← Previous week
Week in brief

First-method passkeys begin October rollout as Entra documents V2 web filtering

The most consequential development is a Microsoft Entra rollout scheduled from October 2026 through February 2027 that will let users register a passkey or passwordless sign-in as their first multifactor authentication method, without first setting up weaker methods. Microsoft Learn also adds a new conceptual account of Entra Internet Access V2 web filtering and documents Preview browser support for Token Protection. The remaining changes are chiefly configuration, security, and documentation clarifications, including Agent ID consent rules and passkey opt-out permissions.

  • A Microsoft Entra Message Center notice says passkeys and other passwordless sign-in methods can be registered as a user’s first multifactor authentication method. Rollout is scheduled from October 2026 through February 2027, removing the need to establish weaker methods first; the notice indicates no administrator action is required.

  • A new concept article describes the V2 web-filtering model in Microsoft Entra Internet Access: one policy per security profile, multiple rules with individual actions, a default action, and URL-based FQDN destinations. Existing V1 web-content-filtering policies continue to function until migration.

  • The Token Protection page now documents Preview support for selected browser-based applications accessing Azure Resource Manager on Windows and macOS, while iOS and iPadOS browsers remain unsupported. It also adds browser, extension, operating-system, and configuration requirements and identifies the Windows Azure Service Management API resource for Conditional Access enforcement.

  • The updated flow guidance says Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated against the blueprint and child agent identity. It also clarifies that agent and child-agent identities cannot use interactive consent; delegated permissions must be preauthorized through inheritable blueprint permissions.

  • The passkey and Microsoft-provided SMS and voice authentication article now explicitly states that Microsoft Graph opt-out requests require the Policy.ReadWrite.AuthenticationMethod permission. This is a documentation clarification, but it gives administrators using Graph a concrete permission requirement to verify.

For Entra administrators

No administrator action is required for the first-method passkey rollout according to the Message Center notice. Administrators evaluating Internet Access V2 or browser-based Token Protection should review the documented policy model, coexistence rules, prerequisites, supported platforms, and Conditional Access resource. Teams using Agent ID on-behalf-of flows must preauthorize delegated permissions and use the documented audiences. Administrators opting out of passkey changes through Microsoft Graph must include Policy.ReadWrite.AuthenticationMethod.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

2

Microsoft Entra: Users can register a passkey or passwordless sign-in as their first multifactor authentication method

New

Users can now register passkeys or passwordless sign-in as their first multifactor authentication method in Microsoft Entra, eliminating the need to set up weaker methods first. This change, rolling out from October 2026 to February 2027, aims to increase adoption of phishing-resistant authentication without requiring admin action.

11 August 2026
Message CenterMC1450133 on mc.merill.net ↗Stay informed

Token Protection

Updated

The token protection article removes a screenshot of a Conditional Access policy requiring token protection as a session control. The Primary Refresh Token link remains.

10 August 2026
1
1

Token Protection

Updated

The page now documents browser-based application support in Preview for selected web apps accessing Azure Resource Manager on Windows and macOS. iOS/iPadOS browser support is not supported. The page also adds requirements for supported browsers, extensions, operating systems, and configurations.

10 August 2026
1

Discover identities in target applications with account discovery

Updated

The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.

11 August 2026
1

Optional Claims

Updated

The documentation now explains how to configure granular AMR values for SAML applications through the manifest or Microsoft Graph, since the admin center has no UI option for `include_granular_amr`. It also documents adding the `amr` claim to OIDC token types and clarifies that `include_granular_amr` applies only to SAML.

12 August 2026
1

Howto Analyze Provisioning Logs

Updated

The article’s Microsoft MCP Server for Enterprise overview and setup links changed from Microsoft Learn paths to the EnterpriseMCP GitHub repository. The article continues to describe the service as preview, global-service-only, and read-only.

12 August 2026
1

Orgvue Tutorial

Updated

The tutorial replaces the Orgvue authentication and SAML callback URLs with orgvue-staging URLs and changes the Sign-on URL to include the application login path and domain parameter. It also clarifies that both Reply URL and Sign-on URL values are placeholders.

10 August 2026
2

Agent On Behalf Of Oauth Flow

Updated

The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.

11 August 2026

Agent On Behalf Of Oauth Flow

Updated

The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.

11 August 2026
1

Web filtering in Global Secure Access (V2)

New

A new concept article documents the V2 web filtering model in Microsoft Entra Internet Access, including policies, rules, destination matching, and coexistence with V1 web content filtering.

12 August 2026
1

Custom Proxy File Hosting

Updated

The instructions now consistently use `efpUrl` instead of `efpURL` and explain that PAC file JavaScript is case-sensitive.

11 August 2026
2
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…