Cross-product topic

Governance

A cross-product view of Microsoft Entra changes related to Governance.

Latest Governance changes

Create Tenant

Governance

The article now states that a governance relationship and related resources are established only when the home tenant has a default governance policy template.

Create Tenant

Governance

The documentation now states that the Tenant Creator role is required regardless of the “Restrict non-admin users from creating tenants” setting.

Create Lifecycle Workflow

Governance

The page removes the standalone setup section and detailed steps for configuring relative time-based triggers, including timing options, offsets, supported attributes, and enablement notes.

Create Lifecycle Workflow

Governance

Administrators can configure triggers using operators, offsets from 0 to 180 days, before or after event timing, and supported user attributes such as hire date, leave date, and creation date. Both the workflow and its schedule must be enabled for evaluation.

Entitlement Management Request Behalf

Governance

The documentation adds examples describing how designated users can request access packages for others and clarifies that both requestors and targets need the required license.

Lifecycle Workflow Execution Conditions

Governance

Documentation describes relative comparisons using Exactly, Between, or Less than or equal to, with event offsets from 0 to 180 days before or after supported user-attribute dates. The admin center temporarily shows two choices for the same time-based trigger.

Understanding Lifecycle Workflows

Governance

The documentation now explains that relative time-based comparisons expand the standard time-based attribute trigger. During preview, the admin center shows two choices, but both represent the same trigger.

Automatic formation of governance relationships

Governance

The documentation now specifies selecting an existing Microsoft Customer Agreement (MCA) subscription and resource group from the billing account when creating a tenant with the secure add-on tenant creation feature.

Automatic formation of governance relationships

Governance

The documentation now specifies that secure add-on tenant creation requires an existing paid Azure subscription and resource group, with the subscription associated with an Enterprise Agreement.

Automatic Governance Relationships

Governance

The secure add-on tenant creation documentation now refers to selecting an existing subscription, rather than specifically an existing Microsoft Customer Agreement subscription, from the billing account.

Create a governed workforce tenant

Governance

The documentation now specifies paid-account, billing, tenant-creation permission, role, and default governance-policy requirements for creating governed workforce tenants. Free or trial tenants cannot create additional tenants, and EA or pay-as-you-go billing accounts are supported.

Create Lifecycle Workflow

Governance

The documentation now describes creating a lifecycle workflow by cloning an existing workflow in the Microsoft Entra admin center, including review and customization steps.

Create Tenant

Governance

The tenant creation guidance now links references to the Microsoft Entra ID Free billing asset to the relevant billing documentation instead of the previous signals-and-metrics page.

Create Tenant

Governance

The documentation now says the home tenant—not the governing tenant—must have the default governance policy template for this optional prerequisite. The service uses the template with ID `default`.

Create Tenant

Governance

The documentation now labels the governing tenant’s default governance policy template as optional instead of a required prerequisite. The tenant creation service still uses only the default template (ID: `default`).

Create Tenant

Governance

The documentation now explicitly states that the required Enterprise Agreement or Pay-As-You-Go subscription must be paid.

Create Tenant

Governance

The prerequisite now specifies that the home tenant must have at least one paid, license-based Microsoft product. Free and trial licenses do not qualify.

Create Tenant

Governance

The document’s `ms.author` metadata changed from `tafra00` to `tazkiaafra`.

Create Tenant

Governance

The guide now links the Microsoft Online Subscription Agreement (MOSA) in its billing-account prerequisites. The Enterprise Agreement and Pay-As-You-Go references remain.

Create Tenant

Governance

The prerequisite now refers to Enterprise Agreement or Pay-As-You-Go subscriptions and identifies MOSA and MCA subscriptions, replacing billing-account wording.

Create Tenant

Governance

The tenant creation guide now explicitly states that the required subscription permissions are Azure Resource Manager (ARM) permissions, provided through the Tenant Contributor or Subscription Owner/Creator role.

Deploy Microsoft Entra Tenant Governance end to end

Governance

The deployment guide now documents a paid Azure subscription linked to an Enterprise Agreement or pay-as-you-go billing account, with Tenant Contributor or Subscription Owner/Creator access for the selected subscription.

Lifecycle Workflow Templates

Governance

The mover workflow templates now list the “Remove all access package assignments for user” task, with removal scheduled by default for 15 days.

Lifecycle Workflows Deployment

Governance

The task is now listed for both Leaver and Mover templates. The documentation also states that setting daysUntilExpiration schedules removal instead of removing assignments immediately.

Lifecycle Workflows Tasks Table

Governance

The lifecycle workflows task table now lists “Remove all access package assignments for user” for both Leaver and Mover workflow templates.

Entitlement Management Access Package Assignments

Governance

The access package assignments page no longer includes a note stating that assignment managers cannot bypass required approval settings or directly assign identities without approval.

Entitlement Management Access Package Request Policy

Governance

The documentation now expands its guidance that administrators must verify users meet existing access package policy requirements before assigning them; otherwise, assignment may fail.

Entitlement Management Access Package Request Policy

Governance

The documentation removes an inaccurate statement implying that direct assignment to an access package requires approval. It now states only that assigned users must meet the policy’s eligibility requirements.

Entitlement Management Delegate

Governance

The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.

Catalog Access Reviews

Governance

The documentation no longer labels Catalog Access Reviews or custom data provided resources as preview. It also generalizes reviewers beyond managers and adds a note that changes within 12 hours before a review starts may not appear.

Catalog Access Reviews

Governance

The page no longer labels Catalog Access Reviews or Custom Data Provided Resource as preview. It updates wording from managers to reviewers, removes the statement that managers are primary reviewers, adds a 12-hour data-change limitation before review start, and updates links.

Licensing Governance

Governance

The governance licensing documentation now includes “PIM - Custom extensions for role activation (Preview)” with licensing indicators.

Discover identities in target applications with account discovery

Governance

The article was revised to use lowercase “account discovery,” clarify connector and limitation wording, update the GitHub reference, and change its date from May 26, 2026, to August 11, 2026. It continues to describe the existing discovery process and requirements.

Automatic Governance Relationships

Governance

When you create a new Microsoft Entra tenant using the secure add-on tenant creation feature, you're prompted to select an existing subscription and resource group from your billing account. When you create your new tenant, Microsoft generates a new billing asset called **Entra ID Free** under that subscription and resource group, which links to the newly created tenant.

Create a configuration monitor

Governance

Learn how to create a configuration monitor in Microsoft Entra Tenant Governance to evaluate a tenant against a configuration baseline and report drift

Create a governed workforce tenant

Governance

Learn how to securely create a governed Microsoft Entra workforce tenant and establish governance from your home tenant.

Create configuration snapshots

Governance

Learn how to create configuration snapshots in Microsoft Entra Tenant Governance to capture tenant configuration for baselines or audit evidence

Cross-tenant delegated administration

Governance

Learn about cross-tenant delegated administration and the GDAP-based permission model for managing tenants in Microsoft Entra.

Customize Workflow Email

Governance

In the message body, you can customize the email text to personalize it for each recipient. You can optionally include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes by embedding them in the text. Before the email is sent, the placeholders are replaced with the actual user information.

Governance Policy Templates

Governance

- Manage the governed tenant without needing a local or business-to-business (B2B) account in that tenant.

Interpret tenant discovery data

Governance

Learn how to interpret tenant discovery data, signals, and metrics in Microsoft Entra Tenant Governance to assess related tenants

Lifecycle Workflow Tasks

Governance

With customized emails, you're able to include dynamic attributes within the subject and body to personalize these emails. You can include built-in user attributes, custom security attributes, directory extensions, and on-premises extension attributes. The list of dynamic attributes that can be included are as follows:

Prerequisites

Governance

- Microsoft Entra Cloud Sync agent must be installed on a domain-joined server. We recommend using Windows Server 2025 or Windows Server 2022. You can also deploy Microsoft Entra Cloud Sync on older Windows Server versions that are in extended support; however, support for this configuration may require [a paid support program](/lifecycle/policies/fixed#extended-support).

Related tenants in Tenant Governance

Governance

Learn how Microsoft Entra Tenant Governance discovers related tenants through identity, application, and billing signals across your organization

Lifecycle Workflow Inactive Users

Governance

1. Under the **Days of inactivity**, enter the number of days you want the trigger to run for if exceeded, and then select **Next**.

Lifecycle Workflow Templates

Governance

The **Pre-Offboard inactive users** template is designed to configure tasks that must be completed before offboarding inactive users.

Governance Policy Templates

Governance

Learn about governance policy templates and how to use them to enforce consistent governance across tenants in Microsoft Entra

Groups Lifecycle

Governance

For more information on Microsoft Entra groups, see:

Entitlement Management Access Package Assignments

Governance

In entitlement management, you can see who is assigned to access packages, their policy, status, and identity lifecycle (preview). If an access package has an appropriate policy, you can also directly assign identities to an access package. This article describes how to view, add, and remove assignments for access packages.

Entitlement Management Access Package Manage Lifecycle

Governance

Guest users that already existed in your tenant by being invited are ungoverned. After an ungoverned guest that requests access packages lose their last access package assignment, they'll remain in the tenant indefinitely. If there are guests that have an access package assignment, and only need access from that access package, and there's no other need for them to remain in the tenant, you can convert them to be governed during the time they have that access package assignment. You can directly convert those ungoverned users to be governed by using the **Mark Guests as Governed** functionality in the top menu bar of an access package.

Entitlement Management Delegate

Governance

To determine the least privileged role for a task, you can also reference [Least privileged roles by task in Microsoft Entra ID](../identity/role-based-access-control/delegate-by-task.md#entitlement-management-least-privileged-roles).

Migrate Copilot Studio Agents To Agent Id

Governance

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.

Account Discovery

Governance

Learn how to use Account Discovery to find and categorize existing user accounts in target applications, match them to Microsoft Entra ID users, and prepare for provisioning governance.

Agent Access Packages

Governance

This article explains how access packages provide governance for agent identity access to resources.

Groups Sensitivity Labels

Governance

Learn how to apply sensitivity labels to cloud security groups in Microsoft Entra ID for consistent classification and governance.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including non-Microsoft integrations, migration guides, and enterprise governance.

Licensing Governance

Governance

|[EM - Agents and service principals assigned to access packages](~/id-governance/entitlement-management-access-package-create.md#allow-users-service-principals-and-agent-identities-in-your-directory-to-request-the-access-package)|||||| :white_check_mark: |

userimpact: Low

Governance

Microsoft Entra Agent ID requires every [agent identity](/entra/agent-id/agent-identities) and [agent identity blueprint](/entra/agent-id/agent-blueprint) to have at least one sponsor. A sponsor is a human user, or supported group, that holds business accountability for the agent's lifecycle, such as deciding when the agent is no longer needed, approving extensions when access expires, and authorizing suspension during incidents. A sponsor is different from an owner, which designates the human users responsible for technical operations and incident response.

userimpact: Medium

Governance

Microsoft Entra Agent ID introduced two identity types: [agent identities](/entra/agent-id/agent-identities) and [agent identity blueprint principals](/entra/agent-id/agent-blueprint). These identity objects derive from service principals, and so carry the same requirements and best practices for ownership, lifecycle management, and cleanup as any service principal. Blueprint principals are the provisioning surface from which agent identities are created and can hold grants that propagate to child agents. Having a designated owner for these objects helps in two important areas of agent identity management:

Agent Access Packages

Governance

1. Select **Next: Resource roles**. On the **Resource roles** tab, you select the resource roles to include in the access package. Access packages for agent identities can have security group memberships, directory roles, or API permissions as resource roles. For more information, see [add a group](/entra/id-governance/entitlement-management-access-package-resources#add-a-group-or-team-resource-role), [add a Microsoft Entra role](/entra/id-governance/entitlement-management-access-package-resources#add-a-microsoft-entra-role-assignment), and [add an API permission](/entra/id-governance/entitlement-management-access-package-resources#add-an-api-permission-preview). Don't add application roles, SAP roles, or SharePoint Online site roles to an access package for agent identities.

Migrate Copilot Studio agents to Agent ID

Governance

Learn how to recreate Microsoft Copilot Studio agents with Microsoft Entra Agent ID for enhanced governance and security. No in-place migration path exists today.

Migrate From Sap Idm

Governance

In SAP IDM, the Identity Store represents identity data through entry types such as `MX_PERSON`, `MX_ROLE`, or `MX_PRIVILEGE`.

Lifecycle Workflow Tasks

Governance

Lifecycle Workflows allow you to automate the updating of user attributes for users in your organization. You're able to customize the task name and description for this task in the Microsoft Entra admin center.

What's new in Microsoft Entra Agent ID

Governance

Learn about new features and updates in Microsoft Entra Agent ID at general availability, including third-party integrations, migration guides, and enterprise governance.

Create a monitor (preview)

Governance

Learn how to create and configure a tenant configuration monitor in Microsoft Entra Tenant Governance to track configuration drift

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…