By January 7, 2026, Microsoft Entra will switch from DigiCert Global Root G1 to G2 certificates. Organizations must trust the DigiCert G2 root CA to avoid authentication failures with Entra services. Remove any pinning to G1 and update trust settings to prevent service disruption.
DigiCert G2 trust deadline is the week’s urgent Entra action; EAM preview registration is now enforced
The week of 8 December 2025 was not a launch-heavy period: the supplied record shows no new or removed items, and most entries are Microsoft Learn documentation updates. The material exceptions are an Entra certificate-trust change with a 7 January 2026 deadline, an External Authentication Methods (EAM) public-preview registration change, and the continuing Microsoft baseline-security rollout. Other notable edits describe Agent ID preview governance and clarify existing authentication and app-consent behavior; they do not establish general availability or a retirement. The authentication edits also clarify that security questions are for SSPR only, not sign-in, and cannot verify administrator accounts during SSPR.
A Microsoft 365 Message Center major update says Entra will switch to DigiCert Global Root G2 certificates by 7 January 2026. Organizations must trust the G2 root CA, remove any pinning to G1, and update trust settings to avoid authentication failures or service disruption. This is an operational certificate-trust requirement, not a documentation-only clarification.
- Entra ID — External Authentication Methods (EAM)External Authentication Methods public preview now enforces registration
The EAM public preview update says registration enforcement begins 8 December 2025. Existing users are pre-registered, while new users after 2 December 2025 must complete inline setup; administrators can also register users. The changed onboarding path should be communicated and reflected in configuration reviews. The notice identifies EAM as public preview, not generally available.
- Entra ID and Microsoft 365Baseline Security Mode continues its cross-workload security rollout
The major update describes Microsoft Baseline Security Mode rolling out from November 2025 through March 2026 across Office, SharePoint, Exchange, Teams, and Entra. It centralizes recommended security standards and provides a dashboard with impact reports and risk-based recommendations. The update explicitly says there is no immediate user impact, so this is a security-posture assessment and improvement rollout rather than an immediate user-facing change.
- Entra ID — app consent policiesMicrosoft-managed app-consent guidance now documents a mutable default policy
The updated Manage App Consent Policies article says the ‘Let Microsoft manage your consent settings’ option uses a Microsoft-managed policy that will update with Microsoft’s latest recommended default consent settings and is the default for new tenants. It documents end-user consent exclusions including broad Files, Sites, Mail, and Calendar permissions. This is updated policy guidance; the supplied record does not announce a dated rollout of a particular rule change.
Updated Agent ID pages describe identities for agents themselves through four object types: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Separate Manage Agents guidance, explicitly marked Preview, describes owners and sponsors viewing agent details and enabling, disabling, or requesting access for agent identities. The evidence supports a governance and preview-documentation update, not a general-availability launch.
Verify that DigiCert Global Root G2 is trusted for Entra services and remove any G1 pinning before 7 January 2026; the Message Center update warns that otherwise authentication failures may occur. For EAM, prepare for inline setup by users added after 2 December 2025, communicate the preview registration requirement, and note that admins can register users. For Baseline Security Mode, use the dashboard, impact reports, and risk-based recommendations as the rollout proceeds; the update says there is no immediate user impact. If using the Microsoft-managed app-consent setting, account for its documented ability to update with Microsoft’s latest recommended defaults. The supplied Agent ID material gives no GA date or migration requirement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
15 updatesFundamentals
9Microsoft Entra ID allows the use of a range of authentication methods to support a wide variety of sign-in scenarios. For an overview of the available options, see [Authentication methods in Microsoft Entra ID](overview-authentication.md). Administrators can specifically configure each method to meet their goals for user experience and security. This topic explains how to manage authentication methods for Microsoft Entra ID, and how configuration options affect user sign-in and password reset scenarios.
External Authentication Methods (EAM) Public Preview will enforce registration starting December 8, 2025. Existing users are pre-registered; new users after December 2, 2025, must complete in-line setup. Admins can register users. Organizations should prepare by communicating changes and reviewing configurations.
Sspr Howitworks
Updated* [Software OATH tokens](concept-authentication-oath-tokens.md#software-oath-tokens)
Sspr Howitworks
UpdatedThe following authentication methods are available for SSPR:
1. Under **Include**, select **Directory roles**, then all roles with administrator in the name.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Security questions aren't used as an authentication method during a sign-in event. Instead, security questions can be used during the self-service password reset (SSPR) process to confirm who you are. Administrator accounts can't use security questions as verification method with SSPR.
Authentication
Updated| [Short Message Service (SMS) sign-in](howto-authentication-sms-signin.md) | Yes | MFA and SSPR |
Authentication
2Mfa Registration Campaign
Updatedauthor: mjsantani
Disable User Sign In Portal
UpdatedIn this article, you learn how to prevent users from signing in to an application in Microsoft Entra ID through both the Microsoft Entra admin center and PowerShell. If you're looking for how to block specific users from accessing an application, use [user or group assignment](./assign-user-or-group-access-portal.md).
General
2Gpad Prereqs
Updated|Scoping Mode |Number of in-scope groups | Number of membership links (Direct members only) |Notes |
Manage App Consent Policies
UpdatedThe setting labeled "Let Microsoft manage your consent settings," the Microsoft managed policy, will update with Microsoft's latest recommended default consent settings. This is also the default for a new tenant. The setting's rules are currently: End users can consent for any user consentable delegated permissions EXCEPT: `Files.Read.All`, `Files.ReadWrite.All`, `Sites.Read.All`, `Sites.ReadWrite.All`, `Mail.Read`, `Mail.ReadWrite`, `Mail.ReadBasic`, `Mail.Read.Shared`, `Mail.ReadBasic.Shared`, `Mail.ReadWrite.Shared`, `MailboxItem.Read`, `Calendars.Read`, `Calendars.ReadBasic`, `Calendars.ReadWrite`, `Calendars.Read.Shared`, `Calendars.ReadBasic.Shared`, `Calendars.ReadWrite.Shared`, `Chat.Read`, `Chat.ReadWrite`, `ChannelMessage.Read.All`, `OnlineMeetings.Read`, `OnlineMeetings.ReadWrite`, `OnlineMeetingTranscript.Read.All`, `OnlineMeetingsRecording.Read.All`. Updates to this consent policy will have at least 30 days of given notice.
Developer
1GET https://graph.microsoft.com/beta/applications/{application-id}?$select=displayName,isDisabled,appId
Standards
1Baseline Security Mode centralizes Microsoft’s recommended security standards for Office, SharePoint, Exchange, Teams, and Entra. Rolling out from November 2025 to March 2026, it provides admins with a dashboard to assess and improve security posture using impact reports and risk-based recommendations, with no immediate user impact.
Microsoft Entra Agent ID
2 updatesFundamentals
1Agent Id Governance Overview
UpdatedHistorically, AI agents would rely upon tools to interact with various applications and systems, and each of those tools would have their own identities in those applications and systems. Some of those tools would use service principals to authenticate to Microsoft services via Microsoft Graph or Microsoft Azure APIs. [Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) introduces support for identities for the agents themselves, with four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Through the [agent identity blueprint](../agent-id/identity-platform/agent-blueprint.md), the agent can create one or more agent identities, and optionally an agent user for each agent identity. Each agent identity and agent user can have distinct access rights.
General
1The Manage Agents feature in Microsoft Entra lets you view, and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-is-agent-id.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
Microsoft Entra ID Governance
1 updateGovernance
1Review Your Access
UpdatedThe first step to perform an access review is to find and open the access review.
Microsoft Entra External ID
1 updateFundamentals
1B2b Guest Access
Updated**Q: Can I configure MFA on the resource tenant?**
Microsoft Entra Workload ID
1 updateGeneral
1Managed Identities Status
Updated| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
General
1Configure Kerberos Sso
Updatedai-usage: ai-assisted
