Week in brief

Future Entra ID sign-in CSP enforcement is the week’s main behavior change; preview-agent and federation guidance are the meaningful documentation moves

The week of 1 December 2025 is primarily a Learn-maintenance period: 70 entries were updated, alongside four new entries and one Message Center notice. The most consequential item is a future Content Security Policy enforcement for browser-based sign-ins at login.microsoftonline.com, scheduled to begin in mid-October 2026. Other meaningful changes are new documentation for the Identity Risk Management Agent (Preview), expanded Agent ID governance guidance, an exact OIDC Discovery URL contract for External ID, and updated documentation for Catalog access reviews (preview). No supplied item establishes general availability, a mandatory in-week rollout, or a product retirement; the four removals have no retirement details.

  • The Message Center notice says Microsoft Entra ID will enforce a Content Security Policy that blocks external script injection and permits only trusted Microsoft scripts for browser-based sign-ins on login.microsoftonline.com. Rollout is stated to begin in mid-October 2026, and Entra External ID tenants are explicitly excluded. This is a future behavior change, not evidence of an in-week rollout; the notice does not specify a tenant setting or remediation.

  • Microsoft Entra External ID — external authentication method providersDocumentation clarification: External ID requires an exact OIDC Discovery URL form

    Updated Authentication External Method Provider guidance says the provider’s OIDC Discovery URL must use https and end exactly with /.well-known/openid-configuration. Additional path segments, query strings, and fragments are not permitted, and the full URL must be supplied when the EAM is created. This is a standards and configuration clarification; the supplied record does not say that service-side validation changed.

  • Microsoft Entra ID Protection — Identity Risk Management Agent (Preview)New preview documentation: Identity Risk Management Agent in ID Protection

    Three ID Protection entries are marked New: the Identity Risk Management Agent, its settings, and review of its findings in the Risky user report. Related updates describe a Preview agent that analyzes risky identities, uses a large language model to suggest remediation, and supports configurable run frequency and email notifications. These entries provide operational guidance for a preview capability, not evidence of general availability or a new rollout.

  • The updated governance overview spells out four object types: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. It describes lifecycle and access governance for agent identities and the assignment of sponsors. Separate guidance distinguishes registry-only agents, which may have no associated Entra agent identity, while a new error-code reference and updated Preview Known Issues page add troubleshooting context. This is documentation expansion, not an availability or GA�‍�

  • Microsoft Entra ID Governance — Catalog access reviews (preview)Preview documentation: Catalog access reviews cover multiple resource types

    The updated Catalog access reviews (preview) guidance describes a multi-stage process in which managers can review access to groups, applications, and custom disconnected resources together. Related catalog documentation identifies catalogs as also being used for these preview reviews. The change clarifies scope and workflow; it is not a GA or launch announcement.

For Entra administrators

No broad tenant-wide action is evidenced for this week. If an Entra ID browser sign-in implementation depends on external scripts, assess compatibility ahead of the 2026 CSP rollout; the notice explicitly excludes Entra External ID tenants. For External ID EAM configuration, validate the full HTTPS Discovery URL in the exact permitted form. Teams evaluating the agent or catalog-review previews can use the new operational guidance, but the evidence does not indicate GA status, licensing changes, or mandatory enablement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

6

Howto Configure Health Alert Notifications

Updated

To start receiving notifications, your application sends a `POST` request to the /`subscriptions` endpoint to subscribe to a specific resource, in this case, health monitoring alerts. Microsoft Graph then validates the request and confirms the subscription. Once the subscription is active, Microsoft Graph sends a notification to your designated endpoint whenever the subscribed resource is created. For more information, see [Microsoft Graph change notifications](/graph/change-notifications-overview).

6 December 2025

Sign In Log Activity Details

Updated

- **Multifactor authentication:** When a user signs in with MFA, several separate MFA events are actually taking place. For example, if a user enters the wrong validation code or doesn't respond in time, more MFA events are sent to reflect the latest status of the sign-in attempt. These sign-in events appear as one line item in the Microsoft Entra sign-in logs. That same sign-in event in Azure Monitor, however, appears as multiple line items. These events all have the same `correlationId`.

2 December 2025

Licensing

Updated

manager: pmwongera

2 December 2025

Secure Remote Workers

Removed

A Microsoft Entra documentation page was updated: Secure Remote Workers.

2 December 2025

General

4

Cloud Sync Version History

Updated

Get notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your ![RSS feed reader icon](media/cloud-sync-version-history/feed-icon-16-x-16.png) feed reader.

5 December 2025

Cloud Sync Version History

Updated

Get notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your ![RSS feed reader icon](media/cloud-sync-version-history/feed-icon-16-x-16.png) feed reader.

4 December 2025

Cloud Sync Version History

Updated

Get notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your ![RSS feed reader icon](media/cloud-sync-version-history/feed-icon-16-x-16.png) feed reader.

3 December 2025

Authentication

2

Security

2

Entra Agents

Updated

| Attribute | Description |

3 December 2025

Architecture

1

Secure Best Practices

Updated

The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.

2 December 2025

Developer

1

Microsoft identity platform

1

Whats New Docs

Updated

Welcome to what's new in the Microsoft identity platform documentation. This article lists new articles that were added or had significant updates in the last three months.

3 December 2025

Monitoring

1

Sla Performance

Updated

| August | 99.999% | 99.999% | 99.999% | 99.999% | 99.999% |

6 December 2025

Provisioning

1

Tutorial Group Provisioning

Updated

Use case | Parent group type | User member group type | Sync Direction | How sync works

6 December 2025

Troubleshooting

1

Microsoft identity platform

2

Fundamentals

1

Agent Id Governance Overview

Updated

[Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) includes four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. These can be created in [Microsoft Foundry](/azure/ai-foundry/agents/concepts/agent-identity), [Microsoft Copilot Studio](/microsoft-copilot-studio/admin-use-entra-agent-identities), or other platforms. The agent identity, and optionally the agent user, allows AI agents to take on digital identities within Microsoft Entra. Once a digital identity is established, these agent identities are able to be governed using lifecycle and access features. Sponsors can be assigned to agent identities after creation. Sponsors of agent identities are human users accountable for making decisions about its lifecycle and access. For more information about the role of a sponsor of agent identities, see: [Administrative relationships for agent IDs](../agent-id/identity-platform/agent-owners-sponsors-managers.md).

2 December 2025

General

1

Security

1

Manage agents with no agent identities

Updated

As an admin, you want to have a 360-degree view of your agents for both security and operational efficiency. Some agents will be represented in Microsoft Entra with an agent identity blueprint principal and agent identities, or as a service principal. It isn't uncommon to also have agents that are registered in the agent registry but don't have an associated Microsoft Entra agent identity. These agents are referred to as registry-only agents. They might be in the process of being onboarded or they may have registered in the registry without needing to use Microsoft Entra Agent ID as the agent's identity provider.

4 December 2025

Security

6

Identity Risk Management Agent (Preview) settings

Updated

The Identity Risk Management Agent in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing user behavior and suggesting actions to mitigate potential identity risks. You can configure the settings to meet your organization's needs, such as how often it runs, and email notifications.

2 December 2025

Identity Risk Management Agent

New

Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.

2 December 2025

Fundamentals

2

Risky User Report

Updated

Knowing which users are at risk and *why* they're at risk is a key responsibility of security and identity administrators. The Risky user report in Microsoft Entra ID Protection provides the full report, along with a risk data summary, and an activity timeline.

2 December 2025

Monitoring

2

Troubleshooting

1

Review agent findings

Updated

The Identity Risk Management Agent (Preview) in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing the risky identities and suggesting actions to remediate them. By using a Large Language Model, the agent helps security administrators review and respond to risky activities before they lead to security incidents.

2 December 2025

Governance

27

Sensitivity labels in Lifecycle Workflows

Updated

Maintaining and classifying data within your environment is an important part in maintaining a secure environment. Sensitivity labels from Microsoft Purview Information Protection let you classify and protect your organization's data, while making sure that user productivity and their ability to collaborate isn't hindered. With sensitivity labels in Lifecycle Workflows, administrators are able to quickly view the sensitivity labels of groups and teams during workflow creation, and editing.

5 December 2025

Lifecycle Workflows Tasks Table

Updated

| [Disable user account](../id-governance/lifecycle-workflow-tasks.md#disable-user-account) | 1dfdfcc7-52fa-4c2e-bf3a-e3919cc12950 | Leaver |

5 December 2025

Apps

Updated

<a name='entra-identity-governance-integrations'></a>

4 December 2025

Deploy Sap Netweaver

Updated

This article describes how to set up a lab environment with SAP ECC for testing.

4 December 2025

Catalog Access Reviews (preview)

Updated

Catalog access reviews in Microsoft Entra ID Governance enables organizations to simplify how managers can review users access to multiple resource types, such as groups, applications and custom disconnected resource at once. This helps ensure only the right people retain access, while enabling managers and resource owners to review access efficiently through a multi-stage process.

3 December 2025

Custom Data Resource Access Reviews

Updated

If you do not yet have a catalog, then create a new catalog. If you have a catalog already, then continue at the [next section](#add-a-custom-data-provided-resource-to-a-catalog).

3 December 2025

Create Access Review

Updated

- To review access package assignments, see [configure an access review in entitlement management](entitlement-management-access-reviews-create.md).

3 December 2025

Delegate Approvals My Access

Updated

Approval delegation in My Access allows approvers to assign another individual to respond to access package approval requests on their behalf. This feature helps maintain productivity when approvers are unavailable due to leave, travel, or other commitments.

3 December 2025

Create Access Review Pim For Groups

Updated

![Screenshot that shows the Access reviews pane in Identity Governance.](./media/create-access-review/access-reviews.png)

3 December 2025

Manage User Access With Access Reviews

Updated

1. Select a group in Microsoft Entra ID that has one or more members. Or select an application connected to Microsoft Entra ID that has one or more users assigned to it.

3 December 2025

Identity Governance Applications Integrate

Updated

1. If the application was using AD security groups, and those groups were created in AD, then once the review is complete, you need to manually update the AD groups to remove memberships of those users who were denied. Subsequently, to have denied access rights removed automatically, you can either update the application to use an AD group that was created in Microsoft Entra ID and [written back to Microsoft Entra ID](~/identity/hybrid/cloud-sync/how-to-configure-entra-to-active-directory.md), or move the membership from the AD group to the Microsoft Entra group, and [nest the written back group as the only member of the AD group](~/identity/hybrid/cloud-sync/govern-on-premises-groups.md).

2 December 2025

Govern an application's existing users - Microsoft PowerShell

Updated

There are four common scenarios in which it's necessary to populate Microsoft Entra ID with existing access rights and users of an application before you use the application with a Microsoft Entra ID Governance feature such as [access reviews](access-reviews-application-preparation.md).

2 December 2025

Deploy Access Reviews

Updated

| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |

2 December 2025

Perform Access Review

Updated

The Access Review Agent assists you in completing your pending access reviews by guiding you in Microsoft Teams with natural language, insights, and recommendations.

2 December 2025

Identity Governance Applications Not Provisioned Users

Updated

For more information on those first two scenarios, where the application supports provisioning, or uses an LDAP directory, SQL database, has a SOAP or REST API or relies upon Microsoft Entra ID as its identity provider, see the article [govern an application's existing users](identity-governance-applications-existing-users.md). That article covers how to use identity governance features for existing users of those categories of applications.

2 December 2025

Create Access Review

Updated

- [Complete an access review of groups or applications](complete-access-review.md)

2 December 2025

Fundamentals

4

Access Reviews Overview

Updated

| Microsoft Entra role | Specified reviewers</br>Self-review | [PIM](../id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json) | Microsoft Entra admin center |

3 December 2025

Identity Governance Overview

Updated

Organizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.

2 December 2025

General

3

Branding

1

Microsoft Entra ID: Enhance protection of the authentication experience by blocking external script injection

New

Microsoft Entra ID will enhance authentication security by enforcing a Content Security Policy that blocks external script injection, allowing only trusted Microsoft scripts. This rollout begins mid-October 2026, affecting browser-based sign-ins on login.microsoftonline.com, with no impact on Entra External ID tenants.

4 December 2025
Message CenterMC1191924 on mc.merill.net ↗Stay informed

Standards

1

Authentication External Method Provider

Updated

An external identity provider needs to provide an [OIDC Discovery endpoint](http://openid.net/specs/openid-connect-discovery-1_0.html#ProviderConfig). This endpoint is used to get more configuration data. The Discovery URL **MUST** use the `https` scheme and **MUST** end with `/.well-known/openid-configuration`. No additional path segments, query strings, or fragments are permitted after this segment. The full Discovery URL must be included in the Discovery URL configured when the EAM is created.

3 December 2025

Troubleshooting

1

Network Content Filtering

Updated

:::image type="content" source="media/how-to-network-content-filtering/internet-access-rules.png" alt-text="Screenshot of the Global Secure Access Advanced Diagnostics window on the Forwarding Profile tab, showing Internet Access rules in the Rules section." lightbox="media/how-to-network-content-filtering/internet-access-rules.png":::

5 December 2025

General

2

Fundamentals

1

Dnsbind

Updated

The domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.contoso.com/`.

4 December 2025

General

3

Customize Block Page

Updated

- For guidance on configuring web content filtering, see [Configure web content filtering](./how-to-configure-web-content-filtering.md).

5 December 2025

Windows Client Release History

Updated

This article tracks the changes in each released version of the Global Secure Access client for Windows.

4 December 2025