```
Planned CSP enforcement is the main material change in a documentation-heavy day
On 4 December, the only substantive behavior change announced was a Microsoft Entra ID authentication-security update: browser-based sign-ins to login.microsoftonline.com will begin enforcing a Content Security Policy in mid-October 2026. The remaining 21 items are documentation updates, with useful clarifications for Agent ID inventory and Verified ID domain setup. The supplied evidence identifies no new feature, preview, general-availability release, or retirement.
- Microsoft Entra ID will block external script injection in browser-based sign-ins
External ID · Authentication
The Message Center notice describes a planned Content Security Policy on browser-based sign-ins to login.microsoftonline.com. Only trusted Microsoft scripts will be allowed, beginning in mid-October 2026. This is a planned authentication-security behavior change rather than evidence of a new preview or generally available feature. The notice explicitly excludes Microsoft Entra External ID tenants; administrators whose sign-in flows rely on external scripts should review compatibility before rollout.
- Agent ID documentation distinguishes registry-only agents from Entra agent identities
Agent ID · Security
The updated guidance explains that some agents can exist in the agent registry without an associated Microsoft Entra agent identity or service principal. These registry-only agents may be onboarding or may not use Microsoft Entra Agent ID as their identity provider. This is an operational and security-inventory clarification, not evidence of a new capability or availability change.
- Verified ID guidance makes the DID domain requirement explicit
Verified ID · Fundamentals
The updated Dnsbind documentation states that the domain used to verify ownership to a DID must be under the administrator’s control and should use a format such as https://www.contoso.com/. This is configuration guidance clarification for Verified ID, not evidence of a feature launch or changed availability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
21 updates
Microsoft Entra ID
2 updatesCloud Sync Version History
UpdatedGet notified about when to revisit this page for updates by copying and pasting this URL: `https://aka.ms/cloudsyncrss` into your  feed reader.
Microsoft Entra Agent ID
1 updateAs an admin, you want to have a 360-degree view of your agents for both security and operational efficiency. Some agents will be represented in Microsoft Entra with an agent identity blueprint principal and agent identities, or as a service principal. It isn't uncommon to also have agents that are registered in the agent registry but don't have an associated Microsoft Entra agent identity. These agents are referred to as registry-only agents. They might be in the process of being onboarded or they may have registered in the registry without needing to use Microsoft Entra Agent ID as the agent's identity provider.
Microsoft Entra ID Governance
11 updatesApps
Updated<a name='entra-identity-governance-integrations'></a>
This article provides best practices for securing deploying Microsoft Entra ID Governance.
Deploy Sap Netweaver
UpdatedThis article describes how to set up a lab environment with SAP ECC for testing.
Describes how to use Entitlement Management with Private Access
This document describes how to provision users into SAP ERP Central Component (SAP ECC, formerly SAP R/3) with NetWeaver AS ABAP 7.0 or later.
This document describes how you can govern on-premises uses by provisioning them into SQL based applications using the ECMA Connector host
This document describes how to configure Microsoft Entra ID to provision users into an on-premises LDAP directory.
This article describes use cases Microsoft Entra ID Governance.
Sap Template
Updateddocumentationcenter: ''
author: owinfreyATL
Describes overview of identity lifecycle management for Microsoft Entra ID Governance.
Microsoft Entra External ID
2 updatesNew and updated documentation for the Microsoft Entra External ID.
> [!NOTE]
Microsoft Entra Verified ID
3 updatesServices Partners
Updatedauthor: barclayn
Idv Partners
Updatedauthor: barclayn
Dnsbind
UpdatedThe domain you verify ownership of to your DID is defined in the [overview section](verifiable-credentials-configure-tenant.md#set-up-verified-id). The domain needs to be a domain under your control and it should be in the format `https://www.contoso.com/`.
Microsoft Entra Global Secure Access
2 updatesNetwork Content Filtering
Updated1. On the **Review** tab, review your settings.
This article tracks the changes in each released version of the Global Secure Access client for Windows.
