MondayMon
TuesdayTue
WednesdayWed
ThursdayThu
FridayFri
SaturdaySat
SundaySun
2414Entra IDID GovernanceGlobal Secure Access2514Entra IDExternal IDGlobal Secure Access2629Entra IDID GovernanceGlobal Secure Access2714Agent IDEntra IDExternal ID2841Entra IDWorkload IDID Governance2912Entra IDGlobal Secure Access303122Agent IDEntra IDID Governance118Global Secure AccessEntra ID23Entra ID312Entra IDID GovernanceWorkload ID412Agent IDID GovernanceEntra ID59Workload IDEntra ID671Entra ID84External IDEntra IDWorkload ID91Entra ID104Entra IDExternal ID1133External IDEntra IDWorkload ID121ID Protection131418Entra IDID GovernancePrivate Access158External IDEntra ID1635Entra IDID Governance175Global Secure AccessInternet AccessEntra ID18
19
20
21
22
23
24
25
26
27
28
29
30
1
2
3
4
Month in brief

Passkeys become Entra default as Microsoft sets SMS and voice retirement deadlines

September reset Entra authentication: passkeys became the default Microsoft Entra authentication on September 1, while Microsoft-provided SMS and voice authentication face retirement deadlines beginning February 1, 2027. Microsoft also narrowed the Microsoft Graph User.ReadBasic.All permission, documented an External ID system-browser handoff for brokered identity providers, and described preview Continue Evaluation behavior in Global Secure Access Web Filtering v2. A phased rollout from October 2026 through February 2027 will let users register passkeys or passwordless sign-in as their first MFA method. Most remaining activity was documentation maintenance; notable operational exceptions included the removal of Enterprise State Roaming management from the Entra admin center and a newly documented Cloud Sync migration workflow.

  • The detailed guidance sets February 1, 2027, for users including internal guests, and July 1, 2027, for Global Administrators and external users. After the applicable date, users whose only MFA method is SMS or voice receive a blocking passkey-registration prompt; a customer-managed telecom provider is the documented option where those methods must remain available.

  • Beginning in mid-September, the permission no longer grants access to user app role assignments or license details as part of a security fix. Applications that need this data must switch to User.Read.All or LicenseAssignment.Read.All to avoid disruption.

  • Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and providers that block WebViews. Before using the flow, administrators should check the listed platform, broker, application-version, federation-protocol, and cloud support.

  • With the preview Continue Evaluation action, unmatched traffic passes to the next applicable security profile, while a matching rule or an Allow or Block action stops evaluation. The Baseline Profile must use Allow or Block, which matters when composing or migrating overlapping profiles.

  • A phased rollout from October 2026 through February 2027 lets users register passkeys or passwordless sign-in as their first multifactor authentication method, removing the need to establish a weaker method first.

For Entra administrators

Inventory applications using User.ReadBasic.All and replace it with User.Read.All or LicenseAssignment.Read.All where the removed data is required. Plan SMS and voice migration by user category, moving users to phishing-resistant methods or a customer-managed telecom provider where necessary. If adopting External ID browser authentication, verify the listed platform, broker, application-version, federation-protocol, and cloud prerequisites. For Web Filtering v2, review overlapping profile defaults and ensure the Baseline Profile uses Allow or Block.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

164 updates by product

29

Sspr Policy

Doc update

The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”

17 September 2026

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

RetirementAction required

Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.

16 September 2026

Sms Voice Retirement

RetirementAction required

The documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.

16 September 2026

Howto Sspr Windows

Doc update

The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.

16 September 2026

Connect Version History

Doc update

The Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.

16 September 2026

Authentication

Doc update

The authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.

16 September 2026

Connect Passwordless Authentication

Doc update

The documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.

16 September 2026

Netskope Administrator Console Provisioning Tutorial

Doc update

The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.

16 September 2026

Connect Version History

Doc updateAction required

The documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.

16 September 2026

Connect Version History

Doc update

The version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.

16 September 2026

Connect Version History

Doc update

The version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.

16 September 2026

Connect Version History

Doc update

The Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.

16 September 2026

Authentication Qr Code

Doc update

The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.

11 September 2026

Fido2 Compatibility

Doc update

The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.

11 September 2026

Microsoft Entra: Optimized passkey registration campaign experience

New

Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.

9 September 2026
Message CenterMC1469555 on mc.merill.net ↗Plan for change

Sspr Writeback

Doc update

The documentation now states that when Cloud Sync and Connect Sync are configured for the same domain, Cloud Sync processes password writeback for users synchronized from that domain.

7 September 2026

Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator

Feature update

The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.

5 September 2026

Permissions Reference

Doc update

The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.

4 September 2026

Permissions Reference

Doc update

The role description now states that Security Administrators can perform identity containment actions during security incidents.

4 September 2026

Test-only PFX password

Doc update

The documented password example now includes an exclamation mark at the end.

3 September 2026

Troubleshoot STATUS_ACCOUNT_DISABLED in Microsoft Entra

Doc update

A new article explains how to diagnose intermittent STATUS_ACCOUNT_DISABLED sign-in and unlock errors on Microsoft Entra hybrid joined Windows devices, including relevant event logs and the stale-cache and connectivity conditions that can cause them.

2 September 2026
29

Connect Version History

Feature update

The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.

16 September 2026

Connect Version History

New featureAction required

The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.

16 September 2026

Connect Version History

Doc update

The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.

16 September 2026

Connect Version History

Doc update

The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.

16 September 2026

Connect Version History

Doc updateAction required

The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.

16 September 2026

Connect Version History

Doc updateAction required

The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.

16 September 2026

Connect Version History

Doc update

The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.

16 September 2026

Connect Version History

Doc update

Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.

16 September 2026

Connect Version History

Feature update

The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.

16 September 2026

Connect Version History

Doc updateAction required

The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.

16 September 2026

Connect Version History

Doc update

The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.

16 September 2026

Using single sign-on with cloud sync

Doc update

The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.

16 September 2026

Migrate Microsoft Entra Enterprise State Roaming

RetirementAction required

As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.

14 September 2026

Validate Oidc Multitenant App Gallery

Doc updateAction required

The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.

14 September 2026

Configure

Doc update

The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.

14 September 2026

Use My Staff to delegate user management

Retirement

My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.

11 September 2026

Licensing Service Plan Reference

Doc update

Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.

11 September 2026

Licensing Service Plan Reference

Doc update

Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.

11 September 2026

My Staff Configure

Doc update

The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.

11 September 2026

Whats New

New feature

The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.

4 September 2026

Delegate By Task

Feature update

The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.

4 September 2026

Permissions Reference

Doc update

The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.

4 September 2026

Least privileged roles by task

New feature

The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.

4 September 2026

Publish App Gallery

Doc update

The documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.

3 September 2026

V2 Howto App Gallery Listing

Doc update

The app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.

3 September 2026

V2 Howto App Gallery Listing

Doc update

The app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.

3 September 2026

Validate Oidc Multitenant App Gallery

Doc update

The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.

1 September 2026

Connect Install Roadmap

Doc update

The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.

1 September 2026

Validate Oidc Multitenant App Gallery

Doc update

The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.

1 September 2026
14

Validate User Provisioning App Gallery

Doc update

The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.

11 September 2026

Validate Saml Single Sign On App Gallery

Doc update

The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.

11 September 2026

Validate Saml Single Sign On App Gallery

Doc update

The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.

11 September 2026

Entra Id Scim Api Reference

Feature update

The reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.

5 September 2026

Enable Scim Api

Doc update

The permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.

5 September 2026

Entra Id Scim Api Reference

Feature updateAction required

The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.

5 September 2026

Enable Scim Api

Doc update

The permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.

5 September 2026

Entra Id Scim Api Schema Documentation

New feature

The schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.

5 September 2026

Entra Id Scim Api Reference

Doc update

The SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.

5 September 2026

Publish App Gallery

Doc update

The app gallery publishing documentation now refers to the required identifier as a Partner One ID and notes that it was formerly called the Microsoft Partner Network (MPN) ID.

3 September 2026

Validate Saml Single Sign On App Gallery

Doc update

The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”

1 September 2026
12

Connect Version History

Feature updateAction required

Microsoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.

16 September 2026

Connect Version History

Doc update

The version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.

16 September 2026

Whatis Azure Ad Connect

Doc update

The page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.

16 September 2026

Connect Version History

Doc update

The documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.

16 September 2026

Clear attribute values (Preview)

Feature update

The documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.

15 September 2026

Microsoft Entra ID and Workday integration reference

Doc update

The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.

15 September 2026

Validate User Provisioning App Gallery

Doc update

The documentation and screenshot alt text now refer to the field as “Submission ID” instead of “submission request ID.”

11 September 2026

Configure HiBob to Active Directory hybrid user provisioning

New feature

New documentation explains how HiBob can provision and update users in on-premises Active Directory through Microsoft Entra API-driven provisioning and the provisioning agent. It covers prerequisites, permissions, configuration, and synchronization flow.

4 September 2026
6

Tshoot Connect Sso

Doc update

The procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.

16 September 2026

Hr User Update Issues

Doc update

The documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.

15 September 2026
4

Connect Version History

Doc updateAction required

The version history entry now links readers to the latest available Microsoft Entra Connect Sync version.

16 September 2026

Credential Management Api

Doc update

The Microsoft Entra External ID credential management API reference was deleted. It previously documented how applications let signed-in customers list, register, and delete passkeys.

10 September 2026

Microsoft Viva Engage: Microsoft Entra permissions required for community and membership administration

New

Starting late September 2026, Microsoft Viva Engage will require Microsoft Entra permissions—Yammer Administrator role or Community Admin assignment—for community and membership management tasks previously allowed to Verified or Network Admins. Administrators should review and update role assignments accordingly.

1 September 2026
Message CenterMC1465773 on mc.merill.net ↗Major updatePlan for change
3

Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

New

Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.

15 September 2026
Message CenterMC1426371 on mc.merill.net ↗Major updatePlan for change

Microsoft Entra ID: Passkey support for B2B users

New

Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.

14 September 2026
Message CenterMC1459133 on mc.merill.net ↗Stay informed
3

End-user experiences for applications

Retirement

The documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.

11 September 2026

Publish App Gallery

Doc update

The app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.

11 September 2026

Prerequisites to validate and publish your app

Feature updateAction required

The documentation now instructs app publishers to provide a Partner One ID associated with their Microsoft AI Cloud Partner Program organization and explains how to find help if they do not know it.

3 September 2026
3

Policy Teams Devices Device Code Flow

Doc updateAction required

The instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.

10 September 2026

Policy Teams Devices Device Code Flow

Doc update

The guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.

10 September 2026

Privileged Roles Permissions

Doc update

The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.

4 September 2026
2
2

Sample V2 Code

Doc update

The Node.js Express and web application entries in the sample code documentation were updated, including their linked sample resources.

2 September 2026
1

Tenant Estate Primary

Doc update

The tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

11 September 2026
1

Connect Install Roadmap

Doc update

The page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.

16 September 2026
2

Permissions Reference

Doc update

The AI Administrator and AI Reader descriptions were updated from “Microsoft 365 Copilot” to “Microsoft Copilot.” Their role IDs remain unchanged.

11 September 2026

Agent Owners Sponsors Managers

Doc update

Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.

4 September 2026
1

Manage Agent Identities End User

Doc update

The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.

4 September 2026
1

Howto Export Risk Data

Doc update

The page now distinguishes diagnostic setting categories from KQL table names and maps six ID Protection signals to their corresponding AAD-prefixed Log Analytics tables.

12 September 2026
9

Extend Application Attributes

Doc update

The documentation now uses clearer wording for configuring LCW extensibility workflow mappings, creating an Azure Logic App and workflow, and configuring provisioning jobs with attribute mappings.

16 September 2026

Licensing

Doc update

The Tenant Governance licensing page now links to Microsoft Agent 365 licensing FAQs and guidance for using governance relationships with Microsoft Defender.

14 September 2026

Entitlement Management Access Package Create

Doc update

The access package creation documentation now explains that the search box can find matching SharePoint Online roles that are not initially displayed, especially on sites with many roles.

14 September 2026

Entitlement Management Access Package Resources

Doc update

The documentation now recommends using the search box to find SharePoint Online roles when adding them to an access package. Search returns matching roles even when they are not initially displayed.

14 September 2026

Licensing

Doc update

The licensing documentation’s Microsoft author alias was updated from `tafra00` to `tazkiaafra`.

14 September 2026

Entitlement Management Access Package Request Policy

Doc update

The documentation now specifies that existing guest users can be directly assigned, but external users who are not yet in the directory cannot be invited through direct assignment when access is limited to administrator direct assignments.

11 September 2026

Apps

Doc update

The HR integrations table now includes a link for HiBob to Microsoft Entra ID/Active Directory and updates the Rippling provisioning link text.

4 September 2026

Pim How To Use Audit Log

Doc update

The documentation explains that related PIM activation and deactivation events can have different CorrelationId values. It recommends using roleAssignmentRequestId to trace a complete request and adds Log Analytics query examples.

3 September 2026

Entitlement Management Request Behalf

Doc update

The documentation now directs administrators to the **Who can request access** section on the **Requests** tab, where selecting **Manager** enables managers to request access packages for employees.

3 September 2026
2

Microsoft Entra ID Governance licensing fundamentals

Doc update

The licensing fundamentals page was updated to align the Account Discovery section and state that the feature requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite.

14 September 2026

Licensing

Doc update

The page now lists the Microsoft Agent 365 Licensing FAQs and governance relationships links without the previous section heading and introductory text.

14 September 2026
8

Browser authentication for external identity providers in Microsoft Entra ID

New feature

Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.

15 September 2026

Apple Federation Customers

Doc update

The article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.

11 September 2026

Add an identity provider to a user flow

Doc update

A single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.

11 September 2026

Entra Id Federation Customers

Doc update

The article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.

11 September 2026

Custom Oidc Federation Customers

Doc update

The article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.

11 September 2026

Facebook Federation Customers

Doc update

The article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.

11 September 2026

Google Federation Customers

Doc update

The article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.

11 September 2026

Sign In With Passkey

Feature update

The documentation no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and states that low-privilege passkey credential management APIs are on the roadmap.

10 September 2026
3

Microsoft Accounts Federation Customers

Doc update

The article replaces its embedded steps and screenshot for adding the Microsoft account identity provider with a link to the shared user-flow guidance.

11 September 2026

Direct Federation

Doc update

The External tenants guidance now links to the consolidated article for adding a SAML/WS-Fed identity provider to a user flow.

11 September 2026

Saml Ws Federation Self Service Sign Up

Doc update

The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.

11 September 2026
2

Manage User Profile Info

Doc update

The user profile information documentation no longer includes guidance that users can use My Apps preview features or that administrators can access My Staff.

11 September 2026

Manage User Profile Info

Doc update

The user profile information guidance no longer includes the “Manage user feature settings” reference.

11 September 2026
1

Set up B2B direct connect

Doc update

The documentation now explains how Microsoft Entra ID accepts compliant-device claims from an external user’s home tenant and how Conditional Access evaluates those claims. It also describes the trust implications and behavior when the setting is disabled.

8 September 2026
1

Set up Microsoft Entra Verified ID

Doc update

The new article explains how to use Quick setup, register applications, create credentials, and issue and verify credentials in a Microsoft Entra External ID tenant. It documents prerequisites and limits, including custom-domain requirements, shared signing keys, two requests per second per tenant, and six-month credential validity.

8 September 2026
2

Microsoft Purview: Integration with Entra GSA Internet Access to enable sensitive file filtering at the network layer

New

Microsoft Purview DLP integrates with Entra Global Secure Access Internet Access to filter sensitive files at the network layer, preventing data leaks to unmanaged cloud apps. Public preview starts mid-November 2025; general availability by October 2026. Admins must configure policies, TLS inspection, and activate Purview pay-as-you-go.

11 September 2026
Message CenterMC1181769 on mc.merill.net ↗Stay informed
1

Web filtering in Global Secure Access (V2)

New feature

The documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.

17 September 2026
1
1
3

Configure Managed Identities Assignment Restriction

Doc updateAction required

The documentation now clarifies that Azure CLI commands and IaC templates must use the provider namespace Microsoft.Storage, while Microsoft.Storage/* is only an Azure portal display convention.

5 September 2026

Managed Identities Assignment Restriction

Doc updateAction required

The documentation now clarifies that Azure CLI commands and IaC templates must use Microsoft.Storage. The Microsoft.Storage/* format shown in the portal is only a display convention and is not accepted by the API.

5 September 2026

Managed Identities Faq

Feature update

The documentation now states that creating a managed identity is blocked when the resulting directory usage reaches or exceeds 98% of the tenant quota. This applies to new or recreated service principals; existing identities and assignments continue to work.

3 September 2026
2

What Is Entra

Doc update

The Entra documentation now uses the singular verb “needs” for “GitHub Actions” in an example about workload identities accessing Azure subscriptions.

8 September 2026
4

How to configure custom headers (preview)

Doc update

The page now explains how to find modified-header transactions in Global Secure Access traffic logs and add the Custom Headers column. During the September 2026 rollout, a special Entra Admin Center link may be needed to view these details.

11 September 2026

Configure Custom Headers

Doc update

Consistent spacing was added to domain lists for Claude, GitHub, Slack, Dropbox, and YouTube entries. Header names and descriptions are unchanged.

1 September 2026
4

Transport Layer Security

Doc update

The TLS inspection documentation now explains how to configure either a Microsoft-managed certificate or your own certificate authority.

1 September 2026

Configure TLS inspection with a Microsoft-managed certificate

New featureAction required

The guide explains how to create a tenant-specific Microsoft-managed root CA, deploy its public certificate to client devices, and enable it for Microsoft Entra Internet Access TLS inspection. The capability is in preview, and the private key remains protected by Microsoft.

1 September 2026

Configure TLS inspection with your own certificate

Doc update

The article now focuses on bringing your own certificate authority for TLS inspection, including CSR creation, PKI signing, and certificate upload. It also links to separate Microsoft-managed certificate guidance.

1 September 2026
3

Learn about Universal Continuous Evaluation

Feature update

The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.

17 September 2026

Generative Ai Insights

Doc update

The documentation now refers to “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

11 September 2026
3

Troubleshoot Transport Layer Security

Doc update

The troubleshooting page now links to separate guides for Microsoft-managed certificates and customer-provided certificates, and its publication date was updated.

1 September 2026

Troubleshoot App Access

Doc update

The app-access troubleshooting guide now recommends enabling session persistence after confirming the application works through a single connector, keeping the same user and device routed through that connector during the session.

1 September 2026
1

Secure Generative Ai

Doc update

The guidance now labels the link “Microsoft Copilot requirements” instead of “Microsoft 365 Copilot requirements.”

11 September 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…