← Previous day

Keep up with Microsoft Entra

Daily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →

Day in brief

SOC Identity Responder guidance names containment actions; Agent ID sponsors cannot restore agents

Role and permission references dominate 4 September: the June 2026 update records the Entra SOC Identity Responder role and changes to Security Operator and AI Administrator definitions, while companion pages spell out SOC containment and privileged-account boundaries. Agent ID pages define what sponsors can disable or delete and who must restore agents. Two same-day permissions-reference edits also give opposing descriptions of Security Administrator’s containment authority.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

9 updates

4

Whats New

New feature

The June 2026 update adds the Entra SOC Identity Responder role and updates the Security Operator and AI Administrator roles.

Delegate By Task

Feature update

The documentation now lists Security Administrator, alongside Helpdesk Administrator and User Administrator, for invalidating non-admin users’ refresh tokens.

Permissions Reference

Doc update

The permissions reference now documents the Entra SOC Identity Responder role and its identity-containment actions, including disabling users, revoking active sign-in sessions, and resetting passwords.

Least privileged roles by task

New feature

The task delegation table now maps identity containment actions for SOC incident response to the Entra SOC Identity Responder role.

2

Permissions Reference

Doc update

The permissions reference no longer states that Security Administrators can perform identity containment actions during security incidents. It now describes the role as reading security information and reports and managing configuration in Microsoft Entra ID and Office 365.

Permissions Reference

Doc update

The role description now states that Security Administrators can perform identity containment actions during security incidents.

1

Privileged Roles Permissions

Doc update

The documentation now lists Security Administrator alongside Security Operator and Entra SOC Identity Responder as limited to non-administrative user accounts and unable to act on privileged accounts.

1

Manage Agent Identities End User

Doc update

The documentation now states that sponsors cannot re-enable disabled agents; an owner or administrator must help re-enable them.

1

Agent Owners Sponsors Managers

Doc update

Sponsors can disable agent identities, modify sponsors, and soft-delete resources, but cannot enable or restore agent blueprints or identities.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…