Skip to content

Commit 3a7bb3b

Browse files
Learn Build Service GitHub AppLearn Build Service GitHub App
authored andcommitted
Merging changes synced from https://github.com/MicrosoftDocs/entra-docs-pr (branch live)
2 parents c97de37 + 9dfa8d7 commit 3a7bb3b

9 files changed

Lines changed: 166 additions & 16 deletions

File tree

docs/fundamentals/whats-new.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1034,13 +1034,13 @@ In addition to the [global banned password lists](../identity/authentication/con
10341034

10351035
---
10361036

1037-
### Upcoming Changes - Jailbreak Detection in Authenticator App
1037+
### Upcoming Changes Jailbreak/root Detection in Authenticator App
10381038

10391039
**Type:** New feature
10401040
**Service category:** Microsoft Authenticator App
10411041
**Product capability:** Identity Security & Protection
10421042

1043-
Starting February 2026, Microsoft Authenticator will introduce jailbreak/root detection for Microsoft Entra credentials in the Android app. The rollout progresses from warning mode → blocking mode → wipe mode. Users must move to compliant devices to continue using Microsoft Entra accounts in Authenticator.
1043+
Starting February 2026, Microsoft Authenticator will introduce jailbreak/root detection for Microsoft Entra credentials in the Authenticator app. The rollout progresses from warning mode → blocking mode. Users must move to compliant devices to continue using Microsoft Entra accounts in Authenticator.
10441044

10451045
---
10461046

docs/global-secure-access/concept-bring-your-own-device.md

Lines changed: 6 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.reviewer: gauthamca
99
ai-usage: ai-assisted
1010
---
1111

12-
# Bring Your Own Device (Preview)
12+
# Bring Your Own Device
1313

1414
## Overview
1515

@@ -24,6 +24,9 @@ The Global Secure Access client supports bring your own device (BYOD) scenarios
2424
- Only private application traffic is supported. Enable Private Access traffic profiles for these users.
2525
- If the device isn’t registered or joined, the client registers the device to your tenant during first sign-in.
2626
- If the device isn’t joined and has multiple registrations, the user selects the tenant at sign-in with Microsoft Entra user of the tenant.
27+
- Supports an account picker in the sign-in flow to make it easier to sign in with a different account.
28+
- The account picker appears by default on Microsoft Entra-registered devices.
29+
- To enable the account picker or to switch to another tenant on Microsoft Entra-joined devices, enable the **Sign out** option. For details, see [Hide or unhide menu buttons in the system tray](how-to-install-windows-client.md#hide-or-unhide-system-tray-menu-buttons).
2730

2831
> [!IMPORTANT]
2932
> On Windows devices that are Microsoft Entra joined or hybrid joined, the client always connects to the joined tenant.
@@ -52,20 +55,12 @@ BYOD support without device enrollment is available through Microsoft Entra devi
5255
- Install and register the device using the Company Portal (no device enrollment required).
5356
- Enable private traffic profiles for these users.
5457

55-
## Tenant selection and switching (Preview)
56-
57-
How the Global Secure Access client selects a tenant depends on platform and Microsoft Entra device state.
58-
59-
### Key concepts
60-
- Microsoft Entra joined or hybrid joined: Windows-only device state that establishes tenant ownership and management.
61-
- Microsoft Entra registered: User-associated device identity for BYOD and unmanaged devices across platforms.
62-
6358
### Platform behavior
6459

6560
| Platform/device state | Connection target | Microsoft Entra tunnel | M365 tunnel | Internet tunnel | Private tunnel | Notes |
6661
|---|---|---|---|---|---|---|
67-
| Windows Microsoft Entra Joined and Hybrid joined device | Client connects to the tenant to which device joined. ||||| Cannot switch to a registered tenants for now. Allows user to switch to a resource tenant using external user access(B2B). |
68-
| Windows Microsoft Entra Registered device | User selects a tenant at first sign-in; remains connected to that tenant. ||||| Cannot switch to other registered tenants for now. Allows user to switch to a resource tenant using external user access(B2B). |
62+
| Windows Microsoft Entra Joined and Hybrid joined device | Client connects to the tenant to which device joined. ||||| Enable the Sign out option in the client to allow users to sign out and switch to an external tenant. Allows user to switch to a resource tenant using external user access(B2B). |
63+
| Windows Microsoft Entra Registered device | User selects a tenant at first sign-in; remains connected to that tenant. ||||| Can switch to other tenant by selecting **Sign out** option on the client. Allows user to switch to a resource tenant using external user access(B2B). |
6964
| MacOS Microsoft Entra Registered device with and without device enrollment | User selects a tenant at first sign-in; remains connected to that tenant ||||| Uses Company Portal to Microsoft Entra register the device. |
7065
| Android Microsoft Entra Registered with and without device enrollment | User selects a tenant at first sign-in; remains connected to that tenant ||||| Applies to enrolled devices with Company Portal. For unmanaged devices, Microsoft Entra registration can be done with Company portal and Authenticator app. |
7166
| iOS Microsoft Entra Registered with and without device enrollment | User selects a tenant at first sign-in; remains connected to that tenant ||||| Applies to enrolled devices with Company Portal. For unmanaged devices, Microsoft Entra registration can be done with Authenticator app. |

docs/identity/hybrid/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -357,6 +357,8 @@
357357
href: connect/how-to-connect-install-express.md
358358
- name: Install Microsoft Entra Connect federation or other Custom settings
359359
href: connect/how-to-connect-install-custom.md
360+
- name: Sign in with passwordless authentication
361+
href: connect/how-to-connect-passwordless-authentication.md
360362
- name: Import and export configuration settings
361363
href: connect/how-to-connect-import-export-config.md
362364
- name: Install Microsoft Entra Connect with pass-through authentication

docs/identity/hybrid/connect/authenticate-application-id.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,7 +127,7 @@ The Microsoft Entra Connect Sync managed application and credential is automatic
127127

128128
### Automatic
129129

130-
Starting with version 2.5.76.0 or higher, the service will automatically configure application authentication within a six-hour window if the service is using username and password to authenticate to Microsoft Entra ID.
130+
New installations of Microsoft Entra Connect Sync are configured for application-based authentication during setup. Microsoft Entra Connect doesn't automatically switch existing servers that use a legacy directory synchronization account. To switch an existing server, follow the steps in the [Manual](#manual) section.
131131

132132
### Manual
133133

Lines changed: 114 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,114 @@
1+
---
2+
title: Sign in to Microsoft Entra Connect Sync by using passwordless authentication
3+
description: Learn how to sign in to Microsoft Entra Connect Sync by using passwordless authentication methods such as FIDO2 security keys and passkeys.
4+
author: omondiatieno
5+
ms.author: jomondi
6+
ms.service: entra-id
7+
ms.subservice: hybrid-connect
8+
ms.topic: how-to
9+
ms.custom: msecd-doc-authoring-1013
10+
ms.date: 06/15/2026
11+
ai-usage: ai-assisted
12+
13+
#customer intent: As a hybrid identity administrator, I want to sign in to Microsoft Entra Connect Sync by using passwordless authentication so that I can install and configure synchronization without using a password.
14+
15+
---
16+
17+
<!-- TODO: Confirm whether passwordless authentication for Microsoft Entra Connect Sync is in public preview. If it is, add the standard preview note or [!INCLUDE] near the top of the article. -->
18+
<!-- TODO: Confirm the minimum Microsoft Entra Connect Sync version that supports passwordless authentication, and add it to the prerequisites. -->
19+
20+
# Sign in to Microsoft Entra Connect Sync by using passwordless authentication
21+
22+
Passwordless authentication for Microsoft Entra Connect Sync lets administrators sign in with secure, modern credentials (such as FIDO2 security keys, passkeys, or Windows Hello) instead of typing a password.
23+
24+
This article shows you how to enable passwordless authentication methods in Microsoft Entra ID, register a credential, turn on passwordless sign-in for Microsoft Entra Connect Sync, and verify that you can sign in without a password. You can choose from the following passwordless methods:
25+
26+
- **FIDO2 security keys**: Insert a USB or NFC key (for example, a YubiKey), enter a PIN, and tap the key.
27+
- **Passkeys**: Use a platform-stored credential (for example, an iCloud Keychain or Android passkey) through the system browser or a device prompt.
28+
29+
## Prerequisites
30+
31+
- A Microsoft Entra account with the **Hybrid Administrator** or **Global Administrator** role.
32+
- A FIDO2 security key, such as a YubiKey.
33+
- Windows Server 2022 or later.
34+
35+
## Enable passwordless authentication methods in Microsoft Entra ID
36+
37+
Before you can register a passwordless credential, enable the passkey or FIDO2 authentication method for your account in Microsoft Entra ID.
38+
39+
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
40+
1. Browse to **Entra ID** > **Authentication methods** > **Policies**.
41+
1. Select **Passkey (FIDO2)**.
42+
1. Set the method to **Enabled**, and target **All users** or a specific group that contains your administrator account.
43+
44+
:::image type="content" source="media/how-to-connect-passwordless-authentication/authentication-methods-policies.png" alt-text="Screenshot of the Authentication methods Policies page in the Microsoft Entra admin center with Passkey (FIDO2) enabled for all users." lightbox="media/how-to-connect-passwordless-authentication/authentication-methods-policies.png":::
45+
46+
## Register a passwordless credential
47+
48+
After the authentication method is enabled, register the credential that you want to use to sign in. You can register a passkey, a security key, or both.
49+
50+
### Register a passkey
51+
52+
Register a passkey that's stored on your device or password manager:
53+
54+
1. Go to [Security info](https://mysignins.microsoft.com/security-info) and sign in with your administrator account.
55+
1. Select **Add sign-in method**.
56+
1. Select **Passkey**.
57+
1. Follow the prompts to create the passkey with your device, such as Windows Hello, Face ID, Touch ID, or a synced password manager.
58+
59+
After registration finishes, the new passkey appears under your registered sign-in methods.
60+
61+
### Register a security key
62+
63+
Register your FIDO2 security key, such as a YubiKey:
64+
65+
1. Go to [Security info](https://mysignins.microsoft.com/security-info) and sign in with your administrator account.
66+
1. Select **Add sign-in method**.
67+
1. Select **Security key**.
68+
1. Select **USB device**.
69+
1. Insert your YubiKey, and then touch it when it blinks.
70+
1. Set a PIN if you're prompted, and then touch the key again to finish registration.
71+
72+
## Turn on passwordless authentication for Microsoft Entra Connect Sync
73+
74+
To make passwordless sign-in available in the installation wizard, install Microsoft Entra Connect Sync and set a registry key.
75+
76+
1. Install Microsoft Entra Connect Sync. For installation steps, see [Get started with Microsoft Entra Connect Sync by using express settings](how-to-connect-install-express.md).
77+
1. On the server, open PowerShell and run the following command to enable passwordless authentication:
78+
79+
```powershell
80+
# Enable passwordless authentication
81+
New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Azure AD Connect" -Name "EnablePasswordlessAuth" -Value 1 -PropertyType DWORD -Force
82+
```
83+
84+
## Sign in to Microsoft Entra Connect Sync without a password
85+
86+
After passwordless authentication is enabled, use your passkey or security key to sign in when you run the installer.
87+
88+
1. Run the Microsoft Entra Connect Sync installer. When you're prompted to sign in to Microsoft Entra ID, select **Sign-in options**.
89+
90+
:::image type="content" source="media/how-to-connect-passwordless-authentication/sign-in-options.png" alt-text="Screenshot of the Microsoft sign-in window with Sign-in options available below the sign-in dialog." lightbox="media/how-to-connect-passwordless-authentication/sign-in-options.png":::
91+
92+
1. Select **Face, fingerprint, PIN or security key**, and then complete the prompt with the passkey or security key that you registered.
93+
94+
:::image type="content" source="media/how-to-connect-passwordless-authentication/face-fingerprint-pin-security-key.png" alt-text="Screenshot of the Sign-in options screen with Face, fingerprint, PIN or security key selected." lightbox="media/how-to-connect-passwordless-authentication/face-fingerprint-pin-security-key.png":::
95+
96+
When sign-in succeeds, you're signed in to Microsoft Entra Connect Sync without entering a password. The same steps apply whether you sign in with a passkey or a security key.
97+
98+
## Disable passwordless authentication
99+
100+
To turn off passwordless authentication and return to signing in with a username and password, set the registry value to `0`.
101+
102+
1. On the server, open PowerShell and run the following command to disable passwordless authentication:
103+
104+
```powershell
105+
# Disable passwordless authentication
106+
Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Azure AD Connect" -Name "EnablePasswordlessAuth" -Value 0
107+
```
108+
109+
1. Run the Microsoft Entra Connect Sync installer again. The passwordless sign-in option is no longer available, and you can sign in with your username and password.
110+
111+
## Related content
112+
113+
- [Get started with Microsoft Entra Connect Sync by using express settings](how-to-connect-install-express.md)
114+
- [Choose the right authentication method for your Microsoft Entra hybrid identity solution](choose-ad-authn.md)
89.6 KB
Loading
53.6 KB
Loading
106 KB
Loading

docs/identity/hybrid/connect/reference-connect-version-history.md

Lines changed: 41 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: 'Microsoft Entra Connect: Version release history'
33
description: This article lists all releases of Microsoft Entra Connect and Azure AD Sync.
44
ms.assetid: ef2797d7-d440-4a9a-a648-db32ad137494
55
ms.topic: reference
6-
ms.date: 03/10/2026
6+
ms.date: 06/22/2026
77
ms.subservice: hybrid-connect
88
ms.custom: no-azure-ad-ps-ref, sfi-ga-nochange
99

@@ -105,7 +105,8 @@ Required permissions | For permissions required to apply an update, see [Microso
105105
|[2.5.79.0](#25790)|23 Oct 2026 (12 months after release of 2.5.190.0)|
106106
|[2.5.190.0](#251900)|02 Feb 2027 (12 months after release of 2.6.1.0)|
107107
|[2.6.1.0](#2610)|10 Mar 2027 (12 months after release of 2.6.3.0)|
108-
|[2.6.3.0](#2630)||
108+
|[2.6.3.0](#2630)|22 Jun 2027 (12 months after release of 2.6.79.0)|
109+
|[2.6.79.0](#26790)||
109110

110111
**All other versions are not supported**
111112

@@ -131,6 +132,44 @@ To read more about autoupgrade, see [Microsoft Entra Connect: Automatic upgrade]
131132

132133

133134

135+
## 2.6.79.0
136+
137+
> [!IMPORTANT]
138+
> This release includes security fixes. We recommend upgrading to this version as soon as possible.
139+
140+
### Release status
141+
142+
06/22/2026: Released for download via the Microsoft Entra admin center.
143+
144+
### Added features
145+
146+
- Added support for phishing-resistant authentication methods in the Microsoft Entra Connect setup wizard (preview). Administrators can now sign in using passkeys and FIDO2 security keys through Windows Web Account Manager (WAM) when configuring Microsoft Entra Connect.
147+
- Added support for the France sovereign cloud environment, including Pass-through Authentication, Seamless Single Sign-On, password writeback, and Health Agent monitoring.
148+
149+
### Updated features
150+
151+
- Improved the auto-upgrade process to preserve customer modifications to configuration files. Previously, auto-upgrade overwrote the `miiserver.exe.config` file, discarding any manual customizations. The system now merges customer modifications with the new configuration and validates the result before applying.
152+
- Improved the setup process for Application-Based Authentication to handle Trusted Platform Module (TPM)-backed certificates. The system now tests a certificate's signing capability upfront and handles TPM signature verification correctly.
153+
- Microsoft Entra Connect setup wizard no longer silently falls back to the legacy directory synchronization account when Application-Based Authentication setup fails. The wizard now stops with an error so the underlying issue can be resolved: "Microsoft Entra Connect could not configure application-based authentication for this server. Setup cannot continue."
154+
- Microsoft Entra Connect no longer automatically switches existing servers from the legacy directory synchronization account to Application-Based Authentication during background sync. New installations continue to configure Application-Based Authentication during setup. To switch an existing server, run the wizard and choose **Configure application-based authentication to Microsoft Entra ID**.
155+
- PowerShell cmdlets that modify cloud configuration (`Set-ADSyncAADCompanyFeature`, `Set-ADSyncAADPasswordSyncState`) now require explicit `-AADUsername` for interactive admin authentication. The setup wizard uses interactive Microsoft Authentication Library (MSAL) authentication for cloud writes instead of stored service credentials. The uninstall wizard now prompts for admin credentials to clean up cloud configuration; if skipped, local cleanup still proceeds.
156+
- Removed Password Hash Synchronization (PHS) self-healing. PHS no longer automatically re-enables its cloud feature flag in the background. If the PHS cloud feature flag is disabled, an administrator must explicitly re-enable it.
157+
- Updated the bundled MSAL from version 4.64.1 to 4.83.3.
158+
- Upgraded the bundled SQL LocalDB from SQL Server 2019 to SQL Server 2022.
159+
- Upgraded the Visual C++ redistributable from version 12 (2013) to version 14.42.34438 (2015-2022).
160+
- Removed the Visual C++ 2013 redistributable dependency.
161+
162+
### Bug fixes
163+
164+
- Fixed an issue in the PowerShell diagnostic HTML report rendering.
165+
- Fixed an issue in the Synchronization Service Manager metaverse search.
166+
- Improved Application-Based Authentication setup on servers with non-conforming TPM firmware by falling back to a software-based certificate when the TPM cannot produce a valid signature.
167+
- Fixed an issue where Generic SQL (GSQL) connector profile creation failed because required profile parameters were not populated during configuration.
168+
- Fixed an issue where the Application Proxy cloud name was not correctly resolved in the France cloud environment, causing Pass-through Authentication registration to fail with an "EnvironmentName attribute is invalid" error.
169+
- Fixed an issue where the China cloud instance name was not correctly resolved by the Discovery Endpoint API, which could cause cloud instance detection to fail.
170+
- Fixed an issue where admin actions audit logging captured the service account identity instead of the actual administrator performing the action for Synchronization Rule changes.
171+
- Fixed multiple security vulnerabilities in bundled third-party dependencies.
172+
134173
## 2.6.3.0
135174

136175
### Release status

0 commit comments

Comments
 (0)