Entra Global Secure Access: Zero Trust beyond VPN sprawl

Entra Global Secure Access - Zero Trust for every resource

In its Microsoft Entra blog post from 12 August 2026, Microsoft explains how organizations can extend Zero Trust controls beyond Microsoft 365 to AI apps, SaaS, internet destinations, and private applications. This matters for small and midsize companies because many environments now combine Microsoft 365 services, a few line-of-business systems, remote access, and selected AI … Read more

Entra ID memberOf operator ends in November 2026

Entra ID - memberOf operator for dynamic groups

Microsoft is ending the public preview of the memberOf operator for dynamic membership in Microsoft Entra ID. After 3 November 2026, dynamic membership groups, dynamic administrative units, and access package auto-assignment policies that use this operator stop updating. For companies, the practical question is not whether the feature was convenient, but where it is already … Read more

DeadLock ransomware: Microsoft lists Defender protections

DeadLock ransomware – Defender protections

Microsoft Threat Intelligence describes DeadLock as a ransomware operation observed since July 2025 that combines encryption, data theft, and a resilient recovery and leak infrastructure. The new Microsoft report matters for organizations that protect Windows endpoints with Microsoft Defender and Defender XDR: it does not only describe malware internals, but also lists concrete settings that … Read more

Conditional Access: custom controls are being retired

Conditional Access - custom controls retire in May 2027

Microsoft is retiring custom controls in Conditional Access and replacing them with external MFA. From September 2026, no new custom controls can be created and existing ones can no longer be edited; in May 2027 the feature is switched off entirely. This affects every company that has plugged a third-party provider such as Duo, RSA … Read more

Passkeys become the default in Entra ID as SMS MFA ends

Passkeys become the default in Microsoft Entra ID

Microsoft is making passkeys the default sign-in experience in Microsoft Entra ID and ending its own delivery of one-time codes by SMS and voice call. From 1 September 2026, users currently enabled for SMS or voice will be automatically enabled for passkeys and prompted to register one at their next sign-in with MFA. From 1 … Read more