11 Entra Updates Shipped This Week — Only One Comes With a Deadline

11 Entra Updates Shipped This Week — Only One Comes With a Deadline
This Week's Updates & Innovations · Entra News #159

11 Entra Updates Shipped This Week — Only One Comes With a Deadline

Every GA release, retirement, and hardening change from this week's Entra platform update, scanned fast so you know what's new before you read why it matters.

Entra ID Conditional Access Passkeys Identity Governance Agent ID Zero Trust

Eleven updates shipped in this week's Entra release wave.
Only one of them comes with an actual deadline: 2027.

🆕 This Week at a Glance

Every update from this release wave, in one scan. Details and rollout guidance below.

Passkey ProfilesGAMigration path from existing FIDO2 registrations (MC1221452).
Passkeys on WindowsGANative passkey support ships on Windows (MC1282568).
SMS & Voice MFARetiringMicrosoft-provided phone-based auth sunsets by 2027.
Custom Sign-In CSSRetiringCustom positioning properties in branding retire (MC1435782).
Device Code FlowHardenedNew default blocks a live phishing vector.
SSPR CAPTCHAUpdatedStronger bot protection on the reset flow (MC1400824).
Passwordless Password ChangeNewRotate a password without typing the old one, via My Sign-Ins (MC1437671).
B2C Migration Policy AnalyzerNew ToolSystematic planning for Azure AD B2C migrations.
Entra Agent IDFlaggedFour security weaknesses identified in Agent ID blueprints.
Token ProtectionGap FoundLimitations surfaced in hybrid → Entra join migrations.
MaesterExpandedActive Directory testing added; Xbox runs it nightly across 70+ tenants.

📱 The Retirement That Actually Has Teeth

Microsoft-provided SMS and Voice MFA are on the clock. Passkeys are the mandated path forward.

⏱ Phone-Based MFA Retirement Timeline
JUL 2026 — NOW Passkey Profiles GA Passkeys on Windows GA TRANSITION WINDOW Migrate phone-based methods Roll out passkeys tenant-wide 2027 SMS/Voice MFA fully retired

⏱ Microsoft shipped the replacement (passkeys) before the deadline (2027) — the transition window is now

What changed: Microsoft confirmed a 2027 retirement date for Microsoft-provided SMS and voice call authentication, and shipped two passkey GA releases in the same wave — Passkey Profiles (MC1221452, a defined migration path from existing FIDO2 registrations) and native Entra Passkeys on Windows (MC1282568).

This has been "coming eventually" for years. A dated retirement changes it from a roadmap slide into a line item your CAB needs to see — and Microsoft shipped the replacement path in the same release that announced the removal, not months later.

I mapped the exact attack chain that makes this retirement necessary two weeks ago: an attacker calls a target at 3 a.m., the call rolls to voicemail, and the OTP sits there as a recorded message behind a default PIN nobody changed. Full MFA compliance, zero real protection. Confirming how many identities in your tenant are still exposed to it takes one five-minute Graph query.

The practical move this week: pull every user still assigned phone as an authentication method via Microsoft Graph, and start the Authentication Methods Policy conversation before 2027 turns into "why didn't we plan for this."

🔑 Passwordless Is Winning the SSPR Fight Too

Two smaller updates that point the same direction as the MFA retirement.

What changed: SSPR picked up updated CAPTCHA protection (MC1400824), closing off automated abuse of the reset flow. And passwordless password change landed directly in My Sign-Ins (MC1437671) — users can now rotate credentials without ever typing the password they're replacing.

Individually these are minor line items. Together with the MFA retirement and the passkey GA announcements, the pattern is consistent: Microsoft is closing off every path back to a shared secret, phone-based or otherwise.

🎨 One CSS Rule Is About to Break Your Sign-In Page

MC1435782 — a quiet branding change with an immediate blast radius for custom sign-in pages.

What changed: Microsoft is retiring custom CSS positioning properties in company branding (MC1435782), part of a broader security hardening pass on branded sign-in experiences. If your sign-in page has hand-tuned CSS for logo placement, banner positioning, or layout tweaks beyond what the branding UI exposes, that styling is on notice.

This is the kind of change that never makes it to a stakeholder meeting until the sign-in page suddenly looks wrong in production. Worth a five-minute audit of your current branding customization now, while there's still time to redo it deliberately instead of reactively.

🤖 Agent Identity Just Became a First-Class Attack Surface

Four flagged weaknesses in Entra Agent ID blueprints, plus a hardening move against a live phishing vector.

What changed: Derk van der Woude's community review identified four specific security weaknesses in Entra Agent ID blueprints, and Microsoft tightened default handling of device code flow to block a phishing vector that's been showing up against Microsoft 365 tenants.

The four weaknesses matter less individually than the timing: Microsoft is standing up first-class identity primitives for AI agents faster than most tenants are building a governance model to match. Device code flow abuse and agent identity gaps are different mechanisms, but the same category of risk: authentication paths built for a narrow legitimate use case, now under active probing because the broader ecosystem — non-human identities, service accounts, agents acting on a user's behalf — expanded faster than the controls around it.

If your tenant has any Copilot Studio agents, Power Platform automations, or early Agent ID pilots running, this is the week to inventory them the same way you'd inventory service principals — because that's functionally what they are now.

🔗 The Migration Gotcha Nobody Puts in the Runbook

Token Protection has real limitations when moving from hybrid join to Entra join.

What changed: Sreejith Reghunathan Pillai documented real limitations in Entra Token Protection behavior during hybrid-to-Entra-join migrations — exactly the kind of detail that gets discovered mid-cutover instead of during planning. If Token Protection is part of your Conditional Access baseline, confirm its behavior across the join-type transition before you schedule the migration window — not while it's already in progress.

🧪 Community Proof: Maester Is Running at Real Scale

Xbox Security is validating 70+ tenants nightly. That's the automation maturity bar now.

What changed: Maester — Microsoft's open-source Pester-based testing framework — added Active Directory security testing alongside its existing Entra checks. Audrey Long from Xbox Security published how her team runs gaming-specific Entra baselines nightly across more than 70 tenants using it, and Jan Bakker documented using AI to generate new Maester test cases, cutting the time to add a baseline check from a design conversation to a working pull request.

Worth noting for anyone still validating tenant security posture by hand: if a gaming security team is running nightly automated checks across 70+ tenants, "we review Conditional Access quarterly" is no longer a defensible baseline for a single-tenant environment. Darren Robinson also built an MCP server exposing searchable Entra.Chat episodes and newsletters as context for AI agents — a small but telling sign of how fast tooling is catching up to the volume of Entra platform changes shipping every month.

🎯 Final Thoughts

None of this week's items are individually urgent. Together, they describe where the identity perimeter is actually moving: phone-based factors are being retired on a real clock, non-human and agent identities are getting first-class treatment before most governance models are ready for them, and the small operational changes — branding CSS, token protection edge cases — are exactly the ones that get skipped until they cause an incident.

The three things worth putting on this week's change calendar: audit phone-based auth method assignments, inventory any agent identities already running in your tenant, and check your branded sign-in page against the upcoming CSS retirement. None of them are big projects. All three are cheaper to handle now than after GA lands and someone else finds the gap first.

Source coverage: Entra News #159, entra.news — analysis and recommendations above are ModernEndpoint's own.

Article Focus

This digest reads this week's Entra platform and community updates for operational impact — separating what's genuinely new attack surface from what's routine housekeeping, and flagging what belongs on a change calendar now.

This Week's Action List

1Query Graph for identities still assigned phone-based auth methods
2Inventory Copilot Studio / Agent ID identities like service principals
3Audit custom sign-in CSS against the MC1435782 retirement
4Confirm Token Protection behavior before any hybrid → Entra join cutover

Governance Angle

Agent identities are the biggest structural risk in this release wave: most tenants have no ownership model for them yet, regardless of how severe any one flagged weakness turns out to be. Treat every agent identity as a service principal: owner assigned, scope reviewed, lifecycle tracked.