← Previous day

Next day →
Day in brief

Entra ID Protection alert defaults change on 11 December; most other updates clarify documentation

The clearest administrator-facing change is an upcoming Microsoft Defender XDR behavior change for Entra ID Protection alerts: risk-level filtering will be introduced and the default will become High risk only. The other meaningful items are Microsoft Learn updates covering a macOS platform credential preview, access-package assignments for agent identities, and Entitlement Management catalog restrictions. The supplied evidence does not establish a general-availability launch, retirement, or tenant-wide rollout for those documentation entries.

  • The Microsoft 365 Message Center says that starting 11 December 2025, Defender XDR will let administrators filter Entra ID Protection alerts by High only, High + Medium, or All. The default will change to High risk only, reducing alert volume. This is an upcoming alert-behavior change rather than a retirement.

  • The Entra ID planning documentation for phishing-resistant passwordless authentication was updated to include “Platform credential for macOS (preview).” This supports rollout planning, but the supplied change does not establish general availability or a new tenant configuration requirement.

  • The Agent ID Governance Overview now documents that agent identities can receive resources directly through access packages. An agent can request a package itself, or its owner or sponsor can request one on its behalf. This clarifies the documented governance and request paths; it does not state a launch or availability status.

  • The Access Package Resources documentation states that access package managers can use only resources already available in the package’s catalog. They cannot add resources to a catalog, even when they own those resources. This is a documentation clarification of an operational restriction, so catalog availability must be handled before package creation.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

13 updates

1
1

User provisioning for Slack

Updated

Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Slack.

1

Agent Id Governance Overview

Updated

Agent identities can have resources assigned to them directly via access packages. Resource assignments allow agent identities to request an access package for themselves, or have their owner or sponsor request one on their behalf. With Access packages, you're able to assign agent identities the following resources:

5

Microsoft Entra ID Governance licensing fundamentals

Updated

This following document discusses Microsoft Entra ID Governance licensing for employees. It's intended for IT decision makers, IT administrators, and IT professionals who are considering Microsoft Entra ID Governance services for their organizations.

Identity Governance Overview

Updated

| Provisioning users into on-premises and cloud applications that have their own directories or databases | [Configure automatic user provisioning](../identity/app-provisioning/user-provisioning.md) with user assignments or [scoping filters](../identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md) |

Entitlement Management Access Package Request Policy

Updated

Guest users refer to external users that have been invited into your directory with [Microsoft Entra B2B](../external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](../fundamentals/users-default-permissions.md).

Entra Entitlement Management Request Policy

Updated

Guest users are external identities who have been invited into your directory via [Microsoft Entra B2B](~/external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](~/fundamentals/users-default-permissions.md).

3

Entitlement Management Access Package Resources

Updated

If you need to add resources such as groups or apps to an access package, you should check whether the resources you need are available in the access package's catalog. If you're an access package manager, you can't add resources to a catalog, even if you own them. You're restricted to using the resources available in the catalog.

Entitlement Management Access Package Create

Updated

If you're not sure which resource roles to include, you can skip adding them while creating the access package, and then [add them](entitlement-management-access-package-resources.md) later.

1
1

Supported Features Customers

Updated

Microsoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include edge protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…