manager: pmwongera
Conditional Access Optimization Agent rollout guidance is the week’s main signal in an otherwise documentation-heavy update
All 28 recorded changes for the week of 5 January 2026 were Microsoft Learn updates; there were no new or removed items and no Message Center entries. The clearest substantive thread is a coordinated update to five Conditional Access Optimization Agent pages. However, the evidence does not establish preview or general availability status, rollout scope, changed policy behavior, or a required tenant action. Most remaining changes are reference or operational clarifications, with more meaningful exceptions in ID Protection remediation, SAP integration, and External ID federation guidance.
- Entra ID — Conditional AccessConditional Access Optimization Agent documentation now reflects a phased rollout
Five Entra ID Conditional Access pages were updated together: the phased-rollout page and pages for Agent Optimization, Chat, Settings, and Review Suggestions. This indicates a broader documentation set around the capability, but the supplied evidence does not identify the rollout population, licensing, preview or GA status, or any changed Conditional Access behavior. Treat this as rollout documentation rather than a launch notice.
- ID ProtectionID Protection guidance connects risk-based Conditional Access with remediation procedures
Updated ID Protection material covers identifying risk-based Conditional Access policies, investigating risky users, detections, and sign-ins, and configuring self-remediation or manually remediating risky users. The remediation guidance states that SSPR password reset or a secure password change involving MFA and a password change can remediate user risk, after which the related risk state and details are updated. This is operational and security guidance; the evidence does not indicate that the underlying risk or
There is no evidence of a tenant-wide migration, retirement, or mandatory configuration change. Administrators should review the Conditional Access Agent material if it is relevant to their rollout plans, and validate ID Protection, SAP, or External ID runbooks where those integrations are in use. Updated documentation alone should not be treated as proof of a launch, availability change, or changed product behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Entra ID
17 updatesConditional Access
5author: shlipsey3
manager: pmwongera
author: shlipsey3
manager: pmwongera
Authentication
3Howto Password Smart Lockout
Updated> [!NOTE]
Reports Data Retention
UpdatedLog storage within Microsoft Entra varies by report type and license type. You can retain the audit and sign-in activity data for longer than the default retention period outlined in the previous table by routing it to an Azure storage account using Azure Monitor. For more information, see [Archive Microsoft Entra logs to an Azure storage account](./howto-archive-logs-to-storage-account.md).
- Users can authenticate
Provisioning
3App Provisioning Sap
Updated> - Keep user attributes synchronized between Microsoft Entra ID and SAP ECC.
Configuring Microsoft Entra ID to provision users into SAP ECC with NetWeaver AS ABAP 7.0 or later
UpdatedThe following documentation provides configuration and tutorial information demonstrating how to provision users from Microsoft Entra ID into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver 7.0 or later. If you're using other versions of SAP R/3, you can still use the guides provided in the [Connectors for Microsoft Identity Manager 2016](https://www.microsoft.com/download/details.aspx?id=51495) download as a reference to build your own template for provisioning.
The Microsoft Entra provisioning agent and generic web services connector provides connectivity to on-premises SAP ECC SOAP endpoints, including SAP BAPIs.
Fundamentals
2Application Gallery
Updated- **Risk Score** – View applications by their calculated security risk score from 1 (highest risk) to 10 (lowest risk). This score helps identify applications that meet your organization's security requirements.
Explains requirements to prepare FIDO2 hardware for attestation with Microsoft Entra ID
Architecture
1A Microsoft Entra documentation page was updated: Road To The Cloud Ad Minimization.
Developer
1Manage App Consent Policies
UpdatedEvery tenant comes with a set of app consent policies that are the same across all tenants. Some of these built-in policies are used in existing built-in directory roles. For example, the `microsoft-application-admin` app consent policy describes the conditions under which the Application Administrator and Cloud Application Administrator roles are allowed to grant tenant-wide admin consent. Built-in policies can be used in custom directory roles or to configure an organization's default consent policy. These policies can't be edited. A list of the built-in policies are:
Microsoft identity platform
11. Select the **Resource** link to go directly to the app registration for the app.
Monitoring
1Sla Performance
Updated| September | 99.999% | 99.998% | 99.999% | 99.999% | 99.999% |
Microsoft Entra ID Protection
5 updatesFundamentals
3Identity Protection Policies
UpdatedIdentifying risk-based Conditional Access policies
Identity Protection Risks
Updatedauthor: shlipsey3
If a user is prompted to use self-service password reset (SSPR) to remediate user risk, they are prompted to update their password as shown in the [Microsoft Entra ID Protection user experience](concept-identity-protection-user-experience.md) article. Once they update their password, the user risk is remediated. A secure password change (MFA and password change) can also remediate user risk. The user can then proceed to sign in with their new password. The risk state and risk details for the user, sign-ins, and corresponding risk detections are updated as follows:
Authentication
1Learn how to investigate risky users, detections, and sign-ins in Microsoft Entra ID Protection.
Troubleshooting
1Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Microsoft Entra ID Governance
3 updatesGovernance
3- Attribute Changes
- The Microsoft Entra User Account configuring the connector and Access Packages must be synced to SAP Cloud Identity Services (IAS) and SAP IAG.
Sap
UpdatedOnce you have users in Microsoft Entra ID, you can provision those users from Microsoft Entra ID to SAP Cloud Identity Services or SAP ECC, to enable them to sign in to SAP applications. If you have [`SAP S/4HANA On-Premise`](https://help.sap.com/docs/identity-provisioning/identity-provisioning/target-sap-s-4hana-on-premise), then provision users from Microsoft Entra ID to SAP Cloud Identity Directory. SAP Cloud Identity Services then provisions the users originating from Microsoft Entra ID that are in the SAP Cloud Identity Directory into the downstream SAP applications to SAP S/4HANA On-Premise through the SAP cloud connector.
Microsoft Entra External ID
2 updatesGeneral
1Faq Customers
UpdatedStandards
1- [Configure a new OpenID connect identity provider in the admin center](customers/how-to-custom-oidc-federation-customers.md) - Client secret updates
Microsoft Entra Private Access
1 updateMonitoring
1Configure Domain Controllers
Updated- Use **Event Viewer** from **Application and Service Logs** > **Microsoft** > **Windows** > **Private Access Sensor** to review Private Access Sensor logs.
