- **Risky sign-ins**: The agent suggests a policy to require multifactor authentication for high risk sign-ins. Requires Microsoft Entra ID P2 license.
14 May: Conditional Access documentation details P2-required high-risk MFA guidance; Private Access documents connector-capacity thresholds
This was a documentation-only period: all six supplied entries were Microsoft Learn updates, with no new or removed items and no Message Center notices. The most consequential updates clarify Conditional Access agent guidance for risky sign-ins and policy coverage, Private Access connector-capacity response, Entra schema-extension limits, and the licensing prerequisite for ID Governance Account Discovery. The evidence does not identify a preview, general-availability release, retirement, or tenant-wide configuration change. The separate Agent ID update is setup guidance for users with the GitHub Copilot for Azure extension, not evidence of a launch.
- Conditional Access agent guidance now documents high-risk sign-in MFA suggestions
Entra ID · Conditional Access
Security guidance clarification: the updated page says the agent suggests a policy requiring multifactor authentication for high-risk sign-ins and states that Microsoft Entra ID P2 is required for this scenario. This describes agent guidance, not evidence that a policy was automatically created or deployed; administrators evaluating the suggestion should confirm the licensing dependency and validate the policy before rollout.
- Deep analysis guidance covers policy gaps, overlap, and exclusions
Entra ID · Conditional Access
Conditional Access analysis guidance clarification: deep analysis is documented as reviewing policies that block legacy authentication or device control flow and those requiring device or MFA controls. It evaluates user, group, and role coverage for gaps, redundant or overlapping policies, and consolidation opportunities, while also flagging broad exclusions and recommending explicit break-glass exclusions to reduce accidental-lockout risk. The update does not report changes to existing tenant policies.
- Private Access runbook specifies connector high-resource thresholds
Private Access · Monitoring
Operational guidance: the updated Operate Private Access page documents a connector-host alert condition of CPU above 80% or memory above 85% sustained for more than 15 minutes. The associated response is to check active sessions, redistribute load by adding another connector to the group, and investigate applications generating unusual traffic; Azure Monitor alerting is identified as the monitoring path.
- Entra schema-extension limits are spelled out
Entra ID · Developer
Service-limit clarification: string extensions are limited to 256 characters and binary extensions to 256 bytes; no more than 100 extension values across all types and applications can be written to one resource. The page also limits string or binary single-valued attributes to User, Group, TenantDetail, Device, Application, and ServicePrincipal entities, and states that DateTime extensions support only the equals operator, not range operators.
- Account Discovery licensing prerequisite is clarified
ID Governance · Fundamentals
Licensing clarification: the updated ID Governance guidance states that Account Discovery requires either the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. The feature is described as finding existing accounts in target applications and identifying matching Entra accounts or orphan accounts, so teams planning that use should verify entitlement before proceeding.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Entra ID
3 updatesDeep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.
Entra Service Limits Include
Updated| Schema extensions |<ul><li>String-type extensions can have a maximum of 256 characters. </li><li>Binary-type extensions are limited to 256 bytes.</li><li>Only 100 extension values, across *all* types and *all* applications, can be written to any single Microsoft Entra resource.</li><li>Only User, Group, TenantDetail, Device, Application, and ServicePrincipal entities can be extended with string-type or binary-type single-valued attributes.</li><li> Only the "equals" operator is supported for DateTime-type extensions. Range operators like "greater than" or "less than" are not supported.</li></ul> |
Microsoft Entra Agent ID
1 updateAgent Id Ai Guided Setup
UpdatedIf you have the GitHub Copilot for Azure extension installed, ask Copilot to set up Agent ID. For example:
Microsoft Entra ID Governance
1 updateLicensing Fundamentals
UpdatedAccount Discovery requires the Microsoft Entra ID Governance add-on or Microsoft Entra Suite. This feature allows administrators to discover existing user accounts in target applications and identify which users have matching Entra accounts or are orphan accounts. For more information, see [Discover identities in target applications with Account Discovery](../identity/app-provisioning/how-to-account-discovery.md).
Microsoft Entra Private Access
1 updateOperate Private Access
Updated| Connector high resource usage | CPU > 80% or memory > 85% sustained for 15+ minutes on a connector host | Network Ops L1 | Azure Monitor alert ([Playbook 5](#playbook-5-connector-group-capacity-alert)) | 1. Check the number of active sessions on the connector.<br>2. Redistribute load by adding another connector to the group.<br>3. Investigate if a specific application is generating unusual traffic volume. |
