Administrators using the tutorial should substitute the actual domain and correct application URLs.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-10/#doc-2026-08-10-token-protection-02" style="color:#11181d;text-decoration:none">Token Protection policy screenshot removed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A screenshot showing a Conditional Access policy requiring Token Protection as a session control was removed. The Primary Refresh Token link remains. This is a presentation-only documentation change, with no administrator action or product-behavior change indicated.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-10/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 10 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Hard-match remediation guidance now explicitly requires resetting the protection flag — 9 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-09/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-09/</guid>
      <pubDate>Sun, 09 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 9 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-09/" style="color:#11181d;text-decoration:none">Hard-match remediation guidance now explicitly requires resetting the protection flag</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">A troubleshooting update for Microsoft Entra ID clarifies the commands used to enable and verify `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`. It also documents restoring the setting to `$false` after remediation, so hard-match protection is re-enabled. This is a procedural documentation clarification, not evidence of a new feature or changed service behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/troubleshooting.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Troubleshooting</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-09/#doc-2026-08-09-connect-to-microsoft-graph-01" style="color:#11181d;text-decoration:none">Revised Microsoft Graph troubleshooting commands clarify hard-match remediation</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Entra ID guidance shows clearer commands for enabling and verifying `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`, and explicitly includes the step to restore it to `$false` after remediation.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-09/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 9 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 9 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-09/" style="color:#11181d;text-decoration:none">Hard-match remediation guidance now explicitly requires resetting the protection flag</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">A troubleshooting update for Microsoft Entra ID clarifies the commands used to enable and verify `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`. It also documents restoring the setting to `$false` after remediation, so hard-match protection is re-enabled. This is a procedural documentation clarification, not evidence of a new feature or changed service behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/troubleshooting.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Troubleshooting</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-09/#doc-2026-08-09-connect-to-microsoft-graph-01" style="color:#11181d;text-decoration:none">Revised Microsoft Graph troubleshooting commands clarify hard-match remediation</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Entra ID guidance shows clearer commands for enabling and verifying `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`, and explicitly includes the step to restore it to `$false` after remediation.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-09/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 9 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Managed policies may enable after 30 days, with high-risk remediation scope clarified — 8 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-08/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-08/</guid>
      <pubDate>Sat, 08 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 8 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-08/" style="color:#11181d;text-decoration:none">Managed policies may enable after 30 days, with high-risk remediation scope clarified</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">This quiet Entra ID period contains one material change to Managed Policies guidance and one reference-data correction. The Managed Policies update shortens the documented Report-only review period from 45 to at least 30 days and adds security-group scope information for high-risk remediation. The SLA update is documentation-only; it does not indicate a product or service change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-08/#doc-2026-08-08-managed-policies-02" style="color:#11181d;text-decoration:none">Managed Policies review window and scope</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID Managed Policies page now says Microsoft may enable a managed policy at least 30 days after introduction when it remains in Report-only, replacing the previously documented 45-day period. It also documents creation of a security group with the high-risk remediation policy.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-08/#doc-2026-08-08-sla-performance-01" style="color:#11181d;text-decoration:none">July SLA performance data corrected</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID SLA Performance table now includes an additional 99.999% value in the July row. The source explicitly indicates that this is a reference update, not a product change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-08/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 8 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 8 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-08/" style="color:#11181d;text-decoration:none">Managed policies may enable after 30 days, with high-risk remediation scope clarified</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">This quiet Entra ID period contains one material change to Managed Policies guidance and one reference-data correction. The Managed Policies update shortens the documented Report-only review period from 45 to at least 30 days and adds security-group scope information for high-risk remediation. The SLA update is documentation-only; it does not indicate a product or service change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-08/#doc-2026-08-08-managed-policies-02" style="color:#11181d;text-decoration:none">Managed Policies review window and scope</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID Managed Policies page now says Microsoft may enable a managed policy at least 30 days after introduction when it remains in Report-only, replacing the previously documented 45-day period. It also documents creation of a security group with the high-risk remediation policy.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-08/#doc-2026-08-08-sla-performance-01" style="color:#11181d;text-decoration:none">July SLA performance data corrected</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID SLA Performance table now includes an additional 99.999% value in the July row. The source explicitly indicates that this is a reference update, not a product change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-08/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 8 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>MemberOf support ends 3 November 2026 as Entra expands first-method passkey registration — 7 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-07/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-07/</guid>
      <pubDate>Fri, 07 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 7 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/" style="color:#11181d;text-decoration:none">MemberOf support ends 3 November 2026 as Entra expands first-method passkey registration</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">7 August is mostly a documentation-maintenance day: provisioning pages converge on the Scoping filters wizard and current Attribute Mapping, Advanced Options, and Edit schema labels. The consequential exceptions are a revised ID Governance retirement date, two MFA behavior notices, and new preview-oriented security guidance. Agent ID pages also replace earlier licensing wording with an Agent 365 requirement; that is licensing guidance, not evidence of a separate launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#doc-2026-08-07-entitlement-management-access-package-auto-assignment-policy-16" style="color:#11181d;text-decoration:none">`memberOf` auto-assignment support now ends 3 November 2026</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated ID Governance guidance moves the end date from 27 October to 3 November 2026. Policies that still use the operator will be quarantined and stop processing assignments after the cutoff, making this a retirement deadline rather than a terminology edit.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#MC1450133" style="color:#11181d;text-decoration:none">Passkeys can be registered as users’ first MFA method</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Microsoft 365 Message Center notice says users can register passkeys or passwordless sign-in as their first multifactor authentication method, removing the former weaker-method-first requirement. Rollout is phased from January 2026 through November 2027; the supplied notice specifies no administrator configuration action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#MC1450134" style="color:#11181d;text-decoration:none">Windows Hello and macOS Platform SSO become standalone MFA factors</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Message Center says Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are required, but onboarding and documentation should be updated.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#doc-2026-08-07-configure-global-secure-access-mcp-firewall-to-secure-model-context-protocol-traffic-02" style="color:#11181d;text-decoration:none">Global Secure Access guidance covers its preview MCP firewall</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new how-to article—not a launch announcement—describes using the Global Secure Access MCP firewall to inspect, audit, and allow or block supported Model Context Protocol traffic by server, primitive, method, and protocol version. The documented prerequisites include Global Secure Access and Conditional Access Administrator roles, an Internet Access license, a joined device with the Global Secure Access client, and TLS inspection; the firewall is in preview.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#doc-2026-08-07-token-protection-deployment-guide-web-apps-preview-01" style="color:#11181d;text-decoration:none">Token Protection web-app support is documented as a preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Entra deployment guide covers enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Scope is limited to listed apps, platforms, browsers, and device configurations; the guide requires Entra ID P1 and additional Windows or macOS device setup, and recommends report-only mode followed by a pilot before enforcement.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-07/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 7 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 7 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/" style="color:#11181d;text-decoration:none">MemberOf support ends 3 November 2026 as Entra expands first-method passkey registration</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">7 August is mostly a documentation-maintenance day: provisioning pages converge on the Scoping filters wizard and current Attribute Mapping, Advanced Options, and Edit schema labels. The consequential exceptions are a revised ID Governance retirement date, two MFA behavior notices, and new preview-oriented security guidance. Agent ID pages also replace earlier licensing wording with an Agent 365 requirement; that is licensing guidance, not evidence of a separate launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#doc-2026-08-07-entitlement-management-access-package-auto-assignment-policy-16" style="color:#11181d;text-decoration:none">`memberOf` auto-assignment support now ends 3 November 2026</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated ID Governance guidance moves the end date from 27 October to 3 November 2026. Policies that still use the operator will be quarantined and stop processing assignments after the cutoff, making this a retirement deadline rather than a terminology edit.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#MC1450133" style="color:#11181d;text-decoration:none">Passkeys can be registered as users’ first MFA method</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Microsoft 365 Message Center notice says users can register passkeys or passwordless sign-in as their first multifactor authentication method, removing the former weaker-method-first requirement. Rollout is phased from January 2026 through November 2027; the supplied notice specifies no administrator configuration action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#MC1450134" style="color:#11181d;text-decoration:none">Windows Hello and macOS Platform SSO become standalone MFA factors</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Message Center says Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are required, but onboarding and documentation should be updated.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#doc-2026-08-07-configure-global-secure-access-mcp-firewall-to-secure-model-context-protocol-traffic-02" style="color:#11181d;text-decoration:none">Global Secure Access guidance covers its preview MCP firewall</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new how-to article—not a launch announcement—describes using the Global Secure Access MCP firewall to inspect, audit, and allow or block supported Model Context Protocol traffic by server, primitive, method, and protocol version. The documented prerequisites include Global Secure Access and Conditional Access Administrator roles, an Internet Access license, a joined device with the Global Secure Access client, and TLS inspection; the firewall is in preview.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-07/#doc-2026-08-07-token-protection-deployment-guide-web-apps-preview-01" style="color:#11181d;text-decoration:none">Token Protection web-app support is documented as a preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Entra deployment guide covers enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Scope is limited to listed apps, platforms, browsers, and device configurations; the guide requires Entra ID P1 and additional Windows or macOS device setup, and recommends report-only mode followed by a pilot before enforcement.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-07/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 7 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Choose Your Own Telephony Provider replaces older Entra SMS and voice terminology — 6 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-06/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-06/</guid>
      <pubDate>Thu, 06 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 6 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-06/" style="color:#11181d;text-decoration:none">Choose Your Own Telephony Provider replaces older Entra SMS and voice terminology</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The Entra ID Authentication page replaces “customer-managed telephony providers” with “Choose Your Own Telephony Provider” and refreshes related wording. This is a documentation and terminology clarification, not evidence of a product-behavior change. The page continues to state that provider information will be available on September 18, 2026, with configuration beginning October 30, 2026.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-06/#doc-2026-08-06-choose-a-telephony-provider-for-sms-and-voice-authentication-01" style="color:#11181d;text-decoration:none">Telephony-provider terminology and planning details revised</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The page’s terminology changed from “customer-managed telephony providers” to “Choose Your Own Telephony Provider,” related wording was updated, and the page date moved from August 4 to August 5, 2026. Its stated September 18 information date and October 30 configuration date remain in place.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-06/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 6 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 6 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-06/" style="color:#11181d;text-decoration:none">Choose Your Own Telephony Provider replaces older Entra SMS and voice terminology</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The Entra ID Authentication page replaces “customer-managed telephony providers” with “Choose Your Own Telephony Provider” and refreshes related wording. This is a documentation and terminology clarification, not evidence of a product-behavior change. The page continues to state that provider information will be available on September 18, 2026, with configuration beginning October 30, 2026.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-06/#doc-2026-08-06-choose-a-telephony-provider-for-sms-and-voice-authentication-01" style="color:#11181d;text-decoration:none">Telephony-provider terminology and planning details revised</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The page’s terminology changed from “customer-managed telephony providers” to “Choose Your Own Telephony Provider,” related wording was updated, and the page date moved from August 4 to August 5, 2026. Its stated September 18 information date and October 30 configuration date remain in place.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-06/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 6 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Urgent Entra cleanup: MemberOf retires by 3 November 2026, while GitHub Actions OIDC migration is already overdue — 5 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-05/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-05/</guid>
      <pubDate>Wed, 05 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 5 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/" style="color:#11181d;text-decoration:none">Urgent Entra cleanup: MemberOf retires by 3 November 2026, while GitHub Actions OIDC migration is already overdue</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The significant work on 5 August is deadline-driven rather than a broad feature launch. Entra ID is retiring MemberOf rules, with a specific ID Governance failure mode arriving earlier for automatic assignment policies; Workload ID&#039;s GitHub Actions OIDC migration deadline was late July. Separately, SSPR rollout milestones moved, and a new telephony-provider article describes future planning only. Other edits were lower-impact documentation clarification: Global Secure Access clarified Agent/User source classification for a still-preview condition, provisioning documentation described read-only MCP log analysis, and a consent page changed only capitalization and alt text.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#MC1448379" style="color:#11181d;text-decoration:none">MemberOf rule operator retirement sets a 3 November 2026 remediation deadline</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID will retire the MemberOf rule operator in dynamic groups, administrative units, and entitlement policies. Administrators should identify and replace affected rules before the deadline to avoid stale access, licensing, and policy-enforcement results.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#doc-2026-08-05-configure-an-automatic-assignment-policy-for-an-access-package-in-entitlement-management-03" style="color:#11181d;text-decoration:none">Entitlement Management will quarantine automatic-assignment policies that still use MemberOf</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Starting 27 October 2026, automatic assignment policies using MemberOf will be quarantined: assignment processing will stop, and no assignments will be added or removed until MemberOf is removed. The updated guidance points administrators to a PowerShell discovery script and replacement rules using a supported attribute-based operator or an alternative assignment method.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#MC1447671" style="color:#11181d;text-decoration:none">GitHub Actions OIDC subjects must move to immutable repository and owner IDs</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Workload ID message says GitHub Actions now supports immutable OIDC subject formats containing repository and owner IDs. Organizations using GitHub Actions federated identity credentials were told to migrate by late July 2026; because that date has passed, affected deployments should be checked promptly to avoid token mismatches and reduce unauthorized-access risk.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#doc-2026-08-05-howto-sspr-authenticationdata-05" style="color:#11181d;text-decoration:none">SSPR authentication-data rollout milestones moved later</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID documentation now lists 9 November 2026 instead of 6 August for the registration campaign, and 5 October instead of 7 September for accepting only explicitly registered methods. This is a schedule update, so administrators should revise rollout plans and user communications rather than infer a new authentication capability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#doc-2026-08-05-choose-a-telephony-provider-for-sms-and-voice-authentication-01" style="color:#11181d;text-decoration:none">Customer-managed SMS and voice providers are planned, not yet available</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new concept article describes planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning 18 September 2026 and configuration beginning 30 October, but providers cannot be configured yet. Administrators can use the interim period to identify affected users, evaluate requirements, and plan a limited pilot and fallback method; Microsoft recommends phishing-resistant methods such as passkeys where possible.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-05/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 5 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 5 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/" style="color:#11181d;text-decoration:none">Urgent Entra cleanup: MemberOf retires by 3 November 2026, while GitHub Actions OIDC migration is already overdue</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The significant work on 5 August is deadline-driven rather than a broad feature launch. Entra ID is retiring MemberOf rules, with a specific ID Governance failure mode arriving earlier for automatic assignment policies; Workload ID&#039;s GitHub Actions OIDC migration deadline was late July. Separately, SSPR rollout milestones moved, and a new telephony-provider article describes future planning only. Other edits were lower-impact documentation clarification: Global Secure Access clarified Agent/User source classification for a still-preview condition, provisioning documentation described read-only MCP log analysis, and a consent page changed only capitalization and alt text.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#MC1448379" style="color:#11181d;text-decoration:none">MemberOf rule operator retirement sets a 3 November 2026 remediation deadline</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID will retire the MemberOf rule operator in dynamic groups, administrative units, and entitlement policies. Administrators should identify and replace affected rules before the deadline to avoid stale access, licensing, and policy-enforcement results.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#doc-2026-08-05-configure-an-automatic-assignment-policy-for-an-access-package-in-entitlement-management-03" style="color:#11181d;text-decoration:none">Entitlement Management will quarantine automatic-assignment policies that still use MemberOf</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Starting 27 October 2026, automatic assignment policies using MemberOf will be quarantined: assignment processing will stop, and no assignments will be added or removed until MemberOf is removed. The updated guidance points administrators to a PowerShell discovery script and replacement rules using a supported attribute-based operator or an alternative assignment method.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#MC1447671" style="color:#11181d;text-decoration:none">GitHub Actions OIDC subjects must move to immutable repository and owner IDs</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Workload ID message says GitHub Actions now supports immutable OIDC subject formats containing repository and owner IDs. Organizations using GitHub Actions federated identity credentials were told to migrate by late July 2026; because that date has passed, affected deployments should be checked promptly to avoid token mismatches and reduce unauthorized-access risk.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#doc-2026-08-05-howto-sspr-authenticationdata-05" style="color:#11181d;text-decoration:none">SSPR authentication-data rollout milestones moved later</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID documentation now lists 9 November 2026 instead of 6 August for the registration campaign, and 5 October instead of 7 September for accepting only explicitly registered methods. This is a schedule update, so administrators should revise rollout plans and user communications rather than infer a new authentication capability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-05/#doc-2026-08-05-choose-a-telephony-provider-for-sms-and-voice-authentication-01" style="color:#11181d;text-decoration:none">Customer-managed SMS and voice providers are planned, not yet available</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new concept article describes planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning 18 September 2026 and configuration beginning 30 October, but providers cannot be configured yet. Administrators can use the interim period to identify affected users, evaluate requirements, and plan a limited pilot and fallback method; Microsoft recommends phishing-resistant methods such as passkeys where possible.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-05/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 5 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID documents SMS and voice MFA deadlines for public-cloud tenants — 4 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-04/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-04/</guid>
      <pubDate>Tue, 04 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 4 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/" style="color:#11181d;text-decoration:none">Entra ID documents SMS and voice MFA deadlines for public-cloud tenants</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The substantive change on 4 August is an Entra ID MFA retirement and behavior timeline: the updated documentation says passkeys will be automatically enabled for users using SMS or voice on 1 September 2026, and tenants without a customer-managed telecom provider will lose SMS and voice MFA from 1 February 2027. Azure AD B2C and Entra External ID are excluded. The other three updates are documentation and reference changes, including Preview provisioning guidance, revised licensing identifiers, and a link-only clarification for attribute mappings; there is no evidence of a general-availability launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-sms-voice-retirement-02" style="color:#11181d;text-decoration:none">SMS and voice MFA retirement timeline is now explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Entra ID fundamentals documentation states that passkeys will be automatically enabled for users using SMS or voice on 1 September 2026. From 1 February 2027, public-cloud tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. Azure AD B2C and Entra External ID are excluded. This is a documented behavior and retirement change, not a new general-availability feature.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-extend-application-attributes-01" style="color:#11181d;text-decoration:none">Provisioning guidance adds Graph-based custom task extensions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Extend Application Attributes article now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and request/response examples. The workflow example is labeled Preview, so the supplied evidence does not establish general availability. It also describes linking the extension to an extensibility workflow and target attribute.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-product-names-and-service-plan-identifiers-for-licensing-03" style="color:#11181d;text-decoration:none">Licensing reference updates service-plan identifiers and adds Agent 365</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID licensing reference now links to license management in the Azure portal, updates its table as of 3 August 2026, adds Agent 365, and revises service and plan identifier entries. This is a reference-data update rather than an indicated licensing behavior change; administrators using licensing APIs, PowerShell, or CSV data should review the revised entries.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-customize-application-attributes-04" style="color:#11181d;text-decoration:none">Attribute-customization guidance adds an LCW workflow link</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Customize Application Attributes article now links to guidance on extending attribute mappings with LCW extensibility workflows. This is an ordinary documentation clarification, and the supplied evidence explicitly indicates no product behavior change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-04/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 4 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 4 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/" style="color:#11181d;text-decoration:none">Entra ID documents SMS and voice MFA deadlines for public-cloud tenants</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The substantive change on 4 August is an Entra ID MFA retirement and behavior timeline: the updated documentation says passkeys will be automatically enabled for users using SMS or voice on 1 September 2026, and tenants without a customer-managed telecom provider will lose SMS and voice MFA from 1 February 2027. Azure AD B2C and Entra External ID are excluded. The other three updates are documentation and reference changes, including Preview provisioning guidance, revised licensing identifiers, and a link-only clarification for attribute mappings; there is no evidence of a general-availability launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-sms-voice-retirement-02" style="color:#11181d;text-decoration:none">SMS and voice MFA retirement timeline is now explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Entra ID fundamentals documentation states that passkeys will be automatically enabled for users using SMS or voice on 1 September 2026. From 1 February 2027, public-cloud tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. Azure AD B2C and Entra External ID are excluded. This is a documented behavior and retirement change, not a new general-availability feature.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-extend-application-attributes-01" style="color:#11181d;text-decoration:none">Provisioning guidance adds Graph-based custom task extensions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Extend Application Attributes article now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and request/response examples. The workflow example is labeled Preview, so the supplied evidence does not establish general availability. It also describes linking the extension to an extensibility workflow and target attribute.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-product-names-and-service-plan-identifiers-for-licensing-03" style="color:#11181d;text-decoration:none">Licensing reference updates service-plan identifiers and adds Agent 365</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID licensing reference now links to license management in the Azure portal, updates its table as of 3 August 2026, adds Agent 365, and revises service and plan identifier entries. This is a reference-data update rather than an indicated licensing behavior change; administrators using licensing APIs, PowerShell, or CSV data should review the revised entries.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-04/#doc-2026-08-04-customize-application-attributes-04" style="color:#11181d;text-decoration:none">Attribute-customization guidance adds an LCW workflow link</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Customize Application Attributes article now links to guidance on extending attribute mappings with LCW extensibility workflows. This is an ordinary documentation clarification, and the supplied evidence explicitly indicates no product behavior change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-04/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 4 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Internet Access guidance expands the profile’s traffic and policy model — 3 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-03/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-03/</guid>
      <pubDate>Mon, 03 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 3 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-03/" style="color:#11181d;text-decoration:none">Internet Access guidance expands the profile’s traffic and policy model</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period contained one documentation update for Microsoft Entra Internet Access. The revised guidance now covers traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. This is a documentation expansion; the supplied evidence does not indicate a new release or changed availability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-03/#doc-2026-08-03-how-to-manage-the-internet-access-profile-01" style="color:#11181d;text-decoration:none">Internet Access profile documentation adds expanded forwarding, policy, and bypass guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The “How to manage the Internet Access profile” article now describes forwarding through the Global Secure Access client and remote networks, six policies rather than three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. Custom Bypass configuration guidance also now covers destination types, ports, and protocols.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-03/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 3 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 3 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-03/" style="color:#11181d;text-decoration:none">Internet Access guidance expands the profile’s traffic and policy model</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period contained one documentation update for Microsoft Entra Internet Access. The revised guidance now covers traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. This is a documentation expansion; the supplied evidence does not indicate a new release or changed availability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-03/#doc-2026-08-03-how-to-manage-the-internet-access-profile-01" style="color:#11181d;text-decoration:none">Internet Access profile documentation adds expanded forwarding, policy, and bypass guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The “How to manage the Internet Access profile” article now describes forwarding through the Global Secure Access client and remote networks, six policies rather than three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. Custom Bypass configuration guidance also now covers destination types, ports, and protocols.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-03/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 3 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>1 August 2026: Custom-branding CSS retirement is the clearest action; Conditional Access enforcement and tenant-governance guidance are the other key signals — 1 August 2026</title>
      <link>https://daily.entra.news/day/2026-08-01/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-08-01/</guid>
      <pubDate>Sat, 01 Aug 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 1 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/" style="color:#11181d;text-decoration:none">1 August 2026: Custom-branding CSS retirement is the clearest action; Conditional Access enforcement and tenant-governance guidance are the other key signals</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Two Microsoft Entra ID Message Center items carry the greatest operational weight. Microsoft Entra ID will retire custom CSS positioning properties in company branding starting in October 2026, while a Conditional Access notice gives 15 June 2026 as the start date for stronger enforcement of policies targeting All resources with exclusions in certain scope-only sign-ins. The remaining notable changes are documentation and architecture guidance: Tenant Governance baseline and drift-monitoring procedures, a new tenant-estate architecture set, and Internet Access/Defender for Cloud Apps coexistence instructions. The supplied evidence does not establish a GA or feature launch for those Learn updates.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#MC1435782" style="color:#11181d;text-decoration:none">Retirement: custom CSS positioning in Microsoft Entra company branding</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting in October 2026 as a security and phishing-resistance measure. Existing users must remove those properties, with no migration path provided; branding elements will remain visible but can return to default placement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#MC1223829" style="color:#11181d;text-decoration:none">Changed behavior: Conditional Access enforcement for resource exclusions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Message Center notice states that, starting 15 June 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Custom applications using only those requests may encounter new challenges such as MFA. Because the stated date precedes this reporting period, affected app owners should evaluate current sign-in behavior; the notice says most organizations need no action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#doc-2026-08-01-create-configuration-snapshots-08" style="color:#11181d;text-decoration:none">Tenant Governance documentation now connects snapshots, drift monitoring, and permissions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Entra Tenant Governance article documents configuration snapshots for tenant baselines or audit evidence. Related updates cover monitors that evaluate a tenant against a baseline and report configuration drift, viewing results, end-to-end deployment, and the application permissions and roles used by the configuration-management service. The evidence describes a procedural documentation expansion, not a stated preview, GA, or service-behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#doc-2026-08-01-microsoft-entra-tenant-estate-guidance-introduction-03" style="color:#11181d;text-decoration:none">New guidance for composing a Microsoft Entra tenant estate</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new architecture-guidance set introduces common tenant patterns intended to help organizations meet requirements with as few tenants as possible. Companion guidance covers primary production, nonproduction multitenant environments, collaborating production tenants, business-partner access, critical business systems, and hybrid identity and isolation. It is design guidance for comparing architectural options, not evidence of a mandatory tenant restructuring.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#doc-2026-08-01-global-secure-access-and-microsoft-defender-for-cloud-apps-coexistence-01" style="color:#11181d;text-decoration:none">New coexistence guidance for Microsoft Entra Internet Access and Defender for Cloud Apps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new article explains how to configure Microsoft Entra Internet Access alongside Microsoft Defender for Cloud Apps without proxying traffic twice. This is targeted operational guidance for environments using both products, rather than an announced launch or availability change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-01/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 1 August 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 1 August 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/" style="color:#11181d;text-decoration:none">1 August 2026: Custom-branding CSS retirement is the clearest action; Conditional Access enforcement and tenant-governance guidance are the other key signals</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Two Microsoft Entra ID Message Center items carry the greatest operational weight. Microsoft Entra ID will retire custom CSS positioning properties in company branding starting in October 2026, while a Conditional Access notice gives 15 June 2026 as the start date for stronger enforcement of policies targeting All resources with exclusions in certain scope-only sign-ins. The remaining notable changes are documentation and architecture guidance: Tenant Governance baseline and drift-monitoring procedures, a new tenant-estate architecture set, and Internet Access/Defender for Cloud Apps coexistence instructions. The supplied evidence does not establish a GA or feature launch for those Learn updates.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#MC1435782" style="color:#11181d;text-decoration:none">Retirement: custom CSS positioning in Microsoft Entra company branding</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting in October 2026 as a security and phishing-resistance measure. Existing users must remove those properties, with no migration path provided; branding elements will remain visible but can return to default placement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#MC1223829" style="color:#11181d;text-decoration:none">Changed behavior: Conditional Access enforcement for resource exclusions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Message Center notice states that, starting 15 June 2026, Conditional Access policies targeting All resources with exclusions will be enforced for sign-ins requesting only certain OIDC or directory scopes. Custom applications using only those requests may encounter new challenges such as MFA. Because the stated date precedes this reporting period, affected app owners should evaluate current sign-in behavior; the notice says most organizations need no action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#doc-2026-08-01-create-configuration-snapshots-08" style="color:#11181d;text-decoration:none">Tenant Governance documentation now connects snapshots, drift monitoring, and permissions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Entra Tenant Governance article documents configuration snapshots for tenant baselines or audit evidence. Related updates cover monitors that evaluate a tenant against a baseline and report configuration drift, viewing results, end-to-end deployment, and the application permissions and roles used by the configuration-management service. The evidence describes a procedural documentation expansion, not a stated preview, GA, or service-behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#doc-2026-08-01-microsoft-entra-tenant-estate-guidance-introduction-03" style="color:#11181d;text-decoration:none">New guidance for composing a Microsoft Entra tenant estate</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new architecture-guidance set introduces common tenant patterns intended to help organizations meet requirements with as few tenants as possible. Companion guidance covers primary production, nonproduction multitenant environments, collaborating production tenants, business-partner access, critical business systems, and hybrid identity and isolation. It is design guidance for comparing architectural options, not evidence of a mandatory tenant restructuring.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-08-01/#doc-2026-08-01-global-secure-access-and-microsoft-defender-for-cloud-apps-coexistence-01" style="color:#11181d;text-decoration:none">New coexistence guidance for Microsoft Entra Internet Access and Defender for Cloud Apps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new article explains how to configure Microsoft Entra Internet Access alongside Microsoft Defender for Cloud Apps without proxying traffic twice. This is targeted operational guidance for environments using both products, rather than an announced launch or availability change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-08-01/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 1 August 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Workload ID credential guidance is more prescriptive; SMS/voice retirement scope is limited to public cloud — 31 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-31/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-31/</guid>
      <pubDate>Fri, 31 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 31 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/" style="color:#11181d;text-decoration:none">Workload ID credential guidance is more prescriptive; SMS/voice retirement scope is limited to public cloud</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period contained three documentation updates and no supplied evidence of a new feature launch, preview, or general-availability change. The meaningful changes clarify Workload ID federated-credential values and GitHub subject mapping, while an Entra ID retirement page now distinguishes public-cloud timing from other cloud environments.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/#doc-2026-07-31-workload-identities-github-immutable-subjects-02" style="color:#11181d;text-decoration:none">GitHub Workload ID guidance specifies app object IDs and per-subject credentials</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated GitHub immutable-subjects guidance says to replace `&lt;application-object-id&gt;` with the object ID of the app registration and create one credential for each subject presented by the workflow, such as a branch or environment. This is configuration guidance, not evidence of a new capability or changed service behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/#doc-2026-07-31-workload-identities-federated-credential-mutable-subjects-01" style="color:#11181d;text-decoration:none">Federated-credential documentation shows the token-exchange audience value</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The mutable-subjects documentation update includes `&quot;audiences&quot;: [&quot;api://AzureADTokenExchange&quot;]`. The supplied evidence establishes a documentation change only, so administrators should use the value to verify applicable federated-credential definitions rather than treat it as proof of a tenant-wide behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/#doc-2026-07-31-sms-voice-retirement-03" style="color:#11181d;text-decoration:none">SMS and voice retirement guidance is explicitly scoped to public cloud</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID retirement documentation now states that its timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, with advance communications promised; no specific dates or migration actions are included in this update.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-31/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 31 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 31 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/" style="color:#11181d;text-decoration:none">Workload ID credential guidance is more prescriptive; SMS/voice retirement scope is limited to public cloud</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period contained three documentation updates and no supplied evidence of a new feature launch, preview, or general-availability change. The meaningful changes clarify Workload ID federated-credential values and GitHub subject mapping, while an Entra ID retirement page now distinguishes public-cloud timing from other cloud environments.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/#doc-2026-07-31-workload-identities-github-immutable-subjects-02" style="color:#11181d;text-decoration:none">GitHub Workload ID guidance specifies app object IDs and per-subject credentials</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated GitHub immutable-subjects guidance says to replace `&lt;application-object-id&gt;` with the object ID of the app registration and create one credential for each subject presented by the workflow, such as a branch or environment. This is configuration guidance, not evidence of a new capability or changed service behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/#doc-2026-07-31-workload-identities-federated-credential-mutable-subjects-01" style="color:#11181d;text-decoration:none">Federated-credential documentation shows the token-exchange audience value</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The mutable-subjects documentation update includes `&quot;audiences&quot;: [&quot;api://AzureADTokenExchange&quot;]`. The supplied evidence establishes a documentation change only, so administrators should use the value to verify applicable federated-credential definitions rather than treat it as proof of a tenant-wide behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-31/#doc-2026-07-31-sms-voice-retirement-03" style="color:#11181d;text-decoration:none">SMS and voice retirement guidance is explicitly scoped to public cloud</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID retirement documentation now states that its timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, with advance communications promised; no specific dates or migration actions are included in this update.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-31/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 31 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Security guidance leads 30 July: immutable GitHub Actions subjects, passkey migration, and Tenant Governance preview — 30 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-30/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-30/</guid>
      <pubDate>Thu, 30 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 30 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/" style="color:#11181d;text-decoration:none">Security guidance leads 30 July: immutable GitHub Actions subjects, passkey migration, and Tenant Governance preview</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">30 July was primarily a Microsoft Learn documentation day, but it contained two important security threads. New Workload ID guidance covers the risk of mutable OIDC subjects and migration of GitHub Actions federated identity credentials to GitHub&#039;s immutable subject format; updated Entra ID guidance covers preparation for retiring Microsoft-provided SMS and voice authentication in favor of passkeys. ID Governance also added documented Microsoft Graph investigation guidance for related-tenant signals, explicitly in preview, and updated its delegated-administration guidance. The remaining edits, including Lifecycle Workflow email attributes, External ID OIDC setup, Global Secure Access tenant restrictions, and Cloud Sync prerequisites, are best read as instructional clarifications rather than confirmed launches or behavior changes.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-migrate-github-actions-federated-credentials-to-immutable-subjects-02" style="color:#11181d;text-decoration:none">Workload ID: new guidance moves GitHub Actions credentials toward immutable subjects</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Two new Workload ID pages form a related security guidance package: mutable OIDC subject claims can expose federated identity credentials to subject recycling, and GitHub Actions credentials can be migrated from mutable subjects to GitHub&#039;s immutable subject format. This is documentation and security guidance, not evidence of a new feature launch or an automatic tenant-wide change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-09" style="color:#11181d;text-decoration:none">Entra ID: updated preparation guidance covers passkeys and SMS/voice retirement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. The supplied evidence does not provide a retirement date or establish that passkeys became the default, or that SMS and voice were disabled, on 30 July.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-investigate-related-tenant-signals-by-using-microsoft-graph-preview-03" style="color:#11181d;text-decoration:none">Tenant Governance: related-tenant signal investigation is documented through Microsoft Graph (preview)</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new ID Governance page documents how Microsoft Graph can retrieve the underlying users and applications behind Tenant Governance related-tenant discovery signals. Because the route is explicitly preview, this is newly documented preview usage rather than evidence of general availability or a production behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-cross-tenant-delegated-administration-04" style="color:#11181d;text-decoration:none">ID Governance: updated guidance clarifies cross-tenant delegated administration</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated guidance describes cross-tenant delegated administration and its GDAP-based permission model for managing tenants in Microsoft Entra. This clarifies the documented operating model; the supplied evidence does not announce a new permission set or rollout on this date.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-30/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 30 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 30 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/" style="color:#11181d;text-decoration:none">Security guidance leads 30 July: immutable GitHub Actions subjects, passkey migration, and Tenant Governance preview</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">30 July was primarily a Microsoft Learn documentation day, but it contained two important security threads. New Workload ID guidance covers the risk of mutable OIDC subjects and migration of GitHub Actions federated identity credentials to GitHub&#039;s immutable subject format; updated Entra ID guidance covers preparation for retiring Microsoft-provided SMS and voice authentication in favor of passkeys. ID Governance also added documented Microsoft Graph investigation guidance for related-tenant signals, explicitly in preview, and updated its delegated-administration guidance. The remaining edits, including Lifecycle Workflow email attributes, External ID OIDC setup, Global Secure Access tenant restrictions, and Cloud Sync prerequisites, are best read as instructional clarifications rather than confirmed launches or behavior changes.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-migrate-github-actions-federated-credentials-to-immutable-subjects-02" style="color:#11181d;text-decoration:none">Workload ID: new guidance moves GitHub Actions credentials toward immutable subjects</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Two new Workload ID pages form a related security guidance package: mutable OIDC subject claims can expose federated identity credentials to subject recycling, and GitHub Actions credentials can be migrated from mutable subjects to GitHub&#039;s immutable subject format. This is documentation and security guidance, not evidence of a new feature launch or an automatic tenant-wide change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-09" style="color:#11181d;text-decoration:none">Entra ID: updated preparation guidance covers passkeys and SMS/voice retirement</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. The supplied evidence does not provide a retirement date or establish that passkeys became the default, or that SMS and voice were disabled, on 30 July.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-investigate-related-tenant-signals-by-using-microsoft-graph-preview-03" style="color:#11181d;text-decoration:none">Tenant Governance: related-tenant signal investigation is documented through Microsoft Graph (preview)</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new ID Governance page documents how Microsoft Graph can retrieve the underlying users and applications behind Tenant Governance related-tenant discovery signals. Because the route is explicitly preview, this is newly documented preview usage rather than evidence of general availability or a production behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-30/#doc-2026-07-30-cross-tenant-delegated-administration-04" style="color:#11181d;text-decoration:none">ID Governance: updated guidance clarifies cross-tenant delegated administration</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated guidance describes cross-tenant delegated administration and its GDAP-based permission model for managing tenants in Microsoft Entra. This clarifies the documented operating model; the supplied evidence does not announce a new permission set or rollout on this date.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-30/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 30 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Connect Health installation guidance adds URL requirements for locked-down environments — 29 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-29/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-29/</guid>
      <pubDate>Wed, 29 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 29 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-29/" style="color:#11181d;text-decoration:none">Connect Health installation guidance adds URL requirements for locked-down environments</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The only change on 29 July was an update to the Entra ID Connect Health Agent Install documentation. It clarifies that highly restricted environments need additional URLs beyond those listed for Internet Explorer Enhanced Security, including URLs in the following table. This is documentation clarification, not evidence of a new feature, availability change, or changed tenant behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-29/#doc-2026-07-29-connect-health-agent-install-01" style="color:#11181d;text-decoration:none">Connect Health agent documentation clarifies allowlist requirements</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The installation guidance now explicitly states that highly locked-down environments must add more URLs than those listed in the Internet Explorer Enhanced Security table and must also add the URLs in the next section’s table. The update affects installation and network configuration guidance rather than the agent’s stated functionality.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-29/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 29 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 29 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-29/" style="color:#11181d;text-decoration:none">Connect Health installation guidance adds URL requirements for locked-down environments</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The only change on 29 July was an update to the Entra ID Connect Health Agent Install documentation. It clarifies that highly restricted environments need additional URLs beyond those listed for Internet Explorer Enhanced Security, including URLs in the following table. This is documentation clarification, not evidence of a new feature, availability change, or changed tenant behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-29/#doc-2026-07-29-connect-health-agent-install-01" style="color:#11181d;text-decoration:none">Connect Health agent documentation clarifies allowlist requirements</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The installation guidance now explicitly states that highly locked-down environments must add more URLs than those listed in the Internet Explorer Enhanced Security table and must also add the URLs in the next section’s table. The update affects installation and network configuration guidance rather than the agent’s stated functionality.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-29/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 29 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID will optimize passkey registration across existing registration and authentication experiences — 28 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-28/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-28/</guid>
      <pubDate>Tue, 28 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 28 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-28/" style="color:#11181d;text-decoration:none">Entra ID will optimize passkey registration across existing registration and authentication experiences</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft’s 28 July Message Center notice says Entra ID will optimize passkey registration through Registration Campaign, Authentication Strengths, and My Sign-Ins. The stated goals are to improve compliance with passkey policies and prioritize local device passkeys, with rollout planned for late August 2026.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-28/#MC1440968" style="color:#11181d;text-decoration:none">Passkey registration optimization announced</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Entra ID is changing the passkey registration experience across Registration Campaign, Authentication Strengths, and My Sign-Ins to encourage compliance with passkey policies and prioritize local device passkeys. This is described as an optimization rolling out in late August 2026, not as a separately identified preview, general-availability launch, or retirement.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-28/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 28 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 28 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-28/" style="color:#11181d;text-decoration:none">Entra ID will optimize passkey registration across existing registration and authentication experiences</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft’s 28 July Message Center notice says Entra ID will optimize passkey registration through Registration Campaign, Authentication Strengths, and My Sign-Ins. The stated goals are to improve compliance with passkey policies and prioritize local device passkeys, with rollout planned for late August 2026.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-28/#MC1440968" style="color:#11181d;text-decoration:none">Passkey registration optimization announced</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Entra ID is changing the passkey registration experience across Registration Campaign, Authentication Strengths, and My Sign-Ins to encourage compliance with passkey policies and prioritize local device passkeys. This is described as an optimization rolling out in late August 2026, not as a separately identified preview, general-availability launch, or retirement.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-28/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 28 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID had a quiet documentation-only day: token-expiry semantics and SCIM authentication guidance were clarified. — 25 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-25/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-25/</guid>
      <pubDate>Sat, 25 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 25 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-25/" style="color:#11181d;text-decoration:none">Entra ID had a quiet documentation-only day: token-expiry semantics and SCIM authentication guidance were clarified.</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">All five entries were Microsoft Learn updates for Entra ID; there were no new features, retirements, or Message Center notices. The most consequential updates clarify that the JWT `exp` value does not guarantee acceptance until that time and explicitly discourage username/password authentication for new SCIM gallery and non-gallery apps. The remaining edits are lower-impact documentation changes: an app-gallery page adds a link to the SCIM 2.0 tutorial, while the Salesforce and Salesforce Sandbox pages contain a general account-management statement. The supplied evidence does not establish a tenant-side rollout or changed enforcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-25/#doc-2026-07-25-access-token-claims-reference-05" style="color:#11181d;text-decoration:none">Access Token Claims Reference clarifies that `exp` is not an unconditional acceptance deadline</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated `exp` entry defines a Unix timestamp before which a JWT can be accepted, while stating that a resource may reject it earlier when authentication requirements change or the token is revoked. This is a token-processing documentation clarification, not evidence of a new validation feature.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-25/#doc-2026-07-25-use-scim-to-provision-users-and-groups-01" style="color:#11181d;text-decoration:none">SCIM guidance explicitly rules out username/password for new app provisioning</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated SCIM comparison labels username/password insecure and not recommended or supported by Microsoft Entra ID, and states that it is not supported for new gallery or non-gallery apps. This is security and compatibility guidance; the supplied evidence does not say that existing integrations were disabled.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-25/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 25 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 25 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-25/" style="color:#11181d;text-decoration:none">Entra ID had a quiet documentation-only day: token-expiry semantics and SCIM authentication guidance were clarified.</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">All five entries were Microsoft Learn updates for Entra ID; there were no new features, retirements, or Message Center notices. The most consequential updates clarify that the JWT `exp` value does not guarantee acceptance until that time and explicitly discourage username/password authentication for new SCIM gallery and non-gallery apps. The remaining edits are lower-impact documentation changes: an app-gallery page adds a link to the SCIM 2.0 tutorial, while the Salesforce and Salesforce Sandbox pages contain a general account-management statement. The supplied evidence does not establish a tenant-side rollout or changed enforcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-25/#doc-2026-07-25-access-token-claims-reference-05" style="color:#11181d;text-decoration:none">Access Token Claims Reference clarifies that `exp` is not an unconditional acceptance deadline</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated `exp` entry defines a Unix timestamp before which a JWT can be accepted, while stating that a resource may reject it earlier when authentication requirements change or the token is revoked. This is a token-processing documentation clarification, not evidence of a new validation feature.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-25/#doc-2026-07-25-use-scim-to-provision-users-and-groups-01" style="color:#11181d;text-decoration:none">SCIM guidance explicitly rules out username/password for new app provisioning</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated SCIM comparison labels username/password insecure and not recommended or supported by Microsoft Entra ID, and states that it is not supported for new gallery or non-gallery apps. This is security and compatibility guidance; the supplied evidence does not say that existing integrations were disabled.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-25/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 25 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Plan for the upcoming Entra ID passwordless password-change flow; Global Secure Access guidance adds concrete egress and per-app configuration details. — 24 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-24/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-24/</guid>
      <pubDate>Fri, 24 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 24 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/" style="color:#11181d;text-decoration:none">Plan for the upcoming Entra ID passwordless password-change flow; Global Secure Access guidance adds concrete egress and per-app configuration details.</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential item is Message Center notice MC1437671: Microsoft Entra will let passwordless users change passwords in My Sign-Ins with passkeys or Windows Hello, without knowing the current password or using SSPR. It is disabled by default and planned for global rollout in late October 2026. The remaining notable changes are documentation updates or new integration guidance for Global Secure Access, Azure Databricks provisioning, and GitHub Actions federation. No retirement or GA/preview announcement is evidenced; the FortiGate entry is a narrow URL-level tutorial edit.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#MC1437671" style="color:#11181d;text-decoration:none">Upcoming Entra ID passwordless password change requires admin activation</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra is announcing a future My Sign-Ins flow in which passwordless users can change passwords using strong credentials such as passkeys or Windows Hello, without the current password or SSPR. The feature is disabled by default, requires administrator activation, and is scheduled for global rollout in late October 2026. This is a future Message Center announcement, not evidence that the capability is generally available today.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-global-secure-access-egress-ip-ranges-02" style="color:#11181d;text-decoration:none">Global Secure Access adds an egress IP range reference</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Global Secure Access page lists the IP ranges used for outbound internet traffic, giving administrators the information needed to allowlist those ranges on target services. The evidence supports a new reference document, not a claim that the service itself launched or that its egress behavior changed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-configure-per-app-access-03" style="color:#11181d;text-decoration:none">Per App Access guidance clarifies the application ID and default routing reset</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated instructions tell administrators to replace `{appRegistrationObjectId}` with the application registration&#039;s Object ID, located in the Microsoft Entra admin center under the app registration&#039;s Overview page. They also specify that setting `trafficRoutingMethod` to `random` returns Per App Access to its default behavior. This is a configuration-documentation update; the record does not establish a broader service behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-configure-azure-databricks-for-automatic-user-provisioning-with-microsoft-entra-id-01" style="color:#11181d;text-decoration:none">New Entra ID guidance covers Azure Databricks SCIM provisioning</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new integration guide explains how to configure Microsoft Entra ID to automatically provision and de-provision user accounts in Azure Databricks using SCIM. It is implementation guidance for the integration, not evidence of a newly announced provisioning feature or availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-workload-identity-federation-05" style="color:#11181d;text-decoration:none">Workload ID documentation makes the GitHub Actions federation flow explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Workload Identity Federation guidance describes establishing trust between a user-assigned managed identity or application in Microsoft Entra ID and a GitHub repository, using the admin center or Microsoft Graph, followed by configuring a GitHub Actions workflow to obtain an access token and access Azure resources. This is clarification of the setup path rather than a stated new capability or rollout.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-24/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 24 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 24 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/" style="color:#11181d;text-decoration:none">Plan for the upcoming Entra ID passwordless password-change flow; Global Secure Access guidance adds concrete egress and per-app configuration details.</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential item is Message Center notice MC1437671: Microsoft Entra will let passwordless users change passwords in My Sign-Ins with passkeys or Windows Hello, without knowing the current password or using SSPR. It is disabled by default and planned for global rollout in late October 2026. The remaining notable changes are documentation updates or new integration guidance for Global Secure Access, Azure Databricks provisioning, and GitHub Actions federation. No retirement or GA/preview announcement is evidenced; the FortiGate entry is a narrow URL-level tutorial edit.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#MC1437671" style="color:#11181d;text-decoration:none">Upcoming Entra ID passwordless password change requires admin activation</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra is announcing a future My Sign-Ins flow in which passwordless users can change passwords using strong credentials such as passkeys or Windows Hello, without the current password or SSPR. The feature is disabled by default, requires administrator activation, and is scheduled for global rollout in late October 2026. This is a future Message Center announcement, not evidence that the capability is generally available today.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-global-secure-access-egress-ip-ranges-02" style="color:#11181d;text-decoration:none">Global Secure Access adds an egress IP range reference</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Global Secure Access page lists the IP ranges used for outbound internet traffic, giving administrators the information needed to allowlist those ranges on target services. The evidence supports a new reference document, not a claim that the service itself launched or that its egress behavior changed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-configure-per-app-access-03" style="color:#11181d;text-decoration:none">Per App Access guidance clarifies the application ID and default routing reset</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated instructions tell administrators to replace `{appRegistrationObjectId}` with the application registration&#039;s Object ID, located in the Microsoft Entra admin center under the app registration&#039;s Overview page. They also specify that setting `trafficRoutingMethod` to `random` returns Per App Access to its default behavior. This is a configuration-documentation update; the record does not establish a broader service behavior change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-configure-azure-databricks-for-automatic-user-provisioning-with-microsoft-entra-id-01" style="color:#11181d;text-decoration:none">New Entra ID guidance covers Azure Databricks SCIM provisioning</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new integration guide explains how to configure Microsoft Entra ID to automatically provision and de-provision user accounts in Azure Databricks using SCIM. It is implementation guidance for the integration, not evidence of a newly announced provisioning feature or availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/identity-platform.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · Microsoft identity platform</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-24/#doc-2026-07-24-workload-identity-federation-05" style="color:#11181d;text-decoration:none">Workload ID documentation makes the GitHub Actions federation flow explicit</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Workload Identity Federation guidance describes establishing trust between a user-assigned managed identity or application in Microsoft Entra ID and a GitHub repository, using the admin center or Microsoft Graph, followed by configuring a GitHub Actions workflow to obtain an access token and access Azure resources. This is clarification of the setup path rather than a stated new capability or rollout.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-24/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 24 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>External ID authentication-retirement scope and tenant-restriction guidance lead a documentation-heavy 22 July — 22 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-22/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-22/</guid>
      <pubDate>Wed, 22 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 22 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/" style="color:#11181d;text-decoration:none">External ID authentication-retirement scope and tenant-restriction guidance lead a documentation-heavy 22 July</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">All supplied entries for the period are Microsoft Learn documentation updates; there are no new or removed entries. The most consequential update clarifies that B2B and internal guest users are in scope for the retirement of Microsoft-provided SMS and voice authentication, with passkey support planned by the end of calendar year 2026. Global Secure Access guidance also clarifies Universal Tenant Restrictions coverage and documents two optional Web Content Filtering conditions. The three Entra ID branding updates are ordinary reference and instructional refreshes. The evidence does not establish a new launch, preview, or general-availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-sms-voice-retirement-07" style="color:#11181d;text-decoration:none">External ID: Microsoft-provided SMS and voice retirement includes B2B and internal guest users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated retirement guidance places B2B users and internal guest users within the scope of Microsoft-provided SMS and voice authentication retirement. It says passkey support for these users is planned by the end of calendar year 2026. This is future retirement guidance; the supplied evidence does not provide a final retirement date or say that passkey support is generally available.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-universal-tenant-restrictions-03" style="color:#11181d;text-decoration:none">Global Secure Access: Universal Tenant Restrictions are documented for all Entra-integrated third-party apps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Universal Tenant Restrictions page states that the capability works with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in. This is a coverage and behavior clarification; the item is not identified as a new feature, preview, or GA announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-gsa-poc-internet-access-08" style="color:#11181d;text-decoration:none">External ID: architecture guidance points organizations toward Tenant Restrictions v2</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated architecture guidance directs readers to set up tenant restrictions v2 and tells organizations using v1 to review the v1-to-v2 migration guide. This is concrete migration guidance, but the supplied evidence does not state a forced cutover date or another availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-configure-web-content-filtering-05" style="color:#11181d;text-decoration:none">Global Secure Access: Web Content Filtering documents two optional traffic-aware rule conditions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The update states that Web Content Filtering supports two optional rule conditions that enable traffic-aware policy enforcement. The supplied summary does not name the conditions or provide release status, so this is best treated as documented capability detail rather than a confirmed launch or GA change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-agent-owners-sponsors-managers-06" style="color:#11181d;text-decoration:none">Agent ID: sponsor relationships are differentiated across agent resources and user accounts</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The revised guidance distinguishes sponsors associated with an agent&#039;s identity, blueprint, and blueprint principal from sponsors associated with an agent user account, and notes differences from the Entra user sponsor relationship. This is an object-model and governance clarification, not evidence of a new sponsor capability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-22/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 22 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 22 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/" style="color:#11181d;text-decoration:none">External ID authentication-retirement scope and tenant-restriction guidance lead a documentation-heavy 22 July</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">All supplied entries for the period are Microsoft Learn documentation updates; there are no new or removed entries. The most consequential update clarifies that B2B and internal guest users are in scope for the retirement of Microsoft-provided SMS and voice authentication, with passkey support planned by the end of calendar year 2026. Global Secure Access guidance also clarifies Universal Tenant Restrictions coverage and documents two optional Web Content Filtering conditions. The three Entra ID branding updates are ordinary reference and instructional refreshes. The evidence does not establish a new launch, preview, or general-availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-sms-voice-retirement-07" style="color:#11181d;text-decoration:none">External ID: Microsoft-provided SMS and voice retirement includes B2B and internal guest users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated retirement guidance places B2B users and internal guest users within the scope of Microsoft-provided SMS and voice authentication retirement. It says passkey support for these users is planned by the end of calendar year 2026. This is future retirement guidance; the supplied evidence does not provide a final retirement date or say that passkey support is generally available.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-universal-tenant-restrictions-03" style="color:#11181d;text-decoration:none">Global Secure Access: Universal Tenant Restrictions are documented for all Entra-integrated third-party apps</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Universal Tenant Restrictions page states that the capability works with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in. This is a coverage and behavior clarification; the item is not identified as a new feature, preview, or GA announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-gsa-poc-internet-access-08" style="color:#11181d;text-decoration:none">External ID: architecture guidance points organizations toward Tenant Restrictions v2</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated architecture guidance directs readers to set up tenant restrictions v2 and tells organizations using v1 to review the v1-to-v2 migration guide. This is concrete migration guidance, but the supplied evidence does not state a forced cutover date or another availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-configure-web-content-filtering-05" style="color:#11181d;text-decoration:none">Global Secure Access: Web Content Filtering documents two optional traffic-aware rule conditions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The update states that Web Content Filtering supports two optional rule conditions that enable traffic-aware policy enforcement. The supplied summary does not name the conditions or provide release status, so this is best treated as documented capability detail rather than a confirmed launch or GA change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-family.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Agent ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-22/#doc-2026-07-22-agent-owners-sponsors-managers-06" style="color:#11181d;text-decoration:none">Agent ID: sponsor relationships are differentiated across agent resources and user accounts</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The revised guidance distinguishes sponsors associated with an agent&#039;s identity, blueprint, and blueprint principal from sponsors associated with an agent user account, and notes differences from the Entra user sponsor relationship. This is an object-model and governance clarification, not evidence of a new sponsor capability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-22/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 22 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Existing FIDO2 tenants face automatic passkey-profile migration as Entra broadens passkey GA — 21 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-21/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-21/</guid>
      <pubDate>Tue, 21 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 21 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/" style="color:#11181d;text-decoration:none">Existing FIDO2 tenants face automatic passkey-profile migration as Entra broadens passkey GA</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period is driven by two distinct passkey changes: tenant-side migration to passkey profiles and general availability of Entra passkeys on Windows. It also introduces a network-layer Microsoft Purview DLP integration through Entra Internet Access and replaces legacy CAPTCHA protection in self-service password reset with backend abuse detection.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1221452" style="color:#11181d;text-decoration:none">Passkey profiles and existing FIDO2 configurations move to general availability</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">For tenants with Passkeys (FIDO2) enabled, Microsoft Entra is making passkey profiles and synced passkeys generally available. Existing configurations migrate to a Default passkey profile with a new passkeyType property, while automatic migration and registration-campaign updates roll out regionally through October 2026. This is a tenant-configuration behavior change, not merely a documentation update.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1419797" style="color:#11181d;text-decoration:none">Microsoft Purview DLP extends to the network layer through Entra Internet Access</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The integration enables inspection and protection of sensitive data in AI interactions and cloud services at the network layer, with policy enforcement, alerts, and auditing. The rollout is scheduled from July through October 2026 and spans Microsoft Purview, Microsoft Entra, and Defender administration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1282568" style="color:#11181d;text-decoration:none">Microsoft Entra passkeys on Windows reach general availability</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Windows capability is generally available from late April 2026, providing phishing-resistant, passwordless sign-in on corporate, personal, and shared Windows devices without explicit opt-in. Administrators can control the capability through Authentication Methods policies and Conditional Access; the notice says no action is needed unless blocking is desired.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1400824" style="color:#11181d;text-decoration:none">SSPR replaces legacy CAPTCHA with backend abuse detection</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Beginning in early August 2026, self-service password reset replaces legacy CAPTCHA with backend throttling and behavior-based abuse detection. The change is intended to improve security and accessibility while preserving current password-reset functionality, with no new controls and no user or administrator action required.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-21/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 21 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 21 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/" style="color:#11181d;text-decoration:none">Existing FIDO2 tenants face automatic passkey-profile migration as Entra broadens passkey GA</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The period is driven by two distinct passkey changes: tenant-side migration to passkey profiles and general availability of Entra passkeys on Windows. It also introduces a network-layer Microsoft Purview DLP integration through Entra Internet Access and replaces legacy CAPTCHA protection in self-service password reset with backend abuse detection.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1221452" style="color:#11181d;text-decoration:none">Passkey profiles and existing FIDO2 configurations move to general availability</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">For tenants with Passkeys (FIDO2) enabled, Microsoft Entra is making passkey profiles and synced passkeys generally available. Existing configurations migrate to a Default passkey profile with a new passkeyType property, while automatic migration and registration-campaign updates roll out regionally through October 2026. This is a tenant-configuration behavior change, not merely a documentation update.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1419797" style="color:#11181d;text-decoration:none">Microsoft Purview DLP extends to the network layer through Entra Internet Access</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The integration enables inspection and protection of sensitive data in AI interactions and cloud services at the network layer, with policy enforcement, alerts, and auditing. The rollout is scheduled from July through October 2026 and spans Microsoft Purview, Microsoft Entra, and Defender administration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1282568" style="color:#11181d;text-decoration:none">Microsoft Entra passkeys on Windows reach general availability</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Windows capability is generally available from late April 2026, providing phishing-resistant, passwordless sign-in on corporate, personal, and shared Windows devices without explicit opt-in. Administrators can control the capability through Authentication Methods policies and Conditional Access; the notice says no action is needed unless blocking is desired.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-21/#MC1400824" style="color:#11181d;text-decoration:none">SSPR replaces legacy CAPTCHA with backend abuse detection</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Beginning in early August 2026, self-service password reset replaces legacy CAPTCHA with backend throttling and behavior-based abuse detection. The change is intended to improve security and accessibility while preserving current password-reset functionality, with no new controls and no user or administrator action required.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-21/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 21 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Quiet period: one External ID documentation update, with no substantive change described — 20 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-20/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-20/</guid>
      <pubDate>Mon, 20 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 20 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-20/" style="color:#11181d;text-decoration:none">Quiet period: one External ID documentation update, with no substantive change described</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The 20 July period contains a single updated Microsoft Learn item for External ID, titled “Custom Oidc Federation Customers.” The supplied record provides only an IMPORTANT callout and does not explain whether the update changes configuration, behavior, availability, security guidance, or retirement status.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-20/#doc-2026-07-20-custom-oidc-federation-customers-01" style="color:#11181d;text-decoration:none">External ID documentation update has insufficient detail to classify its impact</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The “Custom Oidc Federation Customers” page was marked Updated, but its supplied summary contains only an IMPORTANT marker. The evidence does not support calling this a new feature, preview, general availability change, retirement, behavior change, security recommendation, or ordinary clarification.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-20/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 20 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 20 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-20/" style="color:#11181d;text-decoration:none">Quiet period: one External ID documentation update, with no substantive change described</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The 20 July period contains a single updated Microsoft Learn item for External ID, titled “Custom Oidc Federation Customers.” The supplied record provides only an IMPORTANT callout and does not explain whether the update changes configuration, behavior, availability, security guidance, or retirement status.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-20/#doc-2026-07-20-custom-oidc-federation-customers-01" style="color:#11181d;text-decoration:none">External ID documentation update has insufficient detail to classify its impact</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The “Custom Oidc Federation Customers” page was marked Updated, but its supplied summary contains only an IMPORTANT marker. The evidence does not support calling this a new feature, preview, general availability change, retirement, behavior change, security recommendation, or ordinary clarification.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-20/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 20 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>SharePoint OTP retirement leads the period; Entra Internet Access has a DLP rollout timeline and proxy security guidance — 18 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-18/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-18/</guid>
      <pubDate>Sat, 18 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 18 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/" style="color:#11181d;text-decoration:none">SharePoint OTP retirement leads the period; Entra Internet Access has a DLP rollout timeline and proxy security guidance</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">A Microsoft 365 Message Center major update says SharePoint One-Time Passcode authentication will retire in October 2026, with new external sharing using Microsoft Entra B2B from May 2026. A second message sets out the Microsoft Purview DLP integration timeline for Entra Internet Access, while updated Explicit Forward Proxy documentation provides Conditional Access guidance. The other supplied changes are ordinary documentation updates, with no specific new behavior identified in their summaries.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/#MC1243549" style="color:#11181d;text-decoration:none">SharePoint One-Time Passcode retires as external sharing moves to Microsoft Entra B2B</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft 365 Message Center classifies this as a major update: SharePoint One-Time Passcode authentication retires in October 2026. The transition is tied to new external sharing using Entra B2B from May 2026; external users need guest accounts for access, and administrators are told to update policies and manage those guests.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/#MC1181769" style="color:#11181d;text-decoration:none">Purview DLP integration with Entra Internet Access has a stated preview-to-GA timeline</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The message describes Microsoft Purview DLP integrating with Microsoft Entra Global Secure Access Internet Access to filter sensitive files at the network layer and help prevent leaks to unmanaged cloud apps. It lists mid-November 2025 as the public-preview start and September 2026 as the general-availability target, with granular policies managed through Purview and Defender. This is a rollout timeline, not evidence of a July 18 launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/#doc-2026-07-18-configure-a-microsoft-entra-conditional-access-policy-for-explicit-forward-proxy-01" style="color:#11181d;text-decoration:none">Updated Explicit Forward Proxy guidance emphasizes Conditional Access</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated guidance says a Conditional Access policy isn&#039;t required for Explicit Forward Proxy, but recommends using one to restrict proxy use to trusted networks. It also describes using Conditional Access to assign Microsoft Entra Internet Access security profiles to users. This is security and deployment guidance, not an announced change in proxy availability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-18/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 18 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 18 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/" style="color:#11181d;text-decoration:none">SharePoint OTP retirement leads the period; Entra Internet Access has a DLP rollout timeline and proxy security guidance</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">A Microsoft 365 Message Center major update says SharePoint One-Time Passcode authentication will retire in October 2026, with new external sharing using Microsoft Entra B2B from May 2026. A second message sets out the Microsoft Purview DLP integration timeline for Entra Internet Access, while updated Explicit Forward Proxy documentation provides Conditional Access guidance. The other supplied changes are ordinary documentation updates, with no specific new behavior identified in their summaries.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/#MC1243549" style="color:#11181d;text-decoration:none">SharePoint One-Time Passcode retires as external sharing moves to Microsoft Entra B2B</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft 365 Message Center classifies this as a major update: SharePoint One-Time Passcode authentication retires in October 2026. The transition is tied to new external sharing using Entra B2B from May 2026; external users need guest accounts for access, and administrators are told to update policies and manage those guests.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/#MC1181769" style="color:#11181d;text-decoration:none">Purview DLP integration with Entra Internet Access has a stated preview-to-GA timeline</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The message describes Microsoft Purview DLP integrating with Microsoft Entra Global Secure Access Internet Access to filter sensitive files at the network layer and help prevent leaks to unmanaged cloud apps. It lists mid-November 2025 as the public-preview start and September 2026 as the general-availability target, with granular policies managed through Purview and Defender. This is a rollout timeline, not evidence of a July 18 launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-18/#doc-2026-07-18-configure-a-microsoft-entra-conditional-access-policy-for-explicit-forward-proxy-01" style="color:#11181d;text-decoration:none">Updated Explicit Forward Proxy guidance emphasizes Conditional Access</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated guidance says a Conditional Access policy isn&#039;t required for Explicit Forward Proxy, but recommends using one to restrict proxy use to trusted networks. It also describes using Conditional Access to assign Microsoft Entra Internet Access security profiles to users. This is security and deployment guidance, not an announced change in proxy availability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-18/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 18 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID will make passkeys the default and retire Microsoft-provided SMS and voice authentication — 17 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-17/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-17/</guid>
      <pubDate>Fri, 17 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 17 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-17/" style="color:#11181d;text-decoration:none">Entra ID will make passkeys the default and retire Microsoft-provided SMS and voice authentication</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">17 July was a quiet Entra ID period, with one consequential Message Center announcement and one low-impact documentation update. The major update describes a future authentication behavior change: passkeys become the default on 1 September 2026, while Microsoft-provided SMS and voice authentication retire by 1 February 2027. The Linux Device Registration Tool item provides no evidence of changed product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-17/#MC1426371" style="color:#11181d;text-decoration:none">Passkeys become the default authentication method, with Microsoft-provided SMS and voice authentication retiring</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Microsoft 365 Message Center major update announces a planned Entra ID authentication change, not a launch occurring on this date. Passkeys will be the default authentication method starting 1 September 2026, and Microsoft-provided SMS and voice authentication will be retired by 1 February 2027. Customers must configure telecom providers for SMS and voice through the Microsoft Security Store to avoid disruption. The notice describes passkeys as phishing-resistant and available at no extra cost.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/troubleshooting.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Troubleshooting</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-17/#doc-2026-07-17-troubleshoot-device-registration-tool-linux-01" style="color:#11181d;text-decoration:none">Linux Device Registration Tool troubleshooting documentation was updated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Microsoft Learn page was marked as updated, but the supplied summary contains only a NOTE marker and no changed troubleshooting steps, tenant settings, security guidance, or rollout behavior. Treat this as an ordinary documentation clarification rather than evidence of a product change or required configuration action.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-17/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 17 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 17 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-17/" style="color:#11181d;text-decoration:none">Entra ID will make passkeys the default and retire Microsoft-provided SMS and voice authentication</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">17 July was a quiet Entra ID period, with one consequential Message Center announcement and one low-impact documentation update. The major update describes a future authentication behavior change: passkeys become the default on 1 September 2026, while Microsoft-provided SMS and voice authentication retire by 1 February 2027. The Linux Device Registration Tool item provides no evidence of changed product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-17/#MC1426371" style="color:#11181d;text-decoration:none">Passkeys become the default authentication method, with Microsoft-provided SMS and voice authentication retiring</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A Microsoft 365 Message Center major update announces a planned Entra ID authentication change, not a launch occurring on this date. Passkeys will be the default authentication method starting 1 September 2026, and Microsoft-provided SMS and voice authentication will be retired by 1 February 2027. Customers must configure telecom providers for SMS and voice through the Microsoft Security Store to avoid disruption. The notice describes passkeys as phishing-resistant and available at no extra cost.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/troubleshooting.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Troubleshooting</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-17/#doc-2026-07-17-troubleshoot-device-registration-tool-linux-01" style="color:#11181d;text-decoration:none">Linux Device Registration Tool troubleshooting documentation was updated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Microsoft Learn page was marked as updated, but the supplied summary contains only a NOTE marker and no changed troubleshooting steps, tenant settings, security guidance, or rollout behavior. Treat this as an ordinary documentation clarification rather than evidence of a product change or required configuration action.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-17/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 17 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>New Entra ID documentation covers automatic SSO-permission acceptance; ID Governance guidance clarifies inactive-user workflows — 16 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-16/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-16/</guid>
      <pubDate>Thu, 16 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 16 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/" style="color:#11181d;text-decoration:none">New Entra ID documentation covers automatic SSO-permission acceptance; ID Governance guidance clarifies inactive-user workflows</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential change is a new Entra ID page describing a supported registry setting that lets IT administrators automatically accept SSO permissions on managed Windows devices. Three ID Governance updates provide operational guidance for inactive-user workflows: setting the inactivity threshold, using the Pre-Offboard inactive users template, and testing execution with the What-if tool. The supplied evidence does not establish GA, preview status, retirement, or a broader tenant behavior change. The remaining Entra ID update only adds SLA performance data.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-admin-control-for-sso-prompts-01" style="color:#11181d;text-decoration:none">New admin control for SSO permission prompts</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Entra ID document says IT administrators can automatically accept SSO permissions on managed Windows devices through a supported registry setting. This documents an admin-controlled behavior, but the supplied evidence does not classify it as generally available or preview, nor does it provide additional rollout requirements.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-lifecycle-workflow-inactive-users-04" style="color:#11181d;text-decoration:none">Inactive-user workflow threshold instructions clarified</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Lifecycle Workflows guidance tells administrators to enter the desired number of days under Days of inactivity before proceeding. This is a configuration-documentation clarification; the evidence does not show that the trigger semantics changed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-simulate-workflow-execution-using-the-what-if-tool-03" style="color:#11181d;text-decoration:none">What-if guidance supports no-impact workflow testing</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated What-if documentation explains that administrators can simulate Lifecycle Workflow execution and preview results without affecting actual users. It is operational guidance for validating workflows, not evidence of a newly launched capability or changed availability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-lifecycle-workflow-templates-02" style="color:#11181d;text-decoration:none">Pre-offboarding template guidance for inactive users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Lifecycle Workflow Templates update identifies the Pre-Offboard inactive users template and explains that it is intended for tasks that must be completed before offboarding inactive users. This complements the inactivity-threshold and simulation guidance, while the evidence does not indicate a change to the template itself.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-16/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 16 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 16 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/" style="color:#11181d;text-decoration:none">New Entra ID documentation covers automatic SSO-permission acceptance; ID Governance guidance clarifies inactive-user workflows</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential change is a new Entra ID page describing a supported registry setting that lets IT administrators automatically accept SSO permissions on managed Windows devices. Three ID Governance updates provide operational guidance for inactive-user workflows: setting the inactivity threshold, using the Pre-Offboard inactive users template, and testing execution with the What-if tool. The supplied evidence does not establish GA, preview status, retirement, or a broader tenant behavior change. The remaining Entra ID update only adds SLA performance data.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-admin-control-for-sso-prompts-01" style="color:#11181d;text-decoration:none">New admin control for SSO permission prompts</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Entra ID document says IT administrators can automatically accept SSO permissions on managed Windows devices through a supported registry setting. This documents an admin-controlled behavior, but the supplied evidence does not classify it as generally available or preview, nor does it provide additional rollout requirements.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-lifecycle-workflow-inactive-users-04" style="color:#11181d;text-decoration:none">Inactive-user workflow threshold instructions clarified</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Lifecycle Workflows guidance tells administrators to enter the desired number of days under Days of inactivity before proceeding. This is a configuration-documentation clarification; the evidence does not show that the trigger semantics changed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-simulate-workflow-execution-using-the-what-if-tool-03" style="color:#11181d;text-decoration:none">What-if guidance supports no-impact workflow testing</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated What-if documentation explains that administrators can simulate Lifecycle Workflow execution and preview results without affecting actual users. It is operational guidance for validating workflows, not evidence of a newly launched capability or changed availability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-16/#doc-2026-07-16-lifecycle-workflow-templates-02" style="color:#11181d;text-decoration:none">Pre-offboarding template guidance for inactive users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Lifecycle Workflow Templates update identifies the Pre-Offboard inactive users template and explains that it is intended for tasks that must be completed before offboarding inactive users. This complements the inactivity-threshold and simulation guidance, while the evidence does not indicate a change to the template itself.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-16/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 16 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID documentation updated for Netskope automatic provisioning — 15 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-15/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-15/</guid>
      <pubDate>Wed, 15 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 15 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-15/" style="color:#11181d;text-decoration:none">Entra ID documentation updated for Netskope automatic provisioning</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">15 July was a quiet Entra period: one Microsoft Learn page was updated for configuring Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication. The evidence indicates a documentation change only; it does not identify a new feature, preview, general-availability release, retirement, security change, or changed product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-15/#doc-2026-07-15-configure-netskope-user-authentication-for-automatic-user-provisioning-with-microsoft-entra-id-01" style="color:#11181d;text-decoration:none">Netskope User Authentication provisioning guidance revised</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID documentation covering automatic user provisioning and de-provisioning to Netskope User Authentication was updated. The supplied record does not specify which instructions changed, so it should be treated as documentation clarification or maintenance rather than evidence of a capability change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-15/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 15 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 15 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-15/" style="color:#11181d;text-decoration:none">Entra ID documentation updated for Netskope automatic provisioning</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">15 July was a quiet Entra period: one Microsoft Learn page was updated for configuring Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication. The evidence indicates a documentation change only; it does not identify a new feature, preview, general-availability release, retirement, security change, or changed product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-15/#doc-2026-07-15-configure-netskope-user-authentication-for-automatic-user-provisioning-with-microsoft-entra-id-01" style="color:#11181d;text-decoration:none">Netskope User Authentication provisioning guidance revised</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID documentation covering automatic user provisioning and de-provisioning to Netskope User Authentication was updated. The supplied record does not specify which instructions changed, so it should be treated as documentation clarification or maintenance rather than evidence of a capability change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-15/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 15 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID adds passkey-migration guidance as Explicit Forward Proxy documentation expands — 14 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-14/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-14/</guid>
      <pubDate>Tue, 14 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 14 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/" style="color:#11181d;text-decoration:none">Entra ID adds passkey-migration guidance as Explicit Forward Proxy documentation expands</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The 14 July period was documentation-led rather than a clearly evidenced product-availability day. The most consequential new item is Entra ID guidance to prepare for retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. A concentrated set of Global Secure Access and Microsoft Entra Internet Access updates clarifies Explicit Forward Proxy authentication, a preview session-management method, custom PAC-file hosting, and Edge deployment through Intune. Related updates also document PAC delivery options for unmanaged devices.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-01" style="color:#11181d;text-decoration:none">New Entra ID guidance connects SMS and voice retirement preparation with passkey migration</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new Microsoft Learn page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. This is new security and migration guidance; the evidence does not establish that the retirement or a passkeys-by-default behavior took effect on 14 July.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-explicit-forward-proxy-session-management-05" style="color:#11181d;text-decoration:none">Explicit Forward Proxy documentation specifies an Entra-native session model</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Global Secure Access page says Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization before allowing traffic. That model supports adaptive Microsoft Entra Conditional Access policies, passkeys, and Continuous Access Evaluation with session revocation, while basic, digest, NTLM, and Kerberos proxy authorization methods are not supported. This is a documentation clarification, not evidence of a new GA release.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-configure-http-header-session-management-preview-07" style="color:#11181d;text-decoration:none">HTTP-header session management is documented as a preview dependent on private-IP signaling</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated preview guidance says Explicit Forward Proxy can associate an authenticated user with a device by using the device’s private IP address. Organizations using this method must securely communicate that private IP address to the feature. The update describes a preview deployment model, not a general-availability announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-host-custom-proxy-automatic-configuration-files-for-explicit-forward-proxy-in-microsoft-entra-in-02" style="color:#11181d;text-decoration:none">Microsoft Entra Internet Access documents hosting custom PAC files for Explicit Forward Proxy</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Internet Access page documents how to upload and host an organization’s own Proxy Auto-Configuration files for Explicit Forward Proxy. It adds configuration guidance, but the new page alone does not establish a product launch or an availability change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-configure-microsoft-edge-with-explicit-forward-proxy-by-using-an-intune-application-management-p-03" style="color:#11181d;text-decoration:none">Updated Edge guidance covers Intune delivery of Explicit Forward Proxy settings</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Global Secure Access implementation page says an Intune mobile application management policy can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge for Explicit Forward Proxy. This is updated deployment guidance; the evidence does not indicate a changed availability status.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-14/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 14 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 14 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/" style="color:#11181d;text-decoration:none">Entra ID adds passkey-migration guidance as Explicit Forward Proxy documentation expands</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The 14 July period was documentation-led rather than a clearly evidenced product-availability day. The most consequential new item is Entra ID guidance to prepare for retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. A concentrated set of Global Secure Access and Microsoft Entra Internet Access updates clarifies Explicit Forward Proxy authentication, a preview session-management method, custom PAC-file hosting, and Edge deployment through Intune. Related updates also document PAC delivery options for unmanaged devices.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-passkeys-by-default-and-retirement-of-microsoft-provided-sms-and-voice-authentication-01" style="color:#11181d;text-decoration:none">New Entra ID guidance connects SMS and voice retirement preparation with passkey migration</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new Microsoft Learn page explains how to prepare for the retirement of Microsoft-provided SMS and voice authentication and migrate users to passkeys. This is new security and migration guidance; the evidence does not establish that the retirement or a passkeys-by-default behavior took effect on 14 July.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-explicit-forward-proxy-session-management-05" style="color:#11181d;text-decoration:none">Explicit Forward Proxy documentation specifies an Entra-native session model</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Global Secure Access page says Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization before allowing traffic. That model supports adaptive Microsoft Entra Conditional Access policies, passkeys, and Continuous Access Evaluation with session revocation, while basic, digest, NTLM, and Kerberos proxy authorization methods are not supported. This is a documentation clarification, not evidence of a new GA release.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-configure-http-header-session-management-preview-07" style="color:#11181d;text-decoration:none">HTTP-header session management is documented as a preview dependent on private-IP signaling</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated preview guidance says Explicit Forward Proxy can associate an authenticated user with a device by using the device’s private IP address. Organizations using this method must securely communicate that private IP address to the feature. The update describes a preview deployment model, not a general-availability announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/internet-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Internet Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-host-custom-proxy-automatic-configuration-files-for-explicit-forward-proxy-in-microsoft-entra-in-02" style="color:#11181d;text-decoration:none">Microsoft Entra Internet Access documents hosting custom PAC files for Explicit Forward Proxy</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Internet Access page documents how to upload and host an organization’s own Proxy Auto-Configuration files for Explicit Forward Proxy. It adds configuration guidance, but the new page alone does not establish a product launch or an availability change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-14/#doc-2026-07-14-configure-microsoft-edge-with-explicit-forward-proxy-by-using-an-intune-application-management-p-03" style="color:#11181d;text-decoration:none">Updated Edge guidance covers Intune delivery of Explicit Forward Proxy settings</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Global Secure Access implementation page says an Intune mobile application management policy can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge for Explicit Forward Proxy. This is updated deployment guidance; the evidence does not indicate a changed availability status.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-14/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 14 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Authenticator passkey restore on iOS is getting a guided August rollout; the remaining updates are mainly documentation — 11 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-11/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-11/</guid>
      <pubDate>Sat, 11 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 11 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/" style="color:#11181d;text-decoration:none">Authenticator passkey restore on iOS is getting a guided August rollout; the remaining updates are mainly documentation</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential change is an announced improvement to Microsoft Authenticator passkey restoration for iOS users with iCloud backups. The guided device-migration flow is expected worldwide in August 2026, enabled by default, with no administrator changes required. The other entries update guidance for a Workload ID preview capability, Application Proxy setup, and guest-user licensing; they do not establish a new GA release, retirement, or licensing-policy change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#MC1423108" style="color:#11181d;text-decoration:none">Microsoft Authenticator passkey restore on iOS will use a guided flow</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra Message Center announces a clearer, guided restore experience for Authenticator passkeys during iOS device migration. It affects iOS users with iCloud backups, is expected to be available worldwide in August 2026, is enabled by default, and requires no admin action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#doc-2026-07-11-configure-assignment-restriction-for-user-assigned-managed-identities-preview-01" style="color:#11181d;text-decoration:none">Workload ID preview guidance documents resource-provider assignment restrictions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated guidance explains how to configure assignment restriction for a user-assigned managed identity in the Azure portal, limiting it to specified resource providers. This is documentation for a preview capability; the supplied evidence does not indicate general availability, a new rollout, or a required migration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#doc-2026-07-11-connect-with-the-required-scope-03" style="color:#11181d;text-decoration:none">Application Proxy setup guidance calls out User.Read admin consent</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated connection guidance says that after creating a new Application Proxy application, administrators should grant admin consent for the User.Read delegated permission in the Microsoft Entra admin center or through Microsoft Graph PowerShell. The evidence supports a setup clarification, not a change to the permission model.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#doc-2026-07-11-microsoft-entra-id-governance-licensing-for-guest-users-04" style="color:#11181d;text-decoration:none">Guest-user licensing documentation was updated without evidence of a licensing-policy change</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Microsoft Entra ID Governance page explains how Microsoft Entra ID is licensed for guest users. The supplied summary identifies no new SKU, entitlement, price, or policy, so this should be treated as reference documentation rather than a licensing launch or change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-11/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 11 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 11 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/" style="color:#11181d;text-decoration:none">Authenticator passkey restore on iOS is getting a guided August rollout; the remaining updates are mainly documentation</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential change is an announced improvement to Microsoft Authenticator passkey restoration for iOS users with iCloud backups. The guided device-migration flow is expected worldwide in August 2026, enabled by default, with no administrator changes required. The other entries update guidance for a Workload ID preview capability, Application Proxy setup, and guest-user licensing; they do not establish a new GA release, retirement, or licensing-policy change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#MC1423108" style="color:#11181d;text-decoration:none">Microsoft Authenticator passkey restore on iOS will use a guided flow</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra Message Center announces a clearer, guided restore experience for Authenticator passkeys during iOS device migration. It affects iOS users with iCloud backups, is expected to be available worldwide in August 2026, is enabled by default, and requires no admin action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/workload-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Workload ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#doc-2026-07-11-configure-assignment-restriction-for-user-assigned-managed-identities-preview-01" style="color:#11181d;text-decoration:none">Workload ID preview guidance documents resource-provider assignment restrictions</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated guidance explains how to configure assignment restriction for a user-assigned managed identity in the Azure portal, limiting it to specified resource providers. This is documentation for a preview capability; the supplied evidence does not indicate general availability, a new rollout, or a required migration.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#doc-2026-07-11-connect-with-the-required-scope-03" style="color:#11181d;text-decoration:none">Application Proxy setup guidance calls out User.Read admin consent</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated connection guidance says that after creating a new Application Proxy application, administrators should grant admin consent for the User.Read delegated permission in the Microsoft Entra admin center or through Microsoft Graph PowerShell. The evidence supports a setup clarification, not a change to the permission model.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-11/#doc-2026-07-11-microsoft-entra-id-governance-licensing-for-guest-users-04" style="color:#11181d;text-decoration:none">Guest-user licensing documentation was updated without evidence of a licensing-policy change</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Microsoft Entra ID Governance page explains how Microsoft Entra ID is licensed for guest users. The supplied summary identifies no new SKU, entitlement, price, or policy, so this should be treated as reference documentation rather than a licensing launch or change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-11/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 11 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Conditional Access Custom Controls retirement makes External MFA migration the top Entra priority — 10 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-10/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-10/</guid>
      <pubDate>Fri, 10 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 10 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/" style="color:#11181d;text-decoration:none">Conditional Access Custom Controls retirement makes External MFA migration the top Entra priority</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra ID administrators received a retirement notice requiring Conditional Access policies that use Custom Controls to move to External MFA by September 2026; Custom Controls are scheduled to retire by May 2027. The period also brings changed first-factor authentication behavior for Microsoft-managed tenants and an upcoming general-availability capability for managing Dynamics 365 Contact Center users through Entra security groups. An accompanying Learn-page update supports the migration guidance, but its supplied summary does not establish a separate product change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/#MC1422061" style="color:#11181d;text-decoration:none">Retirement: Custom Controls replaced by External MFA in Conditional Access</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027. External MFA is the stated replacement for standardized third-party MFA integration, and administrators must migrate affected policies by September 2026 to maintain support.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/#MC1411574" style="color:#11181d;text-decoration:none">Changed behavior: system-preferred authentication now applies to first-factor sign-in</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">For tenants in the Microsoft managed state, system-preferred authentication now applies to first-factor authentication and selects the most secure registered method. Rollout starts in late June 2026; tenants can keep or change the setting and should update user guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/#MC1421819" style="color:#11181d;text-decoration:none">Upcoming GA: Entra security groups can manage Dynamics 365 Contact Center users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new capability will allow user management in Dynamics 365 Contact Center through Microsoft Entra security groups. The message states that the capability will reach general availability on July 24, 2026, so this is an upcoming GA milestone rather than a launch on July 10.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-10/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 10 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 10 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/" style="color:#11181d;text-decoration:none">Conditional Access Custom Controls retirement makes External MFA migration the top Entra priority</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Entra ID administrators received a retirement notice requiring Conditional Access policies that use Custom Controls to move to External MFA by September 2026; Custom Controls are scheduled to retire by May 2027. The period also brings changed first-factor authentication behavior for Microsoft-managed tenants and an upcoming general-availability capability for managing Dynamics 365 Contact Center users through Entra security groups. An accompanying Learn-page update supports the migration guidance, but its supplied summary does not establish a separate product change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/#MC1422061" style="color:#11181d;text-decoration:none">Retirement: Custom Controls replaced by External MFA in Conditional Access</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027. External MFA is the stated replacement for standardized third-party MFA integration, and administrators must migrate affected policies by September 2026 to maintain support.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/#MC1411574" style="color:#11181d;text-decoration:none">Changed behavior: system-preferred authentication now applies to first-factor sign-in</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">For tenants in the Microsoft managed state, system-preferred authentication now applies to first-factor authentication and selects the most secure registered method. Rollout starts in late June 2026; tenants can keep or change the setting and should update user guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/security.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Security</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-10/#MC1421819" style="color:#11181d;text-decoration:none">Upcoming GA: Entra security groups can manage Dynamics 365 Contact Center users</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new capability will allow user management in Dynamics 365 Contact Center through Microsoft Entra security groups. The message states that the capability will reach general availability on July 24, 2026, so this is an upcoming GA milestone rather than a launch on July 10.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-10/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 10 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Global Secure Access guest-licensing prerequisite documented; new External ID migration guidance added — 8 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-08/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-08/</guid>
      <pubDate>Wed, 08 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 8 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/" style="color:#11181d;text-decoration:none">Global Secure Access guest-licensing prerequisite documented; new External ID migration guidance added</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">An updated External ID licensing article gives the period’s clearest operational instruction: Global Secure Access external-user access licensing is supported through Microsoft Entra External ID subscription linking, and the administrator must link the subscription in the resource tenant for private-resource access and correct billing. A new External ID article documents Migration Policy Analyzer for assessing Azure AD B2C custom policies, while new Entra ID guidance covers transferring Microsoft Authenticator to a new phone. These are documentation changes, not evidence of a preview, general availability announcement, retirement, or service launch. The Connect version-history update is routine reference maintenance; the External User Access update’s supplied summary contains only a tip marker and does not support a substantive claim.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-licensing-guest-users-03" style="color:#11181d;text-decoration:none">Updated licensing guidance documents the subscription-linking prerequisite for Global Secure Access guests</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Licensing Guest Users article states that Global Secure Access external-user access licensing is supported through Microsoft Entra External ID subscription linking. It specifies that the administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly. This is a documented licensing and configuration prerequisite, not a stated feature launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-analyze-azure-ad-b2c-custom-policies-for-microsoft-entra-external-id-migration-01" style="color:#11181d;text-decoration:none">New Migration Policy Analyzer guidance supports Azure AD B2C custom-policy assessment</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Learn article explains how to use Migration Policy Analyzer to scan Azure AD B2C custom policies and generate a detailed migration assessment for Microsoft Entra External ID. It provides a concrete assessment path for migration planning, but the supplied evidence does not label the analyzer as a preview or generally available capability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-transfer-microsoft-authenticator-to-a-new-phone-02" style="color:#11181d;text-decoration:none">New Authenticator guidance covers backup and restore when users change phones</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new Entra ID authentication article covers backing up and restoring Microsoft Authenticator account entries during a phone change, including passkey setup steps. It is operational and user-support guidance; the supplied change does not state that tenant settings, authentication policies, or security requirements changed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-connect-version-history-04" style="color:#11181d;text-decoration:none">Microsoft Entra Connect version-history documentation was refreshed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Connect Version History article lists releases of Microsoft Entra Connect and Azure AD Sync. The supplied summary does not identify a specific release, retirement, or upgrade requirement, so this is reference maintenance rather than evidence of a product rollout.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-08/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 8 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 8 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/" style="color:#11181d;text-decoration:none">Global Secure Access guest-licensing prerequisite documented; new External ID migration guidance added</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">An updated External ID licensing article gives the period’s clearest operational instruction: Global Secure Access external-user access licensing is supported through Microsoft Entra External ID subscription linking, and the administrator must link the subscription in the resource tenant for private-resource access and correct billing. A new External ID article documents Migration Policy Analyzer for assessing Azure AD B2C custom policies, while new Entra ID guidance covers transferring Microsoft Authenticator to a new phone. These are documentation changes, not evidence of a preview, general availability announcement, retirement, or service launch. The Connect version-history update is routine reference maintenance; the External User Access update’s supplied summary contains only a tip marker and does not support a substantive claim.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-licensing-guest-users-03" style="color:#11181d;text-decoration:none">Updated licensing guidance documents the subscription-linking prerequisite for Global Secure Access guests</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Licensing Guest Users article states that Global Secure Access external-user access licensing is supported through Microsoft Entra External ID subscription linking. It specifies that the administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly. This is a documented licensing and configuration prerequisite, not a stated feature launch.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-analyze-azure-ad-b2c-custom-policies-for-microsoft-entra-external-id-migration-01" style="color:#11181d;text-decoration:none">New Migration Policy Analyzer guidance supports Azure AD B2C custom-policy assessment</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Learn article explains how to use Migration Policy Analyzer to scan Azure AD B2C custom policies and generate a detailed migration assessment for Microsoft Entra External ID. It provides a concrete assessment path for migration planning, but the supplied evidence does not label the analyzer as a preview or generally available capability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-transfer-microsoft-authenticator-to-a-new-phone-02" style="color:#11181d;text-decoration:none">New Authenticator guidance covers backup and restore when users change phones</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new Entra ID authentication article covers backing up and restoring Microsoft Authenticator account entries during a phone change, including passkey setup steps. It is operational and user-support guidance; the supplied change does not state that tenant settings, authentication policies, or security requirements changed.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-08/#doc-2026-07-08-connect-version-history-04" style="color:#11181d;text-decoration:none">Microsoft Entra Connect version-history documentation was refreshed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Connect Version History article lists releases of Microsoft Entra Connect and Azure AD Sync. The supplied summary does not identify a specific release, retirement, or upgrade requirement, so this is reference maintenance rather than evidence of a product rollout.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-08/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 8 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Conditional Access enforcement completes as Entra expands passkey guidance — 7 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-07/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-07/</guid>
      <pubDate>Tue, 07 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 7 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/" style="color:#11181d;text-decoration:none">Conditional Access enforcement completes as Entra expands passkey guidance</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">7 July is primarily a documentation and service-behavior update rather than a broad feature-launch day. Microsoft reports completion of the Conditional Access enforcement update for policies with resource exclusions. The main documentation theme is passkeys: synced-passkey workflows were added, Windows Hello-based Microsoft Entra passkey guidance was expanded but remains explicitly in preview, and Authenticator troubleshooting now documents a potential Conditional Access loop. Microsoft Entra External ID also gained a new Amazon Cognito migration guide. No supplied item announces general availability, and the two removed passkey pages do not by themselves establish retirement of the underlying capability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#MC1418116" style="color:#11181d;text-decoration:none">Conditional Access enforcement for resource-exclusion policies is complete</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Microsoft 365 Message Center records the Conditional Access enforcement update for policies with resource exclusions as completed in the tenant. This is a completed service-behavior notification, not a documentation change; the supplied summary does not specify the enforcement semantics or a required administrator action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-enable-synced-passkeys-in-microsoft-entra-id-02" style="color:#11181d;text-decoration:none">Synced-passkey enablement guidance is now documented</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Learn article covers how to configure, register, and sign in with synced passkeys in Microsoft Entra ID. It gives administrators a consolidated workflow reference, but the evidence describes a documentation addition rather than a new feature launch, availability change, or general-availability announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-enable-microsoft-entra-passkey-on-windows-preview-10" style="color:#11181d;text-decoration:none">Windows Hello-based Microsoft Entra passkey guidance expands, still as preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated enablement material describes Microsoft Entra passkey on Windows, using Windows Hello as a FIDO2 passkey provider for phishing-resistant work or school account sign-in; new registration and sign-in pages accompany it. The explicit preview label means these changes should be treated as preview guidance rather than evidence of GA.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-troubleshoot-19" style="color:#11181d;text-decoration:none">Authenticator passkey troubleshooting documents a Conditional Access loop</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated External ID troubleshooting guidance warns that organizations deploying passkeys can encounter a loop when a Conditional Access policy requires phishing-resistant authentication for All resources and a user attempts to add a passkey to Microsoft Authenticator. The page points to workarounds, making this an actionable enrollment and security-guidance change rather than a stated change to Conditional Access behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-migrate-from-amazon-cognito-to-microsoft-entra-external-id-01" style="color:#11181d;text-decoration:none">External ID adds Amazon Cognito migration guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new guide provides step-by-step guidance, feature mapping, and validation strategies for migrating from Amazon Cognito to Microsoft Entra External ID. This is planning and documentation support; the supplied evidence does not indicate an automated migration tool or a change in product availability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-07/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 7 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 7 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/" style="color:#11181d;text-decoration:none">Conditional Access enforcement completes as Entra expands passkey guidance</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">7 July is primarily a documentation and service-behavior update rather than a broad feature-launch day. Microsoft reports completion of the Conditional Access enforcement update for policies with resource exclusions. The main documentation theme is passkeys: synced-passkey workflows were added, Windows Hello-based Microsoft Entra passkey guidance was expanded but remains explicitly in preview, and Authenticator troubleshooting now documents a potential Conditional Access loop. Microsoft Entra External ID also gained a new Amazon Cognito migration guide. No supplied item announces general availability, and the two removed passkey pages do not by themselves establish retirement of the underlying capability.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#MC1418116" style="color:#11181d;text-decoration:none">Conditional Access enforcement for resource-exclusion policies is complete</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Microsoft 365 Message Center records the Conditional Access enforcement update for policies with resource exclusions as completed in the tenant. This is a completed service-behavior notification, not a documentation change; the supplied summary does not specify the enforcement semantics or a required administrator action.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-enable-synced-passkeys-in-microsoft-entra-id-02" style="color:#11181d;text-decoration:none">Synced-passkey enablement guidance is now documented</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Learn article covers how to configure, register, and sign in with synced passkeys in Microsoft Entra ID. It gives administrators a consolidated workflow reference, but the evidence describes a documentation addition rather than a new feature launch, availability change, or general-availability announcement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-enable-microsoft-entra-passkey-on-windows-preview-10" style="color:#11181d;text-decoration:none">Windows Hello-based Microsoft Entra passkey guidance expands, still as preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated enablement material describes Microsoft Entra passkey on Windows, using Windows Hello as a FIDO2 passkey provider for phishing-resistant work or school account sign-in; new registration and sign-in pages accompany it. The explicit preview label means these changes should be treated as preview guidance rather than evidence of GA.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-troubleshoot-19" style="color:#11181d;text-decoration:none">Authenticator passkey troubleshooting documents a Conditional Access loop</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated External ID troubleshooting guidance warns that organizations deploying passkeys can encounter a loop when a Conditional Access policy requires phishing-resistant authentication for All resources and a user attempts to add a passkey to Microsoft Authenticator. The page points to workarounds, making this an actionable enrollment and security-guidance change rather than a stated change to Conditional Access behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-07/#doc-2026-07-07-migrate-from-amazon-cognito-to-microsoft-entra-external-id-01" style="color:#11181d;text-decoration:none">External ID adds Amazon Cognito migration guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new guide provides step-by-step guidance, feature mapping, and validation strategies for migrating from Amazon Cognito to Microsoft Entra External ID. This is planning and documentation support; the supplied evidence does not indicate an automated migration tool or a change in product availability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-07/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 7 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID documentation reinforces the move away from implicit grant — 4 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-04/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-04/</guid>
      <pubDate>Sat, 04 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 4 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/" style="color:#11181d;text-decoration:none">Entra ID documentation reinforces the move away from implicit grant</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">This was a quiet Entra ID documentation day: all three reported changes were updates to Microsoft Learn pages, with no new feature, preview, general-availability change, retirement event, or Message Center notice. The most consequential update clarifies that implicit-flow ID tokens are disabled by default in the app-manifest guidance and that Microsoft recommends authorization code flow with PKCE for browser-based apps. The remaining updates clarify OIDC redirect-URI setup and the documented location of the legacy app-manifest logoUrl property.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/#doc-2026-07-04-app-manifest-03" style="color:#11181d;text-decoration:none">App Manifest guidance explicitly discourages implicit grant</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated App Manifest documentation states that the flag allowing a web app to request OAuth 2.0 implicit-flow ID tokens defaults to false, applies to browser-based apps such as JavaScript SPAs, and recommends authorization code flow with PKCE instead. This is security guidance and documentation clarification, not evidence that the platform default itself changed during the period.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/#doc-2026-07-04-v2-protocols-oidc-01" style="color:#11181d;text-decoration:none">OIDC redirect-URI setup instructions clarified</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The V2 Protocols OIDC page now instructs readers to add the application&#039;s redirect URI and provides https://localhost:8080/ as an example. This is an ordinary setup-documentation clarification; the supplied evidence does not indicate a change to OIDC protocol behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/#doc-2026-07-04-azure-active-directory-graph-app-manifest-deprecation-02" style="color:#11181d;text-decoration:none">The documented app-manifest location of logoUrl was relocated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Azure Active Directory Graph app-manifest deprecation reference now lists logoUrl as a property of the info attribute. This may matter to administrators maintaining manifest documentation or tooling, but the update provides no evidence of a new deprecation milestone or runtime change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-04/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 4 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 4 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/" style="color:#11181d;text-decoration:none">Entra ID documentation reinforces the move away from implicit grant</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">This was a quiet Entra ID documentation day: all three reported changes were updates to Microsoft Learn pages, with no new feature, preview, general-availability change, retirement event, or Message Center notice. The most consequential update clarifies that implicit-flow ID tokens are disabled by default in the app-manifest guidance and that Microsoft recommends authorization code flow with PKCE for browser-based apps. The remaining updates clarify OIDC redirect-URI setup and the documented location of the legacy app-manifest logoUrl property.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/#doc-2026-07-04-app-manifest-03" style="color:#11181d;text-decoration:none">App Manifest guidance explicitly discourages implicit grant</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated App Manifest documentation states that the flag allowing a web app to request OAuth 2.0 implicit-flow ID tokens defaults to false, applies to browser-based apps such as JavaScript SPAs, and recommends authorization code flow with PKCE instead. This is security guidance and documentation clarification, not evidence that the platform default itself changed during the period.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/#doc-2026-07-04-v2-protocols-oidc-01" style="color:#11181d;text-decoration:none">OIDC redirect-URI setup instructions clarified</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The V2 Protocols OIDC page now instructs readers to add the application&#039;s redirect URI and provides https://localhost:8080/ as an example. This is an ordinary setup-documentation clarification; the supplied evidence does not indicate a change to OIDC protocol behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-04/#doc-2026-07-04-azure-active-directory-graph-app-manifest-deprecation-02" style="color:#11181d;text-decoration:none">The documented app-manifest location of logoUrl was relocated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Azure Active Directory Graph app-manifest deprecation reference now lists logoUrl as a property of the info attribute. This may matter to administrators maintaining manifest documentation or tooling, but the update provides no evidence of a new deprecation milestone or runtime change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-04/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 4 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Documentation-only day: Entra Connect matching guidance and a Global Secure Access Chennai PoP entry are the clearest changes — 3 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-03/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-03/</guid>
      <pubDate>Fri, 03 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 3 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/" style="color:#11181d;text-decoration:none">Documentation-only day: Entra Connect matching guidance and a Global Secure Access Chennai PoP entry are the clearest changes</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">On 3 July 2026, all five recorded changes were Microsoft Learn updates: three for Entra ID, one for External ID, and one for Global Secure Access. There were no new or removed items and no Message Center entries. The supplied evidence does not establish a feature launch, preview, general availability change, retirement, changed product behavior, or new security guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/#doc-2026-07-03-configure-microsoft-entra-connect-for-an-existing-tenant-01" style="color:#11181d;text-decoration:none">Entra ID: updated guidance for matching objects in an existing tenant</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Microsoft Entra Connect article covers matching and synchronizing on-premises objects with an existing tenant and resolving hard-match conflicts. The record does not identify a change to synchronization behavior or configuration; treat this as operational documentation guidance and review it when planning or troubleshooting hybrid identity.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/#doc-2026-07-03-points-of-presence-04" style="color:#11181d;text-decoration:none">Global Secure Access: Points of Presence content shows a Chennai, India row</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated page contains a South India / Chennai, India entry with both displayed status cells checked. Because the supplied extract omits the column headings, it supports a documentation update to the regional PoP table but not a precise conclusion about which services or availability states the checks represent. No routing or deployment change is evidenced.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/#doc-2026-07-03-what-s-new-in-microsoft-entra-application-management-03" style="color:#11181d;text-decoration:none">Entra application-management documentation was refreshed without a named capability change</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated “What’s new in Microsoft Entra application management” article is described as listing new and updated application-management documentation. It names no specific feature, preview, GA status, retirement, behavior change, or administrator action, so this is best classified as documentation or index maintenance.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-03/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 3 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 3 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/" style="color:#11181d;text-decoration:none">Documentation-only day: Entra Connect matching guidance and a Global Secure Access Chennai PoP entry are the clearest changes</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">On 3 July 2026, all five recorded changes were Microsoft Learn updates: three for Entra ID, one for External ID, and one for Global Secure Access. There were no new or removed items and no Message Center entries. The supplied evidence does not establish a feature launch, preview, general availability change, retirement, changed product behavior, or new security guidance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/#doc-2026-07-03-configure-microsoft-entra-connect-for-an-existing-tenant-01" style="color:#11181d;text-decoration:none">Entra ID: updated guidance for matching objects in an existing tenant</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated Microsoft Entra Connect article covers matching and synchronizing on-premises objects with an existing tenant and resolving hard-match conflicts. The record does not identify a change to synchronization behavior or configuration; treat this as operational documentation guidance and review it when planning or troubleshooting hybrid identity.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/#doc-2026-07-03-points-of-presence-04" style="color:#11181d;text-decoration:none">Global Secure Access: Points of Presence content shows a Chennai, India row</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated page contains a South India / Chennai, India entry with both displayed status cells checked. Because the supplied extract omits the column headings, it supports a documentation update to the regional PoP table but not a precise conclusion about which services or availability states the checks represent. No routing or deployment change is evidenced.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/developer.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Developer</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-03/#doc-2026-07-03-what-s-new-in-microsoft-entra-application-management-03" style="color:#11181d;text-decoration:none">Entra application-management documentation was refreshed without a named capability change</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated “What’s new in Microsoft Entra application management” article is described as listing new and updated application-management documentation. It names no specific feature, preview, GA status, retirement, behavior change, or administrator action, so this is best classified as documentation or index maintenance.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-03/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 3 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Documentation-focused day: Office 365 Conditional Access guidance changed and a Customer Lockbox page was removed — 2 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-02/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-02/</guid>
      <pubDate>Thu, 02 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 2 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/" style="color:#11181d;text-decoration:none">Documentation-focused day: Office 365 Conditional Access guidance changed and a Customer Lockbox page was removed</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">2 July was a quiet, documentation-led period. The clearest substantive edit was to the Entra ID Office 365 Application Contents page, which now explicitly references the Office 365 app in Conditional Access. Governance policy, administrator-role, and Harness provisioning pages were also updated, but the supplied evidence does not identify changed permissions, service behavior, availability, or a feature rollout. The removal of the Entra Customer Lockbox Approver page should not be interpreted as evidence that the underlying role or capability was retired.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/#doc-2026-07-02-office-365-application-contents-05" style="color:#11181d;text-decoration:none">Office 365 Conditional Access documentation was updated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID Office 365 Application Contents page explicitly references the “Office 365 app in Conditional Access” section. The supplied record supports a documentation clarification, but does not establish a change to cloud-app targeting, policy evaluation, or tenant behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/#doc-2026-07-02-entra-customer-lockbox-approver-06" style="color:#11181d;text-decoration:none">The Entra Customer Lockbox Approver page was removed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Learn records the Entra Customer Lockbox Approver page as removed. This is a documentation removal, not evidence of a role or Customer Lockbox capability retirement. Administrators should check any internal links or procedures that depended on the page.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/#doc-2026-07-02-governance-policy-templates-01" style="color:#11181d;text-decoration:none">Governance policy template guidance was refreshed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The ID Governance Governance Policy Templates page was updated and continues to describe using templates to enforce consistent governance across tenants. No specific change to template behavior, availability, or required configuration is provided, so this supports a documentation review rather than an administrative change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-02/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 2 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 2 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/" style="color:#11181d;text-decoration:none">Documentation-focused day: Office 365 Conditional Access guidance changed and a Customer Lockbox page was removed</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">2 July was a quiet, documentation-led period. The clearest substantive edit was to the Entra ID Office 365 Application Contents page, which now explicitly references the Office 365 app in Conditional Access. Governance policy, administrator-role, and Harness provisioning pages were also updated, but the supplied evidence does not identify changed permissions, service behavior, availability, or a feature rollout. The removal of the Entra Customer Lockbox Approver page should not be interpreted as evidence that the underlying role or capability was retired.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/#doc-2026-07-02-office-365-application-contents-05" style="color:#11181d;text-decoration:none">Office 365 Conditional Access documentation was updated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The Entra ID Office 365 Application Contents page explicitly references the “Office 365 app in Conditional Access” section. The supplied record supports a documentation clarification, but does not establish a change to cloud-app targeting, policy evaluation, or tenant behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/#doc-2026-07-02-entra-customer-lockbox-approver-06" style="color:#11181d;text-decoration:none">The Entra Customer Lockbox Approver page was removed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Learn records the Entra Customer Lockbox Approver page as removed. This is a documentation removal, not evidence of a role or Customer Lockbox capability retirement. Administrators should check any internal links or procedures that depended on the page.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-governance.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Governance · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-02/#doc-2026-07-02-governance-policy-templates-01" style="color:#11181d;text-decoration:none">Governance policy template guidance was refreshed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The ID Governance Governance Policy Templates page was updated and continues to describe using templates to enforce consistent governance across tenants. No specific change to template behavior, availability, or required configuration is provided, so this supports a documentation review rather than an administrative change.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-02/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 2 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>1 July 2026: Global Secure Access publishes Microsoft-traffic guidance and calls out HTTP-method filtering in preview; ID Protection documents unified risk — 1 July 2026</title>
      <link>https://daily.entra.news/day/2026-07-01/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-07-01/</guid>
      <pubDate>Wed, 01 Jul 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 1 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/" style="color:#11181d;text-decoration:none">1 July 2026: Global Secure Access publishes Microsoft-traffic guidance and calls out HTTP-method filtering in preview; ID Protection documents unified risk</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">This is a Microsoft Learn-led update rather than a release bulletin, with no Message Center item. The meaningful changes are a new set of Global Secure Access tutorials for Microsoft traffic controls, an updated Web Content Filtering page that explicitly labels HTTP method request filtering as preview, new ID Protection guidance for correlated risk, and Entra ID documentation for OIDC extensibility and SCIM API setup. The supplied evidence does not establish general availability, retirement, or an automatic tenant behavior change; the remaining edits are mainly standards, integration, logging, Security Copilot, and troubleshooting documentation maintenance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-tutorial-get-started-with-microsoft-traffic-labs-05" style="color:#11181d;text-decoration:none">Global Secure Access adds a Microsoft traffic labs tutorial and related configuration guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new tutorial brings source IP restoration, compliant network checks, and universal tenant restrictions into a Microsoft traffic lab path. Related new tutorials add the steps for enabling the Microsoft traffic profile, assigning users, installing the client, verifying forwarding, validating restored source IP in Entra sign-in logs, and configuring a Conditional Access policy that requires a compliant network. This is a new how-to set, not evidence of general availability or automatic changes to existing policies</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-configure-web-content-filtering-12" style="color:#11181d;text-decoration:none">Global Secure Access Web Content Filtering documents HTTP-method request filtering as preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated guidance identifies HTTP method request filtering as preview and describes blocking or allowing methods including GET, POST, PUT, PATCH, and DELETE. The evidence supports a documented preview capability, not general availability or a change to existing content policies; administrators should account for that status when assessing the option</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-unified-risk-signals-in-microsoft-entra-id-protection-01" style="color:#11181d;text-decoration:none">Microsoft Entra ID Protection documents unified risk signals and compounded user risk</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new fundamentals article explains that identity-risk signals from Microsoft Entra ID Protection and Microsoft Defender are correlated to calculate compounded user risk. Related dashboard guidance describes correlation across other Microsoft security products within the same time window, and the Risky User Report update documents an option to aggregate risk signals by risky sign-ins. This clarifies risk interpretation and reporting; it does not announce a new tenant setting or scoring rollout</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-microsoft-identity-platform-oidc-extensibility-reference-07" style="color:#11181d;text-decoration:none">Entra ID adds an OIDC extensibility-to-Graph reference</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft identity platform reference maps each OpenID Connect extensibility surface to its configuration article and the Microsoft Graph API resource that programs it. Alongside updates to the OAuth and OIDC protocol pages, this is a navigation and implementation clarification for application and identity-platform owners, not evidence of a new protocol capability or availability change</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-entra-id-scim-api-reference-20" style="color:#11181d;text-decoration:none">Entra ID SCIM API documentation spells out call prerequisites</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated SCIM API reference states that callers must enable the SCIM Provisioning API, configure billing, set up credentials, and obtain an access token before calling the documented endpoints. A related enablement-page update points readers to API-call pricing. This is a documentation clarification with planning implications for SCIM API adopters; it does not state that existing integrations changed</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-01/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 1 July 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 1 July 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/" style="color:#11181d;text-decoration:none">1 July 2026: Global Secure Access publishes Microsoft-traffic guidance and calls out HTTP-method filtering in preview; ID Protection documents unified risk</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">This is a Microsoft Learn-led update rather than a release bulletin, with no Message Center item. The meaningful changes are a new set of Global Secure Access tutorials for Microsoft traffic controls, an updated Web Content Filtering page that explicitly labels HTTP method request filtering as preview, new ID Protection guidance for correlated risk, and Entra ID documentation for OIDC extensibility and SCIM API setup. The supplied evidence does not establish general availability, retirement, or an automatic tenant behavior change; the remaining edits are mainly standards, integration, logging, Security Copilot, and troubleshooting documentation maintenance.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-tutorial-get-started-with-microsoft-traffic-labs-05" style="color:#11181d;text-decoration:none">Global Secure Access adds a Microsoft traffic labs tutorial and related configuration guidance</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The new tutorial brings source IP restoration, compliant network checks, and universal tenant restrictions into a Microsoft traffic lab path. Related new tutorials add the steps for enabling the Microsoft traffic profile, assigning users, installing the client, verifying forwarding, validating restored source IP in Entra sign-in logs, and configuring a Conditional Access policy that requires a compliant network. This is a new how-to set, not evidence of general availability or automatic changes to existing policies</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/general.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · General</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-configure-web-content-filtering-12" style="color:#11181d;text-decoration:none">Global Secure Access Web Content Filtering documents HTTP-method request filtering as preview</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated guidance identifies HTTP method request filtering as preview and describes blocking or allowing methods including GET, POST, PUT, PATCH, and DELETE. The evidence supports a documented preview capability, not general availability or a change to existing content policies; administrators should account for that status when assessing the option</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/id-protection.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/fundamentals.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">ID Protection · Fundamentals</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-unified-risk-signals-in-microsoft-entra-id-protection-01" style="color:#11181d;text-decoration:none">Microsoft Entra ID Protection documents unified risk signals and compounded user risk</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new fundamentals article explains that identity-risk signals from Microsoft Entra ID Protection and Microsoft Defender are correlated to calculate compounded user risk. Related dashboard guidance describes correlation across other Microsoft security products within the same time window, and the Risky User Report update documents an option to aggregate risk signals by risky sign-ins. This clarifies risk interpretation and reporting; it does not announce a new tenant setting or scoring rollout</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-microsoft-identity-platform-oidc-extensibility-reference-07" style="color:#11181d;text-decoration:none">Entra ID adds an OIDC extensibility-to-Graph reference</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft identity platform reference maps each OpenID Connect extensibility surface to its configuration article and the Microsoft Graph API resource that programs it. Alongside updates to the OAuth and OIDC protocol pages, this is a navigation and implementation clarification for application and identity-platform owners, not evidence of a new protocol capability or availability change</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/standards.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Standards</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-07-01/#doc-2026-07-01-entra-id-scim-api-reference-20" style="color:#11181d;text-decoration:none">Entra ID SCIM API documentation spells out call prerequisites</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The updated SCIM API reference states that callers must enable the SCIM Provisioning API, configure billing, set up credentials, and obtain an access token before calling the documented endpoints. A related enablement-page update points readers to API-call pricing. This is a documentation clarification with planning implications for SCIM API adopters; it does not state that existing integrations changed</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-07-01/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 1 July 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra will block new Partner Tier support-role assignments on 3 August 2026 — 30 June 2026</title>
      <link>https://daily.entra.news/day/2026-06-30/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-06-30/</guid>
      <pubDate>Tue, 30 Jun 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 30 June 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-30/" style="color:#11181d;text-decoration:none">Entra will block new Partner Tier support-role assignments on 3 August 2026</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential update is a planned retirement change for the Partner Tier1 and Partner Tier2 Support roles: Microsoft Entra will stop accepting new assignments from 3 August 2026, while existing assignments remain valid. The period also adds a new provisioning guide for Visa Spend Clarity for Enterprise. A separate update to the User Type Workload Limitations Include documentation does not provide evidence of a behavior or policy change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-30/#MC1409305" style="color:#11181d;text-decoration:none">New assignments to Partner Tier1 and Tier2 Support roles will be blocked</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra is retiring these partner support roles and will block new assignments beginning 3 August 2026. Existing assignments remain valid, so the immediate task is to update scripts and assignment workflows before the change; Microsoft identifies alternatives such as User Administrator.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-30/#doc-2026-06-30-configure-visa-spend-clarity-for-enterprise-for-automatic-user-provisioning-with-microsoft-entra-01" style="color:#11181d;text-decoration:none">New Microsoft Entra provisioning guidance for Visa Spend Clarity for Enterprise</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Learn added configuration guidance for automatically provisioning and deprovisioning user accounts from Microsoft Entra ID to Visa Spend Clarity for Enterprise. The supplied evidence establishes a new documentation path, not a separate availability or product-launch claim.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-06-30/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 30 June 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 30 June 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-30/" style="color:#11181d;text-decoration:none">Entra will block new Partner Tier support-role assignments on 3 August 2026</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">The most consequential update is a planned retirement change for the Partner Tier1 and Partner Tier2 Support roles: Microsoft Entra will stop accepting new assignments from 3 August 2026, while existing assignments remain valid. The period also adds a new provisioning guide for Visa Spend Clarity for Enterprise. A separate update to the User Type Workload Limitations Include documentation does not provide evidence of a behavior or policy change.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/governance.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Governance</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-30/#MC1409305" style="color:#11181d;text-decoration:none">New assignments to Partner Tier1 and Tier2 Support roles will be blocked</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra is retiring these partner support roles and will block new assignments beginning 3 August 2026. Existing assignments remain valid, so the immediate task is to update scripts and assignment workflows before the change; Microsoft identifies alternatives such as User Administrator.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/provisioning.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Provisioning</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-30/#doc-2026-06-30-configure-visa-spend-clarity-for-enterprise-for-automatic-user-provisioning-with-microsoft-entra-01" style="color:#11181d;text-decoration:none">New Microsoft Entra provisioning guidance for Visa Spend Clarity for Enterprise</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Learn added configuration guidance for automatically provisioning and deprovisioning user accounts from Microsoft Entra ID to Visa Spend Clarity for Enterprise. The supplied evidence establishes a new documentation path, not a separate availability or product-launch claim.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-06-30/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 30 June 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>External ID deployment and security-operations guidance updated — 28 June 2026</title>
      <link>https://daily.entra.news/day/2026-06-28/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-06-28/</guid>
      <pubDate>Sun, 28 Jun 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 28 June 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-28/" style="color:#11181d;text-decoration:none">External ID deployment and security-operations guidance updated</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Learn updated the External ID “Deployment External Operations” architecture documentation. It covers edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations. The supplied evidence does not identify a new capability, preview, general availability milestone, retirement, or changed product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-28/#doc-2026-06-28-deployment-external-operations-01" style="color:#11181d;text-decoration:none">Deployment External Operations documentation updated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The External ID architecture guidance now reflects an update to its coverage of edge protection, domains, subscriptions, consumer app security, and fraud tactics. The evidence does not specify which content changed, so this should not be treated as a product behavior change or feature launch without further review.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-06-28/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 28 June 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 28 June 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-28/" style="color:#11181d;text-decoration:none">External ID deployment and security-operations guidance updated</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">Microsoft Learn updated the External ID “Deployment External Operations” architecture documentation. It covers edge protection, domains, subscriptions, consumer app security, and fraud tactics in security operations. The supplied evidence does not identify a new capability, preview, general availability milestone, retirement, or changed product behavior.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/external-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">External ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-28/#doc-2026-06-28-deployment-external-operations-01" style="color:#11181d;text-decoration:none">Deployment External Operations documentation updated</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">The External ID architecture guidance now reflects an update to its coverage of edge protection, domains, subscriptions, consumer app security, and fraud tactics. The evidence does not specify which content changed, so this should not be treated as a product behavior change or feature launch without further review.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-06-28/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 28 June 2026 →</a></p></div>]]></content:encoded>
    </item>
    <item>
      <title>Entra ID SSPR will require registered methods on 7 September; new tenant-recovery guidance arrives — 27 June 2026</title>
      <link>https://daily.entra.news/day/2026-06-27/</link>
      <guid isPermaLink="true">https://daily.entra.news/day/2026-06-27/</guid>
      <pubDate>Sat, 27 Jun 2026 08:15:00 GMT</pubDate>
      <description><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 27 June 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/" style="color:#11181d;text-decoration:none">Entra ID SSPR will require registered methods on 7 September; new tenant-recovery guidance arrives</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">27 June was dominated by documentation maintenance—264 updates, one new article, and one Message Center announcement—with many routine provisioning and fundamentals pages among the updates. The meaningful exceptions are an announced SSPR verification behavior change, new tenant-scoped recovery guidance, and refreshed security and preview-operational documentation. The supplied evidence shows no general-availability launch or retirement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#MC1325414" style="color:#11181d;text-decoration:none">Changed SSPR verification behavior is scheduled for 7 September 2026</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID Self-Service Password Reset will require users to have explicitly registered authentication methods for password-reset verification. Directory-sourced contact information will no longer be accepted unless it is registered. A registration campaign begins on 6 August 2026 to help users avoid reset failures.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#doc-2026-06-27-plan-for-tenant-recoverability-01" style="color:#11181d;text-decoration:none">New guidance covers tenant-scoped recovery</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Entra ID article explains how administrators can prepare for and execute tenant-scoped recovery under the shared responsibility model. This is resilience guidance, not a product launch, and is the period’s clearest new planning content.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#doc-2026-06-27-deploy-passkeys-with-the-microsoft-entra-conditional-access-optimization-agent-265" style="color:#11181d;text-decoration:none">Passkey rollout and authentication-strength guidance was refreshed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Entra ID guidance explains how to use the Conditional Access Optimization Agent to safely deploy a passkey program for phishing-resistant authentication. A related authentication-strength update covers advanced options for passkey (FIDO2) security keys and certificate-based authentication. These records describe documentation and rollout guidance, not a stated availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#doc-2026-06-27-how-to-view-model-context-protocol-mcp-traffic-logs-in-global-secure-access-preview-30" style="color:#11181d;text-decoration:none">Global Secure Access preview documentation adds MCP traffic-log procedures</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">An updated Global Secure Access (Preview) article documents how to view and analyze Model Context Protocol traffic between AI agents and remote MCP servers through the Generative AI Insights page. It is operational guidance for a preview capability, not evidence of general availability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-06-27/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 27 June 2026 →</a></p></div>]]></description>
      <content:encoded><![CDATA[<div style="max-width:760px;color:#11181d;font-family:Arial,sans-serif"><div style="margin:0 0 24px"><div style="margin:0 0 6px;color:#0d5745;font:700 11px/1.3 Arial,sans-serif;letter-spacing:.08em;text-transform:uppercase">Day in brief · 27 June 2026</div><h2 style="margin:0 0 12px;font:650 28px/1.2 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/" style="color:#11181d;text-decoration:none">Entra ID SSPR will require registered methods on 7 September; new tenant-recovery guidance arrives</a></h2><p style="margin:0;color:#263030;font:16px/1.6 Arial,sans-serif">27 June was dominated by documentation maintenance—264 updates, one new article, and one Message Center announcement—with many routine provisioning and fundamentals pages among the updates. The meaningful exceptions are an announced SSPR verification behavior change, new tenant-scoped recovery guidance, and refreshed security and preview-operational documentation. The supplied evidence shows no general-availability launch or retirement.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/authentication.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Authentication</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#MC1325414" style="color:#11181d;text-decoration:none">Changed SSPR verification behavior is scheduled for 7 September 2026</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Microsoft Entra ID Self-Service Password Reset will require users to have explicitly registered authentication methods for password-reset verification. Directory-sourced contact information will no longer be accepted unless it is registered. A registration campaign begins on 6 August 2026 to help users avoid reset failures.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/architecture.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Architecture</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#doc-2026-06-27-plan-for-tenant-recoverability-01" style="color:#11181d;text-decoration:none">New guidance covers tenant-scoped recovery</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">A new Microsoft Entra ID article explains how administrators can prepare for and execute tenant-scoped recovery under the shared responsibility model. This is resilience guidance, not a product launch, and is the period’s clearest new planning content.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/entra-id.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/conditional-access.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Entra ID · Conditional Access</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#doc-2026-06-27-deploy-passkeys-with-the-microsoft-entra-conditional-access-optimization-agent-265" style="color:#11181d;text-decoration:none">Passkey rollout and authentication-strength guidance was refreshed</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">Updated Entra ID guidance explains how to use the Conditional Access Optimization Agent to safely deploy a passkey program for phishing-resistant authentication. A related authentication-strength update covers advanced options for passkey (FIDO2) security keys and certificate-based authentication. These records describe documentation and rollout guidance, not a stated availability milestone.</p></div><div style="margin:0 0 20px;padding:0 0 18px;border-bottom:1px solid #d8d3c7"><table role="presentation" width="100%" cellspacing="0" cellpadding="0" border="0" style="width:100%;border:0;border-collapse:collapse"><tr><td width="46" valign="top" style="width:46px;min-width:46px;padding:1px 8px 0 0;vertical-align:top;white-space:nowrap"><img src="https://daily.entra.news/assets/products/global-secure-access.svg" width="20" height="20" alt="" style="display:inline-block;width:20px!important;max-width:20px!important;height:20px!important;max-height:20px!important;object-fit:contain;vertical-align:middle"><span style="display:inline-block;width:5px"></span><img src="https://daily.entra.news/assets/topics/monitoring.svg" width="16" height="16" alt="" style="display:inline-block;width:16px!important;max-width:16px!important;height:16px!important;max-height:16px!important;object-fit:contain;vertical-align:middle"></td><td valign="top" style="padding:0;vertical-align:top"><div style="margin:0 0 5px;color:#0d5745;font:700 11px/1.35 Arial,sans-serif;letter-spacing:.04em;text-transform:uppercase">Global Secure Access · Monitoring</div><h3 style="margin:0 0 7px;font:600 18px/1.3 Georgia,serif"><a href="https://daily.entra.news/day/2026-06-27/#doc-2026-06-27-how-to-view-model-context-protocol-mcp-traffic-logs-in-global-secure-access-preview-30" style="color:#11181d;text-decoration:none">Global Secure Access preview documentation adds MCP traffic-log procedures</a></h3></td></tr></table><p style="margin:5px 0 0;color:#46514e;font:14px/1.55 Arial,sans-serif">An updated Global Secure Access (Preview) article documents how to view and analyze Model Context Protocol traffic between AI agents and remote MCP servers through the Generative AI Insights page. It is operational guidance for a preview capability, not evidence of general availability.</p></div><p style="margin:24px 0 0"><a href="https://daily.entra.news/day/2026-06-27/" style="color:#0d5745;font:700 15px/1.4 Georgia,serif">View all updates for 27 June 2026 →</a></p></div>]]></content:encoded>
    </item>
  </channel>
</rss>