Week in brief

Entra ID’s FIDO2 passkey API retirement is the week’s clearest admin deadline; Agent ID preview controls and Security Copilot rollout are the other material signals

The week of 17 November was mainly Learn maintenance—51 updates, five removals, and only two new pages—rather than a broad Entra feature-release week. The meaningful exceptions were a scheduled passkey API retirement, concentrated operational guidance for the Microsoft Entra Agent ID preview, and a Message Center notice about Microsoft Security Copilot’s phased inclusion in Microsoft 365 E5. The five removed records are documentation-page removals; the supplied evidence identifies no additional product retirement.

  • A 20 November Message Center major update says Microsoft will retire isAttestationEnforced and keyRestrictions from the fido2AuthenticationMethodConfiguration API starting in the October–November 2027 timeframe. During the transition, the properties will sync with new properties in the updated passkey policy API schema. This is a compatibility and migration issue for Entra ID configurations, automations, and integrations—not a general passkey feature announcement.

  • Two new 19 November Learn pages describe the Microsoft Entra Agent ID sign-in process and known issues and gaps. Related updates explain consent pages, trust criteria, agent permissions, Agent Registry roles for managing agent instances, card manifests, and collections, and controls for agent identities that the guidance says are enabled by default in all Entra tenants. The material continues to identify Agent ID as a preview, and does not establish general availability. ID Protection guidance also states that ID ‍

  • A 19 November Message Center notice says Microsoft Security Copilot is included at no extra cost in Microsoft 365 E5, with AI-driven security agents spanning Defender, Entra, Intune, and Purview. It says customers receive monthly Security Compute Units based on user count, the rollout is phased, and administrators control access through Entra ID group membership. This is a cross-product entitlement and rollout notice, not evidence of a new Entra feature reaching general availability.

  • The 20 November documentation updates cover the Microsoft Entra Internet Access TLS inspection overview, configuring inspection settings and a certificate authority, and configuring and assigning a TLS inspection policy in Global Secure Access. The overview describes making encrypted traffic available for protections such as malware detection, data loss prevention, and prompt inspection. The records show expanded documentation coverage, not a stated preview, GA, or service-behavior change.

  • An updated Entra ID Assign Local Admin page says groups deployed to a device with this policy do not apply to Remote Desktop connections. For Entra-joined devices, the documented method for controlling RDP permissions is to add the individual user’s SID to the appropriate group. This is a behavior and documentation clarification, not evidence that the policy itself changed during the week.

For Entra administrators

Prioritize inventorying uses of the affected passkey properties and updating configurations, automation, and integrations ahead of the stated October–November 2027 retirement timeframe. For Agent ID, review the preview’s sign-in, consent, known-issue, default-enablement, role, and permission guidance. Microsoft 365 E5 administrators should track the phased Security Copilot rollout, its monthly Security Compute Units based on user count, and the Entra group-membership controls. The TLS inspection and RDP items are conditional documentation clarifications rather than stated availability changes.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

17

Assign Local Admin

Updated

- Microsoft Entra groups deployed to a device with this policy don't apply to remote desktop connections. To control remote desktop permissions for Microsoft Entra joined devices, you need to add the individual user's SID to the appropriate group.

21 November 2025

Sharepoint Administrator

Updated

> | microsoft.azure.supportTickets/allEntities/allTasks | Create and manage Azure support tickets |

20 November 2025

Connect Version History

Updated

11/19/2025: Released for download via the Microsoft Entra admin center.

20 November 2025

Dragon Administrator

Updated

A Microsoft Entra documentation page was updated: Dragon Administrator.

20 November 2025

Global Administrator

Updated

A Microsoft Entra documentation page was updated: Global Administrator.

20 November 2025

Global Reader

Updated

A Microsoft Entra documentation page was updated: Global Reader.

20 November 2025

User Administrator

Updated

A Microsoft Entra documentation page was updated: User Administrator.

20 November 2025

Sso Linux

Updated

The Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):

19 November 2025

Manage App Consent Policies

Updated

- **microsoft-user-default-recommended:** Permissions consentable based on Microsoft's current recommendations.

19 November 2025

Agent Contact App Owners

Removed

A Microsoft Entra documentation page was updated: Agent Contact App Owners.

19 November 2025

Authentication

5

Kerberos

Updated

For example, when a Microsoft Entra ID-joined Windows client accesses a file share or application over the internet, Microsoft Entra ID can issue the necessary Kerberos tickets as a KDC associated with the resource.

21 November 2025

Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

New

Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.

20 November 2025
Message CenterMC1188230 on mc.merill.net ↗Major updatePlan for change

Fundamentals

4

Native Authentication

Updated

| | Browser-delegated authentication | Native authentication |

22 November 2025

Conditional Access Cloud Apps

Updated

- [Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 groups, and SharePoint sites](/purview/sensitivity-labels-teams-groups-sites)

21 November 2025

Token Protection

Updated

- Windows Server 2019 or newer that are hybrid Microsoft Entra joined.

21 November 2025

Kerberos

Updated

For more information about Kerberos in Windows, see [Kerberos authentication overview in Windows Server](/windows-server/security/kerberos/kerberos-authentication-overview).

19 November 2025

Governance

2

Troubleshooting

2

Authenticate Application Id

Updated

Microsoft Entra Connect warns if the certificate rotation is due. That is, if expiration is less than or equal to 30 days. It emits an error if the certificate is already expired. You can find these warnings (Event ID 1011) and errors (Event ID 1012) in the Application event log.

20 November 2025

Monitoring

1

Standards

1

Bis Tutorial

Updated

1. On the **Basic SAML Configuration** section, perform the following step:

20 November 2025

General

3

Preview Known Issues

Updated

The following known issues and gaps relate to consent and permissions.

19 November 2025

Grant Agent Access Microsoft 365

Updated

The type of permissions you request depends on how your agent operates and what resources it needs to access.

19 November 2025

Security

3

Microsoft Entra Agent Registry roles

Updated

In the Microsoft Entra Agent Registry, you can assign roles to administrators or other security principals to manage agent instances, agent card manifests, and agent collections. These roles provide the permissions required to perform specific actions, such as creating or updating agent instances, create agent card manifests, or managing collection membership.

19 November 2025

Microsoft Entra Agent Identities For Ai Agents

Updated

- Using real-time signals such as agent identities risk controlling agent access to resources, with Microsoft Managed Policies providing a secure baseline by blocking high-risk agents.

19 November 2025

Standards

2

Assign Agent Identities To Applications

Updated

Applications using the Microsoft Entra identity platform can [expose APIs for other client applications to call](../../identity-platform/quickstart-configure-app-expose-web-apis.md#register-the-web-api). The application with the API can expose OAuth scopes for those API calls. The tool's service principal can be consented permission to those scopes, allowing it to call the APIs.

21 November 2025

Disable agent identities in your tenant

Updated

Agent identities are enabled by default in all Microsoft Entra ID tenants. Customers who want to control which Agent IDs are allowed in their tenant can follow the guidance in this article to configure their preferred settings. Microsoft Entra Agent ID is subject to its [standard preview terms and conditions](/entra/fundamentals/licensing-preview-info).

19 November 2025

Authentication

1

Microsoft Entra Agent ID sign-in process

New

Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.

19 November 2025

Microsoft identity platform

1

Monitoring

1

How are agent identities created?

Updated

Learn the channels and roles involved in creating Microsoft Entra agent identity blueprints, agent identities, and agent users. Monitor and control their introduction into your tenant.

19 November 2025

Troubleshooting

1

Fundamentals

2

Risky Agents

Updated

- ID Protection for agents is included with the Microsoft Entra P2 license while in preview.

19 November 2025

Whats New Ignite 2025

Updated

- [Configure risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) (Updated)

19 November 2025

Governance

4

Entra Entitlement Management Request Policy

Updated

After you create the access package, you can directly assign specific internal and external users to it. If you specify an external user, a guest user account is created in your directory. For information about directly assigning a user, see [View, add, and remove assignments for an access package](~/id-governance/entitlement-management-access-package-assignments.md).

21 November 2025

Custom Data Resource Access Reviews

Updated

:::image type="content" source="media/custom-data-resource-access-reviews/upload-access-data-files.png" alt-text="Screenshot of uploading files to custom access data.":::

19 November 2025

Microsoft identity platform

1

Fundamentals

1

General

1

Microsoft identity platform

1

Native Authentication Api

Updated

1. [Associate your app registration with the user flow](../external-id/customers/how-to-user-flow-add-application.md).

22 November 2025

Fundamentals

1

What is Transport Layer Security inspection?

Updated

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

20 November 2025

Monitoring

1

Security

1

Security

3

Secure Web Ai Gateway Agents

Updated

- The enforcement feature supports only the baseline profile. Network security policies apply per tenant.

19 November 2025