Week in brief

Passkeys default in September; SMS/voice and SharePoint OTP retirements set Entra’s agenda

The period is dominated by two concrete authentication retirements and a related default change: Microsoft Entra says passkeys become the default on September 1, 2026, Microsoft-provided SMS and voice authentication retire on February 1, 2027, and SharePoint One-Time Passcode authentication retires in October 2026 as external sharing transitions to Entra B2B. The other substantive thread is Microsoft Entra Internet Access and Global Secure Access Explicit Forward Proxy: this week’s Learn content documents PAC-based deployment and Entra/Conditional Access session controls, with HTTP-header session management marked preview. Microsoft also says Purview DLP network-layer filtering is targeted for general availability by September 2026. The remaining supplied Learn entries—RBAC and token reference, Lifecycle Workflows procedures, Netskope provisioning, Linux troubleshooting, and SLA data—are ordinary documentation maintenance; their summaries do not establish additional launches, behavior changes, or required configuration.

  • This Entra ID change combines a behavior change with a retirement. Passkeys become the default authentication method on September 1, 2026, while Microsoft-provided SMS and voice authentication retire on February 1, 2027. Customers using SMS or voice must configure telecom providers through the Microsoft Security Store or risk disruption. The notice describes passkeys as phishing-resistant and available at no extra cost; the new Learn page provides migration and preparation guidance.

  • External ID · Conditional Access
    SharePoint OTP transitions to Microsoft Entra B2B

    The External ID notice sets October 2026 as the retirement point for SharePoint One-Time Passcode authentication. It says new external sharing has used Microsoft Entra B2B since May 2026, and external users need guest accounts for access. The stated administrator preparation is to update policies and manage those guest accounts.

  • The supplied Internet Access and Global Secure Access entries describe using Explicit Forward Proxy without the Global Secure Access client in PAC-capable browsers, hosting custom PAC files, delivering proxy and certificate-authority trust settings to Edge through Intune MAM, and using manual or DHCP/WPAD configuration for unmanaged devices. The session model uses Entra authentication and authorization, Conditional Access, passkeys, and Continuous Access Evaluation; basic, digest, NTLM, and Kerberos proxy author­

  • A Message Center item describes Microsoft Purview DLP integrating with Entra Global Secure Access Internet Access to filter sensitive files at the network layer and prevent leaks to unmanaged cloud apps. Its stated timeline places public preview in mid-November 2025 and general availability by September 2026. Administrators can create granular policies through Purview and Defender; the period’s notice is not evidence that general availability has already occurred.

  • A new Entra ID Learn page says IT administrators can automatically accept SSO permissions on managed Windows devices through a supported registry setting. The supplied entry provides no rollout date or preview/GA status, so it should be treated as a newly documented control rather than a dated product-launch announcement.

For Entra administrators

Treat the authentication and external-sharing notices as the planning priorities. For SMS/voice, the Message Center notice says customers must configure telecom providers through the Microsoft Security Store or risk disruption; the companion Learn page focuses on migrating users to passkeys. For SharePoint, the notice says new external sharing has used Entra B2B since May 2026, external users need guest accounts, and admins should update policies and manage those accounts. For Explicit Forward Proxy deployments, the guidance says Conditional Access is not required but recommends restricting use to trusted networks and using Conditional Access to assign Internet Access security profiles; HTTP-header session management is preview. The DLP notice says policy controls are managed through Purก์

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

3

Access tokens in the Microsoft identity platform

Updated

Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.

18 July 2026
3

Admin Control for SSO prompts

New

IT administrators can now automatically accept SSO permissions on managed Windows devices using a supported registry setting.

16 July 2026
1

Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

New

Microsoft Entra will make passkeys the default authentication method starting September 1, 2026, retiring Microsoft-provided SMS and voice authentication by February 1, 2027. Customers must configure telecom providers for SMS/voice via the Microsoft Security Store or face disruptions. Passkeys offer stronger, phishing-resistant security at no extra cost.

16 July 2026
Message CenterMC1426371 on mc.merill.net ↗Major updatePlan for change
1

Sla Performance

Updated

| March | 99.568% | 99.998% | 99.999% | 99.999% | 99.996% | 99.999% |

16 July 2026
1
4

Lifecycle Workflow Inactive Users

Updated

1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.

16 July 2026

Lifecycle Workflow Templates

Updated

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

16 July 2026
1

Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B

New

SharePoint One-Time Passcode (SPO OTP) authentication retires in October 2026, transitioning external sharing and authentication to Microsoft Entra B2B. New external sharing uses Entra B2B from May 2026. External users need guest accounts for access; admins should prepare by updating policies and managing guest accounts accordingly.

17 July 2026
Message CenterMC1243549 on mc.merill.net ↗Major updatePlan for change
2

Configure a Microsoft Entra Conditional Access policy for Explicit Forward Proxy

Updated

Explicit Forward Proxy for Microsoft Entra Internet Access relies on IP affinity, among other mechanisms, for session management. Although a Conditional Access policy isn't required, we recommend that you configure one that restricts the use of Explicit Forward Proxy to networks that your organization trusts. Additionally, you use Conditional Access policies to assign the Microsoft Entra Internet Access security profiles to users.

18 July 2026

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

New

Microsoft Purview DLP will integrate with Entra Global Secure Access Internet Access to filter sensitive files at the network layer. Public preview starts mid-November 2025; general availability by September 2026. Admins can create granular policies to prevent data leaks to unmanaged cloud apps, managed via Purview and Defender.

17 July 2026
Message CenterMC1181769 on mc.merill.net ↗Stay informed
2

Configure Explicit Forward Proxy

Updated

With Explicit Forward Proxy, you can use the secure web and AI gateway capabilities of Microsoft Entra Internet Access without installing the Global Secure Access client. Explicit Forward Proxy works with any browser that supports proxy automatic configuration (PAC).

18 July 2026
2

Proxy Automatic Configuration Files

Updated

For unmanaged devices, you can instruct users to manually enter the PAC file location in browser settings or rely on a network-provided configuration. A network-provided configuration might be Dynamic Host Configuration Protocol (DHCP) or Web Proxy Auto-Discovery (WPAD).

14 July 2026

Explicit Forward Proxy overview

Updated

Explicit Forward Proxy is a traffic acquisition mechanism that's useful in scenarios where installation of the Global Secure Access client is difficult or not possible. Explicit Forward Proxy helps protect internet traffic when users use browsers to access resources from:

14 July 2026
1

Configure HTTP header session management (preview)

Updated

You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.

14 July 2026
1

Explicit Forward Proxy session management

Updated

Explicit Forward Proxy uses Microsoft Entra ID authentication and authorization to validate user access before allowing network traffic. This validation method allows for adaptive policies in Microsoft Entra Conditional Access, modern credentials like passkeys, and Continuous Access Evaluation with session revocation. Classic proxy authorization methods, such as basic, digest, NTLM, or Kerberos, aren't supported.

14 July 2026
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…