<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Entra Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/microsoft-entra-blog</link>
    <description>Microsoft Entra Blog articles</description>
    <pubDate>Sat, 01 Aug 2026 18:54:42 GMT</pubDate>
    <dc:creator>microsoft-entra-blog</dc:creator>
    <dc:date>2026-08-01T18:54:42Z</dc:date>
    <item>
      <title>What's New in Microsoft Entra: July 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-july-2026/ba-p/4534631</link>
      <description>&lt;P&gt;Welcome to the July edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What went into General Availability (GA) since June 2026?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/backup/overview" target="_blank"&gt;&lt;STRONG&gt;Microsoft Entra Backup and Recovery&lt;/STRONG&gt;&lt;/A&gt; - A&amp;nbsp;capability that helps organizations restore a tenant after accidental or malicious changes. On by default, it automatically backs up critical directory objects, including users, groups, applications, Service Principals, managed identities, Conditional Access policies, named locations, agent IDs, and authentication and authorization policies, so admins can return&amp;nbsp;to a known good state. The service takes daily backups of supported objects and retains them for 7 days with Microsoft Entra ID P1 or P2 licenses. Admins can view snapshots, compare changes, and run recovery jobs. This feature is a reliable safety net to minimize downtime and strengthen protection against misconfigurations and security incidents.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-access-package-assignments#directly-assign-any-identity" target="_blank"&gt;&lt;STRONG&gt;Direct admin assignment to external users using email address&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Entitlement management admins can assign external users, not in the directory, to an access package with the user's email. Users are invited into the tenant as Guest users and are governed when Microsoft Entra ID Governance is configured.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-bring-your-own-device" target="_blank"&gt;&lt;STRONG&gt;Bring your own device (BYOD) support for the Global Secure Access Windows client using Microsoft Entra‑registered devices&lt;/STRONG&gt;&lt;/A&gt; - Enable&amp;nbsp;users and partners&amp;nbsp;to access corporate resources from their own devices. Administrators can assign the&amp;nbsp;Private Application&amp;nbsp;traffic profile to users with internal accounts, including&amp;nbsp;internal guest users. This removes the previous requirement for Windows devices to be domain‑joined.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/kerberos-server-key-rotation" target="_blank"&gt;&lt;STRONG&gt;Microsoft Entra Kerberos key rotation&lt;/STRONG&gt;&lt;/A&gt; - Improves reliability for environments by using incoming trust referral flows. The update enhances authentication resiliency during key rollover by validating referral tickets with primary and secondary Kerberos keys. This combination reduces the likelihood of authentication failures and minimizes disruption during rotation events.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/direct-federation#domainless-saml-idp-federation-preview" target="_blank"&gt;&lt;STRONG&gt;Domainless SAML federation with a SAML identity provider&lt;/STRONG&gt;&lt;/A&gt; - Enable external users to sign in to applications or workforce resources using their Identity Provider (IdP)-managed credentials, regardless of their email domain. With no need to match user email domains with preconfigured identity provider domains, this capability simplifies onboarding and access for external users, streamlines invitation redemption, and improves flexibility for cross-organization collaboration in Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;New in Public Preview&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/howto-target-agent-identities" target="_blank"&gt;&lt;STRONG&gt;Strengthen AI agent security with Conditional Access&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra Conditional Access has broader controls to secure AI agents that leverage&amp;nbsp;user&amp;nbsp;accounts. Administrators can target agent user accounts more precisely by including, or excluding, agents, or by using custom security attributes for dynamic grouping. Organizations can apply Conditional Access policies, based on agent risk, require compliant devices for agents running on managed endpoints, including Windows 365 for Agents, and enforce device, network, and platform-based access conditions. These enhancements extend Zero Trust protections to agent user accounts while using the familiar Conditional Access policy experience.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/hybrid/cloud-sync/how-to-ad-group-enforcement" target="_blank"&gt;&lt;STRONG&gt;Restrict AD group changes to Microsoft Entra provisioning&lt;/STRONG&gt;&lt;/A&gt; - Designate specific Active Directory (AD) groups so all modifications are managed through the Microsoft Entra provisioning service. This capability helps maintain consistency between Microsoft Entra ID and AD by ensuring group changes are centrally controlled. Reduce configuration drift and improve alignment across identity systems.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;STRONG&gt;Generate unique aliases with custom call-outs&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;- Use custom call-outs with Azure Logic Apps during user provisioning to perform advanced attribute transformations that meet your organization's requirements. Custom call-outs can generate values such as unique employee aliases and are supported for create events in HR inbound, SaaS outbound, and cross-tenant synchronization provisioning flows in Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;Announcements&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-US/authenticator/jailbreak-root-detection-in-microsoft-authenticator" target="_blank"&gt;&lt;STRONG&gt;Jailbreak/root detection in Microsoft Authenticator&lt;/STRONG&gt;&amp;nbsp;&lt;/A&gt;- This feature strengthens security by preventing Microsoft Entra credentials from being added or used on jailbroken or rooted devices. Users move to compliant devices to continue using work or school accounts in Authenticator.&amp;nbsp;It is secure by default, requires no admin configuration, and applies to iOS and Android. Personal and third-party accounts are not affected.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Starting August 2026, Microsoft Authenticator on iOS will offer an improved backup and restore experience&lt;/STRONG&gt; - Users can back up account names securely by using iCloud and iCloud Keychain with end-to-end encryption. This experience includes work or school accounts, Microsoft personal accounts, and non-Microsoft accounts like Amazon or Google, also third-party time-based one-time password (TOTP). No other credentials are included in the backup. This update removes the need for a Microsoft personal account and simplifies device setup by automatically restoring account names on new iOS devices. Users manage the feature through iCloud settings&lt;/P&gt;
&lt;H2&gt;New guidance and information&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/app-provisioning/enable-scim-api" target="_blank"&gt;&lt;STRONG&gt;SCIM APIs available in U.S. Government Cloud&lt;/STRONG&gt;&lt;/A&gt; -&amp;nbsp;Microsoft Entra SCIM 2.0 APIs, which went into GA, in the public cloud, earlier in 2026, are available in Microsoft U.S. Government Cloud. Organizations can use standards-based SCIM operations to provision and manage users and groups in Microsoft Entra ID from external SCIM-compatible identity sources. Enable scalable identity lifecycle management, while you reduce the need for custom integrations.&lt;/P&gt;
&lt;H2&gt;Tell us what you think!&lt;/H2&gt;
&lt;P&gt;If you have feedback on this newsletter, fill out the dedicated &lt;A href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR3tZ6taaY2dAnA0rWwJeTkRUM1BUWjM5TjI5Sk1HME45TVVYOEdBNkJRNy4u" target="_blank"&gt;Microsoft Form&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Blogs&lt;/H2&gt;
&lt;P&gt;Check out the latest blog posts on our &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity" target="_blank"&gt;Microsoft Entra Blog&lt;/A&gt; and our &lt;A href="https://aka.ms/devblog/ms-entra" target="_blank"&gt;Microsoft Entra Identity Developer Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What's new in Microsoft Entra?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new" target="_blank"&gt;Learn what is new with Microsoft Entra&lt;/A&gt;, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find &lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new-sovereign-clouds" target="_blank"&gt;releases specific for Sovereign Clouds&lt;/A&gt; on a dedicated release notes page.&lt;/P&gt;
&lt;H2&gt;Become a certified Microsoft Identity and Access Administrator&lt;/H2&gt;
&lt;P&gt;Check out the &lt;A href="https://learn.microsoft.com/credentials/certifications/exams/sc-300/" target="_blank"&gt;certification&lt;/A&gt; and related &lt;A href="https://learn.microsoft.com/credentials/certifications/identity-and-access-administrator/" target="_blank"&gt;training&lt;/A&gt; for the Microsoft Identity and Access Administrator available for customers and partners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Martin Coetzer&lt;/P&gt;
&lt;P&gt;Principal Product Manager, Identity and Network Access, Customer Experience Engineering (CXE)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra" target="_blank"&gt;Microsoft Entra Community | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 24 Jul 2026 17:47:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-july-2026/ba-p/4534631</guid>
      <dc:creator>Martin_Coetzer</dc:creator>
      <dc:date>2026-07-24T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Modernize SAP Identity Management with Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/modernize-sap-identity-management-with-microsoft-entra/ba-p/4528596</link>
      <description>&lt;P&gt;Many organizations are rethinking how they manage identity across their SAP landscape as they move away from on-premises identity management systems and adopt a more unified cloud strategy. That shift often starts with a practical question: how do you connect SAP identity processes with the rest of your application estate without introducing more complexity?&lt;/P&gt;
&lt;P&gt;That is where the ongoing work between Microsoft Entra and SAP can help. Over the past several years, we have continued to expand integration points that help organizations automate lifecycle changes, apply access policies more consistently, and strengthen governance across SAP and non-SAP applications.&lt;/P&gt;
&lt;P&gt;If you are transitioning from SAP Identity Management (SAP IDM), modernizing an existing SAP identity architecture, or looking for better access governance across business-critical systems, the &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/scenarios/migrate-from-sap-idm" target="_blank" rel="noopener"&gt;latest integrations&lt;/A&gt; in Microsoft Entra can help.&lt;/P&gt;
&lt;P&gt;In this post, I’ll highlight what’s new, recap the key integration points, and explain how these capabilities can support your identity modernization journey.&lt;/P&gt;
&lt;H2&gt;What’s new in Microsoft Entra and SAP integrations&lt;/H2&gt;
&lt;P&gt;Over the &lt;A href="https://techcommunity.microsoft.com/discussions/microsoft-entra/new-blog--sap-identity-management-to-microsoft-entra-id-migration-guidance-now-a/4164406" target="_blank" rel="noopener"&gt;past two years&lt;/A&gt;, Microsoft Entra and SAP have continued to deepen interoperability and support more deployment models. Key updates include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;More flexible provisioning patterns between Microsoft Entra and SAP Cloud Identity Services&lt;/LI&gt;
&lt;LI&gt;Support for custom extension attributes on Microsoft Entra users for SAP-specific scenarios&lt;/LI&gt;
&lt;LI&gt;Account discovery to identify accounts in SAP Cloud Identity Services that are not yet correlated with users in Microsoft Entra&lt;/LI&gt;
&lt;LI&gt;OAuth 2.0 client credentials support to secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services&lt;/LI&gt;
&lt;LI&gt;Integration between Microsoft Entra ID Governance and SAP Identity Access Governance (SAP Identity Access Governance), so organizations can request and govern SAP business roles alongside other access rights&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities help organizations create a more unified identity control plane across SAP and the rest of the enterprise.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;“This partnership brings together the best of both worlds: Microsoft Entra’s identity-first foundation and SAP Access Governance’s (SAP Identity Access Governance and SAP Access Control) deep business and access risk context, enriched with AI to transform access governance into a continuous, intelligent trust model.”&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Swetta Singh, Strategic Product Manager for Access Governance solutions, SAP&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;A centralized identity control plane for SAP and beyond&lt;/H2&gt;
&lt;P&gt;Microsoft Entra provides a centralized identity layer that integrates with SAP applications and platforms. With it, organizations can automate joiner, mover, and leaver processes, apply access policies more consistently, and strengthen governance across a broader set of systems.&lt;/P&gt;
&lt;P&gt;That kind of consistency matters in complex environments. For example, &lt;A href="https://www.microsoft.com/en/customers/story/26155-cenibra-celulose-nipo-brasileira-sa-microsoft-entra-id-governance" target="_blank" rel="noopener"&gt;Cenibra&lt;/A&gt; used Microsoft Entra ID Governance to modernize identity management across more than 80 systems, including SAP as a core platform. That approach helped reduce manual work, improve audit readiness, and create a more scalable foundation for managing access.&lt;/P&gt;
&lt;H2&gt;SAP Cloud Identity Services: More flexible provisioning&lt;/H2&gt;
&lt;P&gt;SAP Cloud Identity Services centralizes authentication and provisioning across SAP applications. It provides single sign-on and helps organizations provision users and groups more consistently to downstream SAP systems.&lt;/P&gt;
&lt;P&gt;The latest integration improvements with Microsoft Entra give organizations more flexibility in synchronizing users and groups across both environments through standards-based approaches. This flexibility helps teams maintain consistent identity data between Microsoft Entra and SAP environments while using SAP Cloud Identity Services to distribute identities to downstream cloud-hosted and on-premises SAP applications.&lt;/P&gt;
&lt;P&gt;Some of the recent updates include:&lt;/P&gt;
&lt;H3&gt;Custom extension attributes for SAP-specific scenarios&lt;/H3&gt;
&lt;P&gt;Many SAP environments depend on attributes tied to business processes, regions, or organizational structures. Microsoft Entra now supports provisioning custom extension attributes on users in those scenarios, making it easier to align identity data with the needs of SAP applications.&lt;/P&gt;
&lt;H3&gt;Account discovery for SAP Cloud Identity Services&lt;/H3&gt;
&lt;P&gt;Microsoft Entra account discovery retrieves accounts from SAP Cloud Identity Services so you can identify accounts that are not yet correlated with users in Microsoft Entra. This visibility can help teams reduce manual investigation and strengthen governance.&lt;/P&gt;
&lt;H3&gt;OAuth 2.0 client credentials for connector authentication&lt;/H3&gt;
&lt;P&gt;We have also updated connector authentication to use OAuth 2.0 client credentials. This change helps secure service-to-service communication between Microsoft Entra and SAP Cloud Identity Services and supports a more modern integration approach.&lt;/P&gt;
&lt;H2&gt;SAP Identity Access Governance integration&lt;/H2&gt;
&lt;P&gt;SAP Identity Access Governance is SAP’s cloud-based access governance solution. The integration between Microsoft Entra ID Governance and SAP Identity Access Governance connects SAP role governance to a broader access strategy, allowing users to request or receive SAP business roles through Microsoft Entra access packages alongside non-SAP access rights.&lt;/P&gt;
&lt;P&gt;This integration matters because access governance often spans applications: employees, contractors, and partners may need coordinated access across SAP and non-SAP resources. Organizations can use the integration to manage those requests consistently across applications.&lt;/P&gt;
&lt;P&gt;When a user requests assignment to an access package with an SAP business role through Microsoft Entra, the request is sent automatically to SAP Identity Access Governance. SAP Identity Access Governance then enforces approvals and additional checks within its own governance process. This approach helps organizations connect enterprise-wide access packages in Microsoft Entra with the business role and risk context available in SAP Identity Access Governance.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra integrates with SAP Cloud Identity Services and SAP Identity Access Governance to support authentication, user provisioning, and identity governance across SAP applications.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Migration projects move faster with the right partner support&lt;/H2&gt;
&lt;P&gt;A successful transition from legacy IAM products such as SAP IDM often depends on practical experience across both SAP environments and enterprise identity platforms. Many organizations work with partners who can support SAP system integration, Microsoft Entra identity and governance capabilities, and identity strategies that connect SAP with the rest of the application estate.&lt;/P&gt;
&lt;P&gt;If you are planning a migration and want to involve a partner, review the partner list in &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/scenarios/migrate-from-sap-idm" target="_blank" rel="noopener"&gt;Migrate identity management scenarios from SAP IDM to Microsoft Entra&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Beyond identity: Microsoft Security for SAP&lt;/H2&gt;
&lt;P&gt;Identity establishes the foundation for securing SAP in your security environment. In addition to Microsoft Entra, Microsoft delivers SAP-aware capabilities aligned with the NIST Cybersecurity Framework:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Identify&lt;/STRONG&gt;: Microsoft Purview discovers and classifies sensitive SAP data—including data mirrored into Microsoft Fabric through SAP Datasphere—helping organizations apply more consistent data security policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Protect&lt;/STRONG&gt;: Microsoft Defender safeguards the endpoints, servers, and cloud resources surrounding SAP applications with continuous, adaptive controls.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt;: &lt;SPAN data-teams="true"&gt;Microsoft Sentinel connects SAP signals across your estate to detect incidents, with built-in analytics rules in an SAP-certified solution that cover known threats. Through strategic partnership with SAP, organizations can also incorporate security telemetry from SAP Enterprise Threat Detection (ETD) and SAP LogServ, providing broader visibility into SAP-specific threats and activities alongside the rest of the enterprise security estate&lt;/SPAN&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Respond&lt;/STRONG&gt;: Microsoft Security Copilot accelerates investigation and guides response, helping teams contain SAP incidents faster.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together with the identity investments described above, these capabilities advance an identity-first Zero Trust strategy across the SAP environment. Microsoft uses these same capabilities across its global SAP estate.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;If you are evaluating your SAP identity strategy, now is a good time to review how your current architecture maps to the latest integration options in Microsoft Entra.&lt;/P&gt;
&lt;P&gt;Start with these resources:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/MigrateFromSAPIDM" target="_blank" rel="noopener"&gt;Read the SAP IDM to Microsoft Entra migration guidance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/sap" target="_blank" rel="noopener"&gt;Manage access to your SAP applications&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://demos.microsoft.com/Microsoft/play/6373/securing-sap-workloads-end-to-end-protection-with-microsoft-security#/0/0" target="_blank" rel="noopener"&gt;Watch a demo of Securing SAP Workloads: End-to-End Protection with Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;As always, I would love to hear about your SAP identity modernization journey and the topics you would like us to cover next.&lt;/P&gt;
&lt;P&gt;Thanks for reading,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Mark Wahl&lt;BR /&gt;Product Architect, Microsoft Entra&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/mawahl/" target="_blank" rel="noopener"&gt;Mark Wahl | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en/customers/story/26155-cenibra-celulose-nipo-brasileira-sa-microsoft-entra-id-governance" target="_blank" rel="noopener"&gt;Microsoft ID Governance Case Study&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/app-provisioning/plan-sap-user-source-and-target" target="_blank" rel="noopener"&gt;Plan deploying Microsoft Entra for user provisioning with SAP | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 17:54:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/modernize-sap-identity-management-with-microsoft-entra/ba-p/4528596</guid>
      <dc:creator>Mark_Wahl</dc:creator>
      <dc:date>2026-07-24T17:54:07Z</dc:date>
    </item>
    <item>
      <title>Microsoft Entra ID enhances security of branded sign-ins</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-enhances-security-of-branded-sign-ins/ba-p/4537471</link>
      <description>&lt;P&gt;To align with Microsoft’s &lt;A href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative?msockid=22346ecb805f631739b27a6e81726266" target="_blank" rel="noopener"&gt;Secure Future Initiative&lt;/A&gt;&amp;nbsp;and its focus on identity security and phishing resistance, we’re evolving &lt;A href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding" target="_blank" rel="noopener"&gt;Microsoft Entra custom branding&lt;/A&gt; to help customers deliver sign-in experiences that are more secure, reliable, and consistent.&lt;/P&gt;
&lt;P&gt;Beginning&amp;nbsp;&lt;STRONG&gt;October 26, 2026&lt;/STRONG&gt;, Microsoft Entra will retire support for&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fentra%2Ffundamentals%2Freference-company-branding-css-template%23deprecation-of-custom-css-positioning-properties&amp;amp;data=05%7C02%7Cmkokkalera%40microsoft.com%7C5db9189be1024d5cdb6708dee1ff5ea1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639196684102815380%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=RxKo2Q49Kz4IBUAZ%2F5EbyrAWWHQukpqG29LWg3UlQho%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt; &lt;STRONG&gt;custom CSS positioning properties&lt;/STRONG&gt;&lt;/A&gt; used in custom branding. &lt;STRONG&gt;Full retirement of all custom CSS&lt;/STRONG&gt; is planned for &lt;STRONG&gt;later in 2027&lt;/STRONG&gt;. Microsoft will provide advance notice ahead of this milestone, along with alternative customization options.&lt;/P&gt;
&lt;P&gt;These changes add an additional layer of security by reducing opportunities for deceptive page layouts and helping ensure trusted, recognizable sign-in experiences that better protect users from phishing attacks.&lt;/P&gt;
&lt;H2&gt;When will this happen?&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;July 21, 2026: &lt;/STRONG&gt;Microsoft Entra ID tenants &lt;STRONG&gt;not &lt;/STRONG&gt;using custom CSS positioning properties before July 21, 2026, will not be able to configure them going forward.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;October 26, 2026: &lt;/STRONG&gt;Microsoft Entra ID will retire custom CSS positioning properties globally.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Later in 2027: &lt;/STRONG&gt;Microsoft Entra plans to move towards full custom CSS retirement, with advance notice provided.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Who will be affected?&lt;/H2&gt;
&lt;P&gt;To retire support for positioning properties, Microsoft is helping prevent tenants from creating new dependencies on custom CSS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Tenants that will be affected and need to take action by October 26, 2026:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Entra ID tenants that already use custom CSS positioning properties. After this date, these properties will be blocked and will no longer function.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tenants that are not affected:&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Entra ID tenants that&amp;nbsp;&lt;STRONG&gt;do not&lt;/STRONG&gt; already use custom CSS positioning properties will not be able to configure them after July 21, 2026.&lt;/LI&gt;
&lt;LI&gt;New Microsoft Entra ID tenants created after January 5, 2026, do not have custom CSS available for custom branding.&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra External ID tenants.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;How will this affect your organization?&lt;/H2&gt;
&lt;P&gt;Microsoft Entra ID customers using the deprecated positioning properties may see changes to the layout of their branded sign-in experience after October 26, 2026, and won’t have a supported migration or replacement. In most cases, branding elements such as logos, images, or text will remain visible but will appear in their default state once the positioning properties are no longer honored.&lt;/P&gt;
&lt;P&gt;If your Microsoft Entra ID tenant uses any of these custom CSS positioning properties below in either &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding" target="_blank" rel="noopener"&gt;Company Branding&lt;/A&gt; or &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding-themes-apps" target="_blank" rel="noopener"&gt;Branding Themes&lt;/A&gt; , we recommend removing them from your configuration:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;position (including top&lt;/STRONG&gt;, &lt;STRONG&gt;right&lt;/STRONG&gt;, &lt;STRONG&gt;bottom&lt;/STRONG&gt;, &lt;STRONG&gt;left&lt;/STRONG&gt;, and &lt;STRONG&gt;z-index)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;margin&lt;/STRONG&gt;&lt;STRONG&gt; (including margin-top, margin-bottom, margin-left, &lt;/STRONG&gt;&lt;STRONG&gt;and &lt;/STRONG&gt;&lt;STRONG&gt;margin-right)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;transform&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;opacity&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;overflow&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;filter&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;pointer&lt;/STRONG&gt;&lt;STRONG&gt;-events&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;clip&lt;/STRONG&gt;&lt;STRONG&gt;-path&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;mix&lt;/STRONG&gt;&lt;STRONG&gt;-blend-mode&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;translate&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft Entra ID customers who use the properties above will be notified directly in advance.&lt;/P&gt;
&lt;H2&gt;What do you need to do to prepare?&lt;/H2&gt;
&lt;P&gt;To determine whether your tenant uses positioning properties and requires you to take action:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure you use a global administrator or branding administrator role.&lt;/LI&gt;
&lt;LI&gt;Navigate to &lt;A href="https://developer.microsoft.com/en-us/graph/graph-explorer" target="_blank" rel="noopener"&gt;MS Graph Explorer&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Sign in into your tenant using the 'profile/sign in' button at the top right corner.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;If you have your tenantID, skip to step 5. Otherwise, you can get this by sending a GET request to the organization resource on the MS Graph Explorer. To do this, enter &lt;STRONG&gt;https://graph.microsoft.com/v1.0/organization &lt;/STRONG&gt;and run the query. Then, copy the “id” value of the response.&amp;nbsp;&lt;img /&gt;&lt;/LI&gt;
&lt;LI&gt;Get all the configured company branding locales by sending a GET request to the branding resource. To do this, enter &lt;STRONG&gt;https://graph.microsoft.com/v1.0/organization/&amp;lt;your tenant ID here&lt;/STRONG&gt;&lt;STRONG&gt;&amp;gt;/branding/localizations&lt;/STRONG&gt; and run the query.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="6"&gt;
&lt;LI&gt;Copy the contents of the response or export it to a JSON file&lt;/LI&gt;
&lt;LI&gt;Navigate to this &lt;A href="https://entra-branding-tools.github.io/tenant-branding-inspector/" target="_blank" rel="noopener"&gt;tool&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Paste the contents from step 6 or upload the exported JSON file to the input in the tool. You should get a list of locales and the properties impacted for each locale. These properties will be deprecated and are encouraged to be removed from your configuration.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Next steps&lt;/H2&gt;
&lt;P&gt;With these updates, Microsoft Entra custom branding continues to evolve as part of our proactive investment in secure, trusted, and consistent sign-in experiences.&lt;/P&gt;
&lt;P&gt;To ensure a smooth transition, we encourage you to review your custom CSS configurations and remove any affected properties ahead of time. This will help you catch and address potential layout issues early, so your users stay protected and your branded sign-in experience remains seamless.&lt;/P&gt;
&lt;P&gt;We’ll provide advance notice, guidance, and alternative customization options before broader custom CSS retirement. Thank you for your partnership as we make this transition.&lt;/P&gt;
&lt;P&gt;-Adam Steenwyk&lt;/P&gt;
&lt;P&gt;Principal Lead Product Manager, Microsoft Identity, Authentication Experiences&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Flearn.microsoft.com%2Fentra%2Ffundamentals%2Freference-company-branding-css-template%23deprecation-of-custom-css-positioning-properties&amp;amp;data=05%7C02%7Cmkokkalera%40microsoft.com%7C5db9189be1024d5cdb6708dee1ff5ea1%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639196684102815380%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=RxKo2Q49Kz4IBUAZ%2F5EbyrAWWHQukpqG29LWg3UlQho%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Custom CSS overview &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding-themes-apps" target="_blank" rel="noopener"&gt;Customize the sign-in experience for your application with branding themes&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/how-to-customize-branding" target="_blank" rel="noopener"&gt;Configure your Company Branding&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative?msockid=22346ecb805f631739b27a6e81726266" target="_blank" rel="noopener"&gt;Microsoft Secure Future Initiative (SFI)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least-privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and cloud environments.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 21 Jul 2026 17:58:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-enhances-security-of-branded-sign-ins/ba-p/4537471</guid>
      <dc:creator>Adam Steenwyk</dc:creator>
      <dc:date>2026-07-21T17:58:43Z</dc:date>
    </item>
    <item>
      <title>Secure AI, web, and private apps with Zero Trust</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-web-and-private-apps-with-zero-trust/ba-p/4516387</link>
      <description>&lt;P&gt;Today's threats don't respect boundaries. As AI agents proliferate across enterprise workflows, employees work from everywhere, and organizations adopt cloud-first architectures, the attack surface has fundamentally shifted. Traditional perimeter security can no longer keep pace with how work actually happens.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-internet-access" target="_blank" rel="noopener"&gt;Microsoft Entra Internet Access&lt;/A&gt; and &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access" target="_blank" rel="noopener"&gt;Microsoft Entra Private Access&lt;/A&gt; extend Zero Trust principles to all traffic, ensuring that every access request is verified against identity, device, and risk context, whether it originates from a user, a device, or an AI agent.&lt;/P&gt;
&lt;P&gt;Today, we're building on our &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/lock-down-ai-web-and-private-apps-what%E2%80%99s-new-in-internet-access-and-private-acce/3847825" target="_blank" rel="noopener"&gt;recent announcement&lt;/A&gt;, where we introduced a significant wave of new capabilities across both public preview and general availability. These updates span AI security, data protection, private access, and connectivity resilience, bringing the breadth of our SASE platform to meet the security demands of the AI era.&lt;/P&gt;
&lt;H1&gt;Now in public preview: deeper controls for AI, data, and access&lt;/H1&gt;
&lt;P&gt;&lt;EM&gt;Microsoft Entra Internet Access and Microsoft Entra Private Access&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This July, we’re introducing new capabilities in public preview to help you secure AI interactions, protect sensitive data, strengthen access controls, and improve operational resilience—all through an identity-first approach to security. These capabilities bring deeper visibility and policy enforcement across users, AI agents, devices, locations, and applications, helping you innovate with confidence while maintaining Zero Trust principles.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with-microsoft-purview-/4529310" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Network Data Loss Protection (DLP) &lt;/STRONG&gt;&lt;/A&gt;extends Microsoft Purview data security to the network layer with Microsoft Entra Internet Access. Discover sensitive content in risky AI and cloud apps, block unsafe sharing (including file uploads, prompts, and responses), and apply context-aware controls based on identity and activity.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra network controls are now available for agents, &lt;/STRONG&gt;&lt;/A&gt;including Microsoft Copilot Studio agents and those running on user endpoint devices, and local agents such as OpenClaw. These controls can help identify unsanctioned AI usage, restrict connections to only approved web destinations, filter risky file movement, and help block malicious prompt-based attacks before they lead to harmful actions.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-manage-internet-access-profile" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Custom Acquire and Agentic Acquire&lt;/STRONG&gt;&lt;/A&gt; on Entra Internet Access traffic profile enables side by side deployment of Global Secure Access for AI Gateway and Agentic scenarios with other vendors.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/agents/network-security-globalsecureaccess" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 365 for Agents&lt;/STRONG&gt;&lt;/A&gt; integrates with Global Secure Access platform to provide enterprise-grade network security to agentic Cloud PCs with traffic monitoring, web filtering and threat blocking on agentic sessions.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1: Demo of Network data security&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;&lt;SPAN data-teams="true"&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank" rel="noopener" aria-label="Link See the full demo here"&gt;See the full demo here.&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Now generally available: broader coverage and stronger controls for users, applications, and AI&lt;/H2&gt;
&lt;P&gt;As secure access becomes foundational to every AI, cloud, and hybrid work initiative, organizations need solutions that are both powerful and operationally simple. The latest generally available capabilities for Microsoft Entra Internet Access and Microsoft Entra Private Access help organizations accelerate Zero Trust adoption, extend protection to unmanaged and remote environments, and gain greater visibility into how users, applications, and AI services interact with enterprise resources. The following capabilities are now GA and ready for organizations to deploy:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/concept-explicit-forward-proxy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Browser-based access to internet resources&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;for&lt;STRONG&gt; &lt;/STRONG&gt;Microsoft Entra Internet Access&lt;STRONG&gt; &lt;/STRONG&gt;extends secure web access to kiosk and BYOD devices using PAC file-based proxy configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-bring-your-own-device" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;BYOD with Client &lt;/STRONG&gt;&lt;/A&gt;in Microsoft Entra Private Access lets you enforce Zero Trust for unmanaged devices, so employees and contractors can securely access private apps without compromising security or user experience.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-view-model-context-protocol-logging" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Shadow MCP Visibility &lt;/STRONG&gt;&lt;/A&gt;provides advanced monitoring and analysis capabilities for MCP traffic between client MCP on devices and remote MCP servers. This feature provides thorough visibility into which MCP servers are being used, what tools and resources they expose, and how those tools are invoked.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Want to Learn More?&lt;/H1&gt;
&lt;P&gt;Join our three-part webinar series, &lt;STRONG&gt;Securing Data and Access in the Era of AI&lt;/STRONG&gt; (July 21–23, 9:00 AM PDT), where Microsoft Entra and Microsoft Purview product leaders will share practical guidance for securing data, governing access, and scaling AI adoption with confidence. &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/securing-data-and-access-in-the-era-of-ai-with-microsoft-entra-and-microsoft-pur/4529488" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Save the dates and register to attend&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;-Sinead O’Donovan | VP of Product Management, Identity and Network Access&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/sineadco/" target="_blank" rel="noopener"&gt;Sinead O'Donovan | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with-microsoft-purview-/4529310" target="_blank" rel="noopener"&gt;Protect sensitive data in motion across SaaS and AI apps with Microsoft Purview and Microsoft Entra&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/secure-ai-at-scale-join-the-microsoft-entra--purview-webinar-series/4530257" target="_blank" rel="noopener"&gt;Secure AI at scale: Join the Microsoft Entra + Purview webinar series | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/lock-down-ai-web-and-private-apps-what%E2%80%99s-new-in-internet-access-and-private-acce/3847825?afd_azwaf_tok=eyJraWQiOiIxNkY3M0JFMkNDMjZDOUM1ODBGMzM4NjAzN0I1ODRCQTc4REQ1ODcwQUFFRkJGNEZDRUJFOUZEQkNGMENGMTNEIiwiYWxnIjoiUlMyNTYifQ.eyJhdWQiOiJ0ZWNoY29tbXVuaXR5Lm1pY3Jvc29mdC5jb20iLCJleHAiOjE3ODEyOTMyMjAsImlhdCI6MTc4MTI5MzIxMCwiaXNzIjoidGllcjEtNzlkNjZkNmJjNC12cHdseiIsInN1YiI6IjQuMTk0LjEyMi4xNzAiLCJkYXRhIjp7InR5cGUiOiJpc3N1ZWQiLCJyZWYiOiIyMDI2MDYxMlQxOTQwMTBaLTE3OWQ2NmQ2YmM0dnB3bHpoQzFJQURyNDIwMDAwMDAwMDRiMDAwMDAwMDAwNjlnZCIsImIiOiJ6akpLY3dSOVRBZEZFb20xamdtQmlJb2YwVVJ2cXRHRXpyQnRBVTBOV2RJIiwiaCI6IjFMeXQ5V2xqYm91MUhRaGgySjU1Zk9xS1g1VmY0dzdfYmtKeHRGVVJUUVEifX0.h86gKB4lhy7qwzePrV7-KLzLc1zwm3AZl2qB5ERV7DfxMyTaU-eAN2Cu3dLQeER-Q2RwUeTxCJEc0Gy6tNOWko7TzAzRtYuPmuAJoXx3jiEJ75hW5IyIHkDq0HpP0Ld-VaTCTq2BJ4DztT5KcfzNKzvbSbxl1ChkBuLdDHUkc4Hkvyr28gnKETNR54OYUimxk9DEETWO5F_SbVEVYrISxsF9S0sDfGOex0Dkef3xNbqjHaSuzVu-xdzKThqbtKjXTIpnITXrnW_3Y7T0SI7UfE4oLFCOFtvq0rglqd9wAR05bOncmb3l9IJVnMlqUdi6wU7tYT-994uUtvfgOCYR-Q.WF3obl2IDtqgvMFRqVdYkD5s" target="_blank" rel="noopener"&gt;Lock down AI, web, and private apps: what’s new in Internet Access and Private Access&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-private-access" target="_blank" rel="noopener"&gt;Microsoft Entra Private Access | Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-internet-access" target="_blank" rel="noopener"&gt;Microsoft Entra Internet Access | Microsoft Security&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 05:13:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-web-and-private-apps-with-zero-trust/ba-p/4516387</guid>
      <dc:creator>Sinead_ODonovan</dc:creator>
      <dc:date>2026-07-21T05:13:32Z</dc:date>
    </item>
    <item>
      <title>Plan your Azure AD B2C migration with the Migration Policy Analyzer</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/plan-your-azure-ad-b2c-migration-with-the-migration-policy/ba-p/4532874</link>
      <description>&lt;H2&gt;Migration planning starts with visibility&lt;/H2&gt;
&lt;P&gt;One of the first challenges organizations face when &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930about:blank" target="_blank" rel="noopener"&gt;planning a migration from Azure AD B2C to Microsoft Entra External ID&lt;/A&gt; is understanding exactly what is implemented in their tenant today.&lt;/P&gt;
&lt;P&gt;Over time, Azure AD B2C deployments often grow to include custom user journeys, federation integrations, claims transformations, API connections, and tailored sign-up and sign-in experiences. As teams change and solutions evolve, assessing migration scope can become time-consuming and complex.&lt;/P&gt;
&lt;P&gt;To help organizations accelerate migration planning, the&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-analyze-azure-ad-b2c-custom-policies" target="_blank"&gt; &lt;STRONG&gt;Migration Policy Analyzer&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;is now &lt;STRONG&gt;Generally Available&lt;/STRONG&gt; (&lt;STRONG&gt;GA&lt;/STRONG&gt;).&amp;nbsp; This capability analyzes your Azure AD B2C custom policies and generates a structured assessment of the authentication features implemented, reducing the manual effort and guesswork that typically slow down early migration planning.&lt;/P&gt;
&lt;P&gt;The resulting report helps architects and technical decision-makers understand migration readiness, identify implementation gaps, and prioritize next steps.&lt;/P&gt;
&lt;H2&gt;Understand your current implementation&lt;/H2&gt;
&lt;P&gt;Available through the&lt;A href="https://learn.microsoft.com/en-us/azure/active-directory-b2c/custom-policy-overview" target="_blank"&gt; &lt;STRONG&gt;Identity Experience Framework&lt;/STRONG&gt;&lt;/A&gt; experience in Azure AD B2C, Migration Policy Analyzer performs a deterministic analysis of custom policy definitions. It is important to note that the analysis is scoped to the Azure AD B2C custom policies within IEF; it is not a full tenant-wide scan and produces an inventory of the authentication capabilities implemented in those policies.&lt;/P&gt;
&lt;P&gt;The assessment provides guidance on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Authentication features detected in custom policies&lt;/LI&gt;
&lt;LI&gt;Migration paths to Microsoft Entra External ID&lt;/LI&gt;
&lt;LI&gt;Scenarios that may require custom development&lt;/LI&gt;
&lt;LI&gt;Areas where an alternative architectural approach may be recommended&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Rather than manually reviewing policy files, teams receive a structured assessment that can serve as a starting point for migration planning and technical discovery.&lt;/P&gt;
&lt;H2&gt;Generate a migration assessment in three steps&lt;/H2&gt;
&lt;P&gt;Getting started requires no policy modifications or additional configuration:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the &lt;STRONG&gt;Identity Experience Framework&lt;/STRONG&gt; in your Azure AD B2C tenant.&lt;/LI&gt;
&lt;LI&gt;Select a policy and click on &lt;STRONG&gt;Analyze policy&lt;/STRONG&gt; to begin policy analysis.&lt;/LI&gt;
&lt;LI&gt;Review and download the generated migration assessment report.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img /&gt;
&lt;P&gt;The analyzer scans your custom policy definitions and produces a report that can be shared across engineering, architecture, and business stakeholders.&lt;/P&gt;
&lt;H2&gt;See Migration Policy Analyzer in action&lt;/H2&gt;
&lt;P&gt;Migration Policy Analyzer analyzes Azure AD B2C custom policies and generates a migration assessment to help organizations plan their move to Microsoft Entra External ID.&lt;/P&gt;
&lt;DIV style="position: relative; width: 100%; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;&lt;IFRAME src="https://medius.microsoft.com/Embed/video-nc/11e93c1a-e082-4914-b903-7b83bb7ee7e0?r=75985634368" title="Demo" allowfullscreen="allowfullscreen" frameborder="0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%;" sandbox="allow-scripts allow-same-origin allow-forms"&gt;&lt;/IFRAME&gt;&lt;/DIV&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The Migration Policy Analyzer analyzes Azure AD B2C custom policies and generates a&lt;/EM&gt; migration &lt;EM&gt;assessment to help organizations plan their move to Microsoft Entra External ID.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Understand migration readiness&lt;/H2&gt;
&lt;P&gt;Each detected capability is categorized to help organizations evaluate migration complexity and planning requirements:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Available - Capabilities that can be implemented using existing Microsoft Entra External ID functionality, including common sign-up and sign-in experiences, federation scenarios, verification workflows, and account recovery experiences.&lt;/LI&gt;
&lt;LI&gt;Requires Custom Development -&amp;nbsp;Capabilities that may require extensibility mechanisms, API integrations, partner-developed solutions, or additional application logic.&lt;/LI&gt;
&lt;LI&gt;Architecture Change Recommended- Scenarios that may be better served by a different implementation pattern in Microsoft Entra External ID.&lt;/LI&gt;
&lt;LI&gt;Not Currently Supported-&amp;nbsp;Capabilities that do not currently have a direct implementation path and may require alternative approaches or future evaluation.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For example, a policy that combines social identity federation, REST API claims enrichment, and a custom password reset flow might be categorized as Available for the federation and password reset experiences and Requires Custom Development for the REST API claims enrichment, giving you an immediate sense of where effort will be concentrated.&lt;/P&gt;
&lt;P&gt;For each finding, the report provides migration guidance and recommended next steps to support planning discussions.&lt;/P&gt;
&lt;H2&gt;Turn discovery into a migration plan&lt;/H2&gt;
&lt;P&gt;The value of the Migration Policy Analyzer extends beyond identifying features; it helps you move from discovery to an actionable plan while reducing migration risk and effort. With a categorized inventory in hand, teams can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Estimate migration scope and effort&lt;/LI&gt;
&lt;LI&gt;Prioritize proof-of-concept activities&lt;/LI&gt;
&lt;LI&gt;Highlight areas requiring redesign or additional development&lt;/LI&gt;
&lt;LI&gt;Build a phased migration strategy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By establishing a shared understanding of the current state, architects, developers, and business stakeholders can align on migration priorities before implementation begins.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;If you are evaluating a &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/migrate-to-external-id" target="_blank" rel="noopener"&gt;transition from Azure AD B2C to Microsoft Entra External ID&lt;/A&gt;, migration planning starts with understanding what is deployed today.&lt;/P&gt;
&lt;P&gt;Use the Migration Policy Analyzer to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Generate an inventory of custom policy capabilities&lt;/LI&gt;
&lt;LI&gt;Understand migration readiness&lt;/LI&gt;
&lt;LI&gt;Identify scenarios requiring additional planning&lt;/LI&gt;
&lt;LI&gt;Evaluate areas that may require redesign or custom development&lt;/LI&gt;
&lt;LI&gt;Begin building your migration strategy&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Open your Azure AD B2C tenant, navigate to &lt;STRONG&gt;Identity Experience Framework&lt;/STRONG&gt;, and run an analysis to generate your migration assessment. In minutes, you'll have the visibility needed to move from assessment to action, with less manual effort and lower migration risk.&lt;/P&gt;
&lt;P&gt;The Migration Policy Analyzer provides the visibility needed to move from assessment to action.&lt;/P&gt;
&lt;P&gt;-Namita Singh&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-analyze-azure-ad-b2c-custom-policies" target="_blank" rel="noopener"&gt;Analyze Azure AD B2C custom policies for Microsoft Entra External ID migration&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://review.learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930" target="_blank" rel="noopener"&gt;Plan your migration from Azure AD B2C to External ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/active-directory-b2c/custom-policy-overview" target="_blank" rel="noopener"&gt;Identity Experience Framework&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/" target="_blank" rel="noopener"&gt;Microsoft Entra External ID documentation&lt;/A&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/migrate-to-external-id" target="_blank" rel="noopener"&gt;Transition to Microsoft Entra External ID for CIAM&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 20 Jul 2026 17:18:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/plan-your-azure-ad-b2c-migration-with-the-migration-policy/ba-p/4532874</guid>
      <dc:creator>NamitaSingh</dc:creator>
      <dc:date>2026-07-20T17:18:24Z</dc:date>
    </item>
    <item>
      <title>AI agents are everywhere. Are your access controls ready?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/ai-agents-are-everywhere-are-your-access-controls-ready/ba-p/4531379</link>
      <description>&lt;P&gt;At Identiverse 2026, Microsoft Security hosted a Power Breakfast that brought together 150 identity professionals across 10 simultaneous roundtable discussions. Participants came from industries including financial services, healthcare, government, and energy, and represented every stage of AI adoption.&lt;BR /&gt;&lt;BR /&gt;We asked participants what they’ve built to secure agents, what they’ve rolled back, and where control is breaking down.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“The pace has been crazy fast. We have thousands of agents. Most of them are unmanaged.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;What your peers are saying about securing agents&lt;/H2&gt;
&lt;H3&gt;Agent sprawl is already here and bigger than most teams realize&lt;/H3&gt;
&lt;P&gt;Nine in 10 roundtables described unmanaged agent sprawl not as a future risk, but as a present reality. What started as dozens of agents became tens of thousands in months or even weeks. No single audit could capture the full picture. Practitioners described discovering the true number by accident, often finding far more than they expected: &lt;EM&gt;“I was doing a demo one day, I looked at our corporate tenant, and we had like 44,000 agents. I just couldn’t believe it, after so little time.”&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Agents are proliferating across every cloud, SaaS platform, and vendor environment simultaneously&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Nine in 10 roundtables reported agents running across SaaS, multicloud, and third-party environments with no governance visibility. Eight in 10 said shadow AI is already present in their organizations, running across platforms that no single governance layer currently covers and tracked only through network logs, if tracked at all. The challenge isn’t unique to any one platform: every SaaS vendor is now shipping with an agent, every cloud provider has a builder framework, and every team has a developer standing up something new.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“When everybody has a single pane of glass, nobody has a single pane of glass.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;Assigning human ownership to agents becomes complex when people change roles or leave organizations&lt;/H3&gt;
&lt;P&gt;Nine in 10 roundtables raised the ownerless-agents problem. Agents get built, tied to their creator’s identity, and keep running long after that person has changed roles or left the organization—unreviewed, over-permissioned, and undetected. This results in agents with no clear accountability, stale permissions, and no obvious path for review, reassignment, or decommissioning.&lt;/P&gt;
&lt;H3&gt;Agent-to-agent interactions are where control fails hardest&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Eight in 10 roundtables identified agent-to-agent chains as the most difficult security challenge they had encountered. Multiple teams rolled back agent-to-agent deployments after finding they could not maintain consistent governance across the chain.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“I can control point A to point B, but point B needs to talk to point C, and that’s where context was lost. I can control permissions. I can control authentication. I do not know how to control the impact.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;H2&gt;How Microsoft Entra Agent ID can help&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra Agent ID&lt;/STRONG&gt; is the identity foundation for every AI agent, and it’s where your control starts. Every governance, access, and lifecycle decision flows through agent identity. Without it, none of the controls below are possible. Microsoft Agent 365 builds on that foundation as the unified control plane, giving IT and security teams a single place to see and act on every agent across the organization.&lt;/P&gt;
&lt;P&gt;If you have similar pain points around managing agents, here are three actionable starting points for securing them:&lt;/P&gt;
&lt;H3&gt;1. Build your inventory before you do anything else&lt;/H3&gt;
&lt;P&gt;You cannot govern what you cannot see. Start here.&lt;/P&gt;
&lt;P&gt;The Microsoft Entra admin center shows every agent identity in your tenant across Copilot Studio, Microsoft Foundry, and third-party platforms in one view. Start in &lt;STRONG&gt;Microsoft Entra ID &amp;gt; Agents &amp;gt; Agents overview&lt;/STRONG&gt; to get a full picture of the total number of agents with identities, how many were recently created, how many are active, and how many are unmanaged. Then go to &lt;STRONG&gt;Microsoft Entra ID &amp;gt; Agents &amp;gt; Agent identities&lt;/STRONG&gt; and run your first audit. Agents without an Agent ID appear as classic agents with no governance controls attached. That list is your backlog and needs to be addressed right away to prevent sprawl.&lt;/P&gt;
&lt;P&gt;For agents running outside the Microsoft ecosystem, register them using the Agent 365 CLI and SDK or federated identity credentials. You do not need to migrate them; you need to get them into the registry so they are visible and can be governed.&lt;/P&gt;
&lt;P&gt;For third-party agents, running the Agent 365 SDK assigns each agent an agent identity blueprint, an agent identity, and a sponsor from the start, helping ensure that agents are trackable and more secure. A blueprint is a template that defines permissions, policies, and metadata for every agent instance created from it. It provides centralized control, allowing you to manage or disable agents created from it at scale. Skipping blueprints and creating agents as ad hoc service principals is how you end up with the sprawl the roundtable participants described.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;Get started with Microsoft Entra Agent ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/how-to-plan-agent-identity-architecture" target="_blank" rel="noopener"&gt;Plan your agent identity architecture&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-blueprint" target="_blank" rel="noopener"&gt;Agent identity blueprints&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;2. Assign an owner and a sponsor to every agent, then automate what happens when they leave&lt;/H3&gt;
&lt;P&gt;The orphaned-agent problem practitioners described has a direct solution. Every agent identity in Microsoft Entra Agent ID requires a &lt;STRONG&gt;sponsor&lt;/STRONG&gt; (the person accountable for what the agent does) and an &lt;STRONG&gt;owner&lt;/STRONG&gt; (the person responsible for its technical management). Assign both at creation time, at the blueprint layer. If you have existing agents with neither, start there.&lt;/P&gt;
&lt;P&gt;When someone leaves your organization,&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Entra lifecycle workflows&lt;/STRONG&gt;&lt;/A&gt; can automatically trigger an ownership review for every agent associated with that person. You define the escalation path and the window: reassign, pause, or decommission. This replaces the manual scripts your team has been running for service accounts.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Set up recurring &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;access reviews&lt;/STRONG&gt;&lt;/A&gt; for agent identities. Scope them to surface active permissions, usage signals, and business justification—not just whether the agent still exists. Agents that cannot be justified should be decommissioned, not left running.&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/best-practices-agent-id" target="_blank" rel="noopener"&gt;Best practices for Microsoft Entra Agent ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview" target="_blank" rel="noopener"&gt;Govern agent identities and lifecycle&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/what-are-lifecycle-workflows" target="_blank" rel="noopener"&gt;Lifecycle Workflows overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-overview" target="_blank" rel="noopener"&gt;Access reviews for agents overview&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;3. Scope permissions tightly, and apply Conditional Access and RBAC at the blueprint level&lt;/H3&gt;
&lt;P&gt;Start with enumerated scopes on every blueprint: only the specific delegated permissions the agent needs, nothing more. This is not optional. Agents do not self-restrict.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;“An agent doesn’t self-restrict. It’s going to do whatever it feels like it needs to do.”&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Roundtable participant, Identiverse 2026&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;For agents acting on behalf of a user, use the on-behalf-of flow so that user-level access policies apply. For autonomous agents, use the client credentials flow, scoped narrowly. Do not grant application-level permissions when delegated permissions accomplish the same task.&lt;/P&gt;
&lt;P&gt;Apply &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/security-for-ai-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Conditional Access policies&lt;/STRONG&gt;&lt;/A&gt; at the blueprint level, not agent by agent. Every agent instance created from that blueprint inherits the policy automatically. This is how you extend Zero Trust controls from your workforce to your agents. Next, Microsoft Entra ID Protection analyzes agent behavior to detect anomalies such as unusual access patterns, spikes in activity, or interactions with unfamiliar resources. When an agent is flagged as risky, those signals automatically trigger Conditional Access policies to block or restrict access in real time, moving you from static policies to adaptive protection.&lt;/P&gt;
&lt;P&gt;Lastly, turn on sign-in and audit logs in the Microsoft Entra admin center. Agent-initiated events are flagged separately from human-initiated ones. This is your baseline for detecting unauthorized access and demonstrating compliance.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin" target="_blank" rel="noopener"&gt;Manage agent identities and inheritable permissions&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/security-for-ai-overview" target="_blank" rel="noopener"&gt;Security for AI overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID documentation&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;If you have had a similar experience, please share your learnings in the comments!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Kaitlin Murphy&lt;/P&gt;
&lt;P&gt;Senior Director, Identity and Network Access Product Marketing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Microsoft Entra Agent ID documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 15 Jul 2026 18:16:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/ai-agents-are-everywhere-are-your-access-controls-ready/ba-p/4531379</guid>
      <dc:creator>Kaitlin_Murphy</dc:creator>
      <dc:date>2026-07-15T18:16:41Z</dc:date>
    </item>
    <item>
      <title>Govern AI agent identities and access the same way you govern your employees</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/govern-ai-agent-identities-and-access-the-same-way-you-govern/ba-p/4529302</link>
      <description>&lt;P&gt;In our conversations with customers, we’ve heard consistent feedback: organizations want to embrace AI agents, but they need the same governance rigor they apply to human identities—adapted for the speed and scale of AI. As agents take on real work, the critical question becomes: how do you give each agent the access it needs to be productive without letting that access become a risk?&lt;/P&gt;
&lt;P&gt;For example, an agent tasked with analyzing purchase trends and delivering a report needs the ability to read transaction data from an ERP system. Historically, agents may have used shared credentials or access rights borrowed from an employee. As AI adoption grows, organizations are increasingly adopting dedicated agent identities that provide clearer ownership, accountability, and governance. This gives each agent a distinct identity with a named human sponsor and governed access, while providing enterprise security and lifecycle management.&lt;/P&gt;
&lt;P&gt;With a distinct identity for each agent, ownership becomes clear, organizations gain visibility into each agent’s access, and access does not accumulate over time. Knowing which agent has what access, who is responsible for it, and whether that access is appropriate is foundational to secure and govern agents—just as it is for your human workforce.&lt;/P&gt;
&lt;P&gt;Microsoft Entra surfaces agent identity governance capabilities that are generally available as part of &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;New challenges for governing agent access&lt;/H2&gt;
&lt;P&gt;Traditional software is relatively static. Once deployed, its capabilities and permissions don’t change without a deliberate software update. Agents are fundamentally different; their capabilities evolve over time, and each new capability represents a change in the agent’s access footprint. This constant evolution means their access needs to change too, and without governance, that access compounds organizational risk.&lt;BR /&gt;&lt;BR /&gt;As organizations scale their AI agent deployments, security and IT teams are facing new challenges that traditional identity governance wasn’t designed for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Overprivileged access:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Agents often receive access at runtime, accumulate access over time, and retain it indefinitely, multiplying security risk across the organization.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;No human accountability:&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;When an agent acts autonomously, who is accountable for it? Without clear accountability, no person is responsible for its access or lifecycle.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Manual lifecycle management policies don’t scale: &lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Organizations managing hundreds or thousands of agents across multiple platforms need consistent access governance policies that admins can manage at scale. They can’t rely on manual processes to track sponsors or determine which agent identities and access assignments are still needed.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Govern agent identity and access with Microsoft Entra Agent ID&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt; enables organizations to govern agent identities and access at scale throughout the agent lifecycle. For example, an agent identity should follow the below identity and access lifecycle process:&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 1: Agent identity and access lifecycle.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Govern access for agents with Microsoft Entra access packages&lt;/H2&gt;
&lt;P&gt;Access packages, a capability within &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-overview" target="_blank" rel="noopener"&gt;Microsoft Entra Entitlement Management&lt;/A&gt;, brings structure and accountability to the entire access lifecycle for agent identities. Organizations can provide access policies that governs how access is requested, approved, and scoped in the first place, and ensures access is reviewed and expires when it's no longer needed. The result is access that's intentional, right-sized, time-bound, and easy to prove in an audit, without slowing teams down. &amp;nbsp;This applies to both assistive agents that require delegated OAuth permissions to act on behalf of users and autonomous agents that operate independently with their own application roles and permissions.&lt;/P&gt;
&lt;P&gt;By managing access assignments through access packages, you can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Scale efficiently when many agents need similar access rights&lt;/LI&gt;
&lt;LI&gt;Delegate approvals to the right decision-makers—application owners, compliance teams, or business stakeholders—for high-risk or compliance-sensitive access&lt;/LI&gt;
&lt;LI&gt;Time-limit access assignments so agents don’t retain access indefinitely&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Now consider a scenario where a DevOps agent needs access to certain OAuth permissions. An admin creates an access package policy scoped to agents, with approvals and access expiration settings, so its sponsor can request access on behalf of the agent identity:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure &lt;/EM&gt;&lt;EM&gt;2: &lt;/EM&gt;&lt;EM&gt;Admin experience with &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-access-packages" target="_blank" rel="noopener"&gt;&lt;EM&gt;access package policy for agents.&lt;/EM&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Sponsors from across your organization, who don’t need to be IT admins, can use the &lt;A href="https://myaccess.microsoft.com/" target="_blank" rel="noopener"&gt;My Access portal&lt;/A&gt; to submit the access request on behalf of the agent identity. The request goes through an approval flow before time-limited access is assigned.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure &lt;/EM&gt;&lt;EM&gt;3:&lt;/EM&gt;&lt;EM&gt; Sponsor experience for &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/entitlement-management-request-behalf#request-an-access-package-on-behalf-of-an-agent-identity" target="_blank" rel="noopener"&gt;&lt;EM&gt;requesting an access package&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; on behalf of an agent.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Additionally, Microsoft 365 administrators can use custom policy templates that leverage Microsoft Entra access packages, providing a streamlined experience for governing agent access during onboarding. The AI admin in Microsoft Agent 365 can request Microsoft Entra access packages through Microsoft Agent 365 policy templates. This ensures an agent’s access is secure from day one with approval flows and access expiration, so that the access does not persist longer than needed.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 4: The &lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/admin/agent-template#access-packages" target="_blank" rel="noopener"&gt;Agent 365 template&lt;/A&gt; to apply access package policy during agent onboarding.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Hold every agent accountable with a named sponsor&lt;/H2&gt;
&lt;P&gt;Every agent identity and &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-blueprint" target="_blank" rel="noopener"&gt;agent identity blueprint&lt;/A&gt; in Microsoft Entra can have a designated sponsor—a person accountable for that agent’s access and lifecycle. You can learn more about sponsor responsibilities &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-owners-sponsors-managers" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Agent sponsors provide the human accountability needed to govern agent identities at enterprise scale. By assigning sponsors, organizations can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Establish clear ownership for every agent identity&lt;/LI&gt;
&lt;LI&gt;Enable business stakeholders, not just IT administrators, to participate in governance decisions&lt;/LI&gt;
&lt;LI&gt;Ensure a responsible person reviews and requests access on behalf of the agent&lt;/LI&gt;
&lt;LI&gt;Empower sponsors to make lifecycle decisions for agent identities, including renewing, extending, or removing agent identities based on ongoing business need&lt;/LI&gt;
&lt;LI&gt;Provide a designated contact for audit, compliance and security reviews&lt;/LI&gt;
&lt;LI&gt;Reduce the risk of orphaned and unmanaged agent identities&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 5: &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-owners-sponsors-managers" target="_blank" rel="noopener"&gt;Owners and Sponsors&lt;/A&gt; of agent identities&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Automate the agent lifecycle with Lifecycle Workflows&lt;/H2&gt;
&lt;P&gt;With Microsoft Entra Lifecycle Workflows, you can add tasks for agent sponsors to your workflows so that as employees change roles, Microsoft Entra automatically:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Notifies the manager and co-sponsors when an agent’s sponsor moves or leaves, helping ensure no agent is left without accountability&lt;/LI&gt;
&lt;LI&gt;Transfers sponsorship automatically to a co-worker or manager, so there’s always a human accountable for every agent, even during organizational transitions&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 6: &lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/agent-sponsor-tasks" target="_blank" rel="noopener"&gt;Lifecycle Workflows&lt;/A&gt; automate sponsor maintenance when sponsors move or leave.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Sponsors can then see a list of agent identities they are responsible for and take lifecycle actions, such as disabling agent identities when they are no longer needed.&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Figure 7: The &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-end-user" target="_blank" rel="noopener"&gt;Manage Agents&lt;/A&gt; end-user experience enables sponsors to make lifecycle decisions.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;The path forward&lt;/H2&gt;
&lt;P&gt;Organizations benefit most from AI agents when governance is an enabler, not an afterthought—with guardrails in place from the moment an agent is onboarded. The agentic era extends identity governance to a new class of non-human identities that are more dynamic and numerous than the service accounts of the past. The principles stay the same—least privilege, accountability, lifecycle management, and continuous governance—but the mechanisms must evolve to match the speed and scale of agentic AI.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Ready to bring your AI agents under control with &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview" target="_blank" rel="noopener"&gt;Microsoft Entra ID Governance&lt;/A&gt; for agent identities? Explore &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=3937ac211e5f69b11004ba2c1f136810" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt; to start a trial and see how you can observe, govern, and secure agents across your organization.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Chirag Dayani&lt;BR /&gt;Sr Product Manager, Microsoft Entra Identity and Access Management&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/chiragdayani/" target="_blank" rel="noopener"&gt;Connect on LinkedIn&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Mark Wahl&lt;BR /&gt;Principal Product Architect&lt;BR /&gt;&lt;A href="https://www.linkedin.com/in/mawahl/" target="_blank" rel="noopener"&gt;Connect on LinkedIn&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/what-is-microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;What is Microsoft Entra Agent ID?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview" target="_blank" rel="noopener"&gt;Learn about governing agent identities&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 07 Jul 2026 21:34:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/govern-ai-agent-identities-and-access-the-same-way-you-govern/ba-p/4529302</guid>
      <dc:creator>chiragdayani</dc:creator>
      <dc:date>2026-07-07T21:34:53Z</dc:date>
    </item>
    <item>
      <title>Bring business logic into PIM role activation workflows</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bring-business-logic-into-pim-role-activation-workflows/ba-p/4531380</link>
      <description>&lt;P&gt;Privileged access often depends on business context that lives outside Privileged identity Management (PIM)—ticket validity, HR status, compliance checks, or on-call schedules. With custom extensions for Microsoft Entra Privileged Identity Management, organizations can bring that context directly into activation workflows.&lt;/P&gt;
&lt;P&gt;We’re excited to announce the preview of custom extensions for Microsoft Entra Privileged Identity Management (PIM), a powerful new capability that lets you integrate your organization’s business logic directly into PIM role activation workflows.&lt;/P&gt;
&lt;H2&gt;The challenge&lt;/H2&gt;
&lt;P&gt;Many organizations need governance controls that go beyond what PIM offers natively. While PIM already supports MFA, justification, and approval workflows, organizations also often want to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validate ticket numbers against an ITSM system&lt;/LI&gt;
&lt;LI&gt;Enforce HR-based access rules, such as employment status&lt;/LI&gt;
&lt;LI&gt;Integrate compliance or audit workflows before granting activation&lt;/LI&gt;
&lt;LI&gt;Apply dynamic approval logic based on the specific context of a request&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Until now, these validations required manual processes outside of PIM, which can create gaps in enforcement and auditability.&lt;/P&gt;
&lt;H2&gt;Introducing PIM custom extensions&lt;/H2&gt;
&lt;P&gt;With custom extensions, PIM can now call your REST API during role activation. Your API evaluates the request against your business rules and returns a decision that PIM enforces automatically.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it works:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;A user requests role activation in PIM.&lt;/LI&gt;
&lt;LI&gt;PIM sends a structured request payload to your custom extension API, including details like principalId, roleDefinitionId, justification, ticketInfo, and scheduleInfo.&lt;/LI&gt;
&lt;LI&gt;Your API applies your business logic and validates the ticket, checks HR status, or runs compliance checks.&lt;/LI&gt;
&lt;LI&gt;Your API returns a decision—Approved, AutoApproved, or Denied—along with a reason.&lt;/LI&gt;
&lt;LI&gt;PIM enforces the decision and logs the interaction for audit.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Supported scope&lt;/H2&gt;
&lt;P&gt;In this preview, custom extensions support:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PIM for Groups&lt;/LI&gt;
&lt;LI&gt;PIM for Microsoft Entra roles&lt;/LI&gt;
&lt;LI&gt;PIM for Azure resources&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The extension is invoked synchronously during the activation workflow (pre-approval stage), enabling real-time decisioning.&lt;/P&gt;
&lt;H2&gt;Audit and traceability&lt;/H2&gt;
&lt;P&gt;Every extension interaction is fully auditable. Each response includes an evaluationId, evaluationOutcome, and reason, giving you end-to-end traceability for compliance reviews and security investigations.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Setting up PIM custom extensions involves five steps:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Create a new custom extension API — a REST API (HTTP POST) that implements your business logic.&lt;/LI&gt;
&lt;LI&gt;Secure the API with Microsoft Entra ID — register an app and implement token validation.&lt;/LI&gt;
&lt;LI&gt;Onboard the extension in PIM — use Microsoft Graph API to create the custom extension object.&lt;/LI&gt;
&lt;LI&gt;Link the extension to role settings — enable Require pre-approval custom extension in PIM role settings.&lt;/LI&gt;
&lt;LI&gt;Activate and validate — test the end-to-end flow by activating a role.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Example scenarios&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-align-center"&gt;&lt;table border="1" style="width: 81.4815%; height: 499px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 39px;"&gt;&lt;td style="height: 39px;"&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Scenario&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 39px;"&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Extension logic&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;Ticket validation&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Verify that the ticket ID is valid and assigned to the requester&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;HR compliance gate&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Confirm that the requester meets the required criteria&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;Auto-approval for on-call&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Auto-approve activation for users who are currently on call&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 115px;"&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;Deny after hours&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 115px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deny activation outside approved maintenance windows&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;What's next&lt;/H2&gt;
&lt;P&gt;Microsoft Entra ID Governance helps you protect, monitor, and audit access to critical assets while ensuring employee productivity. It gives you the ability to ensure the right people have the right access to the right resources with the right controls—preventing identity attacks, enforcing least privilege access, and unifying access control across your environment.&lt;/P&gt;
&lt;P&gt;We’re continuing to enhance custom extensions, and your feedback during this preview will shape the future of extensible governance in Microsoft Entra. We recommend enabling PIM custom extensions end-to-end and sharing your feedback &lt;A href="https://forms.cloud.microsoft/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR28-budnJ4dIuN_0D601vJtUNEdJNlJKUVlXWUdRTjRSSFBJVUdXRDRVMC4u" target="_blank" rel="noopener"&gt;here.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;-Kaitlin Murphy&lt;/P&gt;
&lt;P&gt;Senior Director, Product Marketing&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/kaitmurphy/" target="_blank" rel="noopener"&gt;Kaitlin Murphy | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/privileged-identity-management-custom-extensions" target="_blank" rel="noopener"&gt;Configure custom extensions for PIM role activation (preview) - Microsoft Entra ID Governance | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/graph/api/resources/privilegedidentitymanagementv3-overview" target="_blank" rel="noopener"&gt;Microsoft Graph API reference for PIM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/privileged-identity-management/pim-deployment-plan" target="_blank" rel="noopener"&gt;PIM deployment plan&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;Microsoft Entra blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra" target="_blank" rel="noopener"&gt;Microsoft Entra documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/ct-p/MicrosoftEntra" target="_blank" rel="noopener"&gt;Microsoft Entra community discussions&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 16:35:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bring-business-logic-into-pim-role-activation-workflows/ba-p/4531380</guid>
      <dc:creator>Kaitlin_Murphy</dc:creator>
      <dc:date>2026-07-01T16:35:45Z</dc:date>
    </item>
    <item>
      <title>Protect sensitive data in motion across SaaS and AI apps with Microsoft Purview and Microsoft Entra</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with/ba-p/4529310</link>
      <description>&lt;P&gt;Once, securing data meant protecting them within the confines of endpoints and managed apps. It lived inside boundaries you controlled. Today, those boundaries have disappeared—and with them, the old playbook for data security.&lt;/P&gt;
&lt;H2&gt;Data security must keep up with how data moves in the AI-era&lt;/H2&gt;
&lt;P&gt;Organizational data now travels constantly between trusted endpoints and unmanaged web apps, SaaS apps, and most critically, generative AI tools over the network. Employees type and paste sensitive information into prompts, upload work-related files to external services or personal cloud storage, and interact with systems that sit entirely outside the traditional enterprise perimeter. AI has expanded the risk surface for potential enterprise data loss.&lt;/P&gt;
&lt;P&gt;Traditional data loss prevention (DLP) approaches lack real-time visibility and enforcement, often flagging incidents after data has already left the organization. In other cases, vendors rely heavily on physical network appliances that are complex and expensive to deploy, or compute-intensive resources that can add latency. In the era of AI, that model breaks down quickly.&lt;/P&gt;
&lt;H2&gt;Enabling real-time data protection for how work happens&lt;/H2&gt;
&lt;P&gt;To address this shift, &lt;STRONG&gt;we’re announcing the&lt;/STRONG&gt; &lt;STRONG&gt;extension of data security to the network layer, powered by Microsoft Purview and Microsoft Entra&lt;/STRONG&gt;, now in public preview.&lt;/P&gt;
&lt;P&gt;This integration brings together data context and identity-aware enforcement to help protect sensitive data in transit, in real-time:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Detect how sensitive data is shared to shadow AI tools, unmanaged SaaS apps, and personal cloud repositories.&lt;/LI&gt;
&lt;LI&gt;Help block or limit data exposure in real-time based on identity, user activity, and data context.&lt;/LI&gt;
&lt;LI&gt;Unify investigation workflows by correlating identity, data, and insider risk signals across Microsoft Purview, Microsoft Entra, and Microsoft Defender.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By combining Microsoft Purview data classification, DLP policies, and insider risk detection with identity-aware enforcement at the network layer through Microsoft Entra, organizations can dynamically apply protections based on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The sensitivity of the data&lt;/LI&gt;
&lt;LI&gt;Who the user is&lt;/LI&gt;
&lt;LI&gt;How that user has interacted with sensitive data over time&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these capabilities help protect data in motion across browser sessions, SaaS usage, and AI interactions (including prompts and responses), all at the speed and scale that today’s work demands. The result is a more complete, consistent approach to data protection that follows the data instead of relying on fixed, at-rest controls.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H2&gt;What this changes in practice&lt;/H2&gt;
&lt;P&gt;With network-level visibility and enforcement, security teams can finally understand how sensitive data is moving across unmanaged SaaS and AI apps, not just within Microsoft applications or endpoint devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;Prevent employees from sharing proprietary or sensitive organizational data to potentially risky locations such as consumer AI apps.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That includes scenarios that have historically been difficult to see and protect, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Text that’s inputted directly into unmanaged apps and email services, such as prompts and responses&lt;/LI&gt;
&lt;LI&gt;Files that are uploaded to personal cloud storage repositories&lt;/LI&gt;
&lt;LI&gt;Files and text that could be scanned and processed by unsanctioned plugins or add-ins&lt;/LI&gt;
&lt;LI&gt;Files and text that are shared outside of a managed browser session&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank" rel="noopener"&gt;See the full demo here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Most importantly, protection preempts data leakage. Instead of relying on downstream detection, organizations can detect and block sensitive data in transit before it’s exposed. Because enforcement is tied to identity and user context, policies can adapt based on risk without introducing unnecessary friction for end users.&lt;/P&gt;
&lt;P&gt;Underneath, this is powered by a unified policy model, where the classification and protection policies defined in Microsoft Purview for the rest of your data estate are also enforced consistently at the network layer through Microsoft Entra. This reduces the need to juggle multiple point solutions to secure data holistically across your environment.&lt;/P&gt;
&lt;H2&gt;A shift to real-time data protection&lt;/H2&gt;
&lt;P&gt;This shift reflects a broader transformation in how data and network security teams must operate.&lt;/P&gt;
&lt;P&gt;Traditional approaches rely on static boundaries and after-the-fact controls. That model breaks down when data is continuously exchanged across SaaS apps and AI systems.&lt;/P&gt;
&lt;P&gt;Data protection now needs to operate in real-time and in the flow of user activity.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Network data security&lt;/STRONG&gt; – now available in Microsoft 365 E7* – plays a critical role in enabling this shift by extending enforcement beyond endpoints and applications to the network itself, helping protect data wherever it moves.&lt;/P&gt;
&lt;H2&gt;Learn more&lt;/H2&gt;
&lt;P&gt;As organizations adopt AI at scale, securing data and access during AI and agent use becomes mission-critical.&lt;/P&gt;
&lt;P&gt;Join our &lt;STRONG&gt;three-part webinar series, Securing Data and Access in the Era of AI&lt;/STRONG&gt;, to see how Microsoft Entra and Microsoft Microsoft Purview help protect data, govern access, and reduce risk across your AI journey.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Register for the webinar series: &lt;/STRONG&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/securing-data-and-access-in-the-era-of-ai-with-microsoft-entra-and-microsoft-pur/4529488" target="_blank" rel="noopener"&gt;Securing data and access in the era of AI with Microsoft Entra and Microsoft Purview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/NetworkDataSecurityDemo" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;See it in action&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Sule Tatar, &lt;/EM&gt;Senior Product Marketing Manager, SCI Identity&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-Vivian Ma, &lt;/EM&gt;Senior Product Marketing Manager, Microsoft Purview Data Security&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/vivian-y-ma/" target="_blank" rel="noopener"&gt;Vivian Ma | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;*Network data security capabilities are also available to customers with &lt;U&gt;both&lt;/U&gt; a Purview ME5 (or equivalent) and Entra Internet Access (or equivalent) license.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Microsoft Purview&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Dynamically secure your data with an integrated approach across your multi-structured data estate, devices, and generative AI apps and agents.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/product/microsoft-purview/" target="_blank" rel="noopener"&gt;Microsoft Purview news and insights | Microsoft Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/tag/microsoft%20purview?nodeId=board%3Amicrosoft-security-blog" target="_blank" rel="noopener"&gt;Microsoft Purview community blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/" target="_blank" rel="noopener"&gt;Microsoft Purview documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra news and insights | Microsoft Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 16:32:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/protect-sensitive-data-in-motion-across-saas-and-ai-apps-with/ba-p/4529310</guid>
      <dc:creator>SuleTatar</dc:creator>
      <dc:date>2026-07-01T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Microsoft Entra Backup and Recovery is now generally available</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-backup-and-recovery-is-now-generally-available/ba-p/4521997</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Microsoft Entra Backup and Recovery is now generally available.&lt;/STRONG&gt; Microsoft Entra customers licensed for Entra ID P1 or P2 now can restore supported critical identity data after accidental changes or malicious updates, rolling out to all workforce tenants this week.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity resilience and disaster recovery are top challenges for IT teams. Microsoft Entra Backup and Recovery helps address both by automatically backing up core directory objects daily. Supported objects include &lt;STRONG&gt;users, groups, applications, service principals, managed identities, Conditional Access policies, named locations, and authentication and authorization policy,&lt;/STRONG&gt; helping administrators return their environment to a previously known‑good state.&lt;/P&gt;
&lt;img&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/backup/" target="_blank" rel="noopener"&gt;Microsoft Entra Backup and Recovery&lt;/A&gt; is a built-in backup and recovery solution that lets you recover critical Microsoft Entra directory objects to a previously known good state after accidental changes or security compromises. The overview dashboard highlights alerts, recent backups, difference reports, and protected actions.&lt;/img&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-clear-both"&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/backup/overview" target="_blank" rel="noopener"&gt;Get started today with the built-in backup and recovery solution in Microsoft Entra | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H3&gt;What's changed since public preview?&lt;/H3&gt;
&lt;P&gt;Based on feedback from the Backup and Recovery &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426?previewMessage=true" target="_blank" rel="noopener"&gt;public preview&lt;/A&gt;, we’ve increased the retention period for supported directory objects from 5 days to 7 days to provide extended protection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity admins now have more flexibility when viewing available snapshots, generating difference reports to understand what changed, and running recovery jobs to restore objects to a prior state. These capabilities help teams quickly assess what changed and take action to return to a known good state.&lt;/P&gt;
&lt;P&gt;But recovery is not just about restoring objects. It’s about being prepared to return your tenant to a known‑good state under pressure. Entra Backup and Recovery fits into a broader tenant recoverability strategy so you can reduce disruption, respond to common recovery scenarios, and recover with confidence.&lt;/P&gt;
&lt;H2&gt;Why recoverability matters&lt;/H2&gt;
&lt;P&gt;Accidental deletion, misconfiguration, and malicious changes can disrupt sign‑in, block access to business‑critical applications, and quickly impact downstream operations.&lt;/P&gt;
&lt;P&gt;Backup and Recovery provides an important foundation for restoring supported objects, but tenant recoverability requires a broader approach. Recoverability is the ability to restore tenant configuration and identity objects to a known‑good state after unintended or malicious changes, using clear processes and supported recovery paths.&lt;/P&gt;
&lt;P&gt;This means recovery readiness is not a single solution. It is a combination of capabilities, processes, and preparation across your organization.&lt;/P&gt;
&lt;H3&gt;Layers of Recovery: Best Practices&lt;/H3&gt;
&lt;P&gt;Organizations that recover quickly combine built‑in capabilities like Backup and Recovery with additional layers of preparation and control.&lt;/P&gt;
&lt;P&gt;Key elements of a strong tenant recoverability strategy include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Built&lt;/STRONG&gt;‑&lt;STRONG&gt;in recovery for supported objects&lt;/STRONG&gt;: Use Microsoft Entra Backup and Recovery to restore supported objects and configuration changes within the retention window.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Maintaining a known&lt;/STRONG&gt;‑&lt;STRONG&gt;good configuration state&lt;/STRONG&gt;: Regularly capture tenant configuration using tools such as Tenant Configuration Management APIs and Microsoft Graph exports to support recovery beyond built‑in capabilities.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Operational readiness&lt;/STRONG&gt;: Define recovery processes, retain audit and sign‑in logs, and establish recovery objectives so that recovery actions can be executed under pressure.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reducing blast radius&lt;/STRONG&gt;: Apply least‑privilege access, Privileged Identity Management, and protected actions to limit the scope of potential incidents and simplify recovery.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Together, these layers help organizations move from reactive fixes to a structured recovery strategy.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;"Overall, we like the functionality offered by Microsoft Entra Backup and Recovery. The API support looks solid as well."&lt;/P&gt;
&lt;P class="lia-align-right"&gt;&lt;EM&gt;– A large European automobile manufacturer&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;Scenario: Conflicting identity changes disrupt access&lt;/H2&gt;
&lt;P&gt;To illustrate how organizations can use Backup and Recovery, let’s walk through a potential scenario using a fictitious company called “Contoso”.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here's the situation:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The IT team at Contoso relies on Microsoft Entra&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/conditional-access/concept-conditional-access-policies" target="_blank" rel="noopener"&gt;Conditional Access policies&lt;/A&gt; and &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/role-based-access-control/security-planning?toc=/entra/identity/privileged-identity-management/toc.json&amp;amp;bc=/entra/identity/id-governance/privileged-identity-management/breadcrumb/toc.json" target="_blank" rel="noopener"&gt;Privileged Identity Management&lt;/A&gt; to protect access to business-critical applications. Policies are tightly controlled, and administrative access is granted just in time.&lt;/P&gt;
&lt;P&gt;But during a routine day, remote workers suddenly can’t sign in to a critical ordering application. Nothing appears compromised, and the application itself is healthy. &lt;STRONG&gt;The team needs to understand what changed—and restore access quickly.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;Step 1: Identify and restore application access.&lt;/H3&gt;
&lt;P&gt;An administrator runs a Microsoft Entra Backup and Recovery difference report against a recent snapshot and correlates it with Entra audit logs to identify recent changes. The report shows a Conditional Access policy was modified by a known administrator. The update accidentally blocked the remote worker group from accessing the ordering application. Using Backup and Recovery, the administrator restores the policy to a previous state. Access is quickly re‑enabled.&lt;/P&gt;
&lt;H3&gt;Step 2: Investigate beyond the initial fix.&lt;/H3&gt;
&lt;P&gt;With access restored, the team continues investigating to understand how an unintended policy change reached production. They review&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/id-governance/tenant-governance/overview" target="_blank" rel="noopener"&gt;Microsoft Entra Tenant Governance&lt;/A&gt; monitoring signals to identify any related configuration changes.&lt;/P&gt;
&lt;H3&gt;Step 3: Detect configuration drift.&lt;/H3&gt;
&lt;P&gt;Tenant Governance signals reveal drift in role governance configuration during the same timeframe: a change to role eligibility settings broadened who could administer the Conditional Access policy. This change does not align with the approved configuration baseline.&lt;/P&gt;
&lt;H3&gt;Step 4: Confirm conflicting changes.&lt;/H3&gt;
&lt;P&gt;Correlating audit logs with the drift findings, the team reconstructs the sequence. To resolve an urgent, unrelated issue, an administrator had temporarily modified role-eligibility settings — unintentionally allowing a second administrator to edit the Conditional Access policy and block the remote worker group. Two well-intended changes, made independently, combined to cause the outage.&lt;/P&gt;
&lt;H3&gt;Step 5: Restore governance baseline and prevent recurrence.&lt;/H3&gt;
&lt;P&gt;The team initiates an established workflow to restore role governance configuration to the approved baseline. Because Contoso routinely practices scenarios like this during Business Continuity and Disaster Recovery (BCDR) drills, the team is able to coordinate rapidly. They restore both application access and governance controls, reducing the likelihood of similar issues in the future.&lt;/P&gt;
&lt;H2&gt;Recover with confidence: Get started today&lt;/H2&gt;
&lt;P&gt;Microsoft Entra Backup and Recovery provides a built‑in foundation for restoring supported identity data that organizations can adopt as part of a layered recoverability approach that combines built‑in capabilities with preparation, governance, and operational discipline.&lt;/P&gt;
&lt;P&gt;Microsoft Entra Backup and Recovery is built as an API‑first, extensible platform that gives customers the flexibility to design backup and recovery workflows aligned to their operational needs. These same APIs enable independent software vendors (ISVs) to integrate and deliver complementary solutions that extend Entra with their domain expertise.&lt;/P&gt;
&lt;P&gt;By aligning Backup and Recovery with a broader identity resilience strategy, organizations can reduce downtime, respond faster to change‑related incidents, and maintain confidence in the integrity of their identity environment.&lt;/P&gt;
&lt;H4&gt;Ready to strengthen your identity resilience?&lt;/H4&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/backup/" target="_blank" rel="noopener"&gt;Learn how to enable Microsoft Entra Backup and Recovery in your production environment with Microsoft Learn documentation.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;-&lt;/EM&gt; &lt;EM&gt;Cindy Crane, Principal Product Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/architecture/recoverability-tenant" target="_blank" rel="noopener"&gt;Learn more about how to plan for Tenant recoverability &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://techcommunity.microsoft.com/event/microsoft-security-events/recover-with-confidence-using-microsoft-entra-backup-and-recovery/4504269" target="_blank" rel="noopener"&gt;Watch the webinar: Microsoft Entra Backup and Recovery: Recover with confidence&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426?previewMessage=true" target="_blank" rel="noopener"&gt;Learn how to Strengthen Identity Resilience with Microsoft Entra Backup and Recovery&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/backup/" target="_blank" rel="noopener"&gt;Microsoft Entra Backup and Recovery documentation on Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/architecture/recoverability-overview" target="_blank" rel="noopener"&gt;Learn more about Recoverability best practices in Microsoft Entra ID&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;A class="lia-external-url" href="https://www.microsoft.com/security/blog/tag/in-the-loop/" target="_blank" rel="noopener"&gt;Read the new monthly blog series: What’s new in Microsoft Security&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 30 Jun 2026 18:27:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-backup-and-recovery-is-now-generally-available/ba-p/4521997</guid>
      <dc:creator>CindyCrane</dc:creator>
      <dc:date>2026-06-30T18:27:57Z</dc:date>
    </item>
    <item>
      <title>Secure AI at scale: Join the Microsoft Entra + Purview webinar series</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-at-scale-join-the-microsoft-entra-purview-webinar/ba-p/4530257</link>
      <description>&lt;P&gt;AI is reshaping how data moves, how access gets granted, and how risk multiplies—faster than most security strategies were built to handle. Sensitive data is flowing through AI prompts, browsers, and agents. Identities are extending to non-human actors. And traditional perimeters are no longer enough.&lt;/P&gt;
&lt;P&gt;As organizations scale AI, security teams need a practical way to protect data, govern access, and manage risk before adoption outpaces control.&lt;/P&gt;
&lt;P&gt;Securing AI end-to-end requires bringing identity, access, and data protection together—not as separate functions, but as a unified strategy.&lt;/P&gt;
&lt;P&gt;To help you put that strategy into practice, we’re launching a new three-part webinar series: &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/securing-data-and-access-in-the-era-of-ai-with-microsoft-entra-and-microsoft-pur/4529488" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Securing Data and Access in the Era of AI&lt;/STRONG&gt;&lt;/A&gt;. Each session brings together product experts from Microsoft Entra and Microsoft Purview to help you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Protect sensitive data across networks, apps, and AI interactions&lt;/LI&gt;
&lt;LI&gt;Govern access for users, applications, and AI agents&lt;/LI&gt;
&lt;LI&gt;Reduce risk while enabling innovation at scale&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether you’re shaping strategy or implementing controls, you’ll leave with practical steps to secure data, govern access, and reduce risk across your AI journey.&lt;/P&gt;
&lt;H2&gt;Register now and learn how to secure AI end-to-end across access, data, and agents&lt;/H2&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/secure-the-age-of-ai-redefining-trust-data-and-access/4529480" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Secure the age of AI: Redefining trust, data, and access&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;July 21, 2026, 9:00 AM PDT – &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/secure-the-age-of-ai-redefining-trust-data-and-access/4529480" target="_blank" rel="noopener"&gt;Add to calendar&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Sinead O’Donovan&lt;/EM&gt;&lt;EM&gt;, VP of Product, Microsoft Entra; Maithili Dandige, GM of Product, Microsoft Purview;&lt;/EM&gt;&lt;EM&gt; Diana Vicezar, Product Marketing Manager, Microsoft Entra&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;There is no question that AI is transforming the enterprise: changing how data moves, how decisions are made, and how risk takes shape. As agents access, interpret, and act on sensitive data, unmanaged AI use expands and traditional boundaries blur.&lt;/P&gt;
&lt;P&gt;Kicking off our series on Securing Data and Access in the Era of AI, Microsoft Entra VP of Product Sinead O’Donovan and Microsoft Purview GM of Product Maithili Dandige explain why legacy security models fall short in the age of AI—and why you need a strategy that brings together identity, access, and data protection. Want to adopt and enable AI innovation with greater control and confidence? Join us to learn how leading organizations are securing access, protecting data, and establishing trust for the next generation of AI-powered work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/data-and-identity-controls-for-the-browser-and-network/4529481" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;D&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;ata and identity controls for the browser and network&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;July 22, 2026, 9:00 AM PDT – &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/data-and-identity-controls-for-the-browser-and-network/4529481" target="_blank" rel="noopener"&gt;Add to calendar&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Alexander Pavlovsky, Principal Product Manager, Microsoft Entra; Brendon Lee, Senior Product Manager, Microsoft Purview;&lt;/EM&gt;&lt;EM&gt; Diana Vicezar, Product Marketing Manager, Microsoft Entra&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Sensitive data doesn’t stay still. It moves through browsers, SaaS apps, generative AI tools, and prompts—often beyond the visibility of traditional controls. In this session, see how Microsoft Entra and Microsoft Purview bring real-time visibility and control to sensitive data in motion across the network. You’ll learn how integrated data security and secure access controls can help reduce leakage risk, support responsible AI adoption, and enable modern work without slowing the business down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-21"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/unlock-ai-agents-without-sacrificing-security/4529484" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Unlock AI &lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;agents without sacrificing security&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;July 23, 2026, 9:00 AM PDT – &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/unlock-ai-agents-without-sacrificing-security/4529484" target="_blank" rel="noopener"&gt;Add to calendar&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Jeevan Bisht, Principal PM Manager, Microsoft Entra; Safeena Begum Lepakshi, Principal PM Manager, Microsoft Purview;&lt;/EM&gt;&lt;EM&gt; Diana Vicezar, Product Marketing Manager, Microsoft Entra&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;AI agents are reaching into mailboxes, files, line-of-business apps, and the open web on behalf of your users—and the business wants more of them, faster. To scale agents safely, your security teams need to be able to verify each agent, govern what it can access, and enforce clear boundaries across every interaction.&lt;/P&gt;
&lt;P&gt;Learn how Microsoft Entra helps you discover shadow AI agents, govern agent permissions, keep BYOD and endpoint-based agents in scope, and apply Conditional Access to AI prompts and responses. Then see how Microsoft Purview provides visibility into agent activity, strengthens runtime data protection, helps detect agentic risk, and supports auditability across local agents developed on GitHub Copilot CLI, Claude Code, OpenAI Codex, and OpenClaw. Walk away with practical ways to unlock AI agents while keeping access and data protection aligned with your enterprise security needs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ready to take the next step?&lt;/STRONG&gt;&lt;BR /&gt;Visit the session pages to &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/securing-data-and-access-in-the-era-of-ai-with-microsoft-entra-and-microsoft-pur/4529488" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;save the dates&lt;/STRONG&gt;&lt;/A&gt; for the Securing Data and Access in the Era of AI series. Select &lt;EM&gt;Attend&lt;/EM&gt; to &lt;STRONG&gt;secure your place and receive reminders&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;—Diana Vicezar, Product Marketing Manager&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 25 Jun 2026 20:17:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/secure-ai-at-scale-join-the-microsoft-entra-purview-webinar/ba-p/4530257</guid>
      <dc:creator>Diana_Vicezar</dc:creator>
      <dc:date>2026-06-25T20:17:14Z</dc:date>
    </item>
    <item>
      <title>AI is accelerating cyberattacks—here’s how to stay ahead</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/ai-is-accelerating-cyberattacks-here-s-how-to-stay-ahead/ba-p/4528592</link>
      <description>&lt;P&gt;In March, we wrote that identity security has become &lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/25/identity-security-is-the-new-pressure-point-for-modern-cyberattacks/" target="_blank" rel="noopener"&gt;the new pressure point for modern cyberattacks&lt;/A&gt;. Since then, AI has only increased that pressure.&lt;/P&gt;
&lt;P&gt;AI helps cyberattackers move faster across the attack chain: personalizing social engineering at scale, automating reconnaissance, analyzing leaked credentials, identifying privileged users, probing exposed systems, and adapting tactics in real time. Attacks that once depended on manual effort can now unfold with greater speed, scale, and autonomy.&lt;/P&gt;
&lt;P&gt;Yet even as methods evolve, identity remains one of the most common entry points. Every account, admin, workload, application, &lt;A href="https://aka.ms/NHI-security-26" target="_blank" rel="noopener"&gt;non-human identity&lt;/A&gt;, and AI agent can become a path to sensitive data and critical systems if not properly secured. Attackers do not need to break every defense; they only need to compromise or misuse the right identity with the right access at the right moment.&lt;/P&gt;
&lt;P&gt;When attacks are accelerated by AI, speed and accuracy in detection and response are critical. Identity security can no longer operate in silos. Even a minor delay between when a threat is detected and action is taken can be the difference between suspicious activity becoming a contained incident or a business-impacting breach. This shift is reshaping how organizations think about security. The imperative is becoming clear: identity and security teams need comprehensive visibility and integrated solutions that streamline how they prevent, detect, and respond to identity threats.&lt;/P&gt;
&lt;H2&gt;Securing the future of identity at the speed of AI&lt;/H2&gt;
&lt;P&gt;One of the biggest security challenges organizations face today is fragmentation, and identity security is no exception. IAM and SOC teams often work across separate tools, separate workflows, and separate operational models. But identity attacks don’t respect those organizational boundaries.&lt;/P&gt;
&lt;P&gt;Modern identity attacks span infrastructure, access control, and detection. At Microsoft, we understand this, and we are continuing to expand how Microsoft Entra and Microsoft Defender work together to provide more unified identity security experiences.&lt;/P&gt;
&lt;H3&gt;Actionable intelligence, everywhere&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/25/identity-security-is-the-new-pressure-point-for-modern-cyberattacks/" target="_blank" rel="noopener"&gt;At RSA earlier this year, we unveiled our unified identity risk score&lt;/A&gt;, a new way to turn broader attack-chain insight into real-time access decisions. This score analyzes and correlates relevant signals across related accounts, sessions, workloads, and applications to surface a single, comprehensive evaluation of an identity’s true risk level and enable more dynamic response directly within authentication flows as part of risk-based Conditional Access policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;View of a risky user within Entra ID Protection with new identity risk score and attack timeline.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;Identity admins also gain a stronger operational experience through the new Microsoft Entra ID Protection experience. Rather than forcing identity teams to piece together risk signals across disconnected views, the updated experience brings deeper visibility into risky users, sign-ins, workloads, and associated detections in one place. The new identity risk score adds another layer of context by surfacing insights across related accounts and activity, including signals from Microsoft environments and connected identity activity beyond them. This helps admins understand whether a risky user, agent, workload, or sign-in is an isolated event or part of a broader pattern spanning sessions, applications, and associated accounts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;New user dashboard in Entra ID Protection which provides deeper visibility for identity admins into risky users, sign-ins, and associated detections.&lt;/EM&gt;&lt;/img&gt;&lt;img&gt;&lt;EM&gt;New risky user details view provides more information about a user's risk and the attack timeline within Entra ID Protection.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;That richer context gives identity teams a more complete view of how risk is developing across the identity estate. Admins can better understand how risk is calculated, which related accounts or workloads contributed to the score, what detections are driving concern, and why a given identity requires attention. By connecting Microsoft and cross-environment signals into a single evaluation, the risk score helps identity admins prioritize the identities that matter most, make more informed access decisions, and explain the rationale behind remediation actions with greater confidence.&lt;/P&gt;
&lt;P&gt;For security operations teams, this new score helps prioritize and triage investigations faster by focusing analysts on the identities that pose the greatest risk. But knowing what to fix is only half the challenge. In many organizations, security operations teams lack the needed permissions to take action; instead, they can only wait for separate IAM workflows to resolve the issue. That delay creates friction during moments when response speed matters most. Some solutions address this by giving SOC teams, or the security application itself, broad standing permissions across the identity environment. That may solve the permissions issue, but it also expands the blast radius if the application or identity is misused or compromised.&lt;/P&gt;
&lt;P&gt;Microsoft takes a different approach because our solution natively spans identity infrastructure, the identity control plane, and ITDR. Customers get streamlined workflows across the full identity security lifecycle, and with a new identity-focused RBAC role, coming soon in public preview, security operations teams can access the core identity response actions they need without broad administrative permissions. This allows organizations to preserve least privilege access while reducing operational friction between IAM and SOC teams. Combined with the native privileged identity management in Microsoft Entra, organizations can also create just-in-time access policies for these response roles, further reducing standing privilege while still enabling responders to elevate quickly during incidents and investigations.&lt;/P&gt;
&lt;P&gt;Together, unified risk, the new Microsoft Entra ID Protection experience, and least-privilege response roles give identity and security teams the shared context and governed action paths they need to move from insight to response faster.&lt;/P&gt;
&lt;H3&gt;Shifting left with proactive prevention&lt;/H3&gt;
&lt;P&gt;Shifting identity protection left means addressing risk earlier, before it becomes an active threat or incident. By continuously strengthening posture and adapting access controls as conditions change, organizations can reduce exposure, improve resilience, and stay ahead of emerging risks.&lt;/P&gt;
&lt;P&gt;The Conditional Access Optimization Agent continues to evolve to help organizations keep pace with a rapidly changing threat landscape. Instead of manually auditing policies or reacting after gaps are exposed, the agent continuously analyzes identity signals, usage patterns, and emerging threats to recommend the right policy changes at the right time. New recommendations, like the “Block risky user agent” policy, are designed to address emerging attack vectors such as agent-based abuse and automated access attempts. These optimizations give organizations a more adaptive way to enforce Zero Trust, where access decisions continuously adjust based on risk and context rather than relying on one-time configuration.&lt;/P&gt;
&lt;P&gt;And as part of our continued effort to help customers close the loop and move beyond reactive responses, we are soon bringing more threat detections and insights from Defender that are automatically fed directly into the Conditional Access Optimization recommendations in Microsoft Entra. Administrators receive clear, explainable, and reviewable recommendations that outline why the change is important, who is impacted, and what action to take, empowering a more proactive and preventative approach to mitigating future attacks.&lt;/P&gt;
&lt;H3&gt;Accelerating response&lt;/H3&gt;
&lt;P&gt;In AI-accelerated attacks, response speed matters just as much as visibility. Manual investigation and response will always be necessary, but in today’s AI-accelerated threat landscape, defenders need automation that helps level the playing field. That’s why we were so excited to extend the &lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-alert-triage-agent?tabs=email-alerts" target="_blank" rel="noopener"&gt;Security Alert Triage Agent&lt;/A&gt; to identity scenarios and pair it with automatic attack disruption and new predictive shielding capabilities. Together, these capabilities create an end-to-end automation loop that helps defenders triage identity threats, disrupt active attacks, drive response, and continuously harden posture before the next incident.&lt;/P&gt;
&lt;P&gt;At Microsoft Security, we are building toward that future by embedding this kind of adaptive, AI-driven enforcement directly into identity security. That means accelerating detection across the attack chain, speeding up investigation and response through AI, and ensuring every authentication and access decision reflects real-time risk. It also means bringing IAM and security operations closer together, so identity signals, policy enforcement, and incident response work as one continuous system rather than separate workflows.&lt;/P&gt;
&lt;H2&gt;The future of identity security&lt;/H2&gt;
&lt;P&gt;In the AI era, identity is not just a control point. It is the system that connects prevention, detection, and response into a single, adaptive defense system. And Microsoft is building and operating that system as both the identity provider and policy enforcement layer, with real-time risk signals that can immediately influence access decisions. The organizations that defend identity fastest will be the organizations that defend everything else better.&lt;/P&gt;
&lt;P&gt;-Sandeep Deo and Yaron Paryanty&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2026/03/25/identity-security-is-the-new-pressure-point-for-modern-cyberattacks/" target="_blank" rel="noopener"&gt;Identity security is the new pressure point for modern cyberattacks | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/redefining-identity-security-for-the-modern-enterprise/4503129" target="_blank" rel="noopener"&gt;Redefining identity security for the modern enterprise | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/NHI-security-26" target="_blank" rel="noopener"&gt;Securing the Invisible Workforce | Microsoft Community Hub&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="http://Aka.ms/itdr" target="_blank" rel="noopener"&gt;Get comprehensive identity threat detection and response&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Jun 2026 16:37:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/ai-is-accelerating-cyberattacks-here-s-how-to-stay-ahead/ba-p/4528592</guid>
      <dc:creator>Sandeep Deo</dc:creator>
      <dc:date>2026-06-17T16:37:33Z</dc:date>
    </item>
    <item>
      <title>Tools for Azure AD B2C migration now available</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/tools-for-azure-ad-b2c-migration-now-available/ba-p/4525678</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you rely on Azure AD B2C for customer identity, you’re likely starting to evaluate what comes next. With &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%E2%80%99s-new-in-microsoft-entra-%E2%80%93-march-2025/4352581" target="_blank" rel="noopener"&gt;Azure AD B2C no longer receiving new features&lt;/A&gt; and several features recently added to Microsoft Entra External ID, planning your migration is easier and can help you with this important next step in your identity strategy.&lt;/P&gt;
&lt;P&gt;Below you’ll find tooling, guidance, and a partner ecosystem resource to help you migrate with confidence. This post walks through what’s available and how to get started.&lt;/P&gt;
&lt;H2&gt;What’s new: Platform updates and migration tooling&lt;/H2&gt;
&lt;P&gt;Microsoft has invested significantly in Microsoft Entra External ID to help Azure AD B2C customers migrate with confidence and ease. Over the past three months, several new features have reached general availability.&lt;/P&gt;
&lt;P&gt;Azure AD B2C Migration tooling:&amp;nbsp;Just-in-Time (JIT) migration, High-Scale Compatibility (HSC) mode, and the published Migration Guidance document and architecture blueprint.&lt;/P&gt;
&lt;P&gt;Native authentication GA features in Entra External ID: Email and SMS one-time passcode (OTP) MFA, social identity providers via browser-delegated (web-view) flows, single sign-on (SSO) from native apps to web views, and refresh token transfer to Apple Watch.&lt;/P&gt;
&lt;P&gt;Web and federated in Entra External ID: Sign-in and sign-up with alias, Microsoft Entra ID federation with External ID (public preview), and self-service password reset (SSPR) with phone SMS OTP.&lt;/P&gt;
&lt;P&gt;For a complete list of recent platform updates, see the &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%E2%80%99s-new-in-microsoft-entra-%E2%80%93-march-2026/4502150" target="_blank" rel="noopener"&gt;What’s new in Microsoft Entra&lt;/A&gt; blog.&lt;/P&gt;
&lt;H2&gt;Where Azure AD B2C stands today&lt;/H2&gt;
&lt;P&gt;Azure AD B2C has reached a significant milestone in its lifecycle. It has served as a reliable foundation for customer identity, and that doesn’t change for existing customers. What has changed is where Microsoft is investing going forward. Two facts define what that means for existing customers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;May 2025 — End of sale:&amp;nbsp;&lt;/STRONG&gt;New Azure AD B2C tenants can no longer be&amp;nbsp;purchased. Existing tenants&amp;nbsp;remain&amp;nbsp;supported.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No new features:&amp;nbsp;&lt;/STRONG&gt;All platform innovation is now exclusive to Microsoft Entra External ID. Azure AD B2C will not receive new capabilities going forward.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Your existing Azure AD B2C environment continues to function. Starting your migration early helps you stay in control of sequencing, validation, and user experience. For questions about planning,&amp;nbsp;&lt;A href="mailto:aadb2cmigrationsupport@microsoft.com" target="_blank" rel="noopener"&gt;contact support&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What is Microsoft Entra External ID?&lt;/H2&gt;
&lt;P&gt;Microsoft Entra External ID is a purpose-built, next-generation customer identity platform. It is not a rebrand of Azure AD B2C. It is a new foundation designed to simplify implementation, improve extensibility, and align with the broader Microsoft Entra ecosystem. Key platform improvements include the following.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Modern extensibility model — &lt;/STRONG&gt;Custom authentication extensions replace complex custom policy XML, helping reduce&amp;nbsp;&amp;nbsp; implementation complexity.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Entra ecosystem integration — &lt;/STRONG&gt;Full alignment with Microsoft Entra ID, Conditional Access, Identity Governance, and Microsoft’s broader security stack.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Continuous platform innovation —&amp;nbsp;&lt;/STRONG&gt;Native Authentication SDKs, advanced branding controls, fraud protection, and&amp;nbsp;passwordless-first flows are built exclusively into External ID.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Improved observability — &lt;/STRONG&gt;Enhanced monitoring, diagnostics, and audit capabilities for identity and security teams.&lt;/P&gt;
&lt;H2&gt;&lt;BR /&gt;Migration tooling&lt;/H2&gt;
&lt;P&gt;Two primary migration paths are available, and both are now generally available.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Just-in-Time (JIT) Migration&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;High-Scale Compatibility (HSC) Mode&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Generally available&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Generally available&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Best for&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Most customers seeking a clean cutover with minimal user disruption&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;High-scale environments (5M+ users) or complex architectural constraints&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;How it works&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Migrates users progressively as they sign in — no bulk&amp;nbsp;password reset&amp;nbsp;required&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Moves application traffic to External ID first&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Key benefit&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Full External ID feature parity from day one with minimal user impact&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Supports parallel operation of B2C and External ID during transition, reducing cutover risk&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Documentation&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-migrate-passwords-just-in-time?branch=main" target="_blank" rel="noopener"&gt;JIT Migration Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/enable-external-id-high-scale-compatibility-mode?branch=main" target="_blank" rel="noopener"&gt;HSC Mode Documentation&amp;nbsp;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Choosing between JIT and HSC is less about technical capability and more about migration priorities. JIT prioritizes user experience and simplicity, while HSC prioritizes scale and operational continuity.&lt;/P&gt;
&lt;P&gt;Alongside these tools, Microsoft has published a comprehensive &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930" target="_blank" rel="noopener"&gt;migration guide&lt;/A&gt; and architecture blueprint covering end-to-end migration scenarios, credential migration approaches, and application sequencing guidance.&lt;/P&gt;
&lt;H2&gt;Partner ecosystem&lt;/H2&gt;
&lt;P&gt;For organizations with complex environments, migration is not just a technical exercise. It involves coordinating identity flows, applications, and user experiences across systems.&lt;/P&gt;
&lt;P&gt;Microsoft has established a global ecosystem of qualified migration partners across EMEA, the Americas, LATAM, ANZ, and the Middle East.&lt;/P&gt;
&lt;P&gt;Partner support includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Mapping custom policies to External ID equivalents&lt;/LI&gt;
&lt;LI&gt;Designing credential migration strategies&lt;/LI&gt;
&lt;LI&gt;Sequencing application cutovers&lt;/LI&gt;
&lt;LI&gt;Running staged validation and testing&lt;/LI&gt;
&lt;LI&gt;Supporting production deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Qualified partners meet criteria such as proven Azure AD B2C experience, active engagement with External ID, and participation in Microsoft migration readiness programs.&lt;/P&gt;
&lt;P&gt;Examples include EY, Avanade, Edgile, Slalom, Plan B, WhoIAM, and Grit.&lt;/P&gt;
&lt;P&gt;You can explore the full partner directory in the &lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/services-integration-partners" target="_blank" rel="noopener"&gt;Migration partner directory&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Next steps: How to get started&lt;/H2&gt;
&lt;P&gt;The organizations that navigate migration most successfully are the ones that start planning early. Beginning now gives you greater control over sequencing, application transitions, and user experience changes before they become urgent. Migration challenges rarely come from the tooling itself; they come from coordination across systems, teams, and timelines.&lt;/P&gt;
&lt;P&gt;A structured approach can help accelerate progress:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Assess&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Inventory Applications, user populations, and custom policies&lt;/LI&gt;
&lt;LI&gt;Understand dependencies and integrations&lt;/LI&gt;
&lt;LI&gt;Inventory applications, user populations, and custom policies&lt;/LI&gt;
&lt;LI&gt;Understand dependencies and integrations&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt; Decide&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Review migration guidance&lt;/LI&gt;
&lt;LI&gt;Choose between JIT and HSC based on your priorities&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; Execute&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;Run a proof of concept in a non-production environment&lt;/LI&gt;
&lt;LI&gt;Validate identity flows and user experience&lt;/LI&gt;
&lt;LI&gt;Engage a &lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/services-integration-partners" target="_blank" rel="noopener"&gt;qualified partner&lt;/A&gt; if needed&lt;/LI&gt;
&lt;LI&gt;Align with your Microsoft account team&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Migrating from Azure AD B2C to Microsoft Entra External ID is an opportunity to modernize your customer identity platform while reducing operational complexity. With the right planning, tooling, and support available today, you can move forward with confidence while maintaining a seamless experience for your users.&lt;/P&gt;
&lt;P&gt;For additional support, &lt;A href="mailto:aadb2cmigrationsupport@microsoft.com" target="_blank" rel="noopener"&gt;contact support&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;-Namita Singh - Senior Product Manager, Microsoft Entra External ID&lt;/P&gt;
&lt;P&gt;-Pawan Nrisimha - Principal Manager of Product, Microsoft Entra External ID&lt;/P&gt;
&lt;P&gt;-Isaac Christian - Product Marketing Manager, Microsoft Entra&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/external-identities-overview" target="_blank" rel="noopener"&gt;Microsoft Entra External ID – Platform Overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/plan-your-migration-from-b2c-to-external-id?branch=main&amp;amp;branchFallbackFrom=pr-en-us-11930" target="_blank" rel="noopener"&gt;Azure AD B2C Migration Guide &amp;amp; Architecture Blueprint&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-migrate-passwords-just-in-time?branch=main" target="_blank" rel="noopener"&gt;Just-in-Time Migration Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/external-id/customers/enable-external-id-high-scale-compatibility-mode?branch=main" target="_blank" rel="noopener"&gt;High-Scale Compatibility (HSC) Mode Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/external-id/customers/services-integration-partners" target="_blank" rel="noopener"&gt;Qualified Migration Partner Directory&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 15 Jun 2026 18:39:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/tools-for-azure-ad-b2c-migration-now-available/ba-p/4525678</guid>
      <dc:creator>NamitaSingh</dc:creator>
      <dc:date>2026-06-15T18:39:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Entra ID security updates: What organizations need to do now</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-security-updates-what-organizations-need-to/ba-p/4522024</link>
      <description>&lt;P&gt;Microsoft Entra ID continues to strengthen identity security by modernizing how authentication and access policies are enforced. As part of this effort, Microsoft is retiring legacy capabilities and closing gaps that attackers could exploit. These updates focus on three key areas: replacing Custom controls with External MFA, enforcing Conditional Access consistently during credential registration, and requiring explicitly registered authentication methods for self-service password reset (SSPR). Together, these changes help ensure that your security policies are applied uniformly and backed by strong, user-verified signals.&lt;/P&gt;
&lt;H2&gt;Key points&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Custom controls are being deprecated in favor of External MFA. Existing configurations keep working during the transition, but you should begin migration planning now. Custom controls retire September 30, 2026, and reach end of life in May 2027.&lt;/LI&gt;
&lt;LI&gt;Conditional Access will be enforced consistently during credential registration. Starting July 6, 2026, policies targeting the Register security information action will also apply to Windows Hello for Business provisioning and macOS Platform Single Sign-on registration. Test policies in report-only mode before then.&lt;/LI&gt;
&lt;LI&gt;SSPR will require explicitly registered authentication methods. A registration campaign begins July 6, 2026, and from September 7, 2026, SSPR will accept only registered methods — directory-sourced phone numbers and email addresses that were never formally registered will no longer be accepted.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Deprecation of Custom controls&lt;/H2&gt;
&lt;H3&gt;&lt;U&gt;What’s changing?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft Entra ID is deprecating Custom controls in favor of &lt;A href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-external-method-provider" target="_blank" rel="noopener"&gt;External MFA&lt;/A&gt;, a more integrated, standards-based capability for incorporating third-party MFA providers directly into Conditional Access. External MFA delivers deeper policy integration, a more seamless user experience, and greater flexibility than the legacy Custom controls model. While existing Custom controls configurations will continue to function during the transition period, organizations should begin planning their migration to External MFA.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;When will you see this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Custom controls will be retired on September 30, 2026, and the service will reach end of life in May 2027.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Who will be affected by this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This update affects organizations currently using Custom controls to integrate third-party MFA providers with Conditional Access.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;How will this affect your organization?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations relying on Custom controls will need to transition to External MFA to maintain support and continue using third-party MFA solutions within Microsoft Entra ID. Moving to External MFA also enables more consistent Conditional Access enforcement and improved integration with Microsoft Entra security capabilities.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;What do you need to do to prepare?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations should:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review existing Custom controls integrations&lt;/LI&gt;
&lt;LI&gt;Evaluate External MFA migration requirements&lt;/LI&gt;
&lt;LI&gt;Test Conditional Access policies and user experiences before migration&lt;/LI&gt;
&lt;LI&gt;Begin migration planning ahead of the retirement date&lt;/LI&gt;
&lt;LI&gt;Read more in the &lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/external-mfa-in-microsoft-entra-id-is-now-generally-available/4488926" target="_blank" rel="noopener"&gt;External MFA General Availability&lt;/A&gt; announcement and &lt;A href="https://learn.microsoft.com/en-us/entra/identity/conditional-access/how-to-migrate-custom-controls-external-mfa?tabs=microsoft-entra-admin-center" target="_blank" rel="noopener"&gt;migration guidance.&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Consistent Conditional Access enforcement for credential registration&lt;/H2&gt;
&lt;H3&gt;&lt;U&gt;What’s changing?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft is strengthening Conditional Access enforcement during credential registration flows to close a long-standing enforcement gap.&lt;/P&gt;
&lt;P&gt;Today, policies targeting the &lt;STRONG&gt;Register security information&lt;/STRONG&gt; user action are enforced in My Security Info and Microsoft Authenticator, but not during Windows Hello for Business provisioning or macOS Platform Single Sign-on registration. Conditional Access policies will be enforced consistently across these registration experiences. If users do not meet policy requirements, they will be prompted to satisfy those requirements before completing registration. MFA will continue to be required by default for passwordless credential enrollment, with Conditional Access providing an additional layer of control.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;When will you see this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This update will roll out during the week of &lt;STRONG&gt;July 6, 2026 &lt;/STRONG&gt;to all tenants.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Who will be affected by this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This change affects organizations using:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Conditional Access policies scoped to registration flows&lt;/LI&gt;
&lt;LI&gt;Windows Hello for Business&lt;/LI&gt;
&lt;LI&gt;macOS Platform Single Sign-on&lt;/LI&gt;
&lt;LI&gt;Passwordless credential enrollment scenarios&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;U&gt;How will this affect your organization?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations may see additional prompts or enforcement steps during device setup and credential registration if users do not meet Conditional Access requirements. This change ensures registration flows are governed by the same security controls already applied across other authentication experiences.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;What do you need to do to prepare?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations should review existing registration policies and validate that users can meet Conditional Access requirements during onboarding and device setup. Microsoft recommends testing policies in report-only mode before enforcement begins.&lt;/P&gt;
&lt;H2&gt;SSPR update: Registered authentication methods required&lt;/H2&gt;
&lt;H3&gt;&lt;U&gt;What’s changing?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft is updating Microsoft Entra self-service password reset (SSPR) so that only explicitly registered authentication methods can be used for verification. Directory-sourced phone numbers or email addresses stored only as user object properties—but never formally registered as authentication methods—will no longer be accepted. This change aligns SSPR with Entra ID’s broader authentication model by requiring verification methods tied to user intent and proof of possession.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;When will you see this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Beginning &lt;STRONG&gt;July 6, 2026&lt;/STRONG&gt;, Microsoft will deploy an &lt;STRONG&gt;SSPR registration campaign&lt;/STRONG&gt; that prompts affected administrators and end users to register authentication methods ahead of enforcement. No administrator action is required to enable this campaign.&lt;/P&gt;
&lt;P&gt;Starting &lt;STRONG&gt;September 7, 2026&lt;/STRONG&gt;, SSPR will accept &lt;STRONG&gt;only authentication methods that users or administrators have explicitly registered&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;Who will be affected by this change?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;This update affects organizations and users that still rely on unregistered directory-based phone numbers or email addresses for password reset verification.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;How will this affect your organization?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Users without registered authentication methods may experience interruptions during password reset or account recovery flows after enforcement begins. Organizations may also see an increase in registration prompts during the transition period.&lt;/P&gt;
&lt;H3&gt;&lt;U&gt;What do you need to do to prepare?&lt;/U&gt;&lt;/H3&gt;
&lt;P&gt;Organizations should:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review &lt;A href="https://entra.microsoft.com/" target="_blank" rel="noopener"&gt;authentication method registration coverage&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Identify users relying on unregistered directory values&lt;/LI&gt;
&lt;LI&gt;Encourage users to register approved authentication methods&lt;/LI&gt;
&lt;LI&gt;Communicate upcoming changes to users and help desk teams&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft will prompt affected users and administrators during the transition period to help organizations prepare before enforcement begins.&lt;/P&gt;
&lt;P&gt;Now is the time to review your current configurations, identify where these changes apply in your environment, and begin preparing your users and admins before enforcement milestones arrive. Start by assessing any Custom controls dependencies, validating registration-related Conditional Access policies, and confirming that authentication methods used for SSPR are explicitly registered.&lt;/P&gt;
&lt;P&gt;- &lt;A class="lia-external-url" href="https://www.linkedin.com/in/swaroopk" target="_blank" rel="noopener"&gt;Swaroop Krishnamurthy, Principal Product Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/external-mfa-in-microsoft-entra-id-is-now-generally-available/4488926" target="_blank" rel="noopener"&gt;External MFA in Microsoft Entra ID (general availability announcement)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/" target="_blank" rel="noopener"&gt;Conditional Access in Microsoft Entra ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/" target="_blank" rel="noopener"&gt;Authentication methods in Microsoft Entra ID&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-sspr-howitworks" target="_blank" rel="noopener"&gt;Microsoft Entra self-service password reset (SSPR)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://aka.ms/mysecurityinfo" target="_blank" rel="noopener"&gt;Register security information (My Security Info)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Jun 2026 16:38:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-entra-id-security-updates-what-organizations-need-to/ba-p/4522024</guid>
      <dc:creator>Swaroop Krishnamurthy</dc:creator>
      <dc:date>2026-06-17T16:38:05Z</dc:date>
    </item>
    <item>
      <title>Run Global Secure Access with confidence: Introducing the GSA Operations Guide</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/run-global-secure-access-with-confidence-introducing-the-gsa/ba-p/4524891</link>
      <description>&lt;P&gt;In working with customers, I’ve seen the same pattern again and again: deployment gets the attention, but day 2 operations are where teams need the most structure. This guide is meant to make that part easier—with practical guidance teams can use right away.&lt;/P&gt;
&lt;H2&gt;TL;DR: Your day 2 playbook is here&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What’s new?&lt;/STRONG&gt; A prescriptive &lt;STRONG&gt;Microsoft Entra Global Secure Access operations guide&lt;/STRONG&gt; on Microsoft Learn&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Why it matters:&lt;/STRONG&gt; It brings actionable, alert-first procedures for teams running Global Secure Access after deployment&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;What’s inside:&lt;/STRONG&gt; A role matrix, automated health checks, capability-specific guides, templates, and automation scripts&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Start here:&lt;/STRONG&gt; &lt;A class="lia-external-url" href="http://aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;The day 2 gap&lt;/H2&gt;
&lt;P&gt;Deploying Global Secure Access (GSA) is only the beginning. Day 2 challenges raise questions like: &lt;BR /&gt;&lt;EM&gt;Who monitors what? When do checks happen? How do we know everything is healthy?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The deployment guide covers rollout, and the product documentation explains configuration. But until now, there was no single resource that explained&amp;nbsp;&lt;STRONG&gt;how to operate Global Secure Access in production&lt;/STRONG&gt;. Customers, FastTrack, and partners built their own runbooks—and rebuilt them for each deployment.&lt;/P&gt;
&lt;P&gt;That ends today.&lt;/P&gt;
&lt;H2&gt;Announcing the Operations Guide&lt;/H2&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="http://aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt; is now live on Microsoft Learn.&lt;/P&gt;
&lt;P&gt;This post-deployment playbook delivers prescriptive guidance for&amp;nbsp;&lt;STRONG&gt;running Global Secure Access in production at scale&lt;/STRONG&gt;. It was created by the Global Secure Access customer experience engineering team with input from &lt;STRONG&gt;Thomas Detzner, Janice Ricketts, Jeff Bley, Luis Flores, Marilee Turscak, Peter Lenzke, Mohammad Zmaili, and Ken Withe&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H2&gt;Who this guide empowers&lt;/H2&gt;
&lt;P&gt;This guide is for the teams that keep Global Secure Access running every day: IT administrators, network engineers, and platform operations teams that need clear answers to questions like “Who owns what?” and “How do we prevent issues before they happen?”&lt;/P&gt;
&lt;P&gt;It also equips security leaders with structured reporting so they can demonstrate value and service health to executives. If you’re responsible for Global Secure Access performance, alerting, or automation, this is your new reference playbook. &lt;EM&gt;(And if you haven’t deployed yet, start with the &lt;/EM&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/architecture/gsa-deployment-guide-intro" target="_blank" rel="noopener"&gt;&lt;EM&gt;deployment guide&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;.)&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;What you’ll gain from this guide&lt;/H2&gt;
&lt;H3&gt;Shared practices that work across any environment&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Know your roles early:&lt;/STRONG&gt; A RACI matrix so responsibilities never overlap&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Manage change with confidence:&lt;/STRONG&gt; A GSA-tailored change-control framework for smooth updates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prove success with clarity:&lt;/STRONG&gt; Reporting templates for operators, managers, and executives&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Adopt continuous improvement:&lt;/STRONG&gt; Built-in processes to spot gaps before they become issues&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Capability-specific playbooks structured for speed&lt;/H3&gt;
&lt;P&gt;Every workload (Private Access, Internet Access, Remote Networks, Microsoft Traffic) follows one clear pattern so teams always know what comes next:&lt;BR /&gt;&amp;nbsp;✔ Begin with &lt;STRONG&gt;alert-first monitoring&lt;/STRONG&gt; steps that catch issues early&lt;BR /&gt;&amp;nbsp;✔ Follow &lt;STRONG&gt;daily, weekly, monthly routines&lt;/STRONG&gt; for health maintenance&lt;BR /&gt;&amp;nbsp;✔ Automate critical workflows with &lt;STRONG&gt;Sentinel, Graph API, and PowerShell scripts&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;✔ Track and tune KPIs using measured baselines&lt;BR /&gt;&amp;nbsp;✔ Diagnose and resolve quickly with &lt;STRONG&gt;symptom-to-fix troubleshooting&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;Don’t start from zero—use the templates&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Daily health check across all GSA capabilities&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;Ready-made change request forms and notification playbooks&lt;/LI&gt;
&lt;LI&gt;Modular checklists ready for your ITSM process&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Why this guide is different&lt;/H2&gt;
&lt;P&gt;Unlike generic environment monitoring advice, this guide delivers concrete, tested procedures built from field experience. It applies an alert-first approach so teams can act on signals from Microsoft Sentinel and Azure Monitor before dashboards show trouble.&lt;/P&gt;
&lt;P&gt;Each alert comes with an action—nothing is left unanswered. Automation is embedded throughout, including role-based access control (RBAC) hygiene checks and failover tests. Because operations demand clarity, the guide also provides measurable thresholds, baseline methods, and recovery steps that reduce noise and reinforce uptime.&lt;/P&gt;
&lt;H2&gt;Six moves to launch operational maturity&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Assign roles using the RACI matrix for full coverage&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;Configure critical alerts before adding custom workflows&lt;/LI&gt;
&lt;LI&gt;Collect 30 days of baseline data before adjusting thresholds&lt;/LI&gt;
&lt;LI&gt;Automate backups and priority alert notifications early&lt;/LI&gt;
&lt;LI&gt;Schedule routine checks using provided templates&lt;/LI&gt;
&lt;LI&gt;Begin structured reporting starting with weekly operations and monthly management reviews&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Why it matters for customers and partners&lt;/H2&gt;
&lt;P&gt;This framework reduces time to readiness after deployment, documents a defensible Day 2 plan for audits, cuts escalations by linking every alert to a clear action path, and gives FastTrack and partners a baseline for consistency in engagements.&lt;/P&gt;
&lt;H3&gt;Next up&lt;/H3&gt;
&lt;P&gt;Soon we will publish the GSA Security Operations Guide for Microsoft Entra Global Secure Access, providing a dedicated security monitoring and detection companion to the operational guides for Private Access, Internet Access, Remote Networks, and Microsoft traffic. It brings together the built-in alerts, log sources, Sentinel detections, and cross-signal investigation patterns that security teams need to identify suspicious activity and unauthorized changes across the GSA environment.&lt;/P&gt;
&lt;P&gt;If deployment is still ahead, start with the &lt;A href="https://learn.microsoft.com/en-us/entra/architecture/gsa-deployment-guide-intro" target="_blank" rel="noopener"&gt;GSA Deployment Guide&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Your move&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt; Open the full guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Download templates and run your first daily health check today&lt;/LI&gt;
&lt;LI&gt;Post feedback and ideas to help shape future updates&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Thomas Detzner&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/thomasdetzner/" target="_blank" rel="noopener"&gt;Thomas Detzner | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://microsoft.sharepoint.com/teams/AzureActiveDirectoryBlogcopy/Shared%20Documents/Entra%20Blog%20Publishing/aka.ms/GSAOpsGuide" target="_blank" rel="noopener"&gt;Microsoft Entra Global Secure Access operations guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://aka.ms/IRPlaybooks" target="_blank" rel="noopener"&gt;Microsoft Incident Response Playbooks: response guidance for containment, eradication, and recovery after a SecOps detection is confirmed&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-sentinel-integration" target="_blank" rel="noopener"&gt;Enhance threat detection with Global Secure Access in Microsoft Sentinel: how to stream GSA data into Sentinel, install the solution, enable analytics rules, and use the built-in workbooks.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-alerts" target="_blank" rel="noopener"&gt;What are Global Secure Access alerts?: the built-in GSA alert types, what they mean, and where to view them.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/concept-global-secure-access-logs-monitoring" target="_blank" rel="noopener"&gt;Global Secure Access logs and monitoring: overview of dashboards, traffic logs, audit logs, enriched Microsoft 365 logs, retention, and monitoring surfaces.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-access-audit-logs" target="_blank" rel="noopener"&gt;How to access the Global Secure Access audit logs: where to find GSA-related audit activity and how to filter it for operational or security investigations&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/monitoring-health/reference-audit-activities" target="_blank" rel="noopener"&gt;Microsoft Entra audit log categories and activities for Global Secure Access: the authoritative list of GSA audit operations and categories for change monitoring&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2026 18:04:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/run-global-secure-access-with-confidence-introducing-the-gsa/ba-p/4524891</guid>
      <dc:creator>tdetzner</dc:creator>
      <dc:date>2026-06-05T18:04:21Z</dc:date>
    </item>
    <item>
      <title>Build AI agents for production with secure identities from day one</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/build-ai-agents-for-production-with-secure-identities-from-day/ba-p/4524606</link>
      <description>&lt;P&gt;Building an AI agent is no longer the hard part. The real challenge begins when that agent must run securely in production and meet identity, access, audit, and security requirements. That’s where many agents get stuck. It’s relatively easy to build a prototype, but much harder to deploy an agent that operates with the security controls required for production. Microsoft Entra Agent ID helps close that gap by giving agents a consistent identity foundation. Together with the Microsoft Agent 365 CLI and SDK, it helps you deploy AI agents that are ready to be managed, governed, and protected within your organization.&lt;/P&gt;
&lt;H2&gt;What is Microsoft Entra Agent ID?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt;, now generally available, is the identity and access platform in Microsoft Entra for AI agents. It introduces a set of identity constructs that match how agents are built and operated. There are three key concepts worth noting when deploying agents in your organization.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;BR /&gt;Agent blueprint:&lt;/STRONG&gt; A blueprint is the reusable identity template for a class of agents. It defines the common configuration, accountability model, credentials, and scopes used when creating agent identities so developers can create them consistently across deployments.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The agent blueprint manifest is a JSON representation of the blueprint, which you can view or edit under developer settings.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-left lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Agent identity:&lt;/STRONG&gt; Every agent instance gets its own identity in Microsoft Entra. Each identity has its own sign-in history, audit trail, assigned scopes, and targetable principal for Conditional Access. When you need to know what agent #4,712 did at 3:47 a.m. yesterday, the answer is in Microsoft Entra sign-in logs, indexed by the agent identity itself. When you need to retire a single malicious instance without touching the rest of your fleet, there is a kill switch for that agent identity.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The agent identities view in the Microsoft Entra admin center shows you an inventory of the agent identities in your tenant.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-align-left lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;&lt;BR /&gt;Agent sponsors and owners:&lt;/STRONG&gt; Every agent needs clear accountability through two distinct roles. Sponsors provide business accountability for the agent’s purpose and lifecycle decisions, such as whether it should retain access or be retired. Owners are responsible for the technical configuration and management of the agent identity.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;The overview of the individual agent identity shows the sponsor, blueprint, and granted permissions for the agent.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;These concepts matter because they shape how agent onboarding works in practice. Once you understand the blueprint, the agent identity, and the accountability roles around it, the next question is how those pieces are created during deployment.&lt;/P&gt;
&lt;H2&gt;How an agent gets an agent identity, blueprint, and sponsor&lt;/H2&gt;
&lt;P&gt;There isn’t one single way to provision an agent identity, and that’s intentional. Microsoft Entra documents the official &lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/agent-id-creation-channels" target="_blank" rel="noopener"&gt;creation channels&lt;/A&gt; through which agent identity blueprints and identities can land in your tenant. Each channel has its own audience and control surface, and every creation event is recorded in Microsoft Entra audit logs with the channel attached. The channels developers use most often are outlined here.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft product integrations: &lt;/STRONG&gt;Agents built in Microsoft Foundry, Copilot Studio, and Security Copilot get a Microsoft Entra Agent ID automatically as part of platform onboarding. Identity is provisioned from a blueprint and connected without any additional developer effort.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Agent 365 CLI and SDK:&lt;/STRONG&gt; For agents built on any other framework (Microsoft Agent Framework, OpenAI Agents SDK, Anthropic Claude Agent SDK, Google ADK, AWS Bedrock, LangChain, LlamaIndex, CrewAI, Semantic Kernel, GitHub Copilot SDK, and others), the Microsoft Agent 365 CLI provisions the agent’s identity through Microsoft Graph, and the Microsoft Agent 365 SDK connects the running agent to the control plane so observability, governance, and security come with the identity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is the recommended channel for cross-platform and non-Microsoft agents because one integration delivers Microsoft Entra Agent ID plus the rest of Microsoft Agent 365 as a single bundle.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;For developers who don’t already have an onboarding pipeline, the fastest way to take an agent from a code repository to a managed, governed, and protected agent in your tenant is to use the AI-guided onboarding experience in the &lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/" target="_blank" rel="noopener"&gt;Microsoft Agent 365 CLI and SDK&lt;/A&gt; documentation. It walks you through the end-to-end steps: running the Microsoft Agent 365 CLI, wrapping your agent entry point with the Microsoft Agent 365 SDK, and configuring the runtime credentials Microsoft Entra will use to issue tokens.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Learn more about &lt;A href="https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-agent-id" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID&lt;/A&gt; and how it helps organizations secure access for AI agents&lt;/LI&gt;
&lt;LI&gt;Learn how to &lt;A href="https://aka.ms/A365SDK-Blog" target="_blank" rel="noopener"&gt;make any agent enterprise-ready with the Agent 365 SDK&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Explore: &lt;A href="https://www.microsoft.com/en-us/microsoft-agent-365?msockid=01e7c8230a52661133cfdf100b696796" target="_blank" rel="noopener"&gt;Microsoft Agent 365&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;-Arturo Lucatero, Principal Product Manager&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/" target="_blank" rel="noopener"&gt;Microsoft Agent 365 CLI and SDK Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/agent-id/" target="_blank" rel="noopener"&gt;Microsoft Entra Agent ID Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/" target="_blank" rel="noopener"&gt;Microsoft Agent 365 Documentation&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 19:15:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/build-ai-agents-for-production-with-secure-identities-from-day/ba-p/4524606</guid>
      <dc:creator>ArLucaID</dc:creator>
      <dc:date>2026-06-02T19:15:00Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Entra: June 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-june-2026/ba-p/4517885</link>
      <description>&lt;P&gt;Welcome to the June edition of our monthly newsletter, summarizing the latest news and developments in the exciting, ever-evolving world of Microsoft Entra.&lt;/P&gt;
&lt;H2&gt;What went into General Availability (GA) since May 2026?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/devices/sso-linux?tabs=password-auth%2cdebian-install%2cdebian-update%2cdebian-uninstall%2cdebian-sc-example" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable Phish‑Resistant MFA for Linux Desktops with Microsoft Entra&lt;/STRONG&gt;&amp;nbsp;&lt;/A&gt;-&amp;nbsp;Microsoft Entra extends Phish Resistant Multi-Factor Authentication support to Linux desktops through the Microsoft identity broker, closing a long-standing gap in cross-platform identity. This update brings Linux to parity with Windows and macOS, enabling secure, modern authentication using phishing-resistant credentials. Support is now available for Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, helping organizations consistently enforce strong authentication across all major desktop platforms.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/customers/enable-external-id-high-scale-compatibility-mode" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable improved B2C-to-External ID migration with High Scale Compatibility (HSC) mode&lt;/STRONG&gt;&lt;/A&gt; – HSC mode is a new tenant-level migration option that lets Azure AD B2C customers transition their applications to Microsoft Entra External ID without re-registering users or resetting passwords, by keeping existing B2C credentials in place during coexistence. It's intended for high-scale tenants - generally those with 5 million or more objects - where the standard bulk migration with JIT password sync isn't practical. Tenants below the 5M threshold should continue to use the standard migration path, and even eligible high-scale tenants should carefully evaluate both options before choosing. Customers can run the B2C Policy Analyzer to assess migration readiness, and account teams and partners should engage the EEID migration team to guide eligible Azure Active Directory B2C customers toward the right migration path.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-system-preferred-authentication" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable system-preferred authentication for first and second factors&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra ID updates system-preferred authentication to apply to both first-factor and second-factor authentication in Microsoft Managed state. The system evaluates registered credentials for the user and selects the highest-ranked method for each authentication step. This update applies automatically in the Microsoft managed state, ensuring seamless and secure authentication experiences.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-US/accounts-billing/work-school/my-account-portal-for-work-or-school-accounts" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Modernize account management with redesigned My Account pages&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra introduces redesigned &lt;STRONG&gt;Devices, Security Info,&lt;/STRONG&gt; and &lt;STRONG&gt;Organizations pages &lt;/STRONG&gt;in the My Account portal. The &lt;STRONG&gt;Devices &lt;/STRONG&gt;page simplifies registered device management and prominently surfaces BitLocker recovery keys, reducing IT helpdesk dependency. The &lt;STRONG&gt;Security Info&lt;/STRONG&gt; page in &lt;STRONG&gt;Settings &amp;amp; Privacy&lt;/STRONG&gt; centralizes profile information, language, and region settings for easier updates. The &lt;STRONG&gt;Organizations&lt;/STRONG&gt; page resolves issues with end users leaving organizations and delivers a streamlined experience. These updates automatically roll out to Microsoft Entra ID customers by the end of June 2026, requiring no administrator action.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/multi-tenant-organizations/cross-tenant-synchronization-overview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cross-tenant group synchronization in Microsoft Entra&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;-&amp;nbsp;This enables organizations to synchronize security groups and memberships across tenants for centralized management and consistent access control. This simplifies cross-tenant collaboration by allowing groups managed in a source tenant to be used in one or more target tenants for scenarios like shared application access and resource authorization.&amp;nbsp;Beyond collaboration, this enables more seamless cross-tenant administration by allowing organizations to extend governance and access control consistently across tenant boundaries.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/accountDiscoveryDocumentation" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Account discovery for connected applications in Microsoft Entra ID Governance&lt;/STRONG&gt;&lt;/A&gt; - Administrators gain visibility into all accounts within connected applications, including orphan accounts not assigned to the enterprise application in Microsoft Entra. Generate discovery reports directly from the provisioning experience to identify access gaps and simplify application onboarding. This capability requires a Microsoft Entra ID Governance or Microsoft Entra Suite license.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/agent-sponsor-tasks" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Automate agent identity sponsorship transitions&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra ID Governance ensures agent identities always have a delegated human sponsor accountable for their access and lifecycle. With Lifecycle Workflows, when a sponsor leaves the organization, sponsorship automatically transfers to their manager, maintaining continuity. Lifecycle workflows can also notify cosponsors and managers of impending sponsorship changes, streamlining the process and reducing manual oversight.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-mfa-registration-campaign" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Drive Passkey Adoption with Microsoft Entra Registration Campaigns&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;- Microsoft Entra Registration Campaigns now supports Passkeys such as Fast Identity Online (FIDO2), as an authentication method. Administrators can configure registration campaigns to nudge users to register passkeys during sign-in, helping organizations drive passkey adoption. This first rollout experience is optimized for users in a passkey profile without restrictions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/app-disablement-docs" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;App Deactivation for Microsoft Entra applications&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- App Deactivation introduces a safe, reversible, and self-service way for app owners and admins to turn off applications that are unused, deprecated, or under investigation - without deleting them or breaking tenant-level governance.&amp;nbsp;Deactivating an app registration provides a reversible way to prevent the application from accessing protected resources without permanently removing it from your tenant. When you deactivate an application, it immediately stops receiving new access tokens, but existing tokens remain valid until they expire. This approach is useful for security investigations, temporary suspension of suspicious applications, or when you need to maintain application configuration data.&amp;nbsp;Unlike permanently deleting an application, deactivation preserves all application metadata, permissions, and configuration settings, making it easy to reactivate the application if needed. The application remains visible in your tenant's enterprise applications list, but users can't sign in and no new tokens are issued.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-entra-passkeys-on-windows" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enable phishing-resistant sign-in with Microsoft Entra passkeys on Windows&lt;/STRONG&gt;&lt;/A&gt; - Users register device-bound passkeys in the local Windows Hello container and use them for secure sign-in with Windows Hello biometrics or PIN. These passkeys function as FIDO2 credentials and work without requiring the device to be Microsoft Entra joined or registered. This capability is automatically available in tenants where passkey profiles permit Windows Hello as a provider, supporting phishing-resistant authentication for Entra-protected cloud resources. Interactive Windows console sign-in is not supported.&lt;/P&gt;
&lt;H2&gt;New in Public Preview&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/external-id/direct-federation#domainless-saml-idp-federation-preview" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Support domain-less SAML Federation on workforce tenants&lt;/STRONG&gt;&lt;/A&gt; - Domainless SAML federation with a SAML Identity Provider allows external users to authenticate into your apps or workforce resources using their IdP-managed credentials, regardless of their email domain. Domainless federation removes the need for domain matching between the user's email and pre-configured IdP domains during sign-in or invitation redemption.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/users/groups-sensitivity-labels" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Sensitivity labels for Entra security groups &lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;-&amp;nbsp;&lt;/STRONG&gt;Microsoft Entra ID supports applying Microsoft Purview sensitivity labels to Entra cloud security groups in public preview. This enables administrators to use the same labels and policies already used for Microsoft 365 groups to govern security group behaviors such as guest access and other controls. Sensitivity labels are managed in Microsoft Purview and can be applied through the Entra Admin Center, Azure portal, and Microsoft Graph, helping organizations apply consistent governance across identities and access.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/devices/concept-soft-delete-devices?branch=main&amp;amp;branchFallbackFrom=pr-en-us-12460" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Safely remove and restore devices with Device Soft Delete&lt;/STRONG&gt;&lt;/A&gt; - This enables administrators to move device objects to a recoverable state instead of permanently deleting them. Organizations can restore devices within a defined retention period while preserving critical data like device identity and associated security artifacts. The feature supports Microsoft Entra joined, registered, and hybrid joined devices, reducing risks from accidental deletions and improving device lifecycle management.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aka.ms/EntraSAPSFConnectivityGuide" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Move SAP SuccessFactors Provisioning to Workload Identity-based authentication&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;- Microsoft Entra introduces Workload Identity-based authentication for SAP SuccessFactors provisioning, replacing long-lived usernames and passwords with Entra-managed credentials and short‑lived, standards‑based access tokens. This update allows customers to perform this authentication upgrade in-place on their existing provisioning jobs, without recreating or restarting them. This will switch their Entra or SuccessFactors integrations to a more secure model that is aligned with SAP SuccessFactors' plan to deprecate basic authentication for SAP SuccessFactors' APIs by November 2026. The new option applies to SAP SuccessFactors inbound provisioning to Active Directory and Microsoft Entra ID, as well as writeback scenarios, and improves security by eliminating the need to manually handle credentials and rotate them periodically.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/entitlement-management-azure-role-assignments" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Govern Azure role assignments with access packages&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra enables governance of eligible and active assignments to Azure roles at the Management Group, Subscription, and Resource Group levels through access packages. Role assignments now follow the same request, approval, and lifecycle governance model as apps and groups. This simplifies managing access to Azure resources at scale while supporting least privilege and just-in-time access principles.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/id-governance/how-to-lifecycle-workflow-update-user-attributes" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Automate user attribute updates in Lifecycle Workflows&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra introduces the User Attribute Updates task in Lifecycle Workflows, enabling automated attribute changes directly within workflows. Administrators can set or clear attribute values including custom attributes with a secure, consistent, and auditable process. This feature reduces manual effort, enhances governance, and scales identity automation with confidence.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Improve privileged identity response for Security Operations Center (SOC)&lt;/STRONG&gt; – Microsoft is extending the Entra Security Operator role so SOC analysts can take identity response actions such as disable users, revoke sessions, mark users compromised, force password resets (including cloud-only accounts), and delete individual authentication methods , directly from the Microsoft Defender unified role-based access control (RBAC) experience, without broad Entra admin roles or identity and access management (IAM) escalation during active incidents. Permissions are scoped to non-admin users enabling faster containment, least-privilege boundaries, and auditability.&lt;/P&gt;
&lt;H2&gt;Announcements&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/concept-sspr-policy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Require registered methods for Self-Service Password Reset&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra Self-Service Password Reset (SSPR) will only accept explicitly registered authentication methods for identity verification starting September 7, 2026. Directory-sourced contact information, such as phone numbers and email addresses stored as user object properties, will no longer be accepted unless registered as authentication methods. This change applies to all users, including administrators, across Public cloud, GCC, GCC High, and DoD. Beginning July 6, 2026, Microsoft will automatically launch a registration campaign prompting affected users to register authentication methods after sign-in. Administrators should ensure users have at least one registered method to meet SSPR policy requirements before enforcement to avoid disruptions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/conditional-access/policy-all-users-security-info-registration" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enforce conditional Access during credential registration&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;- Starting&amp;nbsp;&lt;STRONG&gt;July 6, 2026,&lt;/STRONG&gt; Entra ID Conditional Access policies scoped to the&amp;nbsp;&lt;STRONG&gt;Register security information&lt;/STRONG&gt;&amp;nbsp;user action will be evaluated during credential registration for Windows Hello for Business and macOS Platform SSO .This ensures registration policies apply consistently across all registration flows. Users must satisfy policy controls, such as multifactor authentication (MFA), network restrictions, device compliance, or other tenant defined requirement before completing registration. Organizations without Conditional Access policies targeting this user action are unaffected, and MFA remains required by default for all passwordless credential registrations. Enforcement completes by July 13, 2026.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-passkeys-fido2#passkey-profile-prerequisites" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Expand passkey policy size and profiles in authentication methods policy&lt;/STRONG&gt;&lt;/A&gt; - Microsoft Entra increases the passkey (Fast Identity Online 2, FIDO2) policy size limit to a dedicated 20 KB allocation within the authentication methods policy. Previously, all authentication methods shared a single 20 KB limit. This update ensures passkey policies have their own allocation, simplifying adoption and advanced targeting scenarios. Additionally, the maximum number of passkey profiles per tenant increases from 3 to 10, allowing greater flexibility in managing passkey configurations.&lt;/P&gt;
&lt;H2&gt;New guidance and information&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/global-secure-access/overview-operations" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Global Secure Access Operations Guide&lt;/STRONG&gt;&lt;/A&gt; - The new GSA Operations Guide is your post-deployment companion for running Global Secure Access reliably at scale. It covers alerting, health checks, change management, metrics, and recovery playbooks, with ready-to-use KQL queries and templates you can adopt on day one. Capability-specific guides are included for Private Access, Internet Access, Remote Networks, and Microsoft Traffic.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Tell us what you think!&lt;/H2&gt;
&lt;P&gt;If you have feedback on this newsletter, fill out the dedicated &lt;A href="https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR3tZ6taaY2dAnA0rWwJeTkRUM1BUWjM5TjI5Sk1HME45TVVYOEdBNkJRNy4u" target="_blank" rel="noopener"&gt;Microsoft Form&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Blogs&lt;/H2&gt;
&lt;P&gt;Check out the latest blog posts on our &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;Microsoft Entra Blog&lt;/A&gt; and our &lt;A href="https://aka.ms/devblog/ms-entra" target="_blank" rel="noopener"&gt;Microsoft Entra Identity Developer Blog&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What's new in Microsoft Entra?&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new" target="_blank" rel="noopener"&gt;Learn what is new with Microsoft Entra&lt;/A&gt;, such as the latest release notes, known issues, bug fixes, deprecation functionality, and upcoming changes. You can find &lt;A href="https://learn.microsoft.com/entra/fundamentals/whats-new-sovereign-clouds" target="_blank" rel="noopener"&gt;releases specific for Sovereign Clouds&lt;/A&gt; on a dedicated release notes page.&lt;/P&gt;
&lt;H2&gt;Become a certified Microsoft Identity and Access Administrator&lt;/H2&gt;
&lt;P&gt;Check out the &lt;A href="https://learn.microsoft.com/credentials/certifications/exams/sc-300/" target="_blank" rel="noopener"&gt;certification&lt;/A&gt; and related &lt;A href="https://learn.microsoft.com/credentials/certifications/identity-and-access-administrator/" target="_blank" rel="noopener"&gt;training&lt;/A&gt; for the Microsoft Identity and Access Administrator available for customers and partners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Martin Coetzer&lt;/P&gt;
&lt;P&gt;Principal Product Manager, Identity and Network Access, Customer Experience Engineering (CXE)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/company/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra Community | LinkedIn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 01 Jun 2026 22:54:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/what-s-new-in-microsoft-entra-june-2026/ba-p/4517885</guid>
      <dc:creator>Martin_Coetzer</dc:creator>
      <dc:date>2026-06-01T22:54:12Z</dc:date>
    </item>
    <item>
      <title>Find shadow tenants and reduce risk fast with Microsoft Entra Tenant Governance</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/find-shadow-tenants-and-reduce-risk-fast-with-microsoft-entra/ba-p/4521996</link>
      <description>&lt;P&gt;As organizations grow, so does their tenant footprint. Over time, tenants created for acquisitions, development projects, regional operations, or partner collaboration can fall outside central IT visibility, creating what many security teams now refer to as shadow tenants.&lt;/P&gt;
&lt;P&gt;One of the foundational pillars of &lt;STRONG&gt;Microsoft Entra Tenant Governance&lt;/STRONG&gt; is discovering &lt;STRONG&gt;related tenants&lt;/STRONG&gt;. This capability helps you identify tenants connected to your environment through signals such as B2B collaboration, multitenant applications and shared billing relationships. With that visibility, you can reduce hidden security risks before they become incidents.&lt;/P&gt;
&lt;P&gt;Let’s explore what this looks like in practice through the lens of the &lt;STRONG&gt;Related Tenants&lt;/STRONG&gt; pillar.&lt;/P&gt;
&lt;H2&gt;Scenario: Contoso discovers its hidden tenant landscape&lt;/H2&gt;
&lt;P&gt;Contoso's IT security team knows about their primary production tenant and a handful of dev/test tenants. But after reading about the Midnight Blizzard attack, the CISO wants a complete picture. Are there tenants out there that Contoso doesn't know about?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Turn on discovery.&lt;/STRONG&gt; A Contoso admin, Alice, opens the &lt;A href="https://entra.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Entra admin center&lt;/A&gt;, navigates to &lt;STRONG&gt;Tenant governance &amp;gt; Related tenants&lt;/STRONG&gt;, and enables discovery. It takes a single click—no infrastructure to configure.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Discover what’s connected.&lt;/STRONG&gt; Within hours, the system surfaces tenants connected to Contoso through cross-tenant signals (B2B collaboration, multitenant app registrations, and shared billing accounts). Alice sees 14 related tenants. The team recognizes nine of them. The other five are a mix of tenants from a 2023 acquisition that were never onboarded, a proof-of-concept tenant a partner team spun up, and two legacy test environments nobody remembered existed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3: Assess and act.&lt;/STRONG&gt; For each discovered tenant, Contoso can see the relationship type and the signals behind it. The security team flags unknown tenants for review and immediately runs a quarantine workflow for one unsanctioned tenant that has high-risk multitenant app permissions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Confirm exposure.&lt;/STRONG&gt; Validate which app permissions were granted, whether admin consent exists, and which users or workloads are affected.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Block user sign-in paths.&lt;/STRONG&gt; In cross-tenant access settings, add the suspect tenant and block inbound and outbound user sign-in so collaboration with that tenant is stopped without disrupting trusted tenants.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Contain application access.&lt;/STRONG&gt; Find enterprise applications whose “appOwnerOrganizationId” matches the suspect tenant, then revoke granted permissions or delete the corresponding service principals to cut off app-based access.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Harden with tenant restrictions.&lt;/STRONG&gt; Apply a tenant restrictions v2 policy through Global Secure Access and universal tenant restrictions so managed users can’t authenticate unsanctioned tenants.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate and decide. &lt;/STRONG&gt;Verify blocking in sign-in and audit logs, run a short scream test for business impact, then either onboard the tenant into governance relationships and policy baselines or keep it isolated until retirement.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra Tenant Governance related tenants.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;EM&gt;Microsoft Entra Tenant Governance discovery signals.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This isn’t a one-time scan. Related tenants are a continuously updated inventory; as new tenants appear in Contoso’s identity landscape, they surface automatically. No more blind spots waiting to be exploited.&lt;/P&gt;
&lt;P&gt;Following the guidance in &lt;A href="https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/discover-cloud-footprint" target="_blank" rel="noopener"&gt;Discover your Microsoft cloud footprint&lt;/A&gt;, organizations can further expand their visibility by using additional telemetry sources including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Azure subscription billing data&lt;/LI&gt;
&lt;LI&gt;Authentication logs (Microsoft Entra sign-ins)&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 activity&lt;/LI&gt;
&lt;LI&gt;Audit logs&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These sources help organizations inventory all Microsoft tenants where users have signed in or resources are provisioned, identify cross-tenant relationships through app consent and Global Secure Access network traffic, and surface potential risks from tenants with elevated permissions or suspicious patterns.&lt;/P&gt;
&lt;P&gt;For tenants that are discovered but not yet trusted, organizations can take immediate action using existing &lt;A href="https://aka.ms/tenantquarantine" target="_blank" rel="noopener"&gt;tenant quarantine capabilities&lt;/A&gt; to isolate potentially risky tenants and restrict their interactions until they've been assessed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Important: &lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;Using the new add-on tenant creation flow is a crucial part of establishing a secure tenant landscape. To ensure organizations are using the most secure methods possible to create add-on tenants, the legacy workforce tenant creation flow will be retired August 15, 2026.&lt;/EM&gt;&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Threat actors continue to innovate, but so do we. By making tenant discovery a foundational part of your identity strategy, you can close gaps before adversaries find them.&lt;/P&gt;
&lt;P&gt;To get started, enable related tenants discovery in the &lt;A href="https://entra.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Entra admin center&lt;/A&gt; or through the tenant governance API. Your feedback is instrumental in shaping these tools. We invite you to try the public preview and share your experience.&lt;/P&gt;
&lt;P&gt;Stay secure, stay informed, and stay ahead.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;-Cindy Crane, Principal Product Manager&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/id-governance/tenant-governance/overview" target="_blank" rel="noopener"&gt;What is Microsoft Entra Tenant Governance? (preview) – Microsoft Entra ID Governance | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/discover-cloud-footprint" target="_blank" rel="noopener"&gt;Discover your Microsoft cloud footprint&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/fundamentals/quarantine-unsanctioned-tenants" target="_blank" rel="noopener"&gt;Quarantine unsanctioned tenants&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 26 May 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/find-shadow-tenants-and-reduce-risk-fast-with-microsoft-entra/ba-p/4521996</guid>
      <dc:creator>CindyCrane</dc:creator>
      <dc:date>2026-05-26T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Platform SSO during automated device enrollment is now generally available for macOS</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/platform-sso-during-automated-device-enrollment-is-now-generally/ba-p/4436813</link>
      <description>&lt;P&gt;Getting new devices into users’ hands quickly while maintaining strong identity and compliance has always required a careful balance. IT admins need streamlined deployment workflows, while end users expect a frictionless experience from the very first sign-in.&lt;/P&gt;
&lt;P&gt;Today, we’re excited to announce that &lt;STRONG&gt;Platform SSO (PSSO) during Automated Device Enrollment (ADE) on macOS is now generally available&lt;/STRONG&gt;. This capability simplifies onboarding by enabling device registration and Platform SSO setup to occur automatically during enrollment, eliminating extra steps for both IT administrators and end users.&lt;/P&gt;
&lt;H2&gt;Streamline setup for IT admins&lt;/H2&gt;
&lt;P&gt;Automated Device Enrollment already provides a powerful way to provision macOS devices with the right configuration, policies, and applications from the start. With Platform SSO now integrated directly into this flow, IT admins can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ensure Platform SSO is enabled as part of enrollment — no post-setup steps required.&lt;/LI&gt;
&lt;LI&gt;Standardize device identity and access configuration from day one.&lt;/LI&gt;
&lt;LI&gt;Reduce deployment complexity by avoiding separate workflows for completing SSO setup.&lt;/LI&gt;
&lt;LI&gt;Improve compliance posture immediately with identity-backed device trust.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;By incorporating PSSO into ADE, organizations can treat identity configuration as a core part of provisioning—not as an afterthought.&lt;/P&gt;
&lt;H2&gt;Reduce friction for end users&lt;/H2&gt;
&lt;P&gt;Previously, users enrolling macOS devices might encounter an additional step after setup to complete Platform SSO registration, typically requiring them to respond to a prompt or click a “Finish” action.&lt;/P&gt;
&lt;P&gt;With this new capability, that extra step is removed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No additional prompts to complete Platform SSO&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No need for users to manually finish enrollment steps&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Immediate access to single sign-on experiences after setup&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result is a smoother, more intuitive onboarding experience where users can begin working right away without interruption.&lt;/P&gt;
&lt;H2&gt;Understand how it works&lt;/H2&gt;
&lt;P&gt;With the &lt;STRONG&gt;EnableRegistrationDuringSetup&lt;/STRONG&gt; capability, Platform SSO registration is performed as part of the Automated Device Enrollment process. This ensures that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The device is properly registered with Microsoft Entra ID during setup.&lt;/LI&gt;
&lt;LI&gt;Platform SSO is activated automatically.&lt;/LI&gt;
&lt;LI&gt;The user’s identity is fully integrated into the device experience from first sign-in.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because this happens within the managed enrollment flow, it aligns naturally with existing MDM configurations and provisioning policies.&lt;/P&gt;
&lt;H2&gt;See why it matters&lt;/H2&gt;
&lt;P&gt;For organizations adopting modern identity and device management, reducing friction during onboarding is critical—not just for productivity, but for security consistency at scale.&lt;/P&gt;
&lt;P&gt;With Platform SSO during ADE:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;IT admins gain a predictable, simplified setup experience.&lt;/LI&gt;
&lt;LI&gt;Users avoid confusing or redundant steps during onboarding.&lt;/LI&gt;
&lt;LI&gt;Organizations achieve faster time-to-productivity with stronger identity integration.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is especially impactful in environments where devices are deployed at scale, such as enterprise rollouts, education, or frontline scenarios.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Ready to simplify macOS onboarding? Configure Platform SSO during Automated Device Enrollment in Microsoft Intune to reduce setup friction and strengthen identity from day one.&lt;/P&gt;
&lt;P&gt;To enable Platform SSO during Automated Device Enrollment, follow the &lt;A href="https://review.learn.microsoft.com/en-us/mem/intune/configuration/configure-platform-sso-during-enrollment.md" target="_blank" rel="noopener"&gt;MDM configuration steps&lt;/A&gt; below:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure Automated Device Enrollment for macOS in your MDM solution.&lt;/LI&gt;
&lt;LI&gt;Ensure Platform SSO is configured for your organization.&lt;/LI&gt;
&lt;LI&gt;Enable the &lt;STRONG&gt;EnableRegistrationDuringSetup&lt;/STRONG&gt; setting as part of your deployment profile.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Once enabled, new devices will automatically complete Platform SSO setup during enrollment—with no additional user action required.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;-&lt;/STRONG&gt; Justin Ploegert&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/macos-psso" target="_blank" rel="noopener"&gt;macOS Platform single sign-on (PSSO) overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-macos-platform-single-sign-on-extension" target="_blank" rel="noopener"&gt;macOS Platform single sign-on known issues and troubleshooting&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://review.learn.microsoft.com/en-us/mem/intune/configuration/configure-platform-sso-during-enrollment.md" target="_blank" rel="noopener"&gt;Configure Platform SSO for macOS devices in Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos" target="_blank" rel="noopener"&gt;Single Sign-on scenarios&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment" target="_blank" rel="noopener"&gt;Single Sign-on in ADE profile&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-macos" target="_blank" rel="noopener"&gt;Platform SSO configuration guide for macOS devices using Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos" target="_blank" rel="noopener"&gt;Common Platform SSO scenarios for macOS devices&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-company-portal-macos" target="_blank" rel="noopener"&gt;Install Company Portal for macOS as a macOS LOB app&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-macos" target="_blank" rel="noopener"&gt;Set up automated device enrollment (ADE)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra-blog/bg-p/Identity" target="_blank" rel="noopener"&gt;⁠Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;⁠&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-entra/bd-p/Azure-Active-Directory" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 18 May 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/platform-sso-during-automated-device-enrollment-is-now-generally/ba-p/4436813</guid>
      <dc:creator>Justin-Ploegert</dc:creator>
      <dc:date>2026-05-18T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft Identity Manager 2016 SP3 now available: Enhanced stability for hybrid identity</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-identity-manager-2016-sp3-now-available-enhanced/ba-p/4519489</link>
      <description>&lt;P&gt;Many organizations continue to depend on Microsoft Identity Manager (MIM) 2016 for scenarios that are not easily replicated elsewhere, such as:&lt;/P&gt;
&lt;P&gt;Synchronization across multiple directories and forests:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Complex attribute flows and identity correlation logic&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Management of custom objects and extended schemas&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Deep integration with on-premises applications&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Microsoft Identity Manager (MIM) 2016 Service Pack 3 (SP3) is now generally available. SP3 focuses on stability and supportability and updates compatibility with current platform components such as SQL Server, SharePoint, and Exchange. It also adds a new deployment option for the Synchronization Service: Azure SQL Database, with authentication through system-assigned and user-assigned managed identities to help reduce operational risk in hybrid identity environments.&lt;/P&gt;
&lt;H2&gt;In this release&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Run MIM on current platform components&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Updated compatibility for newer platform releases, including SQL Server 2022 and Exchange Server Subscription Edition (SE).&lt;/LI&gt;
&lt;LI&gt;New Synchronization Service database option: Azure SQL Database with authentication via system-assigned and user-assigned managed identities.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Modernize the MIM Service and Portal experience&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Deploy the MIM Portal on SharePoint Subscription Edition (SE).&lt;/LI&gt;
&lt;LI&gt;Support for System Center Service Manager Data Warehouse (DW) 2022 for reporting and audit integration.&lt;/LI&gt;
&lt;LI&gt;Active Directory Federation Services (AD FS) single sign-on (SSO) support for claims-based authentication, enabling users to sign in through AD FS instead of Windows integrated authentication.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Download and upgrade information&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Based on your licensing, you can download the installer packages here:&amp;nbsp;&lt;A href="https://outlook.office.com/mail/safelink.html?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmicrosoft-identity-manager%2Fmicrosoft-identity-manager-licensing%23obtaining-windows-installer-packages&amp;amp;locale=en-GB&amp;amp;wau=https%3A%2F%2FNAM06.safelinks.protection.outlook.com%2FGetUrlReputation&amp;amp;wid=00730A1A-3310-48BA-AB07-9EC288151649&amp;amp;corid=a787c79a-92b9-0eb6-a13a-2fe6ff92860a&amp;amp;srcid=&amp;amp;appname=Microsoft+Outlook+Web+App&amp;amp;appver=20260421013.02&amp;amp;os=Windows+11&amp;amp;scdt=&amp;amp;pc=7%252fv%252bt5EOVYXu109FvnxFD%252fwR7Qvhy9uHtEa0WV1bs9Ah51LkVFh39W%252fhDcAY%252fRfPmEAUDf7Bv2s7Y4VIICkWP39fY7IUsbFe1a7Uj5VgGuV8vtuRtkKfapn2fLPCcm81Ib3cClE1cmYlI95mXpW7FxH2QG9bcfLYmR9z8pec56TAUjSlvbchBZFVrq7HEpERaTLfeJKeM4eJnjG5B2ZI0xNdniZTeyUsvJuYlIesFZpnoELN7SRt9%252fXPRk7rgQ%252bo3Sq2DKU7Tdjvr40SX0bnLeYms1zMsR72N92hJLYh1zHxfzgig1HcmHkYJ8C9e7ux7EWTCf5U72JljmUwCJj7ZSaRilLFGsAeZb8sY7XamjQ45CBpC0eAvUuYrNdQmJ9a5TzzUNG1vgFJQFMFqdmMcHoLl%252bV%252fh4e1Q2DfxUrSLp5TDO2V8blOgREyoaVghvZfT%252bwBCsvLrJaoZU1hhc%252bfwN9GFLCEQHlT%252fj192OzANrTFWVOdssiS7foHlmzR51t0toaTEhlFGCmLVp1DXHnfUUI3NyPYHQZKN0i8tTB6hkdM43sgw9lIzeHhUdJNxG%252bxeYyC981nsbOfTo3xVyHdKIbi0Y%252bvGLvJ9PR4jTiRkKcO3zQ6ftssz7JDUgSAWTYswnC8NBrFDyOPSCZa6SSVHSDP3mHhj7FbbbECwL8xLQPLji6gHrjdglerHN4Rakr1GRKroclvFb7rJh8ovdsmRQyoshSdhjTnoOIdYmb9PeJTxH0My5DQZSZBUFDAi4gZNuXHe7tSM8CxJFrFWUydlHj1tmotwjDekpsp8TnXzA1EiAjJ67TbWIMV66t83pZtOr5AkHj7yv79ZbTGw4XH8CQ0woU7YQ4bFEWzplwdWpiMPDAZ7h00NrWpHaOHuvE4vwtAXpRvGOtp6fS9AGt2fRMeQ3XTHOqprLprt5gBi5iUlV0u8kxlu7sr7JhDlX2jftKJ%252bwcXR1HIG19pNlFQ0qklifkONovD8rm3H919Tjus%252foXPDEyrGL3yDuAZ8KCW32HxzSaespvzKofX2bfTus4xlx3FJMccKJqqfIL32jxueBsuIIIEB1z6NDQYzB%252bZayuEZKvmqwnMYg2oUR24lOaZ%252fZOIIvQq8uRKZVuTuIrMgzCmvIMPa5UWtNEiqrmZ%252f66DJMTekn0stjGZRGZF2iCwplh0FmkGgOlbeBlPUqExKR2sPe106jqt6g2T9aZynppkMSDLOI5CDHmhv12w2xy92A7wcKVjk1kdTfx1oIA3rbAFt%252fOltAjuWQAwb%252fcuaEOSqRNPj1r3DsQVznVbz%252bDcAVzpYy08t%252fpa%252bwonbdxiJBlXCkv1ilIxnG0xUE5CNBoCkxolWDOUqyv%252fY3jJ%252fKUyEJxMclAkyS2tsEFuC3Com%252b9QUlqeBuIXYhD3cl8wKbKZ8h%252b4SFgE%252fx3aRxd7htBX7JPsooeIQTszYlHYs2I%253d%3B+expires%3DSat%2C+25+Apr+2026+08%3A53%3A09+GMT%3B+path%3D%2F%3B+SameSite%3DNone%3B+secure%3B+httponly&amp;amp;urlsrc=Body&amp;amp;msgdata=" target="_blank" rel="noopener"&gt;Microsoft Identity Manager licensing and downloads | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;SP3 introduces a&amp;nbsp;new upgrade process. Please follow the documented steps carefully:&amp;nbsp;&lt;A href="https://outlook.office.com/mail/safelink.html?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fmicrosoft-identity-manager%2Fmicrosoft-identity-manager-2016-upgrade-from-service-pack-2-to-service-pack-3&amp;amp;locale=en-GB&amp;amp;wau=https%3A%2F%2FNAM06.safelinks.protection.outlook.com%2FGetUrlReputation&amp;amp;wid=00730A1A-3310-48BA-AB07-9EC288151649&amp;amp;corid=7f31feba-b8f1-f7f5-b46a-4c1837cf01b5&amp;amp;srcid=&amp;amp;appname=Microsoft+Outlook+Web+App&amp;amp;appver=20260421013.02&amp;amp;os=Windows+11&amp;amp;scdt=&amp;amp;pc=7%252fv%252bt5EOVYXu109FvnxFD%252fwR7Qvhy9uHtEa0WV1bs9Ah51LkVFh39W%252fhDcAY%252fRfPmEAUDf7Bv2s7Y4VIICkWP39fY7IUsbFe1a7Uj5VgGuV8vtuRtkKfapn2fLPCcm81Ib3cClE1cmYlI95mXpW7FxH2QG9bcfLYmR9z8pec56TAUjSlvbchBZFVrq7HEpERaTLfeJKeM4eJnjG5B2ZI0xNdniZTeyUsvJuYlIesFZpnoELN7SRt9%252fXPRk7rgQ%252bo3Sq2DKU7Tdjvr40SX0bnLeYms1zMsR72N92hJLYh1zHxfzgig1HcmHkYJ8C9e7ux7EWTCf5U72JljmUwCJj7ZSaRilLFGsAeZb8sY7XamjQ45CBpC0eAvUuYrNdQmJ9a5TzzUNG1vgFJQFMFqdmMcHoLl%252bV%252fh4e1Q2DfxUrSLp5TDO2V8blOgREyoaVghvZfT%252bwBCsvLrJaoZU1hhc%252bfwN9GFLCEQHlT%252fj192OzANrTFWVOdssiS7foHlmzR51t0toaTEhlFGCmLVp1DXHnfUUI3NyPYHQZKN0i8tTB6hkdM43sgw9lIzeHhUdJNxG%252bxeYyC981nsbOfTo3xVyHdKIbi0Y%252bvGLvJ9PR4jTiRkKcO3zQ6ftssz7JDUgSAWTYswnC8NBrFDyOPSCZa6SSVHSDP3mHhj7FbbbECwL8xLQPLji6gHrjdglerHN4Rakr1GRKroclvFb7rJh8ovdsmRQyoshSdhjTnoOIdYmb9PeJTxH0My5DQZSZBUFDAi4gZNuXHe7tSM8CxJFrFWUydlHj1tmotwjDekpsp8TnXzA1EiAjJ67TbWIMV66t83pZtOr5AkHj7yv79ZbTGw4XH8CQ0woU7YQ4bFEWzplwdWpiMPDAZ7h00NrWpHaOHuvE4vwtAXpRvGOtp6fS9AGt2fRMeQ3XTHOqprLprt5gBi5iUlV0u8kxlu7sr7JhDlX2jftKJ%252bwcXR1HIG19pNlFQ0qklifkONovD8rm3H919Tjus%252foXPDEyrGL3yDuAZ8KCW32HxzSaespvzKofX2bfTus4xlx3FJMccKJqqfIL32jxueBsuIIIEB1z6NDQYzB%252bZayuEZKvmqwnMYg2oUR24lOaZ%252fZOIIvQq8uRKZVuTuIrMgzCmvIMPa5UWtNEiqrmZ%252f66DJMTekn0stjGZRGZF2iCwplh0FmkGgOlbeBlPUqExKR2sPe106jqt6g2T9aZynppkMSDLOI5CDHmhv12w2xy92A7wcKVjk1kdTfx1oIA3rbAFt%252fOltAjuWQAwb%252fcuaEOSqRNPj1r3DsQVznVbz%252bDcAVzpYy08t%252fpa%252bwonbdxiJBlXCkv1ilIxnG0xUE5CNBoCkxolWDOUqyv%252fY3jJ%252fKUyEJxMclAkyS2tsEFuC3Com%252b9QUlqeBuIXYhD3cl8wKbKZ8h%252b4SFgE%252fx3aRxd7htBX7JPsooeIQTszYlHYs2I%253d%3B+expires%3DSat%2C+25+Apr+2026+08%3A53%3A09+GMT%3B+path%3D%2F%3B+SameSite%3DNone%3B+secure%3B+httponly&amp;amp;urlsrc=Body&amp;amp;msgdata=" target="_blank" rel="noopener"&gt;Upgrade Microsoft Identity Manager 2016 from SP2 to SP3 | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Operational recommendation: Validate SP3 in a non-production environment first, then roll it out to your production environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Support lifecycle&lt;/H2&gt;
&lt;P&gt;MIM 2016 SP2 will remain supported for 12 months (through May 2027), in line with the service pack support lifecycle policy. Customers should plan to upgrade from SP2 to SP3 within that window. For details, see: &lt;A href="https://outlook.office.com/mail/safelink.html?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Flifecycle%2Fpolicies%2Ffixed&amp;amp;locale=en-GB&amp;amp;wau=https%3A%2F%2FNAM06.safelinks.protection.outlook.com%2FGetUrlReputation&amp;amp;wid=00730A1A-3310-48BA-AB07-9EC288151649&amp;amp;corid=4b1f8d0c-1e37-14bc-eb62-221250febb59&amp;amp;srcid=&amp;amp;appname=Microsoft+Outlook+Web+App&amp;amp;appver=20260421013.02&amp;amp;os=Windows+11&amp;amp;scdt=&amp;amp;pc=7%252fv%252bt5EOVYXu109FvnxFD%252fwR7Qvhy9uHtEa0WV1bs9Ah51LkVFh39W%252fhDcAY%252fRfPmEAUDf7Bv2s7Y4VIICkWP39fY7IUsbFe1a7Uj5VgGuV8vtuRtkKfapn2fLPCcm81Ib3cClE1cmYlI95mXpW7FxH2QG9bcfLYmR9z8pec56TAUjSlvbchBZFVrq7HEpERaTLfeJKeM4eJnjG5B2ZI0xNdniZTeyUsvJuYlIesFZpnoELN7SRt9%252fXPRk7rgQ%252bo3Sq2DKU7Tdjvr40SX0bnLeYms1zMsR72N92hJLYh1zHxfzgig1HcmHkYJ8C9e7ux7EWTCf5U72JljmUwCJj7ZSaRilLFGsAeZb8sY7XamjQ45CBpC0eAvUuYrNdQmJ9a5TzzUNG1vgFJQFMFqdmMcHoLl%252bV%252fh4e1Q2DfxUrSLp5TDO2V8blOgREyoaVghvZfT%252bwBCsvLrJaoZU1hhc%252bfwN9GFLCEQHlT%252fj192OzANrTFWVOdssiS7foHlmzR51t0toaTEhlFGCmLVp1DXHnfUUI3NyPYHQZKN0i8tTB6hkdM43sgw9lIzeHhUdJNxG%252bxeYyC981nsbOfTo3xVyHdKIbi0Y%252bvGLvJ9PR4jTiRkKcO3zQ6ftssz7JDUgSAWTYswnC8NBrFDyOPSCZa6SSVHSDP3mHhj7FbbbECwL8xLQPLji6gHrjdglerHN4Rakr1GRKroclvFb7rJh8ovdsmRQyoshSdhjTnoOIdYmb9PeJTxH0My5DQZSZBUFDAi4gZNuXHe7tSM8CxJFrFWUydlHj1tmotwjDekpsp8TnXzA1EiAjJ67TbWIMV66t83pZtOr5AkHj7yv79ZbTGw4XH8CQ0woU7YQ4bFEWzplwdWpiMPDAZ7h00NrWpHaOHuvE4vwtAXpRvGOtp6fS9AGt2fRMeQ3XTHOqprLprt5gBi5iUlV0u8kxlu7sr7JhDlX2jftKJ%252bwcXR1HIG19pNlFQ0qklifkONovD8rm3H919Tjus%252foXPDEyrGL3yDuAZ8KCW32HxzSaespvzKofX2bfTus4xlx3FJMccKJqqfIL32jxueBsuIIIEB1z6NDQYzB%252bZayuEZKvmqwnMYg2oUR24lOaZ%252fZOIIvQq8uRKZVuTuIrMgzCmvIMPa5UWtNEiqrmZ%252f66DJMTekn0stjGZRGZF2iCwplh0FmkGgOlbeBlPUqExKR2sPe106jqt6g2T9aZynppkMSDLOI5CDHmhv12w2xy92A7wcKVjk1kdTfx1oIA3rbAFt%252fOltAjuWQAwb%252fcuaEOSqRNPj1r3DsQVznVbz%252bDcAVzpYy08t%252fpa%252bwonbdxiJBlXCkv1ilIxnG0xUE5CNBoCkxolWDOUqyv%252fY3jJ%252fKUyEJxMclAkyS2tsEFuC3Com%252b9QUlqeBuIXYhD3cl8wKbKZ8h%252b4SFgE%252fx3aRxd7htBX7JPsooeIQTszYlHYs2I%253d%3B+expires%3DSat%2C+25+Apr+2026+08%3A53%3A09+GMT%3B+path%3D%2F%3B+SameSite%3DNone%3B+secure%3B+httponly&amp;amp;urlsrc=Body&amp;amp;msgdata=" target="_blank" rel="noopener"&gt;Fixed Lifecycle Policy | Microsoft Learn&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MIM 2016 remains supported through January 9, 2029, under Microsoft’s Fixed Lifecycle Policy. While MIM continues to support critical identity scenarios, Microsoft is actively investing in Microsoft Entra as the long-term platform for identity governance and lifecycle management. We recognize that some MIM use cases require a phased or hybrid approach, and we are working closely with customers to support these transitions.&lt;/P&gt;
&lt;P&gt;Questions about upgrading to SP3 or planning your longer-term identity strategy? Contact your Microsoft account team or support contact to review your environment, timelines, and transition path.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ben Mann&lt;/STRONG&gt;, Group Product Manager&lt;BR /&gt;&amp;nbsp;Microsoft Entra&lt;/P&gt;
&lt;P&gt;Africa Development Center (ADC)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Additional resources&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;About MIM 2016 - &lt;A href="https://learn.microsoft.com/en-us/microsoft-identity-manager/microsoft-identity-manager-2016" target="_blank" rel="noopener"&gt;Microsoft Identity Manager | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Migrate from MIM to Entra ID - &lt;A href="https://learn.microsoft.com/en-us/microsoft-identity-manager/migrate-entra-id" target="_blank" rel="noopener"&gt;Migrating to Microsoft Entra ID from Microsoft Identity Manager | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Learn more about Microsoft Entra &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;⁠&lt;A href="https://www.microsoft.com/en-us/security/blog/products/microsoft-entra/" target="_blank" rel="noopener"&gt;Microsoft Entra News and Insights | Microsoft Security Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/blog/microsoft-entra-blog" target="_blank" rel="noopener"&gt;Microsoft Entra blog | Tech Community&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/" target="_blank" rel="noopener"&gt;Microsoft Entra documentation | Microsoft Learn&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/category/microsoft-entra/discussions/microsoft-entra" target="_blank" rel="noopener"&gt;Microsoft Entra discussions | Microsoft Community&amp;nbsp;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 14 May 2026 17:30:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-entra-blog/microsoft-identity-manager-2016-sp3-now-available-enhanced/ba-p/4519489</guid>
      <dc:creator>benmann</dc:creator>
      <dc:date>2026-05-14T17:30:53Z</dc:date>
    </item>
  </channel>
</rss>

