By January 7, 2026, Microsoft Entra will switch from DigiCert Global Root G1 to G2 certificates. Organizations must trust the DigiCert G2 root CA to avoid authentication failures with Entra services. Remove any pinning to G1 and update trust settings to prevent service disruption.
Agent ID’s governance model and Manage Agents preview were the substantive updates on 12 December
This was a quiet, documentation-only period: all four entries were updates, with no new or removed items and no Message Center notices. The meaningful changes were two Microsoft Entra Agent ID pages. The Workload ID and ID Governance entries appear narrow or procedural from the supplied summaries, so no broader feature, availability, or behavior change is evidenced.
- Agent ID governance is described through four agent-specific object types
Agent ID · Authentication
The updated governance overview explains that Microsoft Entra Agent ID supports identities for agents themselves, rather than relying only on identities belonging to the tools agents use. It identifies four object types: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. This is a governance and identity-model clarification in the supplied evidence, not proof of a launch on this date.
- Manage Agents preview documents owner- and sponsor-based controls
Agent ID · General
The updated preview documentation describes a Manage Agents experience for viewing and controlling agent identities that a user owns or sponsors. It includes reviewing agent details, enabling or disabling agents, and requesting access. The evidence confirms the Preview designation but does not state rollout scope or broader availability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Entra ID
2 updatesExternal Authentication Methods (EAM) Public Preview will enforce registration starting December 8, 2025. Existing users are pre-registered; new users after December 2, 2025, must complete in-line setup. Admins can register users. Organizations should prepare by communicating changes and reviewing configurations.
Microsoft Entra Agent ID
2 updatesAgent Id Governance Overview
UpdatedHistorically, AI agents would rely upon tools to interact with various applications and systems, and each of those tools would have their own identities in those applications and systems. Some of those tools would use service principals to authenticate to Microsoft services via Microsoft Graph or Microsoft Azure APIs. [Microsoft Entra Agent ID](../agent-id/identity-platform/what-is-agent-id.md) introduces support for identities for the agents themselves, with four new types of object: agent identity blueprint, agent identity blueprint principal, agent identity, and agent user. Through the [agent identity blueprint](../agent-id/identity-platform/agent-blueprint.md), the agent can create one or more agent identities, and optionally an agent user for each agent identity. Each agent identity and agent user can have distinct access rights.
The Manage Agents feature in Microsoft Entra lets you view, and control, [agent identities you own or sponsor](agent-owners-sponsors-managers.md). [Agents identities](what-is-agent-id.md) are special identities, such as bots or automated processes, that act on behalf of users or teams. With the manage agents feature, you can easily see which agents you’re responsible for, review their details, and take action to enable, disable, or request access for them.
Microsoft Entra ID Governance
1 updateReview Your Access
UpdatedThe first step to perform an access review is to find and open the access review.
Microsoft Entra Workload ID
1 updateManaged Identities Status
Updated| Azure Event Grid | [Event delivery with a managed identity](/azure/event-grid/managed-service-identity)|
