Week in brief

Conditional Access Optimization Agent rollout guidance is the week’s main signal in an otherwise documentation-heavy update

All 28 recorded changes for the week of 5 January 2026 were Microsoft Learn updates; there were no new or removed items and no Message Center entries. The clearest substantive thread is a coordinated update to five Conditional Access Optimization Agent pages. However, the evidence does not establish preview or general availability status, rollout scope, changed policy behavior, or a required tenant action. Most remaining changes are reference or operational clarifications, with more meaningful exceptions in ID Protection remediation, SAP integration, and External ID federation guidance.

  • Five Entra ID Conditional Access pages were updated together: the phased-rollout page and pages for Agent Optimization, Chat, Settings, and Review Suggestions. This indicates a broader documentation set around the capability, but the supplied evidence does not identify the rollout population, licensing, preview or GA status, or any changed Conditional Access behavior. Treat this as rollout documentation rather than a launch notice.

  • Updated ID Protection material covers identifying risk-based Conditional Access policies, investigating risky users, detections, and sign-ins, and configuring self-remediation or manually remediating risky users. The remediation guidance states that SSPR password reset or a secure password change involving MFA and a password change can remediate user risk, after which the related risk state and details are updated. This is operational and security guidance; the evidence does not indicate that the underlying risk or

For Entra administrators

There is no evidence of a tenant-wide migration, retirement, or mandatory configuration change. Administrators should review the Conditional Access Agent material if it is relevant to their rollout plans, and validate ID Protection, SAP, or External ID runbooks where those integrations are in use. Updated documentation alone should not be treated as proof of a launch, availability change, or changed product behavior.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Conditional Access

5

Authentication

3

Reports Data Retention

Updated

Log storage within Microsoft Entra varies by report type and license type. You can retain the audit and sign-in activity data for longer than the default retention period outlined in the previous table by routing it to an Azure storage account using Azure Monitor. For more information, see [Archive Microsoft Entra logs to an Azure storage account](./howto-archive-logs-to-storage-account.md).

8 January 2026

Provisioning

3

App Provisioning Sap

Updated

> - Keep user attributes synchronized between Microsoft Entra ID and SAP ECC.

8 January 2026

Configuring Microsoft Entra ID to provision users into SAP ECC with NetWeaver AS ABAP 7.0 or later

Updated

The following documentation provides configuration and tutorial information demonstrating how to provision users from Microsoft Entra ID into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver 7.0 or later. If you're using other versions of SAP R/3, you can still use the guides provided in the [Connectors for Microsoft Identity Manager 2016](https://www.microsoft.com/download/details.aspx?id=51495) download as a reference to build your own template for provisioning.

8 January 2026

Plan Sap User Source And Target

Updated

The Microsoft Entra provisioning agent and generic web services connector provides connectivity to on-premises SAP ECC SOAP endpoints, including SAP BAPIs.

8 January 2026

Fundamentals

2

Application Gallery

Updated

- **Risk Score** – View applications by their calculated security risk score from 1 (highest risk) to 10 (lowest risk). This score helps identify applications that meet your organization's security requirements.

10 January 2026

Architecture

1

Developer

1

Manage App Consent Policies

Updated

Every tenant comes with a set of app consent policies that are the same across all tenants. Some of these built-in policies are used in existing built-in directory roles. For example, the `microsoft-application-admin` app consent policy describes the conditions under which the Application Administrator and Cloud Application Administrator roles are allowed to grant tenant-wide admin consent. Built-in policies can be used in custom directory roles or to configure an organization's default consent policy. These policies can't be edited. A list of the built-in policies are:

6 January 2026

Microsoft identity platform

1

Monitoring

1

Sla Performance

Updated

| September | 99.999% | 99.998% | 99.999% | 99.999% | 99.999% |

10 January 2026

Fundamentals

3

Howto Identity Protection Remediate Unblock

Updated

If a user is prompted to use self-service password reset (SSPR) to remediate user risk, they are prompted to update their password as shown in the [Microsoft Entra ID Protection user experience](concept-identity-protection-user-experience.md) article. Once they update their password, the user risk is remediated. A secure password change (MFA and password change) can also remediate user risk. The user can then proceed to sign in with their new password. The risk state and risk details for the user, sign-ins, and corresponding risk detections are updated as follows:

8 January 2026

Authentication

1

Troubleshooting

1

Governance

3

Entitlement Management Sap Integration

Updated

- The Microsoft Entra User Account configuring the connector and Access Packages must be synced to SAP Cloud Identity Services (IAS) and SAP IAG.

9 January 2026

Sap

Updated

Once you have users in Microsoft Entra ID, you can provision those users from Microsoft Entra ID to SAP Cloud Identity Services or SAP ECC, to enable them to sign in to SAP applications. If you have [`SAP S/4HANA On-Premise`](https://help.sap.com/docs/identity-provisioning/identity-provisioning/target-sap-s-4hana-on-premise), then provision users from Microsoft Entra ID to SAP Cloud Identity Directory. SAP Cloud Identity Services then provisions the users originating from Microsoft Entra ID that are in the SAP Cloud Identity Directory into the downstream SAP applications to SAP S/4HANA On-Premise through the SAP cloud connector.

8 January 2026

General

1

Standards

1

External ID in external tenants

Updated

- [Configure a new OpenID connect identity provider in the admin center](customers/how-to-custom-oidc-federation-customers.md) - Client secret updates

7 January 2026

Monitoring

1

Configure Domain Controllers

Updated

- Use **Event Viewer** from **Application and Service Logs** > **Microsoft** > **Windows** > **Private Access Sensor** to review Private Access Sensor logs.

10 January 2026