Sspr Policy
The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Daily.Entra.NewsTrack documentation and Message Center changes for Microsoft Entra ID.
Microsoft Learn documentation ↗The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
The authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.
The page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.
The documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.
The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.
The Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.
The version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.
Microsoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.
The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.
The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.
The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.
The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.
Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.
The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.
The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.
The version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.
The Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.
The documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.
The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.
The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.
The version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.
The documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.
The version history entry now links readers to the latest available Microsoft Entra Connect Sync version.
The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.
The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.
The procedure now uses revised Microsoft Entra Connect paths and module-import commands, including the ADSync module and the AzureADSSO module. Step numbering and wording were also updated.
Microsoft added documentation for using the guided migration tool to assess an environment, create Cloud Sync configurations, run a preactivation check, and validate synchronization after migration.
The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.
Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.
A how-to article explains how to enable FIDO2 and passkey methods, register credentials, configure a registry setting, and sign in to Microsoft Entra Connect Sync without a password.
The documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.
The procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.
The article now documents configuring a SCIM endpoint that uses an OAuth2 client-credentials grant from a non-Entra issuer, including the token endpoint, client credentials, credential placement, and scopes.
The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.
The page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.
The documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.
The documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.
The documentation now explains how optional single-valued source attributes can clear mapped target attributes when SAP SuccessFactors returns null or empty values.
The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.
Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.
The documentation now distinguishes Microsoft-managed and enabled campaigns. It specifies the MFA method required for each targeted authentication method and broadens eligible users from SMS or voice sign-ins to users signing in with any MFA method.
The documentation now explains how to configure attribute value clearing, fallback values, or ignored values when HR applications return null or empty attributes during provisioning.
The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.
Account discovery now covers users and groups, classifying them as local, unassigned, or assigned identities. Group discovery is identified as being in preview, and correlation requires a direct matching attribute.
The tutorial now requires Microsoft Entra ID P1, P2, or Governance licenses for every identity sourced through API-driven provisioning.
The troubleshooting guidance for SEC_E_NO_AUTHENTICATING_AUTHORITY now links to Windows Server 2025 build 26100.6905 information.
Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.
Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out in phases from October 2026 to February 2027, aims to increase adoption of phishing-resistant sign-in.
As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.
The troubleshooting guide now uses `-vAuth` instead of `-v` when starting `Start-auth.ps1`.
The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.
The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.
The Windows token protection guide now refers to Microsoft Copilot instead of Microsoft 365 Copilot.
The documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.
The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.
Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.
Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.
User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a security issue. Applications needing this data must switch to User.Read.All or LicenseAssignment.Read.All permissions and update accordingly to avoid disruptions.
The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.
The app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.
The tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”
My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.
The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.
The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.
The documentation and screenshot alt text now refer to the field as “Submission ID” instead of “submission request ID.”
The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.
The Microsoft Entra External ID credential management API reference was deleted. It previously documented how applications let signed-in customers list, register, and delete passkeys.
The instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.
The guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.
The documentation now explains how supported audit events can include DUSI, maps linkable identifiers to audit-log attributes, and provides steps for correlating sign-ins with administrative activity. Some events may not include DUSI.
The documentation now states that when Cloud Sync and Connect Sync are configured for the same domain, Cloud Sync processes password writeback for users synchronized from that domain.
The permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.
The permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.
The SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.
The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.
The reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.
The schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.
The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
New documentation explains how HiBob can provision and update users in on-premises Active Directory through Microsoft Entra API-driven provisioning and the provisioning agent. It covers prerequisites, permissions, configuration, and synchronization flow.
The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.
The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.
Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.
The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.
The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.
The role description now states that Security Administrators can perform identity containment actions during security incidents.
The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.
The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.
The page title and heading no longer include “(preview).”
The documentation now explains how Entitlement Management integrates with ServiceNow for access package requests, request history, and approvals. It covers licensing, installation, configuration, and user workflows.
The documentation now instructs app publishers to provide a Partner One ID associated with their Microsoft AI Cloud Partner Program organization and explains how to find help if they do not know it.
The documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.
The app gallery publishing documentation now refers to the required identifier as a Partner One ID and notes that it was formerly called the Microsoft Partner Network (MPN) ID.
A new how-to explains registering an MCP server as an OAuth 2.0 protected resource, enabling v2 access tokens, and connecting MCP clients through Microsoft Entra Agent ID.
The documented password example now includes an exclamation mark at the end.
The app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.
The app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.
The Node.js Express and web application entries in the sample code documentation were updated, including their linked sample resources.
The documentation now states that Microsoft-managed system-preferred authentication deployment will continue through September 2026, rather than August 2026.
A new article explains how to diagnose intermittent STATUS_ACCOUNT_DISABLED sign-in and unlock errors on Microsoft Entra hybrid joined Windows devices, including relevant event logs and the stale-cache and connectivity conditions that can cause them.
The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.
Microsoft Entra improves the iOS Microsoft Authenticator app's passkey restore experience with a clearer, guided flow for device migration, launching worldwide mid-September 2026. It affects iOS users with iCloud backup, requires no action, and includes updated user guidance without policy changes.
Starting late September 2026, Microsoft Viva Engage will require Microsoft Entra permissions—Yammer Administrator role or Community Admin assignment—for community and membership management tasks previously allowed to Verified or Network Admins. Administrators should review and update role assignments accordingly.
The hybrid join troubleshooting page was updated with revised guidance for AADSTS50034, and its date changed from July 27, 2025, to September 1, 2026.
The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.
The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.
The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”
The SAML App Gallery validation article adds lightbox support to screenshots and a Next step link to the validation-results section.
The user provisioning validation guide now uses an updated Microsoft Entra admin center URL with additional parameters.
The article was rewritten for provisioning groups from Microsoft Entra ID to Active Directory, adding updated setup steps, screenshots, and sections for scoping, attribute mapping, testing, and default settings. Previous combined users-and-groups guidance was removed, and a deprecation notice was added.
The article comparing group-only, user-only, and users-and-groups provisioning from Microsoft Entra ID to Active Directory was deleted, including guidance on scoping, configuration limits, and performance.
The documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.
The guidance now links to the group provisioning tutorial and its updated section on nested groups and membership references.
The article explaining how Microsoft Entra Cloud Sync provisions users, groups, and memberships to Active Directory was deleted.
The article was retitled and updated to focus on provisioning directory extensions to Active Directory with Cloud Sync, including group schema, scoping, and attribute mapping. Links now point to updated Cloud Sync resources and a group-provisioning scenario.
The article’s introduction now describes on-demand provisioning from Microsoft Entra ID to Active Directory and links to related guidance.
The article now documents selecting a group and up to five members for testing. User-specific instructions and result-review details were removed, and provisioning-direction references were updated.
The documentation now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.
The article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises Active Directory with Cloud Sync was deleted, along with its related links and next-step guidance.
The article describing the preview GroupDN setup for preserving a group’s organizational unit and name during Source of Authority conversion was deleted.