Cross-product topic

Authentication

A cross-product view of Microsoft Entra changes related to Authentication.

Latest Authentication changes

Assignment Network

Authentication

The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.

Assignment Network

Authentication

The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.

Assignment Network

Authentication

A link was fixed on the Conditional Access network assignment page.

Assignment Network

Authentication

The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.

Strengthen federated sign-in security

Authentication

The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.

Howto Arc Sign In Windows

Authentication

The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.

Howto Arc Sign In Windows

Authentication

The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.

Howto Arc Sign In Windows

Authentication

The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.

Howto Arc Sign In Windows

Authentication

The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.

Howto Arc Sign In Windows

Authentication

The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.

Migrate Passwords Just In Time

Authentication

The password migration documentation now uses a different example API application identifier.

Sign In With Passkey

Authentication

The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.

Fido2 Hardware Vendor

Authentication

The security key entry’s table formatting was corrected by removing an extra space before a separator.

Fido2 Hardware Vendor

Authentication

Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.

Fido2 Hardware Vendor

Authentication

The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.

Fido2 Hardware Vendor

Authentication

The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.

Fido2 Hardware Vendor

Authentication

The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.

Microsoft Entra ID: Retirement of custom CSS layout and positioning properties in company branding

Message CenterMC1458474 on mc.merill.net ↗Major updatePlan for change
Authentication

Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.

Company Branding Css Template

Authentication

The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.

Customize Branding

Authentication

The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.

Deployment Guide Token Protection Apple

Authentication

The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.

Optional Claims Reference

Authentication

The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.

Single Sign On Saml Protocol

Authentication

The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.

Strengthen federated sign-in security

Authentication

New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.

Identity Protection Policies

Authentication

The documentation now states that disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens.

Policy Guests Mfa Strength

Authentication

The guidance now states that authentication strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts, alongside the previously listed methods. It directs administrators to use the MFA grant control instead.

Agent Token Claims

Authentication

The Agent ID token claims documentation no longer includes one `tid` claim table row.

Authentication protocols in agents

Authentication

The page description was shortened by removing the phrase “Key concepts.” The documented OAuth 2.0 protocols and token exchange patterns remain unchanged.

Authentication with Microsoft Entra ID Auth SDK (sidecar)

Authentication

The documentation now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” and expands “SPA” to “single-page application.” The described authentication flows and responsibilities are otherwise unchanged in the supplied diff.

Error Codes

Authentication

The error-code documentation now separates quota, blueprint, blueprint principal, agent identity, and agent identity creation errors, with clearer descriptions and table headings.

Get the service principal for Microsoft Graph

Authentication

The documentation replaces inconsistent tenant placeholders with `<your-tenant-id>` and standardizes `<agent-blueprint-clientid>` to `<agent-blueprint-client-id>` in code samples.

Identity Protection Policies

Authentication

The documentation replaces “Device disablement” with “Attacker-added device” and explains that the Entra device object is disabled, new token issuance is blocked, existing device-bound refresh tokens are revoked, and user sessions are revoked.

Identity Protection Policies

Authentication

The documentation now describes a Device disablement response for users flagged by Microsoft threat intelligence as having an attacker-added device. The device is disabled, and the user is prompted to sign in from a trusted device.

Sign in with a Microsoft Entra passkey on Windows

Authentication

The page title and heading no longer include “(preview).” No other change is shown, and the diff does not explicitly announce general availability or a product launch.

Validate agent identity tokens in a downstream API

Authentication

The documentation now refers to the “Microsoft Entra ID Auth SDK (sidecar)” instead of the “Microsoft Entra SDK auth sidecar.” The token-validation guidance is otherwise unchanged.

What Is Microsoft Entra Agent Id

Authentication

The page updates image accessibility text, refines wording about agent identities, and standardizes the name “Microsoft Entra ID Auth SDK (sidecar)” for third-party agent integrations.

Connect Staged Rollout

Authentication

The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” No procedural content changed in the supplied diff.

Microsoft Entra Connect: Cloud authentication via Staged Rollout

Authentication

The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.

Managed Policies

Authentication

The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.

Howto Arc Sign In Windows

Authentication

The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.

Choose a telephony provider for SMS and voice authentication

Authentication

The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.

Choose a telephony provider for SMS and voice authentication

Authentication

A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.

Howto Sspr Authenticationdata

Authentication

The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.

Microsoft Entra ID SSPR will require registered authentication methods starting November 9, 2026

Message CenterMC1325414 on mc.merill.net ↗Major updatePlan for change
Authentication

Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.

Sms Voice Retirement

Authentication

The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.

Sms Voice Retirement

Authentication

This timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.

Add OIDC for customer sign-in

Authentication

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

Access Token Claims Reference

Authentication

| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |

Use Scim To Provision Users And Groups

Authentication

|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|

Microsoft Entra: Passwordless password change in My Sign-Ins

Message CenterMC1437671 on mc.merill.net ↗Stay informed
Authentication

Microsoft Entra will enable passwordless users to change their passwords via My Sign-Ins using strong credentials like passkeys or Windows Hello, without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally in late October 2026.

Company Branding Css Template

Authentication

Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.

Sms Voice Retirement

Authentication

Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.

Universal Tenant Restrictions

Authentication

- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.

(Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants

Message CenterMC1221452 on mc.merill.net ↗Major updatePlan for change
Authentication

Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.

Access tokens in the Microsoft identity platform

Authentication

Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.

Configure HTTP header session management (preview)

Authentication

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

Register a synced passkey (FIDO2)

Authentication

Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.

Register Passkey Mobile

Authentication

A Microsoft Entra documentation page was updated: Register Passkey Mobile.

Sign in with a FIDO2 security key

Authentication

Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.

Sign in with a synced passkey (FIDO2)

Authentication

Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.

OAuth 2.0 and OpenID Connect protocols

Authentication

Learn about OAuth 2.0 and OpenID Connect in Microsoft identity platform. Explore authentication flows, endpoints, and secure user authentication.

Risky User Report

Authentication

To see risk sign-in events together with risky user events, select the **Aggregate risk signals by risky sign-ins** checkbox.

Tutorial: Enable source IP restoration

Authentication

Learn how to enable source IP restoration for Microsoft traffic in Global Secure Access and validate Microsoft Entra sign-in logs.

Choose Authentication Approach

Authentication

Compare browser-delegated and native authentication in Microsoft Entra External ID and choose the right approach for your customer-facing app.

Security Defaults

Authentication

Enable Microsoft Entra ID security defaults to strengthen your organization's security posture with preconfigured MFA requirements and legacy authentication protection.

Sign in with alias

Authentication

Learn how to sign in and sign up with alias/username with External ID for customer identity and access management (CIAM). Get detailed steps to enable username as a sign-in identifier and create users with both email address and username.

Howto Sspr Authenticationdata

Authentication

Some organizations prefer to bootstrap this process through synchronization of authentication data that already exists in Active Directory Domain Services. This synchronized data is made available to Microsoft Entra ID and SSPR without requiring user interaction. When users need to change or reset their password, they can do so even if they haven't previously registered their contact information.

Tutorial Native Authentication Single Page App React Sdk Sign Up

Authentication

1. Create *sign-up/components/InitialForm.tsx* file, then paste the code from [sign-up/components/InitialForm.tsx](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/blob/main/typescript/native-auth/react-nextjs-sample/src/app/sign-up/components/InitialForm.tsx). This component displays a form that collects user sign-up attributes.

Required update for organizational authentication in Excel Power Query (Entra ID)

Message CenterMC1403409 on mc.merill.net ↗Prevent or fix issue
Authentication

Excel Power Query is updating its authentication flow for Organizational Accounts (Microsoft Entra ID) to enhance security and reliability. Users on Excel 2021 version 21.08 or older must update to build 16.0.14334.20754 or later by July 24, 2026, or upgrade to a newer version to avoid authentication loss. Microsoft 365 and newer Excel versions are unaffected.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…