Learn about generally available and public preview identity and network access capabilities released in the past 30 days.
Hello everyone, I'm Yina Arenas. I'm honored to have joined Microsoft Security as the CVP and Chief Product Officer of Identity and Network Access and to introduce myself to the legendary Microsoft Entra community. Having spent much of my career focused on platform innovation, I've seen how transformative technology can be when it's built on trust. Today, as organizations embrace AI at unprecedented scale, identity and access are becoming the foundation for secure innovation. I look forward to engaging with you as we navigate this extraordinary opportunity together.
Welcome to the August edition of “What’s New in Microsoft Entra”.
What went into General Availability (GA) since July 2026?
- Admin control for single sign-on prompts in Windows - Administrators can now use a supported registry setting to automatically accept single sign-on (SSO) permissions on managed Windows devices, enabling the use of Microsoft credentials from a user’s Windows sign-in to access other Microsoft apps and services without additional prompts. This capability is available starting with the July 2026 monthly security update for Windows 11, version 24H2 and 25H2 via the 2026—KB5101650 security update.
- Exchange Online-managed attributes writeback to Active Directory - Cloud-managed remote mailboxes let organizations move the Source of Authority (SOA) for a directory-synchronized mailbox’s Exchange attributes to Exchange Online while the user identity remains synchronized from on-premises Active Directory. Writeback synchronizes key Exchange attribute changes from Exchange Online back to on-premises Active Directory through Microsoft Entra Cloud Sync.
- What-if mode in Lifecycle Workflows - Simulate workflow processing to discover which users are in the execution scope and troubleshoot potential issues without impacting users.
- Cancel workflow runs using Lifecycle Workflows - Cancel queued or in-progress Lifecycle Workflows runs to prevent or contain the impact of automation errors or misconfigurations. Canceling a workflow run cancels tasks that have not yet been processed; changes from completed tasks are not reversed.
- User Attribute Updates task in Lifecycle Workflows - Automatically set or clear user attributes when lifecycle events occur. Supported attributes include built-in user attributes and on-premises extension attributes for cloud-managed users, as well as directory extension attributes for both cloud-managed users and users synchronized from on-premises Active Directory. Administrators can configure up to 10 attribute updates per task.
- Expanded dynamic attributes for Lifecycle Workflow custom email notifications - Lifecycle Workflows custom emails now support a new attribute format and expanded set of dynamic attributes, including additional built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes.
- Make email optional for external identity provider sign-up - Microsoft Entra External ID now supports federation with external identity providers that do not share users’ email addresses. Users signing up with social identity providers can also choose not to share their email address and still complete registration.
New in Public Preview
- Synchronize on-premises Active Directory (AD) devices with Microsoft Entra Cloud Sync - Synchronize on-premises AD devices to Microsoft Entra ID using Microsoft Entra Cloud Sync. This enables Hybrid Azure AD Join (HAADJ) and device lifecycle management across both connected and disconnected forests, allowing device attribute updates, disables, and deletions to flow from AD to Microsoft Entra ID without requiring Microsoft Entra Connect Sync or AD FS. This helps close a key parity gap and provides more flexibility for organizations looking to transition from Microsoft Entra Connect Sync to Microsoft Entra Cloud Sync.
- Automate Detection and Cleanup of Sponsorless Guests - Microsoft Entra is adding support in Lifecycle Workflows for administrators to create workflows that automatically detect and clean up sponsorless guest accounts. This helps prevent the buildup of stale, unused, or over‑permissioned external users that may remain long after an engagement has ended, reducing security and compliance risks while keeping environments cleaner and easier to manage.
- Back Up and Restore Group Policy Objects in Microsoft Entra Domain Services - Microsoft Entra Domain Services automatically maintains backups of managed GPOs, enabling administrators to restore policy settings after unintended changes. This capability helps organizations recover GPO configuration data from available backup points and maintain consistent policy management across managed domains.
I hope you'll take advantage of this added functionality to secure access for people and agents in your organization. Thank you for your ongoing feedback to the team, and for your role in navigating some of the toughest challenges in business today.
Onwards,
Yina Arenas
Additional resources
Learn what is new with Microsoft Entra, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find releases specific for Sovereign Clouds on a dedicated release notes page.
Learn more about Microsoft Entra
Secure access for any identity to any resource, anywhere.
- Microsoft Entra blog | Tech Community
- Microsoft Entra discussions | Tech Community
- Microsoft Entra Identity Platform blog | Dev Blogs
- Microsoft Entra documentation | Microsoft Learn
- Identity and Access Administrator Certification and Training | Microsoft Learn