Just when you thought the Entra ID news cycle might slow down before the September 1 passkeys-by-default rollout, Microsoft has dropped another batch of updates. This time the focus is on removing friction from phishing-resistant authentication, extending Zero Trust to AI agent traffic, and giving admins a bit more breathing room on SSPR enforcement. Here’s what changed in the week leading up to August 8, 2026.
1. Passkeys Can Now Be Registered as Your First MFA Method (MC1450133)
This is one of those changes that makes you ask, “Wait, that wasn’t already the case?” Until now, Microsoft Entra ID required users to register a weaker authentication method — like SMS, voice, or a Temporary Access Pass — before they could enroll a passkey. It was a chicken-and-egg problem: organizations wanting to go passwordless from day one had to first provision a method they were actively trying to eliminate.
That requirement is gone. Users can now register a passkey or passwordless sign-in method as their very first MFA factor, with no prerequisite weaker method needed.
Why This Matters
This change directly supports the upcoming September 1 passkeys-by-default rollout. New users joining an organization can go straight to passkey registration during their initial sign-in experience. No more enrolling SMS “just to get started” and then migrating to passkeys later. The friction is gone.
For organizations building greenfield Entra ID tenants or onboarding new cohorts of users, this simplifies the authentication setup flow dramatically. It also aligns with the broader industry push toward phishing-resistant authentication as the baseline, not the upgrade.
Key Details
- Rollout: Phased from January 2026 through November 2027
- Admin action: No configuration changes required — but review your authentication method policy and registration campaign settings to ensure they reflect this new capability
- Message Center: MC1450133
2. Windows Hello for Business and macOS Platform SSO Become Standalone MFA Factors (MC1450134)
Starting in October 2026, Microsoft Entra ID will recognize Windows Hello for Business and macOS Platform SSO as standalone MFA factors. This means users on managed Windows and macOS devices can satisfy MFA requirements through their device’s built-in biometrics or PIN — without needing to separately register a passkey or other MFA method.
Why This Matters
If your organization has already deployed Windows Hello for Business or macOS Platform SSO across managed devices, you’ve essentially had MFA-capable authentication this whole time — but Entra ID didn’t fully recognize it as such for all Conditional Access scenarios. That changes in October.
For admins, this means:
- Simpler onboarding flows for managed device users
- Fewer registered methods to manage and audit
- Conditional Access policies that require MFA can be satisfied by the platform credential itself
- No additional passkey enrollment needed for users who already have Windows Hello or macOS Platform SSO
Key Details
- Timeline: Starting October 2026
- Admin action: No configuration changes needed, but update onboarding documentation and review your Conditional Access authentication strength policies to confirm these methods are accepted where intended
- Message Center: MC1450134
3. Global Secure Access MCP Firewall — Zero Trust for AI Agent Traffic (Preview)
As AI agents proliferate across enterprise environments, a new attack surface has emerged: the Model Context Protocol (MCP) traffic flowing between AI agents and remote MCP servers. Microsoft’s answer is the Global Secure Access MCP firewall, now in preview.
What It Does
The MCP firewall is a network-based, identity-centric security control that inspects MCP traffic (JSON-RPC 2.0 over streamable HTTP and Server-Sent Events) and enforces Allow or Block decisions at the Global Secure Access edge. It extends Zero Trust to the MCP protocol layer — without requiring changes to MCP clients, hosts, or servers.
Key capabilities include:
- Block all MCP traffic tenant-wide while you review and approve trusted servers
- Allow/block MCP servers by URL pattern — create allow-lists and deny-lists
- Selective primitive control — allow or block Tools, Resources, or Prompt templates on a per-server basis
- Method and protocol version enforcement — block unencrypted HTTP connections, enforce protocol hygiene by blocking outdated MCP versions
Prerequisites
This is a preview capability with specific requirements:
- Microsoft Entra tenant with Internet Access license
- Global Secure Access Administrator and Conditional Access Administrator roles
- Entra-joined device with the Global Secure Access client installed
- TLS inspection enabled (required because MCP messages travel in the encrypted payload)
Configuration Flow
- Create an MCP policy in the Entra admin center under Global Secure Access > Secure > MCP policies (Preview)
- Link the MCP policy to a security profile
- Configure a Conditional Access policy that enforces the security profile
Why This Matters
If your organization is using AI agents — and increasingly, most are — MCP traffic is a blind spot in your security stack. Agents can call external tools, access resources, and execute prompts on remote servers, all without traditional network controls having visibility into what’s happening. The MCP firewall closes that gap by bringing the same Zero Trust principles we apply to human identity to AI agent communications.
Cisco’s Secure Access team announced a similar MCP semantic inspection capability earlier this year, indicating this is becoming a competitive space across SSE vendors. Microsoft’s approach is notable for its deep integration with Conditional Access and Entra ID identity signals.
4. Token Protection for Web Apps — New Deployment Guide (Preview)
Microsoft has published a new deployment guide for enforcing Token Protection with Conditional Access for browser-based applications accessing Azure Resource Manager. This extends token replay protection to browser sessions, an area where token theft has been historically harder to prevent.
What’s Covered
The guide walks through configuring Token Protection for supported browser-based applications that access Azure Resource Manager. Key characteristics:
- Scope: Limited to specifically listed apps, platforms, browsers, and device configurations
- Requirements: Entra ID P1, plus additional Windows or macOS device setup
- Recommendation: Start in report-only mode, run a pilot, then enforce
- Status: Preview — browser-based application support is explicitly not yet GA
Why This Matters
Token theft and replay attacks remain a significant threat vector. Token Protection binds sign-in session tokens to the originating device, making stolen tokens useless if they’re replayed from a different machine. Until now, this protection was primarily available for native client applications. Extending it to browser-based apps — even in preview — closes a meaningful gap in the enforcement model.
For organizations using Azure Resource Manager extensively through browser portals, this is worth evaluating in a pilot capacity. The report-only mode recommendation is sensible: browser app compatibility varies significantly across platforms and configurations.
5. SSPR Enforcement Dates Moved — More Time to Get Users Registered
If you’ve been tracking the SSPR change requiring explicitly registered authentication methods, you now have more time. Microsoft has rescheduled the key milestones:
| Milestone | Previous Date | New Date |
|---|---|---|
| Registration campaign begins | August 6, 2026 | October 5, 2026 |
| Only registered methods accepted (enforcement) | September 7, 2026 | November 9, 2026 |
Why This Matters
After November 9, 2026, SSPR will no longer accept directory-sourced contact information (phone numbers, email addresses stored as user object properties) for password reset verification. Only explicitly registered authentication methods will work. The registration campaign that precedes enforcement will prompt affected users to register methods after sign-in.
The extra time is welcome, but don’t squander it. The November 9 enforcement date is now just three months away. Organizations should:
- Identify users who rely on directory-sourced contact info for SSPR
- Run the registration campaign when it starts October 5
- Communicate the change to users well in advance
- Ensure every user has at least one registered authentication method before November 9
6. Agent 365 Licensing Requirement Clarified for Conditional Access for Agents
Microsoft has updated the documentation for Conditional Access for agents to explicitly state that a Microsoft Agent 365 license is required. This replaces the previous “Starting soon” wording with a direct requirement.
Licensing Details
Agent 365 is:
- Included with Microsoft 365 E7
- Available as an add-on to Microsoft E5, A5, Business Premium, or Defender Suite plus Purview Suite
Why This Matters
If your organization is using or planning to use Entra Agent ID with Conditional Access policies, you need to verify your licensing. The documentation update also clarifies that both Entra Conditional Access for Agents and Entra ID Protection for Agents require Agent 365 licensing. This is a guidance clarification rather than a new product launch — the requirement was telegraphed earlier — but the “Starting soon” language is now gone.
7. SCIM Provisioning Documentation Gets a Navigation Overhaul
Multiple SCIM provisioning documentation pages have been updated with new navigation labels and workflows that align with the current Entra admin center experience:
- “Show advanced options” is now the Advanced Options dropdown
- “Edit attribute list for ScimOnPremises” is now Edit target User attributes / Edit schema
- Expression Builder is now accessed from the left navigation menu instead of Attribute Mapping > Advanced Options
- Scoping filters wizard replaces the former Mappings-based steps for assignment-based and attribute-based filtering
- Page dates updated from March 2025 to August 6, 2026
- Provisioning logs documentation now includes Microsoft MCP Server for Enterprise integration for natural-language, read-only analysis via delegated permissions
Why This Matters
If you’re following older documentation to configure SCIM provisioning, you’ll find the navigation paths have changed. The updates bring the documentation in line with the current portal experience. Admins who frequently configure provisioning jobs should bookmark the updated pages.
Key Dates Summary
| Date | Event |
|---|---|
| October 5, 2026 | SSPR registration campaign begins (moved from August 6) |
| October 2026 | Windows Hello and macOS Platform SSO recognized as standalone MFA factors |
| October 30, 2026 | Telecom partner configuration opens for SMS/voice continuation |
| November 3, 2026 | MemberOf rule operator retirement (dynamic groups and AUs stop processing) |
| November 9, 2026 | SSPR enforcement — only registered methods accepted (moved from September 7) |
| January 2026 – November 2027 | Passkeys-as-first-MFA phased rollout |
| February 1, 2027 | Microsoft-provided SMS/voice authentication retired |
Action Items for Admins
- Update onboarding documentation to reflect that passkeys can now be the first MFA method — remove any guidance that says users need to enroll a weaker method first
- Review Conditional Access authentication strength policies for Windows Hello and macOS Platform SSO ahead of the October 2026 standalone MFA recognition
- Evaluate the MCP firewall if your organization uses AI agents with MCP — verify you meet the prerequisites (Internet Access license, GSA client, TLS inspection)
- Pilot Token Protection for web apps in report-only mode if you use Azure Resource Manager through browser portals
- Revise SSPR rollout plans with the updated October 5 and November 9 dates
- Verify Agent 365 licensing if using or planning Conditional Access for agents
- Bookmark updated SCIM provisioning docs — the navigation paths have changed
Stay Informed
The pace of Entra ID changes continues to accelerate as the September 1 passkeys-by-default milestone approaches. Between authentication evolution, AI agent security, and documentation overhauls, there’s a lot to track. We’ll continue providing actionable analysis as new announcements emerge.
Follow the conversation on X at https://x.com/kkaminsk for real-time updates and analysis.
Big Hat Group Inc. is a Microsoft partner with 20+ years of experience helping organizations navigate identity and security transformations. Contact us to discuss how these changes affect your environment and how we can help you plan your migration.