Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors starting October 2026, allowing users to meet MFA requirements without additional passkeys. No configuration changes are needed, but organizations should update onboarding and MFA registration guidance accordingly.
Federated sign-in validation tightens as Windows Hello and macOS SSO gain standalone MFA
The day’s consequential changes are two Entra authentication behavior updates. Microsoft says the federatedTokenValidationPolicy default will block federated sign-ins when internalDomainFederation does not match the user’s UPN domain for federated domains configured before December 2025. Starting in October 2026, Windows Hello for Business and macOS Platform SSO will count as standalone MFA factors. Workload ID’s flexible federated identity credential preview guidance also tightens GitHub claim matching, while the remaining updates are lower-impact synchronization and licensing reference maintenance.
- FederatedTokenValidationPolicy default will block mismatched federated domains
External ID · Conditional Access
Microsoft’s Message Center notice describes a mid-August 2026 default change affecting federated domains configured before December 2025. Federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. Administrators can customize the policy through Microsoft Graph, although Microsoft discourages customization.
- Windows Hello and macOS Platform SSO become standalone MFA factors
Entra ID · Conditional Access
Starting in October 2026, Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors, allowing users to satisfy MFA requirements without an additional passkey. Microsoft says no configuration changes are required, but onboarding and MFA-registration guidance should be updated.
- GitHub flexible FIC preview guidance requires immutable repository claims
Workload ID · Security
The updated preview documentation says GitHub flexible federated identity credentials must match sub and at least one immutable claim: repository_id or repository_owner_id. The examples and operator guidance now use these claims with the eq operator when defining or reviewing trust.
- Synchronization guidance adds sAMAccountName coverage for Domain Services
Entra ID · Provisioning
The Synchronization page now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance for that scenario.
The reference, updated August 14, 2026, adds Windows 10 ESU service-plan identifiers to two Windows 365 plan entries. No administrator action is stated beyond using the updated reference when matching those plans.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Entra ID
3 updatesLicensing Service Plan Reference
Doc updateThe reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.
Synchronization
Public previewThe synchronization documentation now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance.
Microsoft Entra External ID
1 updateMicrosoft Entra will update federatedTokenValidationPolicy by mid-August 2026 to block federated sign-ins when internalDomainFederation doesn't match the user's UPN domain, enhancing security. This affects federated domains configured before December 2025. Admins can customize the policy via Microsoft Graph but it's discouraged.
Microsoft Entra Workload ID
2 updatesSet up a Flexible Federated identity credential (preview)
Feature updateAction requiredThe guidance now requires GitHub flexible federated identity credentials to match `sub` plus `repository_id`, `repository_owner_id`, or both. Portal and Microsoft Graph examples include these claims and optional workflow matching.
Flexible federated identity credentials (preview)
Feature updateThe documentation now states that GitHub flexible federated identity credentials must match `sub` and at least one immutable claim: `repository_id` or `repository_owner_id`. It also updates examples and operator support details.
