Entra ID

Microsoft Entra March 2026: Key Identity Updates

3 min read

Summary

Microsoft Entra’s Q1 2026 roundup introduces passkey enhancements, new governance APIs, External MFA general availability, and broader Conditional Access enforcement. The updates matter for IT teams because several changes require policy reviews, sync planning, and helpdesk preparation before enforcement deadlines in May and June 2026.

Audio Summary

0:00--:--
Need help with Entra ID?Talk to an Expert

Introduction

Microsoft Entra’s March 2026 roundup brings a broad set of identity, governance, and access updates across Entra ID, ID Governance, External ID, Agent ID, and Global Secure Access. For IT administrators, the biggest takeaway is that several security-related changes have rollout dates in Q2 2026 and may require policy reviews before they affect users.

What’s new in Microsoft Entra

Microsoft Entra ID

Key new releases include:

  • Synced passkeys in Microsoft Entra ID
  • Passkey profiles for better passkey management
  • Microsoft Single Sign-On for Linux with phish-resistant MFA credential support
  • Improved readability for Authentication Methods Policy update audit logs
  • External MFA is now generally available
  • Service principal creation audit logs for alerting and monitoring
  • Better enforcement for All resources policies with resource exclusions

Conditional Access change for registration flows

Starting May 25, 2026, and completing by June 3, 2026, Conditional Access policies scoped to Register security information will also apply to:

  • Windows Hello for Business setup
  • macOS Platform SSO credential registration

This can introduce new prompts during device setup. Microsoft notes that Windows Hello for Business uses the Device Registration Client, which is classified as Other clients in Conditional Access. If your policy blocks Other clients, provisioning may fail.

Authenticator jailbreak detection

Microsoft Authenticator on Android now introduces jailbreak/root detection for Entra credentials, moving through warning, blocking, and wipe modes. Users on compromised devices will need to move to compliant devices.

Agent 365 consolidation

The Agent registry and Agent collections blades in Entra admin center will retire on May 1, 2026. Agent inventory remains available in the All agents view in the Microsoft 365 admin center. A new Agent 365-powered API will replace the current registry Graph API, and existing registered agents will eventually need re-registration.

ID Governance and sync updates

Notable additions include:

  • SCIM 2.0 APIs
  • Tenant configuration management APIs
  • Expanded Lifecycle Workflows capabilities
  • Windows Server 2025 support for Entra Connect Sync
  • Ability to convert synced on-premises AD users to cloud users

A major security change arrives June 1, 2026: Entra ID will block hard match attempts for new AD users targeting existing cloud-managed users with Entra roles. This helps prevent takeover of privileged accounts.

Impact on IT administrators

Admins should expect more scrutiny on Conditional Access design, identity sync processes, and mobile device trust. Helpdesk teams may also see increased calls when users encounter new prompts during device registration or Authenticator restrictions.

Next steps

  • Review Conditional Access policies targeting Register security information
  • Check for policies blocking Other clients and test in report-only mode
  • Update helpdesk guidance for Windows Hello for Business and macOS Platform SSO prompts
  • Prepare for Agent 365 management changes and API transition
  • Review Entra Connect and Cloud Sync processes before the June 1, 2026 hard match restriction

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraConditional AccesspasskeysEntra ID GovernanceAgent 365

Related Posts

Entra ID

Microsoft Entra AI Access Strategy Risks in 2026

Microsoft highlights new research showing that AI adoption is rapidly expanding identity and network access risk, with AI agents, GenAI use, and fragmented tools increasing incidents across enterprises. The report argues that organizations need a more unified access strategy, or "access fabric," to improve visibility, enforce policy faster, and reduce risk as AI scales.

Entra ID

Microsoft Entra SCIM 2.0 APIs Now Generally Available

Microsoft Entra has introduced new SCIM 2.0 APIs that let external SCIM-compatible identity sources provision and manage users and groups directly in Entra. The update matters for IT teams because it enables standards-based identity lifecycle automation, reduces custom integration work, and supports reuse of existing SCIM tooling and workflows.

Entra ID

Conditional Access Optimization Agent Gets Smarter

Microsoft has expanded the Conditional Access Optimization Agent in Entra ID public preview with context-aware recommendations, continuous gap analysis, least-privilege enforcement for agent identities, phased rollouts, passkey campaigns, and Zero Trust posture reporting. These updates help security teams move from static policy reviews to continuous identity security optimization with safer deployment and clearer visibility into access gaps.

Entra ID

Microsoft Entra Tenant Governance for Multi-Tenant Security

Microsoft has introduced Entra Tenant Governance to help organizations discover, govern, and secure related tenants from a central control plane. The new capabilities matter for IT teams managing mergers, acquisitions, and shadow IT because they reduce cross-tenant risk, streamline delegated administration, and enforce consistent security baselines at scale.

Entra ID

Microsoft Entra Backup and Recovery Enters Preview

Microsoft has launched Microsoft Entra Backup and Recovery in public preview, giving organizations a Microsoft-managed way to restore critical identity objects and configurations to a known-good state. The service helps IT teams recover faster from accidental admin changes, provisioning errors, and malicious modifications that could otherwise disrupt access and security.

Entra ID

Microsoft Entra External MFA Now Generally Available

Microsoft has announced general availability of external MFA in Microsoft Entra ID, allowing organizations to integrate trusted third-party MFA providers using OpenID Connect. The feature lets IT teams keep Microsoft Entra ID as the central identity control plane while maintaining Conditional Access, risk evaluation, and unified authentication method management.