Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration [MC1326253]

Conditional Access policies now apply to Windows Hello for Business and macOS Platform SSO registration [MC1326253]

Message ID: MC1326253 If your organization has Conditional Access policies scoped to Register security information, those policies will now apply when users set up Windows Hello for Business (WHfB) or register macOS Platform SSO credentials.Today, these registration flows enforce MFA,…
Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026 [MC1325414]

Microsoft Entra ID SSPR will require registered authentication methods starting September 7, 2026 [MC1325414]

Message ID: MC1325414 [What and Why]You’re receiving this message because your organization uses Microsoft Entra ID Self-Service Password Reset (SSPR).Currently, SSPR may allow users to verify their identity using contact information stored in directory attributes such as mobile phone, business…
Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings [MC1303719]

Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings [MC1303719]

Message ID: MC1303719 [Introduction]To strengthen security for federated authentication, Microsoft Entra will update the default behavior of federatedTokenValidationPolicy. This policy governs how Microsoft Entra validates federated authentication tokens and determines whether sign-ins are allowed when the internalDomainFederation does not match…
Microsoft Entra: App Instance Lock enabled by default for new applications [MC1300584]

Microsoft Entra: App Instance Lock enabled by default for new applications [MC1300584]

Message ID: MC1300584 [Introduction]To improve application security, Microsoft Entra ID will enable App Instance Lock by default for newly created applications. This change prevents sensitive application properties from being modified outside the application’s home tenant, reducing the risk of unauthorized…
(Updated) Microsoft Entra: Passkeys in registration campaigns update [MC1279092]

(Updated) Microsoft Entra: Passkeys in registration campaigns update [MC1279092]

Message ID: MC1279092 (Updated) Updated April 23, 2026: We have updated the content. Thank you for your patience. [Introduction]Earlier communication indicated a change in direction; however, Microsoft will continue to add support for passkeys (FIDO2) in the Enabled state within Registration…
(Updated) Microsoft Entra: Cross-tenant security group synchronization [MC1198077]

(Updated) Microsoft Entra: Cross-tenant security group synchronization [MC1198077]

Message ID: MC1198077 (Updated) Updated April 22, 2026: We have updated the timeline. Thank you for your patience. We’re introducing cross-tenant group synchronization, a new capability that enables organizations to synchronize security groups across Microsoft Entra tenants. This feature simplifies collaboration…