Microsoft Entra improves the Microsoft Authenticator passkey restore experience on iOS with a clearer, guided flow for device migration, available worldwide in August 2026. It affects iOS users with iCloud backups, is enabled by default, requires no admin changes, and no action is needed.
Custom Controls retirement sets a September 2026 deadline to move affected Conditional Access policies to External MFA
During the week of 6 July 2026, the strongest administrator signal is a Conditional Access lifecycle change rather than a broad Entra feature launch. Custom Controls are scheduled to retire by May 2027, with policy migration to External MFA required by September 2026; system-preferred authentication also now applies to first-factor sign-in for tenants in the Microsoft-managed state. The other substantial thread is passkey operations: new and revised guidance spans synced passkeys, Authenticator, FIDO2, and Windows Hello, with the Windows path explicitly in preview. An iOS Authenticator restore improvement is scheduled worldwide for August, while Dynamics 365 Contact Center user management through Entra security groups has an explicit 24 July general availability date. The remaining supplied items are mostly how-to, troubleshooting, migration, licensing, or maintenance documentation.
- Retirement: Conditional Access Custom Controls move to External MFA
Entra ID · Conditional Access
A Microsoft 365 Message Center major update says Entra ID will retire Custom Controls in Conditional Access by May 2027. Administrators must migrate policies by September 2026, replacing Custom Controls with External MFA for standardized third-party MFA integration. This is an explicit retirement and migration notice, not a new-feature or general availability announcement.
- Changed behavior: system-preferred authentication now covers first-factor sign-in
Entra ID · Authentication
Microsoft Entra now applies system-preferred authentication to first-factor sign-in for tenants in the Microsoft-managed state and selects the most secure registered method. The notice says rollout starts in late June 2026; tenants can keep or change the setting and should update user guidance. This is a changed authentication behavior, not a new authentication method.
- Passkeys: new and revised operating guidance, with Windows explicitly in preview
Entra ID · Authentication
New and updated Microsoft Learn pages cover enabling, registering, and signing in with synced passkeys; Microsoft Authenticator on Android and iOS; FIDO2 security keys; and backup and restore when moving Authenticator to a new phone. The Windows-specific Entra passkey flow uses Windows Hello as a FIDO2 passkey provider and is labeled preview. A related External ID troubleshooting update warns that a phishing-resistant authentication-strength Conditional Access policy scoped to All resources can loop when a userAdds
- Authenticator passkey restore on iOS is scheduled for worldwide August availability
Entra ID · Authentication
Message Center describes a clearer, guided device-migration flow for restoring Microsoft Authenticator passkeys on iOS for users with iCloud backups. It will be available worldwide in August 2026, is enabled by default, and requires no administrator changes or action. This is a user-experience rollout, not a tenant configuration change.
- General availability: Dynamics 365 Contact Center user management through Entra security groups
Entra ID · Security
Microsoft announced that managing Dynamics 365 Contact Center users through Microsoft Entra security groups will reach general availability on 24 July 2026. This is a GA milestone for that Contact Center integration; the supplied message does not state additional Entra configuration steps.
The clearest near-term task is to migrate affected Conditional Access policies from Custom Controls to External MFA by September 2026; the retirement target is May 2027. For tenants in the Microsoft-managed state, decide whether to keep or change system-preferred authentication and update user guidance, because first-factor sign-in now selects the most secure registered method. Use the passkey registration, sign-in, and Conditional Access loop guidance where relevant, but do not infer general availability from documentation updates; the Windows path remains preview. The iOS restore notice explicitly requires no administrator changes or action.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
27 updatesLearn how to back up and restore Microsoft Authenticator account entries when you switch to a new phone, including passkey setup steps.
Learn how to register passkeys in Microsoft Authenticator on Android and iOS. Sign in to the app, use Security info, or register cross-device.
Learn how to enable passwordless security key sign-in to Windows with Microsoft Entra ID using FIDO2 security keys.
Learn how to register a passkey with a FIDO2 security key in Microsoft Entra ID. Use Security info or a prompted sign-in flow.
Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
Learn how to sign in to Microsoft Entra ID with a FIDO2 security key. Sign in to web apps, Windows, and on-premises resources.
Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.
Learn how to register a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant sign-in.
Learn how to sign in with a Microsoft Entra passkey on Windows by using Windows Hello as a FIDO2 passkey provider for phishing-resistant authentication.
Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID.
Learn about synced passkeys in Microsoft Entra ID, including how to configure, register, and sign in with synced passkeys.
Learn how to register a synced passkey (FIDO2) as an authentication method on Windows, iOS, or Android by using a browser for phishing-resistant sign-in.
Learn how to sign in to Microsoft Entra ID with a synced passkey (FIDO2) for your work or school account by using a browser on Windows, iOS, or Android.
Learn how to sign in with passkeys in Microsoft Authenticator for Android and iOS. Use same-device, cross-device, or native app authentication.
Register Passkey Mobile
RemovedA Microsoft Entra documentation page was updated: Register Passkey Mobile.
A Microsoft Entra documentation page was updated: Support Authenticator Passkey.
- **Conditional Access**: The new policy evaluated and granted access
Microsoft Entra ID is retiring Custom Controls in Conditional Access by May 2027, replacing them with External MFA for standardized third-party MFA integration. Administrators must migrate policies by September 2026, updating Conditional Access to use External MFA to ensure continued support and security.
Conditional Access enforcement update completed in your tenant
Connect Version History
UpdatedThis article lists all releases of Microsoft Entra Connect and Azure AD Sync.
ai-usage: ai-assisted
* [Federated MFA](/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-mfa)
After creating a new application proxy application, grant admin consent for the **User.Read** delegated permission in the Microsoft Entra admin center or using the Microsoft Graph PowerShell.
Primary Refresh Token
Updated| **Term** | **Description** |
With Privileged Identity Management (PIM) for Groups, you can provide just-in-time access to groups in Snowflake and reduce the number of users who have permanent access to privileged groups in Snowflake.
We are announcing the ability to manage users through Microsoft Entra security groups in Dynamics 365 Contact Center. This feature will reach general availability on July 24, 2026.
Microsoft Entra ID Governance
1 updateLearn how Microsoft Entra ID is licensed for guest users.
Microsoft Entra External ID
4 updatesUse the Migration Policy Analyzer to scan Azure AD B2C custom policies and generate a detailed migration assessment for Microsoft Entra External ID. Start your migration today.
Licensing Guest Users
UpdatedGlobal Secure Access external user access licensing is supported through Microsoft Entra External ID subscription linking. The administrator must link the subscription in the resource tenant so guest users can access private resources and usage is billed correctly.
Learn to migrate from Amazon Cognito to Microsoft Entra External ID with step-by-step guidance, feature mapping, and validation strategies.
Troubleshoot
UpdatedOrganizations that are deploying passkeys and have Conditional Access policies that require phishing-resistant authentication when accessing **All resources (formerly 'All cloud apps')** can run into a looping issue when users attempt to add a passkey to Microsoft Authenticator. For more information and possible workarounds, see [Workarounds for an authentication strength Conditional Access policy loop](~/identity/authentication/how-to-enable-authenticator-passkey.md#workarounds-for-an-authentication-strength-conditional-access-policy-loop).
Microsoft Entra Workload ID
2 updatesLearn how to configure assignment restriction for a user-assigned managed identity in the Azure portal to scope it to specific resource providers.
Learn how assignment restrictions scope a user-assigned managed identity to one or more resource providers to improve security and resilience.
External User Access
Updated> [!TIP]
