Daily summary for changes since August 2nd 2026, 8:12 PM PDT
Report generated on August 3rd 2026, 8:12 PM PDT
Todayβs Entra documentation updates cover MFA retirement planning, Global Secure Access NAT deployments, provisioning integrations and extensibility, Zscaler automation, and licensing references.
A new how-to explains configuring a Global Secure Access remote network when the CPE has a private WAN address behind an upstream NAT router, using IKEv2 NAT Traversal (NAT-T) over UDP 4500. It covers topology, prerequisites, and setup considerations.
Why admins should care: Administrators can use this guidance for supported NAT-based deployments. The CPE must support NAT-T, the upstream router must allow UDP 500 and 4500 traffic, and its public IP should be static.
Microsoft added a tutorial describing how to configure automatic user provisioning and deprovisioning between Microsoft Entra ID and Zscaler Provisioning, including user and group synchronization, prerequisites, SCIM setup, application-gallery configuration, scoping, and attribute mapping.
Why admins should care: Administrators integrating Zscaler can follow the documented steps and prerequisites, including required roles, a Zscaler admin account, app-role assignments, and OAuth client credentials. The documentation does not indicate a new product launch or preview.
The documentation now explains how to use Microsoft Graph Explorer to create custom task extensions and extensibility workflows, including required permissions, sample requests, and responses. The workflow example is labeled Preview.
Why admins should care: Administrators can follow the new API-based procedure to configure these extensions, but must consent to the documented Lifecycle Workflows permissions. This documents an existing capability; it does not indicate a new product launch.
The page now documents the retirement timeline, passkey auto-enablement beginning September 1, 2026, and loss of SMS/voice MFA without a customer-managed telecom provider from February 1, 2027. It also covers costs, SSPR, scope, and a temporary opt-out.
Why admins should care: Administrators should identify affected users, plan passkey or telecom-provider migration, and review the temporary opt-out before September 1, 2026. The documented timeline applies to public cloud tenants; Azure AD B2C and Entra External ID are excluded from this announcement.
The documentation now includes Azure portal licensing management, refreshes product and service-plan identifier entries, adds Agent 365, and states the table was last updated August 3, 2026.
Why admins should care: Administrators using PowerShell or license-management tools should review the updated identifiers and CSV reference when mapping products and service plans.
The application attribute customization documentation now links the LCW extensibility workflow mapping type to a separate article explaining how to extend attribute mappings with these workflows.
Why admins should care: Administrators can use the new link for additional guidance; no product behavior or configuration change is documented.