Month in brief

Passkey API retirement sets the clearest long-term deadline; alert defaults, group recovery, and Agent ID preview controls shape November

November 2025 was primarily a documentation-maintenance period: 133 items were updated, compared with 3 new items and 7 removals, alongside 5 Message Center notices. The consequential changes were narrower and more specific: Entra ID announced a November preview of passkey profiles and a separate October–November 2027 retirement of two FIDO2 policy API properties; cloud security-group recovery is staged from preview to February 2026 general availability; and Defender XDR will change Entra ID Protection alert options and its default on December 11. Agent ID also received substantive preview operating and governance guidance. The remaining Learn edits were largely links, notes, prerequisites, and procedure clarifications—not evidence of broad new GA launches. Removed documentation pages likewise do not by themselves establish product retirements.

  • Passkey profiles preview alongside a scheduled FIDO2 policy API retirementEntra ID — passkey and FIDO2 authentication methods policy

    The Entra ID authentication methods policy notice describes a November 2025 preview of passkey profiles, adding group-based passkey controls and a new API schema, with worldwide and GCC rollout timing specified. It says no administrator action is needed before rollout, but recommends reviewing configurations and documentation. Separately, Microsoft will retire `isAttestationEnforced` and `keyRestrictions` from the `fido2AuthenticationMethodConfiguration` API in the October–November 2027 window; during transition,

  • Cloud security groups gain soft deletion and restorationEntra ID — cloud security groups

    Microsoft Entra announced soft deletion and restoration for cloud security groups. A deleted group can be recovered within 30 days while preserving settings, ownership, and membership; access is removed until restoration, and audit logs record the actions. The supplied rollout is preview beginning in late October 2025, followed by general availability in February 2026, so this is staged availability rather than evidence of a November GA launch.

  • Defender XDR changes the default Entra ID Protection alert filterID Protection — Defender XDR alert settings

    Starting December 11, 2025, Defender XDR will let administrators configure Entra ID Protection alerts as High only, High plus Medium, or All. High only becomes the default, reducing alert volume and improving clarity. This is a monitoring and default-behavior change, not a new risk-detection launch; teams that rely on Medium or all-risk alerts should review the setting and related operating processes.

  • Agent ID preview guidance defines sign-in, default enablement, and governanceMicrosoft Entra Agent ID (preview) and ID Governance

    New and updated Learn content documents the Agent ID sign-in flow, including consent pages, trust criteria, agent permissions, and known issues. Registry guidance explains roles for managing agent instances, agent card manifests, and collections. The disablement guidance says agent identities are enabled by default in all Entra ID tenants and explains how to control which Agent IDs are allowed; related access-package guidance presents agent access as intentional, auditable, and time-bound. These are operational and

  • Security Copilot receives a phased Microsoft 365 E5 inclusion rolloutMicrosoft Security Copilot / Entra ID

    A Message Center notice says Microsoft Security Copilot is included at no extra cost in Microsoft 365 E5, with AI-driven security agents spanning Defender, Entra, Intune, and Purview. The rollout is phased; monthly Security Compute Units are based on user count, and Entra ID group membership provides administrator controls. This is an E5 entitlement and rollout notice, not evidence that every tenant received the capability during November.

For Entra administrators

Inventory configurations, automation, and integrations that use `isAttestationEnforced` or `keyRestrictions` in the `fido2AuthenticationMethodConfiguration` API, and plan migration within the stated October–November 2027 retirement window. The passkey-profile notice says no action is required before its November preview rollout, but asks administrators to review configurations and documentation. Before December 11, check whether Defender XDR alert operations depend on Medium-risk or all-risk Entra ID Protection alerts, because High risk only will become the default. For cloud security groups, account for access being removed during deletion, the 30-day restoration window, and related audit records. If using the Agent ID preview, review its default-enabled posture, allow/disable controls, ­

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

148 updates by product

General

23

Assign Local Admin

Updated

- Microsoft Entra groups deployed to a device with this policy don't apply to remote desktop connections. To control remote desktop permissions for Microsoft Entra joined devices, you need to add the individual user's SID to the appropriate group.

21 November 2025

Sharepoint Administrator

Updated

> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |

20 November 2025

Connect Version History

Updated

11/19/2025: Released for download via the Microsoft Entra admin center.

20 November 2025

Dragon Administrator

Updated

A Microsoft Entra documentation page was updated: Dragon Administrator.

20 November 2025

Global Administrator

Updated

A Microsoft Entra documentation page was updated: Global Administrator.

20 November 2025

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

20 November 2025

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

20 November 2025

Sso Linux

Updated

The Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):

19 November 2025

Manage App Consent Policies

Updated

- **microsoft-user-default-recommended:** Permissions consentable based on Microsoft's current recommendations.

19 November 2025

Agent Contact App Owners

Removed

A Microsoft Entra documentation page was updated: Agent Contact App Owners.

19 November 2025

Whats New

Updated

| Date | Area | Description |

8 November 2025

Fundamentals

15

Custom Extension Overview

Updated

The token issuance start event, **OnTokenIssuanceStart** is triggered when a token is about to be issued to an application. It is an event type set up within a [custom claims provider](custom-claims-provider-overview.md). The custom claims provider is a custom authentication extension that calls a REST API to fetch claims from external systems. A custom claims provider maps claims from external systems into tokens and can be assigned to one or many applications in your directory.

26 November 2025

Native Authentication

Updated

| | Browser-delegated authentication | Native authentication |

22 November 2025

Conditional Access Cloud Apps

Updated

- [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 groups, and SharePoint sites](/purview/sensitivity-labels-teams-groups-sites)

21 November 2025

Token Protection

Updated

- Windows Server 2019 or newer that are hybrid Microsoft Entra joined.

21 November 2025

Kerberos

Updated

For more information about Kerberos in Windows, see [Kerberos authentication overview in Windows Server](/windows-server/security/kerberos/kerberos-authentication-overview).

19 November 2025

Configure Security

Updated

Manually checking this guidance against a tenant's configuration can be time-consuming and error-prone. The Zero Trust Assessment transforms this process with automation to test for these security configuration items and more. Learn more in [What is the Zero Trust Assessment?](/security/zero-trust/assessment/overview)

8 November 2025

Whats New

Updated

A Microsoft Entra documentation page was updated: Whats New.

1 November 2025

Authentication

13

Content Security Policy

Updated

- **Step 1**: Go through a sign-in flow with the dev console open to identify any violations.

26 November 2025

Kerberos

Updated

For example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Microsoft Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.

21 November 2025

Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

New

Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.

20 November 2025
Message CenterMC1188230 on mc.merill.net ↗Major updatePlan for change

Mfa Number Match Preview

Removed

A Microsoft Entra documentation page was updated: Mfa Number Match Preview.

7 November 2025

minimumlicense: Free

Updated

- [Deploy Conditional Access policy to target privileged accounts and require phishing resistant credentials using authentication strengths](/entra/identity/conditional-access/policy-admin-phish-resistant-mfa)

4 November 2025

Provisioning

3

User provisioning for Slack

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Slack.

27 November 2025

On Premises Ldap Connector Prepare Directory

Updated

In order to enable SSL to work, you need to grant the NETWORK SERVICE read permissions to our newly created certificate. To grant permissions, use the following steps.

26 November 2025

Standards

3

Access packages for Agent identities in Microsoft Entra ID

Updated

Microsoft Entra entitlement management provides access packages as a governance mechanism. Access packages ensure that agent access assignments are intentional, auditable, and time-bound. Access packages represent a structured approach to managing agent identity permissions, contrasting with ad-hoc permission assignments that might lack appropriate governance controls. Access packages enable standardized access for many AI Agents with the same access needs, for example, a fleet of customer support AI Agents. Through access packages, organizations can establish consistent governance practices for all agent identity resource access. For more information, see [Governing agent identities](/entra/id-governance/agent-id-governance-overview).

26 November 2025

Bis Tutorial

Updated

1. On the **Basic SAML Configuration** section, perform the following step:

20 November 2025

Governance

2

Monitoring

2

Troubleshooting

2

Authenticate Application Id

Updated

Microsoft Entra Connect warns if the certificate rotation is due. That is, if expiration is less than or equal to 30 days. It emits an error if the certificate is already expired. You can find these warnings (Event ID 1011) and errors (Event ID 1012) in the Application event log.

20 November 2025

Architecture

1

Conditional Access

1

Conditional Access Agent Optimization

Updated

To identify Intune device compliance and app protection policies, the agent must be running as a Global Administrator or Conditional Access Administrator AND Global Reader. Conditional Access Administrator isn't sufficient on its own for the agent to produce Intune suggestions.

1 November 2025

Microsoft identity platform

1

Entra ID: Upcoming changes to support passkey profiles in the authentication methods policy (preview)

New

In November 2025, Microsoft Entra ID will preview passkey profiles in the authentication methods policy, enabling group-based passkey controls and new API schema. Rollout occurs worldwide early November and GCC mid-November. No admin action is needed before rollout; admins should review configurations and update documentation.

6 November 2025
Message CenterMC1097225 on mc.merill.net ↗Major updatePlan for change

General

5

Preview Known Issues

Updated

The following known issues and gaps relate to consent and permissions.

19 November 2025

Grant Agent Access Microsoft 365

Updated

The type of permissions you request depends on how your agent operates and what resources it needs to access.

19 November 2025

Security

3

Microsoft Entra Agent Registry roles

Updated

In the Microsoft Entra Agent Registry, you can assign roles to administrators or other security principals to manage agent instances, agent card manifests, and agent collections. These roles provide the permissions required to perform specific actions, such as creating or updating agent instances, create agent card manifests, or managing collection membership.

19 November 2025

Microsoft Entra Agent Identities For Ai Agents

Updated

- Using real-time signals such as agent identities risk controlling agent access to resources, with Microsoft Managed Policies providing a secure baseline by blocking high-risk agents.

19 November 2025

Standards

3

Assign Agent Identities To Applications

Updated

Applications using the Microsoft Entra identity platform can [expose APIs for other client applications to call](../../identity-platform/quickstart-configure-app-expose-web-apis.md#register-the-web-api). The application with the API can expose OAuth scopes for those API calls. The tool's service principal can be consented permission to those scopes, allowing it to call the APIs.

21 November 2025

Disable agent identities in your tenant

Updated

Agent identities are enabled by default in all Microsoft Entra ID tenants. Customers who want to control which Agent IDs are allowed in their tenant can follow the guidance in this article to configure their preferred settings. Microsoft Entra Agent ID is subject to its [standard preview terms and conditions](/entra/fundamentals/licensing-preview-info).

19 November 2025

Authentication

1

Microsoft Entra Agent ID sign-in process

New

Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.

19 November 2025

Fundamentals

1

Agent Id Governance Overview

Updated

Agent identities can have resources assigned to them directly via access packages. Resource assignments allow agent identities to request an access package for themselves, or have their owner or sponsor request one on their behalf. With Access packages, you're able to assign agent identities the following resources:

27 November 2025

Governance

1

Security For Ai

Updated

Agent proliferation creates a governance challenge termed "agent sprawl"—the uncontrolled expansion of agents across an organization without adequate visibility, management, or lifecycle controls.

26 November 2025

Microsoft identity platform

1

Monitoring

1

How are agent identities created?

Updated

Learn the channels and roles involved in creating Microsoft Entra agent identity blueprints, agent identities, and agent users. Monitor and control their introduction into your tenant.

19 November 2025

Troubleshooting

1

Fundamentals

2

Risky Agents

Updated

- ID Protection for agents is included with the Microsoft Entra P2 license while in preview.

19 November 2025

Whats New Ignite 2025

Updated

- [Configure risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) (Updated)

19 November 2025

Architecture

1

Id Protection Guide Analyze

Updated

A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.

7 November 2025

Monitoring

1

Governance

21

Entitlement Management Access Package Resources

Updated

If you need to add resources such as groups or apps to an access package, you should check whether the resources you need are available in the access package's catalog. If you're an access package manager, you can't add resources to a catalog, even if you own them. You're restricted to using the resources available in the catalog.

27 November 2025

Entitlement Management Access Package Create

Updated

If you're not sure which resource roles to include, you can skip adding them while creating the access package, and then [add them](entitlement-management-access-package-resources.md) later.

27 November 2025

Custom Extension Security

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Catalog Create

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Custom Data Resource Access Reviews

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Delegate Managers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Delegate

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](~/identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Dynamic Approval

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) of the catalog where the custom extension will be located.

26 November 2025

Entra Entitlement Management Request Policy

Updated

After you create the access package, you can directly assign specific internal and external users to it. If you specify an external user, a guest user account is created in your directory. For information about directly assigning a user, see [View, add, and remove assignments for an access package](~/id-governance/entitlement-management-access-package-assignments.md).

21 November 2025

Custom Data Resource Access Reviews

Updated

:::image type="content" source="media/custom-data-resource-access-reviews/upload-access-data-files.png" alt-text="Screenshot of uploading files to custom access data.":::

19 November 2025

Sensitivity labels in Lifecycle Workflows

Updated

Maintaining and classifying secure data within your environment is an important part in maintaining a secure environment. Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization's data, while making sure that user productivity and their ability to collaborate isn't hindered. With sensitivity labels in Lifecycle Workflows, administrators are able to quickly view the sensitivity labels of groups during creation, and editing, of workflow tasks.

11 November 2025

Microsoft Entra Id Governance Licensing For Guest Users

Updated

To use Microsoft Entra ID Governance features for guest users, your tenant must be linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. If the guest billing meter isn't enabled, the following behavior applies:

6 November 2025

Delegated workflow management (preview)

Updated

Workflows by default, unless specified during creation, are managed by users with either the Lifecycle Workflows, or Global, administrator roles. As workflows grow and change to meet the needs of members of your organization, so does the need to limit who can manage them. With delegated workflow management, you can scope management of workflows using [Administrative Units](../identity/role-based-access-control/administrative-units.md). When scoped, specific admins are only granted access to manage specific workflows. Scoping allows for greater security within your environment by following Microsoft's least privileged access guidelines by only giving access to specifically what's needed.

1 November 2025

Fundamentals

5

Microsoft Entra ID Governance licensing fundamentals

Updated

This following document discusses Microsoft Entra ID Governance licensing for employees. It's intended for IT decision makers, IT administrators, and IT professionals who are considering Microsoft Entra ID Governance services for their organizations.

27 November 2025

Identity Governance Overview

Updated

| Provisioning users into on-premises and cloud applications that have their own directories or databases | [Configure automatic user provisioning](../identity/app-provisioning/user-provisioning.md) with user assignments or [scoping filters](../identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md) |

27 November 2025

Entitlement Management Access Package Request Policy

Updated

Guest users refer to external users that have been invited into your directory with [Microsoft Entra B2B](../external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](../fundamentals/users-default-permissions.md).

27 November 2025

Entra Entitlement Management Request Policy

Updated

Guest users are external identities who have been invited into your directory via [Microsoft Entra B2B](~/external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](~/fundamentals/users-default-permissions.md).

27 November 2025

Architecture

2

Authentication

1

Entitlement Management Scenarios

Updated

1. [Sign in to the My Access portal](entitlement-management-request-access.md#sign-in-to-the-my-access-portal)

27 November 2025

Microsoft identity platform

1

Fundamentals

5

Supported Features Customers

Updated

Microsoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include Distributed Denial-of-Service (DDoS) attack protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.

28 November 2025

Supported Features Customers

Updated

Microsoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include edge protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.

27 November 2025

Whats New Docs

Updated

- [Identity providers for external tenants](customers/concept-authentication-methods-customers.md) - Added domain acceleration information

26 November 2025

Solutions Customers

Removed

A Microsoft Entra documentation page was updated: Solutions Customers.

26 November 2025

General

5

Configure Waf Integration

Updated

Once you’ve connected Cloudflare WAF with Microsoft Entra External ID, it’s important to test the configuration to ensure everything is working as expected.

11 November 2025

Branding

1

Microsoft identity platform

1

Native Authentication Api

Updated

1. [Associate your app registration with the user flow](../external-id/customers/how-to-user-flow-add-application.md).

22 November 2025

Monitoring

1

Azure Monitor

Updated

> If you select **Review** before adding settings, the **Subscription** and **Resource group** appear on the right-hand side. These fields are read-only. To make changes, remove the existing service provider information and restart the wizard.

7 November 2025

Security

1

Fundamentals

1

What is Transport Layer Security inspection?

Updated

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

20 November 2025

General

1

Monitoring

1

General

1

Enable Intelligent Local Access (preview)

Updated

Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.

8 November 2025

General

2

Whats New

Updated

This article lists the latest features, improvements, and changes in the Microsoft Entra Verified ID service.

7 November 2025

Security

1

Idv Partners

Updated

| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |

6 November 2025

Security

1

Fundamentals

3

General

3

Macos Client Release History

Updated

Track the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.

26 November 2025

Security

3

Secure Web Ai Gateway Agents

Updated

- The enforcement feature supports only the baseline profile. Network security policies apply per tenant.

19 November 2025