A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.
Urgent Entra cleanup: MemberOf retires by 3 November 2026, while GitHub Actions OIDC migration is already overdue
The significant work on 5 August is deadline-driven rather than a broad feature launch. Entra ID is retiring MemberOf rules, with a specific ID Governance failure mode arriving earlier for automatic assignment policies; Workload ID's GitHub Actions OIDC migration deadline was late July. Separately, SSPR rollout milestones moved, and a new telephony-provider article describes future planning only. Other edits were lower-impact documentation clarification: Global Secure Access clarified Agent/User source classification for a still-preview condition, provisioning documentation described read-only MCP log analysis, and a consent page changed only capitalization and alt text.
- MemberOf rule operator retirement sets a 3 November 2026 remediation deadline
Entra ID · Conditional Access
Microsoft Entra ID will retire the MemberOf rule operator in dynamic groups, administrative units, and entitlement policies. Administrators should identify and replace affected rules before the deadline to avoid stale access, licensing, and policy-enforcement results.
- Entitlement Management will quarantine automatic-assignment policies that still use MemberOf
ID Governance · Governance
Starting 27 October 2026, automatic assignment policies using MemberOf will be quarantined: assignment processing will stop, and no assignments will be added or removed until MemberOf is removed. The updated guidance points administrators to a PowerShell discovery script and replacement rules using a supported attribute-based operator or an alternative assignment method.
- GitHub Actions OIDC subjects must move to immutable repository and owner IDs
Workload ID · Authentication
The Workload ID message says GitHub Actions now supports immutable OIDC subject formats containing repository and owner IDs. Organizations using GitHub Actions federated identity credentials were told to migrate by late July 2026; because that date has passed, affected deployments should be checked promptly to avoid token mismatches and reduce unauthorized-access risk.
- SSPR authentication-data rollout milestones moved later
Entra ID · Authentication
The Entra ID documentation now lists 9 November 2026 instead of 6 August for the registration campaign, and 5 October instead of 7 September for accepting only explicitly registered methods. This is a schedule update, so administrators should revise rollout plans and user communications rather than infer a new authentication capability.
- Customer-managed SMS and voice providers are planned, not yet available
Entra ID · Authentication
A new concept article describes planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning 18 September 2026 and configuration beginning 30 October, but providers cannot be configured yet. Administrators can use the interim period to identify affected users, evaluate requirements, and plan a limited pilot and fallback method; Microsoft recommends phishing-resistant methods such as passkeys where possible.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
8 updates
Microsoft Entra ID
5 updatesThe documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.
Microsoft Entra ID will retire the MemberOf rule operator by November 3, 2026. Organizations using MemberOf in dynamic groups, administrative units, or entitlement policies must replace these rules to avoid stale access, licensing, and policy enforcement issues. Review and update configurations before the deadline.
The page title capitalization and image alt text were revised. No configuration or product behavior changes are shown.
The article now explains viewing and downloading provisioning logs through the admin center, Microsoft Graph, and Microsoft MCP Server for Enterprise. The MCP integration supports natural-language, read-only analysis through delegated permissions and is currently limited to the global service.
Microsoft Entra ID Governance
1 updateThe documentation states that, starting October 27, 2026, automatic assignment policies using memberOf will be quarantined. Assignment processing will stop, and no assignments will be added or removed until memberOf is removed.
Microsoft Entra Workload ID
1 updateGitHub Actions now supports immutable OIDC subject formats with repository and owner IDs to enhance Microsoft Entra federated identity security. Organizations using GitHub Actions OIDC must migrate to this format by late July 2026 to prevent token mismatches and reduce unauthorized access risks.
Network Content Filtering
UpdatedThe documentation now states that **Agent** matches traffic classified as AI agent traffic, while traffic not classified as agent traffic is treated as **User** traffic. If the condition is omitted, the rule applies to all traffic. The condition remains in preview.
