Whats New
New featureThe June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
Role and permission references dominate 4 September: the June 2026 update records the Entra SOC Identity Responder role and changes to Security Operator and AI Administrator definitions, while companion pages spell out SOC containment and privileged-account boundaries. Agent ID pages define what sponsors can disable or delete and who must restore agents. Two same-day permissions-reference edits also give opposing descriptions of Security Administrator’s containment authority.
The Permissions Reference now describes the role’s identity-containment actions as disabling users, revoking active sign-in sessions, and resetting passwords.
Privileged Roles Permissions now lists Security Administrator, Security Operator, and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.
One updated reference removes the statement that Security Administrators can perform identity-containment actions and instead describes reading security information and reports and managing Microsoft Entra ID and Office 365 configuration. A separate same-day entry says the role description now states that Security Administrators can perform identity containment during security incidents.
Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.
The end-user guidance says sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.
The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.
The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.
The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.
The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.
The role description now states that Security Administrators can perform identity containment actions during security incidents.
The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.
The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.
Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.