Policy Autonomous Agents
Updated- Target all agent users or select specific agent users
Daily.Entra.NewsAll eight recorded items were Microsoft Learn updates, with no new or removed entries and no Message Center notices. The most substantive changes clarify Conditional Access signals for agents, autonomous-agent policy targeting, and the resource roles available in Agent Access Packages. An External ID passkey page also documents a user capability around viewing registered passkeys. The supplied evidence does not identify a launch, general-availability event, retirement, or tenant behavior change.
The updated guidance describes Conditional Access evaluating both users and agents through context, device, location, and session-risk signals, with possible outcomes including allowing, blocking, limiting, or requiring additional verification. This is a documentation update, not evidence of a new release or changed tenant behavior. Teams governing agent access should use the clarified model when reviewing existing policy design.
The Entra ID policy guidance explicitly identifies two targeting choices: all agent users or a selected set of agent users. This clarifies policy scope for implementation and audits, but the evidence does not indicate whether the behavior is new, in preview, or generally available.
The updated instructions say agent-identity access packages can include security group memberships, directory roles, or API permissions as resource roles. The API-permission path is marked as preview in the linked guidance, and the excerpt warns not to add application roles. Administrators designing agent entitlements should validate that assignments use the documented role types.
The Sign In With Passkey update includes the step that users can view their registered passkeys. The supplied record does not establish a new authentication flow, rollout status, or administrative configuration requirement, so this should be treated as a documentation clarification unless it differs from an existing implementation.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
- Target all agent users or select specific agent users
> [!WARNING]
Learn how Microsoft Entra smart lockout helps protect your organization from brute-force attacks that try to guess user passwords.

Conditional Access is an intelligent policy engine that helps organizations control how users and agents access corporate resources. It brings together real-time signals such as user's and agent's context, device, location, and session risk information to determine when to allow, block, or limit access, or require more verification steps.
1. Select **Next: Resource roles**. On the **Resource roles** tab, you select the resource roles to include in the access package. Access packages for agent identities can have security group memberships, directory roles, or API permissions as resource roles. For more information, see [add a group](/entra/id-governance/entitlement-management-access-package-resources#add-a-group-or-team-resource-role), [add a Microsoft Entra role](/entra/id-governance/entitlement-management-access-package-resources#add-a-microsoft-entra-role-assignment), and [add an API permission](/entra/id-governance/entitlement-management-access-package-resources#add-an-api-permission-preview). Don't add application roles, SAP roles, or SharePoint Online site roles to an access package for agent identities.
- View their registered passkeys.