Understand the difference between soft and hard deletions and how to recover or recreate objects in Microsoft Entra ID.
Agent ID permission-inheritance guidance and RC4 audit coverage are the notable updates in a documentation-focused day
On 7 May, all four supplied changes were Microsoft Learn documentation updates: two for Microsoft Entra Agent ID and two for Entra ID. The Agent ID entries clarify how blueprint permissions work, while the Entra ID entries provide targeted RC4 Kerberos auditing guidance and deletion-recovery reference material. There is no supplied evidence of a new preview, general-availability release, retirement, enforcement change, or Message Center announcement.
- Agent ID documentation explains configuration of inheritable blueprint permissions
Agent ID · Standards
The updated guidance describes how to configure inheritable permissions for agent identity blueprints so they can automatically grant OAuth 2.0 delegated permission scopes and application roles to agent identities. This is a configuration-documentation update, not evidence of a newly launched, preview, or generally available capability.
- Agent ID guidance separates inherited permissions from required resource access
Agent ID · Fundamentals
A companion fundamentals update clarifies the difference between required resource access declarations and inheritable permissions for agent identity blueprints. That distinction should help administrators review permission design and avoid treating the two mechanisms as interchangeable; the record does not indicate a behavior change or availability milestone.
- Entra ID security guidance focuses on RC4 Kerberos dependencies
Entra ID · Monitoring
The updated Security Audit Events documentation describes viewing Kerberos ticket-granting events (4768) and service-ticket events (4769) that used RC4 encryption during the last seven days. Administrators can use this guidance to identify workloads and service accounts that still rely on RC4. It is audit and security guidance, not evidence of an enforcement change.
- Deletion-recovery documentation clarifies soft and hard deletion paths
Entra ID · Architecture
The updated recovery guidance explains the difference between soft and hard deletions and how objects can be recovered or recreated in Microsoft Entra ID. This is ordinary operational documentation clarification; the supplied change does not announce a new recovery feature or altered deletion behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Entra ID
3 updatesWe have identified that you have activated early access to the Entra Group control for model-driven app in-app skills in Power Apps and/or Dynamics 365 Apps. On May 21, 2026, we will switch this feature to a new underlying service in preparation for general availability.
Security Audit Events
UpdatedView all Kerberos ticket-granting (event ID 4768) and service ticket (event ID 4769) events that used RC4 encryption in the last seven days, to identify workloads and service accounts that still rely on RC4:
Microsoft Entra Agent ID
2 updatesUnderstand the difference between required resource access declarations and inheritable permissions for agent identity blueprints in Microsoft Entra Agent ID.
Learn how to configure inheritable permissions for agent identity blueprints to automatically grant OAuth 2.0 delegated permission scopes and application roles to agent identities.
