11 Entra Updates Shipped This Week — Only One Comes With a Deadline
11 Entra Updates Shipped This Week — Only One Comes With a Deadline
Every GA release, retirement, and hardening change from this week's Entra platform update, scanned fast so you know what's new before you read why it matters.
Eleven updates shipped in this week's Entra release wave.
Only one of them comes with an actual deadline: 2027.
🆕 This Week at a Glance
Every update from this release wave, in one scan. Details and rollout guidance below.
📱 The Retirement That Actually Has Teeth
Microsoft-provided SMS and Voice MFA are on the clock. Passkeys are the mandated path forward.
⏱ Microsoft shipped the replacement (passkeys) before the deadline (2027) — the transition window is now
What changed: Microsoft confirmed a 2027 retirement date for Microsoft-provided SMS and voice call authentication, and shipped two passkey GA releases in the same wave — Passkey Profiles (MC1221452, a defined migration path from existing FIDO2 registrations) and native Entra Passkeys on Windows (MC1282568).
This has been "coming eventually" for years. A dated retirement changes it from a roadmap slide into a line item your CAB needs to see — and Microsoft shipped the replacement path in the same release that announced the removal, not months later.
The practical move this week: pull every user still assigned phone as an authentication method via Microsoft Graph, and start the Authentication Methods Policy conversation before 2027 turns into "why didn't we plan for this."
🔑 Passwordless Is Winning the SSPR Fight Too
Two smaller updates that point the same direction as the MFA retirement.
What changed: SSPR picked up updated CAPTCHA protection (MC1400824), closing off automated abuse of the reset flow. And passwordless password change landed directly in My Sign-Ins (MC1437671) — users can now rotate credentials without ever typing the password they're replacing.
Individually these are minor line items. Together with the MFA retirement and the passkey GA announcements, the pattern is consistent: Microsoft is closing off every path back to a shared secret, phone-based or otherwise.
🎨 One CSS Rule Is About to Break Your Sign-In Page
MC1435782 — a quiet branding change with an immediate blast radius for custom sign-in pages.
What changed: Microsoft is retiring custom CSS positioning properties in company branding (MC1435782), part of a broader security hardening pass on branded sign-in experiences. If your sign-in page has hand-tuned CSS for logo placement, banner positioning, or layout tweaks beyond what the branding UI exposes, that styling is on notice.
This is the kind of change that never makes it to a stakeholder meeting until the sign-in page suddenly looks wrong in production. Worth a five-minute audit of your current branding customization now, while there's still time to redo it deliberately instead of reactively.
🤖 Agent Identity Just Became a First-Class Attack Surface
Four flagged weaknesses in Entra Agent ID blueprints, plus a hardening move against a live phishing vector.
What changed: Derk van der Woude's community review identified four specific security weaknesses in Entra Agent ID blueprints, and Microsoft tightened default handling of device code flow to block a phishing vector that's been showing up against Microsoft 365 tenants.
The four weaknesses matter less individually than the timing: Microsoft is standing up first-class identity primitives for AI agents faster than most tenants are building a governance model to match. Device code flow abuse and agent identity gaps are different mechanisms, but the same category of risk: authentication paths built for a narrow legitimate use case, now under active probing because the broader ecosystem — non-human identities, service accounts, agents acting on a user's behalf — expanded faster than the controls around it.
If your tenant has any Copilot Studio agents, Power Platform automations, or early Agent ID pilots running, this is the week to inventory them the same way you'd inventory service principals — because that's functionally what they are now.
🔗 The Migration Gotcha Nobody Puts in the Runbook
Token Protection has real limitations when moving from hybrid join to Entra join.
What changed: Sreejith Reghunathan Pillai documented real limitations in Entra Token Protection behavior during hybrid-to-Entra-join migrations — exactly the kind of detail that gets discovered mid-cutover instead of during planning. If Token Protection is part of your Conditional Access baseline, confirm its behavior across the join-type transition before you schedule the migration window — not while it's already in progress.
🧪 Community Proof: Maester Is Running at Real Scale
Xbox Security is validating 70+ tenants nightly. That's the automation maturity bar now.
What changed: Maester — Microsoft's open-source Pester-based testing framework — added Active Directory security testing alongside its existing Entra checks. Audrey Long from Xbox Security published how her team runs gaming-specific Entra baselines nightly across more than 70 tenants using it, and Jan Bakker documented using AI to generate new Maester test cases, cutting the time to add a baseline check from a design conversation to a working pull request.
Worth noting for anyone still validating tenant security posture by hand: if a gaming security team is running nightly automated checks across 70+ tenants, "we review Conditional Access quarterly" is no longer a defensible baseline for a single-tenant environment. Darren Robinson also built an MCP server exposing searchable Entra.Chat episodes and newsletters as context for AI agents — a small but telling sign of how fast tooling is catching up to the volume of Entra platform changes shipping every month.
🎯 Final Thoughts
None of this week's items are individually urgent. Together, they describe where the identity perimeter is actually moving: phone-based factors are being retired on a real clock, non-human and agent identities are getting first-class treatment before most governance models are ready for them, and the small operational changes — branding CSS, token protection edge cases — are exactly the ones that get skipped until they cause an incident.
The three things worth putting on this week's change calendar: audit phone-based auth method assignments, inventory any agent identities already running in your tenant, and check your branded sign-in page against the upcoming CSS retirement. None of them are big projects. All three are cheaper to handle now than after GA lands and someone else finds the gap first.
Source coverage: Entra News #159, entra.news — analysis and recommendations above are ModernEndpoint's own.