Week in brief

MemberOf retirement and MFA deadlines reshape Entra access administration

The week’s most consequential changes are deadline-driven: Microsoft Entra ID will retire the MemberOf rule operator on November 3, 2026; SMS and voice MFA guidance sets a September 1, 2026 passkey transition and a February 1, 2027 service cutoff for tenants without a customer-managed telecom provider; and SSPR will require explicitly registered methods from November 9, 2026, following a registration campaign beginning October 5. Two new security guides cover capabilities that remain in preview: the Global Secure Access MCP firewall and web-app Token Protection. Most other activity clarified provisioning navigation, labels, and terminology rather than introducing product behavior changes.

  • Microsoft Entra ID will retire the MemberOf rule operator on November 3, 2026. Rules in dynamic groups, administrative units, and entitlement policies must be replaced to avoid stale access, licensing, and policy-enforcement outcomes.

  • Updated Entra authentication guidance says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to the public cloud and excludes Azure AD B2C and Entra External ID.

  • Starting November 9, 2026, self-service password reset verification will require explicitly registered authentication methods; directory-sourced contact information will not qualify unless it is registered. A user registration campaign begins October 5, 2026.

  • A new how-to covers configuring the Global Secure Access MCP firewall to inspect, audit, and allow or block supported Model Context Protocol traffic. Controls include MCP servers, primitives, methods, and protocol versions. The firewall is currently in preview and requires the documented roles, Internet Access license, joined device, client, and TLS inspection setup.

  • A new deployment guide explains Conditional Access Token Protection for supported browser-based applications accessing Azure Resource Manager. Web-app support is limited to listed applications, platforms, browsers, and device configurations and is explicitly in preview; Microsoft Entra ID P1 and additional Windows or macOS device setup are required.

For Entra administrators

Inventory and replace MemberOf rules before the November deadline, including rules used by dynamic groups, administrative units, and entitlement policies. Review users relying on SMS or voice MFA and plan migration, the documented temporary opt-out, or a customer-managed provider; also prepare users for the SSPR registration campaign and its November enforcement date. Preview evaluations require the documented Global Secure Access roles, Internet Access license, joined device, and TLS inspection for the MCP firewall, while Token Protection guidance calls for Microsoft Entra ID P1, supported device setup, report-only mode, and a pilot group. For the many provisioning updates, revise runbooks to match the new portal paths and labels rather than infer a feature migration.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

18

Provision Custom Security Attributes

Doc update

The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.

7 August 2026

Sap Successfactors Integration Reference

Doc update

The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.

7 August 2026

Customize Application Attributes

Doc update

The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.

7 August 2026

Export Import Provisioning Configuration

Doc update

The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.

7 August 2026

Expression Builder

Doc update

The documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.

7 August 2026

Inbound Provisioning Api Custom Attributes

Doc update

The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.

7 August 2026

Inbound Provisioning Api Faqs

Doc update

The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.

7 August 2026

On Premises Ldap Connector Linux

Doc update

The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.

7 August 2026

On Premises Powershell Connector

Doc update

The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”

7 August 2026

On Premises Web Services Connector

Doc update

The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.

7 August 2026

Plan Cloud Hr Provision

Doc update

The guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.

7 August 2026

Workday Retrieve Pronoun Information

Doc update

The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.

7 August 2026

How to analyze the Microsoft Entra provisioning logs

Public preview

The article now explains viewing and downloading provisioning logs through the admin center, Microsoft Graph, and Microsoft MCP Server for Enterprise. The MCP integration supports natural-language, read-only analysis through delegated permissions and is currently limited to the global service.

5 August 2026

Extend Application Attributes

Doc update

The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.

4 August 2026

Customize Application Attributes

Doc update

The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.

4 August 2026
7

Managed Policies

Doc update

The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.

8 August 2026

Howto Arc Sign In Windows

Doc update

The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.

7 August 2026

Choose a telephony provider for SMS and voice authentication

Doc update

The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.

6 August 2026

Choose a telephony provider for SMS and voice authentication

Doc update

A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.

5 August 2026

Howto Sspr Authenticationdata

Doc update

The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.

5 August 2026

Sms Voice Retirement

Retirement

The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.

4 August 2026

Microsoft Entra ID SSPR will require registered authentication methods starting November 9, 2026

New

Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.

4 August 2026
Message CenterMC1325414 on mc.merill.net ↗Major updatePlan for change
4

Import ADSyncTools module

Doc update

The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.

7 August 2026

Import ADSyncTools module

Doc update

The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.

7 August 2026

Whats New

Doc update

The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.

7 August 2026

Provide the user's identity.

Doc update

The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.

7 August 2026
2

Token Protection deployment guide - Web apps (Preview)

Doc update

Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.

7 August 2026

Microsoft Entra ID: Replace MemberOf rules by November 3, 2026

New

Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.

5 August 2026
Message CenterMC1448379 on mc.merill.net ↗Major updatePlan for change
2
1

Token Protection

Doc update

The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.

7 August 2026
1

Sla Performance

Doc update

The July row now includes an additional 99.999% value in the performance table; no product change is indicated.

8 August 2026
1

Connect to Microsoft Graph.

Doc update

The documentation now uses clearer commands to enable and verify `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`, and explicitly shows how to set it back to `$false` after remediation to re-enable hard match protection.

9 August 2026
2

Howto Target Agent Identities

Doc update

The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.

7 August 2026

Howto Target Agent Identities

Doc update

The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.

7 August 2026
1

Licensing Agent Id

Doc update

The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.

7 August 2026
2

Licensing Conditional Access

Doc update

The documentation now lists two supported licensing options: Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.

7 August 2026

Licensing Conditional Access

Doc update

The documentation now states that Conditional Access for agents requires a Microsoft Agent 365 license to apply policies through Microsoft Entra Agent ID, replacing “Starting soon.”

7 August 2026
2
2

Configure cross-tenant synchronization

Doc update

The guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.

7 August 2026
1

How to manage the Internet Access profile

Doc update

The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.

3 August 2026
1
1

Network Content Filtering

Doc update

The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.

5 August 2026
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…