👋 Hi, Merill and Joshua here with this week’s roundup of the latest news on Microsoft Entra from around the globe 🌍.
We are light on posts from Microsoft but there are a few interesting Message Center posts on passkeys. Microsoft finally confirming passkey support for guests, as well as WHfB and Platform SSO for macOS to be recognized as stand-alone MFA from October 2026.
We also learnt about a severe Entra ID flaw (CVSS 10.0) that allowed remote code execution. Microsoft has already fixed it and there is nothing for you to do. It was not exploited, and it was found by one of their own engineers.
Don’t forget to check out this week’s Entra.Chat podcast. The demos that Michael Grafnetter showed made me do a double take. Must watch for any Entra admin.
Pass-the-Passkey: What Michael Grafnetter's Black Hat Research Means for Entra Admins
Passkeys are phishing-resistant. But that resistance is enforced by your browser, which binds every authentication to the origin that requested it. Skip the browser, and the guarantee weakens.
Enjoy!
Sponsored by:
Know Every AI Agent in Your Tenant? Neither Does
Copilot Studio mints a new Entra agent identity every time someone builds an agent. Each one is a live service principal: its own credentials, its own reach into your systems. Entra creates them fast. Nobody’s watching what happens next.
Oasis Platform is.
Every agent discovered and owned, the full picture. No spreadsheet archaeology
Secrets rotated automatically, without breaking production
Stale agents recertified and retired with confidence
⚡️ Microsoft
🗣️ Message Center
MC1459133 - Microsoft Entra ID: Passkey support for B2B users
MC1303719 - Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings
From the community…
🚀 Most popular posts from last week
🥇 Secret’s out: How to replace client secrets with Azure managed identity • Sep Behesti
🥈 Microsoft is Tracking your Entra ID License Usage – Are You Compliant? • Rudy Mens
🥉 Entra Admin Center Flags Licensing Problems with Conditional Access • Tony Redmond
Sponsored by:
Webinar: From App Sprawl to Control in Entra ID
Wednesday, August 26 at 3 pm ET | Register
Entra ID app sprawl happens when nobody owns the process after approval. App registrations, service principals, and integrations pile up, and questions about ownership, permissions, credentials, and usage go unanswered until nobody’s confident enough to remove them.
Hosted by ENow, Microsoft MVPs Nicolas Blank and Alistair Pugin welcome guest Merill Fernando for a practical look at governing apps starting from onboarding through their full lifecycle. You’ll learn:
What application onboarding should establish
How to assign real ownership (technical and business)
Where app lifecycle gaps create risk
How to govern credentials and access over time
Which Entra ID controls help, where gaps remain, and what to do about it
☀️ Learn
👩✈️ AI & Copilot
Identity Risk Management Agent | Security Copilot • Michael Frank
🧰 Workload ID
Logic Managed Identity works – Retire the workaround! • Chris Bradshaw
Configuring Microsoft Entra ID Authentication for Azure SQL Database using Azure Bicep • Brian Veldman
👮♂️ ID Governance
🌐 Private Access & Internet Access (GSA)
Private DNS Hygiene in GSA — Suffixes, Segments, and the Order Things Resolve In • Christopher Brumm
🎙️ Renewing our understanding of Microsoft Global Secure Access | Ctrl+Alt+Azure • Jussi Roine and Tobias Zimmergren
📦 Apps
Microsoft Graph’s Move Toward More Granular API Permissions • AIMA
📺 Microsoft Entra ID and SSO explained minimum required knowledge • Cobuman
Authentication
Pass-the-Passkey: What Michael Grafnetter’s Black Hat Research Means for Entra Admins • Merill Fernando
How to create a Microsoft 365 device-bound passkey on macOS • Jan Bakker
📺 How to Handle Entra Passkey & SMS Changes [5 Critical FAQs] • Ru Campbell
👥 User & Group Management
Stop agent users joining Microsoft Entra dynamic groups • Daniel Bradley
Microsoft Entra agent users can join your dynamic groups. Here is what to check • Merill Fernando
Microsoft Entra memberOf Retirement: 2026 Checklist • Driek Desmet
🤖 DevOps & PowerShell
Use of AZURE_TOKEN_CREDENTIALS in Azure.Identity • Jaliya Udagedara
Connect to Microsoft Graph, Teams and Exchange with PowerShell Simultaneously • Martin Heusser
🚦 Conditional Access
🏙️ External ID - Guests & Multi-Tenant Organizations
Microsoft Entra brings passkeys to B2B guest users • Daniel Bradley
🥷 Security
Microsoft quietly expands the Entra Application Developer role • Daniel Bradley
Microsoft adds user actions to the Security Administrator role • Daniel Bradley
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution • The Hacker News
📺 Check Your Customers’ Entra ID Tenants with Maester - Constantin Hager - PSConfEU 2026 • Constantin Hager
📒 Tenant Configuration
Microsoft says use Tenant Restrictions to block personal Copilot access. I have questions. • Adam Fowler
🛍️ External ID - Customers
Integrating Entra External ID (EEID) with a third-party MFA provider, e.g. Authsignal • Rory Braybrook
🔥 Maester
👨🏽💻 Merill’s corner
Want to get featured on Entra.News? → Submit your content 😎
Want us to say nice things about your company? Sponsor entra.news 🤩
Love the newsletter? Tell us 💚❤️💜
🪃 Acknowledgement of Country
Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.








