- Platform credential for macOS (preview)
Entra ID Protection alert defaults change on 11 December; most other updates clarify documentation
The clearest administrator-facing change is an upcoming Microsoft Defender XDR behavior change for Entra ID Protection alerts: risk-level filtering will be introduced and the default will become High risk only. The other meaningful items are Microsoft Learn updates covering a macOS platform credential preview, access-package assignments for agent identities, and Entitlement Management catalog restrictions. The supplied evidence does not establish a general-availability launch, retirement, or tenant-wide rollout for those documentation entries.
- Entra ID Protection alerts in Defender XDR will default to High risk only
ID Protection · Monitoring
The Microsoft 365 Message Center says that starting 11 December 2025, Defender XDR will let administrators filter Entra ID Protection alerts by High only, High + Medium, or All. The default will change to High risk only, reducing alert volume. This is an upcoming alert-behavior change rather than a retirement.
- macOS platform credentials are now listed as a preview prerequisite
Entra ID · Authentication
The Entra ID planning documentation for phishing-resistant passwordless authentication was updated to include “Platform credential for macOS (preview).” This supports rollout planning, but the supplied change does not establish general availability or a new tenant configuration requirement.
- Agent ID governance documentation describes access-package assignments
Agent ID · Fundamentals
The Agent ID Governance Overview now documents that agent identities can receive resources directly through access packages. An agent can request a package itself, or its owner or sponsor can request one on its behalf. This clarifies the documented governance and request paths; it does not state a launch or availability status.
- Entitlement Management catalog boundaries are clarified
ID Governance · Governance
The Access Package Resources documentation states that access package managers can use only resources already available in the package’s catalog. They cannot add resources to a catalog, even when they own those resources. This is a documentation clarification of an operational restriction, so catalog availability must be handled before package creation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
13 updates
Microsoft Entra ID
2 updatesUser provisioning for Slack
UpdatedLearn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Slack.
Microsoft Entra Agent ID
1 updateAgent Id Governance Overview
UpdatedAgent identities can have resources assigned to them directly via access packages. Resource assignments allow agent identities to request an access package for themselves, or have their owner or sponsor request one on their behalf. With Access packages, you're able to assign agent identities the following resources:
Microsoft Entra ID Governance
9 updatesThis following document discusses Microsoft Entra ID Governance licensing for employees. It's intended for IT decision makers, IT administrators, and IT professionals who are considering Microsoft Entra ID Governance services for their organizations.
A Microsoft Entra documentation page was updated: Entitlement Management Overview.
Identity Governance Overview
Updated| Provisioning users into on-premises and cloud applications that have their own directories or databases | [Configure automatic user provisioning](../identity/app-provisioning/user-provisioning.md) with user assignments or [scoping filters](../identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts.md) |
Guest users refer to external users that have been invited into your directory with [Microsoft Entra B2B](../external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](../fundamentals/users-default-permissions.md).
Guest users are external identities who have been invited into your directory via [Microsoft Entra B2B](~/external-id/what-is-b2b.md). For more information about the differences between member users and guest users, see [What are the default user permissions in Microsoft Entra ID?](~/fundamentals/users-default-permissions.md).
If you need to add resources such as groups or apps to an access package, you should check whether the resources you need are available in the access package's catalog. If you're an access package manager, you can't add resources to a catalog, even if you own them. You're restricted to using the resources available in the catalog.
If you're not sure which resource roles to include, you can skip adding them while creating the access package, and then [add them](entitlement-management-access-package-resources.md) later.
- [Understanding least privileged](least-privileged.md)
1. [Sign in to the My Access portal](entitlement-management-request-access.md#sign-in-to-the-my-access-portal)
Microsoft Entra External ID
1 updateSupported Features Customers
UpdatedMicrosoft Entra External ID supports integrated security features and partner solutions to help protect identities across the lifecycle. These capabilities include edge protection, sign-up fraud prevention, and unified monitoring. You can enable these solutions directly in External ID and access partner integrations through the [Microsoft Security Store](https://securitystore.microsoft.com/). This approach allows organizations to deploy trusted security tools quickly without complex setup. All these features are available in a wizard under the Security Store blade experience.
