← Previous week
Week in brief

Microsoft Entra sets passkeys as default and schedules Microsoft-provided SMS and voice retirement

Authentication drove the week: passkeys became Microsoft Entra’s default authentication on September 1, 2026, while Microsoft-provided SMS and voice authentication now has staged 2027 retirement dates. Other substantive updates cover first-MFA passkey registration, an October B2B passkey rollout, browser handoff guidance for External ID, and preview Continue Evaluation behavior in Web Filtering (v2). Much of the remaining activity was maintenance to Connect and Connect Health navigation, screenshots, release-history links, and terminology.

For Entra administrators

Identify users dependent on SMS or voice and move them to phishing-resistant methods before their applicable deadline; if those methods must remain, use a customer-managed telecom provider. Review B2B authentication policies before the October rollout, although Microsoft says no immediate action is required. For External ID, check the supported browser, broker, app, platform, federation, and cloud combinations before adoption. In Web Filtering (v2), review default actions and keep the Baseline Profile set to Allow or Block.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

19

Microsoft Entra Connect Health operations

Doc update

The article updates navigation and steps for email notifications, server or service deletion, and role-based access control, with new screenshots.

18 September 2026

Connect Health Adfs

Doc update

The documentation now describes the AD FS service overview, updated alert filtering and details, and the revised Usage Analytics experience with time-range controls. Screenshots and metadata were also refreshed.

18 September 2026

Connect Health Data Retrieval

Doc update

The guide now uses the Microsoft Entra Connect Health Sync errors area to access notification settings, review Global Administrator and custom recipients, and export recorded sync errors as a CSV from the command bar.

18 September 2026

Health service data isn't up to date alert

Doc update

The page now explains selecting an alert row to view its details, including detection times, affected servers, resolution guidance, and related documentation. It also replaces the alert screenshot and improves image descriptions.

18 September 2026

Connect Version History

Feature update

The documentation adds release notes for an upcoming version with Delos sovereign cloud support, authentication and connector behavior changes, bug fixes, and security improvements. The version and release date remain TBD.

16 September 2026

Connect Version History

New featureAction required

The 2.6.90.0 release adds a guided migration workflow from Microsoft Entra Connect Sync to Cloud Sync, including assessment, agent setup, staged activation, validation, and rollback. It is available only in the Azure public cloud.

16 September 2026

Connect Version History

Doc update

The entry now uses “phishing-resistant authentication” instead of “passwordless authentication” and updates the page date to September 14, 2026.

16 September 2026

Connect Version History

Doc update

The version history table adds a Release date column for listed Microsoft Entra Connect versions while retaining end-of-support dates.

16 September 2026

Connect Version History

Doc updateAction required

The documentation replaces version 2.6.90.0 with 2.6.91.0 and updates related guidance, including the 2.6.84.0 support timeline and fixes for existing-database upgrades and Synchronization Service Manager crashes.

16 September 2026

Connect Version History

Doc updateAction required

The documentation replaces references to version 2.6.90.0 with 2.6.91.0, updates related fix guidance, and identifies 2.6.91.0 as the latest available version.

16 September 2026

Connect Version History

Doc update

The documentation metadata and release entries now show September 16, 2026 instead of September 15, 2026 for version 2.6.91.0 and its related timeline.

16 September 2026

Connect Version History

Doc update

Four references to version 2.6.91.0 now point to the correct documentation section, #26910, instead of #26900.

16 September 2026

Connect Version History

Feature update

The documentation now records a fix for an issue where reopening the wizard and expanding a fully deselected domain could reselect it and enable synchronization for the entire domain.

16 September 2026

Connect Version History

Doc updateAction required

The documentation now requires importing `ADSync.psd1` before `AzureADSSO.psd1` when configuring Seamless Single Sign-On with the standalone module.

16 September 2026

Connect Version History

Doc update

The documentation now states that the Select Containers dialog remains available for viewing selections, while changes should be made through Customize synchronization options in the Microsoft Entra Connect wizard.

16 September 2026

Using single sign-on with cloud sync

Doc update

The article’s publication date changed from April 9, 2025, to September 15, 2026, and an AI-assisted usage marker was added.

16 September 2026

Migrate Microsoft Entra Enterprise State Roaming

RetirementAction required

As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.

14 September 2026

Validate Oidc Multitenant App Gallery

Doc updateAction required

The documentation now states that applications using Microsoft identity platform v1 endpoints cannot be validated through self-service App Gallery onboarding. It recommends migrating to v2 endpoints.

14 September 2026

Configure

Doc update

The configuration guide no longer includes the note about synchronization service account creation and possible errors involving multifactor or interactive authentication.

14 September 2026
15

Sspr Policy

Doc update

The SSPR policy documentation now uses “Microsoft Entra administrators” instead of “Azure administrators.”

17 September 2026

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

RetirementAction required

Microsoft-provided SMS and voice authentication retires February 1, 2027, for users including internal guests. Global Administrators and external users follow a later July 1, 2027 retirement date. Users whose only MFA method is SMS or voice will receive a blocking passkey-registration prompt after their applicable date.

16 September 2026

Sms Voice Retirement

RetirementAction required

The documentation clarifies that Global Administrators and external users are affected on July 1, 2027, while internal guest users follow the February 1, 2027 date. Users can continue using phishing-resistant methods such as passkeys.

16 September 2026

Howto Sspr Windows

Doc update

The instructions replace the custom OMA-URI profile process with a Microsoft Intune Settings Catalog policy. Administrators now select **Authentication > Allow Aad Password Reset** and set it to **Allow**.

16 September 2026

Connect Version History

Doc update

The Microsoft Entra Connect version history page removes Learn more links from entries covering WAM and phishing-resistant authentication. The descriptions remain unchanged.

16 September 2026

Authentication

Doc update

The authentication overview now shows “No” for Microsoft Authenticator push notifications in the affected status column; the method remains listed for MFA and SSPR.

16 September 2026

Connect Passwordless Authentication

Doc update

The documentation page describing passwordless sign-in for Microsoft Entra Connect Sync, including setup, credential registration, registry configuration, and sign-in steps, was deleted.

16 September 2026

Netskope Administrator Console Provisioning Tutorial

Doc update

The tutorial replaces the previous SCIM token steps with instructions to create an OAuth2 service account, copy its Client ID and Client Secret, and select OAuth2 Client Credentials Grant. Screenshots and navigation steps were also refreshed.

16 September 2026

Connect Version History

Doc updateAction required

The documentation now states that Select Containers is read-only, clarifies the existing ADSync database error, and lists failures in version 2.6.84.0 plus a Connector Properties crash.

16 September 2026

Connect Version History

Doc update

The version history page now uses “Learn more” as the link text to the cloud sync SSO instructions. The documented PowerShell import order is unchanged.

16 September 2026

Connect Version History

Doc update

The version history entry now states that the Generic LDAP connector validates the TLS server certificate chain and server name, removing the detailed rejection conditions.

16 September 2026

Connect Version History

Doc update

The Connect version history page no longer states that the Generic LDAP connector wizard validates the TLS server certificate chain and server name.

16 September 2026
9

Connect Version History

Feature updateAction required

Microsoft Graph permissions have been added to Microsoft Entra Connect. Administrators using app-scoped Conditional Access policies should review policies targeting Microsoft.Azure.SyncFabric or Microsoft 365 Reporting Service.

16 September 2026

Connect Version History

Doc update

The version history now refers to an additional sovereign cloud environment instead of naming Delos. Support for Pass-through Authentication, Seamless SSO, password writeback, and Health Agent monitoring remains listed.

16 September 2026

Whatis Azure Ad Connect

Doc update

The page now describes Connect Health as providing monitoring data in one place and directs administrators to the Microsoft Entra admin center for alerts, performance monitoring, usage analytics, synchronization errors, and service information.

16 September 2026

Connect Version History

Doc update

The documented workflow now covers configuration assessment, provisioning agent setup, staged activation, and validation. Rollback is no longer included, and the workflow remains limited to the Azure public cloud.

16 September 2026

Clear attribute values (Preview)

Feature update

The documentation adds preview support for clearing mapped target attributes through Workday and SAP SuccessFactors inbound provisioning, with configuration, schema, testing, and troubleshooting guidance.

15 September 2026

Microsoft Entra ID and Workday integration reference

Doc update

The reference explains how optional single-valued source attributes can clear mapped target attributes when Workday returns null or empty values, with configuration guidance linked.

15 September 2026
6

Diagnose and remediate duplicated attribute sync errors

Doc update

The article now documents the guided workflow for duplicate-attribute errors, including finding affected objects, opening Error Details, using Troubleshoot, reviewing proposed resolutions, and applying supported fixes. Status descriptions and diagnostic images were also updated.

18 September 2026

Tshoot Connect Sso

Doc update

The procedure now imports the ADSync PowerShell module before importing the Seamless SSO module, with updated command and path details.

16 September 2026

Hr User Update Issues

Doc update

The documentation now explains that target attributes are cleared only when **Flow null values** is enabled for both the source attribute and target mapping. It also documents options to clear, preserve, or replace empty values.

15 September 2026
4

Microsoft Entra ID: Follow-up on SMS first-factor sign-in retirement and upcoming changes

New

Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide starting February 1, 2027, to enhance security. Organizations must identify affected users, migrate them to phishing-resistant methods like passkeys, and update policies to avoid sign-in disruptions and comply with new requirements.

18 September 2026
Message CenterMC1474104 on mc.merill.net ↗Major updatePlan for change

Microsoft Entra: Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

New

Passkeys became the default Microsoft Entra authentication on September 1, 2026. Microsoft-provided SMS and voice authentication will retire February 1, 2027, requiring customers to use telecom providers from the Microsoft Security Store. Transition to passkeys is recommended for stronger, phishing-resistant security.

15 September 2026
Message CenterMC1426371 on mc.merill.net ↗Major updatePlan for change

Microsoft Entra ID: Passkey support for B2B users

New

Microsoft Entra ID will support passkey registration and sign-in for B2B users, enabling phishing-resistant MFA using resource tenant passkeys. Rollout begins October 2026, with automatic enablement for eligible users. Administrators should review authentication policies and configurations; no immediate action is required.

14 September 2026
Message CenterMC1459133 on mc.merill.net ↗Stay informed
4

The Risky IP report

Retirement

The documentation now notes that the AD FS Risky IP report is being deprecated and links to the Risky IP report workbook. It also updates portal navigation, export handling, notification settings, and threshold guidance.

18 September 2026

Using Microsoft Entra Connect Health with AD DS

Doc update

The guide now documents the updated service overview, alert details and search, domain controller filtering and column options, replication error details, and 24-hour authentication performance charts.

18 September 2026

Sla Performance

Doc update

The August row on the SLA performance reference page now shows 99.999% in the previously blank final metric column.

18 September 2026
1

Connect Install Roadmap

Doc update

The page now directs administrators to Microsoft Entra Connect Health in the Microsoft Entra admin center and documents updated navigation for Sync, AD FS, AD DS, settings, troubleshooting, and support. It also clarifies that agents must be installed before monitoring data appears.

16 September 2026
1
1

Connect Version History

Doc updateAction required

The version history entry now links readers to the latest available Microsoft Entra Connect Sync version.

16 September 2026
1
6

View reports and logs in entitlement management

New feature

The documentation adds access package drift reporting for groups and enterprise applications, including detection, remediation, export, roles, licensing, refresh timing, and limitations. The reports are in preview.

18 September 2026

Extend Application Attributes

Doc update

The documentation now uses clearer wording for configuring LCW extensibility workflow mappings, creating an Azure Logic App and workflow, and configuring provisioning jobs with attribute mappings.

16 September 2026

Licensing

Doc update

The Tenant Governance licensing page now links to Microsoft Agent 365 licensing FAQs and guidance for using governance relationships with Microsoft Defender.

14 September 2026

Entitlement Management Access Package Create

Doc update

The access package creation documentation now explains that the search box can find matching SharePoint Online roles that are not initially displayed, especially on sites with many roles.

14 September 2026

Entitlement Management Access Package Resources

Doc update

The documentation now recommends using the search box to find SharePoint Online roles when adding them to an access package. Search returns matching roles even when they are not initially displayed.

14 September 2026

Licensing

Doc update

The licensing documentation’s Microsoft author alias was updated from `tafra00` to `tazkiaafra`.

14 September 2026
3

Microsoft Entra ID Governance licensing fundamentals

Doc update

The licensing fundamentals page was updated to align the Account Discovery section and state that the feature requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite.

14 September 2026

Licensing

Doc update

The page now lists the Microsoft Agent 365 Licensing FAQs and governance relationships links without the previous section heading and introductory text.

14 September 2026
1

Browser authentication for external identity providers in Microsoft Entra ID

New feature

Microsoft Entra can hand brokered external-IdP authentication from an embedded WebView to the system browser, enabling external-IdP passkeys, browser SSO, and IdPs that block WebViews. The documentation lists supported platforms, brokers, versions, apps, and cloud availability.

15 September 2026
1
1

Web filtering in Global Secure Access (V2)

New feature

The documentation now describes a preview Continue Evaluation default action. Unmatched traffic can pass to the next applicable security profile, while matching rules and Allow or Block stop evaluation. The Baseline Profile must use Allow or Block.

17 September 2026
1
1
1

Learn about Universal Continuous Evaluation

Feature update

The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.

17 September 2026
1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…