The Entra ID news cycle is in a brief calm before the September 1 passkeys-by-default storm, but Microsoft hasn’t stopped shipping. This week’s batch is smaller in volume but includes one significant preview feature for AI agent governance, a policy process change that tightens the review window, and a licensing expansion that could reshape how E3 customers adopt advanced identity protection. Here’s what changed in the days leading up to August 9, 2026.

1. Entra Agent ID for Dataverse — AI Agents Get Their Own Identities in Power Platform (Public Preview)

The most consequential announcement this week is the public preview of Microsoft Entra Agent ID for Dataverse, published August 6 on the Power Platform blog. If your organization is building AI agents on Copilot Studio or Azure AI Foundry that interact with business data in Dataverse, this changes the identity model fundamentally.

What It Does

Until now, AI agents accessing Dataverse typically used shared application identities or ran under the context of the user who triggered them. There was no clean way to say “this specific agent accessed this specific record” — you’d see the application identity or the user’s identity in the audit logs, not the agent’s.

Entra Agent ID for Dataverse solves this by giving each AI agent its own identity — a dedicated, individually identifiable, policy-controlled security principal that exists in both Entra ID and Dataverse.

The model is a split architecture:

  • Microsoft Entra handles enterprise identity, authentication, and policy (Conditional Access, Identity Protection, lifecycle management)
  • Dataverse / Power Platform handles in-environment authorization — assigning Dataverse security roles, enforcing least-privilege access to tables and records, and attributing actions in audit logs

How It Works

The setup is straightforward:

  1. Create or enable the agent identity through a supported Microsoft agent creation experience (Copilot Studio, Azure AI Foundry, or other supported tooling)
  2. Add the Entra agent identity to your Dataverse environment as a Dataverse agent user via the Power Platform admin center
  3. Assign a dedicated Dataverse security role that follows least-privilege principles — the agent should only have access to the tables and actions it needs
  4. Test and verify that expected operations succeed, denied operations fail, and all agent actions are visible in audit and monitoring processes

Why This Matters

This is a meaningful step toward treating AI agents as first-class citizens in enterprise identity governance. Instead of agents being anonymous automations or borrowing human credentials, each agent gets:

  • Authentication: A distinct enterprise identity with its own credentials and tokens
  • Authorization: Specific Dataverse security roles scoped to what the agent actually needs to do
  • Auditability: Every data access and change is attributed to the specific agent, not a shared identity
  • Lifecycle management: Agents can be created, updated, and retired with the same governance as human users

For organizations worried about shadow AI and unmanaged agent sprawl — which, according to Microsoft’s own Identiverse 2026 roundtable, is already a reality for 9 out of 10 organizations — this provides a path to bring agent access under governance.

Context: Copilot Studio Agent ID Migration

Copilot Studio has been automatically creating Entra Agent IDs for all new agents since July 2026 (mandatory, no opt-out). Agents created before July 2026 still use traditional app registrations and will be migrated to Agent IDs in a future update. If you’re building new agents today, they’ll automatically get Agent IDs — the Dataverse integration extends that identity into Power Platform environments.

Licensing

Full Agent ID capabilities (Conditional Access for agents, Identity Protection for agents) require Microsoft Agent 365, which is included with Microsoft 365 E7 and available as an add-on to E5, A5, Business Premium, or Defender Suite plus Purview Suite.

The Dataverse agent user feature itself is in public preview. Microsoft’s release plan indicates general availability is targeted for August 2026, though the August 6 blog post still references preview status. Evaluate for pilot use, not production workloads yet.

2. Managed Policies Review Window Shortened from 45 to 30 Days

On August 8, Microsoft updated the Entra ID Managed Policies documentation with a change that affects your change management process. The documented review period for managed policies in Report-only mode has been shortened from 45 days to at least 30 days before Microsoft may enable them automatically.

What Changed

The Managed Policies page now states:

  • Microsoft may enable a managed policy at least 30 days after introduction when it remains in Report-only (previously 45 days)
  • A security group is created with the high-risk remediation policy (newly documented)

Why This Matters

Managed policies are Microsoft-enforced Conditional Access policies that ship in Report-only mode to give organizations time to evaluate their impact before automatic enforcement. Losing 15 days of review time means your change management process needs to be faster.

If your organization has been treating the 45-day window as the standard review cycle for new managed policies, update your runbooks. The new window is 30 days minimum — Microsoft could enable enforcement sooner if they deem it necessary, but 30 days is the documented floor.

The newly documented security group for high-risk remediation is also worth noting. If your organization has high-risk users or sign-ins that trigger managed policy remediation, a security group will be created automatically. Admins should be aware this group exists and may need to be reviewed as part of your governance processes.

3. CSP Security Add-Ons for Microsoft 365 E3 — Entra ID P2 Now Available Without E5 Upgrade

Announced August 6 in the Microsoft Partner Center, new security add-on offers are now available through Cloud Solution Provider (CSP) with consistent pricing across Enterprise Agreements and CSP:

  • Microsoft Entra ID P2 add-on for Microsoft 365 E3
  • Microsoft Defender for Endpoint P2 add-on for Microsoft 365 E3
  • Microsoft Defender for Office 365 P2 add-on for Microsoft 365 E3

Why This Matters

Previously, organizations on Microsoft 365 E3 who wanted Entra ID P2 features — Conditional Access, Privileged Identity Management (PIM), Identity Protection, Entitlement Management — had limited options. They could upgrade to E5, which is a significant cost jump, or pursue Enterprise Agreement add-ons, which weren’t available through all licensing channels.

With this announcement, CSP partners can offer Entra ID P2 as a standalone add-on to E3 customers. This democratizes access to advanced identity protection features:

  • Conditional Access — the policy engine that controls who can access what, from where, under what conditions
  • Privileged Identity Management — just-in-time admin access with approval workflows and audit trails
  • Identity Protection — risk-based Conditional Access powered by Microsoft’s threat intelligence
  • Entitlement Management — structured access packages for onboarding, offboarding, and cross-organizational access

For Big Hat Group and other Microsoft partners, this creates a new conversation starter with E3 customers. The barrier to adopting advanced identity security just dropped significantly.

Pricing

Microsoft has committed to consistent pricing across EA and CSP channels for these add-ons, removing a historical friction point where CSP pricing could be less predictable. Check the current price list in Partner Center for specifics.

4. July SLA Performance Data Corrected

A minor reference update: the Entra ID SLA Performance table now includes an additional 99.999% value in the July row. This is a data correction, not a product or service change. If you track SLA performance metrics for compliance or reporting purposes, update your records.

Key Dates Summary

DateEvent
September 1, 2026Passkeys become default authentication method (auto-enabled for SMS/voice users)
September 18, 2026Telecom partner details published for SMS/voice continuation
October 5, 2026SSPR registration campaign begins
October 30, 2026Telecom partner configuration opens in Microsoft Security Store
November 3, 2026MemberOf rule operator retirement
November 9, 2026SSPR enforcement — only registered methods accepted
February 1, 2027Microsoft-provided SMS/voice authentication retired

Action Items for Admins

  1. Evaluate Entra Agent ID for Dataverse if you’re building AI agents on Power Platform — set up a pilot environment, create an agent identity, and test the security role assignment model
  2. Update your managed policies review process — the 45-day window is now 30 days. Adjust your change management timelines accordingly
  3. Review CSP add-on opportunities if you’re a Microsoft partner — Entra ID P2 as an E3 add-on opens new conversations with customers who couldn’t justify E5 upgrades
  4. Update SLA records if you track Entra ID SLA performance — July data has been corrected

The Bigger Picture

This week’s updates are relatively quiet compared to the waves of passkey and authentication changes rolling through August. But the Entra Agent ID for Dataverse preview is significant — it’s one of the first concrete implementations of treating AI agents as identity-aware entities with governance, rather than as automations that borrow credentials. As agent sprawl continues to accelerate, this model will become the standard for how organizations secure and manage AI workloads.

The CSP licensing change is also quietly important. Making Entra ID P2 accessible to E3 customers through CSP removes a significant adoption barrier for advanced identity protection. Expect to see more E3 organizations adopting Conditional Access, PIM, and Identity Protection as a result.

We’ll be watching for the September 1 passkeys-by-default rollout — that’s the next major milestone. Until then, use this quieter period to get your managed policies review processes updated and evaluate whether Agent ID for Dataverse fits your AI agent strategy.

Follow the conversation on X at https://x.com/kkaminsk for real-time updates and analysis.


Big Hat Group Inc. is a Microsoft partner with 20+ years of experience helping organizations navigate identity and security transformations. Contact us to discuss how these changes affect your environment and how we can help you plan your migration.