Microsoft Entra ID
Authentication

Microsoft Entra Connect: Cloud authentication via Staged Rollout

In brief

The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.

What Entra admins need to know

Administrators should account for an additional federated or Microsoft Entra sign-in when troubleshooting authentication changes during Staged Rollout transitions.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

title: 'Microsoft Entra Connect: Cloud authentication via Staged Rollout' description: This article explains how to migrate from federated authentication, to cloud authentication, by using a Staged Rollout. ms.topic: how-to ms.date: 07/22/08/11/2026 ai-usage: ai-assisted ms.subservice: hybrid-connect ms.custom: sfi-image-nochange

Editing a group (adding or removing users), it can take up to 24 hours for changes to take effect. Seamless SSO will apply only if users are in the Seamless SSO group and also in either a PTA or PHS group.

User Authentication Behavior Duringauthentication behavior during Staged Rollout Transitionstransitions

Scenarios that require an additional federated or managed sign-in

  1. User added to Staged Rollout.When a user is added to a Staged Rollout (SR) groupgroup, or when a group they belong to is added to SR, theirenabled for Staged Rollout, the authentication method will transitionexperience doesn't switch from federated to managed. This change takes effect after themanaged immediately. The user completesmust complete one moreadditional interactive sign-in using their existing federated login.authentication method. After this sign-in, Microsoft Entra updates the user's state and applies the managed authentication experience for subsequent logins.sign-ins.

  2. Similarly, whenUser removed from Staged Rollout. When a user is removed from the SR groupa Staged Rollout group, or when their group is removed from SR, they will continueStaged Rollout, the user continues to use managed authentication until theyauthentication. The user must complete one moreadditional interactive sign-in.in through Microsoft Entra. After that, federation is re-appliedthis sign-in, Microsoft Entra switches the user back to federated authentication, and future logins willsubsequent sign-ins redirect to the federated identity provider.

  3. This behavior ensuresMicrosoft Entra ID Protection remediation events. Certain account recovery and Microsoft Entra ID Protection remediation actions, including self-service password reset (SSPR), risk remediation, and risk dismissal, can reset the user's Staged Rollout state. As a seamless transition betweenresult, the user might be redirected to the federated identity provider on their next sign-in. The user must complete one additional interactive sign-in using their existing federated authentication methods while maintaining user access continuity and security.method. After this sign-in, Microsoft Entra reestablishes managed authentication for subsequent sign-ins.

Workaround for newly added Staged Rollout users

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…