Microsoft’s identity platform continues its rapid evolution, with late July 2026 bringing a wave of updates that touch every corner of the Entra ecosystem. From passkeys reaching general availability on Windows to mandatory AI agent identities, from network-layer data loss prevention to deeper threat detection — these updates collectively push Entra ID toward a passwordless, agent-centric, network-aware Zero Trust control plane.

Let’s break down what’s new, what changed, and what your organization should do about it.

1. Entra Passkeys on Windows Reach General Availability (MC1282568)

Announced: July 20, 2026 (updated timeline) Source: M365 Message Center MC1282568

Microsoft Entra passkeys on Windows are now generally available for most tenants in Worldwide and GCC. This capability, previously in public preview (MC1247893), allows users to create device-bound passkeys stored in the Windows Hello container and authenticate using Windows Hello biometrics or PIN.

What’s Changed with GA

The most significant change: passkeys on Windows no longer require explicit opt-in through Windows Hello AAGUID allow-listing in a passkey (FIDO2) profile. If your authentication methods policy allows device-bound passkeys, they simply work.

This expands passwordless authentication to Windows devices that aren’t Microsoft Entra-joined or registered — covering corporate-managed, personal, and shared device scenarios.

Updated GCC High/DoD Timeline

The timeline for sovereign clouds has been revised:

  • Worldwide, GCC: Rollout completed by mid-June 2026
  • GCC High, DoD: Rollout begins early October 2026 (previously September), completes by late October 2026 (previously late September)

Why This Matters

With passkeys becoming the default authentication method in Entra ID starting September 1, 2026, and Microsoft-provided SMS/voice being retired by February 1, 2027, having Windows fully supported is critical. This GA removes the last platform gap — Windows now joins iOS, Android, and macOS in offering native passkey support through Microsoft’s identity platform.

Action items:

  • Validate that your passkey (FIDO2) authentication method policy is configured
  • Update user documentation to include Windows passkey enrollment
  • For GCC High/DoD environments, plan for October 2026 readiness

2. Copilot Studio Now Mandatorily Creates Entra Agent IDs

Announced: July 2026 Source: Microsoft Learn — Copilot Studio Agent IDs

Starting July 2026, Microsoft Copilot Studio automatically creates a Microsoft Entra Agent ID for every new agent. The previous ability to opt out at the environment level has been removed — all new agents must have Agent IDs.

How It Works

When the first agent is created in a tenant after the rollout, a “Microsoft Copilot Studio agent identity blueprint” is added. This blueprint serves as the template for all subsequent agent identities. Each agent gets:

  • Audit logging in Entra ID — all authentication activity is tracked
  • Agent lifecycle management integrated with Entra ID Governance
  • Connector permission visibility — admins can see what each agent can do without opening Power Platform admin center
  • Conditional Access policy targeting — apply network location, device compliance, or risk conditions to agents

Existing agents created before July 2026 continue using app registrations and will be migrated to Agent IDs in the future.

Why This Matters

This is a pivotal shift in how AI agents are managed in the enterprise. By making Agent IDs mandatory and automatic, Microsoft ensures that every AI agent has a governed identity — no more shadow agents operating outside central IT visibility.

For identity teams, this means AI agents are now part of your core IAM scope. You need to:

  • Define naming conventions and ownership for agent identities
  • Establish lifecycle governance (creation, access reviews, decommissioning)
  • Apply Conditional Access policies to agents just as you do for users
  • Include agents in access reviews and entitlement management

3. Entra Internet Access & Private Access: Major July Wave

Announced: July 20, 2026 Source: Tech Community Blog — Secure AI, web, and private apps with Zero Trust

Microsoft delivered a significant update to Entra Internet Access and Entra Private Access, with new capabilities in both public preview and general availability.

Public Preview: AI-Aware Network Security

Network Data Loss Prevention (DLP): Microsoft Purview data security now extends to the network layer through Entra Internet Access. This means you can:

  • Discover sensitive content in risky AI and cloud applications
  • Block unsafe sharing — including file uploads, AI prompts, and AI responses
  • Apply context-aware controls based on identity and activity

This is significant for organizations concerned about sensitive data leaking through AI tools. Instead of relying solely on application-level DLP, network-level enforcement catches data movement regardless of which app or agent is involved.

Entra Network Controls for Agents: Network controls now apply to AI agents — including Copilot Studio agents, agents running on user endpoint devices, and local agents. These controls can:

  • Identify unsanctioned AI usage
  • Restrict agent connections to approved web destinations only
  • Filter risky file movement
  • Block malicious prompt-based attacks before they lead to harmful actions

Custom Acquire and Agentic Acquire: New traffic profile capabilities enable side-by-side deployment of Global Secure Access for AI Gateway and Agentic scenarios alongside other vendors — no need to rip and replace existing infrastructure.

Windows 365 for Agents Integration: Agentic Cloud PCs now integrate with the Global Secure Access platform, providing enterprise-grade network security including traffic monitoring, web filtering, and threat blocking on agentic sessions.

General Availability: Broader Coverage

Browser-Based Access to Internet Resources: Entra Internet Access now extends secure web access to kiosk and BYOD devices using PAC file-based proxy configuration — no client installation required for basic web access scenarios.

BYOD with Client in Private Access: Zero Trust enforcement for unmanaged devices is now GA. Employees and contractors can securely access private apps without compromising security or user experience. This removes the previous requirement for Windows devices to be domain-joined.

Shadow MCP Visibility: Perhaps the most intriguing new GA capability — advanced monitoring and analysis of MCP (Model Context Protocol) traffic between client MCPs on devices and remote MCP servers. This provides:

  • Visibility into which MCP servers are being used
  • What tools and resources they expose
  • How those tools are invoked

This is the identity-security equivalent of shadow IT discovery, but for the AI era. As MCP adoption grows, knowing which servers your users (and agents) are connecting to becomes critical for governing AI usage.

Why This Matters

These updates position Entra as a full SASE platform — not just identity, but identity-integrated network security. The convergence of DLP, ZTNA, and AI agent governance under a single identity-aware control plane is a strategic shift.

For enterprises, this means:

  • Evaluate whether Entra Internet/Private Access can replace existing ZTNA/DLP tools
  • Pilot network DLP for AI traffic — this is a new capability with no direct equivalent in most stacks
  • Use Shadow MCP Visibility to audit current MCP usage in your environment

4. Defender for Identity: Identity Risk Score GA

Announced: June 2026 (GA) Source: Microsoft Learn — Defender for Identity What’s New

The identity risk score is now generally available. This score ranges from 0 to 100 and reflects how likely an identity is to be compromised and how much damage a compromise could cause, based on the identity’s criticality level and privileged role assignments.

The Risk Score tab on the Identity page in Microsoft Defender provides:

  • Detailed breakdown of risk factors
  • Percentile comparison against similar identities
  • Risk trends over time

Why This Matters

A GA identity risk score provides a consistent, quantifiable metric that can drive policies across Entra Conditional Access, Defender for Identity, and other Microsoft 365 components. Instead of reacting to discrete alerts, security teams can:

  • Define policies like “block or step-up authentication if identity risk score exceeds X for privileged roles”
  • Track identity risk as a KPI over time
  • Prioritize remediation based on numeric risk levels
  • Feed risk scores into SIEM/SOAR for automated response

This shifts identity security from reactive alert-handling toward continuous risk management.

5. New Defender for Identity Security Alerts

Announced: June 2026 Source: Microsoft Learn — Defender for Identity What’s New

Microsoft added a substantial set of new security alerts across multiple identity systems:

New Entra ID Alerts:

  • Anomalous activity following Global Administrator elevation — detects suspicious behavior after admin privilege escalation
  • Reciprocal Temporary Access Pass creation between users — flags potential privilege abuse through TAP exchange
  • Suspicious service principal sign-in following credential addition — catches credential stuffing on service principals
  • Suspicious bulk user deletion via scripted activity — detects mass user removal attempts
  • Suspicious removal of privileged app role assignment through Graph API — flags privilege stripping
  • Suspicious sign-in by a user exhibiting a spike in account update activity — correlates sign-in anomalies with directory changes
  • User exhibiting spike in distinct application-resource access combinations — identifies broad resource access patterns

New Active Directory Alerts:

  • DCSync attack (replication of directory services) — detects DCSync replication attempts
  • Suspicious Entra Connect account authentication — flags anomalous authentication by sync accounts

New Other IdP Alerts:

  • SailPoint ISC suspected brute-force attack — extends detection to third-party IGA platforms

Why This Matters

These alerts significantly expand Defender for Identity’s coverage across hybrid and multi-identity-provider environments. The SailPoint integration is particularly noteworthy — it signals Microsoft’s intent to be the unified threat detection layer across the entire identity ecosystem, not just Entra ID and Active Directory.

The new Entra ID alerts target sophisticated attack patterns that traditional logging would miss: TAP abuse, Graph API privilege manipulation, and credential-based service principal attacks. These are exactly the techniques attackers use against modern identity infrastructure.

6. Entra RBAC Role Updates: AI and Agent Roles

Announced: June 2026 Source: Microsoft Learn — Entra RBAC What’s New

Microsoft updated several Entra built-in roles to reflect the growing importance of AI and agent management:

  • AI Administrator — updated (June 2026)
  • AI Reader — updated (June 2026)
  • Agent ID Administrator — updated (June 2026)
  • Agent ID Developer — updated (June 2026)

Why This Matters

These role updates formalize AI and agent management as distinct operational responsibilities within Entra ID. They enable separation of duties:

  • Developers can build agents (Agent ID Developer) without full directory admin rights
  • AI administrators can govern AI policies (AI Administrator) without direct application ownership
  • Security teams can review AI configurations (AI Reader) without modification privileges
  • Agent identity lifecycle can be managed (Agent ID Administrator) independently from general identity admin

For enterprises, this means updating RACI models and defining where these roles sit in your organization — whether that’s the IAM team, a dedicated AI governance function, or distributed across business units.

7. Defender for Identity: Identity Explorer & Custom Account Correlation Rules

Announced: April 2026 (Public Preview) Source: Microsoft Learn — Defender for Identity What’s New

Two capabilities that launched in preview earlier in 2026 deserve attention:

Identity Explorer (Preview): A new tab on the Identity page for customers with a Microsoft Sentinel Data Lake license. It uses the hunting graph to visualize identity attack paths and exposure scenarios as interactive graphs. Predefined identity scenarios help discover:

  • Lateral movement paths
  • Privilege escalation routes
  • Credential-access risks

Custom Account Correlation Rules (Preview): Link accounts that belong to the same identity — even when they don’t share strong identifiers like account ID, SID, or UPN. Rules can be defined based on UPN prefix, UPN suffix, or domain UPN, making it possible to correlate privileged accounts with unique naming conventions.

Strategic Takeaways: What This All Means Together

Looking at these updates as a whole, a clear strategic picture emerges:

1. Entra ID Is Becoming the Control Plane for Everything — Not Just Users

AI agents, network traffic, data loss prevention, and threat detection are all converging under Entra ID’s umbrella. Organizations that treat Entra as “just a directory” are missing the strategic direction.

2. Secure-by-Default Is Replacing Configure-Your-Security

Passkeys on Windows work without opt-in. Agent IDs are created automatically. Backup and recovery is always on. Microsoft is removing the configuration burden — and the configuration risk — by making security the default.

3. AI Agent Governance Is No Longer Optional

With mandatory Agent IDs, agent-specific RBAC roles, agent network controls, and agent Conditional Access policies, Microsoft has built a complete governance framework for AI agents. The question isn’t whether to govern agents — it’s how quickly you can operationalize that governance.

4. Identity Risk Is Now Quantifiable

The GA identity risk score transforms identity security from a qualitative discussion (“we have some risky accounts”) to a quantitative one (“12% of our privileged identities have a risk score above 75”). This enables executive reporting, KPI tracking, and risk-based policy automation.

5. Network Security Is Identity-Aware

With Network DLP, Shadow MCP Visibility, and agent network controls, Entra is extending Zero Trust to the network layer — tied to identity context. This is the SASE vision realized through identity, not through separate network appliances.

PriorityActionTimeline
ImmediateInventory tenants still using SMS/voice MFA; plan passkey migrationBefore September 1, 2026
ImmediateAudit current MCP usage in your environment using Shadow MCP VisibilityThis week
Short-termDefine naming conventions and ownership for Entra Agent IDsWithin 30 days
Short-termAssign AI Administrator and Agent ID Administrator rolesWithin 30 days
Short-termUpdate break-glass and helpdesk procedures for passwordlessWithin 60 days
Medium-termPilot Network DLP for AI traffic in Entra Internet AccessWithin 90 days
Medium-termIntegrate identity risk scores into SOC dashboards and Conditional AccessWithin 90 days
Medium-termEvaluate Entra Internet/Private Access vs. existing ZTNA/DLP stackQ3 2026

Stay Informed

Follow Kevin Kaminski on X for daily updates on Microsoft Entra ID, identity security, and the evolving AI governance landscape. Big Hat Group Inc. provides consulting services to help organizations navigate these transitions — from passkey migration strategies to AI agent governance frameworks.

Big Hat Group Inc. is a 20+ year Microsoft partner specializing in AI and cloud identity consulting.