What's New in Microsoft Entra: August 2026
Hi everyone, I’m Yina Arenas. I’m thrilled to be joining Microsoft Security as the Chief Product Officer of Identity and Network Access. I’m excited to connect with the fantastic Microsoft Entra community! My career has focused on platform innovation, and I’ve seen firsthand how much of a game-changer trustworthy technology can be. As companies dive into AI like never before, identity and access management is becoming essential for secure innovation. I’m eager to work with all of you as we explore the amazing opportunities ahead.
Welcome to the August edition of “What’s New in Microsoft Entra”.
- Admin Control for Single Sign-On Prompts in Windows – Administrators can now easily set up a registry option to automatically accept single sign-on (SSO) permissions on their managed Windows devices. This means that users can use their Microsoft credentials from their Windows sign-in to access various Microsoft apps and services without any extra prompts. This feature will be available starting from the July 2026 monthly security update for Windows 11, versions 24H2 and 25H2 through the 2026—KB5101650 security update.
- Exchange Online-Managed Attributes Writeback to Active Directory – With cloud-managed remote mailboxes, organisations can shift the Source of Authority (SOA) for directory-synchronised mailbox Exchange attributes to Exchange Online, while keeping the user identity synced with on-premises Active Directory. This writeback feature synchronises crucial Exchange attribute changes from Exchange Online back to on-premises Active Directory through Microsoft Entra Cloud Sync.
- What-If Mode in Lifecycle Workflows – This new feature allows you to simulate workflow processing, helping you identify which users are included in the execution scope and troubleshoot potential issues without affecting users.
- Cancel Workflow Runs Using Lifecycle Workflows – If you need to prevent or manage the impact of automation errors, you can now cancel queued or in-progress Lifecycle Workflow runs. Cancelling a workflow will stop any tasks that haven’t been processed yet; however, changes from tasks that are already completed won’t be undone.
- User Attribute Updates in Lifecycle Workflows – You can now automate the setting or clearing of user attributes when lifecycle events occur. This supports both built-in and on-premises extension attributes for cloud-managed users and allows up to 10 attribute updates per task.
- Expanded Dynamic Attributes for Lifecycle Workflow Custom Email Notifications – Custom emails for Lifecycle Workflows now include a new attribute format and an expanded range of dynamic attributes, which now also encompass additional built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes.
- Make Email Optional for External Identity Provider Sign-Up – Microsoft Entra External ID now supports federating with external identity providers that do not share users’ email addresses. Users who register with social identity providers can choose not to share their email address and still complete the registration process.
- Synchronise On-Premises Active Directory (AD) Devices with Microsoft Entra Cloud Sync – You can now synchronise your on-premises AD devices with Microsoft Entra ID using Microsoft Entra Cloud Sync. This feature supports Hybrid Azure AD Join (HAADJ) and device lifecycle management across various connected and disconnected forests, allowing updates, disables, and deletions to flow from AD to Microsoft Entra ID without the need for Microsoft Entra Connect Sync or AD FS. This helps organisations transition smoothly to Microsoft Entra Cloud Sync.
- Automate Detection and Cleanup of Sponsorless Guests – Microsoft Entra now allows administrators to create workflows that automatically identify and remove guest accounts that lack sponsors. This helps avoid accumulating inactive or over-permissioned external users, reducing security risks while streamlining account management.
- Back Up and Restore Group Policy Objects in Microsoft Entra Domain Services – Microsoft Entra Domain Services now offers automatic backups of managed GPOs. This means that administrators can easily restore policy settings after any unintended changes, helping to maintain consistent policy management across their domains.
I truly hope you’ll make the most of these new features to enhance access security within your organisation. Your invaluable feedback continues to help us navigate the challenges faced in today’s business landscape.
Cheers,
Yina Arenas
Discover the latest updates with Microsoft Entra, including release notes, known issues, bug fixes, and upcoming changes. You can also find releases specifically for Sovereign Clouds on a dedicated page.
Ensure secure access for any identity to any resource, anywhere.
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.