Microsoft’s identity platform continues its rapid evolution, with late July 2026 bringing a wave of updates that touch every corner of the Entra ecosystem. From passkeys reaching general availability on Windows to mandatory AI agent identities, from network-layer data loss prevention to deeper threat detection — these updates collectively push Entra ID toward a passwordless, agent-centric, network-aware Zero Trust control plane.
Let’s break down what’s new, what changed, and what your organization should do about it.
1. Entra Passkeys on Windows Reach General Availability (MC1282568)
Announced: July 20, 2026 (updated timeline) Source: M365 Message Center MC1282568
Microsoft Entra passkeys on Windows are now generally available for most tenants in Worldwide and GCC. This capability, previously in public preview (MC1247893), allows users to create device-bound passkeys stored in the Windows Hello container and authenticate using Windows Hello biometrics or PIN.
What’s Changed with GA
The most significant change: passkeys on Windows no longer require explicit opt-in through Windows Hello AAGUID allow-listing in a passkey (FIDO2) profile. If your authentication methods policy allows device-bound passkeys, they simply work.
This expands passwordless authentication to Windows devices that aren’t Microsoft Entra-joined or registered — covering corporate-managed, personal, and shared device scenarios.
Updated GCC High/DoD Timeline
The timeline for sovereign clouds has been revised:
- Worldwide, GCC: Rollout completed by mid-June 2026
- GCC High, DoD: Rollout begins early October 2026 (previously September), completes by late October 2026 (previously late September)
Why This Matters
With passkeys becoming the default authentication method in Entra ID starting September 1, 2026, and Microsoft-provided SMS/voice being retired by February 1, 2027, having Windows fully supported is critical. This GA removes the last platform gap — Windows now joins iOS, Android, and macOS in offering native passkey support through Microsoft’s identity platform.
Action items:
- Validate that your passkey (FIDO2) authentication method policy is configured
- Update user documentation to include Windows passkey enrollment
- For GCC High/DoD environments, plan for October 2026 readiness
2. Copilot Studio Now Mandatorily Creates Entra Agent IDs
Announced: July 2026 Source: Microsoft Learn — Copilot Studio Agent IDs
Starting July 2026, Microsoft Copilot Studio automatically creates a Microsoft Entra Agent ID for every new agent. The previous ability to opt out at the environment level has been removed — all new agents must have Agent IDs.
How It Works
When the first agent is created in a tenant after the rollout, a “Microsoft Copilot Studio agent identity blueprint” is added. This blueprint serves as the template for all subsequent agent identities. Each agent gets:
- Audit logging in Entra ID — all authentication activity is tracked
- Agent lifecycle management integrated with Entra ID Governance
- Connector permission visibility — admins can see what each agent can do without opening Power Platform admin center
- Conditional Access policy targeting — apply network location, device compliance, or risk conditions to agents
Existing agents created before July 2026 continue using app registrations and will be migrated to Agent IDs in the future.
Why This Matters
This is a pivotal shift in how AI agents are managed in the enterprise. By making Agent IDs mandatory and automatic, Microsoft ensures that every AI agent has a governed identity — no more shadow agents operating outside central IT visibility.
For identity teams, this means AI agents are now part of your core IAM scope. You need to:
- Define naming conventions and ownership for agent identities
- Establish lifecycle governance (creation, access reviews, decommissioning)
- Apply Conditional Access policies to agents just as you do for users
- Include agents in access reviews and entitlement management
3. Entra Internet Access & Private Access: Major July Wave
Announced: July 20, 2026 Source: Tech Community Blog — Secure AI, web, and private apps with Zero Trust
Microsoft delivered a significant update to Entra Internet Access and Entra Private Access, with new capabilities in both public preview and general availability.
Public Preview: AI-Aware Network Security
Network Data Loss Prevention (DLP): Microsoft Purview data security now extends to the network layer through Entra Internet Access. This means you can:
- Discover sensitive content in risky AI and cloud applications
- Block unsafe sharing — including file uploads, AI prompts, and AI responses
- Apply context-aware controls based on identity and activity
This is significant for organizations concerned about sensitive data leaking through AI tools. Instead of relying solely on application-level DLP, network-level enforcement catches data movement regardless of which app or agent is involved.
Entra Network Controls for Agents: Network controls now apply to AI agents — including Copilot Studio agents, agents running on user endpoint devices, and local agents. These controls can:
- Identify unsanctioned AI usage
- Restrict agent connections to approved web destinations only
- Filter risky file movement
- Block malicious prompt-based attacks before they lead to harmful actions
Custom Acquire and Agentic Acquire: New traffic profile capabilities enable side-by-side deployment of Global Secure Access for AI Gateway and Agentic scenarios alongside other vendors — no need to rip and replace existing infrastructure.
Windows 365 for Agents Integration: Agentic Cloud PCs now integrate with the Global Secure Access platform, providing enterprise-grade network security including traffic monitoring, web filtering, and threat blocking on agentic sessions.
General Availability: Broader Coverage
Browser-Based Access to Internet Resources: Entra Internet Access now extends secure web access to kiosk and BYOD devices using PAC file-based proxy configuration — no client installation required for basic web access scenarios.
BYOD with Client in Private Access: Zero Trust enforcement for unmanaged devices is now GA. Employees and contractors can securely access private apps without compromising security or user experience. This removes the previous requirement for Windows devices to be domain-joined.
Shadow MCP Visibility: Perhaps the most intriguing new GA capability — advanced monitoring and analysis of MCP (Model Context Protocol) traffic between client MCPs on devices and remote MCP servers. This provides:
- Visibility into which MCP servers are being used
- What tools and resources they expose
- How those tools are invoked
This is the identity-security equivalent of shadow IT discovery, but for the AI era. As MCP adoption grows, knowing which servers your users (and agents) are connecting to becomes critical for governing AI usage.
Why This Matters
These updates position Entra as a full SASE platform — not just identity, but identity-integrated network security. The convergence of DLP, ZTNA, and AI agent governance under a single identity-aware control plane is a strategic shift.
For enterprises, this means:
- Evaluate whether Entra Internet/Private Access can replace existing ZTNA/DLP tools
- Pilot network DLP for AI traffic — this is a new capability with no direct equivalent in most stacks
- Use Shadow MCP Visibility to audit current MCP usage in your environment
4. Defender for Identity: Identity Risk Score GA
Announced: June 2026 (GA) Source: Microsoft Learn — Defender for Identity What’s New
The identity risk score is now generally available. This score ranges from 0 to 100 and reflects how likely an identity is to be compromised and how much damage a compromise could cause, based on the identity’s criticality level and privileged role assignments.
The Risk Score tab on the Identity page in Microsoft Defender provides:
- Detailed breakdown of risk factors
- Percentile comparison against similar identities
- Risk trends over time
Why This Matters
A GA identity risk score provides a consistent, quantifiable metric that can drive policies across Entra Conditional Access, Defender for Identity, and other Microsoft 365 components. Instead of reacting to discrete alerts, security teams can:
- Define policies like “block or step-up authentication if identity risk score exceeds X for privileged roles”
- Track identity risk as a KPI over time
- Prioritize remediation based on numeric risk levels
- Feed risk scores into SIEM/SOAR for automated response
This shifts identity security from reactive alert-handling toward continuous risk management.
5. New Defender for Identity Security Alerts
Announced: June 2026 Source: Microsoft Learn — Defender for Identity What’s New
Microsoft added a substantial set of new security alerts across multiple identity systems:
New Entra ID Alerts:
- Anomalous activity following Global Administrator elevation — detects suspicious behavior after admin privilege escalation
- Reciprocal Temporary Access Pass creation between users — flags potential privilege abuse through TAP exchange
- Suspicious service principal sign-in following credential addition — catches credential stuffing on service principals
- Suspicious bulk user deletion via scripted activity — detects mass user removal attempts
- Suspicious removal of privileged app role assignment through Graph API — flags privilege stripping
- Suspicious sign-in by a user exhibiting a spike in account update activity — correlates sign-in anomalies with directory changes
- User exhibiting spike in distinct application-resource access combinations — identifies broad resource access patterns
New Active Directory Alerts:
- DCSync attack (replication of directory services) — detects DCSync replication attempts
- Suspicious Entra Connect account authentication — flags anomalous authentication by sync accounts
New Other IdP Alerts:
- SailPoint ISC suspected brute-force attack — extends detection to third-party IGA platforms
Why This Matters
These alerts significantly expand Defender for Identity’s coverage across hybrid and multi-identity-provider environments. The SailPoint integration is particularly noteworthy — it signals Microsoft’s intent to be the unified threat detection layer across the entire identity ecosystem, not just Entra ID and Active Directory.
The new Entra ID alerts target sophisticated attack patterns that traditional logging would miss: TAP abuse, Graph API privilege manipulation, and credential-based service principal attacks. These are exactly the techniques attackers use against modern identity infrastructure.
6. Entra RBAC Role Updates: AI and Agent Roles
Announced: June 2026 Source: Microsoft Learn — Entra RBAC What’s New
Microsoft updated several Entra built-in roles to reflect the growing importance of AI and agent management:
- AI Administrator — updated (June 2026)
- AI Reader — updated (June 2026)
- Agent ID Administrator — updated (June 2026)
- Agent ID Developer — updated (June 2026)
Why This Matters
These role updates formalize AI and agent management as distinct operational responsibilities within Entra ID. They enable separation of duties:
- Developers can build agents (Agent ID Developer) without full directory admin rights
- AI administrators can govern AI policies (AI Administrator) without direct application ownership
- Security teams can review AI configurations (AI Reader) without modification privileges
- Agent identity lifecycle can be managed (Agent ID Administrator) independently from general identity admin
For enterprises, this means updating RACI models and defining where these roles sit in your organization — whether that’s the IAM team, a dedicated AI governance function, or distributed across business units.
7. Defender for Identity: Identity Explorer & Custom Account Correlation Rules
Announced: April 2026 (Public Preview) Source: Microsoft Learn — Defender for Identity What’s New
Two capabilities that launched in preview earlier in 2026 deserve attention:
Identity Explorer (Preview): A new tab on the Identity page for customers with a Microsoft Sentinel Data Lake license. It uses the hunting graph to visualize identity attack paths and exposure scenarios as interactive graphs. Predefined identity scenarios help discover:
- Lateral movement paths
- Privilege escalation routes
- Credential-access risks
Custom Account Correlation Rules (Preview): Link accounts that belong to the same identity — even when they don’t share strong identifiers like account ID, SID, or UPN. Rules can be defined based on UPN prefix, UPN suffix, or domain UPN, making it possible to correlate privileged accounts with unique naming conventions.
Strategic Takeaways: What This All Means Together
Looking at these updates as a whole, a clear strategic picture emerges:
1. Entra ID Is Becoming the Control Plane for Everything — Not Just Users
AI agents, network traffic, data loss prevention, and threat detection are all converging under Entra ID’s umbrella. Organizations that treat Entra as “just a directory” are missing the strategic direction.
2. Secure-by-Default Is Replacing Configure-Your-Security
Passkeys on Windows work without opt-in. Agent IDs are created automatically. Backup and recovery is always on. Microsoft is removing the configuration burden — and the configuration risk — by making security the default.
3. AI Agent Governance Is No Longer Optional
With mandatory Agent IDs, agent-specific RBAC roles, agent network controls, and agent Conditional Access policies, Microsoft has built a complete governance framework for AI agents. The question isn’t whether to govern agents — it’s how quickly you can operationalize that governance.
4. Identity Risk Is Now Quantifiable
The GA identity risk score transforms identity security from a qualitative discussion (“we have some risky accounts”) to a quantitative one (“12% of our privileged identities have a risk score above 75”). This enables executive reporting, KPI tracking, and risk-based policy automation.
5. Network Security Is Identity-Aware
With Network DLP, Shadow MCP Visibility, and agent network controls, Entra is extending Zero Trust to the network layer — tied to identity context. This is the SASE vision realized through identity, not through separate network appliances.
Recommended Actions
| Priority | Action | Timeline |
|---|---|---|
| Immediate | Inventory tenants still using SMS/voice MFA; plan passkey migration | Before September 1, 2026 |
| Immediate | Audit current MCP usage in your environment using Shadow MCP Visibility | This week |
| Short-term | Define naming conventions and ownership for Entra Agent IDs | Within 30 days |
| Short-term | Assign AI Administrator and Agent ID Administrator roles | Within 30 days |
| Short-term | Update break-glass and helpdesk procedures for passwordless | Within 60 days |
| Medium-term | Pilot Network DLP for AI traffic in Entra Internet Access | Within 90 days |
| Medium-term | Integrate identity risk scores into SOC dashboards and Conditional Access | Within 90 days |
| Medium-term | Evaluate Entra Internet/Private Access vs. existing ZTNA/DLP stack | Q3 2026 |
Stay Informed
Follow Kevin Kaminski on X for daily updates on Microsoft Entra ID, identity security, and the evolving AI governance landscape. Big Hat Group Inc. provides consulting services to help organizations navigate these transitions — from passkey migration strategies to AI agent governance frameworks.
Big Hat Group Inc. is a 20+ year Microsoft partner specializing in AI and cloud identity consulting.