Week in brief

Passkey GA and automatic FIDO2 migration lead the period, with network-layer DLP close behind

Authentication is the period’s main story, but the notices describe a mix of already-dated GA statuses and staged future rollouts rather than one July launch. Entra passkey profiles and synced passkeys are moving to GA for tenants with Passkeys (FIDO2) enabled, with existing configurations migrating through October. Windows passkeys are described as GA from late April, while passwordless password change is scheduled for late October and remains disabled by default. External ID documentation clarifies future SMS and voice retirement scope for B2B and internal guest users. Separately, Microsoft Purview DLP is rolling network-layer inspection and protection through Entra Internet Access (Global Secure Access) from July to October. The remaining Learn work is mostly maintenance or clarification; the new GSA egress-range and Databricks SCIM pages are operational references, not evidence of new service launches.

  • The July 21 Message Center major update describes GA beginning in March 2026 for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new `passkeyType` property, while automatic migration and registration-campaign changes roll out regionally through October 2026. Because the schedule is already underway, this is a GA and migration update rather than a new July launch.

  • The Windows passkey notice places Entra passkeys on Windows in GA from late April 2026, without explicit opt-in, for corporate, personal, and shared devices. Authentication Methods policies and Conditional Access are the stated admin controls. Separately, passwordless users will be able to change passwords in My Sign-Ins with passkeys or Windows Hello, without the current password or SSPR; that capability is disabled by default, requires admin activation, and is scheduled for global rollout in late October 2026.

  • The major update describes Microsoft Purview DLP integrating with Entra Internet Access (Global Secure Access) to inspect and protect sensitive data at the network layer, including in AI interactions and cloud services. The stated capabilities include policy enforcement, alerts, and auditing, with rollout scheduled from July through October 2026. It explicitly affects Purview, Entra, and Defender administrators, but the supplied summary does not provide additional configuration steps.

  • An updated External ID page says B2B users and internal guest users are included in the retirement scope for Microsoft-provided SMS and voice authentication. It also says passkey support for those users is planned by the end of calendar year 2026. This is a future-scope clarification, not evidence that the retirement or passkey support completed during this period; no migration procedure or retirement date is supplied.

  • Beginning in early August 2026, Microsoft Entra self-service password reset is scheduled to replace its legacy CAPTCHA with backend throttling and behavior-based abuse detection. The notice says current password-reset functionality remains, no new controls are introduced, and neither users nor administrators need to act. This is a security and accessibility behavior change, not a new admin feature to configure.

For Entra administrators

Existing Passkeys (FIDO2) configurations and registration campaigns are subject to the stated regional migration. Windows passkeys are controlled through Authentication Methods policies and Conditional Access; the notice says no action is needed unless blocking is desired. The My Sign-Ins passwordless password-change capability remains off until an administrator activates it, while the SSPR CAPTCHA replacement requires no user or administrator action. The DLP rollout is cross-product, affecting Purview, Entra, and Defender administrators, but the supplied notice gives no specific configuration task. For External ID, the evidence establishes the affected user populations and planned passkey timing, not a retirement date or migration procedure. Learn updates are mostly documentation: the GSA

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

8

Access Token Claims Reference

Updated

| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |

25 July 2026

Use Scim To Provision Users And Groups

Updated

|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|

25 July 2026

Company Branding Css Template

Updated

Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.

22 July 2026

(Update)Microsoft Entra ID: General Availability of passkey profiles and migration for existing Passkeys (FIDO2) tenants

New

Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.

20 July 2026
Message CenterMC1221452 on mc.merill.net ↗Major updatePlan for change
3

V2 Howto App Gallery Listing

Updated

- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)

25 July 2026
2
1

General Availability: Microsoft Entra passkeys on Windows

New

Microsoft Entra passkeys on Windows will be generally available from late April 2026, enabling phishing-resistant, passwordless sign-in on Windows devices without explicit opt-in. This supports corporate, personal, and shared devices, with admin controls via Authentication Methods policies and Conditional Access. No action is needed unless blocking is desired.

20 July 2026
Message CenterMC1282568 on mc.merill.net ↗Stay informed
1

Agent Owners Sponsors Managers

Updated

In Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.

22 July 2026
1

Microsoft Purview | Data Loss Prevention - Extend Purview data security to the network layer via Entra GSA integration

New

Microsoft Purview extends data loss prevention to the network layer via integration with Entra Internet Access, enabling inspection and protection of sensitive data in AI interactions and cloud services. It supports policy enforcement, alerts, and auditing, with rollout from July to October 2026, affecting Purview, Entra, and Defender administrators.

20 July 2026
Message CenterMC1419797 on mc.merill.net ↗Major updatePlan for change
1

Gsa Poc Internet Access

Updated

1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).

22 July 2026
1

Sms Voice Retirement

Updated

Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.

22 July 2026
1
1

Workload Identity Federation

Updated

- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.

24 July 2026
2

Global Secure Access egress IP ranges

New

Reference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.

24 July 2026

Configure Web Content Filtering

Updated

Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:

22 July 2026
1

Universal Tenant Restrictions

Updated

- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.

22 July 2026
1

Configure Per App Access

Updated

Replace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).

24 July 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…