August 10, 2026, brings one of the most consequential Entra ID update days in recent memory. Microsoft Entra Tenant Governance reaches general availability — giving organizations a built-in control plane for multi-tenant security at scale. The August monthly roundup introduces five new Lifecycle Workflows capabilities. Defender XDR’s August monthly news adds AI agent posture risk assessment, GA agent protection, and prompt injection detection in email. And there’s a new GitHub Actions OIDC migration deadline that’s already passed. Here’s everything you need to know.

1. Microsoft Entra Tenant Governance Reaches General Availability

The headline announcement is the general availability of Microsoft Entra Tenant Governance, a built-in capability for centrally governing and securing multi-tenant environments at scale. Built on learnings from Microsoft’s response to the Midnight Blizzard nation-state attack, Tenant Governance moves organizations from reactive incident response to proactive, scalable multi-tenant management.

Four Pillars

Tenant Governance unifies four capabilities:

Related Tenants Discovery automatically identifies tenants connected to your organization using signals like B2B sign-in patterns, multitenant application consents, and shared billing relationships. This surfaces shadow IT tenants — test, demo, or employee-created tenants flying under central IT’s radar.

Governance Relationships establish directional, least-privileged cross-tenant delegated administration. A three-step handshake (invitation → request → acceptance) prevents accidental or malicious takeovers. Admins in the governing tenant sign in with their own accounts — no local or B2B admin accounts needed in governed tenants. The model supports one-to-many and many-to-one but not multi-tier arrangements.

Tenant Configuration Management lets you define configuration baselines across over 200 resource types spanning Microsoft Entra, Intune, Exchange Online, Teams, Purview, and Defender. Continuous drift monitoring runs every six hours, alerting you the moment a security setting changes. You can snapshot a compliant tenant and use it as the baseline for others.

Secure Tenant Creation controls which users can create new tenants and automatically establishes governance relationships with new add-on tenants. This ensures new tenants are governed from day one rather than discovered months later during a security audit.

What’s New Since Preview

Since the July 30 public preview, Microsoft has added increased limits on configuration monitors and snapshots (for ID Governance, Entra Suite, or E7 licensees), richer tenant discovery insights, new admin portal experiences for configuration monitoring (in preview), enhanced delegated admin capabilities for tenant switching, and expanded secure tenant creation to support legacy billing models including Enterprise Agreement and Pay-As-You-Go.

Multi-Tenant Agent Management

Of particular note for AI-forward organizations: Tenant Governance enables multi-tenant agent management (currently in preview, requires Microsoft Agent 365). Once a governance relationship is established, administrators can view agent inventory and activity, identify risky agents, and install or block agents in the governed tenant from the Microsoft 365 admin center. Defender and Sentinel multi-tenant management experiences also leverage these governance relationships.

Licensing

Tenant Governance is licensed per-administrator rather than per-user, making it more accessible for organizations managing large tenant estates. Two service levels are available: Basic and Premium. Multi-tenant agent management requires an Agent 365 license in the governed tenant. See the Tenant Governance licensing guide for details.

Getting Started

Review the Tenant Governance documentation, the new tenant estate architecture guide, and the deployment guide.

2. Five New Lifecycle Workflows Capabilities

The August monthly roundup from Yina Arenas — Microsoft’s new CVP and Chief Product Officer of Identity and Network Access — introduces five significant Lifecycle Workflows enhancements:

What-If Mode

Simulate workflow processing to discover which users are in the execution scope and troubleshoot potential issues — all without impacting users. This is the identity governance equivalent of Conditional Access report-only mode, and it’s equally valuable for safe rollout of automation.

Cancel Workflow Runs

Cancel queued or in-progress Lifecycle Workflows runs to prevent or contain the impact of automation errors or misconfigurations. Canceling a run cancels tasks that haven’t yet been processed; changes from completed tasks are not reversed. This gives admins a safety valve when a workflow goes sideways.

User Attribute Updates Task

Automatically set or clear user attributes when lifecycle events occur. Supported attributes include built-in user attributes and on-premises extension attributes for cloud-managed users, as well as directory extension attributes for both cloud-managed users and users synchronized from on-premises Active Directory. Administrators can configure up to 10 attribute updates per task, opening up scenarios like automatically setting department codes, clearing temporary access attributes during offboarding, or syncing extension attributes during transfers.

Expanded Dynamic Attributes for Custom Email Notifications

Lifecycle Workflows custom emails now support a new attribute format and an expanded set of dynamic attributes — including additional built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. This means personalized, context-rich email notifications without custom code.

Sponsorless Guest Cleanup

Automated detection and cleanup of sponsorless guest accounts via Lifecycle Workflows. This directly addresses a persistent problem in Microsoft 365 environments: guest accounts that accumulate over time as contractors leave, projects end, and sponsors move on. Workflows can now automatically detect guests without active sponsors and clean them up, reducing security and compliance risk.

3. Exchange Online-Managed Attributes Writeback (GA)

Cloud-managed remote mailboxes are now generally available, letting organizations move the Source of Authority for a directory-synchronized mailbox’s Exchange attributes to Exchange Online while the user identity remains synchronized from on-premises Active Directory. Writeback synchronizes key Exchange attribute changes from Exchange Online back to on-premises AD through Microsoft Entra Cloud Sync. This is particularly relevant for organizations in hybrid mail scenarios that want to manage Exchange properties in the cloud while keeping identity on-premises.

4. Entra Domain Services GPO Backup and Restore

Microsoft Entra Domain Services now automatically maintains backups of managed Group Policy Objects (GPOs), enabling administrators to restore policy settings after unintended changes. This capability helps organizations recover GPO configuration data from available backup points and maintain consistent policy management across managed domains. If you’ve ever had a GPO change go wrong in production, you’ll appreciate having a restore button.

5. External ID: Email-Optional IdP Sign-Up

Microsoft Entra External ID now supports federation with external identity providers that don’t share users’ email addresses. Users signing up with social identity providers can also choose not to share their email address and still complete registration. This removes a friction point for consumer-facing applications where email-less sign-up flows are common — think loyalty programs, gaming platforms, or services where phone numbers or usernames are the primary identifier.

6. GitHub Actions OIDC Migration — Deadline Already Passed (MC1447671)

GitHub Actions now supports immutable OIDC subject formats containing repository and owner IDs for enhanced Microsoft Entra federated identity security. Organizations using GitHub Actions federated identity credentials were told to migrate by late July 2026. Since that deadline has passed, affected deployments should be checked immediately to avoid token mismatches and reduce unauthorized-access risk.

This aligns with the broader “Harden GitHub and GitLab Federated Credentials” guidance published August 1, which recommends adopting immutable subject identifiers, restricting federation to specific repos/branches, and applying least privilege to CI apps. If you haven’t audited your GitHub Actions trust relationships recently, now is the time.

7. Defender XDR August 2026: AI Agent Protection, Prompt Injection Detection, and More

The Defender XDR August monthly news covers July 2026 product updates. Several items are new since the baseline:

AI Agent Posture Risk Assessment (Public Preview)

Microsoft Defender now assesses posture risk for AI agents — both enterprise agents and local agents discovered on endpoint devices. Risk levels are based on active risk indicators including configuration, access, runtime activity, endpoint and user context, and active alerts. Security teams can use posture risk and recommendations to prioritize risky agents and improve agent security.

Microsoft Defender AI Agent Protection (GA)

With a Microsoft Agent 365 license, Defender provides discovery, security posture, threat detection, investigation, and real-time protection for AI agents in your tenant. Onboarding includes enabling data collection, connecting the Microsoft 365 app connector, and connecting Copilot Studio for real-time protection of Copilot Studio agents.

Prompt Injection Protection in Defender for Office 365 (GA)

Defender for Office 365 now detects prompt injection attacks hidden in inbound email. This is a significant addition — it bridges the gap between traditional email security and AI threat vectors, catching attacks designed to manipulate AI assistants through email-delivered instructions.

M365 E3 Now Includes Defender for Office 365 Plan 1

Microsoft 365 E3 now includes Microsoft Defender for Office 365 Plan 1 at no additional cost. This expands EDR and threat protection coverage to E3 customers without requiring an add-on purchase, raising the security baseline for the mid-tier SKU.

Codename MDASH — Agentic Code Scanner (Private Preview)

Microsoft Security Exposure Management now includes an agentic code scanner in private preview. Codename MDASH uses a multi-model agentic AI system to detect code vulnerabilities with greater depth and accuracy than traditional static analysis. Security teams can run scans from Defender CLI or through a GitHub connector. A MAI-Augmented scan profile includes MAI-Cyber-1-Flash, a new cyber-specialized model.

Defender for Endpoint AI Agent Runtime Protection Enhancements (Public Preview)

Agent event interfaces now work with standard platform and engine update channels (no Beta channel needed). Network inspection is now supported for agents that don’t expose vendor-supported event interfaces — including OpenClaw and similar Node.js-based agents. Agent-native event inspection now supports Codex CLI and the GitHub Copilot app.

Defender Experts MDR P2 (GA)

Defender Experts MDR (formerly Defender Experts for XDR) expands with new third-party and multi-cloud coverage powered by Microsoft Sentinel. The P2 service supports AWS (cloud), Okta (identity), Proofpoint (email), Palo Alto Networks/Cisco/Fortinet/ZScaler (network), and CrowdStrike (endpoint) — all ingested through Sentinel for end-to-end visibility in heterogeneous environments.

8. Entra ID Private Connector v1.5.4892.0

A new version of the Entra ID Private Connector (formerly Application Proxy) is available for download. The connector enables integration of on-premises web applications with Entra for authentication and access control without opening inbound ports on your perimeter firewall.

What This Means for Your Organization

Tenant Governance GA is the big one. If your organization operates more than one Entra tenant — and most enterprises do — this changes the economics of multi-tenant management. Per-admin licensing instead of per-user, 200+ resource types for drift monitoring, and automatic discovery of shadow tenants all combine to close what has been a significant governance gap.

Lifecycle Workflows enhancements make identity automation safer and more flexible. The what-if mode alone is worth adopting — testing workflow scope before execution prevents costly mistakes. Sponsorless guest cleanup addresses a problem every Microsoft 365 admin has faced.

Defender’s AI agent protection is rapidly maturing. With posture risk assessment, runtime protection for non-vendor agents, and prompt injection detection in email, Microsoft is building a comprehensive AI agent security layer. If you’re deploying AI agents (and at this point, who isn’t), you should be evaluating these capabilities.

The GitHub Actions OIDC deadline has already passed. If you haven’t migrated, prioritize it this week — token mismatches from outdated subject formats will break CI/CD pipelines and potentially expose your tenant to unauthorized access.

As always, the September 1 passkeys-by-default rollout and February 2027 SMS/voice retirement loom large. Use the remaining time wisely — the temporary opt-out API is available via Graph Beta, but the February 2027 retirement has no opt-out.

For the full Entra What’s New reference, visit Microsoft Learn. Follow along on X for daily identity security updates.


Kevin Kaminski is the owner of Big Hat Group Inc., a Microsoft Partner focused on AI and identity security. This article is part of a daily series tracking Microsoft Entra ID changes.