Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings
- Vendor
- Microsoft
- Product
- Microsoft Entra
- Type
- Security
- Announcement date
- 2026-07-01
- Effective date
- Date not published
- Impact
- Affected
In brief
Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings
What the source says
The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
Read the primary source
Choose your reading
The role changes the reading angle, not the facts, date or level of evidence.
Reading for a salesperson
Who is affected: The audience described by the Microsoft update is represented by: Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will
Why it matters: The change matters because the official source describes: Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will
Urgency: Monitor
Next action: Review affected accounts with the customer using the official announcement.
Commercial opportunities
- Use the verified change to open a scoped customer conversation.
Technical actions
- Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
- Does this documented change affect a product or workload in scope?
Risks and objections
- The official source does not establish facts beyond the quoted material.
Points to confirm
- The effective date is unknown and must be confirmed before scheduling action.
Evidence and traceability
Each excerpt is linked to the primary source and retained for verification.
- Raw capture
2026-08-29T09:22:49.319599+00:00
- Event
Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
source - Product Microsoft Entra
Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
source - Insight a salesperson
Microsoft Entra: Upcoming changes to federatedTokenValidationPolicy default settings The federatedTokenValidationPolicy is a resource type in Microsoft Graph (beta) that governs the validation of federated authentication tokens and allows customers to configure a rule to block logins where internalDomainFederation does not match UPN domain. The feature by default requires manual configuration in the tenant to prohibit cross-domain logins. To strengthen security with cross-domain sign-in we will change the default rule for federatedTokenValidationPolicy to block logins where internalDomainFederation does not match UPN domain. This internalDomainFederation object is typically created automatically during federation setup with AD federation server or other IdPs. GA date: August CY2026 In development General Availability Worldwide (Standard Multi-Tenant) GCC GCC High DoD Microsoft Entra Android Desktop iOS Mac Web
source
Back to the public feed