Week in brief

Mid-June web-category reclassification is the week’s main operational change; Agent ID guidance is the other substantive theme

For the week of 1 June 2026, the record is overwhelmingly a documentation-maintenance cycle: 1,822 items were updated, with no recorded new or removed items, alongside one Message Center notice. That notice is the clearest operational change: Microsoft Entra Internet Access will add an AI Agents web category and refine existing categories in mid-June, potentially reclassifying sites used by filtering policies. The strongest Learn-content exception is a set of Microsoft Entra Agent ID updates covering agent-aware Conditional Access, risk, and lifecycle governance. SSPR and system-preferred authentication updates are documentation clarification or security guidance rather than identified launches. The remaining representative edits are primarily app SSO and provisioning tutorials, reference pages, and troubleshooting content.

  • Microsoft Entra Internet Access will change web categorizationInternet Access

    A Microsoft 365 Message Center notice says Microsoft Entra Internet Access will update web categorization in mid-June 2026. It adds a new AI Agents category and refines existing categories, so some sites will be reclassified and filtering policies may be affected. The notice says no action is required, but tells admins to review and adjust policies as needed. This is an announced behavior change, not merely a Learn-page edit.

  • Agent ID guidance defines an agent-aware Conditional Access and risk modelAgent ID

    Several updated Agent ID pages describe Conditional Access as using user and agent context, device, location, and session-risk information. They also note that agents can obtain tokens without an interactive user session and without the device, location, or MFA signals that classic Conditional Access uses for human trust decisions. The documentation says Microsoft Entra ID Protection for agents continuously evaluates agent behavior and emits a risk level, while related policy guidance allows targeting all agent—or-

  • Agent ID governance guidance separates sponsorship from ownershipAgent ID

    The updated guidance states that every agent identity and agent identity blueprint must have at least one sponsor: a human user or supported group accountable for lifecycle decisions such as approving access extensions and authorizing suspension. It distinguishes sponsorship from ownership for technical operations and incident response. The guidance also says these objects derive from service principals and that blueprint principals can hold grants that propagate to child agents. Access-package guidance lists group

For Entra administrators

For Microsoft Entra Internet Access, the Message Center says no action is required, but admins should review and adjust filtering policies if reclassified sites affect intended access. The related Global Secure Access guidance covers category-, URL-, and FQDN-based filtering through security profiles and Conditional Access. For Agent ID, administrators deploying agents should account for the absence of classic human sign-in signals and review the documented agent targeting and risk model. The updated governance guidance states that every agent identity and blueprint requires a sponsor, separate from a technical owner. The supplied evidence does not establish a new general-availability release, retirement, or tenant-wide rollout, and does not show a required tenant change for the SSPR orาะ?

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

Microsoft Entra ID

1807 updates

General

1483

Provisioning

164

Standards

55

Security

32

Monitoring

31

Authentication

16

Prevent attacks using smart lockout

Updated

Learn how Microsoft Entra smart lockout helps protect your organization from brute-force attacks that try to guess user passwords.

4 June 2026

Howto Sspr Authenticationdata

Updated

Some organizations prefer to bootstrap this process through synchronization of authentication data that already exists in Active Directory Domain Services. This synchronized data is made available to Microsoft Entra ID and SSPR without requiring user interaction. When users need to change or reset their password, they can do so even if they haven't previously registered their contact information.

2 June 2026

Developer

10

Fundamentals

7

Zero Trust Ai

Updated

A Microsoft Entra documentation page was updated: Zero Trust Ai.

5 June 2026

System Preferred Authentication

Updated

System-preferred authentication prompts users to sign in by using the most secure method they registered. It's an important security enhancement for users who authenticate by using less secure methods like passwords or SMS.

3 June 2026

Soft Delete Devices

Updated

During the preview, device soft delete is supported for the following device types:

2 June 2026

Troubleshooting

4

61008

Updated

**Remediation action**

5 June 2026

61011

Updated

**Remediation action**

5 June 2026

61006

Updated

**Remediation action**

5 June 2026

Governance

3

Architecture

2

Governance

4

userimpact: Low

Updated

Microsoft Entra Agent ID requires every [agent identity](/entra/agent-id/agent-identities) and [agent identity blueprint](/entra/agent-id/agent-blueprint) to have at least one sponsor. A sponsor is a human user, or supported group, that holds business accountability for the agent's lifecycle, such as deciding when the agent is no longer needed, approving extensions when access expires, and authorizing suspension during incidents. A sponsor is different from an owner, which designates the human users responsible for technical operations and incident response.

5 June 2026

userimpact: Medium

Updated

Microsoft Entra Agent ID introduced two identity types: [agent identities](/entra/agent-id/agent-identities) and [agent identity blueprint principals](/entra/agent-id/agent-blueprint). These identity objects derive from service principals, and so carry the same requirements and best practices for ownership, lifecycle management, and cleanup as any service principal. Blueprint principals are the provisioning surface from which agent identities are created and can hold grants that propagate to child agents. Having a designated owner for these objects helps in two important areas of agent identity management:

5 June 2026

Licensing Governance

Updated

|[EM - Agents and service principals assigned to access packages](~/id-governance/entitlement-management-access-package-create.md#allow-users-service-principals-and-agent-identities-in-your-directory-to-request-the-access-package)|||||| :white_check_mark: |

5 June 2026

Agent Access Packages

Updated

1. Select **Next: Resource roles**. On the **Resource roles** tab, you select the resource roles to include in the access package. Access packages for agent identities can have security group memberships, directory roles, or API permissions as resource roles. For more information, see [add a group](/entra/id-governance/entitlement-management-access-package-resources#add-a-group-or-team-resource-role), [add a Microsoft Entra role](/entra/id-governance/entitlement-management-access-package-resources#add-a-microsoft-entra-role-assignment), and [add an API permission](/entra/id-governance/entitlement-management-access-package-resources#add-an-api-permission-preview). Don't add application roles, SAP roles, or SharePoint Online site roles to an access package for agent identities.

4 June 2026

Conditional Access

3

userimpact: Low

Updated

When an organization enables AI agents in Microsoft Entra, [agent identities](/entra/agent-id/agent-identities) can access tokens to access organizational resources without an interactive user session and device, location, or MFA signals that classic Conditional Access uses to make trust decisions for human users. Microsoft Entra ID Protection for agents continuously evaluates each agent's behavior and emits a risk level that is driven by signals such as:

5 June 2026

61009

Updated

When an organization deploys AI agents, those agents acquire access tokens to access organizational resources on every interaction, but without an interactive user session and device, location, or MFA signals that classic Conditional Access uses to make trust decisions for human users. Microsoft Entra Agent ID introduces two distinct identity types:

5 June 2026

Agent Id

Updated

Conditional Access is an intelligent policy engine that helps organizations control how users and agents access corporate resources. It brings together real-time signals such as user's and agent's context, device, location, and session risk information to determine when to allow, block, or limit access, or require more verification steps.

4 June 2026

Authentication

1

Developer

1

Validate Agent Tokens Downstream Api

Updated

:::image type="content" source="media/how-to-validate-agent-tokens-downstream-api/agent-token-flow-to-downstream-api.png" alt-text="Diagram showing the agent caller sending a Bearer token to the weather API, which verifies the token and calls Open-Meteo." lightbox="media/how-to-validate-agent-tokens-downstream-api/agent-token-flow-to-downstream-api.png":::

5 June 2026

General

1

Authentication

1

Fundamentals

1

General

1

Conditional Access

1

General

1

General

1