| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |
Passkey GA and automatic FIDO2 migration lead the period, with network-layer DLP close behind
Authentication is the period’s main story, but the notices describe a mix of already-dated GA statuses and staged future rollouts rather than one July launch. Entra passkey profiles and synced passkeys are moving to GA for tenants with Passkeys (FIDO2) enabled, with existing configurations migrating through October. Windows passkeys are described as GA from late April, while passwordless password change is scheduled for late October and remains disabled by default. External ID documentation clarifies future SMS and voice retirement scope for B2B and internal guest users. Separately, Microsoft Purview DLP is rolling network-layer inspection and protection through Entra Internet Access (Global Secure Access) from July to October. The remaining Learn work is mostly maintenance or clarification; the new GSA egress-range and Databricks SCIM pages are operational references, not evidence of new service launches.
- Passkey profiles and synced passkeys reach GA with automatic FIDO2-tenant migration
Entra ID · Authentication
The July 21 Message Center major update describes GA beginning in March 2026 for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new `passkeyType` property, while automatic migration and registration-campaign changes roll out regionally through October 2026. Because the schedule is already underway, this is a GA and migration update rather than a new July launch.
- Windows passkeys are GA; passwordless password change is a separate, later admin-enabled capability
Entra ID · Conditional Access
The Windows passkey notice places Entra passkeys on Windows in GA from late April 2026, without explicit opt-in, for corporate, personal, and shared devices. Authentication Methods policies and Conditional Access are the stated admin controls. Separately, passwordless users will be able to change passwords in My Sign-Ins with passkeys or Windows Hello, without the current password or SSPR; that capability is disabled by default, requires admin activation, and is scheduled for global rollout in late October 2026.
- Purview DLP is extending to the network layer through Entra Internet Access
ID Protection · Conditional Access
The major update describes Microsoft Purview DLP integrating with Entra Internet Access (Global Secure Access) to inspect and protect sensitive data at the network layer, including in AI interactions and cloud services. The stated capabilities include policy enforcement, alerts, and auditing, with rollout scheduled from July through October 2026. It explicitly affects Purview, Entra, and Defender administrators, but the supplied summary does not provide additional configuration steps.
- External ID documentation clarifies SMS and voice retirement scope for B2B and internal guests
External ID · Authentication
An updated External ID page says B2B users and internal guest users are included in the retirement scope for Microsoft-provided SMS and voice authentication. It also says passkey support for those users is planned by the end of calendar year 2026. This is a future-scope clarification, not evidence that the retirement or passkey support completed during this period; no migration procedure or retirement date is supplied.
- SSPR is replacing legacy CAPTCHA with backend abuse controls
Entra ID · Authentication
Beginning in early August 2026, Microsoft Entra self-service password reset is scheduled to replace its legacy CAPTCHA with backend throttling and behavior-based abuse detection. The notice says current password-reset functionality remains, no new controls are introduced, and neither users nor administrators need to act. This is a security and accessibility behavior change, not a new admin feature to configure.
Existing Passkeys (FIDO2) configurations and registration campaigns are subject to the stated regional migration. Windows passkeys are controlled through Authentication Methods policies and Conditional Access; the notice says no action is needed unless blocking is desired. The My Sign-Ins passwordless password-change capability remains off until an administrator activates it, while the SSPR CAPTCHA replacement requires no user or administrator action. The DLP rollout is cross-product, affecting Purview, Entra, and Defender administrators, but the supplied notice gives no specific configuration task. For External ID, the evidence establishes the affected user populations and planned passkey timing, not a retirement date or migration procedure. Learn updates are mostly documentation: the GSA
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
14 updates|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|
Microsoft Entra will enable passwordless users to change their passwords via My Sign-Ins using strong credentials like passkeys or Windows Hello, without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally in late October 2026.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.
Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.
V2 Howto App Gallery Listing
Updated- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Azure Databricks using SCIM.
Fortigate Ssl Vpn Tutorial
Updated`https://<FortiGate IP or FQDN address>:<Custom SSL VPN port>/remote/saml/login`.
Salesforce Tutorial
Updated* Manage your accounts in one central location.
Salesforce Sandbox Tutorial
Updated* Manage your accounts in one central location.
Microsoft Entra passkeys on Windows will be generally available from late April 2026, enabling phishing-resistant, passwordless sign-in on Windows devices without explicit opt-in. This supports corporate, personal, and shared devices, with admin controls via Authentication Methods policies and Conditional Access. No action is needed unless blocking is desired.
Microsoft Entra Agent ID
1 updateIn Microsoft Agent ID, the agent's identity, blueprint, and blueprint principal may all have sponsors associated with them. In addition, agents can have an [agent's user account](agent-users.md) created in order to access user-oriented services. While the Entra user has a sponsor relationship, there are differences between the user account sponsors and sponsors of the agent identity, blueprint, or blueprint principal.
Microsoft Entra ID Protection
1 updateMicrosoft Purview extends data loss prevention to the network layer via integration with Entra Internet Access, enabling inspection and protection of sensitive data in AI interactions and cloud services. It supports policy enforcement, alerts, and auditing, with rollout from July to October 2026, affecting Purview, Entra, and Defender administrators.
Microsoft Entra External ID
3 updatesGsa Poc Internet Access
Updated1. [Set up tenant restrictions v2](/azure/active-directory/external-identities/tenant-restrictions-v2). If your organization currently uses tenant restrictions v1, review the [guide for migrating to tenant restrictions v2](https://aka.ms/trv2migration).
Sms Voice Retirement
UpdatedPasskey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
> [!IMPORTANT]
Microsoft Entra Workload ID
1 updateWorkload Identity Federation
Updated- GitHub Actions. First, configure a trust relationship between your [user-assigned managed identity](workload-identity-federation-create-trust-user-assigned-managed-identity.md) or [application](workload-identity-federation-create-trust.md) in Microsoft Entra ID and a GitHub repo in the [Microsoft Entra admin center](https://entra.microsoft.com) or using Microsoft Graph. Then [configure a GitHub Actions workflow](/azure/developer/github/connect-from-azure) to get an access token from Microsoft identity provider and access Azure resources.
Microsoft Entra Global Secure Access
4 updatesReference list of the egress IP ranges that Global Secure Access uses for outbound internet traffic, so you can allowlist them on target services.
Web content filtering also supports two optional rule conditions that enable traffic-aware policy enforcement:
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
Configure Per App Access
UpdatedReplace `{appRegistrationObjectId}` with the application registration's object ID. You can find this value in the Microsoft Entra admin center under **Identity** > **Applications** > **App registrations** by selecting the app registration for your Global Secure Access application and copying the **Object ID** from the **Overview** page. To return to the default behavior, set `trafficRoutingMethod` to `random`. For more information, see [Update application](/graph/api/application-update?view=graph-rest-beta&preserve-view=true).
