Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on August 11, 2026, due to fraud risks. Users must switch to other authentication methods before then. SMS as a multifactor method remains unaffected. Admins should identify affected users and update authentication policies accordingly.
Entra ID Free SMS first-factor sign-in retirement makes alternate authentication necessary
The period’s main administrator-impacting notice is Microsoft’s planned retirement of SMS first-factor sign-in for Microsoft Entra ID Free tenants on 11 August 2026 because of fraud risks; SMS used for multifactor authentication remains unaffected. Microsoft also added first-party Workload ID federation tutorials for Google Cloud and SPIFFE/SPIRE, expanded Agent ID permission guidance, and revised Catalog Access Reviews documentation. Most remaining edits were maintenance, including a corrected Global Secure Access section name and updated links.
- SMS first-factor sign-in retirement for Entra ID Free tenants
Entra ID · Authentication
A Microsoft 365 Message Center notice says Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on 11 August 2026 because of fraud risks. Users must switch to another authentication method before retirement; SMS as a multifactor method is unaffected. This is a security-related product retirement, not a documentation clarification.
- Catalog Access Reviews documentation adds a 12-hour data-freshness caveat
ID Governance · Governance
Updated ID Governance guidance removes Preview labels, broadens reviewer terminology beyond managers, and warns that changes made within 12 hours before a review starts may not appear. The supplied evidence does not explicitly announce general availability, so the status change should not be treated as a confirmed GA announcement.
- Google Cloud workload federation gets a first-party Workload ID tutorial
Workload ID · General
A new tutorial shows how an Entra application can trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets. It documents a configuration scenario rather than announcing a new product launch and requires permission to add a federated identity credential.
- SPIFFE/SPIRE workload federation gets a first-party Workload ID tutorial
Workload ID · General
A new tutorial documents exchanging a Kubernetes workload’s SPIFFE JWT-SVID for a Microsoft Entra access token so it can access Azure resources without stored secrets. The page is implementation guidance for an existing federation scenario, not evidence of a new product launch.
- Agent ID guidance maps Microsoft 365 channels to required permissions
Agent ID · Developer
Updated guidance now covers agents communicating through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, with permissions for receiving events and sending responses. Administrators can use the channel-by-channel table to configure agent access; no underlying product behavior change is stated.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
12 updates
Microsoft Entra ID
1 updateMicrosoft Entra Agent ID
1 updateThe documentation now lists how an agent with its own identity can communicate through Outlook email, OneDrive and SharePoint comments, Teams chats, and Teams channels, including the permissions required for inbound and outbound communication.
Microsoft Entra ID Governance
5 updatesThe guide removes the Preview label and adds steps for creating the resource and Logic App, automatic upload notifications, manual result application, and new resource parameters.
The page no longer labels the capability as Preview and now documents catalog resource setup, Logic App integration, manual uploads, and applying results to non-Approve decisions. The previous note about single-stage reviews with manager reviewers was removed.
Catalog Access Reviews
UpdatedThe documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.
Catalog Access Reviews
UpdatedThe page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.
Licensing Governance
UpdatedThe governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.
Microsoft Entra Workload ID
3 updatesAdds a first-party tutorial showing how a Kubernetes workload can exchange a SPIFFE JWT-SVID for a Microsoft Entra access token and access Azure resources without stored secrets. This is documentation for the scenario, not evidence of a new product launch.
Adds a step-by-step tutorial showing how to configure a Microsoft Entra application to trust a Google-issued service-account token, exchange it for an Entra access token, and access Azure resources without storing application secrets.
Workload Identity Federation
UpdatedThe concept page now points to first-party tutorials for Google Cloud and SPIFFE/SPIRE scenarios instead of the previous links. No product feature change is indicated.
Microsoft Entra Global Secure Access
2 updatesManage Microsoft Profile
UpdatedThe instructions now refer to the “Remote network assignments” section instead of “Remove network assignments.”
Manage Microsoft Profile
UpdatedThe step now refers to the **Remote network assignments** section instead of **Remove network assignments** when selecting the profile’s **View** link.
