← Previous day

Next day →
Day in brief

Agent ID preview guidance expands around tenant control and sign-in, while Security Copilot enters a phased E5 rollout

The meaningful changes on 19 November center on Microsoft Entra Agent ID preview operations rather than a confirmed broad general-availability launch. New Learn content covers the agent sign-in, consent, and trust flow, plus known issues; updated guidance says agent identities are enabled by default and clarifies preview security coverage. A separate Message Center notice announces Microsoft Security Copilot inclusion in Microsoft 365 E5 with phased rollout and Entra group controls. Five Agent App Lifecycle pages are marked removed, but the supplied records do not establish whether content was consolidated or whether a capability was retired.

  • The updated guidance says agent identities are enabled by default in all Microsoft Entra ID tenants and explains that customers can configure settings to control which Agent IDs are allowed. It also identifies Agent ID as subject to standard preview terms. This is an updated guidance statement, not evidence that the default changed on this date.

  • A new article describes the Agent ID sign-in process, including consent pages, trust criteria, and management of agent permissions for secure access to AI agents using work accounts. It is an operational documentation addition; the record does not claim a new sign-in feature or general availability.

  • A new troubleshooting page covers current known issues and errors encountered in the Microsoft Entra Agent ID preview. The supplied summary does not enumerate those issues, so administrators should consult the page during pilots and troubleshooting rather than infer a specific blocker or required fix from this record.

  • The updated Risky Agents guidance states that ID Protection for agents is included with a Microsoft Entra P2 license while the capability is in preview. This is a licensing and lifecycle clarification, not a general-availability announcement; pilot owners should validate entitlement and account for the preview status.

  • A Message Center notice says Microsoft Security Copilot is included at no extra cost in Microsoft 365 E5, providing AI-driven security agents across Defender, Entra, Intune, and Purview. Rollout is phased; monthly Security Compute Units are based on user count, and administrator controls are provided through Entra ID group membership. The notice does not indicate immediate access for every tenant.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

25 updates

4

Sso Linux

Updated

The Microsoft single sign-on for Linux is supported with the following operating systems (physical or Hyper-V machine with x86/64 CPUs):

Manage App Consent Policies

Updated

- **microsoft-user-default-recommended:** Permissions consentable based on Microsoft's current recommendations.

3

Microsoft Entra ID: Retirement of duplicative properties in passkey (FIDO2) authentication methods policy

New

Starting October to November 2027, Microsoft will retire the isAttestationEnforced and keyRestrictions properties from the fido2AuthenticationMethodConfiguration API. These will sync with new properties in the updated passkey policy API schema during transition. Admins must update configurations, automations, and integrations accordingly.

Message CenterMC1188230 on mc.merill.net ↗Major updatePlan for change

Kerberos

Updated

For more information about Kerberos in Windows, see [Kerberos authentication overview in Windows Server](/windows-server/security/kerberos/kerberos-authentication-overview).

2
1
1
3

Microsoft Entra Agent Registry roles

Updated

In the Microsoft Entra Agent Registry, you can assign roles to administrators or other security principals to manage agent instances, agent card manifests, and agent collections. These roles provide the permissions required to perform specific actions, such as creating or updating agent instances, create agent card manifests, or managing collection membership.

Microsoft Entra Agent Identities For Ai Agents

Updated

- Using real-time signals such as agent identities risk controlling agent access to resources, with Microsoft Managed Policies providing a secure baseline by blocking high-risk agents.

2
1

Microsoft Entra Agent ID sign-in process

New

Learn about the Microsoft Entra Agent ID sign-in process, including consent pages, trust criteria, and how to manage agent permissions for secure access to AI agents using work accounts.

1

How are agent identities created?

Updated

Learn the channels and roles involved in creating Microsoft Entra agent identity blueprints, agent identities, and agent users. Monitor and control their introduction into your tenant.

1

Disable agent identities in your tenant

Updated

Agent identities are enabled by default in all Microsoft Entra ID tenants. Customers who want to control which Agent IDs are allowed in their tenant can follow the guidance in this article to configure their preferred settings. Microsoft Entra Agent ID is subject to its [standard preview terms and conditions](/entra/fundamentals/licensing-preview-info).

1
2

Risky Agents

Updated

- ID Protection for agents is included with the Microsoft Entra P2 license while in preview.

Whats New Ignite 2025

Updated

- [Configure risk policies](../id-protection/howto-identity-protection-configure-risk-policies.md) (Updated)

1

Custom Data Resource Access Reviews

Updated

:::image type="content" source="media/custom-data-resource-access-reviews/upload-access-data-files.png" alt-text="Screenshot of uploading files to custom access data.":::

1
1

Secure Web Ai Gateway Agents

Updated

- The enforcement feature supports only the baseline profile. Network security policies apply per tenant.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…