M365 Change Tracker

← Home

Authentications (Logins) — changes & security (12)

Roadmap, security and documentation changes captured for Authentications (Logins).

GAMicrosoft Entra IDAuthentications (Logins)

Microsoft Entra Kerberos key rotation improved reliability for incoming trust referral flows

General availability of Microsoft Entra Kerberos key rotation improved reliability particularly for environments using incoming trust referral flows. Previously, authentication failures could occur during Kerberos key rotation if referral tickets were encrypted with a secondary key. The update enhances validation logic to attempt decryption with both primary and secondary Kerberos keys, improving resiliency during key rollover operations and reducing authentication disruption during rotation eve

GAMicrosoft Entra IDAuthentications (Logins)

Microsoft Entra Certificate-based authentication (CBA) support on iOS and CBA as second factor

Microsoft Entra Certificate-Based Authentication (CBA) is now generally available on iOS. Native iOS sign-ins now avoid unnecessary password and MFA prompts, enabling CBA as a supported second factor and allowing it to be prioritized as a system‑preferred MFA method. Users can choose another allowed MFA method if needed, based on tenant policy. More information at Microsoft Entra certificate-based authentication on Apple devices

GAMicrosoft Entra IDAuthentications (Logins)

Entra CBA as third option in system-preferred MFA methods

General Availability - Due to known issues on iOS platform, the Entra certificate-based authentication (CBA) method was not allowed as a second factor on iOS and CBA was moved to the last place in the system-preferred MFA list as documented at FAQ.

GAMicrosoft Entra IDAuthentications (Logins)

Entra CBA Certificate Authority (CA) scoping

Entra CBA Certificate Authority (CA) scoping in Microsoft Entra allows tenant administrators to restrict the use of specific certificate authorities (CAs) to defined user groups. This feature enhances the security and manageability of certificate-based authentication (CBA) by ensuring that only authorized users can authenticate using certificates issued by specific CAs. More information at Certificate Authority (CA) scoping

GAMicrosoft Entra IDAuthentications (Logins)

Issuer Hints for Microsoft Entra CBA

Issuer Hints is generally available now and helps improve the sign‑in experience for Entra Certificate‑Based Authentication (CBA) by ensuring users are prompted to select only certificates that are trusted and valid for their organization. This reduces confusion, minimizes sign‑in errors, and streamlines certificate selection especially on devices with multiple certificates installed. Issuers hints are designed to enhance both security and usability without changing how certificates are issued o

GAMicrosoft Entra IDAuthentications (Logins)

Configurable Token Lifetime Policies

Configurable token lifetime policies are now generally available in Microsoft Entra ID. This feature allows administrators to customize the lifetimes of access tokens, ID tokens, and SAML tokens issued by the Microsoft identity platform by creating and assigning token lifetime policies to applications and service principals.

GAMicrosoft Entra IDAuthentications (Logins)

Synced passkeys in Microsoft Entra ID

Microsoft Entra ID now supports synced passkeys as a generally available authentication method. Synced passkeys are FIDO2-based credentials that can be stored in built-in or third-party passkey providers and made available across a user’s devices. Administrators can manage the use of synced passkeys alongside device-bound passkeys through passkey profiles in the authentication methods policy. Existing passkey configurations can be managed using the same Entra ID authentication policies and repor

PreviewMicrosoft Entra IDAuthentications (Logins)

Microsoft Entra passkeys on Windows

Microsoft Entra passkeys on Windows are now available in public preview. This feature allows users to register device‑bound passkeys directly in the local Windows Hello container and use them to sign in to Microsoft Entra ID with Windows Hello biometrics or PIN.

GAMicrosoft Entra IDAuthentications (Logins)

Passkey profiles in Microsoft Entra ID

Passkey profiles in Microsoft Entra ID are now generally available. Passkey profiles provide a structured way to manage passkey (FIDO2) authentication by allowing administrators to define multiple profiles with different requirements and target them to specific user groups.

UpdateMicrosoft Entra IDAuthentications (Logins)

General Availability – Improved readability for Authentication Methods Policy Update audit logs

Starting in April 2026, the Authentication Methods Policy Update and Authentication Methods Policy Reset audit log activities has been updated to improve readability and clarity. Previously, audit logs included the full authentication methods policy payload in both the old and new values, even when only a small number of settings were changed. With this update, audit log entries now surface only the specific properties that were modified, along with their corresponding old and new values.