
Entra, previously known as Azure Active Directory, is Microsoft's Identity Management-as-a-Service solution, offering seamless access, easy collaboration, efficiency in IT processes and improved security and compliance. In its Release Notes for Entra ID and in the Message Center, Microsoft communicated the following planned, new and changed functionality for Entra for January 2026:
What's New
Service Principal creation audit logs General Availability
Service category: Audit
Product capability: Monitoring & Reporting
New audit log properties now make it easy for admins to understand why a service principal was created and who or what triggered it. The logs now surface the provisioning mechanism, the specific SKUs or service plans that enabled just‑in‑time creation, and the home tenant of the app registration. This helps admins quickly distinguish Microsoft‑driven provisioning from tenant‑driven activity, streamlining alerting and investigations into newly created service principals.
Ability to convert Source of Authority of synced on-premises AD users to cloud users General Availability
Service category: User Management
Product capability: Microsoft Entra Cloud Sync
With object-level Source of Authority (SOA) switching for Microsoft Entra ID, admins can transition individuals from being synchronized with Active Directory to becoming cloud-managed accounts within Microsoft Entra ID. The accounts for these people are no longer tied to Entra Connect Sync and behave like native cloud user accounts, giving admins greater flexibility and control. This capability enables organizations to gradually reduce dependence on Active Directory and simplify migration to the cloud, all while minimizing disruption to people and daily operations. Both Microsoft Entra Connect Sync and Cloud Sync fully support this SOA switch, ensuring a smooth transition process.
Microsoft Entra ID Governance guest billing meter enforcement General Availability
Service category: Entitlement Management, Lifecycle Workflows
Product capability: Entitlement Management, Lifecycle Workflows
Enforcement for the Microsoft Entra ID Governance guest billing meter is now in effect for :
- Entitlement Management
- Lifecycle Workflows
To keep using Entra ID Governance premium features for guest users in workforce tenants, admins must link a valid Azure subscription to activate the Microsoft Entra ID Governance for guests add-on. If a subscription isn’t linked, creation or updates of new guest-scoped governance configurations will be restricted, and guest-specific governance actions may fail until billing is configured.
Note:
Enforcement for the Microsoft Entra ID Governance guest billing meter for Access Reviews will be enforced later in CY26 Q1.
Client Credentials in Microsoft Entra External ID General Availability General Availability
Service category: B2C – Consumer Identity Management
Product capability: B2B/B2C
Client credentials in Entra External ID are now generally available. The OAuth 2.0 client credentials grant flow permits a web service (confidential client) to use its own credentials, instead of impersonating a user, to authenticate when calling another web service. Permissions are granted directly to the application itself by an administrator.
Billing: When you configure machine-to-machine (M2M) authentication for Microsoft Entra External ID, you must use the M2M Premium add‑on. Review your organization’s premium add‑on usage policy to understand cost implications and ensure the implementation complies with internal governance and licensing guidelines.
App-based branding via Branding themes in Entra External ID General Availability
Service category: B2C – Consumer Identity Management
Product capability: B2B/B2C
In Entra External ID, organizations can create a single, tenant-wide, customized branding experience that applies to all apps. Microsoft is introducing the concept of Branding "themes" to allow organizations to create different branding experiences for specific applications. A new Live Preview feature also helps quickly visualize the changes before saving.
Session Control Conditional Access Policies in Entra External ID General Availability
Service category: Conditional Access
Product capability: B2B/B2C
Entra External ID admins can configure persistent browser session and sign‑in frequency in Conditional Access.
Entra Private Access for Domain Controllers General Availability
Service category: Private Access
Product capability: Network Access
Bring multi-factor authentication to on‑premises applications when accessed from on‑premises, i.e., local‑to‑local access, while safeguarding domain controllers against identity threats. Enable secure access to private apps that use domain controllers for Kerberos authentication.
What's Changed
Improved enforcement for All resources policies with resource exclusions General Availability
ervice category: Conditional Access
Product capability: Access Control
Microsoft Entra Conditional Access is strengthening how policies that target All resources with resource exclusions are enforced in a narrow set of authentication flows. After this change, in user sign‑ins where a client application requests only OIDC or specific directory scopes, Conditional Access policies that target All resources with one or more resource exclusions, or policies that explicitly target Azure AD Graph, will be enforced. This ensures that policies are consistently applied regardless of the scope set requested by the client application.






Login