
Passkeys Become the Default as Microsoft Entra Retires SMS and Voice Authentication
Passkeys become the default authentication method in Entra as Microsoft retires SMS and voice. Learn the timeline and migration steps.
6 min read
Microsoft has officially announced that passkeys will become the default authentication method in Microsoft Entra, replacing Microsoft-provided SMS and voice authentication. The change begins rolling out on September 1, 2026, with the transition completing on February 1, 2027.
Microsoft is adding two new PowerShell settings that let admins control who can join federated group chats in Microsoft Teams. These settings are disabled by default and will roll out globally between late July and late September 2026.
Microsoft has introduced cross-tenant message recall in Exchange Online. This feature allows users to recall emails sent to external Microsoft 365 tenants. It is disabled by default and works only when the receiving organization explicitly enables it and adds the sender’s Microsoft Entra tenant IDs to an allow list via PowerShell. The rollout begins in mid-August 2026, delivering a secure recall experience for cross-organization collaboration.
Microsoft’s Network Data Security helps protect sensitive company data when people use AI tools, cloud apps, or websites outside of managed Microsoft 365 apps. It checks data in real time as it is being uploaded, pasted, or shared, and can block it if it breaks company rules. It works by combining Microsoft Purview’s data protection with Microsoft Entra’s network control to make sure sensitive information doesn’t accidentally leave the organization.
Microsoft recently introduced manual incident creation in preview for Defender to help security teams investigate threats beyond automated detections. Analysts can now instantly track, manage, and correlate user reported threats and other security findings, even when no alert is generated automatically.
Microsoft has introduced two new service plans named ‘Entra Conditional Access for Agents’ and ‘Entra ID Protection for Agents’ under Microsoft 365 Agent and E7 licenses. Starting in July 2026, organizations using agent security capabilities must ensure they have the required Microsoft 365 Agent or E7 licenses to continue accessing these features without disruption. This blog explains the licensing update, its impact on organizations, and the steps admins should take to ensure AI agents remain protected.
Struggling to automate secure monitor manage M365?
Try AdminDroid for Free!What’s new in Microsoft 365 – the latest announcements, features, and updates, delivered as quick reads.

Passkeys become the default authentication method in Entra as Microsoft retires SMS and voice. Learn the timeline and migration steps.
6 min read

Use EnableExternalAccessRestrictionsForChatParticipants, EnableMutualFederationForChatParticipants to strengthen Teams federated group chats.
5 min read

Microsoft brings cross-tenant message recall to Exchange Online. Learn how it works to successfully recall emails sent to external tenants.
3 min read

Learn how Network Data Security combines Microsoft Purview and Entra to prevent sensitive data leaks to AI and SaaS apps.
5 min read

Learn how to create manual incidents and alerts in Microsoft Defender and investigate user reported threats beyond automated detections.
6 min read

Explore the new service plans for Agent Conditional Access and Identity Protection to ensure uninterrupted access to agent security features.
3 min read

Microsoft will require registered authentication methods for SSPR verification. Find unregistered users amd prepare for enforcement.
4 min read

Explore new pay-as-you-go billing for SharePoint Storage and learn how to enable consumption-based billing to pay for what you consume.
5 min read

Learn about Device Soft Delete in Microsoft Entra ID and how deleted devices can be recovered within a 30-day window before permanent removal.
4 min read

Microsoft adds external email tag support to help users move external emails to a folder using Outlook inbox rules.
3 min read

Explore the unified workflow experience in SharePoint Online to create and manage Power Automate flows directly from lists and libraries.
5 min read

The Storm-2949 attack shows how hackers use different approaches until they gain full Microsoft 365 cloud access.
9 min read