Learn about the Identity Risk Management Agent and its role in identifying and mitigating risks within Microsoft Entra ID Protection.
Internet Access licensing and Global Secure Access endpoint coverage are the clearest admin signals in a Verified ID-heavy documentation refresh
The 11 February record contains 48 updates, with no new or removed entries and no message-center announcements. The most operationally specific items are updated Internet Access provisioning guidance and Global Secure Access security guidance. The remaining changes are mainly how-to and reference updates for Verified ID and Microsoft Entra ID Protection. Nothing supplied indicates a new feature, preview, general availability milestone, retirement, or changed service behavior.
- Internet Access: licensing prerequisites and routing consequences are documented
Internet Access · Provisioning
The updated provisioning guidance states that Microsoft Entra Internet Access and Microsoft Entra Private Access require Microsoft Entra ID P1. It also describes the operational consequences of missing licenses: administrators can't configure traffic-forwarding profiles, security policies, or remote network connections, and traffic from users without assigned licenses doesn't route through Global Secure Access. This is updated provisioning guidance, not evidence that the licensing model changed on this date.
- Global Secure Access: client coverage remains central to the security model
Global Secure Access · Security
The updated security guidance says managed endpoints without the Global Secure Access client operate outside the organization's Security Service Edge controls, leaving network-level policies unable to protect those devices. This is security guidance rather than evidence of a new client capability or deployment change. Deployment owners should use it when assessing coverage of managed endpoints.
- ID Protection: risk-policy administration guidance was refreshed
ID Protection · Security
The updated risk-policies article covers enabling and configuring Microsoft Entra ID Protection risk policies. Related ID Protection updates address risk detection types and levels, reports, remediation, feedback, simulation, data export, Graph PowerShell, and MFA registration. The supplied records identify documentation maintenance, not a change to risk-policy behavior or enforcement. Administrators can compare current policy and incident-response runbooks with the revised instructions.
- Verified ID: API, setup, and credential-lifecycle guidance received a broad refresh
Verified ID · Security
The updated Admin API article covers managing a verifiable-credential deployment. The same update set includes Request Service REST API, issuance and presentation, tenant setup, credential revocation, signing-key rotation, DID and domain configuration, and error-code guidance. The evidence supports a documentation refresh for existing issuer and verifier implementations, not a new API surface, preview, GA announcement, or confirmed contract change.
- Verified ID Face Check: billing and add-on enablement guidance was updated
Verified ID · General
The Face Check pricing article was updated to cover its billing model and enabling the add-on by linking an Azure subscription. No price, billing amount, or availability change is supplied, so administrators should treat this as documentation clarification and recheck the instructions if their tenant uses Face Check.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
48 updates
Microsoft Entra ID Protection
12 updatesQuery Microsoft Graph risk detections and associated information from Microsoft Entra ID
How and why should you provide feedback on ID Protection risk detections.
Enable and configure risk policies in Microsoft Entra ID Protection.
Learn how to simulate risk detections in Microsoft Entra ID Protection to enhance security. Test risk-based policies effectively.
Learn about risk detections and risk levels, including the difference between real-time and offline detections.
What are risk detections?
UpdatedExplore the full list of risk detections and their corresponding risk event types, along with a description of each risk event type.
Automation to detect, remediate, investigate, and analyze risk data with Microsoft Entra ID Protection
ID Protection Risk Reports
UpdatedLearn how to access, filter, and use the Microsoft Entra ID Protection risk reports to mark users and sign-ins as risky or confirmed compromised.
Learn how to configure the Microsoft Entra ID Protection multifactor authentication registration policy.
Learn about the many long-term data storage and monitoring options for exporting risk data from Microsoft Entra ID Protection.
Learn how to configure user self-remediation and manually remediate risky users in Microsoft Entra ID Protection.
Microsoft Entra Internet Access
1 updateuserimpact: Low
UpdatedGlobal Secure Access requires specific Microsoft Entra licenses to function, including Microsoft Entra Internet Access and Microsoft Entra Private Access, both of which require Microsoft Entra ID P1 as a prerequisite. Without valid licenses provisioned in the tenant, administrators can't configure traffic forwarding profiles, security policies, or remote network connections. If you don't assign licenses to users, their traffic doesn't route through Global Secure Access, and remains unprotected by security controls.
Microsoft Entra Verified ID
34 updatesAdmin Api
UpdatedLearn how to manage your verifiable credential deployment using Admin API.
In this article, you learn how to use a quickstart to create a custom verifiable credential for an ID token hint.
Learn how to use a quickstart to create custom credentials for ID tokens
Learn how to use a quickstart to create custom credentials for self-issued claims.
Learn how to use a quickstart to create custom credentials with multiple attestations.
Issuance Request Api
UpdatedLearn how to issue a verifiable credential.
Learn how to use a quickstart to create custom credentials for from other Verifiable Credential attestation.
Presentation Request Api
UpdatedLearn how to start a presentation request in Verifiable Credentials
Learn how to revoke an issued verifiable credential.
In this tutorial, you learn how to manually configure your tenant to support the Verified ID service.
In this tutorial, you learn how to configure your tenant to verify credentials.
In this tutorial, you learn how to issue verifiable credentials, from directory based claims, by using a sample app.
In this tutorial, you learn how to issue verifiable credentials by using a sample app.
In this tutorial, you learn how to quickly configure your tenant to support the Verified ID service.
In this article, you learn how to use the Microsoft Entra Verified ID Network to verify credentials.
Learn about Face Check with Microsoft Entra Verified ID billing model. Learn how to enable the Face Check add-on in your tenant by linking your Microsoft Azure subscription.
Learn how to enable support for did:web:path
Learn how to link your domain to your decentralized identifier (DID).
Learn how to opt out of Microsoft Entra Verified ID.
Learn to plan your end-to-end issuance solution.
Learn foundational information to plan and design your verification solution.
Register your website ID
UpdatedLearn how to register your website ID for did:web.
Rotate signing keys
UpdatedLearn how to rotate Microsoft Entra Verified ID signing keys.
Rules and Display Definition Reference
In this tutorial, you learn how to use Face Check with Microsoft Entra Verified ID.
Upgrade signing keys
UpdatedLearn how to upgrade Microsoft Entra Verified ID signing keys to become FIPS compliant.
Recent updates for Microsoft Entra Verified ID
Learn foundational information to plan and design your solution
A design pattern describing how to onboard new employees remotely
A design pattern describing how to verify in helpdesk scenarios
Learn how to issue and verify by using the Request Service REST API.
Vc Network Api
UpdatedLearn how to use the Microsoft Entra Verified ID Network API
In this tutorial, you learn how to install and use Microsoft Authenticator for VerifiedID.
Error Codes
UpdatedReference of error codes for Microsoft Entra Verified ID APIs
userimpact: Low
UpdatedComprehensive deployment of the Global Secure Access client is foundational to achieving Zero Trust network security. If you don't deploy the Global Secure Access client to managed endpoints, those devices operate outside the organization's Security Service Edge controls. Threat actors can exploit unprotected endpoints to establish initial access, move laterally, or exfiltrate data without triggering network-level security policies.
