security
Jun 2, 2026
By Teun
Microsoft Entra adds passkeys and tighter identity controls
Microsoft has shipped new Entra features over the past 30 days, including phishing-resistant MFA on Linux, passkey registration campaigns, and changes to Conditional Access and self-service password reset. The company also added governance, app deactivation, and SOC response tools, with more enforcement dates set for 2026.
Microsoft has rolled out a wide set of identity and network access updates for Entra over the last 30 days, adding new passkey support, stronger governance tools, and several policy changes that will take effect in 2026. Entra is Microsoft’s family of identity and access products, used to help organizations apply zero trust security controls across users, devices, apps, and networks.
One of the biggest updates is phishing-resistant multifactor authentication on Linux desktops through the Microsoft identity broker. According to Microsoft, the feature now supports Ubuntu 24.04 and 26.04, plus RHEL 8, 9, and 10, which brings Linux support closer to what Windows and macOS users already have.
⚡ New to this?
This news matters because identity systems decide who gets access to apps, devices, and data. Entra is Microsoft’s access-management platform, and changes to passkeys, MFA, and password reset rules can affect how employees sign in and how admins respond to incidents.
MFA means multifactor authentication, which requires more than a password. Passkeys are a passwordless sign-in method tied to a device and usually unlocked with a fingerprint, face scan, or PIN, which makes phishing harder.
🦞 OpenClaw angle
If you run self-hosted automation or internal tools behind Microsoft identity, check whether your login flows depend on password reset via phone or email stored on the user object. Microsoft says those details will stop counting for Self-Service Password Reset on September 7, 2026, so make sure your automation can handle registered-method-only recovery.
If your agents or operators use Entra-backed apps, plan for passkey and Conditional Access prompts during registration flows. Also, if you support incident response tooling, map routine account-disable and session-revoke tasks to the new Security Operator role instead of granting full Entra admin access.
Microsoft also expanded passkey enrollment. Registration Campaigns now support passkeys, including FIDO2 credentials, so administrators can prompt users to enroll during sign-in. Users can create device-bound passkeys through Windows Hello and use them for biometric or PIN-based sign-in. Microsoft said the feature does not require the device to be Entra joined or registered, although interactive Windows console sign-in is not supported.
On the migration side, High Scale Compatibility mode is now available for large Azure AD B2C customers moving to Microsoft Entra External ID. Microsoft said the option is intended for organizations with about 5 million or more objects and is designed to let them move applications without forcing users to re-register or reset passwords. Martin Coetzer, Principal Product Manager at Microsoft, said customers can use the B2C Policy Analyzer to assess readiness and work with account teams and partners on the migration path.
Microsoft also said system-preferred authentication now covers first- and second-factor authentication in the Microsoft Managed state. The service automatically chooses the highest-ranked authentication method available to each user. In addition, the Devices, Security Info, and Organizations pages in the My Account portal have been redesigned, with rollout expected to finish by the end of June 2026.
Several governance features are now generally available. Organizations can synchronize security groups and memberships between Microsoft Entra tenants, which lets centrally managed groups control access across multiple tenants. Administrators can also see all accounts in connected applications, including orphaned accounts, and use discovery reports to find access gaps and support application onboarding. Microsoft said those reporting features require Microsoft Entra ID Governance or Microsoft Entra Suite.
App control has also been tightened. App Deactivation lets administrators disable an application without deleting it. Microsoft said deactivated apps cannot get new access tokens or sign users in, but their configuration, permissions, and metadata stay available for later reactivation. Coetzer said that can be useful for security investigations or temporary suspension of suspicious applications.
For incident response, the Entra Security Operator role now expands support for SOC actions in Microsoft Defender RBAC. SOC, or Security Operations Center, analysts can disable users, revoke sessions, mark accounts as compromised, force password resets, and remove authentication methods. Microsoft said these actions apply to non-admin users and reduce the need for full Entra administrative privileges during response.
Microsoft has also set out several policy changes for 2026. Starting July 6, 2026, Conditional Access policies assigned to the “Register security information” action will apply during registration for Windows Hello for Business and macOS Platform SSO. Full enforcement for passwordless credential registration begins July 13, 2026. Then, beginning September 7, 2026, Self-Service Password Reset will accept only authentication methods that users have actually registered, not contact details stored on the user object.
Microsoft said a registration campaign will prompt users without registered methods to enroll after sign-in starting July 6, 2026. The company also said the passkey authentication policy gets a dedicated 20 KB allocation and the number of passkey profiles per tenant rises from three to ten.