Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.
Passkeys default in September; SMS/voice and SharePoint OTP retirements set Entra’s agenda
The period is dominated by two concrete authentication retirements and a related default change: Microsoft Entra says passkeys become the default on September 1, 2026, Microsoft-provided SMS and voice authentication retire on February 1, 2027, and SharePoint One-Time Passcode authentication retires in October 2026 as external sharing transitions to Entra B2B. The other substantive thread is Microsoft Entra Internet Access and Global Secure Access Explicit Forward Proxy: this week’s Learn content documents PAC-based deployment and Entra/Conditional Access session controls, with HTTP-header session management marked preview. Microsoft also says Purview DLP network-layer filtering is targeted for general availability by September 2026. The remaining supplied Learn entries—RBAC and token reference, Lifecycle Workflows procedures, Netskope provisioning, Linux troubleshooting, and SLA data—are ordinary documentation maintenance; their summaries do not establish additional launches, behavior changes, or required configuration.
- Passkeys become the default while Microsoft-provided SMS and voice retire
Entra ID · Conditional Access
This Entra ID change combines a behavior change with a retirement. Passkeys become the default authentication method on September 1, 2026, while Microsoft-provided SMS and voice authentication retire on February 1, 2027. Customers using SMS or voice must configure telecom providers through the Microsoft Security Store or risk disruption. The notice describes passkeys as phishing-resistant and available at no extra cost; the new Learn page provides migration and preparation guidance.
- SharePoint OTP transitions to Microsoft Entra B2B
External ID · Conditional Access
The External ID notice sets October 2026 as the retirement point for SharePoint One-Time Passcode authentication. It says new external sharing has used Microsoft Entra B2B since May 2026, and external users need guest accounts for access. The stated administrator preparation is to update policies and manage those guest accounts.
- Explicit Forward Proxy documentation broadens the deployment and security playbook
Internet Access · Conditional Access
The supplied Internet Access and Global Secure Access entries describe using Explicit Forward Proxy without the Global Secure Access client in PAC-capable browsers, hosting custom PAC files, delivering proxy and certificate-authority trust settings to Edge through Intune MAM, and using manual or DHCP/WPAD configuration for unmanaged devices. The session model uses Entra authentication and authorization, Conditional Access, passkeys, and Continuous Access Evaluation; basic, digest, NTLM, and Kerberos proxy author
- Purview DLP integration receives a preview-to-GA timeline
Internet Access · Conditional Access
A Message Center item describes Microsoft Purview DLP integrating with Entra Global Secure Access Internet Access to filter sensitive files at the network layer and prevent leaks to unmanaged cloud apps. Its stated timeline places public preview in mid-November 2025 and general availability by September 2026. Administrators can create granular policies through Purview and Defender; the period’s notice is not evidence that general availability has already occurred.
- Admin control for SSO prompts is documented for managed Windows devices
Entra ID · General
A new Entra ID Learn page says IT administrators can automatically accept SSO permissions on managed Windows devices through a supported registry setting. The supplied entry provides no rollout date or preview/GA status, so it should be treated as a newly documented control rather than a dated product-launch announcement.
Treat the authentication and external-sharing notices as the planning priorities. For SMS/voice, the Message Center notice says customers must configure telecom providers through the Microsoft Security Store or risk disruption; the companion Learn page focuses on migrating users to passkeys. For SharePoint, the notice says new external sharing has used Entra B2B since May 2026, external users need guest accounts, and admins should update policies and manage those accounts. For Explicit Forward Proxy deployments, the guidance says Conditional Access is not required but recommends restricting use to trusted networks and using Conditional Access to assign Internet Access security profiles; HTTP-header session management is preview. The DLP notice says policy controls are managed through Purก์
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
9 updatesConfigure Netskope User Authentication for automatic user provisioning with Microsoft Entra ID
UpdatedLearn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Learn about the new features and documentation improvements in Microsoft Entra role-based access control (RBAC).
Describes the Microsoft Entra built-in roles and permissions.
IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.
Microsoft Entra will make passkeys the default authentication method starting September 1, 2026, retiring Microsoft-provided SMS and voice authentication by February 1, 2027. Customers must configure telecom providers for SMS/voice via the Microsoft Security Store or face disruptions. Passkeys offer stronger, phishing-resistant security at no extra cost.
Sla Performance
Updated| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% | 99.999% |
> [!NOTE]
Microsoft Entra ID Governance
4 updatesTenant Governance Administrator
Learn how to use the What-if tool in Lifecycle Workflows to simulate workflow execution and preview results without impacting actual users.
1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.
Lifecycle Workflow Templates
UpdatedThe **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.
Microsoft Entra External ID
1 updateSharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.
Microsoft Entra Internet Access
4 updatesExplicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.
Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.
With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).
Learn how to upload and host your own Proxy Auto-Configuration (PAC) files
Microsoft Entra Global Secure Access
5 updatesFor unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).
Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:
You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.
Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.
You can automatically deliver proxy settings and certificate authority trust settings in Microsoft Edge by using an Intune mobile application management (MAM) policy. The policy can take advantage of the Explicit Forward Proxy feature of Global Secure Access.
