Learn to configure Conditional Access adaptive session lifetime policies to protect critical apps, sensitive data, and high-impact users in your organization.
Future Entra ID sign-in CSP enforcement is the week’s main behavior change; preview-agent and federation guidance are the meaningful documentation moves
The week of 1 December 2025 is primarily a Learn-maintenance period: 70 entries were updated, alongside four new entries and one Message Center notice. The most consequential item is a future Content Security Policy enforcement for browser-based sign-ins at login.microsoftonline.com, scheduled to begin in mid-October 2026. Other meaningful changes are new documentation for the Identity Risk Management Agent (Preview), expanded Agent ID governance guidance, an exact OIDC Discovery URL contract for External ID, and updated documentation for Catalog access reviews (preview). No supplied item establishes general availability, a mandatory in-week rollout, or a product retirement; the four removals have no retirement details.
- Microsoft Entra ID — browser-based authenticationChanged behavior and security notice: CSP enforcement on Microsoft Entra ID browser sign-ins
The Message Center notice says Microsoft Entra ID will enforce a Content Security Policy that blocks external script injection and permits only trusted Microsoft scripts for browser-based sign-ins on login.microsoftonline.com. Rollout is stated to begin in mid-October 2026, and Entra External ID tenants are explicitly excluded. This is a future behavior change, not evidence of an in-week rollout; the notice does not specify a tenant setting or remediation.
- Microsoft Entra External ID — external authentication method providersDocumentation clarification: External ID requires an exact OIDC Discovery URL form
Updated Authentication External Method Provider guidance says the provider’s OIDC Discovery URL must use https and end exactly with /.well-known/openid-configuration. Additional path segments, query strings, and fragments are not permitted, and the full URL must be supplied when the EAM is created. This is a standards and configuration clarification; the supplied record does not say that service-side validation changed.
- Microsoft Entra ID Protection — Identity Risk Management Agent (Preview)New preview documentation: Identity Risk Management Agent in ID Protection
Three ID Protection entries are marked New: the Identity Risk Management Agent, its settings, and review of its findings in the Risky user report. Related updates describe a Preview agent that analyzes risky identities, uses a large language model to suggest remediation, and supports configurable run frequency and email notifications. These entries provide operational guidance for a preview capability, not evidence of general availability or a new rollout.
- Microsoft Entra Agent IDAgent ID documentation clarifies its governance model and registry-only agents
The updated governance overview spells out four object types: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. It describes lifecycle and access governance for agent identities and the assignment of sponsors. Separate guidance distinguishes registry-only agents, which may have no associated Entra agent identity, while a new error-code reference and updated Preview Known Issues page add troubleshooting context. This is documentation expansion, not an availability or GA��
- Microsoft Entra ID Governance — Catalog access reviews (preview)Preview documentation: Catalog access reviews cover multiple resource types
The updated Catalog access reviews (preview) guidance describes a multi-stage process in which managers can review access to groups, applications, and custom disconnected resources together. Related catalog documentation identifies catalogs as also being used for these preview reviews. The change clarifies scope and workflow; it is not a GA or launch announcement.
No broad tenant-wide action is evidenced for this week. If an Entra ID browser sign-in implementation depends on external scripts, assess compatibility ahead of the 2026 CSP rollout; the notice explicitly excludes Entra External ID tenants. For External ID EAM configuration, validate the full HTTPS Discovery URL in the exact permitted form. Teams evaluating the agent or catalog-review previews can use the new operational guidance, but the evidence does not indicate GA status, licensing changes, or mandatory enablement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
20 updatesFundamentals
6To start receiving notifications, your application sends a `POST` request to the /`subscriptions` endpoint to subscribe to a specific resource, in this case, health monitoring alerts. Microsoft Graph then validates the request and confirms the subscription. Once the subscription is active, Microsoft Graph sends a notification to your designated endpoint whenever the subscribed resource is created. For more information, see [Microsoft Graph change notifications](/graph/change-notifications-overview).
| Metadata value | Value | Comments |
Sign In Log Activity Details
Updated- **Multifactor authentication:** When a user signs in with MFA, several separate MFA events are actually taking place. For example, if a user enters the wrong validation code or doesn't respond in time, more MFA events are sent to reflect the latest status of the sign-in attempt. These sign-in events appear as one line item in the Microsoft Entra sign-in logs. That same sign-in event in Azure Monitor, however, appears as multiple line items. These events all have the same `correlationId`.
Licensing
Updatedmanager: pmwongera
Secure Remote Workers
RemovedA Microsoft Entra documentation page was updated: Secure Remote Workers.
General
4Policy Block By Location
Updated1. Under **Include**, select **Selected networks and locations**
Cloud Sync Version History
UpdatedGet notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Cloud Sync Version History
UpdatedGet notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Cloud Sync Version History
UpdatedGet notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Authentication
2> [!NOTE]
```
Security
2Entra Agents
Updated| Attribute | Description |
Entra Agents
Updatedauthor: shlipsey3
Architecture
1Secure Best Practices
UpdatedThe following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.
Developer
1This article shows the new and updated documentation for the Microsoft Entra application management.
Microsoft identity platform
1Whats New Docs
UpdatedWelcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.
Monitoring
1Sla Performance
Updated| August | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |
Provisioning
1Tutorial Group Provisioning
UpdatedUse case | Parent group type | User member group type | Sync Direction | How sync works
Troubleshooting
1If you're locked out because of an incorrect setting in a Conditional Access policy:
Microsoft Entra Agent ID
5 updatesMicrosoft identity platform
2Learn about the Agent ID, Agent Blueprint, and Agent Identity error codes.
This article provides a comprehensive reference for error codes you might encounter when working with the Microsoft agent identity platform.
Fundamentals
1Agent Id Governance Overview
Updated[Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) includes four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. These can be created in [Microsoft Foundry](/azure/ai-foundry/agents/concepts/agent-identity), [Microsoft Copilot Studio](/microsoft-copilot-studio/admin-use-entra-agent-identities), or other platforms. The agent identity, and optionally the agent user, allows AI agents to take on digital identities within Microsoft Entra. Once a digital identity is established, these agent identities are able to be governed using lifecycle and access features. Sponsors can be assigned to agent identities after creation. Sponsors of agent identities are human users accountable for making decisions about its lifecycle and access. For more information about the role of a sponsor of agent identities, see: [Administrative relationships for agent IDs](../agent-id/identity-platform/agent-owners-sponsors-managers.md).
General
1Preview Known Issues
Updatedmanager: mwongerapk
Security
1As an admin, you want to have a 360-degree view of your agents for both security and operational efficiency. Some agents will be represented in Microsoft Entra with an agent identity blueprint principal and agent identities, or as a service principal. It isn't uncommon to also have agents that are registered in the agent registry but don't have an associated Microsoft Entra agent identity. These agents are referred to as registry-only agents. They might be in the process of being onboarded or they may have registered in the registry without needing to use Microsoft Entra Agent ID as the agent's identity provider.
Microsoft Entra ID Protection
11 updatesSecurity
6author: shlipsey3
The Identity Risk Management Agent in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing user behavior and suggesting actions to mitigate potential identity risks. You can configure the settings to meet your organization's needs, such as how often it runs, and email notifications.
Learn how to configure the settings for the Identity Risk Management Agent in Microsoft Entra ID Protection.
Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.
A Microsoft Entra documentation page was updated: Identity Risk Management Agent Get Started.
A Microsoft Entra documentation page was updated: Identity Risk Management Agent Settings.
Fundamentals
2Risky User Report
UpdatedKnowing which users are at risk and *why* they're at risk is a key responsibility of security and identity administrators. The Risky user report in Microsoft Entra ID Protection provides the full report, along with a risk data summary, and an activity timeline.
Risk Reports
Updatedauthor: shlipsey3
Monitoring
2Learn about how the Identity Risk Management Agent works with the Risky user report in Microsoft Entra ID Protection
A Microsoft Entra documentation page was updated: Identity Risk Management Agent Risky User Report.
Troubleshooting
1Review agent findings
UpdatedThe Identity Risk Management Agent (Preview) in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing the risky identities and suggesting actions to remediate them. By using a Large Language Model, the agent helps security administrators review and respond to risky activities before they lead to security incidents.
Microsoft Entra ID Governance
31 updatesGovernance
27Maintaining and classifying data within your environment is an important part in maintaining a secure environment. Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization's data, while making sure that user productivity and their ability to collaborate isn't hindered. With sensitivity labels in Lifecycle Workflows, administrators are able to quickly view the sensitivity labels of groups and teams during workflow creation, and editing.
Lifecycle Workflow Tasks
Updated```
| [Disable user account](../id-governance/lifecycle-workflow-tasks.md#disable-user-account) | 1dfdfcc7-52fa-4c2e-bf3a-e3919cc12950 | Leaver |
Apps
Updated<a name='entra-identity-governance-integrations'></a>
This article provides best practices for securing deploying Microsoft Entra ID Governance.
Deploy Sap Netweaver
UpdatedThis article describes how to set up a lab environment with SAP ECC for testing.
Describes how to use Entitlement Management with Private Access
This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host
This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.
This article describes use cases Microsoft Entra ID Governance.
Sap Template
Updateddocumentationcenter: ''
author: owinfreyATL
Catalog access reviews in Microsoft Entra ID Governance enables organizations to simplify how managers can review users access to multiple resource types, such as groups, applications and custom disconnected resource at once. This helps ensure only the right people retain access, while enabling managers and resource owners to review access efficiently through a multi-stage process.
This article shows you how to create and manage a catalog of resources and access packages in entitlement management. Catalogs are also used in [access reviews (preview)](catalog-access-reviews.md).
If you do not yet have a catalog, then create a new catalog. If you have a catalog already, then continue at the [next section](#add-a-custom-data-provided-resource-to-a-catalog).
Create Access Review
Updated- To review access package assignments, see [configure an access review in entitlement management](entitlement-management-access-reviews-create.md).
Delegate Approvals My Access
UpdatedApproval delegation in My Access allows approvers to assign another individual to respond to access package approval requests on their behalf. This feature helps maintain productivity when approvers are unavailable due to leave, travel, or other commitments.

1. Select a group in Microsoft Entra ID that has one or more members. Or select an application connected to Microsoft Entra ID that has one or more users assigned to it.
1. If the application was using AD security groups, and those groups were created in AD, then once the review is complete, you need to manually update the AD groups to remove memberships of those users who were denied. Subsequently, to have denied access rights removed automatically, you can either update the application to use an AD group that was created in Microsoft Entra ID and [written back to Microsoft Entra ID](~/identity/hybrid/cloud-sync/how-to-configure-entra-to-active-directory.md), or move the membership from the AD group to the Microsoft Entra group, and [nest the written back group as the only member of the AD group](~/identity/hybrid/cloud-sync/govern-on-premises-groups.md).
1. Select **Create**.
There are four common scenarios in which it's necessary to populate Microsoft Entra ID with existing access rights and users of an application before you use the application with a Microsoft Entra ID Governance feature such as [access reviews](access-reviews-application-preparation.md).
Deploy Access Reviews
Updated| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |
Perform Access Review
UpdatedThe Access Review Agent assists you in completing your pending access reviews by guiding you in Microsoft Teams with natural language, insights, and recommendations.
For more information on those first two scenarios, where the application supports provisioning, or uses an LDAP directory, SQL database, has a SOAP or REST API or relies upon Microsoft Entra ID as its identity provider, see the article [govern an application's existing users](identity-governance-applications-existing-users.md). That article covers how to use identity governance features for existing users of those categories of applications.
Create Access Review
Updated- [Complete an access review of groups or applications](complete-access-review.md)
Fundamentals
4Describes overview of identity lifecycle management for Microsoft Entra ID Governance.
Access Reviews Overview
Updated| Microsoft Entra role | Specified reviewers</br>Self-review | [PIM](../id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json) | Microsoft Entra admin center |
Identity Governance Overview
UpdatedOrganizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.
Access Reviews Overview
Updated>[!NOTE]
Microsoft Entra External ID
5 updatesGeneral
3New and updated documentation for the Microsoft Entra External ID.
> [!NOTE]
Current Known Limitations
Updated<a name="b2b-guest-access-limitations"></a>
Branding
1Microsoft Entra ID will enhance authentication security by enforcing a Content Security Policy that blocks external script injection, allowing only trusted Microsoft scripts. This rollout begins mid-October 2026, affecting browser-based sign-ins on login.microsoftonline.com, with no impact on Entra External ID tenants.
Standards
1An external identity provider needs to provide an [OIDC Discovery endpoint](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig). This endpoint is used to get more configuration data. The Discovery URL **MUST** use the `https` scheme and **MUST** end with `/.well-known/openid-configuration`. No additional path segments, query strings, or fragments are permitted after this segment. The full Discovery URL must be included in the Discovery URL configured when the EAM is created.
Microsoft Entra Internet Access
1 updateTroubleshooting
1Network Content Filtering
Updated:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::
Microsoft Entra Verified ID
3 updatesGeneral
2Services Partners
Updatedauthor: barclayn
Idv Partners
Updatedauthor: barclayn
Fundamentals
1Dnsbind
UpdatedThe domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.contoso.com/`.
Microsoft Entra Global Secure Access
3 updatesGeneral
3Customize Block Page
Updated- For guidance on configuring web content filtering, see [Configure web content filtering](./how-to-configure-web-content-filtering.md).
Network Content Filtering
Updated1. On the **Review** tab, review your settings.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
