← Previous day

Next day →
Day in brief

12 June 2026: New PIM preview guidance, with sharper Entra coverage for agent controls and reauthentication

The period was dominated by targeted Microsoft Learn updates rather than announced service launches. The only new item documents a Preview approach for adding custom business logic to Microsoft Entra Privileged Identity Management role activation. Other notable updates clarify Conditional Access for agent identities, organization-specific recommendations from the Conditional Access Optimization Agent, post-revocation behavior in Identity Protection, and stronger-sign-in registration campaigns. The supplied evidence contains no general-availability announcement, retirement, or Message Center notice.

  • A new ID Governance article explains how to configure custom extensions in Microsoft Entra Privileged Identity Management so custom business logic can be integrated into role-activation workflows. It is explicitly marked Preview; the record does not establish general availability or a service launch.

  • Updated Agent ID guidance describes using Conditional Access policies for agent identities, including targeting the appropriate agents, evaluating signals, and enforcing controls as organizations deploy more agents. This is expanded documentation coverage, not evidence of a newly announced availability status.

  • The updated knowledge-base article explains that knowledge bases help the Conditional Access Optimization Agent produce policy recommendations tailored to an organization’s unique standards. Administrators assessing this workflow should review the related standards and knowledge-base guidance rather than treat the update as a standalone product launch.

  • The updated Identity Protection Policies guidance states that Require authentication strength and Sign-in frequency – Every time are automatically applied so that, after session revocation, users are immediately prompted to reauthenticate with the specified authentication strength. The evidence supports a documentation clarification of expected behavior, so administrators should check their policy and user-experience expectations.

  • Updated Entra ID guidance explains how to run a registration campaign that nudges users toward passkeys or Microsoft Authenticator for stronger sign-in security. It is rollout and security guidance, not evidence that a new campaign capability launched during this period.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

26 updates

8
4

What If Tool

Updated

The [What If Evaluation API](/graph/api/conditionalaccessroot-evaluate) is a Microsoft Graph API that is called by the Conditional Access experience. The API is different from the legacy What If evaluation in a few ways:

Conditional Access Agent Optimization Settings

Updated

The agent settings described in this article cover standard options like triggers, notifications, and scope. But the settings also include advanced options like custom instructions, Intune integrations, and permissions.

3

Assign App Owners

Updated

"@odata.id" = "https://graph.microsoft.com/v1.0/directoryObjects/aaaaaaaa-0000-1111-2222-bbbbbbbbbbbb"

1

Howto Update Permissions

Updated

1. Identify the permissions your app requires, their permission IDs, and whether they're app roles (application permissions) or delegated permissions. For example, if you want to request Microsoft Graph permissions, see [Microsoft Graph permissions](/graph/permissions-reference#permission-scenarios) for a list of permissions and their IDs.

1
1

Breaking Changes

Updated

`https://login.microsoftonline.com/contoso.com/oauth2/authorize?resource=https://gateway.contoso.com/api&response_type=token&client_id=00001111-aaaa-2222-bbbb-3333cccc4444&...`

2

Agent Id

Updated

- High-level overview of Conditional Access: [What is Conditional Access?](overview.md)

Target agent identities in Conditional Access policies

Updated

Conditional Access policies for agent identities let you control how AI agents access corporate resources. As your organization deploys more agents, you need policies that target the right agents, evaluate the right signals, and enforce the right controls. To learn more about how Conditional Access policies for agents work for different scenarios, see [Conditional Access policies for agents](agent-id.md).

1

Identity Protection Policies

Updated

- **Require authentication strength** and **Sign-in frequency - Every time** are automatically applied to the policy to ensure that after session revocation, end users are immediately prompted to reauthenticate with the specified authentication strength.

1
1

Add OIDC for customer sign-in

Updated

Learn how to set up OpenID Connect as an external identity provider in Microsoft Entra External ID, enabling users to sign in using their existing accounts.

1
1

Set up claims mapping for OIDC

Updated

Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.

1

Idv Partners

Updated

| 1Kosmos | [1Kosmos offer](https://aka.ms/1kosmos) | [VerifiedIdentity](https://verifiedid.did.msidentity.com/v1.0/tenants/8108e610-606c-4dc3-ae95-d3ad8be3b24c/verifiableCredentials/contracts/1197e066-a9a2-2dc5-f245-4c31d1f4b456/manifest) | 1Kosmos and Microsoft Entra Verified ID unite to deliver trusted, privacy-preserving identity verification that empowers secure, passwordless access across ecosystems. |

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…