Entra 🆔 News #161 → This week in Microsoft Entra
Learn about Entra passwordless resource account support for Teams Rooms on Windows and Android devices going GA and more
👋 Hi, Merill and Joshua here with this week’s roundup of the latest news on Microsoft Entra from around the globe 🌍.
Lots happening in Entra this week, including the retirement of the memberOf operator for dynamic groups and administrative units, new passkey updates, changes to managed policies, and more.
Also, don’t miss my latest podcast with Andres Canello, where we dive into migrating from existing VPN and SSE solutions to Microsoft Entra Global Secure Access.
The Ultimate Microsoft Entra Global Secure Access Migration Guide
An Entra GSA migration should not mean throwing away years of useful SSE policy work and rebuilding every application, segment, and rule by hand.
Enjoy!
Sponsored by:
88% say AI has outrun their identity stack
AI agents are already making production API calls, running workflows, and touching sensitive data. Your written policies can’t regulate what a machine does at runtime or prove its actions.
FusionAuth’s 2026 State of AI and Identity Report surveyed over 300 technology leaders on the gap:
88% say AI adoption has outrun their identity and security readiness
The more confident a team is in its AI posture, the more likely it’s had a confirmed incident
Multi-tenant SaaS identity environments report far higher incident rates than isolated or self-hosted deployments
In an AI world, your deployment model is a security decision. Get the data.
⚡️ Microsoft
🏆 General Availability
🔥 Public Preview
Token Protection deployment guide - Web apps (Preview) • Microsoft Learn
Analyze provisioning logs with Microsoft MCP Server for Enterprise (Preview) • Microsoft Learn
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps • Ron Pessner
📖 Read
🗣️ Message Center
Sponsored by:
What’s been left exposed in your Microsoft 365 tenant?
The devices Defender never picked up, the dead Teams and SharePoint sites, the forgotten Entra apps, the shared mailboxes nobody owns. None of it looks urgent. All of it is exposure: standing access, unprotected devices, and data nobody is watching. Inspect 365 finds it, prioritizes what matters, and tracks each one from review to resolved.
Continuous Microsoft 365 tenant hygiene, built to find and address security risks:
Small enough to do. Prioritized by impact, so you start with the few that matter, not the whole list.
Documented as you go. Every decision recorded with its note.
Provable after. What got resolved, what got accepted and why, whether you bill for the work or answer for it.
Connect a tenant in minutes and see what’s exposed in yours.
From the community…
🚀 Most popular posts from last week
🥇 Conditional Access Visualizer & Deployer Tool • Joey Verlinden
🥈 Conditional Access Framework (2026.6.1) • Joey Verlinden
🥉 Why Intune Devices Became Noncompliant After the July Windows Update • Rudy Ooms
☀️ Learn
👩✈️ AI & Copilot
Manage your AI Agents at Scale with Entra Agent ID • Brian Veldman
🧰 Workload ID
Bypassing the IMDS cache • Jos Lieben
📺 No more passwords: The future is now! • Ben Reader
⛑️ ID Protection
User Risk with Unified Identity Signals from Defender is here! • Michael Morten Sonne
👮♂️ ID Governance
No Guest? No Problem: Direct External Assignments in Microsoft Entra • Colby Pryor
Updated ECMA2Host Tools with Entra Application Provisioning Job Management • Darren Robinson
🌐 Private Access & Internet Access (GSA)
New Entra ID Private Connector version • Benoit HAMET
📦 Apps
Authentication
Microsoft Entra Just Made Passwordless MFA Registration Easier • Daniel Bradley
System-Preferred Authentication and September 1st Passkey Change • Shehan Perera
Windows Hello for Business (WHfB) in Practice • Marco Wohler
📺 Microsoft Is Killing SMS MFA • Jonathan Edwards
📺 Why Your Passkeys Deployment Fails [5 Major Pitfalls] • Ru Campbell
👥 User & Group Management
Access Microsoft Entra Group Insights with Group Analytics API • Blesslin Rinu
Entra ID Enables Blocking for Nested Security Groups • Tony Redmond
Entra ID Drops the memberOf Rule Operator for Dynamic Groups and Dynamic Admin Units • Tony Redmond
Microsoft Entra Retires the MemberOf Rule Operator for Dynamic Membership Rules • Kanaga
Microsoft Entra ID Is Retiring the MemberOf Rule for Dynamic Groups • Rudy Mens
The memberOf rule operator is ending for dynamic Groups in Entra • Daniel Bradley
Replacing MemberOf in Entra after it is deprecated • Jos Lieben
🚦 Conditional Access
CA Baseline changes affecting Citrix Authentication • Julian Jakob
How to Set Up Microsoft Entra Terms of Use • Mark Oldham
📺 MFA vs Conditional Access | They’re Not the Same Thing! • Travis Roberts
📺 Microsoft Entra Terms of Use Require Acceptance Before Microsoft 365 Access • Mark Oldham
🖥️ Devices
Hide the AVD SSO Consent Prompt • Flavio Meyer
Strengthening Endpoint Security with Device Lock Policies in Microsoft Intune • Nicky De Westelinck
Entra Cloud Sync now allows Active Directory devices synchronization • Benoit HAMET
📺 Entra Join vs Hybrid Join vs Registered FINALLY Explained! • Andy Malone
🏙️ External ID - Guests & Multi-Tenant Organizations
🥷 Security
Borrowing Windows Hello keys for authentication and persistence • Dirk-jan Mollema
Audit your entra permissions with LeastPrivilegedEntra • Morten Mynster
Pass-the-Passkey v2.pdf • Michael Grafnetter
♻️ Sync
📒 Tenant Configuration
📺 Microsoft Entra Identity Architecture – Why Identity Is Your Most Important Security Decision • Shabaz Darr
🛍️ External ID - Customers
Using OIDC federation via native auth in Entra External ID (EEID) • Rory Braybrook
Using social federation via native auth in Entra External ID (EEID) • Rory Braybrook
👨🏽💻 Merill’s corner
Want to get featured on Entra.News? → Submit your content 😎
Want us to say nice things about your company? Sponsor entra.news 🤩
Love the newsletter? Tell us 💚❤️💜
🪃 Acknowledgement of Country
Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.









