← Previous day

Next day →
Day in brief

MemberOf support ends 3 November 2026 as Entra expands first-method passkey registration

7 August is mostly a documentation-maintenance day: provisioning pages converge on the Scoping filters wizard and current Attribute Mapping, Advanced Options, and Edit schema labels. The consequential exceptions are a revised ID Governance retirement date, two MFA behavior notices, and new preview-oriented security guidance. Agent ID pages also replace earlier licensing wording with an Agent 365 requirement; that is licensing guidance, not evidence of a separate launch.

  • Updated ID Governance guidance moves the end date from 27 October to 3 November 2026. Policies that still use the operator will be quarantined and stop processing assignments after the cutoff, making this a retirement deadline rather than a terminology edit.

  • A Microsoft 365 Message Center notice says users can register passkeys or passwordless sign-in as their first multifactor authentication method, removing the former weaker-method-first requirement. Rollout is phased from January 2026 through November 2027; the supplied notice specifies no administrator configuration action.

  • Message Center says Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are required, but onboarding and documentation should be updated.

  • A new how-to article—not a launch announcement—describes using the Global Secure Access MCP firewall to inspect, audit, and allow or block supported Model Context Protocol traffic by server, primitive, method, and protocol version. The documented prerequisites include Global Secure Access and Conditional Access Administrator roles, an Internet Access license, a joined device with the Global Secure Access client, and TLS inspection; the firewall is in preview.

  • A new Entra deployment guide covers enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Scope is limited to listed apps, platforms, browsers, and device configurations; the guide requires Entra ID P1 and additional Windows or macOS device setup, and recommends report-only mode followed by a pilot before enforcement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

33 updates

15

Provision Custom Security Attributes

Updated

The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.

Sap Successfactors Integration Reference

Updated

The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.

Customize Application Attributes

Updated

The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.

Export Import Provisioning Configuration

Updated

The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.

Expression Builder

Updated

The documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.

Inbound Provisioning Api Custom Attributes

Updated

The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.

Inbound Provisioning Api Faqs

Updated

The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.

On Premises Ldap Connector Linux

Updated

The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.

On Premises Powershell Connector

Updated

The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”

On Premises Web Services Connector

Updated

The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.

Plan Cloud Hr Provision

Updated

The guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.

Workday Retrieve Pronoun Information

Updated

The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.

4

Import ADSyncTools module

Updated

The documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.

Import ADSyncTools module

Updated

The existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.

Whats New

Updated

The August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.

Provide the user's identity.

Updated

The documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.

3

Token Protection deployment guide - Web apps (Preview)

New

Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.

1

Howto Arc Sign In Windows

Updated

The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.

1

Token Protection

Updated

The Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.

2

Howto Target Agent Identities

Updated

The documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.

Howto Target Agent Identities

Updated

The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.

1

Licensing Agent Id

Updated

The documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.

2

Licensing Conditional Access

Updated

The documentation now lists two supported licensing options: Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.

Licensing Conditional Access

Updated

The documentation now states that Conditional Access for agents requires a Microsoft Agent 365 license to apply policies through Microsoft Entra Agent ID, replacing “Starting soon.”

1
2

Configure cross-tenant synchronization

Updated

The guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…