← Previous week
Week in brief

System-preferred first-factor sign-ins roll out ahead of automatic Windows Global Secure Access upgrades

Microsoft’s strongest administrator-facing changes this week are behavioral and rollout-related: in Microsoft-managed tenants, system-preferred authentication now applies to first-factor sign-ins, while eligible Windows Global Secure Access clients are slated to upgrade through Windows Update from November 2026. Entra’s Linux broker guidance also changes the device-trust path, and Lifecycle Workflows gain a longer relative-date window. Much of the remaining activity is documentation maintenance, including sample-ID replacements and App Gallery guidance.

  • For tenants in the Microsoft managed state, Entra now selects the most secure registered method for first-factor sign-ins. Rollout runs from late June through late September 2026; tenants can keep or change the setting, and Microsoft says user guidance should be updated.

  • Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 adds Prefer local network, faster tunnel creation, and other fixes; administrators can opt out with the documented installer parameter and maintain updates manually.

  • For Microsoft Single Sign-On for Linux version 2.0.2 and later, device trust uses Microsoft Entra join instead of device registration. Existing upgraded devices must be re-joined and re-enrolled; the guidance calls for allowing device joins, removing broker state, reinstalling the broker, and re-joining devices.

  • The allowed offset for Days from event, and Days to event when using Between, increased from 180 to 365 days. Administrators can configure lifecycle workflow conditions for events up to one year before or after the relevant date.

  • The new setting can source sAMAccountName from onPremisesSamAccountName. Existing domains retain current behavior until the setting is enabled; enabling it updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation. The setting applies to Enterprise or Premium managed domains and requires Application Administrator and Groups Administrator roles.

For Entra administrators

Update first-factor sign-in guidance and decide whether to retain or change the system-managed authentication setting. For Global Secure Access, inventory eligible Windows clients, review minimum versions, and choose Windows Update or the documented opt-out and manual-update path. For Linux broker upgrades, allow device joins and plan removal, reinstall, rejoin, and re-enrollment. Also review Lifecycle Workflow date windows and sAMAccountName source values and application dependencies before using those options.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

10

Breaking Changes

Doc update

The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.

26 August 2026

Breaking Changes

Doc update

The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.

26 August 2026

SSO requirements for Microsoft Entra App Gallery

Doc update

Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.

26 August 2026

Groups Settings V2 Cmdlets

Doc update

The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.

26 August 2026

Breaking Changes

Doc update

The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

25 August 2026
8

Prerequisites to validate and publish your app

Doc update

The documentation separates shared prerequisites from SSO and SCIM requirements, with dedicated guidance for each capability. Applications supporting both must complete validation for both.

26 August 2026

Prerequisites to validate and publish your app

Doc update

The article now covers prerequisites for validating and publishing apps, with updated wording and links. Detailed portal submission, request tracking, implementation, and update/removal instructions were removed.

26 August 2026

Howto Update Permissions

Doc update

The permission-addition and permission-removal examples now use different sample object and client IDs.

26 August 2026

Howto Update Permissions

Doc update

The add and remove permission examples now use app registration ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.

26 August 2026

Howto Update Permissions

Doc update

The examples for adding and removing Microsoft Graph permissions now use app registration identifier `00001111-aaaa-2222-bbbb-3333cccc4444` instead of the previous sample identifier.

26 August 2026

Howto Update Permissions

Doc update

The Microsoft Graph Update application example now uses a different app registration object ID when adding the documented delegated permissions.

26 August 2026

Howto Update Permissions

Doc update

The permission-management examples now use app registration identifier `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444` when adding or removing Microsoft Graph permissions.

25 August 2026
7

Strengthen federated sign-in security

Doc update

The documentation now distinguishes standard token validation, user mapping, and authentication policy checks from the additional domain-consistency validation provided by Federated Token Validation Policy. It also clarifies root-domain matching for federated sign-ins.

26 August 2026

Howto Arc Sign In Windows

Doc update

The documentation wording about Microsoft Entra joining Arc-enabled machines and disconnecting them from another domain was updated.

25 August 2026

Howto Arc Sign In Windows

Doc update

The how-to documentation revised its guidance explaining that enabling the capability joins an Arc-enabled machine to Microsoft Entra and is intended for machines not joined to another domain.

25 August 2026

Howto Arc Sign In Windows

Doc update

The guidance on enabling sign-in for Arc-enabled machines was revised, including their Microsoft Entra join behavior and domain-joining scenario.

25 August 2026

Howto Arc Sign In Windows

Doc update

The documentation fixes a typo in the sentence explaining that an Arc-enabled machine becomes Microsoft Entra joined and updates nearby truncated wording.

25 August 2026

Howto Arc Sign In Windows

Doc update

The documentation now states that this capability is intended for Arc-enabled machines not planned to join another domain, such as on-premises Active Directory or Microsoft Entra Domain Services.

25 August 2026
7

Publish your app to Microsoft Entra App Gallery

Doc update

A tutorial now documents the self-service publishing workflow, including validation prerequisites, submission creation, capability selection, required application details, Microsoft review, and draft tracking.

26 August 2026

Plan Sso Deployment

Doc update

Removed an extra space from the Help desk admin row in the documentation table.

26 August 2026

Whats New Linux

Feature updateAction required

Starting with broker version 2.0.2, Microsoft Single Sign-on for Linux uses Microsoft Entra join instead of registration for device trust. Existing upgraded devices must be re-joined and re-enrolled.

25 August 2026

Connect Health Version History

Doc update

The version history now records agent version 4.5.2614.0, including credential-security and key-rotation improvements, better cloud compatibility and telemetry resilience, and installation, registration, reliability, and quality improvements.

24 August 2026

Connect Health Agent Install

Doc update

The installation documentation now points to download ID 108777 for the AD FS and AD Domain Services agents instead of 108565.

24 August 2026
1

Clean broker state including certificates (requires sudo)

Feature updateAction required

Microsoft Single Sign-on for Linux version 2.0.2 and later uses Microsoft Entra join for device trust instead of device registration. The documentation also adds MSAL integration support guidance and updates device removal terminology.

25 August 2026
1

Primary Refresh Token

Doc update

The documentation now references the Chrome Windows 10 Accounts extension and Mozilla Firefox v91+ Windows SSO setting.

25 August 2026
1
1

SAM Account Name

Public preview

Enhanced synchronization can source sAMAccountName for hybrid users from onPremisesSamAccountName in Microsoft Entra ID. Existing domains retain current behavior until enabled; enabling updates existing hybrid users during synchronization, while cloud-only users without the source value continue using mailNickname-based generation.

25 August 2026
1

Manage Device Identities

Feature update

The documentation now states that the “Users may join devices to Microsoft Entra ID” setting applies to Windows 10 or newer, macOS, and Linux. It also adds troubleshooting guidance to verify registration or join settings when users encounter errors.

25 August 2026
9

Create Tenant

Doc update

The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.

26 August 2026

Create Tenant

Feature updateAction required

The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.

26 August 2026

Understanding Lifecycle Workflows

Public preview

The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.

24 August 2026

Create Lifecycle Workflow

Public preview

Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.

24 August 2026

Lifecycle Workflow Execution Conditions

Public preview

Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.

24 August 2026

Entitlement Management Request Behalf

Doc update

The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.

24 August 2026

Create Lifecycle Workflow

Doc update

The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.

24 August 2026
1

Understanding Lifecycle Workflows

Public preview

The documentation now describes the Time based attribute V2 trigger, including Exactly, Less than or equal to, and Between comparisons with offsets from 0 to 180 days before or after a date attribute. It also documents that workflows and schedules must be enabled and that V2 has no three-day catch-up window.

24 August 2026
1
7

Global Secure Access Client Release Notes

New feature

Starting in November 2026, eligible Windows clients automatically receive Global Secure Access upgrades through Windows Update. Version 2.32.294 also adds Prefer local network, faster tunnel creation, and other fixes and improvements.

26 August 2026

Current Known Limitations

Doc update

The documentation now uses the full names for GCC and GCC-H and clarifies that Global Secure Access is available in GCC but not yet supported in GCC-H, Department of Defense, or other government or sovereign cloud environments.

26 August 2026

Current Known Limitations

Doc update

The documentation received a minor formatting change with no substantive content changes identified.

26 August 2026

Current Known Limitations

Doc update

The documentation now explicitly states that Global Secure Access is available in GCC, but not supported in GCC-H, Department of Defense, or other government and sovereign cloud environments.

26 August 2026

Global Secure Access Client for macOS Release Notes

New feature

The August 21, 2026 release adds Home Network traffic controls, a Connections page, agentic detection support, and Secure DNS bypass. It also includes connectivity, sign-in, tunnel, cache-reset, and crash fixes.

24 August 2026

Install the Global Secure Access Client for macOS

Doc update

The documentation now states that version 1.1.26060207 includes com.microsoft.autoupdate2 and that an existing installation may conflict with Intune detection rules. It also advises optionally removing that app from the Included apps list.

24 August 2026

Macos Client Release History

Doc update

The release history now lists the macOS client as available for download on August 24, 2026, instead of August 21, 2026.

24 August 2026
1

Netskope Integration

Doc update

The Netskope integration example now uses different values for the tenantId and userId fields.

25 August 2026
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…