Week in brief

DigiCert G2 trust deadline is the week’s urgent Entra action; EAM preview registration is now enforced

The week of 8 December 2025 was not a launch-heavy period: the supplied record shows no new or removed items, and most entries are Microsoft Learn documentation updates. The material exceptions are an Entra certificate-trust change with a 7 January 2026 deadline, an External Authentication Methods (EAM) public-preview registration change, and the continuing Microsoft baseline-security rollout. Other notable edits describe Agent ID preview governance and clarify existing authentication and app-consent behavior; they do not establish general availability or a retirement. The authentication edits also clarify that security questions are for SSPR only, not sign-in, and cannot verify administrator accounts during SSPR.

  • A Microsoft 365 Message Center major update says Entra will switch to DigiCert Global Root G2 certificates by 7 January 2026. Organizations must trust the G2 root CA, remove any pinning to G1, and update trust settings to avoid authentication failures or service disruption. This is an operational certificate-trust requirement, not a documentation-only clarification.

  • Entra ID — External Authentication Methods (EAM)External Authentication Methods public preview now enforces registration

    The EAM public preview update says registration enforcement begins 8 December 2025. Existing users are pre-registered, while new users after 2 December 2025 must complete inline setup; administrators can also register users. The changed onboarding path should be communicated and reflected in configuration reviews. The notice identifies EAM as public preview, not generally available.

  • The major update describes Microsoft Baseline Security Mode rolling out from November 2025 through March 2026 across Office, SharePoint, Exchange, Teams, and Entra. It centralizes recommended security standards and provides a dashboard with impact reports and risk-based recommendations. The update explicitly says there is no immediate user impact, so this is a security-posture assessment and improvement rollout rather than an immediate user-facing change.

  • The updated Manage App Consent Policies article says the ‘Let Microsoft manage your consent settings’ option uses a Microsoft-managed policy that will update with Microsoft’s latest recommended default consent settings and is the default for new tenants. It documents end-user consent exclusions including broad Files, Sites, Mail, and Calendar permissions. This is updated policy guidance; the supplied record does not announce a dated rollout of a particular rule change.

  • Updated Agent ID pages describe identities for agents themselves through four object types: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Separate Manage Agents guidance, explicitly marked Preview, describes owners and sponsors viewing agent details and enabling, disabling, or requesting access for agent identities. The evidence supports a governance and preview-documentation update, not a general-availability launch.

For Entra administrators

Verify that DigiCert Global Root G2 is trusted for Entra services and remove any G1 pinning before 7 January 2026; the Message Center update warns that otherwise authentication failures may occur. For EAM, prepare for inline setup by users added after 2 December 2025, communicate the preview registration requirement, and note that admins can register users. For Baseline Security Mode, use the dashboard, impact reports, and risk-based recommendations as the rollout proceeds; the update says there is no immediate user impact. If using the Microsoft-managed app-consent setting, account for its documented ability to update with Microsoft’s latest recommended defaults. The supplied Agent ID material gives no GA date or migration requirement.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Fundamentals

9

Manage authentication methods for Microsoft Entra ID

Updated

Microsoft Entra ID allows the use of a range of authentication methods to support a wide variety of sign-in scenarios. For an overview of the available options, see [Authentication methods in Microsoft Entra ID](overview-authentication.md). Administrators can specifically configure each method to meet their goals for user experience and security. This topic explains how to manage authentication methods for Microsoft Entra ID, and how configuration options affect user sign-in and password reset scenarios.

13 December 2025

Sspr Howitworks

Updated

* [Software OATH tokens](concept-authentication-oath-tokens.md#software-oath-tokens)

13 December 2025

Sspr Howitworks

Updated

The following authentication methods are available for SSPR:

11 December 2025

Condition Filters For Devices

Updated

1. Under **Include**, select **Directory roles**, then all roles with administrator in the name.

11 December 2025

Authentication Security Questions

Updated

Security questions aren't used as an authentication method during a sign-in event. Instead, security questions can be used during the self-service password reset (SSPR) process to confirm who you are. Administrator accounts can't use security questions as verification method with SSPR.

8 December 2025

Authentication

Updated

| [Short Message Service (SMS) sign-in](howto-authentication-sms-signin.md) | Yes | MFA and SSPR |

8 December 2025

Authentication

2

Disable User Sign In Portal

Updated

In this article, you learn how to prevent users from signing in to an application in Microsoft Entra ID through both the Microsoft Entra admin center and PowerShell. If you're looking for how to block specific users from accessing an application, use [user or group assignment](./assign-user-or-group-access-portal.md).

13 December 2025

General

2

Gpad Prereqs

Updated

|Scoping Mode |Number of in-scope groups | Number of membership links (Direct members only) |Notes |

10 December 2025

Manage App Consent Policies

Updated

The setting labeled "Let Microsoft manage your consent settings," the Microsoft managed policy, will update with Microsoft's latest recommended default consent settings. This is also the default for a new tenant. The setting's rules are currently: End users can consent for any user consentable delegated permissions EXCEPT: `Files.Read.All`, `Files.ReadWrite.All`, `Sites.Read.All`, `Sites.ReadWrite.All`, `Mail.Read`, `Mail.ReadWrite`, `Mail.ReadBasic`, `Mail.Read.Shared`, `Mail.ReadBasic.Shared`, `Mail.ReadWrite.Shared`, `MailboxItem.Read`, `Calendars.Read`, `Calendars.ReadBasic`, `Calendars.ReadWrite`, `Calendars.Read.Shared`, `Calendars.ReadBasic.Shared`, `Calendars.ReadWrite.Shared`, `Chat.Read`, `Chat.ReadWrite`, `ChannelMessage.Read.All`, `OnlineMeetings.Read`, `OnlineMeetings.ReadWrite`, `OnlineMeetingTranscript.Read.All`, `OnlineMeetingsRecording.Read.All`. Updates to this consent policy will have at least 30 days of given notice.

9 December 2025

Developer

1

Deactivate Application Portal

Updated

GET https://graph.microsoft.com/beta/applications/{application-id}?$select=displayName,isDisabled,appId

13 December 2025

Standards

1

Microsoft baseline security mode for Office, SharePoint, Exchange, Teams, and Entra

New

Baseline Security Mode centralizes Microsoft’s recommended security standards for Office, SharePoint, Exchange, Teams, and Entra. Rolling out from November 2025 to March 2026, it provides admins with a dashboard to assess and improve security posture using impact reports and risk-based recommendations, with no immediate user impact.

10 December 2025
Message CenterMC1193689 on mc.merill.net ↗Major updatePlan for change

Fundamentals

1

Agent Id Governance Overview

Updated

Historically, AI agents would rely upon tools to interact with various applications and systems, and each of those tools would have their own identities in those applications and systems. Some of those tools would use service principals to authenticate to Microsoft services via Microsoft Graph or Microsoft Azure APIs. [Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) introduces support for identities for the agents themselves, with four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Through the [agent identity blueprint](../agent-id/identity-platform/agent-blueprint.md), the agent can create one or more agent identities, and optionally an agent user for each agent identity. Each agent identity and agent user can have distinct access rights.

12 December 2025

General

1

Manage Agents in end user experience (Preview)

Updated

The Manage Agents feature in Microsoft Entra lets you view, and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-is-agent-id.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.

12 December 2025

Governance

1

Review Your Access

Updated

The first step to perform an access review is to find and open the access review.

12 December 2025

Fundamentals

1

B2b Guest Access

Updated

**Q: Can I configure MFA on the resource tenant?**

11 December 2025

General

1

Managed Identities Status

Updated

| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|

12 December 2025

General

1