Entra ID

Microsoft Entra September 2026: Key Identity Updates

3 min read

Summary

Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft Entra’s September 2026 updates focus on three priorities for IT teams: stronger tenant governance, simpler identity lifecycle management, and better protection for AI-era access patterns. For administrators managing hybrid identity, Microsoft 365, and Zero Trust initiatives, this release includes both new capabilities and time-sensitive changes that require planning.

What’s new in Microsoft Entra

General availability updates

  • Microsoft Entra Tenant Governance is now generally available, helping admins discover shadow IT tenants, apply least-privilege governance relationships, and monitor configuration drift across Entra, Intune, Exchange Online, Teams, Purview, and Defender.
  • User-centric Access Reviews (UAR) provide a unified view of a user’s access across multiple resources, including Entra ID groups and external applications.
  • Lifecycle Workflows cloning lets administrators duplicate an existing workflow and modify it before deployment, reducing setup time for repeatable identity processes.
  • Microsoft Entra Resource Accounts for Teams Devices introduces a secure, passwordless identity model for Teams Rooms, Teams Panels, Common Area Phones, and other shared Teams devices.

Public preview features

  • sAMAccountName sync with Entra Domain Services now supports synchronization from the onPremisesSamAccountName attribute, helping hybrid apps that still depend on this value.
  • Microsoft Entra Cloud Sync can now provision users, groups, and memberships from Entra ID to on-premises AD DS, which is useful for cloud-first organizations that still rely on AD-backed apps.
  • Global Secure Access MCP Firewall adds visibility and policy enforcement for Model Context Protocol traffic between AI agents and MCP servers, supporting secure AI adoption.

Important change announcements

  • Security Administrator role enhancements will add more identity response actions for non-privileged users, including account disable/enable, session revocation, and forced password resets. Rollout finishes by the end of September 2026.
  • MemberOf rule operator preview ends November 3, 2026. Any dynamic groups, dynamic administrative units, or entitlement management auto-assignment policies using MemberOf must be replaced before that date.
  • User.ReadBasic.All permission scope update removes unintended access to app role assignments and license details. Apps that need those properties should move to User.Read.All and/or LicenseAssignment.Read.All.

Impact on IT administrators

These updates are especially relevant for identity, security, and Microsoft 365 admins managing multiple tenants or hybrid environments. Tenant Governance and Cloud Sync improve centralized control, while MCP Firewall signals Microsoft’s growing focus on securing AI-related traffic and services.

Next steps

  • Review whether your organization has unmanaged or shadow tenants.
  • Audit dynamic group and entitlement configurations for MemberOf usage.
  • Validate app permissions that currently rely on User.ReadBasic.All.
  • Evaluate Cloud Sync and Resource Accounts if you support hybrid identity or shared Teams devices.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft Entraidentity governanceaccess reviewscloud synctenant governance

Related Posts

Entra ID

Microsoft Entra Passkeys for External IdP App Sign-Ins

Microsoft has made browser-based authentication for external identity providers generally available for supported Microsoft app sign-ins on Android, iOS, and managed macOS. This lets federated Microsoft 365 users use passkeys, FIDO2 security keys, and eligible SSO sessions in apps like Outlook, Teams, and OneDrive, reducing password fallback and embedded web view limitations.

Entra ID

Microsoft Entra Tenant Governance Webinars 2026

Microsoft is promoting upcoming webinars focused on securing multi-tenant environments with Microsoft Entra Tenant Governance, now generally available. The sessions highlight how organizations can detect shadow tenants, apply consistent governance, and build a stronger identity foundation for AI readiness.

Entra ID

Microsoft Entra App Gallery Self-Service Onboarding Preview

Microsoft has launched a public preview of self-service onboarding for new Microsoft Entra App Gallery applications. The new workflow lets publishers validate OIDC, SAML, and provisioning integrations before submission, then create, submit, and track app listings in the Entra admin center, reducing delays and rework.

Entra ID

Microsoft Entra Private Access Replaces VPNs

Microsoft is positioning Entra Private Access as a practical replacement for traditional VPNs, using identity-driven, per-app access instead of broad network tunnels. The guidance outlines a phased migration approach that helps IT teams reduce attack surface, strengthen Zero Trust controls, and simplify remote access operations.

Entra ID

HiBob Microsoft Entra Integration Now Generally Available

Microsoft has announced general availability of HiBob’s native integration with Microsoft Entra, enabling HR-driven identity lifecycle automation for joiners, movers, and leavers. The integration helps IT teams govern provisioning and access changes across hybrid and cloud environments while reducing manual processes and security risk.

Entra ID

Entra ID CAE Revokes Service Principal Tokens Instantly

Microsoft Entra now supports instant revocation of CAE-enabled service principal bearer tokens, giving security teams a faster kill switch for compromised workload identities. By adding the cp1 client capability claim, admins can invalidate tokens on high-risk, disabled, or deleted service principals instead of waiting 60 to 90 minutes for token expiry.