Cross-product topic

Conditional Access

A cross-product view of Microsoft Entra changes related to Conditional Access.

Latest Conditional Access changes

Clean broker state including certificates (requires sudo)

Conditional Access

Microsoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.

Microsoft Entra ID: Passkey support for B2B users

Message CenterMC1459133 on mc.merill.net ↗Stay informed
Conditional Access

Microsoft Entra ID will support passkey registration and sign-in for B2B users to meet resource tenant MFA requirements, enhancing phishing resistance. This feature, enabled by default, rolls out from October 2026 to February 2027, requiring no admin action but recommending policy reviews to align user scopes and MFA settings.

Token Protection Deployment Guide - Apple Platforms

Conditional Access

The guide removes the Preview designation, adds Microsoft Scout to the support matrix, and replaces detailed storage-flag instructions with updated Apple SSO plugin and Platform SSO guidance.

Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings

Message CenterMC1303719 on mc.merill.net ↗Plan for change
Conditional Access

Microsoft Entra will update federatedTokenValidationPolicy by mid-August 2026 to block federated sign-ins when internalDomainFederation doesn't match the user's UPN domain, enhancing security. This affects federated domains configured before December 2025. Admins can customize the policy via Microsoft Graph but it's discouraged.

Microsoft Entra: Windows Hello for Business and macOS Platform SSO as standalone MFA factors

Message CenterMC1450134 on mc.merill.net ↗Plan for change
Conditional Access

Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are needed, but organizations should update onboarding and MFA registration guidance accordingly.

Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

Message CenterMC1450133 on mc.merill.net ↗Stay informed
Conditional Access

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.

Token Protection

Conditional Access

The token protection article removes a screenshot of a Conditional Access policy requiring token protection as a session control. The Primary Refresh Token link remains.

Licensing Conditional Access

Conditional Access

The documentation now lists two supported licensing options: Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.

Licensing Conditional Access

Conditional Access

The documentation now states that Conditional Access for agents requires a Microsoft Agent 365 license to apply policies through Microsoft Entra Agent ID, replacing “Starting soon.”

Token Protection deployment guide - Web apps (Preview)

Conditional Access

Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.

Microsoft Entra ID: Replace MemberOf rules by November 3, 2026

Message CenterMC1448379 on mc.merill.net ↗Major updatePlan for change
Conditional Access

Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.

General Availability: Microsoft Entra passkeys on Windows

Message CenterMC1282568 on mc.merill.net ↗Stay informed
Conditional Access

Microsoft Entra passkeys on Windows will be generally available from late April 2026, enabling phishing-resistant, passwordless sign-in on Windows devices without explicit opt-in. This supports corporate, personal, and shared devices, with admin controls via Authentication Methods policies and Conditional Access. No action is needed unless blocking is desired.

Microsoft Purview | Data Loss Prevention - Extend Purview data security to the network layer via Entra GSA integration

Message CenterMC1419797 on mc.merill.net ↗Major updatePlan for change
Conditional Access

Microsoft Purview extends data loss prevention to the network layer via integration with Entra Internet Access, enabling inspection and protection of sensitive data in AI interactions and cloud services. It supports policy enforcement, alerts, and auditing, with rollout from July to October 2026, affecting Purview, Entra, and Defender administrators.

Configure a Microsoft Entra Conditional Access policy for Explicit Forward Proxy

Conditional Access

Explicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

Message CenterMC1181769 on mc.merill.net ↗Stay informed
Conditional Access

Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.

Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B

Message CenterMC1243549 on mc.merill.net ↗Major updatePlan for change
Conditional Access

SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.

Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Message CenterMC1426371 on mc.merill.net ↗Major updatePlan for change
Conditional Access

Microsoft Entra will make passkeys the default authentication method starting September 1, 2026, retiring Microsoft-provided SMS and voice authentication by February 1, 2027. Customers must configure telecom providers for SMS/voice via the Microsoft Security Store or face disruptions. Passkeys offer stronger, phishing-resistant security at no extra cost.

Explicit Forward Proxy session management

Conditional Access

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Microsoft Entra ID: Retirement of Custom Controls in Conditional Access and migration to External MFA

Message CenterMC1422061 on mc.merill.net ↗Major updatePlan for change
Conditional Access

Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027, replacing them with External MFA for standardized third-party MFA integration. Administrators must migrate policies by September 2026, updating Conditional Access to use External MFA to ensure continued support and security.

Troubleshoot

Conditional Access

Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).

Identity Protection Policies

Conditional Access

ID Protection analyzes signals about user accounts and calculates a risk score based on the probability that the user is compromised. If a user has risky user sign-in behavior, or their credentials were leaked, ID Protection uses these signals to calculate the user risk level. Administrators can configure risk-based Conditional Access policies to enforce access controls based on user risk, including requirements such as:

Tutorial Internet Access Introduction

Conditional Access

This series of exercises covers the fundamentals of Internet Access. The exercises assume that you follow them in order. If you skip around, you might miss a step. For example, in the baseline web-filtering tutorial, you create a security profile and assign it to a Microsoft Entra Conditional Access policy. Subsequent labs instruct you to assign the new policy to this existing security profile rather than creating a new security profile and Conditional Access policy each time.

Licensing Conditional Access

Conditional Access

Microsoft Entra Suite includes all Microsoft Entra Conditional Access features. Microsoft 365 E7 also includes Conditional Access features through the Entra Suite.

Agent Id

Conditional Access

In this flow, the agent can't reuse the user's original token because it was issued for a different audience. Instead, the agent uses the OBO flow to exchange tokens with Microsoft Entra ID, obtaining a new token scoped to the target resource. This token exchange is also evaluated by Conditional Access, letting admins enforce granular controls over which resources agents can access on behalf of the user.

Manage agent identities in your organization

Conditional Access

Learn how to manage agent identities across your organization. View, disable, govern, and monitor agents using the Microsoft Entra admin center and Conditional Access.

Authentication Strengths

Conditional Access

Learn how admins can use Microsoft Entra Conditional Access to distinguish which authentication methods users can use based on relevant security factors.

Manage agent identities in your organization

Conditional Access

Learn how to manage agent identities across your organization. View, disable, govern, and monitor agents using the Microsoft Entra admin center and Conditional Access.

Migrate Custom Controls External Mfa

Conditional Access

Learn how to migrate from custom controls to external multifactor authentication in Microsoft Entra Conditional Access.

Agent Id

Conditional Access

- High-level overview of Conditional Access: [What is Conditional Access?](overview.md)

Conditional Access Agent Optimization Settings

Conditional Access

The agent settings described in this article cover standard options like triggers, notifications, and scope. But the settings also include advanced options like custom instructions, Intune integrations, and permissions.

Target agent identities in Conditional Access policies

Conditional Access

Conditional Access policies for agent identities let you control how AI agents access corporate resources. As your organization deploys more agents, you need policies that target the right agents, evaluate the right signals, and enforce the right controls. To learn more about how Conditional Access policies for agents work for different scenarios, see [Conditional Access policies for agents](agent-id.md).

What If Tool

Conditional Access

The [What If Evaluation API](/graph/api/conditionalaccessroot-evaluate) is a Microsoft Graph API that is called by the Conditional Access experience. The API is different from the legacy What If evaluation in a few ways:

61009

Conditional Access

When an organization deploys AI agents, those agents acquire access tokens to access organizational resources on every interaction, but without an interactive user session and device, location, or MFA signals that classic Conditional Access uses to make trust decisions for human users. Microsoft Entra Agent ID introduces two distinct identity types:

userimpact: Low

Conditional Access

When an organization enables AI agents in Microsoft Entra, [agent identities](/entra/agent-id/agent-identities) can access tokens to access organizational resources without an interactive user session and device, location, or MFA signals that classic Conditional Access uses to make trust decisions for human users. Microsoft Entra ID Protection for agents continuously evaluates each agent's behavior and emits a risk level that is driven by signals such as:

Agent Id

Conditional Access

Conditional Access is an intelligent policy engine that helps organizations control how users and agents access corporate resources. It brings together real-time signals such as user's and agent's context, device, location, and session risk information to determine when to allow, block, or limit access, or require more verification steps.

Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration

Message CenterMC1326253 on mc.merill.net ↗Stay informed
Conditional Access

Conditional Access policies will apply to Windows Hello for Business and macOS Platform SSO registration starting July 6, 2026, enforcing policy requirements like MFA and trusted locations during enrollment. Organizations should review and test policies, update documentation, and ensure users can meet requirements before rollout completes July 13, 2026.

Conditional Access Agent Optimization

Conditional Access

- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.

Conditional Access Agent Optimization Review Suggestions

Conditional Access

Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.

Id Protection Guide Introduction

Conditional Access

- [Conditional Access Administrator](../identity/role-based-access-control/permissions-reference.md#conditional-access-administrator)

Plan Conditional Access

Conditional Access

- [Security Reader](~/identity/role-based-access-control/permissions-reference.md#security-reader)

Tutorial Enable Azure Mfa

Conditional Access

* An account with at least the [Conditional Access Administrator](~/identity/role-based-access-control/permissions-reference.md#conditional-access-administrator) role. Some MFA settings can also be managed by an [Authentication Policy Administrator](../role-based-access-control/permissions-reference.md#authentication-policy-administrator).

Explicit Forward Proxy (preview) session management

Conditional Access

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

Licensing Agent Id

Conditional Access

- **Conditional Access for agents**: Microsoft Entra ID P1 or Microsoft 365 E3.

Conditional Access Users Groups

Conditional Access

A workload identity is an identity that allows an application or service principal access to resources, sometimes in the context of a user. Conditional Access policies can be applied to single tenant service principals registered in your tenant. Non-Microsoft SaaS and multitenant apps are out of scope. Managed identities aren't covered by policy.

Workload Identity

Conditional Access

> In directories without appropriate licenses, existing Conditional Access policies for workload identities continue to function, but can't be modified. For more information, see [Microsoft Entra Workload ID](https://www.microsoft.com/security/business/identity-access/microsoft-entra-workload-identities#office-StandaloneSKU-k3hubfz).

Whats New

Conditional Access

Microsoft Entra Backup and Recovery is a built-in solution to help restore your tenant after accidental changes or malicious updates. Always on by default, it automatically backs up critical directory objects — including users, groups, applications, service principals, managed identities, conditional Access policies, named locations, agent IDs, and authentication and authorization policy, so admins can quickly restore them to a previously known good state.

Conditional Access Grant

Conditional Access

When user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation control](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control).

Conditional Access Cloud Apps

Conditional Access

Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, are enforced in user sign-in flows where the client application requests only these scopes. There is no change in behavior when an application requests any additional scope beyond those listed above.

Improved Enforcement Resource Exclusions

Conditional Access

Microsoft Entra ID is rolling out an improved enforcement model for Conditional Access policies that target **All resources** and include one or more **resource exclusions**. This change ensures that sign-ins requesting only baseline scopes receive the same Conditional Access protections as other resource access.

Quickstart: Create a new tenant in Microsoft Entra ID

Conditional Access

- To learn about access management, see [Azure role-based access control (RBAC)](/azure/role-based-access-control/overview) and [Conditional Access](~/identity/conditional-access/overview.md) to help manage your organization's application and resource access.

Conditional Access Cloud Apps

Conditional Access

Admins can select published authentication contexts in Conditional Access policies by going to **Assignments** > **Target resources** and selecting **Authentication context** from the **Select what this policy applies to** menu.

Plan Conditional Access

Conditional Access

- Which users, groups, directory roles, or workload identities are included in or excluded from the policy?

Policy Alt All Users Compliant Hybrid Or Mfa

Conditional Access

The prompt for authentication usually occurs when a device is offline for an extended period of time. This change eliminates the need for an exclusion in the Conditional Access policy for Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later. A Conditional Access policy can still be used with Windows 11, version 23H2 with [KB5034848](https://support.microsoft.com/help/5034848) or later if the prompt for user authentication via a toast notification isn't desired.

Policy Block By Location

Conditional Access

- [Conditional Access templates](concept-conditional-access-policy-common.md)

Mandatory Multifactor Authentication

Conditional Access

Some customers apply Conditional Access policies to user-based service accounts. You can reclaim the user-based license, and add a [workload identities](~/workload-id/workload-identities-overview.md) license to apply [Conditional Access for workload identities](~/identity/conditional-access/workload-identity.md).

Plan Conditional Access

Conditional Access

Creating a policy for each app isn't efficient and makes managing policies difficult. Conditional Access has a limit of 240 policies per tenant. This 240-policy limit includes Conditional Access policies in any state, including report-only mode, on, or off.

Secure Generative Ai

Conditional Access

Enforce least privilege principles and apply the right access controls to keep your organization secure with [Conditional Access policies](../identity/conditional-access/plan-conditional-access.md). Think of Conditional Access policies as if-then statements where identities that meet certain criteria can only access resources if they meet specific requirements such as MFA or device compliance status.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…