Week in brief

SMS first-factor sign-in retires for Entra ID Free tenants on August 11

The week’s biggest administrator deadline was Microsoft’s August 11 retirement of SMS first-factor sign-in for Entra ID Free tenants; SMS used for multifactor authentication remains available. Microsoft also announced first-method passkey and passwordless registration rolling out from October 2026 through February 2027, a September 11 general-availability target for Dynamics 365 Commerce on-behalf-of ordering with Microsoft Entra External ID, and new Global Secure Access V2 migration guidance. Token Protection’s browser-based support is documented as Preview; much of the remaining activity, especially across Agent ID, was terminology, sample, and procedural clarification rather than a launch.

  • A Message Center notice says Microsoft will retire SMS first-factor sign-in for Entra ID Free tenants on August 11, 2026, because of fraud risks. Users must switch to another authentication method, while SMS as a multifactor method remains unaffected. This is a security-driven retirement, not a documentation clarification.

  • Microsoft announced that users can register a passkey or passwordless sign-in as their first multifactor authentication method instead of setting up a weaker method first. The change rolls out from October 2026 through February 2027, and the notice says no administrator action is required.

  • A new how-to article describes the guided migration experience, including eligible and ineligible security profiles and the conversion of V1 policies into rules within one enabled V2 policy while preserving destinations, actions, and priorities. Profiles that already contain V2 policies require manual handling, and administrators should review changed evaluation behavior across multiple security profiles. This is migration documentation, not evidence of a separate product launch.

  • The updated Token Protection page documents Preview support for selected browser-based web apps accessing Azure Resource Manager on Windows and macOS. Browser use on iOS and iPadOS is unsupported; administrators must review the supported browsers, extensions, operating systems, configurations, deployment guidance, and the Windows Azure Service Management API resource used for Conditional Access enforcement.

  • Microsoft announced that on-behalf-of ordering can be enabled for Microsoft Entra External ID in Dynamics 365 Commerce, with general availability scheduled for September 11, 2026. The announcement does not specify additional administrator action.

For Entra administrators

Prioritize Free-tenant users still relying on SMS first-factor sign-in and move them to another authentication method; do not confuse this retirement with SMS MFA. The passkey-first registration rollout requires no administrator action according to the notice. For Global Secure Access, check security-profile eligibility, use the Global Secure Access Administrator role, review changed V2 evaluation behavior, and manually handle profiles that already contain V2 policies. Administrators evaluating browser-based Token Protection should verify the documented browser, extension, operating-system, and Conditional Access requirements. The External ID notice provides a GA date but no additional required action.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

8

Policy Guests Mfa Strength

Doc update

The guidance now states that authentication strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts, alongside the previously listed methods. It directs administrators to use the MFA grant control instead.

15 August 2026

Authentication with Microsoft Entra ID Auth SDK (sidecar)

Doc update

The documentation now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” and expands “SPA” to “single-page application.” The described authentication flows and responsibilities are otherwise unchanged in the supplied diff.

14 August 2026

Microsoft Entra Connect: Cloud authentication via Staged Rollout

Doc update

The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.

12 August 2026
6

Howto Analyze Provisioning Logs

Doc update

The article’s Microsoft MCP Server for Enterprise overview and setup links changed from Microsoft Learn paths to the EnterpriseMCP GitHub repository. The article continues to describe the service as preview, global-service-only, and read-only.

12 August 2026

Zscaler Zidentity Provisioning Tutorial

Doc update

The tutorial now documents entering a Tenant URL, Client identifier, Client secret, and OAuth token endpoint, and includes a list of SCIM user attributes and data types.

12 August 2026

Account Discovery

Doc update

The account discovery documentation now links to the Microsoft MCP Server for Enterprise GitHub repository instead of Microsoft Learn pages for investigating reports and provisioning an MCP client.

12 August 2026
2

Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

New

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.

11 August 2026
Message CenterMC1450133 on mc.merill.net ↗Stay informed

Token Protection

Doc update

The token protection article removes a screenshot of a Conditional Access policy requiring token protection as a session control. The Primary Refresh Token link remains.

10 August 2026
2

Concepts Replica Sets

Doc update

The documentation now states that replica sets require connectivity between all virtual networks hosting them. They are deployed in one Active Directory site and rely on a fully meshed virtual network topology for directory replication.

14 August 2026

Token Protection

Doc update

The page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. iOS/iPadOS browser support is not supported. The page also adds requirements for supported browsers, extensions, operating systems, and configurations.

10 August 2026
1

Manage rules for dynamic membership groups in Microsoft Entra ID

Doc update

The article now explains that agent user accounts are evaluated by user-based membership rules and can join dynamic user groups. By default, they are not distinguished from other user identities; rules can explicitly exclude or include them, including accounts tied to a specific agent identity blueprint.

14 August 2026
1

Discover identities in target applications with account discovery

Doc update

The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.

11 August 2026
1

Optional Claims

Doc update

The documentation now explains how to configure granular AMR values for SAML applications through the manifest or Microsoft Graph, since the admin center has no UI option for `include_granular_amr`. It also documents adding the `amr` claim to OIDC token types and clarifies that `include_granular_amr` applies only to SAML.

12 August 2026
1

Orgvue Tutorial

Doc update

The tutorial replaces the Orgvue authentication and SAML callback URLs with orgvue-staging URLs and changes the Sign-on URL to include the application login path and domain parameter. It also clarifies that both Reply URL and Sign-on URL values are placeholders.

10 August 2026
14

Create Delete Agent Identities

Doc update

The documentation updates the C# sample’s imports, endpoint structure, downstream API call, and model declarations to provide valid create-agent-identity code.

14 August 2026

Call Api Microsoft Graph

Doc update

The documentation adds Microsoft Graph and Microsoft.Identity.Web imports, changes sample calls from Applications to Users, and clarifies that configured scopes must match the Graph resources used. Examples use User.Read and User.ReadBasic.All.

14 August 2026

Call Api Custom

Doc update

The documentation updates its C# examples, including distinct method names for UPN and object ID calls, a revised controller constructor signature, and clearer user-data method names.

14 August 2026

Microsoft Entra Sdk For Agent Identities

Doc update

The documentation now identifies app-only tokens as using client credentials, expands on-behalf-of to OBO, and consistently uses the `agent-identity-client-id` placeholder in request examples.

14 August 2026

Secure an Amazon Bedrock agent with Microsoft Entra Agent ID

Doc update

The Amazon Bedrock integration guide now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” in its description, explanations, container reference, and links. No behavior or availability change is described.

14 August 2026

Call Api Microsoft Graph

Doc update

The documentation adds an OpenID Connect using directive and renames two C# sample variables: `applications` to `applicationsForUser` and `me` to `meByOid`.

14 August 2026

Call Api Microsoft Graph

Doc update

The Agent ID Microsoft Graph documentation now labels sample variables as `usersAppOnly` and `usersOnBehalfOfUser`, clarifying the scenarios they represent.

14 August 2026

Microsoft Entra Sdk For Agent Identities

Doc update

The documentation replaces “Entra ID Auth SDK” with “Microsoft Entra ID Auth SDK” in two descriptions. The endpoint formats and behavior are unchanged.

14 August 2026

Agent Tokens

Doc update

The user delegation section now spells out “on-behalf-of (OBO)” on first use. No feature behavior or requirements changed in the supplied diff.

14 August 2026

Call Api Azure Services

Doc update

The code sample now uses `<your-tenant-id>` instead of `<your-tenant>` for the `TenantId` value.

14 August 2026

Call Api Custom

Doc update

The documentation now spells out “on-behalf-of (OBO)” on first use in the token scenario guidance. The referenced method is unchanged.

14 August 2026

Call Api Microsoft Graph

Doc update

The `TenantId` example value changed from `<my-test-tenant>` to `<your-tenant-id>` for clearer documentation.

14 August 2026

Configure Third Party Agents

Doc update

The third-party agents documentation now labels the sidecar setup link “Configure Microsoft Entra ID Auth SDK for agent identities” instead of “Configure Entra ID Auth SDK.”

14 August 2026

Grant Agent Access Microsoft 365

Doc update

The documentation now lists how an agent with its own identity can communicate through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, including the permissions required for inbound and outbound communication.

13 August 2026
10

Authentication protocols in agents

Doc update

The page description was shortened by removing the phrase “Key concepts.” The documented OAuth 2.0 protocols and token exchange patterns remain unchanged.

14 August 2026

Error Codes

Doc update

The error-code documentation now separates quota, blueprint, blueprint principal, agent identity, and agent identity creation errors, with clearer descriptions and table headings.

14 August 2026

Get the service principal for Microsoft Graph

Doc update

The documentation replaces inconsistent tenant placeholders with `<your-tenant-id>` and standardizes `<agent-blueprint-clientid>` to `<agent-blueprint-client-id>` in code samples.

14 August 2026

What Is Microsoft Entra Agent Id

Doc update

The page updates image accessibility text, refines wording about agent identities, and standardizes the name “Microsoft Entra ID Auth SDK (sidecar)” for third-party agent integrations.

14 August 2026

Validate agent identity tokens in a downstream API

Doc update

The documentation now refers to the “Microsoft Entra ID Auth SDK (sidecar)” instead of the “Microsoft Entra SDK auth sidecar.” The token-validation guidance is otherwise unchanged.

14 August 2026

Agent Token Claims

Doc update

The Agent ID token claims documentation no longer includes one `tid` claim table row.

14 August 2026
4

Security For Ai Overview

Doc update

The documentation now expands MCP, A2A, and OBO on first use to improve clarity and retrievability.

14 August 2026

Key Concepts

Doc update

The key concepts page now labels the link “Microsoft Entra Agent ID OAuth protocols” instead of “oauth protocols.”

14 August 2026

Inheritable Permissions

Doc update

The page no longer includes a TODO questioning support for enumerated scopes versus `allAllowed`/`none`. The diff provides no evidence of a product or feature change.

14 August 2026
4

Integrate Aws Bedrock Agent

Doc update

The documentation now spells out “on-behalf-of” before introducing the OBO acronym in the OAuth 2.0 authentication description.

14 August 2026

Create Delete Agent Identities

Doc update

The documentation now uses `<your-tenant-id>` instead of `<my-test-tenant>` in the token endpoint and `TenantId` code examples.

14 August 2026

Manage agents in end user experience

Doc update

The page’s `ms.topic` metadata was changed from `how-to #Required; leave this attribute/value as-is` to `how-to`. The topic classification remains unchanged.

14 August 2026

Howto Delete Agent Identity

Doc update

The delete-agent-identity article no longer contains a TODO asking engineering to confirm whether cascade cleanup removes associated agent user accounts.

14 August 2026
3

Best Practices Agent Id

Doc update

The best-practices documentation now uses the full “Microsoft Entra Agent ID” and “Microsoft Entra ID” names in two recommendations. The guidance itself is unchanged.

14 August 2026

Integrate N8n Agent

Doc update

The n8n integration page now consistently calls the pattern “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK.”

14 August 2026

What Is Agent Id Platform

Doc update

The page’s bullet describing platforms and services that create agents retains the same wording and examples, including Copilot Studio, AWS Bedrock, and n8n. No substantive content change is shown.

14 August 2026
3

Best Practices Agent Id

Doc update

The documentation now recommends creating agent identities from an agent identity blueprint instead of using standard app registrations or service principals. It also adds .NET usage guidance and lists required roles and permission.

14 August 2026

Call Api Azure Services

Doc update

The documentation updates its C# examples, separating app-only, on-behalf-of-user, and user-identification scenarios. Samples now configure agent identity options and pass the credential to the Blob client correctly.

14 August 2026

Integrate Aws Bedrock Agent

Doc update

The guide updates “Entra” to “Microsoft Entra” in the diagram alt text, setup heading, and TENANT_ID descriptions. No technical procedure or feature change is shown.

14 August 2026
2

Plan Agent Identity Architecture

Doc update

The agent identity architecture planning page now links to the correct interactive agent authentication article instead of the previous broken path.

14 August 2026

Plan Agent Identity Architecture

Doc update

The documentation now explains that agents should use an agent identity blueprint and the `#Microsoft.Graph.AgentIdentity` object, rather than standard app-registration APIs. It also lists supported creation channels, roles, permissions, and .NET usage.

14 August 2026
2

Agent On Behalf Of Oauth Flow

Doc update

The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.

11 August 2026

Agent On Behalf Of Oauth Flow

Doc update

The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.

11 August 2026
1

Whats New Agent Id

Doc update

The Agent ID documentation now refers to the linked SDK as the “Microsoft Entra ID Auth SDK” instead of “Entra ID Auth SDK.”

14 August 2026
4

Identity Protection Policies

Doc update

The documentation now states that disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens.

15 August 2026

Identity Protection Policies

Doc update

The documentation replaces “Device disablement” with “Attacker-added device” and explains that the Entra device object is disabled, new token issuance is blocked, existing device-bound refresh tokens are revoked, and user sessions are revoked.

14 August 2026

Identity Protection Policies

Doc update

The documentation now describes a Device disablement response for users flagged by Microsoft threat intelligence as having an attacker-added device. The device is disabled, and the user is prompted to sign in from a trusted device.

14 August 2026

Connect Staged Rollout

Doc update

The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” No procedural content changed in the supplied diff.

12 August 2026
9

Entitlement Management Access Package Request Policy

Doc update

The documentation now expands its guidance that administrators must verify users meet existing access package policy requirements before assigning them; otherwise, assignment may fail.

14 August 2026

Entitlement Management Access Package Request Policy

Doc update

The documentation removes an inaccurate statement implying that direct assignment to an access package requires approval. It now states only that assigned users must meet the policy’s eligibility requirements.

14 August 2026

Entitlement Management Access Package Assignments

Doc update

The access package assignments page no longer includes a note stating that assignment managers cannot bypass required approval settings or directly assign identities without approval.

14 August 2026

Entitlement Management Delegate

Doc update

The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.

14 August 2026

Catalog Access Reviews

Generally available

The documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.

13 August 2026

Catalog Access Reviews

Doc update

The page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.

13 August 2026

Licensing Governance

Doc update

The governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.

13 August 2026
2

Allow Deny List

Doc update

The guidance now includes an approximate domain-count example and reiterates that capacity depends on domain length within the 25 KB (25,000-character) policy limit.

14 August 2026
1

Web filtering in Global Secure Access (V2)

Doc update

A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.

12 August 2026
1

Custom Proxy File Hosting

Doc update

The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.

11 August 2026
2

Federate a SPIFFE/SPIRE workload identity

Doc update

Adds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.

13 August 2026

Federate a Google Cloud workload identity

Doc update

Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.

13 August 2026
2
1

Workload Identity Federation

Doc update

The concept page now points to first-party tutorials for Google Cloud and SPIFFE/SPIRE scenarios instead of the previous links. No product feature change is indicated.

13 August 2026
3

Migrate web content filtering policies from V1 to V2

Doc update

A new how-to article explains the guided Global Secure Access migration experience. It covers eligible and ineligible security profiles, migration steps, policy and rule naming, and how V1 policies become rules in a single enabled V2 policy while preserving destinations, actions, and priorities.

15 August 2026

Manage Microsoft Profile

Doc update

The instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”

13 August 2026

Manage Microsoft Profile

Doc update

The step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.

13 August 2026
1

Web Filtering

Doc update

The web filtering documentation now links to an article explaining how to migrate web content filtering policies from V1 to V2.

15 August 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…