Sso Linux
UpdatedThe Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):
Daily.Entra.NewsThe meaningful changes on 19 November center on Microsoft Entra Agent ID preview operations rather than a confirmed broad general-availability launch. New Learn content covers the agent sign-in, consent, and trust flow, plus known issues; updated guidance says agent identities are enabled by default and clarifies preview security coverage. A separate Message Center notice announces Microsoft Security Copilot inclusion in Microsoft 365 E5 with phased rollout and Entra group controls. Five Agent App Lifecycle pages are marked removed, but the supplied records do not establish whether content was consolidated or whether a capability was retired.
The updated guidance says agent identities are enabled by default in all Microsoft Entra ID tenants and explains that customers can configure settings to control which Agent IDs are allowed. It also identifies Agent ID as subject to standard preview terms. This is an updated guidance statement, not evidence that the default changed on this date.
A new article describes the Agent ID sign-in process, including consent pages, trust criteria, and management of agent permissions for secure access to AI agents using work accounts. It is an operational documentation addition; the record does not claim a new sign-in feature or general availability.
A new troubleshooting page covers current known issues and errors encountered in the Microsoft Entra Agent ID preview. The supplied summary does not enumerate those issues, so administrators should consult the page during pilots and troubleshooting rather than infer a specific blocker or required fix from this record.
The updated Risky Agents guidance states that ID Protection for agents is included with a Microsoft Entra P2 license while the capability is in preview. This is a licensing and lifecycle clarification, not a general-availability announcement; pilot owners should validate entitlement and account for the preview status.
A Message Center notice says Microsoft Security Copilot is included at no extra cost in Microsoft 365 E5, providing AI-driven security agents across Defender, Entra, Intune, and Purview. Rollout is phased; monthly Security Compute Units are based on user count, and administrator controls are provided through Entra ID group membership. The notice does not indicate immediate access for every tenant.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):
> | Role | Description | Template ID |
- **microsoft-user-default-recommended:** Permissions consentable based on Microsoft's current recommendations.
A Microsoft Entra documentation page was updated: Agent Contact App Owners.
Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.
For more information about Kerberos in Windows, see [Kerberos authentication overview in Windows Server](/windows-server/security/kerberos/kerberos-authentication-overview).
> [!NOTE]
A Microsoft Entra documentation page was updated: Agent App Lifecycle Discovery Onboard.
A Microsoft Entra documentation page was updated: Agent App Lifecycle Management.
- [How to use Microsoft Entra health monitoring signals and alerts](/entra/identity/monitoring-health/howto-use-health-scenario-alerts)
A Microsoft Entra documentation page was updated: Agent App Lifecycle Remediation Plans.
In the Microsoft Entra Agent Registry, you can assign roles to administrators or other security principals to manage agent instances, agent card manifests, and agent collections. These roles provide the permissions required to perform specific actions, such as creating or updating agent instances, create agent card manifests, or managing collection membership.
- Using real-time signals such as agent identities risk controlling agent access to resources, with Microsoft Managed Policies providing a secure baseline by blocking high-risk agents.
A Microsoft Entra documentation page was updated: Agent Identify Prioritize Risky Apps.
The following known issues and gaps relate to consent and permissions.
The type of permissions you request depends on how your agent operates and what resources it needs to access.
Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.
Learn the channels and roles involved in creating Microsoft Entra agent identity blueprints, agent identities, and agent users. Monitor and control their introduction into your tenant.
Agent identities are enabled by default in all Microsoft Entra ID tenants. Customers who want to control which Agent IDs are allowed in their tenant can follow the guidance in this article to configure their preferred settings. Microsoft Entra Agent ID is subject to its [standard preview terms and conditions](/entra/fundamentals/licensing-preview-info).
Learn about currently known issues and errors encountered when using the Microsoft Entra Agent ID preview.
- ID Protection for agents is included with the Microsoft Entra P2 license while in preview.
- [Configure risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) (Updated)
:::image type="content" source="media/custom-data-resource-access-reviews/upload-access-data-files.png" alt-text="Screenshot of uploading files to custom access data.":::
- Select the **Internet applications blocked by Entra Internet Access Policy** scenario.
- The enforcement feature supports only the baseline profile. Network security policies apply per tenant.