The documentation now states that opting out requires the Microsoft Graph `Policy.ReadWrite.AuthenticationMethod` permission. The page date changed from July 29 to August 10, 2026.
First-method passkey registration rolls out from October 2026 through February 2027
The period’s consequential item is a Microsoft Entra rollout announcement: users will be able to register a passkey or passwordless sign-in as their first multifactor authentication method, without setting up weaker methods first. The remaining changes are documentation clarifications covering Agent ID token exchange, a Microsoft Graph permission prerequisite, account discovery limits, workload identity guidance links, and PAC-file syntax. No new or removed documentation items are recorded, and the evidence does not establish a separate preview, general-availability, or retirement event.
- First-method passkey and passwordless registration is scheduled to roll out
Entra ID · Conditional Access
The Message Center announcement says users can register a passkey or passwordless sign-in as their first multifactor authentication method, eliminating the need to configure weaker methods first. Rollout is stated for October 2026 through February 2027, with no administrator action required.
- Agent ID guidance clarifies audiences and the preauthorization requirement
Agent ID · Standards
Updated Agent ID on-behalf-of guidance says Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated against the blueprint and child agent identity. It also clarifies that agent identities cannot use interactive consent and that delegated permissions must be preauthorized through inheritable blueprint permissions. This is a documentation clarification with concrete configuration implications.
- Graph opt-out guidance now names the required authentication-method permission
Entra ID · Authentication
The passkey and Microsoft-provided SMS and voice authentication page now states that opting out through Microsoft Graph requires Policy.ReadWrite.AuthenticationMethod. The supplied evidence supports this as a documentation prerequisite clarification, not a new retirement date or separately documented API behavior change.
- Account discovery documentation tightens prerequisites and limitation wording
Entra ID · Governance
The account discovery article now uses lowercase “account discovery” and clarifies connector requirements, direct attribute matching, SCIM support, unsupported scenarios, the GitHub reference, and the expectation that reports take at least 30 minutes. It continues to describe the existing process; no launch or required action is indicated.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
8 updates
Microsoft Entra ID
3 updatesUsers can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.
The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.
Microsoft Entra Agent ID
2 updatesThe documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.
The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.
Microsoft Entra Internet Access
1 updateCustom Proxy File Hosting
UpdatedThe instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.
Microsoft Entra Workload ID
2 updatesThe documentation now links to guidance on mutable subjects and migrating GitHub Actions federated credentials to immutable subjects.
The setup documentation now links to guidance on mutable subjects and migrating GitHub Actions federated credentials to immutable subjects.
