‹ Back to list
Stay InformedCC00174

Microsoft Entra: May 2026

Services: Microsoft Entra ID· Published: 2026-05-01· MS modified: 2026-05-01· View source ↗
What's new

Microsoft announcement

Public Preview - Enable soft-delete for Microsoft Entra Device objects

Type: New feature
Service category: Device Access Management
Product capability: Entra Backup and Recovery

Device Soft Delete, now available in preview, enables administrators to safely remove device objects by moving them to a recoverable state instead of permanently deleting them. This feature allows organizations to restore devices within a defined retention period while preserving critical data such as device identity and associated security artifacts. The feature supports Microsoft Entra joined, registered, and hybrid joined devices and helps reduce risk from accidental deletions while improving device lifecycle management.


General Availability - NetBiosName resolution test now informational

Type: Changed feature
Service category: Entra Connect
Product capability: Entra Connect

The “NetBIOS Name Sysvol Connectivity resolution” test in the AD DS health monitoring agent has been reclassified from an alerting test to an informational test. Going forward, if this test fails, it will no longer generate an alert or require remediation action on your part. Instead, the test runs in the background and logs results for your information only.

What Changed

The NetBIOS Name Sysvol Connectivity test is now informational-only. Previously, when this test failed (e.g. if a domain controller couldn’t resolve the NetBIOS name to access its SYSVOL share), an alert was triggered in Connect Health, prompting you for action. Now, failures in this test will not raise an alert in Microsoft Entra Connect Health.

Why We Made This Change

NetBIOS is a legacy networking protocol that is not critical in modern Active Directory environments. Many organizations no longer rely on NetBIOS name resolution in day-to-day operations. Reclassifying this test as informational reduces noise in your alert feed and allows you to focus on issues that are genuinely critical to your identity infrastructure. In short, we want to ensure that Connect Health alerts highlight meaningful issues and help you prioritize real problems, rather than flagging non-essential conditions.


Upcoming change - Enhanced admin authorization for Microsoft Entra Connect Sync configuration changes

Type: Changed feature
Service category: Entra Connect
Product capability: Entra Connect

We're enhancing the security posture of Microsoft Entra Connect Sync by introducing interactive admin authorization for configuration changes. With this update, an authorized administrator will need to sign in and explicitly approve changes to sync settings, ensuring that configuration updates are intentional and made by the right person.

What’s changing

  • Interactive admin authorization for sync configuration changes: Going forward, changes to sync configuration settings – such as enabling or disabling features – will require interactive authentication from an authorized cloud administrator. Whether you're using the Entra Connect wizard or PowerShell, a verified admin sign-in will be required to complete the action. This strengthens the authorization model for all sync-related configuration changes.

  • Greater consistency in admin-driven configuration: We are aligning sync behavior so that configuration decisions made by cloud administrators are consistently respected. The cloud will serve as the source of truth for sync feature state, giving administrators greater confidence that their intended configuration is maintained.

  • Updated management paths: All management interfaces for Entra Connect will incorporate delegated admin authentication where needed. Specifically:

  • Entra Connect wizard flows: The installation and configuration wizard will use delegated admin tokens for sync configuration changes, providing a more secure authorization flow.

  • PowerShell cmdlets: PowerShell-based management of sync settings will now prompt for an interactive admin sign-in to complete configuration changes. Ensure you run these commands in a session where you can provide admin credentials.

  • Uninstall behavior: If you uninstall Entra Connect Sync and choose to make cloud-side changes such as converting the tenant to cloud-only synchronization, the uninstall process will require admin authentication before modifying settings in the cloud tenant.

What’s not changing

  • Sync functionality and the end-user experience remain unchanged. Everything continues to work as expected when features are enabled or disabled.
  • There is no change to how administrators choose to enable or disable sync features; only that these actions now require interactive authentication.

The Microsoft Entra Connect Sync .msi installation file for this change is exclusively available on Microsoft Entra admin center under Microsoft Entra Connect.

Check our version history page for more details on available versions.


Public Preview - Workload identity-based authentication for SAP SuccessFactors provisioning integrations

Type: New feature
Service category: Provisioning
Product capability: Inbound to Entra ID

Microsoft Entra is introducing workload identity–based authentication for SAP SuccessFactors provisioning. This new capability allows the Microsoft Entra provisioning service to authenticate to SAP SuccessFactors using Entra workload identity and short‑lived tokens instead of static credentials (username and password). 

This change helps customers transition to a more secure authentication model in preparation for SAP’s plan to deprecate basic authentication for SuccessFactors APIs by November 2026

What’s changing 

What this means for you 

  • If you are currently using basic authentication for any of the above SAP SuccessFactors provisioning integrations, you must upgrade to workload identity-based authentication before November 2026 to ensure uninterrupted operation of the integrations. 
  • No immediate action is required, but we recommend planning your migration early to avoid last-minute disruption.  The new method improves security by:  
  • Eliminating stored passwords 
  • Using short-lived, verifiable tokens 
  • Aligning with SAP’s supported authentication model 

Recommended action 

  • Evaluate the new authentication option once available in your tenant 
  • Plan and test migration of existing provisioning jobs to workload identity-based authentication 
  • Update any internal documentation or operational processes that reference basic authentication 

Additional information 

For detailed configuration guidance and step-by-step instructions visit https://aka.ms/EntraSAPSFConnectivityGuide.


Public Preview - Sensitivity labels for Microsoft Entra security groups

Type: New feature
Service category: Group Management
Product capability: Platform

Microsoft Entra ID now supports applying Microsoft Purview sensitivity labels to Entra cloud security groups in public preview.

Administrators can use labels to govern security group settings such as guest access using the same labels and policies that apply to Microsoft 365 groups today.

Labels can be managed in Microsoft Purview and applied through the Microsoft Entra Admin Center, Azure portal, and Microsoft Graph. For more information, see: Assign sensitivity labels to Microsoft Entra security groups (preview).


General Availability - Account Discovery

Type: General Availability
Service category: Provisioning
Product capability: 3rd Party Integration

Account discovery for connected applications is now generally available in Microsoft Entra ID Governance. This capability provides administrators with visibility into all accounts that exist within connected applications, including orphan accounts.

By generating discovery reports directly from the provisioning experience, organizations can identify accounts in connected applications that aren't assigned to the enterprise application in Microsoft Entra and simplify onboarding the application.

This capability requires a Microsoft Entra ID Governance or Microsoft Entra Suite license. Learn more: https://aka.ms/accountDiscoveryDocumentation.


General Availability - Cross tenant group synchronization

Type: General Availability
Service category: Provisioning
Product capability: Identity Lifecycle Management

Cross tenant group synchronization allows organizations to synchronize security groups across Microsoft Entra tenants. This feature enables centralized management of group membership in a source tenant while making those groups available in one or more target tenants, simplifying cross-tenant collaboration and reducing administrative overhead associated with managing duplicate groups.

With cross tenant group synchronization, organizations can extend their existing cross tenant synchronization configurations to include groups, supporting scenarios such as shared application access, resource authorization, and consistent group-based access control across tenants. Admins can opt in to this functionality and configure attribute mappings and cross tenant access policies to enable group synchronization into target tenants. Use of cross-tenant group synchronization requires Microsoft Entra ID Governance licenses. Existing licensing requirements for cross tenant user synchronization features remains unchanged. https://learn.microsoft.com/entra/identity/multi-tenant-organizations/cross-tenant-synchronization-overview.


General Availability - Modernized My Account pages

Type: Changed feature
Service category: Modernized My Account pages
Product capability: End User Experiences

We're excited to announce the upcoming general availability of three redesigned pages in the My Account portal (myaccount.microsoft.com), bringing a modernized experience to help end users manage their account with greater ease and clarity.

The redesigned Devices page features a modernized layout that makes it easier for users to view and manage their registered devices. BitLocker recovery keys are now more prominently surfaced, reducing the need to contact IT helpdesk for key retrieval.

The new Personal Info page gives users a centralized view of their profile information alongside language and region settings - making it simple to review and update personal details in one place.

The redesigned Organizations page delivers a modernized experience and resolves a longstanding issue where users were unable to successfully leave an organization.

Availability: These pages will be generally available to all Microsoft Entra ID customers by end of June 2026. No admin action is required - users will see the updated experience automatically.


General Availability - Support for passkeys in Microsoft Entra ID registration campaign

Type: General Availability
Service category: MFA
Product capability: Identity Security & Protection

Microsoft Registration Campaigns now supports Passkeys (FIDO2) as an authentication method. Administrators can configure registration campaigns to nudge users to register passkeys during sign-in, helping organizations drive passkey adoption at scale. This first rollout experience is optimized for users who are in a passkey profile that doesn't have any restrictions.


Public Preview - Automate setting or clearing user attributes values in Lifecycle workflows

Type: New feature
Service category: Lifecycle Workflows
Product capability: Identity Governance

We're excited to introduce the User Attribute Updates task in Lifecycle Workflows, extending existing attribute change trigger capabilities with a built-in, customer-ready way to automate attribute updates (set or clear values) directly within a workflow. With a secure, consistent, and auditable experience, organizations can reduce manual effort, improve governance, and scale identity automation with greater confidence.


General Availability - System-preferred authentication expanded to first-factor in Microsoft Entra ID

Type: General Availability
Service category: MFA
Product capability: Identity Security & Protection

We're extending system-preferred authentication to apply to the first factor in Microsoft-managed configurations (in addition to second factor). With this change, the system evaluates the credentials registered for a user and selects the highest-ranked authentication method for each step of the sign-in flow.

As a result, users with strong, phishing-resistant credentials (such as passkeys) might be signed in without needing to use a password, improving both security and user experience.

This behavior applies only to the Microsoft-managed state, where system-preferred authentication now covers both first- and second-factor authentication. The rollout is currently in progress and will be fully deployed to all Microsoft-managed tenants by the end of June.


General Availability - High Scale Compatibility (HSC) mode for Microsoft Entra External ID

Type: General Availability
Service category: B2C - Consumer Identity Management
Product capability: B2B/B2C

High Scale Compatibility (HSC) mode enables organizations to migrate to Microsoft Entra External ID while preserving their existing user directory. It's designed for large, established customer identity platforms transitioning from Azure AD B2C.

With HSC mode, customers can rebuild applications on External ID while maintaining continuity for existing users, supporting a seamless, phased migration at scale. Some advanced customization capabilities are limited in this mode and will continue to evolve. For more information, see: Enable External ID High Scale Compatibility (HSC) mode.


Expanded policy storage for passkeys (FIDO2) in Microsoft Entra ID

Type: Changed feature
Service category: Authentications (Logins)
Product capability: User Authentication

We increased the passkey (FIDO2) policy size limit in the authentication methods policy to a dedicated 20-KB allocation.

Previously, all authentication methods shared a single 20-KB policy size limit. With this update, a dedicated 20-KB limit is now allocated specifically to the passkey (FIDO2) policy, while the remaining authentication methods continue to use their existing limit.

This change helps address scenarios where tenants approach the overall policy size limit, which can block configuration of passkey profiles. By separating passkey policy storage, organizations can more easily adopt passkeys and configure advanced targeting scenarios.

In addition, the maximum number of passkey profiles per tenant has been increased from 3 to 10.


Public Preview - Azure Role assignments can now be governed via Entitlement Management

Type: New feature
Service category: Entitlement Management
Product capability: Identity Governance

You can now govern eligible and active assignments to Azure roles at the Management Group, Subscription, and Resource Group levels directly through access packages. This brings role assignment into the same request, approval, and lifecycle governance model as apps, groups, and more - making it easier to manage access to Azure resources at scale while aligning to least privilege and just-in-time access.


General Availability - Manage Agent ID sponsorship lifecycle with Lifecycle Workflows

Type: General Availability
Service category: Lifecycle Workflows
Product capability: Identity Governance

One of the most important parts of governing agent identities is making sure that a delegated human user is always assigned to make sure the agent identity's access to resources are current. If the sponsor is leaving the organization, sponsorship of the agent identities is automatically transferred to their manager. With sponsorship transferred, there's always a human user accountable for managing the access and lifecycle of the agent identities. Microsoft Entra ID Governance features can help streamline this process within your organization. Lifecycle workflows include multiple tasks around notifying cosponsors, and managers of sponsors, of impending sponsorship changes. For a guide on setting up a workflow for agent identities sponsors, see: Agent identity sponsor tasks in Lifecycle Workflows.


Source

Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#may-2026

Change history