Entra ID

Microsoft Entra June 2026: Passkeys, Linux MFA, B2C

3 min read

Summary

Microsoft Entra’s June 2026 updates bring major identity improvements across passkeys, phishing-resistant MFA for Linux desktops, and Azure AD B2C migration to External ID. The release also adds cross-tenant group sync, app deactivation, redesigned My Account pages, and new governance features that help IT teams strengthen security and simplify administration.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft Entra’s June 2026 updates focus on a clear priority for identity teams: stronger phishing-resistant authentication, smoother cross-tenant administration, and lower operational overhead. For IT administrators managing hybrid and multi-platform environments, this release closes several long-standing gaps while adding safer lifecycle and governance controls.

What’s new in Microsoft Entra

Phishing-resistant MFA expands to Linux

Microsoft Entra now supports phish-resistant MFA on Linux desktops through the Microsoft identity broker. Supported platforms include Ubuntu 24.04 and 26.04, plus RHEL 8, 9, and 10. This brings Linux closer to parity with Windows and macOS for secure modern authentication.

Passkey adoption gets a boost

Two important passkey updates arrived:

  • Registration campaigns now support passkeys, including FIDO2, so admins can prompt users to enroll during sign-in.
  • Windows passkey sign-in now supports device-bound passkeys stored in the Windows Hello container, even when the device is not Entra joined or registered.

Easier B2C migration to External ID

High Scale Compatibility (HSC) mode gives large Azure AD B2C tenants a new migration path to Microsoft Entra External ID without forcing password resets or user re-registration. This is aimed at organizations with roughly 5 million or more objects.

Cross-tenant and governance improvements

Several new admin capabilities stand out:

  • Cross-tenant group synchronization for centralized group and membership management across tenants
  • Account discovery for connected apps in Entra ID Governance, including orphaned accounts
  • Automated agent identity sponsorship transitions through Lifecycle Workflows
  • App Deactivation to safely disable applications without deleting them
  • Device Soft Delete to recover deleted device objects during a retention period

User experience and preview features

Microsoft also updated the My Account portal with redesigned Devices, Security Info, and Organizations pages. In preview, admins can test:

  • Domain-less SAML federation for workforce tenants
  • Sensitivity labels for Entra security groups using Microsoft Purview

Why this matters for IT admins

These updates improve both security posture and operational resilience. Linux MFA and passkeys help reduce password and phishing risk, while app deactivation and device soft delete add safer recovery options during incidents or administrative mistakes. Cross-tenant group sync and governance enhancements are especially useful for enterprises managing mergers, partners, or multi-tenant operations.

Next steps

Administrators should review passkey profiles, evaluate Linux desktop support requirements, and identify whether B2C environments may qualify for HSC migration. It’s also a good time to assess app deactivation, device soft delete, and cross-tenant group sync for inclusion in identity governance and incident response processes.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft Entrapasskeysphishing-resistant MFAExternal IDidentity governance

Related Posts

Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.

Entra ID

macOS Platform SSO in ADE Now Generally Available

Microsoft has made Platform SSO during Automated Device Enrollment generally available for macOS. The update lets organizations register devices and enable Platform SSO automatically during setup, reducing user prompts and helping IT teams deliver a more secure, consistent onboarding experience from day one.

Entra ID

Microsoft Identity Manager 2016 SP3 Now Available

Microsoft Identity Manager 2016 SP3 is now generally available, bringing improved stability, broader platform compatibility, and a new Azure SQL Database deployment option for the Synchronization Service. The update matters for organizations running hybrid identity environments because it reduces operational risk, supports newer infrastructure components, and gives customers a supported path forward while planning longer-term moves to Microsoft Entra.

Entra ID

Microsoft Entra Face Check Secures High-Risk Identity Flows

Microsoft is expanding Face Check in Microsoft Entra Verified ID to strengthen identity verification during remote onboarding, access requests, and account recovery. The update removes per-user Face Check limits in Microsoft Entra Suite and highlights general availability for verified account recovery, helping organizations reduce impersonation risk and help desk dependency.

Entra ID

Microsoft Entra May 2026: Global Secure Access GA

Microsoft Entra’s May 2026 updates focus heavily on Global Secure Access, certificate-based authentication, and stronger privileged access controls. The new capabilities help IT teams extend Zero Trust protections to branch offices, mobile devices, external users, and AI workloads while improving usability and policy enforcement.

Entra ID

Microsoft Entra ID Passkeys: Fixing Recovery Gaps

Microsoft is expanding its passkey-first strategy in Entra ID by addressing the security gaps that remain after passkey deployment, including fallback credentials and weak account recovery. New capabilities such as Windows passkeys, passkey-preferred authentication, and generally available Entra ID account recovery help organizations reduce phishing and social engineering risk while improving user experience.