đź“‹ Microsoft Entra Documentation Changes

Daily summary for changes since October 26th 2025, 8:13 PM PDT

Report generated on October 27th 2025, 8:13 PM PDT

📊 Summary

10
Total Commits
0
New Files
3
Modified Files
0
Deleted Files
6
Contributors

📝 Modified Documentation Files

+33 / -2 lines changed
Commit: ca-agent-updates-102725
Changes:
Before
After
 
With the Conditional Access optimization agent chat interface, you can use natural language to get more information on a policy suggestion or have the agent present the suggestions in a different order.
 
### Prioritize suggestions
 
With the chat capability you can ask the agent to help you prioritize the suggestions. The agent compares the potential impact of the policy changes and provides a ranked list of suggestions based on [Zero Trust principles](/security/zero-trust/zero-trust-overview), so you don't have to review the full list and make that decision yourself.
 
If you didn't ask the agent to prioritize the order of the suggestions and you ask for more details on the first suggestion, the agent tells you about the first item in the **Recent suggestions** list.
 
### Understand agent decisions
 
In some cases, the agent might identify several policy suggestions that, at first glance, might appear similar to other policies. You can ask the agent to help you understand why one policy was selected for an update when multiple policies could apply. You can ask in the chat why the agent chose a specific policy for update.
 
:::image type="content" source="media/conditional-access-agent-optimization-chat/agent-chat-policy-suggestions.png" alt-text="Screenshot of a policy suggestion details page with the Chat with agent button highlighted." lightbox="media/conditional-access-agent-optimization-chat/agent-chat-policy-suggestions.png":::
 
1. Enter a prompt in the chat window using natural language from the supported scenarios in the [What you can do with chat](#what-you-can-do-with-chat) section.
 
1. Review the response and apply the recommended changes. For more information, see the [Confirm changes in chat](#confirm-changes-in-chat) section.
 
:::image type="content" source="media/conditional-access-agent-optimization-chat/agent-chat-confirm-cancel.png" alt-text="Screenshot of the Conditional Access optimization agent chat with the options to confirm or cancel changes." lightbox="media/conditional-access-agent-optimization-chat/agent-chat-confirm-cancel.png":::
 
With the Conditional Access optimization agent chat interface, you can use natural language to get more information on a policy suggestion or have the agent present the suggestions in a different order.
 
### Explain agent capabilities
 
The Conditional Access Optimization Agent provides several capabilities, so it might help to ask the agent what it can do and how it assists with policy management. The agent can explain its supported functions.
 
Sample prompts:
- *What can the Conditional Access Optimization Agent help me with?*
- *Summarize your capabilities.*
 
### Prioritize suggestions
 
With the chat capability you can ask the agent to help you prioritize the suggestions. The agent compares the potential impact of the policy changes and provides a ranked list of suggestions based on [Zero Trust principles](/security/zero-trust/zero-trust-overview), so you don't have to review the full list and make that decision yourself.
 
If you didn't ask the agent to prioritize the order of the suggestions and you ask for more details on the first suggestion, the agent tells you about the first item in the **Recent suggestions** list.
 
### Explain agent findings
 
Ask the agent to to describe the details about the findings included in a policy suggestion. The agent will clarify the logic behind the suggestion and its impact on security and user experience.
+14 / -10 lines changed
Commit: ca-agent-updates-102725
Changes:
Before
After
 
:::image type="content" source="media/conditional-access-agent-optimization-review-suggestions/review-suggestions-details.png" alt-text="Screenshot of the agent with the policy suggestion details open." lightbox="media/conditional-access-agent-optimization-review-suggestions/review-suggestions-details-expanded.png":::
 
From this view you can make decisions about the suggestion, including:
 
- Turn on a new policy in report-only mode
- Apply changes to an existing policy
- Mark a suggestion as reviewed
- Snooze a suggestion for 14 days
- Add notes about the suggestion for other admins to review
 
You can also edit, duplicate, or download the policy from this page. The policy suggestions detail page is detailed and provides every option needed to make an informed decision about the suggestion. But if you need more information, you can also view the policy impact and see details about the agent's activity.
 
### Policy impact
 
 
Deep analysis performs an in-depth review of Conditional Access policies for scenarios such as blocking legacy authentication, blocking device control flow, and policies that require device or MFA controls. It evaluates the targeted users, groups, and roles to identify coverage gaps, overlapping or redundant policies, and consolidation opportunities. It also analyzes exclusions—flagging policies that exclude a large portion of users and recommending explicit exclusion of break‑glass accounts to reduce the risk of accidental lockout.
 
Because the policy suggestions that come through deep analysis might have a significant impact on your environment, consider using the "snooze" option to give you time to investigate the suggestion and make any needed changes to your policies before applying the suggestion. You can also add notes about the suggestion that can be saved for other admins to review. If you choose to snooze the suggestion, it reappears in the list after 14 days with the notes intact.
 
 
:::image type="content" source="media/conditional-access-agent-optimization-review-suggestions/review-suggestions-details.png" alt-text="Screenshot of the agent with the policy suggestion details open." lightbox="media/conditional-access-agent-optimization-review-suggestions/review-suggestions-details-expanded.png":::
 
From the policy details, you can take action on the suggestion using several options. At the top of the page, you can edit, duplicate, download, or delete the policy. You can also use the [Chat with agent (Preview)](conditional-access-agent-optimization-chat.md) feature.
 
:::image type="content" source="media/conditional-access-agent-optimization-review-suggestions/policy-details-buttons.png" alt-text="Screenshot of the policy details with the buttons highlighted." lightbox="media/conditional-access-agent-optimization-review-suggestions/policy-details-buttons.png":::
 
Below the policy suggestion summary, you can take several actions:
 
- **Review policy changes**: View a summary or JSON details of the suggestion.Further details described in the [Review policy changes](#review-policy-changes) section.
- **Turn on policy**: Turn on new policies that were created in report-only mode by the agent.
- **Mark suggestion as reviewed**: Select from the down arrow on the **Turn on policy** button to indicate that you've reviewed the suggestion without applying it.
- **Snooze for 14 days**: Select from the down arrow on the **Turn on policy** button to temporarily hide the suggestion. The suggestion reappears in the list after 14 days.
- **View agent's full activity**: View the full activity and decisions. Further details described in the [View agent's full activity](#view-agents-full-activity) section.
- **Add notes**: Select the pen and paper icon to add notes about the suggestion for other admins to review
 
The policy suggestions detail page is detailed and provides every option needed to make an informed decision about the suggestion. But if you need more information, you can also view the policy impact and see details about the agent's activity.
Ask Copilot about this file-diff
 
### Policy impact
+3 / -2 lines changed
Commit: preview-cleanup
Changes:
Before
After
The Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion, you can have the agent update the associated policy with one click-remediation.
 
> [!IMPORTANT]
> The chat capability and policy reports in the Conditional Access optimization agent are currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
## Prerequisites
 
### Notifications
 
The Conditional Access optimization agent can send notifications through Microsoft Teams to a select set of recipients. With the **Conditional Access agent** app in Microsoft Teams, recipients receive notifications directly in their Teams chat when the agent surfaces a new suggestion.
 
To add the agent app to Microsoft Teams:
 
At this time, the agent's communication is one direction, so you can receive notifications but can't respond to them in Microsoft Teams. To take action on a suggestion, select **Review suggestion** from the chat to open the Conditional Access optimization agent in the Microsoft Entra admin center.
 
:::image type="content" source="media/conditional-access-agent-optimization/agent-teams-suggestion-message.png" alt-text="Screenshot of the Conditional Access agent notification message in Teams." lightbox="media/conditional-access-agent-optimization/agent-teams-suggestion-message.png":::
### Phased rollout
 
When the agent creates a new policy in report-only mode, the policy is rolled out in phases, so you can monitor the effect of the new policy. Phased rollout is on by default.
The Conditional Access optimization agent evaluates policies such as requiring multifactor authentication (MFA), enforcing device based controls (device compliance, app protection policies, and domain-joined devices), and blocking legacy authentication and device code flow. The agent also evaluates all existing enabled policies to propose potential consolidation of similar policies. When the agent identifies a suggestion, you can have the agent update the associated policy with one click-remediation.
 
> [!IMPORTANT]
> The ServiceNow and Microsoft Teams integrations in the Conditional Access optimization agent are currently in PREVIEW.
> This information relates to a prerelease product that might be substantially modified before release. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
 
## Prerequisites
 
### Notifications
 
As part of a preview capability, the Conditional Access optimization agent can send notifications through Microsoft Teams to a select set of recipients. With the **Conditional Access agent** app in Microsoft Teams, recipients receive notifications directly in their Teams chat when the agent surfaces a new suggestion.
 
To add the agent app to Microsoft Teams:
 
At this time, the agent's communication is one direction, so you can receive notifications but can't respond to them in Microsoft Teams. To take action on a suggestion, select **Review suggestion** from the chat to open the Conditional Access optimization agent in the Microsoft Entra admin center.
 
:::image type="content" source="media/conditional-access-agent-optimization/agent-teams-suggestion-message.png" alt-text="Screenshot of the Conditional Access agent notification message in Teams." lightbox="media/conditional-access-agent-optimization/agent-teams-suggestion-message.png":::
 
### Phased rollout