👋 Hi, Merill and Joshua here with this week’s roundup of the latest news on Microsoft Entra from around the globe 🌍.
There’s a LOT happening with Entra this week, with passkeys being the biggest topic now that we’re past 1 September. We also have more clarity from Microsoft, with new updates to the docs on Microsoft Learn walking through the changes and what to expect.
Plus, our Entra MVPs do some deep dives and provide practical guidance on these changes and what to do.
If you are looking for inspiration for your passkey rollout, check out this week’s timely Entra Chat podcast episode with Andrew Cameron, Distinguished Identity Engineer at General Motors, who graciously shared their learnings as they roll out passkeys to nearly 200,000 GM staff.
How General Motors Moved 200,000 People to Passkeys
Microsoft starts making passkeys the default in Microsoft Entra ID on 1 September 2026, and retires Microsoft-provided SMS and voice MFA on 1 February 2027. Every organisation with a large, messy population now has to answer a question that has nothing to do with passkey technology itself: how do you move a hundred thousand real people - office workers,…
BTW, I’ll be at the Hybrid Identity Protection conference in Nashville this week, and I’m looking forward to catching up with many folks from the Entra community, hanging out, and talking about Entra, AI and Maester. Hopefully, I’ll record a few podcasts too.
Merill
Sponsored by:
Is Each App in Entra ID Still Worth Governing?
App registrations and enterprise applications accumulate. Owners change. Projects and pilots end. Credentials linger. And stale or unused apps and their permissions can continue adding risk and governance overhead long after their purpose is gone.
ENow App Governance Accelerator helps you understand what’s in your Entra ID application estate, who owns it, which apps, permissions, and credentials need attention, and what can safely be cleaned up to reduce your attack surface on a continuous basis as your tenant grows and changes.
Get visibility and automated workflows to investigate application lifecycles at scale, reduce stale apps, and spend less time governing applications that no longer need to be there.
⚡️ Microsoft
🏆 General Availability
What’s new in Microsoft Entra: September 2026 • Yina Arenas
Microsoft Entra Tenant Governance
Improve access governance with User-centric Access Reviews (UAR)
Create workflows by cloning an existing workflow in Lifecycle Workflows
Microsoft Entra Resource Accounts for Teams Devices
🏁 Public Preview
What’s new in Microsoft Entra: September 2026 • Yina Arenas
Synchronize sAMAccountName with Microsoft Entra Domain Services
Manage identity lifecycle from the cloud with Microsoft Entra Cloud Sync
Microsoft Entra Global Secure Access MCP Firewall
Change announcements
Enhancements to Security Administrator role
Replace MemberOf-Based Configurations by November 3, 2026
Permission scope update for User.ReadBasic.All
🗣️ Message Center
MC1440968 - Microsoft Entra ID: Optimizations for passkey registration experience
MC1423108 - Microsoft Entra: Improved restore experience for Authenticator passkeys on iOS
MC1438571 - Default visibility of additional profile card properties in Microsoft 365 profile cards
RM568784 - Microsoft Defender for Identity: Unified identity timeline on the Identity page
📕 Microsoft Learn Docs
Run a registration campaign to set up a passkey or Microsoft Authenticator - Updated
Major doc update on 5 Sep: The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
📆 Upcoming Events
📺 Live AMA: Secure multi-tenant environments with Microsoft Entra Tenant Governance • Microsoft Community Learning
From the community…
🚀 Most popular posts from last week
🥇 Microsoft accidentally created a new “All Company” group in Entra ID • Tobias Asböck
🥈 Agent 365 settings explained • Derk van der Woude
🥉 Entra ID P2 for SMBs: Is it Worth It and Which License to choose? • Gannon Novak
Sponsored by:
Maester Cloud turns every Maester and Microsoft Zero Trust Assessment run into a durable evidence trail. See new failures, fixes, accepted risks, and posture changes across every tenant - without digging through old HTML reports.
Keep 5+ years of tenant history in your chosen Azure region
Compare runs, spot drift, and get change alerts
Self-hosted private preview now available at $99/month! Helps fund open-source Maester development, shape the roadmap.
☀️ Learn
👩✈️ AI & Copilot
The magic of Agent Identities in Microsoft Entra • Gabe Corsini
🎁 Apps
Introducing Entra Extensions Manager: A Better Way to Manage Custom Extensions • Sebastian Flaeng Markdanner
🧰 Workload ID
Revoking Access Tokens for Risky Service Principals • Tony Redmond
Running a Regular Check for New Graph Permissions • Tony Redmond
NHI? Never Heard of Him — The Service Principal Sitting in Your Tenant • Jonathan Hope
👮♂️ ID Governance
Securing Microsoft Entra Guest Access: Lifecycle Management with Access Packages and Access Reviews • Oliver Mueller
Your governance model is probably built around the wrong thing • Sandra Saluti
When a Manager Isn’t an Attribute • Sandra Saluti
🌐 Private Access & Internet Access (GSA)
Entra Private Network Connector Session Persistence • Richard M. Hicks
Entra Global Secure Access (GSA) Client Intune Deployment PowerShell Script • Richard M. Hicks
Authentication
Passkey as first MFA method: What could go wrong? • Per-Torben Sorensen
How General Motors Moved 200,000 People to Passkeys • Merill Fernando
📺 Your SSPR Is About To Stop Working • Jonathan Edwards
👥 User & Group Management
Need More User Attributes in Entra ID? Here Are Your Options • Klaus Bierschenk
🚦 Conditional Access
Missing Service Principals in Entra ID: Why Conditional Access, App Protection and Global Secure Access will fail + more fun • Michael Morten Sonne
🖥️ Devices
How to Block Personal Windows Devices in Microsoft Intune • Mark Oldham
📺 Group Policy Vs Microsoft Intune - Is It Time to Let Go? • Andy Malone
📺 How Attackers Abuse Device Code Flow [How to Stop it] • Ru Campbell
🏙️ External ID - Guests & Multi-Tenant Organizations
How to Resolve External User ID by Email Address and Vice Versa • Martin Heusser
Cross-Tenant Policies To Replace Free/Busy Organization Relationships • Brian Reid
🥷 Security
📺 The Cruellest Phishing Email I’ve Ever Seen! • Andy Malone
♻️ Sync
How to sync user accounts from Entra ID to Active Directory • Daniel Bradley
📒 Tenant Configuration
Teams Clamps Down on MOERA-Only Tenants • Tony Redmond
Microsoft Graph hints at external tenant reporting • Daniel Bradley
Restricting the new Copilot desktop app with Entra ID Tenant Restrictions • Tobias Asböck
🛍️ External ID - Customers
How to run a .http file • Rory Braybrook
Making Email Optional in Microsoft Entra External ID: Why This Matters for Modern CIAM • Colby Pryor
Using the .NET .http file to test native auth with SSPR in Entra External ID (EEID) • Rory Braybrook
Using the .NET .http file to test native auth with email/OTP in Entra External ID (EEID) • Rory Braybrook
🔥 Maester
👨🏽💻 Merill’s corner
Join Mike Soule and me in January 2027 at Workplace Ninjas US for a session on Mastering Maester. 👇
Want to get featured on Entra.News? → Submit your content 😎
Want us to say nice things about your company? Sponsor entra.news 🤩
Love the newsletter? Tell us 💚❤️💜
🪃 Acknowledgement of Country
Entra.News is created on Wurundjeri land and acknowledges the traditional owners of country throughout Australia, recognising their continuing connection to land, water and community. We pay our respect to them and their cultures and to elders both past and present.











