← Previous day

Next day →
Microsoft Entra daily update

What changed on this day

14 changes were tracked across 5 Microsoft Entra products. The leading updates include Troubleshoot Conditional Access policies for Security Copilot; Copilot Entra Security Scenarios; Security Best Practices For App Registration.

14 updates

Monitoring

2

userimpact: Low

Updated

Organizations without proper activation alerts for highly privileged roles lack visibility into when users access these critical permissions. Threat actors can exploit this monitoring gap to perform privilege escalation by activating highly privileged roles without detection, then establish persistence through admin account creation or security policy modifications. The absence of real-time alerts enables attackers to conduct lateral movement, modify audit configurations, and disable security controls without triggering immediate response procedures.

Sla Performance

Updated

| February | 99.999% | 99.999% | 99.999% | 99.999% | 99.998% |

Fundamentals

1

Microsoft identity platform

1

Troubleshooting

1

Fundamentals

2

Copilot Entra Security Scenarios

Updated

- [Investigate insights within entitlements management](#investigate-insights-within-entitlements-management): Get quick access to information about access packages, policies, connected organizations, and catalog resources.

Microsoft Entra Id Governance Licensing For Guest Users

Updated

Microsoft Entra ID Governance utilizes Monthly Active User (MAU) licensing for guest users which is different than licensing for employees. See [Microsoft Entra ID Governance licensing fundamentals](/entra/id-governance/licensing-fundamentals) for complete details on licensing for employees.

Governance

2

Entitlement Management Dynamic Approval

Updated

In entitlement management, approvers for access package requests can either be directly assigned, or determined dynamically. Entitlement management natively supports approvers when they are the requestors manager, their second-level manager, or a sponsor from a connected organization:

Developer

1

Microsoft Accounts Federation Customers

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

Fundamentals

1

Cross Tenant Access Overview

Updated

- If you block access to all apps by default, users are unable to read emails encrypted with Microsoft Rights Management Service, also known as Office 365 Message Encryption (OME). To avoid this issue, we recommend configuring your outbound settings to allow your users to access this app ID: 00000012-0000-0000-c000-000000000000. If you allow only this application, access to all other apps is blocked by default.

Governance

1

userimpact: Low

Updated

Azure Logic Apps integrated with Microsoft Entra Identity Governance create a significant attack surface when access controls are inadequate. Threat actors can exploit misaligned permissions between Logic Apps management roles and Microsoft Entra directory roles to gain initial access through compromised accounts with excessive Azure RBAC permissions. With access, threat actors can modify workflow logic to insert malicious automation into provisioning processes, then use managed identities and existing connections for lateral movement across connected systems.

Security

1

Troubleshooting

1