azureblog.co.uk
// changes

Change feed

What Microsoft has changed in Entra ID, Intune and Azure, newest first. Items that need you to do something are flagged. For dated retirements, see the deadline timeline.

29 changes

  1. October 2026

  2. IntuneNew

    Deployment plans: staged rollouts in rings

    Stage Win32 apps, catalog apps, Settings Catalog and endpoint security policies across rings with controlled timing.

  3. IntunePreview

    Client-driven compliance evaluation

    Supported Windows devices ask Intune to re-evaluate compliance as soon as a signal such as BitLocker or the firewall changes.

  4. IntuneChangeaction needed

    Multi Admin Approval now applies to Microsoft Graph calls

    Scripts and apps that change MAA-protected resources without approval now get HTTP 403. Update them or add a temporary exclusion.

  5. IntuneNew

    Windows 11 26H2 security baseline

    A new baseline version is available. Existing profiles don't update automatically.

  6. IntuneChangeaction needed

    iOS/iPadOS 18 is now the minimum

    Standard device management, Company Portal and app protection now require iOS/iPadOS 18 or later.

  7. September 2026

  8. Entra IDRetirementaction needed

    Microsoft-provided SMS and voice MFA retiring

    Text and phone call authentication ends for most users on 1 February 2027. Passkeys are being switched on for affected users.

  9. IntuneNew

    Unattended Remote Help for Windows

    Helpdesk agents can connect to physical Windows devices with nobody at the keyboard. Scope the role carefully.

  10. IntuneNew

    Apple VPP apps through declarative device management

    Set the management type to DDM when uploading a VPP token. Needs iOS/iPadOS 17.2+ or macOS 26+.

  11. IntuneNew

    eSIM management for corporate Android

    Activate and remove eSIMs, and choose whether they're removed on wipe, on corporate-owned Android devices.

  12. August 2026

  13. IntuneNew

    Custom compliance for macOS

    A script reports values and a JSON rules file defines what's compliant, as on Windows and Linux.

  14. IntunePreview

    Controlled configuration for Defender Antivirus

    Lets Intune or Defender for Endpoint own Defender settings so Group Policy and other sources stop overriding them.

  15. July 2026

  16. Entra IDChangeaction needed

    Authenticator blocks jailbroken and rooted devices

    Work and school accounts can't be added or used in Authenticator on modified phones. Brief the service desk.

  17. Entra IDGA

    BYOD Windows access with Entra registration

    Users, partners and internal guests can reach corporate resources from personal Windows PCs using Entra registration.

  18. Entra IDChangeaction needed

    Phased move from Connect Sync to Cloud Sync

    Tenants are being notified of their own transition timeline. Inventory your sync features and pilot Cloud Sync.

  19. IntuneChange

    Intune advanced features coming to Microsoft 365 E3 and E5

    Remote Help, Endpoint Privilege Management, Cloud PKI and more move into the main licences.

  20. June 2026

  21. Entra IDGA

    Entra Backup and Recovery

    Daily, tamper-proof backups of key directory objects with seven days of history, difference reports and restore.

  22. Entra IDGA

    Account Discovery

    Reports accounts inside connected apps, including orphaned accounts with no Entra assignment.

  23. Entra IDPreview

    Soft delete for device objects

    Deleted devices become recoverable, with their identity and BitLocker keys intact, for a retention period.

  24. Entra IDGA

    Cross-tenant group sync

    Sync security groups and memberships from a source tenant into target tenants alongside users.

  25. Entra IDChangeaction needed

    Hard match blocked for users with Entra roles

    Sync can no longer take over a cloud account that holds an Entra role by hard matching.

  26. May 2026

  27. Entra IDChange

    System-preferred authentication picks the first factor too

    Users with a passkey may sign in without a password prompt, and registration campaigns can prompt for passkeys.

  28. Entra IDGA

    Entra Agent ID

    First-class identities for AI agents, with sponsors, and Conditional Access for agents in preview.

  29. April 2026

  30. Entra IDGA

    Configurable token lifetimes

    Set access, ID and SAML token lifetimes per application.

  31. Entra IDGA

    Authentication context on PIM activation

    PIM can require a Conditional Access authentication context every time a role is activated.

  32. Entra IDGA

    Tenant configuration management APIs

    Snapshot tenant configuration as JSON and monitor it for drift. The admin center experience is in preview.

  33. Entra IDPreview

    Hybrid join using Entra Kerberos

    Windows devices can become hybrid joined at provisioning, without Entra Connect device sync or AD FS.

  34. March 2026

  35. Entra IDGA

    Synced passkeys and passkey profiles

    Passkeys in password managers and phone platforms are supported, with different passkey rules per group.

  36. February 2026

  37. Entra IDGA

    External MFA

    Third-party MFA providers become a proper authentication method, replacing custom controls.

  38. January 2026

  39. Entra IDGA

    Source of Authority conversion for users

    Switch an individual AD-synced user to cloud-managed without recreating it.

Each entry links to Microsoft's own announcement. Details can change after publication, so check the source before acting.