Microsoft Entra: January 2026
Microsoft announcement
General Availability - Ability to convert Source of Authority of synced on-premises AD users to cloud users is now available
Type: New feature
Service category: User Management
Product capability: Microsoft Entra Cloud Sync
We’re pleased to announce the general availability of object-level Source of Authority (SOA) switching for Microsoft Entra ID. With this feature, administrators can transition individual users from being synced with Active Directory (AD) to becoming cloud-managed accounts within Microsoft Entra ID. These users are no longer tied to AD sync and behave like native cloud users, giving you greater flexibility and control. This capability enables organizations to gradually reduce dependence on AD and simplify migration to the cloud, all while minimizing disruption for users and daily operations. Both Microsoft Entra Connect Sync and Cloud Sync fully support this SOA switch, ensuring a smooth transition process.
For more information, see: Embrace cloud-first posture: Transfer user Source of Authority (SOA) to the cloud.
General Availability - Microsoft Entra ID Governance guest billing meter enforcement
Type: New feature
Service category: Entitlement Management, Lifecycle Workflows
Product capability: Entitlement Management, Lifecycle Workflows
Enforcement for the Microsoft Entra ID Governance guest billing meter is now in effect for Entitlement Management and Lifecycle Workflows (Access Reviews will be enforced later in CY26 Q1). To keep using Entra ID Governance premium features for guest users in workforce tenants, you must link a valid Azure subscription to activate the Microsoft Entra ID Governance for guests add-on. If a subscription isn’t linked, creation or updates of new guest-scoped governance configurations will be restricted (for example, certain access package policies, access reviews, and lifecycle workflows), and guest-specific governance actions may fail until billing is configured.
For more information, see: Microsoft Entra ID Governance licensing for guest users.
General Availability - Client Credentials in Microsoft Entra External ID
Type: New feature
Service category: B2C - Consumer Identity Management
Product capability: B2B/B2C
We are pleased to announce the general availability of client credentials in Entra External ID. The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. Permissions are granted directly to the application itself by an administrator.
Billing: When you configure machine-to-machine (M2M) authentication for Microsoft Entra External ID, you must use the M2M Premium add‑on. Review your organization’s premium add‑on usage policy to understand cost implications and ensure the implementation complies with internal governance and licensing guidelines. For more information, see: Microsoft identity platform and the OAuth 2.0 client credentials flow.
General Availability - App-based branding via Branding themes in Entra External ID
Type: New feature
Service category: B2C - Consumer Identity Management
Product capability: B2B/B2C
In Entra External ID (EEID), customers can create a single, tenant-wide, customized branding experience that applies to all apps. We're introducing a concept of Branding "themes" to allow customers to create different branding experiences for specific applications. A new Live Preview feature also helps quickly visualize the changes before saving. For more information, see: Customize the sign‑in experience for your application with branding themes.
General Availability - Service Principal creation audit logs for alerting & monitoring
Type: New feature
Service category: Audit
Product capability: Monitoring & Reporting
New audit log properties now make it easy for admins to understand why a service principal was created and who or what triggered it. The logs now surface the provisioning mechanism, the specific SKUs or service plans that enabled just‑in‑time creation, and the home tenant of the app registration. This helps admins quickly distinguish Microsoft‑driven provisioning from tenant‑driven activity, streamlining alerting and investigations into newly created service principals. For more information, see:
- Understand why a service principal was created in your tenant
- How to download and analyze the Microsoft Entra provisioning logs
General Availability - Session Control Conditional Access Policies in Entra External ID
Type: New feature
Service category: Conditional Access
Product capability: B2B/B2C
EEID admins can configure persistent browser session and sign‑in frequency in Conditional Access. For more information, see Conditional Access: Manage Session Controls Effectively.
General Availability - Entra Private Access for Domain Controllers
Type: New feature
Service category: Private Access
Product capability: Network Access
Bring MFA to on‑premises applications when accessed from on‑premises, i.e., local‑to‑local access, while safeguarding domain controllers against identity threats. Enable secure access to private apps that use domain controllers for Kerberos authentication. For more information, see: Configure Microsoft Entra Private Access for Active Directory domain controllers.
General Availability - Improved enforcement for All resources policies with resource exclusions
Type: Changed feature
Service category: Conditional Access
Product capability: Access Control
Microsoft Entra Conditional Access is strengthening how policies that target All resources with resource exclusions are enforced in a narrow set of authentication flows. After this change, in user sign‑ins where a client application requests only OIDC or specific directory scopes, Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, will be enforced. This ensures that policies are consistently applied regardless of the scope set requested by the client application. For more information, see: New Conditional Access behavior when an ALL resources policy has a resource exclusion.
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#january-2026
Change history
- 2026-07-15 · Created · All