← Previous day

Next day →
Day in brief

First-factor system-preferred authentication rolls out as Lifecycle Workflow guidance expands to 365 days

Microsoft Entra is applying system-preferred authentication to first-factor sign-ins for tenants in the Microsoft-managed state, with rollout continuing through late September 2026. ID Governance guidance now documents 365-day event offsets and clarifies the Time based attribute V2 trigger, while Global Secure Access records an August macOS client release with new controls and deployment considerations. Most remaining updates are documentation maintenance, including Connect Health version and download references and lifecycle-page reorganization.

  • For tenants in the Microsoft-managed state, Microsoft Entra now selects the most secure registered authentication method for first-factor sign-ins. Rollout runs from late June through late September 2026; administrators can keep or change the setting and should update user guidance.

  • The updated Execution Conditions page now states that the limits for Days from event, and Days to event when using Between, increased from 180 to 365 days. It describes conditions up to one year before or after an event and states that no administrator action is required.

  • The documentation describes Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after supported date attributes. It also says both the workflow and schedule must be enabled, V2 has no three-day catch-up window, and the preview admin center may show two choices representing the same trigger.

  • Release notes for August 21, 2026 list Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass, along with connectivity, sign-in, tunnel, cache-reset, and crash fixes. Administrators should review the release when planning macOS deployments.

  • The installation page states that client version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It advises optionally removing that app from the Included apps list.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

14 updates

2

Connect Health Version History

Doc update

The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.

Connect Health Agent Install

Doc update

The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.

1
7

Understanding Lifecycle Workflows

Public preview

The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.

Create Lifecycle Workflow

Public preview

Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.

Lifecycle Workflow Execution Conditions

Public preview

Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.

Entitlement Management Request Behalf

Doc update

The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.

Create Lifecycle Workflow

Doc update

The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.

1

Understanding Lifecycle Workflows

Public preview

The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.

3

Global Secure Access Client for macOS Release Notes

New feature

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

Install the Global Secure Access Client for macOS

Doc update

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

Macos Client Release History

Doc update

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…