← Previous day

Next day →
Day in brief

Identity Risk Management Agent guidance was reorganized around a Preview, while Agent ID governance and MFA-log interpretation gained important clarification.

2 December was primarily a documentation-maintenance day: 3 new pages, 20 updates, and 4 removals, with no Message Center items in the supplied evidence. The most consequential cluster was Microsoft Entra ID Protection’s Identity Risk Management Agent: new pages cover the agent, its settings, and findings in the Risky user report, while related guidance explicitly labels the capability Preview. The evidence supports a documentation rework and clearer operating guidance—not general availability, a confirmed tenant behavior change, or a product retirement. Other notable updates covered Agent ID governance objects, the Access Review Agent in Teams, and MFA event correlation across Entra sign-in logs and Azure Monitor.

  • Updated guidance identifies the Identity Risk Management Agent as Preview and describes analysis of risky identities, suggested remediation, and LLM-assisted review of risky activity. Three new pages cover the agent, its settings, and findings in the Risky user report, while older similarly named agent pages were removed. This indicates documentation restructuring; it does not establish general availability or that the capability itself was retired.

  • The updated Agent Id Governance Overview documents agent identity blueprints, agent identity blueprint principals, agent identities, and agent users. It explains that agent identities—and optionally agent users—can give AI agents digital identities in Microsoft Entra, which can then be governed through lifecycle and access features, with sponsors assigned to agent identities. This is an updated governance model description, not evidence of a new GA release.

  • The updated Perform Access Review page says the Access Review Agent assists with pending reviews in Microsoft Teams using natural-language guidance, insights, and recommendations. The supplied change is documentation guidance and provides no availability, licensing, or rollout details, so it should not be treated as a confirmed launch.

  • The updated Sign In Log Activity Details page explains that failed or timed-out MFA validations can generate multiple MFA events. Microsoft Entra sign-in logs show those events as one line item, whereas Azure Monitor can show multiple line items sharing the same correlationId. This is a monitoring and interpretation clarification rather than evidence that the sign-in behavior changed on this date.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

27 updates

2
1

Secure Best Practices

Updated

The following are design considerations for all isolation configurations. Throughout this content, there are many links. We link to content, rather than duplicate it here, so you'll always have access to the most up-to-date information.

1

Sign In Log Activity Details

Updated

- **Multifactor authentication:** When a user signs in with MFA, several separate MFA events are actually taking place. For example, if a user enters the wrong validation code or doesn't respond in time, more MFA events are sent to reflect the latest status of the sign-in attempt. These sign-in events appear as one line item in the Microsoft Entra sign-in logs. That same sign-in event in Azure Monitor, however, appears as multiple line items. These events all have the same `correlationId`.

1
1

Agent Id Governance Overview

Updated

[Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) includes four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. These can be created in [Microsoft Foundry](/azure/ai-foundry/agents/concepts/agent-identity), [Microsoft Copilot Studio](/microsoft-copilot-studio/admin-use-entra-agent-identities), or other platforms. The agent identity, and optionally the agent user, allows AI agents to take on digital identities within Microsoft Entra. Once a digital identity is established, these agent identities are able to be governed using lifecycle and access features. Sponsors can be assigned to agent identities after creation. Sponsors of agent identities are human users accountable for making decisions about its lifecycle and access. For more information about the role of a sponsor of agent identities, see: [Administrative relationships for agent IDs](../agent-id/identity-platform/agent-owners-sponsors-managers.md).

6

Identity Risk Management Agent (Preview) settings

Updated

The Identity Risk Management Agent in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing user behavior and suggesting actions to mitigate potential identity risks. You can configure the settings to meet your organization's needs, such as how often it runs, and email notifications.

Identity Risk Management Agent

New

Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.

2

Risky User Report

Updated

Knowing which users are at risk and *why* they're at risk is a key responsibility of security and identity administrators. The Risky user report in Microsoft Entra ID Protection provides the full report, along with a risk data summary, and an activity timeline.

2
1

Review agent findings

Updated

The Identity Risk Management Agent (Preview) in Microsoft Entra ID Protection provides proactive risk management capabilities by analyzing the risky identities and suggesting actions to remediate them. By using a Large Language Model, the agent helps security administrators review and respond to risky activities before they lead to security incidents.

7

Identity Governance Applications Integrate

Updated

1. If the application was using AD security groups, and those groups were created in AD, then once the review is complete, you need to manually update the AD groups to remove memberships of those users who were denied. Subsequently, to have denied access rights removed automatically, you can either update the application to use an AD group that was created in Microsoft Entra ID and [written back to Microsoft Entra ID](~/identity/hybrid/cloud-sync/how-to-configure-entra-to-active-directory.md), or move the membership from the AD group to the Microsoft Entra group, and [nest the written back group as the only member of the AD group](~/identity/hybrid/cloud-sync/govern-on-premises-groups.md).

Govern an application's existing users - Microsoft PowerShell

Updated

There are four common scenarios in which it's necessary to populate Microsoft Entra ID with existing access rights and users of an application before you use the application with a Microsoft Entra ID Governance feature such as [access reviews](access-reviews-application-preparation.md).

Deploy Access Reviews

Updated

| [Self-review your access](../id-governance/privileged-identity-management/pim-perform-roles-and-resource-roles-review.md?toc=/azure/active-directory/governance/toc.json)| If you're assigned to an administrative role, approve or deny access to your role. |

Perform Access Review

Updated

The Access Review Agent assists you in completing your pending access reviews by guiding you in Microsoft Teams with natural language, insights, and recommendations.

Identity Governance Applications Not Provisioned Users

Updated

For more information on those first two scenarios, where the application supports provisioning, or uses an LDAP directory, SQL database, has a SOAP or REST API or relies upon Microsoft Entra ID as its identity provider, see the article [govern an application's existing users](identity-governance-applications-existing-users.md). That article covers how to use identity governance features for existing users of those categories of applications.

Create Access Review

Updated

- [Complete an access review of groups or applications](complete-access-review.md)

2

Identity Governance Overview

Updated

Organizations that previously had been using an on-premises identity governance product can [migrate their organizational role model](identity-governance-organizational-roles.md) to Microsoft Entra ID Governance.

1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…