Sspr Policy
The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Authentication.
The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”
The authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.
The documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.
The Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.
The version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.
The Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.
The version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.
The documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.
The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.
The procedure now uses revised Microsoft Entra Connect paths and module-import commands, including the ADSync module and the AzureADSSO module. Step numbering and wording were also updated.
The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.
Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.
A how-to article explains how to enable FIDO2 and passkey methods, register credentials, configure a registry setting, and sign in to Microsoft Entra Connect Sync without a password.
The documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.
Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.
The documentation now distinguishes Microsoft-managed and enabled campaigns. It specifies the MFA method required for each targeted authentication method and broadens eligible users from SMS or voice sign-ins to users signing in with any MFA method.
A single article now documents how to add a configured OIDC, SAML/WS-Fed, or social identity provider to an External ID user flow, including prerequisites, permissions, portal steps, and testing.
The article now links to the authentication methods overview and the consolidated “Add an identity provider to a user flow” article instead of listing the Apple-specific setup steps inline.
The QR code authentication documentation now links to the main My Staff setup page instead of a specific section anchor.
The article now provides explicit prerequisites, required Microsoft Entra and SAP permissions, SAP IAS OIDC and JWT Trust-by-Issuer configuration details, and a clearer token flow and revocation explanation.
The article’s step-by-step instructions and screenshot for adding an OIDC provider to a user flow were replaced with a link to a consolidated guide.
The article now links to a consolidated guide for adding an identity provider to a user flow and reorganizes the sign-in and sign-up guidance. The duplicated setup and testing steps were removed.
The article now links to a consolidated guide for adding Facebook as an identity provider to a user flow and updates the section heading and introductory guidance.
The table now refers to “Microsoft Copilot (Office)” instead of “Microsoft 365 Copilot (Office)”; compatibility indicators are unchanged.
The article now directs administrators to a consolidated guide for adding Google as an identity provider to a user flow, instead of listing the steps inline.
The documentation no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and states that low-privilege passkey credential management APIs are on the roadmap.
Microsoft Entra is enhancing passkey registration campaigns to optimize user experience and increase phishing-resistant authentication adoption. Eligible users will be automatically prompted based on qualifying passkey profiles. Rollout begins early September 2026. Administrators should review campaign configurations and user assignments before rollout.
The documentation now explains how supported audit events can include DUSI, maps linkable identifiers to audit-log attributes, and provides steps for correlating sign-ins with administrative activity. Some events may not include DUSI.
The Entra documentation now uses the singular verb “needs” for “GitHub Actions” in an example about workload identities accessing Azure subscriptions.
The documentation now states that when Cloud Sync and Connect Sync are configured for the same domain, Cloud Sync processes password writeback for users synchronized from that domain.
The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
Microsoft Entra ID is optimizing passkey registration to better align with administrator policies, prioritize local device passkeys, and improve successful registrations without UI changes. The rollout begins late August 2026, completing by mid-September. No action is required; organizations should continue promoting passkey adoption.
The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.
The role description now states that Security Administrators can perform identity containment actions during security incidents.
The page title and heading no longer include “(preview).”
The documented password example now includes an exclamation mark at the end.
The documentation now states that Microsoft-managed system-preferred authentication deployment will continue through September 2026, rather than August 2026.
A new article explains how to diagnose intermittent STATUS_ACCOUNT_DISABLED sign-in and unlock errors on Microsoft Entra hybrid joined Windows devices, including relevant event logs and the stale-cache and connectivity conditions that can cause them.
Microsoft Entra improves the iOS Microsoft Authenticator app's passkey restore experience with a clearer, guided flow for device migration, launching worldwide mid-September 2026. It affects iOS users with iCloud backup, requires no action, and includes updated user guidance without policy changes.
The Conditional Access documentation now describes Android Microsoft Authenticator’s use of the Google Play Integrity API for jailbreak detection and the resulting access denial if the API is unavailable.
The updated Conditional Access documentation states that Microsoft Authenticator on Android uses Google Play Integrity API for jailbreak detection. If the API is unavailable, requests are denied unless the policy is disabled.
The Conditional Access documentation now describes Microsoft Authenticator for Android using Google Play Integrity API for jailbreak detection and denying access when the API is unavailable, unless the policy is disabled.
The documented query now filters for UserId `00aa00aa-bb11-cc22-dd33-44ee44ee44ee` instead of the previous identifier.
The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.
The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.
The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.
The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.
The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.
The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.
The password migration documentation now uses a different example API application identifier.
Microsoft Entra now applies system-preferred authentication to first-factor sign-ins for tenants in the Microsoft managed state, selecting the most secure registered method. Rollout is from late June to late September 2026. Tenants can keep or change this setting and should update user guidance accordingly.
Microsoft Entra External ID now documents an API that lets applications list, register, and delete signed-in customers’ passkeys using delegated access tokens.
The documentation now describes using the preview credential management API with delegated permissions so signed-in customers can list, register, and delete their own passkeys. It also clarifies that the sample uses high-privilege administrator provisioning and is for testing.
The security key entry’s table formatting was corrected by removing an extra space before a separator.
Several FIDO2 hardware vendor entries were reordered to restore their previous sequence. Product names, identifiers, and support indicators remain unchanged.
The vendor table was re-rendered in its original order, with minor whitespace and line-formatting changes. Vendor names and support indicators are unchanged.
The documentation updates compatibility indicators for several Arculus, Feitian, Hyper FIDO, and IDmelon authenticators and removes multiple vendor entries.
The documentation now reflects FIDO Metadata Service version 275, with updated FIDO2 model entries, AAGUIDs, and capability indicators, including newly listed authenticators.
The document date changed from August 18 to August 20, 2026, and existing vendor entries were reordered. Their displayed identifiers and support indicators remain unchanged.
Microsoft Entra ID will retire custom CSS layout and positioning properties in company branding by late October 2026 to enhance security and reduce phishing risks. Organizations using these properties must update branding configurations before then; new use will be blocked from July 21, 2026. Branding will revert to default layouts after retirement.
The documentation now states that, after July 21, 2026, eligible tenants without existing custom CSS cannot configure it. It also expands the list of layout and positioning properties that will eventually be blocked and updates the inspection steps.
The documentation now states that tenants created after January 5, 2026, cannot use custom CSS. After July 21, 2026, older tenants not already using it cannot configure it, and support for custom CSS layout and positioning properties is being retired.
The documentation now covers custom CSS layout and positioning properties, and updates its publication date to August 18, 2026. It describes support for these properties as being retired under the Secure Future Initiative.
The deployment guide no longer states that Platform SSO for macOS uses hardware-backed storage by default. The Intune setup link remains unchanged.
The reference now distinguishes `hwk` for multifactor CBA from `x509` for single-factor CBA, adds device-based X.509 authentication, and explains that `x509` alone does not indicate phishing-resistant MFA.
The documentation now identifies device-based X.509 authentication with the `x509` AMR value and explains that `x509` alone does not meet phishing-resistant MFA requirements. An additional authentication factor is required.
New documentation explains how the policy blocks federated sign-ins when the trusted realm and mapped user account have different root domains. It also documents the related Microsoft Graph beta APIs.
The documentation now states that disabling the Entra device blocks new token issuance, revokes user sessions, and prompts the user to sign in again. It no longer mentions revoking existing device-bound refresh tokens.
The guidance now states that authentication strength policies cannot currently be applied to external users authenticating through Microsoft personal (MSA) accounts, alongside the previously listed methods. It directs administrators to use the MFA grant control instead.
The Agent ID token claims documentation no longer includes one `tid` claim table row.
The page description was shortened by removing the phrase “Key concepts.” The documented OAuth 2.0 protocols and token exchange patterns remain unchanged.
The documentation now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” and expands “SPA” to “single-page application.” The described authentication flows and responsibilities are otherwise unchanged in the supplied diff.
The autonomous agent authentication and authorization flow documentation now adds `using Microsoft.Identity.Web;` to a C# setup sample.
The error-code documentation now separates quota, blueprint, blueprint principal, agent identity, and agent identity creation errors, with clearer descriptions and table headings.
The documentation replaces inconsistent tenant placeholders with `<your-tenant-id>` and standardizes `<agent-blueprint-clientid>` to `<agent-blueprint-client-id>` in code samples.
The documentation replaces “Device disablement” with “Attacker-added device” and explains that the Entra device object is disabled, new token issuance is blocked, existing device-bound refresh tokens are revoked, and user sessions are revoked.
The documentation now describes a Device disablement response for users flagged by Microsoft threat intelligence as having an attacker-added device. The device is disabled, and the user is prompted to sign in from a trusted device.
The article now consistently refers to the sidecar integration as the Microsoft Entra ID Auth SDK instead of the Microsoft Entra Auth SDK. The integration guidance is otherwise unchanged.
The interactive agent authentication and authorization documentation now includes `using Microsoft.AspNetCore.Authentication.JwtBearer;` in its C# setup samples.
The documentation now consistently uses `<your-tenant-id>` instead of `<my-test-tenant>` or `<your-test-tenant>` in PowerShell, OAuth URLs, and JSON examples.
The article title and heading no longer include “(preview).” No other change is shown.
The local-development article now consistently uses “Microsoft Entra ID Auth SDK (sidecar)” instead of “Microsoft Entra Auth SDK,” including its title, description, intent, link text, and container description.
The page title and heading no longer include “(preview).” No other change is shown, and the diff does not explicitly announce general availability or a product launch.
The documentation now refers to the “Microsoft Entra ID Auth SDK (sidecar)” instead of the “Microsoft Entra SDK auth sidecar.” The token-validation guidance is otherwise unchanged.
The page updates image accessibility text, refines wording about agent identities, and standardizes the name “Microsoft Entra ID Auth SDK (sidecar)” for third-party agent integrations.
Microsoft will retire SMS first-factor sign-in for Microsoft Entra ID Free tenants on August 11, 2026, due to fraud risks. Users must switch to other authentication methods before then. SMS as a multifactor method remains unaffected. Admins should identify affected users and update authentication policies accordingly.
The heading changed from “Workaround for newly added Staged Rollout users” to “Workaround to avoid one additional federated sign-in.” No procedural content changed in the supplied diff.
The documentation, dated August 11, 2026, replaces general transition text with scenarios describing additional interactive sign-ins when users are added to or removed from Staged Rollout. It also covers certain Microsoft Entra ID Protection remediation events, including SSPR and risk remediation.
The documentation now states that opting out requires the Microsoft Graph `Policy.ReadWrite.AuthenticationMethod` permission. The page date changed from July 29 to August 10, 2026.
The documentation now says Microsoft may enable managed policies at least 30 days after introduction when they remain in Report-only, instead of 45 days. It also documents that a security group is created with the high-risk remediation policy.
The documentation now describes Microsoft Entra joining as intended for Arc-enabled machines planned not to join another domain, replacing the stronger “can't join” wording. It still directs administrators to disconnect from Microsoft Entra by uninstalling the extension if another domain join is needed.
The page now uses “Choose Your Own Telephony Provider” instead of “customer-managed telephony providers,” updates wording throughout, and changes its date to August 5, 2026. It retains the stated availability dates: provider information from September 18, 2026, and configuration from October 30, 2026.
A new concept article explains planned customer-managed providers for SMS and voice authentication. Provider information is expected beginning September 18, 2026, with configuration beginning October 30, 2026; providers aren't available to configure yet.
The documentation changes the registration campaign date from August 6 to November 9, 2026, and the date for accepting only explicitly registered methods from September 7 to October 5, 2026.
GitHub Actions now supports immutable OIDC subject formats with repository and owner IDs to enhance Microsoft Entra federated identity security. Organizations using GitHub Actions OIDC must migrate to this format by late July 2026 to prevent token mismatches and reduce unauthorized access risks.
Starting November 9, 2026, Microsoft Entra ID SSPR will require explicitly registered authentication methods for password reset verification, disallowing directory-sourced contact info unless registered. A registration campaign begins October 5, 2026. Organizations must ensure users register methods to avoid reset failures.
The updated documentation says passkeys will be automatically enabled for users using SMS or voice on September 1, 2026. From February 1, 2027, tenants without a customer-managed telecom provider will no longer be able to use SMS or voice for MFA. The timeline applies to public cloud; Azure AD B2C and Entra External ID are excluded from this announcement.
Microsoft Entra ID will retire support for custom CSS positioning properties in company branding starting October 2026 to enhance security and phishing resistance. Existing users must remove these properties by then, as no migration path exists. Branding elements remain visible but may revert to default placement.
This timeline applies to public cloud environments only. Other cloud environments will follow on a later schedule, and we will provide advance communications to help customers prepare for the transition.
Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
| `exp` | int, a Unix timestamp | Specifies the expiration time before which the JWT can be accepted for processing. A resource may reject the token before this time as well. The rejection can occur for a required change in authentication or when a token is revoked. | |
|Username and password (not recommended or supported by Microsoft Entra ID)|Easy to implement|Insecure - [Your Pa$$word doesn't matter](https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/your-pa-word-doesn-t-matter/ba-p/731984)|Not supported for new gallery or non-gallery apps.|
Microsoft Entra will enable passwordless users to change their passwords via My Sign-Ins using strong credentials like passkeys or Windows Hello, without knowing the current password or using SSPR. This feature, disabled by default, requires admin activation and will roll out globally in late October 2026.
Reference guide for the CSS template selectors for customizing Microsoft Entra sign-in page company branding.
Instructions about how to add your organization's custom branding to the Microsoft Entra sign-in experience.
Learn how to create branding themes and apply them to the sign-in experience for your application in Microsoft Entra ID.
Passkey support for B2B users and internal guest users is planned to be available by the end of calendar year 2026. These users are included in the scope of the retirement of Microsoft-provided SMS and voice authentication.
- They work with all Microsoft Entra-integrated third-party apps at the authentication plane during sign-in.
Starting March 2026, Microsoft Entra ID will GA passkey profiles and synced passkeys for tenants with Passkeys (FIDO2) enabled. Existing configurations migrate to a Default passkey profile with a new passkeyType property. Automatic migration and registration campaign updates roll out regionally through October 2026.
Microsoft Entra is replacing legacy CAPTCHA in self-service password reset with backend throttling and behavior-based abuse detection to enhance security and accessibility. The rollout starts early August 2026, requires no user or admin action, and maintains current password reset functionality without introducing new controls.
Access tokens are a type of security token designed for authorization, granting access to specific resources on behalf of an authenticated user. Information in access tokens determines whether a user has the right to access a particular resource, similar to keys unlocking specific doors in a building. These individual pieces of information that make up tokens are called claims. Therefore, they are sensitive credentials and pose a security risk if not handled correctly. Access tokens differ from [ID tokens](./id-tokens.md) which serve as proof of authentication.
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Netskope User Authentication.
You can configure Explicit Forward Proxy (preview) to rely on the private IP addresses of devices on your network to associate authenticated users with their devices. To use HTTP header session management with Explicit Forward Proxy, you need to securely communicate the private IP address of the device to the Explicit Forward Proxy feature.
Learn how to prepare for the retirement of Microsoft provided SMS and Voice authentication in Microsoft Entra ID and migrate users to passkeys.
Learn how to back up and restore Microsoft Authenticator account entries when you switch to a new phone, including passkey setup steps.
Learn about mandatory multifactor authentication (MFA) enforcement for Azure, Microsoft 365, and other admin portals, and how to prepare your tenant.
Learn about Authenticator-specific requirements, configuration, and troubleshooting for passkeys in Microsoft Authenticator for Microsoft Entra ID.
Learn how Microsoft Entra passkey on Windows enables phishing-resistant authentication with work or school accounts by using Windows Hello as a FIDO2 passkey provider.