← Previous day

Next day →
Plain-English daily brief

What changed on this day

25 changes were tracked across 6 Microsoft Entra products. The leading updates include Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy; Risky Agents; Microsoft Entra Agent Registry roles.

25 updates

General

4

Sso Linux

Updated

The Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):

Manage App Consent Policies

Updated

- **microsoft-user-default-recommended:** Permissions consentable based on Microsoft's current recommendations.

Authentication

2

Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

New

Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.

Message CenterMC1188230 on mc.merill.net ↗Major updatePlan for change

Governance

2

Fundamentals

1

Kerberos

Updated

For more information about Kerberos in Windows, see [Kerberos authentication overview in Windows Server](/windows-server/security/kerberos/kerberos-authentication-overview).

Monitoring

1

Troubleshooting

1

Security

3

Microsoft Entra Agent Registry roles

Updated

In the Microsoft Entra Agent Registry, you can assign roles to administrators or other security principals to manage agent instances, agent card manifests, and agent collections. These roles provide the permissions required to perform specific actions, such as creating or updating agent instances, create agent card manifests, or managing collection membership.

Microsoft Entra Agent Identities For Ai Agents

Updated

- Using real-time signals such as agent identities risk controlling agent access to resources, with Microsoft Managed Policies providing a secure baseline by blocking high-risk agents.

General

2

Authentication

1

Microsoft Entra Agent ID sign-in process

New

Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.

Monitoring

1

How are agent identities created?

Updated

Learn the channels and roles involved in creating Microsoft Entra agent identity blueprints, agent identities, and agent users. Monitor and control their introduction into your tenant.

Standards

1

Disable agent identities in your tenant

Updated

Agent identities are enabled by default in all Microsoft Entra ID tenants. Customers who want to control which Agent IDs are allowed in their tenant can follow the guidance in this article to configure their preferred settings. Microsoft Entra Agent ID is subject to its [standard preview terms and conditions](/entra/fundamentals/licensing-preview-info).

Troubleshooting

1

Fundamentals

2

Risky Agents

Updated

- ID Protection for agents is included with the Microsoft Entra P2 license while in preview.

Whats New Ignite 2025

Updated

- [Configure risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) (Updated)

Governance

1

Custom Data Resource Access Reviews

Updated

:::image type="content" source="media/custom-data-resource-access-reviews/upload-access-data-files.png" alt-text="Screenshot of uploading files to custom access data.":::

Monitoring

1

Security

1

Secure Web Ai Gateway Agents

Updated

- The enforcement feature supports only the baseline profile. Network security policies apply per tenant.