The documentation now refers to the **Advanced Options** dropdown instead of **Show advanced options**, and directs administrators to **Edit schema** for modifying attribute mappings.
MemberOf support ends 3 November 2026 as Entra expands first-method passkey registration
7 August is mostly a documentation-maintenance day: provisioning pages converge on the Scoping filters wizard and current Attribute Mapping, Advanced Options, and Edit schema labels. The consequential exceptions are a revised ID Governance retirement date, two MFA behavior notices, and new preview-oriented security guidance. Agent ID pages also replace earlier licensing wording with an Agent 365 requirement; that is licensing guidance, not evidence of a separate launch.
- `memberOf` auto-assignment support now ends 3 November 2026
ID Governance · Governance
Updated ID Governance guidance moves the end date from 27 October to 3 November 2026. Policies that still use the operator will be quarantined and stop processing assignments after the cutoff, making this a retirement deadline rather than a terminology edit.
- Passkeys can be registered as users’ first MFA method
Entra ID · Conditional Access
A Microsoft 365 Message Center notice says users can register passkeys or passwordless sign-in as their first multifactor authentication method, removing the former weaker-method-first requirement. Rollout is phased from January 2026 through November 2027; the supplied notice specifies no administrator configuration action.
- Windows Hello and macOS Platform SSO become standalone MFA factors
Entra ID · Conditional Access
Message Center says Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are required, but onboarding and documentation should be updated.
- Global Secure Access guidance covers its preview MCP firewall
Global Secure Access · Monitoring
A new how-to article—not a launch announcement—describes using the Global Secure Access MCP firewall to inspect, audit, and allow or block supported Model Context Protocol traffic by server, primitive, method, and protocol version. The documented prerequisites include Global Secure Access and Conditional Access Administrator roles, an Internet Access license, a joined device with the Global Secure Access client, and TLS inspection; the firewall is in preview.
- Token Protection web-app support is documented as a preview
Entra ID · Conditional Access
A new Entra deployment guide covers enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Scope is limited to listed apps, platforms, browsers, and device configurations; the guide requires Entra ID P1 and additional Windows or macOS device setup, and recommends report-only mode followed by a pilot before enforcement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
33 updates
Microsoft Entra ID
24 updatesThe documentation replaces the former Mappings-based steps with a Scoping filters wizard covering assignment-based and attribute-based filtering for users and groups. Existing operator details and limitations remain documented.
The documentation replaces older attribute-mapping navigation with the newer labels: **Advanced Options**, **Edit target User attributes**, and **Edit schema**.
The article now directs administrators to Manage > Attribute Mapping, with mappings organized by Users and Groups. It documents row-level edit and delete controls, group sync via Scoping filters, and the Advanced Options menu for custom attributes.
The documentation now says to open Expression Builder from the left navigation menu instead of Attribute Mapping > Advanced Options. The page date was also updated from March 4, 2025, to August 6, 2026, and the access screenshot was removed.
The documentation removes an example image and the instructions to enable or disable group provisioning through Attribute Mapping. It now directs administrators to the Scoping filters page for apps that support group sync.
The documentation now directs administrators to Provisioning > Manage > Attribute Mapping > Advanced Options > Edit schema, replacing the previous navigation labels and path.
Expression Builder
UpdatedThe documentation now says to open the **Advanced Options** dropdown, then select **Expression builder**, on the attribute mapping page. This replaces the previous **Show advanced options** wording.
The documentation replaces the previous Attribute Mappings instructions with the current Attribute Mapping page, Advanced Options dropdown, and Edit target User attributes selection.
The FAQ changes “Scoping filter” to “scoping filter” and clarifies that administrators define scoping filter rules to include or exclude users from processing. The existing Sales example remains.
The documentation now refers to the **Advanced Options** dropdown and **Edit target User attributes** instead of the former UI labels.
The documentation replaces the old “Show advanced options” and “Edit attribute list for ScimOnPremises” labels with “Advanced Options” and “Edit target User attributes.”
The documentation replaces the old **Show advanced options** checkbox and **Edit attribute list for ScimOnPremises** labels with **Advanced Options** and **Edit target User attributes**.
Plan Cloud Hr Provision
UpdatedThe guide now refers to using “scoping filters” instead of the “Source Object Scope” field when selecting users for provisioning to Active Directory.
The instructions now refer to the Attribute Mapping page, the Advanced Options dropdown, and Edit target User attributes instead of the previous UI labels.
Import ADSyncTools module
UpdatedThe documentation replaces a direct Microsoft Graph beta PATCH request with Microsoft Graph PowerShell cmdlets, including the `OnPremDirectorySynchronization.ReadWrite.All` scope. It now sets `AllowOnPremUpdateOfOnPremisesObjectIdentifierEnabled` to `$true` temporarily and explains that `$false` re-enables hard match protection.
Import ADSyncTools module
UpdatedThe existing-tenant installation documentation now instructs administrators to import the ADSyncTools module with a minimum version of 2.5.
Whats New
UpdatedThe August 2026 update revises configuration steps for the Overview, Attribute mapping, Provisioning configuration, and Basics settings pages.
Provide the user's identity.
UpdatedThe documentation no longer includes the “Import ADSyncTools module” heading and `Import-Module ADSyncTools` command.
Adds a guide for deploying and enforcing Token Protection with Conditional Access for supported browser-based applications accessing Azure Resource Manager. Web application support is explicitly in preview and limited to listed apps, platforms, browsers, and device configurations.
Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, removing the prior requirement to register weaker methods first. This change, rolling out in phases from January 2026 to November 2027, aims to simplify adoption of phishing-resistant sign-in.
Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are needed, but organizations should update onboarding and documentation accordingly.
Howto Arc Sign In Windows
UpdatedThe documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.
Token Protection
UpdatedThe Conditional Access token protection documentation now links to a deployment guide for web apps that access Azure Resource Manager. The linked guidance is marked Preview.
Microsoft Entra Agent ID
3 updatesThe documentation now lists two license options: Microsoft 365 E7, or Microsoft Agent 365 paired with Microsoft Entra P1 or Microsoft 365 E3.
The documentation replaces the Microsoft Entra ID P1/P2 license requirement and the note that an Agent 365 license would soon be required with a direct Agent 365 license requirement.
Licensing Agent Id
UpdatedThe documentation replaces standalone Entra licensing options for agents with guidance that Microsoft Agent 365 is required. It states that Agent 365 is included with Microsoft 365 E7 and available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite.
Microsoft Entra ID Protection
2 updatesLicensing Conditional Access
UpdatedThe documentation now lists two supported licensing options: Microsoft 365 E7, which includes Agent 365 and Microsoft Entra Suite, or Microsoft Agent 365 paired with at least Microsoft Entra P1 or Microsoft 365 E3.
Licensing Conditional Access
UpdatedThe documentation now states that Conditional Access for agents requires a Microsoft Agent 365 license to apply policies through Microsoft Entra Agent ID, replacing “Starting soon.”
Microsoft Entra ID Governance
1 updateThe documentation now states that support for the `memberOf` rule operator ends November 3, 2026, replacing October 27, 2026. Policies using it will be quarantined and stop processing assignments from that date.
Microsoft Entra External ID
2 updatesThe guide now reflects revised Entra portal navigation and controls, including **New configuration**, **Create**, **Overview > Properties**, and **Attribute mapping**. It also updates terminology and scope-setting guidance.
The documentation now directs administrators to Entra ID > Cross-tenant Synchronization > Configurations, removing the External Identities step.
Microsoft added a how-to article for configuring the Global Secure Access MCP firewall to inspect, audit, and allow or block Model Context Protocol traffic. It covers server, primitive, method, and protocol-version controls for supported MCP traffic.
