← Previous day

Next day →
Day in brief

Federated sign-in validation tightens as Windows Hello and macOS SSO gain standalone MFA

The day’s consequential changes are two Entra authentication behavior updates. Microsoft says the federatedTokenValidationPolicy default will block federated sign-ins when internalDomainFederation does not match the user’s UPN domain for federated domains configured before December 2025. Starting in October 2026, Windows Hello for Business and macOS Platform SSO will count as standalone MFA factors. Workload ID’s flexible federated identity credential preview guidance also tightens GitHub claim matching, while the remaining updates are lower-impact synchronization and licensing reference maintenance.

  • Microsoft’s Message Center notice describes a mid-August 2026 default change affecting federated domains configured before December 2025. Federated sign-ins will be blocked when internalDomainFederation does not match the user’s UPN domain. Administrators can customize the policy through Microsoft Graph, although Microsoft discourages customization.

  • Starting in October 2026, Microsoft Entra will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors, allowing users to satisfy MFA requirements without an additional passkey. Microsoft says no configuration changes are required, but onboarding and MFA-registration guidance should be updated.

  • The updated preview documentation says GitHub flexible federated identity credentials must match sub and at least one immutable claim: repository_id or repository_owner_id. The examples and operator guidance now use these claims with the eq operator when defining or reviewing trust.

  • The Synchronization page now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance for that scenario.

  • The reference, updated August 14, 2026, adds Windows 10 ESU service-plan identifiers to two Windows 365 plan entries. No administrator action is stated beyond using the updated reference when matching those plans.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

6 updates

1
1

Licensing Service Plan Reference

Doc update

The reference was updated August 14, 2026, adding Windows 10 ESU service-plan identifiers to two Windows 365 plan entries.

1

Synchronization

Public preview

The synchronization documentation now describes enhanced support for synchronizing sAMAccountName with Microsoft Entra Domain Services and links to dedicated guidance.

1
2

Set up a Flexible Federated identity credential (preview)

Feature updateAction required

The guidance now requires GitHub flexible federated identity credentials to match `sub` plus `repository_id`, `repository_owner_id`, or both. Portal and Microsoft Graph examples include these claims and optional workflow matching.

Flexible federated identity credentials (preview)

Feature update

The documentation now states that GitHub flexible federated identity credentials must match `sub` and at least one immutable claim: `repository_id` or `repository_owner_id`. It also updates examples and operator support details.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…