<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-entra/ct-p/microsoft-entra</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Fri, 05 Jun 2026 22:19:40 GMT</pubDate>
    <dc:creator>microsoft-entra</dc:creator>
    <dc:date>2026-06-05T22:19:40Z</dc:date>
    <item>
      <title>Run Global Secure Access with confidence: Introducing the GSA Operations Guide</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/run-global-secure-access-with-confidence-introducing-the-gsa/ba-p/4524891</link>
      <description>&lt;P&gt;In working with customers, I’ve seen the same pattern again and again: deployment gets the attention, but day 2 operations are where teams need the most structure. This guide is meant to make that part easier—with practical guidance teams can use right away.&lt;/P&gt;
&lt;H2&gt;TL;DR: Your day 2 playbook is here&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What’s new?&lt;/STRONG&gt; A prescriptive &lt;STRONG&gt;Microsoft Entra Global Secure Access operations guide&lt;/STRONG&gt; on Microsoft Learn&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Why it matters:&lt;/STRONG&gt; It brings actionable, alert-first procedures for teams running Global Secure Access after deployment&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;What’s inside:&lt;/STRONG&gt; A role matrix, automated health checks, capability-specific guides, templates, and automation scripts&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Start here:&lt;/STRONG&gt; &lt;A class="lia-external-url" href="http://aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;The day 2 gap&lt;/H2&gt;
&lt;P&gt;Deploying Global Secure Access (GSA) is only the beginning. Day 2 challenges raise questions like: &lt;BR /&gt;&lt;EM&gt;Who monitors what? When do checks happen? How do we know everything is healthy?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The deployment guide covers rollout, and the product documentation explains configuration. But until now, there was no single resource that explained&amp;nbsp;&lt;STRONG&gt;how to operate Global Secure Access in production&lt;/STRONG&gt;. Customers, FastTrack, and partners built their own runbooks—and rebuilt them for each deployment.&lt;/P&gt;
&lt;P&gt;That ends today.&lt;/P&gt;
&lt;H2&gt;Announcing the Operations Guide&lt;/H2&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="http://aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt; is now live on Microsoft Learn.&lt;/P&gt;
&lt;P&gt;This post-deployment playbook delivers prescriptive guidance for&amp;nbsp;&lt;STRONG&gt;running Global Secure Access in production at scale&lt;/STRONG&gt;. It was created by the Global Secure Access customer experience engineering team with input from &lt;STRONG&gt;Thomas Detzner, Janice Ricketts, Jeff Bley, Luis Flores, Marilee Turscak, Peter Lenzke, Mohammad Zmaili, and Ken Withe&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H2&gt;Who this guide empowers&lt;/H2&gt;
&lt;P&gt;This guide is for the teams that keep Global Secure Access running every day: IT administrators, network engineers, and platform operations teams that need clear answers to questions like “Who owns what?” and “How do we prevent issues before they happen?”&lt;/P&gt;
&lt;P&gt;It also equips security leaders with structured reporting so they can demonstrate value and service health to executives. If you’re responsible for Global Secure Access performance, alerting, or automation, this is your new reference playbook. &lt;EM&gt;(And if you haven’t deployed yet, start with the &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/architecture/gsa-deployment-guide-intro" target="_blank" rel="noopener"&gt;&lt;EM&gt;deployment guide&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;.)&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What you’ll gain from this guide&lt;/H2&gt;
&lt;H3&gt;Shared practices that work across any environment&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Know your roles early:&lt;/STRONG&gt; A RACI matrix so responsibilities never overlap&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Manage change with confidence:&lt;/STRONG&gt; A GSA-tailored change-control framework for smooth updates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prove success with clarity:&lt;/STRONG&gt; Reporting templates for operators, managers, and executives&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Adopt continuous improvement:&lt;/STRONG&gt; Built-in processes to spot gaps before they become issues&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Capability-specific playbooks structured for speed&lt;/H3&gt;
&lt;P&gt;Every workload (Private Access, Internet Access, Remote Networks, Microsoft Traffic) follows one clear pattern so teams always know what comes next:&lt;BR /&gt;&amp;nbsp;✔ Begin with &lt;STRONG&gt;alert-first monitoring&lt;/STRONG&gt; steps that catch issues early&lt;BR /&gt;&amp;nbsp;✔ Follow &lt;STRONG&gt;daily, weekly, monthly routines&lt;/STRONG&gt; for health maintenance&lt;BR /&gt;&amp;nbsp;✔ Automate critical workflows with &lt;STRONG&gt;Sentinel, Graph API, and PowerShell scripts&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;✔ Track and tune KPIs using measured baselines&lt;BR /&gt;&amp;nbsp;✔ Diagnose and resolve quickly with &lt;STRONG&gt;symptom-to-fix troubleshooting&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;Don’t start from zero—use the templates&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Daily health check across all GSA capabilities&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;Ready-made change request forms and notification playbooks&lt;/LI&gt;
&lt;LI&gt;Modular checklists ready for your ITSM process&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Why this guide is different&lt;/H2&gt;
&lt;P&gt;Unlike generic environment monitoring advice, this guide delivers concrete, tested procedures built from field experience. It applies an alert-first approach so teams can act on signals from Microsoft Sentinel and Azure Monitor before dashboards show trouble.&lt;/P&gt;
&lt;P&gt;Each alert comes with an action—nothing is left unanswered. Automation is embedded throughout, including role-based access control (RBAC) hygiene checks and failover tests. Because operations demand clarity, the guide also provides measurable thresholds, baseline methods, and recovery steps that reduce noise and reinforce uptime.&lt;/P&gt;
&lt;H2&gt;Six moves to launch operational maturity&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Assign roles using the RACI matrix for full coverage&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;Configure critical alerts before adding custom workflows&lt;/LI&gt;
&lt;LI&gt;Collect 30 days of baseline data before adjusting thresholds&lt;/LI&gt;
&lt;LI&gt;Automate backups and priority alert notifications early&lt;/LI&gt;
&lt;LI&gt;Schedule routine checks using provided templates&lt;/LI&gt;
&lt;LI&gt;Begin structured reporting starting with weekly operations and monthly management reviews&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Why it matters for customers and partners&lt;/H2&gt;
&lt;P&gt;This framework reduces time to readiness after deployment, documents a defensible Day 2 plan for audits, cuts escalations by linking every alert to a clear action path, and gives FastTrack and partners a baseline for consistency in engagements.&lt;/P&gt;
&lt;H3&gt;Next up&lt;/H3&gt;
&lt;P&gt;Soon we will publish the GSA Security Operations Guide for Microsoft Entra Global Secure Access, providing a dedicated security monitoring and detection companion to the operational guides for Private Access, Internet Access, Remote Networks, and Microsoft traffic. It brings together the built-in alerts, log sources, Sentinel detections, and cross-signal investigation patterns that security teams need to identify suspicious activity and unauthorized changes across the GSA environment.&lt;/P&gt;
&lt;P&gt;If deployment is still ahead, start with the &lt;A href="https://learn.microsoft.com/en-us/entra/architecture/gsa-deployment-guide-intro" target="_blank" rel="noopener"&gt;GSA Deployment Guide&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Your move&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt; Open the full guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Download templates and run your first daily health check today&lt;/LI&gt;
&lt;LI&gt;Post feedback and ideas to help shape future updates&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Thomas Detzner&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/thomasdetzner/" target="_blank" rel="noopener"&gt;Thomas Detzner | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.sharepoint.com/teams/AzureActiveDirectoryBlogcopy/Shared%20Documents/Entra%20Blog%20Publishing/aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/IRPlaybooks" target="_blank" rel="noopener"&gt;Microsoft Incident Response Playbooks: response guidance for containment, eradication, and recovery after a SecOps detection is confirmed&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-sentinel-integration" target="_blank" rel="noopener"&gt;Enhance threat detection with Global Secure Access in Microsoft Sentinel: how to stream GSA data into Sentinel, install the solution, enable analytics rules, and use the built-in workbooks.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-alerts" target="_blank" rel="noopener"&gt;What are Global Secure Access alerts?: the built-in GSA alert types, what they mean, and where to view them.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-global-secure-access-logs-monitoring" target="_blank" rel="noopener"&gt;Global Secure Access logs and monitoring: overview of dashboards, traffic logs, audit logs, enriched Microsoft 365 logs, retention, and monitoring surfaces.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-access-audit-logs" target="_blank" rel="noopener"&gt;How to access the Global Secure Access audit logs: where to find GSA-related audit activity and how to filter it for operational or security investigations&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities" target="_blank" rel="noopener"&gt;Microsoft Entra audit log categories and activities for Global Secure Access: the authoritative list of GSA audit operations and categories for change monitoring&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 18:04:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/run-global-secure-access-with-confidence-introducing-the-gsa/ba-p/4524891</guid>
      <dc:creator>tdetzner</dc:creator>
      <dc:date>2026-06-05T18:04:21Z</dc:date>
    </item>
    <item>
      <title>Build AI agents for production with secure identities from day one</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/build-ai-agents-for-production-with-secure-identities-from-day/ba-p/4524606</link>
      <description>&lt;P&gt;Building an AI agent is no longer the hard part. The real challenge begins when that agent must run securely in production and meet identity, access, audit, and security requirements. That’s where many agents get stuck. It’s relatively easy to build a prototype, but much harder to deploy an agent that operates with the security controls required for production. Microsoft Entra Agent ID helps close that gap by giving agents a consistent identity foundation. Together with the Microsoft Agent 365 CLI and SDK, it helps you deploy AI agents that are ready to be managed, governed, and protected within your organization.&lt;/P&gt;
&lt;H2&gt;What is Microsoft Entra Agent ID?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt;, now generally available, is the identity and access platform in Microsoft Entra for AI agents. It introduces a set of identity constructs that match how agents are built and operated. There are three key concepts worth noting when deploying agents in your organization.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;BR /&gt;Agent blueprint:&lt;/STRONG&gt; A blueprint is the reusable identity template for a class of agents. It defines the common configuration, accountability model, credentials, and scopes used when creating agent identities so developers can create them consistently across deployments.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The agent blueprint manifest is a JSON representation of the blueprint, which you can view or edit under developer settings.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-left lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Agent identity:&lt;/STRONG&gt; Every agent instance gets its own identity in Microsoft Entra. Each identity has its own sign-in history, audit trail, assigned scopes, and targetable principal for Conditional Access. When you need to know what agent #4,712 did at 3:47 a.m. yesterday, the answer is in Microsoft Entra sign-in logs, indexed by the agent identity itself. When you need to retire a single malicious instance without touching the rest of your fleet, there is a kill switch for that agent identity.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The agent identities view in the Microsoft Entra admin center shows you an inventory of the agent identities in your tenant.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-left lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;BR /&gt;Agent sponsors and owners:&lt;/STRONG&gt; Every agent needs clear accountability through two distinct roles. Sponsors provide business accountability for the agent’s purpose and lifecycle decisions, such as whether it should retain access or be retired. Owners are responsible for the technical configuration and management of the agent identity.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The overview of the individual agent identity shows the sponsor, blueprint, and granted permissions for the agent.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;These concepts matter because they shape how agent onboarding works in practice. Once you understand the blueprint, the agent identity, and the accountability roles around it, the next question is how those pieces are created during deployment.&lt;/P&gt;
&lt;H2&gt;How an agent gets an agent identity, blueprint, and sponsor&lt;/H2&gt;
&lt;P&gt;There isn’t one single way to provision an agent identity, and that’s intentional. Microsoft Entra documents the official &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-id-creation-channels" target="_blank" rel="noopener"&gt;creation channels&lt;/A&gt; through which agent identity blueprints and identities can land in your tenant. Each channel has its own audience and control surface, and every creation event is recorded in Microsoft Entra audit logs with the channel attached. The channels developers use most often are outlined here.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft product integrations: &lt;/STRONG&gt;Agents built in Microsoft Foundry, Copilot Studio, and Security Copilot get a Microsoft Entra Agent ID automatically as part of platform onboarding. Identity is provisioned from a blueprint and connected without any additional developer effort.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Agent 365 CLI and SDK:&lt;/STRONG&gt; For agents built on any other framework (Microsoft Agent Framework, OpenAI Agents SDK, Anthropic Claude Agent SDK, Google ADK, AWS Bedrock, LangChain, LlamaIndex, CrewAI, Semantic Kernel, GitHub Copilot SDK, and others), the Microsoft Agent 365 CLI provisions the agent’s identity through Microsoft Graph, and the Microsoft Agent 365 SDK connects the running agent to the control plane so observability, governance, and security come with the identity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is the recommended channel for cross-platform and non-Microsoft agents because one integration delivers Microsoft Entra Agent ID plus the rest of Microsoft Agent 365 as a single bundle.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;For developers who don’t already have an onboarding pipeline, the fastest way to take an agent from a code repository to a managed, governed, and protected agent in your tenant is to use the AI-guided onboarding experience in the &lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/" target="_blank" rel="noopener"&gt;Microsoft Agent 365 CLI and SDK&lt;/A&gt; documentation. It walks you through the end-to-end steps: running the Microsoft Agent 365 CLI, wrapping your agent entry point with the Microsoft Agent 365 SDK, and configuring the runtime credentials Microsoft Entra will use to issue tokens.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Learn more about &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt; and how it helps organizations secure access for AI agents&lt;/LI&gt;
&lt;LI&gt;Learn how to &lt;A href="https://aka.ms/A365SDK-Blog" target="_blank" rel="noopener"&gt;make any agent enterprise-ready with the Agent 365 SDK&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Explore: &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=01e7c8230a52661133cfdf100b696796" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;-Arturo Lucatero, Principal Product Manager&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/" target="_blank" rel="noopener"&gt;Microsoft Agent 365 CLI and SDK Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/" target="_blank" rel="noopener"&gt;Microsoft Agent 365 Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 19:15:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/build-ai-agents-for-production-with-secure-identities-from-day/ba-p/4524606</guid>
      <dc:creator>ArLucaID</dc:creator>
      <dc:date>2026-06-02T19:15:00Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Entra: June 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-june-2026/ba-p/4517885</link>
      <description>&lt;P&gt;Welcome to the June edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;What went into General Availability (GA) since May 2026?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/devices/sso-linux?tabs=password-auth%2cdebian-install%2cdebian-update%2cdebian-uninstall%2cdebian-sc-example" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable Phish‑Resistant MFA for Linux Desktops with Microsoft Entra&lt;/STRONG&gt;&amp;nbsp;&lt;/A&gt;-&amp;nbsp;Microsoft Entra extends Phish Resistant Multi-Factor Authentication support to Linux desktops through the Microsoft identity broker, closing a long-standing gap in cross-platform identity. This update brings Linux to parity with Windows and macOS, enabling secure, modern authentication using phishing-resistant credentials. Support is now available for Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, helping organizations consistently enforce strong authentication across all major desktop platforms.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/customers/enable-external-id-high-scale-compatibility-mode" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable improved B2C-to-External ID migration with High Scale Compatibility (HSC) mode&lt;/STRONG&gt;&lt;/A&gt; – HSC mode is a new tenant-level migration option that lets Azure AD B2C customers transition their applications to Microsoft Entra External ID without re-registering users or resetting passwords, by keeping existing B2C credentials in place during coexistence. It's intended for high-scale tenants - generally those with 5 million or more objects - where the standard bulk migration with JIT password sync isn't practical. Tenants below the 5M threshold should continue to use the standard migration path, and even eligible high-scale tenants should carefully evaluate both options before choosing. Customers can run the B2C Policy Analyzer to assess migration readiness, and account teams and partners should engage the EEID migration team to guide eligible Azure Active Directory B2C customers toward the right migration path.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-system-preferred-authentication" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable system-preferred authentication for first and second factors&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra ID updates system-preferred authentication to apply to both first-factor and second-factor authentication in Microsoft Managed state. The system evaluates registered credentials for the user and selects the highest-ranked method for each authentication step. This update applies automatically in the Microsoft managed state, ensuring seamless and secure authentication experiences.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-US/accounts-billing/work-school/my-account-portal-for-work-or-school-accounts" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Modernize account management with redesigned My Account pages&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra introduces redesigned &lt;STRONG&gt;Devices, Security Info,&lt;/STRONG&gt; and &lt;STRONG&gt;Organizations pages &lt;/STRONG&gt;in the My Account portal. The &lt;STRONG&gt;Devices &lt;/STRONG&gt;page simplifies registered device management and prominently surfaces BitLocker recovery keys, reducing IT helpdesk dependency. The &lt;STRONG&gt;Security Info&lt;/STRONG&gt; page in &lt;STRONG&gt;Settings &amp;amp; Privacy&lt;/STRONG&gt; centralizes profile information, language, and region settings for easier updates. The &lt;STRONG&gt;Organizations&lt;/STRONG&gt; page resolves issues with end users leaving organizations and delivers a streamlined experience. These updates automatically roll out to Microsoft Entra ID customers by the end of June 2026, requiring no administrator action.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/multi-tenant-organizations/cross-tenant-synchronization-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cross-tenant group synchronization in Microsoft Entra&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;-&amp;nbsp;This enables organizations to synchronize security groups and memberships across tenants for centralized management and consistent access control. This simplifies cross-tenant collaboration by allowing groups managed in a source tenant to be used in one or more target tenants for scenarios like shared application access and resource authorization.&amp;nbsp;Beyond collaboration, this enables more seamless cross-tenant administration by allowing organizations to extend governance and access control consistently across tenant boundaries.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/accountDiscoveryDocumentation" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Account discovery for connected applications in Microsoft Entra ID Governance&lt;/STRONG&gt;&lt;/A&gt; - Administrators gain visibility into all accounts within connected applications, including orphan accounts not assigned to the enterprise application in Microsoft Entra. Generate discovery reports directly from the provisioning experience to identify access gaps and simplify application onboarding. This capability requires a Microsoft Entra ID Governance or Microsoft Entra Suite license.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/agent-sponsor-tasks" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Automate agent identity sponsorship transitions&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra ID Governance ensures agent identities always have a delegated human sponsor accountable for their access and lifecycle. With Lifecycle Workflows, when a sponsor leaves the organization, sponsorship automatically transfers to their manager, maintaining continuity. Lifecycle workflows can also notify cosponsors and managers of impending sponsorship changes, streamlining the process and reducing manual oversight.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-mfa-registration-campaign" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Drive Passkey Adoption with Microsoft Entra Registration Campaigns&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;- Microsoft Entra Registration Campaigns now supports Passkeys such as Fast Identity Online (FIDO2), as an authentication method. Administrators can configure registration campaigns to nudge users to register passkeys during sign-in, helping organizations drive passkey adoption. This first rollout experience is optimized for users in a passkey profile without restrictions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/app-disablement-docs" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;App Deactivation for Microsoft Entra applications&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- App Deactivation introduces a safe, reversible, and self-service way for app owners and admins to turn off applications that are unused, deprecated, or under investigation - without deleting them or breaking tenant-level governance.&amp;nbsp;Deactivating an app registration provides a reversible way to prevent the application from accessing protected resources without permanently removing it from your tenant. When you deactivate an application, it immediately stops receiving new access tokens, but existing tokens remain valid until they expire. This approach is useful for security investigations, temporary suspension of suspicious applications, or when you need to maintain application configuration data.&amp;nbsp;Unlike permanently deleting an application, deactivation preserves all application metadata, permissions, and configuration settings, making it easy to reactivate the application if needed. The application remains visible in your tenant's enterprise applications list, but users can't sign in and no new tokens are issued.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-entra-passkeys-on-windows" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable phishing-resistant sign-in with Microsoft Entra passkeys on Windows&lt;/STRONG&gt;&lt;/A&gt; - Users register device-bound passkeys in the local Windows Hello container and use them for secure sign-in with Windows Hello biometrics or PIN. These passkeys function as FIDO2 credentials and work without requiring the device to be Microsoft Entra joined or registered. This capability is automatically available in tenants where passkey profiles permit Windows Hello as a provider, supporting phishing-resistant authentication for Entra-protected cloud resources. Interactive Windows console sign-in is not supported.&lt;/P&gt;
&lt;H2&gt;New in Public Preview&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/direct-federation#domainless-saml-idp-federation-preview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Support domain-less SAML Federation on workforce tenants&lt;/STRONG&gt;&lt;/A&gt; - Domainless SAML federation with a SAML Identity Provider allows external users to authenticate into your apps or workforce resources using their IdP-managed credentials, regardless of their email domain. Domainless federation removes the need for domain matching between the user's email and pre-configured IdP domains during sign-in or invitation redemption.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/users/groups-sensitivity-labels" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Sensitivity labels for Entra security groups &lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;-&amp;nbsp;&lt;/STRONG&gt;Microsoft Entra ID supports applying Microsoft Purview sensitivity labels to Entra cloud security groups in public preview. This enables administrators to use the same labels and policies already used for Microsoft 365 groups to govern security group behaviors such as guest access and other controls. Sensitivity labels are managed in Microsoft Purview and can be applied through the Entra Admin Center, Azure portal, and Microsoft Graph, helping organizations apply consistent governance across identities and access.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/devices/concept-soft-delete-devices?branch=main&amp;amp;branchFallbackFrom=pr-en-us-12460" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Safely remove and restore devices with Device Soft Delete&lt;/STRONG&gt;&lt;/A&gt; - This enables administrators to move device objects to a recoverable state instead of permanently deleting them. Organizations can restore devices within a defined retention period while preserving critical data like device identity and associated security artifacts. The feature supports Microsoft Entra joined, registered, and hybrid joined devices, reducing risks from accidental deletions and improving device lifecycle management.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/EntraSAPSFConnectivityGuide" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Move SAP SuccessFactors Provisioning to Workload Identity-based authentication&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Microsoft Entra introduces Workload Identity-based authentication for SAP SuccessFactors provisioning, replacing long-lived usernames and passwords with Entra-managed credentials and short‑lived, standards‑based access tokens. This update allows customers to perform this authentication upgrade in-place on their existing provisioning jobs, without recreating or restarting them. This will switch their Entra or SuccessFactors integrations to a more secure model that is aligned with SAP SuccessFactors' plan to deprecate basic authentication for SAP SuccessFactors' APIs by November 2026. The new option applies to SAP SuccessFactors inbound provisioning to Active Directory and Microsoft Entra ID, as well as writeback scenarios, and improves security by eliminating the need to manually handle credentials and rotate them periodically.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-azure-role-assignments" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Govern Azure role assignments with access packages&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra enables governance of eligible and active assignments to Azure roles at the Management Group, Subscription, and Resource Group levels through access packages. Role assignments now follow the same request, approval, and lifecycle governance model as apps and groups. This simplifies managing access to Azure resources at scale while supporting least privilege and just-in-time access principles.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/how-to-lifecycle-workflow-update-user-attributes" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Automate user attribute updates in Lifecycle Workflows&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra introduces the User Attribute Updates task in Lifecycle Workflows, enabling automated attribute changes directly within workflows. Administrators can set or clear attribute values including custom attributes with a secure, consistent, and auditable process. This feature reduces manual effort, enhances governance, and scales identity automation with confidence.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Improve privileged identity response for Security Operations Center (SOC)&lt;/STRONG&gt; – Microsoft is extending the Entra Security Operator role so SOC analysts can take identity response actions such as disable users, revoke sessions, mark users compromised, force password resets (including cloud-only accounts), and delete individual authentication methods , directly from the Microsoft Defender unified role-based access control (RBAC) experience, without broad Entra admin roles or identity and access management (IAM) escalation during active incidents. Permissions are scoped to non-admin users enabling faster containment, least-privilege boundaries, and auditability.&lt;/P&gt;
&lt;H2&gt;Announcements&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-sspr-policy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Require registered methods for Self-Service Password Reset&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra Self-Service Password Reset (SSPR) will only accept explicitly registered authentication methods for identity verification starting September 7, 2026. Directory-sourced contact information, such as phone numbers and email addresses stored as user object properties, will no longer be accepted unless registered as authentication methods. This change applies to all users, including administrators, across Public cloud, GCC, GCC High, and DoD. Beginning July 6, 2026, Microsoft will automatically launch a registration campaign prompting affected users to register authentication methods after sign-in. Administrators should ensure users have at least one registered method to meet SSPR policy requirements before enforcement to avoid disruptions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/policy-all-users-security-info-registration" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enforce conditional Access during credential registration&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;- Starting&amp;nbsp;&lt;STRONG&gt;July 6, 2026,&lt;/STRONG&gt; Entra ID Conditional Access policies scoped to the&amp;nbsp;&lt;STRONG&gt;Register security information&lt;/STRONG&gt;&amp;nbsp;user action will be evaluated during credential registration for Windows Hello for Business and macOS Platform SSO .This ensures registration policies apply consistently across all registration flows. Users must satisfy policy controls, such as multifactor authentication (MFA), network restrictions, device compliance, or other tenant defined requirement before completing registration. Organizations without Conditional Access policies targeting this user action are unaffected, and MFA remains required by default for all passwordless credential registrations. Enforcement completes by July 13, 2026.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkeys-fido2#passkey-profile-prerequisites" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Expand passkey policy size and profiles in authentication methods policy&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra increases the passkey (Fast Identity Online 2, FIDO2) policy size limit to a dedicated 20 KB allocation within the authentication methods policy. Previously, all authentication methods shared a single 20 KB limit. This update ensures passkey policies have their own allocation, simplifying adoption and advanced targeting scenarios. Additionally, the maximum number of passkey profiles per tenant increases from 3 to 10, allowing greater flexibility in managing passkey configurations.&lt;/P&gt;
&lt;H2&gt;New guidance and information&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/overview-operations" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Global Secure Access Operations Guide&lt;/STRONG&gt;&lt;/A&gt; - The new GSA Operations Guide is your post-deployment companion for running Global Secure Access reliably at scale. It covers alerting, health checks, change management, metrics, and recovery playbooks, with ready-to-use KQL queries and templates you can adopt on day one. Capability-specific guides are included for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Tell us what you think!&lt;/H2&gt;
&lt;P&gt;If you have feedback on this newsletter, fill out the dedicated &lt;A href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR3tZ6taaY2dAnA0rWwJeTkRUM1BUWjM5TjI5Sk1HME45TVVYOEdBNkJRNy4u" target="_blank" rel="noopener"&gt;Microsoft Form&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Blogs&lt;/H2&gt;
&lt;P&gt;Check out the latest blog posts on our &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;Microsoft Entra Blog&lt;/A&gt; and our &lt;A href="https://aka.ms/devblog/ms-entra" target="_blank" rel="noopener"&gt;Microsoft Entra Identity Developer Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What's new in Microsoft Entra?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new" target="_blank" rel="noopener"&gt;Learn what is new with Microsoft Entra&lt;/A&gt;, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find &lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new-sovereign-clouds" target="_blank" rel="noopener"&gt;releases specific for Sovereign Clouds&lt;/A&gt; on a dedicated release notes page.&lt;/P&gt;
&lt;H2&gt;Become a certified Microsoft Identity and Access Administrator&lt;/H2&gt;
&lt;P&gt;Check out the &lt;A href="https://learn.microsoft.com/credentials/certifications/exams/sc-300/" target="_blank" rel="noopener"&gt;certification&lt;/A&gt; and related &lt;A href="https://learn.microsoft.com/credentials/certifications/identity-and-access-administrator/" target="_blank" rel="noopener"&gt;training&lt;/A&gt; for the Microsoft Identity and Access Administrator available for customers and partners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Martin Coetzer&lt;/P&gt;
&lt;P&gt;Principal Product Manager, Identity and Network Access, Customer Experience Engineering (CXE)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra Community | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 01 Jun 2026 22:54:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-june-2026/ba-p/4517885</guid>
      <dc:creator>Martin_Coetzer</dc:creator>
      <dc:date>2026-06-01T22:54:12Z</dc:date>
    </item>
    <item>
      <title>Entra ID Governance vs Saviynt for SAP IGA Use Cases</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/entra-id-governance-vs-saviynt-for-sap-iga-use-cases/m-p/4523348#M10330</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We are currently evaluating Microsoft Entra ID Governance as a potential replacement for Saviynt for SAP-focused IGA requirements across a mixed SAP landscape, including:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SAP SuccessFactors&lt;/LI&gt;&lt;LI&gt;SAP Concur&lt;/LI&gt;&lt;LI&gt;SAP S/4HANA Private Cloud&lt;/LI&gt;&lt;LI&gt;Other SAP SaaS and enterprise applications&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I wanted to get insights from anyone who has implemented or worked extensively with Entra Governance in SAP-centric environments, specifically around the following areas:&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;1. Birthright RBAC Provisioning&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Can Entra Governance provision a single composite/business role (similar to Saviynt Enterprise Roles) through HR-driven JML events?&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HR event triggers provisioning&lt;/LI&gt;&lt;LI&gt;User automatically receives bundled SAP access/business roles&lt;/LI&gt;&lt;LI&gt;Role assignment follows birthright/access package logic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;How mature/scalable is this approach in Entra compared to Saviynt?&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;2. SoD (Segregation of Duties) Capabilities&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Saviynt supports preventative SoD checks directly during request submission, including SAP-specific SoD analysis.&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Does Entra Governance support preventative SoD evaluation at request time?&lt;/LI&gt;&lt;LI&gt;Can conflicts be surfaced before approval/provisioning?&lt;/LI&gt;&lt;LI&gt;Is there native SAP SoD support or dependency on external tooling (for example SAP GRC/IAG)?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, Saviynt supports granular SAP authorization object analysis down to field-level min/max values within SAP Private Cloud environments.&lt;/P&gt;&lt;P&gt;Does Entra provide similar depth for SAP authorization analysis?&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;3. SAP Integrations / Connectors&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;While Entra provides OOTB Enterprise Applications and provisioning connectors for SAP applications:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What differences or limitations have you observed compared to Saviynt’s SAP connectors?&lt;/LI&gt;&lt;LI&gt;How well does Entra handle SAP role imports, entitlement hierarchy, and provisioning workflows?&lt;/LI&gt;&lt;LI&gt;Any known gaps for SAP Private Cloud integrations?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Would appreciate any implementation experiences, architecture guidance, lessons learned, or recommendations from teams who have evaluated or deployed Entra Governance in SAP-heavy environments.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2026 17:28:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/entra-id-governance-vs-saviynt-for-sap-iga-use-cases/m-p/4523348#M10330</guid>
      <dc:creator>carltonflewis</dc:creator>
      <dc:date>2026-05-27T17:28:07Z</dc:date>
    </item>
    <item>
      <title>Find shadow tenants and reduce risk fast with Microsoft Entra Tenant Governance</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/find-shadow-tenants-and-reduce-risk-fast-with-microsoft-entra/ba-p/4521996</link>
      <description>&lt;P&gt;As organizations grow, so does their tenant footprint. Over time, tenants created for acquisitions, development projects, regional operations, or partner collaboration can fall outside central IT visibility, creating what many security teams now refer to as shadow tenants.&lt;/P&gt;
&lt;P&gt;One of the foundational pillars of &lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt; is discovering &lt;STRONG&gt;related tenants&lt;/STRONG&gt;. This capability helps you identify tenants connected to your environment through signals such as B2B collaboration, multitenant applications and shared billing relationships. With that visibility, you can reduce hidden security risks before they become incidents.&lt;/P&gt;
&lt;P&gt;Let’s explore what this looks like in practice through the lens of the &lt;STRONG&gt;Related Tenants&lt;/STRONG&gt; pillar.&lt;/P&gt;
&lt;H2&gt;Scenario: Contoso discovers its hidden tenant landscape&lt;/H2&gt;
&lt;P&gt;Contoso's IT security team knows about their primary production tenant and a handful of dev/test tenants. But after reading about the Midnight Blizzard attack, the CISO wants a complete picture. Are there tenants out there that Contoso doesn't know about?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Turn on discovery.&lt;/STRONG&gt; A Contoso admin, Alice, opens the &lt;A href="https://entra.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Entra admin center&lt;/A&gt;, navigates to &lt;STRONG&gt;Tenant governance &amp;gt; Related tenants&lt;/STRONG&gt;, and enables discovery. It takes a single click—no infrastructure to configure.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Discover what’s connected.&lt;/STRONG&gt; Within hours, the system surfaces tenants connected to Contoso through cross-tenant signals (B2B collaboration, multitenant app registrations, and shared billing accounts). Alice sees 14 related tenants. The team recognizes nine of them. The other five are a mix of tenants from a 2023 acquisition that were never onboarded, a proof-of-concept tenant a partner team spun up, and two legacy test environments nobody remembered existed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3: Assess and act.&lt;/STRONG&gt; For each discovered tenant, Contoso can see the relationship type and the signals behind it. The security team flags unknown tenants for review and immediately runs a quarantine workflow for one unsanctioned tenant that has high-risk multitenant app permissions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Confirm exposure.&lt;/STRONG&gt; Validate which app permissions were granted, whether admin consent exists, and which users or workloads are affected.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Block user sign-in paths.&lt;/STRONG&gt; In cross-tenant access settings, add the suspect tenant and block inbound and outbound user sign-in so collaboration with that tenant is stopped without disrupting trusted tenants.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Contain application access.&lt;/STRONG&gt; Find enterprise applications whose “appOwnerOrganizationId” matches the suspect tenant, then revoke granted permissions or delete the corresponding service principals to cut off app-based access.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Harden with tenant restrictions.&lt;/STRONG&gt; Apply a tenant restrictions v2 policy through Global Secure Access and universal tenant restrictions so managed users can’t authenticate unsanctioned tenants.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate and decide. &lt;/STRONG&gt;Verify blocking in sign-in and audit logs, run a short scream test for business impact, then either onboard the tenant into governance relationships and policy baselines or keep it isolated until retirement.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra Tenant Governance related tenants.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra Tenant Governance discovery signals.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This isn’t a one-time scan. Related tenants are a continuously updated inventory; as new tenants appear in Contoso’s identity landscape, they surface automatically. No more blind spots waiting to be exploited.&lt;/P&gt;
&lt;P&gt;Following the guidance in &lt;A href="https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/discover-cloud-footprint" target="_blank" rel="noopener"&gt;Discover your Microsoft cloud footprint&lt;/A&gt;, organizations can further expand their visibility by using additional telemetry sources including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Azure subscription billing data&lt;/LI&gt;
&lt;LI&gt;Authentication logs (Microsoft Entra sign-ins)&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 activity&lt;/LI&gt;
&lt;LI&gt;Audit logs&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These sources help organizations inventory all Microsoft tenants where users have signed in or resources are provisioned, identify cross-tenant relationships through app consent and Global Secure Access network traffic, and surface potential risks from tenants with elevated permissions or suspicious patterns.&lt;/P&gt;
&lt;P&gt;For tenants that are discovered but not yet trusted, organizations can take immediate action using existing &lt;A href="https://aka.ms/tenantquarantine" target="_blank" rel="noopener"&gt;tenant quarantine capabilities&lt;/A&gt; to isolate potentially risky tenants and restrict their interactions until they've been assessed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Important: &lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;Using the new add-on tenant creation flow is a crucial part of establishing a secure tenant landscape. To ensure organizations are using the most secure methods possible to create add-on tenants, the legacy workforce tenant creation flow will be retired August 15, 2026.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Threat actors continue to innovate, but so do we. By making tenant discovery a foundational part of your identity strategy, you can close gaps before adversaries find them.&lt;/P&gt;
&lt;P&gt;To get started, enable related tenants discovery in the &lt;A href="https://entra.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Entra admin center&lt;/A&gt; or through the tenant governance API. Your feedback is instrumental in shaping these tools. We invite you to try the public preview and share your experience.&lt;/P&gt;
&lt;P&gt;Stay secure, stay informed, and stay ahead.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-Cindy Crane, Principal Product Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview" target="_blank" rel="noopener"&gt;What is Microsoft Entra Tenant Governance? (preview) – Microsoft Entra ID Governance | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/discover-cloud-footprint" target="_blank" rel="noopener"&gt;Discover your Microsoft cloud footprint&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/quarantine-unsanctioned-tenants" target="_blank" rel="noopener"&gt;Quarantine unsanctioned tenants&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 26 May 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/find-shadow-tenants-and-reduce-risk-fast-with-microsoft-entra/ba-p/4521996</guid>
      <dc:creator>CindyCrane</dc:creator>
      <dc:date>2026-05-26T15:00:00Z</dc:date>
    </item>
    <item>
      <title>ssoSilent() not working across Next.js apps — timed_out or account picker on localhost</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/ssosilent-not-working-across-next-js-apps-timed-out-or-account/m-p/4521758#M10329</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been stuck on this for a few days and would really appreciate some guidance from anyone who has dealt with cross-app silent SSO using MSAL.js v5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the setup. We have 3 separate Next.js applications all belonging to the same organisation, all registered under a single Azure Entra ID App Registration with the same clientId and tenantId. In production they all live under the same parent domain — app1.contoso.com, app2.contoso.com, app3.contoso.com — so localStorage is shared between them. On localhost we run them on ports 3000, 3001, and 3002.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is simple: if a user is already signed into App 1, opening App 2 in a new tab should silently authenticate them without any popup, redirect, or account picker. Just seamless SSO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how I've set up the msalConfig:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;export const msalConfig: Configuration = {&lt;/P&gt;&lt;P&gt;auth: {&lt;/P&gt;&lt;P&gt;clientId: 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx',&lt;/P&gt;&lt;P&gt;authority: 'https://login.microsoftonline.com/yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy',&lt;/P&gt;&lt;P&gt;redirectUri: 'http://localhost:3001/',&lt;/P&gt;&lt;P&gt;postLogoutRedirectUri: '/login',&lt;/P&gt;&lt;P&gt;},&lt;/P&gt;&lt;P&gt;cache: {&lt;/P&gt;&lt;P&gt;cacheLocation: 'localStorage',&lt;/P&gt;&lt;P&gt;storeAuthStateInCookie: true,&lt;/P&gt;&lt;P&gt;},&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;export const loginRequest = {&lt;/P&gt;&lt;P&gt;scopes: ['openid', 'profile', 'email', 'User.Read'],&lt;/P&gt;&lt;P&gt;};&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inside a component called SsoInitializer that sits inside MsalProvider, I scan localStorage for a sibling app's MSAL account on mount. I check both msal.2.account.keys (MSAL v5 format) and msal.account.keys (older format), extract the username/email as a loginHint, and then call ssoSilent(). If no loginHint is found — which is always the case on localhost since different ports are different origins — I still call ssoSilent() without a hint, expecting it to fall back to the Entra session cookie that was set when the user logged into port 3000.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;instance.ssoSilent({&lt;/P&gt;&lt;P&gt;...loginRequest,&lt;/P&gt;&lt;P&gt;...(loginHint ? { loginHint } : {}),&lt;/P&gt;&lt;P&gt;redirectUri: `${window.location.origin}/silent-callback.html`,&lt;/P&gt;&lt;P&gt;})&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The silent-callback.html in /public is just a blank HTML page with no scripts, which I believe is the correct approach based on the docs since MSAL v5 uses postMessage to communicate with the iframe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Azure app registration has the SPA platform selected, all redirect URIs including the /silent-callback.html variants are registered for all three localhost ports, ID tokens are enabled, and User.Read has admin consent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now here is the problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When App 1 is logged in on localhost:3000 and I open App 2 on localhost:3001, ssoSilent() fires but one of two things happens:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first failure is a timed_out error — BrowserAuthError: timed_out from BrowserUtils.ts. The server-telemetry key in localStorage shows redirect_bridge_timeout repeated multiple times with cacheHits of 0. This started happening when I had a CDN import of MSAL inside silent-callback.html trying to call handleRedirectPromise(). The CDN download was too slow for the iframe timeout window, so I removed it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second failure happens after switching to the blank HTML silent-callback page. The timed_out goes away but now ssoSilent() seems to fall through entirely and the Microsoft "Pick an account" full-page redirect opens — which completely defeats the purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also tried passing prompt: 'none' explicitly in the ssoSilent request. No change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One important observation from DevTools: the Entra session cookie IS present in the browser. The user is fully signed in on port 3000. Based on my understanding of the docs, ssoSilent() without a loginHint should detect this session cookie and authenticate silently. But it's either timing out or showing the account picker.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a few specific questions I'm hoping someone can help with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, is ssoSilent() actually supposed to work without a loginHint using only the Entra session cookie? Or does it require a hint and will always show the account picker if multiple accounts are signed in to the browser?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second, what is the correct content of silent-callback.html for MSAL v5 specifically? The blank page causes redirect_bridge_timeout, but adding MSAL scripts causes a different timeout because they load too slowly. Has the iframe handshake mechanism changed between v1/v2 and v5?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third, is there an officially recommended pattern for cross-app silent SSO when developing on localhost with different ports? In production the same-domain setup handles localStorage sharing fine, but on localhost the browser's same-origin policy makes each port completely isolated, so the sibling token scan always returns null.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fourth, does the redirectUri passed to ssoSilent() need to point to a page that actively runs MSAL code, or is a blank page genuinely sufficient for the iframe to complete its handshake in v5?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="73893" data-lia-user-login="azure" class="lia-mention lia-mention-user"&gt;azure&lt;/a&gt;/msal-browser 5.6.1, &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="73893" data-lia-user-login="azure" class="lia-mention lia-mention-user"&gt;azure&lt;/a&gt;/msal-react 3.0.20, Next.js 14 App Router, Chrome on Windows 11, single tenant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or a working example from someone who has done this in MSAL v5 would be hugely appreciated. Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 07:08:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/ssosilent-not-working-across-next-js-apps-timed-out-or-account/m-p/4521758#M10329</guid>
      <dc:creator>CilansSystem</dc:creator>
      <dc:date>2026-05-21T07:08:45Z</dc:date>
    </item>
    <item>
      <title>Platform SSO during automated device enrollment is now generally available for macOS</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/platform-sso-during-automated-device-enrollment-is-now-generally/ba-p/4436813</link>
      <description>&lt;P&gt;Getting new devices into users’ hands quickly while maintaining strong identity and compliance has always required a careful balance. IT admins need streamlined deployment workflows, while end users expect a frictionless experience from the very first sign-in.&lt;/P&gt;
&lt;P&gt;Today, we’re excited to announce that &lt;STRONG&gt;Platform SSO (PSSO) during Automated Device Enrollment (ADE) on macOS is now generally available&lt;/STRONG&gt;. This capability simplifies onboarding by enabling device registration and Platform SSO setup to occur automatically during enrollment, eliminating extra steps for both IT administrators and end users.&lt;/P&gt;
&lt;H2&gt;Streamline setup for IT admins&lt;/H2&gt;
&lt;P&gt;Automated Device Enrollment already provides a powerful way to provision macOS devices with the right configuration, policies, and applications from the start. With Platform SSO now integrated directly into this flow, IT admins can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ensure Platform SSO is enabled as part of enrollment — no post-setup steps required.&lt;/LI&gt;
&lt;LI&gt;Standardize device identity and access configuration from day one.&lt;/LI&gt;
&lt;LI&gt;Reduce deployment complexity by avoiding separate workflows for completing SSO setup.&lt;/LI&gt;
&lt;LI&gt;Improve compliance posture immediately with identity-backed device trust.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By incorporating PSSO into ADE, organizations can treat identity configuration as a core part of provisioning—not as an afterthought.&lt;/P&gt;
&lt;H2&gt;Reduce friction for end users&lt;/H2&gt;
&lt;P&gt;Previously, users enrolling macOS devices might encounter an additional step after setup to complete Platform SSO registration, typically requiring them to respond to a prompt or click a “Finish” action.&lt;/P&gt;
&lt;P&gt;With this new capability, that extra step is removed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No additional prompts to complete Platform SSO&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No need for users to manually finish enrollment steps&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Immediate access to single sign-on experiences after setup&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result is a smoother, more intuitive onboarding experience where users can begin working right away without interruption.&lt;/P&gt;
&lt;H2&gt;Understand how it works&lt;/H2&gt;
&lt;P&gt;With the &lt;STRONG&gt;EnableRegistrationDuringSetup&lt;/STRONG&gt; capability, Platform SSO registration is performed as part of the Automated Device Enrollment process. This ensures that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The device is properly registered with Microsoft Entra ID during setup.&lt;/LI&gt;
&lt;LI&gt;Platform SSO is activated automatically.&lt;/LI&gt;
&lt;LI&gt;The user’s identity is fully integrated into the device experience from first sign-in.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because this happens within the managed enrollment flow, it aligns naturally with existing MDM configurations and provisioning policies.&lt;/P&gt;
&lt;H2&gt;See why it matters&lt;/H2&gt;
&lt;P&gt;For organizations adopting modern identity and device management, reducing friction during onboarding is critical—not just for productivity, but for security consistency at scale.&lt;/P&gt;
&lt;P&gt;With Platform SSO during ADE:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;IT admins gain a predictable, simplified setup experience.&lt;/LI&gt;
&lt;LI&gt;Users avoid confusing or redundant steps during onboarding.&lt;/LI&gt;
&lt;LI&gt;Organizations achieve faster time-to-productivity with stronger identity integration.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is especially impactful in environments where devices are deployed at scale, such as enterprise rollouts, education, or frontline scenarios.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Ready to simplify macOS onboarding? Configure Platform SSO during Automated Device Enrollment in Microsoft Intune to reduce setup friction and strengthen identity from day one.&lt;/P&gt;
&lt;P&gt;To enable Platform SSO during Automated Device Enrollment, follow the &lt;A href="https://review.learn.microsoft.com/en-us/mem/intune/configuration/configure-platform-sso-during-enrollment.md" target="_blank" rel="noopener"&gt;MDM configuration steps&lt;/A&gt; below:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure Automated Device Enrollment for macOS in your MDM solution.&lt;/LI&gt;
&lt;LI&gt;Ensure Platform SSO is configured for your organization.&lt;/LI&gt;
&lt;LI&gt;Enable the &lt;STRONG&gt;EnableRegistrationDuringSetup&lt;/STRONG&gt; setting as part of your deployment profile.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once enabled, new devices will automatically complete Platform SSO setup during enrollment—with no additional user action required.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;-&lt;/STRONG&gt; Justin Ploegert&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/macos-psso" target="_blank" rel="noopener"&gt;macOS Platform single sign-on (PSSO) overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-macos-platform-single-sign-on-extension" target="_blank" rel="noopener"&gt;macOS Platform single sign-on known issues and troubleshooting&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://review.learn.microsoft.com/en-us/mem/intune/configuration/configure-platform-sso-during-enrollment.md" target="_blank" rel="noopener"&gt;Configure Platform SSO for macOS devices in Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos" target="_blank" rel="noopener"&gt;Single Sign-on scenarios&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment" target="_blank" rel="noopener"&gt;Single Sign-on in ADE profile&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos" target="_blank" rel="noopener"&gt;Platform SSO configuration guide for macOS devices using Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos" target="_blank" rel="noopener"&gt;Common Platform SSO scenarios for macOS devices&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-company-portal-macos" target="_blank" rel="noopener"&gt;Install Company Portal for macOS as a macOS LOB app&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-macos" target="_blank" rel="noopener"&gt;Set up automated device enrollment (ADE)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;⁠Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/bd-p/Azure-Active-Directory" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 18 May 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/platform-sso-during-automated-device-enrollment-is-now-generally/ba-p/4436813</guid>
      <dc:creator>Justin-Ploegert</dc:creator>
      <dc:date>2026-05-18T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Identity Manager 2016 SP3 now available: Enhanced stability for hybrid identity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-identity-manager-2016-sp3-now-available-enhanced/ba-p/4519489</link>
      <description>&lt;P&gt;Many organizations continue to depend on Microsoft Identity Manager (MIM) 2016 for scenarios that are not easily replicated elsewhere, such as:&lt;/P&gt;
&lt;P&gt;Synchronization across multiple directories and forests:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Complex attribute flows and identity correlation logic&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Management of custom objects and extended schemas&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Deep integration with on-premises applications&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft Identity Manager (MIM) 2016 Service Pack 3 (SP3) is now generally available. SP3 focuses on stability and supportability and updates compatibility with current platform components such as SQL Server, SharePoint, and Exchange. It also adds a new deployment option for the Synchronization Service: Azure SQL Database, with authentication through system-assigned and user-assigned managed identities to help reduce operational risk in hybrid identity environments.&lt;/P&gt;
&lt;H2&gt;In this release&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Run MIM on current platform components&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Updated compatibility for newer platform releases, including SQL Server 2022 and Exchange Server Subscription Edition (SE).&lt;/LI&gt;
&lt;LI&gt;New Synchronization Service database option: Azure SQL Database with authentication via system-assigned and user-assigned managed identities.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Modernize the MIM Service and Portal experience&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Deploy the MIM Portal on SharePoint Subscription Edition (SE).&lt;/LI&gt;
&lt;LI&gt;Support for System Center Service Manager Data Warehouse (DW) 2022 for reporting and audit integration.&lt;/LI&gt;
&lt;LI&gt;Active Directory Federation Services (AD FS) single sign-on (SSO) support for claims-based authentication, enabling users to sign in through AD FS instead of Windows integrated authentication.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Download and upgrade information&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Based on your licensing, you can download the installer packages here:&amp;nbsp;&lt;A href="https://outlook.office.com/mail/safelink.html?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmicrosoft-identity-manager%2Fmicrosoft-identity-manager-licensing%23obtaining-windows-installer-packages&amp;amp;locale=en-GB&amp;amp;wau=https%3A%2F%2FNAM06.safelinks.protection.outlook.com%2FGetUrlReputation&amp;amp;wid=00730A1A-3310-48BA-AB07-9EC288151649&amp;amp;corid=a787c79a-92b9-0eb6-a13a-2fe6ff92860a&amp;amp;srcid=&amp;amp;appname=Microsoft+Outlook+Web+App&amp;amp;appver=20260421013.02&amp;amp;os=Windows+11&amp;amp;scdt=&amp;amp;pc=7%252fv%252bt5EOVYXu109FvnxFD%252fwR7Qvhy9uHtEa0WV1bs9Ah51LkVFh39W%252fhDcAY%252fRfPmEAUDf7Bv2s7Y4VIICkWP39fY7IUsbFe1a7Uj5VgGuV8vtuRtkKfapn2fLPCcm81Ib3cClE1cmYlI95mXpW7FxH2QG9bcfLYmR9z8pec56TAUjSlvbchBZFVrq7HEpERaTLfeJKeM4eJnjG5B2ZI0xNdniZTeyUsvJuYlIesFZpnoELN7SRt9%252fXPRk7rgQ%252bo3Sq2DKU7Tdjvr40SX0bnLeYms1zMsR72N92hJLYh1zHxfzgig1HcmHkYJ8C9e7ux7EWTCf5U72JljmUwCJj7ZSaRilLFGsAeZb8sY7XamjQ45CBpC0eAvUuYrNdQmJ9a5TzzUNG1vgFJQFMFqdmMcHoLl%252bV%252fh4e1Q2DfxUrSLp5TDO2V8blOgREyoaVghvZfT%252bwBCsvLrJaoZU1hhc%252bfwN9GFLCEQHlT%252fj192OzANrTFWVOdssiS7foHlmzR51t0toaTEhlFGCmLVp1DXHnfUUI3NyPYHQZKN0i8tTB6hkdM43sgw9lIzeHhUdJNxG%252bxeYyC981nsbOfTo3xVyHdKIbi0Y%252bvGLvJ9PR4jTiRkKcO3zQ6ftssz7JDUgSAWTYswnC8NBrFDyOPSCZa6SSVHSDP3mHhj7FbbbECwL8xLQPLji6gHrjdglerHN4Rakr1GRKroclvFb7rJh8ovdsmRQyoshSdhjTnoOIdYmb9PeJTxH0My5DQZSZBUFDAi4gZNuXHe7tSM8CxJFrFWUydlHj1tmotwjDekpsp8TnXzA1EiAjJ67TbWIMV66t83pZtOr5AkHj7yv79ZbTGw4XH8CQ0woU7YQ4bFEWzplwdWpiMPDAZ7h00NrWpHaOHuvE4vwtAXpRvGOtp6fS9AGt2fRMeQ3XTHOqprLprt5gBi5iUlV0u8kxlu7sr7JhDlX2jftKJ%252bwcXR1HIG19pNlFQ0qklifkONovD8rm3H919Tjus%252foXPDEyrGL3yDuAZ8KCW32HxzSaespvzKofX2bfTus4xlx3FJMccKJqqfIL32jxueBsuIIIEB1z6NDQYzB%252bZayuEZKvmqwnMYg2oUR24lOaZ%252fZOIIvQq8uRKZVuTuIrMgzCmvIMPa5UWtNEiqrmZ%252f66DJMTekn0stjGZRGZF2iCwplh0FmkGgOlbeBlPUqExKR2sPe106jqt6g2T9aZynppkMSDLOI5CDHmhv12w2xy92A7wcKVjk1kdTfx1oIA3rbAFt%252fOltAjuWQAwb%252fcuaEOSqRNPj1r3DsQVznVbz%252bDcAVzpYy08t%252fpa%252bwonbdxiJBlXCkv1ilIxnG0xUE5CNBoCkxolWDOUqyv%252fY3jJ%252fKUyEJxMclAkyS2tsEFuC3Com%252b9QUlqeBuIXYhD3cl8wKbKZ8h%252b4SFgE%252fx3aRxd7htBX7JPsooeIQTszYlHYs2I%253d%3B+expires%3DSat%2C+25+Apr+2026+08%3A53%3A09+GMT%3B+path%3D%2F%3B+SameSite%3DNone%3B+secure%3B+httponly&amp;amp;urlsrc=Body&amp;amp;msgdata=" target="_blank" rel="noopener"&gt;Microsoft Identity Manager licensing and downloads | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;SP3 introduces a&amp;nbsp;new upgrade process. Please follow the documented steps carefully:&amp;nbsp;&lt;A href="https://outlook.office.com/mail/safelink.html?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmicrosoft-identity-manager%2Fmicrosoft-identity-manager-2016-upgrade-from-service-pack-2-to-service-pack-3&amp;amp;locale=en-GB&amp;amp;wau=https%3A%2F%2FNAM06.safelinks.protection.outlook.com%2FGetUrlReputation&amp;amp;wid=00730A1A-3310-48BA-AB07-9EC288151649&amp;amp;corid=7f31feba-b8f1-f7f5-b46a-4c1837cf01b5&amp;amp;srcid=&amp;amp;appname=Microsoft+Outlook+Web+App&amp;amp;appver=20260421013.02&amp;amp;os=Windows+11&amp;amp;scdt=&amp;amp;pc=7%252fv%252bt5EOVYXu109FvnxFD%252fwR7Qvhy9uHtEa0WV1bs9Ah51LkVFh39W%252fhDcAY%252fRfPmEAUDf7Bv2s7Y4VIICkWP39fY7IUsbFe1a7Uj5VgGuV8vtuRtkKfapn2fLPCcm81Ib3cClE1cmYlI95mXpW7FxH2QG9bcfLYmR9z8pec56TAUjSlvbchBZFVrq7HEpERaTLfeJKeM4eJnjG5B2ZI0xNdniZTeyUsvJuYlIesFZpnoELN7SRt9%252fXPRk7rgQ%252bo3Sq2DKU7Tdjvr40SX0bnLeYms1zMsR72N92hJLYh1zHxfzgig1HcmHkYJ8C9e7ux7EWTCf5U72JljmUwCJj7ZSaRilLFGsAeZb8sY7XamjQ45CBpC0eAvUuYrNdQmJ9a5TzzUNG1vgFJQFMFqdmMcHoLl%252bV%252fh4e1Q2DfxUrSLp5TDO2V8blOgREyoaVghvZfT%252bwBCsvLrJaoZU1hhc%252bfwN9GFLCEQHlT%252fj192OzANrTFWVOdssiS7foHlmzR51t0toaTEhlFGCmLVp1DXHnfUUI3NyPYHQZKN0i8tTB6hkdM43sgw9lIzeHhUdJNxG%252bxeYyC981nsbOfTo3xVyHdKIbi0Y%252bvGLvJ9PR4jTiRkKcO3zQ6ftssz7JDUgSAWTYswnC8NBrFDyOPSCZa6SSVHSDP3mHhj7FbbbECwL8xLQPLji6gHrjdglerHN4Rakr1GRKroclvFb7rJh8ovdsmRQyoshSdhjTnoOIdYmb9PeJTxH0My5DQZSZBUFDAi4gZNuXHe7tSM8CxJFrFWUydlHj1tmotwjDekpsp8TnXzA1EiAjJ67TbWIMV66t83pZtOr5AkHj7yv79ZbTGw4XH8CQ0woU7YQ4bFEWzplwdWpiMPDAZ7h00NrWpHaOHuvE4vwtAXpRvGOtp6fS9AGt2fRMeQ3XTHOqprLprt5gBi5iUlV0u8kxlu7sr7JhDlX2jftKJ%252bwcXR1HIG19pNlFQ0qklifkONovD8rm3H919Tjus%252foXPDEyrGL3yDuAZ8KCW32HxzSaespvzKofX2bfTus4xlx3FJMccKJqqfIL32jxueBsuIIIEB1z6NDQYzB%252bZayuEZKvmqwnMYg2oUR24lOaZ%252fZOIIvQq8uRKZVuTuIrMgzCmvIMPa5UWtNEiqrmZ%252f66DJMTekn0stjGZRGZF2iCwplh0FmkGgOlbeBlPUqExKR2sPe106jqt6g2T9aZynppkMSDLOI5CDHmhv12w2xy92A7wcKVjk1kdTfx1oIA3rbAFt%252fOltAjuWQAwb%252fcuaEOSqRNPj1r3DsQVznVbz%252bDcAVzpYy08t%252fpa%252bwonbdxiJBlXCkv1ilIxnG0xUE5CNBoCkxolWDOUqyv%252fY3jJ%252fKUyEJxMclAkyS2tsEFuC3Com%252b9QUlqeBuIXYhD3cl8wKbKZ8h%252b4SFgE%252fx3aRxd7htBX7JPsooeIQTszYlHYs2I%253d%3B+expires%3DSat%2C+25+Apr+2026+08%3A53%3A09+GMT%3B+path%3D%2F%3B+SameSite%3DNone%3B+secure%3B+httponly&amp;amp;urlsrc=Body&amp;amp;msgdata=" target="_blank" rel="noopener"&gt;Upgrade Microsoft Identity Manager 2016 from SP2 to SP3 | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Operational recommendation: Validate SP3 in a non-production environment first, then roll it out to your production environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Support lifecycle&lt;/H2&gt;
&lt;P&gt;MIM 2016 SP2 will remain supported for 12 months (through May 2027), in line with the service pack support lifecycle policy. Customers should plan to upgrade from SP2 to SP3 within that window. For details, see: &lt;A href="https://outlook.office.com/mail/safelink.html?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Flifecycle%2Fpolicies%2Ffixed&amp;amp;locale=en-GB&amp;amp;wau=https%3A%2F%2FNAM06.safelinks.protection.outlook.com%2FGetUrlReputation&amp;amp;wid=00730A1A-3310-48BA-AB07-9EC288151649&amp;amp;corid=4b1f8d0c-1e37-14bc-eb62-221250febb59&amp;amp;srcid=&amp;amp;appname=Microsoft+Outlook+Web+App&amp;amp;appver=20260421013.02&amp;amp;os=Windows+11&amp;amp;scdt=&amp;amp;pc=7%252fv%252bt5EOVYXu109FvnxFD%252fwR7Qvhy9uHtEa0WV1bs9Ah51LkVFh39W%252fhDcAY%252fRfPmEAUDf7Bv2s7Y4VIICkWP39fY7IUsbFe1a7Uj5VgGuV8vtuRtkKfapn2fLPCcm81Ib3cClE1cmYlI95mXpW7FxH2QG9bcfLYmR9z8pec56TAUjSlvbchBZFVrq7HEpERaTLfeJKeM4eJnjG5B2ZI0xNdniZTeyUsvJuYlIesFZpnoELN7SRt9%252fXPRk7rgQ%252bo3Sq2DKU7Tdjvr40SX0bnLeYms1zMsR72N92hJLYh1zHxfzgig1HcmHkYJ8C9e7ux7EWTCf5U72JljmUwCJj7ZSaRilLFGsAeZb8sY7XamjQ45CBpC0eAvUuYrNdQmJ9a5TzzUNG1vgFJQFMFqdmMcHoLl%252bV%252fh4e1Q2DfxUrSLp5TDO2V8blOgREyoaVghvZfT%252bwBCsvLrJaoZU1hhc%252bfwN9GFLCEQHlT%252fj192OzANrTFWVOdssiS7foHlmzR51t0toaTEhlFGCmLVp1DXHnfUUI3NyPYHQZKN0i8tTB6hkdM43sgw9lIzeHhUdJNxG%252bxeYyC981nsbOfTo3xVyHdKIbi0Y%252bvGLvJ9PR4jTiRkKcO3zQ6ftssz7JDUgSAWTYswnC8NBrFDyOPSCZa6SSVHSDP3mHhj7FbbbECwL8xLQPLji6gHrjdglerHN4Rakr1GRKroclvFb7rJh8ovdsmRQyoshSdhjTnoOIdYmb9PeJTxH0My5DQZSZBUFDAi4gZNuXHe7tSM8CxJFrFWUydlHj1tmotwjDekpsp8TnXzA1EiAjJ67TbWIMV66t83pZtOr5AkHj7yv79ZbTGw4XH8CQ0woU7YQ4bFEWzplwdWpiMPDAZ7h00NrWpHaOHuvE4vwtAXpRvGOtp6fS9AGt2fRMeQ3XTHOqprLprt5gBi5iUlV0u8kxlu7sr7JhDlX2jftKJ%252bwcXR1HIG19pNlFQ0qklifkONovD8rm3H919Tjus%252foXPDEyrGL3yDuAZ8KCW32HxzSaespvzKofX2bfTus4xlx3FJMccKJqqfIL32jxueBsuIIIEB1z6NDQYzB%252bZayuEZKvmqwnMYg2oUR24lOaZ%252fZOIIvQq8uRKZVuTuIrMgzCmvIMPa5UWtNEiqrmZ%252f66DJMTekn0stjGZRGZF2iCwplh0FmkGgOlbeBlPUqExKR2sPe106jqt6g2T9aZynppkMSDLOI5CDHmhv12w2xy92A7wcKVjk1kdTfx1oIA3rbAFt%252fOltAjuWQAwb%252fcuaEOSqRNPj1r3DsQVznVbz%252bDcAVzpYy08t%252fpa%252bwonbdxiJBlXCkv1ilIxnG0xUE5CNBoCkxolWDOUqyv%252fY3jJ%252fKUyEJxMclAkyS2tsEFuC3Com%252b9QUlqeBuIXYhD3cl8wKbKZ8h%252b4SFgE%252fx3aRxd7htBX7JPsooeIQTszYlHYs2I%253d%3B+expires%3DSat%2C+25+Apr+2026+08%3A53%3A09+GMT%3B+path%3D%2F%3B+SameSite%3DNone%3B+secure%3B+httponly&amp;amp;urlsrc=Body&amp;amp;msgdata=" target="_blank" rel="noopener"&gt;Fixed Lifecycle Policy | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MIM 2016 remains supported through January 9, 2029, under Microsoft’s Fixed Lifecycle Policy. While MIM continues to support critical identity scenarios, Microsoft is actively investing in Microsoft Entra as the long-term platform for identity governance and lifecycle management. We recognize that some MIM use cases require a phased or hybrid approach, and we are working closely with customers to support these transitions.&lt;/P&gt;
&lt;P&gt;Questions about upgrading to SP3 or planning your longer-term identity strategy? Contact your Microsoft account team or support contact to review your environment, timelines, and transition path.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ben Mann&lt;/STRONG&gt;, Group Product Manager&lt;BR /&gt;&amp;nbsp;Microsoft Entra&lt;/P&gt;
&lt;P&gt;Africa Development Center (ADC)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;About MIM 2016 - &lt;A href="https://learn.microsoft.com/en-us/microsoft-identity-manager/microsoft-identity-manager-2016" target="_blank" rel="noopener"&gt;Microsoft Identity Manager | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Migrate from MIM to Entra ID - &lt;A href="https://learn.microsoft.com/en-us/microsoft-identity-manager/migrate-entra-id" target="_blank" rel="noopener"&gt;Migrating to Microsoft Entra ID from Microsoft Identity Manager | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 14 May 2026 17:30:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-identity-manager-2016-sp3-now-available-enhanced/ba-p/4519489</guid>
      <dc:creator>benmann</dc:creator>
      <dc:date>2026-05-14T17:30:53Z</dc:date>
    </item>
    <item>
      <title>"Access package assignment manager" role with "Restricted access to Microsoft Entra admin center"</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/quot-access-package-assignment-manager-quot-role-with-quot/m-p/4519739#M10325</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How can I allow a user with the &lt;STRONG&gt;"Access package assignment manager"&lt;/STRONG&gt; role assigned only to a single catalog to manage access package assignments when &lt;STRONG&gt;"Restricted access to Microsoft Entra admin center"&lt;/STRONG&gt; is set to &lt;STRONG&gt;Yes&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;I do not see any option to manage assignments through the &lt;STRONG&gt;MyAccess&lt;/STRONG&gt; portal, so it seems this must be done through the &lt;STRONG&gt;Entra Admin Center&lt;/STRONG&gt;. However, the user cannot access the Entra Admin Center because they do not have any Entra administrative roles.&lt;/P&gt;&lt;P&gt;I do not have an &lt;STRONG&gt;Entra ID Governance&lt;/STRONG&gt; license, so the option to use &lt;STRONG&gt;on-behalf-of access package assignment requests&lt;/STRONG&gt; is not available.&lt;/P&gt;&lt;P&gt;How can this scenario be solved?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2026 11:49:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/quot-access-package-assignment-manager-quot-role-with-quot/m-p/4519739#M10325</guid>
      <dc:creator>PawelKowalczyk</dc:creator>
      <dc:date>2026-05-14T11:49:27Z</dc:date>
    </item>
    <item>
      <title>Secure the moments attackers target: onboarding, access requests, and account recovery</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-the-moments-attackers-target-onboarding-access-requests/ba-p/3627344</link>
      <description>&lt;P&gt;High assurance identity verification is no longer limited to regulated industries or edge cases. It is increasingly becoming a baseline requirement for scenarios like remote onboarding, account recovery, and access to sensitive resources. Microsoft tracks &lt;A href="https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;over 600 million identity attacks every day&lt;/STRONG&gt;&lt;/A&gt;, with &lt;STRONG&gt;more than 7,000 password attacks blocked per second&lt;/STRONG&gt; across Microsoft Entra environments.&lt;/P&gt;
&lt;P&gt;Even as organizations adopt multifactor identification and move towards passwordless sign-in, including &lt;STRONG&gt;passkeys&lt;/STRONG&gt;, an essential step toward eliminating passwords, security teams also need to protect the &lt;STRONG&gt;passkey lifecycle&lt;/STRONG&gt; (enrollment, device changes, and recovery). Attackers are shifting upstream to impersonation and gaps in identity verification. Microsoft reports that &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/?msockid=1da3b11f9fdc65802aeaa21c9e906454" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;more than 99%&lt;/STRONG&gt;&lt;/A&gt; of identity attacks still target passwords, often combined with phishing or adversary-in-the-middle techniques designed to bypass traditional authentication controls.&lt;/P&gt;
&lt;P&gt;This shift exposes a growing challenge. Possession of a credential is no longer enough to establish trust. Organizations increasingly need to verify that the &lt;STRONG&gt;person attempting to log in is the legitimate owner&lt;/STRONG&gt; during high-risk moments such as onboarding, access requests, and account recovery. &lt;BR /&gt;&lt;BR /&gt;That's where&amp;nbsp;&lt;A href="https://youtu.be/HG6-aLnDoM0?si=EZGVHP-ODA83SQtZ" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Face Check&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; with Microsoft Entra Verified ID&lt;/STRONG&gt; can help.&lt;/P&gt;
&lt;H2&gt;What is Face Check?&lt;/H2&gt;
&lt;P&gt;Face Check is a&amp;nbsp;&lt;STRONG&gt;privacy‑respecting facial matching capability&lt;/STRONG&gt; built into Microsoft Entra Verified ID. It helps organizations perform high‑assurance identity verification by matching a real‑time selfie with a trusted photo from a verified credential.&lt;/P&gt;
&lt;P&gt;Face Check adds an extra layer of confidence during verification by:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Comparing a live selfie with a photo already associated with a Verified ID credential.&lt;/LI&gt;
&lt;LI&gt;Performing facial matching using Azure AI services.&lt;/LI&gt;
&lt;LI&gt;Sharing only a match confidence score with the relying application, rather than the selfie or biometric data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;Face Check is designed with privacy in mind. The verifier receives only the match result and confidence score. Sensitive identity data and liveness footage are not shared or stored long term.&lt;/P&gt;
&lt;P&gt;To make it easier to use Face Check across your organization&lt;A href="https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing?msockid=1da3b11f9fdc65802aeaa21c9e906454" target="_blank" rel="noopener"&gt;, &lt;STRONG&gt;we have removed the per&lt;/STRONG&gt;&lt;STRONG&gt; user Face Check limit in Microsoft Entra Suite&lt;/STRONG&gt;&lt;/A&gt;. This lets you apply Face Check more broadly across key scenarios like remote onboarding, access requests with entitlement management, and account recovery.&lt;/P&gt;
&lt;P&gt;In addition, as we announced on &lt;STRONG&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/passkeys-aren%E2%80%99t-the-finish-line-eliminating-fallbacks-and-fixing-recovery/3627345" target="_blank" rel="noopener"&gt;World Passkey Day&lt;/A&gt;,&lt;/STRONG&gt; verified account recovery is now generally available. In this blog, we will dive into three scenarios, including account recovery where you can enable high assurance identity verification with Face Check today:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Employee verification when onboarding&lt;/LI&gt;
&lt;LI&gt;Access to sensitive resources via access packages&lt;/LI&gt;
&lt;LI&gt;Self-service account recovery&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Remote onboarding with Face Check&lt;/H2&gt;
&lt;P&gt;Alex is joining Contoso as a remote finance employee. Like many organizations, Contoso must onboard new hires who are not yet inside the trust boundary and cannot complete in‑person identity checks.&lt;/P&gt;
&lt;P&gt;To address this, Contoso has created a custom onboarding workflow that allows new employees to verify their identity with Face Check with Microsoft Entra Verified ID. This workflow uses government‑issued, ID‑based attestations from verification partners to help establish trust during remote onboarding.&lt;/P&gt;
&lt;img&gt;Face Check in Authenticator App&lt;/img&gt;
&lt;H3&gt;How the onboarding flow works&lt;/H3&gt;
&lt;P&gt;Alex receives a unique, time‑limited onboarding link that maps to his HR record. Through a custom onboarding portal, Alex is guided to acquire a Verified ID credential from an identity verification partner and then present it back to the organization.&lt;/P&gt;
&lt;P&gt;Using Verified ID APIs, the system validates the credential claims, matches them to Alex’s pre‑created Microsoft Entra ID account, and continues the onboarding flow. This can include generating a Temporary Access Pass for first sign‑in.&lt;/P&gt;
&lt;P&gt;Face Check strengthens this flow by helping confirm that &lt;STRONG&gt;Alex is the person presenting the Verified ID&lt;/STRONG&gt;. During credential presentation, Face Check compares a live selfie with the photo on Alex’s government-issued ID and returns a confidence score to the relying application.&lt;/P&gt;
&lt;P&gt;This is especially useful in remote onboarding scenarios where:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The initial interaction occurs outside the organization’s trust boundary.&lt;/LI&gt;
&lt;LI&gt;In‑person verification is not possible.&lt;/LI&gt;
&lt;LI&gt;Organizations want higher assurance without adding manual review for every hire.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Face Check fits naturally into the Verified ID presentation step without changing the overall onboarding architecture.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/verified-id/remote-onboarding-new-employees-id-verification" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Learn how to enable Face Check for onboarding.&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Requesting access with Face Check&lt;/H2&gt;
&lt;P&gt;After onboarding, Alex needs access to an internal financial tool through an access package. Because this access carries higher risk, the organization requires stronger identity assurance before approving the request.&lt;/P&gt;
&lt;P&gt;With Microsoft Entra entitlement management, organizations can configure &lt;STRONG&gt;access packages to require Verified ID verification&lt;/STRONG&gt; as part of the request flow. This allows the system to confirm the requester’s identity before access is granted. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;When Alex requests access:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The access package policy requires Verified ID verification.&lt;/LI&gt;
&lt;LI&gt;Alex presents a Verified ID credential during the request process.&lt;/LI&gt;
&lt;LI&gt;The system validates the credential before continuing with approval and assignment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;Face Check in Entitlement Management&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Face Check helps confirm that &lt;STRONG&gt;Alex is the person presenting the credential&lt;/STRONG&gt;. A live selfie is matched against the photo associated with the Verified ID, and the relying application receives a confidence score.&lt;/P&gt;
&lt;P&gt;This is especially useful for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access to sensitive or high‑impact resources.&lt;/LI&gt;
&lt;LI&gt;Time‑bound or just‑in‑time access scenarios.&lt;/LI&gt;
&lt;LI&gt;Reducing the risk of impersonation during access requests.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-verified-id-settings" target="_blank" rel="noopener"&gt;Learn how to enable Face Check for in entitlement management. &lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;Account recovery with Face Check (Now generally available)&lt;/H2&gt;
&lt;P&gt;After a few months in the role, Alex experiences a device issue and can no longer access his passkey. All registered authentication methods are unavailable.&lt;/P&gt;
&lt;P&gt;In these total lockout scenarios, traditional self‑service password reset does is not sufficient because it depends on access to an existing authentication method. This often results in help desk calls, delayed recovery, and lost productivity.&lt;/P&gt;
&lt;P&gt;Microsoft Entra &lt;STRONG&gt;self-service&lt;/STRONG&gt; &lt;STRONG&gt;account recovery&lt;/STRONG&gt; is designed for these scenarios by focusing on &lt;STRONG&gt;identity verification and trust re‑establishment&lt;/STRONG&gt; rather than simple credential reset.&lt;/P&gt;
&lt;H3&gt;A better experience for Alex&lt;/H3&gt;
&lt;P&gt;Instead of contacting the help desk, Alex can start account recovery directly from the sign-in experience. Identity verification is performed through a selected &lt;A href="https://learn.microsoft.com/en-us/entra/verified-id/idv-partners#security-store-integration-partners" target="_blank" rel="noopener"&gt;identity verification &lt;/A&gt;&amp;nbsp;partner from the &lt;A href="https://securitystore.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Security Store&lt;/A&gt;, which validates government-issued documents such as passports or driver’s licenses. This will be further cross-validated with the internal HR system with Alex’s government ID information. Face Check helps confirm that the person presenting the credential is the legitimate holder.&lt;/P&gt;
&lt;P&gt;Once verified:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Alex receives temporary access to reregister his authentication methods&lt;/LI&gt;
&lt;LI&gt;He can return to work without prolonged downtime.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This turns account recovery into a guided, self-service experience rather than a disruptive support escalation.&lt;/P&gt;
&lt;P&gt;📺 Watch the account recovery experience in action&lt;/P&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=5ivST2bw7uQ/1778255917291" data-video-remote-vid="https://www.youtube.com/watch?v=5ivST2bw7uQ/1778255917291" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F5ivST2bw7uQ%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D5ivST2bw7uQ&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F5ivST2bw7uQ%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H3&gt;Lower help desk costs, stronger security&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=iU-zJIGFEYQ" target="_blank" rel="noopener"&gt;Account recovery&lt;/A&gt; with government IDs and Face Check also helps organizations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reduce high‑risk, high‑touch help desk tickets related to lockouts. &amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Minimize reliance on human judgment, which can be vulnerable to social engineering.&lt;/LI&gt;
&lt;LI&gt;Support passwordless users who have no fallback recovery options.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We have also released a cost saving calculator to help you estimate potential help desk savings when enabling self-service account recovery. You can find this calculator under the&amp;nbsp;&lt;STRONG&gt;Microsoft Entra ID&lt;/STRONG&gt; blade under &lt;STRONG&gt;Account Recovery&lt;/STRONG&gt;.&lt;/P&gt;
&lt;img&gt;Cost savings with account recovery&lt;/img&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-account-recovery-overview" target="_blank" rel="noopener"&gt;Learn how to enable account recovery.&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;Get started with Face Check in Microsoft Verified ID&lt;/H1&gt;
&lt;P&gt;To get started with Face Check across these scenarios and more, &lt;A href="https://learn.microsoft.com/en-us/entra/verified-id/using-facecheck" target="_blank" rel="noopener"&gt;visit Microsoft Learn&lt;/A&gt; to see how to enable Face Check and integrate it into your Verified ID and Microsoft Entra workflows.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;-&lt;EM&gt; Ankur Patel&amp;nbsp; &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.youtube.com/watch?v=5ivST2bw7uQ" target="_blank" rel="noopener"&gt;Account Recovery End User Video&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/verified-id/using-facecheck" target="_blank" rel="noopener"&gt;Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;⁠Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/bd-p/Azure-Active-Directory" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 18:35:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-the-moments-attackers-target-onboarding-access-requests/ba-p/3627344</guid>
      <dc:creator>AnkurPatel</dc:creator>
      <dc:date>2026-05-11T18:35:54Z</dc:date>
    </item>
    <item>
      <title>passkeys in the Authenticator app regarding attestation</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra/passkeys-in-the-authenticator-app-regarding-attestation/m-p/4518458#M10320</link>
      <description>&lt;P&gt;I have a question about passkeys in the Authenticator app regarding attestation in connection with QR code-based cross-device sign-in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we register a passkey with attestation enabled in the Authenticator app, it can be used to complete the sign-in process on another device via QR code and Bluetooth Low Energy. According to Microsoft’s documentation, this shouldn’t be possible with attestation enabled, yet it works. What are we misunderstanding here?&lt;/P&gt;&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-authenticator-passkey" target="_blank"&gt;https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2&lt;/A&gt;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks for your inputs.&lt;BR /&gt;&lt;BR /&gt;Johannes&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 13:22:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra/passkeys-in-the-authenticator-app-regarding-attestation/m-p/4518458#M10320</guid>
      <dc:creator>jgeisler</dc:creator>
      <dc:date>2026-05-11T13:22:45Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Entra: May 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-may-2026/ba-p/4517884</link>
      <description>&lt;P&gt;Welcome to the May edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;What went into General Availability (GA) since April 2026?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/how-to-network-content-filtering" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Network content filtering by file type in Global Secure Access&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Global Secure Access supports network-based content filtering, based on file types. Administrators can monitor and control file transfers to generative AI and software-as-a-service (SaaS) applications. Organizations can define policies to block or restrict transfers of sensitive file types, such as documents, spreadsheets, and PDFs, preventing unauthorized data exfiltration across the network. This feature adds data loss prevention (DLP) on the network level.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/how-to-ai-prompt-injection-protection" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Prompt injection protection&lt;/STRONG&gt;&lt;/A&gt; - AI Gateway, part of Microsoft Global Secure Access, safeguards generative AI applications, agents, and language models. The prompt injection protection capability in AI Gateway is real-time protection against malicious prompt injection attacks on enterprise generative AI apps, a top risk for large language models (LLMs). By enforcing guardrails at the network level, prompt injection protection ensures consistent security across generative AI applications, without the need for code changes.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/how-to-install-ios-client" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Global Secure Access client on iOS and iPadOS&lt;/STRONG&gt;&lt;/A&gt; - Global Secure Access is available on iOS and iPadOS, extending secure network access to mobile Apple devices. No new agent installation is required, the client uses Microsoft Defender for Endpoint to route traffic through Global Secure Access for Microsoft 365, Microsoft Entra Internet Access, and Microsoft Entra Private Access. This enables organizations to apply consistent Zero Trust network policies across Microsoft Windows, macOS, and iOS platforms.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/how-to-configure-cloud-firewall" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Configure Global Secure Access with Cloud Firewall and remote networks for internet access&lt;/STRONG&gt;&lt;/A&gt; - Customers can use Global Secure Access with Cloud Firewall to apply administrator-configurable filtering: source IP, destination IP, protocol, source port, destination port for internet traffic acquired from branch offices through Global Secure Access remote networks capability.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-external-user-access" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;External user access in the Global Secure Access Windows client&lt;/STRONG&gt;&lt;/A&gt; - Enable Microsoft Private Access for external guest users and external members signing in with their home organization’s Microsoft Entra ID. The client automatically detects external tenant context and allows users to seamlessly switch to the appropriate external tenant. External guest users are now billed using Monthly Active User (MAU) licensing.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-remote-network-connectivity" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Secure branch office Microsoft Entra Internet Access with Global Secure Access remote network connectivity&lt;/STRONG&gt;&lt;/A&gt; - Global Secure Access remote network connectivity enables secure access to full internet, including Microsoft 365, from branch offices and remote sites using Internet Protocol Security (IPsec) tunnels, without requiring Global Secure Access on end‑user devices. Traffic from customer-premises equipment, such as firewalls or routers, is routed to Global Secure Access, where centralized security controls like web filtering, cloud firewall, and threat inspection are applied at the network layer. This capability extends Zero Trust protections to branch offices and unmanaged devices such as printers, servers, kiosks, Internet of Things (IoT), and bring-your-own-device (BYOD), enabling consistent policy enforcement, unified logging, and simplified operations without additional hardware.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-request-access#view-approver-information-for-pending-requests-preview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;View approver details for access package requests in the My Access portal&lt;/STRONG&gt;&lt;/A&gt; - Entitlement management in Microsoft Entra ID enables requestors to view approver name, email address, and their pending access package requests in the My Access portal. Streamline communication between requestors and approvers, reduce delays in access approvals. Approver information appears, by default, to members and can be controlled at the tenant and access package level.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/privileged-identity-management/groups-role-settings#on-activation-require-microsoft-entra-conditional-access-authentication-context" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enforce Conditional Access policies on Privileged Identity Management role activation&lt;/STRONG&gt;&lt;/A&gt; - Privileged Identity Management (PIM) in Microsoft Entra ID supports configuration of reauthentication through Microsoft Entra Conditional Access policies for role activation. Administrators can require multifactor authentication (MFA) or other Conditional Access controls when a user activates a privileged role. Help ensure elevated access is protected with current authentication signals. This enhancement strengthens privileged identity security and enforces Zero Trust principles for administrative access.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/microsoft-identity-manager/microsoft-identity-manager-2016" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Reduce risk with Microsoft Identity Manager 2016 Service Pack 3&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Identity Manager 2016 Service Pack 3 (MIM 2016 SP3) delivers improved stability, broader platform compatibility, and reduced operational risk for hybrid identity environments. SP3 supports Microsoft SQL Server 2022, Microsoft SharePoint Server Subscription Edition, Microsoft Exchange Server Subscription Edition, and Microsoft System Center Service Manager DW 2022. SP3 has a new deployment option for the MIM Synchronization Service using Microsoft Azure SQL Database with managed identity authentication.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-certificate-based-authentication-technical-deep-dive#issuer-hints" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Issuer Hints streamline certificate selection in certificate-based authentication&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra certificate-based authentication (CBA) supports Issuer Hints to improve the sign-in experience for users with multiple certificates installed on their devices. Issuer Hints ensures the certificate picker shows trusted certificates valid for the organization, reducing confusion and minimizing sign-in errors. This enhancement improves security and usability without requiring changes to how certificates are issued or managed.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-certificate-based-authentication-mobile-ios" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Certificate-based authentication on iOS&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra CBA is available on iOS, delivering phish-resistant authentication on Apple mobile devices. Native iOS sign-ins no longer generate unnecessary password or multifactor authentication (MFA) prompts. CBA is supported as a second factor with priority (third place) in the system-preferred MFA list. Users can select another allowed MFA method, based on tenant policy, ensuring a more secure and seamless experience.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-system-preferred-multifactor-authentication#faq" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Certificate-based authentication elevated in system-preferred MFA list on iOS&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra CBA is supported as a second-factor method on iOS and is compatible with single sign-on (SSO) and Primary Refresh Token (PRT). Native iOS sign-in flows reduce unnecessary password and MFA prompts, enabling an easier user experience.&amp;nbsp; In addition, CBA is third in the system-preferred MFA hierarchy, ensuring stronger, phishing-resistant authentication methods are prioritized, when available.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-certificate-based-authentication-technical-deep-dive#certificate-authority-ca-scoping" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Certificate Authority scoping for certificate-based authentication&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra now supports Certificate Authority (CA) scoping for certificate-based authentication (CBA). Tenant administrators can restrict specific certificate authorities to defined user groups. This ensures authorized users authenticate using certificates issued by a particular CA, improving security and policy enforcement. Administrators can create tailored authentication policies for differing user scenarios, while they maintain a seamless sign-in experience.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity-platform/configurable-token-lifetimes" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Configurable token lifetimes in Microsoft Entra ID&lt;/STRONG&gt;&lt;/A&gt; - This feature enables administrators to customize the lifetime of access tokens, ID tokens, and Security Assertion Markup Language (SAML) tokens issued by the Microsoft Identity Platform. Create and assign token lifetime policies to applications and Service Principals. With this capability, organizations align token duration with their security and operational needs.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://devblogs.microsoft.com/identity/native-auth-social-idps-web-view-ga/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Social identity provider support for native authentication in Microsoft Entra External ID&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra External ID supports social identity providers (IdPs) such as Apple, Facebook, Google and custom Open ID Connect (OIDC) providers through browser-delegated, web-view, authentication in native authentication. Developers can build native sign-up and sign-in experiences using software development kits (SDKs), while keeping users in the app for primary authentication. Social IdP sign-in is handled through secure web-view flows enforced by Microsoft Entra Conditional Access. This helps organizations streamline user onboarding, meet modern security expectations, and deliver authentication experiences customers trust.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/app-provisioning/configure-workday-termination-lookahead" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Prefetch Workday termination data to customize account disable logic&lt;/STRONG&gt;&lt;/A&gt; - This update to the Workday connector addresses termination processing delays affecting workers in the Asia Pacific (APAC) and Australia and New Zealand (ANZ) regions. Admins can enable the termination look-ahead setting to prefetch data and customize deprovisioning logic for accounts in Microsoft Entra ID and on-premises Active Directory.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/concept-license-usage-insights" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Track and optimize Microsoft Entra license usage in the Microsoft Entra admin center&lt;/STRONG&gt;&lt;/A&gt; - The License Usage page in the Microsoft Entra admin center gives organizations visibility into feature usage across the tenant. Administrators can view Microsoft Entra ID P1, P2, and Suite licenses and usage metrics for key features such as Conditional Access and risk-based Conditional Access, mapped to license tiers. Usage trends over the past six months illustrate license footprint, the value derived from Microsoft Entra, and potential over-usage risks.&lt;/P&gt;
&lt;H2&gt;New in Public Preview&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-explicit-forward-proxy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Explicit Forward Proxy for Microsoft Entra Internet Access&lt;/STRONG&gt;&lt;/A&gt; - Explicit Forward Proxy (EFP) for Internet Access enables secure web and AI gateway features in scenarios where installation of the GSA client is difficult or not possible. EFP is an effective mechanism to protect internet traffic when users use browsers to access resources from: multi-session Virtual Desktop Infrastructure (VDI), kiosks, browsers on Linux desktops, on lightly managed devices, and on bring-your-own devices with Microsoft Edge and Intune app policies.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/accountDiscoveryDocumentation" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Account discovery for connected applications in Microsoft Entra ID Governance&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Microsoft Entra ID Governance supports account discovery for connected applications. Administrators gain visibility into accounts in connected applications, including orphan accounts not assigned to the enterprise application in Microsoft Entra. Generate discovery reports from the provisioning experience and identify access gaps while simplifying application onboarding.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/role-based-access-control/permissions-reference#security-operator" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Improve privileged identity response for Security Operations Centers&lt;/STRONG&gt;&lt;/A&gt; - Microsoft is extending the Entra Security Operator role, so a Security Operations Cetner (SOC) analyst can take identity response actions such as disable users, revoke sessions, mark users compromised, force password resets (including cloud-only accounts), and delete individual authentication methods. These actions are done from the Microsoft Defender role-based access control (RBAC) experience, without broad Microsoft Entra admin roles, or IAM escalation during active incidents. Permissions are scoped to non-admin users and a limited set of administrative roles, enabling faster containment, least-privilege boundaries, and auditability.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/how-to-customize-branding-themes-apps" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Create app‑specific sign‑in experiences with branding themes&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;-&amp;nbsp;Microsoft Entra&amp;nbsp;introduces&amp;nbsp;branding themes to create multiple, app‑specific, sign‑in branding experiences, instead of a limited tenant‑wide configuration. This capability supports differing audiences, use cases, and application requirements.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/customers/how-to-entra-id-federation-customers" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Federate external tenants with Microsoft Entra ID using OIDC&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;-&amp;nbsp;Microsoft Entra ID supports OIDC federation between Microsoft Entra ID&amp;nbsp;workforce and Microsoft Entra External ID tenants. Users sign in to customer-facing applications with their Microsoft Entra ID workforce identities.&amp;nbsp;Users authenticate with their home tenant and access Microsoft Entra External ID tenant applications. This action eliminates the need for duplicate accounts, simplifies sign-in, and enables consistent security controls across workforce and external scenarios.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/graph/query-parameters?tabs=http" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Optimize sign‑in insights with $count in Microsoft Graph&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Graph supports $count in sign-in Application Programming Interface (API) requests. &amp;nbsp;Customers compute record counts in their queries. Combined with Microsoft Graph query parameters such as $filter, $select, $orderby, $top, and $expand, developers return the data they need, reduce response size, and improve application performance. These query options make it easier to build efficient, scalable solutions, especially for security and identity scenarios in Microsoft Entra, by optimizing how sign-in data is queried, processed, and presented.&lt;/P&gt;
&lt;H2&gt;Announcements&lt;/H2&gt;
&lt;P&gt;In April 2026, Microsoft transitions from Microsoft Entra Connect Sync to the cloud‑native Microsoft Entra Cloud Sync to simplify hybrid identity management and strengthen Zero Trust security. This move reduces on‑premises complexity while it improves reliability, security, and day‑to‑day operations. Starting July 2026, customers will be notified of their assigned transition window through the Microsoft 365 Message Center, Microsoft Entra Connect Health, and targeted emails. Phased transitions start with tenants supported by Microsoft Entra Cloud Sync, and expand as capabilities grow. During the transition window, tools and guidance help you assess readiness, migrate, and test. Microsoft Entra Cloud Sync becomes the primary identity synchronization solution, with unchanged hybrid authentication experiences.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra transitions SCIM apps from OAuth authorization code grant&lt;/STRONG&gt; – Microsoft Entra transitions System for Cross-domain Identity Management (SCIM) provisioning applications, from the OAuth 2.0 Authorization Code grant, to modern authentication methods: OAuth 2.0 client credentials or workload identity federation. As the service change rolls out, updated applications prompt customers to reconfigure provisioning jobs and use more secure options. Some applications, which can’t migrate, will be retired from the Microsoft Entra app gallery.&lt;/P&gt;
&lt;P&gt;This change improves security, simplifies credential management and rotation, and prepares customers for a more resilient provisioning experience. Customers are advised to not create new provisioning jobs using the Authorization Code grant and instead to &lt;STRONG&gt;monitor upcoming What's New updates for timelines and guidance from the Microsoft Entra team.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;New guidance and information&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://youtu.be/7l5vDNXPY1E?si=13-PKUzi5ekfEplU" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;New video | Build secure verification with Microsoft Entra Verified ID&lt;/STRONG&gt;&lt;/A&gt; - Ever wonder what secure, seamless identity verification looks like? In this video, see the full journey with Microsoft Entra Verified ID. From an organization issuing digital credentials, to individuals presenting and verifying them. Whether you're looking for a quick deployment or a tailor-made solution, Microsoft Entra Verified ID flexes to fit your identity verification requirements.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/microsoft-entra-id-governance-licensing-for-guest-users" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra ID Governance guest usage monitoring workbook&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Administrators can monitor and understand guest user governance activity under the new Monthly Active User (MAU) billing model for Microsoft Entra ID Governance. The workbook has billable governance actions, so admins can track guest usage, forecast costs, and optimize governance posture before billing enforcement. It's located under Identity Governance and Access in Microsoft Entra ID Workbooks.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/troubleshoot-prompt-injection-protection" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Troubleshoot prompt injection protection&amp;nbsp;article&lt;/STRONG&gt;&lt;/A&gt; - This article walks through prompt injection protection policies that help Global Secure Access administrators inspect, and control malicious prompts sent to AI services and reduce the risk of sensitive data exfiltration. It provides steps to validate that policies are applying as expected.&lt;/P&gt;
&lt;H2&gt;Tell us what you think!&lt;/H2&gt;
&lt;P&gt;If you have feedback on this newsletter, fill out the dedicated &lt;A href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR3tZ6taaY2dAnA0rWwJeTkRUM1BUWjM5TjI5Sk1HME45TVVYOEdBNkJRNy4u" target="_blank" rel="noopener"&gt;Microsoft Form&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Blogs&lt;/H2&gt;
&lt;P&gt;Check out the latest blog posts on our &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;Microsoft Entra Blog&lt;/A&gt; and our &lt;A href="https://aka.ms/devblog/ms-entra" target="_blank" rel="noopener"&gt;Microsoft Entra Identity Developer Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What's new in Microsoft Entra?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new" target="_blank" rel="noopener"&gt;Learn what is new with Microsoft Entra&lt;/A&gt;, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find &lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new-sovereign-clouds" target="_blank" rel="noopener"&gt;releases specific for Sovereign Clouds&lt;/A&gt; on a dedicated release notes page.&lt;/P&gt;
&lt;H2&gt;Become a certified Microsoft Identity and Access Administrator&lt;/H2&gt;
&lt;P&gt;Check out the &lt;A href="https://learn.microsoft.com/credentials/certifications/exams/sc-300/" target="_blank" rel="noopener"&gt;certification&lt;/A&gt; and related &lt;A href="https://learn.microsoft.com/credentials/certifications/identity-and-access-administrator/" target="_blank" rel="noopener"&gt;training&lt;/A&gt; for the Microsoft Identity and Access Administrator available for customers and partners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Martin Coetzer&lt;/P&gt;
&lt;P&gt;Principal Product Manager, Identity and Network Access, Customer Experience Engineering (CXE)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra" target="_blank"&gt;Microsoft Entra Community | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 May 2026 22:03:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-may-2026/ba-p/4517884</guid>
      <dc:creator>Martin_Coetzer</dc:creator>
      <dc:date>2026-05-08T22:03:27Z</dc:date>
    </item>
    <item>
      <title>Passkeys aren’t the finish line: Eliminating fallbacks and fixing recovery</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/passkeys-aren-t-the-finish-line-eliminating-fallbacks-and-fixing/ba-p/3627345</link>
      <description>&lt;P&gt;Every year, World Passkey Day gives us an opportunity to reflect on how far we’ve come in moving beyond passwords—and how much further we still need to go. Billions of accounts are protected by passkeys worldwide. At Microsoft, hundreds of millions of people use passkeys every day. The progress is real.&lt;/P&gt;
&lt;P&gt;But deploying a strong sign-in method isn’t enough if attackers can get around it. According to the Microsoft Digital Defense Report, AI-driven phishing campaigns are achieving click-through rates as high as 54%. Impersonation attacks—deepfakes, SIM swaps, and social engineering of help desks—target the moments when a user isn’t signing in: when they’re locked out, recovering access, or calling IT to prove who they are. In an enterprise where AI agents act autonomously on behalf of users, a compromised identity isn’t just a stolen mailbox—it’s an attacker operating agents and triggering actions at machine speed.&lt;/P&gt;
&lt;P&gt;These attack paths expose three critical gaps that organizations must close.&lt;/P&gt;
&lt;H2&gt;Three gaps attackers exploit&lt;/H2&gt;
&lt;P&gt;Even in an organization that has deployed passkeys, a sophisticated attacker still has options:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Gap 1 · Phishable sign-in methods. &lt;/STRONG&gt;Passwords, SMS codes, push notifications — as long as users sign in with these methods, the sign-in moment remains vulnerable.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Gap 2 · Dormant credentials. &lt;/STRONG&gt;Even after passkeys are deployed, most accounts still have a password or SMS method attached "just in case." The user doesn't use it. The attacker does.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Gap 3 · Weak recovery channels. &lt;/STRONG&gt;Recovery typically means calling a helpdesk and answering knowledge-based questions—information easily available from social media and data breaches. In an era of AI-generated deepfakes, that isn’t verification.&lt;/P&gt;
&lt;P&gt;Here's how we're closing each one.&lt;/P&gt;
&lt;H2&gt;Closing gap 1—passkeys on every platform, for every user&lt;/H2&gt;
&lt;P&gt;Over the past year, synced passkeys have become the default sign-in method for hundreds of millions of Microsoft account users — across every major operating system, device type, and browser. Our consumer users are 3× more successful signing in with passkeys than with legacy methods (95% vs. 30%), and sign-ins are 14× faster compared to password-plus-code MFA. These aren't lab results — that's what we've measured across one of the most diverse, heterogeneous user bases on the internet.&lt;/P&gt;
&lt;P&gt;Our consumer and enterprise identity platforms share a common foundation, so every usability improvement we make for Microsoft account users—registration flows, error handling, cross-device sync—reaches &lt;STRONG&gt;Microsoft Entra ID&lt;/STRONG&gt; and &lt;STRONG&gt;Microsoft Entra External ID&lt;/STRONG&gt; customers too. We’re thrilled to bring these advances to our enterprise customers—for workforce and external users alike.&lt;/P&gt;
&lt;P&gt;Think about what sign-in looks like for most enterprise users right now. Type a password. Switch to your phone. Approve a push notification — or copy an SMS code — then switch back to the browser. On mobile, it's even worse: juggling between an authenticator app and the app you're trying to reach, losing context along the way. Every one of those steps is friction for the user and a phishable surface for an attacker.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/synced-passkey-faq" target="_blank" rel="noopener"&gt;Synced passkeys&lt;/A&gt;—now generally available for external users and already available for workforce users—change that completely. The employee taps a fingerprint or glances at their camera, on any device, and they’re in. Phone, browser, laptop. No password, no code, no app switching. The passkey syncs across devices via iCloud Keychain, Google Password Manager, Microsoft Password Manager or other platform credential managers, so it works wherever they work. The same seamless experience extends to your customers through &lt;STRONG&gt;Microsoft Entra External ID&lt;/STRONG&gt;—passkey sign-in out of the box for customer-facing applications, with no custom integration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Sign in experience with synced passkeys.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;And now, Windows. Contractors, frontline workers, and bring-your-own-device (BYOD) users on unmanaged Windows devices have historically fallen back to passwords and SMS—because managed device enrollment wasn’t practical. With &lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-authentication-entra-passkeys-on-windows" target="_blank" rel="noopener"&gt;Microsoft Entra passkeys on Windows&lt;/A&gt;, they create a device-bound passkey using Windows Hello—face, fingerprint, or PIN—directly on their own device. No enrollment. No hardware token to ship.&lt;/P&gt;
&lt;P&gt;General availability is a milestone, not a finish line. We're continuing to invest in making passkeys the default experience — not just an option:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Passkey profiles&lt;/STRONG&gt;— Group-based passkey policies: attestation requirements, passkey type, specific provider selection — applied differently to different user groups.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Passkey-preferred authentication (preview)&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;—Detects registered methods and prompts the strongest one first. If a passkey is registered, that’s what the user sees immediately.&lt;/SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Passkey profiles for granular admin control.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Synced passkeys are the simplest path for most users — and for high-privilege roles or regulated industries, Microsoft Entra ID continues to support device-bound passkeys, Microsoft Authenticator passkeys, and FIDO2 security keys. With passkey profiles, admins deploy both side by side in the same tenant.&lt;/P&gt;
&lt;H2&gt;Close the fallback gap—and the recovery gap it reveals&lt;/H2&gt;
&lt;P&gt;Deploying passkeys improves sign-in. But most accounts still have a password or SMS method attached “just in case”—and as long as those credentials exist, they’re an attack surface. Admins can now remove phishable credentials from user accounts entirely. At Microsoft, we’ve rolled out phishing-resistant authentication to 99.9% of our users and devices, eliminating weaker methods from our own accounts.&lt;/P&gt;
&lt;P&gt;⚠️ Deprecation notice: &lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-security-questions" target="_blank" rel="noopener"&gt;Security questions for password reset in Microsoft Entra ID will be deprecated starting March 2027&lt;/A&gt;. If your organization still uses knowledge-based recovery, now is the time to migrate to high-assurance account recovery.&lt;/P&gt;
&lt;P&gt;Removing phishable credentials is the right move—but it raises an important question. Synced passkeys handle the most common lockout scenario by design: lose one device, your passkey is still on your other devices. But device-bound passkey users—including those on FIDO2 security keys and Windows Hello—don’t get cross-device sync. And for any user who loses all their credentials, recovery today still means helpdesk calls, temporary passwords, and knowledge-based questions that are easily guessable. That’s the weakest link.&lt;/P&gt;
&lt;H2&gt;Reduce impersonation—verified account recovery&lt;/H2&gt;
&lt;P&gt;Picture what happens when an employee gets locked out. They call the helpdesk, wait on hold, answer questions an attacker could guess from a LinkedIn profile, and eventually receive a temporary password—which they then have to change immediately. Twenty to thirty minutes: frustrating for the user, expensive for the organization, and vulnerable to social engineering.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-account-recovery-overview" target="_blank" rel="noopener"&gt;Microsoft Entra ID account recovery&lt;/A&gt;—now generally available—replaces all of that. The employee opens any browser, selects “Recover my account,” scans their driver’s license, takes a quick selfie, and registers a new passkey—all in minutes, without a phone call, and with controls that are harder to spoof. Since preview, we’ve expanded identity verification (IDV) provider coverage, added recovery profiles for regional compliance, and refined the end-user flow based on customer feedback across 192+ countries.&lt;/P&gt;
&lt;P&gt;As NIST recommends, high-assurance recovery requires government-issued ID and biometric verification. We've made it simple — setup takes minutes, not months:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Verify identity with a government-issued ID — driver's license, passport, or other supported document&lt;/LI&gt;
&lt;LI&gt;Complete a live face check—&lt;STRONG&gt;Face Check&lt;/STRONG&gt; in &lt;STRONG&gt;Microsoft Entra Verified ID&lt;/STRONG&gt;, powered by Azure AI, matches a real-time selfie with the photo on the identity document&lt;/LI&gt;
&lt;LI&gt;Match verified attributes against the organization's directory and HR system via custom authentication extensions&lt;/LI&gt;
&lt;LI&gt;Register a synced passkey immediately — so the user is protected going forward&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Only the match result is shared — never the sensitive identity data itself. Privacy is preserved. And this is what makes removing phishable fallbacks safe: the recovery channel is now harder to compromise than the primary authentication.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Account recovery user flow.&lt;/EM&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Ericsson&lt;/U&gt;&lt;/STRONG&gt;: &lt;EM&gt;Phishing-resistant MFA is one of those rare opportunities that strengthens security while simultaneously improving the employee experience. Ericsson has been at the forefront of this journey since 2020, early adopting Microsoft’s passwordless technologies—what we today refer to as passkeys or phishing-resistant MFA. Our approach has been to seamlessly integrate passkeys into managed user devices, such as Windows Hello for Business and passkeys in Microsoft Authenticator, complemented by FIDO2 security keys (YubiKey 5-series) for high-risk and privileged use cases—delivering strong protection with simplicity and peace of mind for users.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;Easy to set up, flexible by design&lt;/H3&gt;
&lt;P&gt;Admins configure recovery in a few steps: choose an IDV provider from the &lt;STRONG&gt;Microsoft Security Store&lt;/STRONG&gt;, assign user groups, and optionally match verified attributes against HR data via custom authentication extensions. You can simulate the entire flow before activating it for production. Just like passkey profiles, account recovery profiles let admins assign different IDV providers by region or country to meet local regulatory requirements.&lt;/P&gt;
&lt;P&gt;Through the &lt;STRONG&gt;Microsoft Security Store&lt;/STRONG&gt;, customers can choose from leading IDV providers—Au10tix, IDEMIA, TrueCredential (LexisNexis), 1Kosmos, and CLEAR1—without custom business contracts or bespoke integrations. These providers cover most government-issued ID documents across 192+ countries.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Bringing it all together&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;The gap&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Before&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What's better now&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Phishable sign-in&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Passwords, SMS codes, app-switching, push fatigue&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Synced passkeys — one biometric tap, on any device&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Dormant credentials&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Passwords and SMS sit on accounts "just in case"&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Phishable credential removal — admins eliminate every weak method&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Weak recovery&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helpdesk calls, security questions, temporary passwords&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Verified account recovery — government ID + live face check, self-service in minutes&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each capability is valuable on its own. Together, they close the entire credential lifecycle — not just the sign-in moment, but everything before and after.&lt;/P&gt;
&lt;H2&gt;Licensing and availability&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Capability&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Availability&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Synced passkeys in Microsoft Entra ID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Included for all Microsoft Entra ID customers&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Passkeys in Microsoft Entra External ID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Included with Entra External ID&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Entra passkeys on Windows&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Included for all Microsoft Entra ID customers&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Passkey profiles&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Included for all Microsoft Entra ID customers&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Passkey-preferred authentication&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Preview — included for all Microsoft Entra ID customers&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Entra ID account recovery&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Included with Microsoft Entra ID P1 license&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Entra Verified ID (Face Check)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Available as an add-on per verification, or as part of Microsoft Entra Suite&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Government ID verification&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Pay-per-verification via Microsoft Security Store&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;We've been on this journey together — from introducing these capabilities at Ignite 2025, to the general availability we're announcing today. Tens of thousands of organizations helped shape these experiences during preview.&lt;/P&gt;
&lt;P&gt;Passkeys make sign-in faster and phishing-resistant. Verified identity makes recovery seamless and impersonation-proof. Credential removal closes the fallback gap. Together, there's no weak link left.&lt;/P&gt;
&lt;P&gt;This matters even more as AI reshapes how work gets done. Every agent that acts on behalf of a user, every automated workflow that touches sensitive data, every copilot that executes a decision — all of it traces back to an identity. The person using, developing, and managing these agents must be securely verified. Passkeys and verified recovery ensure that identity is genuine, from sign-in to recovery. That's the foundation safe AI is built on.&lt;/P&gt;
&lt;P&gt;And we're just getting started.&lt;/P&gt;
&lt;P&gt;We love hearing from you — share your feedback and let us know how it's going.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ankur&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/4ankurpatel/" target="_blank" rel="noopener"&gt;Ankur Patel | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2" target="_blank" rel="noopener"&gt;Enable passkeys for your organization&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-account-recovery-overview" target="_blank" rel="noopener"&gt;Enable high-assurance account recovery&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-deploy-phishing-resistant-passwordless-authentication" target="_blank" rel="noopener"&gt;Passwordless deployment guide&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/bd-p/Azure-Active-Directory" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2026 16:28:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/passkeys-aren-t-the-finish-line-eliminating-fallbacks-and-fixing/ba-p/3627345</guid>
      <dc:creator>AnkurPatel</dc:creator>
      <dc:date>2026-05-07T16:28:47Z</dc:date>
    </item>
    <item>
      <title>Build a secure identity foundation: 5 webinars to strengthen access management with Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/build-a-secure-identity-foundation-5-webinars-to-strengthen/ba-p/4515965</link>
      <description>&lt;P&gt;To avoid gaps in protection, organizations need to fully deploy and scale core identity protections–from phishing-resistant authentication to Conditional Access policies to risk remediation and resiliency–across cloud and hybrid deployments.&lt;/P&gt;
&lt;P&gt;That’s why we’re launching the &lt;STRONG&gt;Secure identity foundation with Microsoft Entra&lt;/STRONG&gt; series: a five-part webinar lineup focused on implementing these core identity capabilities across Microsoft Entra.&lt;/P&gt;
&lt;P&gt;Think of this series as a guided path to building secure foundations, identifying quick wins, and applying repeatable patterns across your identity environment. Across five sessions, Microsoft experts share practical implementation guidance to help teams strengthen access strategies, improve visibility across tenant environments, and apply identity security controls across users, applications, and workloads.&lt;/P&gt;
&lt;H2&gt;Moving off passwords in Microsoft Entra ID: Deployment guidance&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;May 7, 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Malak Moussa, Senior Customer Experience Tech SME&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This session delivers a hands-on walkthrough of deploying phishing-resistant, passwordless authentication in Microsoft Entra ID. Led by a Customer Experience Engineering subject matter expert, we’ll demonstrate real-world implementation in a live tenant—covering passkey rollout, policy configuration, and securing both sign-in and recovery flows. Attendees will leave with clear deployment steps and the opportunity to engage directly with an expert during live Q&amp;amp;A chat.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learning.eventbuilder.com/events/11f131f7d57c43d0b9b3d13eec082789" target="_blank" rel="noopener"&gt;Register now&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Strengthen your security posture with Microsoft Entra Conditional Access&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;June 8th, 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Swaroop Krishnamurthy, Principal Product Manager; Danielle Augustin, Product Marketing Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In this session, learn how Microsoft Entra Conditional Access—our Microsoft Zero Trust policy engine—protects access for workforce users and agents by enforcing real-time, adaptive access policies that continuously assess risk signals and use AI-driven automation to dynamically allow, challenge, or block access for every identity. Join Microsoft experts as they walk through real-world scenarios and share practical guidance to help your identity team address policy sprawl, enforce consistent Conditional Access policies, and strengthen security posture across your environment.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/strengthen-your-security-posture-with-microsoft-entra-conditional-access/4514237" target="_blank" rel="noopener"&gt;Register now&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Stop identity attacks in real-time with Microsoft Entra ID Protection&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;June 17, 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Anna Qi, Senior Product Marketing Manager; Jared Ross, Principal Product Architect&lt;/EM&gt;&lt;BR /&gt;In this session, learn how &lt;STRONG&gt;Microsoft Entra ID Protection&lt;/STRONG&gt; delivers &lt;A href="https://aka.ms/IDProtectionReport" target="_blank" rel="noopener"&gt;premium, real-time protection&lt;/A&gt; with adaptive risk remediation, comprehensive detections, and expanded coverage for human and non-human identities. Join us to learn how identity and security operations teams scale risk remediation with Entra ID, and how these capabilities extend across your broader identity security portfolio—natively integrated with Microsoft Defender and Security Copilot—to strengthen protection in both cloud and hybrid environments.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/stop-identity-attacks-in-real-time-with-microsoft-entra-id-protection/4514242" target="_blank" rel="noopener"&gt;Register now&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Protect and govern every tenant with Microsoft Entra Tenant Governance&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;July 1, 2026&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Cindy Crane, Principal Product Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;As organizations scale, tenant sprawl becomes inevitable. This session introduces &lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt;, a new Entra capability that provides centralized visibility and control across multi-tenant environments. We’ll cover how Tenant Governance enables tenant discovery, secure governance relationships, configuration monitoring, and governed tenant creation from day one. Walk away with a clear framework for bringing order, visibility, and governance to your multi-tenant identity landscape.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/protect-and-govern-every-tenant-with-microsoft-entra-tenant-governance/4514244" target="_blank" rel="noopener"&gt;Register now&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Recover with confidence using Microsoft Entra Backup and Recovery&lt;/H2&gt;
&lt;P&gt;&lt;EM&gt;Danielle Augustin, Product Marketing Manager; Yuan Karppanen, Principal Product Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Accidental changes and security compromises can quickly cascade across your tenant. Learn how to recover with confidence using Microsoft Entra Backup and Recovery.&lt;/P&gt;
&lt;P&gt;Tune in to see how this Microsoft-managed, always-on solution helps minimize downtime and protects your tenant by enabling rapid recovery of critical identity data. We will walk through how automated backups, Difference Reports, and recovery workflows help you return to a known good state. Whether you work in identity, security, or IT operations, you will leave with practical guidance and a clear checklist to strengthen identity resilience in your organization.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/recover-with-confidence-using-microsoft-entra-backup-and-recovery/4504269" target="_blank" rel="noopener"&gt;Watch on demand&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Whether you’re modernizing access, reducing identity risk, or operationalizing Zero Trust, this series gives you a clear path to stronger protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Melanie Maynes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication" target="_blank" rel="noopener"&gt;Get started with a phishing-resistant passwordless authentication deployment in Microsoft Entra ID …&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/evolving-identity-security-how-the-conditional-access-optimization-agent-helps-y/4488927" target="_blank" rel="noopener"&gt;Evolving identity security: How the Conditional Access Optimization Agent helps you adapt | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/25/identity-security-is-the-new-pressure-point-for-modern-cyberattacks/?msockid=07579b4cf13d6f2502f68809f53d6132" target="_blank" rel="noopener"&gt;Identity security is the new pressure point for modern cyberattacks | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/microsoft-entra-tenant-governance-secure-and-manage-multi-tenant-environments-at/4462427" target="_blank" rel="noopener"&gt;Microsoft Entra Tenant Governance: Secure and Manage Multi-Tenant Environments at Scale&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426" target="_blank" rel="noopener"&gt;Strengthen Identity Resilience: Recover with Confidence using Microsoft Entra Backup and Recovery&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Entra blog | Tech Community" data-lia-auto-title-active="0"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Entra discussions | Microsoft Community&amp;nbsp;" data-lia-auto-title-active="0"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 11 May 2026 16:59:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/build-a-secure-identity-foundation-5-webinars-to-strengthen/ba-p/4515965</guid>
      <dc:creator>Melanie_Maynes</dc:creator>
      <dc:date>2026-05-11T16:59:28Z</dc:date>
    </item>
    <item>
      <title>Lock down AI, web, and private apps: what’s new in Internet Access and Private Access</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/lock-down-ai-web-and-private-apps-what-s-new-in-internet-access/ba-p/3847825</link>
      <description>&lt;P&gt;&lt;SPAN data-teams="true"&gt;One theme is crystal clear across the security industry&lt;/SPAN&gt;: AI is transforming security, and security must transform with it. Organizations everywhere are embracing generative AI to boost productivity and accelerate innovation. But with this rapid adoption comes new challenges that security teams can’t ignore:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Which AI tools are your employees using?&lt;/LI&gt;
&lt;LI&gt;Is sensitive data being uploaded to unsanctioned services?&lt;/LI&gt;
&lt;LI&gt;How do you prevent AI-specific attacks like prompt injection?&lt;/LI&gt;
&lt;LI&gt;How do you secure private apps without slowing down users?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These aren’t hypothetical questions. They’re the reality for every organization today. And the answer starts with &lt;STRONG&gt;identity&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H2&gt;Identity: The foundation for AI and app security&lt;/H2&gt;
&lt;P&gt;Traditional network security was built for a time when users, devices, and applications were mostly on-premises and predictable. Today, employees work from anywhere on any device, and generative AI and SaaS apps often sit outside the corporate perimeter. Static controls struggle to keep pace, creating gaps that increase risk.&lt;/P&gt;
&lt;P&gt;That’s why we built &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-internet-access" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra Internet Access&lt;/STRONG&gt;&lt;/A&gt; and &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra Private Access&lt;/STRONG&gt;&lt;/A&gt; within the Global Secure Access platform. These solutions extend &lt;STRONG&gt;Zero Trust protections&lt;/STRONG&gt; to web, SaaS, AI, and private-app traffic. They provide the visibility and control organizations need to embrace AI and hybrid work with confidence—without slowing innovation.&lt;/P&gt;
&lt;P&gt;A key capability of Microsoft Entra Internet Access is the &lt;STRONG&gt;Secure Web and AI Gateway&lt;/STRONG&gt;, which applies identity-centric network controls to web and AI traffic. Identity-based network security ties access decisions to the user’s sign-in risk, device posture, and data sensitivity—not just an IP address or network location. This approach delivers consistent protection everywhere users work, reduces risk, and helps organizations scale AI adoption securely across the enterprise.&lt;/P&gt;
&lt;P&gt;Late last year, we introduced most of the capabilities in &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/securing-the-ai-era-starts-with-identity/4478952" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;public preview&lt;/STRONG&gt;&lt;/A&gt; at Microsoft Ignite. Today, we’re excited to share the latest features now generally available in Microsoft Entra Internet Access and Private Access and to announce brand-new capabilities in public preview.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1: Microsoft’s identity-centric Secure Access Service Edge (SASE) solution.&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Public preview: More flexibility for diverse environments&lt;/H3&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Entra Internet Access &amp;amp; Microsoft Entra Private Access&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;We’re introducing new capabilities in public preview, giving you more options to secure every scenario:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-bring-your-own-device" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;BYOD with client&lt;/STRONG&gt;&lt;/A&gt; in Microsoft Entra Private Access lets you enforce Zero Trust for unmanaged devices, so employees and contractors can securely access private apps without compromising security or user experience.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-explicit-forward-proxy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Explicit Forward Proxy for Microsoft Entra Internet Access&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp; extends secure web access to agentless and legacy devices using PAC file-based proxy configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/how-to-configure-explicit-forward-proxy-intune-policy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Secure Browser Integra&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;tion&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;enables Intune-managed Microsoft Edge to route internet traffic through Microsoft Entra Internet Access using Explicit Forward Proxy with TLS termination and inspection, delivering deep visibility and policy enforcement for secure browsing.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-view-model-context-protocol-logging" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Shadow MCP visibility&lt;/STRONG&gt;&lt;/A&gt; identifies unauthorized or high‑risk MCP servers on the network traffic and surfaces MCP data paths, logs, and observability to help monitor and manage AI‑related risk.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These new features help you reduce risk across every device type, simplify deployment, and deliver consistent protection everywhere.&lt;/P&gt;
&lt;H3&gt;Now generally available: New AI security capabilities&lt;/H3&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Entra Internet Access&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;AI adoption is accelerating, but so are the risks. Employees often experiment with AI tools without IT approval, creating compliance and data security gaps. With Microsoft Entra Internet Access, you can see what is happening, protect what matters, and simplify how you manage it all.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/overview-application-usage-analytics" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Shadow AI discovery&lt;/STRONG&gt;&lt;/A&gt; gives you visibility into unsanctioned AI tools and SaaS apps so you can uncover unknown risks and make informed decisions before enforcing policy.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-ai-prompt-injection-protection" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Prompt Injection Protection&lt;/STRONG&gt;&lt;/A&gt; helps block malicious prompts that could trick AI models into exposing sensitive data, reducing AI-specific attack risk without slowing innovation.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-network-content-filtering" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Network content filtering&lt;/STRONG&gt;&lt;/A&gt; prevents sensitive files from being uploaded to unsanctioned AI services, reducing compliance risk and data loss.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-web-content-filtering" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;URL filtering&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;and &lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-threat-intelligence" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;threat intelligence&lt;/STRONG&gt;&lt;/A&gt; block access to risky or malicious sites, enforce acceptable use policies, and reduce data leakage.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-cloud-firewall" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cloud firewall&lt;/STRONG&gt; &lt;STRONG&gt;for remote networks&lt;/STRONG&gt;&lt;/A&gt; provides advanced network-layer protection for traffic from remote sites, enabling granular policy enforcement and reducing exposure to threats.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-install-ios-client" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;iOS support&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;and&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-create-remote-networks?tabs=microsoft-entra-admin-center" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;remote network connectivity&lt;/STRONG&gt;&lt;/A&gt; extend protection everywhere your users work.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result is simple. Your teams can use AI tools to work smarter while you maintain control and reduce risk without introducing friction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure2: Demo of prompt injection protection.&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Now generally available: New capabilities for modernizing app connectivity&lt;/H3&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Entra Private Access&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;While Internet Access secures your web and AI traffic, &lt;STRONG&gt;Microsoft Entra Private Access&lt;/STRONG&gt; helps you replace legacy VPNs with Zero Trust Network Access for private apps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-external-user-access" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;External User Access &lt;/STRONG&gt;&lt;/A&gt;enforces Zero Trust for partners and contractors, simplifying onboarding while maintaining strong security.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/enable-intelligent-local-access" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intelligent Local Access&lt;/STRONG&gt;&lt;/A&gt; improves user experience by routing traffic efficiently, reducing latency, and delivering consistent security without unnecessary backhauling.&lt;/LI&gt;
&lt;LI&gt;The result is a better experience for users and simpler operations for your IT teams.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Ready to secure AI and modernize identity?&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="http://aka.ms/EntraWebinarSeries" target="_blank" rel="noopener"&gt;Watch the Microsoft Entra Showcase webinar&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Watch the&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://www.youtube.com/watch?v=LaDSrwAOszQ" target="_blank" rel="noopener"&gt;Microsoft Entra Mechanics video&lt;/A&gt; for a deep dive into AI-aware protections&lt;/LI&gt;
&lt;LI&gt;Start your journey today: &lt;A href="https://techcommunity.microsoft.com/t5/aka.ms/EntraSuiteTrial" target="_blank" rel="noopener"&gt;Entra Suite Trial&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Sinead O’Donovan | VP of Product Management, Identity and Network Access&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/sineadco/" target="_blank" rel="noopener"&gt;Sinead O'Donovan | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/securing-the-ai-era-starts-with-identity/4478952" target="_blank" rel="noopener"&gt;Securing the AI era starts with identity&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-internet-access" target="_blank" rel="noopener"&gt;Microsoft Entra Internet Access | Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access" target="_blank" rel="noopener"&gt;https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Entra blog | Tech Community" data-lia-auto-title-active="0"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-forum" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Entra discussions | Microsoft Community&amp;nbsp;" data-lia-auto-title-active="0"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 05 May 2026 02:15:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/lock-down-ai-web-and-private-apps-what-s-new-in-internet-access/ba-p/3847825</guid>
      <dc:creator>Sinead_ODonovan</dc:creator>
      <dc:date>2026-05-05T02:15:47Z</dc:date>
    </item>
    <item>
      <title>SASE 101: How to get started with secure access in a cloud-first world</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/sase-101-how-to-get-started-with-secure-access-in-a-cloud-first/ba-p/4516005</link>
      <description>&lt;P&gt;As organizations adopt cloud applications, hybrid work, and distributed teams, many are re-evaluating how users securely access applications and data. &lt;STRONG&gt;Secure Access Service Edge (SASE)&lt;/STRONG&gt; has become a common starting point for these conversations, but for many teams, understanding where to begin can feel unclear.&lt;/P&gt;
&lt;P&gt;This article provides a practical foundation for teams learning about SASE for the first time. It explains what SASE is, why it emerged, how it differs from Security Service Edge (SSE), and how organizations can use SASE as a modern framework for secure access. The goal is to build shared understanding before diving into tools or technical decisions.&lt;/P&gt;
&lt;H2&gt;What is SASE?&lt;/H2&gt;
&lt;P&gt;Secure Access Service Edge (SASE) is a &lt;STRONG&gt;cloud-delivered approach&lt;/STRONG&gt; that combines networking and security capabilities into a unified access model.&lt;/P&gt;
&lt;P&gt;Instead of relying on centralized data centers and fixed network perimeters, SASE delivers secure access closer to users and applications, using cloud services to apply policies in most user locations.&lt;/P&gt;
&lt;P&gt;At a foundational level, SASE shifts access and security from being &lt;STRONG&gt;network-centric&lt;/STRONG&gt; to &lt;STRONG&gt;identity-centric&lt;/STRONG&gt;. This is why SASE is often discussed early in security modernization efforts that also include Zero Trust.&lt;/P&gt;
&lt;H2&gt;Why SASE is often a starting point&lt;/H2&gt;
&lt;P&gt;Many organizations begin exploring SASE because existing models no longer match how work happens today.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Traditional assumptions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Users worked primarily from corporate offices&lt;/LI&gt;
&lt;LI&gt;Applications lived inside data centers&lt;/LI&gt;
&lt;LI&gt;Network location determined trust&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Today’s reality:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Employees work remotely or in hybrid models&lt;/LI&gt;
&lt;LI&gt;Applications live across multiple clouds and SaaS platforms&lt;/LI&gt;
&lt;LI&gt;Contractors and partners require controlled access&lt;/LI&gt;
&lt;LI&gt;Devices connect from many different networks&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SASE provides a way to align secure access with these realities, making it a natural entry point for organizations looking to modernize without immediately restructuring their entire environment.&lt;/P&gt;
&lt;H2&gt;Core concepts to understand when getting started with SASE&lt;/H2&gt;
&lt;P&gt;SASE is not a single technology or deployment. It is a &lt;STRONG&gt;framework&lt;/STRONG&gt; made up of several core ideas:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud-Delivered Networking&lt;/STRONG&gt;&lt;BR /&gt;Connectivity adapts to where users and applications are located rather than forcing traffic through fixed sites.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Integrated Security Controls&lt;/STRONG&gt;&lt;BR /&gt;Security inspection and enforcement are applied consistently across users, devices, and destinations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity-Aware Access&lt;/STRONG&gt;&lt;BR /&gt;Access decisions are based on who the user is and the context of the request, not the network they are coming from.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Globally Distributed Delivery&lt;/STRONG&gt;&lt;BR /&gt;Services are delivered through cloud infrastructure that operates close to users around the world.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Understanding these concepts early helps teams define what SASE means for their environment before evaluating vendors or technologies.&lt;/P&gt;
&lt;H2&gt;How SASE fits with Zero Trust&lt;/H2&gt;
&lt;P&gt;SASE is closely aligned with &lt;STRONG&gt;Zero Trust principles&lt;/STRONG&gt;, which require continuous verification of access requests and avoid relying on implicit trust.&lt;/P&gt;
&lt;P&gt;Rather than replacing Zero Trust, SASE provides a scalable architecture for supporting it in distributed, &lt;STRONG&gt;cloud-first&lt;/STRONG&gt; environments. It helps enforce &lt;STRONG&gt;identity-based&lt;/STRONG&gt; access and apply consistent security policies regardless of user or application location.&lt;/P&gt;
&lt;P&gt;For many organizations, SASE is a practical way to begin operationalizing Zero Trust for real-world access scenarios.&lt;/P&gt;
&lt;H2&gt;SASE vs. SSE: An important early distinction&lt;/H2&gt;
&lt;P&gt;When getting started with SASE, teams often encounter the related term &lt;STRONG&gt;Security Service Edge (SSE)&lt;/STRONG&gt;. Understanding the distinction helps clarify scope and expectations.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What Is SSE (Security Service Edge)?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;SSE is a&amp;nbsp;&lt;STRONG&gt;cloud-delivered&lt;/STRONG&gt; security model focused specifically on protecting user access to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The web&lt;/LI&gt;
&lt;LI&gt;Cloud and SaaS applications&lt;/LI&gt;
&lt;LI&gt;Private applications&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SSE concentrates on security controls and policy enforcement. It does not address network optimization or routing.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How SASE and SSE Are Related:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;SASE&lt;/STRONG&gt; is the broader architecture that combines networking and security.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SSE&lt;/STRONG&gt; represents the security portion of SASE.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In other words, SSE is a subset of SASE. Many organizations begin their modernization journey with SSE because it allows them to improve user access security before making broader networking changes.&lt;/P&gt;
&lt;H2&gt;Using scenarios to build early understanding&lt;/H2&gt;
&lt;P&gt;When first learning about SASE, scenarios often help bring the concepts to life. For example:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A remote employee securely accesses applications without routing traffic through a corporate office.&lt;/LI&gt;
&lt;LI&gt;A contractor receives limited, identity-based access without joining the internal network.&lt;/LI&gt;
&lt;LI&gt;A branch office connects directly to cloud services without relying on complex on-premises infrastructure.&lt;/LI&gt;
&lt;LI&gt;These examples illustrate the outcomes that SASE helps enable, which helps teams evaluate alignment with their needs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Who should be involved when getting started with SASE?&lt;/H2&gt;
&lt;P&gt;SASE discussions often involve multiple roles, even in early conversations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IT leaders&lt;/STRONG&gt; evaluating future access models&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Security teams&lt;/STRONG&gt; supporting Zero Trust initiatives&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Network professionals&lt;/STRONG&gt; adapting connectivity to cloud delivery&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Business leaders&lt;/STRONG&gt; focused on reducing complexity and risk&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because SASE spans both networking and security, early alignment across these teams often determines long-term success.&lt;/P&gt;
&lt;H2&gt;How to get started with Microsoft Global Secure Access&lt;/H2&gt;
&lt;P&gt;Microsoft Global Secure Access helps organizations begin their SASE journey by delivering &lt;STRONG&gt;identity-aware&lt;/STRONG&gt;, &lt;STRONG&gt;cloud-delivered&lt;/STRONG&gt; access controls. Here’s how to start:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Deploy the traffic forwarding client&lt;/STRONG&gt; to route user traffic through Microsoft’s global network for policy enforcement.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Apply Conditional Access policies&lt;/STRONG&gt; to enforce identity-based access decisions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enable shadow AI visibility&lt;/STRONG&gt; to monitor and control unsanctioned app usage.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These steps help organizations operationalize Zero Trust principles while building toward a full SASE architecture.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://demos.microsoft.com/app/present/3070#/0/0" target="_blank" rel="noopener"&gt;See Microsoft Global Secure Access in action&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Getting started means building the right foundation&lt;/H2&gt;
&lt;P&gt;Getting started with SASE does not begin with tools or deployments. It begins with a shared understanding. SASE provides a way to think about secure access that is:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud-based&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity-driven&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Consistent across users and locations&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For organizations navigating hybrid work and cloud adoption, understanding SASE concepts early helps create a foundation for designing secure access strategies that scale with the business.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Next Steps&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Explore &lt;A href="https://learn.microsoft.com/entra/global-secure-access" target="_blank" rel="noopener"&gt;Microsoft Global Secure Access documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Take the &lt;A href="https://learn.microsoft.com/training/paths/zero-trust/" target="_blank" rel="noopener"&gt;Microsoft Learn Zero Trust modules&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Read related blogs on &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/MicrosoftEntraBlog" target="_blank" rel="noopener"&gt;modern identity security strategies&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Sule Tatar, Senior Product Marketing Manager&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/security-101/what-is-sase" target="_blank" rel="noopener"&gt;What Is Secure Access Service Edge (SASE)? | Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/identity-and-network-security-practitioner-webinar-series/4448759" target="_blank" rel="noopener"&gt;Identity and Network Security Practitioner Webinar Series | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftmechanicsblog/replace-your-vpn-%E2%80%94-global-secure-access-in-microsoft-entra/4473004" target="_blank" rel="noopener"&gt;Replace your VPN — Global Secure Access in Microsoft Entra | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" data-lia-auto-title="Microsoft Entra blog | Tech Community" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" data-lia-auto-title="Microsoft Entra discussions | Microsoft Community&amp;nbsp;" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 06 May 2026 16:51:38 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/sase-101-how-to-get-started-with-secure-access-in-a-cloud-first/ba-p/4516005</guid>
      <dc:creator>SuleTatar</dc:creator>
      <dc:date>2026-05-06T16:51:38Z</dc:date>
    </item>
    <item>
      <title>You can’t govern what you can’t see: Closing the identity visibility gap for apps</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/you-can-t-govern-what-you-can-t-see-closing-the-identity/ba-p/4507464</link>
      <description>&lt;P&gt;Effective identity governance often starts with a simple question:&amp;nbsp;&lt;STRONG&gt;who has access?&lt;/STRONG&gt; Today, I am happy to introduce &lt;A href="https://aka.ms/accountDiscoveryDocumentation" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;account discovery&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;with&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/identity-governance-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra ID Governance&lt;/STRONG&gt;&lt;/A&gt;, a new capability designed to close this visibility gap from day one.&lt;/P&gt;
&lt;P&gt;As organizations connect SaaS and on-premises applications to Microsoft Entra, they unlock critical identity governance capabilities. But applications are rarely greenfield. By the time an app is connected, it already contains users and permissions that were created outside modern governance workflows.&lt;/P&gt;
&lt;P&gt;Account Discovery brings those existing accounts into view so teams can act on them with confidence. When you run a discovery, Microsoft Entra connects directly to the target application and retrieves the full list of user accounts and their properties. Each account is then evaluated against your Microsoft Entra directory using configurable matching attributes such as user principal name or email address. The service also checks whether matched users are already assigned to the enterprise application in Entra.&lt;/P&gt;
&lt;P&gt;The result is a clear, actionable discovery report that shows exactly where governance is strong and where gaps still exist.&lt;/P&gt;
&lt;P&gt;Why does this matter? Applications often contain access that was created manually, migrated from legacy systems, or provisioned directly—without consistent ownership or policy. Former employees can retain access. Service accounts can accumulate without owners. Local accounts can bypass MFA and Conditional Access entirely. These are not edge cases. Our latest&lt;A class="lia-external-url" href="http://aka.ms/SecureAccessReport" target="_blank" rel="noopener"&gt; Secure Access&lt;/A&gt; research found that 97% of organizations experienced an identity or access-related incident in the past year, and 22% of those had direct business impact. One of the most persistent contributors is fragmented access environments that limit visibility and slow response when risk emerges.&lt;/P&gt;
&lt;H3&gt;How account discovery classifies application accounts&lt;/H3&gt;
&lt;P&gt;Every account returned from a discovery run is cate into one of three categories:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Matched and assigned&lt;/STRONG&gt;: The user exists in Microsoft Entra and is assigned to the application. These accounts are already governed and subject to your existing access controls.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Matched but unassigned&lt;/STRONG&gt;: The user exists in Microsoft Entra but is not assigned to the application. Access exists directly in the application, outside of Entra governance controls such as Conditional Access, access reviews, and lifecycle policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Orphaned &lt;/STRONG&gt;&lt;STRONG&gt;or local accounts&lt;/STRONG&gt;: No matching identity is found in Microsoft Entra. These accounts exist only in the application and have no corporate identity association.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This classification gives identity teams immediate visibility into the true access state of an application. More importantly, it provides a clear path forward. Govern what is already aligned. Bring unassigned users under policy. Investigate or remove orphaned accounts that introduce unnecessary risk.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Discover identities (Preview).&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;A real‑world example: Gaining visibility into Salesforce with account discovery&lt;/H2&gt;
&lt;P&gt;To see how account discovery works in practice, consider an organization onboarding Salesforce into Microsoft Entra ID Governance.&lt;/P&gt;
&lt;P&gt;For Zava, Salesforce has been in use for several years. During that time, accounts were created through a mix of manual provisioning, direct sign‑ups, contractors, and a legacy identity system. While the organization is ready to standardize access using Microsoft Entra, the identity team does not yet have a clear picture of who already has access or how that access was granted.&lt;/P&gt;
&lt;P&gt;Account discovery provides that visibility before any governance changes are made.&lt;/P&gt;
&lt;H3&gt;Phase 1: Establishing a baseline during application onboarding&lt;/H3&gt;
&lt;P&gt;As part of the onboarding process, the identity team runs an account discovery report directly from the Salesforce enterprise application in the Microsoft Entra admin center.&lt;/P&gt;
&lt;P&gt;Within minutes, the report returns a complete, complete view of Salesforce users:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hundreds of users match identities in Microsoft Entra but are not assigned to the application.&lt;/LI&gt;
&lt;LI&gt;A small number of accounts have no matching Entra identity and appear to be local or orphaned.&lt;/LI&gt;
&lt;LI&gt;Several service and test accounts are clearly visible for separate review.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This baseline matters. Before provisioning, access packages, or Conditional Access policies are applied, the team now understands the true access state of the application. There are no assumptions and no spreadsheets. Every existing account is accounted for.&lt;/P&gt;
&lt;P&gt;This visibility allows the identity team to plan governance intentionally instead of reacting to surprises after rollout.&lt;/P&gt;
&lt;H3&gt;Phase 2: Bringing existing users under policy‑driven access&lt;/H3&gt;
&lt;P&gt;With the discovery report in hand, the next priority is addressing the matched but unassigned users. These users are legitimate employees who already rely on Salesforce, but their access assignments exist entirely outside Entra governance.&lt;/P&gt;
&lt;P&gt;The organization has already defined access packages in Entitlement Management aligned to job functions, such as sales and customer support. Each package includes approval workflows, expiration policies, and recurring access reviews.&lt;/P&gt;
&lt;P&gt;With the discovery results, the identity team can then bring these users under governance by mapping them to the right Entitlement Management access packages—for example, assigning sales users to the sales package and support users to the support package. This turns “existing but unmanaged” access into access that’s explicitly owned and governed in Entra, with guardrails like approvals, time-bound access, and regular access reviews.&lt;/P&gt;
&lt;P&gt;Orphaned accounts are handled separately. The identity team partners with application owners to determine whether these accounts should be removed, disabled, or linked to a valid corporate identity. Importantly, these decisions are now informed by data rather than guesswork.&lt;/P&gt;
&lt;H3&gt;Phase 3: Maintaining visibility with ongoing discovery&lt;/H3&gt;
&lt;P&gt;Once Salesforce is governed and provisioning is enabled, account discovery continues to play a role in detecting and reconciling any future drift.&lt;/P&gt;
&lt;P&gt;Each month, the app owners run another discovery. This time, the report highlights a small number of new local accounts that were created directly in Salesforce outside the approved provisioning workflow. A closer look reveals a mix of expired contractor accounts, a temporary test user, and one former employee whose account was missed during offboarding.&lt;/P&gt;
&lt;P&gt;None of these accounts are subject to Conditional Access or MFA policies. Without periodic discovery, they would likely remain unnoticed.&lt;/P&gt;
&lt;P&gt;The team disables the accounts and updates internal processes so that future exceptions trigger investigation. Account Discovery becomes a recurring governance checkpoint that helps ensure access remains aligned with policy over time.&lt;/P&gt;
&lt;H2&gt;Closing the visibility gap&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;Effective identity governance includes having visibility into ungoverned access.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Most organizations inherit access across their applications. Without a clear view of who already has access, governance efforts begin with blind spots that introduce unnecessary risk. Account discovery helps close that gap by giving identity teams a practical, repeatable way to see existing application accounts and bring them under policy.&lt;/P&gt;
&lt;P&gt;Whether you are onboarding an application for the first time or validating access in a long‑running environment, visibility provides the foundation for confident governance.&lt;/P&gt;
&lt;P&gt;This is the first step in a broader journey to make identity governance more proactive, expanding visibility into access across groups and memberships, and adding enforcement controls to help prevent changes to access unless those changes come through a governed process.&lt;/P&gt;
&lt;H3&gt;Licensing and availability&lt;/H3&gt;
&lt;P&gt;Account discovery is available in public preview for organizations with &lt;STRONG&gt;Microsoft Entra ID Governance, Microsoft Entra Suite and Microsoft E7 licenses&lt;/STRONG&gt;. The capability is accessible through the Microsoft Entra admin center and through Microsoft Graph APIs.&lt;/P&gt;
&lt;H3&gt;Get started&lt;/H3&gt;
&lt;P&gt;To get started, navigate to an enterprise application in the Microsoft Entra admin center and select &lt;A class="lia-external-url" href="https://aka.ms/accountDiscoveryDocumentation" target="_blank" rel="noopener"&gt;account discovery.&lt;/A&gt; Run your first discovery in minutes and begin building a complete picture of application access across your environment.&lt;/P&gt;
&lt;P&gt;We welcome your feedback as we continue to evolve this capability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Joseph Dadzie&lt;/STRONG&gt;&lt;BR /&gt;Vice President, Product Management&lt;BR /&gt;Microsoft Entra&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://aka.ms/accountDiscoveryDocumentation" target="_blank" rel="noopener"&gt;Account Discovery documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/id-governance/identity-governance-overview" target="_blank" rel="noopener"&gt;Microsoft Entra ID Governance overview&lt;/A&gt;&amp;nbsp; &amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;⁠Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/bd-p/Azure-Active-Directory" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 30 Apr 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/you-can-t-govern-what-you-can-t-see-closing-the-identity/ba-p/4507464</guid>
      <dc:creator>Joseph Dadzie</dc:creator>
      <dc:date>2026-04-30T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft’s perspective on agentic identity standards</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-s-perspective-on-agentic-identity-standards/ba-p/2111910</link>
      <description>&lt;H2&gt;A new identity inflection point&lt;/H2&gt;
&lt;P&gt;If you’ve gotten past the headline to this first sentence, you’re probably my kind of people. You’re probably a professional in the world of IAM (Identity and Access Management) who’s looking after their own enterprise; and you may even have opinions about what the future holds that range from salty to optimistic. In the world of granting access to enable productivity while preventing fraud, we’ve been supporting impulsive humans and predictable non-human identities… and now we are in the wild and wooly world where the software could be way more YOLO than the employees.&lt;/P&gt;
&lt;P&gt;In the last year, AI agents have moved quickly from experimentation into real business roles, and identity infrastructure is necessarily along for the ride, absorbing new constructs and adapting old ones.&amp;nbsp; The landscape of standards has been evolving rapidly as well, and I believe it's important to share updates with those who may not be immersed in these discussions day-to-day. In this fast-changing environment, staying informed about developments is crucial. My goal here is to talk about what is changing in the industry at large, why it is changing, and how we at Microsoft view this critical architectural identity layer.&lt;/P&gt;
&lt;P&gt;From a standards perspective, I think the biggest industry change has been mental.&amp;nbsp; There were always entities in the standards world that were non-human and needed resource access, but a clear line in the sand existed as to what those non-human entities would be allowed to accomplish. Different kinds of non-human entities were described by their task orientation and given different names that seemed separate – OAuth Clients, SPIFFE workloads, Token Exchange Actors. These standards had different taxonomies partly so that the security promise of non-human and human interactions could be kept straight.&amp;nbsp; If software needed an access token to act on behalf of “something”, the aligned delegation request flows presumed that the “something” in that sentence was a real person; the idea of “user present” transactions became a critical part of our access management threat model and vocabulary.&amp;nbsp; In the absence of a user, different flows and standards apply. Because consent is a human concept, software cannot grant access on behalf of other software, and a separate decision-making mechanism is required. Yet here we are in a world where agents &lt;U&gt;are&lt;/U&gt; delegating, because they have enough reasoning capability to make choices.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may come to the logical conclusion that the agentic revolution therefore must have caused a standards revolution to match – but no.&amp;nbsp; The mindset change was pretty quick. In my opinion it has been aided in great part by the community developing the Model Context Protocol (MCP). MCP developed an incredible amount of momentum, and their choice to adopt OAuth for MCP authorization created a forcing function that all of us in the Enterprise world will be benefitting from for a long time to come.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Identity standards innovation&lt;/H2&gt;
&lt;P&gt;There’s a growing set of identity standards we’re paying close attention to, and each merits deeper discussion. For now, I’ll anchor on three broad areas of interest that are shaping how identity standards are evolving for agentic systems: bootstrapping of trust, delegation, and shared secrets. As a broad statement, a lot of work is going on to connect the agentic dots between families of standards, especially in areas for which manual processes could previously bridge automation gaps.&lt;/P&gt;
&lt;P&gt;The first area of work is the bootstrapping of trust between non-human entities. If you are wondering what a non-human entity is, it could be anything from an infrastructure endpoint like an OAuth authorization server to a directory-based service principal representing an application, to a workload identity working within in a hypervisor context, or now an agentic identity such as an LLM harness or an autonomous business agent. In the federation world, SAML standardized an &lt;A href="https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-idp-discovery.pdf" target="_blank" rel="noopener"&gt;IDP discovery protocol&lt;/A&gt; in 2008, OpenID Connect v1 &lt;A href="https://openid.net/specs/openid-connect-discovery-1_0.html" target="_blank" rel="noopener"&gt;included a discovery spec&lt;/A&gt; in 2014 and OAuth 2.0 Protected Resource Metadata became &lt;A href="https://datatracker.ietf.org/doc/rfc9728/" target="_blank" rel="noopener"&gt;RFC 9728&lt;/A&gt; in 2025.&amp;nbsp; Despite widespread ratification, IAM admins typically uploaded metadata manually from installation guides or app galleries. The data was static, and admins themselves served as the explicit trigger that established a clear starting point of authority for each federation contract. Agents, however, operate at different scale, and the incentive is finally in place to consistently automate a non-human entity announcing itself and requesting access, not just in one identity silo but across the entire technical landscape.&amp;nbsp; The result will be a much more connected and consolidated embrace of all sorts of secure non-human onboarding options, including OAuth CIMD (&lt;A href="https://datatracker.ietf.org/doc/draft-ietf-oauth-client-id-metadata-document/" target="_blank" rel="noopener"&gt;ClientID Metadata Document&lt;/A&gt;), a lot of work in the WIMSE working group at IETF that help &lt;A href="https://datatracker.ietf.org/doc/html/draft-ietf-wimse-workload-identity-practices-03" target="_blank" rel="noopener"&gt;SPIFFE and OAuth work better&lt;/A&gt; (SPIFFE is an open standard that operates similarly to &lt;A href="https://learn.microsoft.com/en-us/entra/identity/managed-identities-azure-resources/overview" target="_blank" rel="noopener"&gt;Managed Identities for Azure&lt;/A&gt;).&amp;nbsp; It’s also worth calling out IoT and identity wallet standards, but those deserve a deeper dive, which we’ll save for later.&lt;/P&gt;
&lt;P&gt;In addition to bootstrapping, the standards world is debating the question of delegation. This is another place where bifurcation between human and non-human identity is breaking down.&amp;nbsp; We have multiple existing concepts in identity standards like token exchange, identity chaining, transaction tokens, OBO (on behalf of), token upscoping/downscoping, and a slew of new IETF proposals all occupying everyone’s minds.&amp;nbsp; Take a look through &lt;A href="https://khaledzaky.com/blog/delegation-is-the-real-identity-problem-in-agentic-ai" target="_blank" rel="noopener"&gt;Khaled Zaky’s blog&lt;/A&gt; on this topic, and stay tuned – this debate has not yet concluded in any way.&lt;/P&gt;
&lt;P&gt;One quieter thread of work is worth calling out here. The standards world is filling those connective tissue gaps around eliminating shared secrets from agentic use.&amp;nbsp; We are already seeing abuse (and perhaps a blurring of the line between what is use and what is abuse) of shared secrets such as API keys in agent contexts – for anyone taking the time to look, bearer token abuse will be next. &amp;nbsp;Looking ahead, there will be a follow-up blog where my colleagues will explore how we’re building critical standards in this area and what that enables next.&lt;/P&gt;
&lt;H2&gt;Perspective on agentic identity standards&lt;/H2&gt;
&lt;P&gt;The deep nature of our Microsoft agentic investment is clear for all to see, but it isn’t always obvious just how much of that investment lies in collaborative spaces such as the standards community. &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/identity-platform/agent-oauth-protocols" target="_blank" rel="noopener"&gt;We have already created a foundational identity layer&lt;/A&gt; built on open standards, with a continued commitment to a standards‑based approach to trust for AI authentication, authorization, and management - one that can scale across the many industries we work with every day. Participation in communities of interest for agentic identity such as AAIF, MCP, IETF, FIDO Alliance and OpenID Foundation are ways in which we stay relevant, and they are communities I’d encourage you to follow as well.&amp;nbsp; We have a lot of learnings about what works and does not work in our very large environment and I look forward to the writing of my brilliant colleagues as they share that hard-won wisdom. In addition, for anyone who &lt;EM&gt;does&lt;/EM&gt; enjoy the technical complexity of agentic standards, &lt;A href="https://www.linkedin.com/in/pameladingle/" target="_blank" rel="noopener"&gt;follow me on LinkedIn&lt;/A&gt; for much deeper content.&amp;nbsp; One last important perspective – while I have a job title that sounds lofty in this area, the truth is that many people are working on this goal all over the company.&amp;nbsp; It is those contributions, those daily decisions to care about whether any given identity standard serves its purpose, that mean a lasting success.&amp;nbsp; Cheers to them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-P. Dingle, Director of Identity Standards&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/security-101/what-is-oauth" target="_blank" rel="noopener"&gt;What is OAuth? – Microsoft Security 101&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/surfing-the-ai-wave-manage-govern-and-protect-ai-agents-with-microsoft-entra-age/2464407" target="_blank" rel="noopener"&gt;Surfing the AI Wave: Manage, Govern, and Protect AI Agents with Microsoft Entra Agent ID | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-teams="true"&gt; &lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftechcommunity.microsoft.com%2Fblog%2Fmicrosoft-entra-blog%2Fthe-future-of-ai-agents%25E2%2580%2594and-why-oauth-must-evolve%2F3827391&amp;amp;data=05%7C02%7Cdavidellis%40microsoft.com%7Cca26cfb8637b4a18664008dea01158c5%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639124193516745278%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=ewyvjKrWZyM8tIN5L3JIyqSvBTgXQ1E0yzmOgeRptWo%3D&amp;amp;reserved=0" target="_blank" rel="noopener" aria-label="Link The future of AI agents—and why OAuth must evolve | Microsoft Community Hub"&gt;The future of AI agents—and why OAuth must evolve | Microsoft Community Hub&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra Agent ID&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" data-lia-auto-title="Microsoft Entra blog | Tech Community" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" data-lia-auto-title="Microsoft Entra discussions | Microsoft Community&amp;nbsp;" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 16:57:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-s-perspective-on-agentic-identity-standards/ba-p/2111910</guid>
      <dc:creator>Pamela Dingle</dc:creator>
      <dc:date>2026-05-06T16:57:22Z</dc:date>
    </item>
    <item>
      <title>Get ahead of agent sprawl: manage and govern AI agents at scale</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/get-ahead-of-agent-sprawl-manage-and-govern-ai-agents-at-scale/ba-p/4513160</link>
      <description>&lt;P&gt;Recently, my team and I met with customers across several industries including finance, retail, telecommunications, and the public sector regarding the topic of agent adoption. During our time with them, several key themes bubbled to the surface. While AI agent adoption is growing rapidly, we need to ensure governance is built-in right from the start and that it is designed for the rapid proliferation of agents. Our customers see agents appearing within their admin portal, but accountability, lifecycle management and access guardrails are lacking, creating situations that could lead to significant security concerns.&lt;/P&gt;
&lt;P&gt;Without clear ownership and access boundaries, risk can build quickly without clear insight about what those agents can access or do.&lt;/P&gt;
&lt;H2&gt;Agents are a new type of identity&lt;/H2&gt;
&lt;P&gt;From an identity perspective, agents can authenticate, access resources, and take action. As outlined in the &lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/bade/documents/products-and-services/en-us/security/secure-access-in-the-age-of-ai-final-2026.pdf" target="_blank" rel="noopener"&gt;Secure Access in the Age of AI&lt;/A&gt; report, security leaders need to find ways to manage, govern, and protect agent identities with the same rigor as human identities, especially as they scale agents across the enterprise. What makes agents different is that they do not fit neatly into existing categories. Sometimes an agent acts as an assistive agent and at other times it behaves more autonomously. Unlike traditional apps, agents are not static. As models and workflows evolve, agents can acquire new capabilities, which in turn can change what they are able to accomplish over time.&lt;/P&gt;
&lt;P&gt;Without a unique agent identity, customers struggle to address key questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Which agent identity is acting?&lt;/LI&gt;
&lt;LI&gt;What can it access?&lt;/LI&gt;
&lt;LI&gt;What actions did it take?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These questions point to a fundamental gap in how identity has traditionally been applied. As agents take on more responsibilities across multiple workflows, treating them simply as applications or as extensions of a user's identity is no longer sufficient. Agents need to be recognized and managed as first-class identities. &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt; provides an identity foundation that applications and platforms can integrate with, enabling agents to authenticate, access resources, and be governed using familiar identity controls&lt;/P&gt;
&lt;P&gt;When platforms integrate with Entra as their identity provider, organizations gain clearer visibility into which agent is acting, what it can access, and how its permissions evolve as models and workflows change. Built on this foundation, Microsoft Entra Agent ID organizes agent identity around three pillars, helping organizations manage AI agents at scale, govern agent identities and lifecycle, and protect agent access to resources.&lt;/P&gt;
&lt;H2&gt;Manage AI agents at scale&lt;/H2&gt;
&lt;P&gt;Organizations consistently face the same initial challenge: gaining visibility into the AI agents operating across their environment. According to our study, 80% of leaders report that AI agent usage has increased over the past year. This underscores the need for a clear view of which agents exist throughout the organization. &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=10e782e862dd6fe619ce943963ea6ea1" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt; was purpose-built to serve as the control plane for AI agents, tackling the challenges of agent management head-on. &lt;SPAN data-teams="true"&gt;With Microsoft Agent 365, organizations can streamline management for AI agents in their environment. Its agent registry provides a unified inventory of all agents operating across the organization, including both Microsoft and non‑Microsoft agents.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Get a complete view of all agents in your organization, including agents built with Microsoft AI platforms, agents from our ecosystem partners, and any agents you register yourself.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;A key building block in Microsoft Entra Agent ID is the agent blueprint. An agent identity blueprint serves as a reusable template for creating agents. It defines how agents are created, authenticated, and governed, while still allowing individual agents to be provisioned or deprovisioned independently, as needed. &lt;SPAN data-teams="true"&gt;With the agent blueprint, security teams can consistently apply consistent access controls to every agent that is created from that specific template.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;Govern agent identities and lifecycle&lt;/H2&gt;
&lt;P&gt;Once your agents are up and running, one of the biggest challenges organizations face is governing agent identities at scale. As teams experiment and deploy agents across environments, agent proliferation can happen quickly, often without consistent sponsorship, review, or retirement processes.&lt;/P&gt;
&lt;P&gt;Effective identity governance must therefore include automated lifecycle management to address agent sprawl. This means ensuring every agent has a designated sponsor, enforcing policies for how agents are created and reviewed, and automatically removing access when agents are no longer needed. Without automated lifecycle controls, dormant or inactive agents can persist and retain access long after their purpose has ended, increasing security risk and administrative burden.&lt;/P&gt;
&lt;P&gt;Microsoft Entra Agent ID helps organizations apply identity governance practices across the full agent lifecycle, from creation through decommissioning, so agent growth remains intentional, auditable, and manageable as environments become larger and more complex.&lt;/P&gt;
&lt;P&gt;Entra Agent ID supports structured governance by allowing organizations to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Identify orphaned agents and ensure every agent always has an accountable human to ensure accountability is maintained as users move or leave the organization&lt;/LI&gt;
&lt;LI&gt;Automate agent lifecycle management from creation through deactivation to help prevent agent sprawl&lt;/LI&gt;
&lt;LI&gt;Ensure agent's access is intentional, auditable and time bound with access packages&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Identify orphaned agents and automate sponsor assignments.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Protect agent access to resources&lt;/H2&gt;
&lt;P&gt;One final, and key, pain point they anticipate is maintaining operational control as agents evolve. Our recent whitepaper, &lt;A href="https://aka.ms/IDProtectionReport" target="_blank" rel="noopener"&gt;Protect Identities in the Era of AI&lt;/A&gt; reveals how identity attacks are rapidly increasing as organizations embrace cloud and AI technologies. As agents gain new capabilities and interact with more resources, organizations need confidence that access is adaptive and secure.&lt;/P&gt;
&lt;P&gt;Entra Agent ID extends familiar identity controls to agents, thereby providing organizations with the ability to&lt;S&gt;:&lt;/S&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Apply Conditional Access policies tailored to agents, enforcing requirements based on the agent identity and access.&lt;/LI&gt;
&lt;LI&gt;Block agent access automatically when risk signals increase and detect anomalous behavior such as unusual sign-in spikes or unfamiliar resource access.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Apply Conditional Access for agents: Enforce Conditional Access policies with custom security attributes, and agent compromise risk assessments.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Built for an expanding agent ecosystem&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;Enterprise environments are incredibly diverse, with organizations building agents across Microsoft platforms as well as a broad ecosystem of non‑Microsoft frameworks and tools. To support this reality, the &lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/agent-365-sdk?tabs=python" target="_blank" rel="noopener" aria-label="Link Microsoft Agent 365 SDK"&gt;Microsoft Agent 365 SDK&lt;/A&gt; enables developers to extend agents built using any agent SDK or platform with enterprise‑ready identity, observability, security, and governed access to Microsoft 365. By integrating with Microsoft Agent 365, the SDK helps organizations onboard and operate agents from any source using consistent management and identity controls.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;To learn more about Microsoft Entra Agent ID and how it empowers organizations to secure access for AI agents:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Learn: &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Explore: &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=01e7c8230a52661133cfdf100b696796" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Watch: &lt;A href="https://www.youtube.com/watch?v=N-B-kD28P2I&amp;amp;t=1s" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID Explained&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;View a demo: &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/secure-access-for-ai-agents-the-new-frontier-of-identity/4486498" target="_blank" rel="noopener"&gt;Secure access for AI agents, the new frontier of identity&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;-&lt;/STRONG&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Ngozi Nwoko, Director of Product Marketing, IDNA&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Related resources:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Webinar series: &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/simplify-your-identity-landscape-reduce-risk-and-modernize-access-for-any-identi/4486059" target="_blank" rel="noopener"&gt;Microsoft Entra on-demand&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/surfing-the-ai-wave-manage-govern-and-protect-ai-agents-with-microsoft-entra-age/2464407" target="_blank" rel="noopener"&gt;Surfing the AI Wave: Manage, Govern, and Protect AI Agents with Microsoft Entra Agent ID | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" data-lia-auto-title="Microsoft Entra blog | Tech Community" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" data-lia-auto-title="Microsoft Entra discussions | Microsoft Community&amp;nbsp;" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 06 May 2026 16:55:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/get-ahead-of-agent-sprawl-manage-and-govern-ai-agents-at-scale/ba-p/4513160</guid>
      <dc:creator>NgoziNwoko</dc:creator>
      <dc:date>2026-05-06T16:55:35Z</dc:date>
    </item>
    <item>
      <title>Tenant Configuration Management APIs are now generally available</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/tenant-configuration-management-apis-are-now-generally-available/ba-p/4513157</link>
      <description>&lt;P&gt;In our &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/microsoft-entra-tenant-governance-secure-and-manage-multi-tenant-environments-at/4462427" target="_blank" rel="noopener"&gt;previous post&lt;/A&gt;, we introduced &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview" target="_blank" rel="noopener"&gt;Microsoft Entra Tenant Governance&lt;/A&gt; and how it helps organizations secure and manage multi-tenant environments at scale. Today, we’re excited to announce that the &lt;STRONG&gt;Tenant Configuration Management (TCM) APIs are now generally available&lt;/STRONG&gt;, providing the foundation for managing configuration at scale with greater consistency and control.&lt;/P&gt;
&lt;P&gt;Before we dive deeper, let’s clarify the distinction:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt;&lt;/A&gt; is the product experience. It delivers a centralized control plane for visibility, policy enforcement, and governance across tenant configurations.&lt;/LI&gt;
&lt;LI&gt;The &lt;A href="https://learn.microsoft.com/en-us/graph/unified-tenant-configuration-management-concept-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;TCM APIs&lt;/STRONG&gt;&lt;/A&gt; are the underlying Microsoft Graph API that powers Tenant Governance’s configuration management capabilities. It enables organizations to &lt;STRONG&gt;programmatically define, export, monitor, and manage configurations across services&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Why this matters&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;As organizations grow, configuration complexity increases across identity, security, and productivity workloads. Over time, even well-configured environments can drift due to incremental changes, operational overhead, and lack of centralized control.&lt;/P&gt;
&lt;P&gt;The challenge isn’t just setting configurations correctly. &lt;STRONG&gt;It’s maintaining that state continuously&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The TCM API addresses this by enabling a shift from &lt;STRONG&gt;reactive configuration management &lt;/STRONG&gt;to a&lt;STRONG&gt; declarative and continuous model&lt;/STRONG&gt;, where desired state is defined and automatically validated over time. This helps organizations reduce risk, improve compliance, and simplify operations.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Core concepts of the TCM API&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;At its core, the TCM API brings configuration-as-code to Microsoft Entra. It introduces a model built around four connected concepts: &lt;STRONG&gt;snapshots,&lt;/STRONG&gt; &lt;STRONG&gt;baselines, monitors, and configuration drifts:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Snapshot&lt;/STRONG&gt;&lt;STRONG&gt;:&lt;/STRONG&gt; Captures the current state of tenant configurations at a point in time. This is often the starting point, helping organizations understand what’s deployed today or to establish a “known good” reference.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Baseline:&lt;/STRONG&gt; Represents the desired configuration state. Instead of manually checking settings across portals, organizations can define what compliant configuration looks like in a structured, repeatable way.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Monitor:&lt;/STRONG&gt; Continuously compares the live environment against that baseline. Any deviation is surfaced as configuration drift, giving teams clear insight into where their environment no longer aligns with expectations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Configuration drifts:&lt;/STRONG&gt; Represents the delta between the desired configuration state and the current configuration state.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these concepts create a closed loop: capture current state, define desired state, and continuously monitor alignment between the two.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;A scalable model for configuration management&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;What makes the TCM API powerful is not just visibility, but &lt;STRONG&gt;repeatability and scale&lt;/STRONG&gt;. Because everything is exposed through Microsoft Graph, configuration management can now be:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Integrated into automation workflows&lt;/LI&gt;
&lt;LI&gt;Connected to existing security and compliance systems&lt;/LI&gt;
&lt;LI&gt;Applied consistently across multiple tenants and services&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This introduces a true configuration-as-code approach, where tenant settings are no longer static or manually enforced, but programmatically defined and continuously evaluated.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How this fits into Tenant Governance&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The TCM API is the foundation that enables many of the capabilities within Microsoft Entra Tenant Governance.&lt;/P&gt;
&lt;P&gt;While the API provides raw access to configuration data and state comparison, Tenant Governance builds on top of it to deliver a &lt;STRONG&gt;unified experience for administrators&lt;/STRONG&gt;. This includes surfacing insights, highlighting drift, and enabling governance actions without requiring customers to build their own tooling.&lt;/P&gt;
&lt;P&gt;In the near future, Tenant Governance will provide a single pane of glass for managing multiple tenants centrally, powered by the TCM API. This relationship is key:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Customers&lt;/STRONG&gt; can rely on Tenant Governance for an out-of-the-box solution.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Partners and advanced organizations&lt;/STRONG&gt; can use the TCM API directly to build custom workflows, integrations, or managed services.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Final thoughts&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Tenant configuration is no longer a one-time activity. It is an ongoing process that directly impacts security, compliance, and operational consistency.&lt;/P&gt;
&lt;P&gt;With the &lt;STRONG&gt;general availability of the TCM API&lt;/STRONG&gt;, organizations now have a scalable way to define, monitor, and enforce configuration across their environments. Whether used directly or through Microsoft Entra Tenant Governance, it enables a more proactive and automated approach to managing tenant configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-Aditya Mukund&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/graph/unified-tenant-configuration-management-concept-overview" target="_blank" rel="noopener" aria-label="Link Overview of the Tenant Configuration Management APIs in Microsoft Graph - Microsoft Graph | Microso…"&gt;Overview of the Tenant Configuration Management APIs in Microsoft Graph - Microsoft Graph | Microso…&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/graph/utcm-authentication-setup" target="_blank" rel="noopener" aria-label="Link Set up authentication for Tenant Configuration Management APIs - Microsoft Graph | Microsoft Learn"&gt;Set up authentication for Tenant Configuration Management APIs - Microsoft Graph | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" data-lia-auto-title="Microsoft Entra blog | Tech Community" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" data-lia-auto-title="Microsoft Entra discussions | Microsoft Community&amp;nbsp;" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 16:58:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/tenant-configuration-management-apis-are-now-generally-available/ba-p/4513157</guid>
      <dc:creator>AdityaMukund</dc:creator>
      <dc:date>2026-05-06T16:58:33Z</dc:date>
    </item>
  </channel>
</rss>

