Provision Custom Security Attributes
Doc updateThe documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.
Daily.Entra.NewsThe week’s most consequential changes are deadline-driven: Microsoft Entra ID will retire the MemberOf rule operator on November 3, 2026; SMS and voice MFA guidance sets a September 1, 2026 passkey transition and a February 1, 2027 service cutoff for tenants without a customer-managed telecom provider; and SSPR will require explicitly registered methods from November 9, 2026, following a registration campaign beginning October 5. Two new security guides cover capabilities that remain in preview: the Global Secure Access MCP firewall and web-app Token Protection. Most other activity clarified provisioning navigation, labels, and terminology rather than introducing product behavior changes.
Microsoft Entra ID will retire the MemberOf rule operator on November 3, 2026. Rules in dynamic groups, administrative units, and entitlement policies must be replaced to avoid stale access, licensing, and policy-enforcement outcomes.
Updated Entra authentication guidance says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to the public cloud and excludes Azure AD B2C and Entra External ID.
Starting November 9, 2026, self-service password reset verification will require explicitly registered authentication methods; directory-sourced contact information will not qualify unless it is registered. A user registration campaign begins October 5, 2026.
A new how-to covers configuring the Global Secure Access MCP firewall to inspect, audit, and allow or block supported Model Context Protocol traffic. Controls include MCP servers, primitives, methods, and protocol versions. The firewall is currently in preview and requires the documented roles, Internet Access license, joined device, client, and TLS inspection setup.
A new deployment guide explains Conditional Access Token Protection for supported browser-based applications accessing Azure Resource Manager. Web-app support is limited to listed applications, platforms, browsers, and device configurations and is explicitly in preview; Microsoft Entra ID P1 and additional Windows or macOS device setup are required.
Inventory and replace MemberOf rules before the November deadline, including rules used by dynamic groups, administrative units, and entitlement policies. Review users relying on SMS or voice MFA and plan migration, the documented temporary opt-out, or a customer-managed provider; also prepare users for the SSPR registration campaign and its November enforcement date. Preview evaluations require the documented Global Secure Access roles, Internet Access license, joined device, and TLS inspection for the MCP firewall, while Token Protection guidance calls for Microsoft Entra ID P1, supported device setup, report-only mode, and a pilot group. For the many provisioning updates, revise runbooks to match the new portal paths and labels rather than infer a feature migration.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.
The documentation replaces the former Mappings-based steps with a Scoping filters wizard covering assignment-based and attribute-based filtering for users and groups. Existing operator details and limitations remain documented.
The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.
The article now directs administrators to Manage > Attribute Mapping, with mappings organized by Users and Groups. It documents row-level edit and delete controls, group sync via Scoping filters, and the Advanced Options menu for custom attributes.
The documentation now says to open Expression Builder from the left navigation menu instead of Attribute Mapping > Advanced Options. The page date was also updated from March 4, 2025, to August 6, 2026, and the access screenshot was removed.
The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.
The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.
The documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.
The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.
The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.
The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.
The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”
The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.
The guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.
The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.
The article now explains viewing and downloading provisioning logs through the admin center, Microsoft Graph, and Microsoft MCP Server for Enterprise. The MCP integration supports natural-language, read-only analysis through delegated permissions and is currently limited to the global service.
The documentation now explains how to create custom task extensions and extensibility workflows through Microsoft Graph, including required permissions and example requests and responses. The workflow example is labeled Preview.
The application attribute customization article now links to guidance on extending attribute mappings with LCW extensibility workflows.
The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.
The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.
The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.
A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.
The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.
The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.
Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.
The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.
The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.
The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.
The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.
Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.
Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.
The page title capitalization and image alt text were revised. No configuration or product behavior changes are shown.
The reference now links to license management in the Azure portal, updates the table as of August 3, 2026, adds Agent 365, and revises service and plan identifier entries.
The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.
The July row now includes an additional 99.999% value in the performance table; no product change is indicated.
The documentation now uses clearer commands to enable and verify `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled`, and explicitly shows how to set it back to `$false` after remediation to re-enable hard match protection.
The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.
The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.
The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.
The documentation now lists two supported licensing options: Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.
The documentation now states that Conditional Access for agents requires a Microsoft Agent 365 license to apply policies through Microsoft Entra Agent ID, replacing “Starting soon.”
The documentation now states that support for the `memberOf` rule operator ends November 3, 2026, replacing October 27, 2026. Policies using it will be quarantined and stop processing assignments from that date.
The documentation states that, starting October 27, 2026, automatic assignment policies using memberOf will be quarantined. Assignment processing will stop, and no assignments will be added or removed until memberOf is removed.
The guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.
The documentation now directs administrators to Entra ID > Cross-tenant Synchronization > Configurations, removing the External Identities step.
The article now describes traffic forwarding through the Global Secure Access client and remote networks, six policies instead of three, Microsoft Traffic Bypass, Custom Acquire, and Agentic Acquire. It also expands Custom Bypass configuration steps to cover destination types, ports, and protocols.
GitHub Actions now supports immutable OIDC subject formats with repository and owner IDs to enhance Microsoft Entra federated identity security. Organizations using GitHub Actions OIDC must migrate to this format by late July 2026 to prevent token mismatches and reduce unauthorized access risks.
The documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.
Microsoft added a how-to article for configuring the Global Secure Access MCP firewall to inspect, audit, and allow or block Model Context Protocol traffic. It covers server, primitive, method, and protocol-version controls for supported MCP traffic.