Product

Microsoft Entra ID

Track documentation and Message Center changes for Microsoft Entra ID.

Microsoft Learn documentation ↗

Latest Microsoft Entra ID changes

Sspr Policy

Authentication

The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”

Authentication

Authentication

The authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.

Connect Install Roadmap

Fundamentals

The page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.

Connect Passwordless Authentication

Authentication

The documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.

Connect Version History

General

The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.

Connect Version History

Authentication

The Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.

Connect Version History

Authentication

The version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.

Connect Version History

Provisioning

Microsoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.

Connect Version History

General

The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.

Connect Version History

General

The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.

Connect Version History

General

The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.

Connect Version History

General

The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.

Connect Version History

General

Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.

Connect Version History

General

The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.

Connect Version History

General

The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.

Connect Version History

Provisioning

The version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.

Connect Version History

Authentication

The Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.

Connect Version History

Provisioning

The documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.

Connect Version History

General

The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.

Connect Version History

General

The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.

Connect Version History

Authentication

The version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.

Connect Version History

Authentication

The documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.

Connect Version History

Security

The version history entry now links readers to the latest available Microsoft Entra Connect Sync version.

Connect Version History

General

The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.

Howto Sspr Windows

Authentication

The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.

Netskope Administrator Console Provisioning Tutorial

Authentication

The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Authentication

Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.

Sms Voice Retirement

Authentication

The documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.

Tshoot Connect Sso

Troubleshooting

The procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.

Using single sign-on with cloud sync

General

The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.

Whatis Azure Ad Connect

Provisioning

The page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.

Clear attribute values (Preview)

Provisioning

The documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.

Hr User Update Issues

Troubleshooting

The documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.

Microsoft Entra ID and Workday integration reference

Provisioning

The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.

Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Message CenterMC1426371 on mc.merill.net ↗Major updatePlan for change
Conditional Access

Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.

Configure

General

The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.

Microsoft Entra ID: Passkey support for B2B users

Message CenterMC1459133 on mc.merill.net ↗Stay informed
Conditional Access

Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.

Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

Message CenterMC1450133 on mc.merill.net ↗Stay informed
Conditional Access

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out in phases from October 2026 to February 2027, aims to increase adoption of phishing-resistant sign-in.

Migrate Microsoft Entra Enterprise State Roaming

General

As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.

Validate Oidc Multitenant App Gallery

General

The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.

Authentication Qr Code

Authentication

The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.

End-user experiences for applications

Developer

The documentation now states that these legacy preview and experience settings no longer affect app launchers or user behavior and are being removed from the Microsoft Entra admin center.

Fido2 Compatibility

Authentication

The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.

Licensing Service Plan Reference

General

Several licensing entries now use updated Microsoft 365 Copilot product names, including Education, Finance, and Sales offerings.

Licensing Service Plan Reference

General

Several entries now use Microsoft Copilot branding instead of Microsoft 365 Copilot branding. Their service plan identifiers and mappings remain unchanged in the documented rows.

Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details

Message CenterMC1470871 on mc.merill.net ↗Prevent or fix issue
Microsoft identity platform

User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a security issue. Applications needing this data must switch to User.Read.All or LicenseAssignment.Read.All permissions and update accordingly to avoid disruptions.

My Staff Configure

General

The page no longer identifies the legacy My Apps and My Staff settings as being under Manage user feature settings. It states that these settings are unused, do not affect behavior, and are being removed from the admin center.

Publish App Gallery

Developer

The app gallery publishing documentation now refers to the Microsoft Partner One ID and identifies Microsoft Partner Network (MPN) ID as its former name.

Tenant Estate Primary

Architecture

The tenant-estate architecture guidance now uses “Microsoft Copilot” instead of “Microsoft 365 Copilot.”

Use My Staff to delegate user management

General

My Staff access is now determined by administrative role assignments and their administrative unit scope. The legacy settings under Manage user feature settings no longer affect behavior and are being removed.

Validate Saml Single Sign On App Gallery

Standards

The article no longer includes guidance to confirm procedures for expired SAML signing certificates, propagation time, and cleanup with the Entra App Validator team before publication. It now directly presents the validation steps.

Validate Saml Single Sign On App Gallery

Standards

The documentation lists SAML capabilities that can be validated, including IdP- and SP-initiated SSO, SLO, application-specific claims, and user identifiers. It also states that applications should reject assertions signed with expired certificates and recommends reviewing validation logic if they do not.

Validate User Provisioning App Gallery

Provisioning

The documentation and screenshot alt text now refer to the field as “Submission ID” instead of “submission request ID.”

Validate User Provisioning App Gallery

Standards

The documentation now explains how to investigate failed validation tests using provisioning error details, recommendation URLs, and Logic App run details. It also lists common authentication, user, group, and SCIM compliance failures with recommended remedies.

Credential Management Api

Security

The Microsoft Entra External ID credential management API reference was deleted. It previously documented how applications let signed-in customers list, register, and delete passkeys.

Policy Teams Devices Device Code Flow

Monitoring

The instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.

Policy Teams Devices Device Code Flow

Monitoring

The guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.

Microsoft Entra: Optimized passkey registration campaign experience

Message CenterMC1469555 on mc.merill.net ↗Plan for change
Authentication

Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.

Sspr Writeback

Authentication

The documentation now states that when Cloud Sync and Connect Sync are configured for the same domain, Cloud Sync processes password writeback for users synchronized from that domain.

Enable Scim Api

Standards

The permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.

Enable Scim Api

Standards

The permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.

Entra Id Scim Api Reference

Standards

The SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.

Entra Id Scim Api Reference

Standards

The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.

Entra Id Scim Api Reference

Standards

The reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.

Entra Id Scim Api Schema Documentation

Standards

The schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.

Run a Registration Campaign to Set Up a Passkey or Microsoft Authenticator

Authentication

The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.

Configure HiBob to Active Directory hybrid user provisioning

Provisioning

New documentation explains how HiBob can provision and update users in on-premises Active Directory through Microsoft Entra API-driven provisioning and the provisioning agent. It covers prerequisites, permissions, configuration, and synchronization flow.

Delegate By Task

General

The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.

Least privileged roles by task

General

The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.

Permissions Reference

General

The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.

Permissions Reference

Authentication

The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.

Permissions Reference

Authentication

The role description now states that Security Administrators can perform identity containment actions during security incidents.

Privileged Roles Permissions

Monitoring

The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.

Whats New

General

The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.

Prerequisites to validate and publish your app

Developer

The documentation now instructs app publishers to provide a Partner One ID associated with their Microsoft AI Cloud Partner Program organization and explains how to find help if they do not know it.

Publish App Gallery

General

The documentation now describes submission states from Draft through Published, with example review and publishing timelines measured in business days. It notes that actual times vary based on submission completeness and validation.

Publish App Gallery

Standards

The app gallery publishing documentation now refers to the required identifier as a Partner One ID and notes that it was formerly called the Microsoft Partner Network (MPN) ID.

Test-only PFX password

Authentication

The documented password example now includes an exclamation mark at the end.

V2 Howto App Gallery Listing

General

The app gallery listing documentation now uses the Partner Program URL without the `/en-US` locale segment.

V2 Howto App Gallery Listing

General

The app gallery listing guide now uses shorter link text for the Microsoft AI Cloud Partner Program; the destination URL is unchanged.

Sample V2 Code

Microsoft identity platform

The Node.js Express and web application entries in the sample code documentation were updated, including their linked sample resources.

Troubleshoot STATUS_ACCOUNT_DISABLED in Microsoft Entra

Authentication

A new article explains how to diagnose intermittent STATUS_ACCOUNT_DISABLED sign-in and unlock errors on Microsoft Entra hybrid joined Windows devices, including relevant event logs and the stale-cache and connectivity conditions that can cause them.

Connect Install Roadmap

General

The roadmap now links to download ID 108777 for both the AD FS and AD DS Connect Health agents, replacing download ID 108565.

Microsoft Viva Engage: Microsoft Entra permissions required for community and membership administration

Message CenterMC1465773 on mc.merill.net ↗Major updatePlan for change
Security

Starting late September 2026, Microsoft Viva Engage will require Microsoft Entra permissions—Yammer Administrator role or Community Admin assignment—for community and membership management tasks previously allowed to Verified or Network Admins. Administrators should review and update role assignments accordingly.

Validate Oidc Multitenant App Gallery

General

The documentation now links to “Publish your app to Microsoft Entra App Gallery” instead of the “Submit your validation results” section.

Validate Oidc Multitenant App Gallery

General

The article adds lightbox links to four screenshots, adds a next-step link to submit validation results, and removes the app gallery publication request link.

Validate Saml Single Sign On App Gallery

Standards

The documentation link now directs readers to “Publish your app to Microsoft Entra App Gallery” instead of “Review and submit validation results.”

Deployment Options Provision To Active Directory

Fundamentals

The article comparing group-only, user-only, and users-and-groups provisioning from Microsoft Entra ID to Active Directory was deleted, including guidance on scoping, configuration limits, and performance.

Group Source Of Authority Configure

General

The documentation now points administrators to the Microsoft Entra Cloud Sync tutorial for provisioning groups to Active Directory Domain Services, replacing the previous provisioning overview and on-premises app governance links.

Group Source Of Authority Guidance

Fundamentals

The guidance now links to the group provisioning tutorial and its updated section on nested groups and membership references.

On Demand Provision

Provisioning

The article’s introduction now describes on-demand provisioning from Microsoft Entra ID to Active Directory and links to related guidance.

Plan Cloud Sync Topologies

Provisioning

The documentation now states that cloud-synced groups can contain only on-premises synchronized users and additional cloud-created security groups, and that all users must have `onPremisesObjectIdentifier`. The example link and diagram descriptions were also updated.

Prerequisites Provision Entra To Active Directory

Provisioning

The article covering prerequisites and license requirements for provisioning users and groups from Microsoft Entra ID to on-premises Active Directory with Cloud Sync was deleted, along with its related links and next-step guidance.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…