← Previous day

Next day →
Plain-English daily brief

What changed on this day

1798 changes were tracked across 3 Microsoft Entra products. The leading updates include userimpact: Low; Configure Forcepoint Cloud Security Gateway - User Authentication for automatic user provisioning with Microsoft Entra ID; Configure Forcepoint Cloud Security Gateway - User Authentication for Single sign-on with Microsoft Entra ID.

1798 updates

Microsoft Entra ID

1789 updates

General

1476

Provisioning

162

Standards

54

Security

32

Monitoring

31

Authentication

14

Developer

10

Troubleshooting

4

61008

Updated

**Remediation action**

61011

Updated

**Remediation action**

61006

Updated

**Remediation action**

Governance

3

Fundamentals

2

Zero Trust Ai

Updated

A Microsoft Entra documentation page was updated: Zero Trust Ai.

Architecture

1

Governance

3

userimpact: Low

Updated

Microsoft Entra Agent ID requires every [agent identity](/entra/agent-id/agent-identities) and [agent identity blueprint](/entra/agent-id/agent-blueprint) to have at least one sponsor. A sponsor is a human user, or supported group, that holds business accountability for the agent's lifecycle, such as deciding when the agent is no longer needed, approving extensions when access expires, and authorizing suspension during incidents. A sponsor is different from an owner, which designates the human users responsible for technical operations and incident response.

userimpact: Medium

Updated

Microsoft Entra Agent ID introduced two identity types: [agent identities](/entra/agent-id/agent-identities) and [agent identity blueprint principals](/entra/agent-id/agent-blueprint). These identity objects derive from service principals, and so carry the same requirements and best practices for ownership, lifecycle management, and cleanup as any service principal. Blueprint principals are the provisioning surface from which agent identities are created and can hold grants that propagate to child agents. Having a designated owner for these objects helps in two important areas of agent identity management:

Licensing Governance

Updated

|[EM - Agents and service principals assigned to access packages](~/id-governance/entitlement-management-access-package-create.md#allow-users-service-principals-and-agent-identities-in-your-directory-to-request-the-access-package)|||||| :white_check_mark: |

Conditional Access

2

userimpact: Low

Updated

When an organization enables AI agents in Microsoft Entra, [agent identities](/entra/agent-id/agent-identities) can access tokens to access organizational resources without an interactive user session and device, location, or MFA signals that classic Conditional Access uses to make trust decisions for human users. Microsoft Entra ID Protection for agents continuously evaluates each agent's behavior and emits a risk level that is driven by signals such as:

61009

Updated

When an organization deploys AI agents, those agents acquire access tokens to access organizational resources on every interaction, but without an interactive user session and device, location, or MFA signals that classic Conditional Access uses to make trust decisions for human users. Microsoft Entra Agent ID introduces two distinct identity types:

Authentication

1

Developer

1

Validate Agent Tokens Downstream Api

Updated

:::image type="content" source="media/how-to-validate-agent-tokens-downstream-api/agent-token-flow-to-downstream-api.png" alt-text="Diagram showing the agent caller sending a Bearer token to the weather API, which verifies the token and calls Open-Meteo." lightbox="media/how-to-validate-agent-tokens-downstream-api/agent-token-flow-to-downstream-api.png":::

General

1

General

1