Kerberos
Updated>[!IMPORTANT]
Daily.Entra.NewsThis was a documentation-heavy period, with no supplied evidence of a new feature launch, preview, general-availability milestone, retirement, or already-applied tenant behavior change. The most consequential item is a Microsoft 365 Message Center security notice about upcoming MFA enforcement for Azure resource management. The other meaningful updates clarify how Entra agent capabilities are documented rather than announcing their availability.
The Microsoft 365 Message Center says Microsoft will enforce MFA for all Azure resource-management actions from 1 October 2025, with a postponement option until July 2026. It calls for users to enable MFA, administrators to update Azure CLI and PowerShell, and tenants to use Azure Policy to assess impact. Gallatin customers are advised to implement MFA without enforcement. This is security and enforcement guidance, not a new Entra feature launch.
The updated phased-rollout guidance describes the agent creating a report-only policy with a phased rollout. This documents a controlled evaluation path; it does not by itself establish a new launch, general availability, or a change to tenant enforcement.
The updated Copilot Entra Agents documentation states that the Conditional Access optimization agent requires at least a Microsoft Entra ID P1 license. This is a licensing prerequisite clarification for the documented capability, not evidence of a new release or availability change.
The updated Agent Optimization page says the risky-users path suggests a policy requiring a secure password change for high-risk users and requires Microsoft Entra ID P2. The supplied item does not state that this capability is new, in preview, or generally available.
The updated Access Review Agent page describes the agent automatically gathering insights and generating recommendations, then guiding reviewers in Microsoft Teams with natural-language summaries and proposed decisions while reviewers make the final call. This is a documentation description of the workflow, not evidence of a new launch.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
>[!IMPORTANT]
- You must have at least the [Microsoft Entra ID P1](licensing.md) license for the Conditional Access optimization agent.
author: shlipsey3
1. [Agent creates a report-only policy with a phased rollout](#agent-creates-a-report-only-policy-with-a-phased-rollout)
- **Risky users**: The agent suggests a policy to require secure password change for high risk users. Requires Microsoft Entra ID P2 license.
Say goodbye to time-consuming research and the uncertainty of rushed decisions. The Access Review Agent works for your reviewers by automatically gathering insights and generating recommendations. It then guides reviewers through the review process in Microsoft Teams with natural language, with simple summaries and proposed decisions, so they can make the final call with confidence and clarity.
1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least an [Identity Governance Administrator](../identity/role-based-access-control/permissions-reference.md#identity-governance-administrator).
To view information about the Access Review Agent, open up the Access Review Agent to get to the overview page. The highlight of the overview page is the Agent summary, which provides a quick summary of agent actions over the course of the last 30 days.
> [!NOTE]
1. To test allow-listing, create a rule in the Threat Intelligence policy to allow access to the site. Within 2 minutes, you should be able to access it. (You may need to clear your browser cache.)