Week in brief

Entra ID Protection alert defaults shift on 11 December; agent identity governance is the main documentation theme

The supplied week is mostly maintenance rather than a launch cycle: 37 records are Microsoft Learn updates, no item is classified as new, one External ID page was removed, and one Message Center notice was issued. That notice announces the clearest behavior change—the Defender XDR alert configuration and default for Entra ID Protection. The more substantive Learn edits add Agent ID governance guidance, list a macOS platform credential as preview in passwordless planning, and clarify Entitlement Management catalog limits and custom claims token issuance. External ID edits add domain-acceleration information and refine descriptions of DDoS protection and the Security Store. Nothing supplied establishes general availability or a product capability retirement.

  • The Message Center notice says that starting 11 December 2025, Defender XDR will let administrators filter Entra ID Protection alerts as High only, High + Medium, or All. The default changes to High risk only, with the stated aim of reducing alert volume and improving clarity. This is an announced alerting behavior change, not a documentation-only edit.

  • Updated Agent ID and entitlement-management guidance frames access packages as intentional, auditable, and time-bound controls for agent resource access. It says an agent identity can request a package itself or have its owner or sponsor request one, while related guidance stresses maintaining sponsors and owners to avoid orphaned IDs amid agent sprawl. The evidence supports governance guidance, not a new general-availability launch.

  • The Entra ID prerequisites page for phishing-resistant passwordless authentication now includes Platform credential for macOS (preview). The supplied record identifies preview status but gives no general-availability date, requirements, or indication of a tenant-wide behavior change; this is a planning-document update rather than a general-availability announcement.

  • The Custom Extension Overview now explicitly describes OnTokenIssuanceStart as the event triggered just before an application token is issued. It explains that a custom claims provider calls a REST API for claims from external systems, maps those claims into tokens, and can be assigned to one or more applications. This clarifies the documented flow and does not report a runtime change.

  • Entitlement Management guidance makes the catalog boundary explicit: if a required group or app is not available in an access package’s catalog, an access package manager cannot add it to the catalog even if the manager owns the resource. Package creation therefore uses the catalog’s existing resource set; the update is an administrative workflow clarification, not evidence of a new entitlement-management feature.

For Entra administrators

Prioritize review of Defender XDR alert configuration before 11 December if Medium-risk or all-risk alerts are operationally important: the available choices will be High only, High + Medium, or All, with High only becoming the default. For Agent ID deployments, review how sponsors, owners, and access packages govern agent resource access, and ensure required resources are available in catalogs before package managers build packages. Treat the macOS platform credential as preview, not general availability. Administrators using custom claims providers should consult the clarified OnTokenIssuanceStart and REST API flow. The removal of the External ID documentation page alone is not evidence that a capability was retired.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

3

Custom Extension Overview

Updated

The token issuance start event, **OnTokenIssuanceStart** is triggered when a token is about to be issued to an application. It is an event type set up within a [custom claims provider](custom-claims-provider-overview.md). The custom claims provider is a custom authentication extension that calls a REST API to fetch claims from external systems. A custom claims provider maps claims from external systems into tokens and can be assigned to one or many applications in your directory.

26 November 2025

Authentication

2

Content Security Policy

Updated

- **Step 1**: Go through a sign-in flow with the dev console open to identify any violations.

26 November 2025

Provisioning

2

User provisioning for Slack

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Slack.

27 November 2025

On Premises Ldap Connector Prepare Directory

Updated

In order to enable SSL to work, you need to grant the NETWORK SERVICE read permissions to our newly created certificate. To grant permissions, use the following steps.

26 November 2025

Standards

2

Access packages for Agent identities in Microsoft Entra ID

Updated

Microsoft Entra entitlement management provides access packages as a governance mechanism. Access packages ensure that agent access assignments are intentional, auditable, and time-bound. Access packages represent a structured approach to managing agent identity permissions, contrasting with ad-hoc permission assignments that might lack appropriate governance controls. Access packages enable standardized access for many AI Agents with the same access needs, for example, a fleet of customer support AI Agents. Through access packages, organizations can establish consistent governance practices for all agent identity resource access. For more information, see [Governing agent identities](/entra/id-governance/agent-id-governance-overview).

26 November 2025

General

1

General

2

Fundamentals

1

Agent Id Governance Overview

Updated

Agent identities can have resources assigned to them directly via access packages. Resource assignments allow agent identities to request an access package for themselves, or have their owner or sponsor request one on their behalf. With Access packages, you're able to assign agent identities the following resources:

27 November 2025

Governance

1

Security For Ai

Updated

Agent proliferation creates a governance challenge termed "agent sprawl"—the uncontrolled expansion of agents across an organization without adequate visibility, management, or lifecycle controls.

26 November 2025

Standards

1

Monitoring

1

Governance

9

Entitlement Management Access Package Resources

Updated

If you need to add resources such as groups or apps to an access package, you should check whether the resources you need are available in the access package's catalog. If you're an access package manager, you can't add resources to a catalog, even if you own them. You're restricted to using the resources available in the catalog.

27 November 2025

Entitlement Management Access Package Create

Updated

If you're not sure which resource roles to include, you can skip adding them while creating the access package, and then [add them](entitlement-management-access-package-resources.md) later.

27 November 2025

Custom Extension Security

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Catalog Create

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Custom Data Resource Access Reviews

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Delegate Managers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Delegate

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](~/identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).

26 November 2025

Entitlement Management Dynamic Approval

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Catalog owner](../id-governance/entitlement-management-delegate.md#entitlement-management-roles) of the catalog where the custom extension will be located.

26 November 2025

Fundamentals

5

Microsoft Entra ID Governance licensing fundamentals

Updated

This following document discusses Microsoft Entra ID Governance licensing for employees. It's intended for IT decision makers, IT administrators, and IT professionals who are considering Microsoft Entra ID Governance services for their organizations.

27 November 2025

Identity Governance Overview

Updated

| Provisioning users into on-premises and cloud applications that have their own directories or databases | [Configure automatic user provisioning](../identity/app-provisioning/user-provisioning.md) with user assignments or [scoping filters](../identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md) |

27 November 2025

Entitlement Management Access Package Request Policy

Updated

Guest users refer to external users that have been invited into your directory with [Microsoft Entra B2B](../external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](../fundamentals/users-default-permissions.md).

27 November 2025

Entra Entitlement Management Request Policy

Updated

Guest users are external identities who have been invited into your directory via [Microsoft Entra B2B](~/external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](~/fundamentals/users-default-permissions.md).

27 November 2025

Architecture

2

Authentication

1

Entitlement Management Scenarios

Updated

1. [Sign in to the My Access portal](entitlement-management-request-access.md#sign-in-to-the-my-access-portal)

27 November 2025

Fundamentals

4

Supported Features Customers

Updated

Microsoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include Distributed Denial-of-Service (DDoS) attack protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.

28 November 2025

Supported Features Customers

Updated

Microsoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include edge protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.

27 November 2025

Whats New Docs

Updated

- [Identity providers for external tenants](customers/concept-authentication-methods-customers.md) - Added domain acceleration information

26 November 2025

Solutions Customers

Removed

A Microsoft Entra documentation page was updated: Solutions Customers.

26 November 2025

General

1

General

1

Macos Client Release History

Updated

Track the latest updates and bug fixes for the Global Secure Access client for macOS. Stay informed about version changes and download instructions.

26 November 2025