Microsoft Entra introduces soft deletion and restoration for cloud security groups, allowing recovery within 30 days while preserving settings, ownership, and membership. Rollout begins in late October 2025 (preview) and February 2026 (general availability). Deleted groups remove access until restored; audit logs track actions.
Entra previews group-based passkey controls while cloud security groups gain 30-day recovery
The most consequential changes on 6 November are two Microsoft Entra ID Message Center updates: passkey profiles are entering preview in the authentication methods policy, and soft deletion/restoration is being introduced for cloud security groups. The remaining meaningful items are documentation clarifications for External ID fraud protection and ID Governance licensing for guests; the supplied Verified ID and Global Secure Access summaries do not establish additional product behavior changes.
- Passkey profiles enter the authentication methods policy preview
Entra ID · Authentication
Microsoft Entra ID is previewing passkey profiles in November 2025. The policy adds group-based passkey controls and a new API schema. Rollout is worldwide in early November and in GCC in mid-November; Microsoft says no pre-rollout action is needed, but administrators should review configurations and update documentation.
- Cloud security groups become restorable after deletion
Entra ID · Architecture
Microsoft Entra is introducing soft deletion and restoration for cloud security groups. Deleted groups can be recovered within 30 days with their settings, ownership, and membership preserved; access is removed until restoration, and audit logs track the actions. The capability is in preview from late October 2025, with general availability indicated for February 2026.
- External ID fraud-protection integration guidance is clarified
External ID · Security
The updated Microsoft Entra External ID documentation describes using the Security Store wizard in the Entra admin center to create a fraud protection provider policy for Arkose Labs. This is a documentation update and does not, from the supplied evidence, establish a new availability or rollout event.
- Guest ID Governance licensing requirements are spelled out
ID Governance · Governance
Updated guidance states that using Microsoft Entra ID Governance features for guest users requires the tenant to be linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. The excerpt also references behavior when the guest billing meter is not enabled, but does not provide those details; this should be treated as a licensing clarification rather than a feature announcement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Entra ID
1 updateMicrosoft Entra ID Governance
1 updateTo use Microsoft Entra ID Governance features for guest users, your tenant must be linked to an Azure subscription with the Microsoft Entra ID Governance for guests add-on. If the guest billing meter isn't enabled, the following behavior applies:
Microsoft Entra External ID
1 updateIntegrate Microsoft Entra External ID with Arkose Labs and HUMAN Security for fraud protection
UpdatedTo integrate Arkose Labs with Microsoft Entra External ID, you can use the Security Store wizard in Microsoft Entra admin center to create a fraud protection provider policy.
Microsoft Entra Verified ID
1 updateIdv Partners
Updated| Idemia | [Idemia documentation](https://na.idemia.com/identity/verifiable-credentials/) | Idemia Integration with Microsoft Entra Verified ID enables "Verify once, use everywhere" functionality. |
manager: sineado
