Week in brief

Custom Controls retirement sets a September 2026 deadline to move affected Conditional Access policies to External MFA

During the week of 6 July 2026, the strongest administrator signal is a Conditional Access lifecycle change rather than a broad Entra feature launch. Custom Controls are scheduled to retire by May 2027, with policy migration to External MFA required by September 2026; system-preferred authentication also now applies to first-factor sign-in for tenants in the Microsoft-managed state. The other substantial thread is passkey operations: new and revised guidance spans synced passkeys, Authenticator, FIDO2, and Windows Hello, with the Windows path explicitly in preview. An iOS Authenticator restore improvement is scheduled worldwide for August, while Dynamics 365 Contact Center user management through Entra security groups has an explicit 24 July general availability date. The remaining supplied items are mostly how-to, troubleshooting, migration, licensing, or maintenance documentation.

  • A Microsoft 365 Message Center major update says Entra ID will retire Custom Controls in Conditional Access by May 2027. Administrators must migrate policies by September 2026, replacing Custom Controls with External MFA for standardized third-party MFA integration. This is an explicit retirement and migration notice, not a new-feature or general availability announcement.

  • Microsoft Entra now applies system-preferred authentication to first-factor sign-in for tenants in the Microsoft-managed state and selects the most secure registered method. The notice says rollout starts in late June 2026; tenants can keep or change the setting and should update user guidance. This is a changed authentication behavior, not a new authentication method.

  • New and updated Microsoft Learn pages cover enabling, registering, and signing in with synced passkeys; Microsoft Authenticator on Android and iOS; FIDO2 security keys; and backup and restore when moving Authenticator to a new phone. The Windows-specific Entra passkey flow uses Windows Hello as a FIDO2 passkey provider and is labeled preview. A related External ID troubleshooting update warns that a phishing-resistant authentication-strength Conditional Access policy scoped to All resources can loop when a userAdds

  • Message Center describes a clearer, guided device-migration flow for restoring Microsoft Authenticator passkeys on iOS for users with iCloud backups. It will be available worldwide in August 2026, is enabled by default, and requires no administrator changes or action. This is a user-experience rollout, not a tenant configuration change.

  • Microsoft announced that managing Dynamics 365 Contact Center users through Microsoft Entra security groups will reach general availability on 24 July 2026. This is a GA milestone for that Contact Center integration; the supplied message does not state additional Entra configuration steps.

For Entra administrators

The clearest near-term task is to migrate affected Conditional Access policies from Custom Controls to External MFA by September 2026; the retirement target is May 2027. For tenants in the Microsoft-managed state, decide whether to keep or change system-preferred authentication and update user guidance, because first-factor sign-in now selects the most secure registered method. Use the passkey registration, sign-in, and Conditional Access loop guidance where relevant, but do not infer general availability from documentation updates; the Windows path remains preview. The iOS restore notice explicitly requires no administrator changes or action.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

17

Sign in with a FIDO2 security key

New

Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.

7 July 2026

Register a synced passkey (FIDO2)

Updated

Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.

7 July 2026

Sign in with a synced passkey (FIDO2)

Updated

Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.

7 July 2026

Register Passkey Mobile

Removed

A Microsoft Entra documentation page was updated: Register Passkey Mobile.

7 July 2026
3
3

Connect Version History

Updated

This article lists all releases of Microsoft Entra Connect and Azure AD Sync.

8 July 2026
1

Connect with the required scope

Updated

After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.

11 July 2026
1
1

Snowflake Provisioning Tutorial

Updated

With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.

7 July 2026
1
1
3

Licensing Guest Users

Updated

Global Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.

8 July 2026
1

Troubleshoot

Updated

Organizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).

7 July 2026
1
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…