Permission update for the AI Administrator role in Entra ID
Microsoft added a new privileged permission to the AI Administrator role in Entra ID. Users with the role can now grant admin consent to delegated permissions for applications and agents.
Microsoft added a new privileged permission to the AI Administrator role in Entra ID. Users with the role can now grant admin consent to delegated permissions for applications and agents.
Learn how to restrict the new Copilot desktop app to allowed organizations using Entra ID tenant restrictions, blocking personal Microsoft accounts and unauthorized tenants on managed Windows clients.
Microsoft recently recommended migrating GitHub Actions federated credentials to an immutable subject format in Microsoft Entra app registrations. This closes a subtle security gap where recycled repo or org names could let someone else’s token match your trust configuration. In this post, I walk through what the migration actually involves. I also tested the newer Flexible Federated Identity Credentials (FFIC), currently in preview.
The Microsoft 365 Admin Agent is now generally available as a Microsoft-managed agent, giving all administrators with an Entra built-in role AI-powered access across the admin center and Copilot Chat. If you don’t need this agent, block it.
Microsoft has introduced a new admin role: Entra SOC Identity Responder. The role lets SOC analysts disable accounts, revoke sessions, and reset passwords for rapid incident containment without broader Entra admin access.
Microsoft is preparing a new Entra admin role. The Entra Customer Lockbox Approver role provides a least privileged option for approving Customer Lockbox requests in Azure.
Passkeys (FIDO2) are being added as a supported targeted authentication method in Microsoft Entra registration campaigns. In addition, tenants in the Microsoft-managed state that meet specific criteria will see additional configuration changes.
Microsoft has started assigning the new Purview workload admin roles in Microsoft Entra, triggering PIM assignment notifications for administrators.
Microsoft is updating the Microsoft-managed default user consent policy for Microsoft Graph as part of the Secure Future Initiative, requiring admin consent for an expanded set of delegated permissions accessing Exchange data.
A new AI Reader role in Microsoft Entra provides broad read-only access to Copilot and Agent 365 settings, usage reports, service health, and Entra ID objects.
The Agent Registry is moving from Microsoft Entra to Agent 365 in the Microsoft 365 admin center on 1 May 2026, giving administrators a unified catalog of all agents across the organization. Also, the agent registry Graph API will soon be deprecated and replaced by a new Agent 365 API.
A new Microsoft Entra admin role lets administrators manage granular delegated admin privilege (GDAP) relationships, including accepting, reviewing, and terminating partner access on behalf of the tenant.
Microsoft has added four new admin roles in Entra to manage all aspects of Microsoft Entra Tenant Governance. I am summarizing what each role covers and how they differ.
The AI Administrator role in Microsoft 365 and Entra now includes additional permissions for Agent 365, enabling AI Administrators to manage agents without involving a Global Administrator.
If you still have EnableAzureADB2BIntegration set to False and strict external collaboration settings in Microsoft Entra External ID in place, the upcoming SharePoint OTP retirement will prevent new guest sharing in your tenant. Here is what to expect and how to work around it using Microsoft Graph.
The “Revoke Sessions” action in Microsoft Entra has been updated to invalidate all user sessions, regardless of whether MFA is enforced via Conditional Access or per-user policies.
Microsoft has published two new Entra admin roles: Teams External Collaboration Administrator and Authentication Extensibility Password Administrator, covering Teams External Collaboration settings and Just-In-Time password migration in Entra External ID.
An unknown Copilot agent named Yuwu9669P1 suddenly appeared in Microsoft 365 tenants without clear ownership or documentation. Admins should block this agent, as it is either suspicious or the result of a misdeployment.
Microsoft is rolling out three new Entra admin roles for Microsoft Purview that are automatically managed through Purview role assignments. These roles should not be assigned directly in Entra, as any manual changes will be overwritten.
Microsoft introduced several new licenses, changes to Dataverse storage, and fresh promotions for Microsoft 365 Copilot Business starting 1 December 2025.