Week in brief

Passkey-profile preview and 30-day cloud-group recovery headline the week of 3 November 2025

The period was chiefly documentation maintenance: no new documentation entries were recorded, while 28 were updated and one was removed. The two Microsoft 365 Message Center notices carry the clearest product-level implications: a November preview of passkey profiles in the Microsoft Entra ID authentication methods policy and a staged rollout of soft deletion and restoration for cloud security groups. Other notable entries are documentation clarifications or procedures for preview and integration scenarios, not evidence of new launches. The removed Mfa Number Match Preview page, alongside an updated article on same-device number matching, does not by itself establish that the Authenticator capability was retired.

  • A 6 November Message Center major update says Microsoft Entra ID will preview passkey profiles in November 2025. The capability enables group-based passkey controls and introduces a new API schema. The notice describes worldwide rollout in early November and GCC rollout in mid-November. No preparation is required before rollout, although administrators should review existing configurations and update internal documentation.

  • A 6 November Message Center notice describes recovery of deleted cloud security groups within 30 days while preserving settings, ownership, and membership. Deleted groups remove access until they are restored, and audit logs track the actions. The notice places the preview rollout in late October 2025 and general availability in February 2026, so this is a preview-to-GA rollout rather than a GA change during the supplied week.

  • Updates on 6 and 7 November state that guest-user governance requires a tenant linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. They also document that, when the guest billing meter is not enabled, new access reviews scoped to guest users cannot be created when any of the specified features is selected. The supplied evidence presents this as clarified guidance, not as an announced new licensing-policy change.

  • An 8 November update explains how to enable Intelligent Local Access for Microsoft Entra Private Access. The preview capability is described as optimizing traffic flow for clients accessing Entra apps through private networks. Because the record is an updated enablement guide and provides no rollout or GA date, it should not be treated as a new launch this week.

  • A 6 November External ID security article documents integration with Arkose Labs and HUMAN Security. Its supplied procedure specifically says Arkose Labs can be configured through the Security Store wizard in the Microsoft Entra admin center to create a fraud protection provider policy. The evidence establishes setup guidance, but not a new provider launch or availability milestone.

For Entra administrators

The passkey notice explicitly says no action is needed before rollout, but asks administrators to review configurations and update documentation. For cloud security groups, deletion removes access until restoration, and the recovery window is 30 days; audit logs record the related actions. Guest-governance tenants must account for the stated Azure subscription, add-on, and billing-meter conditions. The Private Access and External ID items provide enablement or integration guidance, with no supplied GA or rollout announcement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Authentication

5

Mfa Number Match Preview

Removed

A Microsoft Entra documentation page was updated: Mfa Number Match Preview.

7 November 2025

minimumlicense: Free

Updated

- [Deploy Conditional Access policy to target privileged accounts and require phishing resistant credentials using authentication strengths](/entra/identity/conditional-access/policy-admin-phish-resistant-mfa)

4 November 2025

Fundamentals

5

Configure Security

Updated

Manually checking this guidance against a tenant's configuration can be time-consuming and error-prone. The Zero Trust Assessment transforms this process with automation to test for these security configuration items and more. Learn more in [What is the Zero Trust Assessment?](/security/zero-trust/assessment/overview)

8 November 2025

General

5

Whats New

Updated

| Date | Area | Description |

8 November 2025

Architecture

1

Microsoft identity platform

1

Entra ID: Upcoming changes to support passkey profiles in the authentication methods policy (preview)

New

In November 2025, Microsoft Entra ID will preview passkey profiles in the authentication methods policy, enabling group-based passkey controls and new API schema. Rollout occurs worldwide early November and GCC mid-November. No admin action is needed before rollout; admins should review configurations and update documentation.

6 November 2025
Message CenterMC1097225 on mc.merill.net ↗Major updatePlan for change

Architecture

1

Id Protection Guide Analyze

Updated

A Log Analytics workspace is a data store to collect log data types from Azure and non-Azure resources and applications. We recommend you send all log data to one Log Analytics workspace.

7 November 2025

Governance

2

Microsoft Entra Id Governance Licensing For Guest Users

Updated

To use Microsoft Entra ID Governance features for guest users, your tenant must be linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. If the guest billing meter isn't enabled, the following behavior applies:

6 November 2025

General

1

Monitoring

1

Azure Monitor

Updated

> If you select **Review** before adding settings, the **Subscription** and **Resource group** appear on the right-hand side. These fields are read-only. To make changes, remove the existing service provider information and restart the wizard.

7 November 2025

Security

1

General

1

General

1

Enable Intelligent Local Access (preview)

Updated

Learn how to enable the Intelligent Local Access (ILA) capability for Microsoft Entra Private Access, which optimizes traffic flow for clients accessing Entra apps via private networks.

8 November 2025

General

2

Whats New

Updated

This article lists the latest features, improvements, and changes in the Microsoft Entra Verified ID service.

7 November 2025

Security

1

Idv Partners

Updated

| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |

6 November 2025

Fundamentals

2

General

1