Entra ID

Microsoft Entra March 2026: Key Identity Updates

3 min read

Summary

Microsoft Entra’s Q1 2026 roundup introduces passkey enhancements, new governance APIs, External MFA general availability, and broader Conditional Access enforcement. The updates matter for IT teams because several changes require policy reviews, sync planning, and helpdesk preparation before enforcement deadlines in May and June 2026.

Audio Summary

0:00--:--
Need help with Entra ID?Talk to an Expert

Introduction

Microsoft Entra’s March 2026 roundup brings a broad set of identity, governance, and access updates across Entra ID, ID Governance, External ID, Agent ID, and Global Secure Access. For IT administrators, the biggest takeaway is that several security-related changes have rollout dates in Q2 2026 and may require policy reviews before they affect users.

What’s new in Microsoft Entra

Microsoft Entra ID

Key new releases include:

  • Synced passkeys in Microsoft Entra ID
  • Passkey profiles for better passkey management
  • Microsoft Single Sign-On for Linux with phish-resistant MFA credential support
  • Improved readability for Authentication Methods Policy update audit logs
  • External MFA is now generally available
  • Service principal creation audit logs for alerting and monitoring
  • Better enforcement for All resources policies with resource exclusions

Conditional Access change for registration flows

Starting May 25, 2026, and completing by June 3, 2026, Conditional Access policies scoped to Register security information will also apply to:

  • Windows Hello for Business setup
  • macOS Platform SSO credential registration

This can introduce new prompts during device setup. Microsoft notes that Windows Hello for Business uses the Device Registration Client, which is classified as Other clients in Conditional Access. If your policy blocks Other clients, provisioning may fail.

Authenticator jailbreak detection

Microsoft Authenticator on Android now introduces jailbreak/root detection for Entra credentials, moving through warning, blocking, and wipe modes. Users on compromised devices will need to move to compliant devices.

Agent 365 consolidation

The Agent registry and Agent collections blades in Entra admin center will retire on May 1, 2026. Agent inventory remains available in the All agents view in the Microsoft 365 admin center. A new Agent 365-powered API will replace the current registry Graph API, and existing registered agents will eventually need re-registration.

ID Governance and sync updates

Notable additions include:

  • SCIM 2.0 APIs
  • Tenant configuration management APIs
  • Expanded Lifecycle Workflows capabilities
  • Windows Server 2025 support for Entra Connect Sync
  • Ability to convert synced on-premises AD users to cloud users

A major security change arrives June 1, 2026: Entra ID will block hard match attempts for new AD users targeting existing cloud-managed users with Entra roles. This helps prevent takeover of privileged accounts.

Impact on IT administrators

Admins should expect more scrutiny on Conditional Access design, identity sync processes, and mobile device trust. Helpdesk teams may also see increased calls when users encounter new prompts during device registration or Authenticator restrictions.

Next steps

  • Review Conditional Access policies targeting Register security information
  • Check for policies blocking Other clients and test in report-only mode
  • Update helpdesk guidance for Windows Hello for Business and macOS Platform SSO prompts
  • Prepare for Agent 365 management changes and API transition
  • Review Entra Connect and Cloud Sync processes before the June 1, 2026 hard match restriction

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraConditional AccesspasskeysEntra ID GovernanceAgent 365

Related Posts

Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.

Entra ID

macOS Platform SSO in ADE Now Generally Available

Microsoft has made Platform SSO during Automated Device Enrollment generally available for macOS. The update lets organizations register devices and enable Platform SSO automatically during setup, reducing user prompts and helping IT teams deliver a more secure, consistent onboarding experience from day one.

Entra ID

Microsoft Identity Manager 2016 SP3 Now Available

Microsoft Identity Manager 2016 SP3 is now generally available, bringing improved stability, broader platform compatibility, and a new Azure SQL Database deployment option for the Synchronization Service. The update matters for organizations running hybrid identity environments because it reduces operational risk, supports newer infrastructure components, and gives customers a supported path forward while planning longer-term moves to Microsoft Entra.

Entra ID

Microsoft Entra Face Check Secures High-Risk Identity Flows

Microsoft is expanding Face Check in Microsoft Entra Verified ID to strengthen identity verification during remote onboarding, access requests, and account recovery. The update removes per-user Face Check limits in Microsoft Entra Suite and highlights general availability for verified account recovery, helping organizations reduce impersonation risk and help desk dependency.

Entra ID

Microsoft Entra May 2026: Global Secure Access GA

Microsoft Entra’s May 2026 updates focus heavily on Global Secure Access, certificate-based authentication, and stronger privileged access controls. The new capabilities help IT teams extend Zero Trust protections to branch offices, mobile devices, external users, and AI workloads while improving usability and policy enforcement.

Entra ID

Microsoft Entra ID Passkeys: Fixing Recovery Gaps

Microsoft is expanding its passkey-first strategy in Entra ID by addressing the security gaps that remain after passkey deployment, including fallback credentials and weak account recovery. New capabilities such as Windows passkeys, passkey-preferred authentication, and generally available Entra ID account recovery help organizations reduce phishing and social engineering risk while improving user experience.