← Previous day

Next day →
Day in brief

Global Secure Access timing and Agent ID governance guidance lead a documentation-heavy 18 February

The most actionable clarification is in Global Secure Access: web content filtering changes made in the Global Secure Access experience typically take effect in less than five minutes, while related Conditional Access changes take approximately one hour. Other meaningful updates cover Agent ID administrative relationships, the Entra ID control for blocking new app password credentials, and Access Reviews API behavior when notifications are disabled. All 29 tracked entries are marked Updated, with no new or removed items and no Message Center entries. The supplied record therefore supports documentation clarification, security guidance, and governance/API guidance—not a confirmed feature launch, preview, GA release, or retirement.

  • Classification: ordinary operational documentation clarification. The updated page distinguishes changes made in the Global Secure Access experience, which typically take effect in less than five minutes, from Conditional Access changes related to web content filtering, which take approximately one hour. The evidence clarifies expected timing but does not say that the timings themselves changed.

  • Classification: governance guidance. The updated administrative-relationships page describes a model separating technical administration from business accountability and applies it to agent identities, agent identity blueprints, and agent identity blueprint principals. This gives administrators a more specific framework for reviewing Agent ID accountability; it is not presented as a new availability milestone.

  • Classification: security and configuration guidance. The update directs administrators to select Restricted Mode and locate the setting "Block addition of new password credentials to apps." It clarifies the control's location and name, but the supplied evidence does not establish that the control is newly introduced or that tenant settings changed.

  • Classification: API behavior documentation clarification. The FAQ states that the contactedReviewers API returns users who were, or would have been, notified to perform a review, even when notifications were disabled, and includes timestamps indicating when notification would occur. Audit and automation workflows can use this behavior when reconciling reviewer populations and notification schedules; the entry does not claim a new API release.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

30 updates

3

Identifier Uri Restrictions

Updated

There are three possible ways that you can add an identifier URI to your app. We recommend them in the following order:

2
2

Howto Add App Roles In Apps

Updated

After adding app roles in your application, you can assign an app role to a client app by using the Microsoft Entra admin center or programmatically by using [Microsoft Graph](/graph/api/serviceprincipal-post-approleassignments?tabs=http). Assigning an app role to an application shouldn't be confused with [assigning roles to users](../identity/role-based-access-control/manage-roles-portal.md).

Prepare User Source Of Authority Environment

Updated

If you’re planning to only change the SOA for some Active Directory users, and all your users are currently in a single OU using Kerberos applications that don’t use LDAP, we recommend that you create a new AD DS OU for these objects. Having them in a separate OU will enable you to avoid inadvertently making updates to them in Active Directory after the SOA change. Users, whose SOA isn’t changing, can continue to be managed using Active Directory Users and Computers, Active Directory Module for PowerShell, or other Active Directory management tools. After creating an OU, move the objects to that OU. For more information, see: [Move-ADObject](/powershell/module/activedirectory/move-adobject?view=windowsserver2025-ps&preserve-view=true).

1
1

Block Password Addition

Updated

1. Select Restricted Mode, find the **Block addition of new password credentials to apps** setting.

1
1
1
1
1

Agent Access Packages

Updated

Agents can then be assigned access packages through three different request pathways.

1

Administrative relationships in Microsoft Entra Agent ID (Owners, sponsors, and managers)

Updated

The Microsoft agent identity platform introduces an administrative model that separates technical administration from business accountability, ensuring operational control and compliance oversight without excessive permissions. This document explains the administrative relationships for Microsoft Entra Agent ID identity types. This guidance applies to [agent identities](/graph/api/resources/agentidentity?view=graph-rest-beta&preserve-view=true), [agent identity blueprints](/graph/api/resources/agentidentityblueprint?view=graph-rest-beta&preserve-view=true), [agent identity blueprint principals](/graph/api/resources/agentidentityblueprintprincipal?view=graph-rest-beta&preserve-view=true), and [agent users](/graph/api/resources/agentuser?view=graph-rest-beta&preserve-view=true). The article covers owners, sponsors, and managers and their importance in maintaining secure operations.

7

Entitlement Management Dynamic Approval

Updated

:::image type="content" source="media/entitlement-management-dynamic-approval/native-support-diagram.png" alt-text="Screenshot of native support of approvers in Entitlement management." lightbox="media/entitlement-management-dynamic-approval/native-support-diagram.png":::

Entitlement Management Roles

Updated

First, call [Create accessPackageResourceRequest](/graph/api/entitlementmanagement-post-resourcerequests?tabs=http) to add the Microsoft Entra role as a resource to the catalog.

Access Reviews Faqs

Updated

Once an access review starts, you can use the [contactedReviewers](/graph/api/resources/accessreviewreviewer) API to retrieve the list of all users who were, or would have been, notified via email to perform reviews. Even in scenarios where notifications were turned off, the API still provides the list of reviewers along with timestamps indicating when notification would happen.

Entitlement Management Access Package Resources

Updated

:::image type="content" source="media/entitlement-management-access-package-create/api-permissions-roles.png" alt-text="Screenshot of adding API permissions as resource roles to an access package.":::

1

Entitlement Management Scenarios

Updated

You can also manage access packages, catalogs, policies, requests, and assignments using Microsoft Graph. A user in an appropriate role with an application that has the delegated `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` permission can call the [entitlement management API](/graph/api/resources/entitlementmanagement-overview). For more information, see the [Tutorial: manage access to resources - Microsoft Graph](/graph/tutorial-access-package-api?toc=/azure/active-directory/governance/toc.json&bc=/azure/active-directory/governance/breadcrumb/toc.json). An application with the `EntitlementManagement.Read.All` or `EntitlementManagement.ReadWrite.All` application permissions can also use many of those API functions, except for managing resources in catalogs and access packages. An application that only needs to operate within specific catalogs can be added to the **Catalog owner** or **Catalog reader** roles of a catalog to be authorized to update or read within that catalog.

1

10 Secure Local Guest

Updated

Learn more: [Invite internal users to B2B collaboration](~/external-id/invite-internal-users.md)

1

Managed Identities Status

Updated

| Azure Container Apps | [Managed identities in Azure Container Apps](/azure/container-apps/managed-identity) |

2
1

Configure Web Content Filtering

Updated

> Configuration changes in the Global Secure Access experience related to web content filtering typically take effect in less than 5 minutes. Configuration changes in Conditional Access related to web content filtering take effect in approximately one hour.

1
1
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…