Microsoft Entra September 2026: Key Identity Updates
Summary
Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.
Introduction
Microsoft Entra’s September 2026 updates focus on three priorities for IT teams: stronger tenant governance, simpler identity lifecycle management, and better protection for AI-era access patterns. For administrators managing hybrid identity, Microsoft 365, and Zero Trust initiatives, this release includes both new capabilities and time-sensitive changes that require planning.
What’s new in Microsoft Entra
General availability updates
- Microsoft Entra Tenant Governance is now generally available, helping admins discover shadow IT tenants, apply least-privilege governance relationships, and monitor configuration drift across Entra, Intune, Exchange Online, Teams, Purview, and Defender.
- User-centric Access Reviews (UAR) provide a unified view of a user’s access across multiple resources, including Entra ID groups and external applications.
- Lifecycle Workflows cloning lets administrators duplicate an existing workflow and modify it before deployment, reducing setup time for repeatable identity processes.
- Microsoft Entra Resource Accounts for Teams Devices introduces a secure, passwordless identity model for Teams Rooms, Teams Panels, Common Area Phones, and other shared Teams devices.
Public preview features
- sAMAccountName sync with Entra Domain Services now supports synchronization from the
onPremisesSamAccountNameattribute, helping hybrid apps that still depend on this value. - Microsoft Entra Cloud Sync can now provision users, groups, and memberships from Entra ID to on-premises AD DS, which is useful for cloud-first organizations that still rely on AD-backed apps.
- Global Secure Access MCP Firewall adds visibility and policy enforcement for Model Context Protocol traffic between AI agents and MCP servers, supporting secure AI adoption.
Important change announcements
- Security Administrator role enhancements will add more identity response actions for non-privileged users, including account disable/enable, session revocation, and forced password resets. Rollout finishes by the end of September 2026.
- MemberOf rule operator preview ends November 3, 2026. Any dynamic groups, dynamic administrative units, or entitlement management auto-assignment policies using MemberOf must be replaced before that date.
- User.ReadBasic.All permission scope update removes unintended access to app role assignments and license details. Apps that need those properties should move to User.Read.All and/or LicenseAssignment.Read.All.
Impact on IT administrators
These updates are especially relevant for identity, security, and Microsoft 365 admins managing multiple tenants or hybrid environments. Tenant Governance and Cloud Sync improve centralized control, while MCP Firewall signals Microsoft’s growing focus on securing AI-related traffic and services.
Next steps
- Review whether your organization has unmanaged or shadow tenants.
- Audit dynamic group and entitlement configurations for MemberOf usage.
- Validate app permissions that currently rely on User.ReadBasic.All.
- Evaluate Cloud Sync and Resource Accounts if you support hybrid identity or shared Teams devices.
Need help with Entra ID?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies