← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

Entra adds SOC Identity Responder as passkey registration optimization rolls out

The period brings a meaningful Entra role addition and a live passkey-registration rollout, plus new HiBob-to-Active Directory hybrid provisioning guidance. Remaining updates sharpen permissions and recovery boundaries: Security Administrator references diverge on identity containment, while Agent ID sponsors cannot restore resources they disable or delete.

  • The permissions reference documents the Entra SOC Identity Responder role for SOC incident response, including disabling users, revoking active sign-in sessions, and resetting passwords.

  • Microsoft Entra will better follow administrator policies, prioritize local-device passkeys, and improve successful registration without UI changes. The rollout began in late August 2026 and is scheduled to complete by mid-September; no action is required.

  • New guidance covers HiBob provisioning and updating users in on-premises Active Directory through Entra API-driven provisioning and the provisioning agent, including prerequisites, permissions, connection setup, and synchronization flow.

  • One updated permissions reference describes Security Administrators as reading security information and reports and managing Entra ID and Office 365 configuration while removing identity-containment language; another same-day update says the role can perform containment actions. A separate role table limits the role to non-administrative accounts and excludes action on privileged accounts.

  • Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities. Owners or administrators must handle recovery.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

12 updates

4

Whats New

New feature

The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.

Delegate By Task

Feature update

The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.

Permissions Reference

Doc update

The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.

Least privileged roles by task

New feature

The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.

3

Permissions Reference

Doc update

The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.

Permissions Reference

Doc update

The role description now states that Security Administrators can perform identity containment actions during security incidents.

1

Privileged Roles Permissions

Doc update

The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.

1

Configure HiBob to Active Directory hybrid user provisioning

New feature

New documentation explains how HiBob can provision and update users in on-premises Active Directory through Microsoft Entra API-driven provisioning and the provisioning agent. It covers prerequisites, permissions, configuration, and synchronization flow.

1

Manage Agent Identities End User

Doc update

The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.

1

Agent Owners Sponsors Managers

Doc update

Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.

1

Apps

Doc update

The HR integrations table now includes a link for HiBob to Microsoft Entra ID/Active Directory and updates the Rippling provisioning link text.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…