Change feed
What Microsoft has changed in Entra ID, Intune and Azure, newest first. Items that need you to do something are flagged. For dated retirements, see the deadline timeline.
29 changes
October 2026
-
IntuneNew
Deployment plans: staged rollouts in rings
Stage Win32 apps, catalog apps, Settings Catalog and endpoint security policies across rings with controlled timing.
-
IntunePreview
Client-driven compliance evaluation
Supported Windows devices ask Intune to re-evaluate compliance as soon as a signal such as BitLocker or the firewall changes.
-
IntuneChangeaction needed
Multi Admin Approval now applies to Microsoft Graph calls
Scripts and apps that change MAA-protected resources without approval now get HTTP 403. Update them or add a temporary exclusion.
-
IntuneNew
Windows 11 26H2 security baseline
A new baseline version is available. Existing profiles don't update automatically.
-
IntuneChangeaction needed
iOS/iPadOS 18 is now the minimum
Standard device management, Company Portal and app protection now require iOS/iPadOS 18 or later.
September 2026
-
Entra IDRetirementaction needed
Microsoft-provided SMS and voice MFA retiring
Text and phone call authentication ends for most users on 1 February 2027. Passkeys are being switched on for affected users.
-
IntuneNew
Unattended Remote Help for Windows
Helpdesk agents can connect to physical Windows devices with nobody at the keyboard. Scope the role carefully.
-
IntuneNew
Apple VPP apps through declarative device management
Set the management type to DDM when uploading a VPP token. Needs iOS/iPadOS 17.2+ or macOS 26+.
-
IntuneNew
eSIM management for corporate Android
Activate and remove eSIMs, and choose whether they're removed on wipe, on corporate-owned Android devices.
August 2026
-
IntuneNew
Custom compliance for macOS
A script reports values and a JSON rules file defines what's compliant, as on Windows and Linux.
-
IntunePreview
Controlled configuration for Defender Antivirus
Lets Intune or Defender for Endpoint own Defender settings so Group Policy and other sources stop overriding them.
July 2026
-
Entra IDChangeaction needed
Authenticator blocks jailbroken and rooted devices
Work and school accounts can't be added or used in Authenticator on modified phones. Brief the service desk.
-
Entra IDGA
BYOD Windows access with Entra registration
Users, partners and internal guests can reach corporate resources from personal Windows PCs using Entra registration.
-
Entra IDChangeaction needed
Phased move from Connect Sync to Cloud Sync
Tenants are being notified of their own transition timeline. Inventory your sync features and pilot Cloud Sync.
-
IntuneChange
Intune advanced features coming to Microsoft 365 E3 and E5
Remote Help, Endpoint Privilege Management, Cloud PKI and more move into the main licences.
June 2026
-
Entra IDGA
Entra Backup and Recovery
Daily, tamper-proof backups of key directory objects with seven days of history, difference reports and restore.
-
Entra IDGA
Account Discovery
Reports accounts inside connected apps, including orphaned accounts with no Entra assignment.
-
Entra IDPreview
Soft delete for device objects
Deleted devices become recoverable, with their identity and BitLocker keys intact, for a retention period.
-
Entra IDGA
Cross-tenant group sync
Sync security groups and memberships from a source tenant into target tenants alongside users.
-
Entra IDChangeaction needed
Hard match blocked for users with Entra roles
Sync can no longer take over a cloud account that holds an Entra role by hard matching.
May 2026
-
Entra IDChange
System-preferred authentication picks the first factor too
Users with a passkey may sign in without a password prompt, and registration campaigns can prompt for passkeys.
-
Entra IDGA
Entra Agent ID
First-class identities for AI agents, with sponsors, and Conditional Access for agents in preview.
April 2026
-
Entra IDGA
Configurable token lifetimes
Set access, ID and SAML token lifetimes per application.
-
Entra IDGA
Authentication context on PIM activation
PIM can require a Conditional Access authentication context every time a role is activated.
-
Entra IDGA
Tenant configuration management APIs
Snapshot tenant configuration as JSON and monitor it for drift. The admin center experience is in preview.
-
Entra IDPreview
Hybrid join using Entra Kerberos
Windows devices can become hybrid joined at provisioning, without Entra Connect device sync or AD FS.
March 2026
-
Entra IDGA
Synced passkeys and passkey profiles
Passkeys in password managers and phone platforms are supported, with different passkey rules per group.
February 2026
-
Entra IDGA
External MFA
Third-party MFA providers become a proper authentication method, replacing custom controls.
January 2026
-
Entra IDGA
Source of Authority conversion for users
Switch an individual AD-synced user to cloud-managed without recreating it.
No changes match those filters.
Each entry links to Microsoft's own announcement. Details can change after publication, so check the source before acting.