Assignment Network
The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Authentication.
The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.
The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.
The documented query now filters for UserId `00aa00aa-bb11-cc22-dd33-44ee44ee44ee` instead of the previous identifier.
The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.
The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.
The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.
The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.
The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.
The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.
The password migration documentation now uses a different example API application identifier.
Microsoft Entra now applies system-preferred authentication to first-factor sign-ins for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout is from late June to late September 2026. Tenants can keep or change this setting and should update user guidance accordingly.
Microsoft Entra External ID now documents an API that lets applications list, register, and delete signed-in customers’ passkeys using delegated access tokens.
The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.
The security key entry’s table formatting was corrected by removing an extra space before a separator.
Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.
The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.
The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.
The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.
The document date changed from August 18 to August 20, 2026, and existing vendor entries were reordered. Their displayed identifiers and support indicators remain unchanged.
Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.
The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.
The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.
The documentation now covers custom CSS layout and positioning properties, and updates its publication date to August 18, 2026. It describes support for these properties as being retired under the Secure Future Initiative.
The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.
The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.
The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.
New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.
The documentation now states that disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens.
The guidance now states that authentication strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts, alongside the previously listed methods. It directs administrators to use the MFA grant control instead.
The Agent ID token claims documentation no longer includes one `tid` claim table row.
The page description was shortened by removing the phrase “Key concepts.” The documented OAuth 2.0 protocols and token exchange patterns remain unchanged.
The documentation now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” and expands “SPA” to “single-page application.” The described authentication flows and responsibilities are otherwise unchanged in the supplied diff.
The autonomous agent authentication and authorization flow documentation now adds `using Microsoft.Identity.Web;` to a C# setup sample.
The error-code documentation now separates quota, blueprint, blueprint principal, agent identity, and agent identity creation errors, with clearer descriptions and table headings.
The documentation replaces inconsistent tenant placeholders with `<your-tenant-id>` and standardizes `<agent-blueprint-clientid>` to `<agent-blueprint-client-id>` in code samples.
The documentation replaces “Device disablement” with “Attacker-added device” and explains that the Entra device object is disabled, new token issuance is blocked, existing device-bound refresh tokens are revoked, and user sessions are revoked.
The documentation now describes a Device disablement response for users flagged by Microsoft threat intelligence as having an attacker-added device. The device is disabled, and the user is prompted to sign in from a trusted device.
The article now consistently refers to the sidecar integration as the Microsoft Entra ID Auth SDK instead of the Microsoft Entra Auth SDK. The integration guidance is otherwise unchanged.
The interactive agent authentication and authorization documentation now includes `using Microsoft.AspNetCore.Authentication.JwtBearer;` in its C# setup samples.
The documentation now consistently uses `<your-tenant-id>` instead of `<my-test-tenant>` or `<your-test-tenant>` in PowerShell, OAuth URLs, and JSON examples.
The article title and heading no longer include “(preview).” No other change is shown.
The local-development article now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK,” including its title, description, intent, link text, and container description.
The page title and heading no longer include “(preview).” No other change is shown, and the diff does not explicitly announce general availability or a product launch.
The documentation now refers to the “Microsoft Entra ID Auth SDK (sidecar)” instead of the “Microsoft Entra SDK auth sidecar.” The token-validation guidance is otherwise unchanged.
The page updates image accessibility text, refines wording about agent identities, and standardizes the name “Microsoft Entra ID Auth SDK (sidecar)” for third-party agent integrations.
Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on August 11, 2026, due to fraud risks. Users must switch to other authentication methods before then. SMS as a multifactor method remains unaffected. Admins should identify affected users and update authentication policies accordingly.
The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” No procedural content changed in the supplied diff.
The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.
The documentation now states that opting out requires the Microsoft Graph `Policy.ReadWrite.AuthenticationMethod` permission. The page date changed from July 29 to August 10, 2026.
The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.
The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.
The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.
A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.
The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.
GitHub Actions now supports immutable OIDC subject formats with repository and owner IDs to enhance Microsoft Entra federated identity security. Organizations using GitHub Actions OIDC must migrate to this format by late July 2026 to prevent token mismatches and reduce unauthorized access risks.
Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.
The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.
Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting October 2026 to enhance security and phishing resistance. Existing users must remove these properties by then, as no migration path exists. Branding elements remain visible but may revert to default placement.
This timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Microsoft Entra ID is optimizing passkey registration via Registration Campaign, Authentication Strengths, and My Sign-Ins to improve compliance with passkey policies and prioritize local device passkeys. These changes, rolling out in late August 2026, require no user interface changes or action from organizations.
| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |
|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|
Microsoft Entra will enable passwordless users to change their passwords via My Sign-Ins using strong credentials like passkeys or Windows Hello, without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally in late October 2026.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.
Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.
Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication.
You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Microsoft Entra improves the Microsoft Authenticator passkey restore experience on iOS with a clearer, guided flow for device migration, available worldwide in August 2026. It affects iOS users with iCloud backups, is enabled by default, requires no admin changes, and no action is needed.
Learn how to back up and restore Microsoft Authenticator account entries when you switch to a new phone, including passkey setup steps.
Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID.
Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.
Learn about synced passkeys in Microsoft Entra ID, including how to configure, register, and sign in with synced passkeys.
Learn how to enable passwordless security key sign-in to Windows with Microsoft Entra ID using FIDO2 security keys.
Learn how to register a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant sign-in.
Learn how to register a passkey with a FIDO2 security key in Microsoft Entra ID. Use Security info or a prompted sign-in flow.
Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.
A Microsoft Entra documentation page was updated: Register Passkey Mobile.
Learn how to register passkeys in Microsoft Authenticator on Android and iOS. Sign in to the app, use Security info, or register cross-device.
Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.
Learn how to sign in with a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant authentication.
Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.
Learn how to sign in with passkeys in Microsoft Authenticator for Android and iOS. Use same-device, cross-device, or native app authentication.
A Microsoft Entra documentation page was updated: Support Authenticator Passkey.
Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.
To see risk sign-in events together with risky user events, select the **Aggregate risk signals by risky sign-ins** checkbox.
Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.
A Microsoft Entra documentation page was updated: Certificate Based Authentication Certificate Revocation List.
Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Forcepoint Cloud Security Gateway - User Authentication.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks Cloud Identity Engine - Cloud Authentication Service.
Learn how domain and forest trust relationships work in Active Directory and how they apply to Microsoft Entra Domain Services for cross-forest authentication.
Learn the core concepts of identity and access management (IAM), including authentication, authorization, and identity providers, to secure resources effectively.
Get the latest Microsoft Entra release notes, including updates on authentication, governance, and AI-powered identity protection for modern enterprises.
Learn about using QR code authentication method in Microsoft Entra ID to help improve and secure sign-in events for frontline workers.
Enable Microsoft Entra ID security defaults to strengthen your organization's security posture with preconfigured MFA requirements and legacy authentication protection.
Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.
Use shared helper functions for authentication and alert email in Global Secure Access operations automation scripts.
Learn how to sign up users with email one-time passcode or email and password, and collect user attributes including a username (alias), in an Android app by using native authentication.
Learn how to sign up users with email one-time passcode or email and password, and collect user attributes including a username (alias), in an iOS/macOS app by using native authentication.
Some organizations prefer to bootstrap this process through synchronization of authentication data that already exists in Active Directory Domain Services. This synchronized data is made available to Microsoft Entra ID and SSPR without requiring user interaction. When users need to change or reset their password, they can do so even if they haven't previously registered their contact information.
To sign in a user using username (email) and password, collect the email and password from the user. If the username and password are valid, the app signs in the user.
To sign in a user using the **Email with password** flow, capture the email and password. If the username and password are valid, the app signs in the user.
1. Create *sign-up/components/InitialForm.tsx* file, then paste the code from [sign-up/components/InitialForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/sign-up/components/InitialForm.tsx). This component displays a form that collects user sign-up attributes.
Learn about how to administer a Microsoft Entra Domain Services managed domain and the behavior of user accounts and passwords
Excel Power Query is updating its authentication flow for Organizational Accounts (Microsoft Entra ID) to enhance security and reliability. Users on Excel 2021 version 21.08 or older must update to build 16.0.14334.20754 or later by July 24, 2026, or upgrade to a newer version to avoid authentication loss. Microsoft 365 and newer Excel versions are unaffected.