Discover how to set up Microsoft Entra join on a Windows 11 device during OOBE, ensuring seamless integration with your organization's directory.
Passkey API retirement sets the clearest long-term deadline; alert defaults, group recovery, and Agent ID preview controls shape November
November 2025 was primarily a documentation-maintenance period: 133 items were updated, compared with 3 new items and 7 removals, alongside 5 Message Center notices. The consequential changes were narrower and more specific: Entra ID announced a November preview of passkey profiles and a separate October–November 2027 retirement of two FIDO2 policy API properties; cloud security-group recovery is staged from preview to February 2026 general availability; and Defender XDR will change Entra ID Protection alert options and its default on December 11. Agent ID also received substantive preview operating and governance guidance. The remaining Learn edits were largely links, notes, prerequisites, and procedure clarifications—not evidence of broad new GA launches. Removed documentation pages likewise do not by themselves establish product retirements.
- Passkey profiles preview alongside a scheduled FIDO2 policy API retirementEntra ID — passkey and FIDO2 authentication methods policy
The Entra ID authentication methods policy notice describes a November 2025 preview of passkey profiles, adding group-based passkey controls and a new API schema, with worldwide and GCC rollout timing specified. It says no administrator action is needed before rollout, but recommends reviewing configurations and documentation. Separately, Microsoft will retire `isAttestationEnforced` and `keyRestrictions` from the `fido2AuthenticationMethodConfiguration` API in the October–November 2027 window; during transition,
- Cloud security groups gain soft deletion and restorationEntra ID — cloud security groups
Microsoft Entra announced soft deletion and restoration for cloud security groups. A deleted group can be recovered within 30 days while preserving settings, ownership, and membership; access is removed until restoration, and audit logs record the actions. The supplied rollout is preview beginning in late October 2025, followed by general availability in February 2026, so this is staged availability rather than evidence of a November GA launch.
- Defender XDR changes the default Entra ID Protection alert filterID Protection — Defender XDR alert settings
Starting December 11, 2025, Defender XDR will let administrators configure Entra ID Protection alerts as High only, High plus Medium, or All. High only becomes the default, reducing alert volume and improving clarity. This is a monitoring and default-behavior change, not a new risk-detection launch; teams that rely on Medium or all-risk alerts should review the setting and related operating processes.
- Agent ID preview guidance defines sign-in, default enablement, and governanceMicrosoft Entra Agent ID (preview) and ID Governance
New and updated Learn content documents the Agent ID sign-in flow, including consent pages, trust criteria, agent permissions, and known issues. Registry guidance explains roles for managing agent instances, agent card manifests, and collections. The disablement guidance says agent identities are enabled by default in all Entra ID tenants and explains how to control which Agent IDs are allowed; related access-package guidance presents agent access as intentional, auditable, and time-bound. These are operational and
- Security Copilot receives a phased Microsoft 365 E5 inclusion rolloutMicrosoft Security Copilot / Entra ID
A Message Center notice says Microsoft Security Copilot is included at no extra cost in Microsoft 365 E5, with AI-driven security agents spanning Defender, Entra, Intune, and Purview. The rollout is phased; monthly Security Compute Units are based on user count, and Entra ID group membership provides administrator controls. This is an E5 entitlement and rollout notice, not evidence that every tenant received the capability during November.
Inventory configurations, automation, and integrations that use `isAttestationEnforced` or `keyRestrictions` in the `fido2AuthenticationMethodConfiguration` API, and plan migration within the stated October–November 2027 retirement window. The passkey-profile notice says no action is required before its November preview rollout, but asks administrators to review configurations and documentation. Before December 11, check whether Defender XDR alert operations depend on Medium-risk or all-risk Entra ID Protection alerts, because High risk only will become the default. For cloud security groups, account for access being removed during deletion, the 30-day restoration window, and related audit records. If using the Agent ID preview, review its default-enabled posture, allow/disable controls,
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
148 updates by product
Microsoft Entra ID
66 updatesGeneral
23Assign Local Admin
Updated- Microsoft Entra groups deployed to a device with this policy don't apply to remote desktop connections. To control remote desktop permissions for Microsoft Entra joined devices, you need to add the individual user's SID to the appropriate group.
To scope a group for Source of Authority operations within an Administrative Unit, do the following steps:
To scope a user for Source of Authority operations within an Administrative Unit, do the following steps:
Sharepoint Administrator
Updated> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
> | microsoft.backup/siteRestoreArtifacts/allProperties/allTasks | Manage sites added to restore session for SharePoint in Microsoft 365 Backup |
> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |
Agent Registry Administrator
Updated> | Actions | Description |
Connect Version History
Updated11/19/2025: Released for download via the Microsoft Entra admin center.
Dragon Administrator
UpdatedA Microsoft Entra documentation page was updated: Dragon Administrator.
Global Administrator
UpdatedA Microsoft Entra documentation page was updated: Global Administrator.
Global Reader
UpdatedA Microsoft Entra documentation page was updated: Global Reader.
Permissions Reference
Updated> [!div class="mx-tableFixed"]
User Administrator
UpdatedA Microsoft Entra documentation page was updated: User Administrator.
Sso Linux
UpdatedThe Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):
Permissions Reference
Updated> | Role | Description | Template ID |
Manage App Consent Policies
Updated- **microsoft-user-default-recommended:** Permissions consentable based on Microsoft's current recommendations.
Agent Contact App Owners
RemovedA Microsoft Entra documentation page was updated: Agent Contact App Owners.
Assign the Exchange Backup Administrator role to users who need to do the following tasks:
Assign the SharePoint Backup Administrator role to users who need to do the following tasks:
Whats New
Updated| Date | Area | Description |
Refresh Tokens
Updatedauthor: cilwerner
Connect Health Agent Install
Updated| Requirement | Description |
Fundamentals
15Custom Extension Overview
UpdatedThe token issuance start event, **OnTokenIssuanceStart** is triggered when a token is about to be issued to an application. It is an event type set up within a [custom claims provider](custom-claims-provider-overview.md). The custom claims provider is a custom authentication extension that calls a REST API to fetch claims from external systems. A custom claims provider maps claims from external systems into tokens and can be assigned to one or many applications in your directory.
Whats New Archive
Updated**Type:** New feature
Whats New
UpdatedNative Authentication
Updated| | Browser-delegated authentication | Native authentication |
- [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 groups, and SharePoint sites](/purview/sensitivity-labels-teams-groups-sites)
Token Protection
Updated- Windows Server 2019 or newer that are hybrid Microsoft Entra joined.
Kerberos
UpdatedFor more information about Kerberos in Windows, see [Kerberos authentication overview in Windows Server](/windows-server/security/kerberos/kerberos-authentication-overview).
Configure Security
UpdatedManually checking this guidance against a tenant's configuration can be time-consuming and error-prone. The Zero Trust Assessment transforms this process with automation to test for these security configuration items and more. Learn more in [What is the Zero Trust Assessment?](/security/zero-trust/assessment/overview)
A Microsoft Entra documentation page was updated: Customer intent: As a cloud administrator, I want to understand how Microsoft Entra ID handles data residency, so that I can ensure compliance with data residency requirements and make informed decisions about storing and managing identity and access data in the cloud..
Fido2 Compatibility
Updatedauthor: justinha
Configure Security
Updated|---|---|
> [!IMPORTANT]
Whats New Archive
Updated**Type:** New feature
A Microsoft Entra documentation page was updated: Zero Trust Protect Identities.
Whats New
UpdatedA Microsoft Entra documentation page was updated: Whats New.
Authentication
13- Platform credential for macOS (preview)
Content Security Policy
Updated- **Step 1**: Go through a sign-in flow with the dev console open to identify any violations.
Default application
Updatedmanager: mwongerapk
Kerberos
UpdatedFor example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Microsoft Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.
Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.
1. To add a redirect URI to the app that you registered earlier, use the steps in [Add a platform redirect URL](quickstart-mobile-app-sign-in.md#add-a-redirect-uri).
> [!NOTE]
Mfa Number Match Preview
RemovedA Microsoft Entra documentation page was updated: Mfa Number Match Preview.
author: justinha
Learn about improvemenst to number matching in for Microsoft Authenticator.
Howto Mfa App Passwords
Updatedminimumlicense: Free
Updated- [Deploy Conditional Access policy to target privileged accounts and require phishing resistant credentials using authentication strengths](/entra/identity/conditional-access/policy-admin-phish-resistant-mfa)
Feature Availability
Updated|Workday Writeback | ✅ |
Provisioning
3User provisioning for Slack
UpdatedLearn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Slack.
In order to enable SSL to work, you need to grant the NETWORK SERVICE read permissions to our newly created certificate. To grant permissions, use the following steps.
ai-usage: ai-assisted
Standards
3Microsoft Entra entitlement management provides access packages as a governance mechanism. Access packages ensure that agent access assignments are intentional, auditable, and time-bound. Access packages represent a structured approach to managing agent identity permissions, contrasting with ad-hoc permission assignments that might lack appropriate governance controls. Access packages enable standardized access for many AI Agents with the same access needs, for example, a fleet of customer support AI Agents. Through access packages, organizations can establish consistent governance practices for all agent identity resource access. For more information, see [Governing agent identities](/entra/id-governance/agent-id-governance-overview).
V2 Oauth2 On Behalf Of Flow
Updated"scope": "https://graph.microsoft.com/user.read",
Bis Tutorial
Updated1. On the **Basic SAML Configuration** section, perform the following step:
Governance
2A Microsoft Entra documentation page was updated: Agent App Lifecycle Discovery Onboard.
A Microsoft Entra documentation page was updated: Agent App Lifecycle Management.
Monitoring
2- [How to use Microsoft Entra health monitoring signals and alerts](/entra/identity/monitoring-health/howto-use-health-scenario-alerts)
- The `Group.Read.All` permission is the least privileged permission required to *view groups*.
Troubleshooting
2Authenticate Application Id
UpdatedMicrosoft Entra Connect warns if the certificate rotation is due. That is, if expiration is less than or equal to 30 days. It emits an error if the certificate is already expired. You can find these warnings (Event ID 1011) and errors (Event ID 1012) in the Application event log.
A Microsoft Entra documentation page was updated: Agent App Lifecycle Remediation Plans.
Architecture
1Microsoft Entra introduces soft deletion and restoration for cloud security groups, allowing recovery within 30 days while preserving settings, ownership, and membership. Rollout begins in late October 2025 (preview) and February 2026 (general availability). Deleted groups remove access until restored; audit logs track actions.
Conditional Access
1To identify Intune device compliance and app protection policies, the agent must be running as a Global Administrator or Conditional Access Administrator AND Global Reader. Conditional Access Administrator isn't sufficient on its own for the agent to produce Intune suggestions.
Microsoft identity platform
1In November 2025, Microsoft Entra ID will preview passkey profiles in the authentication methods policy, enabling group-based passkey controls and new API schema. Rollout occurs worldwide early November and GCC mid-November. No admin action is needed before rollout; admins should review configurations and update documentation.
Microsoft Entra Agent ID
17 updatesGeneral
5- Ensure sponsors and owners are assigned and maintained for each agent ID, preventing orphaned agent IDs.
1. In the **Agent collections** view, you see a tabbed section containing two options:
Agent Id Administrator
Updated> | --- | --- |
Preview Known Issues
UpdatedThe following known issues and gaps relate to consent and permissions.
The type of permissions you request depends on how your agent operates and what resources it needs to access.
Security
3In the Microsoft Entra Agent Registry, you can assign roles to administrators or other security principals to manage agent instances, agent card manifests, and agent collections. These roles provide the permissions required to perform specific actions, such as creating or updating agent instances, create agent card manifests, or managing collection membership.
- Using real-time signals such as agent identities risk controlling agent access to resources, with Microsoft Managed Policies providing a secure baseline by blocking high-risk agents.
A Microsoft Entra documentation page was updated: Agent Identify Prioritize Risky Apps.
Standards
3* the SAML helper application registration as the resource
Applications using the Microsoft Entra identity platform can [expose APIs for other client applications to call](../../identity-platform/quickstart-configure-app-expose-web-apis.md#register-the-web-api). The application with the API can expose OAuth scopes for those API calls. The tool's service principal can be consented permission to those scopes, allowing it to call the APIs.
Agent identities are enabled by default in all Microsoft Entra ID tenants. Customers who want to control which Agent IDs are allowed in their tenant can follow the guidance in this article to configure their preferred settings. Microsoft Entra Agent ID is subject to its [standard preview terms and conditions](/entra/fundamentals/licensing-preview-info).
Authentication
1Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.
Fundamentals
1Agent Id Governance Overview
UpdatedAgent identities can have resources assigned to them directly via access packages. Resource assignments allow agent identities to request an access package for themselves, or have their owner or sponsor request one on their behalf. With Access packages, you're able to assign agent identities the following resources:
Governance
1Security For Ai
UpdatedAgent proliferation creates a governance challenge termed "agent sprawl"—the uncontrolled expansion of agents across an organization without adequate visibility, management, or lifecycle controls.
Microsoft identity platform
1Agent Id Developer
Updated> | Actions | Description |
Monitoring
1Learn the channels and roles involved in creating Microsoft Entra agent identity blueprints, agent identities, and agent users. Monitor and control their introduction into your tenant.
Troubleshooting
1Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.
Microsoft Entra ID Protection
4 updatesFundamentals
2Risky Agents
Updated- ID Protection for agents is included with the Microsoft Entra P2 license while in preview.
Whats New Ignite 2025
Updated- [Configure risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) (Updated)
Architecture
1Id Protection Guide Analyze
UpdatedA Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.
Monitoring
1Starting December 11, 2025, Microsoft Defender XDR will offer enhanced alert configuration for Entra ID Protection, allowing admins to filter alerts by risk level (High only, High + Medium, or All). The default will change to High risk only, reducing alert volume and improving clarity.
Microsoft Entra ID Governance
30 updatesGovernance
21If you need to add resources such as groups or apps to an access package, you should check whether the resources you need are available in the access package's catalog. If you're an access package manager, you can't add resources to a catalog, even if you own them. You're restricted to using the resources available in the catalog.
If you're not sure which resource roles to include, you can skip adding them while creating the access package, and then [add them](entitlement-management-access-package-resources.md) later.
- [Understanding least privileged](least-privileged.md)
Custom Extension Security
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](~/identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) of the catalog where the custom extension will be located.
After you create the access package, you can directly assign specific internal and external users to it. If you specify an external user, a guest user account is created in your directory. For information about directly assigning a user, see [View, add, and remove assignments for an access package](~/id-governance/entitlement-management-access-package-assignments.md).
> [!NOTE]
1. Select **New assignment** to open Add user to access package.
:::image type="content" source="media/custom-data-resource-access-reviews/upload-access-data-files.png" alt-text="Screenshot of uploading files to custom access data.":::
This article describes sensitivity labels in Workflows, and how to see them during the task creation process.
This article guides a user on reprocessing workflow runs using Lifecycle Workflows
Maintaining and classifying secure data within your environment is an important part in maintaining a secure environment. Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization's data, while making sure that user productivity and their ability to collaborate isn't hindered. With sensitivity labels in Lifecycle Workflows, administrators are able to quickly view the sensitivity labels of groups during creation, and editing, of workflow tasks.
- You won't be able to create new access reviews scoped to guest users if any of the following features are selected:
To use Microsoft Entra ID Governance features for guest users, your tenant must be linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. If the guest billing meter isn't enabled, the following behavior applies:
Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.
This article discusses how to use Custom Attribute Triggers as an attribute change trigger within a workflow in Lifecycle Workflows.
Manage Workflow Properties
Updated7. Update the desired properties.
Fundamentals
5This following document discusses Microsoft Entra ID Governance licensing for employees. It's intended for IT decision makers, IT administrators, and IT professionals who are considering Microsoft Entra ID Governance services for their organizations.
A Microsoft Entra documentation page was updated: Entitlement Management Overview.
Identity Governance Overview
Updated| Provisioning users into on-premises and cloud applications that have their own directories or databases | [Configure automatic user provisioning](../identity/app-provisioning/user-provisioning.md) with user assignments or [scoping filters](../identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md) |
Guest users refer to external users that have been invited into your directory with [Microsoft Entra B2B](../external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](../fundamentals/users-default-permissions.md).
Guest users are external identities who have been invited into your directory via [Microsoft Entra B2B](~/external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](~/fundamentals/users-default-permissions.md).
Architecture
2Follow these steps to create an Entitlement management catalog:
Follow these steps to create an Entitlement management catalog for the scenario.
Authentication
11. [Sign in to the My Access portal](entitlement-management-request-access.md#sign-in-to-the-my-access-portal)
Microsoft identity platform
1Microsoft Security Copilot is now included at no extra cost in Microsoft 365 E5, providing integrated AI-driven security agents across Defender, Entra, Intune, and Purview. Customers receive monthly Security Compute Units based on user count, with phased rollout and admin controls via Entra ID group membership.
Microsoft Entra External ID
14 updatesFundamentals
5Supported Features Customers
UpdatedMicrosoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include Distributed Denial-of-Service (DDoS) attack protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.
Supported Features Customers
UpdatedMicrosoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include edge protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.
Whats New Docs
Updated- [Identity providers for external tenants](customers/concept-authentication-methods-customers.md) - Added domain acceleration information
Solutions Customers
RemovedA Microsoft Entra documentation page was updated: Solutions Customers.
Security Customers
UpdatedGeneral
5Tenant Restrictions V2
Updated- All Office apps (all versions/release channels)
Cross Tenant Custom Roles
Updated| Actions |
Configure Akamai Integration
Updated- An [external tenant](how-to-create-external-tenant-portal.md).
Configure Waf Integration
UpdatedOnce you’ve connected Cloudflare WAF with Microsoft Entra External ID, it’s important to test the configuration to ensure everything is working as expected.
A Microsoft Entra documentation page was updated: Create External Tenant Portal.
Branding
1> Branding themes for applications are currently in PREVIEW.
Microsoft identity platform
1Native Authentication Api
Updated1. [Associate your app registration with the user flow](../external-id/customers/how-to-user-flow-add-application.md).
Monitoring
1Azure Monitor
Updated> If you select **Review** before adding settings, the **Subscription** and **Resource group** appear on the right-hand side. These fields are read-only. To make changes, remove the existing service provider information and restart the wizard.
Security
1Integrate Microsoft Entra External ID with Arkose Labs and HUMAN Security for fraud protection
UpdatedTo integrate Arkose Labs with Microsoft Entra External ID, you can use the Security Store wizard in Microsoft Entra admin center to create a fraud protection provider policy.
Microsoft Entra Internet Access
3 updatesFundamentals
1The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.
General
1Current Known Limitations
UpdatedKnown limitations for Internet Access include:
Monitoring
1- Select the **Internet applications blocked by Entra Internet Access Policy** scenario.
Microsoft Entra Private Access
1 updateGeneral
1Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.
Microsoft Entra Verified ID
3 updatesGeneral
2Idv Partners
Updatedauthor: barclayn
Whats New
UpdatedThis article lists the latest features, improvements, and changes in the Microsoft Entra Verified ID service.
Security
1Idv Partners
Updated| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |
Microsoft Entra Workload ID
1 updateSecurity
1Creation of federated identity credentials is currently **not supported** on user-assigned managed identities created in the following regions:
Microsoft Entra Global Secure Access
9 updatesFundamentals
3Transport Layer Security
Updated|AES256-SHA |
manager: sineado
Partner Ecosystems Overview
Updatedauthor: kenwith
General
3Macos Client Release History
UpdatedTrack the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.
Configure Domain Controllers
Updated- Client IP address
Configure Domain Controllers
Updated1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
Security
3Learn how to configure a Transport Layer Security inspection policy and assign it to users in your organization.
Learn how to configure a Transport Layer Security inspection certificate authority
Secure Web Ai Gateway Agents
Updated- The enforcement feature supports only the baseline profile. Network security policies apply per tenant.
